The Good, the Bad and the Ugly in Cybersecurity , Week 33 (2026)
Strategic summary
The report covers the sentencing of a member of the cybercrime collective "The Com" for blackmail and sextortion, as well as warnings about Gunra ransomware. A UK court sentenced Justin Swaddle to two years in prison after he manipulated and blackmailed 117 minors worldwide. At the same time, US, UK, and South Korean agencies warn of expanding Gunra ransomware operations targeting critical infrastructure. For manufacturing companies in the DACH region, this highlights the need for robust defenses against cybercrime and ransomware.
Key findings
- A UK court sentenced Justin Swaddle, a member of "The Com", to two years in prison for blackmail and sexual abuse of 117 minors.
- Swaddle used Discord, Snapchat, and Telegram to manipulate victims and blackmailed them with intimate recordings and personal data.
- The investigation required cross-border cooperation among law enforcement in the UK, US, Australia, Canada, Norway, and New Zealand.
- US, UK, and South Korean agencies jointly warn of expanding Gunra ransomware operations targeting critical infrastructure.
- "The Com" is a decentralized global network with specialized groups for physical violence, sexual coercion, financial extortion, and corporate ransomware attacks.
Relevance for you
A newly disclosed zero-day in Microsoft Defender (ShieldBreak) bypasses a July patch for privilege escalation and is actively discussed; organizations with Defender deployment should prioritize security updates immediately.
Full text
[The Good, the Bad and the Ugly in Cybersecurity – Week 33 (2026)]
OneCon26: Gain the advantage in the AI era. Oct. 20–22 in Las Vegas.Register Now
Solutions & Use Cases
Security Tuned for Your Industry.
Experiencing a breach?
Our experts are here to help 24/7.
[1-855-868-3733](tel:1-855-868-3733)
One-Click Integrations for Unified Prevention, Detection, and Response
Customer Success & Support
4 min read Aug 14, 2026
))&body=https%3A%2F%2Fwww.sentinelone.com%2Fblog%2Fthe-good-the-bad-and-the-ugly-in-cybersecurity-week-33-8%2F)
The Good | Courts Sentence “The Com” Online Syndicate Member for Blackmail & Sextortion
A court in the UK has sentenced a member of the decentralized online cybercrime collective known as “The Com” to two years in prison following an investigation by the National Crime Agency (NCA). Justin Swaddle, who operated under the digital aliases ‘Epstein’, ‘Rugen’, and ‘Moscow’ across Discord, Snapchat, and Telegram, pleaded guilty to multiple criminal charges of blackmail and child abuse. In addition to his sentence, the court ordered Swaddle’s placement on the National Sex Offenders Register and imposed a ten-year Sexual Harm Prevention Order.
Investigators revealed that Swaddle systematically targeted and groomed young, vulnerable victims globally, using popular chat platforms to exploit his targets. The prosecution identified 117 female victims worldwide, aged thirteen to seventeen, whom Swaddle coerced into performing severe acts of self-harm and generating explicit material. Rather than seeking financial gain, Swaddle was reportedly motivated by the online status and notoriety he obtained by sharing the media within exclusive subgroups. When victims resisted his demands, he used video recordings, home addresses, and school details to blackmail them into compliance.
The investigation, which the NCA initiated in January 2024 following Swaddle’s initial arrest by West Yorkshire Police, required extensive cross-border coordination. British officers collaborated closely with law enforcement agencies in the United States, Australia, Canada, Norway, and New Zealand to identify and safeguard affected children worldwide.
Authorities emphasize that The Com functions as a highly dangerous, loose-knit global network subdivided into specialized factions, including groups dedicated to physical violence, sexual coercion, financial extortion, and high-profile corporate ransomware operations.
The Bad | Agencies Warn of Expanding Gunra Ransomware Operations Targeting Critical Infrastructure
U.S., U.K., and South Korean intelligence and law enforcement agencies have issued a joint cybersecurityadvisorywarning globalcritical infrastructureorganizations about escalating threats by Gunra ransomware. First appearing in April 2025 as a variant specializing in double extortion, the group uses malware derived from leaked Conti source code. Gunra targets public health, financial, and government sectors worldwide, with a heavy concentration of victims in Australia, East Asia, and Europe.
