Aryeh Goretsky @goretsky.bsky.social · 29/09/2026I know I have a few followers in Slovakia. In case you're looking for a job there, here's an interesting-sounding opportunity: www.att.jobs/job/bratisla... No affiliation with the company, just passing it along. 030
Aryeh Goretsky @goretsky.bsky.social · 19/09/2026Today would have been John McAfee's 81st birthday. 020
Aryeh Goretsky @goretsky.bsky.social · 18/09/2026If you purchased a ThinkNode M9 LoRA device from @elecrow.bsky.social be aware the internally-mounted MicroSD card is infected: www.elecrow.com/Thinknode-M9-Security-Advisory-SD-Card-Malware-Risk.htmlelecrow.comOfficial notice regarding the TF card worm virus found on some ThinkNode M9 units 000
Reposted by Aryeh GoretskyESET Research @esetresearch.bsky.social · 17/09/2026#ESETresearch discovered SparroWocky, a new backdoor of the #FamousSparrow APT group. This new malware has quickly replaced SparrowDoor as the 🇨🇳 China-aligned group’s flagship backdoor. www.welivesecurity.com/en/eset-rese... 1/6welivesecurity.comhttps://www.welivesecurity.com/en/eset-research/beware-sparrowock-backdoor-bites-commands-catch/ 177
Reposted by Aryeh GoretskyESET Research @esetresearch.bsky.social · 16/09/2026Heading to #LABScon2026? Join #ESETresearch’s Anton Cherepanov and Peter Strýček on Sept. 18 at 2:45 PM MST in Scottsdale, AZ for: Inside a Sandworm Attack: UAC-0099 Access and a Yggdrasil-backed Backdoor. 1/4 132
Reposted by Aryeh GoretskyESET Research @esetresearch.bsky.social · 15/09/2026Join #ESETresearch’s Filip Jurčacko at #LABScon2026, on Sept. 18 at 2:15 PM MST in Scottsdale, AZ for CinderRelay: The Linux Backbone of ScarCruft’s Covert Network. 1/4 142
Reposted by Aryeh GoretskyESET Research @esetresearch.bsky.social · 01/09/2026#ESETresearch hunted for additional context and found that we detected this backdoor between 2020-11 and 2023-11, targeting financial services sector in the Netherlands and Kazakhstan. 1/6 x.com/genthreatlab...x.comGen Threat Labs (@GenThreatLabs) on XA WMI subscription named "Realtek" started a 12 KB backdoor at 19:50, and it never exited. It read its C2 domain by counting spaces in a fake desktop.ini, then called a domain its operator stopped paying for in July 2021. It kept trying for 11 months. Read more -> https://t.co/z7SSDdpWAq 186
Reposted by Aryeh GoretskyESET Research @esetresearch.bsky.social · 27/08/2026#ESETresearch discovered #GuardBreaker - a technique used by Russia-aligned UAC-0099 against a victim in Ukraine, interfering with AI-assisted malware analysis by deliberately triggering LLM safety mechanisms. 1/3 1106
Reposted by Aryeh GoretskyNeowin @neowin.net · 25/08/2026A security researcher recently uncovered that Microsoft embeds hidden identifiers into images created by Copilot in Paint and the Photos app. #Microsoft #Copilot #GUIDneowin.netMicrosoft hides watermarks in AI images made with Paint and Photos, researcher claimsA security researcher recently uncovered that Microsoft embeds hidden identifiers into images created by Copilot in Paint and the Photos app. 021
Reposted by Aryeh GoretskyNeowin @neowin.net · 26/08/2026Is Windows 11 secretly spying on you? A reverse engineer has dug into Microsoft's mysterious performance service to uncover the truth. #Microsoft #Windows11neowin.netReverse engineer explains if Microsoft's Windows 11 performance service is really spywareIs Windows 11 secretly spying on you? A reverse engineer has dug into Microsoft's mysterious performance service to uncover the truth. 021
Aryeh Goretsky @goretsky.bsky.social · 19/08/2026Apparently, Microsoft's fix for Nightmare Eclipse's ShieldBreak vulnerability in Windows Defender caused it to crash. Known affected versions at this time are v1.457.222.0 - 1.457.230.0. Resolved in v1.457.236.0. Details at old.reddit.com/r/antivirus/...old.reddit.comWindows Defender Not Working.When I try to run a scan, it stops and then tells me to restart the service. There are no exclusions and nothing of note from my start up apps.... 031
