<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0">
  <channel>
    <title>WeLiveSecurity</title>
    <link>https://www.welivesecurity.com</link>
    <description>WeLiveSecurity</description>
    <language>en</language>
    <item>
      <title>Forgotten UEFI shims undermining Secure Boot</title>
      <link>https://www.welivesecurity.com/en/eset-research/forgotten-uefi-shims-undermining-secure-boot/</link>
      <description><![CDATA[ESET researchers discovered 11 vulnerable UEFI shim bootloaders signed by Microsoft that allow attackers to bypass UEFI Secure Boot by exploiting decade-old vulnerabilities]]></description>
      <category>ESET research</category>
      <guid>https://www.welivesecurity.com/en/eset-research/forgotten-uefi-shims-undermining-secure-boot/</guid>
      <pubDate>Tue, 14 Jul 2026 08:53:00 +0000</pubDate>
    </item>
    <item>
      <title>ESET Threat Report H1 2026</title>
      <link>https://www.welivesecurity.com/en/eset-research/eset-threat-report-h1-2026/</link>
      <description><![CDATA[A view of the H1 2026 threat landscape as seen by ESET telemetry and from the perspective of ESET threat detection and research experts.]]></description>
      <category>ESET research</category>
      <guid>https://www.welivesecurity.com/en/eset-research/eset-threat-report-h1-2026/</guid>
      <pubDate>Wed, 08 Jul 2026 08:45:00 +0000</pubDate>
    </item>
    <item>
      <title>Gamaredon in 2025: Leveraging tunnels, workers, dead drops, and new alliances</title>
      <link>https://www.welivesecurity.com/en/eset-research/gamaredon-2025-leveraging-tunnels-workers-dead-drops-new-alliances/</link>
      <description><![CDATA[ESET Research analyzes Gamaredon’s new toolset and the group’s growing reliance on legitimate online services to hide its C&C infrastructure and exfiltrate stolen data]]></description>
      <category>ESET research</category>
      <guid>https://www.welivesecurity.com/en/eset-research/gamaredon-2025-leveraging-tunnels-workers-dead-drops-new-alliances/</guid>
      <pubDate>Thu, 25 Jun 2026 08:45:00 +0000</pubDate>
    </item>
    <item>
      <title>ESET takes part in Operation Endgame to disrupt Amadey and Stealc</title>
      <link>https://www.welivesecurity.com/en/eset-research/eset-takes-part-operation-endgame-disrupt-amadey-stealc/</link>
      <description><![CDATA[ESET researchers assisted in the global disruption of the Amadey botnet and Stealc infostealer, providing technical analysis, infrastructure tracking, and affiliate-level insights]]></description>
      <category>ESET research</category>
      <guid>https://www.welivesecurity.com/en/eset-research/eset-takes-part-operation-endgame-disrupt-amadey-stealc/</guid>
      <pubDate>Wed, 24 Jun 2026 12:35:24 +0000</pubDate>
    </item>
    <item>
      <title>Killing me gently: Inside Gentlemen’s EDR killer framework</title>
      <link>https://www.welivesecurity.com/en/eset-research/killing-me-gently-inside-gentlemens-edr-killer-framework/</link>
      <description><![CDATA[ESET Research shares the results of a months-long investigation into the suite of EDR killers maintained by the RaaS gang Gentlemen]]></description>
      <category>ESET research</category>
      <guid>https://www.welivesecurity.com/en/eset-research/killing-me-gently-inside-gentlemens-edr-killer-framework/</guid>
      <pubDate>Thu, 18 Jun 2026 09:46:32 +0000</pubDate>
    </item>
    <item>
      <title>FishMonger’s arsenal upgraded: SprySOCKS for Windows</title>
      <link>https://www.welivesecurity.com/en/eset-research/fishmongers-arsenal-upgraded-sprysocks-windows/</link>
      <description><![CDATA[ESET researchers have discovered SprySOCKS for Windows, FishMonger’s backdoor weaponizing a kernel driver for advanced stealthiness]]></description>
      <category>ESET research</category>
      <guid>https://www.welivesecurity.com/en/eset-research/fishmongers-arsenal-upgraded-sprysocks-windows/</guid>
