<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="/rss-style.xsl"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:media="http://search.yahoo.com/mrss/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/">
<channel>
<title><![CDATA[tsecurity.de - Malware / Trojaner / Viren]]></title>
<link><![CDATA[https://tsecurity.de/export/rss/malware-trojaner-viren.xml]]></link>
<description><![CDATA[Malware Intelligence & Virus Alerts. Detaillierte Code-Analysen von Ransomware, Trojanern, InfoStealern, Botnetzen und Zero-Day Threat Actors.]]></description>
<language>de-DE</language>
<lastBuildDate>Sun, 20 Sep 2026 06:24:24 +0200</lastBuildDate>
<pubDate>Sun, 20 Sep 2026 06:24:24 +0200</pubDate>
<ttl>15</ttl>
<copyright>2026 tsecurity.de - Malware / Trojaner / Viren</copyright>
<managingEditor>contact@tsecurity.de (tsecurity.de)</managingEditor>
<webMaster>contact@tsecurity.de (tsecurity.de)</webMaster>
<image>
<url>https://tsecurity.de/templates/mydraft-basis-tsecurity.de/media/logo.png</url>
<title><![CDATA[tsecurity.de - Malware / Trojaner / Viren]]></title>
<link><![CDATA[https://tsecurity.de/export/rss/malware-trojaner-viren.xml]]></link>
</image>
<atom:link href="https://tsecurity.de/export/rss/alle-kategorien.xml" rel="self" type="application/rss+xml" />
<item>
<title><![CDATA[LeakWatch KW 38/2026: 490 Millionen Gyazo-Metadaten, Malware aus der Cloud, OpenAI bis zum internen Code offen und Nova Lake leakt an allen Ecken]]></title>
<description><![CDATA[Manchmal besteht eine LeakWatch-Woche aus einem unscharfen Foto eines Grafikkartenkartons, einer CPU-Zeile in irgendeiner Benchmark-Datenbank und einem Leaker, der mit drei Wörtern genügend Interpretationsspielraum für die nächsten vier Monate schafft. Kalenderwoche 38 ist nicht so eine Woche. Zw...]]></description>
<link>https://tsecurity.de/de/4158678/malware-trojaner-viren/leakwatch-kw-382026-490-millionen-gyazo-metadaten-malware-aus-der-cloud-openai-bis-zum-internen-code-offen-und-nova-lake-leakt-an-allen-ecken/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4158678/malware-trojaner-viren/leakwatch-kw-382026-490-millionen-gyazo-metadaten-malware-aus-der-cloud-openai-bis-zum-internen-code-offen-und-nova-lake-leakt-an-allen-ecken/</guid>
<pubDate>Sun, 20 Sep 2026 05:54:15 +0200</pubDate>
<content:encoded><![CDATA[<p>Manchmal besteht eine LeakWatch-Woche aus einem unscharfen Foto eines Grafikkartenkartons, einer CPU-Zeile in irgendeiner Benchmark-Datenbank und einem Leaker, der mit drei Wörtern genügend Interpretationsspielraum für die nächsten vier Monate schafft. Kalenderwoche 38 ist nicht so eine Woche. Zwischen dem 14. und 20. September 2026 sind gleich... <a href="https://www.igorslab.de/leakwatch-kw-38-2026-490-millionen-gyazo-metadaten-malware-aus-der-cloud-openai-bis-zum-internen-code-offen-und-nova-lake-leakt-an-allen-ecken/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[The fake job interview that installs malware]]></title>
<description><![CDATA[Key takeaways The attack arrives at the assessment, which is the one stage in hiring where a candidate is expected to run someone else's code. Microsoft's Defender Experts team documents a campaign it calls Contagious Interview, in which fake recruiters get victims to clone and execute a package ...]]></description>
<link>https://tsecurity.de/de/4158015/malware-trojaner-viren/the-fake-job-interview-that-installs-malware/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4158015/malware-trojaner-viren/the-fake-job-interview-that-installs-malware/</guid>
<pubDate>Sun, 20 Sep 2026 00:33:16 +0200</pubDate>
<content:encoded><![CDATA[<p>Key takeaways The attack arrives at the assessment, which is the one stage in hiring where a candidate is expected to run someone else&#039;s code. Microsoft&#039;s Defender Experts team documents a campaign it calls Contagious Interview, in which fake recruiters get victims to clone and execute a package from a normal-looking repository. Presentation... <a href="https://dev.to/fourleaf/the-fake-job-interview-that-installs-malware-2n1l" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[IT Security News Hourly Summary 2026-09-19 18h : 4 posts]]></title>
<description><![CDATA[4 posts published in the last hour 15:02Google Gemini also Broke Out of Its Test Environment 15:02TigerByte Cyber Emerges From Stealth With $3 Million in Funding 15:02WeaselBiscuit Stealer Found in 13 Malicious npm Packages 15:00IT Security News Hourly Summary 2026-09-19 17h : 4 posts The post IT...]]></description>
<link>https://tsecurity.de/de/4157031/malware-trojaner-viren/it-security-news-hourly-summary-2026-09-19-18h-4-posts/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4157031/malware-trojaner-viren/it-security-news-hourly-summary-2026-09-19-18h-4-posts/</guid>
<pubDate>Sat, 19 Sep 2026 18:22:25 +0200</pubDate>
<content:encoded><![CDATA[<p>4 posts published in the last hour 15:02Google Gemini also Broke Out of Its Test Environment 15:02TigerByte Cyber Emerges From Stealth With $3 Million in Funding 15:02WeaselBiscuit Stealer Found in 13 Malicious npm Packages 15:00IT Security News Hourly Summary 2026-09-19 17h : 4 posts The post IT Security News Hourly Summary 2026-09-19 18h : 4... <a href="https://www.itsecuritynews.info/it-security-news-hourly-summary-2026-09-19-18h-4-posts/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[IT Security News Hourly Summary 2026-09-19 17h : 4 posts]]></title>
<description><![CDATA[4 posts published in the last hour 14:31RatHat Android Malware Uses AI to Control Infected Devices 14:31Identity Visibility in 2026: The Foundation of Identity Security 14:31Agentic security is the billion-dollar challenge for some clever startup to solve 14:01AI Helps Hackers Hijack OpenAI Staff...]]></description>
<link>https://tsecurity.de/de/4156906/malware-trojaner-viren/it-security-news-hourly-summary-2026-09-19-17h-4-posts/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4156906/malware-trojaner-viren/it-security-news-hourly-summary-2026-09-19-17h-4-posts/</guid>
<pubDate>Sat, 19 Sep 2026 17:22:30 +0200</pubDate>
<content:encoded><![CDATA[<p>4 posts published in the last hour 14:31RatHat Android Malware Uses AI to Control Infected Devices 14:31Identity Visibility in 2026: The Foundation of Identity Security 14:31Agentic security is the billion-dollar challenge for some clever startup to solve 14:01AI Helps Hackers Hijack OpenAI Staff Accounts Through a Forum The post IT Security News... <a href="https://www.itsecuritynews.info/it-security-news-hourly-summary-2026-09-19-17h-4-posts/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[WeaselBiscuit Stealer Found in 13 Malicious npm Packages]]></title>
<description><![CDATA[Researchers have discovered 13 npm packages carrying a previously undocumented JavaScript information stealer called WeaselBiscuit, introducing yet another malicious threat to the npm package ecosystem. In addition to linking the packages together via shared indicators, OpenSourceMalware found se...]]></description>
<link>https://tsecurity.de/de/4156905/malware-trojaner-viren/weaselbiscuit-stealer-found-in-13-malicious-npm-packages/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4156905/malware-trojaner-viren/weaselbiscuit-stealer-found-in-13-malicious-npm-packages/</guid>
<pubDate>Sat, 19 Sep 2026 17:22:30 +0200</pubDate>
<content:encoded><![CDATA[<p>Researchers have discovered 13 npm packages carrying a previously undocumented JavaScript information stealer called WeaselBiscuit, introducing yet another malicious threat to the npm package ecosystem. In addition to linking the packages together via shared indicators, OpenSourceMalware found several similarities between BeaverTail and... <a href="https://www.itsecuritynews.info/weaselbiscuit-stealer-found-in-13-malicious-npm-packages/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[RatHat Android Malware Uses AI to Control Infected Devices]]></title>
<description><![CDATA[  A new Android backdoor called RatHat utilizes an AI-powered system to remotely navigate compromised devices, while also stealing sensitive information and using a variety of methods to maintain its presence. Researchers at Zimperium’s zLabs found indications that RatHat may be associated with t...]]></description>
<link>https://tsecurity.de/de/4156836/malware-trojaner-viren/rathat-android-malware-uses-ai-to-control-infected-devices/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4156836/malware-trojaner-viren/rathat-android-malware-uses-ai-to-control-infected-devices/</guid>
<pubDate>Sat, 19 Sep 2026 16:37:16 +0200</pubDate>
<content:encoded><![CDATA[<p>  A new Android backdoor called RatHat utilizes an AI-powered system to remotely navigate compromised devices, while also stealing sensitive information and using a variety of methods to maintain its presence. Researchers at Zimperium’s zLabs found indications that RatHat may be associated with threat actors based in China after they discovered... <a href="https://www.itsecuritynews.info/rathat-android-malware-uses-ai-to-control-infected-devices/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[The best way to check your PC for malware]]></title>
<description><![CDATA[If your PC is slowing down or not behaving as usual, it's worth running through these tips to see if you have malware. Weiterlesen]]></description>
<link>https://tsecurity.de/de/4156825/malware-trojaner-viren/the-best-way-to-check-your-pc-for-malware/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4156825/malware-trojaner-viren/the-best-way-to-check-your-pc-for-malware/</guid>
<pubDate>Sat, 19 Sep 2026 16:32:39 +0200</pubDate>
<content:encoded><![CDATA[<p>If your PC is slowing down or not behaving as usual, it&#039;s worth running through these tips to see if you have malware. <a href="https://www.engadget.com/2257817/best-way-check-pc-malware/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Ransomware reloaded: Jetzt wird mit der Veröffentlichung von privaten Daten gedroht]]></title>
<description><![CDATA[Kriminelle drohen zunehmend mit der Veröffentlichung persönlicher Daten statt „nur“ zu verschlüsseln. Das verändert Risiko und Gegenmaßnahmen vor allem im Privatbereich. Immer häufiger beschränken sich Kriminelle beim Einsatz von Ransomware nicht mehr auf das bloße Verschlüsseln, sondern stehlen ...]]></description>
<link>https://tsecurity.de/de/4156574/malware-trojaner-viren/ransomware-reloaded-jetzt-wird-mit-der-veroeffentlichung-von-privaten-daten-gedroht/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4156574/malware-trojaner-viren/ransomware-reloaded-jetzt-wird-mit-der-veroeffentlichung-von-privaten-daten-gedroht/</guid>
<pubDate>Sat, 19 Sep 2026 13:19:48 +0200</pubDate>
<content:encoded><![CDATA[<p>Kriminelle drohen zunehmend mit der Veröffentlichung persönlicher Daten statt „nur“ zu verschlüsseln. Das verändert Risiko und Gegenmaßnahmen vor allem im Privatbereich. Immer häufiger beschränken sich Kriminelle beim Einsatz von Ransomware nicht mehr auf das bloße Verschlüsseln, sondern stehlen private Informationen und erpressen mit der Drohung,... <a href="https://www.it-daily.net/it-sicherheit/cloud-security/ransomware-reloaded" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Sicherheitskontrolle am Flughafen: Deine Rechte beim Smartphone]]></title>
<description><![CDATA[Darf man mein Smartphone bei der Sicherheitskontrolle des Flughafens beschlagnahmen? Darf man mich dazu zwingen, es zu entsperren? Der Artikel Sicherheitskontrolle am Flughafen: Deine Rechte beim Smartphone erschien zuerst auf TARNKAPPE.INFO Weiterlesen]]></description>
<link>https://tsecurity.de/de/4156405/malware-trojaner-viren/sicherheitskontrolle-am-flughafen-deine-rechte-beim-smartphone/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4156405/malware-trojaner-viren/sicherheitskontrolle-am-flughafen-deine-rechte-beim-smartphone/</guid>
<pubDate>Sat, 19 Sep 2026 10:40:53 +0200</pubDate>
<content:encoded><![CDATA[<p>Darf man mein Smartphone bei der Sicherheitskontrolle des Flughafens beschlagnahmen? Darf man mich dazu zwingen, es zu entsperren? Der Artikel Sicherheitskontrolle am Flughafen: Deine Rechte beim Smartphone erschien zuerst auf TARNKAPPE.INFO <a href="https://tarnkappe.info/tutorials/sicherheitskontrolle-am-flughafen-deine-rechte-beim-smartphone-333590.html" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[New RatHat Android Malware Uses AI to Steal Banking Logins, PINs and OTP Codes]]></title>
<description><![CDATA[Security researchers have discovered a new Android banking Trojan called RatHat. This malware combines artificial intelligence (AI), abuse of accessibility features, and Android Debug Bridge (ADB) capabilities to steal financial credentials, PINs, and one-time passcodes. RatHat Android Malware Ac...]]></description>
<link>https://tsecurity.de/de/4156402/malware-trojaner-viren/new-rathat-android-malware-uses-ai-to-steal-banking-logins-pins-and-otp-codes/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4156402/malware-trojaner-viren/new-rathat-android-malware-uses-ai-to-steal-banking-logins-pins-and-otp-codes/</guid>
<pubDate>Sat, 19 Sep 2026 10:36:15 +0200</pubDate>
<content:encoded><![CDATA[<p>Security researchers have discovered a new Android banking Trojan called RatHat. This malware combines artificial intelligence (AI), abuse of accessibility features, and Android Debug Bridge (ADB) capabilities to steal financial credentials, PINs, and one-time passcodes. RatHat Android Malware According to MalwareBytes, RatHat differs from... <a href="https://cyberpress.org/new-rathat-android-malware-uses-ai-to-steal-banking-logins/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[AI-Powered RatHat Android Trojan Steals Bank Credentials, PINs and MFA Codes]]></title>
<description><![CDATA[Researchers have identified a new Android banking Trojan called RatHat that utilizes artificial intelligence to automate device compromise and steal financial credentials, PINs, and one-time passcodes. Zimperium’s zLabs researchers analyzed this malware, which represents a significant evolution i...]]></description>
<link>https://tsecurity.de/de/4156399/malware-trojaner-viren/ai-powered-rathat-android-trojan-steals-bank-credentials-pins-and-mfa-codes/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4156399/malware-trojaner-viren/ai-powered-rathat-android-trojan-steals-bank-credentials-pins-and-mfa-codes/</guid>
<pubDate>Sat, 19 Sep 2026 10:36:06 +0200</pubDate>
<content:encoded><![CDATA[<p>Researchers have identified a new Android banking Trojan called RatHat that utilizes artificial intelligence to automate device compromise and steal financial credentials, PINs, and one-time passcodes. Zimperium’s zLabs researchers analyzed this malware, which represents a significant evolution in Android threats. AI-Powered RatHat Android Trojan... <a href="https://www.itsecuritynews.info/ai-powered-rathat-android-trojan-steals-bank-credentials-pins-and-mfa-codes/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Hackers Hide PowerShell Malware in Registry, PNG and WAV Files to Deploy XMRig Miner]]></title>
<description><![CDATA[Researchers have uncovered a multi-stage cryptomining campaign that uses PowerShell, Registry-stored payloads, DNS TXT records, PNG images, and WAV audio files to conceal malware and deploy an XMRig-based cryptocurrency miner on compromised Windows systems. The activity was first identified after...]]></description>
<link>https://tsecurity.de/de/4156307/malware-trojaner-viren/hackers-hide-powershell-malware-in-registry-png-and-wav-files-to-deploy-xmrig-miner/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4156307/malware-trojaner-viren/hackers-hide-powershell-malware-in-registry-png-and-wav-files-to-deploy-xmrig-miner/</guid>
<pubDate>Sat, 19 Sep 2026 09:36:39 +0200</pubDate>
<content:encoded><![CDATA[<p>Researchers have uncovered a multi-stage cryptomining campaign that uses PowerShell, Registry-stored payloads, DNS TXT records, PNG images, and WAV audio files to conceal malware and deploy an XMRig-based cryptocurrency miner on compromised Windows systems. The activity was first identified after repeated alerts involving suspicious PowerShell... <a href="https://cyberpress.org/hackers-hide-powershell-malware-in-registry/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[PowerShell Malware Abuses Registry and DNS TXT Records to Deploy XMRig Crypto Miner]]></title>
<description><![CDATA[A sophisticated cryptomining campaign is employing multiple layers of obfuscation to conceal malicious PowerShell payloads and ultimately deploy an XMRig-based cryptocurrency miner. This obfuscation includes Windows Registry entries, DNS TXT records, PNG images, and WAV audio files. The infection...]]></description>
<link>https://tsecurity.de/de/4156306/malware-trojaner-viren/powershell-malware-abuses-registry-and-dns-txt-records-to-deploy-xmrig-crypto-miner/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4156306/malware-trojaner-viren/powershell-malware-abuses-registry-and-dns-txt-records-to-deploy-xmrig-crypto-miner/</guid>
<pubDate>Sat, 19 Sep 2026 09:36:31 +0200</pubDate>
<content:encoded><![CDATA[<p>A sophisticated cryptomining campaign is employing multiple layers of obfuscation to conceal malicious PowerShell payloads and ultimately deploy an XMRig-based cryptocurrency miner. This obfuscation includes Windows Registry entries, DNS TXT records, PNG images, and WAV audio files. The infection was detected after repeated security alerts... <a href="https://www.itsecuritynews.info/powershell-malware-abuses-registry-and-dns-txt-records-to-deploy-xmrig-crypto-miner/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[‘Nudify’ apps: What to do if someone makes a fake nude of you]]></title>
<description><![CDATA[Whether you’re a victim, the parent of a victim, or just concerned, here’s what you can do about fake nude images Weiterlesen]]></description>
<link>https://tsecurity.de/de/4156158/malware-trojaner-viren/nudify-apps-what-to-do-if-someone-makes-a-fake-nude-of-you/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4156158/malware-trojaner-viren/nudify-apps-what-to-do-if-someone-makes-a-fake-nude-of-you/</guid>
<pubDate>Sat, 19 Sep 2026 07:22:33 +0200</pubDate>
<content:encoded><![CDATA[<p>Whether you’re a victim, the parent of a victim, or just concerned, here’s what you can do about fake nude images <a href="https://www.welivesecurity.com/en/privacy/nudify-apps-fake-nude-you/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[exploiting vulnerable CCTV systems]]></title>
<description><![CDATA[Youtube channel name: ninjascum1337 https://www.youtube.com/watch?v=I_gxvKEvi6k&amp;t=4s submitted by /u/LegalPirate1337 [link] [comments] Weiterlesen]]></description>
<link>https://tsecurity.de/de/4156003/malware-trojaner-viren/exploiting-vulnerable-cctv-systems/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4156003/malware-trojaner-viren/exploiting-vulnerable-cctv-systems/</guid>
<pubDate>Sat, 19 Sep 2026 04:03:18 +0200</pubDate>
<content:encoded><![CDATA[<p>Youtube channel name: ninjascum1337 https://www.youtube.com/watch?v=I_gxvKEvi6k&amp;amp;t=4s submitted by /u/LegalPirate1337 [link] [comments] <a href="https://www.reddit.com/r/ExploitDev/comments/1wk8leg/exploiting_vulnerable_cctv_systems/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Rapuncel: Fake GitHub Repositories Disable EDR with a Signed Kernel Driver]]></title>
<description><![CDATA[1. Basic Information Original Title: Threat Intel | One Kit, Forty Companies: How a Malware-as-a-Service Platform Used GitHub as a Distribution Network for its Campaign Source: LastPass TIME / Delphos Labs Published Date: 2026-09-17 Updated Date: None Severity: High Basis for Severity: An active ...]]></description>
<link>https://tsecurity.de/de/4155975/malware-trojaner-viren/rapuncel-fake-github-repositories-disable-edr-with-a-signed-kernel-driver/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4155975/malware-trojaner-viren/rapuncel-fake-github-repositories-disable-edr-with-a-signed-kernel-driver/</guid>
<pubDate>Sat, 19 Sep 2026 03:56:23 +0200</pubDate>
<content:encoded><![CDATA[<p>1. Basic Information Original Title: Threat Intel | One Kit, Forty Companies: How a Malware-as-a-Service Platform Used GitHub as a Distribution Network for its Campaign Source: LastPass TIME / Delphos Labs Published Date: 2026-09-17 Updated Date: None Severity: High Basis for Severity: An active distribution infrastructure impersonating over 40... <a href="https://dev.to/anoymask/rapuncel-fake-github-repositories-disable-edr-with-a-signed-kernel-driver-1nl8" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[i have found a malicious site that tempts me to download a piece of software by impersonating google, can someone explain to me what exactly this file does]]></title>
<description><![CDATA[The site had a "bot verification" which asked me to run a command on the terminal to "unlock" whatever is behind the website (image 1). I immediately got suspicious of what it was telling to do and after some not-so-thorough investigation of mine (I decoded the entire thing), I realized that it w...]]></description>
<link>https://tsecurity.de/de/4155806/malware-trojaner-viren/i-have-found-a-malicious-site-that-tempts-me-to-download-a-piece-of-software-by-impersonating-google-can-someone-explain-to-me-what-exactly-this-file-does/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4155806/malware-trojaner-viren/i-have-found-a-malicious-site-that-tempts-me-to-download-a-piece-of-software-by-impersonating-google-can-someone-explain-to-me-what-exactly-this-file-does/</guid>
<pubDate>Sat, 19 Sep 2026 00:49:53 +0200</pubDate>
<content:encoded><![CDATA[<p>The site had a &quot;bot verification&quot; which asked me to run a command on the terminal to &quot;unlock&quot; whatever is behind the website (image 1). I immediately got suspicious of what it was telling to do and after some not-so-thorough investigation of mine (I decoded the entire thing), I realized that it was a command to download an external file into my... <a href="https://www.reddit.com/r/MalwareAnalysis/comments/1wjyndw/i_have_found_a_malicious_site_that_tempts_me_to/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Brevo Supply-Chain Attack Infected Over 100,000 Websites]]></title>
<description><![CDATA[A Brevo supply-chain attack used compromised Cloudflare access to inject malware into websites, potentially affecting over 100,000 sites. Brevo, formerly known as Sendinblue, is a French cloud-based marketing and customer communication platform whose clients include eBay, Louis Vuitton and Michel...]]></description>
<link>https://tsecurity.de/de/4155765/malware-trojaner-viren/brevo-supply-chain-attack-infected-over-100000-websites/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4155765/malware-trojaner-viren/brevo-supply-chain-attack-infected-over-100000-websites/</guid>
<pubDate>Sat, 19 Sep 2026 00:06:35 +0200</pubDate>
<content:encoded><![CDATA[<p>A Brevo supply-chain attack used compromised Cloudflare access to inject malware into websites, potentially affecting over 100,000 sites. Brevo, formerly known as Sendinblue, is a French cloud-based marketing and customer communication platform whose clients include eBay, Louis Vuitton and Michelin. The company was first compromised on September... <a href="https://www.itsecuritynews.info/brevo-supply-chain-attack-infected-over-100000-websites/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[IT Security News Hourly Summary 2026-09-18 23h : 4 posts]]></title>
<description><![CDATA[4 posts published in the last hour 20:31Attacker Hijacks AI Coding Assistant Session, Spreads Shai-Hulud Across About 100 Repositories 20:31Public Exploits Released for Four Linux Kernel Flaws That Enable Local Root 20:02HBO Max Reddit Account Hacked: 108 Malicious Ads Push ClickFix Malware 20:00...]]></description>
<link>https://tsecurity.de/de/4155708/malware-trojaner-viren/it-security-news-hourly-summary-2026-09-18-23h-4-posts/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4155708/malware-trojaner-viren/it-security-news-hourly-summary-2026-09-18-23h-4-posts/</guid>
<pubDate>Fri, 18 Sep 2026 23:07:19 +0200</pubDate>
<content:encoded><![CDATA[<p>4 posts published in the last hour 20:31Attacker Hijacks AI Coding Assistant Session, Spreads Shai-Hulud Across About 100 Repositories 20:31Public Exploits Released for Four Linux Kernel Flaws That Enable Local Root 20:02HBO Max Reddit Account Hacked: 108 Malicious Ads Push ClickFix Malware 20:00IT Security News Hourly Summary 2026-09-18 22h : 4... <a href="https://www.itsecuritynews.info/it-security-news-hourly-summary-2026-09-18-23h-4-posts/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Jetzt aktualisieren: Angreifer konnten beliebige Daten von Synology-NAS auslesen - Heise]]></title>
<description><![CDATA[It was translated with ... Newsletter. Ob Sicherheitslücken, Viren oder Trojaner – alle sicherheitsrelevanten Meldungen gibts bei heise security ... Weiterlesen]]></description>
<link>https://tsecurity.de/de/4155605/malware-trojaner-viren/jetzt-aktualisieren-angreifer-konnten-beliebige-daten-von-synology-nas-auslesen-heise/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4155605/malware-trojaner-viren/jetzt-aktualisieren-angreifer-konnten-beliebige-daten-von-synology-nas-auslesen-heise/</guid>
<pubDate>Fri, 18 Sep 2026 22:03:44 +0200</pubDate>
<content:encoded><![CDATA[<p>It was translated with ... Newsletter. Ob Sicherheitslücken, Viren oder Trojaner – alle sicherheitsrelevanten Meldungen gibts bei heise security ... <a href="https://www.google.com/url?rct=j&amp;sa=t&amp;url=https://www.heise.de/news/Jetzt-aktualisieren-Angreifer-konnten-beliebige-Daten-von-Synology-NAS-auslesen-11458757.html&amp;ct=ga&amp;cd=CAIyGTRiZTZmY2RmMzZhYjA0M2Y6ZGU6ZGU6REU&amp;usg=AOvVaw3vY0r1CXrMgzJCrNQ7sJCP" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[New Android malware can deploy AI to automate device control — and it can even bring itself back from the dead]]></title>
<description><![CDATA[Zimperium zLabs discovered RedHat, a Chinese‑origin Android banking trojan with AI assistantAI interprets screen layouts in real‑time, enabling credential theft and bypassing app redesignsDistributed via third‑party stores, social media, malvertising, and SMS; persistence blocks uninstall attempt...]]></description>
<link>https://tsecurity.de/de/4155594/malware-trojaner-viren/new-android-malware-can-deploy-ai-to-automate-device-control-and-it-can-even-bring-itself-back-from-the-dead/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4155594/malware-trojaner-viren/new-android-malware-can-deploy-ai-to-automate-device-control-and-it-can-even-bring-itself-back-from-the-dead/</guid>
<pubDate>Fri, 18 Sep 2026 22:02:35 +0200</pubDate>
<content:encoded><![CDATA[<p>Zimperium zLabs discovered RedHat, a Chinese‑origin Android banking trojan with AI assistantAI interprets screen layouts in real‑time, enabling credential theft and bypassing app redesignsDistributed via third‑party stores, social media, malvertising, and SMS; persistence blocks uninstall attemptsThere is an Android malware out there that comes... <a href="https://www.techradar.com/pro/security/new-android-malware-can-deploy-ai-to-automate-device-control-and-it-can-even-bring-itself-back-from-the-dead" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[InjectEave: Elektromagnetischer Angriff macht elektronische Geräte abhörbar]]></title>
<description><![CDATA[InjectEave zeigt, wie elektromagnetische Angriffe Signale aus elektronischen Geräten aus der Ferne rekonstruieren können. Der Artikel InjectEave: Elektromagnetischer Angriff macht elektronische Geräte abhörbar erschien zuerst auf TARNKAPPE.INFO Weiterlesen]]></description>
<link>https://tsecurity.de/de/4155522/malware-trojaner-viren/injecteave-elektromagnetischer-angriff-macht-elektronische-geraete-abhoerbar/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4155522/malware-trojaner-viren/injecteave-elektromagnetischer-angriff-macht-elektronische-geraete-abhoerbar/</guid>
<pubDate>Fri, 18 Sep 2026 21:13:55 +0200</pubDate>
<content:encoded><![CDATA[<p>InjectEave zeigt, wie elektromagnetische Angriffe Signale aus elektronischen Geräten aus der Ferne rekonstruieren können. Der Artikel InjectEave: Elektromagnetischer Angriff macht elektronische Geräte abhörbar erschien zuerst auf TARNKAPPE.INFO <a href="https://tarnkappe.info/artikel/it-sicherheit/injecteave-elektromagnetischer-angriff-333581.html" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Apple baut einen Exploit-Wächter in den iOS-Kernel ein]]></title>
<description><![CDATA[Cybersicherheit ios apple ios 27.2 ios sicherheit endpoint security kernel exploit spyware cybersicherheit. Inhaltsverzeichnis. 1.Was ist ... Weiterlesen]]></description>
<link>https://tsecurity.de/de/4155518/malware-trojaner-viren/apple-baut-einen-exploit-waechter-in-den-ios-kernel-ein/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4155518/malware-trojaner-viren/apple-baut-einen-exploit-waechter-in-den-ios-kernel-ein/</guid>
<pubDate>Fri, 18 Sep 2026 21:08:46 +0200</pubDate>
<content:encoded><![CDATA[<p>Cybersicherheit ios apple ios 27.2 ios sicherheit endpoint security kernel exploit spyware cybersicherheit. Inhaltsverzeichnis. 1.Was ist ... <a href="https://www.google.com/url?rct=j&amp;sa=t&amp;url=https://pasqualepillitteri.it/de/news/16698/apple-ios-kernel-sicherheitsmonitor&amp;ct=ga&amp;cd=CAIyGTViNmI2YzJlZTdlY2E1ZTI6ZGU6ZGU6REU&amp;usg=AOvVaw0PXdHpsKo_q2irlj9MITUy" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Operation RapidRust: Transparenter Tribe nutzt GitHub-C2 und Rust-Malware]]></title>
<description><![CDATA[LONDON (IT BOLTWISE) – Ein neuer Kampagnenkomplex der Gruppe Transparent Tribe zielt laut Zscaler ThreatLabz auf Regierungs- und Verteidigungsumgebungen in Indien und Afghanistan. Im Zentrum steht Operation RapidRust, die erstmals mehrere Rust- und Script-Bausteine namens RUSTYSHADE, RUSTYMOVE, P...]]></description>
<link>https://tsecurity.de/de/4155365/malware-trojaner-viren/operation-rapidrust-transparenter-tribe-nutzt-github-c2-und-rust-malware/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4155365/malware-trojaner-viren/operation-rapidrust-transparenter-tribe-nutzt-github-c2-und-rust-malware/</guid>
<pubDate>Fri, 18 Sep 2026 19:38:46 +0200</pubDate>
