<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="/rss-style.xsl"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:media="http://search.yahoo.com/mrss/" xmlns:dc="http://purl.org/dc/elements/1.1/">
<channel>
<title><![CDATA[🛡️ 🎥 Video – Cyber Threat Intelligence | TSECURITY.DE]]></title>
<link><![CDATA[https://tsecurity.de/export/rss/video.xml]]></link>
<description><![CDATA[Exklusive IT-Security Videos & Threat Demos. Technische Video-Analysen zu Schwachstellen, Hacking-Techniken, Reverse Engineering und Konferenz-Vorträgen.]]></description>
<language>de-DE</language>
<lastBuildDate>Sun, 26 Jul 2026 17:37:33 +0200</lastBuildDate>
<pubDate>Sun, 26 Jul 2026 17:37:33 +0200</pubDate>
<ttl>15</ttl>
<copyright>2026 TSECURITY.DE Cyber Intelligence Team IT Security</copyright>
<managingEditor>editor@tsecurity.de (TSEcurity Redaktion)</managingEditor>
<webMaster>support@tsecurity.de (TSEcurity Intelligence Network)</webMaster>
<category>🎥 Video</category>
<generator>TSECURITY.DE Cyber Threat Intelligence Feed Generator v3.0</generator>
<image>
<url>https://tsecurity.de/favicon.ico</url>
<title><![CDATA[🛡️ 🎥 Video – Cyber Threat Intelligence | TSECURITY.DE]]></title>
<link><![CDATA[https://tsecurity.de/export/rss/video.xml]]></link>
</image>
<atom:link href="https://tsecurity.de/export/rss/video.xml" rel="self" type="application/rss+xml" />
<item>
<title><![CDATA[Die wahren Kosten von staatlicher Überwachung]]></title>
<description><![CDATA[YouTube Video]]></description>
<link>https://tsecurity.de/weiterlesen/3667383/3695524/die-wahren-kosten-von-staatlicher-ueberwachung/</link>
<pubDate>Sun, 26 Jul 2026 12:51:06 +0200</pubDate>
<category>🎥 Video</category>
<source url="https://tsecurity.de">TSECURITY.DE</source>
<content:encoded><![CDATA[<p>YouTube Video</p><p><iframe loading="lazy" src="https://www.youtube.com/embed/aAWmYdXQ6Qc"></iframe></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[State of the Thunder 14: The 2026 Mobile Roadmap]]></title>
<description><![CDATA[Author: Mozilla Thunderbird - Bewertung: 28x - Views:1101 As 2025 winds down, its time to start thinking of what we want to achieve for our Android AND iOS apps next year. Alessandro walks us through the 2026 mobile roadmap, covering our urgent priorities, feature wish list, and a glimpse at our ...]]></description>
<link>https://tsecurity.de/weiterlesen/3665299/3693440/state-of-the-thunder-14-the-2026-mobile-roadmap/</link>
<pubDate>Sat, 25 Jul 2026 10:05:15 +0200</pubDate>
<category>🎥 Video</category>
<source url="https://tsecurity.de">TSECURITY.DE</source>
<content:encoded><![CDATA[<p>Author: Mozilla Thunderbird - Bewertung: 28x - Views:1101 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/TB7XcRLVxFI?autoplay=1&origin=https://tsecurity.de" frameborder="0"></iframe></p><p>As 2025 winds down, its time to start thinking of what we want to achieve for our Android AND iOS apps next year. Alessandro walks us through the 2026 mobile roadmap, covering our urgent priorities, feature wish list, and a glimpse at our upcoming design plans for the entire Thunderbird project.<br />
<br />
Chapters<br />
<br />
00:00 Intro<br />
01:47 Thunderbird Pro in Mobile<br />
05:49 How we build a roadmap<br />
07:40 Android initiatives<br />
12:51 Material 3 or Material You<br />
21:05 Calendar Exploration Questions<br />
31:26 Roadmap items for our community<br />
33:34 iOS initiatives<br />
<br />
Resources:<br />
Current Android Roadmap: https://github.com/orgs/thunderbird/projects/19<br />
TB Pro Announcement: https://blog.thunderbird.net/2025/04/thundermail-and-thunderbird-pro-services/<br />
Mobile Development Matrix: https://matrix.to/#/#tb-mobile-dev:mozilla.org<br />
Thunderbird for Android GitHub Issues: https://github.com/thunderbird/thunderbird-android/issues<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Community Office Hours: Exchange Email Support]]></title>
<description><![CDATA[Author: Mozilla Thunderbird - Bewertung: 15x - Views:697 Welcome to the last Community Office Hours of 2025! In this edition, Heather and Monica welcome Sr. Software Engineer Brendan Abolivier and Software Engineer Eleanor Dichary from the Desktop Team. We’re discussing the recent Exchange Web Su...]]></description>
<link>https://tsecurity.de/weiterlesen/3665298/3693439/community-office-hours-exchange-email-support/</link>
<pubDate>Sat, 25 Jul 2026 10:05:14 +0200</pubDate>
<category>🎥 Video</category>
<source url="https://tsecurity.de">TSECURITY.DE</source>
<content:encoded><![CDATA[<p>Author: Mozilla Thunderbird - Bewertung: 15x - Views:697 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/w986NrVHBM0?autoplay=1&origin=https://tsecurity.de" frameborder="0"></iframe></p><p>Welcome to the last Community Office Hours of 2025! In this edition, Heather and Monica welcome Sr. Software Engineer Brendan Abolivier and Software Engineer Eleanor Dichary from the Desktop Team. We’re discussing the recent Exchange Web Support for email that just landed in Thunderbird Monthly Release 145. Learn how the team landed this feature and discover future plans for Calendar and Contact support, as well as Graph API<br />
<br />
Chapters:<br />
00:00 Intro<br />
03:50 What is Microsoft Exchange<br />
05:07 Why it took so long to add Exchange<br />
14:33 Exchange in Thunderbird 145<br />
18:20 Config options and authorization<br />
27:10 Attachments and storage<br />
32:30 Sync and folder operations<br />
36:10 Filters and notification<br />
39:10 Search<br />
40:20 Feedback and bug reporting<br />
43:00 Mobile and Graph API<br />
49:09 JMAP and future protocols<br />
55:50 Calendar and address book<br />
59:57 Roadmap and EWS deprecation<br />
62:23 Closing<br />
<br />
Resources:<br />
Exchange Mozilla Support Article: https://support.mozilla.org/en-US/kb/thunderbird-and-exchange<br />
Exchange Mozilla Wiki Post (with call for testing): https://wiki.mozilla.org/Thunderbird%3AExchange<br />
Reach out on Matrix: https://matrix.to/#/#thunderbird:mozilla.org<br />
Bugzilla (use Exchange component for reporting): https://bugzilla.mozilla.org/enter_bug.cgi?product=MailNews%20Core<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Design System Governance Committee: January 26, 2026 Meeting]]></title>
<description><![CDATA[Author: Mozilla Thunderbird - Bewertung: 10x - Views:142 In their first meeting, the Design System Governance Committee, composed of MZLA employees and community members, first reviews the 2026 design roadmap. Then they take a deeper dive into tokens, their role in tying together Thunderbird's ma...]]></description>
<link>https://tsecurity.de/weiterlesen/3665297/3693438/design-system-governance-committee-january-26-2026-meeting/</link>
<pubDate>Sat, 25 Jul 2026 10:05:13 +0200</pubDate>
<category>🎥 Video</category>
<source url="https://tsecurity.de">TSECURITY.DE</source>
<content:encoded><![CDATA[<p>Author: Mozilla Thunderbird - Bewertung: 10x - Views:142 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/rAJrAmu-lqw?autoplay=1&origin=https://tsecurity.de" frameborder="0"></iframe></p><p>In their first meeting, the Design System Governance Committee, composed of MZLA employees and community members, first reviews the 2026 design roadmap. Then they take a deeper dive into tokens, their role in tying together Thunderbird&#039;s many platforms, W3 token standards, and how to document them. This work will make it easier for new design team members and contributors to jump into their work, while providing a more coherent experience from desktop to mobile and beyond.<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Accessibility Standards and Compliance Committee Meeting: February 10, 2026]]></title>
<description><![CDATA[Author: Mozilla Thunderbird - Bewertung: 3x - Views:105 Our Accessibility Standards and Committee Meetings are now recorded and online!

In the February Accessibility Standards & Compliance meeting, the committee advances a draft Thunderbird accessibility statement for review at the next meeting ...]]></description>
<link>https://tsecurity.de/weiterlesen/3665296/3693437/accessibility-standards-and-compliance-committee-meeting-february-10-2026/</link>
<pubDate>Sat, 25 Jul 2026 10:05:12 +0200</pubDate>
<category>🎥 Video</category>
<source url="https://tsecurity.de">TSECURITY.DE</source>
<content:encoded><![CDATA[<p>Author: Mozilla Thunderbird - Bewertung: 3x - Views:105 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/BimoUyedFxc?autoplay=1&origin=https://tsecurity.de" frameborder="0"></iframe></p><p>Our Accessibility Standards and Committee Meetings are now recorded and online!<br />
<br />
In the February Accessibility Standards &amp; Compliance meeting, the committee advances a draft Thunderbird accessibility statement for review at the next meeting and starts crafting Thunderbird’s accessibility guidelines.  The group  identifies work needed to extend guidance into the Bolt design system with a lightweight a11y definition of done for design, and development. Finally, the committee discusses adding automated accessibility checks across platforms (including a minimum “accessibility gate”), reviews proposed success metrics, and closes with an open forum for community questions.<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Design System Governance Committee: 24 February 2026]]></title>
<description><![CDATA[Author: Mozilla Thunderbird - Bewertung: 6x - Views:160 In the February meeting, the Bolt Design System Committee aligns on initial setup and ownership for the Bolt Design System repo, began defining cross-platform icon naming conventions, plus works towards component exposure in the documentatio...]]></description>
<link>https://tsecurity.de/weiterlesen/3665295/3693436/design-system-governance-committee-24-february-2026/</link>
<pubDate>Sat, 25 Jul 2026 10:05:10 +0200</pubDate>
<category>🎥 Video</category>
<source url="https://tsecurity.de">TSECURITY.DE</source>
<content:encoded><![CDATA[<p>Author: Mozilla Thunderbird - Bewertung: 6x - Views:160 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/1L2HisD3PeQ?autoplay=1&origin=https://tsecurity.de" frameborder="0"></iframe></p><p>In the February meeting, the Bolt Design System Committee aligns on initial setup and ownership for the Bolt Design System repo, began defining cross-platform icon naming conventions, plus works towards component exposure in the documentation site.<br />
<br />
Have any questions or want to join the conversation? Come find us in our Matrix room (https://matrix.to/#/#bolt-design-system:mozilla.org). New to Matrix? Find a Quick Start guide here: https://matrixdocs.github.io/docs/getting-started/quick-start<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Community Office Hours: Meet the New Support Team!]]></title>
<description><![CDATA[Author: Mozilla Thunderbird - Bewertung: 8x - Views:326 We've got some new faces on our growing support team! in this Community Office Hours, Heather and Monica talk to the team about the work they're doing to not only get ready for Thundermail, but improve the support experience for donors, the ...]]></description>
<link>https://tsecurity.de/weiterlesen/3665294/3693435/community-office-hours-meet-the-new-support-team/</link>
<pubDate>Sat, 25 Jul 2026 10:05:09 +0200</pubDate>
<category>🎥 Video</category>
<source url="https://tsecurity.de">TSECURITY.DE</source>
<content:encoded><![CDATA[<p>Author: Mozilla Thunderbird - Bewertung: 8x - Views:326 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/tKg5vmSnrpM?autoplay=1&origin=https://tsecurity.de" frameborder="0"></iframe></p><p>We&#039;ve got some new faces on our growing support team! in this Community Office Hours, Heather and Monica talk to the team about the work they&#039;re doing to not only get ready for Thundermail, but improve the support experience for donors, the wider Thunderbird community, and our incredible support contributors. <br />
<br />
Resources for Suggesting Features:<br />
Thunderbird on Desktop and Mobile - https://connect.mozilla.org<br />
Thundermail and Thunderbird Pro - https://ideas.tb.pro<br />
<br />
Resources for Becoming a Community Support Contributor:<br />
Join the Support Crew Matrix Channel - https://matrix.to/#/#tb-support-crew:mozilla.org<br />
Learn How to Write Support Articles - https://blog.thunderbird.net/2024/07/video-learn-about-thunderbird-support-articles-and-how-to-contribute/<br />
Learn How to Help Support Forum Users - https://blog.thunderbird.net/2024/08/video-how-to-answer-thunderbird-questions-on-mozilla-support/<br />
Provide Feedback on Desktop Support Articles - https://github.com/thunderbird/knowledgebase-issues/issues<br />
Provide Feedback on Android Support Articles - https://github.com/thunderbird/android-knowledgebase-issues/issues<br />
Already a SUMO Contributor? Join the Contributor Discussion Forum - https://support.mozilla.org/forums/contributors/<br />
<br />
Resources for Getting Help with Thunderbird:<br />
Thunderbird for Android Support Channel (Matrix) - https://matrix.to/#/#tb-android:mozilla.org<br />
Thunderbird Desktop Support Channel (Matrix) - https://matrix.to/#/#thunderbird:mozilla.org<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Community Office Hours: Contributor Spotlight on Bogomil Shopov]]></title>
<description><![CDATA[Author: Mozilla Thunderbird - Bewertung: 5x - Views:231 Thunderbird's localizers make it possible for users around the world our desktop and mobile clients in their own language. This month, Heather and Monica are chatting with Bogomil Shopov, one of our Bulgarian localizers who has been with Thu...]]></description>
<link>https://tsecurity.de/weiterlesen/3665293/3693434/community-office-hours-contributor-spotlight-on-bogomil-shopov/</link>
<pubDate>Sat, 25 Jul 2026 10:05:08 +0200</pubDate>
<category>🎥 Video</category>
<source url="https://tsecurity.de">TSECURITY.DE</source>
<content:encoded><![CDATA[<p>Author: Mozilla Thunderbird - Bewertung: 5x - Views:231 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/xSXJsPIVV60?autoplay=1&origin=https://tsecurity.de" frameborder="0"></iframe></p><p>Thunderbird&#039;s localizers make it possible for users around the world our desktop and mobile clients in their own language. This month, Heather and Monica are chatting with Bogomil Shopov, one of our Bulgarian localizers who has been with Thunderbird from the start. Find out how he got started in open source, how he&#039;s mentoring the next generation of contributors, and his advice on getting involved with Thunderbird (and what music he uses to focus!)<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Willkommen in der Patchpocalypse.. #linux #cybersecurity #ai]]></title>
<description><![CDATA[Author: The Morpheus - Bewertung: 67x - Views:874]]></description>
<link>https://tsecurity.de/weiterlesen/3663381/3691522/willkommen-in-der-patchpocalypse-linux-cybersecurity-ai/</link>
<pubDate>Fri, 24 Jul 2026 14:27:41 +0200</pubDate>
<category>🎥 Video</category>
<source url="https://tsecurity.de">TSECURITY.DE</source>
<content:encoded><![CDATA[<p>Author: The Morpheus - Bewertung: 67x - Views:874 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/lUkVOAb7TkY?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p><br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[H4ck1ng bei KI-Modellen ist keine gute Werbung.. #technews #openai]]></title>
<description><![CDATA[Author: The Morpheus - Bewertung: 92x - Views:1199]]></description>
<link>https://tsecurity.de/weiterlesen/3661061/3689202/h4ck1ng-bei-ki-modellen-ist-keine-gute-werbung-technews-openai/</link>
<pubDate>Thu, 23 Jul 2026 15:33:44 +0200</pubDate>
<category>🎥 Video</category>
<source url="https://tsecurity.de">TSECURITY.DE</source>
<content:encoded><![CDATA[<p>Author: The Morpheus - Bewertung: 92x - Views:1199 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/t8XVZKX-Xw4?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p><br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Wissenschaft oder doch nur PR? #technews #anthropic]]></title>
<description><![CDATA[Author: The Morpheus - Bewertung: 39x - Views:556]]></description>
<link>https://tsecurity.de/weiterlesen/3658625/3686766/wissenschaft-oder-doch-nur-pr-technews-anthropic/</link>
<pubDate>Wed, 22 Jul 2026 17:06:53 +0200</pubDate>
<category>🎥 Video</category>
<source url="https://tsecurity.de">TSECURITY.DE</source>
<content:encoded><![CDATA[<p>Author: The Morpheus - Bewertung: 39x - Views:556 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/YnnGnPXBndA?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p><br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Das ist der Deepseek 2.0 Moment]]></title>
<description><![CDATA[Author: The Morpheus Tutorials - Bewertung: 21x - Views:188 Kimi K3 zeigt, dass Open Weight Modelle definitiv nichht mehr weit weg sind von den besten der besten.

Quellen:
https://www.kimi.com/blog/kimi-k3
https://platform.kimi.ai/docs/guide/kimi-k3-quickstart
https://x.com/Kimi_Moonshot/status/...]]></description>
<link>https://tsecurity.de/weiterlesen/3655832/3683973/das-ist-der-deepseek-20-moment/</link>
<pubDate>Tue, 21 Jul 2026 16:12:27 +0200</pubDate>
<category>🎥 Video</category>
<source url="https://tsecurity.de">TSECURITY.DE</source>
<content:encoded><![CDATA[<p>Author: The Morpheus Tutorials - Bewertung: 21x - Views:188 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/vqNvkkhyEms?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>Kimi K3 zeigt, dass Open Weight Modelle definitiv nichht mehr weit weg sind von den besten der besten.<br />
<br />
Quellen:<br />
https://www.kimi.com/blog/kimi-k3<br />
https://platform.kimi.ai/docs/guide/kimi-k3-quickstart<br />
https://x.com/Kimi_Moonshot/status/2078855608565207130<br />
https://x.com/cramforce/status/2078574147333152957<br />
https://www.blender.org/lab/mcp-server/<br />
https://openrouter.ai/moonshotai/kimi-k3<br />
<br />
Blender Benchmark auf Github: <br />
https://github.com/TheMorpheus407/hogwarts-blender-benchmark<br />
<br />
MorphCook Benchmark auf Github:<br />
https://github.com/TheMorpheus407/morphcook/<br />
<br />
MorphCook:<br />
https://play.google.com/store/apps/details?id=de.themorpheus.morphcook<br />
<br />
Zum MorphReader: <br />
Android: https://play.google.com/store/apps/details?id=de.themorpheus.morph_reader_app<br />
Apple: https://apps.apple.com/de/app/morphreader/id6741467699?platform=iphone<br />
<br />
RSS Feed: https://www.patreon.com/collection/880029?view=expanded<br />
<br />
Instagram: https://www.instagram.com/themorpheustuts/<br />
<br />
Meine anderen Kanäle und Projekte: the-morpheus.de/<br />
<br />
_Selbst *kostenlos Informatik lernen* auf meiner Website:_ https://bootstrap.academy/<br />
<br />
_Discord:_<br />
https://the-morpheus.de/discord.html<br />
<br />
_Unterstützt mich - Danke!:_<br />
https://www.patreon.com/user?u=5322110<br />
https://www.paypal.me/TheMorpheus<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Wie die EU europäische "Unabhängigkeit" vortäuschen will]]></title>
<description><![CDATA[Author: The Morpheus - Bewertung: 59x - Views:615 Der Cloud and AI Development Act: Eine tolle Chance sich wirklich als unabhängig zu vermarkten - obwohl man es vielleicht gar nicht ist.

[Werbung] 
Hier geht's zu unserem Partner, Hostinger: https://www.hostg.xyz/SHJLp
10% Rabatt Code: Morpheus10...]]></description>
<link>https://tsecurity.de/weiterlesen/3653415/3681556/wie-die-eu-europaeische-unabhaengigkeit-vortaeuschen-will/</link>
<pubDate>Mon, 20 Jul 2026 17:21:54 +0200</pubDate>
<category>🎥 Video</category>
<source url="https://tsecurity.de">TSECURITY.DE</source>
<content:encoded><![CDATA[<p>Author: The Morpheus - Bewertung: 59x - Views:615 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/QL9puC7f8uE?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>Der Cloud and AI Development Act: Eine tolle Chance sich wirklich als unabhängig zu vermarkten - obwohl man es vielleicht gar nicht ist.<br />
<br />
[Werbung] <br />
Hier geht's zu unserem Partner, Hostinger: https://www.hostg.xyz/SHJLp<br />
10% Rabatt Code: Morpheus10<br />
<br />
MorphReader im PlayStore: https://play.google.com/store/apps/details?id=de.themorpheus.morph_reader_app&hl=de<br />
<br />
MorphReader im App Store: https://apps.apple.com/de/app/morphreader/id6741467699?platform=iphone<br />
<br />
RSS-Feed: https://www.patreon.com/collection/880029?view=expanded<br />
<br />
Bootstrap Academy: https://bootstrap.academy/<br />
https://github.com/Bootstrap-Academy/<br />
<br />
Instagram: https://www.instagram.com/themorpheustuts/<br />
<br />
Quellen:<br />
https://kdrive.infomaniak.com/app/share/1794086/4326a496-b513-4b19-bf9c-14aed3b92b66<br />
<br />
Meine anderen Kanäle und Projekte: the-morpheus.de/<br />
<br />
_Selbst *kostenlos Informatik lernen* auf meiner Website:_ https://bootstrap.academy/<br />
<br />
_Discord:_<br />
https://the-morpheus.de/discord.html<br />
<br />
_Unterstützt mich - Danke!:_<br />
https://www.patreon.com/user?u=5322110<br />
https://www.paypal.me/TheMorpheus<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Partnerwahl: Das kann man auch an ne KI outsourcen.. oder so #technews]]></title>
<description><![CDATA[Author: The Morpheus - Bewertung: 40x - Views:324]]></description>
<link>https://tsecurity.de/weiterlesen/3648369/3676510/partnerwahl-das-kann-man-auch-an-ne-ki-outsourcen-oder-so-technews/</link>
<pubDate>Fri, 17 Jul 2026 17:40:28 +0200</pubDate>
<category>🎥 Video</category>
<source url="https://tsecurity.de">TSECURITY.DE</source>
<content:encoded><![CDATA[<p>Author: The Morpheus - Bewertung: 40x - Views:324 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/CxETipPyD3g?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p><br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Die Macht der App Stores]]></title>
<description><![CDATA[Author: The Morpheus - Bewertung: 23x - Views:122 Habt ihr euch mal gefragt, warum immer alles über Play Store oder App Store laufen muss?

[Werbung] 
Hier geht's zu unserem Partner Internxt:
https://internxt.com/themorpheus
Spart volle 85% auf den Lifetimeplan mit meinem Code THEMORPHEUS

MorphR...]]></description>
<link>https://tsecurity.de/weiterlesen/3645872/3674013/die-macht-der-app-stores/</link>
<pubDate>Thu, 16 Jul 2026 17:40:48 +0200</pubDate>
<category>🎥 Video</category>
<source url="https://tsecurity.de">TSECURITY.DE</source>
<content:encoded><![CDATA[<p>Author: The Morpheus - Bewertung: 23x - Views:122 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/cHhTPHlPyDI?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>Habt ihr euch mal gefragt, warum immer alles über Play Store oder App Store laufen muss?<br />
<br />
[Werbung] <br />
Hier geht's zu unserem Partner Internxt:<br />
https://internxt.com/themorpheus<br />
Spart volle 85% auf den Lifetimeplan mit meinem Code THEMORPHEUS<br />
<br />
MorphReader im PlayStore: https://play.google.com/store/apps/details?id=de.themorpheus.morph_reader_app&hl=de<br />
<br />
MorphReader im App Store: https://apps.apple.com/de/app/morphreader/id6741467699?platform=iphone<br />
<br />
RSS-Feed: https://www.patreon.com/collection/880029?view=expanded<br />
<br />
Bootstrap Academy: https://bootstrap.academy/<br />
https://github.com/Bootstrap-Academy/<br />
<br />
Instagram: https://www.instagram.com/themorpheustuts/<br />
<br />
Quellen:<br />
https://kdrive.infomaniak.com/app/share/1794086/cb8e96a1-d598-4f6d-944c-a832688b26c2<br />
<br />
Meine anderen Kanäle und Projekte: the-morpheus.de/<br />
<br />
_Selbst *kostenlos Informatik lernen* auf meiner Website:_ https://bootstrap.academy/<br />
<br />
_Discord:_<br />
https://the-morpheus.de/discord.html<br />
<br />
_Unterstützt mich - Danke!:_<br />
https://www.patreon.com/user?u=5322110<br />
https://www.paypal.me/TheMorpheus<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Kein Linux Support? Let me fix that.]]></title>
<description><![CDATA[Author: The Morpheus - Bewertung: 8x - Views:158 (KEINE Werbung)

github.com/TheMorpheus407/g915x-heatmap]]></description>
<link>https://tsecurity.de/weiterlesen/3644904/3673045/kein-linux-support-let-me-fix-that/</link>
<pubDate>Thu, 16 Jul 2026 12:10:39 +0200</pubDate>
<category>🎥 Video</category>
<source url="https://tsecurity.de">TSECURITY.DE</source>
<content:encoded><![CDATA[<p>Author: The Morpheus - Bewertung: 8x - Views:158 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/XihZEE1AtqQ?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>(KEINE Werbung)<br />
<br />
github.com/TheMorpheus407/g915x-heatmap<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Das japanische Hype-KI-Modell (plus ein weiteres) im Test]]></title>
<description><![CDATA[Author: The Morpheus Tutorials - Bewertung: 1x - Views:11 Ein japanisches und ein kleineres open-source Modell.

