ESET WeLiveSecurity
eset · B · active
https://www.welivesecurity.com/en/
ESET research blog; particularly strong on European APT activity. RSS at https://www.welivesecurity.com/en/rss/feed/ mirrors the listing. 2026-05-08 audit: 5 dated posts latest 2026-05-07 on CallPhantom, ScarCruft. | 2026-06-20 full audit (v2.62): live=Y, drill=Y. FETCH → webfetch https://www.welivesecurity.com/en/ (listing) then webfetch per-article URL; RSS mirror at https://www.welivesecurity.com/en/rss/feed/. AVOID: No issues — WebFetch works on listing and detail. No bridge needed.. | 2026-07-05 admiralty audit: B — vendor research lab, original telemetry-driven research (esp. EU APTs); live, keep active.
Cited in 22 entries
Citation cadence
Citation days per ISO week (11 weeks of coverage span, total 17).
- TA458 / Operation RoundPress: a running supply of half-click webmail zero-days adds a fresh SOGo flaw (CVE-2026-8496)2026-07-25
- CVE-2026-8863, CVE-2026-10797 — forgotten pre-0.9 UEFI shims bypass Secure Boot via a signature-length validation mismatch2026-07-14
- ESET Threat Report H1 2026: first Android malware using generative AI at runtime, ClickFix detections more than double, record QR-phishing, 100+ EDR-killers2026-07-09
- The Gentlemen2026-06-29
- ESET "Killing me gently" — a de-facto mid-year RaaS-tooling report2026-06-29
- ESET Gamaredon 2025 — annual actor retrospective2026-06-29
- ESET's 2025 Gamaredon paper: exfil and C2 moved wholesale onto trusted cloud services (ANNUAL REPORT)2026-06-26
- Operation Endgame dismantles the Amadey and StealC malware-as-a-service backbone2026-06-25
- Threat actor: FishMonger (I-SOON) ports SprySOCKS to Windows with a kernel-mode rootkit2026-06-22
- The Gentlemen — EDR-killer framework documented, OT-adjacent victim claimed, operator named2026-06-22
- ESET: the Gentlemen RaaS gang centrally builds and maintains its affiliates' EDR-killer framework2026-06-19
- FishMonger (I-SOON) ports its SprySOCKS backdoor to Windows with a kernel-driver rootkit2026-06-17
- ESET: OceanLotus (APT32) compromises a stock-trading platform's update server — selective SPECTRALVIPER delivery, no integrity checks to defeat2026-06-12
- ESET APT Activity Report Q4 2025–Q1 2026: Sandworm strikes NATO energy, Lazarus targets EU drone sector, UNC5221 pivots to Ivanti SPAWN toolset2026-05-30
- WatchGuard documents Grandoreiro's Delphi-DLL-side-loading + WebSocket/STUN C2 against Portuguese & Spanish banks; ESET maps parallel Android BTMOB MaaS2026-05-29
- Finance — Iberian retail-banking pressure from Grandoreiro plus a parallel Android MaaS2026-05-25
- ESET APT Activity Report Q4 2025–Q1 2026 — three state programmes converging on EU energy, defence and edge appliances2026-05-25
- Webworm (China-aligned) shifts to EU government targets — EchoCreep (Discord C2) and GraphWorm (Microsoft Graph / OneDrive C2) backdoors documented by ESET, with Belgian, Italian, Serbian, Polish and Spanish governmental victims2026-05-21
- Webworm (China-aligned; FishMonger / Aquatic Panda) — pivots to EU government targets2026-05-18
- FrostyNeighbor / Ghostwriter (UNC1151, Belarus state-aligned): ESET documents March–May 2026 campaign targeting Polish, Lithuanian, and Ukrainian government and industrial sectors2026-05-15
- Public administration and government2026-05-11
- FrostyNeighbor / Ghostwriter (UNC1151) — ESET analysis corroborated, Poland / Lithuania / Ukraine in EU scope2026-05-11