ESET Research discovers UEFI Secure Boot bypass vulnerability

ESET researchers have discovered a vulnerability, affecting the majority of UEFI-based systems, that allows actors to bypass UEFI Secure Boot. This vulnerability, assigned CVE-2024-7344, was found in a UEFI application signed by Microsoft’s “Microsoft Corporation UEFI CA 2011” third-party UEFI certificate. Exploitation of this vulnerability can lead to the execution of untrusted code during system … More ESET Research discovers UEFI Secure Boot bypass vulnerability

ESET Research discovers the first UEFI bootkit for Linux

ESET Research has discovered the first UEFI bootkit designed for Linux systems, which has been named Bootkitty by its creators. ESET believes this bootkit is likely an initial proof of concept, and based on ESET telemetry, it has not been deployed in the wild. However, it is the first evidence that UEFI bootkits are no … More ESET Research discovers the first UEFI bootkit for Linux

ESET Research discovers WolfsBane, new Linux cyberespionage backdoor by Gelsemium APT

ESET researchers have identified multiple samples of a Linux backdoor, which they named WolfsBane and attribute with high confidence to Gelsemium advanced persistent threat (APT) group. ESET researchers have identified multiple samples of a Linux backdoor, which they named WolfsBane and attribute with high confidence to Gelsemium advanced persistent threat (APT) group. The goal of … More ESET Research discovers WolfsBane, new Linux cyberespionage backdoor by Gelsemium APT

Small but mighty: Top 5 pocket-sized gadgets to boost your ethical hacking skills

These five formidable bits of kit that can assist cyber-defenders in spotting chinks in corporate armors and help hobbyist hackers deepen their understanding of cybersecurity. While blue teams defend, red teams attack. They share a common goal, however – help identify and address gaps in organizations’ defenses before these weaknesses can be exploited by malicious … More Small but mighty: Top 5 pocket-sized gadgets to boost your ethical hacking skills

400k Linux servers compromised for cryptocurrency theft and financial gain

One of the most advanced server-side malware campaigns is still growing, with hundreds of thousands of compromised servers, and it has diversified to include credit card and cryptocurrency theft. ESET Research released its deep-dive investigation into one of the most advanced server-side malware campaigns, which is still growing and has seen hundreds of thousands of … More 400k Linux servers compromised for cryptocurrency theft and financial gain