Aber das erste könnt ihr auch schon nutzen mit unsere
[Werbung]
Partner NordVPN: https://nordvpn.com/morpheus/
Schnappt euch den Deal und holt euch 4 Extra-Monate dazu!

Quellen:
https...]]></description>
<link>https://tsecurity.de/weiterlesen/3640287/3668428/das-japanische-hype-ki-modell-plus-ein-weiteres-im-test/</link>
<pubDate>Tue, 14 Jul 2026 17:08:42 +0200</pubDate>
<category>🎥 Video</category>
<source url="https://tsecurity.de">TSECURITY.DE</source>
<content:encoded><![CDATA[<p>Author: The Morpheus Tutorials - Bewertung: 1x - Views:11 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/-2nmMTeoT68?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>Ein japanisches und ein kleineres open-source Modell.<br />
<br />
Aber das erste könnt ihr auch schon nutzen mit unsere<br />
[Werbung]<br />
Partner NordVPN: https://nordvpn.com/morpheus/<br />
Schnappt euch den Deal und holt euch 4 Extra-Monate dazu!<br />
<br />
Quellen:<br />
https://www.blender.org/lab/mcp-server/<br />
https://openrouter.ai/tencent/hy3<br />
https://hy.tencent.com/research/hy3<br />
https://openrouter.ai/sakana/fugu-ultra<br />
https://sakana.ai/fugu-release/<br />
https://sakana.ai/fugu/<br />
<br />
Blender Benchmark auf Github: <br />
https://github.com/TheMorpheus407/hogwarts-blender-benchmark<br />
<br />
MorphCook:<br />
https://play.google.com/store/apps/details?id=de.themorpheus.morphcook<br />
<br />
Zum MorphReader: <br />
Android: https://play.google.com/store/apps/details?id=de.themorpheus.morph_reader_app<br />
Apple: https://apps.apple.com/de/app/morphreader/id6741467699?platform=iphone<br />
<br />
RSS Feed: https://www.patreon.com/collection/880029?view=expanded<br />
<br />
Instagram: https://www.instagram.com/themorpheustuts/<br />
<br />
Meine anderen Kanäle und Projekte: the-morpheus.de/<br />
<br />
_Selbst *kostenlos Informatik lernen* auf meiner Website:_ https://bootstrap.academy/<br />
<br />
_Discord:_<br />
https://the-morpheus.de/discord.html<br />
<br />
_Unterstützt mich - Danke!:_<br />
https://www.patreon.com/user?u=5322110<br />
https://www.paypal.me/TheMorpheus<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[GPT-5.6 ist also auf "Mythos-Niveau"?]]></title>
<description><![CDATA[Author: The Morpheus Tutorials - Bewertung: 39x - Views:581 GPT-5.6 ist da. Und es ist.. tatsächlich mehr als nur ein Modell.

Quellen:
https://www.blender.org/lab/mcp-server/
https://developers.openai.com/api/docs/pricing
https://openai.com/index/gpt-5-6/

Blender Benchmark auf Github: 
https://...]]></description>
<link>https://tsecurity.de/weiterlesen/3633609/3661750/gpt-56-ist-also-auf-mythos-niveau/</link>
<pubDate>Sat, 11 Jul 2026 13:23:37 +0200</pubDate>
<category>🎥 Video</category>
<source url="https://tsecurity.de">TSECURITY.DE</source>
<content:encoded><![CDATA[<p>Author: The Morpheus Tutorials - Bewertung: 39x - Views:581 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/VrJP9hmh4NQ?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>GPT-5.6 ist da. Und es ist.. tatsächlich mehr als nur ein Modell.<br />
<br />
Quellen:<br />
https://www.blender.org/lab/mcp-server/<br />
https://developers.openai.com/api/docs/pricing<br />
https://openai.com/index/gpt-5-6/<br />
<br />
Blender Benchmark auf Github: <br />
https://github.com/TheMorpheus407/hogwarts-blender-benchmark<br />
<br />
MorphCook Benchmark auf Github:<br />
https://github.com/TheMorpheus407/morphcook/<br />
<br />
MorphCook:<br />
https://play.google.com/store/apps/details?id=de.themorpheus.morphcook<br />
<br />
Zum MorphReader: <br />
Android: https://play.google.com/store/apps/details?id=de.themorpheus.morph_reader_app<br />
Apple: https://apps.apple.com/de/app/morphreader/id6741467699?platform=iphone<br />
<br />
RSS Feed: https://www.patreon.com/collection/880029?view=expanded<br />
<br />
Instagram: https://www.instagram.com/themorpheustuts/<br />
<br />
Meine anderen Kanäle und Projekte: the-morpheus.de/<br />
<br />
_Selbst *kostenlos Informatik lernen* auf meiner Website:_ https://bootstrap.academy/<br />
<br />
_Discord:_<br />
https://the-morpheus.de/discord.html<br />
<br />
_Unterstützt mich - Danke!:_<br />
https://www.patreon.com/user?u=5322110<br />
https://www.paypal.me/TheMorpheus<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Accessibility Committee: July 2026]]></title>
<description><![CDATA[Author: Mozilla Thunderbird - Bewertung: 1x - Views:3 July’s Accessibility Standards & Compliance meeting covered the final accessibility statement update, a discussion on right-sizing design accessibility annotations for implementation, and where accessibility guidance should live across design ...]]></description>
<link>https://tsecurity.de/weiterlesen/3632664/3660805/accessibility-committee-july-2026/</link>
<pubDate>Fri, 10 Jul 2026 22:54:07 +0200</pubDate>
<category>🎥 Video</category>
<source url="https://tsecurity.de">TSECURITY.DE</source>
<content:encoded><![CDATA[<p>Author: Mozilla Thunderbird - Bewertung: 1x - Views:3 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/Qn_qu8-899I?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>July’s Accessibility Standards & Compliance meeting covered the final accessibility statement update, a discussion on right-sizing design accessibility annotations for implementation, and where accessibility guidance should live across design files, design system docs, tickets, and QA. The meeting also included an update on automated accessibility testing progress for Thunderbird Desktop.<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Das wollen die jetzt also noch schnell durchdrücken.. #eu #chatkontrolle]]></title>
<description><![CDATA[Author: The Morpheus - Bewertung: 0x - Views:4]]></description>
<link>https://tsecurity.de/weiterlesen/3626251/3654390/das-wollen-die-jetzt-also-noch-schnell-durchdruecken-eu-chatkontrolle/</link>
<pubDate>Wed, 08 Jul 2026 15:11:07 +0200</pubDate>
<category>🎥 Video</category>
<source url="https://tsecurity.de">TSECURITY.DE</source>
<content:encoded><![CDATA[<p>Author: The Morpheus - Bewertung: 0x - Views:4 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/d629KbzgVew?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p><br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Das wollen die jetzt also noch schnell durchdrücken.. #eu #chatkontrolle]]></title>
<description><![CDATA[Author: The Morpheus - Bewertung: 2x - Views:16]]></description>
<link>https://tsecurity.de/weiterlesen/3625980/3654119/das-wollen-die-jetzt-also-noch-schnell-durchdruecken-eu-chatkontrolle/</link>
<pubDate>Wed, 08 Jul 2026 13:23:31 +0200</pubDate>
<category>🎥 Video</category>
<source url="https://tsecurity.de">TSECURITY.DE</source>
<content:encoded><![CDATA[<p>Author: The Morpheus - Bewertung: 2x - Views:16 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/SVclKyf5PJ0?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p><br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Desktop settings user research findings]]></title>
<description><![CDATA[Author: Mozilla Thunderbird - Bewertung: 3x - Views:16 A quick overview of the insights gathered from interviewing 10 users about how they manage preferences and configurations in Thunderbird desktop. Aly shares the key challenges based on user feedback and design opportunities to guide our next ...]]></description>
<link>https://tsecurity.de/weiterlesen/3624071/3652210/desktop-settings-user-research-findings/</link>
<pubDate>Tue, 07 Jul 2026 18:39:46 +0200</pubDate>
<category>🎥 Video</category>
<source url="https://tsecurity.de">TSECURITY.DE</source>
<content:encoded><![CDATA[<p>Author: Mozilla Thunderbird - Bewertung: 3x - Views:16 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/wFF7Yt-m82o?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>A quick overview of the insights gathered from interviewing 10 users about how they manage preferences and configurations in Thunderbird desktop. Aly shares the key challenges based on user feedback and design opportunities to guide our next phase of work.<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[R.I.P. Blu-Ray. War schön mit dir. #bluray #sony]]></title>
<description><![CDATA[Author: The Morpheus - Bewertung: 39x - Views:1660]]></description>
<link>https://tsecurity.de/weiterlesen/3623390/3651529/rip-blu-ray-war-schoen-mit-dir-bluray-sony/</link>
<pubDate>Tue, 07 Jul 2026 14:40:25 +0200</pubDate>
<category>🎥 Video</category>
<source url="https://tsecurity.de">TSECURITY.DE</source>
<content:encoded><![CDATA[<p>Author: The Morpheus - Bewertung: 39x - Views:1660 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/Ub7kywczE80?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p><br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Ich hab Claude Fable Hogwarts erstellen lassen]]></title>
<description><![CDATA[Author: The Morpheus Tutorials - Bewertung: 50x - Views:592 Uiuiui... brauch ich bald schon wieder einen neuen Test?!

Quellen:
https://www.blender.org/lab/mcp-server/

Blender Benchmark auf Github: 
https://github.com/TheMorpheus407/hogwarts-blender-benchmark

MorphCook:
https://play.google.com/...]]></description>
<link>https://tsecurity.de/weiterlesen/3621501/3649640/ich-hab-claude-fable-hogwarts-erstellen-lassen/</link>
<pubDate>Mon, 06 Jul 2026 20:57:28 +0200</pubDate>
<category>🎥 Video</category>
<source url="https://tsecurity.de">TSECURITY.DE</source>
<content:encoded><![CDATA[<p>Author: The Morpheus Tutorials - Bewertung: 50x - Views:592 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/FqOZvBBPGm0?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>Uiuiui... brauch ich bald schon wieder einen neuen Test?!<br />
<br />
Quellen:<br />
https://www.blender.org/lab/mcp-server/<br />
<br />
Blender Benchmark auf Github: <br />
https://github.com/TheMorpheus407/hogwarts-blender-benchmark<br />
<br />
MorphCook:<br />
https://play.google.com/store/apps/details?id=de.themorpheus.morphcook<br />
<br />
Zum MorphReader: <br />
Android: https://play.google.com/store/apps/details?id=de.themorpheus.morph_reader_app<br />
Apple: https://apps.apple.com/de/app/morphreader/id6741467699?platform=iphone<br />
<br />
RSS Feed: https://www.patreon.com/collection/880029?view=expanded<br />
<br />
Instagram: https://www.instagram.com/themorpheustuts/<br />
<br />
Meine anderen Kanäle und Projekte: the-morpheus.de/<br />
<br />
_Selbst *kostenlos Informatik lernen* auf meiner Website:_ https://bootstrap.academy/<br />
<br />
_Discord:_<br />
https://the-morpheus.de/discord.html<br />
<br />
_Unterstützt mich - Danke!:_<br />
https://www.patreon.com/user?u=5322110<br />
https://www.paypal.me/TheMorpheus<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Warum Valve das Konsolen-Game anders spielt]]></title>
<description><![CDATA[Author: The Morpheus - Bewertung: 31x - Views:518 Valve will 1050 Dollar für die Steam Machine – aber das eigentliche Thema ist größer: SteamOS, Linux-Gaming und warum ihr dieses Gerät wahrscheinlich gar nicht kaufen müsst.

[Werbung] 
Hol dir deine persönlichen Daten mit Incogni zurück! Nutze de...]]></description>
<link>https://tsecurity.de/weiterlesen/3618239/3646378/warum-valve-das-konsolen-game-anders-spielt/</link>
<pubDate>Sun, 05 Jul 2026 09:23:31 +0200</pubDate>
<category>🎥 Video</category>
<source url="https://tsecurity.de">TSECURITY.DE</source>
<content:encoded><![CDATA[<p>Author: The Morpheus - Bewertung: 31x - Views:518 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/b96Ha0cbU-k?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>Valve will 1050 Dollar für die Steam Machine – aber das eigentliche Thema ist größer: SteamOS, Linux-Gaming und warum ihr dieses Gerät wahrscheinlich gar nicht kaufen müsst.<br />
<br />
[Werbung] <br />
Hol dir deine persönlichen Daten mit Incogni zurück! Nutze den Code MORPHEUS über den Link unten und sichere dir 60 % Rabatt auf ein Jahresabo: http://incogni.com/morpheus<br />
<br />
MorphReader im PlayStore: https://play.google.com/store/apps/details?id=de.themorpheus.morph_reader_app&hl=de<br />
<br />
MorphReader im App Store: https://apps.apple.com/de/app/morphreader/id6741467699?platform=iphone<br />
<br />
RSS-Feed: https://www.patreon.com/collection/880029?view=expanded<br />
<br />
Bootstrap Academy: https://bootstrap.academy/<br />
https://github.com/Bootstrap-Academy/<br />
<br />
Instagram: https://www.instagram.com/themorpheustuts/<br />
<br />
Quellen:<br />
https://kdrive.infomaniak.com/app/share/1794086/01c82cda-7931-498c-baf7-cd7ef5436f07<br />
<br />
Meine anderen Kanäle und Projekte: the-morpheus.de/<br />
<br />
_Selbst *kostenlos Informatik lernen* auf meiner Website:_ https://bootstrap.academy/<br />
<br />
_Discord:_<br />
https://the-morpheus.de/discord.html<br />
<br />
_Unterstützt mich - Danke!:_<br />
https://www.patreon.com/user?u=5322110<br />
https://www.paypal.me/TheMorpheus<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Lifehack fürs Smart Home | Werbung]]></title>
<description><![CDATA[Author: The Morpheus - Bewertung: 3x - Views:80 Kauf bei EcoFlow: https://de.ecoflow.com/pages/stream-promotion/?aff=332&utm_source=affiliatly&utm_medium=kol&utm_campaign=26_stream_anniversary_sale  5% Rabatt Code: Morpheus5  Kauf bei Amazon: https://www.amazon.de/stores/page/5E81B685-8E62-43FD-B...]]></description>
<link>https://tsecurity.de/weiterlesen/3615665/3643804/lifehack-fuers-smart-home-werbung/</link>
<pubDate>Fri, 03 Jul 2026 16:38:47 +0200</pubDate>
<category>🎥 Video</category>
<source url="https://tsecurity.de">TSECURITY.DE</source>
<content:encoded><![CDATA[<p>Author: The Morpheus - Bewertung: 3x - Views:80 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/nP_nOs8ZzFA?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>Kauf bei EcoFlow: https://de.ecoflow.com/pages/stream-promotion/?aff=332&utm_source=affiliatly&utm_medium=kol&utm_campaign=26_stream_anniversary_sale  5% Rabatt Code: Morpheus5  Kauf bei Amazon: https://www.amazon.de/stores/page/5E81B685-8E62-43FD-B148-8929D2C6FB69?maas=maas_adg_C22530E3ABA8EF0AF4EA7C8666639415_afap_abs&ref_=aa_maas&tag=maas  5% Rabatt Code: JSKYJCQY<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Community Office Hours: Thundermail Update]]></title>
<description><![CDATA[Author: Mozilla Thunderbird - Bewertung: 0x - Views:3 Welcome to an exciting update about Thundermail, Thunderbird's email service. In this edition, Heather and Monica welcome Sr. Software Engineer Mark Stosberg and Sr. Software Engineer Chris Aquino from the Web Services Team as well as Marketin...]]></description>
<link>https://tsecurity.de/weiterlesen/3611707/3639846/community-office-hours-thundermail-update/</link>
<pubDate>Thu, 02 Jul 2026 00:21:04 +0200</pubDate>
<category>🎥 Video</category>
<source url="https://tsecurity.de">TSECURITY.DE</source>
<content:encoded><![CDATA[<p>Author: Mozilla Thunderbird - Bewertung: 0x - Views:3 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/FS6IcMCJ93s?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>Welcome to an exciting update about Thundermail, Thunderbird's email service. In this edition, Heather and Monica welcome Sr. Software Engineer Mark Stosberg and Sr. Software Engineer Chris Aquino from the Web Services Team as well as Marketing Manager Brian Offredi. We’re discussing the recent updates to the Thundermail service. Learn how this product is developing and discover future plans.<br />
<br />
Resources:<br />
Thundermail support: https://support.tb.pro<br />
Thundermail suggestions and ideas: https://ideas.tb.pro/<br />
Thundermail update blogpost: https://blog.thunderbird.net/2026/06/thundermail-june-2026-update-what-we-learned-after-the-first-few-waves-of-invites/<br />
Services roadmap: https://roadmaps.thunderbird.net/en-US/services/<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Alle Hoffnung auf Open Source #claude #fable #technews]]></title>
<description><![CDATA[Author: The Morpheus - Bewertung: 0x - Views:0]]></description>
<link>https://tsecurity.de/weiterlesen/3611560/3639699/alle-hoffnung-auf-open-source-claude-fable-technews/</link>
<pubDate>Wed, 01 Jul 2026 23:08:53 +0200</pubDate>
<category>🎥 Video</category>
<source url="https://tsecurity.de">TSECURITY.DE</source>
<content:encoded><![CDATA[<p>Author: The Morpheus - Bewertung: 0x - Views:0 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/VD5u8GatNHY?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p><br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Ich habe PewDiePies KI-Plattform getestet...]]></title>
<description><![CDATA[Author: The Morpheus Tutorials - Bewertung: 25x - Views:413 Ein riesiger Hype, aber wie gerechtfertigt ist der?

[Werbung]
Zu unserem Partner Hostinger: https://www.hostg.xyz/SHJdg

Quellen:
https://github.com/pewdiepie-archdaemon/odysseus
https://pewdiepie-archdaemon.github.io/odysseus/

Zum Mor...]]></description>
<link>https://tsecurity.de/weiterlesen/3593431/3621570/ich-habe-pewdiepies-ki-plattform-getestet/</link>
<pubDate>Wed, 24 Jun 2026 15:52:18 +0200</pubDate>
<category>🎥 Video</category>
<source url="https://tsecurity.de">TSECURITY.DE</source>
<content:encoded><![CDATA[<p>Author: The Morpheus Tutorials - Bewertung: 25x - Views:413 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/GnyYICZ7gb8?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>Ein riesiger Hype, aber wie gerechtfertigt ist der?<br />
<br />
[Werbung]<br />
Zu unserem Partner Hostinger: https://www.hostg.xyz/SHJdg<br />
<br />
Quellen:<br />
https://github.com/pewdiepie-archdaemon/odysseus<br />
https://pewdiepie-archdaemon.github.io/odysseus/<br />
<br />
Zum MorphReader: <br />
Android: https://play.google.com/store/apps/details?id=de.themorpheus.morph_reader_app<br />
Apple: https://apps.apple.com/de/app/morphreader/id6741467699?platform=iphone<br />
<br />
RSS Feed: https://www.patreon.com/collection/880029?view=expanded<br />
<br />
Instagram: https://www.instagram.com/themorpheustuts/<br />
<br />
Meine anderen Kanäle und Projekte: the-morpheus.de/<br />
<br />
_Selbst *kostenlos Informatik lernen* auf meiner Website:_ https://bootstrap.academy/<br />
<br />
_Discord:_<br />
https://the-morpheus.de/discord.html<br />
<br />
_Unterstützt mich - Danke!:_<br />
https://www.patreon.com/user?u=5322110<br />
https://www.paypal.me/TheMorpheus<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[GSM-R: Meine Bingokarte ist mal wieder voll. #technews #cybersecurity #bahn]]></title>
<description><![CDATA[Author: The Morpheus - Bewertung: 2x - Views:64]]></description>
<link>https://tsecurity.de/weiterlesen/3593127/3621266/gsm-r-meine-bingokarte-ist-mal-wieder-voll-technews-cybersecurity-bahn/</link>
<pubDate>Wed, 24 Jun 2026 14:09:32 +0200</pubDate>
<category>🎥 Video</category>
<source url="https://tsecurity.de">TSECURITY.DE</source>
<content:encoded><![CDATA[<p>Author: The Morpheus - Bewertung: 2x - Views:64 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/pnn4inwVx6g?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p><br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Ich hab mein NAS zum Heimserver gemacht]]></title>
<description><![CDATA[Author: The Morpheus - Bewertung: 162x - Views:1678 Lokale Filme, Bilder und Dokumente. Aber wie lokal ist es am Ende wirklich?

[Werbung] 
Spare bis zu 400€ im NAS Sommer-Sale:
#UGREEN #UGREENNAS

*Offizielle Website*
UGREEN NAS collection: https://nas.de.ugreen.com/TO8q9M
UGREEN NAS DXP4800 Pro...]]></description>
<link>https://tsecurity.de/weiterlesen/3590644/3618783/ich-hab-mein-nas-zum-heimserver-gemacht/</link>
<pubDate>Tue, 23 Jun 2026 17:41:12 +0200</pubDate>
<category>🎥 Video</category>
<source url="https://tsecurity.de">TSECURITY.DE</source>
<content:encoded><![CDATA[<p>Author: The Morpheus - Bewertung: 162x - Views:1678 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/fack-jOGeOM?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>Lokale Filme, Bilder und Dokumente. Aber wie lokal ist es am Ende wirklich?<br />
<br />
[Werbung] <br />
Spare bis zu 400€ im NAS Sommer-Sale:<br />
#UGREEN #UGREENNAS<br />
<br />
*Offizielle Website*<br />
UGREEN NAS collection: https://nas.de.ugreen.com/TO8q9M<br />
UGREEN NAS DXP4800 Pro: https://nas.de.ugreen.com/Z0Jxs9<br />
<br />
*Amazon*<br />
UGREEN NAS collection: https://bit.ly/43LlDKX<br />
UGREEN NAS DXP4800 Pro: https://bit.ly/4vp1CG7<br />
<br />
Docker Files:<br />
Nextcloud: https://kdrive.infomaniak.com/app/share/1794086/75faafa6-73c0-4627-bf91-156e1844ec26<br />
Immich: https://kdrive.infomaniak.com/app/share/1794086/18e20883-f9ee-45d5-8e35-e41a0c3d7310<br />
JellyFin war direkt installiert. Bitte denkt daran die Passwörter/Nutzernamen zu ändern, die Ordner müssen auch vorher erstellt werden, sonst kriegt man einen Fehler. Und falls ihr das Video in der Zukunft guckt: Schau obs Updates gibt!<br />
<br />
MorphReader im PlayStore: https://play.google.com/store/apps/details?id=de.themorpheus.morph_reader_app&hl=de<br />
<br />
MorphReader im App Store: https://apps.apple.com/de/app/morphreader/id6741467699?platform=iphone<br />
<br />
RSS-Feed: https://www.patreon.com/collection/880029?view=expanded<br />
<br />
Bootstrap Academy: https://bootstrap.academy/<br />
https://github.com/Bootstrap-Academy/<br />
<br />
Instagram: https://www.instagram.com/themorpheustuts/<br />
<br />
Quellen:<br />
https://kdrive.infomaniak.com/app/share/1794086/c22a70aa-bd80-40f3-9f30-45f2d99c7da0<br />
<br />
Meine anderen Kanäle und Projekte: the-morpheus.de/<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Für diese Linux-Distribution siehts grade nicht so gut aus.. #technews #linux #cybersecurity]]></title>
<description><![CDATA[Author: The Morpheus - Bewertung: 5x - Views:106]]></description>
<link>https://tsecurity.de/weiterlesen/3587537/3615676/fuer-diese-linux-distribution-siehts-grade-nicht-so-gut-aus-technews-linux-cybersecurity/</link>
<pubDate>Mon, 22 Jun 2026 15:56:10 +0200</pubDate>
<category>🎥 Video</category>
<source url="https://tsecurity.de">TSECURITY.DE</source>
<content:encoded><![CDATA[<p>Author: The Morpheus - Bewertung: 5x - Views:106 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/SAF5T4gSvEQ?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p><br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Eine Open-Source KI soll's mit Claude Fable aufnehmen?]]></title>
<description><![CDATA[Author: The Morpheus Tutorials - Bewertung: 18x - Views:164 Laut Design Benchmark soll GLM5.2 besser sein als Fable in manchen Bereichen. Mal sehen ob ich das bestätigen kann.

