BlackLotus is a malware family tracked across 8 threat clusters and 9 intelligence report mentions on ThreatCluster. First observed November 4, 2025; most recent activity July 15, 2026.
BlackLotus is a malware family known for firmware/UEFI-level compromise and bootkit capabilities that enable persistence on Windows devices by loading at startup and potentially bypassing security controls such as Secure Boot. Its significance lies in its stealthy, long-lasting presence that can survive OS reinstall and complicate detection and remediation in enterprise environments.
ESET researchers have identified two new Windows variants of the SprySOCKS backdoor, previously exclusive to Linux, attributed to the Chinese cyberespionage group FishMonger. The variants, labeled WIN_DRV and WIN_PLUS,…
ESET researchers identified a significant vulnerability, CVE-2024-7344, allowing bypass of UEFI Secure Boot on numerous systems. This flaw affects UEFI applications signed by multiple vendors, enabling attackers to…
Microsoft's Secure Boot certificates from 2011 are set to expire between June 24-27, 2026, affecting devices that haven't received the 2023 replacement certificates. While devices will continue to boot, they will lose…
ESET researchers have discovered 11 outdated UEFI shim bootloaders, all version 0.9 or below, that can bypass UEFI Secure Boot protections on systems trusting Microsoft's 2011 certificate. These vulnerabilities allow…
A new cybercrime alliance called Scattered LAPSUS$ Hunters has been formed, comprising the groups Scattered Spider, LAPSUS$, and ShinyHunters. This coalition aims to provide extortion-as-a-service (EaaS) and conduct…
Hackers compromised Salesforce-stored data from more than 200 companies through a supply chain attack involving Gainsight applications. Google confirmed the breach, stating that unauthorized access to customer data was…
In December 2025, CISA, in collaboration with the NSA, released guidance for enterprises on managing UEFI Secure Boot configurations to mitigate bootkit threats. The guidance addresses vulnerabilities such as PKFail,…
A new paper by Tod Beardsley, former CISA KEV Section Chief, provides insights into the CISA Known Exploited Vulnerability (KEV) catalog. It includes a free tool designed to assist security teams in effectively…