      <pubDate>Tue, 16 Jun 2026 08:54:04 +0000</pubDate>
    </item>
    <item>
      <title>OceanLotus: From external espionage to domestic targeting</title>
      <link>https://www.welivesecurity.com/en/eset-research/oceanlotus-external-espionage-domestic-targeting/</link>
      <description><![CDATA[A shift in operational pattern of the infamous Vietnam-aligned APT group]]></description>
      <category>ESET research</category>
      <guid>https://www.welivesecurity.com/en/eset-research/oceanlotus-external-espionage-domestic-targeting/</guid>
      <pubDate>Thu, 11 Jun 2026 08:45:00 +0000</pubDate>
    </item>
    <item>
      <title>ESET APT Activity Report Q4 2025–Q1 2026</title>
      <link>https://www.welivesecurity.com/en/eset-research/eset-apt-activity-report-q4-2025-q1-2026/</link>
      <description><![CDATA[An overview of the activities of selected APT groups investigated and analyzed by ESET Research in Q4 2025 and Q1 2026]]></description>
      <category>ESET research</category>
      <guid>https://www.welivesecurity.com/en/eset-research/eset-apt-activity-report-q4-2025-q1-2026/</guid>
      <pubDate>Thu, 28 May 2026 08:45:00 +0000</pubDate>
    </item>
    <item>
      <title>Webworm: New burrowing techniques</title>
      <link>https://www.welivesecurity.com/en/eset-research/webworm-new-burrowing-techniques/</link>
      <description><![CDATA[ESET researchers describe new tools and techniques that the Webworm APT group recently added to its arsenal]]></description>
      <category>ESET research</category>
      <guid>https://www.welivesecurity.com/en/eset-research/webworm-new-burrowing-techniques/</guid>
      <pubDate>Wed, 20 May 2026 08:40:00 +0000</pubDate>
    </item>
    <item>
      <title>FrostyNeighbor: Fresh mischief and digital shenanigans</title>
      <link>https://www.welivesecurity.com/en/eset-research/frostyneighbor-fresh-mischief-digital-shenanigans/</link>
      <description><![CDATA[ESET researchers uncovered new activities attributed to FrostyNeighbor, updating its compromise chain to support the group’s continual cyberespionage operations]]></description>
      <category>ESET research</category>
      <guid>https://www.welivesecurity.com/en/eset-research/frostyneighbor-fresh-mischief-digital-shenanigans/</guid>
      <pubDate>Thu, 14 May 2026 08:50:00 +0000</pubDate>
    </item>
    <item>
      <title>Fake call logs, real payments: How CallPhantom tricks Android users</title>
      <link>https://www.welivesecurity.com/en/eset-research/fake-call-logs-real-payments-how-callphantom-tricks-android-users/</link>
      <description><![CDATA[ESET researchers uncovered fraudulent apps on Google Play that claim to provide the call history “for any number” and had been downloaded more than seven million times before being taken down]]></description>
      <category>ESET research</category>
      <guid>https://www.welivesecurity.com/en/eset-research/fake-call-logs-real-payments-how-callphantom-tricks-android-users/</guid>
      <pubDate>Thu, 07 May 2026 08:51:19 +0000</pubDate>
    </item>
    <item>
      <title>A rigged game: ScarCruft compromises gaming platform in a supply-chain attack</title>
      <link>https://www.welivesecurity.com/en/eset-research/rigged-game-scarcruft-compromises-gaming-platform-supply-chain-attack/</link>
      <description><![CDATA[ESET researchers have investigated an ongoing attack by the ScarCruft APT group that targets the Yanbian region via backdoor-laced Windows and Android games]]></description>
      <category>ESET research</category>
      <guid>https://www.welivesecurity.com/en/eset-research/rigged-game-scarcruft-compromises-gaming-platform-supply-chain-attack/</guid>
      <pubDate>Tue, 05 May 2026 08:55:27 +0000</pubDate>
    </item>
    <item>
      <title>GopherWhisper: A burrow full of malware</title>