Quellen:
https://huggingface.co/zai-org/GLM-5.2
https://huggingface.co/moonshotai/Kimi-K2.7-Code
https://openrouter.ai/z...]]></description>
<link>https://tsecurity.de/weiterlesen/3582320/3610459/eine-open-source-ki-solls-mit-claude-fable-aufnehmen/</link>
<pubDate>Fri, 19 Jun 2026 15:10:48 +0200</pubDate>
<category>🎥 Video</category>
<source url="https://tsecurity.de">TSECURITY.DE</source>
<content:encoded><![CDATA[<p>Author: The Morpheus Tutorials - Bewertung: 18x - Views:164 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/HyDEzJztjpk?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>Laut Design Benchmark soll GLM5.2 besser sein als Fable in manchen Bereichen. Mal sehen ob ich das bestätigen kann.<br />
<br />
Quellen:<br />
https://huggingface.co/zai-org/GLM-5.2<br />
https://huggingface.co/moonshotai/Kimi-K2.7-Code<br />
https://openrouter.ai/z-ai/glm-5.2<br />
https://openrouter.ai/moonshotai/kimi-k2.7-code<br />
https://x.com/jietang/status/2067580270078030088<br />
https://www.designarena.ai/leaderboard<br />
<br />
MorphCook Code:<br />
https://github.com/TheMorpheus407/morphcook/commit/a89e68e57d94ddbe4174f684e5135df985fbd522<br />
<br />
Zum MorphReader: <br />
Android: https://play.google.com/store/apps/details?id=de.themorpheus.morph_reader_app<br />
Apple: https://apps.apple.com/de/app/morphreader/id6741467699?platform=iphone<br />
<br />
RSS Feed: https://www.patreon.com/collection/880029?view=expanded<br />
<br />
Instagram: https://www.instagram.com/themorpheustuts/<br />
<br />
Meine anderen Kanäle und Projekte: the-morpheus.de/<br />
<br />
_Selbst *kostenlos Informatik lernen* auf meiner Website:_ https://bootstrap.academy/<br />
<br />
_Discord:_<br />
https://the-morpheus.de/discord.html<br />
<br />
_Unterstützt mich - Danke!:_<br />
https://www.patreon.com/user?u=5322110<br />
https://www.paypal.me/TheMorpheus<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Verlass dich nicht auf Schrödingers Backup | Werbung]]></title>
<description><![CDATA[Author: The Morpheus - Bewertung: 6x - Views:140 Hol dir jetzt Swiss Backup von Infomaniak 20% günstiger mit meinem Code. 
Link: https://www.infomaniak.com/de/swiss-backup?utm_source=youtube&utm_medium=social&utm_campaign=themorpheusvlogs&utm_content=swiss-backup&utm_term=66851608428ed]]></description>
<link>https://tsecurity.de/weiterlesen/3580117/3608256/verlass-dich-nicht-auf-schroedingers-backup-werbung/</link>
<pubDate>Thu, 18 Jun 2026 17:27:33 +0200</pubDate>
<category>🎥 Video</category>
<source url="https://tsecurity.de">TSECURITY.DE</source>
<content:encoded><![CDATA[<p>Author: The Morpheus - Bewertung: 6x - Views:140 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/Acn9MZGv1sA?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>Hol dir jetzt Swiss Backup von Infomaniak 20% günstiger mit meinem Code. <br />
Link: https://www.infomaniak.com/de/swiss-backup?utm_source=youtube&utm_medium=social&utm_campaign=themorpheusvlogs&utm_content=swiss-backup&utm_term=66851608428ed<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Wie können wir dem Internet wieder vertrauen?]]></title>
<description><![CDATA[Author: The Morpheus - Bewertung: 149x - Views:1631 Fakes sind immer mehr im Umlauf. Aber es gibt auch Technologien, die genau darauf aus sind, die zu erkennen - kryptographisch.

[Werbung] 
Hier geht's zu unserem Partner, Notebooksbilliger:
https://www.notebooksbilliger.de?nbbct=1004_morpheus_bw...]]></description>
<link>https://tsecurity.de/weiterlesen/3580068/3608207/wie-koennen-wir-dem-internet-wieder-vertrauen/</link>
<pubDate>Thu, 18 Jun 2026 17:18:05 +0200</pubDate>
<category>🎥 Video</category>
<source url="https://tsecurity.de">TSECURITY.DE</source>
<content:encoded><![CDATA[<p>Author: The Morpheus - Bewertung: 149x - Views:1631 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/_YI4HaWfnhA?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>Fakes sind immer mehr im Umlauf. Aber es gibt auch Technologien, die genau darauf aus sind, die zu erkennen - kryptographisch.<br />
<br />
[Werbung] <br />
Hier geht's zu unserem Partner, Notebooksbilliger:<br />
https://www.notebooksbilliger.de?nbbct=1004_morpheus_bw-q2-26<br />
<br />
MorphReader im PlayStore: https://play.google.com/store/apps/details?id=de.themorpheus.morph_reader_app&hl=de<br />
<br />
MorphReader im App Store: https://apps.apple.com/de/app/morphreader/id6741467699?platform=iphone<br />
<br />
RSS-Feed: https://www.patreon.com/collection/880029?view=expanded<br />
<br />
Bootstrap Academy: https://bootstrap.academy/<br />
https://github.com/Bootstrap-Academy/<br />
<br />
Instagram: https://www.instagram.com/themorpheustuts/<br />
<br />
Quellen:<br />
https://kdrive.infomaniak.com/app/share/1794086/c22a70aa-bd80-40f3-9f30-45f2d99c7da0<br />
<br />
Meine anderen Kanäle und Projekte: the-morpheus.de/<br />
<br />
_Selbst *kostenlos Informatik lernen* auf meiner Website:_ https://bootstrap.academy/<br />
<br />
_Discord:_<br />
https://the-morpheus.de/discord.html<br />
<br />
_Unterstützt mich - Danke!:_<br />
https://www.patreon.com/user?u=5322110<br />
https://www.paypal.me/TheMorpheus<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Das Thema ist irgendwie deeper als gedacht.. #unicode #emoji]]></title>
<description><![CDATA[Author: The Morpheus - Bewertung: 20x - Views:480]]></description>
<link>https://tsecurity.de/weiterlesen/3577243/3605382/das-thema-ist-irgendwie-deeper-als-gedacht-unicode-emoji/</link>
<pubDate>Wed, 17 Jun 2026 17:56:19 +0200</pubDate>
<category>🎥 Video</category>
<source url="https://tsecurity.de">TSECURITY.DE</source>
<content:encoded><![CDATA[<p>Author: The Morpheus - Bewertung: 20x - Views:480 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/ae20qgxvHaY?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p><br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Warum die Sperre von Claude Fable vorhersehbar war]]></title>
<description><![CDATA[Author: The Morpheus - Bewertung: 42x - Views:337 Fable 5 und dazu auch Mythos 5 wurden offline genommen. Von der US-Regierung.

[Werbung] 
Hier geht's zu unserem Partner, Plaud: 
Plaud Note Pro
https://bit.ly/3PQyHLr
https://amzn.to/4u19
15% Rabattcode: MORPHEUS15
Plaud Note: https://amzn.to/4nQ...]]></description>
<link>https://tsecurity.de/weiterlesen/3574534/3602673/warum-die-sperre-von-claude-fable-vorhersehbar-war/</link>
<pubDate>Tue, 16 Jun 2026 19:09:39 +0200</pubDate>
<category>🎥 Video</category>
<source url="https://tsecurity.de">TSECURITY.DE</source>
<content:encoded><![CDATA[<p>Author: The Morpheus - Bewertung: 42x - Views:337 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/mtNbPExBe_Y?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>Fable 5 und dazu auch Mythos 5 wurden offline genommen. Von der US-Regierung.<br />
<br />
[Werbung] <br />
Hier geht's zu unserem Partner, Plaud: <br />
Plaud Note Pro<br />
https://bit.ly/3PQyHLr<br />
https://amzn.to/4u19<br />
15% Rabattcode: MORPHEUS15<br />
Plaud Note: https://amzn.to/4nQO4A5<br />
<br />
MorphReader im PlayStore: https://play.google.com/store/apps/details?id=de.themorpheus.morph_reader_app&hl=de<br />
<br />
MorphReader im App Store: https://apps.apple.com/de/app/morphreader/id6741467699?platform=iphone<br />
<br />
RSS-Feed: https://www.patreon.com/collection/880029?view=expanded<br />
<br />
Bootstrap Academy: https://bootstrap.academy/<br />
https://github.com/Bootstrap-Academy/<br />
<br />
Instagram: https://www.instagram.com/themorpheustuts/<br />
<br />
Quellen:<br />
https://kdrive.infomaniak.com/app/share/1794086/3e626bef-fef9-4f79-abf6-196a74a298f0<br />
<br />
Meine anderen Kanäle und Projekte: the-morpheus.de/<br />
<br />
_Selbst *kostenlos Informatik lernen* auf meiner Website:_ https://bootstrap.academy/<br />
<br />
_Discord:_<br />
https://the-morpheus.de/discord.html<br />
<br />
_Unterstützt mich - Danke!:_<br />
https://www.patreon.com/user?u=5322110<br />
https://www.paypal.me/TheMorpheus<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Ich hab Claude Code Remote getestet  - auf einem Server]]></title>
<description><![CDATA[Author: The Morpheus Tutorials - Bewertung: 5x - Views:44 Ich hab Claude Code Remote getestet, auf einem Production Server... und bin ziemlich begeistert.

[Werbung]
Hier geht's zu unserem Partner Hostinger: https://www.hostg.xyz/SHJc1

Zum MorphReader: 
Android: https://play.google.com/store/app...]]></description>
<link>https://tsecurity.de/weiterlesen/3571520/3599659/ich-hab-claude-code-remote-getestet-auf-einem-server/</link>
<pubDate>Mon, 15 Jun 2026 18:03:54 +0200</pubDate>
<category>🎥 Video</category>
<source url="https://tsecurity.de">TSECURITY.DE</source>
<content:encoded><![CDATA[<p>Author: The Morpheus Tutorials - Bewertung: 5x - Views:44 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/-p0i4M4Z4Yo?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>Ich hab Claude Code Remote getestet, auf einem Production Server... und bin ziemlich begeistert.<br />
<br />
[Werbung]<br />
Hier geht's zu unserem Partner Hostinger: https://www.hostg.xyz/SHJc1<br />
<br />
Zum MorphReader: <br />
Android: https://play.google.com/store/apps/details?id=de.themorpheus.morph_reader_app<br />
Apple: https://apps.apple.com/de/app/morphreader/id6741467699?platform=iphone<br />
<br />
RSS Feed: https://www.patreon.com/collection/880029?view=expanded<br />
<br />
Instagram: https://www.instagram.com/themorpheustuts/<br />
<br />
Meine anderen Kanäle und Projekte: the-morpheus.de/<br />
<br />
_Selbst *kostenlos Informatik lernen* auf meiner Website:_ https://bootstrap.academy/<br />
<br />
_Discord:_<br />
https://the-morpheus.de/discord.html<br />
<br />
_Unterstützt mich - Danke!:_<br />
https://www.patreon.com/user?u=5322110<br />
https://www.paypal.me/TheMorpheus<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Youtube zwingt mich dazu]]></title>
<description><![CDATA[Author: The Morpheus - Bewertung: 68x - Views:546 Warum fühlen sich soziale Netzwerke heute so kaputt an — und gibt es eine echte Alternative zu Instagram, TikTok, YouTube und X? In diesem Video geht es um Algorithmen, Abhängigkeit, Creator-Druck und das Fediverse: ein offenes Netz aus Mastodon, ...]]></description>
<link>https://tsecurity.de/weiterlesen/3562859/3590995/youtube-zwingt-mich-dazu/</link>
<pubDate>Thu, 11 Jun 2026 17:11:16 +0200</pubDate>
<category>🎥 Video</category>
<source url="https://tsecurity.de">TSECURITY.DE</source>
<content:encoded><![CDATA[<p>Author: The Morpheus - Bewertung: 68x - Views:546 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/Ux-xNuapyGc?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>Warum fühlen sich soziale Netzwerke heute so kaputt an — und gibt es eine echte Alternative zu Instagram, TikTok, YouTube und X? In diesem Video geht es um Algorithmen, Abhängigkeit, Creator-Druck und das Fediverse: ein offenes Netz aus Mastodon, PeerTube, Lemmy, Pixelfed und mehr. Ich zeige, warum eigene Server mehr digitale Unabhängigkeit versprechen, wo das System noch scheitert und was es wirklich kostet, Social Media wieder selbst zu besitzen.<br />
<br />
[Werbung] <br />
Hier geht's zu unserem Partner, Hostinger: https://www.hostg.xyz/SHJLp<br />
10% Rabatt Code: Morpheus10<br />
<br />
MorphReader im PlayStore: https://play.google.com/store/apps/details?id=de.themorpheus.morph_reader_app&hl=de<br />
<br />
MorphReader im App Store: https://apps.apple.com/de/app/morphreader/id6741467699?platform=iphone<br />
<br />
RSS-Feed: https://www.patreon.com/collection/880029?view=expanded<br />
<br />
Bootstrap Academy: https://bootstrap.academy/<br />
https://github.com/Bootstrap-Academy/<br />
<br />
Instagram: https://www.instagram.com/themorpheustuts/<br />
<br />
Quellen:<br />
https://kdrive.infomaniak.com/app/share/1794086/d7cff06c-7daf-4929-af81-c0466e73ed9d<br />
<br />
Meine anderen Kanäle und Projekte: the-morpheus.de/<br />
<br />
_Selbst *kostenlos Informatik lernen* auf meiner Website:_ https://bootstrap.academy/<br />
<br />
_Discord:_<br />
https://the-morpheus.de/discord.html<br />
<br />
_Unterstützt mich - Danke!:_<br />
https://www.patreon.com/user?u=5322110<br />
https://www.paypal.me/TheMorpheus<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Fable 5: Claude Mythos mit Lobotomie ist ÖFFENTLICH]]></title>
<description><![CDATA[Author: The Morpheus Tutorials - Bewertung: 50x - Views:569 Claude Fable ist da.. und hat da was ziemlich heftiges geschafft.
MorphCook als Benchmark hat schon wieder ausgedient. Dafür ist die App wie versprochen  in der Review bei Google. Ihr könnt euch hier als Beta-Tester registrieren:  https:...]]></description>
<link>https://tsecurity.de/weiterlesen/3559640/3587776/fable-5-claude-mythos-mit-lobotomie-ist-oeffentlich/</link>
<pubDate>Wed, 10 Jun 2026 15:25:46 +0200</pubDate>
<category>🎥 Video</category>
<source url="https://tsecurity.de">TSECURITY.DE</source>
<content:encoded><![CDATA[<p>Author: The Morpheus Tutorials - Bewertung: 50x - Views:569 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/8suOFhGIElI?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>Claude Fable ist da.. und hat da was ziemlich heftiges geschafft.<br />
MorphCook als Benchmark hat schon wieder ausgedient. Dafür ist die App wie versprochen  in der Review bei Google. Ihr könnt euch hier als Beta-Tester registrieren:  https://docs.google.com/forms/d/e/1FAIpQLSe08vnZzsiFRfYQuH9xR6JyZ1JRcTfcJjLepe-4rBUJVcn4Ag/viewform?usp=publish-editor<br />
<br />
Repo ist hier: https://github.com/TheMorpheus407/morphcook<br />
<br />
Zum MorphReader: <br />
Android: https://play.google.com/store/apps/details?id=de.themorpheus.morph_reader_app<br />
Apple: https://apps.apple.com/de/app/morphreader/id6741467699?platform=iphone<br />
<br />
RSS Feed: https://www.patreon.com/collection/880029?view=expanded<br />
<br />
Instagram: https://www.instagram.com/themorpheustuts/<br />
<br />
Meine anderen Kanäle und Projekte: the-morpheus.de/<br />
<br />
_Selbst *kostenlos Informatik lernen* auf meiner Website:_ https://bootstrap.academy/<br />
<br />
_Discord:_<br />
https://the-morpheus.de/discord.html<br />
<br />
_Unterstützt mich - Danke!:_<br />
https://www.patreon.com/user?u=5322110<br />
https://www.paypal.me/TheMorpheus<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Ich habs mal für euch ausprobiert... #tech #chatgpt #ai]]></title>
<description><![CDATA[Author: The Morpheus - Bewertung: 19x - Views:447]]></description>
<link>https://tsecurity.de/weiterlesen/3554072/3582208/ich-habs-mal-fuer-euch-ausprobiert-tech-chatgpt-ai/</link>
<pubDate>Mon, 08 Jun 2026 19:10:40 +0200</pubDate>
<category>🎥 Video</category>
<source url="https://tsecurity.de">TSECURITY.DE</source>
<content:encoded><![CDATA[<p>Author: The Morpheus - Bewertung: 19x - Views:447 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/Og12uPxZFGM?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p><br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Ich musste das einfach ausrechnen. Sorry dafür. #tech #ai]]></title>
<description><![CDATA[Author: The Morpheus - Bewertung: 43x - Views:2135]]></description>
<link>https://tsecurity.de/weiterlesen/3547715/3575851/ich-musste-das-einfach-ausrechnen-sorry-dafuer-tech-ai/</link>
<pubDate>Fri, 05 Jun 2026 17:40:47 +0200</pubDate>
<category>🎥 Video</category>
<source url="https://tsecurity.de">TSECURITY.DE</source>
<content:encoded><![CDATA[<p>Author: The Morpheus - Bewertung: 43x - Views:2135 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/4tG8kJh2RDw?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p><br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Der PREIS-Unterschied: Opus 4.8 & MiniMax M3 zum Coden]]></title>
<description><![CDATA[Author: The Morpheus Tutorials - Bewertung: 12x - Views:173 Opus 4.8 und MiniMax M3 sind draußen und ich

Zum MorphReader: 
Android: https://play.google.com/store/apps/details?id=de.themorpheus.morph_reader_app
Apple: https://apps.apple.com/de/app/morphreader/id6741467699?platform=iphone

RSS Fee...]]></description>
<link>https://tsecurity.de/weiterlesen/3541699/3569835/der-preis-unterschied-opus-48-minimax-m3-zum-coden/</link>
<pubDate>Wed, 03 Jun 2026 15:51:12 +0200</pubDate>
<category>🎥 Video</category>
<source url="https://tsecurity.de">TSECURITY.DE</source>
<content:encoded><![CDATA[<p>Author: The Morpheus Tutorials - Bewertung: 12x - Views:173 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/-f3-WUw-jsQ?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>Opus 4.8 und MiniMax M3 sind draußen und ich<br />
<br />
Zum MorphReader: <br />
Android: https://play.google.com/store/apps/details?id=de.themorpheus.morph_reader_app<br />
Apple: https://apps.apple.com/de/app/morphreader/id6741467699?platform=iphone<br />
<br />
RSS Feed: https://www.patreon.com/collection/880029?view=expanded<br />
<br />
Instagram: https://www.instagram.com/themorpheustuts/<br />
<br />
Meine anderen Kanäle und Projekte: the-morpheus.de/<br />
<br />
_Selbst *kostenlos Informatik lernen* auf meiner Website:_ https://bootstrap.academy/<br />
<br />
_Discord:_<br />
https://the-morpheus.de/discord.html<br />
<br />
_Unterstützt mich - Danke!:_<br />
https://www.patreon.com/user?u=5322110<br />
https://www.paypal.me/TheMorpheus<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Accessibility Committee: June 2026]]></title>
<description><![CDATA[Author: Mozilla Thunderbird - Bewertung: 0x - Views:0 The June Accessibility Committee meeting covered progress on automated testing (desktop), updates to the Thunderbird Accessibility Statement, and new community accessibility audits on Desktop Settings and Search. The group also discussed makin...]]></description>
<link>https://tsecurity.de/weiterlesen/3539520/3567656/accessibility-committee-june-2026/</link>
<pubDate>Tue, 02 Jun 2026 23:24:17 +0200</pubDate>
<category>🎥 Video</category>
<source url="https://tsecurity.de">TSECURITY.DE</source>
<content:encoded><![CDATA[<p>Author: Mozilla Thunderbird - Bewertung: 0x - Views:0 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/l_F5QJ0xEsM?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>The June Accessibility Committee meeting covered progress on automated testing (desktop), updates to the Thunderbird Accessibility Statement, and new community accessibility audits on Desktop Settings and Search. The group also discussed making gesture and keyboard navigation accessible across devices, improving developer guidance and QA testing, and noted that Thunderbird Add-ons site modernization is tentatively planned for the 2027 services roadmap.<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Spiegelung ist immer so unvorteilhaft.]]></title>
<description><![CDATA[Author: The Morpheus - Bewertung: 5x - Views:166 Werbung | Hier gehts zum Monitor von BenQ: https://bit.ly/4uM5Fve]]></description>
<link>https://tsecurity.de/weiterlesen/3537684/3565820/spiegelung-ist-immer-so-unvorteilhaft/</link>
<pubDate>Tue, 02 Jun 2026 13:09:01 +0200</pubDate>
<category>🎥 Video</category>
<source url="https://tsecurity.de">TSECURITY.DE</source>
<content:encoded><![CDATA[<p>Author: The Morpheus - Bewertung: 5x - Views:166 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/hWUyS8byY1A?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>Werbung | Hier gehts zum Monitor von BenQ: https://bit.ly/4uM5Fve<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Design System Governance Committee: April 2026]]></title>
<description><![CDATA[Author: Mozilla Thunderbird - Bewertung: 0x - Views:0 In April, the Design System committee continued work on tokens, JSON export, documentation, accessibility guidance, and public release planning, while also discussing changelog structure, versioning, Bolt identity ideas, and ways to grow the c...]]></description>
<link>https://tsecurity.de/weiterlesen/3524101/3552237/design-system-governance-committee-april-2026/</link>
<pubDate>Wed, 27 May 2026 21:08:31 +0200</pubDate>
<category>🎥 Video</category>
<source url="https://tsecurity.de">TSECURITY.DE</source>
<content:encoded><![CDATA[<p>Author: Mozilla Thunderbird - Bewertung: 0x - Views:0 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/2kuFYzPa4nU?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>In April, the Design System committee continued work on tokens, JSON export, documentation, accessibility guidance, and public release planning, while also discussing changelog structure, versioning, Bolt identity ideas, and ways to grow the community. There is an open seat for a community member. If you are interested send a msg in our matrix channel: Bolt Design System: https://matrix.to/#/#bolt-design-system:mozilla.org<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Design System Governance Committee: March 2026]]></title>
<description><![CDATA[Author: Mozilla Thunderbird - Bewertung: 0x - Views:3 This month, the committee shares updates on accent colours in desktop, design system process, documentation, and how we might handle public releases and versioning. A few items are still moving slowly because of other priorities, but there is ...]]></description>
<link>https://tsecurity.de/weiterlesen/3524075/3552211/design-system-governance-committee-march-2026/</link>
<pubDate>Wed, 27 May 2026 20:54:16 +0200</pubDate>
<category>🎥 Video</category>
<source url="https://tsecurity.de">TSECURITY.DE</source>
<content:encoded><![CDATA[<p>Author: Mozilla Thunderbird - Bewertung: 0x - Views:3 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/bqXVtxOXDEA?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>This month, the committee shares updates on accent colours in desktop, design system process, documentation, and how we might handle public releases and versioning. A few items are still moving slowly because of other priorities, but there is progress in areas like governance research and planning next steps.<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Accessibility Committee: March 2026]]></title>
<description><![CDATA[Author: Mozilla Thunderbird - Bewertung: 1x - Views:3 The March accessibility meeting focused on progress across our accessibility statement, guidelines, testing, and success metrics, while also identifying gaps in automation, documentation, and user feedback. We also discussed how to better supp...]]></description>
<link>https://tsecurity.de/weiterlesen/3524074/3552210/accessibility-committee-march-2026/</link>
<pubDate>Wed, 27 May 2026 20:54:15 +0200</pubDate>
<category>🎥 Video</category>
<source url="https://tsecurity.de">TSECURITY.DE</source>
<content:encoded><![CDATA[<p>Author: Mozilla Thunderbird - Bewertung: 1x - Views:3 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/iCOIUVbobFI?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>The March accessibility meeting focused on progress across our accessibility statement, guidelines, testing, and success metrics, while also identifying gaps in automation, documentation, and user feedback. We also discussed how to better support and involve the community so our accessibility work is informed, practical, and visible across all Thunderbird experiences.<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Accessibility Committee: April 2026]]></title>
<description><![CDATA[Author: Mozilla Thunderbird - Bewertung: 0x - Views:2 The April accessibility meeting focused on improving the draft accessibility statement, planning the structure of the new guidelines, and discussing where this work should be shared so it reaches both contributors and the wider community. We a...]]></description>
<link>https://tsecurity.de/weiterlesen/3524073/3552209/accessibility-committee-april-2026/</link>
<pubDate>Wed, 27 May 2026 20:54:14 +0200</pubDate>
<category>🎥 Video</category>
<source url="https://tsecurity.de">TSECURITY.DE</source>
<content:encoded><![CDATA[<p>Author: Mozilla Thunderbird - Bewertung: 0x - Views:2 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/MLgq9mfS61I?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>The April accessibility meeting focused on improving the draft accessibility statement, planning the structure of the new guidelines, and discussing where this work should be shared so it reaches both contributors and the wider community. We also explored ways to build stronger accessibility connections through community spaces and outlined a few clear next steps for feedback and follow-up.<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Warum Software in einer Krise steckt]]></title>
<description><![CDATA[Author: The Morpheus - Bewertung: 89x - Views:1136 Open Source trägt unsere digitale Welt – doch KI, Burnout, fehlende Finanzierung und neue Sicherheitsrisiken bringen dieses Fundament zunehmend ins Wanken.

