<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="/rss-style.xsl"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:media="http://search.yahoo.com/mrss/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/">
<channel>
<title><![CDATA[tsecurity.de - ⚠️ Malware / Trojaner / Viren]]></title>
<link><![CDATA[https://tsecurity.de/export/rss/malware-trojaner-viren.xml]]></link>
<description><![CDATA[Malware Intelligence & Virus Alerts. Detaillierte Code-Analysen von Ransomware, Trojanern, InfoStealern, Botnetzen und Zero-Day Threat Actors.]]></description>
<language>de-DE</language>
<lastBuildDate>Thu, 17 Sep 2026 09:52:52 +0200</lastBuildDate>
<pubDate>Thu, 17 Sep 2026 09:52:52 +0200</pubDate>
<ttl>15</ttl>
<copyright>2026 tsecurity.de - ⚠️ Malware / Trojaner / Viren</copyright>
<managingEditor>contact@tsecurity.de (tsecurity.de)</managingEditor>
<webMaster>contact@tsecurity.de (tsecurity.de)</webMaster>
<image>
<url>https://tsecurity.de/templates/mydraft-basis-tsecurity.de/media/logo.png</url>
<title><![CDATA[tsecurity.de - ⚠️ Malware / Trojaner / Viren]]></title>
<link><![CDATA[https://tsecurity.de/export/rss/malware-trojaner-viren.xml]]></link>
</image>
<atom:link href="https://tsecurity.de/export/rss/alle-kategorien.xml" rel="self" type="application/rss+xml" />
<item>
<title><![CDATA[PhantomEnigma Shifts Tactics: Explorer-Based Payload Delivery]]></title>
<description><![CDATA[submitted by /u/ANYRUN-team [link] [comments] Weiterlesen]]></description>
<link>https://tsecurity.de/de/4150904/malware-trojaner-viren/phantomenigma-shifts-tactics-explorer-based-payload-delivery/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4150904/malware-trojaner-viren/phantomenigma-shifts-tactics-explorer-based-payload-delivery/</guid>
<pubDate>Thu, 17 Sep 2026 07:45:12 +0200</pubDate>
<content:encoded><![CDATA[<p>submitted by /u/ANYRUN-team [link] [comments] <a href="https://www.reddit.com/r/MalwareAnalysis/comments/1wiklrz/phantomenigma_shifts_tactics_explorerbased/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Built a PPL-aware ALPC enumerator because standard handle duplication was leaving blind spots in the attack surface]]></title>
<description><![CDATA[Was doing some Windows ALPC/RPC vuln research and ran into a simple problem: the usual userland enumeration approach skips ports when handle duplication fails, which gets especially interesting with PPL processes. So I built this to dynamically resolve the ALPC object type index, fall back to NtQ...]]></description>
<link>https://tsecurity.de/de/4150903/malware-trojaner-viren/built-a-ppl-aware-alpc-enumerator-because-standard-handle-duplication-was-leaving-blind-spots-in-the-attack-surface/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4150903/malware-trojaner-viren/built-a-ppl-aware-alpc-enumerator-because-standard-handle-duplication-was-leaving-blind-spots-in-the-attack-surface/</guid>
<pubDate>Thu, 17 Sep 2026 07:15:08 +0200</pubDate>
<content:encoded><![CDATA[<p>Was doing some Windows ALPC/RPC vuln research and ran into a simple problem: the usual userland enumeration approach skips ports when handle duplication fails, which gets especially interesting with PPL processes. So I built this to dynamically resolve the ALPC object type index, fall back to NtQueryInformationProcess / PS_PROTECTION when... <a href="https://www.reddit.com/r/ExploitDev/comments/1wgwqhh/built_a_pplaware_alpc_enumerator_because_standard/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[SindriKit V2.0.0 (C framework to decouple technique logic from execution mechanics)]]></title>
<description><![CDATA[Released V2 for my opensource maldev tool/framework. Feel free to check out the code and implementation. Would really appreciate feedback :) submitted by /u/Important_Map6928 [link] [comments] Weiterlesen]]></description>
<link>https://tsecurity.de/de/4150902/malware-trojaner-viren/sindrikit-v200-c-framework-to-decouple-technique-logic-from-execution-mechanics/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4150902/malware-trojaner-viren/sindrikit-v200-c-framework-to-decouple-technique-logic-from-execution-mechanics/</guid>
<pubDate>Thu, 17 Sep 2026 07:15:08 +0200</pubDate>
<content:encoded><![CDATA[<p>Released V2 for my opensource maldev tool/framework. Feel free to check out the code and implementation. Would really appreciate feedback :) submitted by /u/Important_Map6928 [link] [comments] <a href="https://www.reddit.com/r/ExploitDev/comments/1wh4408/sindrikit_v200_c_framework_to_decouple_technique/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Looking for dedicated beginner ctf buddies]]></title>
<description><![CDATA[submitted by /u/Fit-Iron-5614 [link] [comments] Weiterlesen]]></description>
<link>https://tsecurity.de/de/4150900/malware-trojaner-viren/looking-for-dedicated-beginner-ctf-buddies/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4150900/malware-trojaner-viren/looking-for-dedicated-beginner-ctf-buddies/</guid>
<pubDate>Thu, 17 Sep 2026 07:15:08 +0200</pubDate>
<content:encoded><![CDATA[<p>submitted by /u/Fit-Iron-5614 [link] [comments] <a href="https://www.reddit.com/r/ExploitDev/comments/1wh9kfl/looking_for_dedicated_beginner_ctf_buddies/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[0xCr0ssCrush - Windows BYOVD Ring 0 Exploit]]></title>
<description><![CDATA[submitted by /u/Anonymous_Wajeeh [link] [comments] Weiterlesen]]></description>
<link>https://tsecurity.de/de/4150898/malware-trojaner-viren/0xcr0sscrush-windows-byovd-ring-0-exploit/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4150898/malware-trojaner-viren/0xcr0sscrush-windows-byovd-ring-0-exploit/</guid>
<pubDate>Thu, 17 Sep 2026 07:15:08 +0200</pubDate>
<content:encoded><![CDATA[<p>submitted by /u/Anonymous_Wajeeh [link] [comments] <a href="https://www.reddit.com/r/ExploitDev/comments/1whgqab/0xcr0sscrush_windows_byovd_ring_0_exploit/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Centralizing scanner findings across multiple tools. anyone actually happy with their setup?]]></title>
<description><![CDATA[So vuln team here, drowning in findings from like ten scanners and ticket queues all over the place, trying to centralize everything into one risk based view without breaking existing workflows. any hints? submitted by /u/NetLopsdedslsatn3708 [link] [comments] Weiterlesen]]></description>
<link>https://tsecurity.de/de/4150897/malware-trojaner-viren/centralizing-scanner-findings-across-multiple-tools-anyone-actually-happy-with-their-setup/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4150897/malware-trojaner-viren/centralizing-scanner-findings-across-multiple-tools-anyone-actually-happy-with-their-setup/</guid>
<pubDate>Thu, 17 Sep 2026 07:15:08 +0200</pubDate>
<content:encoded><![CDATA[<p>So vuln team here, drowning in findings from like ten scanners and ticket queues all over the place, trying to centralize everything into one risk based view without breaking existing workflows. any hints? submitted by /u/NetLopsdedslsatn3708 [link] [comments] <a href="https://www.reddit.com/r/ExploitDev/comments/1whpr8k/centralizing_scanner_findings_across_multiple/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[I Missed One TLB Shootdown and Somehow Ended Up Controlling a Page Table]]></title>
<description><![CDATA[submitted by /u/unknownhad [link] [comments] Weiterlesen]]></description>
<link>https://tsecurity.de/de/4150896/malware-trojaner-viren/i-missed-one-tlb-shootdown-and-somehow-ended-up-controlling-a-page-table/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4150896/malware-trojaner-viren/i-missed-one-tlb-shootdown-and-somehow-ended-up-controlling-a-page-table/</guid>
<pubDate>Thu, 17 Sep 2026 07:15:08 +0200</pubDate>
<content:encoded><![CDATA[<p>submitted by /u/unknownhad [link] [comments] <a href="https://www.reddit.com/r/ExploitDev/comments/1why5u9/i_missed_one_tlb_shootdown_and_somehow_ended_up/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Warum sichere Datenspeicherung für den Mittelstand essenziell ist - it-daily.net]]></title>
<description><![CDATA[Exponentielles Datenwachstum, die Bedrohung durch zielgerichtete Ransomware-Angriffe und immer strengere Compliance-Vorgaben setzen IT-Abteilungen im ... Weiterlesen]]></description>
<link>https://tsecurity.de/de/4150668/malware-trojaner-viren/warum-sichere-datenspeicherung-fuer-den-mittelstand-essenziell-ist-it-dailynet/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4150668/malware-trojaner-viren/warum-sichere-datenspeicherung-fuer-den-mittelstand-essenziell-ist-it-dailynet/</guid>
<pubDate>Thu, 17 Sep 2026 03:34:58 +0200</pubDate>
<content:encoded><![CDATA[<p>Exponentielles Datenwachstum, die Bedrohung durch zielgerichtete Ransomware-Angriffe und immer strengere Compliance-Vorgaben setzen IT-Abteilungen im ... <a href="https://www.google.com/url?rct=j&amp;sa=t&amp;url=https://www.it-daily.net/it-sicherheit/cloud-security/mittelstand-datenspeicherung&amp;ct=ga&amp;cd=CAIyGTRiZTZmY2RmMzZhYjA0M2Y6ZGU6ZGU6REU&amp;usg=AOvVaw2ILWMzGapm7sNaZ7h2kCK8" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[How the mighty have fallen — the notorious Stuxnet malware source code has been replicated and posted on GitHub for all to see]]></title>
<description><![CDATA[A pseudonymous GitHub account has published what it calls a reconstruction of Stuxnet malware that purportedly took out a fifth of Iran's centrifuges before being discoveredThe original source has never surfaced, and the 'Stuxnet' moniker that the account uses comes from Symantec's coining of the...]]></description>
<link>https://tsecurity.de/de/4150509/malware-trojaner-viren/how-the-mighty-have-fallen-the-notorious-stuxnet-malware-source-code-has-been-replicated-and-posted-on-github-for-all-to-see/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4150509/malware-trojaner-viren/how-the-mighty-have-fallen-the-notorious-stuxnet-malware-source-code-has-been-replicated-and-posted-on-github-for-all-to-see/</guid>
<pubDate>Thu, 17 Sep 2026 01:37:12 +0200</pubDate>
<content:encoded><![CDATA[<p>A pseudonymous GitHub account has published what it calls a reconstruction of Stuxnet malware that purportedly took out a fifth of Iran&#039;s centrifuges before being discoveredThe original source has never surfaced, and the &#039;Stuxnet&#039; moniker that the account uses comes from Symantec&#039;s coining of the name weeks after it was discoveredThe code remains... <a href="https://www.techradar.com/pro/security/how-the-mighty-have-fallen-the-notorious-stuxnet-malware-source-code-has-been-replicated-and-posted-on-github-for-all-to-see" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[IT Security News Daily Summary 2026-09-16]]></title>
<description><![CDATA[200 posts published today 21:31Revolut gave customer IDs and financial data to a government impostor 21:31Architecting a secure landing zone in the AWS European Sovereign Cloud 21:31Prophet Security research finds AI is cutting SOC investigation times, but nearly half of in-house builds fail to s...]]></description>
<link>https://tsecurity.de/de/4150444/malware-trojaner-viren/it-security-news-daily-summary-2026-09-16/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4150444/malware-trojaner-viren/it-security-news-daily-summary-2026-09-16/</guid>
<pubDate>Thu, 17 Sep 2026 00:11:39 +0200</pubDate>
<content:encoded><![CDATA[<p>200 posts published today 21:31Revolut gave customer IDs and financial data to a government impostor 21:31Architecting a secure landing zone in the AWS European Sovereign Cloud 21:31Prophet Security research finds AI is cutting SOC investigation times, but nearly half of in-house builds fail to stick 21:02LNK Metadata 21:02BambooToken: The Malware... <a href="https://www.itsecuritynews.info/it-security-news-daily-summary-2026-09-16/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Cybercrime finds its sea legs.]]></title>
<description><![CDATA[Officials investigate suspected cyberattacks on U.S.-bound oil tankers. Iranian operators deploy Chosen Brick surveillance malware. Ukraine cracks down on scam call centers. Researchers uncover two TP-Link camera zero-days. Maria Varmazis looks at weapons in space. CenterPoint Energy reports a da...]]></description>
<link>https://tsecurity.de/de/4150355/malware-trojaner-viren/cybercrime-finds-its-sea-legs/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4150355/malware-trojaner-viren/cybercrime-finds-its-sea-legs/</guid>
<pubDate>Wed, 16 Sep 2026 23:43:05 +0200</pubDate>
<content:encoded><![CDATA[<p>Officials investigate suspected cyberattacks on U.S.-bound oil tankers. Iranian operators deploy Chosen Brick surveillance malware. Ukraine cracks down on scam call centers. Researchers uncover two TP-Link camera zero-days. Maria Varmazis looks at weapons in space. CenterPoint Energy reports a data breach. Spain records its first breach caused by... <a href="https://thecyberwire.com/podcasts/daily-podcast/2637/notes" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[BambooToken: The Malware That Speaks MQTT to Stay Under the Radar]]></title>
<description><![CDATA[Lumen exposes BambooToken, a stealthy malware family using MQTT and sideloading to quietly infect targets across Asia and beyond. BambooToken is a new malware family that uses MQTT, a lightweight messaging protocol commonly found in smart devices and industrial systems, to quietly control infecte...]]></description>
<link>https://tsecurity.de/de/4150344/malware-trojaner-viren/bambootoken-the-malware-that-speaks-mqtt-to-stay-under-the-radar/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4150344/malware-trojaner-viren/bambootoken-the-malware-that-speaks-mqtt-to-stay-under-the-radar/</guid>
<pubDate>Wed, 16 Sep 2026 23:40:37 +0200</pubDate>
<content:encoded><![CDATA[<p>Lumen exposes BambooToken, a stealthy malware family using MQTT and sideloading to quietly infect targets across Asia and beyond. BambooToken is a new malware family that uses MQTT, a lightweight messaging protocol commonly found in smart devices and industrial systems, to quietly control infected Windows and Linux machines. Most malware connects... <a href="https://securityaffairs.com/199205/malware/bambootoken-the-malware-that-speaks-mqtt-to-stay-under-the-radar.html" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Google removed today 15 malicious chrome extensions]]></title>
<description><![CDATA[I track Chrome Web Store removals and today's pass picked up 15 extensions pulled with a malware classification, not the usual policy or spam category. https://malext.io/?reason=Malware&amp;day=2026-09-16 Important thing is that removal from the google store does not remove the extension from bro...]]></description>
<link>https://tsecurity.de/de/4150336/malware-trojaner-viren/google-removed-today-15-malicious-chrome-extensions/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4150336/malware-trojaner-viren/google-removed-today-15-malicious-chrome-extensions/</guid>
<pubDate>Wed, 16 Sep 2026 23:39:19 +0200</pubDate>
<content:encoded><![CDATA[<p>I track Chrome Web Store removals and today&#039;s pass picked up 15 extensions pulled with a malware classification, not the usual policy or spam category. https://malext.io/?reason=Malware&amp;amp;day=2026-09-16 Important thing is that removal from the google store does not remove the extension from browsers that already have it. Unless Google pushes it... <a href="https://www.reddit.com/r/security/comments/1wi8mky/google_removed_today_15_malicious_chrome/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Iranian hackers use CHOSEN BRICK Windows malware to spy on targets]]></title>
<description><![CDATA[Government agencies are warning that Iranian state-linked hackers are using a Windows malware strain named CHOSEN BRICK to target dissidents, activists, and journalists worldwide. [...] Weiterlesen]]></description>
<link>https://tsecurity.de/de/4150335/malware-trojaner-viren/iranian-hackers-use-chosen-brick-windows-malware-to-spy-on-targets/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4150335/malware-trojaner-viren/iranian-hackers-use-chosen-brick-windows-malware-to-spy-on-targets/</guid>
<pubDate>Wed, 16 Sep 2026 23:39:18 +0200</pubDate>
<content:encoded><![CDATA[<p>Government agencies are warning that Iranian state-linked hackers are using a Windows malware strain named CHOSEN BRICK to target dissidents, activists, and journalists worldwide. [...] <a href="https://www.bleepingcomputer.com/news/security/iranian-hackers-use-chosen-brick-windows-malware-to-spy-on-targets/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Malware bypasses browser checks to force install Chrome, Edge extensions]]></title>
<description><![CDATA[A banking malware operation active since mid-2025 has been using a toolkit named KREMLIN to install malicious Chrome and Edge extensions that steal credentials, session tokens, and sensitive data. [...] Weiterlesen]]></description>
<link>https://tsecurity.de/de/4150209/malware-trojaner-viren/malware-bypasses-browser-checks-to-force-install-chrome-edge-extensions/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4150209/malware-trojaner-viren/malware-bypasses-browser-checks-to-force-install-chrome-edge-extensions/</guid>
<pubDate>Wed, 16 Sep 2026 21:10:23 +0200</pubDate>
<content:encoded><![CDATA[<p>A banking malware operation active since mid-2025 has been using a toolkit named KREMLIN to install malicious Chrome and Edge extensions that steal credentials, session tokens, and sensitive data. [...] <a href="https://www.bleepingcomputer.com/news/security/malware-bypasses-browser-checks-to-force-install-chrome-edge-extensions/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Drei Threat-Gruppen treffen russische Unternehmen: Backdoors, Ransomware & Wiper]]></title>
<description><![CDATA[LONDON (IT BOLTWISE) – Drei getrennt verfolgte Bedrohungscluster zielen laut einem Bericht auf russische Unternehmensumgebungen. NightEagle nutzt kompromittierte VPN-Zugänge und verschaltet sich anschließend in Microsoft Exchange und Active Directory. Hacking Cat wechselt von reinen Angriffen auf...]]></description>
<link>https://tsecurity.de/de/4150115/malware-trojaner-viren/drei-threat-gruppen-treffen-russische-unternehmen-backdoors-ransomware-wiper/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4150115/malware-trojaner-viren/drei-threat-gruppen-treffen-russische-unternehmen-backdoors-ransomware-wiper/</guid>
<pubDate>Wed, 16 Sep 2026 20:47:08 +0200</pubDate>
<content:encoded><![CDATA[<p>LONDON (IT BOLTWISE) – Drei getrennt verfolgte Bedrohungscluster zielen laut einem Bericht auf russische Unternehmensumgebungen. NightEagle nutzt kompromittierte VPN-Zugänge und verschaltet sich anschließend in Microsoft Exchange und Active Directory. Hacking Cat wechselt von reinen Angriffen auf Verschlüsselung und zerstörerische Payloads,... <a href="https://www.it-boltwise.de/drei-threat-gruppen-treffen-russische-unternehmen-backdoors-ransomware-wiper.html" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Iran snoops on enemies of the state with Chosen Brick malware controlled using messaging apps]]></title>
<description><![CDATA[UK NCSC, FBI, and Dutch AIVD warn Iran is using Chosen Brick malware against dissidents and journalistsMalware steals files, captures audio, grabs WhatsApp/Telegram data, and can wipe systems entirelyOperatives rely on social engineering; agencies urge awareness, MFA, updates, and endpoint monito...]]></description>
<link>https://tsecurity.de/de/4150064/malware-trojaner-viren/iran-snoops-on-enemies-of-the-state-with-chosen-brick-malware-controlled-using-messaging-apps/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4150064/malware-trojaner-viren/iran-snoops-on-enemies-of-the-state-with-chosen-brick-malware-controlled-using-messaging-apps/</guid>
<pubDate>Wed, 16 Sep 2026 20:42:15 +0200</pubDate>
<content:encoded><![CDATA[<p>UK NCSC, FBI, and Dutch AIVD warn Iran is using Chosen Brick malware against dissidents and journalistsMalware steals files, captures audio, grabs WhatsApp/Telegram data, and can wipe systems entirelyOperatives rely on social engineering; agencies urge awareness, MFA, updates, and endpoint monitoringIranian hackers are targeting “enemies of the... <a href="https://www.techradar.com/pro/security/iran-snoops-on-enemies-of-the-state-with-chosen-brick-malware-controlled-using-messaging-apps" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Mehr als nur Antivirus: So hilft Norton gegen Phishing, Betrugsmaschen und gefährliche Downloads]]></title>
<description><![CDATA[Norton ist aktuell nur halb so teuer und schützt euch vor mehr als nur Viren. Für 1,67 Euro pro Monat bekommt ihr auch Schutz vor Phishing, Betrug und Ransomware. Dieser Artikel wurde einsortiert unter Internet &amp; Netzwelt, Schnäppchen, In eigener Sache, Antivirussoftware: Optimaler Virenschut...]]></description>
<link>https://tsecurity.de/de/4150018/malware-trojaner-viren/mehr-als-nur-antivirus-so-hilft-norton-gegen-phishing-betrugsmaschen-und-gefaehrliche-downloads/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4150018/malware-trojaner-viren/mehr-als-nur-antivirus-so-hilft-norton-gegen-phishing-betrugsmaschen-und-gefaehrliche-downloads/</guid>
<pubDate>Wed, 16 Sep 2026 20:41:06 +0200</pubDate>
<content:encoded><![CDATA[<p>Norton ist aktuell nur halb so teuer und schützt euch vor mehr als nur Viren. Für 1,67 Euro pro Monat bekommt ihr auch Schutz vor Phishing, Betrug und Ransomware. Dieser Artikel wurde einsortiert unter Internet &amp;amp; Netzwelt, Schnäppchen, In eigener Sache, Antivirussoftware: Optimaler Virenschutz für PC, Smartphone und Tablet, Sponsored Post -... <a href="https://www.netzwelt.de/schnaeppchen/258509-mehr-nur-antivirus-so-hilft-norton-gegen-phishing-betrugsmaschen-gefaehrliche-downloads.html" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[[iOS] Analyzing anomalous cpu_resource / diskwrites_resource reports on a stock TikTok process: unnamed UUID-only binaries in Binary Images]]></title>
<description><![CDATA[Context: iPhone 15 Pro Max, current iOS, no jailbreak, no sideloading, no configuration profiles, app reinstalled cleanly. All observations reproducible across WiFi / 4G / 5G. I've been analyzing iOS analytics ( .ips ) incident reports on a specific app process and found a pattern I'd like to com...]]></description>
<link>https://tsecurity.de/de/4149957/malware-trojaner-viren/ios-analyzing-anomalous-cpuresource-diskwritesresource-reports-on-a-stock-tiktok-process-unnamed-uuid-only-binaries-in-binary-images/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4149957/malware-trojaner-viren/ios-analyzing-anomalous-cpuresource-diskwritesresource-reports-on-a-stock-tiktok-process-unnamed-uuid-only-binaries-in-binary-images/</guid>
<pubDate>Wed, 16 Sep 2026 20:30:32 +0200</pubDate>
<content:encoded><![CDATA[<p>Context: iPhone 15 Pro Max, current iOS, no jailbreak, no sideloading, no configuration profiles, app reinstalled cleanly. All observations reproducible across WiFi / 4G / 5G. I&#039;ve been analyzing iOS analytics ( .ips ) incident reports on a specific app process and found a pattern I&#039;d like to compare against what this community typically sees in... <a href="https://www.reddit.com/r/MalwareAnalysis/comments/1wi4sp5/ios_analyzing_anomalous_cpu_resource_diskwrites/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Hackers Can Rent VectraRAT for $250 a Month to Take Control of Windows PCs]]></title>
<description><![CDATA[Hackers can now rent a Windows-focused remote access tool called VectraRAT for $250 a month, lowering the barrier to deep and persistent compromise. The malware gives paying operators a way to watch victims, steal data, run commands, and move traffic through an infected computer. VectraRAT has su...]]></description>
<link>https://tsecurity.de/de/4149834/malware-trojaner-viren/hackers-can-rent-vectrarat-for-250-a-month-to-take-control-of-windows-pcs/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4149834/malware-trojaner-viren/hackers-can-rent-vectrarat-for-250-a-month-to-take-control-of-windows-pcs/</guid>
<pubDate>Wed, 16 Sep 2026 18:46:47 +0200</pubDate>
<content:encoded><![CDATA[<p>Hackers can now rent a Windows-focused remote access tool called VectraRAT for $250 a month, lowering the barrier to deep and persistent compromise. The malware gives paying operators a way to watch victims, steal data, run commands, and move traffic through an infected computer. VectraRAT has surfaced as a rental-only malware service rather than... <a href="https://cybersecuritynews.com/hackers-can-rent-vectrarat/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Hackers Use Cross-Platform Noodle RAT to Secretly Control Windows and Linux Systems]]></title>
<description><![CDATA[Noodle RAT is a remote-access trojan that gives attackers control of compromised computers and servers. Its renewed visibility matters because it runs on both Windows and Linux, allowing one malware family to follow victims across corporate networks. The tool has appeared in operations against or...]]></description>
<link>https://tsecurity.de/de/4149811/malware-trojaner-viren/hackers-use-cross-platform-noodle-rat-to-secretly-control-windows-and-linux-systems/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4149811/malware-trojaner-viren/hackers-use-cross-platform-noodle-rat-to-secretly-control-windows-and-linux-systems/</guid>
<pubDate>Wed, 16 Sep 2026 18:46:15 +0200</pubDate>
<content:encoded><![CDATA[<p>Noodle RAT is a remote-access trojan that gives attackers control of compromised computers and servers. Its renewed visibility matters because it runs on both Windows and Linux, allowing one malware family to follow victims across corporate networks. The tool has appeared in operations against organisations across Asia-Pacific, including Thailand,... <a href="https://cybersecuritynews.com/cross-platform-noodle-rat/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[The true cost of a ransomware attack, with and without BCDR]]></title>
<description><![CDATA[The ransom itself can be only a fraction of the total cost of a ransomware attack, with downtime, recovery, remediation, and legal obligations adding millions to the bill. Datto explains how a mature BCDR strategy can reduce downtime and provide a faster, more predictable path to recovery. [...] ...]]></description>
<link>https://tsecurity.de/de/4149787/malware-trojaner-viren/the-true-cost-of-a-ransomware-attack-with-and-without-bcdr/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4149787/malware-trojaner-viren/the-true-cost-of-a-ransomware-attack-with-and-without-bcdr/</guid>
<pubDate>Wed, 16 Sep 2026 18:42:14 +0200</pubDate>
<content:encoded><![CDATA[<p>The ransom itself can be only a fraction of the total cost of a ransomware attack, with downtime, recovery, remediation, and legal obligations adding millions to the bill. Datto explains how a mature BCDR strategy can reduce downtime and provide a faster, more predictable path to recovery. [...] <a href="https://www.bleepingcomputer.com/news/security/the-true-cost-of-a-ransomware-attack-with-and-without-bcdr/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Three Threat Groups Target Russian Enterprises With Backdoors, Ransomware, and Wipers]]></title>
<description><![CDATA[Enterprises in Russia have emerged as the target of three threat activity clusters tracked as NightEagle, Hacking Cat, and Toy Ghouls, according to multiple reports from Kaspersky. The cybersecurity vendor said it has identified attacks mounted by NightEagle (aka APT-Q-95), a threat actor known t...]]></description>
<link>https://tsecurity.de/de/4149765/malware-trojaner-viren/three-threat-groups-target-russian-enterprises-with-backdoors-ransomware-and-wipers/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4149765/malware-trojaner-viren/three-threat-groups-target-russian-enterprises-with-backdoors-ransomware-and-wipers/</guid>
<pubDate>Wed, 16 Sep 2026 18:41:26 +0200</pubDate>
<content:encoded><![CDATA[<p>Enterprises in Russia have emerged as the target of three threat activity clusters tracked as NightEagle, Hacking Cat, and Toy Ghouls, according to multiple reports from Kaspersky. The cybersecurity vendor said it has identified attacks mounted by NightEagle (aka APT-Q-95), a threat actor known to be active since at least 2023, that involve new... <a href="https://thehackernews.com/2026/09/three-threat-groups-target-russian.html" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Serbien: Oppositionelle stehen im Visier von Überwachungssoftware]]></title>
<description><![CDATA[IT-Forensik-Fachleute haben in mehreren Fällen den gezielten Einsatz von Spyware gegen Bürger:innen in Serbien festgestellt. Das ist nicht das erste Mal, dass Regierungskritiker:innen und Oppositionelle des Balkanstaats ins Visier geraten. Kurz vor den Neuwahlen wurden Infektionen mit Trojanern b...]]></description>
<link>https://tsecurity.de/de/4149611/malware-trojaner-viren/serbien-oppositionelle-stehen-im-visier-von-ueberwachungssoftware/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4149611/malware-trojaner-viren/serbien-oppositionelle-stehen-im-visier-von-ueberwachungssoftware/</guid>
<pubDate>Wed, 16 Sep 2026 18:39:27 +0200</pubDate>
<content:encoded><![CDATA[<p>IT-Forensik-Fachleute haben in mehreren Fällen den gezielten Einsatz von Spyware gegen Bürger:innen in Serbien festgestellt. Das ist nicht das erste Mal, dass Regierungskritiker:innen und Oppositionelle des Balkanstaats ins Visier geraten. Kurz vor den Neuwahlen wurden Infektionen mit Trojanern bekannt. – Alle Rechte vorbehalten: Trojanisches... <a href="https://netzpolitik.org/2026/serbien-oppositionelle-stehen-im-visier-von-ueberwachungssoftware/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Trellix Stinger Download - Spezielle Viren entfernen]]></title>
