ESET researchers discovered 11 vulnerable UEFI shim bootloaders signed by Microsoft that allow attackers to bypass UEFI Secure Boot by exploiting decade-old vulnerabilities
A view of the H1 2026 threat landscape as seen by ESET telemetry and from the perspective of ESET threat detection and research experts.
AI is changing cybercrime, but SMB cyber readiness still largely depends on closing the familiar gaps
Three-day patching deadlines, exposed fuel-tank systems, scams costing billions of dollars, and social media bans for children all gave Tony plenty to unpack in June 2026
Your inbox is an identity system all of its own: whoever owns it may own a lot more
Your business may be small, but its attack surface is anything but. Readiness is the first step to resilience.
ESET Research analyzes Gamaredon’s new toolset and the group’s growing reliance on legitimate online services to hide its C&C infrastructure and exfiltrate stolen data
ESET researchers assisted in the global disruption of the Amadey botnet and Stealc infostealer, providing technical analysis, infrastructure tracking, and affiliate-level insights
ESET Research shares the results of a months-long investigation into the suite of EDR killers maintained by the RaaS gang Gentlemen
Many manufacturing plants depend on OT systems that stay in service for many years. That long run can hide significant cybersecurity risks.
ESET researchers have discovered SprySOCKS for Windows, FishMonger’s backdoor weaponizing a kernel driver for advanced stealthiness
A phishing kit subverting Microsoft’s legitimate authentication flow lets attackers break into accounts without stealing passwords or creating fake login pages
A shift in operational pattern of the infamous Vietnam-aligned APT group
A company that’s expecting a cyberattack but hasn’t actively prepared for it risks making the hardest decisions at the worst possible moment
Every organisation gets audited. The question is who does the auditing.
Your child’s first data breach may happen before they’ve even opened a bank account. Here’s how to keep their digital life safe.
In this roundup, Tony looks at attacks against Polish water treatment facilities, how AI-directed attacks failed in Mexico, and what Google believes is the first AI-generated zero-day exploit
An overview of the activities of selected APT groups investigated and analyzed by ESET Research in Q4 2025 and Q1 2026
Using chatbots for medical advice could elicit hallucinations and even expose you to security and privacy risks. Here’s what’s at stake and how to stay safe.
The malware pairs remote access capabilities with ready-made campaign tools, lowering the barrier for full device compromise
Watch out for bogus World Cup websites that mimic official ticket and merchandise flows to steal money and personal data
ESET researchers describe new tools and techniques that the Webworm APT group recently added to its arsenal
A complete decoupling from US technology is neither realistic nor necessary, but the changing environment does require nations and companies to reassess their relationships and dependencies
Conflict is a boon for opportunistic fraudsters. Look out for their ploys.
ESET researchers uncovered new activities attributed to FrostyNeighbor, updating its compromise chain to support the group’s continual cyberespionage operations
Smart glasses allow anyone to track and record the world around them. That could put your data and the privacy of those nearby at risk.
ESET researchers uncovered fraudulent apps on Google Play that claim to provide the call history “for any number” and had been downloaded more than seven million times before being taken down
How come it’s still possible to ‘secure’ an online account with a six-digit string?
ESET researchers have investigated an ongoing attack by the ScarCruft APT group that targets the Yanbian region via backdoor-laced Windows and Android games
Warnings about helpdesk impersonation scams and Iran-linked hackers targeting critical sectors in the US, plus the most damaging scams of 2025 – here’s some of what made the headlines this month
A breach claims the systems as well as the confidence that was, in retrospect, a major vulnerability
ESET Research has discovered a new China-aligned APT group that we’ve named GopherWhisper, which targets Mongolian governmental institutions
ESET researchers discover another iteration of NGate malware, this time possibly developed with the assistance of AI
An attack is what you see, but a business operation is what you’re up against
Ignoring a real breach notification invites risk, but falling for a bogus one could be even worse. Stop reacting on autopilot.
Your biggest risk may be a vendor you trust. How can SMBs map their third-party blind spots and build operational resilience?
If you’ve been the victim of fraud, you’re likely already a lead on a ‘sucker list’ – and if you’re not careful, your ordeal may be about to get worse.
Threat actors are using AI to supercharge tried-and-tested TTPs. When attacks move this fast, cyber-defenders need to rethink their own strategy.
Fraudsters often target the accounts of the deceased or their grieving relatives. Here’s how to keep the scammers at bay.
The past four weeks have seen a slew of new cybersecurity wake-up calls that showed why every organization needs a well-thought-out cyber-resilience plan
This year, AI agents took the center stage – as a defensive capability, but more pressingly as a risk many organizations haven’t caught up with
Silver Fox is back in Japan, spoofing tax and HR emails timed to the one season when no one thinks twice about opening them
Cloud VMs offer unmatched speed, scale and flexibility – all of which could eventually count for little if they’re left to fend for themselves
As IT infrastructure expands, visibility and control often lag behind – until an incident forces a reckoning
What you do – and how fast – after an account is compromised often matters more than it may seem
ESET researchers dive deeper into the EDR killer ecosystem, disclosing how attackers abuse vulnerable drivers
ESET’s Jake Moore used smart glasses, deepfakes and face swaps to ‘hack’ widely-used facial recognition systems – and he’ll demo it all at RSAC 2026
The cybersecurity implications of the war in the Middle East extend far beyond the region. Here’s where to focus your defenses.