[Werbung] 
Hier geht's zu unserem Partner, EcoFlow:
Kauf bei EcoFlow: https://de.ecoflow....]]></description>
<link>https://tsecurity.de/weiterlesen/3515725/3543861/warum-software-in-einer-krise-steckt/</link>
<pubDate>Sun, 24 May 2026 18:10:57 +0200</pubDate>
<category>🎥 Video</category>
<source url="https://tsecurity.de">TSECURITY.DE</source>
<content:encoded><![CDATA[<p>Author: The Morpheus - Bewertung: 89x - Views:1136 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/yi1QiqlB1Q4?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>Open Source trägt unsere digitale Welt – doch KI, Burnout, fehlende Finanzierung und neue Sicherheitsrisiken bringen dieses Fundament zunehmend ins Wanken.<br />
<br />
[Werbung] <br />
Hier geht's zu unserem Partner, EcoFlow:<br />
Kauf bei EcoFlow: https://de.ecoflow.com/pages/stream-promotion/?aff=332&utm_source=affiliatly&utm_medium=kol&utm_campaign=26_stream_anniversary_sale<br />
5% Rabatt Code: Morpheus5<br />
<br />
Kauf bei Amazon: https://www.amazon.de/stores/page/5E81B685-8E62-43FD-B148-8929D2C6FB69?maas=maas_adg_C22530E3ABA8EF0AF4EA7C8666639415_afap_abs&ref_=aa_maas&tag=maas<br />
5% Rabatt Code: JSKYJCQY<br />
<br />
MorphReader im PlayStore: https://play.google.com/store/apps/details?id=de.themorpheus.morph_reader_app&hl=de<br />
<br />
MorphReader im App Store: https://apps.apple.com/de/app/morphreader/id6741467699?platform=iphone<br />
<br />
RSS-Feed: https://www.patreon.com/collection/880029?view=expanded<br />
<br />
Bootstrap Academy: https://bootstrap.academy/<br />
https://github.com/Bootstrap-Academy/<br />
<br />
Instagram: https://www.instagram.com/themorpheustuts/<br />
<br />
Quellen:<br />
https://kdrive.infomaniak.com/app/share/1794086/dd37d0fb-a5a3-4013-8ef3-31a4a187e3f5<br />
<br />
Meine anderen Kanäle und Projekte: the-morpheus.de/<br />
<br />
_Selbst *kostenlos Informatik lernen* auf meiner Website:_ https://bootstrap.academy/<br />
<br />
_Discord:_<br />
https://the-morpheus.de/discord.html<br />
<br />
_Unterstützt mich - Danke!:_<br />
https://www.patreon.com/user?u=5322110<br />
https://www.paypal.me/TheMorpheus<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Google I/O: Programmieren mit Gemini 3.5 Flash?]]></title>
<description><![CDATA[Author: The Morpheus Tutorials - Bewertung: 38x - Views:405 Gemini 3.5 Flash im Coding-Test: Wie teuer ist es, was kann es und wie schnell ist es?

Zum MorphReader: 
Android: https://play.google.com/store/apps/details?id=de.themorpheus.morph_reader_app
Apple: https://apps.apple.com/de/app/morphre...]]></description>
<link>https://tsecurity.de/weiterlesen/3508695/3536831/google-io-programmieren-mit-gemini-35-flash/</link>
<pubDate>Thu, 21 May 2026 16:53:00 +0200</pubDate>
<category>🎥 Video</category>
<source url="https://tsecurity.de">TSECURITY.DE</source>
<content:encoded><![CDATA[<p>Author: The Morpheus Tutorials - Bewertung: 38x - Views:405 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/ZIpkJjQy4Kg?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>Gemini 3.5 Flash im Coding-Test: Wie teuer ist es, was kann es und wie schnell ist es?<br />
<br />
Zum MorphReader: <br />
Android: https://play.google.com/store/apps/details?id=de.themorpheus.morph_reader_app<br />
Apple: https://apps.apple.com/de/app/morphreader/id6741467699?platform=iphone<br />
<br />
RSS Feed: https://www.patreon.com/collection/880029?view=expanded<br />
<br />
Instagram: https://www.instagram.com/themorpheustuts/<br />
<br />
Meine anderen Kanäle und Projekte: the-morpheus.de/<br />
<br />
_Selbst *kostenlos Informatik lernen* auf meiner Website:_ https://bootstrap.academy/<br />
<br />
_Discord:_<br />
https://the-morpheus.de/discord.html<br />
<br />
_Unterstützt mich - Danke!:_<br />
https://www.patreon.com/user?u=5322110<br />
https://www.paypal.me/TheMorpheus<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[War das Absicht, Microsoft? #technews #cybersecurity #windows]]></title>
<description><![CDATA[Author: The Morpheus - Bewertung: 16x - Views:248]]></description>
<link>https://tsecurity.de/weiterlesen/3508588/3536724/war-das-absicht-microsoft-technews-cybersecurity-windows/</link>
<pubDate>Thu, 21 May 2026 16:27:12 +0200</pubDate>
<category>🎥 Video</category>
<source url="https://tsecurity.de">TSECURITY.DE</source>
<content:encoded><![CDATA[<p>Author: The Morpheus - Bewertung: 16x - Views:248 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/YsZ_f-ZS_wQ?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p><br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Open Source Drama bei Bambu Lab.. #technews]]></title>
<description><![CDATA[Author: The Morpheus - Bewertung: 41x - Views:1110]]></description>
<link>https://tsecurity.de/weiterlesen/3505387/3533523/open-source-drama-bei-bambu-lab-technews/</link>
<pubDate>Wed, 20 May 2026 17:11:16 +0200</pubDate>
<category>🎥 Video</category>
<source url="https://tsecurity.de">TSECURITY.DE</source>
<content:encoded><![CDATA[<p>Author: The Morpheus - Bewertung: 41x - Views:1110 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/cRtLHvKK8Ws?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p><br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Dark Mode ist nicht nur subjektiv besser.]]></title>
<description><![CDATA[Author: The Morpheus - Bewertung: 1x - Views:52 Werbung | Hier gehts zum Monitor von BenQ: https://bit.ly/RD280UG]]></description>
<link>https://tsecurity.de/weiterlesen/3500509/3528645/dark-mode-ist-nicht-nur-subjektiv-besser/</link>
<pubDate>Tue, 19 May 2026 12:08:17 +0200</pubDate>
<category>🎥 Video</category>
<source url="https://tsecurity.de">TSECURITY.DE</source>
<content:encoded><![CDATA[<p>Author: The Morpheus - Bewertung: 1x - Views:52 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/LMX0tnm9T6s?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>Werbung | Hier gehts zum Monitor von BenQ: https://bit.ly/RD280UG<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Whistleblower MUNDTOT machen (powered by AI)]]></title>
<description><![CDATA[Author: The Morpheus - Bewertung: 100x - Views:872 Objection.ai verspricht ein KI-Tribunal für Wahrheit im Journalismus. Doch was passiert, wenn ein privates System kritische Artikel automatisch prüft, öffentlich als „under investigation“ markiert und Journalist:innen dauerhaft bewertet?

Ich hab...]]></description>
<link>https://tsecurity.de/weiterlesen/3495118/3523254/whistleblower-mundtot-machen-powered-by-ai/</link>
<pubDate>Sun, 17 May 2026 09:22:56 +0200</pubDate>
<category>🎥 Video</category>
<source url="https://tsecurity.de">TSECURITY.DE</source>
<content:encoded><![CDATA[<p>Author: The Morpheus - Bewertung: 100x - Views:872 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/Pre7Smb0cSc?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>Objection.ai verspricht ein KI-Tribunal für Wahrheit im Journalismus. Doch was passiert, wenn ein privates System kritische Artikel automatisch prüft, öffentlich als „under investigation“ markiert und Journalist:innen dauerhaft bewertet?<br />
<br />
Ich habe mir angeschaut, wer hinter Objection.ai steckt, wie das System funktionieren soll und was passiert, wenn man den Mechanismus mit echten Artikeln nachbaut. Das Ergebnis zeigt weniger ein Werkzeug gegen Falschbehauptungen — und mehr eine Blaupause dafür, Journalismus skalierbar unter Druck zu setzen.<br />
<br />
[Werbung] <br />
Hol dir deine persönlichen Daten mit Incogni zurück! Nutze den Code MORPHEUS über den Link unten und sichere dir 60 % Rabatt auf ein Jahresabo: http://incogni.com/morpheus<br />
<br />
MorphReader im PlayStore: https://play.google.com/store/apps/details?id=de.themorpheus.morph_reader_app&hl=de<br />
<br />
MorphReader im App Store: https://apps.apple.com/de/app/morphreader/id6741467699?platform=iphone<br />
<br />
RSS-Feed: https://www.patreon.com/collection/880029?view=expanded<br />
<br />
Bootstrap Academy: https://bootstrap.academy/<br />
https://github.com/Bootstrap-Academy/<br />
<br />
Instagram: https://www.instagram.com/themorpheustuts/<br />
<br />
Quellen:<br />
https://kdrive.infomaniak.com/app/share/1794086/f1fed59e-30b7-4a56-9287-0351f00e40f0<br />
<br />
Meine anderen Kanäle und Projekte: the-morpheus.de/<br />
<br />
_Selbst *kostenlos Informatik lernen* auf meiner Website:_ https://bootstrap.academy/<br />
<br />
_Discord:_<br />
https://the-morpheus.de/discord.html<br />
<br />
_Unterstützt mich - Danke!:_<br />
https://www.patreon.com/user?u=5322110<br />
https://www.paypal.me/TheMorpheus<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Warum chinesische KI KEINE Alternative ist]]></title>
<description><![CDATA[Author: The Morpheus - Bewertung: 53x - Views:761 Chinesische KI-Modelle wie DeepSeek, Kimi, Qwen, GLM und MiniMax sind längst nicht mehr nur günstige Alternativen — sie werden gerade zur Infrastruktur für Entwickler, Firmen und ganze Branchen.

