Full Report
Courts sentence Com member for sextorting 117 minors, joint advisory warns of Gunra ransomware, and ShieldBreak bypasses MS Defender for SYSTEM access.
Analysis Summary
# Morning News Roll-up August 14, 2026
## Overview
This week's intelligence highlights the sentencing of a prominent "The Com" cybercrime syndicate member for global sextortion, a joint international advisory regarding the rising Gunra ransomware threat targeting critical infrastructure, and the emergence of "ShieldBreak" techniques used to bypass Microsoft Defender for system-level access.
## Top Stories
### "The Com" Member Sentenced for Global Blackmail and Sextortion Campaign
- Summary: Justin Swaddle, a member of the decentralized syndicate "The Com," was sentenced to two years in prison for targeting 117 minors across Discord and Telegram. The group is noted for its diverse criminal factions ranging from physical violence to corporate ransomware.
- Source: hxxps://www[.]nationalcrimeagency[.]gov[.]uk/news/com-group-member-sentenced-for-campaign-of-abuse-against-117-victims-worldwide
### Joint Advisory Issued for Gunra Ransomware Operations
- Summary: U.S., U.K., and South Korean agencies warned of Gunra ransomware, a Conti-based variant exploiting FortiOS vulnerabilities (CVE-2024-55591) to target critical infrastructure in the public health, finance, and government sectors.
- Source: hxxps://content[.]govdelivery[.]com/accounts/USDHSCISA/bulletins/4244745
### ShieldBreak Tool Bypasses MS Defender for SYSTEM Access
- Summary: Recent findings detail "ShieldBreak," a method used by threat actors to circumvent Microsoft Defender security controls. By bypassing these protections, attackers gain high-level SYSTEM access to execute malicious payloads and move laterally within networks.
- Source: hxxps://www[.]sentinelone[.]com/blog/the-good-the-bad-and-the-ugly-in-cybersecurity-week-33-8/
---
# Gunra Ransomware & ShieldBreak Exploitation
This campaign involves the use of Gunra ransomware (a Conti-derived variant) and the ShieldBreak bypass technique to compromise critical infrastructure and maintain persistent access to high-value networks.
## Key Points
- **Cross-Platform Evolution:** Gunra has transitioned from Windows-only to cross-platform operations, increasing its footprint.
- **Double Extortion:** The group utilizes "double extortion," stealing sensitive data before encrypting it to increase leverage during ransom negotiations.
- **Critical Vulnerability Exploitation:** Attackers are actively exploiting N-day vulnerabilities in network edge devices (FortiOS) to gain initial entry.
- **Defender Circumvention:** The use of "ShieldBreak" allows actors to disable or bypass Microsoft Defender, facilitating undetected SYSTEM-level privilege escalation.
## Threat Actors
- **Gunra Ransomware Group:** A specialized ransomware faction utilizing leaked Conti source code.
- **The Com:** A loose-knit global network involved in diverse cyber-physical crimes, including high-profile corporate ransomware.
- **Motivations:** Primarily financial gain (Gunra) and social status/notoriety (individual Com members).
## TTPs
- **Exploitation of Edge Gateways:** Targeting VPNs and firewalls for initial access.
- **Privilege Escalation:** Utilizing ShieldBreak to bypass EDR/AV and gain SYSTEM privileges.
- **Lateral Movement:** Moving through networks once security software is neutralized.
- **Social Engineering:** Grooming and blackmail techniques used by syndicate members on chat platforms.
- **MITRE ATT&CK:** T1190 (Exploit Public-Facing Application), T1562.001 (Impair Defenses: Disable or Modify Tools), T1068 (Exploitation for Privilege Escalation).
## Affected Systems
- **Fortinet FortiOS & FortiProxy:** Specifically versions vulnerable to CVE-2024-55591 and CVE-2025-24472.
- **Microsoft Windows:** Systems running Microsoft Defender targeted by ShieldBreak.
- **Critical Infrastructure:** Public health, financial services, and government agencies globally.
## Mitigations
- **Patch Management:** Immediately update FortiOS and FortiProxy to the latest versions to remediate CVE-2024-55591 and CVE-2025-24472.
- **EDR Hardening:** Implement tamper protection for endpoint security solutions to prevent tools like ShieldBreak from disabling defenses.
- **Network Segmentation:** Isolate critical infrastructure components from the public internet where possible.
- **Multi-Factor Authentication (MFA):** Enforce robust MFA on all VPN gateways and administrative interfaces.
## Conclusion
The convergence of specialized ransomware variants (Gunra) and sophisticated bypass techniques (ShieldBreak) represents a significant escalation in threats to critical infrastructure. Organizations must prioritize patching edge devices and hardening endpoint defenses against bypass tools. Furthermore, the activities of "The Com" demonstrate that decentralized syndicates pose a multifaceted threat across both digital and physical domains.