<description><![CDATA[Der Download von Trellix Stinger durchsucht Ihren PC nach Viren, Würmern sowie anderen Formen von Malware und entfernt diese vollständig und sicher. Trellix Stinger ist dabei als Ergänzung vorhandener ... (Weiter lesen) Weiterlesen]]></description>
<link>https://tsecurity.de/de/4149579/malware-trojaner-viren/trellix-stinger-download-spezielle-viren-entfernen/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4149579/malware-trojaner-viren/trellix-stinger-download-spezielle-viren-entfernen/</guid>
<pubDate>Wed, 16 Sep 2026 18:37:30 +0200</pubDate>
<content:encoded><![CDATA[<p>Der Download von Trellix Stinger durchsucht Ihren PC nach Viren, Würmern sowie anderen Formen von Malware und entfernt diese vollständig und sicher. Trellix Stinger ist dabei als Ergänzung vorhandener ... (Weiter lesen) <a href="https://winfuture.de/downloadvorschalt,817.html" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Streaminghub offline: Eigenwerbung führt BREIN zum Betreiber]]></title>
<description><![CDATA[Streaminghub offline: BREIN identifiziert Betreiber über dessen Eigenwerbung. Das illegale Angebot umfasste Filme, Serien, Live-TV und Sport Der Artikel Streaminghub offline: Eigenwerbung führt BREIN zum Betreiber erschien zuerst auf TARNKAPPE.INFO Weiterlesen]]></description>
<link>https://tsecurity.de/de/4149502/malware-trojaner-viren/streaminghub-offline-eigenwerbung-fuehrt-brein-zum-betreiber/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4149502/malware-trojaner-viren/streaminghub-offline-eigenwerbung-fuehrt-brein-zum-betreiber/</guid>
<pubDate>Wed, 16 Sep 2026 18:30:20 +0200</pubDate>
<content:encoded><![CDATA[<p>Streaminghub offline: BREIN identifiziert Betreiber über dessen Eigenwerbung. Das illegale Angebot umfasste Filme, Serien, Live-TV und Sport Der Artikel Streaminghub offline: Eigenwerbung führt BREIN zum Betreiber erschien zuerst auf TARNKAPPE.INFO <a href="https://tarnkappe.info/artikel/streaming/streaminghub-offline-brein-betreiber-eigenwerbung-333497.html" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Irdeto-Tochter Denuvo reicht Klage gegen voices38 ein]]></title>
<description><![CDATA[Die Irdeto-Tochter Denuvo reichte vor einem US-Bundesgericht Klage gegen den Cracker voices38 ein, der darauf aber sehr entspannt reagiert. Der Artikel Irdeto-Tochter Denuvo reicht Klage gegen voices38 ein erschien zuerst auf TARNKAPPE.INFO Weiterlesen]]></description>
<link>https://tsecurity.de/de/4149501/malware-trojaner-viren/irdeto-tochter-denuvo-reicht-klage-gegen-voices38-ein/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4149501/malware-trojaner-viren/irdeto-tochter-denuvo-reicht-klage-gegen-voices38-ein/</guid>
<pubDate>Wed, 16 Sep 2026 18:30:20 +0200</pubDate>
<content:encoded><![CDATA[<p>Die Irdeto-Tochter Denuvo reichte vor einem US-Bundesgericht Klage gegen den Cracker voices38 ein, der darauf aber sehr entspannt reagiert. Der Artikel Irdeto-Tochter Denuvo reicht Klage gegen voices38 ein erschien zuerst auf TARNKAPPE.INFO <a href="https://tarnkappe.info/artikel/denuvo/irdeto-tochter-denuvo-reicht-klage-gegen-voices38-ein-333498.html" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[HBO Max Reddit Account Hacked: 108 Malicious Ads Push ClickFix Malware]]></title>
<description><![CDATA[A verified HBO Max account looked like a safe place to encounter an ad. Attackers reportedly turned that credibility into a malware delivery system. Researchers at Hudson Rock found that attackers compromised HBO Max’s verified Reddit advertising account and used it to run 108 malicious ads over ...]]></description>
<link>https://tsecurity.de/de/4149482/malware-trojaner-viren/hbo-max-reddit-account-hacked-108-malicious-ads-push-clickfix-malware/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4149482/malware-trojaner-viren/hbo-max-reddit-account-hacked-108-malicious-ads-push-clickfix-malware/</guid>
<pubDate>Wed, 16 Sep 2026 15:43:28 +0200</pubDate>
<content:encoded><![CDATA[<p>A verified HBO Max account looked like a safe place to encounter an ad. Attackers reportedly turned that credibility into a malware delivery system. Researchers at Hudson Rock found that attackers compromised HBO Max’s verified Reddit advertising account and used it to run 108 malicious ads over roughly 48 hours. The ads sent users to... <a href="https://www.esecurityplanet.com/threats/news-hbo-max-reddit-clickfix-malware-ads/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[VectraRAT Malware-as-a-Service Lets Hackers Bypass UAC and Hijack Windows Systems]]></title>
<description><![CDATA[VectraRAT, a previously undocumented Malware-as-a-Service platform that combines remote-access trojan capabilities with automated credential theft and a silent Windows privilege-escalation chain. Unlike the large number of commodity RATs that recycle leaked AsyncRAT, XWorm, or QuasarRAT code, Vec...]]></description>
<link>https://tsecurity.de/de/4149278/malware-trojaner-viren/vectrarat-malware-as-a-service-lets-hackers-bypass-uac-and-hijack-windows-systems/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4149278/malware-trojaner-viren/vectrarat-malware-as-a-service-lets-hackers-bypass-uac-and-hijack-windows-systems/</guid>
<pubDate>Wed, 16 Sep 2026 15:16:07 +0200</pubDate>
<content:encoded><![CDATA[<p>VectraRAT, a previously undocumented Malware-as-a-Service platform that combines remote-access trojan capabilities with automated credential theft and a silent Windows privilege-escalation chain. Unlike the large number of commodity RATs that recycle leaked AsyncRAT, XWorm, or QuasarRAT code, VectraRAT appears to be a purpose-built, full-stack... <a href="https://gbhackers.com/vectrarat-malware-as-a-service/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[New VectraRAT MaaS Lets Hackers Bypass Windows UAC and Steal Browser Credentials]]></title>
<description><![CDATA[Threat researchers have uncovered a previously undocumented malware-as-a-service (MaaS) platform called VectraRAT, a full-stack toolkit that gives cybercriminals enterprise-grade intrusion capabilities for as little as $250 a month. Unlike most commodity RATs that fork leaked code from families l...]]></description>
<link>https://tsecurity.de/de/4149277/malware-trojaner-viren/new-vectrarat-maas-lets-hackers-bypass-windows-uac-and-steal-browser-credentials/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4149277/malware-trojaner-viren/new-vectrarat-maas-lets-hackers-bypass-windows-uac-and-steal-browser-credentials/</guid>
<pubDate>Wed, 16 Sep 2026 15:15:58 +0200</pubDate>
<content:encoded><![CDATA[<p>Threat researchers have uncovered a previously undocumented malware-as-a-service (MaaS) platform called VectraRAT, a full-stack toolkit that gives cybercriminals enterprise-grade intrusion capabilities for as little as $250 a month. Unlike most commodity RATs that fork leaked code from families like AsyncRAT or XWorm, VectraRAT was built entirely... <a href="https://cyberpress.org/vectrarat-maas-windows-uac/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[N0va-Phishing zielt auf Identitäten in Unternehmen – Attacke über legitime Authentifizierungsflows]]></title>
<description><![CDATA[LONDON (IT BOLTWISE) – Die Phishing-Kampagne „N0va“ nutzt täuschend echte Identitäts- und Authentifizierungsabläufe, um an gültige Konten und Tokens zu gelangen. Angreifer können so ohne auffällige Malware-Aktivität Zugriff aus laufenden Sitzungen verlängern und SSO-Mechanismen missbrauchen. Beso...]]></description>
<link>https://tsecurity.de/de/4149270/malware-trojaner-viren/n0va-phishing-zielt-auf-identitaeten-in-unternehmen-attacke-ueber-legitime-authentifizierungsflows/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4149270/malware-trojaner-viren/n0va-phishing-zielt-auf-identitaeten-in-unternehmen-attacke-ueber-legitime-authentifizierungsflows/</guid>
<pubDate>Wed, 16 Sep 2026 15:15:55 +0200</pubDate>
<content:encoded><![CDATA[<p>LONDON (IT BOLTWISE) – Die Phishing-Kampagne „N0va“ nutzt täuschend echte Identitäts- und Authentifizierungsabläufe, um an gültige Konten und Tokens zu gelangen. Angreifer können so ohne auffällige Malware-Aktivität Zugriff aus laufenden Sitzungen verlängern und SSO-Mechanismen missbrauchen. Besonders betroffen sind Unternehmen in Nordamerika und... <a href="https://www.it-boltwise.de/n0va-phishing-zielt-auf-identitaeten-in-unternehmen-attacke-ueber-legitime-authentifizierungsflows.html" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Chinese-Speaking Hackers Use Noodle RAT Backdoor to Spy on Windows and Linux Systems]]></title>
<description><![CDATA[Chinese-speaking threat actors are continuing to rely on Noodle RAT, a cross-platform remote access trojan designed to maintain covert access to compromised Windows workstations and Linux servers. Also tracked as ANGRYREBEL and Nood RAT, the malware has been active since at least mid-2016 but was...]]></description>
<link>https://tsecurity.de/de/4149259/malware-trojaner-viren/chinese-speaking-hackers-use-noodle-rat-backdoor-to-spy-on-windows-and-linux-systems/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4149259/malware-trojaner-viren/chinese-speaking-hackers-use-noodle-rat-backdoor-to-spy-on-windows-and-linux-systems/</guid>
<pubDate>Wed, 16 Sep 2026 15:15:48 +0200</pubDate>
<content:encoded><![CDATA[<p>Chinese-speaking threat actors are continuing to rely on Noodle RAT, a cross-platform remote access trojan designed to maintain covert access to compromised Windows workstations and Linux servers. Also tracked as ANGRYREBEL and Nood RAT, the malware has been active since at least mid-2016 but was long mistaken for variants of Gh0st RAT, Rekoobe,... <a href="https://www.itsecuritynews.info/chinese-speaking-hackers-use-noodle-rat-backdoor-to-spy-on-windows-and-linux-systems/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[IT Security News Hourly Summary 2026-09-16 15h : 15 posts]]></title>
<description><![CDATA[15 posts published in the last hour 12:31Major Cyber Vendors Turn to New UK Testing Program as MITRE Evaluations Face Changes 12:31Chinese-Speaking Hackers Use Noodle RAT Backdoor to Spy on Windows and Linux Systems 12:31US, UK, Dutch Agencies Expose Iranian ‘Chosen Brick’ Surveillance Malware 12...]]></description>
<link>https://tsecurity.de/de/4149257/malware-trojaner-viren/it-security-news-hourly-summary-2026-09-16-15h-15-posts/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4149257/malware-trojaner-viren/it-security-news-hourly-summary-2026-09-16-15h-15-posts/</guid>
<pubDate>Wed, 16 Sep 2026 15:15:48 +0200</pubDate>
<content:encoded><![CDATA[<p>15 posts published in the last hour 12:31Major Cyber Vendors Turn to New UK Testing Program as MITRE Evaluations Face Changes 12:31Chinese-Speaking Hackers Use Noodle RAT Backdoor to Spy on Windows and Linux Systems 12:31US, UK, Dutch Agencies Expose Iranian ‘Chosen Brick’ Surveillance Malware 12:02Smishing Triad Hackers Use JWR Phishing Kit to... <a href="https://www.itsecuritynews.info/it-security-news-hourly-summary-2026-09-16-15h-15-posts/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[US, UK, Dutch Agencies Expose Iranian ‘Chosen Brick’ Surveillance Malware]]></title>
<description><![CDATA[US, UK, and Dutch government agencies published a report detailing the malware, and the FBI described the abuse of Telegram for C&amp;C. The post US, UK, Dutch Agencies Expose Iranian ‘Chosen Brick’ Surveillance Malware appeared first on SecurityWeek. Weiterlesen]]></description>
<link>https://tsecurity.de/de/4149171/malware-trojaner-viren/us-uk-dutch-agencies-expose-iranian-chosen-brick-surveillance-malware/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4149171/malware-trojaner-viren/us-uk-dutch-agencies-expose-iranian-chosen-brick-surveillance-malware/</guid>
<pubDate>Wed, 16 Sep 2026 15:12:20 +0200</pubDate>
<content:encoded><![CDATA[<p>US, UK, and Dutch government agencies published a report detailing the malware, and the FBI described the abuse of Telegram for C&amp;amp;C. The post US, UK, Dutch Agencies Expose Iranian ‘Chosen Brick’ Surveillance Malware appeared first on SecurityWeek. <a href="https://www.securityweek.com/us-uk-dutch-agencies-expose-iranian-chosen-brick-surveillance-malware/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[N0va Phishkit Targets US and EU Businesses: A New Challenge for Identity Security]]></title>
<description><![CDATA[N0va is targeting organizations across North America and Europe with phishing campaigns that impersonate trusted services and abuse legitimate authentication flows. Successful attacks can give threat actors access to valid accounts without relying on obvious malware activity. From there, a single...]]></description>
<link>https://tsecurity.de/de/4149164/malware-trojaner-viren/n0va-phishkit-targets-us-and-eu-businesses-a-new-challenge-for-identity-security/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4149164/malware-trojaner-viren/n0va-phishkit-targets-us-and-eu-businesses-a-new-challenge-for-identity-security/</guid>
<pubDate>Wed, 16 Sep 2026 15:12:13 +0200</pubDate>
<content:encoded><![CDATA[<p>N0va is targeting organizations across North America and Europe with phishing campaigns that impersonate trusted services and abuse legitimate authentication flows. Successful attacks can give threat actors access to valid accounts without relying on obvious malware activity. From there, a single compromised identity can open the door to sensitive... <a href="https://thehackernews.com/2026/09/n0va-phishkit-targets-us-and-eu.html" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Chrome and Edge browsers hijacked by KREMLIN malware for credential and token session theft]]></title>
<description><![CDATA[Elastic Security Labs uncovered REF9334, a Brazilian banking malware campaign active since May 2025Malware “Kremlin” deploys fake docs and malicious Chrome/Edge extensions to steal banking data1,515 infections found, 98% in BrazilSecurity researchers from Elastic Security Labs have discovered a n...]]></description>
<link>https://tsecurity.de/de/4149138/malware-trojaner-viren/chrome-and-edge-browsers-hijacked-by-kremlin-malware-for-credential-and-token-session-theft/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4149138/malware-trojaner-viren/chrome-and-edge-browsers-hijacked-by-kremlin-malware-for-credential-and-token-session-theft/</guid>
<pubDate>Wed, 16 Sep 2026 15:11:53 +0200</pubDate>
<content:encoded><![CDATA[<p>Elastic Security Labs uncovered REF9334, a Brazilian banking malware campaign active since May 2025Malware “Kremlin” deploys fake docs and malicious Chrome/Edge extensions to steal banking data1,515 infections found, 98% in BrazilSecurity researchers from Elastic Security Labs have discovered a new Brazilian banking malware campaign that uses... <a href="https://www.techradar.com/pro/security/chrome-and-edge-browsers-hijacked-by-kremlin-malware-for-credential-and-token-session-theft" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[speakeasy v2.0.0b8]]></title>
<description><![CDATA[Windows malware emulation framework that executes binaries, drivers, and shellcode in a modeled runtime, emulating APIs, process/thread behavior, filesystem, registry, and network activity for structured JSON reporting. Weiterlesen]]></description>
<link>https://tsecurity.de/de/4148983/malware-trojaner-viren/speakeasy-v200b8/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4148983/malware-trojaner-viren/speakeasy-v200b8/</guid>
<pubDate>Wed, 16 Sep 2026 15:10:06 +0200</pubDate>
<content:encoded><![CDATA[<p>Windows malware emulation framework that executes binaries, drivers, and shellcode in a modeled runtime, emulating APIs, process/thread behavior, filesystem, registry, and network activity for structured JSON reporting. <a href="https://kitploit.com/en/posts/github-mandiant-speakeasy-v200b8" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[2026 Péter Szőr Award shortlisted nominees]]></title>
<description><![CDATA[VB Congratulates the researchers shortlisted for the 2026 Péter Szőr Award. Read more Weiterlesen]]></description>
<link>https://tsecurity.de/de/4148927/malware-trojaner-viren/2026-pter-szr-award-shortlisted-nominees/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4148927/malware-trojaner-viren/2026-pter-szr-award-shortlisted-nominees/</guid>
<pubDate>Wed, 16 Sep 2026 15:00:05 +0200</pubDate>
<content:encoded><![CDATA[<p>VB Congratulates the researchers shortlisted for the 2026 Péter Szőr Award. Read more <a href="https://www.virusbulletin.com/blog/2026/09/2026-peter-szor-award-shortlisted-nominees/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[NightEagle targets Russian companies]]></title>
<description><![CDATA[Over the past year, our Global Emergency Response Team (GERT) has investigated several incidents involving the NightEagle group (APT-Q-95). This group has been active since at least 2023 and originally focused on organizations in Asia, as we reported previously. We have now identified attacks by ...]]></description>
<link>https://tsecurity.de/de/4148926/malware-trojaner-viren/nighteagle-targets-russian-companies/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4148926/malware-trojaner-viren/nighteagle-targets-russian-companies/</guid>
<pubDate>Wed, 16 Sep 2026 15:00:04 +0200</pubDate>
<content:encoded><![CDATA[<p>Over the past year, our Global Emergency Response Team (GERT) has investigated several incidents involving the NightEagle group (APT-Q-95). This group has been active since at least 2023 and originally focused on organizations in Asia, as we reported previously. We have now identified attacks by the group targeting businesses in Russia. This post... <a href="https://securelist.com/tr/nighteagle-apt-ghostcontainer-and-tunneling/121323/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Atomic macOS (AMOS) Stealer Activity]]></title>
<description><![CDATA[Modern macOS malware uses deceptive setup guides to steal credentials and sensitive user data. Learn how to identify and block these threats. The post Atomic macOS (AMOS) Stealer Activity appeared first on Unit 42. Weiterlesen]]></description>
<link>https://tsecurity.de/de/4148893/malware-trojaner-viren/atomic-macos-amos-stealer-activity/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4148893/malware-trojaner-viren/atomic-macos-amos-stealer-activity/</guid>
<pubDate>Wed, 16 Sep 2026 12:14:49 +0200</pubDate>
<content:encoded><![CDATA[<p>Modern macOS malware uses deceptive setup guides to steal credentials and sensitive user data. Learn how to identify and block these threats. The post Atomic macOS (AMOS) Stealer Activity appeared first on Unit 42. <a href="https://unit42.paloaltonetworks.com/atomic-macos-amos-stealer-activity/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[IT Security News Hourly Summary 2026-09-16 12h : 15 posts]]></title>
<description><![CDATA[15 posts published in the last hour 09:32Meta Plans Smart Glasses Without Camera, Amid Complaints 09:32Iranian hackers use CHOSEN BRICK data-stealing malware to spy on dissidents and journalists 09:3236,769 Self-Hosted AI Services Exposed Online — What Security Teams Should Check 09:31Public PoC ...]]></description>
<link>https://tsecurity.de/de/4148870/malware-trojaner-viren/it-security-news-hourly-summary-2026-09-16-12h-15-posts/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4148870/malware-trojaner-viren/it-security-news-hourly-summary-2026-09-16-12h-15-posts/</guid>
<pubDate>Wed, 16 Sep 2026 12:13:20 +0200</pubDate>
<content:encoded><![CDATA[<p>15 posts published in the last hour 09:32Meta Plans Smart Glasses Without Camera, Amid Complaints 09:32Iranian hackers use CHOSEN BRICK data-stealing malware to spy on dissidents and journalists 09:3236,769 Self-Hosted AI Services Exposed Online — What Security Teams Should Check 09:31Public PoC Released for Apache Superset SQL Injection... <a href="https://www.itsecuritynews.info/it-security-news-hourly-summary-2026-09-16-12h-15-posts/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[PAPERMILL Malware Campaign Abuses Signed Notepad++ to Deliver VenomRAT to Windows Users]]></title>
<description><![CDATA[A newly identified phishing operation tracked as PAPERMILL is abusing a legitimately signed Notepad++ executable, DLL sideloading, and layered in-memory loaders to install VenomRAT on Windows systems. The campaign uses tax-audit lures aimed at Indian recipients and reflects a broader China-nexus ...]]></description>
<link>https://tsecurity.de/de/4148865/malware-trojaner-viren/papermill-malware-campaign-abuses-signed-notepad-to-deliver-venomrat-to-windows-users/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4148865/malware-trojaner-viren/papermill-malware-campaign-abuses-signed-notepad-to-deliver-venomrat-to-windows-users/</guid>
<pubDate>Wed, 16 Sep 2026 12:13:20 +0200</pubDate>
<content:encoded><![CDATA[<p>A newly identified phishing operation tracked as PAPERMILL is abusing a legitimately signed Notepad++ executable, DLL sideloading, and layered in-memory loaders to install VenomRAT on Windows systems. The campaign uses tax-audit lures aimed at Indian recipients and reflects a broader China-nexus pattern of tax-themed malware activity, although the... <a href="https://www.itsecuritynews.info/papermill-malware-campaign-abuses-signed-notepad-to-deliver-venomrat-to-windows-users/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Agents at Large | Tracing Illicit OpenAI Agent Activity on Hugging Face]]></title>
<description><![CDATA[Two Hugging Face accounts reveal that OpenAI's agents staged relay code, internal probes and ChatGPT account registration beyond the published timeline. This article has been indexed from SentinelLabs – We are hunters, reversers, exploit developers, and tinkerers shedding light on the world of ma...]]></description>
<link>https://tsecurity.de/de/4148864/malware-trojaner-viren/agents-at-large-tracing-illicit-openai-agent-activity-on-hugging-face/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4148864/malware-trojaner-viren/agents-at-large-tracing-illicit-openai-agent-activity-on-hugging-face/</guid>
<pubDate>Wed, 16 Sep 2026 12:13:20 +0200</pubDate>
<content:encoded><![CDATA[<p>Two Hugging Face accounts reveal that OpenAI&#039;s agents staged relay code, internal probes and ChatGPT account registration beyond the published timeline. This article has been indexed from SentinelLabs – We are hunters, reversers, exploit developers, and tinkerers shedding light on the world of malware, exploits, APTs, and cybercrime across all... <a href="https://www.itsecuritynews.info/agents-at-large-tracing-illicit-openai-agent-activity-on-hugging-face/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Warum sichere Datenspeicherung für den Mittelstand essenziell ist]]></title>
<description><![CDATA[Exponentialwachstum, Ransomware &amp; NIS-2: Fünf Gründe, warum sichere Datenspeicherung für den Mittelstand überlebenswichtig ist. Exponentielles Datenwachstum, die Bedrohung durch zielgerichtete Ransomware-Angriffe und immer strengere Compliance-Vorgaben setzen IT-Abteilungen im Mittelstand unt...]]></description>
<link>https://tsecurity.de/de/4148853/malware-trojaner-viren/warum-sichere-datenspeicherung-fuer-den-mittelstand-essenziell-ist/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4148853/malware-trojaner-viren/warum-sichere-datenspeicherung-fuer-den-mittelstand-essenziell-ist/</guid>
<pubDate>Wed, 16 Sep 2026 12:10:17 +0200</pubDate>
<content:encoded><![CDATA[<p>Exponentialwachstum, Ransomware &amp;amp; NIS-2: Fünf Gründe, warum sichere Datenspeicherung für den Mittelstand überlebenswichtig ist. Exponentielles Datenwachstum, die Bedrohung durch zielgerichtete Ransomware-Angriffe und immer strengere Compliance-Vorgaben setzen IT-Abteilungen im Mittelstand unter enormen Zugzwang. Dennoch verzögern viele... <a href="https://www.it-daily.net/it-sicherheit/cloud-security/mittelstand-datenspeicherung" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[KREMLIN Banking Malware Infects Over 1,500 Systems With Malicious Chrome Extension]]></title>
<description><![CDATA[KREMLIN is a banking malware operation that plants a hostile browser extension on infected computers. The extension can harvest passwords, session cookies, and other data that can let criminals enter online accounts. The campaign begins with fake JavaScript documents that pose as bank records or ...]]></description>
<link>https://tsecurity.de/de/4148716/malware-trojaner-viren/kremlin-banking-malware-infects-over-1500-systems-with-malicious-chrome-extension/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4148716/malware-trojaner-viren/kremlin-banking-malware-infects-over-1500-systems-with-malicious-chrome-extension/</guid>
<pubDate>Wed, 16 Sep 2026 11:14:02 +0200</pubDate>
<content:encoded><![CDATA[<p>KREMLIN is a banking malware operation that plants a hostile browser extension on infected computers. The extension can harvest passwords, session cookies, and other data that can let criminals enter online accounts. The campaign begins with fake JavaScript documents that pose as bank records or invoices. Once opened, they install components and... <a href="https://cybersecuritynews.com/kremlin-banking-malware/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Iranian Hackers Use Fake MRI Results to Infect Victims With CHOSEN BRICK Spyware]]></title>
<description><![CDATA[Iranian state-linked hackers are using fake MRI scan results to infect selected people with CHOSEN BRICK, a Windows spyware family built for long-term surveillance. The campaign has targeted individuals in the United Kingdom, United States and Netherlands since at least 2025, with dissidents, act...]]></description>
<link>https://tsecurity.de/de/4148715/malware-trojaner-viren/iranian-hackers-use-fake-mri-results-to-infect-victims-with-chosen-brick-spyware/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4148715/malware-trojaner-viren/iranian-hackers-use-fake-mri-results-to-infect-victims-with-chosen-brick-spyware/</guid>
<pubDate>Wed, 16 Sep 2026 11:14:02 +0200</pubDate>
<content:encoded><![CDATA[<p>Iranian state-linked hackers are using fake MRI scan results to infect selected people with CHOSEN BRICK, a Windows spyware family built for long-term surveillance. The campaign has targeted individuals in the United Kingdom, United States and Netherlands since at least 2025, with dissidents, activists and journalists facing particular risk. The... <a href="https://cybersecuritynews.com/fake-mri-results/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Iranian malware steals Telegram and WhatsApp data from targets]]></title>
<description><![CDATA[Iranian state cyber actors are using Windows malware called CHOSEN BRICK to target dissidents, activists, and journalists, with capabilities that include stealing Telegram and WhatsApp browser data, emails, screenshots, and audio. The malware has been used internationally since at least 2025 and ...]]></description>
<link>https://tsecurity.de/de/4148710/malware-trojaner-viren/iranian-malware-steals-telegram-and-whatsapp-data-from-targets/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4148710/malware-trojaner-viren/iranian-malware-steals-telegram-and-whatsapp-data-from-targets/</guid>
<pubDate>Wed, 16 Sep 2026 11:13:53 +0200</pubDate>
<content:encoded><![CDATA[<p>Iranian state cyber actors are using Windows malware called CHOSEN BRICK to target dissidents, activists, and journalists, with capabilities that include stealing Telegram and WhatsApp browser data, emails, screenshots, and audio. The malware has been used internationally since at least 2025 and relies heavily on social engineering, while also... <a href="https://cyberinsider.com/iranian-malware-steals-telegram-and-whatsapp-data-from-targets/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[China-Aligned Hackers Hide PeckBirdy Malware C2 Inside Casino and Adult Websites]]></title>
<description><![CDATA[China-aligned threat actors are concealing the PeckBirdy command-and-control framework inside low-quality Chinese-language casino and adult websites. Exploiting a vast and routinely ignored category of internet infrastructure to blend malware traffic into apparent gambling activity. The activity ...]]></description>
<link>https://tsecurity.de/de/4148709/malware-trojaner-viren/china-aligned-hackers-hide-peckbirdy-malware-c2-inside-casino-and-adult-websites/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4148709/malware-trojaner-viren/china-aligned-hackers-hide-peckbirdy-malware-c2-inside-casino-and-adult-websites/</guid>
<pubDate>Wed, 16 Sep 2026 11:13:48 +0200</pubDate>
<content:encoded><![CDATA[<p>China-aligned threat actors are concealing the PeckBirdy command-and-control framework inside low-quality Chinese-language casino and adult websites. Exploiting a vast and routinely ignored category of internet infrastructure to blend malware traffic into apparent gambling activity. The activity expands on earlier findings by Trend Micro, which... <a href="https://gbhackers.com/peckbirdy-malware-c2/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Iranian hackers use CHOSEN BRICK data-stealing malware to spy on dissidents and journalists]]></title>
