Ján Trenčanský
@j91321.bsky.social
📤 173
📥 211
📝 114
EDR R&D team lead at ESET. Opinions are my own. @
[email protected]
4 days ago
0
0
0
reposted by
Ján Trenčanský
Nick Pettigrew
6 days ago
I'm convinced AI is our generation's radium - a discovery with genuinely useful applications in specific, controlled circumstances that we stupidly put in everything from kid's toys to toothpaste until we realised the harm far too late where future generations will ask if we were out of our minds.
add a skeleton here at some point
241
17671
5610
reposted by
Ján Trenčanský
Mike Schuster
8 days ago
Breaking: Tragedy at the Winter Olympics
68
7306
2301
reposted by
Ján Trenčanský
Catalin Cimpanu
12 days ago
Russian GRU-linked cyber-espionage group APT28 is now using an Office zero-day disclosed last week for spear-phishing campaigns targeting Ukrainian targets, per a new Ukraine CERT report
cert.gov.ua/article/6287...
loading . . .
CERT-UA
Урядова команда реагування на комп’ютерні надзвичайні події України, яка функціонує в складі Державної служби спеціального зв’язку та захисту інформації України.
https://cert.gov.ua/article/6287250
0
6
5
reposted by
Ján Trenčanský
ESET Research
16 days ago
#BREAKING
#ESETresearch
provides technical details on
#DynoWiper
, a data‑wiping malware used in a data‑destruction incident on December 29, 2025, affecting a company in Poland’s energy sector.
www.welivesecurity.com/en/eset-rese...
1/5
loading . . .
https://www.welivesecurity.com/en/eset-research/dynowiper-update-technical-analysis-attribution/
1
11
10
Extensive report by CERT.PL on Poland’s energy grid incident.
cert.pl/en/posts/202...
loading . . .
Energy Sector Incident Report - 29 December 2025
CERT Polska presents a report on the analysis of an incident in the energy sector that occurred on 29 December 2025. The attacks were destructive in nature and targeted wind and photovoltaic farms, a ...
https://cert.pl/en/posts/2026/01/incident-report-energy-sector-2025/
16 days ago
0
4
6
Release of ESET Protect Cloud 7.0 marks the beginning of big changes for our EDR cloud console. Advanced Search, the main feature being rolled out, allows you to search through indicators using Lucene. It's a more log-based approach enabling access to the underlying EDR and AV data.
16 days ago
1
0
0
reposted by
Ján Trenčanský
evacide
16 days ago
Can we just tell all of the "Signal is an op" guys that all of the real high-opsec organizing is being done on some Telegram channel so they can all go there and cosplay at each other?
7
224
28
Looks like, it really is release day tomorrow.
17 days ago
0
0
0
reposted by
Ján Trenčanský
ESET Research
23 days ago
#BREAKING
#ESETresearch
identified the wiper
#DynoWiper
used in an attempted disruptive cyberattack against the Polish energy sector on Dec 29, 2025. At this point, no successful disruption is known, but the malware’s design clearly indicates destructive intent. 1/5
1
35
35
reposted by
Ján Trenčanský
Kim Zetter
23 days ago
Exclusive: A cyberattack targeting Poland's energy infrastructure in December used wiper malware that would have erased grid computers and rendered them inoperable had it not been thwarted, a researcher at @ESET told me. The researcher calls the attack "unprecedented" for Poland and "substantial"
loading . . .
Cyberattack Targeting Poland’s Energy Grid Used a Wiper
A cyberattack that targeted power plants and other energy producers in Poland at the end of December used malware known as a “wiper” that was intended to erase computers and cause a power outage and o...
https://www.zetter-zeroday.com/cyberattack-targeting-polands-energy-grid-used-a-wiper/
2
64
67
reposted by
Ján Trenčanský
Daniel Kibblesmith
about 1 month ago
If there’s a better obituary for an evil cartoonist than an A.I. generated version of his character that fucks up the defining detail of its design, I can’t think of it. No notes. 👨🏻🍳 💋
84
16550
2641
reposted by
Ján Trenčanský
Catalin Cimpanu
about 1 month ago
Now you understand why every pro-Kremlin Twitter bot has spent 90% of its time over the past decade defending or pushing crypto and blockchain tech while randomly publishing some political tweet once in a while?
add a skeleton here at some point
2
24
21
reposted by
Ján Trenčanský
Catalin Cimpanu
about 1 month ago
The data on more than 8,000 users of far-right dating site WhiteDate was scraped and leaked online after its administrators didn't secure their WordPress site properly
cybernews.com/security/inv...
loading . . .
