ESET Research discovers UEFI Secure Boot bypass vulnerability

ESET researchers have discovered a vulnerability, affecting the majority of UEFI-based systems, that allows actors to bypass UEFI Secure Boot. This vulnerability, assigned CVE-2024-7344, was found in a UEFI application signed by Microsoft’s “Microsoft Corporation UEFI CA 2011” third-party UEFI certificate. Exploitation of this vulnerability can lead to the execution of untrusted code during system … More ESET Research discovers UEFI Secure Boot bypass vulnerability

ESET announces new security integrations with major vendors for enhanced business protection

ESET, a global leader in cybersecurity solutions, today announced the integration of its ESET PROTECT Platform with major vendors in the form of IBM QRadar SIEM and Microsoft Sentinel, providing ESET customers with enhanced capabilities and advanced threat response management. As nuanced as cybersecurity is, it is a necessity that requires organizations to cover their … More ESET announces new security integrations with major vendors for enhanced business protection

ESET Research discovers Mozilla and Windows zero day & zero click vulnerabilities exploited by RomCom APT group

ESET Research details the analysis of a previously unknown vulnerability in Mozilla products exploited in the wild and another previously unknown Microsoft Windows vulnerability, combined in a zero-click exploit. ESET researchers discovered a previously unknown vulnerability, CVE-2024-9680, in Mozilla products, exploited in the wild by APT group RomCom. Further analysis revealed another zero-day vulnerability in … More ESET Research discovers Mozilla and Windows zero day & zero click vulnerabilities exploited by RomCom APT group

Hackers Force Chrome Users To Hand Over Google Passwords

New research has uncovered a new technique used by hackers to force Chrome users to reveal their Google account passwords, writes Forbes*. The malware, called StealC, locks the browser in kiosk mode, blocking the F11 and ESC keys to prevent users from exiting. The only thing displayed is a Google account login window, compelling users … More Hackers Force Chrome Users To Hand Over Google Passwords

ESET Research Podcast: HotPage

ESET researchers discuss HotPage, a recently discovered adware armed with a highest-privilege, yet vulnerable, Microsoft-signed driver. Usually when someone mentions adware, people think of low-quality half-baked malicious code used to spam victims with sketchy ads. But as we explain in this episode of our podcast, not all adware is created equal. HotPage is a recently … More ESET Research Podcast: HotPage