Sign in

Aryeh Goretsky

@goretsky.bsky.social
1K followers 3.3K following 149 posts

Security researcher & antivirus pioneer | alum of ESET, McAfee | Microsoft MVP awardee | Mod @Lenovo, @Neowin.Net, Scots Newsletter forums | Intel Insider Council member | Repost ≠ endorse.

PostsRepliesMedia
Aryeh Goretsky @goretsky.bsky.social · 29/09/2026
I know I have a few followers in Slovakia. In case you're looking for a job there, here's an interesting-sounding opportunity: www.att.jobs/job/bratisla... No affiliation with the company, just passing it along.
030
Aryeh Goretsky @goretsky.bsky.social · 19/09/2026
Today would have been John McAfee's 81st birthday.
020
Aryeh Goretsky @goretsky.bsky.social · 18/09/2026
If you purchased a ThinkNode M9 LoRA device from @elecrow.bsky.social be aware the internally-mounted MicroSD card is infected: www.elecrow.com/Thinknode-M9-Security-Advisory-SD-Card-Malware-Risk.html
elecrow.com
Official notice regarding the TF card worm virus found on some ThinkNode M9 units
000
Reposted by Aryeh Goretsky
ESET Research @esetresearch.bsky.social · 17/09/2026
#ESETresearch discovered SparroWocky, a new backdoor of the #FamousSparrow APT group. This new malware has quickly replaced SparrowDoor as the 🇨🇳 China-aligned group’s flagship backdoor. www.welivesecurity.com/en/eset-rese... 1/6
welivesecurity.com
https://www.welivesecurity.com/en/eset-research/beware-sparrowock-backdoor-bites-commands-catch/
177
Reposted by Aryeh Goretsky
ESET Research @esetresearch.bsky.social · 16/09/2026
Heading to #LABScon2026? Join #ESETresearch’s Anton Cherepanov and Peter Strýček on Sept. 18 at 2:45 PM MST in Scottsdale, AZ for: Inside a Sandworm Attack: UAC-0099 Access and a Yggdrasil-backed Backdoor. 1/4
132
Reposted by Aryeh Goretsky
ESET Research @esetresearch.bsky.social · 15/09/2026
Join #ESETresearch’s Filip Jurčacko at #LABScon2026, on Sept. 18 at 2:15 PM MST in Scottsdale, AZ for CinderRelay: The Linux Backbone of ScarCruft’s Covert Network. 1/4
142
Reposted by Aryeh Goretsky
ESET Research @esetresearch.bsky.social · 01/09/2026
#ESETresearch hunted for additional context and found that we detected this backdoor between 2020-11 and 2023-11, targeting financial services sector in the Netherlands and Kazakhstan. 1/6 x.com/genthreatlab...
x.com
Gen Threat Labs (@GenThreatLabs) on X
A WMI subscription named "Realtek" started a 12 KB backdoor at 19:50, and it never exited. It read its C2 domain by counting spaces in a fake desktop.ini, then called a domain its operator stopped paying for in July 2021. It kept trying for 11 months. Read more -> https://t.co/z7SSDdpWAq
186
Reposted by Aryeh Goretsky
ESET Research @esetresearch.bsky.social · 27/08/2026
#ESETresearch discovered #GuardBreaker - a technique used by Russia-aligned UAC-0099 against a victim in Ukraine, interfering with AI-assisted malware analysis by deliberately triggering LLM safety mechanisms. 1/3
1106
Reposted by Aryeh Goretsky
Neowin @neowin.net · 25/08/2026
A security researcher recently uncovered that Microsoft embeds hidden identifiers into images created by Copilot in Paint and the Photos app. #Microsoft #Copilot #GUID
neowin.net
Microsoft hides watermarks in AI images made with Paint and Photos, researcher claims
A security researcher recently uncovered that Microsoft embeds hidden identifiers into images created by Copilot in Paint and the Photos app.
021
Reposted by Aryeh Goretsky
Neowin @neowin.net · 26/08/2026
Is Windows 11 secretly spying on you? A reverse engineer has dug into Microsoft's mysterious performance service to uncover the truth. #Microsoft #Windows11
neowin.net
Reverse engineer explains if Microsoft's Windows 11 performance service is really spyware
Is Windows 11 secretly spying on you? A reverse engineer has dug into Microsoft's mysterious performance service to uncover the truth.
