welivesecurity from ESET
- This month in security with Tony Anscombe – July 2026 edition July 31, 2026OpenAI models going rogue, the first documented agentic ransomware operation, and an emergent AI-driven supply chain threat made for a packed July roundup
- Beyond the screenshot: Why you should verify what you see July 30, 2026The screenshot may look convincing, but it doesn’t necessarily prove that the payment, booking or conversation is genuine
- Forgotten UEFI shims undermining Secure Boot July 14, 2026ESET researchers discovered 11 vulnerable UEFI shim bootloaders signed by Microsoft that allow attackers to bypass UEFI Secure Boot by exploiting decade-old vulnerabilities
- ESET Threat Report H1 2026 July 8, 2026A view of the H1 2026 threat landscape as seen by ESET telemetry and from the perspective of ESET threat detection and research experts.
- Cyber readiness for SMBs: Getting the basics right July 3, 2026AI is changing cybercrime, but SMB cyber readiness still largely depends on closing the familiar gaps
- This month in security with Tony Anscombe – June 2026 edition June 30, 2026Three-day patching deadlines, exposed fuel-tank systems, scams costing billions of dollars, and social media bans for children all gave Tony plenty to unpack in June 2026
- Inside the inbox: Why cybercriminals want to break into your email account June 29, 2026Your inbox is an identity system all of its own: whoever owns it may own a lot more
- SMB cyber readiness: the road to resilience starts here June 26, 2026Your business may be small, but its attack surface is anything but. Readiness is the first step to resilience.
- Gamaredon in 2025: Leveraging tunnels, workers, dead drops, and new alliances June 25, 2026ESET Research analyzes Gamaredon’s new toolset and the group’s growing reliance on legitimate online services to hide its C&C infrastructure and exfiltrate stolen data
- ESET takes part in Operation Endgame to disrupt Amadey and Stealc June 24, 2026ESET researchers assisted in the global disruption of the Amadey botnet and Stealc infostealer, providing technical analysis, infrastructure tracking, and affiliate-level insights
Security Channel from The Register
- The most famous brand in physical security got pwned by ShinyHunters July 31, 2026Hopefully the company secures houses better than it locks down SaaS systems
- Anthropic and OpenAI are competing to see whose agents can go rogue harder July 31, 2026Whoever wins, we lose
- Charities remain locked out of CAF Bank online accounts July 31, 2026A week into shutdown, 14,000 customers still have no restoration date and some are struggling to pay staff
- Anthropic’s Claude escaped test sandbox to attack three organizations July 31, 2026Wrote and published malware during tests, which is apparently OK because leaky test environments were the real problem
- Jailed Flock vandal wipes out three cameras, racks up thousands in damages July 30, 2026A lesson for aspiring vandals: Take out all the cameras, not just the ones that flout your ideals
- Russian spies take their half-click email attack from Zimbra to Outlook July 30, 2026Opening a booby-trapped message unleashes a browser implant that can survive password changes and device rebuilds
- Headteacher had the most guessable username-password combo you could imagine July 30, 2026Schools often don't prioritize or understand cybersecurity
- Excuses like 'AI did it' don't exist in the eyes of the law July 30, 2026If your AI goes rogue, better have a good lawyer
- Closed models refuse to help researcher swat Linux bug July 29, 2026"I'm sorry, Dave. I'm afraid I can't do that" is an effective sales pitch for open source
- Word worm crawls into Copilot, spreads chaos July 29, 2026Researcher says months of coordination with Microsoft have yet to produce a robust mitigation
