Related Threat Clusters
-
FishMonger Expands SprySOCKS Malware to Windows with Kernel-Level Stealth
ESET researchers have identified two new Windows variants of the SprySOCKS backdoor, previously exclusive to Linux, attributed to the Chinese cyberespionage group FishMonger. The variants, labeled WIN_DRV and WIN_PLUS,…
12 articles · Updated June 16, 2026 -
Critical UEFI Secure Boot Bypass Vulnerability Discovered
ESET researchers identified a significant vulnerability, CVE-2024-7344, allowing bypass of UEFI Secure Boot on numerous systems. This flaw affects UEFI applications signed by multiple vendors, enabling attackers to…
4 articles · Updated June 18, 2026 -
Secure Boot Certificate Expiration Threatens Windows Security Posture
Microsoft's Secure Boot certificates from 2011 are set to expire between June 24-27, 2026, affecting devices that haven't received the 2023 replacement certificates. While devices will continue to boot, they will lose…
35 articles · Updated June 4, 2026 -
Old UEFI Shims Exploit Bypass of Secure Boot Security
ESET researchers have discovered 11 outdated UEFI shim bootloaders, all version 0.9 or below, that can bypass UEFI Secure Boot protections on systems trusting Microsoft's 2011 certificate. These vulnerabilities allow…
14 articles · Updated July 14, 2026 -
Cybercrime Alliance Formed: Scattered Spider, LAPSUS$, and ShinyHunters Unite
A new cybercrime alliance called Scattered LAPSUS$ Hunters has been formed, comprising the groups Scattered Spider, LAPSUS$, and ShinyHunters. This coalition aims to provide extortion-as-a-service (EaaS) and conduct…
2 articles · Updated November 6, 2025 -
Data Breach Affects Over 200 Companies via Gainsight Integration with Salesforce
Hackers compromised Salesforce-stored data from more than 200 companies through a supply chain attack involving Gainsight applications. Google confirmed the breach, stating that unauthorized access to customer data was…
44 articles · Updated November 27, 2025 -
CISA Issues Guidance on UEFI Secure Boot Management to Combat Bootkit Threats
In December 2025, CISA, in collaboration with the NSA, released guidance for enterprises on managing UEFI Secure Boot configurations to mitigate bootkit threats. The guidance addresses vulnerabilities such as PKFail,…
3 articles · Updated December 15, 2025 -
CISA KEV Catalog Insights and Tools Released
A new paper by Tod Beardsley, former CISA KEV Section Chief, provides insights into the CISA Known Exploited Vulnerability (KEV) catalog. It includes a free tool designed to assist security teams in effectively…
3 articles · Updated February 6, 2026
Recent Intelligence Reports
- Eleven Vulnerable UEFI Shims Enable Secure Boot Bypass — Infosecurity-Magazine · July 15, 2026
- Vulnerable UEFI shims allow decade — Feeds.4Sysops · July 15, 2026
- Forgotten UEFI shims undermining Secure Boot — Welivesecurity · July 14, 2026
- Under Cloak Uefi Secure Boot Introducing Cve 2024 7344 — www.welivesecurity.com · June 18, 2026
- Unified Extensible Firmware Interface UEFI — www.techtarget.com · June 16, 2026
- Security analysts — www.stmicro.net · June 4, 2026
- What CISA KEV Is and Isn’t — Thecyberexpress · February 6, 2026
- CISA Releases Guidance for Managing UEFI Secure Boot on Enterprise Devices — Cybersecuritynews · December 15, 2025