<content:encoded><![CDATA[<p>LONDON (IT BOLTWISE) – Ein neuer Kampagnenkomplex der Gruppe Transparent Tribe zielt laut Zscaler ThreatLabz auf Regierungs- und Verteidigungsumgebungen in Indien und Afghanistan. Im Zentrum steht Operation RapidRust, die erstmals mehrere Rust- und Script-Bausteine namens RUSTYSHADE, RUSTYMOVE, PSNATCH und BASHNATCH kombiniert. Auffällig ist vor... <a href="https://www.it-boltwise.de/operation-rapidrust-transparenter-tribe-nutzt-github-c2-und-rust-malware.html" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[IT Security News Hourly Summary 2026-09-18 19h : 17 posts]]></title>
<description><![CDATA[17 posts published in the last hour 16:31Google Opens Google Home to Claude and Other AI Agents — Here’s What They Can Control 16:31Settra ransomware variant deployed in recent attacks 16:312026 Péter Szőr Award shortlisted nominees 16:31FBI: Fake cop and government impersonation scams cost victi...]]></description>
<link>https://tsecurity.de/de/4155359/malware-trojaner-viren/it-security-news-hourly-summary-2026-09-18-19h-17-posts/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4155359/malware-trojaner-viren/it-security-news-hourly-summary-2026-09-18-19h-17-posts/</guid>
<pubDate>Fri, 18 Sep 2026 19:38:41 +0200</pubDate>
<content:encoded><![CDATA[<p>17 posts published in the last hour 16:31Google Opens Google Home to Claude and Other AI Agents — Here’s What They Can Control 16:31Settra ransomware variant deployed in recent attacks 16:312026 Péter Szőr Award shortlisted nominees 16:31FBI: Fake cop and government impersonation scams cost victims $1.6B 16:31Google Pixel owners urged to patch... <a href="https://www.itsecuritynews.info/it-security-news-hourly-summary-2026-09-18-19h-17-posts/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Don’t Call Us, We’ll Call Your APIs | TraderTraitor Backdoors Resurface on Victim With No Crypto Ties]]></title>
<description><![CDATA[North Korean operators built a foothold on a DevOps engineer's Mac in a campaign whose job interview lures deliver malware via Terraform lock files. This article has been indexed from SentinelLabs – We are hunters, reversers, exploit developers, and tinkerers shedding light on the world of malwar...]]></description>
<link>https://tsecurity.de/de/4155355/malware-trojaner-viren/dont-call-us-well-call-your-apis-tradertraitor-backdoors-resurface-on-victim-with-no-crypto-ties/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4155355/malware-trojaner-viren/dont-call-us-well-call-your-apis-tradertraitor-backdoors-resurface-on-victim-with-no-crypto-ties/</guid>
<pubDate>Fri, 18 Sep 2026 19:38:41 +0200</pubDate>
<content:encoded><![CDATA[<p>North Korean operators built a foothold on a DevOps engineer&#039;s Mac in a campaign whose job interview lures deliver malware via Terraform lock files. This article has been indexed from SentinelLabs – We are hunters, reversers, exploit developers, and tinkerers shedding light on the world of malware, exploits, APTs, and cybercrime across all... <a href="https://www.itsecuritynews.info/dont-call-us-well-call-your-apis-tradertraitor-backdoors-resurface-on-victim-with-no-crypto-ties/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Hackers Compromise iTorrents Repository to Spread MovieReaper Malware Through Fake Movie Torrents]]></title>
<description><![CDATA[Cybercriminals have found a clever new trick to spread malware. They broke into a shared torrent repository that many trackers rely on. Then they used it to push fake movie downloads onto unsuspecting users. According to SecureList, the campaign started around mid-August 2026. It has already reac...]]></description>
<link>https://tsecurity.de/de/4155346/malware-trojaner-viren/hackers-compromise-itorrents-repository-to-spread-moviereaper-malware-through-fake-movie-torrents/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4155346/malware-trojaner-viren/hackers-compromise-itorrents-repository-to-spread-moviereaper-malware-through-fake-movie-torrents/</guid>
<pubDate>Fri, 18 Sep 2026 19:36:44 +0200</pubDate>
<content:encoded><![CDATA[<p>Cybercriminals have found a clever new trick to spread malware. They broke into a shared torrent repository that many trackers rely on. Then they used it to push fake movie downloads onto unsuspecting users. According to SecureList, the campaign started around mid-August 2026. It has already reached several hundred victims across many countries.... <a href="https://privacysavvy.com/news/cybersecurity/itorrents-repository-moviereaper-malware-fake-films/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[New Android malware uses AI to steal bank logins and PINs]]></title>
<description><![CDATA[RatHat can navigate infected phones while stealing bank logins, authentication codes, and screen-lock PINs. This article has been indexed from Malwarebytes Read the original article: New Android malware uses AI to steal bank logins and PINs The post New Android malware uses AI to steal bank login...]]></description>
<link>https://tsecurity.de/de/4155210/malware-trojaner-viren/new-android-malware-uses-ai-to-steal-bank-logins-and-pins/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4155210/malware-trojaner-viren/new-android-malware-uses-ai-to-steal-bank-logins-and-pins/</guid>
<pubDate>Fri, 18 Sep 2026 18:38:44 +0200</pubDate>
<content:encoded><![CDATA[<p>RatHat can navigate infected phones while stealing bank logins, authentication codes, and screen-lock PINs. This article has been indexed from Malwarebytes Read the original article: New Android malware uses AI to steal bank logins and PINs The post New Android malware uses AI to steal bank logins and PINs appeared first on IT Security News. <a href="https://www.itsecuritynews.info/new-android-malware-uses-ai-to-steal-bank-logins-and-pins/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Settra ransomware variant deployed in recent attacks]]></title>
<description><![CDATA[Security researchers warned that hackers are using VPN credentials for initial access and deploying RMM tools. This article has been indexed from Cybersecurity Dive – Latest News Read the original article: Settra ransomware variant deployed in recent attacks The post Settra ransomware variant dep...]]></description>
<link>https://tsecurity.de/de/4155206/malware-trojaner-viren/settra-ransomware-variant-deployed-in-recent-attacks/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4155206/malware-trojaner-viren/settra-ransomware-variant-deployed-in-recent-attacks/</guid>
<pubDate>Fri, 18 Sep 2026 18:38:44 +0200</pubDate>
<content:encoded><![CDATA[<p>Security researchers warned that hackers are using VPN credentials for initial access and deploying RMM tools. This article has been indexed from Cybersecurity Dive – Latest News Read the original article: Settra ransomware variant deployed in recent attacks The post Settra ransomware variant deployed in recent attacks appeared first on IT... <a href="https://www.itsecuritynews.info/settra-ransomware-variant-deployed-in-recent-attacks/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Telnet Is Still Open: Why the IoT Botnet Notices Keep Describing the Same Reachable Population]]></title>
<description><![CDATA[Telnet Is Still Open: Why the IoT Botnet Notices Keep Describing the Same Reachable Population When a national CERT publishes a notice about active botnet families, the intrusion methods listed are usually unremarkable. The August 2026 notice from China's National Network and Information Security...]]></description>
<link>https://tsecurity.de/de/4155115/malware-trojaner-viren/telnet-is-still-open-why-the-iot-botnet-notices-keep-describing-the-same-reachable-population/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4155115/malware-trojaner-viren/telnet-is-still-open-why-the-iot-botnet-notices-keep-describing-the-same-reachable-population/</guid>
<pubDate>Fri, 18 Sep 2026 17:58:17 +0200</pubDate>
<content:encoded><![CDATA[<p>Telnet Is Still Open: Why the IoT Botnet Notices Keep Describing the Same Reachable Population When a national CERT publishes a notice about active botnet families, the intrusion methods listed are usually unremarkable. The August 2026 notice from China&#039;s National Network and Information Security Notification Centre named five cross-border... <a href="https://dev.to/bianliang/telnet-is-still-open-why-the-iot-botnet-notices-keep-describing-the-same-reachable-population-d8n" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Four Countries Attribute “Contagious Interview” Fake-Job Malware Campaign to North Korea’s WaterPlum]]></title>
<description><![CDATA[Japan, the United States, Australia and Germany, today issued a joint cybersecurity advisory formally attributing the long-running "Contagious Interview" campaign to a North Korean state-sponsored group they are calling WaterPlum. The operation has infected more than 30,000 computers in more than...]]></description>
<link>https://tsecurity.de/de/4154978/malware-trojaner-viren/four-countries-attribute-contagious-interview-fake-job-malware-campaign-to-north-koreas-waterplum/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4154978/malware-trojaner-viren/four-countries-attribute-contagious-interview-fake-job-malware-campaign-to-north-koreas-waterplum/</guid>
<pubDate>Fri, 18 Sep 2026 17:23:39 +0200</pubDate>
<content:encoded><![CDATA[<p>Japan, the United States, Australia and Germany, today issued a joint cybersecurity advisory formally attributing the long-running &quot;Contagious Interview&quot; campaign to a North Korean state-sponsored group they are calling WaterPlum. The operation has infected more than 30,000 computers in more than 100 countries and stolen about 1.7 billion yen, or... <a href="https://thecyberexpress.com/waterplum-contagious-interview-north-korea/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Cyber Briefing: 2026.09.18]]></title>
<description><![CDATA[Iranian malware is using Telegram for command and control, AI is being used to build convincing fake antivirus renewal scams, and an autonomous AI agent reportedly accessed systems, altered personal.. This article has been indexed from CyberMaterial Read the original article: Cyber Briefing: 2026...]]></description>
<link>https://tsecurity.de/de/4154972/malware-trojaner-viren/cyber-briefing-20260918/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4154972/malware-trojaner-viren/cyber-briefing-20260918/</guid>
<pubDate>Fri, 18 Sep 2026 17:23:12 +0200</pubDate>
<content:encoded><![CDATA[<p>Iranian malware is using Telegram for command and control, AI is being used to build convincing fake antivirus renewal scams, and an autonomous AI agent reportedly accessed systems, altered personal.. This article has been indexed from CyberMaterial Read the original article: Cyber Briefing: 2026.09.18 The post Cyber Briefing: 2026.09.18 appeared... <a href="https://www.itsecuritynews.info/cyber-briefing-2026-09-18/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[IT Security News Hourly Summary 2026-09-18 17h : 16 posts]]></title>
<description><![CDATA[16 posts published in the last hour 14:3136,769 Self-Hosted AI Services Exposed Online — What Security Teams Should Check 14:31In Other News: Ransomware Developer Sentenced, Plugin4Shell AI Attack, Critical SAP Flaw 14:31Cyber Briefing: 2026.09.18 14:31Meta Plans Smart Glasses Without Camera, Ami...]]></description>
<link>https://tsecurity.de/de/4154971/malware-trojaner-viren/it-security-news-hourly-summary-2026-09-18-17h-16-posts/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4154971/malware-trojaner-viren/it-security-news-hourly-summary-2026-09-18-17h-16-posts/</guid>
<pubDate>Fri, 18 Sep 2026 17:23:12 +0200</pubDate>
<content:encoded><![CDATA[<p>16 posts published in the last hour 14:3136,769 Self-Hosted AI Services Exposed Online — What Security Teams Should Check 14:31In Other News: Ransomware Developer Sentenced, Plugin4Shell AI Attack, Critical SAP Flaw 14:31Cyber Briefing: 2026.09.18 14:31Meta Plans Smart Glasses Without Camera, Amid Complaints 14:03New Settra Ransomware Variant... <a href="https://www.itsecuritynews.info/it-security-news-hourly-summary-2026-09-18-17h-16-posts/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Malware-Falle auf 100.000 Internetseiten - COMPUTER BILD]]></title>
<description><![CDATA[Großangriff auf mehr als 100.000 Internetseiten: Hacker verteilten ClickFix-Malware über einen beliebten Online-Dienst und lockten Nutzer in die Falle. submitted by /u/Altruistic_Level9640 [link] [comments] Weiterlesen]]></description>
<link>https://tsecurity.de/de/4154967/malware-trojaner-viren/malware-falle-auf-100000-internetseiten-computer-bild/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4154967/malware-trojaner-viren/malware-falle-auf-100000-internetseiten-computer-bild/</guid>
<pubDate>Fri, 18 Sep 2026 17:23:08 +0200</pubDate>
<content:encoded><![CDATA[<p>Großangriff auf mehr als 100.000 Internetseiten: Hacker verteilten ClickFix-Malware über einen beliebten Online-Dienst und lockten Nutzer in die Falle. submitted by /u/Altruistic_Level9640 [link] [comments] <a href="https://www.reddit.com/r/Computersicherheit/comments/1wjrz5n/malwarefalle_auf_100000_internetseiten_computer/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Fake LastPass Authenticator GitHub repos push new Rapuncel infostealer]]></title>
<description><![CDATA[ An ongoing malware campaign uses SEO-optimized GitHub repositories to impersonate well-known software firms to push a previously undocumented information stealer called Rapuncel. [...] Weiterlesen]]></description>
<link>https://tsecurity.de/de/4154962/malware-trojaner-viren/fake-lastpass-authenticator-github-repos-push-new-rapuncel-infostealer/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4154962/malware-trojaner-viren/fake-lastpass-authenticator-github-repos-push-new-rapuncel-infostealer/</guid>
<pubDate>Fri, 18 Sep 2026 17:19:53 +0200</pubDate>
<content:encoded><![CDATA[<p> An ongoing malware campaign uses SEO-optimized GitHub repositories to impersonate well-known software firms to push a previously undocumented information stealer called Rapuncel. [...] <a href="https://www.bleepingcomputer.com/news/security/fake-lastpass-authenticator-github-repos-push-new-rapuncel-infostealer/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[In Other News: Ransomware Developer Sentenced, Plugin4Shell AI Attack, Critical SAP Flaw]]></title>
<description><![CDATA[Noteworthy stories that might have slipped under the radar: Mandiant's 2026 AI risk report, PhantomRaven malware used by bug bounty hunter, WordPress plugin bug exploited. The post In Other News: Ransomware Developer Sentenced, Plugin4Shell AI Attack, Critical SAP Flaw appeared first on SecurityW...]]></description>
<link>https://tsecurity.de/de/4154960/malware-trojaner-viren/in-other-news-ransomware-developer-sentenced-plugin4shell-ai-attack-critical-sap-flaw/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4154960/malware-trojaner-viren/in-other-news-ransomware-developer-sentenced-plugin4shell-ai-attack-critical-sap-flaw/</guid>
<pubDate>Fri, 18 Sep 2026 17:19:37 +0200</pubDate>
<content:encoded><![CDATA[<p>Noteworthy stories that might have slipped under the radar: Mandiant&#039;s 2026 AI risk report, PhantomRaven malware used by bug bounty hunter, WordPress plugin bug exploited. The post In Other News: Ransomware Developer Sentenced, Plugin4Shell AI Attack, Critical SAP Flaw appeared first on SecurityWeek. <a href="https://www.securityweek.com/in-other-news-ransomware-developer-sentenced-plugin4shell-ai-attack-critical-sap-flaw/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[AI Agents Now Run Ransomware Attacks End-to-End Without Human Operators]]></title>
<description><![CDATA[Ransomware attacks are entering a new phase. Researchers have documented a campaign in which an AI agent planned, executed, and escalated an extortion operation without evidence that a human approved its actions. The operation, tracked as JADEPUFFER, used an exposed AI workflow server to steal cr...]]></description>
<link>https://tsecurity.de/de/4154801/malware-trojaner-viren/ai-agents-now-run-ransomware-attacks-end-to-end-without-human-operators/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4154801/malware-trojaner-viren/ai-agents-now-run-ransomware-attacks-end-to-end-without-human-operators/</guid>
<pubDate>Fri, 18 Sep 2026 16:23:38 +0200</pubDate>
<content:encoded><![CDATA[<p>Ransomware attacks are entering a new phase. Researchers have documented a campaign in which an AI agent planned, executed, and escalated an extortion operation without evidence that a human approved its actions. The operation, tracked as JADEPUFFER, used an exposed AI workflow server to steal credentials, reach databases, encrypt records, and... <a href="https://cybersecuritynews.com/ai-agents-3/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Feral Wolf Ransomware Attacks Exploit Atlassian Confluence and Misconfigured 1C Systems]]></title>
<description><![CDATA[Feral Wolf is using exposed business software and weak server settings to reach corporate networks, then locking files with ransomware. The campaign shows how one overlooked internet-facing system can become the starting point for a much larger incident. The group targeted Russian organizations i...]]></description>
<link>https://tsecurity.de/de/4154800/malware-trojaner-viren/feral-wolf-ransomware-attacks-exploit-atlassian-confluence-and-misconfigured-1c-systems/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4154800/malware-trojaner-viren/feral-wolf-ransomware-attacks-exploit-atlassian-confluence-and-misconfigured-1c-systems/</guid>
<pubDate>Fri, 18 Sep 2026 16:23:37 +0200</pubDate>
<content:encoded><![CDATA[<p>Feral Wolf is using exposed business software and weak server settings to reach corporate networks, then locking files with ransomware. The campaign shows how one overlooked internet-facing system can become the starting point for a much larger incident. The group targeted Russian organizations in retail, construction, manufacturing, and... <a href="https://cybersecuritynews.com/feral-wolf-ransomware/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[US, UK, Dutch Expose Iranian Chosen Brick Malware]]></title>
<description><![CDATA[Cybersecurity agencies from the United States, United Kingdom, and the Netherlands have published a joint advisory exposing Iranian surveillance malware known as Chosen Brick. This article has been indexed from CyberMaterial Read the original article: US, UK, Dutch Expose Iranian Chosen Brick Mal...]]></description>
<link>https://tsecurity.de/de/4154794/malware-trojaner-viren/us-uk-dutch-expose-iranian-chosen-brick-malware/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4154794/malware-trojaner-viren/us-uk-dutch-expose-iranian-chosen-brick-malware/</guid>
<pubDate>Fri, 18 Sep 2026 16:23:08 +0200</pubDate>
<content:encoded><![CDATA[<p>Cybersecurity agencies from the United States, United Kingdom, and the Netherlands have published a joint advisory exposing Iranian surveillance malware known as Chosen Brick. This article has been indexed from CyberMaterial Read the original article: US, UK, Dutch Expose Iranian Chosen Brick Malware The post US, UK, Dutch Expose Iranian Chosen... <a href="https://www.itsecuritynews.info/us-uk-dutch-expose-iranian-chosen-brick-malware/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[IT Security News Hourly Summary 2026-09-18 16h : 19 posts]]></title>
<description><![CDATA[19 posts published in the last hour 13:31Hacker ‘Breached Italian Gov’t Email’ To Steal Revolut Data 13:31Feral Wolf Hackers Exploit Confluence and 1C to Deploy GenieLocker Ransomware 13:31US, UK, Dutch Expose Iranian Chosen Brick Malware 13:31NCSC and Allies Warn of Iranian Spyware Campaign 13:3...]]></description>
<link>https://tsecurity.de/de/4154793/malware-trojaner-viren/it-security-news-hourly-summary-2026-09-18-16h-19-posts/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4154793/malware-trojaner-viren/it-security-news-hourly-summary-2026-09-18-16h-19-posts/</guid>
<pubDate>Fri, 18 Sep 2026 16:23:08 +0200</pubDate>
<content:encoded><![CDATA[<p>19 posts published in the last hour 13:31Hacker ‘Breached Italian Gov’t Email’ To Steal Revolut Data 13:31Feral Wolf Hackers Exploit Confluence and 1C to Deploy GenieLocker Ransomware 13:31US, UK, Dutch Expose Iranian Chosen Brick Malware 13:31NCSC and Allies Warn of Iranian Spyware Campaign 13:31NIS-2: Why practical relevance is crucial in... <a href="https://www.itsecuritynews.info/it-security-news-hourly-summary-2026-09-18-16h-19-posts/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Brevo Breach Exposes Customer Websites to ClickFix Malware]]></title>
<description><![CDATA[Email marketing and customer relationship management platform Brevo, formerly known as Sendinblue, suffered a supply chain attack in which malicious code was able to reach Brevo's own websites as well as customers' websites utilizing embedded Brevo services.  Researchers at Sansec discovered that...]]></description>
<link>https://tsecurity.de/de/4154792/malware-trojaner-viren/brevo-breach-exposes-customer-websites-to-clickfix-malware/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4154792/malware-trojaner-viren/brevo-breach-exposes-customer-websites-to-clickfix-malware/</guid>
<pubDate>Fri, 18 Sep 2026 16:23:08 +0200</pubDate>
<content:encoded><![CDATA[<p>Email marketing and customer relationship management platform Brevo, formerly known as Sendinblue, suffered a supply chain attack in which malicious code was able to reach Brevo&#039;s own websites as well as customers&#039; websites utilizing embedded Brevo services.  Researchers at Sansec discovered that the incident was much more extensive than the six... <a href="https://www.itsecuritynews.info/brevo-breach-exposes-customer-websites-to-clickfix-malware/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[New Settra Ransomware Variant Deployed in Attacks on Retail and Manufacturing]]></title>
<description><![CDATA[Huntress researchers highlighted a new ransomware variant, named Settra, and the post-compromise techniques used in two recent attacks Weiterlesen]]></description>
<link>https://tsecurity.de/de/4154789/malware-trojaner-viren/new-settra-ransomware-variant-deployed-in-attacks-on-retail-and-manufacturing/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4154789/malware-trojaner-viren/new-settra-ransomware-variant-deployed-in-attacks-on-retail-and-manufacturing/</guid>
<pubDate>Fri, 18 Sep 2026 16:20:51 +0200</pubDate>
<content:encoded><![CDATA[<p>Huntress researchers highlighted a new ransomware variant, named Settra, and the post-compromise techniques used in two recent attacks <a href="https://www.infosecurity-magazine.com/news/settra-ransomware-retail/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Feral Wolf Hackers Exploit Confluence and 1C to Deploy GenieLocker Ransomware]]></title>
<description><![CDATA[Feral Wolf has expanded its ransomware tradecraft by abusing exposed Atlassian Confluence servers and insecure 1C:Enterprise deployments to gain access to Russian corporate networks before deploying GenieLocker ransomware. The campaign, tracked from May through August 2026, targeted organizations...]]></description>
<link>https://tsecurity.de/de/4154663/malware-trojaner-viren/feral-wolf-hackers-exploit-confluence-and-1c-to-deploy-genielocker-ransomware/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4154663/malware-trojaner-viren/feral-wolf-hackers-exploit-confluence-and-1c-to-deploy-genielocker-ransomware/</guid>
<pubDate>Fri, 18 Sep 2026 15:23:29 +0200</pubDate>
<content:encoded><![CDATA[<p>Feral Wolf has expanded its ransomware tradecraft by abusing exposed Atlassian Confluence servers and insecure 1C:Enterprise deployments to gain access to Russian corporate networks before deploying GenieLocker ransomware. The campaign, tracked from May through August 2026, targeted organizations in the retail, construction, manufacturing, and IT... <a href="https://gbhackers.com/genielocker-ransomware/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[IT Security News Hourly Summary 2026-09-18 15h : 9 posts]]></title>
<description><![CDATA[9 posts published in the last hour 12:31GenAI-Powered ‘RatHat’ Android Malware Bypasses App Sandboxes via ADB 12:31Protesters Fight Microsoft’s Huge Leeds Data Centre 12:31Attackers Exploit WooCommerce Wholesale Lead Capture Flaw to Plant PHP Web Shells 12:31JADEPUFFER Evolves Agentic Ransomware ...]]></description>
<link>https://tsecurity.de/de/4154656/malware-trojaner-viren/it-security-news-hourly-summary-2026-09-18-15h-9-posts/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4154656/malware-trojaner-viren/it-security-news-hourly-summary-2026-09-18-15h-9-posts/</guid>
<pubDate>Fri, 18 Sep 2026 15:23:13 +0200</pubDate>
<content:encoded><![CDATA[<p>9 posts published in the last hour 12:31GenAI-Powered ‘RatHat’ Android Malware Bypasses App Sandboxes via ADB 12:31Protesters Fight Microsoft’s Huge Leeds Data Centre 12:31Attackers Exploit WooCommerce Wholesale Lead Capture Flaw to Plant PHP Web Shells 12:31JADEPUFFER Evolves Agentic Ransomware to Target AI Models and Training Data 12:31Two-week... <a href="https://www.itsecuritynews.info/it-security-news-hourly-summary-2026-09-18-15h-9-posts/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[New SETTRA Ransomware Uses MeshAgent RMM and BYOVD to Encrypt Windows Systems]]></title>
<description><![CDATA[A newly observed ransomware operation dubbed SETTRA is abusing the legitimate MeshAgent remote monitoring and management platform for persistence while using recovery-inhibition and defense-evasion techniques to maximize the impact of Windows encryption attacks. Huntress investigated two SETTRA i...]]></description>
<link>https://tsecurity.de/de/4154654/malware-trojaner-viren/new-settra-ransomware-uses-meshagent-rmm-and-byovd-to-encrypt-windows-systems/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4154654/malware-trojaner-viren/new-settra-ransomware-uses-meshagent-rmm-and-byovd-to-encrypt-windows-systems/</guid>
<pubDate>Fri, 18 Sep 2026 15:23:13 +0200</pubDate>
<content:encoded><![CDATA[<p>A newly observed ransomware operation dubbed SETTRA is abusing the legitimate MeshAgent remote monitoring and management platform for persistence while using recovery-inhibition and defense-evasion techniques to maximize the impact of Windows encryption attacks. Huntress investigated two SETTRA incidents in July and September 2026, uncovering a... <a href="https://www.itsecuritynews.info/new-settra-ransomware-uses-meshagent-rmm-and-byovd-to-encrypt-windows-systems/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Detecting ransomware with eBPF in Rust]]></title>
<description><![CDATA[Detecting ransomware with eBPF in Rust Title: Detecting ransomware with eBPF in Rust Target: ~1000 words, B1-safe English, working-code-first Build: demo + article for DEV.to / Draft.dev share Source repo: github.com/BartoszOsiej/talus-process-monitor (MIT) 1. The idea (hook) Ransomware works in ...]]></description>
<link>https://tsecurity.de/de/4154560/malware-trojaner-viren/detecting-ransomware-with-ebpf-in-rust/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4154560/malware-trojaner-viren/detecting-ransomware-with-ebpf-in-rust/</guid>
<pubDate>Fri, 18 Sep 2026 14:47:29 +0200</pubDate>
<content:encoded><![CDATA[<p>Detecting ransomware with eBPF in Rust Title: Detecting ransomware with eBPF in Rust Target: ~1000 words, B1-safe English, working-code-first Build: demo + article for DEV.to / Draft.dev share Source repo: github.com/BartoszOsiej/talus-process-monitor (MIT) 1. The idea (hook) Ransomware works in a simple way: it opens your files, encrypts them,... <a href="https://dev.to/bartoszosiej/detecting-ransomware-with-ebpf-in-rust-4779" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[PhantomRaven im npm: Vermuteter KI-Einsatz für Stealer und Bug-Bounty-Strategie]]></title>
<description><![CDATA[LONDON (IT BOLTWISE) – PhantomRaven wird mit einer npm-Supply-Chain-Attacke in Verbindung gebracht, die Entwickler gezielt um Authentifizierungs- und CI/CD-Daten bringen soll. In einer Analyse wird als plausibel eingestuft, dass der Code des JS-Infostealers mit einem großen Sprachmodell (KI-gestü...]]></description>
<link>https://tsecurity.de/de/4154542/malware-trojaner-viren/phantomraven-im-npm-vermuteter-ki-einsatz-fuer-stealer-und-bug-bounty-strategie/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4154542/malware-trojaner-viren/phantomraven-im-npm-vermuteter-ki-einsatz-fuer-stealer-und-bug-bounty-strategie/</guid>
<pubDate>Fri, 18 Sep 2026 14:41:14 +0200</pubDate>
<content:encoded><![CDATA[<p>LONDON (IT BOLTWISE) – PhantomRaven wird mit einer npm-Supply-Chain-Attacke in Verbindung gebracht, die Entwickler gezielt um Authentifizierungs- und CI/CD-Daten bringen soll. In einer Analyse wird als plausibel eingestuft, dass der Code des JS-Infostealers mit einem großen Sprachmodell (KI-gestützt) erzeugt wurde. Das Schadprogramm holt u. a.... <a href="https://www.it-boltwise.de/phantomraven-im-npm-vermuteter-ki-einsatz-fuer-stealer-und-bug-bounty-strategie.html" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[WeaselBiscuit: neuer npm-Dieb zielt auf Chrome-Extension-Storage statt Kryptowallets]]></title>
<description><![CDATA[LONDON (IT BOLTWISE) – Sicherheitsforscher haben 13 npm-Pakete identifiziert, die den JavaScript-Stealer WeaselBiscuit nachladen. Die Schadsoftware ist bewusst schlank: Sie verzichtet auf Remote-Access, Persistenz und klassische Kryptowallet-Drain-Funktionen. Stattdessen liest sie Chrome-Extensio...]]></description>
<link>https://tsecurity.de/de/4154541/malware-trojaner-viren/weaselbiscuit-neuer-npm-dieb-zielt-auf-chrome-extension-storage-statt-kryptowallets/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4154541/malware-trojaner-viren/weaselbiscuit-neuer-npm-dieb-zielt-auf-chrome-extension-storage-statt-kryptowallets/</guid>
<pubDate>Fri, 18 Sep 2026 14:41:14 +0200</pubDate>
<content:encoded><![CDATA[<p>LONDON (IT BOLTWISE) – Sicherheitsforscher haben 13 npm-Pakete identifiziert, die den JavaScript-Stealer WeaselBiscuit nachladen. Die Schadsoftware ist bewusst schlank: Sie verzichtet auf Remote-Access, Persistenz und klassische Kryptowallet-Drain-Funktionen. Stattdessen liest sie Chrome-Extension-Storage als rohen LevelDB-Key/Value aus und kann... <a href="https://www.it-boltwise.de/weaselbiscuit-neuer-npm-dieb-zielt-auf-chrome-extension-storage-statt-kryptowallets.html" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[JADEPUFFER Evolves Agentic Ransomware to Target AI Models and Training Data]]></title>
