1. Executive summary
ESET published a threat-landscape assessment for SMBs noting that AI is lowering the barrier to entry for attackers — improving lure quality, scaling social engineering, and accelerating reconnaissance — but that the primary incident drivers remain familiar: phishing, unpatched vulnerabilities, lack of security monitoring, and weak passwords. No specific CVE, named threat actor, or active exploitation campaign is described. For EMEA financial services, the advisory reinforces that baseline hygiene gaps (patching, MFA, centralised monitoring) remain the dominant risk surface, and that AI-assisted social engineering increases the effectiveness of phishing against finance-sector staff.
2. Regulatory framing
| Article | Trigger (the fact in this item) | Practical impact |
|---|---|---|
| DORA Art. 17: ICT-related incident management process | The item identifies unpatched vulnerabilities and lack of security monitoring as top incident drivers — gaps directly addressed by incident management process requirements. | Financial entities must ensure their ICT incident management process covers detection, classification, and response for the baseline failure modes ESET identifies. |
| DORA Art. 24: digital operational resilience testing — general requirements | "Lack of security monitoring (22%)" and "an alert no one sees" indicate gaps in operational resilience that testing would surface. | Resilience testing should validate that monitoring and alerting are functional and that unpatched vulnerability exposure is identified. |
| NIS2 Art. 21(2)(d): supply chain security measures | "Unpatched security vulnerabilities (23%)" and the observation that smaller organisations run diverse software they cannot always patch via automatic updates. | Entities should assess and address vulnerabilities in their supply chain components, not just first-party systems. |
3. Technical analysis & attack chain
This is a trend/landscape advisory, not an incident report. There is no specific CVE, exploit chain, malware sample, or named actor to analyse. The verified reference data resolved no CVEs or actor profiles for this item.
Key findings from ESET telemetry (second half of 2025)
- Phishing — 26% of top threats. ESET telemetry reports phishing as the top detected threat at 30.8% detection volume in H2 2025, with volumes continuing to rise. Smishing (SMS phishing) and vishing (voice phishing) are noted as growing in popularity. AI is cited as improving lure quality and scaling social engineering, lowering the barrier for less skilled attackers.
- Unpatched security vulnerabilities — 23%. The advisory notes that smaller organisations run diverse software where not all components can be patched via automatic updates. Limited expertise to test and apply critical updates is identified as a roadblock.
- Lack of security monitoring — 22%. ESET observes that organisations may have security tools but lack a centralised place to collect, correlate, and flag alerts. Alert overload — difficulty discerning false from true positives — is called out as a secondary problem.
- Weak passwords — 20%. Reused passwords and weak credentials persist despite industry moves toward phish-resistant MFA.
AI-related observations (single-sourced to ESET; verify before enforcement)
- ESET reports discovering the first AI-written ransomware in 2025, assessed as likely a proof-of-concept.
- ESET reports discovering "PromptSpy," described as the first known Android malware to abuse generative AI in its execution flow to achieve persistence, discovered earlier in 2026.
- ESET's MDR service reports no evidence of incidents in which GenAI played a significant operational role.
- Attribution for PromptSpy and the AI-written ransomware is not corroborated by the verified reference data. No MITRE actor profile is available. Treat these as single-sourced ESET research claims.
What is NOT in the source material: No CVEs, no IOCs, no command-and-control infrastructure, no file hashes, no specific product versions, no named threat actors with confirmed attribution, no exploitation timelines, no ransom-note text, no registry keys, no specific ports or protocols.
4. Mitigation & containment
No vendor fix or specific patch is referenced in the source. The advisory is general. The following actions are derived from the risk areas ESET identifies, applied to an EMEA financial services context.
P1 — Within 24 hours
- Confirm that phishing-resistant MFA (FIDO2/WebAuthn) is enforced for all finance-sector staff with access to sensitive systems or customer data. ESET identifies weak passwords (20%) and phishing (26%) as the top two vectors — MFA directly addresses both.
- Verify that email gateway and endpoint security controls are blocking known phishing patterns and that smishing/vishing vectors are covered in staff awareness training. ESET specifically calls out smishing and vishing as growing.
- Validate that security alerting is reaching a monitored console — ESET's "an alert no one sees" finding suggests verifying alert routing and on-call coverage.
P2 — Within 72 hours
- Conduct an asset and software inventory review against outstanding critical patches. ESET identifies unpatched vulnerabilities (23%) as a top driver and notes that diverse software cannot always rely on automatic updates. Prioritize internet-facing systems and those handling transaction data.
- Review centralised monitoring coverage — confirm that logs from all critical systems are aggregated, and assess whether alert tuning is needed to address the false-positive overload ESET describes.
P3 — Within 7 days
- Tabletop exercise or tabletop component of a DORA Art. 24 resilience test focused on the four failure modes ESET identifies: successful phishing, unpatched vulnerability exploitation, missed alert, and credential reuse. Document gaps.
- Review third-party and supply-chain software patching posture under NIS2 Art. 21(2)(d) — ESET notes that smaller organisations struggle with diverse software inventories.
- Brief staff on AI-assisted social engineering — ESET notes AI is improving lure quality and scaling reconnaissance. This is a human-layer control.
5. Indicators of compromise
No indicators of compromise available in the source material.
6. Detection
Insufficient indicators to author detection rules. The source contains no file hashes, distinctive strings, command-line flags, mutex names, scheduled-task names, registry keys, ransom-note text, or network indicators. The named malware "PromptSpy" is referenced but no technical artefacts (hashes, package names, C2 domains, permissions) are provided in the source material.
7. Sources
- WeLiveSecurity (ESET), "Cyber readiness for SMBs: Getting the basics right," https://www.welivesecurity.com/en/business-security/cyber-readiness-smbs-getting-basics-right/, published 2026-07-03.
8. Adverse Trace position
This is a landscape advisory, not an incident report — severity is informational with no CVSS score, no CISA-KEV entry, and no confirmed exploitation. No CVEs were resolved in the verified reference data for this item. The ESET findings are single-sourced; the PromptSpy and AI-written ransomware claims are uncorroborated and should be verified before any enforcement action. For EMEA financial services clients, the practical takeaway is that baseline hygiene — phishing-resistant MFA, patching discipline, centralised monitoring with tuned alerting, and credential hygiene — remains the dominant risk surface, and AI-assisted social engineering increases the urgency on the human layer. We will continue to monitor for corroborating research on PromptSpy and any AI-assisted malware operationalisation, and will issue a follow-up advisory if technical artefacts become available.
Published via PulseTrace — Adverse Trace threat intelligence.