Forgotten UEFI shims undermining Secure Boot
2026-07-15T20:51:39Z•bde3c92d63d299ad17ea46671be46f512f21d641f14033b2ad2785577aded7cb
AI-enabled attacksAPTAmadeyAndroid RATEDR evasionEvilTokensMicrosoft-signed binariesOT securitySMB securitySecure BootSprySOCKSStealcUEFIUEFI shimbootloader vulnerabilitiesbotnet disruptionmalwarephishingsupply chainthreat intelligence
What happened
ESET’s WeLiveSecurity feed (Apr–Jul 2026) highlights multiple high-impact research findings and practical guidance: discovery of 11 Microsoft-signed vulnerable UEFI shim bootloaders that allow Secure Boot bypasses; analysis of numerous APTs and malware families (FishMonger/SprySOCKS, Gamaredon, OceanLotus, ScarCruft, GopherWhisper, Webworm, FrostyNeighbor, NGate, Amadey/Stealc disruption); new phishing techniques (EvilTokens) and large-scale Android threats (BTMOB, CallPhantom); supply-chain, OT and SMB security guidance; and investigations into EDR-killing frameworks and AI-influenced attack/
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- eset_welivesecurity
- Record identifier
- bde3c92d63d299ad17ea46671be46f512f21d641f14033b2ad2785577aded7cb
- Enrichment time
- 2026-07-15T20:51:39Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.