<description><![CDATA[Iranian state cyber actors are deploying malware called CHOSEN BRICK against individuals they see as a threat to the regime, reaching victims through social messaging apps and infecting their Windows devices, three Western intelligence agencies warned. The UK’s National Cyber Security Centre, the...]]></description>
<link>https://tsecurity.de/de/4148692/malware-trojaner-viren/iranian-hackers-use-chosen-brick-data-stealing-malware-to-spy-on-dissidents-and-journalists/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4148692/malware-trojaner-viren/iranian-hackers-use-chosen-brick-data-stealing-malware-to-spy-on-dissidents-and-journalists/</guid>
<pubDate>Wed, 16 Sep 2026 11:11:11 +0200</pubDate>
<content:encoded><![CDATA[<p>Iranian state cyber actors are deploying malware called CHOSEN BRICK against individuals they see as a threat to the regime, reaching victims through social messaging apps and infecting their Windows devices, three Western intelligence agencies warned. The UK’s National Cyber Security Centre, the FBI and the Netherlands’ AIVD said the campaign has... <a href="https://www.helpnetsecurity.com/2026/09/16/iranian-hackers-chosen-brick-malware-dissidents-journalists/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[NCSC and Allies Warn of Iranian Spyware Campaign]]></title>
<description><![CDATA[The UK’s National Cyber Security Centre says Iranian Chosen Brick spyware is designed to snoop on dissidents Weiterlesen]]></description>
<link>https://tsecurity.de/de/4148691/malware-trojaner-viren/ncsc-and-allies-warn-of-iranian-spyware-campaign/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4148691/malware-trojaner-viren/ncsc-and-allies-warn-of-iranian-spyware-campaign/</guid>
<pubDate>Wed, 16 Sep 2026 11:11:10 +0200</pubDate>
<content:encoded><![CDATA[<p>The UK’s National Cyber Security Centre says Iranian Chosen Brick spyware is designed to snoop on dissidents <a href="https://www.infosecurity-magazine.com/news/ncsc-allies-warn-iranian-chosen/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[OSIRIS, eine Alternative zu Palantir?]]></title>
<description><![CDATA[Unter der URL osirisai.live nahm man im Mai diesen Jahres die Open Source OSINT-Plattform OSIRIS ans Netz. Was leistet dieses Portal? Der Artikel OSIRIS, eine Alternative zu Palantir? erschien zuerst auf TARNKAPPE.INFO Weiterlesen]]></description>
<link>https://tsecurity.de/de/4148549/malware-trojaner-viren/osiris-eine-alternative-zu-palantir/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4148549/malware-trojaner-viren/osiris-eine-alternative-zu-palantir/</guid>
<pubDate>Wed, 16 Sep 2026 11:00:27 +0200</pubDate>
<content:encoded><![CDATA[<p>Unter der URL osirisai.live nahm man im Mai diesen Jahres die Open Source OSINT-Plattform OSIRIS ans Netz. Was leistet dieses Portal? Der Artikel OSIRIS, eine Alternative zu Palantir? erschien zuerst auf TARNKAPPE.INFO <a href="https://tarnkappe.info/artikel/softwareentwicklung/osiris-eine-alternative-zu-palantir-333476.html" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[New KREMLIN Malware Installs Chrome Extensions Users Never Approved to Steal Banking Data]]></title>
<description><![CDATA[Security researchers have uncovered a Brazilian banking-malware operation named KREMLIN that secretly installs malicious extensions in Google Chrome and Microsoft Edge. The malware bypasses Chromium’s built-in extension integrity protections, making the browser load the extension as if the victim...]]></description>
<link>https://tsecurity.de/de/4148482/malware-trojaner-viren/new-kremlin-malware-installs-chrome-extensions-users-never-approved-to-steal-banking-data/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4148482/malware-trojaner-viren/new-kremlin-malware-installs-chrome-extensions-users-never-approved-to-steal-banking-data/</guid>
<pubDate>Wed, 16 Sep 2026 09:46:20 +0200</pubDate>
<content:encoded><![CDATA[<p>Security researchers have uncovered a Brazilian banking-malware operation named KREMLIN that secretly installs malicious extensions in Google Chrome and Microsoft Edge. The malware bypasses Chromium’s built-in extension integrity protections, making the browser load the extension as if the victim had installed and approved it. Elastic Security... <a href="https://cyberpress.org/kremlin-silently-hijacks-chrome/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CHOSEN BRICK Malware Lets Iranian State Hackers Steal Emails, WhatsApp and Telegram Data]]></title>
<description><![CDATA[Iranian state-linked hackers are using a Windows malware family called CHOSEN BRICK to spy on dissidents, activists, journalists, and other individuals viewed as threats to the Iranian regime. The malware has been active since at least 2025 and has targeted people in the UK, United States, Nether...]]></description>
<link>https://tsecurity.de/de/4148480/malware-trojaner-viren/chosen-brick-malware-lets-iranian-state-hackers-steal-emails-whatsapp-and-telegram-data/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4148480/malware-trojaner-viren/chosen-brick-malware-lets-iranian-state-hackers-steal-emails-whatsapp-and-telegram-data/</guid>
<pubDate>Wed, 16 Sep 2026 09:46:20 +0200</pubDate>
<content:encoded><![CDATA[<p>Iranian state-linked hackers are using a Windows malware family called CHOSEN BRICK to spy on dissidents, activists, journalists, and other individuals viewed as threats to the Iranian regime. The malware has been active since at least 2025 and has targeted people in the UK, United States, Netherlands, and other countries. A joint advisory from... <a href="https://cyberpress.org/chosen-brick-steals-messaging-data/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[PeckBirdy Malware Uses Chinese Casino and Adult Websites to Hide APT Command-and-Control]]></title>
<description><![CDATA[China-aligned advanced persistent threat (APT) groups are using low-quality Chinese-language casino and adult websites to conceal command-and-control (C2) infrastructure linked to the PeckBirdy malware framework. The tactic helps attackers blend malicious network activity into a vast ecosystem of...]]></description>
<link>https://tsecurity.de/de/4148478/malware-trojaner-viren/peckbirdy-malware-uses-chinese-casino-and-adult-websites-to-hide-apt-command-and-control/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4148478/malware-trojaner-viren/peckbirdy-malware-uses-chinese-casino-and-adult-websites-to-hide-apt-command-and-control/</guid>
<pubDate>Wed, 16 Sep 2026 09:46:20 +0200</pubDate>
<content:encoded><![CDATA[<p>China-aligned advanced persistent threat (APT) groups are using low-quality Chinese-language casino and adult websites to conceal command-and-control (C2) infrastructure linked to the PeckBirdy malware framework. The tactic helps attackers blend malicious network activity into a vast ecosystem of suspicious gambling sites that many security teams... <a href="https://cyberpress.org/peckbirdy-hides-in-casinos/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[PAPERMILL Hackers Use ISO Files to Bypass Windows Mark-of-the-Web and Deploy VenomRAT]]></title>
<description><![CDATA[A newly identified threat cluster dubbed PAPERMILL is using tax-audit phishing emails to deliver VenomRAT malware to Windows users. The campaign abuses ISO disk-image files, DLL sideloading, anti-analysis checks, and in-memory loaders to evade common security controls. JUMPSEC’s Detection and Res...]]></description>
<link>https://tsecurity.de/de/4148477/malware-trojaner-viren/papermill-hackers-use-iso-files-to-bypass-windows-mark-of-the-web-and-deploy-venomrat/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4148477/malware-trojaner-viren/papermill-hackers-use-iso-files-to-bypass-windows-mark-of-the-web-and-deploy-venomrat/</guid>
<pubDate>Wed, 16 Sep 2026 09:46:20 +0200</pubDate>
<content:encoded><![CDATA[<p>A newly identified threat cluster dubbed PAPERMILL is using tax-audit phishing emails to deliver VenomRAT malware to Windows users. The campaign abuses ISO disk-image files, DLL sideloading, anti-analysis checks, and in-memory loaders to evade common security controls. JUMPSEC’s Detection and Response Team identified the activity after a phishing... <a href="https://cyberpress.org/papermill-deploys-venomrat-via-iso/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Noodle RAT Uses Scheduled Tasks, Cron Jobs and Process Spoofing to Hide on Systems]]></title>
<description><![CDATA[Noodle RAT, also tracked as ANGRYREBEL and Nood RAT, is a modular remote access trojan used by Chinese-speaking threat actors to maintain covert access to Windows and Linux systems. Active since at least mid-2016, the malware was once incorrectly identified as a Gh0st RAT or Rekoobe variant. Rese...]]></description>
<link>https://tsecurity.de/de/4148476/malware-trojaner-viren/noodle-rat-uses-scheduled-tasks-cron-jobs-and-process-spoofing-to-hide-on-systems/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4148476/malware-trojaner-viren/noodle-rat-uses-scheduled-tasks-cron-jobs-and-process-spoofing-to-hide-on-systems/</guid>
<pubDate>Wed, 16 Sep 2026 09:46:20 +0200</pubDate>
<content:encoded><![CDATA[<p>Noodle RAT, also tracked as ANGRYREBEL and Nood RAT, is a modular remote access trojan used by Chinese-speaking threat actors to maintain covert access to Windows and Linux systems. Active since at least mid-2016, the malware was once incorrectly identified as a Gh0st RAT or Rekoobe variant. Researchers now classify it as a distinct backdoor... <a href="https://cyberpress.org/noodle-rat-hides-persistently/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Health Group Issues Alerts Over 2025 Data Breach]]></title>
<description><![CDATA[HCRG Care Group warns patients over theft of their data by Medusa ransomware hackers, 18 months after incident occurred This article has been indexed from Silicon UK Read the original article: Health Group Issues Alerts Over 2025 Data Breach The post Health Group Issues Alerts Over 2025 Data Brea...]]></description>
<link>https://tsecurity.de/de/4148472/malware-trojaner-viren/health-group-issues-alerts-over-2025-data-breach/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4148472/malware-trojaner-viren/health-group-issues-alerts-over-2025-data-breach/</guid>
<pubDate>Wed, 16 Sep 2026 09:46:12 +0200</pubDate>
<content:encoded><![CDATA[<p>HCRG Care Group warns patients over theft of their data by Medusa ransomware hackers, 18 months after incident occurred This article has been indexed from Silicon UK Read the original article: Health Group Issues Alerts Over 2025 Data Breach The post Health Group Issues Alerts Over 2025 Data Breach appeared first on IT Security News. <a href="https://www.itsecuritynews.info/health-group-issues-alerts-over-2025-data-breach/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[IT Security News Hourly Summary 2026-09-16 09h : 8 posts]]></title>
<description><![CDATA[8 posts published in the last hour 06:31CISA Warns Hackers Exploit 17 Active Directory Techniques to Gain Control of Enterprise Networks 06:31What happens when AI agent governance is missing at scale 06:31Health Group Issues Alerts Over 2025 Data Breach 06:02KREMLIN Banking Malware Bypasses Chrom...]]></description>
<link>https://tsecurity.de/de/4148471/malware-trojaner-viren/it-security-news-hourly-summary-2026-09-16-09h-8-posts/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4148471/malware-trojaner-viren/it-security-news-hourly-summary-2026-09-16-09h-8-posts/</guid>
<pubDate>Wed, 16 Sep 2026 09:46:12 +0200</pubDate>
<content:encoded><![CDATA[<p>8 posts published in the last hour 06:31CISA Warns Hackers Exploit 17 Active Directory Techniques to Gain Control of Enterprise Networks 06:31What happens when AI agent governance is missing at scale 06:31Health Group Issues Alerts Over 2025 Data Breach 06:02KREMLIN Banking Malware Bypasses Chrome Security to Steal Banking Sessions 06:02DeepZero:... <a href="https://www.itsecuritynews.info/it-security-news-hourly-summary-2026-09-16-09h-8-posts/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Hackers Disguise CHOSEN BRICK Malware as AI Apps, Antivirus Software and MRI Results]]></title>
<description><![CDATA[Iranian state-linked cyber actors are using fake AI applications, antivirus tools and even fabricated MRI scan results to deliver CHOSEN BRICK, a Windows-focused spyware family designed to surveil dissidents, activists and journalists. A joint advisory from the UK National Cyber Security Centre (...]]></description>
<link>https://tsecurity.de/de/4148470/malware-trojaner-viren/hackers-disguise-chosen-brick-malware-as-ai-apps-antivirus-software-and-mri-results/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4148470/malware-trojaner-viren/hackers-disguise-chosen-brick-malware-as-ai-apps-antivirus-software-and-mri-results/</guid>
<pubDate>Wed, 16 Sep 2026 09:46:12 +0200</pubDate>
<content:encoded><![CDATA[<p>Iranian state-linked cyber actors are using fake AI applications, antivirus tools and even fabricated MRI scan results to deliver CHOSEN BRICK, a Windows-focused spyware family designed to surveil dissidents, activists and journalists. A joint advisory from the UK National Cyber Security Centre (NCSC), the FBI and the Netherlands’ AIVD warns that... <a href="https://www.itsecuritynews.info/hackers-disguise-chosen-brick-malware-as-ai-apps-antivirus-software-and-mri-results/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[PhantomRaven: An LLM-Generated Information Stealer Developed for Bug Bounty Hunting]]></title>
<description><![CDATA[This post has no text preview — click the link below to read the original article. This article has been indexed from Blog Read the original article: PhantomRaven: An LLM-Generated Information Stealer Developed for Bug Bounty Hunting The post PhantomRaven: An LLM-Generated Information Stealer Dev...]]></description>
<link>https://tsecurity.de/de/4148468/malware-trojaner-viren/phantomraven-an-llm-generated-information-stealer-developed-for-bug-bounty-hunting/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4148468/malware-trojaner-viren/phantomraven-an-llm-generated-information-stealer-developed-for-bug-bounty-hunting/</guid>
<pubDate>Wed, 16 Sep 2026 09:46:11 +0200</pubDate>
<content:encoded><![CDATA[<p>This post has no text preview — click the link below to read the original article. This article has been indexed from Blog Read the original article: PhantomRaven: An LLM-Generated Information Stealer Developed for Bug Bounty Hunting The post PhantomRaven: An LLM-Generated Information Stealer Developed for Bug Bounty Hunting appeared first on IT... <a href="https://www.itsecuritynews.info/phantomraven-an-llm-generated-information-stealer-developed-for-bug-bounty-hunting/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Luciferus Uncensored AI Advertised on Hacker Forums for Malware and RAT Development]]></title>
<description><![CDATA[Threat actors are advertising a new “uncensored” artificial intelligence service, dubbed Luciferus, as a subscription-based assistant that can handle malware-development requests mainstream AI platforms typically reject. Sophos Counter Threat Unit (CTU) researchers identified the offering on Augu...]]></description>
<link>https://tsecurity.de/de/4148343/malware-trojaner-viren/luciferus-uncensored-ai-advertised-on-hacker-forums-for-malware-and-rat-development/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4148343/malware-trojaner-viren/luciferus-uncensored-ai-advertised-on-hacker-forums-for-malware-and-rat-development/</guid>
<pubDate>Wed, 16 Sep 2026 08:09:40 +0200</pubDate>
<content:encoded><![CDATA[<p>Threat actors are advertising a new “uncensored” artificial intelligence service, dubbed Luciferus, as a subscription-based assistant that can handle malware-development requests mainstream AI platforms typically reject. Sophos Counter Threat Unit (CTU) researchers identified the offering on August 24, 2026, in a post on the Exploit underground... <a href="https://cyberpress.org/cybercriminals-advertise-uncensored-luciferus-ai/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Luciferus Uncensored AI Service Lets Cybercriminals Generate RAT Malware]]></title>
<description><![CDATA[Cybercriminals are promoting a new “uncensored” artificial intelligence service called Luciferus that allegedly generates malicious code, including components for remote access trojans (RATs), without the safeguards typically found in mainstream AI platforms. Researchers from the Sophos Counter T...]]></description>
<link>https://tsecurity.de/de/4148340/malware-trojaner-viren/luciferus-uncensored-ai-service-lets-cybercriminals-generate-rat-malware/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4148340/malware-trojaner-viren/luciferus-uncensored-ai-service-lets-cybercriminals-generate-rat-malware/</guid>
<pubDate>Wed, 16 Sep 2026 08:09:31 +0200</pubDate>
<content:encoded><![CDATA[<p>Cybercriminals are promoting a new “uncensored” artificial intelligence service called Luciferus that allegedly generates malicious code, including components for remote access trojans (RATs), without the safeguards typically found in mainstream AI platforms. Researchers from the Sophos Counter Threat Unit reported that they first noticed a user... <a href="https://www.itsecuritynews.info/luciferus-uncensored-ai-service-lets-cybercriminals-generate-rat-malware/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[KREMLIN Banking Malware Bypasses Chrome Security to Steal Banking Sessions]]></title>
<description><![CDATA[A Brazilian banking malware operation, dubbed KREMLIN, that can silently implant malicious extensions in Google Chrome and Microsoft Edge, bypassing Chromium’s built-in integrity protections to steal credentials, cookies, and active banking sessions. Despite its name, the KREMLIN toolkit shows no...]]></description>
<link>https://tsecurity.de/de/4148337/malware-trojaner-viren/kremlin-banking-malware-bypasses-chrome-security-to-steal-banking-sessions/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4148337/malware-trojaner-viren/kremlin-banking-malware-bypasses-chrome-security-to-steal-banking-sessions/</guid>
<pubDate>Wed, 16 Sep 2026 08:09:31 +0200</pubDate>
<content:encoded><![CDATA[<p>A Brazilian banking malware operation, dubbed KREMLIN, that can silently implant malicious extensions in Google Chrome and Microsoft Edge, bypassing Chromium’s built-in integrity protections to steal credentials, cookies, and active banking sessions. Despite its name, the KREMLIN toolkit shows no apparent Russian connection. The campaign relies on... <a href="https://www.itsecuritynews.info/kremlin-banking-malware-bypasses-chrome-security-to-steal-banking-sessions/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Casbaneiro: A Banking Trojan with Distributed Data-Receiving Servers]]></title>
<description><![CDATA[2026-09-10 • Fortinet • Rachael Liao • win.metamorfo Open article on Malpedia Weiterlesen]]></description>
<link>https://tsecurity.de/de/4148279/malware-trojaner-viren/casbaneiro-a-banking-trojan-with-distributed-data-receiving-servers/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4148279/malware-trojaner-viren/casbaneiro-a-banking-trojan-with-distributed-data-receiving-servers/</guid>
<pubDate>Wed, 16 Sep 2026 08:00:11 +0200</pubDate>
<content:encoded><![CDATA[<p>2026-09-10 • Fortinet • Rachael Liao • win.metamorfo Open article on Malpedia <a href="https://malpedia.caad.fkie.fraunhofer.de/library/9ea12cca-9d3e-4bd5-8d92-ffbc91fdb1dd/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[The MRI Scan That Wasn’t: Inside Iran’s ‘Chosen Brick’ Malware Campaign Against Its Critics Abroad]]></title>
<description><![CDATA[The file looked like an MRI scan. Lumbar spine, several grey slices of vertebrae, a heading reading something like 'Disk Herniation and Degeneration.' For a dissident living in exile - someone with a body that has been through things, someone waiting on results - it was a plausible thing to open....]]></description>
<link>https://tsecurity.de/de/4148263/malware-trojaner-viren/the-mri-scan-that-wasnt-inside-irans-chosen-brick-malware-campaign-against-its-critics-abroad/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4148263/malware-trojaner-viren/the-mri-scan-that-wasnt-inside-irans-chosen-brick-malware-campaign-against-its-critics-abroad/</guid>
<pubDate>Wed, 16 Sep 2026 07:08:45 +0200</pubDate>
<content:encoded><![CDATA[<p>The file looked like an MRI scan. Lumbar spine, several grey slices of vertebrae, a heading reading something like &#039;Disk Herniation and Degeneration.&#039; For a dissident living in exile - someone with a body that has been through things, someone waiting on results - it was a plausible thing to open. Opening it handed Iranian intelligence the... <a href="https://thecyberexpress.com/inside-irans-chosen-brick-malware-campaign/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[can someone tell me if this is a virus?]]></title>
<description><![CDATA[submitted by /u/Excellent-Dealer-404 [link] [comments] Weiterlesen]]></description>
<link>https://tsecurity.de/de/4147863/malware-trojaner-viren/can-someone-tell-me-if-this-is-a-virus/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4147863/malware-trojaner-viren/can-someone-tell-me-if-this-is-a-virus/</guid>
<pubDate>Wed, 16 Sep 2026 01:30:23 +0200</pubDate>
<content:encoded><![CDATA[<p>submitted by /u/Excellent-Dealer-404 [link] [comments] <a href="https://www.reddit.com/r/MalwareAnalysis/comments/1whfdat/can_someone_tell_me_if_this_is_a_virus/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[KREMLIN-Banking-Malware missbraucht Chrome- und Edge-Erweiterungen zum Diebstahl von Zugangsdaten]]></title>
<description><![CDATA[BRAZIL / LONDON (IT BOLTWISE) – Eine bislang undokumentierte Banking-Malware aus Brasilien zielt auf Google Chrome und Microsoft Edge ab, um Zugangsdaten und Session-Tokens abzugreifen. Die Angreifer installieren dazu eine bösartige Browser-Erweiterung über eine mehrstufige JavaScript- und Instal...]]></description>
<link>https://tsecurity.de/de/4147775/malware-trojaner-viren/kremlin-banking-malware-missbraucht-chrome-und-edge-erweiterungen-zum-diebstahl-von-zugangsdaten/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4147775/malware-trojaner-viren/kremlin-banking-malware-missbraucht-chrome-und-edge-erweiterungen-zum-diebstahl-von-zugangsdaten/</guid>
<pubDate>Tue, 15 Sep 2026 23:45:13 +0200</pubDate>
<content:encoded><![CDATA[<p>BRAZIL / LONDON (IT BOLTWISE) – Eine bislang undokumentierte Banking-Malware aus Brasilien zielt auf Google Chrome und Microsoft Edge ab, um Zugangsdaten und Session-Tokens abzugreifen. Die Angreifer installieren dazu eine bösartige Browser-Erweiterung über eine mehrstufige JavaScript- und Installer-Kette. Auffällig ist die Tarnung der... <a href="https://www.it-boltwise.de/kremlin-banking-malware-missbraucht-chrome-und-edge-erweiterungen-zum-diebstahl-von-zugangsdaten.html" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[IT Security News Hourly Summary 2026-09-15 21h : 4 posts]]></title>
<description><![CDATA[4 posts published in the last hour 18:31Iranian spies hit Windows machines with Chosen Brick data-stealing malware 18:02Europol celebrates the International Day of Police Cooperation 18:02Iranian Hackers Use Telegram-Controlled Malware to Spy on Dissidents and Journalists 18:00IT Security News Ho...]]></description>
<link>https://tsecurity.de/de/4147675/malware-trojaner-viren/it-security-news-hourly-summary-2026-09-15-21h-4-posts/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4147675/malware-trojaner-viren/it-security-news-hourly-summary-2026-09-15-21h-4-posts/</guid>
<pubDate>Tue, 15 Sep 2026 22:13:23 +0200</pubDate>
<content:encoded><![CDATA[<p>4 posts published in the last hour 18:31Iranian spies hit Windows machines with Chosen Brick data-stealing malware 18:02Europol celebrates the International Day of Police Cooperation 18:02Iranian Hackers Use Telegram-Controlled Malware to Spy on Dissidents and Journalists 18:00IT Security News Hourly Summary 2026-09-15 20h : 16 posts The post IT... <a href="https://www.itsecuritynews.info/it-security-news-hourly-summary-2026-09-15-21h-4-posts/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[IT Security News Hourly Summary 2026-09-15 22h : 3 posts]]></title>
<description><![CDATA[3 posts published in the last hour 19:31Architecting resilient authentication with Amazon Cognito multi-Region replication 19:31KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session Tokens 19:00IT Security News Hourly Summary 2026-09-15 21h : 4 posts The post IT Securit...]]></description>
<link>https://tsecurity.de/de/4147673/malware-trojaner-viren/it-security-news-hourly-summary-2026-09-15-22h-3-posts/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4147673/malware-trojaner-viren/it-security-news-hourly-summary-2026-09-15-22h-3-posts/</guid>
<pubDate>Tue, 15 Sep 2026 22:13:23 +0200</pubDate>
<content:encoded><![CDATA[<p>3 posts published in the last hour 19:31Architecting resilient authentication with Amazon Cognito multi-Region replication 19:31KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session Tokens 19:00IT Security News Hourly Summary 2026-09-15 21h : 4 posts The post IT Security News Hourly Summary 2026-09-15 22h : 3 posts... <a href="https://www.itsecuritynews.info/it-security-news-hourly-summary-2026-09-15-22h-3-posts/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[KREMLIN-Banking-Malware kapert Chrome und Edge per Browser-Extension]]></title>
<description><![CDATA[LONDON (IT BOLTWISE) – Eine bislang undokumentierte Banking-Malware namens KREMLIN nutzt in Brasilien gefälschte Bank-Anzeigen und installiert eine schädliche Browser-Erweiterung für Chrome und Edge. Die Kampagne kombiniert mehrstufige JavaScript-Loader, einen C++-Installer und Anti-Sandbox-Check...]]></description>
<link>https://tsecurity.de/de/4147634/malware-trojaner-viren/kremlin-banking-malware-kapert-chrome-und-edge-per-browser-extension/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4147634/malware-trojaner-viren/kremlin-banking-malware-kapert-chrome-und-edge-per-browser-extension/</guid>
<pubDate>Tue, 15 Sep 2026 21:43:44 +0200</pubDate>
<content:encoded><![CDATA[<p>LONDON (IT BOLTWISE) – Eine bislang undokumentierte Banking-Malware namens KREMLIN nutzt in Brasilien gefälschte Bank-Anzeigen und installiert eine schädliche Browser-Erweiterung für Chrome und Edge. Die Kampagne kombiniert mehrstufige JavaScript-Loader, einen C++-Installer und Anti-Sandbox-Checks, um Credentials sowie Session Tokens abzugreifen.... <a href="https://www.it-boltwise.de/kremlin-banking-malware-kapert-chrome-und-edge-per-browser-extension.html" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Low-quality casino sites conceal highly dangerous threat actors]]></title>
<description><![CDATA[If your employees are visiting Chinese-language gambling or adult sites, they may not just be wasting time and money, but potentially encountering serious malware hidden behind domains that look like mostly harmless entertainment at first glance. A report from Infoblox urges the security communit...]]></description>
<link>https://tsecurity.de/de/4147626/malware-trojaner-viren/low-quality-casino-sites-conceal-highly-dangerous-threat-actors/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4147626/malware-trojaner-viren/low-quality-casino-sites-conceal-highly-dangerous-threat-actors/</guid>
<pubDate>Tue, 15 Sep 2026 21:40:14 +0200</pubDate>
<content:encoded><![CDATA[<p>If your employees are visiting Chinese-language gambling or adult sites, they may not just be wasting time and money, but potentially encountering serious malware hidden behind domains that look like mostly harmless entertainment at first glance. A report from Infoblox urges the security community to pay closer attention to these websites, because... <a href="https://www.theregister.com/security/2026/09/15/low-quality-casino-sites-conceal-highly-dangerous-threat-actors/5296652" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session Tokens]]></title>
<description><![CDATA[Cybersecurity researchers have shed light on a previously undocumented Brazilian banking malware operation that delivers a toolkit called KREMLIN. Elastic Security Labs is tracking the activity under the moniker REF9334. Active since at least May 2025, the threat actor has used lures that imperso...]]></description>
<link>https://tsecurity.de/de/4147623/malware-trojaner-viren/kremlin-banking-malware-hijacks-chrome-and-edge-to-steal-credentials-and-session-tokens/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4147623/malware-trojaner-viren/kremlin-banking-malware-hijacks-chrome-and-edge-to-steal-credentials-and-session-tokens/</guid>
<pubDate>Tue, 15 Sep 2026 21:40:06 +0200</pubDate>
<content:encoded><![CDATA[<p>Cybersecurity researchers have shed light on a previously undocumented Brazilian banking malware operation that delivers a toolkit called KREMLIN. Elastic Security Labs is tracking the activity under the moniker REF9334. Active since at least May 2025, the threat actor has used lures that impersonate a dozen Brazilian banks and install a malicious... <a href="https://thehackernews.com/2026/09/kremlin-banking-malware-hijacks-chrome.html" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Security Weekly - A CRA Resource: AI Agents Are Helping Both Sides]]></title>
<description><![CDATA[YouTube VideoAI agents can automate security research and defensive tasks, but similar capabilities are available to attackers. Researchers have also identified malware samples showing evidence of LLM or AI coding-tool involvement.

