Week in review: LastPass breach, GCP data exfiltration, UEFI bootkitHelp Net Security·Mar 5, 00:00 UTC · Mar 5, 2023Ransomware60
MosaicRegressor: Lurking in the Shadows of UEFIKaspersky Securelist·Oct 5, 10:00 UTC · Oct 5, 2020Vulnerability42
China-Linked FishMonger Ports SprySOCKS to Windows With Kernel-Level Stealth and UEFI Bootkit HintsSecurity Affairs·Jun 17, 08:10 UTC · Jun 17, 2026VulnerabilityCVE-2023-2493247
⚡ Weekly Recap: Bootkit Malware, AI-Powered Attacks, Supply Chain Breaches, ZeroThe Hacker News·Oct 14, 10:56 UTC · Oct 14, 2025Malware in the wildCVE-2025-2104360
HybridPetya ransomware bypasses UEFI Secure Boot echoing Petya/NotPetyaSecurity Affairs·Sep 13, 12:06 UTC · Sep 13, 2025Ransomware57
Microsoft fixes two actively exploited bugs, one used by BlackLotus bootkit (CVE-2023-29336, CVE-2023-24932)Help Net Security·May 9, 00:00 UTC · May 9, 2023Vulnerability in the wildCVE-2023-29336CVE-2023-24932CVE-2022-21882+10 CVEs160
MoonBounce: the dark side of UEFI firmwareKaspersky Securelist·Jan 20, 10:00 UTC · Jan 20, 2022Malware42
New 'MosaicRegressor' UEFI Bootkit Malware Found Active in the WildThe Hacker News·Oct 6, 08:33 UTC · Oct 6, 2020Malware30
Just about every Windows and Linux device vulnerable to new LogoFAIL firmware attackArs Technica · Security·Dec 6, 15:02 UTC · Dec 6, 2023Exploit / PoC60
NSA Releases Guide to Mitigate BlackLotus Bootkit InfectionsInfosecurity Magazine·Jun 26, 16:30 UTC · Jun 26, 2023VulnerabilityCVE-2022-2189435
Microsoft’s Secure Boot has been broken for a decade and no one noticed until nowArs Technica · Security·Jul 15, 00:00 UTC · Jul 15, 2026Vulnerability in the wildCVE-2015-5381160
Cisco ASA Firewall Zero-Day Exploits Deploy RayInitiator and LINE VIPER MalwareThe Hacker News·Sep 27, 12:13 UTC · Sep 27, 2025Exploit / PoC in the wildCVE-2025-20362CVE-2025-20333CVE-2025-2036360
MBRFilter — Open Source Tool to Protect Against 'Master Boot Record' MalwareThe Hacker News·Oct 20, 16:33 UTC · Oct 20, 2016Malware42
Kaspersky Security Bulletin 2008: Malware Evolution JanuaryKaspersky Securelist·Sep 24, 10:00 UTC · Sep 24, 2008Malware42
200,000 Linux systems from Framework are shipped with signed UEFI components vulnerable to Secure Boot bypassSecurity Affairs·Oct 15, 14:22 UTC · Oct 15, 2025RansomwareCVE-2022-34302CVE-2023-48733CVE-2024-734460
HybridPetya Mimics NotPetya, Adds UEFI CompromiseInfosecurity Magazine·Sep 15, 16:45 UTC · Sep 15, 2025RansomwareCVE-2024-734460
THN Recap: Top Cybersecurity Threats, Tools and Tips (Nov 25The Hacker News·Dec 2, 11:25 UTC · Dec 2, 2024RansomwareCVE-2024-9680CVE-2024-49039CVE-2024-11680+14 CVEs60
Urgent: Microsoft Issues Patches for 97 Flaws, Including Active Ransomware ExploitThe Hacker News·Apr 15, 00:00 UTC · Apr 15, 2023Ransomware in the wildCVE-2023-28252CVE-2022-24521CVE-2022-37969+6 CVEs60
Advanced threat predictions for 2023Kaspersky Securelist·Nov 14, 08:00 UTC · Nov 14, 2022Ransomware in the wild60
MoonBounce UEFI implant spotted in a targeted APT41 attackSecurity Affairs·Jan 21, 11:59 UTC · Jan 21, 2022Threat actor57
TrickBoot feature allows TrickBot bot to run UEFI attacksSecurity Affairs·Dec 3, 14:32 UTC · Dec 3, 2020Ransomware in the wild60
Bug in widely used bootloader opens Windows, Linux devices to persistent compromiseHelp Net Security·Aug 3, 11:37 UTC · Aug 3, 2020MalwareCVE-2020-1071347
The Careto/Mask APT: Frequently Asked QuestionsKaspersky Securelist·Feb 10, 21:03 UTC · Feb 10, 2014Exploit / PoCCVE-2012-077360
Kaspersky Security Bulletin 2009. Malware Evolution 2009Kaspersky Securelist·Feb 17, 17:16 UTC · Feb 17, 2010Malware30
11 Old Microsoft-Signed Linux UEFI Shims Could Let Attackers Bypass Secure BootThe Hacker News·Jul 15, 00:00 UTC · Jul 15, 2026VulnerabilityCVE-2026-8863CVE-2026-1079747
China-Linked SprySOCKS Backdoor Expands to Windows with DriverThe Hacker News·Jun 15, 00:00 UTC · Jun 15, 2026MalwareCVE-2023-2493247
Patch Tuesday, January 2026 EditionKrebs on Security·Jan 15, 00:00 UTC · Jan 15, 2026Vulnerability in the wildCVE-2026-20805CVE-2026-20952CVE-2026-20953+6 CVEs160
September 2025 CVE LandscapeRecorded Future·Oct 17, 00:00 UTC · Oct 17, 2025Exploit / PoC in the wildCVE-2025-53690CVE-2021-21311CVE-2025-20333+6 CVEs60
ThreatsDay Bulletin: $15B Crypto Bust, Satellite Spying, BillionThe Hacker News·Oct 15, 00:00 UTC · Oct 15, 2025Vulnerability55
UK NCSC warns that attackers exploited Cisco firewall zero-days to deploy RayInitiator and LINE VIPER malwareSecurity Affairs·Sep 26, 11:49 UTC · Sep 26, 2025Exploit / PoCCVE-2025-20362CVE-2025-20333CVE-2025-2036360
HybridPetya: (Proof-of-concept?) ransomware can bypass UEFI Secure BootHelp Net Security·Sep 12, 00:00 UTC · Sep 12, 2025RansomwareCVE-2024-734460
Week in review: Google fixes zero-day vulnerability in Chrome, critical SQL injection flaw in FortiWebHelp Net Security·Jul 20, 00:00 UTC · Jul 20, 2025Exploit / PoC in the wildCVE-2025-6558CVE-2025-2525760
Microsoft Warns of StilachiRAT: A Stealthy RAT Targeting Credentials and Crypto WalletsThe Hacker News·Mar 18, 07:00 UTC · Mar 18, 2025Malware42