      <link>https://www.welivesecurity.com/en/eset-research/gopherwhisper-burrow-full-malware/</link>
      <description><![CDATA[ESET Research has discovered a new China-aligned APT group that we’ve named GopherWhisper, which targets Mongolian governmental institutions]]></description>
      <category>ESET research</category>
      <guid>https://www.welivesecurity.com/en/eset-research/gopherwhisper-burrow-full-malware/</guid>
      <pubDate>Thu, 23 Apr 2026 08:59:18 +0000</pubDate>
    </item>
    <item>
      <title>New NGate variant hides in a trojanized NFC payment app</title>
      <link>https://www.welivesecurity.com/en/eset-research/new-ngate-variant-hides-in-a-trojanized-nfc-payment-app/</link>
      <description><![CDATA[ESET researchers discover another iteration of NGate malware, this time possibly developed with the assistance of AI]]></description>
      <category>ESET research</category>
      <guid>https://www.welivesecurity.com/en/eset-research/new-ngate-variant-hides-in-a-trojanized-nfc-payment-app/</guid>
      <pubDate>Tue, 21 Apr 2026 08:55:00 +0000</pubDate>
    </item>
    <item>
      <title>EDR killers explained: Beyond the drivers</title>
      <link>https://www.welivesecurity.com/en/eset-research/edr-killers-explained-beyond-the-drivers/</link>
      <description><![CDATA[ESET researchers dive deeper into the EDR killer ecosystem, disclosing how attackers abuse vulnerable drivers]]></description>
      <category>ESET research</category>
      <guid>https://www.welivesecurity.com/en/eset-research/edr-killers-explained-beyond-the-drivers/</guid>
      <pubDate>Thu, 19 Mar 2026 09:55:08 +0000</pubDate>
    </item>
    <item>
      <title>Sednit reloaded: Back in the trenches</title>
      <link>https://www.welivesecurity.com/en/eset-research/sednit-reloaded-back-trenches/</link>
      <description><![CDATA[The resurgence of one of Russia’s most notorious APT groups]]></description>
      <category>ESET research</category>
      <guid>https://www.welivesecurity.com/en/eset-research/sednit-reloaded-back-trenches/</guid>
      <pubDate>Tue, 10 Mar 2026 09:58:00 +0000</pubDate>
    </item>
    <item>
      <title>PromptSpy ushers in the era of Android threats using GenAI</title>
      <link>https://www.welivesecurity.com/en/eset-research/promptspy-ushers-in-era-android-threats-using-genai/</link>
      <description><![CDATA[ESET researchers discover PromptSpy, the first known Android malware to abuse generative AI in its execution flow]]></description>
      <category>ESET research</category>
      <guid>https://www.welivesecurity.com/en/eset-research/promptspy-ushers-in-era-android-threats-using-genai/</guid>
      <pubDate>Thu, 19 Feb 2026 10:30:20 +0000</pubDate>
    </item>
    <item>
      <title>DynoWiper update: Technical analysis and attribution</title>
      <link>https://www.welivesecurity.com/en/eset-research/dynowiper-update-technical-analysis-attribution/</link>
      <description><![CDATA[ESET researchers present technical details on a recent data destruction incident affecting a company in Poland’s energy sector]]></description>
      <category>ESET research</category>
      <guid>https://www.welivesecurity.com/en/eset-research/dynowiper-update-technical-analysis-attribution/</guid>
      <pubDate>Fri, 30 Jan 2026 10:28:38 +0000</pubDate>
    </item>
    <item>
      <title>Love? Actually: Fake dating app used as lure in targeted spyware campaign in Pakistan</title>
      <link>https://www.welivesecurity.com/en/eset-research/love-actually-fake-dating-app-used-lure-targeted-spyware-campaign-pakistan/</link>
      <description><![CDATA[ESET researchers discover an Android spyware campaign targeting users in Pakistan via romance scam tactics, revealing links to a broader spy operation]]></description>
      <category>ESET research</category>
      <guid>https://www.welivesecurity.com/en/eset-research/love-actually-fake-dating-app-used-lure-targeted-spyware-campaign-pakistan/</guid>