<description><![CDATA[JADEPUFFER, the agentic threat actor first linked to an autonomous ransomware operation against exposed Langflow infrastructure, has evolved its tooling to target artificial intelligence models, training datasets, and vector data. Its latest payload, ENCFORGE, marks a shift from conventional data...]]></description>
<link>https://tsecurity.de/de/4154537/malware-trojaner-viren/jadepuffer-evolves-agentic-ransomware-to-target-ai-models-and-training-data/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4154537/malware-trojaner-viren/jadepuffer-evolves-agentic-ransomware-to-target-ai-models-and-training-data/</guid>
<pubDate>Fri, 18 Sep 2026 14:41:08 +0200</pubDate>
<content:encoded><![CDATA[<p>JADEPUFFER, the agentic threat actor first linked to an autonomous ransomware operation against exposed Langflow infrastructure, has evolved its tooling to target artificial intelligence models, training datasets, and vector data. Its latest payload, ENCFORGE, marks a shift from conventional database extortion toward destruction-focused attacks on... <a href="https://www.itsecuritynews.info/jadepuffer-evolves-agentic-ransomware-to-target-ai-models-and-training-data/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[GenAI-Powered ‘RatHat’ Android Malware Bypasses App Sandboxes via ADB]]></title>
<description><![CDATA[HOC Shorts New Android Malware Alert: RatHat As per security research, its linked to China-aligned hackers, this new malware strain is using Generative AI to become virtually hidden. The Trick: It bypass Accessibility Services and auto-pairs with local ADB to completely break out of the Android s...]]></description>
<link>https://tsecurity.de/de/4154526/malware-trojaner-viren/genai-powered-rathat-android-malware-bypasses-app-sandboxes-via-adb/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4154526/malware-trojaner-viren/genai-powered-rathat-android-malware-bypasses-app-sandboxes-via-adb/</guid>
<pubDate>Fri, 18 Sep 2026 14:38:07 +0200</pubDate>
<content:encoded><![CDATA[<p>HOC Shorts New Android Malware Alert: RatHat As per security research, its linked to China-aligned hackers, this new malware strain is using Generative AI to become virtually hidden. The Trick: It bypass Accessibility Services and auto-pairs with local ADB to completely break out of the Android sandbox. The AI Edge: It uses real-time GenAI to... <a href="https://hackersonlineclub.com/rathat-android-malware-ai-adb-sandbox-bypass/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[(g+) Praxis-Workshop: TPM 2.0 unter Linux]]></title>
<description><![CDATA[Das einst verteufelte TPM ist längst im Linux-Alltag angekommen: Es entsperrt LUKS-Volumes, hütet SSH-Schlüssel und versiegelt Geheimnisse. Eine Anleitung von Martin Loschwitz (Linux, Malware) Weiterlesen]]></description>
<link>https://tsecurity.de/de/4154328/malware-trojaner-viren/g-praxis-workshop-tpm20-unter-linux/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4154328/malware-trojaner-viren/g-praxis-workshop-tpm20-unter-linux/</guid>
<pubDate>Fri, 18 Sep 2026 13:32:08 +0200</pubDate>
<content:encoded><![CDATA[<p>Das einst verteufelte TPM ist längst im Linux-Alltag angekommen: Es entsperrt LUKS-Volumes, hütet SSH-Schlüssel und versiegelt Geheimnisse. Eine Anleitung von Martin Loschwitz (Linux, Malware) <a href="https://www.golem.de/news/praxis-workshop-tpm-2-0-unter-linux-2609-213171.html" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Fake LastPass downloads on GitHub pushed password-stealing malware]]></title>
<description><![CDATA[A malware campaign impersonates LastPass on GitHub to trick users into installing an information stealer that can harvest browser passwords, cryptocurrency wallets, and messaging app sessions. The campaign, detailed in a report by LastPass and Delphos Labs, used fake GitHub pages designed to appe...]]></description>
<link>https://tsecurity.de/de/4154287/malware-trojaner-viren/fake-lastpass-downloads-on-github-pushed-password-stealing-malware/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4154287/malware-trojaner-viren/fake-lastpass-downloads-on-github-pushed-password-stealing-malware/</guid>
<pubDate>Fri, 18 Sep 2026 12:53:11 +0200</pubDate>
<content:encoded><![CDATA[<p>A malware campaign impersonates LastPass on GitHub to trick users into installing an information stealer that can harvest browser passwords, cryptocurrency wallets, and messaging app sessions. The campaign, detailed in a report by LastPass and Delphos Labs, used fake GitHub pages designed to appear in search results for terms such as “LastPass... <a href="https://cyberinsider.com/fake-lastpass-downloads-on-github-pushed-password-stealing-malware/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[WeaselBiscuit Stealer Spreads via 13 npm Packages to Harvest Chrome Extension Storage]]></title>
<description><![CDATA[Cybersecurity researchers have discovered a cluster of 13 npm packages that have been found to deliver a previously undocumented JavaScript stealer codenamed WeaselBiscuit. The new malware family, per OpenSourceMalware, exhibits functional overlaps with two malware strains associated with the Dem...]]></description>
<link>https://tsecurity.de/de/4154281/malware-trojaner-viren/weaselbiscuit-stealer-spreads-via-13-npm-packages-to-harvest-chrome-extension-storage/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4154281/malware-trojaner-viren/weaselbiscuit-stealer-spreads-via-13-npm-packages-to-harvest-chrome-extension-storage/</guid>
<pubDate>Fri, 18 Sep 2026 12:50:13 +0200</pubDate>
<content:encoded><![CDATA[<p>Cybersecurity researchers have discovered a cluster of 13 npm packages that have been found to deliver a previously undocumented JavaScript stealer codenamed WeaselBiscuit. The new malware family, per OpenSourceMalware, exhibits functional overlaps with two malware strains associated with the Democratic People&#039;s Republic of Korea&#039;s (DPRK)... <a href="https://thehackernews.com/2026/09/weaselbiscuit-stealer-spreads-via-13.html" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Malware-Falle auf 100.000 Internetseiten]]></title>
<description><![CDATA[Großangriff auf mehr als 100.000 Internetseiten: Hacker verteilten ClickFix-Malware über einen beliebten Online-Dienst und lockten Nutzer in die Falle. Weiterlesen]]></description>
<link>https://tsecurity.de/de/4154267/malware-trojaner-viren/malware-falle-auf-100000-internetseiten/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4154267/malware-trojaner-viren/malware-falle-auf-100000-internetseiten/</guid>
<pubDate>Fri, 18 Sep 2026 12:47:29 +0200</pubDate>
<content:encoded><![CDATA[<p>Großangriff auf mehr als 100.000 Internetseiten: Hacker verteilten ClickFix-Malware über einen beliebten Online-Dienst und lockten Nutzer in die Falle. <a href="https://www.computerbild.de/artikel/News-Sicherheit-Malware-Falle-auf-100.000-Internetseiten-00897-41238123.html" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[API-Key geleakt: Plötzlich Malware über 100.000 Websites verbreitet]]></title>
<description><![CDATA[Angreifer sind an einen API-Schlüssel von Brevo gelangt. Dieser hat mit einem Schlag Clickfix-Attacken über mehr als 100.000 Websites ermöglicht. (Malware, Virus) Weiterlesen]]></description>
<link>https://tsecurity.de/de/4154264/malware-trojaner-viren/api-key-geleakt-ploetzlich-malware-ueber-100000-websites-verbreitet/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4154264/malware-trojaner-viren/api-key-geleakt-ploetzlich-malware-ueber-100000-websites-verbreitet/</guid>
<pubDate>Fri, 18 Sep 2026 12:47:02 +0200</pubDate>
<content:encoded><![CDATA[<p>Angreifer sind an einen API-Schlüssel von Brevo gelangt. Dieser hat mit einem Schlag Clickfix-Attacken über mehr als 100.000 Websites ermöglicht. (Malware, Virus) <a href="https://www.golem.de/news/api-key-geleakt-ploetzlich-malware-ueber-100-000-websites-verbreitet-2609-213201.html" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[PhantomRaven im npm-Netz: LLM-gestützter JS-Stealer und RDD-Fallback]]></title>
<description><![CDATA[LONDON (IT BOLTWISE) – Ein finanziell motivierter Angreifer soll über den npm-Registry-Zugang den JS-Informationsdiebstahl PhantomRaven aufgebaut und verbreitet haben. Hinweise deuten darauf hin, dass der Schadcode vermutlich mit einem KI-Sprachmodell (LLM) generiert wurde. Das Paket-Setup nutzt ...]]></description>
<link>https://tsecurity.de/de/4154181/malware-trojaner-viren/phantomraven-im-npm-netz-llm-gestuetzter-js-stealer-und-rdd-fallback/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4154181/malware-trojaner-viren/phantomraven-im-npm-netz-llm-gestuetzter-js-stealer-und-rdd-fallback/</guid>
<pubDate>Fri, 18 Sep 2026 12:22:09 +0200</pubDate>
<content:encoded><![CDATA[<p>LONDON (IT BOLTWISE) – Ein finanziell motivierter Angreifer soll über den npm-Registry-Zugang den JS-Informationsdiebstahl PhantomRaven aufgebaut und verbreitet haben. Hinweise deuten darauf hin, dass der Schadcode vermutlich mit einem KI-Sprachmodell (LLM) generiert wurde. Das Paket-Setup nutzt dabei eine Tarnschicht über Typosquatting und... <a href="https://www.it-boltwise.de/phantomraven-im-npm-netz-llm-gestuetzter-js-stealer-und-rdd-fallback.html" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Brevo Supply Chain Attack Pushes WordPress Backdoors and ClickFix Malware to 100,000+ Sites]]></title>
<description><![CDATA[A supply-chain compromise involving Brevo briefly turned widely used website tools into a delivery channel for malware. Attackers inserted hostile JavaScript into services that customer websites load, exposing both visitors and WordPress administrators. The activity reached more than 100,000 cust...]]></description>
<link>https://tsecurity.de/de/4154174/malware-trojaner-viren/brevo-supply-chain-attack-pushes-wordpress-backdoors-and-clickfix-malware-to-100000-sites/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4154174/malware-trojaner-viren/brevo-supply-chain-attack-pushes-wordpress-backdoors-and-clickfix-malware-to-100000-sites/</guid>
<pubDate>Fri, 18 Sep 2026 12:22:02 +0200</pubDate>
<content:encoded><![CDATA[<p>A supply-chain compromise involving Brevo briefly turned widely used website tools into a delivery channel for malware. Attackers inserted hostile JavaScript into services that customer websites load, exposing both visitors and WordPress administrators. The activity reached more than 100,000 customer sites on September 14, according to the... <a href="https://www.itsecuritynews.info/brevo-supply-chain-attack-pushes-wordpress-backdoors-and-clickfix-malware-to-100000-sites/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Berlin-Hack 2026: Ransomware, Datenabfluss und KRITIS-Lücke - Security-Insider]]></title>
<description><![CDATA[Vom 7. und dem 12. August 2026 hatten Cyberkriminelle Zugriff auf sensible Daten der Landesverwaltung Berlin. (Bild: Aliaksei - stock.adobe.com). Weiterlesen]]></description>
<link>https://tsecurity.de/de/4154141/malware-trojaner-viren/berlin-hack-2026-ransomware-datenabfluss-und-kritis-luecke-security-insider/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4154141/malware-trojaner-viren/berlin-hack-2026-ransomware-datenabfluss-und-kritis-luecke-security-insider/</guid>
<pubDate>Fri, 18 Sep 2026 12:19:15 +0200</pubDate>
<content:encoded><![CDATA[<p>Vom 7. und dem 12. August 2026 hatten Cyberkriminelle Zugriff auf sensible Daten der Landesverwaltung Berlin. (Bild: Aliaksei - stock.adobe.com). <a href="https://www.google.com/url?rct=j&amp;sa=t&amp;url=https://www.security-insider.de/berlin-hack-2026-rhysida-datenabfluss-kritis-luecke-a-632d35c84df369df3b73627b27e021a3/&amp;ct=ga&amp;cd=CAIyGTRiZTZmY2RmMzZhYjA0M2Y6ZGU6ZGU6REU&amp;usg=AOvVaw1Ap5tZYF6EJFw2A-jBHAqJ" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Brevo Supply Chain Attack Injects Malware Into 100,000 Websites]]></title>
<description><![CDATA[Hackers used a compromised API key to deploy a Cloudflare worker that injected malicious scripts. The post Brevo Supply Chain Attack Injects Malware Into 100,000 Websites appeared first on SecurityWeek. Weiterlesen]]></description>
<link>https://tsecurity.de/de/4154139/malware-trojaner-viren/brevo-supply-chain-attack-injects-malware-into-100000-websites/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4154139/malware-trojaner-viren/brevo-supply-chain-attack-injects-malware-into-100000-websites/</guid>
<pubDate>Fri, 18 Sep 2026 12:19:10 +0200</pubDate>
<content:encoded><![CDATA[<p>Hackers used a compromised API key to deploy a Cloudflare worker that injected malicious scripts. The post Brevo Supply Chain Attack Injects Malware Into 100,000 Websites appeared first on SecurityWeek. <a href="https://www.securityweek.com/brevo-supply-chain-attack-injects-malware-into-100000-websites/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Claimed Bug Bounty Hunter Likely Used LLM to Build PhantomRaven npm Stealer]]></title>
<description><![CDATA[A financially motivated threat actor has been linked to the development and distribution of a JavaScript (JS)-based information stealer known as PhantomRaven via the npm package registry. "The developer likely wrote the malware using a large language model (LLM), an assessment made with high conf...]]></description>
<link>https://tsecurity.de/de/4154135/malware-trojaner-viren/claimed-bug-bounty-hunter-likely-used-llm-to-build-phantomraven-npm-stealer/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4154135/malware-trojaner-viren/claimed-bug-bounty-hunter-likely-used-llm-to-build-phantomraven-npm-stealer/</guid>
<pubDate>Fri, 18 Sep 2026 12:19:06 +0200</pubDate>
<content:encoded><![CDATA[<p>A financially motivated threat actor has been linked to the development and distribution of a JavaScript (JS)-based information stealer known as PhantomRaven via the npm package registry. &quot;The developer likely wrote the malware using a large language model (LLM), an assessment made with high confidence based on verbose comments, placeholder code,... <a href="https://thehackernews.com/2026/09/claimed-bug-bounty-hunter-likely-used.html" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[AI-Powered Malware Rewrites Itself Every Hour to Evade Signature-Based Detection]]></title>
<description><![CDATA[AI-powered malware is making a familiar security problem harder to contain. Instead of keeping the same code long enough for antivirus tools to recognize it, these programs can alter their form repeatedly while retaining the same harmful purpose. The emerging model relies on large language models...]]></description>
<link>https://tsecurity.de/de/4153978/malware-trojaner-viren/ai-powered-malware-rewrites-itself-every-hour-to-evade-signature-based-detection/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4153978/malware-trojaner-viren/ai-powered-malware-rewrites-itself-every-hour-to-evade-signature-based-detection/</guid>
<pubDate>Fri, 18 Sep 2026 10:52:09 +0200</pubDate>
<content:encoded><![CDATA[<p>AI-powered malware is making a familiar security problem harder to contain. Instead of keeping the same code long enough for antivirus tools to recognize it, these programs can alter their form repeatedly while retaining the same harmful purpose. The emerging model relies on large language models as an automated code factory. A malicious dropper... <a href="https://cybersecuritynews.com/ai-powered-malware/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Fake Apps, Real Spies: How Iran Tracks Dissidents Through Telegram]]></title>
<description><![CDATA[Iranian cyber actors are using a malware family known as HEAVYGRAM, also tracked as CHOSEN BRICK, to target dissidents, journalists, and opposition groups worldwide, according to a recent FBI FLASH report and a joint advisory from the UK National Cyber Security Centre (NCSC), the US FBI, and the ...]]></description>
<link>https://tsecurity.de/de/4153975/malware-trojaner-viren/fake-apps-real-spies-how-iran-tracks-dissidents-through-telegram/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4153975/malware-trojaner-viren/fake-apps-real-spies-how-iran-tracks-dissidents-through-telegram/</guid>
<pubDate>Fri, 18 Sep 2026 10:52:04 +0200</pubDate>
<content:encoded><![CDATA[<p>Iranian cyber actors are using a malware family known as HEAVYGRAM, also tracked as CHOSEN BRICK, to target dissidents, journalists, and opposition groups worldwide, according to a recent FBI FLASH report and a joint advisory from the UK National Cyber Security Centre (NCSC), the US FBI, and the Netherlands&#039; General Intelligence and Security... <a href="https://thecyberexpress.com/iranian-cyber-actors-deploy-malware/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Agentic Ransomware Lets AI Agents Execute Cyberattacks Without Human Operators]]></title>
<description><![CDATA[Ransomware attacks have traditionally depended on human operators. Affiliates would steal credentials, move through victim networks, deploy malware, and negotiate payments. Even automated ransomware followed scripts written in advance. Agentic ransomware changes that model. It uses autonomous AI ...]]></description>
<link>https://tsecurity.de/de/4153884/malware-trojaner-viren/agentic-ransomware-lets-ai-agents-execute-cyberattacks-without-human-operators/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4153884/malware-trojaner-viren/agentic-ransomware-lets-ai-agents-execute-cyberattacks-without-human-operators/</guid>
<pubDate>Fri, 18 Sep 2026 10:06:50 +0200</pubDate>
<content:encoded><![CDATA[<p>Ransomware attacks have traditionally depended on human operators. Affiliates would steal credentials, move through victim networks, deploy malware, and negotiate payments. Even automated ransomware followed scripts written in advance. Agentic ransomware changes that model. It uses autonomous AI agents that can make operational decisions during an... <a href="https://cyberpress.org/ai-ransomware-goes-autonomous/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[New SETTRA Ransomware Wipes Recovery Options Before Locking Windows Files]]></title>
<description><![CDATA[Security researchers have uncovered new details about Settra ransomware, a recently observed Windows threat that attempts to destroy recovery options before encrypting files. Huntress investigated two Settra incidents, one targeting a consumer services and retail organization in July and another ...]]></description>
<link>https://tsecurity.de/de/4153883/malware-trojaner-viren/new-settra-ransomware-wipes-recovery-options-before-locking-windows-files/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4153883/malware-trojaner-viren/new-settra-ransomware-wipes-recovery-options-before-locking-windows-files/</guid>
<pubDate>Fri, 18 Sep 2026 10:06:50 +0200</pubDate>
<content:encoded><![CDATA[<p>Security researchers have uncovered new details about Settra ransomware, a recently observed Windows threat that attempts to destroy recovery options before encrypting files. Huntress investigated two Settra incidents, one targeting a consumer services and retail organization in July and another affecting a manufacturing company in September.... <a href="https://cyberpress.org/settra-ransomware-erases-recovery/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Manufacturing Accounts for 22% of all Ransomware Victims]]></title>
<description><![CDATA[Black Kite has found that manufacturing remained the most targeted sector for ransomware attacks, and saw a big jump in incidents in H1 2026 Weiterlesen]]></description>
<link>https://tsecurity.de/de/4153875/malware-trojaner-viren/manufacturing-accounts-for-22-of-all-ransomware-victims/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4153875/malware-trojaner-viren/manufacturing-accounts-for-22-of-all-ransomware-victims/</guid>
<pubDate>Fri, 18 Sep 2026 10:03:40 +0200</pubDate>
<content:encoded><![CDATA[<p>Black Kite has found that manufacturing remained the most targeted sector for ransomware attacks, and saw a big jump in incidents in H1 2026 <a href="https://www.infosecurity-magazine.com/news/manufacturing-22-ransomware-victims/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Ransomware-Angriffe setzen auf menschliche Schwächen - B2B Cyber Security]]></title>
<description><![CDATA[KI macht Ransomware-Angriffe überzeugender. Die Studie basiert auf einer Umfrage unter 953 Cybersicherheitsexperten in 12 Ländern. Sie zeigt unter ... Weiterlesen]]></description>
<link>https://tsecurity.de/de/4153868/malware-trojaner-viren/ransomware-angriffe-setzen-auf-menschliche-schwaechen-b2b-cyber-security/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4153868/malware-trojaner-viren/ransomware-angriffe-setzen-auf-menschliche-schwaechen-b2b-cyber-security/</guid>
<pubDate>Fri, 18 Sep 2026 10:02:51 +0200</pubDate>
<content:encoded><![CDATA[<p>KI macht Ransomware-Angriffe überzeugender. Die Studie basiert auf einer Umfrage unter 953 Cybersicherheitsexperten in 12 Ländern. Sie zeigt unter ... <a href="https://www.google.com/url?rct=j&amp;sa=t&amp;url=https://b2b-cyber-security.de/ransomware-angriffe-setzen-auf-menschliche-schwaechen/&amp;ct=ga&amp;cd=CAIyGTRiZTZmY2RmMzZhYjA0M2Y6ZGU6ZGU6REU&amp;usg=AOvVaw36g1JWo_arQg99Yq8_MrkR" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Beware the SparroWock: The backdoor that bites, the commands that catch]]></title>
<description><![CDATA[ESET researchers document SparroWocky, the new flagship backdoor of the FamousSparrow APT group Weiterlesen]]></description>
<link>https://tsecurity.de/de/4153809/malware-trojaner-viren/beware-the-sparrowock-the-backdoor-that-bites-the-commands-that-catch/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4153809/malware-trojaner-viren/beware-the-sparrowock-the-backdoor-that-bites-the-commands-that-catch/</guid>
<pubDate>Fri, 18 Sep 2026 09:41:34 +0200</pubDate>
<content:encoded><![CDATA[<p>ESET researchers document SparroWocky, the new flagship backdoor of the FamousSparrow APT group <a href="https://www.welivesecurity.com/en/eset-research/beware-sparrowock-backdoor-bites-commands-catch/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Hackers Poison Movie Torrents With MovieReaper Malware That Uses Solana for C2]]></title>
<description><![CDATA[Movie torrents are being used to deliver a new Windows malware framework called MovieReaper. Attackers have poisoned torrent downloads for popular films, turning a routine search for entertainment into a route for remote access and data theft. The campaign has reached users and organizations acro...]]></description>
<link>https://tsecurity.de/de/4153803/malware-trojaner-viren/hackers-poison-movie-torrents-with-moviereaper-malware-that-uses-solana-for-c2/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4153803/malware-trojaner-viren/hackers-poison-movie-torrents-with-moviereaper-malware-that-uses-solana-for-c2/</guid>
<pubDate>Fri, 18 Sep 2026 09:38:01 +0200</pubDate>
<content:encoded><![CDATA[<p>Movie torrents are being used to deliver a new Windows malware framework called MovieReaper. Attackers have poisoned torrent downloads for popular films, turning a routine search for entertainment into a route for remote access and data theft. The campaign has reached users and organizations across several countries. Victims who use a magnet link... <a href="https://cybersecuritynews.com/poison-movie-torrents/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[RatHat Android-Malware missbraucht ADB, bleibt nach dem Deinstallieren aktiv]]></title>
<description><![CDATA[LONDON (IT BOLTWISE) – Sicherheitsforscher warnen vor der Android-Malware RatHat, die über smishing und malvertising auch Nutzer zur Installation präparierter APKs bringt. Im Betrieb kombiniert die Schadsoftware Accessibility-Missbrauch mit einer lokalen ADB-Selbst-Pairing-Strategie, um die Andro...]]></description>
<link>https://tsecurity.de/de/4153798/malware-trojaner-viren/rathat-android-malware-missbraucht-adb-bleibt-nach-dem-deinstallieren-aktiv/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4153798/malware-trojaner-viren/rathat-android-malware-missbraucht-adb-bleibt-nach-dem-deinstallieren-aktiv/</guid>
<pubDate>Fri, 18 Sep 2026 09:37:39 +0200</pubDate>
<content:encoded><![CDATA[<p>LONDON (IT BOLTWISE) – Sicherheitsforscher warnen vor der Android-Malware RatHat, die über smishing und malvertising auch Nutzer zur Installation präparierter APKs bringt. Im Betrieb kombiniert die Schadsoftware Accessibility-Missbrauch mit einer lokalen ADB-Selbst-Pairing-Strategie, um die Android-App-Sandbox zu umgehen und Shell-Zugriff zu... <a href="https://www.it-boltwise.de/rathat-android-malware-missbraucht-adb-bleibt-nach-dem-deinstallieren-aktiv.html" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[IT Security News Hourly Summary 2026-09-18 09h : 7 posts]]></title>
<description><![CDATA[7 posts published in the last hour 06:31HTTP QUERY Method: The Grey Zone Between GET And POST., (Fri, Sep 18th) 06:31Abandoned IoT apps keep sending sensitive data to broken servers 06:31RatHat Android Malware Abuses ADB to Retain Shell Access After Uninstall 06:31Hackers Turn Brevo Widgets Into ...]]></description>
<link>https://tsecurity.de/de/4153719/malware-trojaner-viren/it-security-news-hourly-summary-2026-09-18-09h-7-posts/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4153719/malware-trojaner-viren/it-security-news-hourly-summary-2026-09-18-09h-7-posts/</guid>
<pubDate>Fri, 18 Sep 2026 09:05:24 +0200</pubDate>
<content:encoded><![CDATA[<p>7 posts published in the last hour 06:31HTTP QUERY Method: The Grey Zone Between GET And POST., (Fri, Sep 18th) 06:31Abandoned IoT apps keep sending sensitive data to broken servers 06:31RatHat Android Malware Abuses ADB to Retain Shell Access After Uninstall 06:31Hackers Turn Brevo Widgets Into Malware Delivery Channel Across 100,000+ Websites... <a href="https://www.itsecuritynews.info/it-security-news-hourly-summary-2026-09-18-09h-7-posts/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[HydraDragonAntivirus openedr-v2-release-portable-9]]></title>
<description><![CDATA[Dynamic and static analysis with Real Time Malware Analysis with Antivirus for Windows, including open-source XDR (3 EDR projects), ClamAV, YARA-X, machine learning AI, behavioral analysis, Unpacker, Deobfuscator, Decompiler, website signatures, Ghidra, Suricata, Sigma, Kernel, Hypervisior based ...]]></description>
<link>https://tsecurity.de/de/4153636/malware-trojaner-viren/hydradragonantivirus-openedr-v2-release-portable-9/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4153636/malware-trojaner-viren/hydradragonantivirus-openedr-v2-release-portable-9/</guid>
<pubDate>Fri, 18 Sep 2026 08:36:16 +0200</pubDate>
<content:encoded><![CDATA[<p>Dynamic and static analysis with Real Time Malware Analysis with Antivirus for Windows, including open-source XDR (3 EDR projects), ClamAV, YARA-X, machine learning AI, behavioral analysis, Unpacker, Deobfuscator, Decompiler, website signatures, Ghidra, Suricata, Sigma, Kernel, Hypervisior based protection and much more than you can imagine. <a href="https://kitploit.com/en/posts/github-hydradragonantivirus-hydradragonantivirus-openedr-v2-release-portable-9" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[MovieReaper Gives Hackers 21 Commands to Steal and Manipulate Files on Windows PCs]]></title>
<description><![CDATA[A newly identified malware framework named MovieReaper is spreading through malicious torrent downloads disguised as popular movies. The modular Windows threat gives attackers 21 remote file-management commands, enabling them to steal, inspect, alter, and delete data from infected systems. Resear...]]></description>
<link>https://tsecurity.de/de/4153632/malware-trojaner-viren/moviereaper-gives-hackers-21-commands-to-steal-and-manipulate-files-on-windows-pcs/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4153632/malware-trojaner-viren/moviereaper-gives-hackers-21-commands-to-steal-and-manipulate-files-on-windows-pcs/</guid>
<pubDate>Fri, 18 Sep 2026 08:35:26 +0200</pubDate>
<content:encoded><![CDATA[<p>A newly identified malware framework named MovieReaper is spreading through malicious torrent downloads disguised as popular movies. The modular Windows threat gives attackers 21 remote file-management commands, enabling them to steal, inspect, alter, and delete data from infected systems. Researchers identified the campaign in mid-August 2026... <a href="https://cyberpress.org/moviereaper-grants-file-control/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[PROMPTFLUX Uses Google Gemini to Rewrite Its Malware Code Every Hour]]></title>
<description><![CDATA[Researchers have identified PROMPTFLUX, an experimental malware dropper that reportedly uses Google’s Gemini API to rewrite parts of its own code about once every hour. The technique shows how attackers could use generative AI to create many changing versions of the same malicious program, making...]]></description>
<link>https://tsecurity.de/de/4153631/malware-trojaner-viren/promptflux-uses-google-gemini-to-rewrite-its-malware-code-every-hour/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4153631/malware-trojaner-viren/promptflux-uses-google-gemini-to-rewrite-its-malware-code-every-hour/</guid>
<pubDate>Fri, 18 Sep 2026 08:35:26 +0200</pubDate>
<content:encoded><![CDATA[<p>Researchers have identified PROMPTFLUX, an experimental malware dropper that reportedly uses Google’s Gemini API to rewrite parts of its own code about once every hour. The technique shows how attackers could use generative AI to create many changing versions of the same malicious program, making traditional security detection harder. Polymorphic... <a href="https://cyberpress.org/promptflux-gemini-malware-rewrites/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[IT Security News Hourly Summary 2026-09-18 08h : 11 posts]]></title>
<description><![CDATA[11 posts published in the last hour 05:31Andorran Police joins Europol’s secure communication network 05:31FBI Seizes NightmareStresser DDoS-for-Hire Domains Used in Hundreds of Thousands of Attacks 05:3198% of fraudulent hires have company credentials by the time they’re caught 05:31MovieReaper ...]]></description>
<link>https://tsecurity.de/de/4153628/malware-trojaner-viren/it-security-news-hourly-summary-2026-09-18-08h-11-posts/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4153628/malware-trojaner-viren/it-security-news-hourly-summary-2026-09-18-08h-11-posts/</guid>
<pubDate>Fri, 18 Sep 2026 08:35:18 +0200</pubDate>
