WeLiveSecurity WeLiveSecurity
- Forgotten UEFI shims undermining Secure Booton July 14, 2026 at 8:53 am
ESET researchers discovered 11 vulnerable UEFI shim bootloaders signed by Microsoft that allow attackers to bypass UEFI Secure Boot by exploiting decade-old vulnerabilities
- ESET Threat Report H1 2026on July 8, 2026 at 8:45 am
A view of the H1 2026 threat landscape as seen by ESET telemetry and from the perspective of ESET threat detection and research experts.
- Cyber readiness for SMBs: Getting the basics righton July 3, 2026 at 12:36 pm
AI is changing cybercrime, but SMB cyber readiness still largely depends on closing the familiar gaps
- This month in security with Tony Anscombe â June 2026 editionon June 30, 2026 at 2:39 pm
Three-day patching deadlines, exposed fuel-tank systems, scams costing billions of dollars, and social media bans for children all gave Tony plenty to unpack in June 2026
- Inside the inbox: Why cybercriminals want to break into your email accounton June 29, 2026 at 8:50 am
Your inbox is an identity system all of its own: whoever owns it may own a lot more
- SMB cyber readiness: the road to resilience starts hereon June 26, 2026 at 8:50 am
Your business may be small, but its attack surface is anything but. Readiness is the first step to resilience.
- Gamaredon in 2025: Leveraging tunnels, workers, dead drops, and new allianceson June 25, 2026 at 8:45 am
ESET Research analyzes Gamaredonâs new toolset and the groupâs growing reliance on legitimate online services to hide its C&C infrastructure and exfiltrate stolen data
- ESET takes part in Operation Endgame to disrupt Amadey and Stealcon June 24, 2026 at 12:35 pm
ESET researchers assisted in the global disruption of the Amadey botnet and Stealc infostealer, providing technical analysis, infrastructure tracking, and affiliate-level insights
- Killing me gently: Inside Gentlemenâs EDR killer frameworkon June 18, 2026 at 9:46 am
ESET Research shares the results of a months-long investigation into the suite of EDR killers maintained by the RaaS gang Gentlemen
- Protecting legacy OT systems against modern cyberthreatson June 17, 2026 at 8:45 am
Many manufacturing plants depend on OT systems that stay in service for many years. That long run can hide significant cybersecurity risks.
- FishMongerâs arsenal upgraded: SprySOCKS for Windowson June 16, 2026 at 8:54 am
ESET researchers have discovered SprySOCKS for Windows, FishMongerâs backdoor weaponizing a kernel driver for advanced stealthiness
- EvilTokens: A phishing attack that doesnât steal your passwordon June 15, 2026 at 8:55 am
A phishing kit subverting Microsoftâs legitimate authentication flow lets attackers break into accounts without stealing passwords or creating fake login pages
- OceanLotus: From external espionage to domestic targetingon June 11, 2026 at 8:45 am
A shift in operational pattern of the infamous Vietnam-aligned APT group
- Unpacking SMB cyber-readiness â and what makes or breaks iton June 10, 2026 at 9:00 am
A company that’s expecting a cyberattack but hasnât actively prepared for it risks making the hardest decisions at the worst possible moment
- Cybercriminals: the ‘auditors’ you never hiredon June 9, 2026 at 8:50 am
Every organisation gets audited. The question is who does the auditing.
- Lessons for life: Why childrenâs data is a long-term identity riskon June 3, 2026 at 8:50 am
Your childâs first data breach may happen before theyâve even opened a bank account. Hereâs how to keep their digital life safe.
- This month in security with Tony Anscombe â May 2026 editionon May 29, 2026 at 7:30 am
In this roundup, Tony looks at attacks against Polish water treatment facilities, how AI-directed attacks failed in Mexico, and what Google believes is the first AI-generated zero-day exploit
- ESET APT Activity Report Q4 2025âQ1 2026on May 28, 2026 at 8:45 am
An overview of the activities of selected APT groups investigated and analyzed by ESET Research in Q4 2025 and Q1 2026
- What to consider before asking an AI chatbot for health adviceon May 27, 2026 at 8:50 am
Using chatbots for medical advice could elicit hallucinations and even expose you to security and privacy risks. Hereâs whatâs at stake and how to stay safe.
- BTMOB: A stealthy RAT burrowing deep into Android deviceson May 26, 2026 at 8:50 am
The malware pairs remote access capabilities with ready-made campaign tools, lowering the barrier for full device compromise
- Foul play: Fake FIFA websites target soccer fans looking for World Cup tickets, merchandiseon May 22, 2026 at 8:50 am
Watch out for bogus World Cup websites that mimic official ticket and merchandise flows to steal money and personal data
- Webworm: New burrowing techniqueson May 20, 2026 at 8:40 am
ESET researchers describe new tools and techniques that the Webworm APT group recently added to its arsenal
- The quest for greater tech independenceon May 19, 2026 at 8:50 am
A complete decoupling from US technology is neither realistic nor necessary, but the changing environment does require nations and companies to reassess their relationships and dependencies
- Why geopolitical turmoil is a gift for scammers, and how to stay safeon May 15, 2026 at 8:50 am
Conflict is a boon for opportunistic fraudsters. Look out for their ploys.
- FrostyNeighbor: Fresh mischief and digital shenaniganson May 14, 2026 at 8:50 am
ESET researchers uncovered new activities attributed to FrostyNeighbor, updating its compromise chain to support the groupâs continual cyberespionage operations
- Eyes wide open: How to mitigate the security and privacy risks of smart glasseson May 11, 2026 at 8:55 am
Smart glasses allow anyone to track and record the world around them. That could put your data and the privacy of those nearby at risk.
- Fake call logs, real payments: How CallPhantom tricks Android userson May 7, 2026 at 8:51 am
ESET researchers uncovered fraudulent apps on Google Play that claim to provide the call history âfor any numberâ and had been downloaded more than seven million times before being taken down
- Fixing the password problem is as easy as 123456on May 7, 2026 at 7:00 am
How come itâs still possible to âsecureâ an online account with a six-digit string?
- A rigged game: ScarCruft compromises gaming platform in a supply-chain attackon May 5, 2026 at 8:55 am
ESET researchers have investigated an ongoing attack by the ScarCruft APT group that targets the Yanbian region via backdoor-laced Windows and Android games
- This month in security with Tony Anscombe â April 2026 editionon April 30, 2026 at 9:00 am
Warnings about helpdesk impersonation scams and Iran-linked hackers targeting critical sectors in the US, plus the most damaging scams of 2025 – here’s some of what made the headlines this month