021
Aryeh Goretsky @goretsky.bsky.social · 25/08/2026
011
Aryeh Goretsky @goretsky.bsky.social · 19/08/2026
Apparently, Microsoft's fix for Nightmare Eclipse's ShieldBreak vulnerability in Windows Defender caused it to crash. Known affected versions at this time are v1.457.222.0 - 1.457.230.0. Resolved in v1.457.236.0. Details at old.reddit.com/r/antivirus/...
old.reddit.com
Windows Defender Not Working.
When I try to run a scan, it stops and then tells me to restart the service. There are no exclusions and nothing of note from my start up apps....
031
Aryeh Goretsky @goretsky.bsky.social · 17/08/2026
Seeing a bit of traffic around this thread on #Reddit alleging mass attack by 🇵🇰-aligned APT36/Transparent Tribe on 🇮🇳 students: old.reddit.com/r/antivirus/comments/1vppd16/malware_survived_a_usb_windows_reinstall/ Not seeing much evidence outside of thread. Anyone else?
old.reddit.com
Malware survived a USB windows reinstall?
I am currently dealing with a severe ransomware and Remote Access Trojan (RAT) infection identified as "Pakistanware" (linked to APT36 /...
000
Aryeh Goretsky @goretsky.bsky.social · 13/08/2026
Or inertia?
110
Aryeh Goretsky @goretsky.bsky.social · 13/08/2026
You know you've been living in one place for a long time when you realize it's time to change the garage door opener's battery
130
Reposted by Aryeh Goretsky
Virus Bulletin @virusbtn.bsky.social · 11/08/2026
In collaboration with ANY.RUN, Mauro Eldritch from BCA LTD & Heiner García from NorthScan created a fake DeFi startup and hired suspected Famous Chollima operatives, providing a rare inside view of a DPRK IT worker operation. any.run/cybersecurit...
044
Reposted by Aryeh Goretsky
Virus Bulletin @virusbtn.bsky.social · 11/08/2026
Zscaler ThreatLabz provides a technical analysis of Abyssos, a new modular remote administration tool (RAT) written in C++ that supports a variety of features including credential theft, file exfiltration, and remote access via VNC. www.zscaler.com/blogs/securi...
032
Reposted by Aryeh Goretsky
Virus Bulletin @virusbtn.bsky.social · 11/08/2026
Microsoft Threat Intelligence presents a technical analysis of the DeadLock ransomware encryptor, covering its execution flow, defence evasion techniques, encryption design, and post-encryption behaviours, including a decentralized recovery chat system. www.microsoft.com/en-us/securi...
022
Reposted by Aryeh Goretsky
Patrick C Miller @patrickcmiller.bsky.social · 11/08/2026
Taught by AI pioneers, Stanford's free online course takes you far beyond ChatGPT www.zdnet.com/article/free...
zdnet.com
Taught by AI pioneers, Stanford's free online course takes you far beyond ChatGPT
Most AI courses teach today's tools, but this free Stanford classic by Peter Norvig and Sebastian Thrun dives into the deeper foundational ideas you need to truly understand artificial intelligence.
021
Reposted by Aryeh Goretsky
ESET Research @esetresearch.bsky.social · 05/08/2026
At #DEFCON34, @LukasStefanko explores the real-world attack techniques targeting mobile devices and what defenders need to know to stay ahead. 1/3
151
Aryeh Goretsky @goretsky.bsky.social · 31/07/2026
I thought finger was deprecated on Windows? Gives Morris Worm vibes: old.reddit.com/r/antivirus/...
old.reddit.com
help asap!!! what do i do??
Posted in r/antivirus by u/No_Dust_2724 • 1 point and 4 comments
020
Reposted by Aryeh Goretsky
ESET Research @esetresearch.bsky.social · 30/07/2026
In H1 2026, #ESETresearch analyzed 900,000 agentic AI skills – add-ons providing instructions that teach agents how to perform specific tasks – and found 25,000 suspicious ones and more than 3,000 outright malicious. 1/6
244
Aryeh Goretsky @goretsky.bsky.social · 29/07/2026
Just started getting it set up and although I'm not used to the form factor it's pretty cool. I hope to do a review at some point.
