Protecting education: How MDR can tip the balance in favor of schools
2026-03-05T08:51:46Z•5c993c20e2079e4fef7c5168449a9071dad2ff6280ec056a007de97e56ca0d1e
CVE-2025-50165android-malwareaptdata-wiperdynowiperespionagegenailongnosedgoblinmanaged-detection-and-responsemobile-securitymuddywaterphishingransomwaresandwormscamsvulnerabilitywindows-imaging-component
What happened
Collection of ESET WeLiveSecurity reports (Dec 2025–Mar 2026) covering multiple high-risk incidents and research: discovery of PromptSpy — the first known Android malware to abuse generative AI in its execution flow; DynoWiper, a destructive data‑wiper used in an attack on Poland’s energy sector attributed to Sandworm; technical analysis and attribution on the Sandworm activity; and an ESET revisit of CVE-2025-50165, a critical Windows Imaging Component vulnerability. Additional coverage includes espionage APT activity (LongNosedGoblin, MuddyWater), targeted Android spyware campaigns (Pakistan
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- eset_welivesecurity
- Record identifier
- 5c993c20e2079e4fef7c5168449a9071dad2ff6280ec056a007de97e56ca0d1e
- Enrichment time
- 2026-03-05T08:51:46Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.