Aryeh Goretsky @goretsky.bsky.social · 17/08/2026Seeing a bit of traffic around this thread on #Reddit alleging mass attack by 🇵🇰-aligned APT36/Transparent Tribe on 🇮🇳 students: old.reddit.com/r/antivirus/comments/1vppd16/malware_survived_a_usb_windows_reinstall/ Not seeing much evidence outside of thread. Anyone else?old.reddit.comMalware survived a USB windows reinstall?I am currently dealing with a severe ransomware and Remote Access Trojan (RAT) infection identified as "Pakistanware" (linked to APT36 /... 000
Aryeh Goretsky @goretsky.bsky.social · 13/08/2026You know you've been living in one place for a long time when you realize it's time to change the garage door opener's battery 130
Reposted by Aryeh GoretskyVirus Bulletin @virusbtn.bsky.social · 11/08/2026In collaboration with ANY.RUN, Mauro Eldritch from BCA LTD & Heiner García from NorthScan created a fake DeFi startup and hired suspected Famous Chollima operatives, providing a rare inside view of a DPRK IT worker operation. any.run/cybersecurit... 044
Reposted by Aryeh GoretskyVirus Bulletin @virusbtn.bsky.social · 11/08/2026Zscaler ThreatLabz provides a technical analysis of Abyssos, a new modular remote administration tool (RAT) written in C++ that supports a variety of features including credential theft, file exfiltration, and remote access via VNC. www.zscaler.com/blogs/securi... 032
Reposted by Aryeh GoretskyVirus Bulletin @virusbtn.bsky.social · 11/08/2026Microsoft Threat Intelligence presents a technical analysis of the DeadLock ransomware encryptor, covering its execution flow, defence evasion techniques, encryption design, and post-encryption behaviours, including a decentralized recovery chat system. www.microsoft.com/en-us/securi... 022
Reposted by Aryeh GoretskyPatrick C Miller @patrickcmiller.bsky.social · 11/08/2026Taught by AI pioneers, Stanford's free online course takes you far beyond ChatGPT www.zdnet.com/article/free...zdnet.comTaught by AI pioneers, Stanford's free online course takes you far beyond ChatGPTMost AI courses teach today's tools, but this free Stanford classic by Peter Norvig and Sebastian Thrun dives into the deeper foundational ideas you need to truly understand artificial intelligence. 021
Reposted by Aryeh GoretskyESET Research @esetresearch.bsky.social · 05/08/2026At #DEFCON34, @LukasStefanko explores the real-world attack techniques targeting mobile devices and what defenders need to know to stay ahead. 1/3 151
Aryeh Goretsky @goretsky.bsky.social · 31/07/2026I thought finger was deprecated on Windows? Gives Morris Worm vibes: old.reddit.com/r/antivirus/...old.reddit.comhelp asap!!! what do i do??Posted in r/antivirus by u/No_Dust_2724 • 1 point and 4 comments 020
Reposted by Aryeh GoretskyESET Research @esetresearch.bsky.social · 30/07/2026In H1 2026, #ESETresearch analyzed 900,000 agentic AI skills – add-ons providing instructions that teach agents how to perform specific tasks – and found 25,000 suspicious ones and more than 3,000 outright malicious. 1/6 244
Aryeh Goretsky @goretsky.bsky.social · 29/07/2026Full pics of the keyboard, front, and back. Put them all together, and you have the new #Lenovo #ThinkPad X13 Detachable Gen 1! Specs at psref.lenovo.com/Product/Thin... Thanks to everyone who enjoyed the unboxing. Hope you enjoyed the reveal! #LenovoIN #ThinkPadThursday 010
Reposted by Aryeh GoretskyESET Research @esetresearch.bsky.social · 28/07/2026In H1 2026, #ESETresearch continued tracking a growing number of #EDR killers, currently counting 100+ such tools. The dominant approach is still BYOVD, with 60+ of the EDR killers abusing legitimate yet vulnerable drivers. 1/5 1104
Aryeh Goretsky @goretsky.bsky.social · 28/07/2026It's time to take a look inside the 1st part of the package: A #Lenovo logo is clearly visible. It has a webcam, too, and clearly is a member of the #ThinkPad family. It's also powered by an #Intel Core Ultra 7, one of the new Core Ultra Series 3 CPUs. #LenovoIN #ThinkPadThursday 000
Aryeh Goretsky @goretsky.bsky.social · 27/07/2026Here's the #Lenovo stylus. As you can see, it matches up to the pogo pins on the ThinkPad keyboard. It attaches via magnets (I think), with a really satisfying click sound. Very cool design. #LenovoIN #ThinkPadThursday (beginning of the week edition) 110
Aryeh Goretsky @goretsky.bsky.social · 26/07/2026Moving along with the #Lenovo unboxing: Inside is a #ThinkPad keyboard! That TrackPoint is familiar, but it also a circular fingerprint reader (haven't seen one of those before), + a set of pogo pins at the top. I wonder what plugs in there? #LenovoIN #ThinkPadThursday 021