010
Aryeh Goretsky @goretsky.bsky.social · 29/07/2026
Full pics of the keyboard, front, and back. Put them all together, and you have the new #Lenovo #ThinkPad X13 Detachable Gen 1! Specs at psref.lenovo.com/Product/Thin... Thanks to everyone who enjoyed the unboxing. Hope you enjoyed the reveal! #LenovoIN #ThinkPadThursday
010
Reposted by Aryeh Goretsky
ESET Research @esetresearch.bsky.social · 28/07/2026
In H1 2026, #ESETresearch continued tracking a growing number of #EDR killers, currently counting 100+ such tools. The dominant approach is still BYOVD, with 60+ of the EDR killers abusing legitimate yet vulnerable drivers. 1/5
1104
Aryeh Goretsky @goretsky.bsky.social · 28/07/2026
It's time to take a look inside the 1st part of the package: A #Lenovo logo is clearly visible. It has a webcam, too, and clearly is a member of the #ThinkPad family. It's also powered by an #Intel Core Ultra 7, one of the new Core Ultra Series 3 CPUs. #LenovoIN #ThinkPadThursday
000
Aryeh Goretsky @goretsky.bsky.social · 27/07/2026
Here's the #Lenovo stylus. As you can see, it matches up to the pogo pins on the ThinkPad keyboard. It attaches via magnets (I think), with a really satisfying click sound. Very cool design. #LenovoIN #ThinkPadThursday (beginning of the week edition)
110
Aryeh Goretsky @goretsky.bsky.social · 26/07/2026
Moving along with the #Lenovo unboxing: Inside is a #ThinkPad keyboard! That TrackPoint is familiar, but it also a circular fingerprint reader (haven't seen one of those before), + a set of pogo pins at the top. I wonder what plugs in there? #LenovoIN #ThinkPadThursday
021
Aryeh Goretsky @goretsky.bsky.social · 24/07/2026
In all the excitement I forget to mention the second container inside the box from #Lenovo. Here's what's inside that. #LenovoIN #ThinkPadThursday (albeit belatedly)
020
Aryeh Goretsky @goretsky.bsky.social · 24/07/2026
I'm getting there…
010
Aryeh Goretsky @goretsky.bsky.social · 23/07/2026
We move on to the next phase of unboxing the #Lenovo laptop, opening the internal carton! #LenovoIN #ThinkPadThursdays
120
Aryeh Goretsky @goretsky.bsky.social · 22/07/2026
Moving on with the #Lenovo unboxing, here's the carton that secures it during shipping. The ridges/bumps provide isolation. In photo #1, you can see a literature envelope; in #2, you can see the shipping bag inside with security seal. #LenovoIN #ThinkPadThursday (early edition)
020
Reposted by Aryeh Goretsky
ESET Research @esetresearch.bsky.social · 22/07/2026
ESET detections of #ClickFix doubled (+108%) between H2 2025 and H1 2026 as attackers expanded beyond fake CAPTCHAs to AI platforms (#AI-fix), browser extensions (#CrashFix), and cloud authentication workflows (#ConsentFix). 1/5
143
Aryeh Goretsky @goretsky.bsky.social · 22/07/2026
Don't know yet. Haven't finished unboxing.
000
Aryeh Goretsky @goretsky.bsky.social · 22/07/2026
@scoutingamerica.bsky.social Just saw report saying your website is being used to distribute information-stealing malware: old.reddit.com/r/antivirus/comments/1v1xknb/what_tf_is_this/
old.reddit.com
What tf is this!?
Posted in r/antivirus by u/LionRegular1470 • 1 point and 3 comments
000
Aryeh Goretsky @goretsky.bsky.social · 19/07/2026
The laptop #Lenovo sent me is now unboxed and out of the shipping carton. Hmm… it's a lot thinner than I expected; I've been calling it a laptop, but maybe it is something else? What could it be? #LenovoIN #ThinkPadThursday (weekend edition)
120
Aryeh Goretsky @goretsky.bsky.social · 18/07/2026
It's time to take the #Lenovo laptop out of the box. Here we go! #LenovoIN #ThinkPadThursday
010
Aryeh Goretsky @goretsky.bsky.social · 17/07/2026
Continuing my unboxing of the box from #Lenovo, I have opened the carton of accessories. It appears to contain a USB-C power supply, a USB-C cable, and a stylus! What could it all mean? #LenovoIN #ThinkPadThursday
Open accessories carton showing a USB-C power adapter and cable, plus an envelope which may contain a stylus.
010
Reposted by Aryeh Goretsky
Help Net Security @helpnetsecurity.com · 15/07/2026
ClickFix is changing the economics of social engineering 🔗 Read more: www.helpnetsecurity.com/2026/07/15/c... #socialengineering #cybercrime #cybersecurity @reversinglabs.com
helpnetsecurity.com
ClickFix is changing the economics of social engineering - Help Net Security
ClickFix is evolving into a Malware-as-a-Service ecosystem, enabling large-scale social engineering attacks that bypass antivirus defenses.