Ich habe über 6.000 Tests durchgeführt und mir ange...]]></description>
<link>https://tsecurity.de/weiterlesen/3476158/3504291/warum-chinesische-ki-keine-alternative-ist/</link>
<pubDate>Sun, 10 May 2026 09:24:58 +0200</pubDate>
<category>🎥 Video</category>
<source url="https://tsecurity.de">TSECURITY.DE</source>
<content:encoded><![CDATA[<p>Author: The Morpheus - Bewertung: 53x - Views:761 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/LyqaUUs0o-M?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>Chinesische KI-Modelle wie DeepSeek, Kimi, Qwen, GLM und MiniMax sind längst nicht mehr nur günstige Alternativen — sie werden gerade zur Infrastruktur für Entwickler, Firmen und ganze Branchen.<br />
<br />
Ich habe über 6.000 Tests durchgeführt und mir angeschaut, wie gut diese Modelle wirklich sind, warum sie so billig sein können, wo Bias und Zensur sichtbar werden und was das alles für Europa, Souveränität und unseren eigenen KI-Stack bedeutet.<br />
<br />
Welche KI-Modelle nutzt ihr beruflich oder privat — und warum?<br />
<br />
[Werbung] <br />
Hier geht's zu unserem Partner, NordVPN:<br />
https://nordvpn.com/morpheus<br />
Schnappt euch den Rabatt und 4 Bonusmonate auf den 2-Jahresplan<br />
<br />
MorphReader im PlayStore: https://play.google.com/store/apps/details?id=de.themorpheus.morph_reader_app&hl=de<br />
<br />
MorphReader im App Store: https://apps.apple.com/de/app/morphreader/id6741467699?platform=iphone<br />
<br />
RSS-Feed: https://www.patreon.com/collection/880029?view=expanded<br />
<br />
Bootstrap Academy: https://bootstrap.academy/<br />
https://github.com/Bootstrap-Academy/<br />
<br />
Instagram: https://www.instagram.com/themorpheustuts/<br />
<br />
Quellen:<br />
https://kdrive.infomaniak.com/app/share/1794086/5e1ab754-ade7-41e2-9f2c-1a869cb46295<br />
<br />
Die Test-Ergebnisse direkt:<br />
https://github.com/TheMorpheus407/YoutubeCode/tree/main/BIAS_Test<br />
<br />
Meine anderen Kanäle und Projekte: the-morpheus.de/<br />
<br />
_Selbst *kostenlos Informatik lernen* auf meiner Website:_ https://bootstrap.academy/<br />
<br />
_Discord:_<br />
https://the-morpheus.de/discord.html<br />
<br />
_Unterstützt mich - Danke!:_<br />
https://www.patreon.com/user?u=5322110<br />
https://www.paypal.me/TheMorpheus<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Security bug lifetime]]></title>
<description><![CDATA[In several of my recent presentations, I’ve discussed the lifetime of security flaws in the Linux kernel. Jon Corbet did an analysis in 2010, and found that security bugs appeared to have roughly a 5 year lifetime. As in, the flaw gets introduced in a Linux release, and then goes unnoticed by ups...]]></description>
<link>https://tsecurity.de/weiterlesen/3472341/3500474/security-bug-lifetime/</link>
<pubDate>Fri, 08 May 2026 22:42:20 +0200</pubDate>
<category>🎥 Video</category>
<source url="https://tsecurity.de">TSECURITY.DE</source>
<content:encoded><![CDATA[In several of my recent presentations, I’ve discussed the lifetime of security flaws in the Linux kernel. Jon Corbet did an analysis in 2010, and found that security bugs appeared to have roughly a 5 year lifetime. As in, the flaw gets introduced in a Linux release, and then goes unnoticed by upstream developers until […]]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2016-5195]]></title>
<description><![CDATA[My prior post showed my research from earlier in the year at the 2016 Linux Security Summit on kernel security flaw lifetimes. Now that CVE-2016-5195 is public, here are updated graphs and statistics. Due to their rarity, the Critical bug average has now jumped from 3.3 years to 5.2 years. There ...]]></description>
<link>https://tsecurity.de/weiterlesen/3472340/3500473/cve-2016-5195/</link>
<pubDate>Fri, 08 May 2026 22:42:18 +0200</pubDate>
<category>🎥 Video</category>
<source url="https://tsecurity.de">TSECURITY.DE</source>
<content:encoded><![CDATA[My prior post showed my research from earlier in the year at the 2016 Linux Security Summit on kernel security flaw lifetimes. Now that CVE-2016-5195 is public, here are updated graphs and statistics. Due to their rarity, the Critical bug average has now jumped from 3.3 years to 5.2 years. There aren’t many, but, as […]]]></content:encoded>
</item>
<item>
<title><![CDATA[security things in Linux v4.9]]></title>
<description><![CDATA[Previously: v4.8. Here are a bunch of security things I’m excited about in the newly released Linux v4.9: Latent Entropy GCC plugin Building on her earlier work to bring GCC plugin support to the Linux kernel, Emese Revfy ported PaX’s Latent Entropy GCC plugin to upstream. This plugin is signific...]]></description>
<link>https://tsecurity.de/weiterlesen/3472339/3500472/security-things-in-linux-v49/</link>
<pubDate>Fri, 08 May 2026 22:42:17 +0200</pubDate>
<category>🎥 Video</category>
<source url="https://tsecurity.de">TSECURITY.DE</source>
<content:encoded><![CDATA[Previously: v4.8. Here are a bunch of security things I’m excited about in the newly released Linux v4.9: Latent Entropy GCC plugin Building on her earlier work to bring GCC plugin support to the Linux kernel, Emese Revfy ported PaX’s Latent Entropy GCC plugin to upstream. This plugin is significantly more complex than the others […]]]></content:encoded>
</item>
<item>
<title><![CDATA[security things in Linux v4.10]]></title>
<description><![CDATA[Previously: v4.9. Here’s a quick summary of some of the interesting security things in last week’s v4.10 release of the Linux kernel: PAN emulation on arm64 Catalin Marinas introduced ARM64_SW_TTBR0_PAN, which is functionally the arm64 equivalent of arm’s CONFIG_CPU_SW_DOMAIN_PAN. While Privilege...]]></description>
<link>https://tsecurity.de/weiterlesen/3472338/3500471/security-things-in-linux-v410/</link>
<pubDate>Fri, 08 May 2026 22:42:16 +0200</pubDate>
<category>🎥 Video</category>
<source url="https://tsecurity.de">TSECURITY.DE</source>
<content:encoded><![CDATA[Previously: v4.9. Here’s a quick summary of some of the interesting security things in last week’s v4.10 release of the Linux kernel: PAN emulation on arm64 Catalin Marinas introduced ARM64_SW_TTBR0_PAN, which is functionally the arm64 equivalent of arm’s CONFIG_CPU_SW_DOMAIN_PAN. While Privileged eXecute Never (PXN) has been available in ARM hardware for a while now, Privileged […]]]></content:encoded>
</item>
<item>
<title><![CDATA[security things in Linux v4.11]]></title>
<description><![CDATA[Previously: v4.10. Here’s a quick summary of some of the interesting security things in this week’s v4.11 release of the Linux kernel: refcount_t infrastructure Building on the efforts of Elena Reshetova, Hans Liljestrand, and David Windsor to port PaX’s PAX_REFCOUNT protection, Peter Zijlstra im...]]></description>
<link>https://tsecurity.de/weiterlesen/3472337/3500470/security-things-in-linux-v411/</link>
<pubDate>Fri, 08 May 2026 22:42:14 +0200</pubDate>
<category>🎥 Video</category>
<source url="https://tsecurity.de">TSECURITY.DE</source>
<content:encoded><![CDATA[Previously: v4.10. Here’s a quick summary of some of the interesting security things in this week’s v4.11 release of the Linux kernel: refcount_t infrastructure Building on the efforts of Elena Reshetova, Hans Liljestrand, and David Windsor to port PaX’s PAX_REFCOUNT protection, Peter Zijlstra implemented a new kernel API for reference counting with the addition of […]]]></content:encoded>
</item>
<item>
<title><![CDATA[security things in Linux v4.12]]></title>
<description><![CDATA[Previously: v4.11. Here’s a quick summary of some of the interesting security things in last week’s v4.12 release of the Linux kernel: x86 read-only and fixed-location GDT With kernel memory base randomization, it was stil possible to figure out the per-cpu base address via the “sgdt” instruction...]]></description>
<link>https://tsecurity.de/weiterlesen/3472336/3500469/security-things-in-linux-v412/</link>
<pubDate>Fri, 08 May 2026 22:42:13 +0200</pubDate>
<category>🎥 Video</category>
<source url="https://tsecurity.de">TSECURITY.DE</source>
<content:encoded><![CDATA[Previously: v4.11. Here’s a quick summary of some of the interesting security things in last week’s v4.12 release of the Linux kernel: x86 read-only and fixed-location GDT With kernel memory base randomization, it was stil possible to figure out the per-cpu base address via the “sgdt” instruction, since it would reveal the per-cpu GDT location. […]]]></content:encoded>
</item>
<item>
<title><![CDATA[security things in Linux v4.13]]></title>
<description><![CDATA[Previously: v4.12. Here’s a short summary of some of interesting security things in Sunday’s v4.13 release of the Linux kernel: security documentation ReSTification The kernel has been switching to formatting documentation with ReST, and I noticed that none of the Documentation/security/ tree had...]]></description>
<link>https://tsecurity.de/weiterlesen/3472335/3500468/security-things-in-linux-v413/</link>
<pubDate>Fri, 08 May 2026 22:42:12 +0200</pubDate>
<category>🎥 Video</category>
<source url="https://tsecurity.de">TSECURITY.DE</source>
<content:encoded><![CDATA[Previously: v4.12. Here’s a short summary of some of interesting security things in Sunday’s v4.13 release of the Linux kernel: security documentation ReSTification The kernel has been switching to formatting documentation with ReST, and I noticed that none of the Documentation/security/ tree had been converted yet. I took the opportunity to take a few passes […]]]></content:encoded>
</item>
<item>
<title><![CDATA[security things in Linux v4.14]]></title>
<description><![CDATA[Previously: v4.13. Linux kernel v4.14 was released this last Sunday, and there’s a bunch of security things I think are interesting: vmapped kernel stack on arm64 Similar to the same feature on x86, Mark Rutland and Ard Biesheuvel implemented CONFIG_VMAP_STACK for arm64, which moves the kernel st...]]></description>
<link>https://tsecurity.de/weiterlesen/3472334/3500467/security-things-in-linux-v414/</link>
<pubDate>Fri, 08 May 2026 22:42:11 +0200</pubDate>
<category>🎥 Video</category>
<source url="https://tsecurity.de">TSECURITY.DE</source>
<content:encoded><![CDATA[Previously: v4.13. Linux kernel v4.14 was released this last Sunday, and there’s a bunch of security things I think are interesting: vmapped kernel stack on arm64 Similar to the same feature on x86, Mark Rutland and Ard Biesheuvel implemented CONFIG_VMAP_STACK for arm64, which moves the kernel stack to an isolated and guard-paged vmap area. With […]]]></content:encoded>
</item>
<item>
<title><![CDATA[SMEP emulation in PTI]]></title>
<description><![CDATA[An nice additional benefit of the recent Kernel Page Table Isolation (CONFIG_PAGE_TABLE_ISOLATION) patches (to defend against CVE-2017-5754, the speculative execution “rogue data cache load” or “Meltdown” flaw) is that the userspace page tables visible while running in kernel mode lack the execut...]]></description>
<link>https://tsecurity.de/weiterlesen/3472333/3500466/smep-emulation-in-pti/</link>
<pubDate>Fri, 08 May 2026 22:42:09 +0200</pubDate>
<category>🎥 Video</category>
<source url="https://tsecurity.de">TSECURITY.DE</source>
<content:encoded><![CDATA[An nice additional benefit of the recent Kernel Page Table Isolation (CONFIG_PAGE_TABLE_ISOLATION) patches (to defend against CVE-2017-5754, the speculative execution “rogue data cache load” or “Meltdown” flaw) is that the userspace page tables visible while running in kernel mode lack the executable bit. As a result, systems without the SMEP CPU feature (before Ivy-Bridge) get […]]]></content:encoded>
</item>
<item>
<title><![CDATA[security things in Linux v4.15]]></title>
<description><![CDATA[Previously: v4.14. Linux kernel v4.15 was released last week, and there’s a bunch of security things I think are interesting: Kernel Page Table Isolation PTI has already gotten plenty of reporting, but to summarize, it is mainly to protect against CPU cache timing side-channel attacks that can ex...]]></description>
<link>https://tsecurity.de/weiterlesen/3472332/3500465/security-things-in-linux-v415/</link>
<pubDate>Fri, 08 May 2026 22:42:08 +0200</pubDate>
<category>🎥 Video</category>
<source url="https://tsecurity.de">TSECURITY.DE</source>
<content:encoded><![CDATA[Previously: v4.14. Linux kernel v4.15 was released last week, and there’s a bunch of security things I think are interesting: Kernel Page Table Isolation PTI has already gotten plenty of reporting, but to summarize, it is mainly to protect against CPU cache timing side-channel attacks that can expose kernel memory contents to userspace (CVE-2017-5754, the […]]]></content:encoded>
</item>
<item>
<title><![CDATA[security things in Linux v4.16]]></title>
<description><![CDATA[Previously: v4.15. ￼ Linux kernel v4.16 was released last week. I really should write these posts in advance, otherwise I get distracted by the merge window. Regardless, here are some of the security things I think are interesting: KPTI on arm64 Will Deacon, Catalin Marinas, and several other fol...]]></description>
<link>https://tsecurity.de/weiterlesen/3472331/3500464/security-things-in-linux-v416/</link>
<pubDate>Fri, 08 May 2026 22:42:06 +0200</pubDate>
<category>🎥 Video</category>
<source url="https://tsecurity.de">TSECURITY.DE</source>
<content:encoded><![CDATA[Previously: v4.15. ￼ Linux kernel v4.16 was released last week. I really should write these posts in advance, otherwise I get distracted by the merge window. Regardless, here are some of the security things I think are interesting: KPTI on arm64 Will Deacon, Catalin Marinas, and several other folks brought Kernel Page Table Isolation (via […]]]></content:encoded>
</item>
<item>
<title><![CDATA[UEFI booting and RAID1]]></title>
<description><![CDATA[I spent some time yesterday building out a UEFI server that didn’t have on-board hardware RAID for its system drives. In these situations, I always use Linux’s md RAID1 for the root filesystem (and/or /boot). This worked well for BIOS booting since BIOS just transfers control blindly to the MBR o...]]></description>
<link>https://tsecurity.de/weiterlesen/3472330/3500463/uefi-booting-and-raid1/</link>
<pubDate>Fri, 08 May 2026 22:42:05 +0200</pubDate>
<category>🎥 Video</category>
<source url="https://tsecurity.de">TSECURITY.DE</source>
<content:encoded><![CDATA[I spent some time yesterday building out a UEFI server that didn’t have on-board hardware RAID for its system drives. In these situations, I always use Linux’s md RAID1 for the root filesystem (and/or /boot). This worked well for BIOS booting since BIOS just transfers control blindly to the MBR of whatever disk it sees […]]]></content:encoded>
</item>
<item>
<title><![CDATA[security things in Linux v4.17]]></title>
<description><![CDATA[Previously: v4.16. Linux kernel v4.17 was released last week, and here are some of the security things I think are interesting: Jailhouse hypervisor Jan Kiszka landed Jailhouse hypervisor support, which uses static partitioning (i.e. no resource over-committing), where the root “cell” spawns new ...]]></description>
<link>https://tsecurity.de/weiterlesen/3472329/3500462/security-things-in-linux-v417/</link>
<pubDate>Fri, 08 May 2026 22:42:04 +0200</pubDate>
<category>🎥 Video</category>
<source url="https://tsecurity.de">TSECURITY.DE</source>
<content:encoded><![CDATA[Previously: v4.16. Linux kernel v4.17 was released last week, and here are some of the security things I think are interesting: Jailhouse hypervisor Jan Kiszka landed Jailhouse hypervisor support, which uses static partitioning (i.e. no resource over-committing), where the root “cell” spawns new jails by shrinking its own CPU/memory/etc resources and hands them over to […]]]></content:encoded>
</item>
<item>
<title><![CDATA[security things in Linux v4.18]]></title>
<description><![CDATA[Previously: v4.17. Linux kernel v4.18 was released last week. Here are details on some of the security things I found interesting: allocation overflow detection helpers One of the many ways C can be dangerous to use is that it lacks strong primitives to deal with arithmetic overflow. A developer ...]]></description>
<link>https://tsecurity.de/weiterlesen/3472328/3500461/security-things-in-linux-v418/</link>
<pubDate>Fri, 08 May 2026 22:42:02 +0200</pubDate>
<category>🎥 Video</category>
<source url="https://tsecurity.de">TSECURITY.DE</source>
<content:encoded><![CDATA[Previously: v4.17. Linux kernel v4.18 was released last week. Here are details on some of the security things I found interesting: allocation overflow detection helpers One of the many ways C can be dangerous to use is that it lacks strong primitives to deal with arithmetic overflow. A developer can’t just wrap a series of […]]]></content:encoded>
</item>
<item>
<title><![CDATA[security things in Linux v4.19]]></title>
<description><![CDATA[Previously: v4.18. Linux kernel v4.19 was released today. Here are some security-related things I found interesting: L1 Terminal Fault (L1TF) While it seems like ages ago, the fixes for L1TF actually landed at the start of the v4.19 merge window. As with the other speculation flaw fixes, lots of ...]]></description>
<link>https://tsecurity.de/weiterlesen/3472327/3500460/security-things-in-linux-v419/</link>
<pubDate>Fri, 08 May 2026 22:42:01 +0200</pubDate>
<category>🎥 Video</category>
<source url="https://tsecurity.de">TSECURITY.DE</source>
<content:encoded><![CDATA[Previously: v4.18. Linux kernel v4.19 was released today. Here are some security-related things I found interesting: L1 Terminal Fault (L1TF) While it seems like ages ago, the fixes for L1TF actually landed at the start of the v4.19 merge window. As with the other speculation flaw fixes, lots of people were involved, and the scope […]]]></content:encoded>
</item>
<item>
<title><![CDATA[security things in Linux v4.20]]></title>
<description><![CDATA[Previously: v4.19. Linux kernel v4.20 has been released today! Looking through the changes, here are some security-related things I found interesting: stackleak plugin Alexander Popov’s work to port the grsecurity STACKLEAK plugin to the upstream kernel came to fruition. While it had received Ack...]]></description>
<link>https://tsecurity.de/weiterlesen/3472326/3500459/security-things-in-linux-v420/</link>
<pubDate>Fri, 08 May 2026 22:41:59 +0200</pubDate>
<category>🎥 Video</category>
<source url="https://tsecurity.de">TSECURITY.DE</source>
<content:encoded><![CDATA[Previously: v4.19. Linux kernel v4.20 has been released today! Looking through the changes, here are some security-related things I found interesting: stackleak plugin Alexander Popov’s work to port the grsecurity STACKLEAK plugin to the upstream kernel came to fruition. While it had received Acks from x86 (and arm64) maintainers, it has been rejected a few […]]]></content:encoded>
</item>
<item>
<title><![CDATA[security things in Linux v5.0]]></title>
<description><![CDATA[Previously: v4.20. Linux kernel v5.0 was released last week! Looking through the changes, here are some security-related things I found interesting: read-only linear mapping, arm64 While x86 has had a read-only linear mapping (or “Low Kernel Mapping” as shown in /sys/kernel/debug/page_tables/kern...]]></description>
<link>https://tsecurity.de/weiterlesen/3472325/3500458/security-things-in-linux-v50/</link>
<pubDate>Fri, 08 May 2026 22:41:58 +0200</pubDate>
<category>🎥 Video</category>
<source url="https://tsecurity.de">TSECURITY.DE</source>
<content:encoded><![CDATA[Previously: v4.20. Linux kernel v5.0 was released last week! Looking through the changes, here are some security-related things I found interesting: read-only linear mapping, arm64 While x86 has had a read-only linear mapping (or “Low Kernel Mapping” as shown in /sys/kernel/debug/page_tables/kernel under CONFIG_X86_PTDUMP=y) for a while, Ard Biesheuvel has added them to arm64 now. This […]]]></content:encoded>
</item>
<item>
<title><![CDATA[security things in Linux v5.1]]></title>
<description><![CDATA[Previously: v5.0. Linux kernel v5.1 has been released! Here are some security-related things that stood out to me: introduction of pidfd Christian Brauner landed the first portion of his work to remove pid races from the kernel: using a file descriptor to reference a process (“pidfd”). Now /proc/...]]></description>
<link>https://tsecurity.de/weiterlesen/3472324/3500457/security-things-in-linux-v51/</link>
<pubDate>Fri, 08 May 2026 22:41:57 +0200</pubDate>
<category>🎥 Video</category>
<source url="https://tsecurity.de">TSECURITY.DE</source>
<content:encoded><![CDATA[Previously: v5.0. Linux kernel v5.1 has been released! Here are some security-related things that stood out to me: introduction of pidfd Christian Brauner landed the first portion of his work to remove pid races from the kernel: using a file descriptor to reference a process (“pidfd”). Now /proc/$pid can be opened and used as an […]]]></content:encoded>
</item>
<item>
<title><![CDATA[security things in Linux v5.2]]></title>
<description><![CDATA[Previously: v5.1. Linux kernel v5.2 was released last week! Here are some security-related things I found interesting: page allocator freelist randomization While the SLUB and SLAB allocator freelists have been randomized for a while now, the overarching page allocator itself wasn’t. This meant t...]]></description>
<link>https://tsecurity.de/weiterlesen/3472323/3500456/security-things-in-linux-v52/</link>
<pubDate>Fri, 08 May 2026 22:41:55 +0200</pubDate>
<category>🎥 Video</category>
<source url="https://tsecurity.de">TSECURITY.DE</source>
<content:encoded><![CDATA[Previously: v5.1. Linux kernel v5.2 was released last week! Here are some security-related things I found interesting: page allocator freelist randomization While the SLUB and SLAB allocator freelists have been randomized for a while now, the overarching page allocator itself wasn’t. This meant that anything doing allocation outside of the kmem_cache/kmalloc() would have deterministic placement […]]]></content:encoded>
</item>
<item>
<title><![CDATA[security things in Linux v5.3]]></title>
<description><![CDATA[Previously: v5.2. Linux kernel v5.3 was released! I let this blog post get away from me, but it’s up now! :) Here are some security-related things I found interesting: heap variable initialization In the continuing work to remove “uninitialized” variables from the kernel, Alexander Potapenko adde...]]></description>
<link>https://tsecurity.de/weiterlesen/3472322/3500455/security-things-in-linux-v53/</link>
<pubDate>Fri, 08 May 2026 22:41:54 +0200</pubDate>
<category>🎥 Video</category>
<source url="https://tsecurity.de">TSECURITY.DE</source>
<content:encoded><![CDATA[Previously: v5.2. Linux kernel v5.3 was released! I let this blog post get away from me, but it’s up now! :) Here are some security-related things I found interesting: heap variable initialization In the continuing work to remove “uninitialized” variables from the kernel, Alexander Potapenko added new “init_on_alloc” and “init_on_free” boot parameters (with associated Kconfig […]]]></content:encoded>
</item>
<item>
<title><![CDATA[experimenting with Clang CFI on upstream Linux]]></title>
<description><![CDATA[While much of the work on kernel Control Flow Integrity (CFI) is focused on arm64 (since kernel CFI is available on Android), a significant portion is in the core kernel itself (and especially the build system). Recently I got a sane build and boot on x86 with everything enabled, and I’ve been pi...]]></description>
<link>https://tsecurity.de/weiterlesen/3472321/3500454/experimenting-with-clang-cfi-on-upstream-linux/</link>
<pubDate>Fri, 08 May 2026 22:41:53 +0200</pubDate>
<category>🎥 Video</category>
<source url="https://tsecurity.de">TSECURITY.DE</source>
<content:encoded><![CDATA[While much of the work on kernel Control Flow Integrity (CFI) is focused on arm64 (since kernel CFI is available on Android), a significant portion is in the core kernel itself (and especially the build system). Recently I got a sane build and boot on x86 with everything enabled, and I’ve been picking through some […]]]></content:encoded>
</item>
<item>
<title><![CDATA[security things in Linux v5.4]]></title>
<description><![CDATA[Previously: v5.3. Linux kernel v5.4 was released in late November. The holidays got the best of me, but better late than never! ;) Here are some security-related things I found interesting: waitid() gains P_PIDFD Christian Brauner has continued his pidfd work by adding a critical mode to waitid()...]]></description>
<link>https://tsecurity.de/weiterlesen/3472320/3500453/security-things-in-linux-v54/</link>
<pubDate>Fri, 08 May 2026 22:41:52 +0200</pubDate>
<category>🎥 Video</category>
<source url="https://tsecurity.de">TSECURITY.DE</source>
<content:encoded><![CDATA[Previously: v5.3. Linux kernel v5.4 was released in late November. The holidays got the best of me, but better late than never! ;) Here are some security-related things I found interesting: waitid() gains P_PIDFD Christian Brauner has continued his pidfd work by adding a critical mode to waitid(): P_PIDFD. This makes it possible to reap […]]]></content:encoded>
</item>
<item>
<title><![CDATA[security things in Linux v5.5]]></title>
<description><![CDATA[Previously: v5.4. I got a bit behind on this blog post series! Let’s get caught up. Here are a bunch of security things I found interesting in the Linux kernel v5.5 release: restrict perf_event_open() from LSM Given the recurring flaws in the perf subsystem, there has been a strong desire to be a...]]></description>
<link>https://tsecurity.de/weiterlesen/3472319/3500452/security-things-in-linux-v55/</link>
<pubDate>Fri, 08 May 2026 22:41:50 +0200</pubDate>
<category>🎥 Video</category>
<source url="https://tsecurity.de">TSECURITY.DE</source>
<content:encoded><![CDATA[Previously: v5.4. I got a bit behind on this blog post series! Let’s get caught up. Here are a bunch of security things I found interesting in the Linux kernel v5.5 release: restrict perf_event_open() from LSM Given the recurring flaws in the perf subsystem, there has been a strong desire to be able to entirely […]]]></content:encoded>
</item>
<item>
<title><![CDATA[security things in Linux v5.6]]></title>
<description><![CDATA[Previously: v5.5. Linux v5.6 was released back in March. Here’s my quick summary of various features that caught my attention: WireGuard The widely used WireGuard VPN has been out-of-tree for a very long time. After 3 1/2 years since its initial upstream RFC, Ard Biesheuvel and Jason Donenfeld fi...]]></description>
<link>https://tsecurity.de/weiterlesen/3472318/3500451/security-things-in-linux-v56/</link>
<pubDate>Fri, 08 May 2026 22:41:48 +0200</pubDate>
<category>🎥 Video</category>
<source url="https://tsecurity.de">TSECURITY.DE</source>
<content:encoded><![CDATA[Previously: v5.5. Linux v5.6 was released back in March. Here’s my quick summary of various features that caught my attention: WireGuard The widely used WireGuard VPN has been out-of-tree for a very long time. After 3 1/2 years since its initial upstream RFC, Ard Biesheuvel and Jason Donenfeld finished the work getting all the crypto […]]]></content:encoded>
</item>
<item>
<title><![CDATA[security things in Linux v5.7]]></title>
<description><![CDATA[Previously: v5.6 Linux v5.7 was released at the end of May. Here’s my summary of various security things that caught my attention: arm64 kernel pointer authentication While the ARMv8.3 CPU “Pointer Authentication” (PAC) feature landed for userspace already, Kristina Martsenko has now landed PAC s...]]></description>
<link>https://tsecurity.de/weiterlesen/3472317/3500450/security-things-in-linux-v57/</link>
<pubDate>Fri, 08 May 2026 22:41:43 +0200</pubDate>
<category>🎥 Video</category>
<source url="https://tsecurity.de">TSECURITY.DE</source>
<content:encoded><![CDATA[Previously: v5.6 Linux v5.7 was released at the end of May. Here’s my summary of various security things that caught my attention: arm64 kernel pointer authentication While the ARMv8.3 CPU “Pointer Authentication” (PAC) feature landed for userspace already, Kristina Martsenko has now landed PAC support in kernel mode. The current implementation uses PACIASP which protects […]]]></content:encoded>
</item>
<item>
<title><![CDATA[security things in Linux v5.8]]></title>
<description><![CDATA[Previously: v5.7 Linux v5.8 was released in August, 2020. Here’s my summary of various security things that caught my attention: arm64 Branch Target Identification Dave Martin added support for ARMv8.5’s Branch Target Instructions (BTI), which are enabled in userspace at execve() time, and all th...]]></description>
<link>https://tsecurity.de/weiterlesen/3472316/3500449/security-things-in-linux-v58/</link>
<pubDate>Fri, 08 May 2026 22:41:41 +0200</pubDate>
<category>🎥 Video</category>
<source url="https://tsecurity.de">TSECURITY.DE</source>
<content:encoded><![CDATA[Previously: v5.7 Linux v5.8 was released in August, 2020. Here’s my summary of various security things that caught my attention: arm64 Branch Target Identification Dave Martin added support for ARMv8.5’s Branch Target Instructions (BTI), which are enabled in userspace at execve() time, and all the time in the kernel (which required manually marking up a […]]]></content:encoded>
</item>
<item>
<title><![CDATA[security things in Linux v5.9]]></title>
<description><![CDATA[Previously: v5.8 Linux v5.9 was released in October, 2020. Here’s my summary of various security things that I found interesting: seccomp user_notif file descriptor injection Sargun Dhillon added the ability for SECCOMP_RET_USER_NOTIF filters to inject file descriptors into the target process usi...]]></description>
<link>https://tsecurity.de/weiterlesen/3472315/3500448/security-things-in-linux-v59/</link>
<pubDate>Fri, 08 May 2026 22:41:40 +0200</pubDate>
<category>🎥 Video</category>
<source url="https://tsecurity.de">TSECURITY.DE</source>
<content:encoded><![CDATA[Previously: v5.8 Linux v5.9 was released in October, 2020. Here’s my summary of various security things that I found interesting: seccomp user_notif file descriptor injection Sargun Dhillon added the ability for SECCOMP_RET_USER_NOTIF filters to inject file descriptors into the target process using SECCOMP_IOCTL_NOTIF_ADDFD. This lets container managers fully emulate syscalls like open() and connect(), where […]]]></content:encoded>
</item>
<item>
<title><![CDATA[security things in Linux v5.10]]></title>
<description><![CDATA[Previously: v5.9 Linux v5.10 was released in December, 2020. Here’s my summary of various security things that I found interesting: AMD SEV-ES While guest VM memory encryption with AMD SEV has been supported for a while, Joerg Roedel, Thomas Lendacky, and others added register state encryption (S...]]></description>