To establish initial access, operators exploit critical authentication vulnerabilities, specifically CVE-2024-55591 and CVE-2025-24472, in FortiOS and FortiProxy software, alongside security flaws in VPN gateways. While campaigns initially focused on Windows environments, the threat actors expanded to cross-platform operations by introducing a Linux variant. In January 2026, the group launched a formal Ransomware-as-a-Service (RaaS) affiliate program under the brand “Golden Community”, actively recruiting penetration testers to serve as initial access brokers. Attackers deploy their payloads via phishing and conduct ransom negotiations via WhatsApp.
Once inside a network, the actors utilize Impacket tools for credential dumping and lateral movement. They execute malicious tasks during nighttime hours, exfiltrating stolen documents to cloud services and deleting critical backup and archived data across primary and recovery centers. The malware leverages advanced ciphers like Salsa20 or ChaCha20 to encrypt terabytes of data in a limited timeframe.
Strong links have beenidentifiedbetween Gunra and North Korean state-backed threat actors, observing overlapping infrastructure and techniques, such as the exploitation of zero-day flaws in certificate signing software. Despite its sophistication, a catastrophic cryptographic flaw in Gunra’s Linux variant allows victims to fully recover encrypted files.
The Ugly | New ‘ShieldBreak’ Zero-Day Exploit Bypasses Microsoft Defender Protections
A security researcher known as ‘Nightmare Eclipse’ has released a novel Microsoft Defender zero-day exploit dubbed ‘ShieldBreak’ shortly after this month’s Patch Tuesdayupdate. The vulnerability operates as a direct patch bypass for RoguePlanet, a separate privilege escalation flaw in Microsoft’s malware protection engine that was patched in July.
ShieldBreak PoC exploit demo (Source: Nightmare Eclipse)
Although both flaws lead to SYSTEM-level compromise, researchers confirm the underlying exploitation techniques differ significantly. While the original RoguePlanet bug exploits a filesystem race condition using virtual disks to overwrite system files, ShieldBreak hijacks cloud-hydration processes.
Specifically, the exploit leverages user-mode callback hooks to modify file contents during a cloud-hydration scan via the Cloud Filter API. To achieve privilege escalation, an attacker first places a standard test file and utilizes Object Manager symbolic links to redirect Defender’s path to the system32 directory. During scanning, the exploit uses the Common Log File System to swap the file identity and plant a malicious DLL, phoneinfo.dll, where a default system file does not exist. Triggering a scheduled Windows Error Reporting task subsequently forces the system to load this rogue library, spawning a shell with highest privileges.
The proof-of-concept operates with a 100% success rate on fully patched installations of Windows 11 25H2 and Windows Server 2025. Although Windows 10 remains vulnerable to the flaw, the current code does not natively support those legacy systems. Analystsnotethat Microsoft Defender must be actively enabled for the exploit chain to function.
Was this article helpful?
- The Good, the Bad and the Ugly 5 min read
The Good, the Bad and the Ugly in Cybersecurity – Week 33 (2025) * The Good, the Bad and the Ugly 4 min read
The Good, the Bad and the Ugly in Cybersecurity - Week 17 (2025) * The Good, the Bad and the Ugly 4 min read
The Good, the Bad and the Ugly in Cybersecurity - Week 49 (2024) * The Good, the Bad and the Ugly 5 min read
The Good, the Bad and the Ugly in Cybersecurity - Week 34 (2024)
Get the Latest From the SentinelOne Blog
Key Products & Solutions
When you visit any website, it may store or retrieve information on your browser, mostly in the form of cookies. This information might be about you, your preferences, or your device, and is mostly used to make the site work as you expect. The information does not usually identify you directly, but it can give you a more personalized web experience. Because we respect your right to privacy, you can choose not to allow some types of cookies. Click on the different category headings to learn more and change our default settings. Blocking some types of cookies may impact your experience of the site and the services we are able to offer.
Risk score
- cvss base
- 0.00
- kev bonus
- 0.00
- epss bonus
- 0.00
- poc bonus
- 15.00
- raw before weight
- 15.00
- industry weight
- 1.21
- freshness factor
- 0.50
- exploitability factor
- 1.00
- days old
- 26.00
- vendor mismatch penalty
- 0.00
- consensus penalty
- -8.00
Path: operational
Consensus check
The pipeline self-checks before delivery. These rules lowered the score:
-
VENDOR_MISMATCHVendor not found in alert title −5 -
TTP_SKIPPEDTTP mapping skipped (placeholder or aggregation article) −3
- Consensus penalty:
- −8.0
- Total penalty:
- −8.0