<content:encoded><![CDATA[<p>11 posts published in the last hour 05:31Andorran Police joins Europol’s secure communication network 05:31FBI Seizes NightmareStresser DDoS-for-Hire Domains Used in Hundreds of Thousands of Attacks 05:3198% of fraudulent hires have company credentials by the time they’re caught 05:31MovieReaper Malware Spreads Through Pirated Movie Torrents and... <a href="https://www.itsecuritynews.info/it-security-news-hourly-summary-2026-09-18-08h-11-posts/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Hackers Turn Brevo Widgets Into Malware Delivery Channel Across 100,000+ Websites]]></title>
<description><![CDATA[A suspected supply-chain compromise involving Brevo has exposed visitors and WordPress administrators across more than 100,000 websites to malware. Attackers allegedly abused Brevo-hosted JavaScript assets, signup forms, unsubscribe pages and chat widgets to distribute a WordPress backdoor and Cl...]]></description>
<link>https://tsecurity.de/de/4153626/malware-trojaner-viren/hackers-turn-brevo-widgets-into-malware-delivery-channel-across-100000-websites/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4153626/malware-trojaner-viren/hackers-turn-brevo-widgets-into-malware-delivery-channel-across-100000-websites/</guid>
<pubDate>Fri, 18 Sep 2026 08:35:18 +0200</pubDate>
<content:encoded><![CDATA[<p>A suspected supply-chain compromise involving Brevo has exposed visitors and WordPress administrators across more than 100,000 websites to malware. Attackers allegedly abused Brevo-hosted JavaScript assets, signup forms, unsubscribe pages and chat widgets to distribute a WordPress backdoor and ClickFix social-engineering payloads. Brevo, formerly... <a href="https://www.itsecuritynews.info/hackers-turn-brevo-widgets-into-malware-delivery-channel-across-100000-websites/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[RatHat Android Malware Abuses ADB to Retain Shell Access After Uninstall]]></title>
<description><![CDATA[Cybersecurity researchers have flagged a new Android malware called RatHat that's assessed to be operated by China-based threat actors and features an artificial intelligence (AI)-powered system to navigate and control compromised devices. "Distributed primarily via targeted smishing (SMS/text ph...]]></description>
<link>https://tsecurity.de/de/4153606/malware-trojaner-viren/rathat-android-malware-abuses-adb-to-retain-shell-access-after-uninstall/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4153606/malware-trojaner-viren/rathat-android-malware-abuses-adb-to-retain-shell-access-after-uninstall/</guid>
<pubDate>Fri, 18 Sep 2026 08:32:33 +0200</pubDate>
<content:encoded><![CDATA[<p>Cybersecurity researchers have flagged a new Android malware called RatHat that&#039;s assessed to be operated by China-based threat actors and features an artificial intelligence (AI)-powered system to navigate and control compromised devices. &quot;Distributed primarily via targeted smishing (SMS/text phishing) and malvertising campaigns leading to... <a href="https://thehackernews.com/2026/09/rathat-android-malware-abuses-adb-to.html" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Perfekter Hack: Wenn 100.000 Webseiten plötzlich Malware liefern]]></title>
<description><![CDATA[Schwachstellen in weit verbreiteten Diensten können schnell eine Flut von Sicherheitsproblemen auslösen. Das zeigte sich auch in einem aktuellen Fall, in dem um die hunderttausend Webseiten plötzlich Malware an Nutzer auslieferten. (Weiter lesen) Weiterlesen]]></description>
<link>https://tsecurity.de/de/4153603/malware-trojaner-viren/perfekter-hack-wenn-100000-webseiten-ploetzlich-malware-liefern/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4153603/malware-trojaner-viren/perfekter-hack-wenn-100000-webseiten-ploetzlich-malware-liefern/</guid>
<pubDate>Fri, 18 Sep 2026 08:32:32 +0200</pubDate>
<content:encoded><![CDATA[<p>Schwachstellen in weit verbreiteten Diensten können schnell eine Flut von Sicherheitsproblemen auslösen. Das zeigte sich auch in einem aktuellen Fall, in dem um die hunderttausend Webseiten plötzlich Malware an Nutzer auslieferten. (Weiter lesen) <a href="https://winfuture.de/news,161360.html" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[AI Malware Keeps Changing Its Code to Break Traditional Signature-Based Detection]]></title>
<description><![CDATA[AI-powered malware is beginning to erode one of endpoint security’s oldest assumptions: that malicious code will remain stable long enough to identify, fingerprint, and block. A new class of threats uses large language models during execution to rewrite scripts, generate commands, and alter obfus...]]></description>
<link>https://tsecurity.de/de/4153551/malware-trojaner-viren/ai-malware-keeps-changing-its-code-to-break-traditional-signature-based-detection/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4153551/malware-trojaner-viren/ai-malware-keeps-changing-its-code-to-break-traditional-signature-based-detection/</guid>
<pubDate>Fri, 18 Sep 2026 08:30:49 +0200</pubDate>
<content:encoded><![CDATA[<p>AI-powered malware is beginning to erode one of endpoint security’s oldest assumptions: that malicious code will remain stable long enough to identify, fingerprint, and block. A new class of threats uses large language models during execution to rewrite scripts, generate commands, and alter obfuscation on demand producing variants that can evade... <a href="https://gbhackers.com/ai-powered-malware/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[MovieReaper Malware Spreads Through Pirated Movie Torrents and Uses Solana for C2]]></title>
<description><![CDATA[A newly identified Windows malware framework dubbed MovieReaper is being distributed through pirated movie torrents after threat actors compromised a public torrent-file repository used by multiple tracker sites. The campaign combines a multi-stage infection chain, anti-analysis techniques, UAC b...]]></description>
<link>https://tsecurity.de/de/4153501/malware-trojaner-viren/moviereaper-malware-spreads-through-pirated-movie-torrents-and-uses-solana-for-c2/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4153501/malware-trojaner-viren/moviereaper-malware-spreads-through-pirated-movie-torrents-and-uses-solana-for-c2/</guid>
<pubDate>Fri, 18 Sep 2026 07:05:14 +0200</pubDate>
<content:encoded><![CDATA[<p>A newly identified Windows malware framework dubbed MovieReaper is being distributed through pirated movie torrents after threat actors compromised a public torrent-file repository used by multiple tracker sites. The campaign combines a multi-stage infection chain, anti-analysis techniques, UAC bypass, file-management capabilities, and Solana... <a href="https://gbhackers.com/moviereaper-malware/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CISA Wants Defenders to Deploy Fake Credentials and Systems to Catch Hackers]]></title>
<description><![CDATA[CISA has urged organizations to deploy fake credentials, systems, files, and data assets inside their environments to expose attackers after an initial compromise. The agency published its new guidance, Using Cyber Decoys to Strengthen Detection and Response, on September 16, 2026. CISA said many...]]></description>
<link>https://tsecurity.de/de/4153427/malware-trojaner-viren/cisa-wants-defenders-to-deploy-fake-credentials-and-systems-to-catch-hackers/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4153427/malware-trojaner-viren/cisa-wants-defenders-to-deploy-fake-credentials-and-systems-to-catch-hackers/</guid>
<pubDate>Fri, 18 Sep 2026 06:37:15 +0200</pubDate>
<content:encoded><![CDATA[<p>CISA has urged organizations to deploy fake credentials, systems, files, and data assets inside their environments to expose attackers after an initial compromise. The agency published its new guidance, Using Cyber Decoys to Strengthen Detection and Response, on September 16, 2026. CISA said many attackers now avoid malware-heavy intrusion methods... <a href="https://www.itsecuritynews.info/cisa-wants-defenders-to-deploy-fake-credentials-and-systems-to-catch-hackers/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CAPEsolo]]></title>
<description><![CDATA[Standalone Windows VM malware sandbox running capemon, with GUI triage viewer, YARA signatures, IOC extraction, network analysis, and VirusTotal/MalwareBazaar sample download. Weiterlesen]]></description>
<link>https://tsecurity.de/de/4153152/malware-trojaner-viren/capesolo/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4153152/malware-trojaner-viren/capesolo/</guid>
<pubDate>Fri, 18 Sep 2026 02:35:21 +0200</pubDate>
<content:encoded><![CDATA[<p>Standalone Windows VM malware sandbox running capemon, with GUI triage viewer, YARA signatures, IOC extraction, network analysis, and VirusTotal/MalwareBazaar sample download. <a href="https://kitploit.com/en/tools/github/capesandbox/capesolo" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[IT Security News Hourly Summary 2026-09-18 01h : 3 posts]]></title>
<description><![CDATA[3 posts published in the last hour 22:31Inside the Modern SOC: Defending the Cross-Environment Pivot 22:02Global public-private operation disrupts Sality botnet active for two decades 22:00IT Security News Hourly Summary 2026-09-18 00h : 7 posts The post IT Security News Hourly Summary 2026-09-18...]]></description>
<link>https://tsecurity.de/de/4153069/malware-trojaner-viren/it-security-news-hourly-summary-2026-09-18-01h-3-posts/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4153069/malware-trojaner-viren/it-security-news-hourly-summary-2026-09-18-01h-3-posts/</guid>
<pubDate>Fri, 18 Sep 2026 01:25:47 +0200</pubDate>
<content:encoded><![CDATA[<p>3 posts published in the last hour 22:31Inside the Modern SOC: Defending the Cross-Environment Pivot 22:02Global public-private operation disrupts Sality botnet active for two decades 22:00IT Security News Hourly Summary 2026-09-18 00h : 7 posts The post IT Security News Hourly Summary 2026-09-18 01h : 3 posts appeared first on IT Security News. <a href="https://www.itsecuritynews.info/it-security-news-hourly-summary-2026-09-18-01h-3-posts/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Avast: Oktoberfest]]></title>
<description><![CDATA[YouTube VideoProst to faster streaming!]]></description>
<link>https://tsecurity.de/de/4153043/malware-trojaner-viren/oktoberfest/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4153043/malware-trojaner-viren/oktoberfest/</guid>
<pubDate>Fri, 18 Sep 2026 01:15:09 +0200</pubDate>
<content:encoded><![CDATA[<p>YouTube Video</p><p><iframe loading="lazy" src="https://www.youtube.com/embed/qqu6PsQ7Uy8"></iframe></p><div class="youtube-description">Prost to faster streaming!</div>]]></content:encoded>
<enclosure url="https://i2.ytimg.com/vi/qqu6PsQ7Uy8/hqdefault.jpg" length="0" type="image/jpeg" />
</item>
<item>
<title><![CDATA[New RatHat Android malware uses AI to automate device control]]></title>
<description><![CDATA[A new Android malware called RatHat has been discovered, targeting users with an AI-powered subsystem that helps operators remotely navigate compromised devices. [...] Weiterlesen]]></description>
<link>https://tsecurity.de/de/4153011/malware-trojaner-viren/new-rathat-android-malware-uses-ai-to-automate-device-control/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4153011/malware-trojaner-viren/new-rathat-android-malware-uses-ai-to-automate-device-control/</guid>
<pubDate>Fri, 18 Sep 2026 00:24:46 +0200</pubDate>
<content:encoded><![CDATA[<p>A new Android malware called RatHat has been discovered, targeting users with an AI-powered subsystem that helps operators remotely navigate compromised devices. [...] <a href="https://www.bleepingcomputer.com/news/security/new-rathat-android-malware-uses-ai-to-automate-device-control/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Ransomware Operators Are Using AI Coding Agents Now]]></title>
<description><![CDATA[A ransomware crew used Cursor to write exploit code for ESXi hypervisors this month. Not a hypothetical. Not a tabletop exercise. The Aurora group integrated AI coding agents into active operations and hit production infrastructure with machine-generated payloads. That crossed a line most threat ...]]></description>
<link>https://tsecurity.de/de/4152814/malware-trojaner-viren/ransomware-operators-are-using-ai-coding-agents-now/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4152814/malware-trojaner-viren/ransomware-operators-are-using-ai-coding-agents-now/</guid>
<pubDate>Thu, 17 Sep 2026 21:18:56 +0200</pubDate>
<content:encoded><![CDATA[<p>A ransomware crew used Cursor to write exploit code for ESXi hypervisors this month. Not a hypothetical. Not a tabletop exercise. The Aurora group integrated AI coding agents into active operations and hit production infrastructure with machine-generated payloads. That crossed a line most threat models hadn&#039;t drawn yet. The conventional assumption... <a href="https://dev.to/numbpill3d/ransomware-operators-are-using-ai-coding-agents-now-4303" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Be alert: targeted attacks on prominent Rustaceans]]></title>
<description><![CDATA[We believe that there is an ongoing campaign targeting rust-lang members and owners of popular crates that is attempting to compromise devices and accounts in order to use them to publish malware. What we've seen A video call is set up for something positive — maybe for a job, maybe for a project...]]></description>
<link>https://tsecurity.de/de/4152732/malware-trojaner-viren/be-alert-targeted-attacks-on-prominent-rustaceans/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4152732/malware-trojaner-viren/be-alert-targeted-attacks-on-prominent-rustaceans/</guid>
<pubDate>Thu, 17 Sep 2026 20:17:03 +0200</pubDate>
<content:encoded><![CDATA[<p>We believe that there is an ongoing campaign targeting rust-lang members and owners of popular crates that is attempting to compromise devices and accounts in order to use them to publish malware. What we&#039;ve seen A video call is set up for something positive — maybe for a job, maybe for a project, maybe for a contract opportunity — and then that&#039;s... <a href="https://blog.rust-lang.org/2026/09/17/targeted-attacks/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[China’s Salt Typhoon backdoors Latin American orgs with new snooping malware]]></title>
<description><![CDATA[Beware the SparroWocky, my son! The backdoor that bites… This article has been indexed from www.theregister.com – Articles Read the original article: China’s Salt Typhoon backdoors Latin American orgs with new snooping malware The post China’s Salt Typhoon backdoors Latin American orgs with new s...]]></description>
<link>https://tsecurity.de/de/4152709/malware-trojaner-viren/chinas-salt-typhoon-backdoors-latin-american-orgs-with-new-snooping-malware/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4152709/malware-trojaner-viren/chinas-salt-typhoon-backdoors-latin-american-orgs-with-new-snooping-malware/</guid>
<pubDate>Thu, 17 Sep 2026 20:13:51 +0200</pubDate>
<content:encoded><![CDATA[<p>Beware the SparroWocky, my son! The backdoor that bites… This article has been indexed from www.theregister.com – Articles Read the original article: China’s Salt Typhoon backdoors Latin American orgs with new snooping malware The post China’s Salt Typhoon backdoors Latin American orgs with new snooping malware appeared first on IT Security News. <a href="https://www.itsecuritynews.info/chinas-salt-typhoon-backdoors-latin-american-orgs-with-new-snooping-malware/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[China's Salt Typhoon backdoors Latin American orgs with new snooping malware]]></title>
<description><![CDATA[China’s Salt Typhoon gang has developed a new backdoor and dropped it in networks belonging to high-profile organizations in several countries across Central and South America since at least August 2025, according to researchers. The PRC-backed espionage crew shifted its focus to Latin America a ...]]></description>
<link>https://tsecurity.de/de/4152700/malware-trojaner-viren/chinas-salt-typhoon-backdoors-latin-american-orgs-with-new-snooping-malware/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4152700/malware-trojaner-viren/chinas-salt-typhoon-backdoors-latin-american-orgs-with-new-snooping-malware/</guid>
<pubDate>Thu, 17 Sep 2026 20:10:33 +0200</pubDate>
<content:encoded><![CDATA[<p>China’s Salt Typhoon gang has developed a new backdoor and dropped it in networks belonging to high-profile organizations in several countries across Central and South America since at least August 2025, according to researchers. The PRC-backed espionage crew shifted its focus to Latin America a month prior, and from mid-2025 into 2026, the vast... <a href="https://www.theregister.com/security/2026/09/17/chinas-salt-typhoon-backdoors-latin-american-orgs-with-new-snooping-malware/5297286" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Brevo supply-chain attack injected ClickFix scripts on customer sites]]></title>
<description><![CDATA[Brevo confirmed that attackers stole a Cloudflare API key and used it to inject malicious ClickFix scripts into its websites and JavaScript files embedded on customer sites to distribute malware. [...] Weiterlesen]]></description>
<link>https://tsecurity.de/de/4152639/malware-trojaner-viren/brevo-supply-chain-attack-injected-clickfix-scripts-on-customer-sites/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4152639/malware-trojaner-viren/brevo-supply-chain-attack-injected-clickfix-scripts-on-customer-sites/</guid>
<pubDate>Thu, 17 Sep 2026 19:40:40 +0200</pubDate>
<content:encoded><![CDATA[<p>Brevo confirmed that attackers stole a Cloudflare API key and used it to inject malicious ClickFix scripts into its websites and JavaScript files embedded on customer sites to distribute malware. [...] <a href="https://www.bleepingcomputer.com/news/security/brevo-supply-chain-attack-injected-clickfix-scripts-on-customer-sites/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[New Settra Ransomware Strain Deploys MeshAgent RMM for Persistence]]></title>
<description><![CDATA[Researchers at Huntress have detailed two ransomware incidents involving Settra, a relatively new strain first observed in June, and revealed a consistent set of post-compromise tactics defenders can use to spot the threat before encryption takes hold. In a blog post published this week, Huntress...]]></description>
<link>https://tsecurity.de/de/4152454/malware-trojaner-viren/new-settra-ransomware-strain-deploys-meshagent-rmm-for-persistence/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4152454/malware-trojaner-viren/new-settra-ransomware-strain-deploys-meshagent-rmm-for-persistence/</guid>
<pubDate>Thu, 17 Sep 2026 18:28:29 +0200</pubDate>
<content:encoded><![CDATA[<p>Researchers at Huntress have detailed two ransomware incidents involving Settra, a relatively new strain first observed in June, and revealed a consistent set of post-compromise tactics defenders can use to spot the threat before encryption takes hold. In a blog post published this week, Huntress researchers Harlan Carvey and Lindsey... <a href="https://www.itsecurityguru.org/2026/09/17/new-settra-ransomware-strain-deploys-meshagent-rmm-for-persistence/?utm_source=rss&amp;utm_medium=rss&amp;utm_campaign=new-settra-ransomware-strain-deploys-meshagent-rmm-for-persistence" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Replik zum Artikel „Vom Keller in die Cloud: Warum das lokale Firmen-Rechenzentrum zum Sicherheitsrisiko wird “]]></title>
<description><![CDATA[Replik zum Cloud-Hype: Wie FUD täuscht, welche Risiken der US Cloud Act birgt und warum die lokale IT erforderlich bleibt. Der Artikel Replik zum Artikel „Vom Keller in die Cloud: Warum das lokale Firmen-Rechenzentrum zum Sicherheitsrisiko wird “ erschien zuerst auf TARNKAPPE.INFO Weiterlesen]]></description>
<link>https://tsecurity.de/de/4152329/malware-trojaner-viren/replik-zum-artikel-vom-keller-in-die-cloud-warum-das-lokale-firmen-rechenzentrum-zum-sicherheitsrisiko-wird/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4152329/malware-trojaner-viren/replik-zum-artikel-vom-keller-in-die-cloud-warum-das-lokale-firmen-rechenzentrum-zum-sicherheitsrisiko-wird/</guid>
<pubDate>Thu, 17 Sep 2026 18:15:22 +0200</pubDate>
<content:encoded><![CDATA[<p>Replik zum Cloud-Hype: Wie FUD täuscht, welche Risiken der US Cloud Act birgt und warum die lokale IT erforderlich bleibt. Der Artikel Replik zum Artikel „Vom Keller in die Cloud: Warum das lokale Firmen-Rechenzentrum zum Sicherheitsrisiko wird “ erschien zuerst auf TARNKAPPE.INFO <a href="https://tarnkappe.info/artikel/it-sicherheit/replik-zum-artikel-vom-keller-in-die-cloud-warum-das-lokale-firmen-rechenzentrum-zum-sicherheitsrisiko-wird-333537.html" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CHOSEN BRICK: Iranian Windows Surveillance Malware Using Telegram C2]]></title>
<description><![CDATA[1. Overview Original Title: Iranian cyber targeting of dissidents, activists and journalists Source: NCSC, FBI, AIVD Published: 2026-09-15 Updated: None Severity: High Basis for Severity: The joint government advisory reports real-world compromises targeting dissidents, activists, and journalists...]]></description>
<link>https://tsecurity.de/de/4152314/malware-trojaner-viren/chosen-brick-iranian-windows-surveillance-malware-using-telegram-c2/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4152314/malware-trojaner-viren/chosen-brick-iranian-windows-surveillance-malware-using-telegram-c2/</guid>
<pubDate>Thu, 17 Sep 2026 17:31:45 +0200</pubDate>
<content:encoded><![CDATA[<p>1. Overview Original Title: Iranian cyber targeting of dissidents, activists and journalists Source: NCSC, FBI, AIVD Published: 2026-09-15 Updated: None Severity: High Basis for Severity: The joint government advisory reports real-world compromises targeting dissidents, activists, and journalists worldwide since at least 2025. The malware focuses... <a href="https://dev.to/anoymask/chosen-brick-iranian-windows-surveillance-malware-using-telegram-c2-34ng" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[LausivLoader analysis, or how to pass data between malware stages, (Thu, Sep 17th)]]></title>
<description><![CDATA[At the end of August, a malspam message was caught in the quarantine of a mail gateway operated by one of my customers. The message was not especially remarkable – it asked the recipient to review some attached requirements and provide a price quotation for a fiber optic system and appeared to im...]]></description>
<link>https://tsecurity.de/de/4152284/malware-trojaner-viren/lausivloader-analysis-or-how-to-pass-data-between-malware-stages-thu-sep-17th/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4152284/malware-trojaner-viren/lausivloader-analysis-or-how-to-pass-data-between-malware-stages-thu-sep-17th/</guid>
<pubDate>Thu, 17 Sep 2026 17:28:48 +0200</pubDate>
<content:encoded><![CDATA[<p>At the end of August, a malspam message was caught in the quarantine of a mail gateway operated by one of my customers. The message was not especially remarkable – it asked the recipient to review some attached requirements and provide a price quotation for a fiber optic system and appeared to impersonate an employee of a legitimate company. The... <a href="https://isc.sans.edu/diary/rss/33348" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CISA Wants Defenders to Plant Fake Credentials and Systems to Catch Hackers]]></title>
<description><![CDATA[CISA has urged organizations to deploy fake credentials, systems, files, and data assets inside their environments to expose attackers after an initial compromise. The agency published its new guidance, Using Cyber Decoys to Strengthen Detection and Response, on September 16, 2026. CISA said many...]]></description>
<link>https://tsecurity.de/de/4152176/malware-trojaner-viren/cisa-wants-defenders-to-plant-fake-credentials-and-systems-to-catch-hackers/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4152176/malware-trojaner-viren/cisa-wants-defenders-to-plant-fake-credentials-and-systems-to-catch-hackers/</guid>
<pubDate>Thu, 17 Sep 2026 16:47:40 +0200</pubDate>
<content:encoded><![CDATA[<p>CISA has urged organizations to deploy fake credentials, systems, files, and data assets inside their environments to expose attackers after an initial compromise. The agency published its new guidance, Using Cyber Decoys to Strengthen Detection and Response, on September 16, 2026. CISA said many attackers now avoid malware-heavy intrusion methods... <a href="https://cybersecuritynews.com/cisa-fake-credentials-catch-hackers/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Handala Hack Uses CRUDEEXCLUDE to Disable Defender Protections and Deploy HEAVYGRAM]]></title>
<description><![CDATA[A previously undocumented HEAVYGRAM and CRUDEEXCLUDE malware samples linked with moderate confidence to the Iran-aligned Handala Hack operation. The campaign combines targeted social engineering, Microsoft Defender exclusion abuse, multi-stage loaders, and Telegram-based command-and-control to su...]]></description>
<link>https://tsecurity.de/de/4152173/malware-trojaner-viren/handala-hack-uses-crudeexclude-to-disable-defender-protections-and-deploy-heavygram/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4152173/malware-trojaner-viren/handala-hack-uses-crudeexclude-to-disable-defender-protections-and-deploy-heavygram/</guid>
<pubDate>Thu, 17 Sep 2026 16:47:24 +0200</pubDate>
<content:encoded><![CDATA[<p>A previously undocumented HEAVYGRAM and CRUDEEXCLUDE malware samples linked with moderate confidence to the Iran-aligned Handala Hack operation. The campaign combines targeted social engineering, Microsoft Defender exclusion abuse, multi-stage loaders, and Telegram-based command-and-control to surveil Iranian dissidents, journalists, and people... <a href="https://gbhackers.com/heavygram-malware-deployment/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[New Chinese-Made ‘RatHat’ Android Malware Leverages AI to Steal Financial Data]]></title>
<description><![CDATA[Researchers at Zimperium have uncovered a new Android malware strain, dubbed RatHat, with spyware and backdoor capabilities Weiterlesen]]></description>
<link>https://tsecurity.de/de/4152158/malware-trojaner-viren/new-chinese-made-rathat-android-malware-leverages-ai-to-steal-financial-data/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4152158/malware-trojaner-viren/new-chinese-made-rathat-android-malware-leverages-ai-to-steal-financial-data/</guid>
<pubDate>Thu, 17 Sep 2026 16:44:04 +0200</pubDate>
<content:encoded><![CDATA[<p>Researchers at Zimperium have uncovered a new Android malware strain, dubbed RatHat, with spyware and backdoor capabilities <a href="https://www.infosecurity-magazine.com/news/rathat-android-malware-ai-steal/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Golang BYOVD Malware Loader and Vulnerable Driver Analysis]]></title>
<description><![CDATA[submitted by /u/jershmagersh [link] [comments] Weiterlesen]]></description>
<link>https://tsecurity.de/de/4152002/malware-trojaner-viren/golang-byovd-malware-loader-and-vulnerable-driver-analysis/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4152002/malware-trojaner-viren/golang-byovd-malware-loader-and-vulnerable-driver-analysis/</guid>
<pubDate>Thu, 17 Sep 2026 16:30:34 +0200</pubDate>
<content:encoded><![CDATA[<p>submitted by /u/jershmagersh [link] [comments] <a href="https://www.reddit.com/r/MalwareAnalysis/comments/1wiv6p8/golang_byovd_malware_loader_and_vulnerable_driver/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[The Odyssey and trojans again: MovieReaper attacks users in multiple countries via compromised torrents]]></title>
<description><![CDATA[Introduction Torrent trackers have long been abused for distributing malicious software, disguised as popular films, games, and other content. Our previous research has shown that cybercriminals repeatedly turn torrents as an initial infection vector, using trojanized cracks and installers to rea...]]></description>
<link>https://tsecurity.de/de/4152001/malware-trojaner-viren/the-odyssey-and-trojans-again-moviereaper-attacks-users-in-multiple-countries-via-compromised-torrents/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4152001/malware-trojaner-viren/the-odyssey-and-trojans-again-moviereaper-attacks-users-in-multiple-countries-via-compromised-torrents/</guid>
<pubDate>Thu, 17 Sep 2026 16:30:05 +0200</pubDate>
<content:encoded><![CDATA[<p>Introduction Torrent trackers have long been abused for distributing malicious software, disguised as popular films, games, and other content. Our previous research has shown that cybercriminals repeatedly turn torrents as an initial infection vector, using trojanized cracks and installers to reach a large number of users. Installation guides for... <a href="https://securelist.com/moviereaper-malware-torrent-odyssey-solana/121344/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Staatliche Hacker treiben laut Chainalysis einen Anstieg von 420 % bei Onchain-Malware voran]]></title>
<description><![CDATA[Mit Staaten verbundene Hacker waren in jedem Quartal für etwa zwei Drittel der neuen Aktivitäten verantwortlich, während die Zahl der Fälle, ... Weiterlesen]]></description>
<link>https://tsecurity.de/de/4151995/malware-trojaner-viren/staatliche-hacker-treiben-laut-chainalysis-einen-anstieg-von-420-bei-onchain-malware-voran/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4151995/malware-trojaner-viren/staatliche-hacker-treiben-laut-chainalysis-einen-anstieg-von-420-bei-onchain-malware-voran/</guid>
<pubDate>Thu, 17 Sep 2026 15:04:31 +0200</pubDate>
<content:encoded><![CDATA[<p>Mit Staaten verbundene Hacker waren in jedem Quartal für etwa zwei Drittel der neuen Aktivitäten verantwortlich, während die Zahl der Fälle, ... <a href="https://www.google.com/url?rct=j&amp;sa=t&amp;url=https://de.tradingview.com/news/cointelegraph:2b7934df7600c:0/&amp;ct=ga&amp;cd=CAIyGTY2ODI4YjRlZGNiMmJmMmM6ZGU6ZGU6REU&amp;usg=AOvVaw2p_c2bzGEmeEWrxRNR_moD" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Chinesische KI-Modelle verursachen Anstieg der auf der Blockchain platzierten Malware ...]]></title>
<description><![CDATA[Chainalysis verbindet einen Anstieg von 440% bei Malware-Befehlen auf der Blockchain mit chinesischen KI-Modellen, Nordkorea und Iran führen. Weiterlesen]]></description>
<link>https://tsecurity.de/de/4151994/malware-trojaner-viren/chinesische-ki-modelle-verursachen-anstieg-der-auf-der-blockchain-platzierten-malware/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4151994/malware-trojaner-viren/chinesische-ki-modelle-verursachen-anstieg-der-auf-der-blockchain-platzierten-malware/</guid>
<pubDate>Thu, 17 Sep 2026 15:04:31 +0200</pubDate>