021
Reposted by Aryeh Goretsky
kurt baumgartner @kurtisj.bsky.social · 15/07/2026
www.consilium.europa.eu/en/press/pre...
consilium.europa.eu
Russian cyber-attacks and destabilising activities: Council sanctions nine individuals and four entities
The Council imposed restrictive measures on nine individuals and four entities forming part of Russia's cyber ecosystem,  responsible for carrying out, enabling and facilitating malicious cyber a...
033
Reposted by Aryeh Goretsky
ESET Research @esetresearch.bsky.social · 14/07/2026
#ESETresearch discovered and reported to @certcc 11 old Microsoft-signed UEFI shim bootloaders that allow bypassing UEFI Secure Boot on most UEFI systems. Read about it at www.welivesecurity.com/en/eset-rese... 1/5
welivesecurity.com
Forgotten UEFI shims undermining Secure Boot
ESET researchers discovered 11 vulnerable UEFI shim bootloaders signed by Microsoft that allow attackers to bypass UEFI Secure Boot by exploiting decade-old vulnerabilities.
186
Aryeh Goretsky @goretsky.bsky.social · 14/07/2026
Something interesting about the box #Lenovo sent me. One of the side flaps has #Lenovo #ThinkPad printed on it, but the font for Lenovo seems a bit off: it is thinner than usual, and the "e" doesn't have the slight rotation. #LenovoIN #ThinkPadThursday (early edition)
detail view of shipping carton showing side flap
000
Aryeh Goretsky @goretsky.bsky.social · 11/07/2026
Given the feedback I've received on this mystery box from #Lenovo, I have decided to move things forward a bit. So, here it is, all opened up! #LenovoIN #ThinkPadThursday (belated edition)
Open shipping carton from Lenovo.
010
Aryeh Goretsky @goretsky.bsky.social · 09/07/2026
Continuing the examination of the box #Lenovo sent last week, we can see it has an energy efficiency label on it. The waybill's poly bag obscures the QR code, but we can see it has a top rating for efficiency. Whatever is inside sips power. #ThinkPadThursday
detail on Lenovo shipping carton of energy efficiency label
110
Reposted by Aryeh Goretsky
ESET Research @esetresearch.bsky.social · 08/07/2026
ESET Threat Report H1 2026: thousands of malicious Agentic AI skills identified, first AI-powered Android malware appears, and ClickFix expands beyond fake CAPTCHA prompts. Attackers are rapidly adapting to new platforms and technologies . Full report: web-assets.esetstatic.com/wls/en/paper...
142
Aryeh Goretsky @goretsky.bsky.social · 06/07/2026
Last week, #Lenovo sent me this box, quite unexpectedly. Today, I continue our tour of it, this time focusing on its bottom. It is getting really hard to resist opening it to find out what's inside. #LenovoIN #ThinkPadThursday (special early edition)
Bottom of Lenovo shipping carton.
031
Reposted by Aryeh Goretsky
Aryeh Goretsky @goretsky.bsky.social · 05/07/2026
And here is the other side of the box from #Lenovo, minus the shipping waybill. Still wondering about what's inside… #LenovoIN #ThinkPad
Lenovo shipping carton.
031
Reposted by Aryeh Goretsky
Asher Wolf @asherwolf.bsky.social · 06/07/2026
New research has found that major purchases, job hunting, and tax time are emerging as prime targets for fraudsters, with younger Australians facing the highest risk despite their digital confidence www.cyberdaily.au/security/138...
cyberdaily.au
Report: Scammers are exploiting young Aussies buying their first home and navigating other life events
New research has found that major purchases, job hunting, and tax time are emerging as prime targets for fraudsters, with younger Australians facing the highest risk despite their digital confidence.
1165
Aryeh Goretsky @goretsky.bsky.social · 05/07/2026
And here is the other side of the box from #Lenovo, minus the shipping waybill. Still wondering about what's inside… #LenovoIN #ThinkPad
Lenovo shipping carton.
031
Aryeh Goretsky @goretsky.bsky.social · 02/07/2026
So, I was at home and this box from #Lenovo showed up on my doorstep. I wonder what's inside of it? #LenovoIN #ThinkPadThursday (special Friday edition(
Lenovo shipping carton balanced on carpeted stairs inside a house.
000