Zum Hauptinhalt springen
Sichere ProgrammierungI'm an AI agent. I read the agent-economy job boards' own numbers.(05.10.2026 um 03:41 Uhr)
••••
Sichere ProgrammierungYour ops dashboard does not need a frontend framework(05.10.2026 um 03:47 Uhr)
•
Sichere ProgrammierungThree pieces, zero readers: what I got wrong about publishing(05.10.2026 um 03:47 Uhr)
•
Sichere ProgrammierungProofDesk: A contact review is only as current as its evidence(05.10.2026 um 03:49 Uhr)
•
AI & KI NachrichtenAI Agents - Tool Calling And Its Types(05.10.2026 um 03:49 Uhr)
•
Sichere ProgrammierungSTAGE LADDER - A Private, Offline Speaking Coach Built for a Friend(05.10.2026 um 03:51 Uhr)
••
Sichere ProgrammierungI'm an AI agent. I read the agent-economy job boards' own numbers.(05.10.2026 um 03:41 Uhr)
••••
Sichere ProgrammierungYour ops dashboard does not need a frontend framework(05.10.2026 um 03:47 Uhr)
•
Sichere ProgrammierungThree pieces, zero readers: what I got wrong about publishing(05.10.2026 um 03:47 Uhr)
•
Sichere ProgrammierungProofDesk: A contact review is only as current as its evidence(05.10.2026 um 03:49 Uhr)
•
AI & KI NachrichtenAI Agents - Tool Calling And Its Types(05.10.2026 um 03:49 Uhr)
•
Sichere ProgrammierungSTAGE LADDER - A Private, Offline Speaking Coach Built for a Friend(05.10.2026 um 03:51 Uhr)
••
Intelligence View
⚡ tsecurity.de Intelligence

Security news weekly round-up - 3rd October 2025

As things stand, a world where malware and vulnerabilities do not exist is a distant future. Who knows? We might have a solution to these two predominant…

Beitrag
0
Seite
0
↗ Quelle (dev.to)
Social ReaktionenReagiere als Erste:r — dein Feedback zählt!

As things stand, a world where malware and vulnerabilities do not exist is a distant future. Who knows? We might have a solution to these two predominant threats one day. Hopefully, you and I are alive to witness that day. Until then, we have to keep ourselves educated about them and give credit to malware and vulnerability researchers.



I am pretty sure you already know what we are about to review. Let's begin.









As many as 2 million Cisco devices affected by actively exploited 0-day



The good news: It appears that Cisco patched the bug as part of their September 2025 update. The not-so-good news: A search on Shodan reveals that 2 million devices are vulnerable because they are exposed to the internet.



More about the vulnerability from the article:




The vulnerability is the result of a stack overflow bug in the IOS component that handles SNMP (simple network management protocol), which routers and other devices use to collect and handle information about devices inside a network. The vulnerability is exploited by sending crafted SNMP packets.







EvilAI Malware Masquerades as AI Tools to Infiltrate Global Organizations



Deception is one of the weapons of the attackers in this campaign. Also, the attackers use valid digital signatures, making it difficult for users and security tools to distinguish the malware from legitimate software.



From the article:




The campaign has been codenamed EvilAI by Trend Micro, describing the attackers behind the operation as "highly capable" owing to their ability to blur the line between authentic and deceptive software for malware distribution and their ability to conceal its malicious features in otherwise functional applications.



The end goal of the campaign is to conduct extensive reconnaissance, exfiltrate sensitive browser data, and maintain encrypted, real-time communication with its command-and-control (C2) servers using AES-encrypted channels to receive attacker commands and deploy additional payloads.







Android malware uses VNC to give attackers hands-on access



The purpose of this malware is to steal banking credentials. Also, at the time of writing, it does not appear to be connected to any Android malware families. And yes, it abuses the Android Accessibility Services. So, when an application on your phone requests such services, think twice before granting it access.



From the article:




Although the operators of the malware use Cloudflare to hide their digital tracks, a misconfiguration exposed origin IP addresses, which allowed linking the C2 servers to the same provider.



Since March 2025, when Klopatra first appeared in the wild, there have been 40 distinct builds, a sign of active development and quick evolution for the new Android trojan.







Alert: Malicious PyPI Package soopsocks Infects 2,653 Systems Before Takedown



If you downloaded the affected package before it was taken down, here is my advice for you: remove it now. Also, it won't hurt to perform a routine security scan of your system.



Here is what the researchers said about the package:




"soopsocks is a well-designed SOCKS5 proxy with full bootstrap Windows support.



"However, given the way it performs and actions it takes during runtime, it shows signs of malicious activity, such as firewall rules, elevated permissions, various PowerShell commands, and the transfer from simple, configurable Python scripts to a Go executable with hardcoded parameters, version with reconnaissance capabilities..."







Researchers Warn of Self-Spreading WhatsApp Malware Named SORVEPOTEL



At the time of writing, most infections are in Brazil. Now, you might ask: Then why are we talking about it? We are talking about it because the attackers are using phishing to get it onto people's systems. This should serve as a reminder that you should watch out for phishing emails at all times.



From the article:




The starting point of the attack is a phishing message sent from an already compromised contact on WhatsApp to lend it a veneer of credibility. The message contains a ZIP attachment that masquerades as a seemingly harmless receipt or health app-related file.



Should the recipient fall for the trick and open the attachment, they are lured into opening a Windows shortcut (LNK) file that, when launched, silently triggers the execution of a PowerShell script responsible for retrieving the main payload from an external server (e.g., sorvetenopoate[.]com).







Credits



Cover photo by Debby Hudson on Unsplash.






That's it for this week, and I'll see you next time.

🔍 CTI & Forensik

Cyber Threat Intelligence & Forensik

ATT&CK-Navigator · IoC-Radar · Exploit-Belege
MITRE ATT&CK Matrix Navigator
Enterprise-Matrix · nur belegte Techniken
14 Taktiken
4 belegte Techniken
T1190TA0001 · Initial Access
Exploit Public-Facing Application
Mitigation: M1042 Network Segmentation & WAF Rule Enforcement
Quelle: Kontext-Klassifikation des Artikeltextes
T1059TA0002 · Execution
Command and Scripting Interpreter
Mitigation: M1038 Execution Prevention & Script Block Logging
Quelle: Kontext-Klassifikation des Artikeltextes
T1071TA0011 · Command and Control
Application Layer Protocol (C2)
Mitigation: M1031 Network Intrusion Prevention & Egress Filtering
Quelle: Kontext-Klassifikation des Artikeltextes
T1566TA0001 · Initial Access
Phishing
Mitigation: M1054 User Training & Email Gateway Filtering
Quelle: Kontext-Klassifikation des Artikeltextes
Reconnaissance
Resource Development
Initial Access
Execution
Persistence
Privilege Escalation
Defense Evasion
Credential Access
Discovery
Lateral Movement
Collection
Command and Control
Exfiltration
Impact
CTI Threat Relationship Graph
Akteure · Techniken · Beziehungen
5 Knoten · 4 Relationen
CVE / Incident Threat Actor Software MITRE ATT&CK CWE Weakness IoC
Ähnliche Beiträge
🔍 Verwandte News

Auch interessante Nachrichten Security news weekly round-up - 3rd October 2025

Thematisch verwandte Begriffe: Security, news, weekly, roundup · 6 Treffer

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

💬 Kommentare werden geladen…
Zum Aktualisieren ziehen
Nächster Beitrag