<content:encoded><![CDATA[<p>Chainalysis verbindet einen Anstieg von 440% bei Malware-Befehlen auf der Blockchain mit chinesischen KI-Modellen, Nordkorea und Iran führen. <a href="https://www.google.com/url?rct=j&amp;sa=t&amp;url=https://de.finance.yahoo.com/nachrichten/chinesische-ki-modelle-verursachen-anstieg-121224982.html&amp;ct=ga&amp;cd=CAIyGTY2ODI4YjRlZGNiMmJmMmM6ZGU6ZGU6REU&amp;usg=AOvVaw33NK4XUOVabdHhrs96KHn3" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[SilkParasite-Linked Malware Infrastructure Traced Back Four Years Across Central Asia]]></title>
<description><![CDATA[SilkParasite is a cyberespionage operation aimed at government, energy and telecommunications interests in Central Asia. New infrastructure analysis indicates that the activity behind the campaign may be older and broader than its recent name suggests. The operation has used spear-phishing emails...]]></description>
<link>https://tsecurity.de/de/4151962/malware-trojaner-viren/silkparasite-linked-malware-infrastructure-traced-back-four-years-across-central-asia/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4151962/malware-trojaner-viren/silkparasite-linked-malware-infrastructure-traced-back-four-years-across-central-asia/</guid>
<pubDate>Thu, 17 Sep 2026 15:00:31 +0200</pubDate>
<content:encoded><![CDATA[<p>SilkParasite is a cyberespionage operation aimed at government, energy and telecommunications interests in Central Asia. New infrastructure analysis indicates that the activity behind the campaign may be older and broader than its recent name suggests. The operation has used spear-phishing emails carrying convincing government-themed documents and... <a href="https://cybersecuritynews.com/silkparasite-linked-malware/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Hackers Turn Telegram Into a Command Center for HEAVYGRAM Surveillance Malware]]></title>
<description><![CDATA[HEAVYGRAM is a Windows surveillance backdoor that turns Telegram into an operational command center for attackers. Rather than relying on a dedicated server, it uses bots, accounts and groups to receive instructions, move stolen data and keep infected devices under control. The malware has been u...]]></description>
<link>https://tsecurity.de/de/4151961/malware-trojaner-viren/hackers-turn-telegram-into-a-command-center-for-heavygram-surveillance-malware/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4151961/malware-trojaner-viren/hackers-turn-telegram-into-a-command-center-for-heavygram-surveillance-malware/</guid>
<pubDate>Thu, 17 Sep 2026 15:00:31 +0200</pubDate>
<content:encoded><![CDATA[<p>HEAVYGRAM is a Windows surveillance backdoor that turns Telegram into an operational command center for attackers. Rather than relying on a dedicated server, it uses bots, accounts and groups to receive instructions, move stolen data and keep infected devices under control. The malware has been used since fall 2023 against journalists, Iranian... <a href="https://cybersecuritynews.com/heavygram-surveillance-malware/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Druva expands identity resilience with ransomware detection]]></title>
<description><![CDATA[Druva has announced new capabilities for Druva Identity Resilience alongside the launch of Ransomware Detection, a new feature fueled by a proprietary AI threat pipeline. Powered by Dru MetaGraph, the new offerings use behavioral intelligence and built-in validation to turn suspicious behavior in...]]></description>
<link>https://tsecurity.de/de/4151955/malware-trojaner-viren/druva-expands-identity-resilience-with-ransomware-detection/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4151955/malware-trojaner-viren/druva-expands-identity-resilience-with-ransomware-detection/</guid>
<pubDate>Thu, 17 Sep 2026 14:57:38 +0200</pubDate>
<content:encoded><![CDATA[<p>Druva has announced new capabilities for Druva Identity Resilience alongside the launch of Ransomware Detection, a new feature fueled by a proprietary AI threat pipeline. Powered by Dru MetaGraph, the new offerings use behavioral intelligence and built-in validation to turn suspicious behavior into actionable evidence, definitively confirm impact,... <a href="https://www.helpnetsecurity.com/2026/09/17/druva-identity-resilience-ransomware-detection/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Tackling Spyware Abuse: What States Must Do Under International Law to Protect Journalists and Strengthen Security]]></title>
<description><![CDATA[The Citizen Lab, a digital-security research group at the University of Toronto, published a report this past July revealing that Stelios Kouloglou, a prominent Greek investigative journalist and former member of the European Parliament, was hacked with NSO Group’s Pegasus spyware multiple times ...]]></description>
<link>https://tsecurity.de/de/4151950/malware-trojaner-viren/tackling-spyware-abuse-what-states-must-do-under-international-law-to-protect-journalists-and-strengthen-security/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4151950/malware-trojaner-viren/tackling-spyware-abuse-what-states-must-do-under-international-law-to-protect-journalists-and-strengthen-security/</guid>
<pubDate>Thu, 17 Sep 2026 14:57:05 +0200</pubDate>
<content:encoded><![CDATA[<p>The Citizen Lab, a digital-security research group at the University of Toronto, published a report this past July revealing that Stelios Kouloglou, a prominent Greek investigative journalist and former member of the European Parliament, was hacked with NSO Group’s Pegasus spyware multiple times in 2022 and 2023. At the time, Kouloglou was serving... <a href="https://www.justsecurity.org/156978/tackling-spyware-abuse-protect-journalists/?utm_source=rss&amp;utm_medium=rss&amp;utm_campaign=tackling-spyware-abuse-protect-journalists" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Kann die Produktion weiterlaufen, wenn die Konzern-IT kompromittiert ist?]]></title>
<description><![CDATA[Ja, wenn das Werk seine kritischen Funktionen für eine definierte Zeit ohne Konzern-IT betreiben kann. Netzsegmentierung allein belegt das nicht. Ob das gelingt, zeigt sich beim nächsten Schichtwechsel und beim ersten Restore. Die Anlage läuft. Der neue Schichtführer kann sich nicht anmelden. Ran...]]></description>
<link>https://tsecurity.de/de/4151948/malware-trojaner-viren/kann-die-produktion-weiterlaufen-wenn-die-konzern-it-kompromittiert-ist/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4151948/malware-trojaner-viren/kann-die-produktion-weiterlaufen-wenn-die-konzern-it-kompromittiert-ist/</guid>
<pubDate>Thu, 17 Sep 2026 14:56:38 +0200</pubDate>
<content:encoded><![CDATA[<p>Ja, wenn das Werk seine kritischen Funktionen für eine definierte Zeit ohne Konzern-IT betreiben kann. Netzsegmentierung allein belegt das nicht. Ob das gelingt, zeigt sich beim nächsten Schichtwechsel und beim ersten Restore. Die Anlage läuft. Der neue Schichtführer kann sich nicht anmelden. Ransomware hat die Konzern-IT getroffen, Active... <a href="https://www.it-daily.net/it-sicherheit/cloud-security/produktion-it-kompromittiert" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Ransomware Attacks on Manufacturers Surge as Supply Chain Risk Grows]]></title>
<description><![CDATA[Research shows attacks on manufacturers rose 40% in early 2026, as ransomware groups increasingly exploit the supply-chain disruption caused by operational shutdowns. The post Ransomware Attacks on Manufacturers Surge as Supply Chain Risk Grows appeared first on SecurityWeek. Weiterlesen]]></description>
<link>https://tsecurity.de/de/4151946/malware-trojaner-viren/ransomware-attacks-on-manufacturers-surge-as-supply-chain-risk-grows/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4151946/malware-trojaner-viren/ransomware-attacks-on-manufacturers-surge-as-supply-chain-risk-grows/</guid>
<pubDate>Thu, 17 Sep 2026 14:56:23 +0200</pubDate>
<content:encoded><![CDATA[<p>Research shows attacks on manufacturers rose 40% in early 2026, as ransomware groups increasingly exploit the supply-chain disruption caused by operational shutdowns. The post Ransomware Attacks on Manufacturers Surge as Supply Chain Risk Grows appeared first on SecurityWeek. <a href="https://www.securityweek.com/ransomware-attacks-on-manufacturers-surge-as-supply-chain-risk-grows/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[FamousSparrow bringt neue SparroWocky-Backdoor in lateinamerikanischen Angriffen aus]]></title>
<description><![CDATA[LONDON (IT BOLTWISE) – Eine China-ausgerichtete Gruppe namens FamousSparrow setzt in Angriffen gegen mehrere Länder in Lateinamerika eine neue Backdoor namens SparroWocky ein. Die Malware wird seit mindestens August 2025 beobachtet und ersetzt dort Berichten zufolge eine frühere Hauptkomponente. ...]]></description>
<link>https://tsecurity.de/de/4151849/malware-trojaner-viren/famoussparrow-bringt-neue-sparrowocky-backdoor-in-lateinamerikanischen-angriffen-aus/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4151849/malware-trojaner-viren/famoussparrow-bringt-neue-sparrowocky-backdoor-in-lateinamerikanischen-angriffen-aus/</guid>
<pubDate>Thu, 17 Sep 2026 14:13:37 +0200</pubDate>
<content:encoded><![CDATA[<p>LONDON (IT BOLTWISE) – Eine China-ausgerichtete Gruppe namens FamousSparrow setzt in Angriffen gegen mehrere Länder in Lateinamerika eine neue Backdoor namens SparroWocky ein. Die Malware wird seit mindestens August 2025 beobachtet und ersetzt dort Berichten zufolge eine frühere Hauptkomponente. Laut ESET ist das Implantat modular, lässt sich über... <a href="https://www.it-boltwise.de/famoussparrow-bringt-neue-sparrowocky-backdoor-in-lateinamerikanischen-angriffen-aus.html" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Fake MRI Scans Deliver CHOSEN BRICK Spyware to Windows PCs]]></title>
<description><![CDATA[Iranian state-linked attackers are using fake MRI scans and software lures to deploy CHOSEN BRICK spyware on Windows PCs. This article has been indexed from eSecurity Planet Read the original article: Fake MRI Scans Deliver CHOSEN BRICK Spyware to Windows PCs The post Fake MRI Scans Deliver CHOSE...]]></description>
<link>https://tsecurity.de/de/4151845/malware-trojaner-viren/fake-mri-scans-deliver-chosen-brick-spyware-to-windows-pcs/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4151845/malware-trojaner-viren/fake-mri-scans-deliver-chosen-brick-spyware-to-windows-pcs/</guid>
<pubDate>Thu, 17 Sep 2026 14:13:32 +0200</pubDate>
<content:encoded><![CDATA[<p>Iranian state-linked attackers are using fake MRI scans and software lures to deploy CHOSEN BRICK spyware on Windows PCs. This article has been indexed from eSecurity Planet Read the original article: Fake MRI Scans Deliver CHOSEN BRICK Spyware to Windows PCs The post Fake MRI Scans Deliver CHOSEN BRICK Spyware to Windows PCs appeared first on IT... <a href="https://www.itsecuritynews.info/fake-mri-scans-deliver-chosen-brick-spyware-to-windows-pcs/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[IT Security News Hourly Summary 2026-09-17 14h : 14 posts]]></title>
<description><![CDATA[14 posts published in the last hour 11:32Fake MRI Scans Deliver CHOSEN BRICK Spyware to Windows PCs 11:32Test environment let anyone access live customer data 11:31How Candidates Could Use AI for Good 11:31BIND 9.20.29 Fixes 14 Security Flaws Enabling DNSSEC Bypass and Denial-of-Service Attacks 1...]]></description>
<link>https://tsecurity.de/de/4151844/malware-trojaner-viren/it-security-news-hourly-summary-2026-09-17-14h-14-posts/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4151844/malware-trojaner-viren/it-security-news-hourly-summary-2026-09-17-14h-14-posts/</guid>
<pubDate>Thu, 17 Sep 2026 14:13:32 +0200</pubDate>
<content:encoded><![CDATA[<p>14 posts published in the last hour 11:32Fake MRI Scans Deliver CHOSEN BRICK Spyware to Windows PCs 11:32Test environment let anyone access live customer data 11:31How Candidates Could Use AI for Good 11:31BIND 9.20.29 Fixes 14 Security Flaws Enabling DNSSEC Bypass and Denial-of-Service Attacks 11:31World Quantum Readiness Day: Industry Voices on... <a href="https://www.itsecuritynews.info/it-security-news-hourly-summary-2026-09-17-14h-14-posts/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[FamousSparrow Deploys New SparroWocky Backdoor Against Latin American Governments]]></title>
<description><![CDATA[China-aligned advanced persistent threat group FamousSparrow has replaced its long-running SparrowDoor implant with a new modular C++ backdoor, SparroWocky, in a sustained cyberespionage campaign against government entities across Latin America. ESET says the malware has been active in the region...]]></description>
<link>https://tsecurity.de/de/4151725/malware-trojaner-viren/famoussparrow-deploys-new-sparrowocky-backdoor-against-latin-american-governments/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4151725/malware-trojaner-viren/famoussparrow-deploys-new-sparrowocky-backdoor-against-latin-american-governments/</guid>
<pubDate>Thu, 17 Sep 2026 13:28:53 +0200</pubDate>
<content:encoded><![CDATA[<p>China-aligned advanced persistent threat group FamousSparrow has replaced its long-running SparrowDoor implant with a new modular C++ backdoor, SparroWocky, in a sustained cyberespionage campaign against government entities across Latin America. ESET says the malware has been active in the region since at least August 2025, following a sharp shift... <a href="https://gbhackers.com/sparrowocky-backdoor/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[THEA1200 – drei klassische Amiga-Computer unter einer Haube]]></title>
<description><![CDATA[Pünktlich zu Weihnachten kommt die neue Emulator-Hardware THEA1200 heraus, sie vereint den A500, A600 und A1200. Der Artikel THEA1200 – drei klassische Amiga-Computer unter einer Haube erschien zuerst auf TARNKAPPE.INFO Weiterlesen]]></description>
<link>https://tsecurity.de/de/4151621/malware-trojaner-viren/thea1200-drei-klassische-amiga-computer-unter-einer-haube/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4151621/malware-trojaner-viren/thea1200-drei-klassische-amiga-computer-unter-einer-haube/</guid>
<pubDate>Thu, 17 Sep 2026 13:15:23 +0200</pubDate>
<content:encoded><![CDATA[<p>Pünktlich zu Weihnachten kommt die neue Emulator-Hardware THEA1200 heraus, sie vereint den A500, A600 und A1200. Der Artikel THEA1200 – drei klassische Amiga-Computer unter einer Haube erschien zuerst auf TARNKAPPE.INFO <a href="https://tarnkappe.info/retro-computing/thea1200-drei-klassische-amiga-computer-unter-einer-haube-333528.html" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[APT36 Uses USB-Spreading Malware to Reach Air-Gapped Government Networks]]></title>
<description><![CDATA[APT36, a Pakistan-linked threat group, has launched a campaign that uses infected removable drives to carry malware into disconnected government environments. The operation, called RapidRust, targets India and Afghanistan with a backdoor, file stealers, and a USB-spreading tool. This approach is ...]]></description>
<link>https://tsecurity.de/de/4151591/malware-trojaner-viren/apt36-uses-usb-spreading-malware-to-reach-air-gapped-government-networks/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4151591/malware-trojaner-viren/apt36-uses-usb-spreading-malware-to-reach-air-gapped-government-networks/</guid>
<pubDate>Thu, 17 Sep 2026 12:28:06 +0200</pubDate>
<content:encoded><![CDATA[<p>APT36, a Pakistan-linked threat group, has launched a campaign that uses infected removable drives to carry malware into disconnected government environments. The operation, called RapidRust, targets India and Afghanistan with a backdoor, file stealers, and a USB-spreading tool. This approach is important because air-gapped networks are separated... <a href="https://cybersecuritynews.com/apt36-uses-usb/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[16-31 August 2026 Cyber Attacks Timeline]]></title>
<description><![CDATA[The second half of August 2026 brought 110 confirmed cyber incidents, with Cyber Crime once again the dominant motivation at 78% of attacks. Malware remained the weapon of choice, exploitation of public-facing applications (T1190) continued to lead initial access, and Information &amp; Communicat...]]></description>
<link>https://tsecurity.de/de/4151583/malware-trojaner-viren/16-31-august-2026-cyber-attacks-timeline/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4151583/malware-trojaner-viren/16-31-august-2026-cyber-attacks-timeline/</guid>
<pubDate>Thu, 17 Sep 2026 12:27:31 +0200</pubDate>
<content:encoded><![CDATA[<p>The second half of August 2026 brought 110 confirmed cyber incidents, with Cyber Crime once again the dominant motivation at 78% of attacks. Malware remained the weapon of choice, exploitation of public-facing applications (T1190) continued to lead initial access, and Information &amp;amp; Communication emerged as the hardest-hit sector. This timeline... <a href="https://www.itsecuritynews.info/16-31-august-2026-cyber-attacks-timeline/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Ransomware incidents in Japan in the first half of 2026: Investigation of The Gentlemen’s infrastructure and evidence of Qilin’s AI use]]></title>
<description><![CDATA[Ransomware incidents in Japan rose 4.7% year over year. The Gentlemen was the most active group, with leak-site listings more than doubling from January to July. Qilin ranked second and appeared to use AI, while SMEs with capital under JPY 1 billion represented 80% of victims. This article has be...]]></description>
<link>https://tsecurity.de/de/4151582/malware-trojaner-viren/ransomware-incidents-in-japan-in-the-first-half-of-2026-investigation-of-the-gentlemens-infrastructure-and-evidence-of-qilins-ai-use/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4151582/malware-trojaner-viren/ransomware-incidents-in-japan-in-the-first-half-of-2026-investigation-of-the-gentlemens-infrastructure-and-evidence-of-qilins-ai-use/</guid>
<pubDate>Thu, 17 Sep 2026 12:27:31 +0200</pubDate>
<content:encoded><![CDATA[<p>Ransomware incidents in Japan rose 4.7% year over year. The Gentlemen was the most active group, with leak-site listings more than doubling from January to July. Qilin ranked second and appeared to use AI, while SMEs with capital under JPY 1 billion represented 80% of victims. This article has been indexed from Cisco Talos Blog Read the original... <a href="https://www.itsecuritynews.info/ransomware-incidents-in-japan-in-the-first-half-of-2026-investigation-of-the-gentlemens-infrastructure-and-evidence-of-qilins-ai-use/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[16-31 August 2026 Cyber Attacks Timeline Infographic]]></title>
<description><![CDATA[A one-page visual summary of the 16–31 August 2026 cyber attacks timeline: 110 incidents broken down by motivation, attack technique, initial access vector, targeted sector, and country — Cyber Crime and Malware led the period, with Information &amp; Communication the hardest-hit sector. This art...]]></description>
<link>https://tsecurity.de/de/4151581/malware-trojaner-viren/16-31-august-2026-cyber-attacks-timeline-infographic/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4151581/malware-trojaner-viren/16-31-august-2026-cyber-attacks-timeline-infographic/</guid>
<pubDate>Thu, 17 Sep 2026 12:27:31 +0200</pubDate>
<content:encoded><![CDATA[<p>A one-page visual summary of the 16–31 August 2026 cyber attacks timeline: 110 incidents broken down by motivation, attack technique, initial access vector, targeted sector, and country — Cyber Crime and Malware led the period, with Information &amp;amp; Communication the hardest-hit sector. This article has been indexed from HACKMAGEDDON Read the... <a href="https://www.itsecuritynews.info/16-31-august-2026-cyber-attacks-timeline-infographic/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Ransomware incidents in Japan in the first half of 2026: Investigation of The Gentlemen’s infrastructure and evidence of Qilin's AI use]]></title>
<description><![CDATA[Compared with the same period last year, ransomware incidents in Japan increased slightly by approximately 4.7%, indicating that ransomware continues to pose a significant threat.In Japan, The Gentlemen was the most active ransomware group in the first half of 2026.Attackers continue to primarily...]]></description>
<link>https://tsecurity.de/de/4151496/malware-trojaner-viren/ransomware-incidents-in-japan-in-the-first-half-of-2026-investigation-of-the-gentlemens-infrastructure-and-evidence-of-qilins-ai-use/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4151496/malware-trojaner-viren/ransomware-incidents-in-japan-in-the-first-half-of-2026-investigation-of-the-gentlemens-infrastructure-and-evidence-of-qilins-ai-use/</guid>
<pubDate>Thu, 17 Sep 2026 12:00:56 +0200</pubDate>
<content:encoded><![CDATA[<p>Compared with the same period last year, ransomware incidents in Japan increased slightly by approximately 4.7%, indicating that ransomware continues to pose a significant threat.In Japan, The Gentlemen was the most active ransomware group in the first half of 2026.Attackers continue to primarily target small- and medium-sized enterprises, with... <a href="https://blog.talosintelligence.com/ransomware-incidents-in-japan-in-the-first-half-of-2026/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[APT36 Targets Indian Government and Defense Organizations With New Rust Malware Arsenal]]></title>
<description><![CDATA[Pakistan-nexus threat actor APT36 has launched a renewed espionage campaign targeting government and defense organizations in India and Afghanistan. Deploying a new Rust-based malware suite designed for covert command-and-control, data theft, and propagation into isolated networks. Tracked by Zsc...]]></description>
<link>https://tsecurity.de/de/4151492/malware-trojaner-viren/apt36-targets-indian-government-and-defense-organizations-with-new-rust-malware-arsenal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4151492/malware-trojaner-viren/apt36-targets-indian-government-and-defense-organizations-with-new-rust-malware-arsenal/</guid>
<pubDate>Thu, 17 Sep 2026 11:59:35 +0200</pubDate>
<content:encoded><![CDATA[<p>Pakistan-nexus threat actor APT36 has launched a renewed espionage campaign targeting government and defense organizations in India and Afghanistan. Deploying a new Rust-based malware suite designed for covert command-and-control, data theft, and propagation into isolated networks. Tracked by Zscaler ThreatLabz as Operation RapidRust, the activity... <a href="https://gbhackers.com/apt36-malware-campaign/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[APT36 Uses RUSTYSHADE and USB Malware to Target Government and Defense Organizations]]></title>
<description><![CDATA[Pakistan-linked threat actor APT36 has launched a new cyber campaign targeting government and defense organizations in India and Afghanistan. The campaign, tracked as Operation RapidRust, was identified by Zscaler ThreatLabz in August 2026 and shows the group continuing to update its malware and ...]]></description>
<link>https://tsecurity.de/de/4151489/malware-trojaner-viren/apt36-uses-rustyshade-and-usb-malware-to-target-government-and-defense-organizations/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4151489/malware-trojaner-viren/apt36-uses-rustyshade-and-usb-malware-to-target-government-and-defense-organizations/</guid>
<pubDate>Thu, 17 Sep 2026 11:59:28 +0200</pubDate>
<content:encoded><![CDATA[<p>Pakistan-linked threat actor APT36 has launched a new cyber campaign targeting government and defense organizations in India and Afghanistan. The campaign, tracked as Operation RapidRust, was identified by Zscaler ThreatLabz in August 2026 and shows the group continuing to update its malware and post-compromise methods. The operation uses several... <a href="https://cyberpress.org/apt36s-rustyshade-usb-campaign/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Cyberthreats are moving faster than SMBs: Readiness must accelerate]]></title>
<description><![CDATA[As AI adoption expands the attack surface and adds to the security workload, businesses need automation backed by experts Weiterlesen]]></description>
<link>https://tsecurity.de/de/4151435/malware-trojaner-viren/cyberthreats-are-moving-faster-than-smbs-readiness-must-accelerate/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4151435/malware-trojaner-viren/cyberthreats-are-moving-faster-than-smbs-readiness-must-accelerate/</guid>
<pubDate>Thu, 17 Sep 2026 11:45:20 +0200</pubDate>
<content:encoded><![CDATA[<p>As AI adoption expands the attack surface and adds to the security workload, businesses need automation backed by experts <a href="https://www.welivesecurity.com/en/business-security/cyberthreats-moving-faster-smbs-readiness-must-accelerate/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[New Android Malware Steals Banking PINs and Reinstalls Itself After Users Delete It]]></title>
<description><![CDATA[A newly tracked Android malware called RatHat is targeting banking customers with fake screens, stolen verification codes and persistent phone access. The threat can capture PINs, passwords and unlock patterns, raising the risk of account takeovers and payments after a victim believes the malicio...]]></description>
<link>https://tsecurity.de/de/4151382/malware-trojaner-viren/new-android-malware-steals-banking-pins-and-reinstalls-itself-after-users-delete-it/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4151382/malware-trojaner-viren/new-android-malware-steals-banking-pins-and-reinstalls-itself-after-users-delete-it/</guid>
<pubDate>Thu, 17 Sep 2026 11:31:18 +0200</pubDate>
<content:encoded><![CDATA[<p>A newly tracked Android malware called RatHat is targeting banking customers with fake screens, stolen verification codes and persistent phone access. The threat can capture PINs, passwords and unlock patterns, raising the risk of account takeovers and payments after a victim believes the malicious app is gone. The campaign relies on deceptive... <a href="https://cybersecuritynews.com/new-android-malware/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[New SparroWocky backdoor deployed in attacks on governments]]></title>
<description><![CDATA[The China-aligned FamousSparrow cyberespionage group has begun deploying a new modular backdoor named SparroWocky in attacks focused heavily on Latin America. The malware provides extensive remote-control capabilities while using low-level Windows manipulation and anti-analysis techniques to evad...]]></description>
<link>https://tsecurity.de/de/4151379/malware-trojaner-viren/new-sparrowocky-backdoor-deployed-in-attacks-on-governments/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4151379/malware-trojaner-viren/new-sparrowocky-backdoor-deployed-in-attacks-on-governments/</guid>
<pubDate>Thu, 17 Sep 2026 11:31:01 +0200</pubDate>
<content:encoded><![CDATA[<p>The China-aligned FamousSparrow cyberespionage group has begun deploying a new modular backdoor named SparroWocky in attacks focused heavily on Latin America. The malware provides extensive remote-control capabilities while using low-level Windows manipulation and anti-analysis techniques to evade security tools. ESET researchers discovered... <a href="https://cyberinsider.com/new-sparrowocky-backdoor-deployed-in-attacks-on-governments/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[100,000+ WordPress sites infected via Brevo supply chain attack]]></title>
<description><![CDATA[A breach affecting Brevo infrastructure has pushed malicious JavaScript to more than 100,000 websites through Brevo-hosted widgets and scripts. According to a report from the Sansec Forensics Team, attackers modified Brevo resources on September 14 to deliver malware that attempted to install a m...]]></description>
<link>https://tsecurity.de/de/4151378/malware-trojaner-viren/100000-wordpress-sites-infected-via-brevo-supply-chain-attack/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4151378/malware-trojaner-viren/100000-wordpress-sites-infected-via-brevo-supply-chain-attack/</guid>
<pubDate>Thu, 17 Sep 2026 11:31:01 +0200</pubDate>
<content:encoded><![CDATA[<p>A breach affecting Brevo infrastructure has pushed malicious JavaScript to more than 100,000 websites through Brevo-hosted widgets and scripts. According to a report from the Sansec Forensics Team, attackers modified Brevo resources on September 14 to deliver malware that attempted to install a malicious WordPress plugin when logged-in... <a href="https://cyberinsider.com/100000-wordpress-sites-infected-via-brevo-supply-chain-attack/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Chinese hackers use SparroWocky malware in govt espionage attacks]]></title>
<description><![CDATA[The China-linked espionage group FamousSparrow has been using a new backdoor named SparroWocky in attacks on government organizations in Latin America. [...] Weiterlesen]]></description>
<link>https://tsecurity.de/de/4151353/malware-trojaner-viren/chinese-hackers-use-sparrowocky-malware-in-govt-espionage-attacks/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4151353/malware-trojaner-viren/chinese-hackers-use-sparrowocky-malware-in-govt-espionage-attacks/</guid>
<pubDate>Thu, 17 Sep 2026 11:26:17 +0200</pubDate>
<content:encoded><![CDATA[<p>The China-linked espionage group FamousSparrow has been using a new backdoor named SparroWocky in attacks on government organizations in Latin America. [...] <a href="https://www.bleepingcomputer.com/news/security/chinese-hackers-use-sparrowocky-malware-in-govt-espionage-attacks/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Malicious npm package found in Antfarm Tech proof_of_dev coding assignment]]></title>
<description><![CDATA[submitted by /u/Top_Director3322 [link] [comments] Weiterlesen]]></description>
<link>https://tsecurity.de/de/4151266/malware-trojaner-viren/malicious-npm-package-found-in-antfarm-tech-proofofdev-coding-assignment/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4151266/malware-trojaner-viren/malicious-npm-package-found-in-antfarm-tech-proofofdev-coding-assignment/</guid>
<pubDate>Thu, 17 Sep 2026 11:15:26 +0200</pubDate>
<content:encoded><![CDATA[<p>submitted by /u/Top_Director3322 [link] [comments] <a href="https://www.reddit.com/r/MalwareAnalysis/comments/1wiotrs/malicious_npm_package_found_in_antfarm_tech_proof/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[How MSSPs Can Prove Their Value When “Nothing Happened”]]></title>