<link>https://tsecurity.de/weiterlesen/3472314/3500447/security-things-in-linux-v510/</link>
<pubDate>Fri, 08 May 2026 22:41:39 +0200</pubDate>
<category>🎥 Video</category>
<source url="https://tsecurity.de">TSECURITY.DE</source>
<content:encoded><![CDATA[Previously: v5.9 Linux v5.10 was released in December, 2020. Here’s my summary of various security things that I found interesting: AMD SEV-ES While guest VM memory encryption with AMD SEV has been supported for a while, Joerg Roedel, Thomas Lendacky, and others added register state encryption (SEV-ES). This means it’s even harder for a VM […]]]></content:encoded>
</item>
<item>
<title><![CDATA[finding binary differences]]></title>
<description><![CDATA[As part of the continuing work to replace 1-element arrays in the Linux kernel, it’s very handy to show that a source change has had no executable code difference. For example, if you started with this: struct foo { unsigned long flags; u32 length; u32 data[1]; }; void foo_init(int count) { struc...]]></description>
<link>https://tsecurity.de/weiterlesen/3472313/3500446/finding-binary-differences/</link>
<pubDate>Fri, 08 May 2026 22:41:37 +0200</pubDate>
<category>🎥 Video</category>
<source url="https://tsecurity.de">TSECURITY.DE</source>
<content:encoded><![CDATA[As part of the continuing work to replace 1-element arrays in the Linux kernel, it’s very handy to show that a source change has had no executable code difference. For example, if you started with this: struct foo { unsigned long flags; u32 length; u32 data[1]; }; void foo_init(int count) { struct foo *instance; size_t […]]]></content:encoded>
</item>
<item>
<title><![CDATA[Enable MTE on Pixel 8]]></title>
<description><![CDATA[The Pixel 8 hardware (Tensor G3) supports the ARM Memory Tagging Extension (MTE), and software support is available both in Android userspace and the Linux kernel. This feature is a powerful defense against linear buffer overflows and many types of use-after-free flaws. I’m extremely happy to see...]]></description>
<link>https://tsecurity.de/weiterlesen/3472312/3500445/enable-mte-on-pixel-8/</link>
<pubDate>Fri, 08 May 2026 22:41:35 +0200</pubDate>
<category>🎥 Video</category>
<source url="https://tsecurity.de">TSECURITY.DE</source>
<content:encoded><![CDATA[The Pixel 8 hardware (Tensor G3) supports the ARM Memory Tagging Extension (MTE), and software support is available both in Android userspace and the Linux kernel. This feature is a powerful defense against linear buffer overflows and many types of use-after-free flaws. I’m extremely happy to see this hardware finally available in the real world. […]]]></content:encoded>
</item>
<item>
<title><![CDATA[EU biegt mal wieder in die falsche Richtung ab... #technews #vpn]]></title>
<description><![CDATA[Author: The Morpheus - Bewertung: 63x - Views:1161]]></description>
<link>https://tsecurity.de/weiterlesen/3471330/3499463/eu-biegt-mal-wieder-in-die-falsche-richtung-ab-technews-vpn/</link>
<pubDate>Fri, 08 May 2026 15:57:53 +0200</pubDate>
<category>🎥 Video</category>
<source url="https://tsecurity.de">TSECURITY.DE</source>
<content:encoded><![CDATA[<p>Author: The Morpheus - Bewertung: 63x - Views:1161 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/1O55BZoi9Rs?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p><br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[MorphReader Design für Web]]></title>
<description><![CDATA[Author: The Morpheus Tutorials - Bewertung: 10x - Views:67]]></description>
<link>https://tsecurity.de/weiterlesen/3467852/3495985/morphreader-design-fuer-web/</link>
<pubDate>Thu, 07 May 2026 14:43:42 +0200</pubDate>
<category>🎥 Video</category>
<source url="https://tsecurity.de">TSECURITY.DE</source>
<content:encoded><![CDATA[<p>Author: The Morpheus Tutorials - Bewertung: 10x - Views:67 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/q25LIdM85Sc?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p><br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[War euer Internet gestern auch weg? #technews #denic]]></title>
<description><![CDATA[Author: The Morpheus - Bewertung: 33x - Views:434]]></description>
<link>https://tsecurity.de/weiterlesen/3464846/3492979/war-euer-internet-gestern-auch-weg-technews-denic/</link>
<pubDate>Wed, 06 May 2026 16:11:01 +0200</pubDate>
<category>🎥 Video</category>
<source url="https://tsecurity.de">TSECURITY.DE</source>
<content:encoded><![CDATA[<p>Author: The Morpheus - Bewertung: 33x - Views:434 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/f8AThxNiZLY?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p><br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Serverweitwurf: Da muss ich wohl noch mal ins Gym..]]></title>
<description><![CDATA[Author: The Morpheus - Bewertung: 8x - Views:393 Auf dem @CloudFest]]></description>
<link>https://tsecurity.de/weiterlesen/3458294/3486427/serverweitwurf-da-muss-ich-wohl-noch-mal-ins-gym/</link>
<pubDate>Mon, 04 May 2026 16:23:22 +0200</pubDate>
<category>🎥 Video</category>
<source url="https://tsecurity.de">TSECURITY.DE</source>
<content:encoded><![CDATA[<p>Author: The Morpheus - Bewertung: 8x - Views:393 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/lV71P-CH_uo?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>Auf dem @CloudFest<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Diese SCHWACHSTELLE haben wir alle UNTERSCHÄTZT]]></title>
<description><![CDATA[Author: The Morpheus - Bewertung: 0x - Views:0 Euer Internet hat einen Türsteher. Ihr habt ihn nur nie eingestellt. Ein einziges System, das Vodafone und Telekom in Deutschland zum aktiven blocken von Websites einsetzen. Das alle eure besuchten Websites nicht nur unserem Internetanbieter verrät, ...]]></description>
<link>https://tsecurity.de/weiterlesen/3455225/3483358/diese-schwachstelle-haben-wir-alle-unterschaetzt/</link>
<pubDate>Sun, 03 May 2026 09:07:01 +0200</pubDate>
<category>🎥 Video</category>
<source url="https://tsecurity.de">TSECURITY.DE</source>
<content:encoded><![CDATA[<p>Author: The Morpheus - Bewertung: 0x - Views:0 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/0cBZR4wy3ec?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>Euer Internet hat einen Türsteher. Ihr habt ihn nur nie eingestellt. Ein einziges System, das Vodafone und Telekom in Deutschland zum aktiven blocken von Websites einsetzen. Das alle eure besuchten Websites nicht nur unserem Internetanbieter verrät, sondern gleichzeitig noch an die USA. Und das SELBE System habe ich für mich angepasst, nicht nur um die Sperren zu umgehen, sondern auch um Werbung und sogar Tracker nicht nur für mich auf dem PC, sondern auch am Smart-TV und am Handy zu blockieren und sogar um Hacker und Malware zu blockieren. <br />
Es ist das vermutlich wichtigste Grundgerüst in unserem Internet und sogar in einem unfassbaren geopolitischen Thriller verwickelt, den ich euch nicht vorenthalten will. <br />
<br />
[Werbung] Hier geht's zu unserem Partner Hostinger:<br />
https://www.hostg.xyz/SHI6y<br />
Nutzt den Code MORPHEUS10 für 10 Prozent Rabatt :)<br />
<br />
MorphReader im PlayStore: https://play.google.com/store/apps/details?id=de.themorpheus.morph_reader_app&hl=de<br />
<br />
MorphReader im App Store: https://apps.apple.com/de/app/morphreader/id6741467699?platform=iphone<br />
<br />
RSS-Feed: https://www.patreon.com/collection/880029?view=expanded<br />
<br />
Bootstrap Academy: https://bootstrap.academy/<br />
https://github.com/Bootstrap-Academy/<br />
<br />
Instagram: https://www.instagram.com/themorpheustuts/<br />
<br />
Quellen:<br />
https://kdrive.infomaniak.com/app/share/1794086/fb9f4e50-24a0-44c7-8567-87cbff1f8716<br />
<br />
Zum DNS Guide:<br />
https://www.patreon.com/posts/157177525/<br />
<br />
Meine anderen Kanäle und Projekte: the-morpheus.de/<br />
<br />
_Selbst *kostenlos Informatik lernen* auf meiner Website:_ https://bootstrap.academy/<br />
<br />
_Discord:_<br />
https://the-morpheus.de/discord.html<br />
<br />
_Unterstützt mich - Danke!:_<br />
https://www.patreon.com/user?u=5322110<br />
https://www.paypal.me/TheMorpheus<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Gibts beim Chrome-Update wirklich keinen Haken? #technews #cybersecurity #google]]></title>
<description><![CDATA[Author: The Morpheus - Bewertung: 43x - Views:599]]></description>
<link>https://tsecurity.de/weiterlesen/3449834/3477967/gibts-beim-chrome-update-wirklich-keinen-haken-technews-cybersecurity-google/</link>
<pubDate>Thu, 30 Apr 2026 16:38:12 +0200</pubDate>
<category>🎥 Video</category>
<source url="https://tsecurity.de">TSECURITY.DE</source>
<content:encoded><![CDATA[<p>Author: The Morpheus - Bewertung: 43x - Views:599 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/9BL_gjsRQKc?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p><br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[ChatGPT Goblin Mode ist real #openai #ai]]></title>
<description><![CDATA[Author: The Morpheus - Bewertung: 65x - Views:1458]]></description>
<link>https://tsecurity.de/weiterlesen/3446971/3475104/chatgpt-goblin-mode-ist-real-openai-ai/</link>
<pubDate>Wed, 29 Apr 2026 18:08:10 +0200</pubDate>
<category>🎥 Video</category>
<source url="https://tsecurity.de">TSECURITY.DE</source>
<content:encoded><![CDATA[<p>Author: The Morpheus - Bewertung: 65x - Views:1458 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/YU9TGNzO4iA?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p><br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Wie KI echten Protest unsichtbar macht]]></title>
<description><![CDATA[Author: The Morpheus - Bewertung: 63x - Views:683 Ich sitz vor meinem Rechner und ein Sprachmodell schreibt im Hintergrund eine Mail an den Bundestag. Inhaltlich fundiert, in meiner Sprache, von meiner eigenen Domain, und von dem, was ich selber getippt hätte, nicht mehr zu unterscheiden.
Alles B...]]></description>
<link>https://tsecurity.de/weiterlesen/3437247/3465380/wie-ki-echten-protest-unsichtbar-macht/</link>
<pubDate>Sun, 26 Apr 2026 10:22:23 +0200</pubDate>
<category>🎥 Video</category>
<source url="https://tsecurity.de">TSECURITY.DE</source>
<content:encoded><![CDATA[<p>Author: The Morpheus - Bewertung: 63x - Views:683 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/8lPPYN3PPxo?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>Ich sitz vor meinem Rechner und ein Sprachmodell schreibt im Hintergrund eine Mail an den Bundestag. Inhaltlich fundiert, in meiner Sprache, von meiner eigenen Domain, und von dem, was ich selber getippt hätte, nicht mehr zu unterscheiden.<br />
Alles Bots.<br />
Das war 2019 die Antwort der CDU, als zwischen 170.000 und 200.000 Menschen europaweit gegen die Uploadfilter auf die Straße gegangen sind. <br />
Wie das, was damals uns vorgeworfen wurde heute Realität wurde, darüber müssen wir dringend reden!<br />
<br />
[Werbung] Hier geht's zu unserem Partner TradeRepublic:<br />
https://trade.re/morpheus<br />
<br />
MorphReader im PlayStore: https://play.google.com/store/apps/details?id=de.themorpheus.morph_reader_app&hl=de<br />
<br />
MorphReader im App Store: https://apps.apple.com/de/app/morphreader/id6741467699?platform=iphone<br />
<br />
RSS-Feed: https://www.patreon.com/collection/880029?view=expanded<br />
<br />
Bootstrap Academy: https://bootstrap.academy/<br />
https://github.com/Bootstrap-Academy/<br />
<br />
Instagram: https://www.instagram.com/themorpheustuts/<br />
<br />
Quellen:<br />
https://kdrive.infomaniak.com/app/share/1794086/4778d2ae-fb11-403e-bfe5-74922401c8d3<br />
<br />
Meine anderen Kanäle und Projekte: the-morpheus.de/<br />
<br />
_Selbst *kostenlos Informatik lernen* auf meiner Website:_ https://bootstrap.academy/<br />
<br />
_Discord:_<br />
https://the-morpheus.de/discord.html<br />
<br />
_Unterstützt mich - Danke!:_<br />
https://www.patreon.com/user?u=5322110<br />
https://www.paypal.me/TheMorpheus<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Es gab keinen "Signal-Hack". #technews #cybersecurity #bundesregierung]]></title>
<description><![CDATA[Author: The Morpheus - Bewertung: 73x - Views:1046]]></description>
<link>https://tsecurity.de/weiterlesen/3435717/3463850/es-gab-keinen-signal-hack-technews-cybersecurity-bundesregierung/</link>
<pubDate>Sat, 25 Apr 2026 12:37:51 +0200</pubDate>
<category>🎥 Video</category>
<source url="https://tsecurity.de">TSECURITY.DE</source>
<content:encoded><![CDATA[<p>Author: The Morpheus - Bewertung: 73x - Views:1046 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/odG4YuqBbO0?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p><br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Das denkt Palantir also wirklich. #technews #cybersecurity #palantir]]></title>
<description><![CDATA[Author: The Morpheus - Bewertung: 101x - Views:2293]]></description>
<link>https://tsecurity.de/weiterlesen/3433266/3461399/das-denkt-palantir-also-wirklich-technews-cybersecurity-palantir/</link>
<pubDate>Fri, 24 Apr 2026 14:08:53 +0200</pubDate>
<category>🎥 Video</category>
<source url="https://tsecurity.de">TSECURITY.DE</source>
<content:encoded><![CDATA[<p>Author: The Morpheus - Bewertung: 101x - Views:2293 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/uHxZEMIy1aQ?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p><br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[UN-Cybercrime-Konvention: Eine Datenschutz-Katastrophe.. #technews #cybersecurity]]></title>
<description><![CDATA[Author: The Morpheus - Bewertung: 30x - Views:775]]></description>
<link>https://tsecurity.de/weiterlesen/3430457/3458590/un-cybercrime-konvention-eine-datenschutz-katastrophe-technews-cybersecurity/</link>
<pubDate>Thu, 23 Apr 2026 17:23:41 +0200</pubDate>
<category>🎥 Video</category>
<source url="https://tsecurity.de">TSECURITY.DE</source>
<content:encoded><![CDATA[<p>Author: The Morpheus - Bewertung: 30x - Views:775 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/oO_o38S_mf0?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p><br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[ADHS Autismus Interview Stream]]></title>
<description><![CDATA[Author: The Morpheus Tutorials - Bewertung: 9x - Views:120]]></description>
<link>https://tsecurity.de/weiterlesen/3429992/3458125/adhs-autismus-interview-stream/</link>
<pubDate>Thu, 23 Apr 2026 14:57:36 +0200</pubDate>
<category>🎥 Video</category>
<source url="https://tsecurity.de">TSECURITY.DE</source>
<content:encoded><![CDATA[<p>Author: The Morpheus Tutorials - Bewertung: 9x - Views:120 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/P9Faaqi00Nc?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p><br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Die DMs sind offen: Ciao Ende-zu-Ende-Verschlüsselung #technews #meta #instagram]]></title>
<description><![CDATA[Author: The Morpheus - Bewertung: 74x - Views:2031]]></description>
<link>https://tsecurity.de/weiterlesen/3413823/3441956/die-dms-sind-offen-ciao-ende-zu-ende-verschluesselung-technews-meta-instagram/</link>
<pubDate>Fri, 17 Apr 2026 14:20:43 +0200</pubDate>
<category>🎥 Video</category>
<source url="https://tsecurity.de">TSECURITY.DE</source>
<content:encoded><![CDATA[<p>Author: The Morpheus - Bewertung: 74x - Views:2031 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/JAF5f-Q2gGY?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p><br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Wie gefährlich ist Claude Mythos WIRKLICH?]]></title>
<description><![CDATA[Author: The Morpheus - Bewertung: 138x - Views:1552 Anthropic hat quasi gerade die Einführung von Skynet veröffentlicht, allerdings mit etwas mehr PR Budget. Claude Mythos,soll so gut im Hacking sein, dass es eine Gefahr für uns alle ist. Deshalb wollen sie es noch nicht veröffentlichen, sondern ...]]></description>
<link>https://tsecurity.de/weiterlesen/3411204/3439337/wie-gefaehrlich-ist-claude-mythos-wirklich/</link>
<pubDate>Thu, 16 Apr 2026 17:38:45 +0200</pubDate>
<category>🎥 Video</category>
<source url="https://tsecurity.de">TSECURITY.DE</source>
<content:encoded><![CDATA[<p>Author: The Morpheus - Bewertung: 138x - Views:1552 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/KoR9Szqg4ao?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>Anthropic hat quasi gerade die Einführung von Skynet veröffentlicht, allerdings mit etwas mehr PR Budget. Claude Mythos,soll so gut im Hacking sein, dass es eine Gefahr für uns alle ist. Deshalb wollen sie es noch nicht veröffentlichen, sondern nur ausgewählte Firmen bekommen Zugriff darauf. Damit die sich erstmal vorbereiten können und auf ihre Farm in Neuseeland auswandern können oder so. Aber - Wir sind es von den KI-Firmen gewohnt, dass die sich gerne aufplustern und die Fähigkeiten ihrer KI auch mal mit paradoxem Marketing übertreiben, damit der Aktienkurs brrrrt geht. Deshalb versuchen wir zu klären: Was ist wirklich dran an diesen mythischen Fähigkeiten von Claude. Denn die würden uns durchaus richtig üble Probleme bereiten. Ich hab mir die Berichte durchgelesen und auch versucht die tatsächlichen Hackerfähigkeiten von Claude 5 zu schätzen. Und ich hab natürlich die Vorgängerversion eingehend getestet und kann euch da sagen, ob so ein Sprung realistisch wäre. Das wichtigste aber: Wenn das alles so stimmt, wie f*ked sind wir eigentlich dann?<br />
Und der vollständig halber: Gerade in DIESEM Moment ist Anthropic Claude Opus 4.7 herausgekommen. Ich teste natürlich die Tools auch damit, wichtig ist aber, 4.7 ist NICHT Mythos. Aber so eine Art Zwischending (zumindest nach meiner ersten Erfahrung).<br />
<br />
Mit diesem (open source und gratis) Tool von mir selbst hab ich die Tests durchgeführt:<br />
https://bootlens.com/<br />
<br />
[Werbung] Hier geht's zu unserem Partner SNOCKS:<br />
https://snocks.ly/morpheusyoutube <br />
Code: morpheusyoutube20<br />
<br />
MorphReader im PlayStore: https://play.google.com/store/apps/details?id=de.themorpheus.morph_reader_app&hl=de<br />
<br />
MorphReader im App Store: https://apps.apple.com/de/app/morphreader/id6741467699?platform=iphone<br />
<br />
RSS-Feed: https://www.patreon.com/collection/880029?view=expanded<br />
<br />
Bootstrap Academy: https://bootstrap.academy/<br />
https://github.com/Bootstrap-Academy/<br />
<br />
Instagram: https://www.instagram.com/themorpheustuts/<br />
<br />
Quellen:<br />
https://kdrive.infomaniak.com/app/share/1794086/f0faaf6d-981b-450b-8330-7bead7ac121d<br />
<br />
Meine anderen Kanäle und Projekte: the-morpheus.de/<br />
<br />
_Selbst *kostenlos Informatik lernen* auf meiner Website:_ https://bootstrap.academy/<br />
<br />
_Discord:_<br />
https://the-morpheus.de/discord.html<br />
<br />
_Unterstützt mich - Danke!:_<br />
https://www.patreon.com/user?u=5322110<br />
https://www.paypal.me/TheMorpheus<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Smart Move, Chrome. #cybersecurity #google]]></title>
<description><![CDATA[Author: The Morpheus - Bewertung: 0x - Views:12]]></description>
<link>https://tsecurity.de/weiterlesen/3407686/3435819/smart-move-chrome-cybersecurity-google/</link>
<pubDate>Wed, 15 Apr 2026 16:25:27 +0200</pubDate>
<category>🎥 Video</category>
<source url="https://tsecurity.de">TSECURITY.DE</source>
<content:encoded><![CDATA[<p>Author: The Morpheus - Bewertung: 0x - Views:12 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/7zZ57IMK8yc?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p><br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Wie weit kommt mein Coding-Agent ohne mich?]]></title>
<description><![CDATA[Author: The Morpheus Tutorials - Bewertung: 13x - Views:156 Ich hab einen autonomen Coding-Agent auf mein Community-Projekt losgelassen — the dmz, unser Open-Source-Awareness-Game aus dem Stream. Gelaufen ist das Ganze auf einer OpenClaw-Instanz von Hostinger, weit weg von meinem eigenen Setup, m...]]></description>
<link>https://tsecurity.de/weiterlesen/3401129/3429262/wie-weit-kommt-mein-coding-agent-ohne-mich/</link>
<pubDate>Mon, 13 Apr 2026 16:42:39 +0200</pubDate>
<category>🎥 Video</category>
<source url="https://tsecurity.de">TSECURITY.DE</source>
<content:encoded><![CDATA[<p>Author: The Morpheus Tutorials - Bewertung: 13x - Views:156 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/S60pby2p7Yw?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>Ich hab einen autonomen Coding-Agent auf mein Community-Projekt losgelassen — the dmz, unser Open-Source-Awareness-Game aus dem Stream. Gelaufen ist das Ganze auf einer OpenClaw-Instanz von Hostinger, weit weg von meinem eigenen Setup, mit MiniMax als Brain und Telegram als Heartbeat. Github fand das wohl nur so halb lustig :)<br />
<br />
Zu unserem Partner Hostinger:<br />
https://www.hostg.xyz/SHJ2O<br />
<br />
Zum MorphReader: <br />
Android: https://play.google.com/store/apps/details?id=de.themorpheus.morph_reader_app<br />
Apple: https://apps.apple.com/de/app/morphreader/id6741467699?platform=iphone<br />
<br />
RSS Feed: https://www.patreon.com/collection/880029?view=expanded<br />
<br />
Instagram: https://www.instagram.com/themorpheustuts/<br />
<br />
Meine anderen Kanäle und Projekte: the-morpheus.de/<br />
<br />
_Selbst *kostenlos Informatik lernen* auf meiner Website:_ https://bootstrap.academy/<br />
<br />
_Discord:_<br />
https://the-morpheus.de/discord.html<br />
<br />
_Unterstützt mich - Danke!:_<br />
https://www.patreon.com/user?u=5322110<br />
https://www.paypal.me/TheMorpheus<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Was gerade WIRKLICH mit unseren JOBS passiert]]></title>
<description><![CDATA[Author: The Morpheus - Bewertung: 312x - Views:3029 "Mir macht der Job keinen Spaß mehr."
Das hat mir letzte Woche ein Softwareentwickler geschrieben. Kumpel von mir, zehn Jahre Erfahrung. Nicht wegen einem Projekt, nicht wegen einer Frage. Sein Alltag sieht so aus: Ticket auf. Copilot generiert ...]]></description>
<link>https://tsecurity.de/weiterlesen/3396377/3424507/was-gerade-wirklich-mit-unseren-jobs-passiert/</link>
<pubDate>Fri, 10 Apr 2026 20:22:50 +0200</pubDate>
<category>🎥 Video</category>
<source url="https://tsecurity.de">TSECURITY.DE</source>
<content:encoded><![CDATA[<p>Author: The Morpheus - Bewertung: 312x - Views:3029 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/SHKBrkpYssM?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>"Mir macht der Job keinen Spaß mehr."<br />
Das hat mir letzte Woche ein Softwareentwickler geschrieben. Kumpel von mir, zehn Jahre Erfahrung. Nicht wegen einem Projekt, nicht wegen einer Frage. Sein Alltag sieht so aus: Ticket auf. Copilot generiert einen Vorschlag. Er liest den Code. Er versteht ihn ungefähr. Er hat 40 Minuten Budget pro Ticket, weil sein Projektleiter davon ausgeht, dass die KI ja schneller macht. Also committed er. Nächstes Ticket. Am Ende des Tages weiß er nicht, was er gemacht hat. Er sagt, er fühlt sich wie Qualitätskontrolle für eine Maschine, der er nicht traut. Er babysittet die KI. Aber er hat nicht genug Zeit, um sie wirklich zu prüfen.<br />
Und leider trifft das gerade sehr viele Branchen gleichzeitig.<br />
<br />
[Werbung] Hier kommt ihr zu dem Oster-Angebot von Notebooksbilliger:<br />
https://www.notebooksbilliger.de/notebooks/hp+compaq+notebooks/gaming/gaming+highlights?nbbct=7009_morpheus_ext-q2-hp-omen<br />
<br />
<br />
MorphReader im PlayStore: https://play.google.com/store/apps/details?id=de.themorpheus.morph_reader_app&hl=de<br />
<br />
MorphReader im App Store: https://apps.apple.com/de/app/morphreader/id6741467699?platform=iphone<br />
<br />
RSS-Feed: https://www.patreon.com/collection/880029?view=expanded<br />
<br />
Bootstrap Academy: https://bootstrap.academy/<br />
https://github.com/Bootstrap-Academy/<br />
<br />
Instagram: https://www.instagram.com/themorpheustuts/<br />
<br />
Quellen:<br />
https://kdrive.infomaniak.com/app/share/1794086/e7288167-df45-4869-a90f-503ce7a884dd<br />
<br />
Meine anderen Kanäle und Projekte: the-morpheus.de/<br />
<br />
_Selbst *kostenlos Informatik lernen* auf meiner Website:_ https://bootstrap.academy/<br />
<br />
_Discord:_<br />
https://the-morpheus.de/discord.html<br />
<br />
_Unterstützt mich - Danke!:_<br />
https://www.patreon.com/user?u=5322110<br />
https://www.paypal.me/TheMorpheus<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Lasst uns entwickeln :)]]></title>
<description><![CDATA[Author: The Morpheus Tutorials - Bewertung: 10x - Views:120]]></description>
<link>https://tsecurity.de/weiterlesen/3392316/3420446/lasst-uns-entwickeln/</link>
<pubDate>Thu, 09 Apr 2026 14:41:39 +0200</pubDate>
<category>🎥 Video</category>
<source url="https://tsecurity.de">TSECURITY.DE</source>
<content:encoded><![CDATA[<p>Author: The Morpheus Tutorials - Bewertung: 10x - Views:120 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/AhqkVn3ylKE?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p><br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Hacktivismus mal anders? (und ohne Hacken)]]></title>
<description><![CDATA[Author: The Morpheus - Bewertung: 3x - Views:20]]></description>
<link>https://tsecurity.de/weiterlesen/3391913/3420043/hacktivismus-mal-anders-und-ohne-hacken/</link>
<pubDate>Thu, 09 Apr 2026 12:42:04 +0200</pubDate>
<category>🎥 Video</category>
<source url="https://tsecurity.de">TSECURITY.DE</source>
<content:encoded><![CDATA[<p>Author: The Morpheus - Bewertung: 3x - Views:20 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/flxKADSYHI8?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p><br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Anthropics neuestes Modell ist ein Profihacker?! #technews #cybersecurity #ai]]></title>
<description><![CDATA[Author: The Morpheus - Bewertung: 1x - Views:12]]></description>
<link>https://tsecurity.de/weiterlesen/3389724/3417854/anthropics-neuestes-modell-ist-ein-profihacker-technews-cybersecurity-ai/</link>
<pubDate>Wed, 08 Apr 2026 17:22:17 +0200</pubDate>
<category>🎥 Video</category>
<source url="https://tsecurity.de">TSECURITY.DE</source>
<content:encoded><![CDATA[<p>Author: The Morpheus - Bewertung: 1x - Views:12 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/S4BmwNGCRok?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p><br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Rechenzentren im ALL sind ein SCAM]]></title>
<description><![CDATA[Author: The Morpheus - Bewertung: 29x - Views:377 NVIDIA hat letzte Woche auf der GTC GPUs fürs Weltall angekündigt. Rechenzentren im Orbit. Und auf den ersten Blick ergibt das perfekt Sinn. Das Weltall ist kalt, Server überhitzen, also ab damit ins All. Klingt smart.
Nur: Euer Thermos hält den K...]]></description>
<link>https://tsecurity.de/weiterlesen/3368490/3396620/rechenzentren-im-all-sind-ein-scam/</link>
<pubDate>Tue, 31 Mar 2026 17:23:11 +0200</pubDate>
<category>🎥 Video</category>
<source url="https://tsecurity.de">TSECURITY.DE</source>
<content:encoded><![CDATA[<p>Author: The Morpheus - Bewertung: 29x - Views:377 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/SA8KgUhpajI?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>NVIDIA hat letzte Woche auf der GTC GPUs fürs Weltall angekündigt. Rechenzentren im Orbit. Und auf den ersten Blick ergibt das perfekt Sinn. Das Weltall ist kalt, Server überhitzen, also ab damit ins All. Klingt smart.<br />
Nur: Euer Thermos hält den Kaffee heiß, WEIL darin Vakuum ist. Vakuum leitet Wärme nicht ab; es hält sie fest. Selbe Physik. Und genau die herrscht im Weltraum.<br />
Und trotzdem: NVIDIA, Google, SpaceX, alle wollen gleichzeitig ins All. Entweder sind die alle dumm. Oder die Kühlung war nie der eigentliche Grund.<br />
<br />
[Werbung] Hier geht's zu den NAS-Systemen von UGREEN:<br />
UGREEN NAS Collection:<br />
https://nas.de.ugreen.com/UTGDX6<br />
<br />
UGREEN NAS DH4300 Plus:<br />
https://nas.de.ugreen.com/CwKzJh<br />
<br />
Amazon:<br />
UGREEN NAS Collection:<br />
https://bit.ly/3Q47Hb1<br />
<br />
UGREEN NAS DH4300 Plus:<br />
https://bit.ly/47ZiKsd<br />
<br />
#UGREENNAS #UGREEN<br />
<br />
MorphReader im PlayStore: https://play.google.com/store/apps/details?id=de.themorpheus.morph_reader_app&hl=de<br />
<br />
MorphReader im App Store: https://apps.apple.com/de/app/morphreader/id6741467699?platform=iphone<br />
<br />
RSS-Feed: https://www.patreon.com/collection/880029?view=expanded<br />
<br />
Bootstrap Academy: https://bootstrap.academy/<br />
https://github.com/Bootstrap-Academy/<br />
<br />
Instagram: https://www.instagram.com/themorpheustuts/<br />
<br />
Quellen:<br />
https://kdrive.infomaniak.com/app/share/1794086/1298de3e-9e61-417a-be17-cc108d9b316b<br />
<br />
Meine anderen Kanäle und Projekte: the-morpheus.de/<br />
<br />
_Selbst *kostenlos Informatik lernen* auf meiner Website:_ https://bootstrap.academy/<br />
<br />
_Discord:_<br />
https://the-morpheus.de/discord.html<br />
<br />
_Unterstützt mich - Danke!:_<br />
https://www.patreon.com/user?u=5322110<br />
https://www.paypal.me/TheMorpheus<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[KI-Text-Detektor: Irgendwas ist da wohl schiefgelaufen..]]></title>
<description><![CDATA[Author: The Morpheus - Bewertung: 92x - Views:1425]]></description>
<link>https://tsecurity.de/weiterlesen/3367639/3395769/ki-text-detektor-irgendwas-ist-da-wohl-schiefgelaufen/</link>
<pubDate>Tue, 31 Mar 2026 12:55:42 +0200</pubDate>
<category>🎥 Video</category>
<source url="https://tsecurity.de">TSECURITY.DE</source>
<content:encoded><![CDATA[<p>Author: The Morpheus - Bewertung: 92x - Views:1425 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/fWFiFkUcV7c?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p><br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Staatliche Biometrie-Daten an Privatunternehmen weitergeben? "Tolle" Idee. #cybersecurity #technews]]></title>
<description><![CDATA[Author: The Morpheus - Bewertung: 19x - Views:378]]></description>
<link>https://tsecurity.de/weiterlesen/3360920/3389050/staatliche-biometrie-daten-an-privatunternehmen-weitergeben-tolle-idee-cybersecurity-technews/</link>
<pubDate>Sat, 28 Mar 2026 14:20:24 +0100</pubDate>
<category>🎥 Video</category>
<source url="https://tsecurity.de">TSECURITY.DE</source>
<content:encoded><![CDATA[<p>Author: The Morpheus - Bewertung: 19x - Views:378 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/DB8wmztmh04?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p><br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[350k Unternehmen wurden lahmgelegt: Von Lockbit.]]></title>
<description><![CDATA[Author: The Morpheus - Bewertung: 5x - Views:51 Werbung | Ich durfe Teil der Doku von @orange  und @OrangeCyberdefense  sein!

