Approximately a month ago, F5 published advisory on malware deployed to BIG-IP systems vulnerable to CVE-2025-53521. #ESETresearch discovered two related malware components on VirusTotal and named the threat #PoisonedRefresh. 1/6
https://t.co/OfekbKd8a9
I got completely owned by the most sophisticated hack I've ever encountered.
I'm a developer. I know what scams look like.
This didn't look like one.
🧵
#ESETresearch discovered #GopherWhisper, a new 🇨🇳 China-aligned APT group that targeted a governmental entity in Mongolia 🇲🇳. https://t.co/XqdtalstDI 1/7
@GenThreatLabs Airbnb users should be also aware, this is a Whatsapp message regarding a @Airbnb reservation. Accommodation name, client name and dates were all valid. It was sent to the phone number associated with the booking. Link opens a fake reservation site requesting payment information
https://t.co/ecjQDDOlzR is notifying affected users that some reservation data was accessed by unauthorized parties and that reservation PINs are being reset.
Those alerts are real.
At the same time, we are detecting reservation hijack scams that take advantage of real booking data, as in the screenshot here. No obvious red flags, no generic message, just the right hotel, the right dates, the right amount, and a link that feels like part of the normal booking flow.
That is exactly why these scams work.
Do not trust the message alone. Verify through the official website, app, or your original confirmation.
More details in our blog:
https://t.co/6FqCYiipXT
Cisco Talos recently published an analysis of an EDR killer used by the #Qilin#ransomware gang. #ESETresearch tracks this threat as #CardSpaceKiller and we recently provided additional insights in our blog https://t.co/fHOclYAGGn 1/6
#ESETresearch's Eric Howard will be presenting at Botconf. Join him in Reims, France to hear about “GopherWhisper, Uncovering an APT’s secrets through its own words” on Apr 15 at 17.15 CEST. For more information, check out https://t.co/wsI7OyKHae 1/3
#ESETresearch detected a recent intrusion at a 🇵🇱University of Warsaw consistent with #Interlock ransomware gang. Thanks to early warning from our experts and the university's swift cooperation, the attack was disrupted before encryptors could be deployed. https://t.co/aV2QBFdvbO 1/7
How well your AI agent is protected heavily depends on which platform it runs on.
We found this out building Sage 🛡️, an open-source runtime security layer for AI agents. Integrating across Claude Code, Cursor, OpenClaw... each platform exposes a different subset of security-relevant events. A few report properly, some partially, the rest not at all.
No amount of better rules can fix that. You need a contract between agent platforms and security tools. What gets reported, when, and how decisions are enforced.
That contract didn't exist. So we wrote one at @GenThreatLabs.
Today we published AARTS, the AI Agent Runtime Safety Standard. Open spec, vendor-neutral, designed so any security engine can plug into any compliant host. Not tied to Sage.
Spec is open. We need platform builders and security vendors to collaborate on it and adopt it to make it real. 🤝
@bcherny@steipete@OpenAI@Copilot
https://t.co/y1mL3BgZdp
Almost all of us are using #AI agents now. Is it safe? Not always. So with my team we built Sage: Safety for Agents. We call it the first consumer Agent Detection and Response (ADR). And it's #OpenSource now. Try it.
https://t.co/TG09gkgbfW
https://t.co/7l6bZ40D3E
#GenSage
Is here someone who can help me with creating a USB installer for a Macbook Air? I’m trying to reinstall Sequoia on a macbook where recovery constantly fails. I have a macbook with Tahoe but I’m not able to download Sequoia through AppStore or Terminal.
#BREAKNG#ESETresearch identified the wiper #DynoWiper used in an attempted disruptive cyberattack against the 🇵🇱 Polish energy sector on Dec 29, 2025. At this point, no successful disruption is known, but the malware’s design clearly indicates destructive intent. 1/5
A cyberattack targeting Poland's energy infrastructure in December used wiper malware that would have erased grid computers and rendered them inoperable had it not been thwarted, researchers at @ESET told me. https://t.co/h0wFRyvO6C
Call for Papers is now open for #VB2026!
We're looking for engaging, insightful, and original talks for the 36th VB Conference, taking place 14–16 October 2026 in Seville, Spain 🇪🇸
📅 Deadline: 9 April 2026
📝 Submit your abstract 👉https://t.co/ZxKMxHznWw
LAST CALL - for papers!
Today is the last day to submit your paper for a presentation slot at #CARO2026 in Innsbruck, organized by AV-Comparatives.
Find any relevant info at https://t.co/gju6rTltLD
#ESETresearch has observed #Gamaredon exploiting CVE-2025-8088 (#WinRAR path traversal) in an ongoing spearphishing campaign. This vulnerability allows arbitrary file write via crafted RAR archives. 1/5
#ESETresearch has uncovered the North Korea-aligned threat actor, DeceptiveDevelopment, targeting freelance developers with trojanized coding challenges and fake job interviews.
https://t.co/vtWzae7rrp 1/6