      <pubDate>Wed, 28 Jan 2026 09:59:00 +0000</pubDate>
    </item>
    <item>
      <title>ESET Research: Sandworm behind cyberattack on Poland’s power grid in late 2025</title>
      <link>https://www.welivesecurity.com/en/eset-research/eset-research-sandworm-cyberattack-poland-power-grid-late-2025/</link>
      <description><![CDATA[The attack involved data-wiping malware that ESET researchers have now analyzed and named DynoWiper]]></description>
      <category>ESET research</category>
      <guid>https://www.welivesecurity.com/en/eset-research/eset-research-sandworm-cyberattack-poland-power-grid-late-2025/</guid>
      <pubDate>Fri, 23 Jan 2026 16:58:26 +0000</pubDate>
    </item>
    <item>
      <title>Revisiting CVE-2025-50165: A critical flaw in Windows Imaging Component</title>
      <link>https://www.welivesecurity.com/en/eset-research/revisiting-cve-2025-50165-critical-flaw-windows-imaging-component/</link>
      <description><![CDATA[A comprehensive analysis and assessment of a critical severity vulnerability with low likelihood of mass exploitation]]></description>
      <category>ESET research</category>
      <guid>https://www.welivesecurity.com/en/eset-research/revisiting-cve-2025-50165-critical-flaw-windows-imaging-component/</guid>
      <pubDate>Mon, 22 Dec 2025 09:55:00 +0000</pubDate>
    </item>
    <item>
      <title>LongNosedGoblin tries to sniff out governmental affairs in Southeast Asia and Japan</title>
      <link>https://www.welivesecurity.com/en/eset-research/longnosedgoblin-tries-sniff-out-governmental-affairs-southeast-asia-japan/</link>
      <description><![CDATA[ESET researchers discovered a China-aligned APT group, LongNosedGoblin, which uses Group Policy to deploy cyberespionage tools across networks of governmental institutions]]></description>
      <category>ESET research</category>
      <guid>https://www.welivesecurity.com/en/eset-research/longnosedgoblin-tries-sniff-out-governmental-affairs-southeast-asia-japan/</guid>
      <pubDate>Thu, 18 Dec 2025 10:00:00 +0000</pubDate>
    </item>
    <item>
      <title>ESET Threat Report H2 2025</title>
      <link>https://www.welivesecurity.com/en/eset-research/eset-threat-report-h2-2025/</link>
      <description><![CDATA[A view of the H2 2025 threat landscape as seen by ESET telemetry and from the perspective of ESET threat detection and research experts]]></description>
      <category>ESET research</category>
      <guid>https://www.welivesecurity.com/en/eset-research/eset-threat-report-h2-2025/</guid>
      <pubDate>Tue, 16 Dec 2025 09:50:45 +0000</pubDate>
    </item>
    <item>
      <title>MuddyWater: Snakes by the riverbank</title>
      <link>https://www.welivesecurity.com/en/eset-research/muddywater-snakes-riverbank/</link>
      <description><![CDATA[MuddyWater targets critical infrastructure in Israel and Egypt, relying on custom malware, improved tactics, and a predictable playbook]]></description>
      <category>ESET research</category>
      <guid>https://www.welivesecurity.com/en/eset-research/muddywater-snakes-riverbank/</guid>
      <pubDate>Tue, 02 Dec 2025 10:00:15 +0000</pubDate>
    </item>
    <item>
      <title>PlushDaemon compromises network devices for adversary-in-the-middle attacks</title>
      <link>https://www.welivesecurity.com/en/eset-research/plushdaemon-compromises-network-devices-for-adversary-in-the-middle-attacks/</link>
      <description><![CDATA[ESET researchers have discovered a network implant used by the China-aligned PlushDaemon APT group to perform adversary-in-the-middle attacks]]></description>
      <category>ESET research</category>
      <guid>https://www.welivesecurity.com/en/eset-research/plushdaemon-compromises-network-devices-for-adversary-in-the-middle-attacks/</guid>
      <pubDate>Wed, 19 Nov 2025 09:55:00 +0000</pubDate>
    </item>
  </channel>
</rss>