XPAJ: Reversing a Windows x64 BootkitKaspersky Securelist·Jun 19, 18:16 UTC · Jun 19, 2012Ransomware60
BlackLotus UEFI bootkit disables Windows security mechanismsHelp Net Security·Apr 17, 10:14 UTC · Apr 17, 2023Vulnerability in the wildCVE-2022-2189460
BlackLotus is first bootkit bypassing UEFI Secure Boot on Win 11Security Affairs·Mar 1, 20:57 UTC · Mar 1, 2023VulnerabilityCVE-2022-2189460
Researchers Discover "Bootkitty" – First UEFI Bootkit Targeting Linux KernelsThe Hacker News·Dec 2, 16:30 UTC · Dec 2, 2024RansomwareCVE-2023-4023860
BlackLotus Becomes First UEFI Bootkit Malware to Bypass Secure Boot on Windows 11The Hacker News·Jun 23, 08:42 UTC · Jun 23, 2023Malware in the wildCVE-2022-21894160
BlackLotus Malware Hijacks Windows Secure Boot ProcessSchneier on Security·Mar 15, 00:00 UTC · Mar 15, 2023Malware in the wildCVE-2022-2189460
New Bootkit “Bootkitty” Targets Linux Systems via UEFIInfosecurity Magazine·Nov 27, 16:30 UTC · Nov 27, 2024Exploit / PoC60
Critical vulnerability affecting most Linux distros allows for bootkitsArs Technica · Security·Feb 7, 01:37 UTC · Feb 7, 2024VulnerabilityCVE-2023-4054760
Week in review: LastPass breach, GCP data exfiltration, UEFI bootkitHelp Net Security·Mar 5, 00:00 UTC · Mar 5, 2023Ransomware60
⚡ Weekly Recap: Bootkit Malware, AI-Powered Attacks, Supply Chain Breaches, ZeroThe Hacker News·Oct 14, 10:56 UTC · Oct 14, 2025Malware in the wildCVE-2025-2104360
Microsoft fixes two actively exploited bugs, one used by BlackLotus bootkit (CVE-2023-29336, CVE-2023-24932)Help Net Security·May 9, 00:00 UTC · May 9, 2023Vulnerability in the wildCVE-2023-29336CVE-2023-24932CVE-2022-21882+10 CVEs160
Just about every Windows and Linux device vulnerable to new LogoFAIL firmware attackArs Technica · Security·Dec 6, 15:02 UTC · Dec 6, 2023Exploit / PoC60
Microsoft’s Secure Boot has been broken for a decade and no one noticed until nowArs Technica · Security·Jul 15, 00:00 UTC · Jul 15, 2026Vulnerability in the wildCVE-2015-5381160
Cisco ASA Firewall Zero-Day Exploits Deploy RayInitiator and LINE VIPER MalwareThe Hacker News·Sep 27, 12:13 UTC · Sep 27, 2025Exploit / PoC in the wildCVE-2025-20362CVE-2025-20333CVE-2025-2036360
200,000 Linux systems from Framework are shipped with signed UEFI components vulnerable to Secure Boot bypassSecurity Affairs·Oct 15, 14:22 UTC · Oct 15, 2025RansomwareCVE-2022-34302CVE-2023-48733CVE-2024-734460
HybridPetya Mimics NotPetya, Adds UEFI CompromiseInfosecurity Magazine·Sep 15, 16:45 UTC · Sep 15, 2025RansomwareCVE-2024-734460
THN Recap: Top Cybersecurity Threats, Tools and Tips (Nov 25The Hacker News·Dec 2, 11:25 UTC · Dec 2, 2024RansomwareCVE-2024-9680CVE-2024-49039CVE-2024-11680+14 CVEs60
Urgent: Microsoft Issues Patches for 97 Flaws, Including Active Ransomware ExploitThe Hacker News·Apr 15, 00:00 UTC · Apr 15, 2023Ransomware in the wildCVE-2023-28252CVE-2022-24521CVE-2022-37969+6 CVEs60