Investigator breaches white supremacist dating sites, exposes 8,000 users
An investigative journalist infiltrated three white supremacist platforms, including the dating site WhiteDate, exfiltrating over 8,000 user profiles and 100GB of sensitive data.
https://cybernews.com/security/investigator-exposes-white-supremacist-sites-users/
2
15
6
reposted by
Ján Trenčanský
ESET Research
about 2 months ago
In 2025,
#ESETresearch
analyzed hundreds of hands-on-keyboard ransomware attacks, mostly hitting manufacturing, construction, retail, technology, and healthcare. Most of these were seen in the US (17%), Spain (5%), and France, Italy, and Canada (4% each). 1/5
1
4
4
I can remember two incidents that involved PRNI. In both, the information received helped to contain the incident before ransomware was deployed. Disturbing to see damage to a clearly useful and actually working initiative.
add a skeleton here at some point
about 2 months ago
0
0
0
reposted by
Ján Trenčanský
Taggart
about 2 months ago
This is super good news: Docker Hardened Images are now available for free for all devs. These can form a much more secure baseline of your containerized apps.
loading . . .
Hardened Images for Everyone | Docker
Security for everyone. Docker Hardened Images are now free to use, share, and build on with no licensing surprises.
https://www.docker.com/blog/docker-hardened-images-for-every-developer/
0
7
6
reposted by
Ján Trenčanský
Eric Geller
2 months ago
Gotta say, I think Marcus makes an interesting point.
12
347
124
reposted by
Ján Trenčanský
Jake Williams
2 months ago
Why is Microsoft bundling Security Copilot licenses with E5? Clearly because they can't sell it as a standalone product. In other news, E5 costs will certainly go up "due to enhanced value."
www.darkreading.com/cybersecurit...
loading . . .
Microsoft to Bundle Security Copilot in M365 Enterprise License
The move aims to expand the use of Security Copilot and comes with the launch of 12 new agents from Microsoft at the company's Ignite conference last week.
https://www.darkreading.com/cybersecurity-operations/microsoft-bundle-security-copilot-m365-enterprise-license
9
41
13
reposted by
Ján Trenčanský
Kevin Beaumont
2 months ago
bless the heart of whoever posted this and thought it sounded good, lol
6
21
4
I always thought MITRE Enterprise Evals were for security solutions like EDRs. Imagine my surprise seeing Cyberani MDR in the results. MDR is a service, right? Even Cyberani says it's "more than a service". Didn’t Managed Services used to have their own Evals? Did I dream that?
2 months ago
1
2
0
The only thing you really need to know about this year’s MITRE ATT&CK Evaluations is that it had the lowest number of participating vendors ever. Only 11 vendors took part. The APT3 evaluation back in 2018 had 12.
2 months ago
0
0
0
I've built a lot of systems around Elasticsearch and can tell you this Intellexa backend has really shit mapping just based on the screenshots. I'd be embarrassed to show this to the customer.
securitylab.amnesty.org/latest/2025/...
loading . . .
To Catch a Predator: Leak exposes the internal operations of Intellexa’s mercenary spyware - Amnesty International Security Lab
Drawing on leaked internal company documents, sales and marketing material, as well as training videos, the “Intellexa Leaks” investigation gives a never-before-seen glimpse of the internal operations...
https://securitylab.amnesty.org/latest/2025/12/intellexa-leaks-predator-spyware-operations-exposed/
2 months ago
0
1
0
reposted by
Ján Trenčanský
ESET Research
3 months ago
#ESETresearch
is heading to
#AVAR2025
? Dec 4, Thursday in Kuala Lumpur, 11:00–11:30 MYT. ESET researchers Anton Cherepanov & Peter Strýček present: "Sniffing Around: Unmasking the LongNosedGoblin operation in Southeast Asia and Japan”. 1/3
1
3
3
Things must be going really well for Cobalt Strike if they’re advertising on …checks notes… Reddit.
3 months ago
0
2
0
reposted by
Ján Trenčanský
Jeremy Kirk
3 months ago
Anthropic's AI cyberespionage report feels as odd as the last one. Just 13 pages, it has none of the traditional components of a usual threat intel report (IoCs, payload hashes, etc.) and it seems to bury the lead re: technical sophistication. I wonder if a target will come forward.
#infosec
1
30
17
reposted by
Ján Trenčanský
Kevin Beaumont
3 months ago
This is spot on. Quantum’s gonna be the next cyber grift (again), after the bottom falls out of GenAI.
www.linkedin.com/posts/nathan...
7
97
26
reposted by
Ján Trenčanský
Max Böck
3 months ago
Short Answer: Fuck no. Long Answer: If a company tries AI phrenology in their hiring process, they're guaranteed to do worse things once you work there. Don't.
add a skeleton here at some point
1
56
16
I'm glad that, until next year, I don't have to be aware of cybersecurity anymore.
4 months ago
0
0
0
reposted by
Ján Trenčanský
Cian
4 months ago
LUCASARTS PRESENTS Columbo in: SCUMM of the Earth
#pixelart
add a skeleton here at some point
58
6256
2298
Saw some cool glowing rocks last week. My brain: These must be delicious.
4 months ago
0
1
0
reposted by
Ján Trenčanský
2026 all the things
4 months ago
Omg, the solution to CIA's Kryptos being discovered by someone becoming a subject matter expert, going on location, and finding the plaintext sitting in a vault several miles away is the absolute *perfect* ending to Kryptos. You couldn't write it. Just absolutely A+
www.nytimes.com/2025/10/16/s...
loading . . .