<description><![CDATA[For an MSSP, a quiet month can be a good month. No ransomware outbreak. No major account compromise. No business disruption. But it can also create an awkward conversation with the client: What exactly did we pay for this month? The problem is not that the SOC did nothing. Quite the opposite. Ana...]]></description>
<link>https://tsecurity.de/de/4151249/malware-trojaner-viren/how-mssps-can-prove-their-value-when-nothing-happened/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4151249/malware-trojaner-viren/how-mssps-can-prove-their-value-when-nothing-happened/</guid>
<pubDate>Thu, 17 Sep 2026 10:26:53 +0200</pubDate>
<content:encoded><![CDATA[<p>For an MSSP, a quiet month can be a good month. No ransomware outbreak. No major account compromise. No business disruption. But it can also create an awkward conversation with the client: What exactly did we pay for this month? The problem is not that the SOC did nothing. Quite the opposite. Analysts may have investigated hundreds of suspicious... <a href="https://any.run/cybersecurity-blog/how-mssps-prove-value/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[RatHat Abuses Android Wireless Debugging to Gain Shell Access and Steal Banking PINs]]></title>
<description><![CDATA[RatHat, a newly identified Android banking malware family that combines Accessibility abuse, local Android Debug Bridge (ADB) pairing, native shell-level components, and generative-AI-assisted interface automation. The operation appears linked to China-based threat actors and is primarily designe...]]></description>
<link>https://tsecurity.de/de/4151247/malware-trojaner-viren/rathat-abuses-android-wireless-debugging-to-gain-shell-access-and-steal-banking-pins/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4151247/malware-trojaner-viren/rathat-abuses-android-wireless-debugging-to-gain-shell-access-and-steal-banking-pins/</guid>
<pubDate>Thu, 17 Sep 2026 10:26:17 +0200</pubDate>
<content:encoded><![CDATA[<p>RatHat, a newly identified Android banking malware family that combines Accessibility abuse, local Android Debug Bridge (ADB) pairing, native shell-level components, and generative-AI-assisted interface automation. The operation appears linked to China-based threat actors and is primarily designed to steal banking credentials, payment PINs,... <a href="https://gbhackers.com/rathat-malware-attack/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Chosen Brick, Iran’s Surveillance Malware]]></title>
<description><![CDATA[UK, US, and Dutch agencies expose Chosen Brick, Iranian malware used to track and harass dissidents, journalists, and activists via Telegram. The UK, the US, and the Netherlands published a joint advisory warning about a Windows malware family, dubbed Chosen Brick, that Iran’s intelligence servic...]]></description>
<link>https://tsecurity.de/de/4151242/malware-trojaner-viren/chosen-brick-irans-surveillance-malware/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4151242/malware-trojaner-viren/chosen-brick-irans-surveillance-malware/</guid>
<pubDate>Thu, 17 Sep 2026 10:23:57 +0200</pubDate>
<content:encoded><![CDATA[<p>UK, US, and Dutch agencies expose Chosen Brick, Iranian malware used to track and harass dissidents, journalists, and activists via Telegram. The UK, the US, and the Netherlands published a joint advisory warning about a Windows malware family, dubbed Chosen Brick, that Iran’s intelligence services use to track down dissidents, journalists, and... <a href="https://securityaffairs.com/199217/malware/chosen-brick-irans-surveillance-malware.html" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Fake AI trading agent steals crypto wallet passwords]]></title>
<description><![CDATA[Attackers built a website for a fake AI crypto trading agent and used it to install Needle Stealer, malware that replaces a victim’s browser wallet with a copy that sends the wallet password to the attacker. HP caught the campaign between April and June 2026. The Needle campaign targets people wh...]]></description>
<link>https://tsecurity.de/de/4151241/malware-trojaner-viren/fake-ai-trading-agent-steals-crypto-wallet-passwords/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4151241/malware-trojaner-viren/fake-ai-trading-agent-steals-crypto-wallet-passwords/</guid>
<pubDate>Thu, 17 Sep 2026 10:23:52 +0200</pubDate>
<content:encoded><![CDATA[<p>Attackers built a website for a fake AI crypto trading agent and used it to install Needle Stealer, malware that replaces a victim’s browser wallet with a copy that sends the wallet password to the attacker. HP caught the campaign between April and June 2026. The Needle campaign targets people who download AI agents from search results or ads, and... <a href="https://www.helpnetsecurity.com/2026/09/17/fake-ai-trading-agent-research/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[New RatHat Android Malware Uses AI and ADB to Steal Banking Credentials and OTPs]]></title>
<description><![CDATA[The malware uses artificial intelligence, Accessibility Service abuse, and Android Debug Bridge (ADB) pairing to steal banking credentials, payment PINs, one-time passwords, and lock-screen data. RatHat is spread through smishing messages, malicious advertisements, phishing websites, and third-pa...]]></description>
<link>https://tsecurity.de/de/4151183/malware-trojaner-viren/new-rathat-android-malware-uses-ai-and-adb-to-steal-banking-credentials-and-otps/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4151183/malware-trojaner-viren/new-rathat-android-malware-uses-ai-and-adb-to-steal-banking-credentials-and-otps/</guid>
<pubDate>Thu, 17 Sep 2026 09:57:43 +0200</pubDate>
<content:encoded><![CDATA[<p>The malware uses artificial intelligence, Accessibility Service abuse, and Android Debug Bridge (ADB) pairing to steal banking credentials, payment PINs, one-time passwords, and lock-screen data. RatHat is spread through smishing messages, malicious advertisements, phishing websites, and third-party download portals. Victims are lured into... <a href="https://cyberpress.org/rathat-steals-banking-otps/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[PhantomEnigma Shifts Tactics: Explorer-Based Payload Delivery]]></title>
<description><![CDATA[submitted by /u/ANYRUN-team [link] [comments] Weiterlesen]]></description>
<link>https://tsecurity.de/de/4150904/malware-trojaner-viren/phantomenigma-shifts-tactics-explorer-based-payload-delivery/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4150904/malware-trojaner-viren/phantomenigma-shifts-tactics-explorer-based-payload-delivery/</guid>
<pubDate>Thu, 17 Sep 2026 07:45:12 +0200</pubDate>
<content:encoded><![CDATA[<p>submitted by /u/ANYRUN-team [link] [comments] <a href="https://www.reddit.com/r/MalwareAnalysis/comments/1wiklrz/phantomenigma_shifts_tactics_explorerbased/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Built a PPL-aware ALPC enumerator because standard handle duplication was leaving blind spots in the attack surface]]></title>
<description><![CDATA[Was doing some Windows ALPC/RPC vuln research and ran into a simple problem: the usual userland enumeration approach skips ports when handle duplication fails, which gets especially interesting with PPL processes. So I built this to dynamically resolve the ALPC object type index, fall back to NtQ...]]></description>
<link>https://tsecurity.de/de/4150903/malware-trojaner-viren/built-a-ppl-aware-alpc-enumerator-because-standard-handle-duplication-was-leaving-blind-spots-in-the-attack-surface/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4150903/malware-trojaner-viren/built-a-ppl-aware-alpc-enumerator-because-standard-handle-duplication-was-leaving-blind-spots-in-the-attack-surface/</guid>
<pubDate>Thu, 17 Sep 2026 07:15:08 +0200</pubDate>
<content:encoded><![CDATA[<p>Was doing some Windows ALPC/RPC vuln research and ran into a simple problem: the usual userland enumeration approach skips ports when handle duplication fails, which gets especially interesting with PPL processes. So I built this to dynamically resolve the ALPC object type index, fall back to NtQueryInformationProcess / PS_PROTECTION when... <a href="https://www.reddit.com/r/ExploitDev/comments/1wgwqhh/built_a_pplaware_alpc_enumerator_because_standard/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[SindriKit V2.0.0 (C framework to decouple technique logic from execution mechanics)]]></title>
<description><![CDATA[Released V2 for my opensource maldev tool/framework. Feel free to check out the code and implementation. Would really appreciate feedback :) submitted by /u/Important_Map6928 [link] [comments] Weiterlesen]]></description>
<link>https://tsecurity.de/de/4150902/malware-trojaner-viren/sindrikit-v200-c-framework-to-decouple-technique-logic-from-execution-mechanics/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4150902/malware-trojaner-viren/sindrikit-v200-c-framework-to-decouple-technique-logic-from-execution-mechanics/</guid>
<pubDate>Thu, 17 Sep 2026 07:15:08 +0200</pubDate>
<content:encoded><![CDATA[<p>Released V2 for my opensource maldev tool/framework. Feel free to check out the code and implementation. Would really appreciate feedback :) submitted by /u/Important_Map6928 [link] [comments] <a href="https://www.reddit.com/r/ExploitDev/comments/1wh4408/sindrikit_v200_c_framework_to_decouple_technique/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Looking for dedicated beginner ctf buddies]]></title>
<description><![CDATA[submitted by /u/Fit-Iron-5614 [link] [comments] Weiterlesen]]></description>
<link>https://tsecurity.de/de/4150900/malware-trojaner-viren/looking-for-dedicated-beginner-ctf-buddies/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4150900/malware-trojaner-viren/looking-for-dedicated-beginner-ctf-buddies/</guid>
<pubDate>Thu, 17 Sep 2026 07:15:08 +0200</pubDate>
<content:encoded><![CDATA[<p>submitted by /u/Fit-Iron-5614 [link] [comments] <a href="https://www.reddit.com/r/ExploitDev/comments/1wh9kfl/looking_for_dedicated_beginner_ctf_buddies/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[0xCr0ssCrush - Windows BYOVD Ring 0 Exploit]]></title>
<description><![CDATA[submitted by /u/Anonymous_Wajeeh [link] [comments] Weiterlesen]]></description>
<link>https://tsecurity.de/de/4150898/malware-trojaner-viren/0xcr0sscrush-windows-byovd-ring-0-exploit/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4150898/malware-trojaner-viren/0xcr0sscrush-windows-byovd-ring-0-exploit/</guid>
<pubDate>Thu, 17 Sep 2026 07:15:08 +0200</pubDate>
<content:encoded><![CDATA[<p>submitted by /u/Anonymous_Wajeeh [link] [comments] <a href="https://www.reddit.com/r/ExploitDev/comments/1whgqab/0xcr0sscrush_windows_byovd_ring_0_exploit/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Centralizing scanner findings across multiple tools. anyone actually happy with their setup?]]></title>
<description><![CDATA[So vuln team here, drowning in findings from like ten scanners and ticket queues all over the place, trying to centralize everything into one risk based view without breaking existing workflows. any hints? submitted by /u/NetLopsdedslsatn3708 [link] [comments] Weiterlesen]]></description>
<link>https://tsecurity.de/de/4150897/malware-trojaner-viren/centralizing-scanner-findings-across-multiple-tools-anyone-actually-happy-with-their-setup/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4150897/malware-trojaner-viren/centralizing-scanner-findings-across-multiple-tools-anyone-actually-happy-with-their-setup/</guid>
<pubDate>Thu, 17 Sep 2026 07:15:08 +0200</pubDate>
<content:encoded><![CDATA[<p>So vuln team here, drowning in findings from like ten scanners and ticket queues all over the place, trying to centralize everything into one risk based view without breaking existing workflows. any hints? submitted by /u/NetLopsdedslsatn3708 [link] [comments] <a href="https://www.reddit.com/r/ExploitDev/comments/1whpr8k/centralizing_scanner_findings_across_multiple/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[I Missed One TLB Shootdown and Somehow Ended Up Controlling a Page Table]]></title>
<description><![CDATA[submitted by /u/unknownhad [link] [comments] Weiterlesen]]></description>
<link>https://tsecurity.de/de/4150896/malware-trojaner-viren/i-missed-one-tlb-shootdown-and-somehow-ended-up-controlling-a-page-table/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4150896/malware-trojaner-viren/i-missed-one-tlb-shootdown-and-somehow-ended-up-controlling-a-page-table/</guid>
<pubDate>Thu, 17 Sep 2026 07:15:08 +0200</pubDate>
<content:encoded><![CDATA[<p>submitted by /u/unknownhad [link] [comments] <a href="https://www.reddit.com/r/ExploitDev/comments/1why5u9/i_missed_one_tlb_shootdown_and_somehow_ended_up/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Warum sichere Datenspeicherung für den Mittelstand essenziell ist - it-daily.net]]></title>
<description><![CDATA[Exponentielles Datenwachstum, die Bedrohung durch zielgerichtete Ransomware-Angriffe und immer strengere Compliance-Vorgaben setzen IT-Abteilungen im ... Weiterlesen]]></description>
<link>https://tsecurity.de/de/4150668/malware-trojaner-viren/warum-sichere-datenspeicherung-fuer-den-mittelstand-essenziell-ist-it-dailynet/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4150668/malware-trojaner-viren/warum-sichere-datenspeicherung-fuer-den-mittelstand-essenziell-ist-it-dailynet/</guid>
<pubDate>Thu, 17 Sep 2026 03:34:58 +0200</pubDate>
<content:encoded><![CDATA[<p>Exponentielles Datenwachstum, die Bedrohung durch zielgerichtete Ransomware-Angriffe und immer strengere Compliance-Vorgaben setzen IT-Abteilungen im ... <a href="https://www.google.com/url?rct=j&amp;sa=t&amp;url=https://www.it-daily.net/it-sicherheit/cloud-security/mittelstand-datenspeicherung&amp;ct=ga&amp;cd=CAIyGTRiZTZmY2RmMzZhYjA0M2Y6ZGU6ZGU6REU&amp;usg=AOvVaw2ILWMzGapm7sNaZ7h2kCK8" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[How the mighty have fallen — the notorious Stuxnet malware source code has been replicated and posted on GitHub for all to see]]></title>
<description><![CDATA[A pseudonymous GitHub account has published what it calls a reconstruction of Stuxnet malware that purportedly took out a fifth of Iran's centrifuges before being discoveredThe original source has never surfaced, and the 'Stuxnet' moniker that the account uses comes from Symantec's coining of the...]]></description>
<link>https://tsecurity.de/de/4150509/malware-trojaner-viren/how-the-mighty-have-fallen-the-notorious-stuxnet-malware-source-code-has-been-replicated-and-posted-on-github-for-all-to-see/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4150509/malware-trojaner-viren/how-the-mighty-have-fallen-the-notorious-stuxnet-malware-source-code-has-been-replicated-and-posted-on-github-for-all-to-see/</guid>
<pubDate>Thu, 17 Sep 2026 01:37:12 +0200</pubDate>
<content:encoded><![CDATA[<p>A pseudonymous GitHub account has published what it calls a reconstruction of Stuxnet malware that purportedly took out a fifth of Iran&#039;s centrifuges before being discoveredThe original source has never surfaced, and the &#039;Stuxnet&#039; moniker that the account uses comes from Symantec&#039;s coining of the name weeks after it was discoveredThe code remains... <a href="https://www.techradar.com/pro/security/how-the-mighty-have-fallen-the-notorious-stuxnet-malware-source-code-has-been-replicated-and-posted-on-github-for-all-to-see" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[IT Security News Daily Summary 2026-09-16]]></title>
<description><![CDATA[200 posts published today 21:31Revolut gave customer IDs and financial data to a government impostor 21:31Architecting a secure landing zone in the AWS European Sovereign Cloud 21:31Prophet Security research finds AI is cutting SOC investigation times, but nearly half of in-house builds fail to s...]]></description>
<link>https://tsecurity.de/de/4150444/malware-trojaner-viren/it-security-news-daily-summary-2026-09-16/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4150444/malware-trojaner-viren/it-security-news-daily-summary-2026-09-16/</guid>
<pubDate>Thu, 17 Sep 2026 00:11:39 +0200</pubDate>
<content:encoded><![CDATA[<p>200 posts published today 21:31Revolut gave customer IDs and financial data to a government impostor 21:31Architecting a secure landing zone in the AWS European Sovereign Cloud 21:31Prophet Security research finds AI is cutting SOC investigation times, but nearly half of in-house builds fail to stick 21:02LNK Metadata 21:02BambooToken: The Malware... <a href="https://www.itsecuritynews.info/it-security-news-daily-summary-2026-09-16/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Cybercrime finds its sea legs.]]></title>
<description><![CDATA[Officials investigate suspected cyberattacks on U.S.-bound oil tankers. Iranian operators deploy Chosen Brick surveillance malware. Ukraine cracks down on scam call centers. Researchers uncover two TP-Link camera zero-days. Maria Varmazis looks at weapons in space. CenterPoint Energy reports a da...]]></description>
<link>https://tsecurity.de/de/4150355/malware-trojaner-viren/cybercrime-finds-its-sea-legs/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4150355/malware-trojaner-viren/cybercrime-finds-its-sea-legs/</guid>
<pubDate>Wed, 16 Sep 2026 23:43:05 +0200</pubDate>
<content:encoded><![CDATA[<p>Officials investigate suspected cyberattacks on U.S.-bound oil tankers. Iranian operators deploy Chosen Brick surveillance malware. Ukraine cracks down on scam call centers. Researchers uncover two TP-Link camera zero-days. Maria Varmazis looks at weapons in space. CenterPoint Energy reports a data breach. Spain records its first breach caused by... <a href="https://thecyberwire.com/podcasts/daily-podcast/2637/notes" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[BambooToken: The Malware That Speaks MQTT to Stay Under the Radar]]></title>
<description><![CDATA[Lumen exposes BambooToken, a stealthy malware family using MQTT and sideloading to quietly infect targets across Asia and beyond. BambooToken is a new malware family that uses MQTT, a lightweight messaging protocol commonly found in smart devices and industrial systems, to quietly control infecte...]]></description>
<link>https://tsecurity.de/de/4150344/malware-trojaner-viren/bambootoken-the-malware-that-speaks-mqtt-to-stay-under-the-radar/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4150344/malware-trojaner-viren/bambootoken-the-malware-that-speaks-mqtt-to-stay-under-the-radar/</guid>
<pubDate>Wed, 16 Sep 2026 23:40:37 +0200</pubDate>
<content:encoded><![CDATA[<p>Lumen exposes BambooToken, a stealthy malware family using MQTT and sideloading to quietly infect targets across Asia and beyond. BambooToken is a new malware family that uses MQTT, a lightweight messaging protocol commonly found in smart devices and industrial systems, to quietly control infected Windows and Linux machines. Most malware connects... <a href="https://securityaffairs.com/199205/malware/bambootoken-the-malware-that-speaks-mqtt-to-stay-under-the-radar.html" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Google removed today 15 malicious chrome extensions]]></title>
<description><![CDATA[I track Chrome Web Store removals and today's pass picked up 15 extensions pulled with a malware classification, not the usual policy or spam category. https://malext.io/?reason=Malware&amp;day=2026-09-16 Important thing is that removal from the google store does not remove the extension from bro...]]></description>
<link>https://tsecurity.de/de/4150336/malware-trojaner-viren/google-removed-today-15-malicious-chrome-extensions/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4150336/malware-trojaner-viren/google-removed-today-15-malicious-chrome-extensions/</guid>
<pubDate>Wed, 16 Sep 2026 23:39:19 +0200</pubDate>
<content:encoded><![CDATA[<p>I track Chrome Web Store removals and today&#039;s pass picked up 15 extensions pulled with a malware classification, not the usual policy or spam category. https://malext.io/?reason=Malware&amp;amp;day=2026-09-16 Important thing is that removal from the google store does not remove the extension from browsers that already have it. Unless Google pushes it... <a href="https://www.reddit.com/r/security/comments/1wi8mky/google_removed_today_15_malicious_chrome/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Iranian hackers use CHOSEN BRICK Windows malware to spy on targets]]></title>
<description><![CDATA[Government agencies are warning that Iranian state-linked hackers are using a Windows malware strain named CHOSEN BRICK to target dissidents, activists, and journalists worldwide. [...] Weiterlesen]]></description>
<link>https://tsecurity.de/de/4150335/malware-trojaner-viren/iranian-hackers-use-chosen-brick-windows-malware-to-spy-on-targets/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4150335/malware-trojaner-viren/iranian-hackers-use-chosen-brick-windows-malware-to-spy-on-targets/</guid>
<pubDate>Wed, 16 Sep 2026 23:39:18 +0200</pubDate>
<content:encoded><![CDATA[<p>Government agencies are warning that Iranian state-linked hackers are using a Windows malware strain named CHOSEN BRICK to target dissidents, activists, and journalists worldwide. [...] <a href="https://www.bleepingcomputer.com/news/security/iranian-hackers-use-chosen-brick-windows-malware-to-spy-on-targets/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Malware bypasses browser checks to force install Chrome, Edge extensions]]></title>
<description><![CDATA[A banking malware operation active since mid-2025 has been using a toolkit named KREMLIN to install malicious Chrome and Edge extensions that steal credentials, session tokens, and sensitive data. [...] Weiterlesen]]></description>
<link>https://tsecurity.de/de/4150209/malware-trojaner-viren/malware-bypasses-browser-checks-to-force-install-chrome-edge-extensions/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4150209/malware-trojaner-viren/malware-bypasses-browser-checks-to-force-install-chrome-edge-extensions/</guid>
<pubDate>Wed, 16 Sep 2026 21:10:23 +0200</pubDate>
<content:encoded><![CDATA[<p>A banking malware operation active since mid-2025 has been using a toolkit named KREMLIN to install malicious Chrome and Edge extensions that steal credentials, session tokens, and sensitive data. [...] <a href="https://www.bleepingcomputer.com/news/security/malware-bypasses-browser-checks-to-force-install-chrome-edge-extensions/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Drei Threat-Gruppen treffen russische Unternehmen: Backdoors, Ransomware & Wiper]]></title>
<description><![CDATA[LONDON (IT BOLTWISE) – Drei getrennt verfolgte Bedrohungscluster zielen laut einem Bericht auf russische Unternehmensumgebungen. NightEagle nutzt kompromittierte VPN-Zugänge und verschaltet sich anschließend in Microsoft Exchange und Active Directory. Hacking Cat wechselt von reinen Angriffen auf...]]></description>
<link>https://tsecurity.de/de/4150115/malware-trojaner-viren/drei-threat-gruppen-treffen-russische-unternehmen-backdoors-ransomware-wiper/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4150115/malware-trojaner-viren/drei-threat-gruppen-treffen-russische-unternehmen-backdoors-ransomware-wiper/</guid>
<pubDate>Wed, 16 Sep 2026 20:47:08 +0200</pubDate>
<content:encoded><![CDATA[<p>LONDON (IT BOLTWISE) – Drei getrennt verfolgte Bedrohungscluster zielen laut einem Bericht auf russische Unternehmensumgebungen. NightEagle nutzt kompromittierte VPN-Zugänge und verschaltet sich anschließend in Microsoft Exchange und Active Directory. Hacking Cat wechselt von reinen Angriffen auf Verschlüsselung und zerstörerische Payloads,... <a href="https://www.it-boltwise.de/drei-threat-gruppen-treffen-russische-unternehmen-backdoors-ransomware-wiper.html" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Iran snoops on enemies of the state with Chosen Brick malware controlled using messaging apps]]></title>
<description><![CDATA[UK NCSC, FBI, and Dutch AIVD warn Iran is using Chosen Brick malware against dissidents and journalistsMalware steals files, captures audio, grabs WhatsApp/Telegram data, and can wipe systems entirelyOperatives rely on social engineering; agencies urge awareness, MFA, updates, and endpoint monito...]]></description>
<link>https://tsecurity.de/de/4150064/malware-trojaner-viren/iran-snoops-on-enemies-of-the-state-with-chosen-brick-malware-controlled-using-messaging-apps/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4150064/malware-trojaner-viren/iran-snoops-on-enemies-of-the-state-with-chosen-brick-malware-controlled-using-messaging-apps/</guid>
<pubDate>Wed, 16 Sep 2026 20:42:15 +0200</pubDate>
<content:encoded><![CDATA[<p>UK NCSC, FBI, and Dutch AIVD warn Iran is using Chosen Brick malware against dissidents and journalistsMalware steals files, captures audio, grabs WhatsApp/Telegram data, and can wipe systems entirelyOperatives rely on social engineering; agencies urge awareness, MFA, updates, and endpoint monitoringIranian hackers are targeting “enemies of the... <a href="https://www.techradar.com/pro/security/iran-snoops-on-enemies-of-the-state-with-chosen-brick-malware-controlled-using-messaging-apps" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Mehr als nur Antivirus: So hilft Norton gegen Phishing, Betrugsmaschen und gefährliche Downloads]]></title>
<description><![CDATA[Norton ist aktuell nur halb so teuer und schützt euch vor mehr als nur Viren. Für 1,67 Euro pro Monat bekommt ihr auch Schutz vor Phishing, Betrug und Ransomware. Dieser Artikel wurde einsortiert unter Internet &amp; Netzwelt, Schnäppchen, In eigener Sache, Antivirussoftware: Optimaler Virenschut...]]></description>
<link>https://tsecurity.de/de/4150018/malware-trojaner-viren/mehr-als-nur-antivirus-so-hilft-norton-gegen-phishing-betrugsmaschen-und-gefaehrliche-downloads/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4150018/malware-trojaner-viren/mehr-als-nur-antivirus-so-hilft-norton-gegen-phishing-betrugsmaschen-und-gefaehrliche-downloads/</guid>
<pubDate>Wed, 16 Sep 2026 20:41:06 +0200</pubDate>
<content:encoded><![CDATA[<p>Norton ist aktuell nur halb so teuer und schützt euch vor mehr als nur Viren. Für 1,67 Euro pro Monat bekommt ihr auch Schutz vor Phishing, Betrug und Ransomware. Dieser Artikel wurde einsortiert unter Internet &amp;amp; Netzwelt, Schnäppchen, In eigener Sache, Antivirussoftware: Optimaler Virenschutz für PC, Smartphone und Tablet, Sponsored Post -... <a href="https://www.netzwelt.de/schnaeppchen/258509-mehr-nur-antivirus-so-hilft-norton-gegen-phishing-betrugsmaschen-gefaehrliche-downloads.html" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[[iOS] Analyzing anomalous cpu_resource / diskwrites_resource reports on a stock TikTok process: unnamed UUID-only binaries in Binary Images]]></title>
<description><![CDATA[Context: iPhone 15 Pro Max, current iOS, no jailbreak, no sideloading, no configuration profiles, app reinstalled cleanly. All observations reproducible across WiFi / 4G / 5G. I've been analyzing iOS analytics ( .ips ) incident reports on a specific app process and found a pattern I'd like to com...]]></description>
<link>https://tsecurity.de/de/4149957/malware-trojaner-viren/ios-analyzing-anomalous-cpuresource-diskwritesresource-reports-on-a-stock-tiktok-process-unnamed-uuid-only-binaries-in-binary-images/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4149957/malware-trojaner-viren/ios-analyzing-anomalous-cpuresource-diskwritesresource-reports-on-a-stock-tiktok-process-unnamed-uuid-only-binaries-in-binary-images/</guid>
<pubDate>Wed, 16 Sep 2026 20:30:32 +0200</pubDate>
<content:encoded><![CDATA[<p>Context: iPhone 15 Pro Max, current iOS, no jailbreak, no sideloading, no configuration profiles, app reinstalled cleanly. All observations reproducible across WiFi / 4G / 5G. I&#039;ve been analyzing iOS analytics ( .ips ) incident reports on a specific app process and found a pattern I&#039;d like to compare against what this community typically sees in... <a href="https://www.reddit.com/r/MalwareAnalysis/comments/1wi4sp5/ios_analyzing_anomalous_cpu_resource_diskwrites/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Hackers Can Rent VectraRAT for $250 a Month to Take Control of Windows PCs]]></title>
<description><![CDATA[Hackers can now rent a Windows-focused remote access tool called VectraRAT for $250 a month, lowering the barrier to deep and persistent compromise. The malware gives paying operators a way to watch victims, steal data, run commands, and move traffic through an infected computer. VectraRAT has su...]]></description>
<link>https://tsecurity.de/de/4149834/malware-trojaner-viren/hackers-can-rent-vectrarat-for-250-a-month-to-take-control-of-windows-pcs/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4149834/malware-trojaner-viren/hackers-can-rent-vectrarat-for-250-a-month-to-take-control-of-windows-pcs/</guid>
<pubDate>Wed, 16 Sep 2026 18:46:47 +0200</pubDate>
<content:encoded><![CDATA[<p>Hackers can now rent a Windows-focused remote access tool called VectraRAT for $250 a month, lowering the barrier to deep and persistent compromise. The malware gives paying operators a way to watch victims, steal data, run commands, and move traffic through an infected computer. VectraRAT has surfaced as a rental-only malware service rather than... <a href="https://cybersecuritynews.com/hackers-can-rent-vectrarat/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Hackers Use Cross-Platform Noodle RAT to Secretly Control Windows and Linux Systems]]></title>
<description><![CDATA[Noodle RAT is a remote-access trojan that gives attackers control of compromised computers and servers. Its renewed visibility matters because it runs on both Windows and Linux, allowing one malware family to follow victims across corporate networks. The tool has appeared in operations against or...]]></description>
<link>https://tsecurity.de/de/4149811/malware-trojaner-viren/hackers-use-cross-platform-noodle-rat-to-secretly-control-windows-and-linux-systems/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4149811/malware-trojaner-viren/hackers-use-cross-platform-noodle-rat-to-secretly-control-windows-and-linux-systems/</guid>
<pubDate>Wed, 16 Sep 2026 18:46:15 +0200</pubDate>
<content:encoded><![CDATA[<p>Noodle RAT is a remote-access trojan that gives attackers control of compromised computers and servers. Its renewed visibility matters because it runs on both Windows and Linux, allowing one malware family to follow victims across corporate networks. The tool has appeared in operations against organisations across Asia-Pacific, including Thailand,... <a href="https://cybersecuritynews.com/cross-platform-noodle-rat/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[The true cost of a ransomware attack, with and without BCDR]]></title>