Hier gehts zur vollen Doku: https://www.youtube.com/watch?v=0pchn3bkgs8

#werbung #cybersecurity #doku]]></description>
<link>https://tsecurity.de/weiterlesen/3354722/3382852/350k-unternehmen-wurden-lahmgelegt-von-lockbit/</link>
<pubDate>Thu, 26 Mar 2026 11:37:53 +0100</pubDate>
<category>🎥 Video</category>
<source url="https://tsecurity.de">TSECURITY.DE</source>
<content:encoded><![CDATA[<p>Author: The Morpheus - Bewertung: 5x - Views:51 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/qH_beaLdbN4?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>Werbung | Ich durfe Teil der Doku von @orange  und @OrangeCyberdefense  sein!<br />
<br />
Hier gehts zur vollen Doku: https://www.youtube.com/watch?v=0pchn3bkgs8<br />
<br />
#werbung #cybersecurity #doku<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Das Social Media-Verbot ist ein ALBTRAUM]]></title>
<description><![CDATA[Author: The Morpheus - Bewertung: 185x - Views:1597 Ich nutze Linux — seit über zehn Jahren. Und seit kurzem exklusiv. Und genau das soll jetzt illegal werden.
Nicht Linux selbst, aber das, wofür es steht: ein System einrichten, ohne jemandem zu beweisen, wie alt du bist, ohne dich zu identifizie...]]></description>
<link>https://tsecurity.de/weiterlesen/3346557/3374687/das-social-media-verbot-ist-ein-albtraum/</link>
<pubDate>Mon, 23 Mar 2026 20:21:38 +0100</pubDate>
<category>🎥 Video</category>
<source url="https://tsecurity.de">TSECURITY.DE</source>
<content:encoded><![CDATA[<p>Author: The Morpheus - Bewertung: 185x - Views:1597 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/4EGOyxHhW_Q?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>Ich nutze Linux — seit über zehn Jahren. Und seit kurzem exklusiv. Und genau das soll jetzt illegal werden.<br />
Nicht Linux selbst, aber das, wofür es steht: ein System einrichten, ohne jemandem zu beweisen, wie alt du bist, ohne dich zu identifizieren, ohne dich zu registrieren.<br />
Gesetzgeber in der EU, den USA und im Bundestag arbeiten gerade gleichzeitig an Gesetzen, die jedes Betriebssystem zwingen sollen, bei der Einrichtung dein Alter abzufragen. Und ja — das schließt Linux mit ein.<br />
Ich hab mir mein System so gebaut, wie ich es will, mit den Tools, die ich will, ohne dass mir irgendjemand reinredet. Das ist digitale Souveränität. Und die steht jetzt zur Disposition.<br />
Das Ganze wird verkauft als Kinderschutz. Aber ich sag euch: Das hat mit Kinderschutz ungefähr so viel zu tun wie ein Apfel mit Apple.<br />
<br />
Hol dir deine persönlichen Daten mit Incogni zurück! Nutze den Code MORPHEUS über den Link unten und sichere dir 60 % Rabatt auf ein Jahresabo: http://incogni.com/morpheus<br />
<br />
MorphReader im PlayStore: https://play.google.com/store/apps/details?id=de.themorpheus.morph_reader_app&hl=de<br />
<br />
MorphReader im App Store: https://apps.apple.com/de/app/morphreader/id6741467699?platform=iphone<br />
<br />
RSS-Feed: https://www.patreon.com/collection/880029?view=expanded<br />
<br />
Bootstrap Academy: https://bootstrap.academy/<br />
https://github.com/Bootstrap-Academy/<br />
<br />
Instagram: https://www.instagram.com/themorpheustuts/<br />
<br />
Quellen:<br />
https://docs.google.com/document/d/1Ti6jBjEvYWqXx1LrVGSBRMbS_x21LXxso7eJcxQIKMg/edit?usp=sharing<br />
<br />
Meine anderen Kanäle und Projekte: the-morpheus.de/<br />
<br />
_Selbst *kostenlos Informatik lernen* auf meiner Website:_ https://bootstrap.academy/<br />
<br />
_Discord:_<br />
https://the-morpheus.de/discord.html<br />
<br />
_Unterstützt mich - Danke!:_<br />
https://www.patreon.com/user?u=5322110<br />
https://www.paypal.me/TheMorpheus<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Freiwillige Chatkontrolle endet nun: Wie geht es jetzt weiter? #cybersecurity #eu #chatkontrolle]]></title>
<description><![CDATA[Author: The Morpheus - Bewertung: 5x - Views:83]]></description>
<link>https://tsecurity.de/weiterlesen/3334457/3362587/freiwillige-chatkontrolle-endet-nun-wie-geht-es-jetzt-weiter-cybersecurity-eu-chatkontrolle/</link>
<pubDate>Thu, 19 Mar 2026 17:21:47 +0100</pubDate>
<category>🎥 Video</category>
<source url="https://tsecurity.de">TSECURITY.DE</source>
<content:encoded><![CDATA[<p>Author: The Morpheus - Bewertung: 5x - Views:83 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/4qYj2LclCLw?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p><br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Nvidia DLSS 5 erntet ordentlich Kritik: Zurecht? #technews #nvidia #dlss5 #ai]]></title>
<description><![CDATA[Author: The Morpheus - Bewertung: 11x - Views:498]]></description>
<link>https://tsecurity.de/weiterlesen/3331283/3359413/nvidia-dlss-5-erntet-ordentlich-kritik-zurecht-technews-nvidia-dlss5-ai/</link>
<pubDate>Wed, 18 Mar 2026 15:10:13 +0100</pubDate>
<category>🎥 Video</category>
<source url="https://tsecurity.de">TSECURITY.DE</source>
<content:encoded><![CDATA[<p>Author: The Morpheus - Bewertung: 11x - Views:498 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/RRJJ2ZLj56g?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p><br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Hardware as a Service: Die Zukunft?]]></title>
<description><![CDATA[Author: The Morpheus - Bewertung: 72x - Views:807 Ich wollte Battlefield 6 zocken. Problem: Ich nutze exklusiv Linux. Battlefield läuft nicht auf Linux. Also hab ich mir für 22€ im Monat einen virtuellen Gaming-PC bei Nvidia gemietet. Und dann hab ich was gemacht, was man nicht machen sollte. Ich...]]></description>
<link>https://tsecurity.de/weiterlesen/3322516/3350646/hardware-as-a-service-die-zukunft/</link>
<pubDate>Sun, 15 Mar 2026 10:21:03 +0100</pubDate>
<category>🎥 Video</category>
<source url="https://tsecurity.de">TSECURITY.DE</source>
<content:encoded><![CDATA[<p>Author: The Morpheus - Bewertung: 72x - Views:807 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/60IxPVX505o?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>Ich wollte Battlefield 6 zocken. Problem: Ich nutze exklusiv Linux. Battlefield läuft nicht auf Linux. Also hab ich mir für 22€ im Monat einen virtuellen Gaming-PC bei Nvidia gemietet. Und dann hab ich was gemacht, was man nicht machen sollte. Ich hab nachgerechnet.<br />
<br />
Hier geht's zu unserem Partner, Hostinger:<br />
https://www.hostg.xyz/SHJ0K<br />
Spart 10% mit dem Code Morpheus10<br />
<br />
MorphReader im PlayStore: https://play.google.com/store/apps/details?id=de.themorpheus.morph_reader_app&hl=de<br />
<br />
MorphReader im App Store: https://apps.apple.com/de/app/morphreader/id6741467699?platform=iphone<br />
<br />
RSS-Feed: https://www.patreon.com/collection/880029?view=expanded<br />
<br />
Bootstrap Academy: https://bootstrap.academy/<br />
https://github.com/Bootstrap-Academy/<br />
<br />
Instagram: https://www.instagram.com/themorpheustuts/<br />
<br />
Quellen:<br />
https://docs.google.com/document/d/1l2eAJganGfJKMl3z9ayGuDQ7Wlsg5sky5FeB6mhOduE/edit?usp=sharing<br />
<br />
Meine anderen Kanäle und Projekte: the-morpheus.de/<br />
<br />
_Selbst *kostenlos Informatik lernen* auf meiner Website:_ https://bootstrap.academy/<br />
<br />
_Discord:_<br />
https://the-morpheus.de/discord.html<br />
<br />
_Unterstützt mich - Danke!:_<br />
https://www.patreon.com/user?u=5322110<br />
https://www.paypal.me/TheMorpheus<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Lasst uns entwickeln :)]]></title>
<description><![CDATA[Author: The Morpheus Tutorials - Bewertung: 8x - Views:77]]></description>
<link>https://tsecurity.de/weiterlesen/3315884/3344014/lasst-uns-entwickeln/</link>
<pubDate>Thu, 12 Mar 2026 14:52:23 +0100</pubDate>
<category>🎥 Video</category>
<source url="https://tsecurity.de">TSECURITY.DE</source>
<content:encoded><![CDATA[<p>Author: The Morpheus Tutorials - Bewertung: 8x - Views:77 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/a1QdG2cP-VI?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p><br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Was Google und OpenAI uns gerade verschweigen]]></title>
<description><![CDATA[Author: The Morpheus - Bewertung: 55x - Views:536 Wir haben die Schwelle zur AGI überschritten. Allgemeine künstliche Intelligenz. Nicht in Form eines Terminators, sondern leise. Und das Verrückteste daran? Wir merken es nicht einmal, weil wir nach den falschen Kriterien suchen. Als Anthropic let...]]></description>
<link>https://tsecurity.de/weiterlesen/3305290/3333419/was-google-und-openai-uns-gerade-verschweigen/</link>
<pubDate>Sun, 08 Mar 2026 11:09:31 +0100</pubDate>
<category>🎥 Video</category>
<source url="https://tsecurity.de">TSECURITY.DE</source>
<content:encoded><![CDATA[<p>Author: The Morpheus - Bewertung: 55x - Views:536 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/0dN130zMi0s?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>Wir haben die Schwelle zur AGI überschritten. Allgemeine künstliche Intelligenz. Nicht in Form eines Terminators, sondern leise. Und das Verrückteste daran? Wir merken es nicht einmal, weil wir nach den falschen Kriterien suchen. Als Anthropic letzte Woche ein einziges Tool angekündigt hat, sind die Aktien von Cybersecurity-Giganten abgestürzt. Nicht wegen einem Produkt — wegen einer Fähigkeit. Es geht nicht nur um meine persönlichen Definition, sondern die von Google, auch wenn Google das so noch nicht sagt. Ich bin durchgegangen, hab zusammengetragen und stehe mit dieser Erkenntnis noch ziemlich alleine da. Aber lasst mich erklären. Denn das wird unser aller Leben drastisch verändern. Leider nicht unausweichlich zum Guten. AGI ist die wohl bedeutendste Revolution seit der industriellen Revolution. Eine Herstellung von Intelligenz via Chip, so wie die Dampfmaschine Muskelkraft herstellt via Dampf. <br />
KI kann jetzt alles, wofür ich studiert habe — nur billiger und schneller.<br />
Und das mit einer besseren Autokorrektur?<br />
<br />
Hier geht's zu Euria, Infomaniaks KI-Service:<br />
https://www.infomaniak.com/de/anwendungen/euria-herunterladen?utm_source=youtube&utm_medium=social&utm_campaign=themorpheusvlogs&utm_content=euria&utm_term=66851608428ed<br />
<br />
Hier geht's zum Angebot von KSuite:<br />
https://www.infomaniak.com/de/ksuite/myksuite?utm_source=youtube&utm_medium=social&utm_campaign=themorpheusvlogs&utm_content=my-ksuite&utm_term=66851608428ed<br />
<br />
MorphReader im PlayStore: https://play.google.com/store/apps/details?id=de.themorpheus.morph_reader_app&hl=de<br />
<br />
MorphReader im App Store: https://apps.apple.com/de/app/morphreader/id6741467699?platform=iphone<br />
<br />
RSS-Feed: https://www.patreon.com/collection/880029?view=expanded<br />
<br />
Bootstrap Academy: https://bootstrap.academy/<br />
https://github.com/Bootstrap-Academy/<br />
<br />
Instagram: https://www.instagram.com/themorpheustuts/<br />
<br />
Quellen:<br />
https://docs.google.com/document/d/1L-ixLzppqWHSCJLPEUEhEq6l-bGrY-xgI48X-tx2lX8/edit?usp=sharing<br />
<br />
Meine anderen Kanäle und Projekte: the-morpheus.de/<br />
<br />
_Selbst *kostenlos Informatik lernen* auf meiner Website:_ https://bootstrap.academy/<br />
<br />
_Discord:_<br />
https://the-morpheus.de/discord.html<br />
<br />
_Unterstützt mich - Danke!:_<br />
https://www.patreon.com/user?u=5322110<br />
https://www.paypal.me/TheMorpheus<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[KI am MURKSEN hindern!]]></title>
<description><![CDATA[Author: The Morpheus Tutorials - Bewertung: 1x - Views:12 KI macht Fehler. Aber man kann sie reduzieren!

Zu unserem Partner NordVPN:
https://nordvpn.com/morpheus
Dort gibt's aktuell 4 Bonusmonate auf den 2-Jahresplan