Aryeh Goretsky @goretsky.bsky.social · 24/07/2026In all the excitement I forget to mention the second container inside the box from #Lenovo. Here's what's inside that. #LenovoIN #ThinkPadThursday (albeit belatedly) 020
Aryeh Goretsky @goretsky.bsky.social · 23/07/2026We move on to the next phase of unboxing the #Lenovo laptop, opening the internal carton! #LenovoIN #ThinkPadThursdays 120
Aryeh Goretsky @goretsky.bsky.social · 22/07/2026Moving on with the #Lenovo unboxing, here's the carton that secures it during shipping. The ridges/bumps provide isolation. In photo #1, you can see a literature envelope; in #2, you can see the shipping bag inside with security seal. #LenovoIN #ThinkPadThursday (early edition) 020
Reposted by Aryeh GoretskyESET Research @esetresearch.bsky.social · 22/07/2026ESET detections of #ClickFix doubled (+108%) between H2 2025 and H1 2026 as attackers expanded beyond fake CAPTCHAs to AI platforms (#AI-fix), browser extensions (#CrashFix), and cloud authentication workflows (#ConsentFix). 1/5 143
Aryeh Goretsky @goretsky.bsky.social · 22/07/2026@scoutingamerica.bsky.social Just saw report saying your website is being used to distribute information-stealing malware: old.reddit.com/r/antivirus/comments/1v1xknb/what_tf_is_this/old.reddit.comWhat tf is this!?Posted in r/antivirus by u/LionRegular1470 • 1 point and 3 comments 000
Aryeh Goretsky @goretsky.bsky.social · 19/07/2026The laptop #Lenovo sent me is now unboxed and out of the shipping carton. Hmm… it's a lot thinner than I expected; I've been calling it a laptop, but maybe it is something else? What could it be? #LenovoIN #ThinkPadThursday (weekend edition) 120
Aryeh Goretsky @goretsky.bsky.social · 18/07/2026It's time to take the #Lenovo laptop out of the box. Here we go! #LenovoIN #ThinkPadThursday 010
Aryeh Goretsky @goretsky.bsky.social · 17/07/2026Continuing my unboxing of the box from #Lenovo, I have opened the carton of accessories. It appears to contain a USB-C power supply, a USB-C cable, and a stylus! What could it all mean? #LenovoIN #ThinkPadThursday 010
Reposted by Aryeh GoretskyHelp Net Security @helpnetsecurity.com · 15/07/2026ClickFix is changing the economics of social engineering 🔗 Read more: www.helpnetsecurity.com/2026/07/15/c... #socialengineering #cybercrime #cybersecurity @reversinglabs.comhelpnetsecurity.comClickFix is changing the economics of social engineering - Help Net SecurityClickFix is evolving into a Malware-as-a-Service ecosystem, enabling large-scale social engineering attacks that bypass antivirus defenses. 021
Reposted by Aryeh Goretskykurt baumgartner @kurtisj.bsky.social · 15/07/2026www.consilium.europa.eu/en/press/pre...consilium.europa.euRussian cyber-attacks and destabilising activities: Council sanctions nine individuals and four entitiesThe Council imposed restrictive measures on nine individuals and four entities forming part of Russia's cyber ecosystem, responsible for carrying out, enabling and facilitating malicious cyber a... 033
Reposted by Aryeh GoretskyESET Research @esetresearch.bsky.social · 14/07/2026#ESETresearch discovered and reported to @certcc 11 old Microsoft-signed UEFI shim bootloaders that allow bypassing UEFI Secure Boot on most UEFI systems. Read about it at www.welivesecurity.com/en/eset-rese... 1/5welivesecurity.comForgotten UEFI shims undermining Secure BootESET researchers discovered 11 vulnerable UEFI shim bootloaders signed by Microsoft that allow attackers to bypass UEFI Secure Boot by exploiting decade-old vulnerabilities. 186
Aryeh Goretsky @goretsky.bsky.social · 14/07/2026Something interesting about the box #Lenovo sent me. One of the side flaps has #Lenovo #ThinkPad printed on it, but the font for Lenovo seems a bit off: it is thinner than usual, and the "e" doesn't have the slight rotation. #LenovoIN #ThinkPadThursday (early edition) 000
Aryeh Goretsky @goretsky.bsky.social · 11/07/2026Given the feedback I've received on this mystery box from #Lenovo, I have decided to move things forward a bit. So, here it is, all opened up! #LenovoIN #ThinkPadThursday (belated edition) 010