Advanced threat predictions for 2023Kaspersky Securelist·Nov 14, 08:00 UTC · Nov 14, 2022Ransomware in the wild60
TrickBoot feature allows TrickBot bot to run UEFI attacksSecurity Affairs·Dec 3, 14:32 UTC · Dec 3, 2020Ransomware in the wild60
The Careto/Mask APT: Frequently Asked QuestionsKaspersky Securelist·Feb 10, 21:03 UTC · Feb 10, 2014Exploit / PoCCVE-2012-077360
Patch Tuesday, January 2026 EditionKrebs on Security·Jan 15, 00:00 UTC · Jan 15, 2026Vulnerability in the wildCVE-2026-20805CVE-2026-20952CVE-2026-20953+6 CVEs160
September 2025 CVE LandscapeRecorded Future·Oct 17, 00:00 UTC · Oct 17, 2025Exploit / PoC in the wildCVE-2025-53690CVE-2021-21311CVE-2025-20333+6 CVEs60
UK NCSC warns that attackers exploited Cisco firewall zero-days to deploy RayInitiator and LINE VIPER malwareSecurity Affairs·Sep 26, 11:49 UTC · Sep 26, 2025Exploit / PoCCVE-2025-20362CVE-2025-20333CVE-2025-2036360
HybridPetya: (Proof-of-concept?) ransomware can bypass UEFI Secure BootHelp Net Security·Sep 12, 00:00 UTC · Sep 12, 2025RansomwareCVE-2024-734460
Week in review: Google fixes zero-day vulnerability in Chrome, critical SQL injection flaw in FortiWebHelp Net Security·Jul 20, 00:00 UTC · Jul 20, 2025Exploit / PoC in the wildCVE-2025-6558CVE-2025-2525760
Chinese national charged for hacking thousands of Sophos firewallsSecurity Affairs·Dec 11, 10:20 UTC · Dec 11, 2024Policy & legal in the wildCVE-2020-1227160
Sophos details five years of China-linked threat actors' activity targeting network devices worldwideSecurity Affairs·Nov 2, 16:18 UTC · Nov 2, 2024Threat actor60
Microsoft Patch Tuesday, May 2023 EditionKrebs on Security·May 10, 07:06 UTC · May 10, 2023Vulnerability in the wildCVE-2023-29336CVE-2023-24932CVE-2023-24941+2 CVEs60
Week in review: Finding stolen credentials on VirusTotal, BNPL attracting fraudstersHelp Net Security·Feb 28, 14:42 UTC · Feb 28, 2022Phishing & fraudCVE-2021-3524760
IT threat evolution Q3 2021Kaspersky Securelist·Nov 26, 12:00 UTC · Nov 26, 2021Exploit / PoCCVE-2021-4044460
Advanced threat predictions for 2022Kaspersky Securelist·Nov 17, 10:00 UTC · Nov 17, 2021Ransomware60
Japanese businesses are the latest victims of attacks disguised as ransomwareCyberScoop·Nov 3, 18:51 UTC · Nov 3, 2017Ransomware in the wild60
Hacking 4G USB modems and SIM Card via SMSSecurity Affairs·Dec 31, 13:37 UTC · Dec 31, 2014Exploit / PoC60
Oil shipments, drone makers, and a poisoned code library targeted in recent APT campaignsHelp Net Security·Jun 19, 12:07 UTC · Jun 19, 2026Threat actor60
ThreatsDay Bulletin: AI Agents Gone Wrong, Sketchy C2 Tools, ClickFix Tricks, JS Backdoors & 20+ New StoriesThe Hacker News·Jun 4, 14:00 UTC · Jun 4, 2026Malware in the wildCVE-2026-20230160
FIRESTARTER Backdoor Hit Federal Cisco Firepower Device, Survives Security PatchesThe Hacker News·Apr 25, 08:20 UTC · Apr 25, 2026VulnerabilityCVE-2025-20333CVE-2025-2036260
Friday Squid Blogging: Squid Fishing in PeruSchneier on Security·Feb 27, 22:04 UTC · Feb 27, 2026Ransomware60