UEFI is a technology platform tracked across 6 threat clusters and 9 intelligence report mentions on ThreatCluster. First observed December 19, 2025; most recent activity July 15, 2026.
UEFI (Unified Extensible Firmware Interface) is the modern firmware interface that initializes hardware and launches the operating system, replacing legacy BIOS. It represents a high-value target for attackers due to its access to low-level system state and the potential for pre-boot compromise or firmware persistence. The recent article highlights a new UEFI flaw that enables early-boot DMA attacks on ASRock, ASUS, GIGABYTE, and MSI motherboards, underscoring the critical security implications of firmware-level vulnerabilities in the boot process.
ESET researchers have identified two new Windows variants of the SprySOCKS backdoor, previously exclusive to Linux, attributed to the Chinese cyberespionage group FishMonger. The variants, labeled WIN_DRV and WIN_PLUS,…
ESET researchers identified a significant vulnerability, CVE-2024-7344, allowing bypass of UEFI Secure Boot on numerous systems. This flaw affects UEFI applications signed by multiple vendors, enabling attackers to…
On June 30, 2026, openSUSE released advisories for critical vulnerabilities in ImageMagick and 7zip. ImageMagick has multiple CVEs including CVE-2026-45031 and CVE-2026-46520, leading to Denial of Service due to…
ESET researchers have discovered 11 outdated UEFI shim bootloaders, all version 0.9 or below, that can bypass UEFI Secure Boot protections on systems trusting Microsoft's 2011 certificate. These vulnerabilities allow…
A security researcher, known as Chaotic Eclipse, has publicly released exploit code for a zero-day vulnerability in Windows, dubbed BlueHammer, allowing local privilege escalation to SYSTEM or elevated administrator…
A vulnerability in the UEFI firmware of motherboards from ASUS, Gigabyte, MSI, and ASRock allows direct memory access (DMA) attacks that can bypass early-boot memory protections. The issue has been assigned multiple CVE…