Forgotten UEFI shims undermining Secure Boot

2026-07-15T20:51:39Zbde3c92d63d299ad17ea46671be46f512f21d641f14033b2ad2785577aded7cb
AI-enabled attacksAPTAmadeyAndroid RATEDR evasionEvilTokensMicrosoft-signed binariesOT securitySMB securitySecure BootSprySOCKSStealcUEFIUEFI shimbootloader vulnerabilitiesbotnet disruptionmalwarephishingsupply chainthreat intelligence

What happened

ESET’s WeLiveSecurity feed (Apr–Jul 2026) highlights multiple high-impact research findings and practical guidance: discovery of 11 Microsoft-signed vulnerable UEFI shim bootloaders that allow Secure Boot bypasses; analysis of numerous APTs and malware families (FishMonger/SprySOCKS, Gamaredon, OceanLotus, ScarCruft, GopherWhisper, Webworm, FrostyNeighbor, NGate, Amadey/Stealc disruption); new phishing techniques (EvilTokens) and large-scale Android threats (BTMOB, CallPhantom); supply-chain, OT and SMB security guidance; and investigations into EDR-killing frameworks and AI-influenced attack/

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
eset_welivesecurity
Record identifier
bde3c92d63d299ad17ea46671be46f512f21d641f14033b2ad2785577aded7cb
Enrichment time
2026-07-15T20:51:39Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Forgotten UEFI shims undermining Secure Boot · Baitaphish