The Good, the Bad and the Ugly in Cybersecurity
The Good | Courts Sentence âThe Comâ Online Syndicate Member for Blackmail & Sextortion
A court in the UK has sentenced a member of the decentralized online cybercrime collective known as âThe Comâ to two years in prison following an investigation by the National Crime Agency (NCA). Justin Swaddle, who operated under the digital aliases âEpsteinâ, âRugenâ, and âMoscowâ across Discord, Snapchat, and Telegram, pleaded guilty to multiple criminal charges of blackmail and child abuse. In addition to his sentence, the court ordered Swaddleâs placement on the National Sex Offenders Register and imposed a ten-year Sexual Harm Prevention Order.
Investigators revealed that Swaddle systematically targeted and groomed young, vulnerable victims globally, using popular chat platforms to exploit his targets. The prosecution identified 117 female victims worldwide, aged thirteen to seventeen, whom Swaddle coerced into performing severe acts of self-harm and generating explicit material. Rather than seeking financial gain, Swaddle was reportedly motivated by the online status and notoriety he obtained by sharing the media within exclusive subgroups. When victims resisted his demands, he used video recordings, home addresses, and school details to blackmail them into compliance.
The investigation, which the NCA initiated in January 2024 following Swaddleâs initial arrest by West Yorkshire Police, required extensive cross-border coordination. British officers collaborated closely with law enforcement agencies in the United States, Australia, Canada, Norway, and New Zealand to identify and safeguard affected children worldwide.
Authorities emphasize that The Com functions as a highly dangerous, loose-knit global network subdivided into specialized factions, including groups dedicated to physical violence, sexual coercion, financial extortion, and high-profile corporate ransomware operations.
The Bad | Agencies Warn of Expanding Gunra Ransomware Operations Targeting Critical Infrastructure
U.S., U.K., and South Korean intelligence and law enforcement agencies have issued a joint cybersecurity advisory warning global critical infrastructure organizations about escalating threats by Gunra ransomware. First appearing in April 2025 as a variant specializing in double extortion, the group uses malware derived from leaked Conti source code. Gunra targets public health, financial, and government sectors worldwide, with a heavy concentration of victims in Australia, East Asia, and Europe.
To establish initial access, operators exploit critical authentication vulnerabilities, specifically CVE-2024-55591 and CVE-2025-24472, in FortiOS and FortiProxy software, alongside security flaws in VPN gateways. While campaigns initially focused on Windows environments, the threat actors expanded to cross-platform operations by introducing a Linux variant. In January 2026, the group launched a formal Ransomware-as-a-Service (RaaS) affiliate program under the brand âGolden Communityâ, actively recruiting penetration testers to serve as initial access brokers. Attackers deploy their payloads via phishing and conduct ransom negotiations via WhatsApp.
Once inside a network, the actors utilize Impacket tools for credential dumping and lateral movement. They execute malicious tasks during nighttime hours, exfiltrating stolen documents to cloud services and deleting critical backup and archived data across primary and recovery centers. The malware leverages advanced ciphers like Salsa20 or ChaCha20 to encrypt terabytes of data in a limited timeframe.
Strong links have been identified between Gunra and North Korean state-backed threat actors, observing overlapping infrastructure and techniques, such as the exploitation of zero-day flaws in certificate signing software. Despite its sophistication, a catastrophic cryptographic flaw in Gunraâs Linux variant allows victims to fully recover encrypted files.
The Ugly | New âShieldBreakâ Zero-Day Exploit Bypasses Microsoft Defender Protections
A security researcher known as âNightmare Eclipseâ has released a novel Microsoft Defender zero-day exploit dubbed âShieldBreakâ shortly after this monthâs Patch Tuesday update. The vulnerability operates as a direct patch bypass for RoguePlanet, a separate privilege escalation flaw in Microsoftâs malware protection engine that was patched in July.
Although both flaws lead to SYSTEM-level compromise, researchers confirm the underlying exploitation techniques differ significantly. While the original RoguePlanet bug exploits a filesystem race condition using virtual disks to overwrite system files, ShieldBreak hijacks cloud-hydration processes.
Specifically, the exploit leverages user-mode callback hooks to modify file contents during a cloud-hydration scan via the Cloud Filter API. To achieve privilege escalation, an attacker first places a standard test file and utilizes Object Manager symbolic links to redirect Defenderâs path to the system32 directory. During scanning, the exploit uses the Common Log File System to swap the file identity and plant a malicious DLL, phoneinfo.dll
, where a default system file does not exist. Triggering a scheduled Windows Error Reporting task subsequently forces the system to load this rogue library, spawning a shell with highest privileges.
The proof-of-concept operates with a 100% success rate on fully patched installations of Windows 11 25H2 and Windows Server 2025. Although Windows 10 remains vulnerable to the flaw, the current code does not natively support those legacy systems. Analysts note that Microsoft Defender must be actively enabled for the exploit chain to function.
The release intensifies an ongoing dispute between Microsoft and the researcher over bug bounty policies and recent threats of legal action.
How it works
Once you click Generate, Ollama reads this article and crafts 5 comprehension questions. Your answers are graded against the article content â general knowledge won't be enough. Score 70+ to count toward your certificate.
Questions are cached â you'll always get the same 5 for this article.