A C.I.A. Secret Kept for 35 Years Is Found in the Smithsonian’s Vault
https://www.nytimes.com/2025/10/16/science/kryptos-cia-solution-sanborn-auction.html
26
965
264
reposted by
Ján Trenčanský
Kevin Collier
4 months ago
I know this stuff isn't surprising anymore but I really can't stress enough how much everybody involved with CISA and cyber tried to keep the field nonpolitical and nonpartisan before this administration.
add a skeleton here at some point
5
247
74
reposted by
Ján Trenčanský
Randall Munroe
4 months ago
Hot Water Balloon
xkcd.com/3153/
36
2691
229
reposted by
Ján Trenčanský
Catalin Cimpanu
4 months ago
Telegram founder and general a-hole Pavel Durov, who's IM network hosts hundreds of groups where info-ops coordinate their activity and pay for content, is annoyed that democracies are fighting back against the damage he, personally, has helped usher in in many autocratic regimes
7
103
31
reposted by
Ján Trenčanský
Catalin Cimpanu
4 months ago
The Oracle zero-day... kek
labs.watchtowr.com/well-well-we...
2
20
7
reposted by
Ján Trenčanský
Bellingcat
5 months ago
Our researchers have noticed today that NASA FIRMS, one of the main free and available open source sites for monitoring fires around the world has a new notice on it stating that NASA is no longer updating the site due to a lack in federal funding.
firms.modaps.eosdis.nasa.gov/map/
5
280
168
PR: October is cybersecurity awareness month! Let's start... Me: No, nope, don't care, la la la can't hear you *𝘧𝘪𝘯𝘨𝘦𝘳𝘴 𝘪𝘯 𝘮𝘺 𝘦𝘢𝘳𝘴*
5 months ago
0
0
0
I haven't found exploitation of Fortra's GoAnywhere MFT CVE-2025-10035 in EDR telemetry yet. Which means it is probably still rare and folks have some time to patch. Wonder how long it will stay that way. The previously exploited vulns appeared fairly quickly.
5 months ago
1
2
1
reposted by
Ján Trenčanský
Eliot Higgins
5 months ago
add a skeleton here at some point
18
358
52
reposted by
Ján Trenčanský
Catalin Cimpanu
5 months ago
Cisco patched 3 zero-days today... CVE-2025-20352:
sec.cloudapps.cisco.com/security/cen...
And these two used together: -CVE-2025-20333:
sec.cloudapps.cisco.com/security/cen...
-CVE-2025-20362:
sec.cloudapps.cisco.com/security/cen...
0
9
6
reposted by
Ján Trenčanský
Kevin Beaumont
5 months ago
Why TF are
@npr.org
@pbsnews.org
and
@wgcunews.bsky.social
letting an AI cybersecurity *write an article* about a breach and make shit up?
3
17
9
reposted by
Ján Trenčanský
ESET Research
5 months ago
#ESETresearch
has discovered the first known cases of collaboration between Gamaredon and Turla, in Ukraine. Both groups are affiliated with the FSB, Russia’s main domestic intelligence and security agency.
www.welivesecurity.com/en/eset-rese...
1/3
loading . . .
Gamaredon X Turla collab
ESET researchers reveal how the notorious APT group Turla collaborates with fellow FSB-associated group known as Gamaredon to compromise high‑profile targets in Ukraine.
https://www.welivesecurity.com/en/eset-research/gamaredon-x-turla-collab/
1
7
6
reposted by
Ján Trenčanský
Catalin Cimpanu
5 months ago
Three major EDR vendors have pulled out of evaluations for the MITRE ATT&CK framework Microsoft:
techcommunity.microsoft.com/blog/microso...
SentinelOne:
www.sentinelone.com/blog/sentine...
Palo Alto Networks:
www.paloaltonetworks.com/blog/securit...
0
14
5
reposted by
Ján Trenčanský
Kostas
5 months ago
🆕 𝐄𝐃𝐑-𝐭𝐞𝐥𝐞𝐦𝐞𝐭𝐫𝐲 𝐏𝐫𝐨𝐣𝐞𝐜𝐭 𝐔𝐩𝐝𝐚𝐭𝐞 - 𝐖𝐢𝐧𝐝𝐨𝐰𝐬 The Windows table just got an update with 3 new sub-categories: ➡️ VSS Deletion ➡️ Win32 API Telemetry ➡️ JA3/JA3s Coverage isn’t uniform, and some are pending response from the vendors. That’s fine. I’d rather show the uncertainty than pretend otherwise.
1
0
1
reposted by
Ján Trenčanský
ESET Research
5 months ago
HybridPetya installs a malicious EFI application to the EFI System Partition, which then encrypts the Master File Table file, an essential metadata file with information about all files on the NTFS-formatted partition. 2/8
1
3
2
Funnily Google reminded me that I was at the JLR plant in Nitra today 6 years ago. They were just revealing a new model.
5 months ago
0
1
0
This one EDR killer crashes the whole host when EDR is present. Task failed successfully I guess?
5 months ago
0
0
0
Looks like everybody finally figured out the same thing I posted about almost two weeks ago.
add a skeleton here at some point
5 months ago
0
0
0
Load more
feeds!
log in