Weekly review

ThreatNoir Morning Brief — June 19

2026-06-19Morning4 articles
Audio
Listen to the episode

Morning Review in IT Security — June 19, 2026

The threat landscape continues to evolve rapidly as adversaries develop sophisticated evasion techniques, supply chain attacks proliferate, and law enforcement achieves significant victories against established criminal operations. Today's security briefing covers critical developments spanning ransomware defense evasion, open-source software compromises, major vendor patching efforts, and a significant botnet disruption.

Gentlemen Ransomware Deploys Multiple EDR Killers to Evade Detection

The Gentlemen ransomware-as-a-service operation has actively developed and deployed a comprehensive suite of endpoint detection and response killers designed to help affiliates disable security defenses during attacks. The threat actors have created multiple specialized tools including GentleKiller, HavocKiller, HexKiller, OxideHarvest, SystemBC, and ThrottleBlood to systematically neutralize EDR solutions before executing their encryption payloads. This represents a significant escalation in the sophistication of ransomware operations, as attackers increasingly focus on blinding defenders rather than relying solely on encryption capabilities. Source: Gentlemen ransomware uses multiple EDR killers to disable defenses

TeamPCP's Supply Chain Attack Reveals Industry's Security Vulnerabilities

The threat group TeamPCP has successfully poisoned over 1,000 open-source software packages within a four-month campaign, exposing fundamental weaknesses in the software development ecosystem's trust model. Security researchers attribute this remarkable success to the industry's widespread prioritization of rapid code shipping over security implementation and review processes. The attack demonstrates how the velocity-focused culture of modern software development has created an environment where malicious contributions can slip through inadequate vetting mechanisms. Source: How software development's speed obsession enabled TeamPCP's chaos crusade

Oracle Releases Critical Patch Update Addressing 245 Vulnerabilities

Oracle released its June 2026 Critical Patch Update, addressing 245 security vulnerabilities across multiple product families and third-party components. The quarterly update includes patches for several critical remote code execution flaws, with affected products including Oracle Fusion Middleware receiving the highest concentration of patches. Notable vulnerabilities addressed in this update include CVE-2026-35278, CVE-2026-46850, CVE-2026-46860, and CVE-2026-46861. Organizations running Oracle infrastructure should prioritize testing and deployment of these patches to mitigate exposure to actively exploitable vulnerabilities. Source: Oracle Critical Patch Update, June 2026 Security Update Review

Law Enforcement Successfully Dismantles Evil Corp's SocGholish Botnet

International authorities have disrupted the SocGholish botnet operated by Evil Corp, taking down 106 command-and-control servers and remediating nearly 15,000 infected websites. The coordinated operation between cybersecurity firms, researchers, and law enforcement agencies targeted the FakeUpdates malware distribution mechanism and the SocGholish botnet infrastructure that had been used to deliver secondary payloads to compromised systems. This takedown represents a significant blow to one of the most prolific malware distribution networks in operation. Source: Authorities disrupt Evil Corp's SocGholish botnet

These developments underscore the ongoing arms race between defenders and attackers, the critical importance of secure software development practices, and the continued success of coordinated international law enforcement efforts against cybercriminal infrastructure.

Sources & IOCs

Source articles and extracted indicators (defanged where appropriate).

Gentlemen ransomware uses multiple EDR killers to disable defenses
Malware6
  • OxideHarvest
    Rust-based credential-stealer tool used by Gentlemen ransomware
  • SystemBC
    Proxy malware botnet linked to Gentlemen ransomware victims
  • GentleKiller
    EDR killer tool used by Gentlemen ransomware
  • HexKiller
    External EDR killer tool incorporated by Gentlemen ransomware
  • ThrottleBlood
    External EDR killer tool incorporated by Gentlemen ransomware
  • HavocKiller
    External EDR killer tool incorporated by Gentlemen ransomware