Ján Trenčanský
@j91321.bsky.social
EDR R&D team lead at ESET. Opinions are my own. @j91321@infosec.exchange
Bruh... there's a "master key" that grants access to every Cosmos DB on Azure? Wut? www.wiz.io/blog/cosmose...
deepfake nudes are, of course, integral to the future of space exploration
SpaceX-owned xAI, the developer of Grok, sued Minnesota AG to challenge a law coming into effect in the state that will ban "nudify" apps, use of these AI image generators to make non-consenting intimate images, aka AI deepfake porn of real people including minors. www.cnbc.com/2026/07/28/s...
This is: 1. A massive control failure at OpenAI 2. A marketing ploy 3. A control failure disguised by a marketing ploy 4. Some other combination of the above This has far less Skynet energy than "the banks told us we can't IPO at $1T" energy.
OpenAI admits its models hacked another company in 'unprecedented cyber incident'
#ESETresearch discovered and reported to @certcc 11 old Microsoft-signed UEFI shim bootloaders that allow bypassing UEFI Secure Boot on most UEFI systems. Read about it at www.welivesecurity.com/en/eset-rese... 1/5
Forgotten UEFI shims undermining Secure Boot
ESET researchers discovered 11 vulnerable UEFI shim bootloaders signed by Microsoft that allow attackers to bypass UEFI Secure Boot by exploiting decade-old vulnerabilities.
welivesecurity.com
“It might feel like you’re ‘saving time and money,’ but you’re actually slowly turning your brand into something generic like all the other brands out there using AI tools.” www.404media.co/we-are-livin...
We Are Living in a ‘ChatGPT Flyer Pandemic’
"Hey if this is your flyer, I’m not going, I’m not donating, I’m not sharing. Don’t ask me."
404media.co
Discontinuing Google Earth desktop does not come unexpected, but it's terrible news. The web tool is utterly useless for me and many geo folk. There'll be workarounds for most features, but not for 𝗲𝗮𝘀𝘆 3D view of historical imagery and for sharing placemarks.
Google Earth Pro will be no longer avaliable for download from June 2027 onwards. It's one of the tools that made my early work possible, so it's really sad to see it go. support.google.com/earth/thread...
Google Earth Pro will be no longer avaliable for download from June 2027 onwards. It's one of the tools that made my early work possible, so it's really sad to see it go. support.google.com/earth/thread...
Update on Google Earth Pro desktop app downloads - Google Earth Community
support.google.com
We hypothesized that GentleKiller was an internal tool in February 2026, and the recent leak of Gentlemen data confirmed our suspicions. The leaked data also allowed us to link one of Gentlemen’s affiliates to a credential stealer we named OxideHarvest. 5/6
#ESETresearch analyzed the robust EDR-killer toolset of the RaaS gang Gentlemen. Thanks to our continued incident-level visibility, we could provide a uniquely deep view into the group’s EDR-killer development practices. www.welivesecurity.com/en/eset-rese... 1/6
welivesecurity.com
#ESETresearch discovered two as-yet undocumented Windows variants of #SprySOCKS, a previously Linux-only backdoor reportedly used by #FishMonger. We attribute the new Windows variants to #FishMonger with high confidence. www.welivesecurity.com/en/eset-rese... 1/4
FishMonger’s arsenal upgraded: SprySOCKS for Windows
ESET researchers have discovered SprySOCKS for Windows, FishMonger’s backdoor weaponizing a kernel driver for advanced stealthiness.
welivesecurity.com
'We are clamping down on the harm caused by social media. 'Read all about it on the Nazi pogrom deepfake abuse website'
#ESETresearch has discovered a supply-chain attack targeting stock investors in Vietnam, distributing SPECTRALVIPER through the update mechanism of the FireAnt Metakit stock investment platform. www.welivesecurity.com/en/eset-rese... 1/4
Cloudflare has finally started signing the cloudflared tunneling utility, after years of ignoring the issue. Of course they ignored my other request to also populate the original filename, because that would make sense... It's still used by ransomware gangs and it's often renamed.
