Thursday, May 28, 2026
Daily digest
The Gentlemen ransomware writeup from Microsoft is the standout technical read today — a self-propagating Go-based encryptor with aggressive lateral movement that could tear through a flat network fast. Pair that with the DoD contractor security strain story and it's a good day to review your segmentation and incident response plans.
The Gentlemen Ransomware: Dissecting a Self-Propagating Go Encryptor
Microsoft Threat Intelligence published a deep-dive on 'The Gentlemen,' a Go-based ransomware deployed by Storm-2697 affiliates that uses per-file ephemeral key encryption and an aggressive self-propagation module to spread laterally across an entire network simultaneously. The malware abuses trusted internal infrastructure paths to move between hosts, making detection harder in environments that rely on endpoint management tooling. Organizations running AHV or any flat east-west network should treat this as a high-priority review item for segmentation and EDR coverage.
Threat Actors Exploit Critical FortiClient EMS Flaw to Deploy Credential Stealer
Attackers are actively exploiting a patched critical vulnerability in Fortinet's FortiClient Endpoint Management Server to deliver credential-stealing malware across managed endpoints, with the campaign specifically abusing the trusted EMS infrastructure to propagate payloads. Arctic Wolf notes the actors disguised the stealer as a legitimate Fortinet component, making detection difficult without behavioral controls. If FortiClient EMS is in your stack, verify patching status immediately and audit endpoint management traffic for anomalies.
New Gogs Zero-Day Flaw Lets Hackers Get Remote Code Execution
An unpatched zero-day vulnerability in Gogs, a popular self-hosted Git service, allows unauthenticated remote code execution on internet-facing instances with no vendor fix currently available. Organizations running internal source control on Gogs — including those using it for Ansible playbook or infrastructure-as-code repositories — should consider firewall isolation or migration to a patched alternative immediately. This is particularly relevant in environments where Git infrastructure touches CUI or controlled development pipelines.
DoD's System to Protect Classified Information Held by Contractors Is Under Strain
A new report highlights that the Defense Counterintelligence and Security Agency lacks the resources to conduct security assessments at the required number and frequency for contractors handling classified information. The shortfall creates gaps in oversight precisely as CMMC enforcement ramps up and the contractor base expands. DIB organizations should not rely on DCSA visits as their primary compliance signal — internal self-assessment cadence and C3PAO scheduling should be driven proactively.
Top White House Cyber Policy Official to Soon Depart
Alexandra Seymour, principal deputy assistant national cyber director for policy at the Office of the National Cyber Director, is departing in the near term, adding to a pattern of senior cyber policy turnover in the current administration. Leadership instability at ONCD can slow the release of cyber strategy guidance and influence the pace of CMMC and NIST framework updates. Contractors and federal IT shops should monitor whether this affects pending policy documents or rulemaking timelines.
House NDAA Would Set Up Protected Disclosure Program for AI Incidents
The House version of the FY2027 NDAA includes a provision establishing a protected disclosure program at the Pentagon for reporting AI system incidents, with a focus on identifying recurring vulnerabilities and failure modes in military AI. The program would provide safe-harbor protections for disclosures, similar in concept to bug bounty frameworks. This is worth tracking for defense contractors deploying AI tools, as it signals DoD's intent to formalize AI risk reporting requirements that may eventually extend to the DIB.
May Security Update Breaks Windows Server Hosts with 15-Character Hostnames
Microsoft's May 2026 cumulative security update is causing failures on Windows Server systems where the hostname is exactly 15 characters long, a very specific edge case that is nonetheless breaking production systems for affected admins. The issue has no official hotfix released yet, and workarounds involve renaming hosts or rolling back the update. Admins managing Windows Server in M365 GCC High-connected environments should audit hostname lengths before deploying the May update widely.
Bare Metal Cloud Servers Now Cheaper and More Readily Available Than On-Prem Hardware, Says Nutanix CEO
Nutanix CEO Rajiv Ramaswami stated that hyperscalers can now procure hardware faster and at lower cost than enterprise buyers, making bare metal cloud a more attractive option than on-prem refresh cycles — a direct acknowledgment of competitive pressure on Nutanix's core business. He framed it as an opportunity, suggesting customers may increasingly land workloads in cloud rather than waiting for hardware. For shops running Nutanix AHV on-prem, this is worth watching as it may influence future licensing and support strategies.
Advancing Post-Quantum Capabilities of SSH in Red Hat Enterprise Linux
Red Hat Enterprise Linux 10.1 now defaults to post-quantum key exchange algorithms in TLS and has extended post-quantum support to SSH via OpenSSH 9.9, including hybrid key exchange methods combining classical and PQC algorithms. This is a concrete step toward NIST's post-quantum cryptography transition requirements, which are increasingly referenced in federal security standards. Admins running RHEL in GovCloud or on-prem environments handling CUI should evaluate when to enable PQC SSH to get ahead of future compliance mandates.
GPU Mining Malware Spreads via SEO Poisoning and AI Chatbot Recommendations
An ongoing cryptojacking campaign is targeting high-performance systems by manipulating search engine results and AI chatbot recommendations to serve malicious downloads, broadening the delivery surface beyond traditional phishing. The campaign is notable for its abuse of AI tools as a distribution vector, meaning standard URL filtering may not catch threats surfaced through chatbot interactions. Environments where developers or engineers use AI coding assistants or chatbots with internet access should review egress controls and endpoint policy for this class of threat.
Ransomware Actors Showing Up In Person to Steal Law Firm Data
The FBI issued a warning that Silent Ransom Group is physically visiting law firm offices, impersonating IT support staff, and convincing employees to allow them to plug in USB drives to access servers and databases. The tactic bypasses nearly all network-based security controls and highlights that physical security and visitor access policies are part of the cyber threat surface. Defense contractors and professional services firms handling CUI should review reception and physical access procedures as an extension of their insider threat and social engineering controls.
Carnival Cruise Confirms Data Breach Affecting Nearly 6 Million People
Carnival Corporation confirmed that the ShinyHunters extortion group exfiltrated records on approximately 6 million customers in an April 2026 breach, making it one of the larger confirmed consumer data exposures this year. ShinyHunters has been prolific in 2026, hitting multiple large organizations in a sustained crime spree. While not directly relevant to government IT, the breach reinforces the scale of credential and PII exposure that feeds downstream phishing and account takeover campaigns targeting enterprise users.