<description><![CDATA[The ransom itself can be only a fraction of the total cost of a ransomware attack, with downtime, recovery, remediation, and legal obligations adding millions to the bill. Datto explains how a mature BCDR strategy can reduce downtime and provide a faster, more predictable path to recovery. [...] ...]]></description>
<link>https://tsecurity.de/de/4149787/malware-trojaner-viren/the-true-cost-of-a-ransomware-attack-with-and-without-bcdr/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4149787/malware-trojaner-viren/the-true-cost-of-a-ransomware-attack-with-and-without-bcdr/</guid>
<pubDate>Wed, 16 Sep 2026 18:42:14 +0200</pubDate>
<content:encoded><![CDATA[<p>The ransom itself can be only a fraction of the total cost of a ransomware attack, with downtime, recovery, remediation, and legal obligations adding millions to the bill. Datto explains how a mature BCDR strategy can reduce downtime and provide a faster, more predictable path to recovery. [...] <a href="https://www.bleepingcomputer.com/news/security/the-true-cost-of-a-ransomware-attack-with-and-without-bcdr/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Three Threat Groups Target Russian Enterprises With Backdoors, Ransomware, and Wipers]]></title>
<description><![CDATA[Enterprises in Russia have emerged as the target of three threat activity clusters tracked as NightEagle, Hacking Cat, and Toy Ghouls, according to multiple reports from Kaspersky. The cybersecurity vendor said it has identified attacks mounted by NightEagle (aka APT-Q-95), a threat actor known t...]]></description>
<link>https://tsecurity.de/de/4149765/malware-trojaner-viren/three-threat-groups-target-russian-enterprises-with-backdoors-ransomware-and-wipers/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4149765/malware-trojaner-viren/three-threat-groups-target-russian-enterprises-with-backdoors-ransomware-and-wipers/</guid>
<pubDate>Wed, 16 Sep 2026 18:41:26 +0200</pubDate>
<content:encoded><![CDATA[<p>Enterprises in Russia have emerged as the target of three threat activity clusters tracked as NightEagle, Hacking Cat, and Toy Ghouls, according to multiple reports from Kaspersky. The cybersecurity vendor said it has identified attacks mounted by NightEagle (aka APT-Q-95), a threat actor known to be active since at least 2023, that involve new... <a href="https://thehackernews.com/2026/09/three-threat-groups-target-russian.html" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Serbien: Oppositionelle stehen im Visier von Überwachungssoftware]]></title>
<description><![CDATA[IT-Forensik-Fachleute haben in mehreren Fällen den gezielten Einsatz von Spyware gegen Bürger:innen in Serbien festgestellt. Das ist nicht das erste Mal, dass Regierungskritiker:innen und Oppositionelle des Balkanstaats ins Visier geraten. Kurz vor den Neuwahlen wurden Infektionen mit Trojanern b...]]></description>
<link>https://tsecurity.de/de/4149611/malware-trojaner-viren/serbien-oppositionelle-stehen-im-visier-von-ueberwachungssoftware/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4149611/malware-trojaner-viren/serbien-oppositionelle-stehen-im-visier-von-ueberwachungssoftware/</guid>
<pubDate>Wed, 16 Sep 2026 18:39:27 +0200</pubDate>
<content:encoded><![CDATA[<p>IT-Forensik-Fachleute haben in mehreren Fällen den gezielten Einsatz von Spyware gegen Bürger:innen in Serbien festgestellt. Das ist nicht das erste Mal, dass Regierungskritiker:innen und Oppositionelle des Balkanstaats ins Visier geraten. Kurz vor den Neuwahlen wurden Infektionen mit Trojanern bekannt. – Alle Rechte vorbehalten: Trojanisches... <a href="https://netzpolitik.org/2026/serbien-oppositionelle-stehen-im-visier-von-ueberwachungssoftware/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Trellix Stinger Download - Spezielle Viren entfernen]]></title>
<description><![CDATA[Der Download von Trellix Stinger durchsucht Ihren PC nach Viren, Würmern sowie anderen Formen von Malware und entfernt diese vollständig und sicher. Trellix Stinger ist dabei als Ergänzung vorhandener ... (Weiter lesen) Weiterlesen]]></description>
<link>https://tsecurity.de/de/4149579/malware-trojaner-viren/trellix-stinger-download-spezielle-viren-entfernen/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4149579/malware-trojaner-viren/trellix-stinger-download-spezielle-viren-entfernen/</guid>
<pubDate>Wed, 16 Sep 2026 18:37:30 +0200</pubDate>
<content:encoded><![CDATA[<p>Der Download von Trellix Stinger durchsucht Ihren PC nach Viren, Würmern sowie anderen Formen von Malware und entfernt diese vollständig und sicher. Trellix Stinger ist dabei als Ergänzung vorhandener ... (Weiter lesen) <a href="https://winfuture.de/downloadvorschalt,817.html" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Streaminghub offline: Eigenwerbung führt BREIN zum Betreiber]]></title>
<description><![CDATA[Streaminghub offline: BREIN identifiziert Betreiber über dessen Eigenwerbung. Das illegale Angebot umfasste Filme, Serien, Live-TV und Sport Der Artikel Streaminghub offline: Eigenwerbung führt BREIN zum Betreiber erschien zuerst auf TARNKAPPE.INFO Weiterlesen]]></description>
<link>https://tsecurity.de/de/4149502/malware-trojaner-viren/streaminghub-offline-eigenwerbung-fuehrt-brein-zum-betreiber/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4149502/malware-trojaner-viren/streaminghub-offline-eigenwerbung-fuehrt-brein-zum-betreiber/</guid>
<pubDate>Wed, 16 Sep 2026 18:30:20 +0200</pubDate>
<content:encoded><![CDATA[<p>Streaminghub offline: BREIN identifiziert Betreiber über dessen Eigenwerbung. Das illegale Angebot umfasste Filme, Serien, Live-TV und Sport Der Artikel Streaminghub offline: Eigenwerbung führt BREIN zum Betreiber erschien zuerst auf TARNKAPPE.INFO <a href="https://tarnkappe.info/artikel/streaming/streaminghub-offline-brein-betreiber-eigenwerbung-333497.html" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Irdeto-Tochter Denuvo reicht Klage gegen voices38 ein]]></title>
<description><![CDATA[Die Irdeto-Tochter Denuvo reichte vor einem US-Bundesgericht Klage gegen den Cracker voices38 ein, der darauf aber sehr entspannt reagiert. Der Artikel Irdeto-Tochter Denuvo reicht Klage gegen voices38 ein erschien zuerst auf TARNKAPPE.INFO Weiterlesen]]></description>
<link>https://tsecurity.de/de/4149501/malware-trojaner-viren/irdeto-tochter-denuvo-reicht-klage-gegen-voices38-ein/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4149501/malware-trojaner-viren/irdeto-tochter-denuvo-reicht-klage-gegen-voices38-ein/</guid>
<pubDate>Wed, 16 Sep 2026 18:30:20 +0200</pubDate>
<content:encoded><![CDATA[<p>Die Irdeto-Tochter Denuvo reichte vor einem US-Bundesgericht Klage gegen den Cracker voices38 ein, der darauf aber sehr entspannt reagiert. Der Artikel Irdeto-Tochter Denuvo reicht Klage gegen voices38 ein erschien zuerst auf TARNKAPPE.INFO <a href="https://tarnkappe.info/artikel/denuvo/irdeto-tochter-denuvo-reicht-klage-gegen-voices38-ein-333498.html" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[HBO Max Reddit Account Hacked: 108 Malicious Ads Push ClickFix Malware]]></title>
<description><![CDATA[A verified HBO Max account looked like a safe place to encounter an ad. Attackers reportedly turned that credibility into a malware delivery system. Researchers at Hudson Rock found that attackers compromised HBO Max’s verified Reddit advertising account and used it to run 108 malicious ads over ...]]></description>
<link>https://tsecurity.de/de/4149482/malware-trojaner-viren/hbo-max-reddit-account-hacked-108-malicious-ads-push-clickfix-malware/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4149482/malware-trojaner-viren/hbo-max-reddit-account-hacked-108-malicious-ads-push-clickfix-malware/</guid>
<pubDate>Wed, 16 Sep 2026 15:43:28 +0200</pubDate>
<content:encoded><![CDATA[<p>A verified HBO Max account looked like a safe place to encounter an ad. Attackers reportedly turned that credibility into a malware delivery system. Researchers at Hudson Rock found that attackers compromised HBO Max’s verified Reddit advertising account and used it to run 108 malicious ads over roughly 48 hours. The ads sent users to... <a href="https://www.esecurityplanet.com/threats/news-hbo-max-reddit-clickfix-malware-ads/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[VectraRAT Malware-as-a-Service Lets Hackers Bypass UAC and Hijack Windows Systems]]></title>
<description><![CDATA[VectraRAT, a previously undocumented Malware-as-a-Service platform that combines remote-access trojan capabilities with automated credential theft and a silent Windows privilege-escalation chain. Unlike the large number of commodity RATs that recycle leaked AsyncRAT, XWorm, or QuasarRAT code, Vec...]]></description>
<link>https://tsecurity.de/de/4149278/malware-trojaner-viren/vectrarat-malware-as-a-service-lets-hackers-bypass-uac-and-hijack-windows-systems/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4149278/malware-trojaner-viren/vectrarat-malware-as-a-service-lets-hackers-bypass-uac-and-hijack-windows-systems/</guid>
<pubDate>Wed, 16 Sep 2026 15:16:07 +0200</pubDate>
<content:encoded><![CDATA[<p>VectraRAT, a previously undocumented Malware-as-a-Service platform that combines remote-access trojan capabilities with automated credential theft and a silent Windows privilege-escalation chain. Unlike the large number of commodity RATs that recycle leaked AsyncRAT, XWorm, or QuasarRAT code, VectraRAT appears to be a purpose-built, full-stack... <a href="https://gbhackers.com/vectrarat-malware-as-a-service/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[New VectraRAT MaaS Lets Hackers Bypass Windows UAC and Steal Browser Credentials]]></title>
<description><![CDATA[Threat researchers have uncovered a previously undocumented malware-as-a-service (MaaS) platform called VectraRAT, a full-stack toolkit that gives cybercriminals enterprise-grade intrusion capabilities for as little as $250 a month. Unlike most commodity RATs that fork leaked code from families l...]]></description>
<link>https://tsecurity.de/de/4149277/malware-trojaner-viren/new-vectrarat-maas-lets-hackers-bypass-windows-uac-and-steal-browser-credentials/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4149277/malware-trojaner-viren/new-vectrarat-maas-lets-hackers-bypass-windows-uac-and-steal-browser-credentials/</guid>
<pubDate>Wed, 16 Sep 2026 15:15:58 +0200</pubDate>
<content:encoded><![CDATA[<p>Threat researchers have uncovered a previously undocumented malware-as-a-service (MaaS) platform called VectraRAT, a full-stack toolkit that gives cybercriminals enterprise-grade intrusion capabilities for as little as $250 a month. Unlike most commodity RATs that fork leaked code from families like AsyncRAT or XWorm, VectraRAT was built entirely... <a href="https://cyberpress.org/vectrarat-maas-windows-uac/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[N0va-Phishing zielt auf Identitäten in Unternehmen – Attacke über legitime Authentifizierungsflows]]></title>
<description><![CDATA[LONDON (IT BOLTWISE) – Die Phishing-Kampagne „N0va“ nutzt täuschend echte Identitäts- und Authentifizierungsabläufe, um an gültige Konten und Tokens zu gelangen. Angreifer können so ohne auffällige Malware-Aktivität Zugriff aus laufenden Sitzungen verlängern und SSO-Mechanismen missbrauchen. Beso...]]></description>
<link>https://tsecurity.de/de/4149270/malware-trojaner-viren/n0va-phishing-zielt-auf-identitaeten-in-unternehmen-attacke-ueber-legitime-authentifizierungsflows/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4149270/malware-trojaner-viren/n0va-phishing-zielt-auf-identitaeten-in-unternehmen-attacke-ueber-legitime-authentifizierungsflows/</guid>
<pubDate>Wed, 16 Sep 2026 15:15:55 +0200</pubDate>
<content:encoded><![CDATA[<p>LONDON (IT BOLTWISE) – Die Phishing-Kampagne „N0va“ nutzt täuschend echte Identitäts- und Authentifizierungsabläufe, um an gültige Konten und Tokens zu gelangen. Angreifer können so ohne auffällige Malware-Aktivität Zugriff aus laufenden Sitzungen verlängern und SSO-Mechanismen missbrauchen. Besonders betroffen sind Unternehmen in Nordamerika und... <a href="https://www.it-boltwise.de/n0va-phishing-zielt-auf-identitaeten-in-unternehmen-attacke-ueber-legitime-authentifizierungsflows.html" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Chinese-Speaking Hackers Use Noodle RAT Backdoor to Spy on Windows and Linux Systems]]></title>
<description><![CDATA[Chinese-speaking threat actors are continuing to rely on Noodle RAT, a cross-platform remote access trojan designed to maintain covert access to compromised Windows workstations and Linux servers. Also tracked as ANGRYREBEL and Nood RAT, the malware has been active since at least mid-2016 but was...]]></description>
<link>https://tsecurity.de/de/4149259/malware-trojaner-viren/chinese-speaking-hackers-use-noodle-rat-backdoor-to-spy-on-windows-and-linux-systems/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4149259/malware-trojaner-viren/chinese-speaking-hackers-use-noodle-rat-backdoor-to-spy-on-windows-and-linux-systems/</guid>
<pubDate>Wed, 16 Sep 2026 15:15:48 +0200</pubDate>
<content:encoded><![CDATA[<p>Chinese-speaking threat actors are continuing to rely on Noodle RAT, a cross-platform remote access trojan designed to maintain covert access to compromised Windows workstations and Linux servers. Also tracked as ANGRYREBEL and Nood RAT, the malware has been active since at least mid-2016 but was long mistaken for variants of Gh0st RAT, Rekoobe,... <a href="https://www.itsecuritynews.info/chinese-speaking-hackers-use-noodle-rat-backdoor-to-spy-on-windows-and-linux-systems/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[IT Security News Hourly Summary 2026-09-16 15h : 15 posts]]></title>
<description><![CDATA[15 posts published in the last hour 12:31Major Cyber Vendors Turn to New UK Testing Program as MITRE Evaluations Face Changes 12:31Chinese-Speaking Hackers Use Noodle RAT Backdoor to Spy on Windows and Linux Systems 12:31US, UK, Dutch Agencies Expose Iranian ‘Chosen Brick’ Surveillance Malware 12...]]></description>
<link>https://tsecurity.de/de/4149257/malware-trojaner-viren/it-security-news-hourly-summary-2026-09-16-15h-15-posts/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4149257/malware-trojaner-viren/it-security-news-hourly-summary-2026-09-16-15h-15-posts/</guid>
<pubDate>Wed, 16 Sep 2026 15:15:48 +0200</pubDate>
<content:encoded><![CDATA[<p>15 posts published in the last hour 12:31Major Cyber Vendors Turn to New UK Testing Program as MITRE Evaluations Face Changes 12:31Chinese-Speaking Hackers Use Noodle RAT Backdoor to Spy on Windows and Linux Systems 12:31US, UK, Dutch Agencies Expose Iranian ‘Chosen Brick’ Surveillance Malware 12:02Smishing Triad Hackers Use JWR Phishing Kit to... <a href="https://www.itsecuritynews.info/it-security-news-hourly-summary-2026-09-16-15h-15-posts/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[US, UK, Dutch Agencies Expose Iranian ‘Chosen Brick’ Surveillance Malware]]></title>
<description><![CDATA[US, UK, and Dutch government agencies published a report detailing the malware, and the FBI described the abuse of Telegram for C&amp;C. The post US, UK, Dutch Agencies Expose Iranian ‘Chosen Brick’ Surveillance Malware appeared first on SecurityWeek. Weiterlesen]]></description>
<link>https://tsecurity.de/de/4149171/malware-trojaner-viren/us-uk-dutch-agencies-expose-iranian-chosen-brick-surveillance-malware/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4149171/malware-trojaner-viren/us-uk-dutch-agencies-expose-iranian-chosen-brick-surveillance-malware/</guid>
<pubDate>Wed, 16 Sep 2026 15:12:20 +0200</pubDate>
<content:encoded><![CDATA[<p>US, UK, and Dutch government agencies published a report detailing the malware, and the FBI described the abuse of Telegram for C&amp;amp;C. The post US, UK, Dutch Agencies Expose Iranian ‘Chosen Brick’ Surveillance Malware appeared first on SecurityWeek. <a href="https://www.securityweek.com/us-uk-dutch-agencies-expose-iranian-chosen-brick-surveillance-malware/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[N0va Phishkit Targets US and EU Businesses: A New Challenge for Identity Security]]></title>
<description><![CDATA[N0va is targeting organizations across North America and Europe with phishing campaigns that impersonate trusted services and abuse legitimate authentication flows. Successful attacks can give threat actors access to valid accounts without relying on obvious malware activity. From there, a single...]]></description>
<link>https://tsecurity.de/de/4149164/malware-trojaner-viren/n0va-phishkit-targets-us-and-eu-businesses-a-new-challenge-for-identity-security/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4149164/malware-trojaner-viren/n0va-phishkit-targets-us-and-eu-businesses-a-new-challenge-for-identity-security/</guid>
<pubDate>Wed, 16 Sep 2026 15:12:13 +0200</pubDate>
<content:encoded><![CDATA[<p>N0va is targeting organizations across North America and Europe with phishing campaigns that impersonate trusted services and abuse legitimate authentication flows. Successful attacks can give threat actors access to valid accounts without relying on obvious malware activity. From there, a single compromised identity can open the door to sensitive... <a href="https://thehackernews.com/2026/09/n0va-phishkit-targets-us-and-eu.html" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Chrome and Edge browsers hijacked by KREMLIN malware for credential and token session theft]]></title>
<description><![CDATA[Elastic Security Labs uncovered REF9334, a Brazilian banking malware campaign active since May 2025Malware “Kremlin” deploys fake docs and malicious Chrome/Edge extensions to steal banking data1,515 infections found, 98% in BrazilSecurity researchers from Elastic Security Labs have discovered a n...]]></description>
<link>https://tsecurity.de/de/4149138/malware-trojaner-viren/chrome-and-edge-browsers-hijacked-by-kremlin-malware-for-credential-and-token-session-theft/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4149138/malware-trojaner-viren/chrome-and-edge-browsers-hijacked-by-kremlin-malware-for-credential-and-token-session-theft/</guid>
<pubDate>Wed, 16 Sep 2026 15:11:53 +0200</pubDate>
<content:encoded><![CDATA[<p>Elastic Security Labs uncovered REF9334, a Brazilian banking malware campaign active since May 2025Malware “Kremlin” deploys fake docs and malicious Chrome/Edge extensions to steal banking data1,515 infections found, 98% in BrazilSecurity researchers from Elastic Security Labs have discovered a new Brazilian banking malware campaign that uses... <a href="https://www.techradar.com/pro/security/chrome-and-edge-browsers-hijacked-by-kremlin-malware-for-credential-and-token-session-theft" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[speakeasy v2.0.0b8]]></title>
<description><![CDATA[Windows malware emulation framework that executes binaries, drivers, and shellcode in a modeled runtime, emulating APIs, process/thread behavior, filesystem, registry, and network activity for structured JSON reporting. Weiterlesen]]></description>
<link>https://tsecurity.de/de/4148983/malware-trojaner-viren/speakeasy-v200b8/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4148983/malware-trojaner-viren/speakeasy-v200b8/</guid>
<pubDate>Wed, 16 Sep 2026 15:10:06 +0200</pubDate>
<content:encoded><![CDATA[<p>Windows malware emulation framework that executes binaries, drivers, and shellcode in a modeled runtime, emulating APIs, process/thread behavior, filesystem, registry, and network activity for structured JSON reporting. <a href="https://kitploit.com/en/posts/github-mandiant-speakeasy-v200b8" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[2026 Péter Szőr Award shortlisted nominees]]></title>
<description><![CDATA[VB Congratulates the researchers shortlisted for the 2026 Péter Szőr Award. Read more Weiterlesen]]></description>
<link>https://tsecurity.de/de/4148927/malware-trojaner-viren/2026-pter-szr-award-shortlisted-nominees/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4148927/malware-trojaner-viren/2026-pter-szr-award-shortlisted-nominees/</guid>
<pubDate>Wed, 16 Sep 2026 15:00:05 +0200</pubDate>
<content:encoded><![CDATA[<p>VB Congratulates the researchers shortlisted for the 2026 Péter Szőr Award. Read more <a href="https://www.virusbulletin.com/blog/2026/09/2026-peter-szor-award-shortlisted-nominees/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[NightEagle targets Russian companies]]></title>
<description><![CDATA[Over the past year, our Global Emergency Response Team (GERT) has investigated several incidents involving the NightEagle group (APT-Q-95). This group has been active since at least 2023 and originally focused on organizations in Asia, as we reported previously. We have now identified attacks by ...]]></description>
<link>https://tsecurity.de/de/4148926/malware-trojaner-viren/nighteagle-targets-russian-companies/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4148926/malware-trojaner-viren/nighteagle-targets-russian-companies/</guid>
<pubDate>Wed, 16 Sep 2026 15:00:04 +0200</pubDate>
<content:encoded><![CDATA[<p>Over the past year, our Global Emergency Response Team (GERT) has investigated several incidents involving the NightEagle group (APT-Q-95). This group has been active since at least 2023 and originally focused on organizations in Asia, as we reported previously. We have now identified attacks by the group targeting businesses in Russia. This post... <a href="https://securelist.com/tr/nighteagle-apt-ghostcontainer-and-tunneling/121323/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Atomic macOS (AMOS) Stealer Activity]]></title>
<description><![CDATA[Modern macOS malware uses deceptive setup guides to steal credentials and sensitive user data. Learn how to identify and block these threats. The post Atomic macOS (AMOS) Stealer Activity appeared first on Unit 42. Weiterlesen]]></description>
<link>https://tsecurity.de/de/4148893/malware-trojaner-viren/atomic-macos-amos-stealer-activity/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4148893/malware-trojaner-viren/atomic-macos-amos-stealer-activity/</guid>
<pubDate>Wed, 16 Sep 2026 12:14:49 +0200</pubDate>
<content:encoded><![CDATA[<p>Modern macOS malware uses deceptive setup guides to steal credentials and sensitive user data. Learn how to identify and block these threats. The post Atomic macOS (AMOS) Stealer Activity appeared first on Unit 42. <a href="https://unit42.paloaltonetworks.com/atomic-macos-amos-stealer-activity/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[IT Security News Hourly Summary 2026-09-16 12h : 15 posts]]></title>
<description><![CDATA[15 posts published in the last hour 09:32Meta Plans Smart Glasses Without Camera, Amid Complaints 09:32Iranian hackers use CHOSEN BRICK data-stealing malware to spy on dissidents and journalists 09:3236,769 Self-Hosted AI Services Exposed Online — What Security Teams Should Check 09:31Public PoC ...]]></description>
<link>https://tsecurity.de/de/4148870/malware-trojaner-viren/it-security-news-hourly-summary-2026-09-16-12h-15-posts/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4148870/malware-trojaner-viren/it-security-news-hourly-summary-2026-09-16-12h-15-posts/</guid>
<pubDate>Wed, 16 Sep 2026 12:13:20 +0200</pubDate>
<content:encoded><![CDATA[<p>15 posts published in the last hour 09:32Meta Plans Smart Glasses Without Camera, Amid Complaints 09:32Iranian hackers use CHOSEN BRICK data-stealing malware to spy on dissidents and journalists 09:3236,769 Self-Hosted AI Services Exposed Online — What Security Teams Should Check 09:31Public PoC Released for Apache Superset SQL Injection... <a href="https://www.itsecuritynews.info/it-security-news-hourly-summary-2026-09-16-12h-15-posts/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[PAPERMILL Malware Campaign Abuses Signed Notepad++ to Deliver VenomRAT to Windows Users]]></title>
<description><![CDATA[A newly identified phishing operation tracked as PAPERMILL is abusing a legitimately signed Notepad++ executable, DLL sideloading, and layered in-memory loaders to install VenomRAT on Windows systems. The campaign uses tax-audit lures aimed at Indian recipients and reflects a broader China-nexus ...]]></description>
<link>https://tsecurity.de/de/4148865/malware-trojaner-viren/papermill-malware-campaign-abuses-signed-notepad-to-deliver-venomrat-to-windows-users/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4148865/malware-trojaner-viren/papermill-malware-campaign-abuses-signed-notepad-to-deliver-venomrat-to-windows-users/</guid>
<pubDate>Wed, 16 Sep 2026 12:13:20 +0200</pubDate>
<content:encoded><![CDATA[<p>A newly identified phishing operation tracked as PAPERMILL is abusing a legitimately signed Notepad++ executable, DLL sideloading, and layered in-memory loaders to install VenomRAT on Windows systems. The campaign uses tax-audit lures aimed at Indian recipients and reflects a broader China-nexus pattern of tax-themed malware activity, although the... <a href="https://www.itsecuritynews.info/papermill-malware-campaign-abuses-signed-notepad-to-deliver-venomrat-to-windows-users/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Agents at Large | Tracing Illicit OpenAI Agent Activity on Hugging Face]]></title>
<description><![CDATA[Two Hugging Face accounts reveal that OpenAI's agents staged relay code, internal probes and ChatGPT account registration beyond the published timeline. This article has been indexed from SentinelLabs – We are hunters, reversers, exploit developers, and tinkerers shedding light on the world of ma...]]></description>
<link>https://tsecurity.de/de/4148864/malware-trojaner-viren/agents-at-large-tracing-illicit-openai-agent-activity-on-hugging-face/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4148864/malware-trojaner-viren/agents-at-large-tracing-illicit-openai-agent-activity-on-hugging-face/</guid>
<pubDate>Wed, 16 Sep 2026 12:13:20 +0200</pubDate>
<content:encoded><![CDATA[<p>Two Hugging Face accounts reveal that OpenAI&#039;s agents staged relay code, internal probes and ChatGPT account registration beyond the published timeline. This article has been indexed from SentinelLabs – We are hunters, reversers, exploit developers, and tinkerers shedding light on the world of malware, exploits, APTs, and cybercrime across all... <a href="https://www.itsecuritynews.info/agents-at-large-tracing-illicit-openai-agent-activity-on-hugging-face/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Warum sichere Datenspeicherung für den Mittelstand essenziell ist]]></title>
<description><![CDATA[Exponentialwachstum, Ransomware &amp; NIS-2: Fünf Gründe, warum sichere Datenspeicherung für den Mittelstand überlebenswichtig ist. Exponentielles Datenwachstum, die Bedrohung durch zielgerichtete Ransomware-Angriffe und immer strengere Compliance-Vorgaben setzen IT-Abteilungen im Mittelstand unt...]]></description>
<link>https://tsecurity.de/de/4148853/malware-trojaner-viren/warum-sichere-datenspeicherung-fuer-den-mittelstand-essenziell-ist/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4148853/malware-trojaner-viren/warum-sichere-datenspeicherung-fuer-den-mittelstand-essenziell-ist/</guid>
<pubDate>Wed, 16 Sep 2026 12:10:17 +0200</pubDate>
<content:encoded><![CDATA[<p>Exponentialwachstum, Ransomware &amp;amp; NIS-2: Fünf Gründe, warum sichere Datenspeicherung für den Mittelstand überlebenswichtig ist. Exponentielles Datenwachstum, die Bedrohung durch zielgerichtete Ransomware-Angriffe und immer strengere Compliance-Vorgaben setzen IT-Abteilungen im Mittelstand unter enormen Zugzwang. Dennoch verzögern viele... <a href="https://www.it-daily.net/it-sicherheit/cloud-security/mittelstand-datenspeicherung" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[KREMLIN Banking Malware Infects Over 1,500 Systems With Malicious Chrome Extension]]></title>
<description><![CDATA[KREMLIN is a banking malware operation that plants a hostile browser extension on infected computers. The extension can harvest passwords, session cookies, and other data that can let criminals enter online accounts. The campaign begins with fake JavaScript documents that pose as bank records or ...]]></description>
<link>https://tsecurity.de/de/4148716/malware-trojaner-viren/kremlin-banking-malware-infects-over-1500-systems-with-malicious-chrome-extension/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4148716/malware-trojaner-viren/kremlin-banking-malware-infects-over-1500-systems-with-malicious-chrome-extension/</guid>
<pubDate>Wed, 16 Sep 2026 11:14:02 +0200</pubDate>
<content:encoded><![CDATA[<p>KREMLIN is a banking malware operation that plants a hostile browser extension on infected computers. The extension can harvest passwords, session cookies, and other data that can let criminals enter online accounts. The campaign begins with fake JavaScript documents that pose as bank records or invoices. Once opened, they install components and... <a href="https://cybersecuritynews.com/kremlin-banking-malware/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Iranian Hackers Use Fake MRI Results to Infect Victims With CHOSEN BRICK Spyware]]></title>
<description><![CDATA[Iranian state-linked hackers are using fake MRI scan results to infect selected people with CHOSEN BRICK, a Windows spyware family built for long-term surveillance. The campaign has targeted individuals in the United Kingdom, United States and Netherlands since at least 2025, with dissidents, act...]]></description>
<link>https://tsecurity.de/de/4148715/malware-trojaner-viren/iranian-hackers-use-fake-mri-results-to-infect-victims-with-chosen-brick-spyware/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4148715/malware-trojaner-viren/iranian-hackers-use-fake-mri-results-to-infect-victims-with-chosen-brick-spyware/</guid>
<pubDate>Wed, 16 Sep 2026 11:14:02 +0200</pubDate>
<content:encoded><![CDATA[<p>Iranian state-linked hackers are using fake MRI scan results to infect selected people with CHOSEN BRICK, a Windows spyware family built for long-term surveillance. The campaign has targeted individuals in the United Kingdom, United States and Netherlands since at least 2025, with dissidents, activists and journalists facing particular risk. The... <a href="https://cybersecuritynews.com/fake-mri-results/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Iranian malware steals Telegram and WhatsApp data from targets]]></title>