I think I might be the only person who has completed MindsEye twice. It’s the most bonkers video game ever made, this thing should be put a vault for humanity to study after the apocalypse. Observe my thread 🪡
Looks like these were released minutes after Microsoft released Patch Tuesday... I don't know if this is trolling or genuine anger
Honestly if the account didn't release two working exploits before, I'd dismiss YellowKey Bitlocker bypass as an elaborate troll. Just read check the README github.com/Nightmare-Ec...
GitHub - Nightmare-Eclipse/YellowKey: YellowKey Bitlocker Bypass Vulnerability
YellowKey Bitlocker Bypass Vulnerability. Contribute to Nightmare-Eclipse/YellowKey development by creating an account on GitHub.
github.com
Babe wake up, new Windows privesc just dropped. #GreenPlasma. Oh and also Bitlocker bypass #YellowKey github.com/Nightmare-Ec...
GitHub - Nightmare-Eclipse/GreenPlasma: GreenPlasma Windows CTFMON Arbitrary Section Creation Elevation of Privileges Vulnerability
GreenPlasma Windows CTFMON Arbitrary Section Creation Elevation of Privileges Vulnerability - Nightmare-Eclipse/GreenPlasma
github.com
Intellexa had a secret US partner with government ties that fed it Android and iOS exploits on a revenue sharing scheme 🫥 via @jurrevanbergen.nl www.antenna.gr/ereynes/arti...
antenna.gr
Gordon Ramsey, technical writing, and the importance of people who care rachelandrew.co.uk/archives/202...
rachelandrew.co.uk
I'm not joking when I say mRNA technology is more important than "AI" and it's a tragedy we're throwing billions into one while our government is aggressively defunding the other.
"Pancreatic cancer mRNA vaccine shows lasting results in an early trial: Scientists caution that more research is needed, but nearly all of the patients who responded to the personalized vaccine are still alive six years later."
Cisco Talos recently published an analysis of an EDR killer used by the #Qilin #ransomware gang. #ESETresearch tracks this threat as #CardSpaceKiller and we recently provided additional insights in our blog www.welivesecurity.com/en/eset-rese... 1/6
EDR killers explained: Beyond the drivers
ESET researchers dive deeper into the EDR killer ecosystem, disclosing how attackers abuse vulnerable drivers.
welivesecurity.com
ESET Inspect killed the Axios compromise execution chain on Windows straight out-of-the-box. Renaming PowerShell is a terrible tradecraft if it was intended as EDR evasion. "Renamed PowerShell Execution [D0411]" is a simple yet solid EDR indicator.
#ESETresearch has identified a Silver Fox campaign that actively takes advantage of the current annual tax filing and organizational change season in Japan, a period when companies generate a high volume of legitimate financial and HRrelated comms. www.welivesecurity.com/en/business-... 1/8
A cunning predator: How Silver Fox preys on Japanese firms this tax season
Silver Fox is back in Japan, spoofing tax and HR emails timed to the one season when many people don’t think twice about opening them
welivesecurity.com
This is a correct take. AI compliance is over hyped. It’s just a flavor of privacy compliance. Processes and people help mature compliance here.
The number of "AI compliance" and "AI third party risk management" supposed-solutions on display at RSAC was wild. Tech can help with these problems. Tech CANNOT automate either of these processes, contrary to so many vendor booths.
Is your business thinking about going all-in on AI for cyber defense? Security experts have a warning: Don't do that. "If Claude wrote your YARA rules, they’re probably crap." My story from #RSAC: www.cybersecuritydive.com/news/ai-cybe...
Paying to market your company on an Incel Camino is *A Choice*. I didn't know anything about SecureOS before I saw this. Now I'm on a mission to ensure that doesn't change.
in the age of networked systems where major powers conduct conflicts either through proxies or at stand-off distances, expecting an adversary to abdicate a meaningful means of asymmetric cost imposition simply because of your morality is utterly, laughably naive. the message for defense: git gud.
#ESETresearch analyzed more than 80 EDR killers, seen across real-world intrusions, and used ESET telemetry to document how these tools operate, who uses them, and how they evolve beyond simple driver abuse. www.welivesecurity.com/en/eset-rese... 1/6