The resurgence of one of Russia’s most notorious APT groups
The ability to continue operating safely in an unsafe environment where competitors cannot is a competitive advantage that is rarely measured or discussed
We speak to Director of ESET Threat Research Jean-Ian Boutin about where solutions that blend advanced technology with human expertise provide the most practical value for businesses
The education sector is notoriously short on cash, but rich in assets for threat actors to target. How can managed detection and response (MDR) help learning institutions regain the initiative?
In this roundup, Tony looks at how opportunistic threat actors are taking advantage of weak authentication, unmanaged exposure, and popular AI tools
Start using a new app and you’ll often be asked to grant it permissions. But blindly accepting them could expose you to serious privacy and security risks.
Can you believe your ears? Increasingly, the answer is no. Here’s what’s at stake for your business, and how to beat the deepfakers.
ESET researchers discover PromptSpy, the first known Android malware to abuse generative AI in its execution flow
Like any other marketplace, the social commerce platform has its share of red flags. It pays to know what to look for so you can shop or sell without headaches.
When it comes to our children’s digital lives, prohibition rarely works. It’s our responsibility to help them build a healthy relationship with tech.
When corporate data is exposed on a dedicated leak site, the consequences linger long after the attack fades from the news cycle
It’s time to file your tax return. And cybercriminals are lurking to make an already stressful period even more edgy.
The mobile marketplace app has a growing number of users, but not all of them are genuine. Watch out for these common scams.
It’s snow joke – sporting events are a big draw for cybercriminals. Make sure you’re not on the losing side by following these best practices.
The trends that emerged in January offer useful clues about the risks and priorities that security teams are likely to contend with throughout the year
ESET researchers present technical details on a recent data destruction incident affecting a company in Poland’s energy sector
ESET researchers discover an Android spyware campaign targeting users in Pakistan via romance scam tactics, revealing links to a broader spy operation
Has your inbox recently been deluged with unwanted and even outright malicious messages? Here are 10 possible reasons – and how to stem the tide.
The attack involved data-wiping malware that ESET researchers have now analyzed and named DynoWiper
As children turn to AI chatbots for answers, advice, and companionship, questions emerge about their safety, privacy, and emotional development
Here’s how the most common scams targeting Apple Pay users work and what you can do to stay one step ahead
Once again, data shows an uncomfortable truth: the habit of choosing eminently hackable passwords is alive and well
The business social networking site is a vast, publicly accessible database of corporate information. Don’t believe everyone on the site is who they say they are.
Should verified identities become the standard online? Australia’s social media ban for under-16s shows why the question matters.
If your data is on the dark web, it’s probably only a matter of time before it’s abused for fraud or account hijacking. Here’s what to do.
Reusing passwords may feel like a harmless shortcut – until a single breach opens the door to multiple accounts
As 2025 draws to a close, Tony looks back at the cybersecurity stories that stood out both in December and across the whole of this year
Have you ever received a package you never ordered? It could be a warning sign that your data has been compromised, with more fraud to follow.
A comprehensive analysis and assessment of a critical severity vulnerability with low likelihood of mass exploitation
ESET researchers discovered a China-aligned APT group, LongNosedGoblin, which uses Group Policy to deploy cyberespionage tools across networks of governmental institutions
A view of the H2 2025 threat landscape as seen by ESET telemetry and from the perspective of ESET threat detection and research experts
Behind the polished exterior of many modern buildings sit outdated systems with vulnerabilities waiting to be found
Being seen as reliable is good for ‘business’ and ransomware groups care about ‘brand reputation’ just as much as their victims
If you don’t look inside your environment, you can’t know its true state – and attackers count on that
Interpreting the vast cybersecurity vendor landscape through the lens of industry analysts and testing authorities can immensely enhance your cyber-resilience.
Is your organization’s senior leadership vulnerable to a cyber-harpooning? Learn how to keep them safe.
Identity is effectively the new network boundary. It must be protected at all costs.
MuddyWater targets critical infrastructure in Israel and Egypt, relying on custom malware, improved tactics, and a predictable playbook
From LinkedIn to X, GitHub to Instagram, there are plenty of opportunities to share work-related information. But posting could also get your company into trouble.
Data exposure by top AI companies, the Akira ransomware haul, Operation Endgame against major malware families, and more of this month’s cybersecurity news
Online disagreements among young people can easily spiral out of control. Parents need to understand what’s at stake.
Social media influencers can provide reach and trust for scams and malware distribution. Robust account protection is key to stopping the fraudsters.
Why your business needs the best-of-breed combination of technology and human expertise
Here’s how open-source intelligence helps trace your digital footprint and uncover your weak points, plus a few essential tools to connect the dots
ESET researchers have discovered a network implant used by the China-aligned PlushDaemon APT group to perform adversary-in-the-middle attacks
Does your chatbot know too much? Think twice before you tell your AI companion everything.
Look no further to learn how cybercriminals could try to crack your vault and how you can keep your logins safe
From unintentional data leakage to buggy code, here’s why you should care about unsanctioned AI use in your company
Former colleagues and friends remember the cybersecurity researcher, author, and mentor whose work bridged the human and technical sides of security
ESET Chief Security Evangelist Tony Anscombe highlights some of the key findings from the latest issue of the ESET APT Activity Report
An overview of the activities of selected APT groups investigated and analyzed by ESET Research in Q2 2025 and Q3 2025
How a fast-growing scam is tricking WhatsApp users into revealing their most sensitive financial and other data