Aryeh Goretsky @goretsky.bsky.social · 09/07/2026Continuing the examination of the box #Lenovo sent last week, we can see it has an energy efficiency label on it. The waybill's poly bag obscures the QR code, but we can see it has a top rating for efficiency. Whatever is inside sips power. #ThinkPadThursday 110
Reposted by Aryeh GoretskyESET Research @esetresearch.bsky.social · 08/07/2026ESET Threat Report H1 2026: thousands of malicious Agentic AI skills identified, first AI-powered Android malware appears, and ClickFix expands beyond fake CAPTCHA prompts. Attackers are rapidly adapting to new platforms and technologies . Full report: web-assets.esetstatic.com/wls/en/paper... 142
Aryeh Goretsky @goretsky.bsky.social · 06/07/2026Last week, #Lenovo sent me this box, quite unexpectedly. Today, I continue our tour of it, this time focusing on its bottom. It is getting really hard to resist opening it to find out what's inside. #LenovoIN #ThinkPadThursday (special early edition) 031
Reposted by Aryeh GoretskyAryeh Goretsky @goretsky.bsky.social · 05/07/2026And here is the other side of the box from #Lenovo, minus the shipping waybill. Still wondering about what's inside… #LenovoIN #ThinkPad 031
Reposted by Aryeh GoretskyAsher Wolf @asherwolf.bsky.social · 06/07/2026New research has found that major purchases, job hunting, and tax time are emerging as prime targets for fraudsters, with younger Australians facing the highest risk despite their digital confidence www.cyberdaily.au/security/138...cyberdaily.auReport: Scammers are exploiting young Aussies buying their first home and navigating other life eventsNew research has found that major purchases, job hunting, and tax time are emerging as prime targets for fraudsters, with younger Australians facing the highest risk despite their digital confidence. 1165
Aryeh Goretsky @goretsky.bsky.social · 05/07/2026And here is the other side of the box from #Lenovo, minus the shipping waybill. Still wondering about what's inside… #LenovoIN #ThinkPad 031
Aryeh Goretsky @goretsky.bsky.social · 02/07/2026So, I was at home and this box from #Lenovo showed up on my doorstep. I wonder what's inside of it? #LenovoIN #ThinkPadThursday (special Friday edition( 000
Aryeh Goretsky @goretsky.bsky.social · 01/07/2026In 2012 #RunicGames released Torchlight II + last update was in 2017. Multiplayer has had glitches for years that will probably never be fixed. @froggacuda.bsky.social wrote a new game lobby to fix these: github.com/Froggacuda/t... #gamepreservation #reverseengineeringgithub.com 062
Reposted by Aryeh GoretskyESET Research @esetresearch.bsky.social · 25/06/2026#ESETresearch has published a technical analysis of new malicious tools and major infrastructure changes observed in 2025 in the arsenal of the Russia-aligned #Gamaredon #APTgroup targeting Ukraine 🇺🇦. Blogpost: www.welivesecurity.com/en/eset-rese... 1/8welivesecurity.comGamaredon in 2025: Leveraging tunnels, workers, dead drops, and new alliancesESET Research analyzes Gamaredon’s new toolset and the group’s growing reliance on legitimate online services to hide its C&C infrastructure and exfiltrate stolen data. 174
Aryeh Goretsky @goretsky.bsky.social · 19/06/2026Possible McAfee customer data breach: redd.it/1u8fpme Has anyone else received one of these emails?redd.itFrom the antivirus community on Reddit: I got this email from McAfeeExplore this post and more from the antivirus community 031
Reposted by Aryeh GoretskyESET Research @esetresearch.bsky.social · 18/06/2026#ESETresearch analyzed the robust EDR-killer toolset of the RaaS gang Gentlemen. Thanks to our continued incident-level visibility, we could provide a uniquely deep view into the group’s EDR-killer development practices. www.welivesecurity.com/en/eset-rese... 1/6welivesecurity.com 153
Reposted by Aryeh GoretskyESET Research @esetresearch.bsky.social · 16/06/2026#ESETresearch discovered two as-yet undocumented Windows variants of #SprySOCKS, a previously Linux-only backdoor reportedly used by #FishMonger. We attribute the new Windows variants to #FishMonger with high confidence. www.welivesecurity.com/en/eset-rese... 1/4welivesecurity.comFishMonger’s arsenal upgraded: SprySOCKS for WindowsESET researchers have discovered SprySOCKS for Windows, FishMonger’s backdoor weaponizing a kernel driver for advanced stealthiness. 175