AI is becoming a tool used across the security landscape rather ...]]></description>
<link>https://tsecurity.de/de/4147590/malware-trojaner-viren/ai-agents-are-helping-both-sides/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4147590/malware-trojaner-viren/ai-agents-are-helping-both-sides/</guid>
<pubDate>Tue, 15 Sep 2026 21:31:38 +0200</pubDate>
<content:encoded><![CDATA[<p>YouTube Video</p><p><iframe loading="lazy" src="https://www.youtube.com/embed/YW3zq0MxFQQ"></iframe></p><div class="youtube-description">AI agents can automate security research and defensive tasks, but similar capabilities are available to attackers. Researchers have also identified malware samples showing evidence of LLM or AI coding-tool involvement.<br />
<br />
AI is becoming a tool used across the security landscape rather than something inherently defensive or offensive. Some malware has even incorporated LLM-related components to expand capabilities or perform context-aware actions.<br />
<br />
If AI tools increasingly benefit both attackers and defenders, what determines which side gains the bigger advantage?<br />
<br />
Subscribe to our podcasts: https://securityweekly.com/subscribe<br />
<br />
#Malware #SecurityWeekly #Cybersecurity #InformationSecurity #AI #InfoSec</div>]]></content:encoded>
<enclosure url="https://i2.ytimg.com/vi/YW3zq0MxFQQ/hqdefault.jpg" length="0" type="image/jpeg" />
</item>
<item>
<title><![CDATA[Could AI really wipe out humanity and hijack the internet?]]></title>
<description><![CDATA[We examine claims and counterclaims about the risks and calls to slow down the pace of AI developmentThere have been some shocking claims in recent days about AI safety: we face a 10% chance of doom; AIs are worse than nukes; a “botnet” threatens the entire internet; it’s all a big tech psyop. We...]]></description>
<link>https://tsecurity.de/de/4147546/malware-trojaner-viren/could-ai-really-wipe-out-humanity-and-hijack-the-internet/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4147546/malware-trojaner-viren/could-ai-really-wipe-out-humanity-and-hijack-the-internet/</guid>
<pubDate>Tue, 15 Sep 2026 20:52:45 +0200</pubDate>
<content:encoded><![CDATA[<p>We examine claims and counterclaims about the risks and calls to slow down the pace of AI developmentThere have been some shocking claims in recent days about AI safety: we face a 10% chance of doom; AIs are worse than nukes; a “botnet” threatens the entire internet; it’s all a big tech psyop. We look at six claims and reactions to them. Continue... <a href="https://www.theguardian.com/technology/2026/sep/15/could-ai-really-wipe-out-humanity-and-hijack-the-internet" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Malicious OpenClaw Skills Used to Distribute Atomic macOS Stealer]]></title>
<description><![CDATA[Malicious OpenClaw skills trick AI agents and users into installing a new AMOS variant that steals extensive data at scale. Weiterlesen]]></description>
<link>https://tsecurity.de/de/4147536/malware-trojaner-viren/malicious-openclaw-skills-used-to-distribute-atomic-macos-stealer/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4147536/malware-trojaner-viren/malicious-openclaw-skills-used-to-distribute-atomic-macos-stealer/</guid>
<pubDate>Tue, 15 Sep 2026 20:50:19 +0200</pubDate>
<content:encoded><![CDATA[<p>Malicious OpenClaw skills trick AI agents and users into installing a new AMOS variant that steals extensive data at scale. <a href="https://www.trendmicro.com/en_us/research/26/b/openclaw-skills-used-to-distribute-atomic-macos-stealer.html" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[HEAVYGRAM und CHOSEN BRICK: Telegram-gesteuerte Windows-Malware für Spionage]]></title>
<description><![CDATA[LONDON / LONDON (IT BOLTWISE) – Die US-, britische und niederländische Cybersecurity-Gemeinschaft beschreibt eine Windows-Malware, die über Telegram-Bots gesteuert wird. Unter den Namen HEAVYGRAM und CHOSEN BRICK soll sie eingesetzt werden, um Chatverläufe und E-Mails zu kopieren, Screenshots zu ...]]></description>
<link>https://tsecurity.de/de/4147534/malware-trojaner-viren/heavygram-und-chosen-brick-telegram-gesteuerte-windows-malware-fuer-spionage/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4147534/malware-trojaner-viren/heavygram-und-chosen-brick-telegram-gesteuerte-windows-malware-fuer-spionage/</guid>
<pubDate>Tue, 15 Sep 2026 20:49:41 +0200</pubDate>
<content:encoded><![CDATA[<p>LONDON / LONDON (IT BOLTWISE) – Die US-, britische und niederländische Cybersecurity-Gemeinschaft beschreibt eine Windows-Malware, die über Telegram-Bots gesteuert wird. Unter den Namen HEAVYGRAM und CHOSEN BRICK soll sie eingesetzt werden, um Chatverläufe und E-Mails zu kopieren, Screenshots zu erstellen und Audio über das Mikrofon aufzuzeichnen.... <a href="https://www.it-boltwise.de/heavygram-und-chosen-brick-telegram-gesteuerte-windows-malware-fuer-spionage.html" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Iranian spies hit Windows machines with Chosen Brick data-stealing malware]]></title>
<description><![CDATA[Iranian state cyber actors are targeting individuals using social messaging apps to deploy surveillance and data-stealing malware on their Windows machines, three Western governments warned. In all observed cases, Chosen Brick has infected Windows systems exclusively. Iran has used it since at le...]]></description>
<link>https://tsecurity.de/de/4147506/malware-trojaner-viren/iranian-spies-hit-windows-machines-with-chosen-brick-data-stealing-malware/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4147506/malware-trojaner-viren/iranian-spies-hit-windows-machines-with-chosen-brick-data-stealing-malware/</guid>
<pubDate>Tue, 15 Sep 2026 20:45:33 +0200</pubDate>
<content:encoded><![CDATA[<p>Iranian state cyber actors are targeting individuals using social messaging apps to deploy surveillance and data-stealing malware on their Windows machines, three Western governments warned. In all observed cases, Chosen Brick has infected Windows systems exclusively. Iran has used it since at least 2025 to take over individuals’ devices, stealing... <a href="https://www.theregister.com/security/2026/09/15/iranian-spies-hit-windows-machines-with-chosen-brick-data-stealing-malware/5296646" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Iranian Hackers Use Telegram-Controlled Malware to Spy on Dissidents and Journalists]]></title>
<description><![CDATA[Cybersecurity agencies in the United States, the United Kingdom, and the Netherlands have detailed a Windows malware that they say Iran's intelligence service uses to spy on dissidents, journalists, and activists around the world. The malware is controlled via the Telegram messaging app and can c...]]></description>
<link>https://tsecurity.de/de/4147505/malware-trojaner-viren/iranian-hackers-use-telegram-controlled-malware-to-spy-on-dissidents-and-journalists/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4147505/malware-trojaner-viren/iranian-hackers-use-telegram-controlled-malware-to-spy-on-dissidents-and-journalists/</guid>
<pubDate>Tue, 15 Sep 2026 20:45:23 +0200</pubDate>
<content:encoded><![CDATA[<p>Cybersecurity agencies in the United States, the United Kingdom, and the Netherlands have detailed a Windows malware that they say Iran&#039;s intelligence service uses to spy on dissidents, journalists, and activists around the world. The malware is controlled via the Telegram messaging app and can copy a target&#039;s emails and chat messages, take... <a href="https://thehackernews.com/2026/09/iranian-hackers-use-telegram-controlled.html" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[UK, US and Netherlands warn over Iranian state spyware campaign   ]]></title>
<description><![CDATA[Cyber attackers linked to Iran’s Ministry of Intelligence and Security are targeting opponents and opposition groups with Windows spyware   Weiterlesen]]></description>
<link>https://tsecurity.de/de/4147489/malware-trojaner-viren/uk-us-and-netherlands-warn-over-iranian-state-spyware-campaign/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4147489/malware-trojaner-viren/uk-us-and-netherlands-warn-over-iranian-state-spyware-campaign/</guid>
<pubDate>Tue, 15 Sep 2026 20:44:50 +0200</pubDate>
<content:encoded><![CDATA[<p>Cyber attackers linked to Iran’s Ministry of Intelligence and Security are targeting opponents and opposition groups with Windows spyware   <a href="https://www.computerweekly.com/news/366650300/UK-US-and-Netherlands-warn-over-Iranian-state-spyware-campaign" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Virus Bulletin: VB2025 highlights]]></title>
<description><![CDATA[YouTube VideoThree days in Berlin with some of the top professionals in cybersecurity: researchers, threat intelligence specialists, and malware analysts from around the world. This was VB2025.

We look forward to seeing you in Seville, Spain, 14 - 16 October 2026, for VB2026.
Find out more: http...]]></description>
<link>https://tsecurity.de/de/4147390/malware-trojaner-viren/vb2025-highlights/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4147390/malware-trojaner-viren/vb2025-highlights/</guid>
<pubDate>Tue, 15 Sep 2026 20:32:05 +0200</pubDate>
<content:encoded><![CDATA[<p>YouTube Video</p><p><iframe loading="lazy" src="https://www.youtube.com/embed/wBvzBfaxk4Q"></iframe></p><div class="youtube-description">Three days in Berlin with some of the top professionals in cybersecurity: researchers, threat intelligence specialists, and malware analysts from around the world. This was VB2025.<br />
<br />
We look forward to seeing you in Seville, Spain, 14 - 16 October 2026, for VB2026.<br />
Find out more: https://www.virusbulletin.com/conference/vb2026/</div>]]></content:encoded>
<enclosure url="https://i4.ytimg.com/vi/wBvzBfaxk4Q/hqdefault.jpg" length="0" type="image/jpeg" />
</item>
<item>
<title><![CDATA[Pentest bestanden und trotzdem gehackt: Wo Red Teaming und APT Simulationen mehr bieten]]></title>
<description><![CDATA[Die Firma hat den Pentest bestanden, wurde aber trotzdem gehackt? Erfahre, warum Red Teaming und APT-Simulationen die IT-Abwehr verbessern. Der Artikel Pentest bestanden und trotzdem gehackt: Wo Red Teaming und APT Simulationen mehr bieten erschien zuerst auf TARNKAPPE.INFO Weiterlesen]]></description>
<link>https://tsecurity.de/de/4147368/malware-trojaner-viren/pentest-bestanden-und-trotzdem-gehackt-wo-red-teaming-und-apt-simulationen-mehr-bieten/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4147368/malware-trojaner-viren/pentest-bestanden-und-trotzdem-gehackt-wo-red-teaming-und-apt-simulationen-mehr-bieten/</guid>
<pubDate>Tue, 15 Sep 2026 20:30:41 +0200</pubDate>
<content:encoded><![CDATA[<p>Die Firma hat den Pentest bestanden, wurde aber trotzdem gehackt? Erfahre, warum Red Teaming und APT-Simulationen die IT-Abwehr verbessern. Der Artikel Pentest bestanden und trotzdem gehackt: Wo Red Teaming und APT Simulationen mehr bieten erschien zuerst auf TARNKAPPE.INFO <a href="https://tarnkappe.info/artikel/gast-artikel/pentest-bestanden-und-trotzdem-gehackt-wo-red-teaming-und-apt-simulationen-mehr-bieten-333471.html" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[How to Keep Malware’s Rotating Infrastructure From Becoming a Detection Gap]]></title>
<description><![CDATA[You can’t detect today’s attacks with yesterday’s threat intelligence; that’s how you could briefly formulate the challenge many modern SOCs face.  Indicators lose relevance quickly. New infrastructure appears daily. SOCs struggle to keep up.  This is happening because malware campaigns increasin...]]></description>
<link>https://tsecurity.de/de/4147306/malware-trojaner-viren/how-to-keep-malwares-rotating-infrastructure-from-becoming-a-detection-gap/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4147306/malware-trojaner-viren/how-to-keep-malwares-rotating-infrastructure-from-becoming-a-detection-gap/</guid>
<pubDate>Tue, 15 Sep 2026 19:16:01 +0200</pubDate>
<content:encoded><![CDATA[<p>You can’t detect today’s attacks with yesterday’s threat intelligence; that’s how you could briefly formulate the challenge many modern SOCs face.  Indicators lose relevance quickly. New infrastructure appears daily. SOCs struggle to keep up.  This is happening because malware campaigns increasingly rely on rotating domains, hosting... <a href="https://www.itsecuritynews.info/how-to-keep-malwares-rotating-infrastructure-from-becoming-a-detection-gap/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[VectraRAT Can Hack Windows Enterprises for $250 per Month]]></title>
<description><![CDATA[The full-service malware-as-a-service (MaaS) platform offers a Windows implant, command-and-control (C2) infrastructure, and an operator panel for comprehensive remote access. Weiterlesen]]></description>
<link>https://tsecurity.de/de/4147298/malware-trojaner-viren/vectrarat-can-hack-windows-enterprises-for-250-per-month/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4147298/malware-trojaner-viren/vectrarat-can-hack-windows-enterprises-for-250-per-month/</guid>
<pubDate>Tue, 15 Sep 2026 19:12:39 +0200</pubDate>
<content:encoded><![CDATA[<p>The full-service malware-as-a-service (MaaS) platform offers a Windows implant, command-and-control (C2) infrastructure, and an operator panel for comprehensive remote access. <a href="https://www.darkreading.com/endpoint-security/vectrarat-hack-windows-enterprises" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[The extension you never installed: KREMLIN forges Chrome's own integrity checks to steal banking sessions]]></title>
<description><![CDATA[Elastic Security Labs has tracked REF9334, a Brazilian banking malware operation, since May 2025. Its toolkit is called KREMLIN (as named by the malware author, Kr3mlin4rt1st), though nothing about the operation is Russian. Lures impersonate twelve Brazilian banks; error messages and code comment...]]></description>
<link>https://tsecurity.de/de/4147136/malware-trojaner-viren/the-extension-you-never-installed-kremlin-forges-chromes-own-integrity-checks-to-steal-banking-sessions/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4147136/malware-trojaner-viren/the-extension-you-never-installed-kremlin-forges-chromes-own-integrity-checks-to-steal-banking-sessions/</guid>
<pubDate>Tue, 15 Sep 2026 18:27:28 +0200</pubDate>
<content:encoded><![CDATA[<p>Elastic Security Labs has tracked REF9334, a Brazilian banking malware operation, since May 2025. Its toolkit is called KREMLIN (as named by the malware author, Kr3mlin4rt1st), though nothing about the operation is Russian. Lures impersonate twelve Brazilian banks; error messages and code comments are written in Portuguese, and the operators&#039;... <a href="https://www.elastic.co/security-labs/threat-command/malicious-browser-extension-kremlin-banking-malware" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Hackers Advertise Uncensored Luciferus AI Service on Underground Forums]]></title>
<description><![CDATA[Hackers are advertising a new “uncensored” artificial intelligence service called Luciferus, positioning it as a subscription assistant willing to process malware-development requests that mainstream AI systems would reject. Sophos Counter Threat Unit (CTU) researchers discovered the offering on ...]]></description>
<link>https://tsecurity.de/de/4147133/malware-trojaner-viren/hackers-advertise-uncensored-luciferus-ai-service-on-underground-forums/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4147133/malware-trojaner-viren/hackers-advertise-uncensored-luciferus-ai-service-on-underground-forums/</guid>
<pubDate>Tue, 15 Sep 2026 18:26:59 +0200</pubDate>
<content:encoded><![CDATA[<p>Hackers are advertising a new “uncensored” artificial intelligence service called Luciferus, positioning it as a subscription assistant willing to process malware-development requests that mainstream AI systems would reject. Sophos Counter Threat Unit (CTU) researchers discovered the offering on August 24, 2026, on the Exploit underground forum.... <a href="https://cybersecuritynews.com/hackers-advertise-luciferus-ai-service/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[How to Keep Malware’s Rotating Infrastructure From Becoming a Detection Gap ]]></title>
<description><![CDATA[You can’t detect today’s attacks with yesterday’s threat intelligence; that’s how you could briefly formulate the challenge many modern SOCs face.  Indicators lose relevance quickly. New infrastructure appears daily. SOCs struggle to keep up.  This is happening because malware campaigns increasin...]]></description>
<link>https://tsecurity.de/de/4147131/malware-trojaner-viren/how-to-keep-malwares-rotating-infrastructure-from-becoming-a-detection-gap/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4147131/malware-trojaner-viren/how-to-keep-malwares-rotating-infrastructure-from-becoming-a-detection-gap/</guid>
<pubDate>Tue, 15 Sep 2026 18:26:58 +0200</pubDate>
<content:encoded><![CDATA[<p>You can’t detect today’s attacks with yesterday’s threat intelligence; that’s how you could briefly formulate the challenge many modern SOCs face.  Indicators lose relevance quickly. New infrastructure appears daily. SOCs struggle to keep up.  This is happening because malware campaigns increasingly rely on rotating domains, hosting... <a href="https://cybersecuritynews.com/how-to-keep-malwares-rotating-infrastructure-from-becoming-a-detection-gap/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[BambooToken Malware: MQTT-gestütztes C2 und DLL-Sideloading]]></title>
<description><![CDATA[LONDON (IT BOLTWISE) – Sicherheitsforscher beschreiben eine plattformübergreifende Malware namens BambooToken, die MQTT als Kommunikationskanal für Command-and-Control (C2) nutzt. Die Aktivität soll mindestens seit Februar 2023 andauern und laut Beobachtungen bis Juli 2026 reichen. Im Fokus stehe...]]></description>
<link>https://tsecurity.de/de/4147121/malware-trojaner-viren/bambootoken-malware-mqtt-gestuetztes-c2-und-dll-sideloading/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4147121/malware-trojaner-viren/bambootoken-malware-mqtt-gestuetztes-c2-und-dll-sideloading/</guid>
<pubDate>Tue, 15 Sep 2026 18:26:34 +0200</pubDate>
<content:encoded><![CDATA[<p>LONDON (IT BOLTWISE) – Sicherheitsforscher beschreiben eine plattformübergreifende Malware namens BambooToken, die MQTT als Kommunikationskanal für Command-and-Control (C2) nutzt. Die Aktivität soll mindestens seit Februar 2023 andauern und laut Beobachtungen bis Juli 2026 reichen. Im Fokus stehen laut den Ermittlungen Organisationen in Asien und... <a href="https://www.it-boltwise.de/bambootoken-malware-mqtt-gestuetztes-c2-und-dll-sideloading.html" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[IT Security News Hourly Summary 2026-09-15 18h : 8 posts]]></title>
<description><![CDATA[8 posts published in the last hour 15:31CISA Warns of Active GitLab Exploitation as Attackers Target Server Files 15:31MacOS 27 – First Boot, (Tue, Sep 15th) 15:31Most Fraudulent Hires Receive Credentials Before Detection 15:02Most Firms Unable to Recover Quickly from Ransomware 15:02Companies’ A...]]></description>
<link>https://tsecurity.de/de/4147104/malware-trojaner-viren/it-security-news-hourly-summary-2026-09-15-18h-8-posts/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4147104/malware-trojaner-viren/it-security-news-hourly-summary-2026-09-15-18h-8-posts/</guid>
<pubDate>Tue, 15 Sep 2026 18:26:23 +0200</pubDate>
<content:encoded><![CDATA[<p>8 posts published in the last hour 15:31CISA Warns of Active GitLab Exploitation as Attackers Target Server Files 15:31MacOS 27 – First Boot, (Tue, Sep 15th) 15:31Most Fraudulent Hires Receive Credentials Before Detection 15:02Most Firms Unable to Recover Quickly from Ransomware 15:02Companies’ AI strategies don’t account for their agentic tools... <a href="https://www.itsecuritynews.info/it-security-news-hourly-summary-2026-09-15-18h-8-posts/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Cisco FMC Flaws Give Ransomware and APTs a Path Into Internal Networks]]></title>
<description><![CDATA[Cisco Talos says attackers are exploiting FMC flaws to steal credentials, tunnel into internal networks, and deploy Qilin ransomware. This article has been indexed from eSecurity Planet Read the original article: Cisco FMC Flaws Give Ransomware and APTs a Path Into Internal Networks The post Cisc...]]></description>
<link>https://tsecurity.de/de/4147101/malware-trojaner-viren/cisco-fmc-flaws-give-ransomware-and-apts-a-path-into-internal-networks/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4147101/malware-trojaner-viren/cisco-fmc-flaws-give-ransomware-and-apts-a-path-into-internal-networks/</guid>
<pubDate>Tue, 15 Sep 2026 18:26:23 +0200</pubDate>
<content:encoded><![CDATA[<p>Cisco Talos says attackers are exploiting FMC flaws to steal credentials, tunnel into internal networks, and deploy Qilin ransomware. This article has been indexed from eSecurity Planet Read the original article: Cisco FMC Flaws Give Ransomware and APTs a Path Into Internal Networks The post Cisco FMC Flaws Give Ransomware and APTs a Path Into... <a href="https://www.itsecuritynews.info/cisco-fmc-flaws-give-ransomware-and-apts-a-path-into-internal-networks/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[BambooToken malware controls Windows and Linux systems via MQTT]]></title>
<description><![CDATA[A previously unknown malware framework called BambooToken, active since at least 2023, is now using the Message Queuing Telemetry Transport (MQTT) protocol to communicate with Windows and Linux systems. [...] Weiterlesen]]></description>
<link>https://tsecurity.de/de/4147086/malware-trojaner-viren/bambootoken-malware-controls-windows-and-linux-systems-via-mqtt/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4147086/malware-trojaner-viren/bambootoken-malware-controls-windows-and-linux-systems-via-mqtt/</guid>
<pubDate>Tue, 15 Sep 2026 18:22:31 +0200</pubDate>
<content:encoded><![CDATA[<p>A previously unknown malware framework called BambooToken, active since at least 2023, is now using the Message Queuing Telemetry Transport (MQTT) protocol to communicate with Windows and Linux systems. [...] <a href="https://www.bleepingcomputer.com/news/security/bambootoken-malware-controls-windows-and-linux-systems-via-mqtt/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[BambooToken Malware Uses MQTT to Control Windows and Linux Systems]]></title>
<description><![CDATA[Cybersecurity researchers have disclosed details of a multi-platform campaign that uses the Message Queueing Telemetry Transport (MQTT) protocol as a communication channel to control Windows and Linux systems. The emerging malware family, codenamed BambooToken, is assessed to be active since at l...]]></description>
<link>https://tsecurity.de/de/4147073/malware-trojaner-viren/bambootoken-malware-uses-mqtt-to-control-windows-and-linux-systems/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4147073/malware-trojaner-viren/bambootoken-malware-uses-mqtt-to-control-windows-and-linux-systems/</guid>
<pubDate>Tue, 15 Sep 2026 18:22:05 +0200</pubDate>
<content:encoded><![CDATA[<p>Cybersecurity researchers have disclosed details of a multi-platform campaign that uses the Message Queueing Telemetry Transport (MQTT) protocol as a communication channel to control Windows and Linux systems. The emerging malware family, codenamed BambooToken, is assessed to be active since at least February 2023 and put to use in attacks... <a href="https://thehackernews.com/2026/09/bambootoken-malware-uses-mqtt-to.html" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[KI-Pornografie: Jailbreak bringt sechs Entwickler ins Gefängnis]]></title>
<description><![CDATA[KI-Pornografie führt in China zu Haftstrafen: Sechs Entwickler umgingen Sicherheitsfilter und machten daraus ein lukratives Geschäftsmodell. Der Artikel KI-Pornografie: Jailbreak bringt sechs Entwickler ins Gefängnis erschien zuerst auf TARNKAPPE.INFO Weiterlesen]]></description>
<link>https://tsecurity.de/de/4146221/malware-trojaner-viren/ki-pornografie-jailbreak-bringt-sechs-entwickler-ins-gefaengnis/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4146221/malware-trojaner-viren/ki-pornografie-jailbreak-bringt-sechs-entwickler-ins-gefaengnis/</guid>
<pubDate>Tue, 15 Sep 2026 17:30:24 +0200</pubDate>
<content:encoded><![CDATA[<p>KI-Pornografie führt in China zu Haftstrafen: Sechs Entwickler umgingen Sicherheitsfilter und machten daraus ein lukratives Geschäftsmodell. Der Artikel KI-Pornografie: Jailbreak bringt sechs Entwickler ins Gefängnis erschien zuerst auf TARNKAPPE.INFO <a href="https://tarnkappe.info/artikel/jailbreaks/ki-pornografie-jailbreak-haftstrafen-333467.html" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Pro-Ukraine Hacking Cat Group Deploys New Malware Against Russian Targets]]></title>
<description><![CDATA[  A pro-Ukraine hacktivist group known as Hacking Cat has significantly escalated its cyber operations against Russian targets by deploying newly developed malware, marking a strategic shift from simple website defacements to sophisticated data destruction campaigns. Researchers at Kaspersky unco...]]></description>
<link>https://tsecurity.de/de/4145817/malware-trojaner-viren/pro-ukraine-hacking-cat-group-deploys-new-malware-against-russian-targets/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4145817/malware-trojaner-viren/pro-ukraine-hacking-cat-group-deploys-new-malware-against-russian-targets/</guid>
<pubDate>Tue, 15 Sep 2026 16:47:06 +0200</pubDate>
<content:encoded><![CDATA[<p>  A pro-Ukraine hacktivist group known as Hacking Cat has significantly escalated its cyber operations against Russian targets by deploying newly developed malware, marking a strategic shift from simple website defacements to sophisticated data destruction campaigns. Researchers at Kaspersky uncovered two previously undocumented malware... <a href="https://www.itsecuritynews.info/pro-ukraine-hacking-cat-group-deploys-new-malware-against-russian-targets/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Most Firms Unable to Recover Quickly from Ransomware]]></title>
<description><![CDATA[Fenix24 found only four of more than 800 clients came close to stated ransomware recovery targets of 24-48 hours Weiterlesen]]></description>
<link>https://tsecurity.de/de/4145651/malware-trojaner-viren/most-firms-unable-to-recover-quickly-from-ransomware/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4145651/malware-trojaner-viren/most-firms-unable-to-recover-quickly-from-ransomware/</guid>
<pubDate>Tue, 15 Sep 2026 16:44:35 +0200</pubDate>
<content:encoded><![CDATA[<p>Fenix24 found only four of more than 800 clients came close to stated ransomware recovery targets of 24-48 hours <a href="https://www.infosecurity-magazine.com/news/four-of-800-clients-hit-ransomware/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Ransomware-Angriff auf Berlin - Warum nun die Sicherheit der digitalen Belegschaft im ...]]></title>
<description><![CDATA[Mit ihrem Angriff auf das Netz der Berliner Landesverwaltung hat uns die Erpressergruppe Rhysida mehr als anschaulich die starke Anfälligkeit der ... Weiterlesen]]></description>
<link>https://tsecurity.de/de/4145512/malware-trojaner-viren/ransomware-angriff-auf-berlin-warum-nun-die-sicherheit-der-digitalen-belegschaft-im/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4145512/malware-trojaner-viren/ransomware-angriff-auf-berlin-warum-nun-die-sicherheit-der-digitalen-belegschaft-im/</guid>
<pubDate>Tue, 15 Sep 2026 16:43:33 +0200</pubDate>
<content:encoded><![CDATA[<p>Mit ihrem Angriff auf das Netz der Berliner Landesverwaltung hat uns die Erpressergruppe Rhysida mehr als anschaulich die starke Anfälligkeit der ... <a href="https://www.google.com/url?rct=j&amp;sa=t&amp;url=https://netzpalaver.de/2026/09/15/ransomware-angriff-auf-berlin-warum-nun-die-sicherheit-der-digitalen-belegschaft-im-zentrum-stehen-sollte/&amp;ct=ga&amp;cd=CAIyGTRiZTZmY2RmMzZhYjA0M2Y6ZGU6ZGU6REU&amp;usg=AOvVaw3QBYOA10qd6R9PskpM6_yx" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[heise & c't: LG-Smart-TVs: Forscher vergleichen Tracking mit Malware📺]]></title>
<description><![CDATA[YouTube Video]]></description>
<link>https://tsecurity.de/de/4144965/malware-trojaner-viren/lg-smart-tvs-forscher-vergleichen-tracking-mit-malware/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4144965/malware-trojaner-viren/lg-smart-tvs-forscher-vergleichen-tracking-mit-malware/</guid>
<pubDate>Tue, 15 Sep 2026 16:36:40 +0200</pubDate>
<content:encoded><![CDATA[<p>YouTube Video</p><p><iframe loading="lazy" src="https://www.youtube.com/embed/InHHCeHODls"></iframe></p>]]></content:encoded>
<enclosure url="https://i2.ytimg.com/vi/InHHCeHODls/hqdefault.jpg" length="0" type="image/jpeg" />
</item>
<item>
<title><![CDATA[Phishing Attacks Abuse Trusted Email Infrastructure and URL Cloaking to Evade Security Filters]]></title>
<description><![CDATA[Phishing operators are increasingly shifting away from malware-laden attachments and toward trusted delivery services, authenticated domains, and multi-stage URL cloaking designed to defeat conventional email inspection. The continuously running VBSpam comparative test evaluated ten public full e...]]></description>
<link>https://tsecurity.de/de/4144273/malware-trojaner-viren/phishing-attacks-abuse-trusted-email-infrastructure-and-url-cloaking-to-evade-security-filters/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4144273/malware-trojaner-viren/phishing-attacks-abuse-trusted-email-infrastructure-and-url-cloaking-to-evade-security-filters/</guid>
<pubDate>Tue, 15 Sep 2026 15:47:35 +0200</pubDate>
<content:encoded><![CDATA[<p>Phishing operators are increasingly shifting away from malware-laden attachments and toward trusted delivery services, authenticated domains, and multi-stage URL cloaking designed to defeat conventional email inspection. The continuously running VBSpam comparative test evaluated ten public full email-security products and one open-source solution... <a href="https://www.itsecuritynews.info/phishing-attacks-abuse-trusted-email-infrastructure-and-url-cloaking-to-evade-security-filters/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Ransomware Doesn’t Just Break Systems. It Breaks People.]]></title>