<description><![CDATA[Iranian state cyber actors are using Windows malware called CHOSEN BRICK to target dissidents, activists, and journalists, with capabilities that include stealing Telegram and WhatsApp browser data, emails, screenshots, and audio. The malware has been used internationally since at least 2025 and ...]]></description>
<link>https://tsecurity.de/de/4148710/malware-trojaner-viren/iranian-malware-steals-telegram-and-whatsapp-data-from-targets/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4148710/malware-trojaner-viren/iranian-malware-steals-telegram-and-whatsapp-data-from-targets/</guid>
<pubDate>Wed, 16 Sep 2026 11:13:53 +0200</pubDate>
<content:encoded><![CDATA[<p>Iranian state cyber actors are using Windows malware called CHOSEN BRICK to target dissidents, activists, and journalists, with capabilities that include stealing Telegram and WhatsApp browser data, emails, screenshots, and audio. The malware has been used internationally since at least 2025 and relies heavily on social engineering, while also... <a href="https://cyberinsider.com/iranian-malware-steals-telegram-and-whatsapp-data-from-targets/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[China-Aligned Hackers Hide PeckBirdy Malware C2 Inside Casino and Adult Websites]]></title>
<description><![CDATA[China-aligned threat actors are concealing the PeckBirdy command-and-control framework inside low-quality Chinese-language casino and adult websites. Exploiting a vast and routinely ignored category of internet infrastructure to blend malware traffic into apparent gambling activity. The activity ...]]></description>
<link>https://tsecurity.de/de/4148709/malware-trojaner-viren/china-aligned-hackers-hide-peckbirdy-malware-c2-inside-casino-and-adult-websites/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4148709/malware-trojaner-viren/china-aligned-hackers-hide-peckbirdy-malware-c2-inside-casino-and-adult-websites/</guid>
<pubDate>Wed, 16 Sep 2026 11:13:48 +0200</pubDate>
<content:encoded><![CDATA[<p>China-aligned threat actors are concealing the PeckBirdy command-and-control framework inside low-quality Chinese-language casino and adult websites. Exploiting a vast and routinely ignored category of internet infrastructure to blend malware traffic into apparent gambling activity. The activity expands on earlier findings by Trend Micro, which... <a href="https://gbhackers.com/peckbirdy-malware-c2/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Iranian hackers use CHOSEN BRICK data-stealing malware to spy on dissidents and journalists]]></title>
<description><![CDATA[Iranian state cyber actors are deploying malware called CHOSEN BRICK against individuals they see as a threat to the regime, reaching victims through social messaging apps and infecting their Windows devices, three Western intelligence agencies warned. The UK’s National Cyber Security Centre, the...]]></description>
<link>https://tsecurity.de/de/4148692/malware-trojaner-viren/iranian-hackers-use-chosen-brick-data-stealing-malware-to-spy-on-dissidents-and-journalists/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4148692/malware-trojaner-viren/iranian-hackers-use-chosen-brick-data-stealing-malware-to-spy-on-dissidents-and-journalists/</guid>
<pubDate>Wed, 16 Sep 2026 11:11:11 +0200</pubDate>
<content:encoded><![CDATA[<p>Iranian state cyber actors are deploying malware called CHOSEN BRICK against individuals they see as a threat to the regime, reaching victims through social messaging apps and infecting their Windows devices, three Western intelligence agencies warned. The UK’s National Cyber Security Centre, the FBI and the Netherlands’ AIVD said the campaign has... <a href="https://www.helpnetsecurity.com/2026/09/16/iranian-hackers-chosen-brick-malware-dissidents-journalists/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[NCSC and Allies Warn of Iranian Spyware Campaign]]></title>
<description><![CDATA[The UK’s National Cyber Security Centre says Iranian Chosen Brick spyware is designed to snoop on dissidents Weiterlesen]]></description>
<link>https://tsecurity.de/de/4148691/malware-trojaner-viren/ncsc-and-allies-warn-of-iranian-spyware-campaign/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4148691/malware-trojaner-viren/ncsc-and-allies-warn-of-iranian-spyware-campaign/</guid>
<pubDate>Wed, 16 Sep 2026 11:11:10 +0200</pubDate>
<content:encoded><![CDATA[<p>The UK’s National Cyber Security Centre says Iranian Chosen Brick spyware is designed to snoop on dissidents <a href="https://www.infosecurity-magazine.com/news/ncsc-allies-warn-iranian-chosen/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[OSIRIS, eine Alternative zu Palantir?]]></title>
<description><![CDATA[Unter der URL osirisai.live nahm man im Mai diesen Jahres die Open Source OSINT-Plattform OSIRIS ans Netz. Was leistet dieses Portal? Der Artikel OSIRIS, eine Alternative zu Palantir? erschien zuerst auf TARNKAPPE.INFO Weiterlesen]]></description>
<link>https://tsecurity.de/de/4148549/malware-trojaner-viren/osiris-eine-alternative-zu-palantir/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4148549/malware-trojaner-viren/osiris-eine-alternative-zu-palantir/</guid>
<pubDate>Wed, 16 Sep 2026 11:00:27 +0200</pubDate>
<content:encoded><![CDATA[<p>Unter der URL osirisai.live nahm man im Mai diesen Jahres die Open Source OSINT-Plattform OSIRIS ans Netz. Was leistet dieses Portal? Der Artikel OSIRIS, eine Alternative zu Palantir? erschien zuerst auf TARNKAPPE.INFO <a href="https://tarnkappe.info/artikel/softwareentwicklung/osiris-eine-alternative-zu-palantir-333476.html" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[New KREMLIN Malware Installs Chrome Extensions Users Never Approved to Steal Banking Data]]></title>
<description><![CDATA[Security researchers have uncovered a Brazilian banking-malware operation named KREMLIN that secretly installs malicious extensions in Google Chrome and Microsoft Edge. The malware bypasses Chromium’s built-in extension integrity protections, making the browser load the extension as if the victim...]]></description>
<link>https://tsecurity.de/de/4148482/malware-trojaner-viren/new-kremlin-malware-installs-chrome-extensions-users-never-approved-to-steal-banking-data/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4148482/malware-trojaner-viren/new-kremlin-malware-installs-chrome-extensions-users-never-approved-to-steal-banking-data/</guid>
<pubDate>Wed, 16 Sep 2026 09:46:20 +0200</pubDate>
<content:encoded><![CDATA[<p>Security researchers have uncovered a Brazilian banking-malware operation named KREMLIN that secretly installs malicious extensions in Google Chrome and Microsoft Edge. The malware bypasses Chromium’s built-in extension integrity protections, making the browser load the extension as if the victim had installed and approved it. Elastic Security... <a href="https://cyberpress.org/kremlin-silently-hijacks-chrome/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CHOSEN BRICK Malware Lets Iranian State Hackers Steal Emails, WhatsApp and Telegram Data]]></title>
<description><![CDATA[Iranian state-linked hackers are using a Windows malware family called CHOSEN BRICK to spy on dissidents, activists, journalists, and other individuals viewed as threats to the Iranian regime. The malware has been active since at least 2025 and has targeted people in the UK, United States, Nether...]]></description>
<link>https://tsecurity.de/de/4148480/malware-trojaner-viren/chosen-brick-malware-lets-iranian-state-hackers-steal-emails-whatsapp-and-telegram-data/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4148480/malware-trojaner-viren/chosen-brick-malware-lets-iranian-state-hackers-steal-emails-whatsapp-and-telegram-data/</guid>
<pubDate>Wed, 16 Sep 2026 09:46:20 +0200</pubDate>
<content:encoded><![CDATA[<p>Iranian state-linked hackers are using a Windows malware family called CHOSEN BRICK to spy on dissidents, activists, journalists, and other individuals viewed as threats to the Iranian regime. The malware has been active since at least 2025 and has targeted people in the UK, United States, Netherlands, and other countries. A joint advisory from... <a href="https://cyberpress.org/chosen-brick-steals-messaging-data/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[PeckBirdy Malware Uses Chinese Casino and Adult Websites to Hide APT Command-and-Control]]></title>
<description><![CDATA[China-aligned advanced persistent threat (APT) groups are using low-quality Chinese-language casino and adult websites to conceal command-and-control (C2) infrastructure linked to the PeckBirdy malware framework. The tactic helps attackers blend malicious network activity into a vast ecosystem of...]]></description>
<link>https://tsecurity.de/de/4148478/malware-trojaner-viren/peckbirdy-malware-uses-chinese-casino-and-adult-websites-to-hide-apt-command-and-control/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4148478/malware-trojaner-viren/peckbirdy-malware-uses-chinese-casino-and-adult-websites-to-hide-apt-command-and-control/</guid>
<pubDate>Wed, 16 Sep 2026 09:46:20 +0200</pubDate>
<content:encoded><![CDATA[<p>China-aligned advanced persistent threat (APT) groups are using low-quality Chinese-language casino and adult websites to conceal command-and-control (C2) infrastructure linked to the PeckBirdy malware framework. The tactic helps attackers blend malicious network activity into a vast ecosystem of suspicious gambling sites that many security teams... <a href="https://cyberpress.org/peckbirdy-hides-in-casinos/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[PAPERMILL Hackers Use ISO Files to Bypass Windows Mark-of-the-Web and Deploy VenomRAT]]></title>
<description><![CDATA[A newly identified threat cluster dubbed PAPERMILL is using tax-audit phishing emails to deliver VenomRAT malware to Windows users. The campaign abuses ISO disk-image files, DLL sideloading, anti-analysis checks, and in-memory loaders to evade common security controls. JUMPSEC’s Detection and Res...]]></description>
<link>https://tsecurity.de/de/4148477/malware-trojaner-viren/papermill-hackers-use-iso-files-to-bypass-windows-mark-of-the-web-and-deploy-venomrat/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4148477/malware-trojaner-viren/papermill-hackers-use-iso-files-to-bypass-windows-mark-of-the-web-and-deploy-venomrat/</guid>
<pubDate>Wed, 16 Sep 2026 09:46:20 +0200</pubDate>
<content:encoded><![CDATA[<p>A newly identified threat cluster dubbed PAPERMILL is using tax-audit phishing emails to deliver VenomRAT malware to Windows users. The campaign abuses ISO disk-image files, DLL sideloading, anti-analysis checks, and in-memory loaders to evade common security controls. JUMPSEC’s Detection and Response Team identified the activity after a phishing... <a href="https://cyberpress.org/papermill-deploys-venomrat-via-iso/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Noodle RAT Uses Scheduled Tasks, Cron Jobs and Process Spoofing to Hide on Systems]]></title>
<description><![CDATA[Noodle RAT, also tracked as ANGRYREBEL and Nood RAT, is a modular remote access trojan used by Chinese-speaking threat actors to maintain covert access to Windows and Linux systems. Active since at least mid-2016, the malware was once incorrectly identified as a Gh0st RAT or Rekoobe variant. Rese...]]></description>
<link>https://tsecurity.de/de/4148476/malware-trojaner-viren/noodle-rat-uses-scheduled-tasks-cron-jobs-and-process-spoofing-to-hide-on-systems/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4148476/malware-trojaner-viren/noodle-rat-uses-scheduled-tasks-cron-jobs-and-process-spoofing-to-hide-on-systems/</guid>
<pubDate>Wed, 16 Sep 2026 09:46:20 +0200</pubDate>
<content:encoded><![CDATA[<p>Noodle RAT, also tracked as ANGRYREBEL and Nood RAT, is a modular remote access trojan used by Chinese-speaking threat actors to maintain covert access to Windows and Linux systems. Active since at least mid-2016, the malware was once incorrectly identified as a Gh0st RAT or Rekoobe variant. Researchers now classify it as a distinct backdoor... <a href="https://cyberpress.org/noodle-rat-hides-persistently/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Health Group Issues Alerts Over 2025 Data Breach]]></title>
<description><![CDATA[HCRG Care Group warns patients over theft of their data by Medusa ransomware hackers, 18 months after incident occurred This article has been indexed from Silicon UK Read the original article: Health Group Issues Alerts Over 2025 Data Breach The post Health Group Issues Alerts Over 2025 Data Brea...]]></description>
<link>https://tsecurity.de/de/4148472/malware-trojaner-viren/health-group-issues-alerts-over-2025-data-breach/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4148472/malware-trojaner-viren/health-group-issues-alerts-over-2025-data-breach/</guid>
<pubDate>Wed, 16 Sep 2026 09:46:12 +0200</pubDate>
<content:encoded><![CDATA[<p>HCRG Care Group warns patients over theft of their data by Medusa ransomware hackers, 18 months after incident occurred This article has been indexed from Silicon UK Read the original article: Health Group Issues Alerts Over 2025 Data Breach The post Health Group Issues Alerts Over 2025 Data Breach appeared first on IT Security News. <a href="https://www.itsecuritynews.info/health-group-issues-alerts-over-2025-data-breach/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[IT Security News Hourly Summary 2026-09-16 09h : 8 posts]]></title>
<description><![CDATA[8 posts published in the last hour 06:31CISA Warns Hackers Exploit 17 Active Directory Techniques to Gain Control of Enterprise Networks 06:31What happens when AI agent governance is missing at scale 06:31Health Group Issues Alerts Over 2025 Data Breach 06:02KREMLIN Banking Malware Bypasses Chrom...]]></description>
<link>https://tsecurity.de/de/4148471/malware-trojaner-viren/it-security-news-hourly-summary-2026-09-16-09h-8-posts/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4148471/malware-trojaner-viren/it-security-news-hourly-summary-2026-09-16-09h-8-posts/</guid>
<pubDate>Wed, 16 Sep 2026 09:46:12 +0200</pubDate>
<content:encoded><![CDATA[<p>8 posts published in the last hour 06:31CISA Warns Hackers Exploit 17 Active Directory Techniques to Gain Control of Enterprise Networks 06:31What happens when AI agent governance is missing at scale 06:31Health Group Issues Alerts Over 2025 Data Breach 06:02KREMLIN Banking Malware Bypasses Chrome Security to Steal Banking Sessions 06:02DeepZero:... <a href="https://www.itsecuritynews.info/it-security-news-hourly-summary-2026-09-16-09h-8-posts/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Hackers Disguise CHOSEN BRICK Malware as AI Apps, Antivirus Software and MRI Results]]></title>
<description><![CDATA[Iranian state-linked cyber actors are using fake AI applications, antivirus tools and even fabricated MRI scan results to deliver CHOSEN BRICK, a Windows-focused spyware family designed to surveil dissidents, activists and journalists. A joint advisory from the UK National Cyber Security Centre (...]]></description>
<link>https://tsecurity.de/de/4148470/malware-trojaner-viren/hackers-disguise-chosen-brick-malware-as-ai-apps-antivirus-software-and-mri-results/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4148470/malware-trojaner-viren/hackers-disguise-chosen-brick-malware-as-ai-apps-antivirus-software-and-mri-results/</guid>
<pubDate>Wed, 16 Sep 2026 09:46:12 +0200</pubDate>
<content:encoded><![CDATA[<p>Iranian state-linked cyber actors are using fake AI applications, antivirus tools and even fabricated MRI scan results to deliver CHOSEN BRICK, a Windows-focused spyware family designed to surveil dissidents, activists and journalists. A joint advisory from the UK National Cyber Security Centre (NCSC), the FBI and the Netherlands’ AIVD warns that... <a href="https://www.itsecuritynews.info/hackers-disguise-chosen-brick-malware-as-ai-apps-antivirus-software-and-mri-results/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[PhantomRaven: An LLM-Generated Information Stealer Developed for Bug Bounty Hunting]]></title>
<description><![CDATA[This post has no text preview — click the link below to read the original article. This article has been indexed from Blog Read the original article: PhantomRaven: An LLM-Generated Information Stealer Developed for Bug Bounty Hunting The post PhantomRaven: An LLM-Generated Information Stealer Dev...]]></description>
<link>https://tsecurity.de/de/4148468/malware-trojaner-viren/phantomraven-an-llm-generated-information-stealer-developed-for-bug-bounty-hunting/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4148468/malware-trojaner-viren/phantomraven-an-llm-generated-information-stealer-developed-for-bug-bounty-hunting/</guid>
<pubDate>Wed, 16 Sep 2026 09:46:11 +0200</pubDate>
<content:encoded><![CDATA[<p>This post has no text preview — click the link below to read the original article. This article has been indexed from Blog Read the original article: PhantomRaven: An LLM-Generated Information Stealer Developed for Bug Bounty Hunting The post PhantomRaven: An LLM-Generated Information Stealer Developed for Bug Bounty Hunting appeared first on IT... <a href="https://www.itsecuritynews.info/phantomraven-an-llm-generated-information-stealer-developed-for-bug-bounty-hunting/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Luciferus Uncensored AI Advertised on Hacker Forums for Malware and RAT Development]]></title>
<description><![CDATA[Threat actors are advertising a new “uncensored” artificial intelligence service, dubbed Luciferus, as a subscription-based assistant that can handle malware-development requests mainstream AI platforms typically reject. Sophos Counter Threat Unit (CTU) researchers identified the offering on Augu...]]></description>
<link>https://tsecurity.de/de/4148343/malware-trojaner-viren/luciferus-uncensored-ai-advertised-on-hacker-forums-for-malware-and-rat-development/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4148343/malware-trojaner-viren/luciferus-uncensored-ai-advertised-on-hacker-forums-for-malware-and-rat-development/</guid>
<pubDate>Wed, 16 Sep 2026 08:09:40 +0200</pubDate>
<content:encoded><![CDATA[<p>Threat actors are advertising a new “uncensored” artificial intelligence service, dubbed Luciferus, as a subscription-based assistant that can handle malware-development requests mainstream AI platforms typically reject. Sophos Counter Threat Unit (CTU) researchers identified the offering on August 24, 2026, in a post on the Exploit underground... <a href="https://cyberpress.org/cybercriminals-advertise-uncensored-luciferus-ai/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Luciferus Uncensored AI Service Lets Cybercriminals Generate RAT Malware]]></title>
<description><![CDATA[Cybercriminals are promoting a new “uncensored” artificial intelligence service called Luciferus that allegedly generates malicious code, including components for remote access trojans (RATs), without the safeguards typically found in mainstream AI platforms. Researchers from the Sophos Counter T...]]></description>
<link>https://tsecurity.de/de/4148340/malware-trojaner-viren/luciferus-uncensored-ai-service-lets-cybercriminals-generate-rat-malware/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4148340/malware-trojaner-viren/luciferus-uncensored-ai-service-lets-cybercriminals-generate-rat-malware/</guid>
<pubDate>Wed, 16 Sep 2026 08:09:31 +0200</pubDate>
<content:encoded><![CDATA[<p>Cybercriminals are promoting a new “uncensored” artificial intelligence service called Luciferus that allegedly generates malicious code, including components for remote access trojans (RATs), without the safeguards typically found in mainstream AI platforms. Researchers from the Sophos Counter Threat Unit reported that they first noticed a user... <a href="https://www.itsecuritynews.info/luciferus-uncensored-ai-service-lets-cybercriminals-generate-rat-malware/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[KREMLIN Banking Malware Bypasses Chrome Security to Steal Banking Sessions]]></title>
<description><![CDATA[A Brazilian banking malware operation, dubbed KREMLIN, that can silently implant malicious extensions in Google Chrome and Microsoft Edge, bypassing Chromium’s built-in integrity protections to steal credentials, cookies, and active banking sessions. Despite its name, the KREMLIN toolkit shows no...]]></description>
<link>https://tsecurity.de/de/4148337/malware-trojaner-viren/kremlin-banking-malware-bypasses-chrome-security-to-steal-banking-sessions/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4148337/malware-trojaner-viren/kremlin-banking-malware-bypasses-chrome-security-to-steal-banking-sessions/</guid>
<pubDate>Wed, 16 Sep 2026 08:09:31 +0200</pubDate>
<content:encoded><![CDATA[<p>A Brazilian banking malware operation, dubbed KREMLIN, that can silently implant malicious extensions in Google Chrome and Microsoft Edge, bypassing Chromium’s built-in integrity protections to steal credentials, cookies, and active banking sessions. Despite its name, the KREMLIN toolkit shows no apparent Russian connection. The campaign relies on... <a href="https://www.itsecuritynews.info/kremlin-banking-malware-bypasses-chrome-security-to-steal-banking-sessions/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Casbaneiro: A Banking Trojan with Distributed Data-Receiving Servers]]></title>
<description><![CDATA[2026-09-10 • Fortinet • Rachael Liao • win.metamorfo Open article on Malpedia Weiterlesen]]></description>
<link>https://tsecurity.de/de/4148279/malware-trojaner-viren/casbaneiro-a-banking-trojan-with-distributed-data-receiving-servers/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4148279/malware-trojaner-viren/casbaneiro-a-banking-trojan-with-distributed-data-receiving-servers/</guid>
<pubDate>Wed, 16 Sep 2026 08:00:11 +0200</pubDate>
<content:encoded><![CDATA[<p>2026-09-10 • Fortinet • Rachael Liao • win.metamorfo Open article on Malpedia <a href="https://malpedia.caad.fkie.fraunhofer.de/library/9ea12cca-9d3e-4bd5-8d92-ffbc91fdb1dd/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[The MRI Scan That Wasn’t: Inside Iran’s ‘Chosen Brick’ Malware Campaign Against Its Critics Abroad]]></title>
<description><![CDATA[The file looked like an MRI scan. Lumbar spine, several grey slices of vertebrae, a heading reading something like 'Disk Herniation and Degeneration.' For a dissident living in exile - someone with a body that has been through things, someone waiting on results - it was a plausible thing to open....]]></description>
<link>https://tsecurity.de/de/4148263/malware-trojaner-viren/the-mri-scan-that-wasnt-inside-irans-chosen-brick-malware-campaign-against-its-critics-abroad/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4148263/malware-trojaner-viren/the-mri-scan-that-wasnt-inside-irans-chosen-brick-malware-campaign-against-its-critics-abroad/</guid>
<pubDate>Wed, 16 Sep 2026 07:08:45 +0200</pubDate>
<content:encoded><![CDATA[<p>The file looked like an MRI scan. Lumbar spine, several grey slices of vertebrae, a heading reading something like &#039;Disk Herniation and Degeneration.&#039; For a dissident living in exile - someone with a body that has been through things, someone waiting on results - it was a plausible thing to open. Opening it handed Iranian intelligence the... <a href="https://thecyberexpress.com/inside-irans-chosen-brick-malware-campaign/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[can someone tell me if this is a virus?]]></title>
<description><![CDATA[submitted by /u/Excellent-Dealer-404 [link] [comments] Weiterlesen]]></description>
<link>https://tsecurity.de/de/4147863/malware-trojaner-viren/can-someone-tell-me-if-this-is-a-virus/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4147863/malware-trojaner-viren/can-someone-tell-me-if-this-is-a-virus/</guid>
<pubDate>Wed, 16 Sep 2026 01:30:23 +0200</pubDate>
<content:encoded><![CDATA[<p>submitted by /u/Excellent-Dealer-404 [link] [comments] <a href="https://www.reddit.com/r/MalwareAnalysis/comments/1whfdat/can_someone_tell_me_if_this_is_a_virus/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[KREMLIN-Banking-Malware missbraucht Chrome- und Edge-Erweiterungen zum Diebstahl von Zugangsdaten]]></title>
<description><![CDATA[BRAZIL / LONDON (IT BOLTWISE) – Eine bislang undokumentierte Banking-Malware aus Brasilien zielt auf Google Chrome und Microsoft Edge ab, um Zugangsdaten und Session-Tokens abzugreifen. Die Angreifer installieren dazu eine bösartige Browser-Erweiterung über eine mehrstufige JavaScript- und Instal...]]></description>
<link>https://tsecurity.de/de/4147775/malware-trojaner-viren/kremlin-banking-malware-missbraucht-chrome-und-edge-erweiterungen-zum-diebstahl-von-zugangsdaten/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4147775/malware-trojaner-viren/kremlin-banking-malware-missbraucht-chrome-und-edge-erweiterungen-zum-diebstahl-von-zugangsdaten/</guid>
<pubDate>Tue, 15 Sep 2026 23:45:13 +0200</pubDate>
<content:encoded><![CDATA[<p>BRAZIL / LONDON (IT BOLTWISE) – Eine bislang undokumentierte Banking-Malware aus Brasilien zielt auf Google Chrome und Microsoft Edge ab, um Zugangsdaten und Session-Tokens abzugreifen. Die Angreifer installieren dazu eine bösartige Browser-Erweiterung über eine mehrstufige JavaScript- und Installer-Kette. Auffällig ist die Tarnung der... <a href="https://www.it-boltwise.de/kremlin-banking-malware-missbraucht-chrome-und-edge-erweiterungen-zum-diebstahl-von-zugangsdaten.html" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[IT Security News Hourly Summary 2026-09-15 21h : 4 posts]]></title>
<description><![CDATA[4 posts published in the last hour 18:31Iranian spies hit Windows machines with Chosen Brick data-stealing malware 18:02Europol celebrates the International Day of Police Cooperation 18:02Iranian Hackers Use Telegram-Controlled Malware to Spy on Dissidents and Journalists 18:00IT Security News Ho...]]></description>
<link>https://tsecurity.de/de/4147675/malware-trojaner-viren/it-security-news-hourly-summary-2026-09-15-21h-4-posts/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4147675/malware-trojaner-viren/it-security-news-hourly-summary-2026-09-15-21h-4-posts/</guid>
<pubDate>Tue, 15 Sep 2026 22:13:23 +0200</pubDate>
<content:encoded><![CDATA[<p>4 posts published in the last hour 18:31Iranian spies hit Windows machines with Chosen Brick data-stealing malware 18:02Europol celebrates the International Day of Police Cooperation 18:02Iranian Hackers Use Telegram-Controlled Malware to Spy on Dissidents and Journalists 18:00IT Security News Hourly Summary 2026-09-15 20h : 16 posts The post IT... <a href="https://www.itsecuritynews.info/it-security-news-hourly-summary-2026-09-15-21h-4-posts/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[IT Security News Hourly Summary 2026-09-15 22h : 3 posts]]></title>
<description><![CDATA[3 posts published in the last hour 19:31Architecting resilient authentication with Amazon Cognito multi-Region replication 19:31KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session Tokens 19:00IT Security News Hourly Summary 2026-09-15 21h : 4 posts The post IT Securit...]]></description>
<link>https://tsecurity.de/de/4147673/malware-trojaner-viren/it-security-news-hourly-summary-2026-09-15-22h-3-posts/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4147673/malware-trojaner-viren/it-security-news-hourly-summary-2026-09-15-22h-3-posts/</guid>
<pubDate>Tue, 15 Sep 2026 22:13:23 +0200</pubDate>
<content:encoded><![CDATA[<p>3 posts published in the last hour 19:31Architecting resilient authentication with Amazon Cognito multi-Region replication 19:31KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session Tokens 19:00IT Security News Hourly Summary 2026-09-15 21h : 4 posts The post IT Security News Hourly Summary 2026-09-15 22h : 3 posts... <a href="https://www.itsecuritynews.info/it-security-news-hourly-summary-2026-09-15-22h-3-posts/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[KREMLIN-Banking-Malware kapert Chrome und Edge per Browser-Extension]]></title>
<description><![CDATA[LONDON (IT BOLTWISE) – Eine bislang undokumentierte Banking-Malware namens KREMLIN nutzt in Brasilien gefälschte Bank-Anzeigen und installiert eine schädliche Browser-Erweiterung für Chrome und Edge. Die Kampagne kombiniert mehrstufige JavaScript-Loader, einen C++-Installer und Anti-Sandbox-Check...]]></description>
<link>https://tsecurity.de/de/4147634/malware-trojaner-viren/kremlin-banking-malware-kapert-chrome-und-edge-per-browser-extension/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4147634/malware-trojaner-viren/kremlin-banking-malware-kapert-chrome-und-edge-per-browser-extension/</guid>
<pubDate>Tue, 15 Sep 2026 21:43:44 +0200</pubDate>
<content:encoded><![CDATA[<p>LONDON (IT BOLTWISE) – Eine bislang undokumentierte Banking-Malware namens KREMLIN nutzt in Brasilien gefälschte Bank-Anzeigen und installiert eine schädliche Browser-Erweiterung für Chrome und Edge. Die Kampagne kombiniert mehrstufige JavaScript-Loader, einen C++-Installer und Anti-Sandbox-Checks, um Credentials sowie Session Tokens abzugreifen.... <a href="https://www.it-boltwise.de/kremlin-banking-malware-kapert-chrome-und-edge-per-browser-extension.html" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Low-quality casino sites conceal highly dangerous threat actors]]></title>
<description><![CDATA[If your employees are visiting Chinese-language gambling or adult sites, they may not just be wasting time and money, but potentially encountering serious malware hidden behind domains that look like mostly harmless entertainment at first glance. A report from Infoblox urges the security communit...]]></description>
<link>https://tsecurity.de/de/4147626/malware-trojaner-viren/low-quality-casino-sites-conceal-highly-dangerous-threat-actors/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4147626/malware-trojaner-viren/low-quality-casino-sites-conceal-highly-dangerous-threat-actors/</guid>
<pubDate>Tue, 15 Sep 2026 21:40:14 +0200</pubDate>
<content:encoded><![CDATA[<p>If your employees are visiting Chinese-language gambling or adult sites, they may not just be wasting time and money, but potentially encountering serious malware hidden behind domains that look like mostly harmless entertainment at first glance. A report from Infoblox urges the security community to pay closer attention to these websites, because... <a href="https://www.theregister.com/security/2026/09/15/low-quality-casino-sites-conceal-highly-dangerous-threat-actors/5296652" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
</channel>
</rss>
<!-- Generated in 0,48ms -->