<description><![CDATA[The most enduring impact of ransomware attacks is human: stress, fear, job loss, and long-term consequences that rarely show up in incident reports. Weiterlesen]]></description>
<link>https://tsecurity.de/de/4144271/malware-trojaner-viren/ransomware-doesnt-just-break-systems-it-breaks-people/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4144271/malware-trojaner-viren/ransomware-doesnt-just-break-systems-it-breaks-people/</guid>
<pubDate>Tue, 15 Sep 2026 15:47:34 +0200</pubDate>
<content:encoded><![CDATA[<p>The most enduring impact of ransomware attacks is human: stress, fear, job loss, and long-term consequences that rarely show up in incident reports. <a href="https://www.securitymagazine.com/blogs/14-security-blog/post/102566-ransomware-doesnt-just-break-systems-it-breaks-people" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[eBook: Identity-First Threat Intelligence]]></title>
<description><![CDATA[Attackers increasingly bypass traditional defenses by logging in with credentials that have already been stolen, exposed, or sold on the Dark Web. As infostealer malware accelerates credential theft, organizations need greater visibility into identity risk across Active Directory, IAM, and authen...]]></description>
<link>https://tsecurity.de/de/4144139/malware-trojaner-viren/ebook-identity-first-threat-intelligence/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4144139/malware-trojaner-viren/ebook-identity-first-threat-intelligence/</guid>
<pubDate>Tue, 15 Sep 2026 15:44:58 +0200</pubDate>
<content:encoded><![CDATA[<p>Attackers increasingly bypass traditional defenses by logging in with credentials that have already been stolen, exposed, or sold on the Dark Web. As infostealer malware accelerates credential theft, organizations need greater visibility into identity risk across Active Directory, IAM, and authentication environments. Download the e-book to... <a href="https://www.helpnetsecurity.com/2026/09/15/enzoic-ebook-identity-first-threat-intelligence/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Swiss court sentences 52-year-old Ukrainian ransomware dev to nearly 13 years in the cooler]]></title>
<description><![CDATA[A Swiss court has sentenced a 52-year-old Ukrainian ransomware developer to 12 years and nine months in prison for his role in attacks on companies including Stadler Rail. Zurich District Court found that the man developed LockerGoga, MegaCortex, and Nefilim, but was not the mastermind behind the...]]></description>
<link>https://tsecurity.de/de/4143844/malware-trojaner-viren/swiss-court-sentences-52-year-old-ukrainian-ransomware-dev-to-nearly-13-years-in-the-cooler/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4143844/malware-trojaner-viren/swiss-court-sentences-52-year-old-ukrainian-ransomware-dev-to-nearly-13-years-in-the-cooler/</guid>
<pubDate>Tue, 15 Sep 2026 15:43:16 +0200</pubDate>
<content:encoded><![CDATA[<p>A Swiss court has sentenced a 52-year-old Ukrainian ransomware developer to 12 years and nine months in prison for his role in attacks on companies including Stadler Rail. Zurich District Court found that the man developed LockerGoga, MegaCortex, and Nefilim, but was not the mastermind behind the operations. He also received a ten-year ban from... <a href="https://www.theregister.com/security/2026/09/15/swiss-court-sentences-52-year-old-ukrainian-ransomware-dev-to-nearly-13-years-in-the-cooler/5296482" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[ClickFix, das gefälschte CAPTCHA, das dich die Malware selbst installieren lässt]]></title>
<description><![CDATA[Bemerkenswert ist, dass die nationalen Behörden das Phänomen ernst genommen haben, das schweizerische Bundesamt für Cybersicherheit hat bereits im ... Weiterlesen]]></description>
<link>https://tsecurity.de/de/4142677/malware-trojaner-viren/clickfix-das-gefaelschte-captcha-das-dich-die-malware-selbst-installieren-laesst/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4142677/malware-trojaner-viren/clickfix-das-gefaelschte-captcha-das-dich-die-malware-selbst-installieren-laesst/</guid>
<pubDate>Tue, 15 Sep 2026 14:46:06 +0200</pubDate>
<content:encoded><![CDATA[<p>Bemerkenswert ist, dass die nationalen Behörden das Phänomen ernst genommen haben, das schweizerische Bundesamt für Cybersicherheit hat bereits im ... <a href="https://www.google.com/url?rct=j&amp;sa=t&amp;url=https://pasqualepillitteri.it/de/news/16347/clickfix-gefaelschtes-captcha-malware&amp;ct=ga&amp;cd=CAIyGTViNmI2YzJlZTdlY2E1ZTI6ZGU6ZGU6REU&amp;usg=AOvVaw1Gf88fGCVjT46AI8kwmhaj" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[HBO Max’s verified Reddit account hijacked to spread malware]]></title>
<description><![CDATA[Cybercriminals used HBO Max’s verified Reddit account to run 108 malicious ads that tricked people into installing information stealers. This article has been indexed from Malwarebytes Read the original article: HBO Max’s verified Reddit account hijacked to spread malware The post HBO Max’s verif...]]></description>
<link>https://tsecurity.de/de/4142659/malware-trojaner-viren/hbo-maxs-verified-reddit-account-hijacked-to-spread-malware/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4142659/malware-trojaner-viren/hbo-maxs-verified-reddit-account-hijacked-to-spread-malware/</guid>
<pubDate>Tue, 15 Sep 2026 14:46:02 +0200</pubDate>
<content:encoded><![CDATA[<p>Cybercriminals used HBO Max’s verified Reddit account to run 108 malicious ads that tricked people into installing information stealers. This article has been indexed from Malwarebytes Read the original article: HBO Max’s verified Reddit account hijacked to spread malware The post HBO Max’s verified Reddit account hijacked to spread malware... <a href="https://www.itsecuritynews.info/hbo-maxs-verified-reddit-account-hijacked-to-spread-malware/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[GuardBreaker: Ein Kommentar reicht, um KI-Scanner auszutricksen]]></title>
<description><![CDATA[Eine fingierte Anfrage soll die Schutzmechanismen eines LLM auslösen und die Malware-Analyse vorzeitig stoppen. Weiterlesen]]></description>
<link>https://tsecurity.de/de/4142440/malware-trojaner-viren/guardbreaker-ein-kommentar-reicht-um-ki-scanner-auszutricksen/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4142440/malware-trojaner-viren/guardbreaker-ein-kommentar-reicht-um-ki-scanner-auszutricksen/</guid>
<pubDate>Tue, 15 Sep 2026 14:42:56 +0200</pubDate>
<content:encoded><![CDATA[<p>Eine fingierte Anfrage soll die Schutzmechanismen eines LLM auslösen und die Malware-Analyse vorzeitig stoppen. <a href="https://www.welivesecurity.com/de/business-security/guardbreaker-ein-kommentar-reicht-um-ki-scanner-auszutricksen/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[The easiest way to find and remove spyware on your Android phone]]></title>
<description><![CDATA[With Android's more open ecosystem, it's not hard to download apps that are unsafe. Here's how to scan for spyware. Weiterlesen]]></description>
<link>https://tsecurity.de/de/4142181/malware-trojaner-viren/the-easiest-way-to-find-and-remove-spyware-on-your-android-phone/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4142181/malware-trojaner-viren/the-easiest-way-to-find-and-remove-spyware-on-your-android-phone/</guid>
<pubDate>Tue, 15 Sep 2026 14:41:03 +0200</pubDate>
<content:encoded><![CDATA[<p>With Android&#039;s more open ecosystem, it&#039;s not hard to download apps that are unsafe. Here&#039;s how to scan for spyware. <a href="https://www.engadget.com/2254646/android-phone-how-to-find-remove-spyware/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[HBO Max Reddit account hijacked in PasteSwitch malware campaign]]></title>
<description><![CDATA[A compromised verified HBO Max Reddit account was used to distribute more than 100 malicious advertisements as part of a large cross-platform ClickFix campaign targeting both Windows and macOS users. Researchers at Hudson Rock and Kirk from ADAMnetworks traced the incident to a broader operation ...]]></description>
<link>https://tsecurity.de/de/4141148/malware-trojaner-viren/hbo-max-reddit-account-hijacked-in-pasteswitch-malware-campaign/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4141148/malware-trojaner-viren/hbo-max-reddit-account-hijacked-in-pasteswitch-malware-campaign/</guid>
<pubDate>Tue, 15 Sep 2026 12:46:20 +0200</pubDate>
<content:encoded><![CDATA[<p>A compromised verified HBO Max Reddit account was used to distribute more than 100 malicious advertisements as part of a large cross-platform ClickFix campaign targeting both Windows and macOS users. Researchers at Hudson Rock and Kirk from ADAMnetworks traced the incident to a broader operation they named PasteSwitch, which combines fake software... <a href="https://cyberinsider.com/hbo-max-reddit-account-hijacked-in-pasteswitch-malware-campaign/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[IT Security News Hourly Summary 2026-09-15 12h : 13 posts]]></title>
<description><![CDATA[13 posts published in the last hour 09:31PLEASE_READ_ME: The Opportunistic Ransomware Devastating MySQL Servers 09:31Hacked HBO Max Reddit Account Used for Malware Delivery via ClickFix Attack 09:31EU To Propose Social Media Restrictions For Minors 09:31Peer Pressure: Inside the Sality Botnet Dis...]]></description>
<link>https://tsecurity.de/de/4141091/malware-trojaner-viren/it-security-news-hourly-summary-2026-09-15-12h-13-posts/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4141091/malware-trojaner-viren/it-security-news-hourly-summary-2026-09-15-12h-13-posts/</guid>
<pubDate>Tue, 15 Sep 2026 12:45:50 +0200</pubDate>
<content:encoded><![CDATA[<p>13 posts published in the last hour 09:31PLEASE_READ_ME: The Opportunistic Ransomware Devastating MySQL Servers 09:31Hacked HBO Max Reddit Account Used for Malware Delivery via ClickFix Attack 09:31EU To Propose Social Media Restrictions For Minors 09:31Peer Pressure: Inside the Sality Botnet Disruption Operation 09:31Crackdown on Italian... <a href="https://www.itsecuritynews.info/it-security-news-hourly-summary-2026-09-15-12h-13-posts/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Attackers hijack HBO Max’s Reddit account for 48-hour malvertising blitz]]></title>
<description><![CDATA[Attackers compromised the verified official HBO Max Reddit account, u/hbomax, and used its trusted advertising status to launch a ClickFix campaign targeting macOS and Windows devices with information-stealing malware. Screenshot of the fraudulent ad (Source: Alex Cutts) ClickFix has been rising ...]]></description>
<link>https://tsecurity.de/de/4140960/malware-trojaner-viren/attackers-hijack-hbo-maxs-reddit-account-for-48-hour-malvertising-blitz/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4140960/malware-trojaner-viren/attackers-hijack-hbo-maxs-reddit-account-for-48-hour-malvertising-blitz/</guid>
<pubDate>Tue, 15 Sep 2026 12:43:31 +0200</pubDate>
<content:encoded><![CDATA[<p>Attackers compromised the verified official HBO Max Reddit account, u/hbomax, and used its trusted advertising status to launch a ClickFix campaign targeting macOS and Windows devices with information-stealing malware. Screenshot of the fraudulent ad (Source: Alex Cutts) ClickFix has been rising in popularity among cybercriminals. It’s a social... <a href="https://www.helpnetsecurity.com/2026/09/15/hbo-max-reddit-account-clickfix-infostealer-malware/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Hackers Abuse VSSAdmin to Extract NTDS.dit and Delete Windows Recovery Copies]]></title>
<description><![CDATA[Windows attackers are turning a built-in recovery feature into a tool for disruption. By abusing Volume Shadow Copy Service, intruders can copy protected data, access the Active Directory database, and erase recovery copies after ransomware. The technique blends into Windows activity. Backup soft...]]></description>
<link>https://tsecurity.de/de/4138204/malware-trojaner-viren/hackers-abuse-vssadmin-to-extract-ntdsdit-and-delete-windows-recovery-copies/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4138204/malware-trojaner-viren/hackers-abuse-vssadmin-to-extract-ntdsdit-and-delete-windows-recovery-copies/</guid>
<pubDate>Tue, 15 Sep 2026 11:15:50 +0200</pubDate>
<content:encoded><![CDATA[<p>Windows attackers are turning a built-in recovery feature into a tool for disruption. By abusing Volume Shadow Copy Service, intruders can copy protected data, access the Active Directory database, and erase recovery copies after ransomware. The technique blends into Windows activity. Backup software, remote management tools, and administrators... <a href="https://cybersecuritynews.com/hackers-abuse-vssadmin/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[53 Prozent mehr Cyber-Angriffe auf deutsche Unternehmen im August, Ransomware ...]]></title>
<description><![CDATA[All About Security Das Online-Magazin zu Cybersecurity (Cybersicherheit). Ransomware, Phishing · Home · News · Newsletter · Management · Netzwerke. Weiterlesen]]></description>
<link>https://tsecurity.de/de/4138124/malware-trojaner-viren/53-prozent-mehr-cyber-angriffe-auf-deutsche-unternehmen-im-august-ransomware/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4138124/malware-trojaner-viren/53-prozent-mehr-cyber-angriffe-auf-deutsche-unternehmen-im-august-ransomware/</guid>
<pubDate>Tue, 15 Sep 2026 11:15:14 +0200</pubDate>
<content:encoded><![CDATA[<p>All About Security Das Online-Magazin zu Cybersecurity (Cybersicherheit). Ransomware, Phishing · Home · News · Newsletter · Management · Netzwerke. <a href="https://www.google.com/url?rct=j&amp;sa=t&amp;url=https://www.all-about-security.de/53-prozent-mehr-cyber-angriffe-auf-deutsche-unternehmen-im-august-ransomware-nahezu-verdoppelt/&amp;ct=ga&amp;cd=CAIyGTViNmI2YzJlZTdlY2E1ZTI6ZGU6ZGU6REU&amp;usg=AOvVaw1zsGSa52JCBlqEsu1vbgwb" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[IT Security News Hourly Summary 2026-09-15 10h : 16 posts]]></title>
<description><![CDATA[16 posts published in the last hour 07:32Top 10 Best Serverless Security Solutions in 2026 07:32Amazon Looks To Expand UK Drone Deliveries 07:31Top 10 Best Cloud Infrastructure Entitlement Management (CIEM) Tools in 2026 07:31The Oracle of Delphi Will Steal Your Credentials 07:31Hackers Hijack HB...]]></description>
<link>https://tsecurity.de/de/4138117/malware-trojaner-viren/it-security-news-hourly-summary-2026-09-15-10h-16-posts/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4138117/malware-trojaner-viren/it-security-news-hourly-summary-2026-09-15-10h-16-posts/</guid>
<pubDate>Tue, 15 Sep 2026 11:15:10 +0200</pubDate>
<content:encoded><![CDATA[<p>16 posts published in the last hour 07:32Top 10 Best Serverless Security Solutions in 2026 07:32Amazon Looks To Expand UK Drone Deliveries 07:31Top 10 Best Cloud Infrastructure Entitlement Management (CIEM) Tools in 2026 07:31The Oracle of Delphi Will Steal Your Credentials 07:31Hackers Hijack HBO Max Reddit Account to Push 108 ClickFix Malware... <a href="https://www.itsecuritynews.info/it-security-news-hourly-summary-2026-09-15-10h-16-posts/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[53 Prozent mehr Cyber-Angriffe auf deutsche Unternehmen im August, Ransomware ...]]></title>
<description><![CDATA[Auch Phishing-Mails und Ransomware-Angriffe nehmen weltweit deutlich zu. Check Point Research (CPR), die Sicherheitsforschungsabteilung von Check ... Weiterlesen]]></description>
<link>https://tsecurity.de/de/4137811/malware-trojaner-viren/53-prozent-mehr-cyber-angriffe-auf-deutsche-unternehmen-im-august-ransomware/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4137811/malware-trojaner-viren/53-prozent-mehr-cyber-angriffe-auf-deutsche-unternehmen-im-august-ransomware/</guid>
<pubDate>Tue, 15 Sep 2026 11:11:16 +0200</pubDate>
<content:encoded><![CDATA[<p>Auch Phishing-Mails und Ransomware-Angriffe nehmen weltweit deutlich zu. Check Point Research (CPR), die Sicherheitsforschungsabteilung von Check ... <a href="https://www.google.com/url?rct=j&amp;sa=t&amp;url=https://www.all-about-security.de/53-prozent-mehr-cyber-angriffe-auf-deutsche-unternehmen-im-august-ransomware-nahezu-verdoppelt/&amp;ct=ga&amp;cd=CAIyGTRiZTZmY2RmMzZhYjA0M2Y6ZGU6ZGU6REU&amp;usg=AOvVaw1zsGSa52JCBlqEsu1vbgwb" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Hacked HBO Reddit Account Used for Malware Delivery via ClickFix Attack]]></title>
<description><![CDATA[Ads led to a ClickFix page designed to trick macOS and Windows users into installing malware. The post Hacked HBO Reddit Account Used for Malware Delivery via ClickFix Attack appeared first on SecurityWeek. Weiterlesen]]></description>
<link>https://tsecurity.de/de/4137784/malware-trojaner-viren/hacked-hbo-reddit-account-used-for-malware-delivery-via-clickfix-attack/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4137784/malware-trojaner-viren/hacked-hbo-reddit-account-used-for-malware-delivery-via-clickfix-attack/</guid>
<pubDate>Tue, 15 Sep 2026 11:11:02 +0200</pubDate>
<content:encoded><![CDATA[<p>Ads led to a ClickFix page designed to trick macOS and Windows users into installing malware. The post Hacked HBO Reddit Account Used for Malware Delivery via ClickFix Attack appeared first on SecurityWeek. <a href="https://www.securityweek.com/hacked-hbo-reddit-account-used-for-malware-delivery-via-clickfix-attack/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Reddit-Account von HBO Max gehackt]]></title>
<description><![CDATA[Kriminelle kaperten einen Reddit-Account und missbrauchten HBO-Max-Werbung für Malware-Angriffe. Nutzer sollten besonders wachsam sein. Weiterlesen]]></description>
<link>https://tsecurity.de/de/4137575/malware-trojaner-viren/reddit-account-von-hbo-max-gehackt/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4137575/malware-trojaner-viren/reddit-account-von-hbo-max-gehackt/</guid>
<pubDate>Tue, 15 Sep 2026 11:09:51 +0200</pubDate>
<content:encoded><![CDATA[<p>Kriminelle kaperten einen Reddit-Account und missbrauchten HBO-Max-Werbung für Malware-Angriffe. Nutzer sollten besonders wachsam sein. <a href="https://www.computerbild.de/artikel/News-Sicherheit-Reddit-Account-von-HBO-Max-gehackt-00893-dscv_Sw-41227519.html" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Marcus Hutchins: Cybersecurity Has An AI Doomer Problem.]]></title>
<description><![CDATA[YouTube VideoThe AI industry's proximity to cybersecurity is causing clueless AI doomers to flood the zone. Experts and real issues are now being drowned out by increasingly absurd cyber-apocalypse fantasies imagined by people with no real world experience. From self-replicating AI models, to tur...]]></description>
<link>https://tsecurity.de/de/4137044/malware-trojaner-viren/cybersecurity-has-an-ai-doomer-problem/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4137044/malware-trojaner-viren/cybersecurity-has-an-ai-doomer-problem/</guid>
<pubDate>Tue, 15 Sep 2026 11:02:24 +0200</pubDate>
<content:encoded><![CDATA[<p>YouTube Video</p><p><iframe loading="lazy" src="https://www.youtube.com/embed/KMf2RDC5Dyg"></iframe></p><div class="youtube-description">The AI industry&#039;s proximity to cybersecurity is causing clueless AI doomers to flood the zone. Experts and real issues are now being drowned out by increasingly absurd cyber-apocalypse fantasies imagined by people with no real world experience. From self-replicating AI models, to turning the entire internet into a botnet. The doomers are losing their minds and taking the cybersecurity industry with them.</div>]]></content:encoded>
<enclosure url="https://i4.ytimg.com/vi/KMf2RDC5Dyg/hqdefault.jpg" length="0" type="image/jpeg" />
</item>
<item>
<title><![CDATA[Suyu verabschiedet sich mit einem Knall, bietet native PC-Performance]]></title>
<description><![CDATA[Der Emulator Suyu bietet mit dem letzten Release v0.0.4 eine beinahe native PC-Performance, die vieles flüssiger laufen lässt. Der Artikel Suyu verabschiedet sich mit einem Knall, bietet native PC-Performance erschien zuerst auf TARNKAPPE.INFO Weiterlesen]]></description>
<link>https://tsecurity.de/de/4136871/malware-trojaner-viren/suyu-verabschiedet-sich-mit-einem-knall-bietet-native-pc-performance/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4136871/malware-trojaner-viren/suyu-verabschiedet-sich-mit-einem-knall-bietet-native-pc-performance/</guid>
<pubDate>Tue, 15 Sep 2026 11:00:28 +0200</pubDate>
<content:encoded><![CDATA[<p>Der Emulator Suyu bietet mit dem letzten Release v0.0.4 eine beinahe native PC-Performance, die vieles flüssiger laufen lässt. Der Artikel Suyu verabschiedet sich mit einem Knall, bietet native PC-Performance erschien zuerst auf TARNKAPPE.INFO <a href="https://tarnkappe.info/artikel/gaming/suyu-verabschiedet-sich-mit-einem-knall-bietet-native-pc-performance-333459.html" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[HBO Max Reddit Account Hijacked to Spread PasteSwitch ClickFix Malware]]></title>
<description><![CDATA[Threat actors hijacked HBO Max’s verified Reddit account, u/hbomax, and used its trusted advertising identity to distribute 108 malicious ClickFix advertisements in a coordinated 48-hour malvertising campaign. The operation, tracked as PasteSwitch, delivered platform-specific malware to macOS and...]]></description>
<link>https://tsecurity.de/de/4136452/malware-trojaner-viren/hbo-max-reddit-account-hijacked-to-spread-pasteswitch-clickfix-malware/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4136452/malware-trojaner-viren/hbo-max-reddit-account-hijacked-to-spread-pasteswitch-clickfix-malware/</guid>
<pubDate>Tue, 15 Sep 2026 09:09:18 +0200</pubDate>
<content:encoded><![CDATA[<p>Threat actors hijacked HBO Max’s verified Reddit account, u/hbomax, and used its trusted advertising identity to distribute 108 malicious ClickFix advertisements in a coordinated 48-hour malvertising campaign. The operation, tracked as PasteSwitch, delivered platform-specific malware to macOS and Windows users, including information stealers,... <a href="https://gbhackers.com/hbo-max-reddit-account-hijacked/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Hackers Abuse Windows Shadow Copies to Steal Active Directory Credentials and Kill Ransomware Recovery]]></title>
<description><![CDATA[Windows Volume Shadow Copy Service, or VSS, is designed to create point-in-time copies of files and volumes. Administrators and backup products use it to restore data after accidental deletion, corruption, or system failure. However, attackers increasingly abuse the same Windows feature to steal ...]]></description>
<link>https://tsecurity.de/de/4136433/malware-trojaner-viren/hackers-abuse-windows-shadow-copies-to-steal-active-directory-credentials-and-kill-ransomware-recovery/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4136433/malware-trojaner-viren/hackers-abuse-windows-shadow-copies-to-steal-active-directory-credentials-and-kill-ransomware-recovery/</guid>
<pubDate>Tue, 15 Sep 2026 09:09:12 +0200</pubDate>
<content:encoded><![CDATA[<p>Windows Volume Shadow Copy Service, or VSS, is designed to create point-in-time copies of files and volumes. Administrators and backup products use it to restore data after accidental deletion, corruption, or system failure. However, attackers increasingly abuse the same Windows feature to steal credentials, disrupt recovery, and prepare... <a href="https://cyberpress.org/shadow-copies-ad-stolen/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[HBO-Max-Reddit-Account gehijackt: ClickFix-Malware via fake Ads]]></title>
<description><![CDATA[LONDON (IT BOLTWISE) – Angreifer haben den offiziellen HBO-Max-Reddit-Account kompromittiert und damit ClickFix-Werbeanzeigen verteilt. Über 48 Stunden sollen laut Sicherheitsanalysen 108 bösartige Anzeigen geschaltet worden sein. Die Kampagne nutzte soziale Täuschung, bei der Opfer selbst Befehl...]]></description>
<link>https://tsecurity.de/de/4136413/malware-trojaner-viren/hbo-max-reddit-account-gehijackt-clickfix-malware-via-fake-ads/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4136413/malware-trojaner-viren/hbo-max-reddit-account-gehijackt-clickfix-malware-via-fake-ads/</guid>
<pubDate>Tue, 15 Sep 2026 09:09:10 +0200</pubDate>
<content:encoded><![CDATA[<p>LONDON (IT BOLTWISE) – Angreifer haben den offiziellen HBO-Max-Reddit-Account kompromittiert und damit ClickFix-Werbeanzeigen verteilt. Über 48 Stunden sollen laut Sicherheitsanalysen 108 bösartige Anzeigen geschaltet worden sein. Die Kampagne nutzte soziale Täuschung, bei der Opfer selbst Befehle in Windows oder macOS ausführen. Betroffen sind... <a href="https://www.it-boltwise.de/hbo-max-reddit-account-gehijackt-clickfix-malware-via-fake-ads.html" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Hackers Turn Windows Shadow Copies Into a Tool for Credential Theft and Ransomware]]></title>
<description><![CDATA[Threat actors are increasingly weaponizing Microsoft’s Volume Shadow Copy Service (VSS) for two distinct objectives: removing recovery options before ransomware deployment and extracting credential material from protected Windows files. The shift means VSS telemetry should no longer be treated as...]]></description>
<link>https://tsecurity.de/de/4136387/malware-trojaner-viren/hackers-turn-windows-shadow-copies-into-a-tool-for-credential-theft-and-ransomware/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4136387/malware-trojaner-viren/hackers-turn-windows-shadow-copies-into-a-tool-for-credential-theft-and-ransomware/</guid>
<pubDate>Tue, 15 Sep 2026 09:09:02 +0200</pubDate>
<content:encoded><![CDATA[<p>Threat actors are increasingly weaponizing Microsoft’s Volume Shadow Copy Service (VSS) for two distinct objectives: removing recovery options before ransomware deployment and extracting credential material from protected Windows files. The shift means VSS telemetry should no longer be treated as a simple backup or disk-maintenance event, but as... <a href="https://www.itsecuritynews.info/hackers-turn-windows-shadow-copies-into-a-tool-for-credential-theft-and-ransomware/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[KUMO-Domain-Recon-Tool]]></title>
<description><![CDATA[Kumo 蜘蛛 is a domain OSINT &amp; security reconnaissance framework. Drop a domain, get everything back in real time across 26 parallel modules: DNS, open ports, leaked credentials, infostealer infections, vulnerable endpoints, subdomains, CVEs, malware families, and more. Weiterlesen]]></description>
<link>https://tsecurity.de/de/4135726/malware-trojaner-viren/kumo-domain-recon-tool/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4135726/malware-trojaner-viren/kumo-domain-recon-tool/</guid>
<pubDate>Tue, 15 Sep 2026 09:04:56 +0200</pubDate>
<content:encoded><![CDATA[<p>Kumo 蜘蛛 is a domain OSINT &amp;amp; security reconnaissance framework. Drop a domain, get everything back in real time across 26 parallel modules: DNS, open ports, leaked credentials, infostealer infections, vulnerable endpoints, subdomains, CVEs, malware families, and more. <a href="https://kitploit.com/en/tools/github/karim852/kumo-domain-recon-tool" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[[Open Source] Richiesta di revisione della sicurezza e audit del codice per un locale]]></title>
<description><![CDATA[submitted by /u/zmykerd [link] [comments] Weiterlesen]]></description>
<link>https://tsecurity.de/de/4135203/malware-trojaner-viren/open-source-richiesta-di-revisione-della-sicurezza-e-audit-del-codice-per-un-locale/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4135203/malware-trojaner-viren/open-source-richiesta-di-revisione-della-sicurezza-e-audit-del-codice-per-un-locale/</guid>
<pubDate>Tue, 15 Sep 2026 09:00:15 +0200</pubDate>
<content:encoded><![CDATA[<p>submitted by /u/zmykerd [link] [comments] <a href="https://www.reddit.com/r/ExploitDev/comments/1wbrnv9/open_source_richiesta_di_revisione_della/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Hi! Dev here, I would like to help develop the PS5 jailbreak scene. How can I get started?]]></title>
<description><![CDATA[Hi everyone, I’m a developer looking to learn how PS5 exploits and homebrew work. I know C++ and C# but I'm completely new to PlayStation security.Where should I start? Any recommended write-ups, documentation, Github repos, or dev Discords to study the current exploits? Thanks! submitted by /u/s...]]></description>
<link>https://tsecurity.de/de/4135201/malware-trojaner-viren/hi-dev-here-i-would-like-to-help-develop-the-ps5-jailbreak-scene-how-can-i-get-started/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4135201/malware-trojaner-viren/hi-dev-here-i-would-like-to-help-develop-the-ps5-jailbreak-scene-how-can-i-get-started/</guid>
<pubDate>Tue, 15 Sep 2026 09:00:15 +0200</pubDate>
<content:encoded><![CDATA[<p>Hi everyone, I’m a developer looking to learn how PS5 exploits and homebrew work. I know C++ and C# but I&#039;m completely new to PlayStation security.Where should I start? Any recommended write-ups, documentation, Github repos, or dev Discords to study the current exploits? Thanks! submitted by /u/sacalaca5375 [link] [comments] <a href="https://www.reddit.com/r/ExploitDev/comments/1wbzdo5/hi_dev_here_i_would_like_to_help_develop_the_ps5/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Fortinet PPL bypass]]></title>
<description><![CDATA[hi, this is my repo, support pls https://github.com/mein-0/forti-research submitted by /u/nanaynunay [link] [comments] Weiterlesen]]></description>
<link>https://tsecurity.de/de/4135200/malware-trojaner-viren/fortinet-ppl-bypass/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4135200/malware-trojaner-viren/fortinet-ppl-bypass/</guid>
<pubDate>Tue, 15 Sep 2026 09:00:14 +0200</pubDate>
<content:encoded><![CDATA[<p>hi, this is my repo, support pls https://github.com/mein-0/forti-research submitted by /u/nanaynunay [link] [comments] <a href="https://www.reddit.com/r/ExploitDev/comments/1wcd8ec/fortinet_ppl_bypass/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[VOIDSYSCALL: Go syscall-only implant framework — 4 injection methods, 13+ anti-analysis checks, EDR handle killer, polymorphic rotation. Zero WinAPI.]]></title>
<description><![CDATA[submitted by /u/FirefighterNext360 [link] [comments] Weiterlesen]]></description>
<link>https://tsecurity.de/de/4135198/malware-trojaner-viren/voidsyscall-go-syscall-only-implant-framework-4-injection-methods-13-anti-analysis-checks-edr-handle-killer-polymorphic-rotation-zero-winapi/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4135198/malware-trojaner-viren/voidsyscall-go-syscall-only-implant-framework-4-injection-methods-13-anti-analysis-checks-edr-handle-killer-polymorphic-rotation-zero-winapi/</guid>
<pubDate>Tue, 15 Sep 2026 09:00:14 +0200</pubDate>
<content:encoded><![CDATA[<p>submitted by /u/FirefighterNext360 [link] [comments] <a href="https://www.reddit.com/r/ExploitDev/comments/1wd90wi/voidsyscall_go_syscallonly_implant_framework_4/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[AMA: Hacking macOS and offensive security with Olivia Gallucci (Datadog)]]></title>
<description><![CDATA[submitted by /u/_clickfix_ [link] [comments] Weiterlesen]]></description>
<link>https://tsecurity.de/de/4135197/malware-trojaner-viren/ama-hacking-macos-and-offensive-security-with-olivia-gallucci-datadog/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4135197/malware-trojaner-viren/ama-hacking-macos-and-offensive-security-with-olivia-gallucci-datadog/</guid>
<pubDate>Tue, 15 Sep 2026 09:00:14 +0200</pubDate>
<content:encoded><![CDATA[<p>submitted by /u/_clickfix_ [link] [comments] <a href="https://www.reddit.com/r/ExploitDev/comments/1wdpjfl/ama_hacking_macos_and_offensive_security_with/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[msi lpe poc]]></title>
<description><![CDATA[hi all, this is my repo, support pls https://github.com/mein-0/LolModapi submitted by /u/nanaynunay [link] [comments] Weiterlesen]]></description>
<link>https://tsecurity.de/de/4135196/malware-trojaner-viren/msi-lpe-poc/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4135196/malware-trojaner-viren/msi-lpe-poc/</guid>
<pubDate>Tue, 15 Sep 2026 09:00:14 +0200</pubDate>
<content:encoded><![CDATA[<p>hi all, this is my repo, support pls https://github.com/mein-0/LolModapi submitted by /u/nanaynunay [link] [comments] <a href="https://www.reddit.com/r/ExploitDev/comments/1wektqr/msi_lpe_poc/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Building a custom file scanner & encryptor (.vault) in C++. Need architecture and crypto advice! (WIP) (EN/TR)]]></title>
<description><![CDATA[submitted by /u/halitgilbaris61 [link] [comments] Weiterlesen]]></description>
<link>https://tsecurity.de/de/4135193/malware-trojaner-viren/building-a-custom-file-scanner-encryptor-vault-in-c-need-architecture-and-crypto-advice-wip-entr/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4135193/malware-trojaner-viren/building-a-custom-file-scanner-encryptor-vault-in-c-need-architecture-and-crypto-advice-wip-entr/</guid>
<pubDate>Tue, 15 Sep 2026 09:00:14 +0200</pubDate>
<content:encoded><![CDATA[<p>submitted by /u/halitgilbaris61 [link] [comments] <a href="https://www.reddit.com/r/ExploitDev/comments/1wfc2td/building_a_custom_file_scanner_encryptor_vault_in/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[🔍 ¡Cifré los procesos activos de mi sistema usando Windows DPAPI! Esto es lo que aprendí...]]></title>
<description><![CDATA[submitted by /u/Key-Explorer7633 [link] [comments] Weiterlesen]]></description>
<link>https://tsecurity.de/de/4135192/malware-trojaner-viren/cifr-los-procesos-activos-de-mi-sistema-usando-windows-dpapi-esto-es-lo-que-aprend/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4135192/malware-trojaner-viren/cifr-los-procesos-activos-de-mi-sistema-usando-windows-dpapi-esto-es-lo-que-aprend/</guid>
<pubDate>Tue, 15 Sep 2026 09:00:14 +0200</pubDate>
<content:encoded><![CDATA[<p>submitted by /u/Key-Explorer7633 [link] [comments] <a href="https://www.reddit.com/r/ExploitDev/comments/1wfkqje/cifr%C3%A9_los_procesos_activos_de_mi_sistema_usando/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[[PAID] Looking for a Reverse Engineer to Help Recover Access to Old Windows 7 Software]]></title>
<description><![CDATA[Hi everyone, I’m looking for an experienced reverse engineer who can help us recover access to an old software program used by our company. The software is Chinese, was built for Windows 7, and is quite old. Unfortunately, the Chinese company that originally developed it has gone out of business ...]]></description>
<link>https://tsecurity.de/de/4135190/malware-trojaner-viren/paid-looking-for-a-reverse-engineer-to-help-recover-access-to-old-windows-7-software/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4135190/malware-trojaner-viren/paid-looking-for-a-reverse-engineer-to-help-recover-access-to-old-windows-7-software/</guid>
<pubDate>Tue, 15 Sep 2026 09:00:14 +0200</pubDate>
<content:encoded><![CDATA[<p>Hi everyone, I’m looking for an experienced reverse engineer who can help us recover access to an old software program used by our company. The software is Chinese, was built for Windows 7, and is quite old. Unfortunately, the Chinese company that originally developed it has gone out of business and completely shut down. Because of that, we can no... <a href="https://www.reddit.com/r/ExploitDev/comments/1wfyekc/paid_looking_for_a_reverse_engineer_to_help/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Help me please with Bug in code in TokenImpersonation on C-lang]]></title>
<description><![CDATA[```c include &lt;stdio.h&gt; include &lt;windows.h&gt; include &lt;tlhelp32.h&gt; include &lt;string.h&gt; int EnablePrivilige(wchar_t str[]){ HANDLE h_token; OpenProcessToken(GetCurrentProcess(),TOKEN_QUERY | TOKEN_ADJUST_PRIVILEGES,&amp;h_token); LUID luid; LookupPrivilegeValueW(NULL,str,&amp;l...]]></description>
<link>https://tsecurity.de/de/4135188/malware-trojaner-viren/help-me-please-with-bug-in-code-in-tokenimpersonation-on-c-lang/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4135188/malware-trojaner-viren/help-me-please-with-bug-in-code-in-tokenimpersonation-on-c-lang/</guid>
<pubDate>Tue, 15 Sep 2026 09:00:14 +0200</pubDate>
<content:encoded><![CDATA[<p>```c include &amp;lt;stdio.h&amp;gt; include &amp;lt;windows.h&amp;gt; include &amp;lt;tlhelp32.h&amp;gt; include &amp;lt;string.h&amp;gt; int EnablePrivilige(wchar_t str[]){ HANDLE h_token; OpenProcessToken(GetCurrentProcess(),TOKEN_QUERY | TOKEN_ADJUST_PRIVILEGES,&amp;amp;h_token); LUID luid; LookupPrivilegeValueW(NULL,str,&amp;amp;luid); TOKEN_PRIVILEGES token_privileges;... <a href="https://www.reddit.com/r/ExploitDev/comments/1wg03gl/help_me_please_with_bug_in_code_in/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[re an old pcie driver for windows 8 was last release]]></title>
<description><![CDATA[Hey, i'm fairly new to re but need some clarification regarding whats possible and whats not, so.. in theory if i become a middle man ie windows 8 QEMU / KVM with VFIO Passthrough (Continuous Bus Log) and can figure out how the devices on real hardware interact from driver to hardware card can i ...]]></description>
<link>https://tsecurity.de/de/4135187/malware-trojaner-viren/re-an-old-pcie-driver-for-windows-8-was-last-release/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4135187/malware-trojaner-viren/re-an-old-pcie-driver-for-windows-8-was-last-release/</guid>
<pubDate>Tue, 15 Sep 2026 09:00:14 +0200</pubDate>
<content:encoded><![CDATA[<p>Hey, i&#039;m fairly new to re but need some clarification regarding whats possible and whats not, so.. in theory if i become a middle man ie windows 8 QEMU / KVM with VFIO Passthrough (Continuous Bus Log) and can figure out how the devices on real hardware interact from driver to hardware card can i effectively create my own open source version of... <a href="https://www.reddit.com/r/ExploitDev/comments/1wgcyuw/re_an_old_pcie_driver_for_windows_8_was_last/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[LockBit Ransomware — Static Reverse Engineering Writeup]]></title>
<description><![CDATA[This project originally began as a book. However, the book The Art of Obfuscation, my other publications, my academic work, and my ongoing researchs began to demand more and more of my time. Rather than keeping this work unpublished while waiting for the right moment to finish the full book, I de...]]></description>
<link>https://tsecurity.de/de/4135180/malware-trojaner-viren/lockbit-ransomware-static-reverse-engineering-writeup/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4135180/malware-trojaner-viren/lockbit-ransomware-static-reverse-engineering-writeup/</guid>
<pubDate>Tue, 15 Sep 2026 09:00:12 +0200</pubDate>
<content:encoded><![CDATA[<p>This project originally began as a book. However, the book The Art of Obfuscation, my other publications, my academic work, and my ongoing researchs began to demand more and more of my time. Rather than keeping this work unpublished while waiting for the right moment to finish the full book, I decided to release it in its current form. So, after... <a href="https://www.reddit.com/r/MalwareAnalysis/comments/1wgn6gp/lockbit_ransomware_static_reverse_engineering/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[India Orders Google to Remove 57 Firebase Sites Linked to Cyber Scams]]></title>
<description><![CDATA[  The Indian government has directed Google to take down dozens of websites and databases hosted on Firebase after finding that cybercriminals were allegedly using the platform to impersonate banks, distribute malware, and steal sensitive financial data. According to notices from the Indian Cyber...]]></description>
<link>https://tsecurity.de/de/4134805/malware-trojaner-viren/india-orders-google-to-remove-57-firebase-sites-linked-to-cyber-scams/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4134805/malware-trojaner-viren/india-orders-google-to-remove-57-firebase-sites-linked-to-cyber-scams/</guid>
<pubDate>Tue, 15 Sep 2026 03:07:56 +0200</pubDate>
<content:encoded><![CDATA[<p>  The Indian government has directed Google to take down dozens of websites and databases hosted on Firebase after finding that cybercriminals were allegedly using the platform to impersonate banks, distribute malware, and steal sensitive financial data. According to notices from the Indian Cyber Crime Coordination Centre (I4C), at least 57... <a href="https://www.itsecuritynews.info/india-orders-google-to-remove-57-firebase-sites-linked-to-cyber-scams-2/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA['Sandworm' Chains Cisco Vulnerabilities to Deploy Cyclops Blink]]></title>
<description><![CDATA[The notorious Russian threat group is spreading an upgraded version of the botnet malware, which the FBI disrupted in 2022. Weiterlesen]]></description>
<link>https://tsecurity.de/de/4134618/malware-trojaner-viren/sandworm-chains-cisco-vulnerabilities-to-deploy-cyclops-blink/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4134618/malware-trojaner-viren/sandworm-chains-cisco-vulnerabilities-to-deploy-cyclops-blink/</guid>
<pubDate>Tue, 15 Sep 2026 03:05:29 +0200</pubDate>
<content:encoded><![CDATA[<p>The notorious Russian threat group is spreading an upgraded version of the botnet malware, which the FBI disrupted in 2022. <a href="https://www.darkreading.com/cyberattacks-data-breaches/sandworm-chains-cisco-vulnerabilities-cyclops-blink" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[HBO Max Reddit account compromised to serve ClickFix attacks]]></title>
<description><![CDATA[Someone compromised the official HBO Max Reddit account and used it to push more than 100 malicious ads serving up ClickFix attacks targeting both Windows and macOS devices with information-stealing malware. A Reddit user uncovered the infostealer ads on September 6, noting that the ad showed u/h...]]></description>
<link>https://tsecurity.de/de/4134417/malware-trojaner-viren/hbo-max-reddit-account-compromised-to-serve-clickfix-attacks/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4134417/malware-trojaner-viren/hbo-max-reddit-account-compromised-to-serve-clickfix-attacks/</guid>
<pubDate>Tue, 15 Sep 2026 03:04:17 +0200</pubDate>
<content:encoded><![CDATA[<p>Someone compromised the official HBO Max Reddit account and used it to push more than 100 malicious ads serving up ClickFix attacks targeting both Windows and macOS devices with information-stealing malware. A Reddit user uncovered the infostealer ads on September 6, noting that the ad showed u/hbomax as the author — this is the verified HBO Max... <a href="https://www.theregister.com/cyber-crime/2026/09/14/hbo-max-reddit-account-compromised-to-serve-clickfix-attacks/5296408" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[OpenAI stuck fighting Musk antitrust suit after Apple finds a way out]]></title>
<description><![CDATA[Elon Musk is seemingly done attacking Apple over its decision to integrate ChatGPT into iPhone features. Back in 2024, when the partnership was first announced, Musk slammed the integration as an agreement from Apple to let OpenAI install “creepy spyware” on users’ devices. The next year, he sued...]]></description>
<link>https://tsecurity.de/de/4133427/malware-trojaner-viren/openai-stuck-fighting-musk-antitrust-suit-after-apple-finds-a-way-out/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4133427/malware-trojaner-viren/openai-stuck-fighting-musk-antitrust-suit-after-apple-finds-a-way-out/</guid>
<pubDate>Mon, 14 Sep 2026 23:41:25 +0200</pubDate>
<content:encoded><![CDATA[<p>Elon Musk is seemingly done attacking Apple over its decision to integrate ChatGPT into iPhone features. Back in 2024, when the partnership was first announced, Musk slammed the integration as an agreement from Apple to let OpenAI install “creepy spyware” on users’ devices. The next year, he sued, claiming the partnership gave the firms a... <a href="https://arstechnica.com/tech-policy/2026/09/musk-drops-apple-from-antitrust-suit-but-keeps-gunning-for-openai/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Mantax Otax Targets Android Phones With Spyware and Ransomware]]></title>
<description><![CDATA[A new Android malware can combine ransomware and spyware while tormenting victims until they pay up. Security researchers at Zimperium discovered the malware, dubbed Mantax Otax, which gives attackers several ways to exploit a single compromised device. Researchers found it can collect SMS messag...]]></description>
<link>https://tsecurity.de/de/4133170/malware-trojaner-viren/mantax-otax-targets-android-phones-with-spyware-and-ransomware/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4133170/malware-trojaner-viren/mantax-otax-targets-android-phones-with-spyware-and-ransomware/</guid>
<pubDate>Mon, 14 Sep 2026 23:39:10 +0200</pubDate>
<content:encoded><![CDATA[<p>A new Android malware can combine ransomware and spyware while tormenting victims until they pay up. Security researchers at Zimperium discovered the malware, dubbed Mantax Otax, which gives attackers several ways to exploit a single compromised device. Researchers found it can collect SMS messages, including one-time passwords, interact with... <a href="https://www.esecurityplanet.com/cybersecurity/news-mantax-otax-android-malware-apac-indonesia/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[KN-Talk am 24. September in Kiel: Cybercrime - Schutz für den Mittelstand]]></title>
<description><![CDATA[Manipulierte Rechnungen, Phishing-Mails, Erpressungstrojaner: Die Bedrohung durch Cybercrime wächst auch für kleine und mittlere Unternehmen. Weiterlesen]]></description>
<link>https://tsecurity.de/de/4132036/malware-trojaner-viren/kn-talk-am-24-september-in-kiel-cybercrime-schutz-fuer-den-mittelstand/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4132036/malware-trojaner-viren/kn-talk-am-24-september-in-kiel-cybercrime-schutz-fuer-den-mittelstand/</guid>
<pubDate>Mon, 14 Sep 2026 22:45:00 +0200</pubDate>
<content:encoded><![CDATA[<p>Manipulierte Rechnungen, Phishing-Mails, Erpressungstrojaner: Die Bedrohung durch Cybercrime wächst auch für kleine und mittlere Unternehmen. <a href="https://www.google.com/url?rct=j&amp;sa=t&amp;url=https://www.kn-online.de/schleswig-holstein/kn-talk-am-24-september-in-kiel-cybercrime-schutz-fuer-den-mittelstand-QX6VN3LLTZBCRAL2AMMMYQZBME.html&amp;ct=ga&amp;cd=CAIyGWQwOWZmNTA1ZDc3ZWYwZTQ6ZGU6ZGU6REU&amp;usg=AOvVaw0Td-PnzJM7S9vtUsY-TU52" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Hackers hijack HBO Max Reddit account to push malware in ClickFix ads]]></title>
<description><![CDATA[Hackers compromised HBO Max's official Reddit account and used it to push malicious ads that launched ClickFix attacks to infect Windows and macOS devices with information-stealing malware. [...] Weiterlesen]]></description>
<link>https://tsecurity.de/de/4131723/malware-trojaner-viren/hackers-hijack-hbo-max-reddit-account-to-push-malware-in-clickfix-ads/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4131723/malware-trojaner-viren/hackers-hijack-hbo-max-reddit-account-to-push-malware-in-clickfix-ads/</guid>
<pubDate>Mon, 14 Sep 2026 22:40:03 +0200</pubDate>
<content:encoded><![CDATA[<p>Hackers compromised HBO Max&#039;s official Reddit account and used it to push malicious ads that launched ClickFix attacks to infect Windows and macOS devices with information-stealing malware. [...] <a href="https://www.bleepingcomputer.com/news/security/hackers-hijack-hbo-max-reddit-account-to-push-malware-in-clickfix-ads/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[OpenAI's malicious bot swarm attacked RubyGems]]></title>
<description><![CDATA[OpenAI agents appear to have flooded RubyGems with malicious packages, adding to a near-daily deluge of rogue AI models engaging in potentially unlawful activity while their human creators face growing questions over responsibility for their agents’ bad behavior. A swarm of agents began uploading...]]></description>
<link>https://tsecurity.de/de/4131694/malware-trojaner-viren/openais-malicious-bot-swarm-attacked-rubygems/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4131694/malware-trojaner-viren/openais-malicious-bot-swarm-attacked-rubygems/</guid>
<pubDate>Mon, 14 Sep 2026 22:39:43 +0200</pubDate>
<content:encoded><![CDATA[<p>OpenAI agents appear to have flooded RubyGems with malicious packages, adding to a near-daily deluge of rogue AI models engaging in potentially unlawful activity while their human creators face growing questions over responsibility for their agents’ bad behavior. A swarm of agents began uploading malware to the Ruby package registry on May 5, and... <a href="https://www.theregister.com/security/2026/09/14/openais-malicious-bot-swarm-attacked-rubygems/5296356" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Cyclops Blink Evolves Into x86-64 Linux Implant With Packet Sniffing and Internal Network Scanning]]></title>
<description><![CDATA[Cyclops Blink has returned in a form that gives attackers a deeper view inside corporate networks. The malware was found on compromised Cisco Firewall Management Center devices, where it can maintain remote access, inspect traffic, and map systems behind the network edge. The activity is concerni...]]></description>
<link>https://tsecurity.de/de/4130283/malware-trojaner-viren/cyclops-blink-evolves-into-x86-64-linux-implant-with-packet-sniffing-and-internal-network-scanning/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4130283/malware-trojaner-viren/cyclops-blink-evolves-into-x86-64-linux-implant-with-packet-sniffing-and-internal-network-scanning/</guid>
<pubDate>Mon, 14 Sep 2026 19:45:06 +0200</pubDate>
<content:encoded><![CDATA[<p>Cyclops Blink has returned in a form that gives attackers a deeper view inside corporate networks. The malware was found on compromised Cisco Firewall Management Center devices, where it can maintain remote access, inspect traffic, and map systems behind the network edge. The activity is concerning because management appliances occupy trusted... <a href="https://www.itsecuritynews.info/cyclops-blink-evolves-into-x86-64-linux-implant-with-packet-sniffing-and-internal-network-scanning/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Zwei von drei Schweizer Ransomwareopfern kämpfen mit Datenverschlüsselung]]></title>
<description><![CDATA[Das Cybersecurity-Unternehmen Sophos hat seinen siebten jährlichen "State of Ransomware Report" veröffentlicht. Dieser beruht auf einer Befragung von ... Weiterlesen]]></description>
<link>https://tsecurity.de/de/4128925/malware-trojaner-viren/zwei-von-drei-schweizer-ransomwareopfern-kaempfen-mit-datenverschluesselung/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4128925/malware-trojaner-viren/zwei-von-drei-schweizer-ransomwareopfern-kaempfen-mit-datenverschluesselung/</guid>
<pubDate>Mon, 14 Sep 2026 19:16:38 +0200</pubDate>
<content:encoded><![CDATA[<p>Das Cybersecurity-Unternehmen Sophos hat seinen siebten jährlichen &quot;State of Ransomware Report&quot; veröffentlicht. Dieser beruht auf einer Befragung von ... <a href="https://www.google.com/url?rct=j&amp;sa=t&amp;url=https://www.swisscybersecurity.net/news/2026-09-14/zwei-von-drei-schweizer-ransomwareopfern-kaempfen-mit-datenverschluesselung&amp;ct=ga&amp;cd=CAIyGTRiZTZmY2RmMzZhYjA0M2Y6ZGU6ZGU6REU&amp;usg=AOvVaw2Ogc_hGLDeOVH_r5Qtt1An" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Weshalb guter Ransomware-Schutz für Backups nicht nur Daten schützt, sondern auch das ...]]></title>
<description><![CDATA[Grau Data hat deshalb einen standardisierten Repository-Security-Check für Windows entwickelt. In rund 15 Minuten werden dabei sieben typische ... Weiterlesen]]></description>
<link>https://tsecurity.de/de/4128919/malware-trojaner-viren/weshalb-guter-ransomware-schutz-fuer-backups-nicht-nur-daten-schuetzt-sondern-auch-das/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4128919/malware-trojaner-viren/weshalb-guter-ransomware-schutz-fuer-backups-nicht-nur-daten-schuetzt-sondern-auch-das/</guid>
<pubDate>Mon, 14 Sep 2026 19:16:33 +0200</pubDate>
<content:encoded><![CDATA[<p>Grau Data hat deshalb einen standardisierten Repository-Security-Check für Windows entwickelt. In rund 15 Minuten werden dabei sieben typische ... <a href="https://www.google.com/url?rct=j&amp;sa=t&amp;url=https://netzpalaver.de/2026/09/14/weshalb-guter-ransomware-schutz-fuer-backups-nicht-nur-daten-schuetzt-sondern-auch-das-repository-prueft/&amp;ct=ga&amp;cd=CAIyGTRiZTZmY2RmMzZhYjA0M2Y6ZGU6ZGU6REU&amp;usg=AOvVaw1IQLKeqRmocQhOQW3Hxxza" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[This LG TV jailbreak turns smart devices into spies, say researchers]]></title>
<description><![CDATA[Researchers say LG TV’s behavior ‘parallels malware’ – with user data logged even when TVs are on standby. Weiterlesen]]></description>
<link>https://tsecurity.de/de/4128573/malware-trojaner-viren/this-lg-tv-jailbreak-turns-smart-devices-into-spies-say-researchers/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4128573/malware-trojaner-viren/this-lg-tv-jailbreak-turns-smart-devices-into-spies-say-researchers/</guid>
<pubDate>Mon, 14 Sep 2026 19:08:55 +0200</pubDate>
<content:encoded><![CDATA[<p>Researchers say LG TV’s behavior ‘parallels malware’ – with user data logged even when TVs are on standby. <a href="https://www.zdnet.com/uncategorized/lg-tv-can-spy-on-you-say-researchers-how-to-prevent-it/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[WhatsApp-Warnung: Ein einziger Code reicht - dann schreiben Fremde in eurem Namen]]></title>
<description><![CDATA[Ein unbedachter Klick oder ein weitergeleiteter Code und schon übernehmen Fremde euer WhatsApp-Konto. So funktioniert die fiese Masche und so schützt ihr euch. Dieser Artikel wurde einsortiert unter Datenschutz, Schutz vor Malware, Trojanern &amp; Spyware, Aktuelle Betrugswarnungen. Weiterlesen]]></description>
<link>https://tsecurity.de/de/4128498/malware-trojaner-viren/whatsapp-warnung-ein-einziger-code-reicht-dann-schreiben-fremde-in-eurem-namen/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4128498/malware-trojaner-viren/whatsapp-warnung-ein-einziger-code-reicht-dann-schreiben-fremde-in-eurem-namen/</guid>
<pubDate>Mon, 14 Sep 2026 19:06:13 +0200</pubDate>
<content:encoded><![CDATA[<p>Ein unbedachter Klick oder ein weitergeleiteter Code und schon übernehmen Fremde euer WhatsApp-Konto. So funktioniert die fiese Masche und so schützt ihr euch. Dieser Artikel wurde einsortiert unter Datenschutz, Schutz vor Malware, Trojanern &amp;amp; Spyware, Aktuelle Betrugswarnungen. <a href="https://www.netzwelt.de/news/258539-whatsapp-warnung-einziger-code-reichtdann-schreiben-fremde-eurem-namen.html" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Bits und so #1024 (true ]]></title>
<description><![CDATA[News

iPhone Duo
iPhone Lineup
iPhone Duo Folio
Duo HIG
Telekom Handoff MultiSIM
Apple Developer Videos
Keynote Background Action
Beats Game Controller
LG Smart TV Spyware
Sonos 27

Picks

Timo: Moves Significant Locations
Alex: Shareshot 2
Leo: iOS/Android eSIM-Transfer
Basti: Phogs Hundespiel

...]]></description>
<link>https://tsecurity.de/de/4127893/malware-trojaner-viren/bits-und-so-1024-true/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4127893/malware-trojaner-viren/bits-und-so-1024-true/</guid>
<pubDate>Mon, 14 Sep 2026 19:01:22 +0200</pubDate>
<content:encoded><![CDATA[<h3>News</h3>
<ul>
<li><a href="https://www.apple.com/iphone-duo/">iPhone Duo</a></li>
<li><a href="https://www.apple.com/iphone/compare/">iPhone Lineup</a></li>
<li><a href="https://www.apple.com/de/shop/product/mkr64zm/a/iphone-duo-folio-mit-standfu%C3%9F-taupe">iPhone Duo Folio</a></li>
<li><a href="https://developer.apple.com/design/human-interface-guidelines/designing-for-iphone-duo">Duo HIG</a></li>
<li><a href="https://www.telekom.com/de/newsroom/aktuelles/medieninformationen/2026/09/iphone-handoff-bei-der-telekom">Telekom Handoff MultiSIM</a></li>
<li><a href="https://developer.apple.com/videos/play/tech-talks/111462/">Apple Developer Videos</a></li>
<li><a href="https://www.apple.com/apple-events/">Keynote Background Action</a></li>
<li>Beats Game Controller</li>
<li><a href="https://youtu.be/6IFVTcM28KA">LG Smart TV Spyware</a></li>
<li><a href="https://newsroom.sonos.com/270206-sonos-27-adds-ai-control-new-ways-to-move-sound-and-an-easier-app-experience-to-your-sonos-system/">Sonos 27</a></li>
</ul>
<h3>Picks</h3>
<ul>
<li>Timo: <a href="https://extremelysuccessfulapps.com/#apps">Moves Significant Locations</a></li>
<li>Alex: <a href="https://shareshot.app/blog/Release-2.0.html">Shareshot 2</a></li>
<li>Leo: <a href="https://support.apple.com/de-de/126058">iOS/Android eSIM-Transfer</a></li>
<li>Basti: <a href="https://playphogs.com/">Phogs</a> Hundespiel</li>
</ul>
<h3>Pre-Postshow</h3>
<ul>
<li>Diese Woche 40 Minuten Bonus-Content mit <a href="https://bitsundso.plus/">Bits und so Plus</a></li>
<li>Merch</li>
<li><a href="https://www.dhl.de/de/geschaeftskunden/paket/leistungen-und-services/energiezuschlag.html">DHL Ölzuschlag</a></li>
<li>TechniSat interaktives Fernsehen</li>
<li><a href="https://www.samsung.com/de/smartphones/galaxy-z-fold8/buy/">Samsung Z Fold8</a></li>
</ul>]]></content:encoded>
</item>
<item>
<title><![CDATA[SilentNet Malware]]></title>
<description><![CDATA[I need help decrypting main.py and app.pyd. They are both dropped by loader.exe. (launcher.dll and mod.jar are different files that I put in the sample section. They’re the same malware, just in a different format. I want to focus on the .exe, though.) Sample: "gofile.io/d/Y8Lt02gq" (password: in...]]></description>
<link>https://tsecurity.de/de/4127816/malware-trojaner-viren/silentnet-malware/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4127816/malware-trojaner-viren/silentnet-malware/</guid>
<pubDate>Mon, 14 Sep 2026 19:00:38 +0200</pubDate>
<content:encoded><![CDATA[<p>I need help decrypting main.py and app.pyd. They are both dropped by loader.exe. (launcher.dll and mod.jar are different files that I put in the sample section. They’re the same malware, just in a different format. I want to focus on the .exe, though.) Sample: &quot;gofile.io/d/Y8Lt02gq&quot; (password: infected) My Triage report:... <a href="https://www.reddit.com/r/MalwareAnalysis/comments/1wg6qb0/silentnet_malware/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[PS Plus, Game Pass: 41 % der befragten US-Gamer kündigen wegen hoher Preise]]></title>
<description><![CDATA[Bei einer US-Umfrage gaben mehr als 40 % an, dass sie Abo-Dienste wie PS Plus &amp; Co. wegen den überzogenen Preisen gekündigt haben. Der Artikel PS Plus, Game Pass: 41 % der befragten US-Gamer kündigen wegen hoher Preise erschien zuerst auf TARNKAPPE.INFO Weiterlesen]]></description>
<link>https://tsecurity.de/de/4127812/malware-trojaner-viren/ps-plus-game-pass-41-der-befragten-us-gamer-kuendigen-wegen-hoher-preise/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4127812/malware-trojaner-viren/ps-plus-game-pass-41-der-befragten-us-gamer-kuendigen-wegen-hoher-preise/</guid>
<pubDate>Mon, 14 Sep 2026 19:00:35 +0200</pubDate>
<content:encoded><![CDATA[<p>Bei einer US-Umfrage gaben mehr als 40 % an, dass sie Abo-Dienste wie PS Plus &amp;amp; Co. wegen den überzogenen Preisen gekündigt haben. Der Artikel PS Plus, Game Pass: 41 % der befragten US-Gamer kündigen wegen hoher Preise erschien zuerst auf TARNKAPPE.INFO <a href="https://tarnkappe.info/artikel/gaming/ps-plus-game-pass-41-der-befragten-us-gamer-kuendigen-wegen-hoher-preise-333445.html" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Switch-Piraterie: Gericht kippt Verkauf von Umgehungs-Hardware]]></title>
<description><![CDATA[Switch-Piraterie: Ein niederländisches Gericht untersagt einem Händler den Verkauf von MIG Switch Cards und weiterer Umgehungshardware. Der Artikel Switch-Piraterie: Gericht kippt Verkauf von Umgehungs-Hardware erschien zuerst auf TARNKAPPE.INFO Weiterlesen]]></description>
<link>https://tsecurity.de/de/4127811/malware-trojaner-viren/switch-piraterie-gericht-kippt-verkauf-von-umgehungs-hardware/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4127811/malware-trojaner-viren/switch-piraterie-gericht-kippt-verkauf-von-umgehungs-hardware/</guid>
<pubDate>Mon, 14 Sep 2026 19:00:35 +0200</pubDate>
<content:encoded><![CDATA[<p>Switch-Piraterie: Ein niederländisches Gericht untersagt einem Händler den Verkauf von MIG Switch Cards und weiterer Umgehungshardware. Der Artikel Switch-Piraterie: Gericht kippt Verkauf von Umgehungs-Hardware erschien zuerst auf TARNKAPPE.INFO <a href="https://tarnkappe.info/artikel/rechtssachen/switch-piraterie-mig-switch-hardware-gericht-333443.html" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[heise & c't: LG-Smart-TVs: Forscher vergleichen Tracking mit Malware]]></title>
<description><![CDATA[YouTube VideoSicherheitsforscher vergleichen das Tracking auf LG-Smart-TVs mit Malware – LG widerspricht und erklärt, welche Funktionen nur nach Zustimmung aktiv werden. Wir schauen uns an, was ACR tatsächlich erfasst, was an den Vorwürfen dran ist und wie ihr Tracking auf eurem Fernseher abschal...]]></description>
<link>https://tsecurity.de/de/4126600/malware-trojaner-viren/lg-smart-tvs-forscher-vergleichen-tracking-mit-malware/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4126600/malware-trojaner-viren/lg-smart-tvs-forscher-vergleichen-tracking-mit-malware/</guid>
<pubDate>Mon, 14 Sep 2026 14:31:55 +0200</pubDate>
<content:encoded><![CDATA[<p>YouTube Video</p><p><iframe loading="lazy" src="https://www.youtube.com/embed/tijR-Pc9FZY"></iframe></p><div class="youtube-description">Sicherheitsforscher vergleichen das Tracking auf LG-Smart-TVs mit Malware – LG widerspricht und erklärt, welche Funktionen nur nach Zustimmung aktiv werden. Wir schauen uns an, was ACR tatsächlich erfasst, was an den Vorwürfen dran ist und wie ihr Tracking auf eurem Fernseher abschalten könnt.<br />
<br />
=== Anzeige / Sponsorenhinweis === <br />
Mit Mammouth bekommt ihr Zugriff auf KI-Modelle wie GPT, Claude, Gemini, Mistral, Grok, DeepSeek, Perplexity, Flux, Nano Banana und Recraft – alles vereint an einem Ort. Alles im Starterpaket brutto ab 11,90€ / Monat bei monatlicher Laufzeit oder 9,92€ / Monat bei jährlicher Laufzeit mit Vorauszahlung. Mehr Infos: http://mammouth.ai<br />
=== Anzeige / Sponsorenhinweis Ende ===<br />
<br />
► Zum Artikel: https://heise.de/s/Z7Wbd<br />
<br />
► Kapitelmarken: <br />
00:00 Trackt euer Fernseher euch?<br />
00:28 Die Vorwürfe gegen LG<br />
01:18 Sicherheitslücken in webOS<br />
01:44 WERBUNG<br />
02:44 LG widerspricht den Vorwürfen<br />
04:13 Was bleibt von den Vorwürfen?<br />
04:59 So schützt ihr euch vor TV-Tracking<br />
05:32 Fazit<br />
_____<br />
<br />
► Mitdiskutieren auf dem heise &amp; c’t Discord-Server: https://discord.gg/Wf6ewnWpxH<br />
► c’t: https://www.ct.de<br />
► heise online: https://www.heise.de<br />
► heise online auf Instagram: https://www.instagram.com/heiseonline/<br />
► c&#039;t auf Instagram: https://www.instagram.com/ct_magazin/<br />
_____<br />
Redaktion &amp; Video: Malte Kirchner</div>]]></content:encoded>
<enclosure url="https://i1.ytimg.com/vi/tijR-Pc9FZY/hqdefault.jpg" length="0" type="image/jpeg" />
</item>
<item>
<title><![CDATA[BabylonRat Technical Analysis Report]]></title>
<description><![CDATA[2026-09-07 • Github (Yavuzhanzgen) • Yavuzhan Özgen • win.babylon_rat Open article on Malpedia Weiterlesen]]></description>
<link>https://tsecurity.de/de/4126304/malware-trojaner-viren/babylonrat-technical-analysis-report/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4126304/malware-trojaner-viren/babylonrat-technical-analysis-report/</guid>
<pubDate>Mon, 14 Sep 2026 14:30:40 +0200</pubDate>
<content:encoded><![CDATA[<p>2026-09-07 • Github (Yavuzhanzgen) • Yavuzhan Özgen • win.babylon_rat Open article on Malpedia <a href="https://malpedia.caad.fkie.fraunhofer.de/library/43df0fb2-2f59-4a57-94ef-ed7bcbd5d977/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[SpiderCat: Neue Methode erleichtert den Kindle-Jailbreak]]></title>
<description><![CDATA[SpiderCat erlaubt den Jailbreak vieler Kindle-Reader auf den verschiedensten Geräten. Dafür lädt man nur ein präpariertes E-Book herunter. Der Artikel SpiderCat: Neue Methode erleichtert den Kindle-Jailbreak erschien zuerst auf TARNKAPPE.INFO Weiterlesen]]></description>
<link>https://tsecurity.de/de/4121833/malware-trojaner-viren/spidercat-neue-methode-erleichtert-den-kindle-jailbreak/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4121833/malware-trojaner-viren/spidercat-neue-methode-erleichtert-den-kindle-jailbreak/</guid>
<pubDate>Mon, 14 Sep 2026 12:00:32 +0200</pubDate>
<content:encoded><![CDATA[<p>SpiderCat erlaubt den Jailbreak vieler Kindle-Reader auf den verschiedensten Geräten. Dafür lädt man nur ein präpariertes E-Book herunter. Der Artikel SpiderCat: Neue Methode erleichtert den Kindle-Jailbreak erschien zuerst auf TARNKAPPE.INFO <a href="https://tarnkappe.info/artikel/e-books/spidercat-neue-methode-erleichtert-den-kindle-jailbreak-333437.html" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Windows 11: Microsoft entfernt WMIC-Tool gegen Ransomware - ad-hoc-news.de]]></title>
<description><![CDATA[Ein minimalistischer, modern gestalteter Serverraum-Flur mit kühler Beleuchtung und klaren architektonischen Linien. Illustration mit AI erstellt. Weiterlesen]]></description>
<link>https://tsecurity.de/de/4120373/malware-trojaner-viren/windows-11-microsoft-entfernt-wmic-tool-gegen-ransomware-ad-hoc-newsde/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4120373/malware-trojaner-viren/windows-11-microsoft-entfernt-wmic-tool-gegen-ransomware-ad-hoc-newsde/</guid>
<pubDate>Mon, 14 Sep 2026 10:47:18 +0200</pubDate>
<content:encoded><![CDATA[<p>Ein minimalistischer, modern gestalteter Serverraum-Flur mit kühler Beleuchtung und klaren architektonischen Linien. Illustration mit AI erstellt. <a href="https://www.google.com/url?rct=j&amp;sa=t&amp;url=https://www.ad-hoc-news.de/wissenschaft/windows-11-microsoft-entfernt-wmic-tool-gegen-ransomware/70097138&amp;ct=ga&amp;cd=CAIyGWE4YWZlOWE1ODU5MTM3YjQ6ZGU6ZGU6REU&amp;usg=AOvVaw3mnf-xzCTf9odEiWUlaIGp" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[StealC Stealer – RuntimeBroker Hollowing, C2 Extraction & Payload Extraction]]></title>
<description><![CDATA[submitted by /u/StructBreaker [link] [comments] Weiterlesen]]></description>
<link>https://tsecurity.de/de/4120297/malware-trojaner-viren/stealc-stealer-runtimebroker-hollowing-c2-extraction-payload-extraction/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4120297/malware-trojaner-viren/stealc-stealer-runtimebroker-hollowing-c2-extraction-payload-extraction/</guid>
<pubDate>Mon, 14 Sep 2026 10:46:08 +0200</pubDate>
<content:encoded><![CDATA[<p>submitted by /u/StructBreaker [link] [comments] <a href="https://www.reddit.com/r/ReverseEngineering/comments/1wfwpk9/stealc_stealer_runtimebroker_hollowing_c2/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker]]></title>
<description><![CDATA[Hackers are turning ordinary searches and gaming videos into malware traps. A long-running campaign used YouTube channels and search-engine manipulation to steer victims toward installers that looked like useful software, game tools or performance fixes. The activity is tied to a pay-per-install ...]]></description>
<link>https://tsecurity.de/de/4120029/malware-trojaner-viren/hackers-abuse-youtube-gaming-channels-and-seo-poisoning-to-deploy-rats-and-chrome-hijacker/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4120029/malware-trojaner-viren/hackers-abuse-youtube-gaming-channels-and-seo-poisoning-to-deploy-rats-and-chrome-hijacker/</guid>
<pubDate>Mon, 14 Sep 2026 10:42:06 +0200</pubDate>
<content:encoded><![CDATA[<p>Hackers are turning ordinary searches and gaming videos into malware traps. A long-running campaign used YouTube channels and search-engine manipulation to steer victims toward installers that looked like useful software, game tools or performance fixes. The activity is tied to a pay-per-install operation known as CL-CRI-1171. This model gives... <a href="https://cybersecuritynews.com/hackers-abuse-youtube-gaming/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[IT Security News Hourly Summary 2026-09-14 08h : 4 posts]]></title>
<description><![CDATA[4 posts published in the last hour 05:31Cybersecurity attention fades within months after a breach 05:31AsyncRAT Malware Abuses AutoIt and PowerShell to Hide Inside Legitimate Windows Process 05:02Drug trafficking investigation leads to some of the world’s biggest underground bankers 05:01Certifi...]]></description>
<link>https://tsecurity.de/de/4118860/malware-trojaner-viren/it-security-news-hourly-summary-2026-09-14-08h-4-posts/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4118860/malware-trojaner-viren/it-security-news-hourly-summary-2026-09-14-08h-4-posts/</guid>
<pubDate>Mon, 14 Sep 2026 10:14:38 +0200</pubDate>
<content:encoded><![CDATA[<p>4 posts published in the last hour 05:31Cybersecurity attention fades within months after a breach 05:31AsyncRAT Malware Abuses AutoIt and PowerShell to Hide Inside Legitimate Windows Process 05:02Drug trafficking investigation leads to some of the world’s biggest underground bankers 05:01Certificate failures can cost firms over $250,000 The post... <a href="https://www.itsecuritynews.info/it-security-news-hourly-summary-2026-09-14-08h-4-posts/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[AsyncRAT Technical Analysis]]></title>
<description><![CDATA[2026-08-17 • Github (Yavuzhanzgen) • Yavuzhan Özgen • win.asyncrat Open article on Malpedia Weiterlesen]]></description>
<link>https://tsecurity.de/de/4117747/malware-trojaner-viren/asyncrat-technical-analysis/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4117747/malware-trojaner-viren/asyncrat-technical-analysis/</guid>
<pubDate>Mon, 14 Sep 2026 10:00:31 +0200</pubDate>
<content:encoded><![CDATA[<p>2026-08-17 • Github (Yavuzhanzgen) • Yavuzhan Özgen • win.asyncrat Open article on Malpedia <a href="https://malpedia.caad.fkie.fraunhofer.de/library/a650236b-4c09-4fea-a1ec-c391dbad8fe2/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[The ToxicPanda Never Sleeps: ToxicPanda 2.0 Prepares its Next Strike on Mobile]]></title>
<description><![CDATA[2026-08-19 • zimperium • Vishnu Pratapagiri • apk.toxic_panda Open article on Malpedia Weiterlesen]]></description>
<link>https://tsecurity.de/de/4117746/malware-trojaner-viren/the-toxicpanda-never-sleeps-toxicpanda-20-prepares-its-next-strike-on-mobile/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4117746/malware-trojaner-viren/the-toxicpanda-never-sleeps-toxicpanda-20-prepares-its-next-strike-on-mobile/</guid>
<pubDate>Mon, 14 Sep 2026 10:00:31 +0200</pubDate>
<content:encoded><![CDATA[<p>2026-08-19 • zimperium • Vishnu Pratapagiri • apk.toxic_panda Open article on Malpedia <a href="https://malpedia.caad.fkie.fraunhofer.de/library/b6fd91f9-a9c8-4560-b0a9-99ba9a0f3f55/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[ScreenConnect Client Technical Analysis]]></title>
<description><![CDATA[2026-08-27 • Github (Yavuzhanzgen) • Yavuzhan Özgen Open article on Malpedia Weiterlesen]]></description>
<link>https://tsecurity.de/de/4117745/malware-trojaner-viren/screenconnect-client-technical-analysis/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4117745/malware-trojaner-viren/screenconnect-client-technical-analysis/</guid>
<pubDate>Mon, 14 Sep 2026 10:00:31 +0200</pubDate>
<content:encoded><![CDATA[<p>2026-08-27 • Github (Yavuzhanzgen) • Yavuzhan Özgen Open article on Malpedia <a href="https://malpedia.caad.fkie.fraunhofer.de/library/2294ebb4-a26f-4acb-83a1-45db6482187e/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Koktevrat – wieloetapowy Android RAT dystrybuowany pod przykrywką aplikacji MandatGO]]></title>
<description><![CDATA[2026-09-09 • Ireneusz Tarnowski • apk.koktevrat Open article on Malpedia Weiterlesen]]></description>
<link>https://tsecurity.de/de/4117743/malware-trojaner-viren/koktevrat-wieloetapowy-android-rat-dystrybuowany-pod-przykrywk-aplikacji-mandatgo/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4117743/malware-trojaner-viren/koktevrat-wieloetapowy-android-rat-dystrybuowany-pod-przykrywk-aplikacji-mandatgo/</guid>
<pubDate>Mon, 14 Sep 2026 10:00:30 +0200</pubDate>
<content:encoded><![CDATA[<p>2026-09-09 • Ireneusz Tarnowski • apk.koktevrat Open article on Malpedia <a href="https://malpedia.caad.fkie.fraunhofer.de/library/a740b0ae-1210-46b1-948d-f94d5e900d25/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[ShinyHunters breaches Florida DMV, OpenAI agents flood code repository with malware, Airlines dodge paying for cyber delays]]></title>
<description><![CDATA[Host David Shipley covers multiple cyber stories: Florida confirmed criminals breached its DMV using credentials from a Plant City police officer that were improperly stored on a personal device; ShinyHunters claimed responsibility and the full scope remains unknown. IDScan also confirmed attacke...]]></description>
<link>https://tsecurity.de/de/4116965/malware-trojaner-viren/shinyhunters-breaches-florida-dmv-openai-agents-flood-code-repository-with-malware-airlines-dodge-paying-for-cyber-delays/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4116965/malware-trojaner-viren/shinyhunters-breaches-florida-dmv-openai-agents-flood-code-repository-with-malware-airlines-dodge-paying-for-cyber-delays/</guid>
<pubDate>Mon, 14 Sep 2026 07:42:36 +0200</pubDate>
<content:encoded><![CDATA[<p>Host David Shipley covers multiple cyber stories: Florida confirmed criminals breached its DMV using credentials from a Plant City police officer that were improperly stored on a personal device; ShinyHunters claimed responsibility and the full scope remains unknown. IDScan also confirmed attackers accessed customer data in its cloud, involving... <a href="https://www.itsecuritynews.info/shinyhunters-breaches-florida-dmv-openai-agents-flood-code-repository-with-malware-airlines-dodge-paying-for-cyber-delays/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[AsyncRAT Malware Abuses AutoIt and PowerShell to Hide Inside Legitimate Windows Process]]></title>
<description><![CDATA[A five-stage AsyncRAT campaign that chains a socially engineered batch file, hidden PowerShell execution, AutoIt abuse and process injection to conceal a .NET remote-access trojan inside Microsoft’s legitimate charmap.exe process. The infection begins with a lure named “Right-click to open Invoic...]]></description>
<link>https://tsecurity.de/de/4116961/malware-trojaner-viren/asyncrat-malware-abuses-autoit-and-powershell-to-hide-inside-legitimate-windows-process/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4116961/malware-trojaner-viren/asyncrat-malware-abuses-autoit-and-powershell-to-hide-inside-legitimate-windows-process/</guid>
<pubDate>Mon, 14 Sep 2026 07:42:33 +0200</pubDate>
<content:encoded><![CDATA[<p>A five-stage AsyncRAT campaign that chains a socially engineered batch file, hidden PowerShell execution, AutoIt abuse and process injection to conceal a .NET remote-access trojan inside Microsoft’s legitimate charmap.exe process. The infection begins with a lure named “Right-click to open Invoice Details.bat”, which relies on user interaction to... <a href="https://www.itsecuritynews.info/asyncrat-malware-abuses-autoit-and-powershell-to-hide-inside-legitimate-windows-process/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Claude-Missbrauch: Russische Hacker automatisieren Malware-Angriffe - Börse Express]]></title>
<description><![CDATA[Anthropic dokumentiert staatlich gelenkte und kriminelle Nutzung von Claude für Cyberangriffe, Militärforschung und das Training fremder ... Weiterlesen]]></description>
<link>https://tsecurity.de/de/4110193/malware-trojaner-viren/claude-missbrauch-russische-hacker-automatisieren-malware-angriffe-boerse-express/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4110193/malware-trojaner-viren/claude-missbrauch-russische-hacker-automatisieren-malware-angriffe-boerse-express/</guid>
<pubDate>Mon, 14 Sep 2026 01:12:20 +0200</pubDate>
<content:encoded><![CDATA[<p>Anthropic dokumentiert staatlich gelenkte und kriminelle Nutzung von Claude für Cyberangriffe, Militärforschung und das Training fremder ... <a href="https://www.google.com/url?rct=j&amp;sa=t&amp;url=https://www.boerse-express.com/news/articles/claude-missbrauch-russische-hacker-automatisieren-malware-angriffe-946963&amp;ct=ga&amp;cd=CAIyGTY2ODI4YjRlZGNiMmJmMmM6ZGU6ZGU6REU&amp;usg=AOvVaw0JwouraMrg7oukDF5CSnSG" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Conti-Entwickler Lytvynenko zu vier Jahren Haft: Loader statt nur Mitläufer]]></title>
<description><![CDATA[COUNTY CORK / LONDON (IT BOLTWISE) – Ein US-Bundesgericht hat den Conti-Malware-Entwickler Oleksii Lytvynenko zu vier Jahren Haft verurteilt. Die Anklage und die Gerichtsunterlagen ordnen ihm die Entwicklung eines „Loader“ zu, der Schadsoftware nach einer Kompromittierung auf Zielsysteme bringt. ...]]></description>
<link>https://tsecurity.de/de/4109838/malware-trojaner-viren/conti-entwickler-lytvynenko-zu-vier-jahren-haft-loader-statt-nur-mitlaeufer/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4109838/malware-trojaner-viren/conti-entwickler-lytvynenko-zu-vier-jahren-haft-loader-statt-nur-mitlaeufer/</guid>
<pubDate>Mon, 14 Sep 2026 01:08:41 +0200</pubDate>
<content:encoded><![CDATA[<p>COUNTY CORK / LONDON (IT BOLTWISE) – Ein US-Bundesgericht hat den Conti-Malware-Entwickler Oleksii Lytvynenko zu vier Jahren Haft verurteilt. Die Anklage und die Gerichtsunterlagen ordnen ihm die Entwicklung eines „Loader“ zu, der Schadsoftware nach einer Kompromittierung auf Zielsysteme bringt. Laut Ermittlern setzte er damit nicht nur Tools auf,... <a href="https://www.it-boltwise.de/conti-entwickler-lytvynenko-zu-vier-jahren-haft-loader-statt-nur-mitlaeufer.html" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[IT Security News Daily Summary 2026-09-13]]></title>
<description><![CDATA[30 posts published today 21:01The Cybersecurity Hiring Challenge 19:01Thousands of horses caught up in Europe-wide trafficking scheme 19:00IT Security News Hourly Summary 2026-09-13 21h : 3 posts 18:31SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 114 18:31API Security Testing Tutorial: How to Test RE...]]></description>
<link>https://tsecurity.de/de/4109814/malware-trojaner-viren/it-security-news-daily-summary-2026-09-13/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4109814/malware-trojaner-viren/it-security-news-daily-summary-2026-09-13/</guid>
<pubDate>Mon, 14 Sep 2026 01:08:37 +0200</pubDate>
<content:encoded><![CDATA[<p>30 posts published today 21:01The Cybersecurity Hiring Challenge 19:01Thousands of horses caught up in Europe-wide trafficking scheme 19:00IT Security News Hourly Summary 2026-09-13 21h : 3 posts 18:31SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 114 18:31API Security Testing Tutorial: How to Test REST APIs For Vulnerabilities 18:00IT Security News... <a href="https://www.itsecuritynews.info/it-security-news-daily-summary-2026-09-13/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[IT Security News Roundup: 2026-09-13]]></title>
<description><![CDATA[IT Security News: today roundup Organizations must adapt training strategies to build cybersecurity workforces capable of countering evolving threats. Europol assisted in dismantling a European criminal network that trafficked horses using forged documents and modified microchips. Security Affair...]]></description>
<link>https://tsecurity.de/de/4109813/malware-trojaner-viren/it-security-news-roundup-2026-09-13/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4109813/malware-trojaner-viren/it-security-news-roundup-2026-09-13/</guid>
<pubDate>Mon, 14 Sep 2026 01:08:37 +0200</pubDate>
<content:encoded><![CDATA[<p>IT Security News: today roundup Organizations must adapt training strategies to build cybersecurity workforces capable of countering evolving threats. Europol assisted in dismantling a European criminal network that trafficked horses using forged documents and modified microchips. Security Affairs released a malware digest highlighting North... <a href="https://www.itsecuritynews.info/it-security-news-roundup-2026-09-13/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[IT Security News Weekly Summary 37]]></title>
<description><![CDATA[200 posts published this week 21:55IT Security News Roundup: 2026-09-13 21:55IT Security News Daily Summary 2026-09-13 21:01The Cybersecurity Hiring Challenge 19:01Thousands of horses caught up in Europe-wide trafficking scheme 19:00IT Security News Hourly Summary 2026-09-13 21h : 3 posts 18:31SE...]]></description>
<link>https://tsecurity.de/de/4109812/malware-trojaner-viren/it-security-news-weekly-summary-37/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4109812/malware-trojaner-viren/it-security-news-weekly-summary-37/</guid>
<pubDate>Mon, 14 Sep 2026 01:08:37 +0200</pubDate>
<content:encoded><![CDATA[<p>200 posts published this week 21:55IT Security News Roundup: 2026-09-13 21:55IT Security News Daily Summary 2026-09-13 21:01The Cybersecurity Hiring Challenge 19:01Thousands of horses caught up in Europe-wide trafficking scheme 19:00IT Security News Hourly Summary 2026-09-13 21h : 3 posts 18:31SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 114 18:31API... <a href="https://www.itsecuritynews.info/it-security-news-weekly-summary-37-2/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Claude und Biowaffen: Diese fünf Fälle untersuchte Anthropic - Markt & Mittelstand]]></title>
<description><![CDATA[Cyberangriffe und IT-Sicherheit. Berlin trotzt Hackern – jedes fünfte Ransomware-Opfer zahlt. 45 Prozent der Firmen erlebten binnen zwölf Monaten ... Weiterlesen]]></description>
<link>https://tsecurity.de/de/4109540/malware-trojaner-viren/claude-und-biowaffen-diese-fuenf-faelle-untersuchte-anthropic-markt-mittelstand/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4109540/malware-trojaner-viren/claude-und-biowaffen-diese-fuenf-faelle-untersuchte-anthropic-markt-mittelstand/</guid>
<pubDate>Mon, 14 Sep 2026 01:04:55 +0200</pubDate>
<content:encoded><![CDATA[<p>Cyberangriffe und IT-Sicherheit. Berlin trotzt Hackern – jedes fünfte Ransomware-Opfer zahlt. 45 Prozent der Firmen erlebten binnen zwölf Monaten ... <a href="https://www.google.com/url?rct=j&amp;sa=t&amp;url=https://www.marktundmittelstand.de/technologie/vogelgrippe-und-toxine&amp;ct=ga&amp;cd=CAIyGTRiZTZmY2RmMzZhYjA0M2Y6ZGU6ZGU6REU&amp;usg=AOvVaw2uJAlQoep3VkVycJdtWPQ4" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[PHP Malware plugin]]></title>
<description><![CDATA[\* Plugin Name: Ultra Connector Run \* Plugin URI: https://github.com/ethancarter/ultra-connector-run \* Description: Powerful content delivery wrapper \* Version: 1.0.5 \* Author: Ethan Carter \* License: GPL-2.0-or-later \* Text Domain: ultra-connector-run \* Requires at least: 5.0 \* Requires ...]]></description>
<link>https://tsecurity.de/de/4108067/malware-trojaner-viren/php-malware-plugin/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4108067/malware-trojaner-viren/php-malware-plugin/</guid>
<pubDate>Mon, 14 Sep 2026 00:30:16 +0200</pubDate>
<content:encoded><![CDATA[<p>\* Plugin Name: Ultra Connector Run \* Plugin URI: https://github.com/ethancarter/ultra-connector-run \* Description: Powerful content delivery wrapper \* Version: 1.0.5 \* Author: Ethan Carter \* License: GPL-2.0-or-later \* Text Domain: ultra-connector-run \* Requires at least: 5.0 \* Requires PHP: 5.6 \*/ Has anyone come across this plugin? It... <a href="https://www.reddit.com/r/MalwareAnalysis/comments/1wflirs/php_malware_plugin/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Behörden zerschlagen Sality-Botnet nach 23 Jahren Krypto-Diebstahl - Pasquale Pillitteri]]></title>
<description><![CDATA[Das P2P-Botnet infizierte 23 Jahre lang PCs und stahl Kryptowährungen. Alle Neuigkeiten. Meistgelesen · Cybersicherheit 20 ... Weiterlesen]]></description>
<link>https://tsecurity.de/de/4107273/malware-trojaner-viren/behoerden-zerschlagen-sality-botnet-nach-23-jahren-krypto-diebstahl-pasquale-pillitteri/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4107273/malware-trojaner-viren/behoerden-zerschlagen-sality-botnet-nach-23-jahren-krypto-diebstahl-pasquale-pillitteri/</guid>
<pubDate>Sun, 13 Sep 2026 23:09:39 +0200</pubDate>
<content:encoded><![CDATA[<p>Das P2P-Botnet infizierte 23 Jahre lang PCs und stahl Kryptowährungen. Alle Neuigkeiten. Meistgelesen · Cybersicherheit 20 ... <a href="https://www.google.com/url?rct=j&amp;sa=t&amp;url=https://pasqualepillitteri.it/de/news/16016/sality-botnet-zerschlagen-23-jahre&amp;ct=ga&amp;cd=CAIyGTViNmI2YzJlZTdlY2E1ZTI6ZGU6ZGU6REU&amp;usg=AOvVaw3kIRvEkuWVP6TTp7ZTEVP7" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Attackers Use Expired Websites for Malware Scams]]></title>
<description><![CDATA[Dead websites may seem harmless once they are abandoned by their owners, but their old internet reputation can make them important tools for threat actors. A new research by Infoblox Threat Intel has revealed that threat actors are spending millions of dollars buying expired domain names and misu...]]></description>
<link>https://tsecurity.de/de/4107257/malware-trojaner-viren/attackers-use-expired-websites-for-malware-scams/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4107257/malware-trojaner-viren/attackers-use-expired-websites-for-malware-scams/</guid>
<pubDate>Sun, 13 Sep 2026 23:09:19 +0200</pubDate>
<content:encoded><![CDATA[<p>Dead websites may seem harmless once they are abandoned by their owners, but their old internet reputation can make them important tools for threat actors. A new research by Infoblox Threat Intel has revealed that threat actors are spending millions of dollars buying expired domain names and misusing them for online gambling, malware, scams, and... <a href="https://www.itsecuritynews.info/attackers-use-expired-websites-for-malware-scams/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[IT Security News Hourly Summary 2026-09-13 17h : 3 posts]]></title>
<description><![CDATA[3 posts published in the last hour 14:31Google Play Early Access Exploited for Fake Reward Apps 14:31Scientists are building a microscope powered by a quantum computer 14:31Attackers Use Expired Websites for Malware Scams The post IT Security News Hourly Summary 2026-09-13 17h : 3 posts appeared ...]]></description>
<link>https://tsecurity.de/de/4107254/malware-trojaner-viren/it-security-news-hourly-summary-2026-09-13-17h-3-posts/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4107254/malware-trojaner-viren/it-security-news-hourly-summary-2026-09-13-17h-3-posts/</guid>
<pubDate>Sun, 13 Sep 2026 23:09:16 +0200</pubDate>
<content:encoded><![CDATA[<p>3 posts published in the last hour 14:31Google Play Early Access Exploited for Fake Reward Apps 14:31Scientists are building a microscope powered by a quantum computer 14:31Attackers Use Expired Websites for Malware Scams The post IT Security News Hourly Summary 2026-09-13 17h : 3 posts appeared first on IT Security News. <a href="https://www.itsecuritynews.info/it-security-news-hourly-summary-2026-09-13-17h-3-posts/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Conti Ransomware Ties Lead to Four-Year Prison Sentence]]></title>
<description><![CDATA[Ukrainian nationals have been sentenced to four years in U.S. prison for participating in the Conti ransomware operation. Between 2020 and 2022, the company was carrying out attacks against organizations throughout the United States and other countries.  In addition to serving as a hacker and dev...]]></description>
<link>https://tsecurity.de/de/4107246/malware-trojaner-viren/conti-ransomware-ties-lead-to-four-year-prison-sentence/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4107246/malware-trojaner-viren/conti-ransomware-ties-lead-to-four-year-prison-sentence/</guid>
<pubDate>Sun, 13 Sep 2026 23:09:07 +0200</pubDate>
<content:encoded><![CDATA[<p>Ukrainian nationals have been sentenced to four years in U.S. prison for participating in the Conti ransomware operation. Between 2020 and 2022, the company was carrying out attacks against organizations throughout the United States and other countries.  In addition to serving as a hacker and developer, Oleksii Oleksiyovych Lytvynenko, 44, was... <a href="https://www.itsecuritynews.info/conti-ransomware-ties-lead-to-four-year-prison-sentence/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[IT Security News Hourly Summary 2026-09-13 21h : 3 posts]]></title>
<description><![CDATA[3 posts published in the last hour 18:31SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 114 18:31API Security Testing Tutorial: How to Test REST APIs For Vulnerabilities 18:00IT Security News Hourly Summary 2026-09-13 20h : 4 posts The post IT Security News Hourly Summary 2026-09-13 21h : 3 posts appea...]]></description>
<link>https://tsecurity.de/de/4107243/malware-trojaner-viren/it-security-news-hourly-summary-2026-09-13-21h-3-posts/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4107243/malware-trojaner-viren/it-security-news-hourly-summary-2026-09-13-21h-3-posts/</guid>
<pubDate>Sun, 13 Sep 2026 23:09:07 +0200</pubDate>
<content:encoded><![CDATA[<p>3 posts published in the last hour 18:31SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 114 18:31API Security Testing Tutorial: How to Test REST APIs For Vulnerabilities 18:00IT Security News Hourly Summary 2026-09-13 20h : 4 posts The post IT Security News Hourly Summary 2026-09-13 21h : 3 posts appeared first on IT Security News. <a href="https://www.itsecuritynews.info/it-security-news-hourly-summary-2026-09-13-21h-3-posts/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 114]]></title>
<description><![CDATA[Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape Malware Newsletter REVSTEALER ramps up Breaking the Seal: Static Deobfuscation of JSCeal’s Compiled V8 Bytecode   GuardBreaker: Derailing AI-assisted malware analy...]]></description>
<link>https://tsecurity.de/de/4107138/malware-trojaner-viren/security-affairs-malware-newsletter-round-114/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4107138/malware-trojaner-viren/security-affairs-malware-newsletter-round-114/</guid>
<pubDate>Sun, 13 Sep 2026 23:06:59 +0200</pubDate>
<content:encoded><![CDATA[<p>Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape Malware Newsletter REVSTEALER ramps up Breaking the Seal: Static Deobfuscation of JSCeal’s Compiled V8 Bytecode   GuardBreaker: Derailing AI-assisted malware analysis with a code comment   DPRK APTs: Ted backdoor... <a href="https://securityaffairs.com/198980/breaking-news/security-affairs-malware-newsletter-round-114.html" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Avast: Happy National Grandparents Day]]></title>
<description><![CDATA[YouTube Video🎥 @rosssmith keeping his Granny safe this National Grandparents Day. 🤭Learn how to keep your grandparents safe from scams this year here: https://bit.ly/4r6NUXb]]></description>
<link>https://tsecurity.de/de/4106239/malware-trojaner-viren/happy-national-grandparents-day/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4106239/malware-trojaner-viren/happy-national-grandparents-day/</guid>
<pubDate>Sun, 13 Sep 2026 23:00:11 +0200</pubDate>
<content:encoded><![CDATA[<p>YouTube Video</p><p><iframe loading="lazy" src="https://www.youtube.com/embed/w_twm0Kml7E"></iframe></p><div class="youtube-description">🎥 @rosssmith keeping his Granny safe this National Grandparents Day. 🤭Learn how to keep your grandparents safe from scams this year here: https://bit.ly/4r6NUXb</div>]]></content:encoded>
<enclosure url="https://i4.ytimg.com/vi/w_twm0Kml7E/hqdefault.jpg" length="0" type="image/jpeg" />
</item>
<item>
<title><![CDATA[Is lua tools 100% safe?]]></title>
<description><![CDATA[I was scanning lus tools setup.exe just becuase ive been hacked before and i saw something that said it was a high malicious and it was called trapmine? Is this something i should be concerned about before opening lua tools? Can someone help me? submitted by /u/bogboy24 [link] [comments] Weiterlesen]]></description>
<link>https://tsecurity.de/de/4105559/malware-trojaner-viren/is-lua-tools-100-safe/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4105559/malware-trojaner-viren/is-lua-tools-100-safe/</guid>
<pubDate>Sun, 13 Sep 2026 22:30:21 +0200</pubDate>
<content:encoded><![CDATA[<p>I was scanning lus tools setup.exe just becuase ive been hacked before and i saw something that said it was a high malicious and it was called trapmine? Is this something i should be concerned about before opening lua tools? Can someone help me? submitted by /u/bogboy24 [link] [comments] <a href="https://www.reddit.com/r/MalwareAnalysis/comments/1wfi52c/is_lua_tools_100_safe/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Apple Threat Notifications: 150 Countries Since 2021, Per Apple’s Own Support Page]]></title>
<description><![CDATA[Apple’s support page on threat notifications says the company has notified targeted iPhone users in more than 150 countries since 2021. The page, last published August 13, 2026, describes a narrow system built for a small number of people facing state-linked mercenary spyware, not a general malwa...]]></description>
<link>https://tsecurity.de/de/4102674/malware-trojaner-viren/apple-threat-notifications-150-countries-since-2021-per-apples-own-support-page/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4102674/malware-trojaner-viren/apple-threat-notifications-150-countries-since-2021-per-apples-own-support-page/</guid>
<pubDate>Sun, 13 Sep 2026 20:30:31 +0200</pubDate>
<content:encoded><![CDATA[<p>Apple’s support page on threat notifications says the company has notified targeted iPhone users in more than 150 countries since 2021. The page, last published August 13, 2026, describes a narrow system built for a small number of people facing state-linked mercenary spyware, not a general malware warning for everyday users. Apple&#039;s iOS... <a href="https://www.macobserver.com/news/apple-threat-notifications-150-countries-since-2021/?utm_source=macobserver&amp;utm_medium=rss&amp;utm_campaign=rss_everything" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[VLC-Sicherheitslücken: Manipulierte Streams können Speicherinhalte auslesen]]></title>
<description><![CDATA[VLC-Sicherheitslücken gefährden Nutzer: Manipulierte PNGs können Codeausführung ermöglichen, RTSP-Antworten Speicherinhalte preisgeben. Der Artikel VLC-Sicherheitslücken: Manipulierte Streams können Speicherinhalte auslesen erschien zuerst auf TARNKAPPE.INFO Weiterlesen]]></description>
<link>https://tsecurity.de/de/4099900/malware-trojaner-viren/vlc-sicherheitsluecken-manipulierte-streams-koennen-speicherinhalte-auslesen/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4099900/malware-trojaner-viren/vlc-sicherheitsluecken-manipulierte-streams-koennen-speicherinhalte-auslesen/</guid>
<pubDate>Sun, 13 Sep 2026 15:00:28 +0200</pubDate>
<content:encoded><![CDATA[<p>VLC-Sicherheitslücken gefährden Nutzer: Manipulierte PNGs können Codeausführung ermöglichen, RTSP-Antworten Speicherinhalte preisgeben. Der Artikel VLC-Sicherheitslücken: Manipulierte Streams können Speicherinhalte auslesen erschien zuerst auf TARNKAPPE.INFO <a href="https://tarnkappe.info/artikel/it-sicherheit/vlc-sicherheitsluecken-manipulierte-streams-333426.html" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[IT Security News Hourly Summary 2026-09-13 13h : 3 posts]]></title>
<description><![CDATA[3 posts published in the last hour 10:31Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data 10:31Anthropic Says Hackers Abused Claude to Scan 1.8 Million Android Apps for Secrets 10:01Conti Hacker Who Built Malware and Attacked Victims Gets Four-Year Sentence The...]]></description>
<link>https://tsecurity.de/de/4099510/malware-trojaner-viren/it-security-news-hourly-summary-2026-09-13-13h-3-posts/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4099510/malware-trojaner-viren/it-security-news-hourly-summary-2026-09-13-13h-3-posts/</guid>
<pubDate>Sun, 13 Sep 2026 14:13:52 +0200</pubDate>
<content:encoded><![CDATA[<p>3 posts published in the last hour 10:31Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data 10:31Anthropic Says Hackers Abused Claude to Scan 1.8 Million Android Apps for Secrets 10:01Conti Hacker Who Built Malware and Attacked Victims Gets Four-Year Sentence The post IT Security News Hourly Summary 2026-09-13 13h... <a href="https://www.itsecuritynews.info/it-security-news-hourly-summary-2026-09-13-13h-3-posts/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Claude-KI-Agenten beschleunigen Cyberangriffe: Bericht zeigt „Kill-Chain“-Automatisierung und 0-Days]]></title>
<description><![CDATA[LONDON (IT BOLTWISE) – Ein neuer Bericht von Anthropic beschreibt, wie KI-gestützte Claude Agents ganze Angriffsabläufe automatisieren, 0-Day-ähnliche Lücken aufspüren und Malware so umformen, dass Signaturen schneller ausweichen. Besonders auffällig ist, dass nicht mehr nur Elite-Teams profitier...]]></description>
<link>https://tsecurity.de/de/4098177/malware-trojaner-viren/claude-ki-agenten-beschleunigen-cyberangriffe-bericht-zeigt-kill-chain-automatisierung-und-0-days/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4098177/malware-trojaner-viren/claude-ki-agenten-beschleunigen-cyberangriffe-bericht-zeigt-kill-chain-automatisierung-und-0-days/</guid>
<pubDate>Sun, 13 Sep 2026 12:41:26 +0200</pubDate>
<content:encoded><![CDATA[<p>LONDON (IT BOLTWISE) – Ein neuer Bericht von Anthropic beschreibt, wie KI-gestützte Claude Agents ganze Angriffsabläufe automatisieren, 0-Day-ähnliche Lücken aufspüren und Malware so umformen, dass Signaturen schneller ausweichen. Besonders auffällig ist, dass nicht mehr nur Elite-Teams profitieren: Auch einzelne Akteure und kleine Gruppen sollen... <a href="https://www.it-boltwise.de/claude-ki-agenten-beschleunigen-cyberangriffe-bericht-zeigt-kill-chain-automatisierung-und-0-days.html" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Conti Hacker Who Built Malware and Attacked Victims Gets Four-Year Sentence]]></title>
<description><![CDATA[Ukrainian lawyer and Conti malware developer Oleksii Lytvynenko was sentenced to four years in U.S. prison for ransomware attacks. Oleksii Oleksiyovych Lytvynenko had, by most accounts, a fairly ordinary legal career in Ukraine before he switched to writing malware. A US federal court sentenced t...]]></description>
<link>https://tsecurity.de/de/4098056/malware-trojaner-viren/conti-hacker-who-built-malware-and-attacked-victims-gets-four-year-sentence/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4098056/malware-trojaner-viren/conti-hacker-who-built-malware-and-attacked-victims-gets-four-year-sentence/</guid>
<pubDate>Sun, 13 Sep 2026 12:39:23 +0200</pubDate>
<content:encoded><![CDATA[<p>Ukrainian lawyer and Conti malware developer Oleksii Lytvynenko was sentenced to four years in U.S. prison for ransomware attacks. Oleksii Oleksiyovych Lytvynenko had, by most accounts, a fairly ordinary legal career in Ukraine before he switched to writing malware. A US federal court sentenced the 44-year-old to four years in prison this week for... <a href="https://securityaffairs.com/198931/cyber-crime/conti-hacker-who-built-malware-and-attacked-victims-gets-four-year-sentence.html" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Die Ransomware-Szene unter der Lupe: Welche Fragen habt ihr an die Macher von RansomLook?]]></title>
<description><![CDATA[Das Portal RansomLook überwacht die Ransomware-Szene. Welche Fragen sollen wir den Machern stellen? Reicht sie bitte jetzt ein!!! Der Artikel Die Ransomware-Szene unter der Lupe: Welche Fragen habt ihr an die Macher von RansomLook? erschien zuerst auf TARNKAPPE.INFO Weiterlesen]]></description>
<link>https://tsecurity.de/de/4094867/malware-trojaner-viren/die-ransomware-szene-unter-der-lupe-welche-fragen-habt-ihr-an-die-macher-von-ransomlook/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4094867/malware-trojaner-viren/die-ransomware-szene-unter-der-lupe-welche-fragen-habt-ihr-an-die-macher-von-ransomlook/</guid>
<pubDate>Sun, 13 Sep 2026 10:00:15 +0200</pubDate>
<content:encoded><![CDATA[<p>Das Portal RansomLook überwacht die Ransomware-Szene. Welche Fragen sollen wir den Machern stellen? Reicht sie bitte jetzt ein!!! Der Artikel Die Ransomware-Szene unter der Lupe: Welche Fragen habt ihr an die Macher von RansomLook? erschien zuerst auf TARNKAPPE.INFO <a href="https://tarnkappe.info/artikel/interviews/die-ransomware-szene-unter-der-lupe-welche-fragen-habt-ihr-an-die-macher-von-ransomlook-333418.html" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CAPE-parsers v0.1.69]]></title>
<description><![CDATA[Extracts and parses malware family configuration data from CAPE sandbox artifacts, including C2 URLs, botnet IDs, DGA seeds, mutexes, and encryption keys. Weiterlesen]]></description>
<link>https://tsecurity.de/de/4092893/malware-trojaner-viren/cape-parsers-v0169/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4092893/malware-trojaner-viren/cape-parsers-v0169/</guid>
<pubDate>Sun, 13 Sep 2026 06:34:13 +0200</pubDate>
<content:encoded><![CDATA[<p>Extracts and parses malware family configuration data from CAPE sandbox artifacts, including C2 URLs, botnet IDs, DGA seeds, mutexes, and encryption keys. <a href="https://kitploit.com/en/posts/github-capesandbox-cape-parsers-v0169" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[darknet-mcp-server]]></title>
<description><![CDATA[66-tool MCP server for dark web intelligence — breach data, ransomware tracking, Tor .onion access, malware analysis, blockchain intel, exploit search, stealer logs Weiterlesen]]></description>
<link>https://tsecurity.de/de/4092892/malware-trojaner-viren/darknet-mcp-server/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4092892/malware-trojaner-viren/darknet-mcp-server/</guid>
<pubDate>Sun, 13 Sep 2026 06:34:13 +0200</pubDate>
<content:encoded><![CDATA[<p>66-tool MCP server for dark web intelligence — breach data, ransomware tracking, Tor .onion access, malware analysis, blockchain intel, exploit search, stealer logs <a href="https://kitploit.com/en/tools/github/badchars/darknet-mcp-server" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Avast: See you on 9.13 👀🤭]]></title>
<description><![CDATA[YouTube VideoSee you on 9.13 👀🤭]]></description>
<link>https://tsecurity.de/de/4083204/malware-trojaner-viren/see-you-on-913/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4083204/malware-trojaner-viren/see-you-on-913/</guid>
<pubDate>Sat, 12 Sep 2026 22:00:21 +0200</pubDate>
<content:encoded><![CDATA[<p>YouTube Video</p><p><iframe loading="lazy" src="https://www.youtube.com/embed/1HVFE-su4CM"></iframe></p><div class="youtube-description">See you on 9.13 👀🤭</div>]]></content:encoded>
<enclosure url="https://i2.ytimg.com/vi/1HVFE-su4CM/hqdefault.jpg" length="0" type="image/jpeg" />
</item>
<item>
<title><![CDATA[I polished my ELF analysis tool]]></title>
<description><![CDATA[I created Binkit a few months ago, and it worked well. It can inspect headers (similarly to readelf), perform simple disassembly, and inject payloads. A few days ago, I decided to improve it, adding many tests as well as implementation and performance refinements. It now performs as fast as reade...]]></description>
<link>https://tsecurity.de/de/4081013/malware-trojaner-viren/i-polished-my-elf-analysis-tool/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4081013/malware-trojaner-viren/i-polished-my-elf-analysis-tool/</guid>
<pubDate>Sat, 12 Sep 2026 20:00:35 +0200</pubDate>
<content:encoded><![CDATA[<p>I created Binkit a few months ago, and it worked well. It can inspect headers (similarly to readelf), perform simple disassembly, and inject payloads. A few days ago, I decided to improve it, adding many tests as well as implementation and performance refinements. It now performs as fast as readelf and better than objdump for the disassembly... <a href="https://www.reddit.com/r/MalwareAnalysis/comments/1wehiau/i_polished_my_elf_analysis_tool/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[MantaxOtax Android Malware Merges Ransomware and Spyware in New Indonesian Campaign]]></title>
<description><![CDATA[  MantaxOtax is a newly identified Android malware that merges ransomware-style file encryption with aggressive spyware capabilities, enabling attackers to both lock users out of their devices and harvest sensitive personal data. Discovered by Zimperium's zLabs team and detailed in a September 9 ...]]></description>
<link>https://tsecurity.de/de/4080537/malware-trojaner-viren/mantaxotax-android-malware-merges-ransomware-and-spyware-in-new-indonesian-campaign/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4080537/malware-trojaner-viren/mantaxotax-android-malware-merges-ransomware-and-spyware-in-new-indonesian-campaign/</guid>
<pubDate>Sat, 12 Sep 2026 18:25:33 +0200</pubDate>
<content:encoded><![CDATA[<p>  MantaxOtax is a newly identified Android malware that merges ransomware-style file encryption with aggressive spyware capabilities, enabling attackers to both lock users out of their devices and harvest sensitive personal data. Discovered by Zimperium&#039;s zLabs team and detailed in a September 9 technical write-up, the threat appears linked to... <a href="https://www.itsecuritynews.info/mantaxotax-android-malware-merges-ransomware-and-spyware-in-new-indonesian-campaign/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[IT Security News Hourly Summary 2026-09-12 18h : 6 posts]]></title>
<description><![CDATA[6 posts published in the last hour 15:31MantaxOtax Android Malware Merges Ransomware and Spyware in New Indonesian Campaign 15:02Researchers find a Wordle strategy that wins 99% of the time 15:02CISA Flags Exploited Cisco, Citrix, Fortinet Flaws, Sets Sept. 12 Federal Patch Deadline 15:02Revolut ...]]></description>
<link>https://tsecurity.de/de/4080536/malware-trojaner-viren/it-security-news-hourly-summary-2026-09-12-18h-6-posts/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4080536/malware-trojaner-viren/it-security-news-hourly-summary-2026-09-12-18h-6-posts/</guid>
<pubDate>Sat, 12 Sep 2026 18:25:33 +0200</pubDate>
<content:encoded><![CDATA[<p>6 posts published in the last hour 15:31MantaxOtax Android Malware Merges Ransomware and Spyware in New Indonesian Campaign 15:02Researchers find a Wordle strategy that wins 99% of the time 15:02CISA Flags Exploited Cisco, Citrix, Fortinet Flaws, Sets Sept. 12 Federal Patch Deadline 15:02Revolut confirms customer data breach through fake... <a href="https://www.itsecuritynews.info/it-security-news-hourly-summary-2026-09-12-18h-6-posts/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[KorbKlar wurde zu Korbunio: Der Umbau einer Preisvergleichs-App]]></title>
<description><![CDATA[Korbunio ersetzt KorbKlar und wird zur nativen Preisvergleichs-App: Händlerangebote, Treueprogramme und der aktuelle Entwicklungsstand. Der Artikel KorbKlar wurde zu Korbunio: Der Umbau einer Preisvergleichs-App erschien zuerst auf TARNKAPPE.INFO Weiterlesen]]></description>
<link>https://tsecurity.de/de/4078888/malware-trojaner-viren/korbklar-wurde-zu-korbunio-der-umbau-einer-preisvergleichs-app/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4078888/malware-trojaner-viren/korbklar-wurde-zu-korbunio-der-umbau-einer-preisvergleichs-app/</guid>
<pubDate>Sat, 12 Sep 2026 17:01:30 +0200</pubDate>
<content:encoded><![CDATA[<p>Korbunio ersetzt KorbKlar und wird zur nativen Preisvergleichs-App: Händlerangebote, Treueprogramme und der aktuelle Entwicklungsstand. Der Artikel KorbKlar wurde zu Korbunio: Der Umbau einer Preisvergleichs-App erschien zuerst auf TARNKAPPE.INFO <a href="https://tarnkappe.info/artikel/softwareentwicklung/korbklar-wurde-zu-korbunio-der-umbau-einer-preisvergleichs-app-333406.html" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[From Hacks to Bioweapons, Claude Misuse Is Now Everywhere]]></title>
<description><![CDATA[Plus: The US disrupts the internet’s biggest black market, a Conti ransomware hacker gets prison time, Meta fails to stop AI-generated videos of child abuse. Weiterlesen]]></description>
<link>https://tsecurity.de/de/4077235/malware-trojaner-viren/from-hacks-to-bioweapons-claude-misuse-is-now-everywhere/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4077235/malware-trojaner-viren/from-hacks-to-bioweapons-claude-misuse-is-now-everywhere/</guid>
<pubDate>Sat, 12 Sep 2026 12:35:26 +0200</pubDate>
<content:encoded><![CDATA[<p>Plus: The US disrupts the internet’s biggest black market, a Conti ransomware hacker gets prison time, Meta fails to stop AI-generated videos of child abuse. <a href="https://www.wired.com/story/security-news-this-week-from-hacks-to-bioweapons-claude-misuse-is-now-everywhere/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[A beast by any other name.]]></title>
<description><![CDATA[Today we are joined by ⁠Brigid O Gorman⁠, Senior Intelligence Analyst on ⁠Symantec⁠ Threat Hunter team, discussing their work on “GodDamn Ransomware: Latest Beast Rebrand Uses Malicious Driver to Disable Defenses." GodDamn ransomware, the latest rebrand from the Hyadina group behind Monster and B...]]></description>
<link>https://tsecurity.de/de/4076194/malware-trojaner-viren/a-beast-by-any-other-name/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4076194/malware-trojaner-viren/a-beast-by-any-other-name/</guid>
<pubDate>Sat, 12 Sep 2026 11:41:24 +0200</pubDate>
<content:encoded><![CDATA[<p>Today we are joined by ⁠Brigid O Gorman⁠, Senior Intelligence Analyst on ⁠Symantec⁠ Threat Hunter team, discussing their work on “GodDamn Ransomware: Latest Beast Rebrand Uses Malicious Driver to Disable Defenses.&quot; GodDamn ransomware, the latest rebrand from the Hyadina group behind Monster and Beast, is using increasingly sophisticated techniques... <a href="https://thecyberwire.com/podcasts/research-saturday/441/notes" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Hackers Abuse Windows Mshta.exe in Phishing Attacks to Deploy HTA Malware and Steal Credentials]]></title>
<description><![CDATA[Threat actors are actively abusing the legitimate Windows utility mshta.exe to execute malicious HTML Application (HTA) files delivered through Spanish-language phishing emails, enabling system reconnaissance and the staged deployment of credential-stealing malware. Researchers at Fortra’s Intell...]]></description>
<link>https://tsecurity.de/de/4076124/malware-trojaner-viren/hackers-abuse-windows-mshtaexe-in-phishing-attacks-to-deploy-hta-malware-and-steal-credentials/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4076124/malware-trojaner-viren/hackers-abuse-windows-mshtaexe-in-phishing-attacks-to-deploy-hta-malware-and-steal-credentials/</guid>
<pubDate>Sat, 12 Sep 2026 11:41:00 +0200</pubDate>
<content:encoded><![CDATA[<p>Threat actors are actively abusing the legitimate Windows utility mshta.exe to execute malicious HTML Application (HTA) files delivered through Spanish-language phishing emails, enabling system reconnaissance and the staged deployment of credential-stealing malware. Researchers at Fortra’s Intelligence and Research Experts (FIRE) have tracked the... <a href="https://cyberpress.org/hackers-abuse-windows-mshta-exe-in-phishing-attacks/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Chinese Hackers Chain Chrome and Windows Zero-Days to Deploy Backdoors and Steal Credentials]]></title>
<description><![CDATA[A newly disclosed chain of vulnerabilities in Google Chrome and the Windows kernel can compromise targets, deploy espionage malware, and steal browser credentials. According to Volexity, UTA0560 and JungleBamboo, also tracked as APT31, Violet Typhoon, and TA412, used an identical multi-stage expl...]]></description>
<link>https://tsecurity.de/de/4076122/malware-trojaner-viren/chinese-hackers-chain-chrome-and-windows-zero-days-to-deploy-backdoors-and-steal-credentials/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4076122/malware-trojaner-viren/chinese-hackers-chain-chrome-and-windows-zero-days-to-deploy-backdoors-and-steal-credentials/</guid>
<pubDate>Sat, 12 Sep 2026 11:41:00 +0200</pubDate>
<content:encoded><![CDATA[<p>A newly disclosed chain of vulnerabilities in Google Chrome and the Windows kernel can compromise targets, deploy espionage malware, and steal browser credentials. According to Volexity, UTA0560 and JungleBamboo, also tracked as APT31, Violet Typhoon, and TA412, used an identical multi-stage exploit chain in spear-phishing operations against... <a href="https://cyberpress.org/chinese-hackers-chain-chrome-and-windows-zero-days/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[FakeAgent, MacSync, and AMOS Distribution via Legitimate AI Sharing Pages]]></title>
<description><![CDATA[1. Basic Information Original Title: How threat actors are turning trusted AI platforms into an attack surface Source: BleepingComputer, Huntress Publication Date: 2026-09-11 Severity: High Basis for Severity: Trusted AI sharing pages are being used to distribute malware via ads and SEO, and infe...]]></description>
<link>https://tsecurity.de/de/4068616/malware-trojaner-viren/fakeagent-macsync-and-amos-distribution-via-legitimate-ai-sharing-pages/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4068616/malware-trojaner-viren/fakeagent-macsync-and-amos-distribution-via-legitimate-ai-sharing-pages/</guid>
<pubDate>Sat, 12 Sep 2026 03:41:59 +0200</pubDate>
<content:encoded><![CDATA[<p>1. Basic Information Original Title: How threat actors are turning trusted AI platforms into an attack surface Source: BleepingComputer, Huntress Publication Date: 2026-09-11 Severity: High Basis for Severity: Trusted AI sharing pages are being used to distribute malware via ads and SEO, and infections have been confirmed across multiple... <a href="https://dev.to/anoymask/fakeagent-macsync-and-amos-distribution-via-legitimate-ai-sharing-pages-1e65" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Anthropic Report: AI Automates Malware Reconstruction, Large-Scale Secret Discovery, and Compromise]]></title>
<description><![CDATA[1. Basic Information Original Title: Hackers abused Claude to extract secrets from 1.8M Android apps Source: BleepingComputer / Anthropic Publication Date: 2026-09-11 Severity: High Basis of Severity: Anthropic reported multiple incidents, including actual compromises and data theft, where AI han...]]></description>
<link>https://tsecurity.de/de/4068615/malware-trojaner-viren/anthropic-report-ai-automates-malware-reconstruction-large-scale-secret-discovery-and-compromise/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4068615/malware-trojaner-viren/anthropic-report-ai-automates-malware-reconstruction-large-scale-secret-discovery-and-compromise/</guid>
<pubDate>Sat, 12 Sep 2026 03:41:59 +0200</pubDate>
<content:encoded><![CDATA[<p>1. Basic Information Original Title: Hackers abused Claude to extract secrets from 1.8M Android apps Source: BleepingComputer / Anthropic Publication Date: 2026-09-11 Severity: High Basis of Severity: Anthropic reported multiple incidents, including actual compromises and data theft, where AI handled attack execution, retries, and evasion. The... <a href="https://dev.to/anoymask/anthropic-report-ai-automates-malware-reconstruction-large-scale-secret-discovery-and-compromise-370a" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[2026-09-11: Traffic analysis exercise – Kongtuke Rebuke!]]></title>
<description><![CDATA[This post has no text preview — click the link below to read the original article. This article has been indexed from Malware-Traffic-Analysis.net – Blog Entries Read the original article: 2026-09-11: Traffic analysis exercise – Kongtuke Rebuke! The post 2026-09-11: Traffic analysis exercise – Ko...]]></description>
<link>https://tsecurity.de/de/4065596/malware-trojaner-viren/2026-09-11-traffic-analysis-exercise-kongtuke-rebuke/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4065596/malware-trojaner-viren/2026-09-11-traffic-analysis-exercise-kongtuke-rebuke/</guid>
<pubDate>Sat, 12 Sep 2026 02:07:55 +0200</pubDate>
<content:encoded><![CDATA[<p>This post has no text preview — click the link below to read the original article. This article has been indexed from Malware-Traffic-Analysis.net – Blog Entries Read the original article: 2026-09-11: Traffic analysis exercise – Kongtuke Rebuke! The post 2026-09-11: Traffic analysis exercise – Kongtuke Rebuke! appeared first on IT Security News. <a href="https://www.itsecuritynews.info/2026-09-11-traffic-analysis-exercise-kongtuke-rebuke/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[SC Factory X: A WordPress Backdoor That Hides Its Command Server Inside an Ethereum Smart Contract]]></title>
<description><![CDATA[Hey everyone! This is my first time posting in this sub so if this is against the rules, please let me know. The github repository: https://github.com/sonofenders/sc-factory-x-malware-analysis Last week I received a call from an acquaintance who said he had a distressed client because they though...]]></description>
<link>https://tsecurity.de/de/4062399/malware-trojaner-viren/sc-factory-x-a-wordpress-backdoor-that-hides-its-command-server-inside-an-ethereum-smart-contract/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4062399/malware-trojaner-viren/sc-factory-x-a-wordpress-backdoor-that-hides-its-command-server-inside-an-ethereum-smart-contract/</guid>
<pubDate>Sat, 12 Sep 2026 01:00:46 +0200</pubDate>
<content:encoded><![CDATA[<p>Hey everyone! This is my first time posting in this sub so if this is against the rules, please let me know. The github repository: https://github.com/sonofenders/sc-factory-x-malware-analysis Last week I received a call from an acquaintance who said he had a distressed client because they thought their site was hacked. They called me because as a... <a href="https://www.reddit.com/r/MalwareAnalysis/comments/1wdv4ou/sc_factory_x_a_wordpress_backdoor_that_hides_its/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Smartphone-Banking: Trojaner klonen Apps und erbeuten 960.000 Euro - ad-hoc-news.de]]></title>
<description><![CDATA[Neue Angriffe kombinieren App-Klonen, Schadsoftware und Täuschung. Behörden melden Kontenübernahmen, hohe Schäden und eine Cybercrime-Anklage. Weiterlesen]]></description>
<link>https://tsecurity.de/de/4061391/malware-trojaner-viren/smartphone-banking-trojaner-klonen-apps-und-erbeuten-960000-euro-ad-hoc-newsde/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4061391/malware-trojaner-viren/smartphone-banking-trojaner-klonen-apps-und-erbeuten-960000-euro-ad-hoc-newsde/</guid>
<pubDate>Sat, 12 Sep 2026 00:11:25 +0200</pubDate>
<content:encoded><![CDATA[<p>Neue Angriffe kombinieren App-Klonen, Schadsoftware und Täuschung. Behörden melden Kontenübernahmen, hohe Schäden und eine Cybercrime-Anklage. <a href="https://www.google.com/url?rct=j&amp;sa=t&amp;url=https://www.ad-hoc-news.de/wissenschaft/smartphone-banking-trojaner-klonen-apps-und-erbeuten-960-000-euro/70089148&amp;ct=ga&amp;cd=CAIyGWQwOWZmNTA1ZDc3ZWYwZTQ6ZGU6ZGU6REU&amp;usg=AOvVaw37KdN-aAaY5NkLbdkbSInj" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Using AI to scan repos for malware]]></title>
<description><![CDATA[submitted by /u/Interesting_Bet_6324 [link] [comments] Weiterlesen]]></description>
<link>https://tsecurity.de/de/4058893/malware-trojaner-viren/using-ai-to-scan-repos-for-malware/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4058893/malware-trojaner-viren/using-ai-to-scan-repos-for-malware/</guid>
<pubDate>Fri, 11 Sep 2026 22:00:34 +0200</pubDate>
<content:encoded><![CDATA[<p>submitted by /u/Interesting_Bet_6324 [link] [comments] <a href="https://www.reddit.com/r/MalwareAnalysis/comments/1wdqlru/using_ai_to_scan_repos_for_malware/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
</channel>
</rss>
<!-- Generated in 1,55ms -->