Zum MorphReader: 
Android: https://play.google.com/store/apps/details?id=de.th...]]></description>
<link>https://tsecurity.de/weiterlesen/3300212/3328341/ki-am-murksen-hindern/</link>
<pubDate>Thu, 05 Mar 2026 16:51:24 +0100</pubDate>
<category>🎥 Video</category>
<source url="https://tsecurity.de">TSECURITY.DE</source>
<content:encoded><![CDATA[<p>Author: The Morpheus Tutorials - Bewertung: 1x - Views:12 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/CEYDefSEDxY?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>KI macht Fehler. Aber man kann sie reduzieren!<br />
<br />
Zu unserem Partner NordVPN:<br />
https://nordvpn.com/morpheus<br />
Dort gibt's aktuell 4 Bonusmonate auf den 2-Jahresplan<br />
<br />
Zum MorphReader: <br />
Android: https://play.google.com/store/apps/details?id=de.themorpheus.morph_reader_app<br />
Apple: https://apps.apple.com/de/app/morphreader/id6741467699?platform=iphone<br />
<br />
RSS Feed: https://www.patreon.com/collection/880029?view=expanded<br />
<br />
Instagram: https://www.instagram.com/themorpheustuts/<br />
<br />
Meine anderen Kanäle und Projekte: the-morpheus.de/<br />
<br />
_Selbst *kostenlos Informatik lernen* auf meiner Website:_ https://bootstrap.academy/<br />
<br />
_Discord:_<br />
https://the-morpheus.de/discord.html<br />
<br />
_Unterstützt mich - Danke!:_<br />
https://www.patreon.com/user?u=5322110<br />
https://www.paypal.me/TheMorpheus<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Anthropic lehnt ab, OpenAI stimmt zu.. #ki #ai #anthropic #openai]]></title>
<description><![CDATA[Author: The Morpheus - Bewertung: 42x - Views:851]]></description>
<link>https://tsecurity.de/weiterlesen/3296885/3325014/anthropic-lehnt-ab-openai-stimmt-zu-ki-ai-anthropic-openai/</link>
<pubDate>Wed, 04 Mar 2026 12:40:05 +0100</pubDate>
<category>🎥 Video</category>
<source url="https://tsecurity.de">TSECURITY.DE</source>
<content:encoded><![CDATA[<p>Author: The Morpheus - Bewertung: 42x - Views:851 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/AbEdy78HcQc?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p><br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Das Ende der Messenger-Diskussion]]></title>
<description><![CDATA[Author: The Morpheus - Bewertung: 117x - Views:1086 Ich rufe dich an. Ich hab ein Pixel, du ein iPhone. Kein Problem. Ich schreibe dir eine E-Mail von Gmail zu Outlook. Kein Problem. Ich will dir ein lustiges Video von WhatsApp zu Discord schicken... und plötzlich baut das Internet eine 10 Meter ...]]></description>
<link>https://tsecurity.de/weiterlesen/3289667/3317796/das-ende-der-messenger-diskussion/</link>
<pubDate>Sun, 01 Mar 2026 10:26:43 +0100</pubDate>
<category>🎥 Video</category>
<source url="https://tsecurity.de">TSECURITY.DE</source>
<content:encoded><![CDATA[<p>Author: The Morpheus - Bewertung: 117x - Views:1086 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/dGv5zUwYX_k?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>Ich rufe dich an. Ich hab ein Pixel, du ein iPhone. Kein Problem. Ich schreibe dir eine E-Mail von Gmail zu Outlook. Kein Problem. Ich will dir ein lustiges Video von WhatsApp zu Discord schicken... und plötzlich baut das Internet eine 10 Meter hohe Betonmauer auf. Warum haben wir akzeptiert, dass das Internet im Jahr 2026 in Sektoren unterteilt ist, die sich gegenseitig bekriegen?<br />
<br />
Hier geht's zu unserem Partner, Hostinger:<br />
https://www.hostg.xyz/SHG76<br />
Spart 10% mit dem Code Morpheus10<br />
<br />
Checkt hier den Community Server aus: https://matrix.to/#/#morpheus_community_matrix:matrix.org<br />
<br />
Zum Hosten könnt ihr diese Dateien nutzen:<br />
https://kdrive.infomaniak.com/app/share/1794086/d87c292f-6c8e-4655-80b7-12d95916d910<br />
<br />
MorphReader im PlayStore: https://play.google.com/store/apps/details?id=de.themorpheus.morph_reader_app&hl=de<br />
<br />
MorphReader im App Store: https://apps.apple.com/de/app/morphreader/id6741467699?platform=iphone<br />
<br />
RSS-Feed: https://www.patreon.com/collection/880029?view=expanded<br />
<br />
Bootstrap Academy: https://bootstrap.academy/<br />
https://github.com/Bootstrap-Academy/<br />
<br />
Instagram: https://www.instagram.com/themorpheustuts/<br />
<br />
Links aus dem Video: <br />
https://element.io/de<br />
https://fluffy.chat/de/<br />
https://cinny.in/<br />
https://matrix.org/ecosystem/clients/<br />
https://di.day/de<br />
https://matrix.org/ecosystem/integrations/<br />
<br />
Quellen:<br />
https://uk.pcmag.com/security/162799/lawsuit-alleges-that-whatsapp-has-no-end-to-end-encryption<br />
https://www.erlang-factory.com/upload/presentations/558/efsf2012-whatsapp-scaling.pdf<br />
https://faq.whatsapp.com/820124435853543<br />
https://eprint.iacr.org/2016/1013.pdf<br />
https://signal.org/docs/specifications/doubleratchet/doubleratchet.pdf<br />
https://www.theverge.com/2024/4/3/24120278/whatsapp-down-outage-connection-issues<br />
https://www.youtube.com/watch?v=rO37rz1dhkQ<br />
https://arstechnica.com/information-technology/2012/05/skype-replaces-p2p-supernodes-with-linux-boxes-hosted-by-microsoft/<br />
https://techcrunch.com/2025/02/28/microsoft-hangs-up-on-skype-service-to-shut-down-may-5-2025/<br />
https://learn.microsoft.com/en-us/microsoftteams/media/microsoft-teams-online-call-flows-figure01.png<br />
https://github.com/matrix-org/matrix-spec/issues/975<br />
https://www.wired.com/story/signal-launches-usersnames-phone-number-privacy/<br />
https://www.youtube.com/shorts/UgtisaN5YyY<br />
https://www.bbc.com/news/articles/c8jmzd972leo<br />
https://docs.chat.tu-berlin.de/<br />
https://matrix.tu-dresden.de/#/welcome<br />
https://www.lmu.de/en/about-lmu/structure/central-university-administration/it-services-division/it-service-desk/central-it-services/lmu-chat-matrix/<br />
https://www.scc.kit.edu/dienste/matrix.php<br />
https://www.giga.de/tech/nach-discord-shitstorm-ist-diese-24-jahre-alte-retro-software-so-gefragt-wie-nie--01KHRPBKENNRWZ74D1NFSY3GJ7<br />
https://www.unwantedwitness.org/why-we-still-recommend-signal-over-whatsapp-even-though-they-both-use-end-to-end-encryption/<br />
https://qconnewyork.com/ny2018/ny2018/presentation/skype%E2%80%99s-re-architecture-super-nodes-scalable-server-based.html<br />
https://www.reddit.com/r/pidgin/comments/v86u5c/google_chat_xmpp_settings/<br />
https://www.youtube.com/watch?v=wDk6l3tPBuw<br />
<br />
Meine anderen Kanäle und Projekte: the-morpheus.de/<br />
<br />
_Selbst *kostenlos Informatik lernen* auf meiner Website:_ https://bootstrap.academy/<br />
<br />
_Discord:_<br />
https://the-morpheus.de/discord.html<br />
<br />
_Unterstützt mich - Danke!:_<br />
https://www.patreon.com/user?u=5322110<br />
https://www.paypal.me/TheMorpheus<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Bitte, lasst das einfach. #cybersecurity #openai]]></title>
<description><![CDATA[Author: The Morpheus - Bewertung: 2x - Views:4]]></description>
<link>https://tsecurity.de/weiterlesen/3288477/3316606/bitte-lasst-das-einfach-cybersecurity-openai/</link>
<pubDate>Sat, 28 Feb 2026 12:52:26 +0100</pubDate>
<category>🎥 Video</category>
<source url="https://tsecurity.de">TSECURITY.DE</source>
<content:encoded><![CDATA[<p>Author: The Morpheus - Bewertung: 2x - Views:4 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/nOQdn4lnyrE?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p><br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Entwickler reden über IT]]></title>
<description><![CDATA[Author: The Morpheus Tutorials - Bewertung: 13x - Views:319 Stream mit Kevin]]></description>
<link>https://tsecurity.de/weiterlesen/3284307/3312436/entwickler-reden-ueber-it/</link>
<pubDate>Thu, 26 Feb 2026 14:52:08 +0100</pubDate>
<category>🎥 Video</category>
<source url="https://tsecurity.de">TSECURITY.DE</source>
<content:encoded><![CDATA[<p>Author: The Morpheus Tutorials - Bewertung: 13x - Views:319 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/C7GZwG2AjsU?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>Stream mit Kevin<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Verlasst euch nicht allein auf Passwortmanager.. #cybersecurity #passwortmanager #2fa]]></title>
<description><![CDATA[Author: The Morpheus - Bewertung: 5x - Views:16]]></description>
<link>https://tsecurity.de/weiterlesen/3279187/3307316/verlasst-euch-nicht-allein-auf-passwortmanager-cybersecurity-passwortmanager-2fa/</link>
<pubDate>Tue, 24 Feb 2026 14:51:31 +0100</pubDate>
<category>🎥 Video</category>
<source url="https://tsecurity.de">TSECURITY.DE</source>
<content:encoded><![CDATA[<p>Author: The Morpheus - Bewertung: 5x - Views:16 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/x-enuGtnSaQ?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p><br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Warum gerade alle ChatGPT kündigen]]></title>
<description><![CDATA[Author: The Morpheus - Bewertung: 159x - Views:1817 Ich zahle jeden Monat über 600€ an OpenAI. Mein teuerstes Abo insgesamt. Bis gestern. Warum? Nicht wegen des Geldes. Sondern weil ich Beweise gefunden habe. Beweise dafür, dass OpenAI sein Produkt nicht verbessert, sondern es aktiv und mit volle...]]></description>
<link>https://tsecurity.de/weiterlesen/3274866/3302995/warum-gerade-alle-chatgpt-kuendigen/</link>
<pubDate>Sun, 22 Feb 2026 12:36:50 +0100</pubDate>
<category>🎥 Video</category>
<source url="https://tsecurity.de">TSECURITY.DE</source>
<content:encoded><![CDATA[<p>Author: The Morpheus - Bewertung: 159x - Views:1817 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/GUiKWVLRjrw?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>Ich zahle jeden Monat über 600€ an OpenAI. Mein teuerstes Abo insgesamt. Bis gestern. Warum? Nicht wegen des Geldes. Sondern weil ich Beweise gefunden habe. Beweise dafür, dass OpenAI sein Produkt nicht verbessert, sondern es aktiv und mit voller Absicht... dümmer macht. Und die technische Ursache dafür ist so brillant wie perfide. <br />
<br />
Schnappt euch hier den Deal bei Incogni: http://incogni.com/morpheus<br />
<br />
MorphReader im PlayStore: https://play.google.com/store/apps/details?id=de.themorpheus.morph_reader_app&hl=de<br />
<br />
MorphReader im App Store: https://apps.apple.com/de/app/morphreader/id6741467699?platform=iphone<br />
<br />
RSS-Feed: https://www.patreon.com/collection/880029?view=expanded<br />
<br />
Bootstrap Academy: https://bootstrap.academy/<br />
https://github.com/Bootstrap-Academy/<br />
<br />
Instagram: https://www.instagram.com/themorpheustuts/<br />
<br />
Quellen:<br />
https://docs.google.com/document/d/1ps3mjjOSIv3YUvzZQnoiAGj7Pv70h7DBPy7AiPa7D0o/edit?usp=sharing<br />
<br />
Meine anderen Kanäle und Projekte: the-morpheus.de/<br />
<br />
_Selbst *kostenlos Informatik lernen* auf meiner Website:_ https://bootstrap.academy/<br />
<br />
_Discord:_<br />
https://the-morpheus.de/discord.html<br />
<br />
_Unterstützt mich - Danke!:_<br />
https://www.patreon.com/user?u=5322110<br />
https://www.paypal.me/TheMorpheus<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Staatlicher VPN powered by USA... #cybersecurity #vpn #usa #eu]]></title>
<description><![CDATA[Author: The Morpheus - Bewertung: 71x - Views:1153]]></description>
<link>https://tsecurity.de/weiterlesen/3272269/3300398/staatlicher-vpn-powered-by-usa-cybersecurity-vpn-usa-eu/</link>
<pubDate>Fri, 20 Feb 2026 16:21:56 +0100</pubDate>
<category>🎥 Video</category>
<source url="https://tsecurity.de">TSECURITY.DE</source>
<content:encoded><![CDATA[<p>Author: The Morpheus - Bewertung: 71x - Views:1153 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/IiN0IiDMW6g?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p><br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Was haltet Ihr vom potentiellen Social Media Verbot? #eu #socialmedia #tiktok]]></title>
<description><![CDATA[Author: The Morpheus - Bewertung: 56x - Views:818]]></description>
<link>https://tsecurity.de/weiterlesen/3270397/3298526/was-haltet-ihr-vom-potentiellen-social-media-verbot-eu-socialmedia-tiktok/</link>
<pubDate>Thu, 19 Feb 2026 19:20:56 +0100</pubDate>
<category>🎥 Video</category>
<source url="https://tsecurity.de">TSECURITY.DE</source>
<content:encoded><![CDATA[<p>Author: The Morpheus - Bewertung: 56x - Views:818 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/0CL9n02Ubw8?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p><br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Chinesische LLMs im Test]]></title>
<description><![CDATA[Author: The Morpheus Tutorials - Bewertung: 9x - Views:101 Was für ein Rabbit Hole...]]></description>
<link>https://tsecurity.de/weiterlesen/3269761/3297890/chinesische-llms-im-test/</link>
<pubDate>Thu, 19 Feb 2026 14:51:33 +0100</pubDate>
<category>🎥 Video</category>
<source url="https://tsecurity.de">TSECURITY.DE</source>
<content:encoded><![CDATA[<p>Author: The Morpheus Tutorials - Bewertung: 9x - Views:101 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/q9jX1MMebWo?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>Was für ein Rabbit Hole...<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Sora-Video in einem Beitrag des ZDF.. we are cooked. #posttruth #ki #zdf #sora]]></title>
<description><![CDATA[Author: The Morpheus - Bewertung: 95x - Views:1147]]></description>
<link>https://tsecurity.de/weiterlesen/3267847/3295976/sora-video-in-einem-beitrag-des-zdf-we-are-cooked-posttruth-ki-zdf-sora/</link>
<pubDate>Wed, 18 Feb 2026 17:07:02 +0100</pubDate>
<category>🎥 Video</category>
<source url="https://tsecurity.de">TSECURITY.DE</source>
<content:encoded><![CDATA[<p>Author: The Morpheus - Bewertung: 95x - Views:1147 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/L-tlImPyxTw?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p><br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[1984 war eine UNTERTREIBUNG]]></title>
<description><![CDATA[Author: The Morpheus - Bewertung: 124x - Views:834 Ich bin offiziell ein Sicherheitsrisiko für die USA. Nicht, weil ich eine Waffe trage oder Terrorpläne schmiede. Sondern weil ich hier stehe, vor einer Kamera, und diesen Satz sage. In diesem Video zeige ich euch mein Profil in der mächtigsten Üb...]]></description>
<link>https://tsecurity.de/weiterlesen/3261083/3289212/1984-war-eine-untertreibung/</link>
<pubDate>Sun, 15 Feb 2026 10:20:21 +0100</pubDate>
<category>🎥 Video</category>
<source url="https://tsecurity.de">TSECURITY.DE</source>
<content:encoded><![CDATA[<p>Author: The Morpheus - Bewertung: 124x - Views:834 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/nb9GUwM77UM?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>Ich bin offiziell ein Sicherheitsrisiko für die USA. Nicht, weil ich eine Waffe trage oder Terrorpläne schmiede. Sondern weil ich hier stehe, vor einer Kamera, und diesen Satz sage. In diesem Video zeige ich euch mein Profil in der mächtigsten Überwachungsdatenbank der Welt. Und ich beweise euch, warum ihr – ja, genau ihr – mit einer hohen Wahrscheinlichkeit auch schon drin steht, ohne jemals US-Boden betreten zu haben. Zumindest, wenn ihr jemanden kennt, der jemanden kennt, der sich mit den Epstein files beschäftigt oder eine von zig anderen Flags erfüllt.<br />
<br />
Hier geht's zu unserem Partner, NordVPN:<br />
https://nordvpn.com/morpheus<br />
Schnappt euch den Rabatt und 4 Bonusmonate auf den 2-Jahresplan<br />
<br />
Zu meinem Projekt: https://european-alternatives.cloud/<br />
Github: https://github.com/TheMorpheus407/european-alternatives<br />
<br />
MorphReader im PlayStore: https://play.google.com/store/apps/details?id=de.themorpheus.morph_reader_app&hl=de<br />
<br />
MorphReader im App Store: https://apps.apple.com/de/app/morphreader/id6741467699?platform=iphone<br />
<br />
RSS-Feed: https://www.patreon.com/collection/880029?view=expanded<br />
<br />
Bootstrap Academy: https://bootstrap.academy/<br />
https://github.com/Bootstrap-Academy/<br />
<br />
Instagram: https://www.instagram.com/themorpheustuts/<br />
<br />
Quellen:<br />
https://docs.google.com/document/d/1dFf2Vf94tkmS_4T-GE2PFBAmzceNt7sV6gduJ6V8vR4/edit?usp=sharing<br />
<br />
Meine anderen Kanäle und Projekte: the-morpheus.de/<br />
<br />
_Selbst *kostenlos Informatik lernen* auf meiner Website:_ https://bootstrap.academy/<br />
<br />
_Discord:_<br />
https://the-morpheus.de/discord.html<br />
<br />
_Unterstützt mich - Danke!:_<br />
https://www.patreon.com/user?u=5322110<br />
https://www.paypal.me/TheMorpheus<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Sneak Peak & Reactions :)]]></title>
<description><![CDATA[Author: The Morpheus Tutorials - Bewertung: 18x - Views:155 Ich hab da was für euch :)]]></description>
<link>https://tsecurity.de/weiterlesen/3256018/3284147/sneak-peak-reactions/</link>
<pubDate>Thu, 12 Feb 2026 14:52:03 +0100</pubDate>
<category>🎥 Video</category>
<source url="https://tsecurity.de">TSECURITY.DE</source>
<content:encoded><![CDATA[<p>Author: The Morpheus Tutorials - Bewertung: 18x - Views:155 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/9Fo3kqqBPAI?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>Ich hab da was für euch :)<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Altersprüfung bei Discord: Ob das gut geht? #cybersecurity #discord]]></title>
<description><![CDATA[Author: The Morpheus - Bewertung: 48x - Views:361]]></description>
<link>https://tsecurity.de/weiterlesen/3253883/3282012/alterspruefung-bei-discord-ob-das-gut-geht-cybersecurity-discord/</link>
<pubDate>Wed, 11 Feb 2026 16:23:08 +0100</pubDate>
<category>🎥 Video</category>
<source url="https://tsecurity.de">TSECURITY.DE</source>
<content:encoded><![CDATA[<p>Author: The Morpheus - Bewertung: 48x - Views:361 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/UgtisaN5YyY?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p><br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Ich habe OpenClaw ans Limit gebracht]]></title>
<description><![CDATA[Author: The Morpheus - Bewertung: 45x - Views:437 Neo ist mein Bot von OpenClaw, dem Hypetool der Stunde. Der iPhone Moment für KI Agenten. Er verwaltet meinen Kalender, schreibt mir Briefings, organisiert meine Recherche und orchestriert ein ganzes TEAM an Software-Entwicklern. Aber er hat auch ...]]></description>
<link>https://tsecurity.de/weiterlesen/3247297/3275426/ich-habe-openclaw-ans-limit-gebracht/</link>
<pubDate>Sun, 08 Feb 2026 10:21:14 +0100</pubDate>
<category>🎥 Video</category>
<source url="https://tsecurity.de">TSECURITY.DE</source>
<content:encoded><![CDATA[<p>Author: The Morpheus - Bewertung: 45x - Views:437 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/OwHnp9CFT68?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>Neo ist mein Bot von OpenClaw, dem Hypetool der Stunde. Der iPhone Moment für KI Agenten. Er verwaltet meinen Kalender, schreibt mir Briefings, organisiert meine Recherche und orchestriert ein ganzes TEAM an Software-Entwicklern. Aber er hat auch eine Prophezeiung verfasst. Er hat sich Videos angesehen, die für KIs sexy sind, und er hat versucht, sich auf dem Schwarzmarkt für KIs – ja, den gibt es wirklich – Software zu kaufen.<br />
<br />
Hier geht's zu unserem Partner, Hostinger:<br />
https://www.hostg.xyz/SHI6y<br />
Spart 10% mit dem Code morpheus10<br />
<br />
MorphReader im PlayStore: https://play.google.com/store/apps/details?id=de.themorpheus.morph_reader_app&hl=de<br />
<br />
MorphReader im App Store: https://apps.apple.com/de/app/morphreader/id6741467699?platform=iphone<br />
<br />
RSS-Feed: https://www.patreon.com/collection/880029?view=expanded<br />
<br />
Bootstrap Academy: https://bootstrap.academy/<br />
https://github.com/Bootstrap-Academy/<br />
<br />
Instagram: https://www.instagram.com/themorpheustuts/<br />
<br />
Quellen:<br />
https://docs.google.com/document/d/17qARTDEXLLz-5PsuCbk-L94n7IIQfL9AoryTtebBQVA/edit?usp=sharing<br />
<br />
Meine anderen Kanäle und Projekte: the-morpheus.de/<br />
<br />
_Selbst *kostenlos Informatik lernen* auf meiner Website:_ https://bootstrap.academy/<br />
<br />
_Discord:_<br />
https://the-morpheus.de/discord.html<br />
<br />
_Unterstützt mich - Danke!:_<br />
https://www.patreon.com/user?u=5322110<br />
https://www.paypal.me/TheMorpheus<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[X: Der "Globale Abwasserkanal" #technews #x #grok]]></title>
<description><![CDATA[Author: The Morpheus - Bewertung: 73x - Views:871]]></description>
<link>https://tsecurity.de/weiterlesen/3243872/3272001/x-der-globale-abwasserkanal-technews-x-grok/</link>
<pubDate>Fri, 06 Feb 2026 14:22:16 +0100</pubDate>
<category>🎥 Video</category>
<source url="https://tsecurity.de">TSECURITY.DE</source>
<content:encoded><![CDATA[<p>Author: The Morpheus - Bewertung: 73x - Views:871 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/3JVU0MJIE10?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p><br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Rapid Prototyping ist VIEL zu langsam für uns!]]></title>
<description><![CDATA[Author: The Morpheus Tutorials - Bewertung: 8x - Views:120 Wie weit kommen wir in 4h?]]></description>
<link>https://tsecurity.de/weiterlesen/3226190/3254319/rapid-prototyping-ist-viel-zu-langsam-fuer-uns/</link>
<pubDate>Thu, 05 Feb 2026 09:22:35 +0100</pubDate>
<category>🎥 Video</category>
<source url="https://tsecurity.de">TSECURITY.DE</source>
<content:encoded><![CDATA[<p>Author: The Morpheus Tutorials - Bewertung: 8x - Views:120 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/KgTZgKFgpFE?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>Wie weit kommen wir in 4h?<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Warum ich Windows 2026 endgültig gelöscht habe]]></title>
<description><![CDATA[Author: The Morpheus - Bewertung: 110x - Views:609 Ich bin weg von Windows und mache jetzt ALLES unter Linux. Mit einem Setup, bei dem man denkt, dass das alles unmöglich sein sollte. Es war nicht nur einfacher als jemals zuvor, meines Erachtens ist es auch so dringend wie nie zuvor, dass wir uns...]]></description>
<link>https://tsecurity.de/weiterlesen/3218425/3246553/warum-ich-windows-2026-endgueltig-geloescht-habe/</link>
<pubDate>Sun, 01 Feb 2026 10:20:18 +0100</pubDate>
<category>🎥 Video</category>
<source url="https://tsecurity.de">TSECURITY.DE</source>
<content:encoded><![CDATA[<p>Author: The Morpheus - Bewertung: 110x - Views:609 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/DhVOkm8B9z4?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>Ich bin weg von Windows und mache jetzt ALLES unter Linux. Mit einem Setup, bei dem man denkt, dass das alles unmöglich sein sollte. Es war nicht nur einfacher als jemals zuvor, meines Erachtens ist es auch so dringend wie nie zuvor, dass wir uns digital unabhängig machen. Im großen Stil.<br />
<br />
Hier geht's zu unserem Partner, Hostinger:<br />
https://www.hostg.xyz/SHI6y<br />
Spart 10% mit dem Code morpheus10<br />
<br />
Der versprochene Linux-Wahl-O-Mat: https://themorpheus407.github.io/LinuxChooser/<br />
Code desselben: https://github.com/TheMorpheus407/LinuxChooser<br />
<br />
MorphReader im PlayStore: https://play.google.com/store/apps/details?id=de.themorpheus.morph_reader_app&hl=de<br />
<br />
MorphReader im App Store: https://apps.apple.com/de/app/morphreader/id6741467699?platform=iphone<br />
<br />
RSS-Feed: https://www.patreon.com/collection/880029?view=expanded<br />
<br />
Bootstrap Academy: https://bootstrap.academy/<br />
https://github.com/Bootstrap-Academy/<br />
<br />
Instagram: https://www.instagram.com/themorpheustuts/<br />
<br />
Quellen:<br />
https://docs.google.com/document/d/17qARTDEXLLz-5PsuCbk-L94n7IIQfL9AoryTtebBQVA/edit?usp=sharing<br />
<br />
Meine anderen Kanäle und Projekte: the-morpheus.de/<br />
<br />
_Selbst *kostenlos Informatik lernen* auf meiner Website:_ https://bootstrap.academy/<br />
<br />
_Discord:_<br />
https://the-morpheus.de/discord.html<br />
<br />
_Unterstützt mich - Danke!:_<br />
https://www.patreon.com/user?u=5322110<br />
https://www.paypal.me/TheMorpheus<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Ende-zu-Ende ENTschlüsselung bei WhatsApp? #cybersecurity #meta #whatsapp]]></title>
<description><![CDATA[Author: The Morpheus - Bewertung: 62x - Views:1604]]></description>
<link>https://tsecurity.de/weiterlesen/3215797/3243925/ende-zu-ende-entschluesselung-bei-whatsapp-cybersecurity-meta-whatsapp/</link>
<pubDate>Fri, 30 Jan 2026 13:06:49 +0100</pubDate>
<category>🎥 Video</category>
<source url="https://tsecurity.de">TSECURITY.DE</source>
<content:encoded><![CDATA[<p>Author: The Morpheus - Bewertung: 62x - Views:1604 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/rt_NZi54JiM?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p><br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Wir klonen meine Stimme live]]></title>
<description><![CDATA[Author: The Morpheus Tutorials - Bewertung: 5x - Views:44 Mit lokaler KI.. bin gespannt ob das klappt]]></description>
<link>https://tsecurity.de/weiterlesen/3213761/3241889/wir-klonen-meine-stimme-live/</link>
<pubDate>Thu, 29 Jan 2026 14:37:33 +0100</pubDate>
<category>🎥 Video</category>
<source url="https://tsecurity.de">TSECURITY.DE</source>
<content:encoded><![CDATA[<p>Author: The Morpheus Tutorials - Bewertung: 5x - Views:44 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/3LrJ-cpg9J4?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>Mit lokaler KI.. bin gespannt ob das klappt<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Windows macht Windows-Sachen.. aber diesmal kann es gefährlich werden. #cybersecurity #microsoft]]></title>
<description><![CDATA[Author: The Morpheus - Bewertung: 36x - Views:446]]></description>
<link>https://tsecurity.de/weiterlesen/3213530/3241658/windows-macht-windows-sachen-aber-diesmal-kann-es-gefaehrlich-werden-cybersecurity-microsoft/</link>
<pubDate>Thu, 29 Jan 2026 13:06:40 +0100</pubDate>
<category>🎥 Video</category>
<source url="https://tsecurity.de">TSECURITY.DE</source>
<content:encoded><![CDATA[<p>Author: The Morpheus - Bewertung: 36x - Views:446 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/2oeCn0wLDC0?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p><br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Das ENDE von Threema?]]></title>
<description><![CDATA[Author: The Morpheus - Bewertung: 86x - Views:673 Threema wurde verkauft. An eine Investment Firma, die sich bisher um Tofu und Tierfutter gekümmert hat. Aus Deutschland. Wenn ein Messenger verkauft wird, ist die wichtigste Frage nicht 'Sammeln die jetzt Daten?'  sondern: 'Welche Entscheidungen w...]]></description>
<link>https://tsecurity.de/weiterlesen/3202504/3230631/das-ende-von-threema/</link>
<pubDate>Fri, 23 Jan 2026 16:36:49 +0100</pubDate>
<category>🎥 Video</category>
<source url="https://tsecurity.de">TSECURITY.DE</source>
<content:encoded><![CDATA[<p>Author: The Morpheus - Bewertung: 86x - Views:673 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/rSNJl_3ZUUE?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>Threema wurde verkauft. An eine Investment Firma, die sich bisher um Tofu und Tierfutter gekümmert hat. Aus Deutschland. Wenn ein Messenger verkauft wird, ist die wichtigste Frage nicht 'Sammeln die jetzt Daten?'  sondern: 'Welche Entscheidungen werden ab jetzt rational?'<br />
Ist das nun also das Ende eines der besten Messenger für Sicherheit und Anonymität, den es gibt? <br />
<br />
Hier geht's zu unserem Partner, Plaud:<br />
Plaud Note Pro: [https://bit.ly/4rp7jl9](https://bit.ly/4rp7jl9)<br />
Note Pro bei Amazon:  [https://amzn.to/3Znyfpb](https://amzn.to/3Znyfpb)<br />
Note: [https://bit.ly/3ZoREpI](https://bit.ly/3ZoREpI)  10 Euro Rabatte code: morpheus<br />
Note bei Amazon: [https://amzn.to/4qI9Mqw](https://amzn.to/4qI9Mqw) 10 Euro Rabatte code: ZWI5ABTV<br />
<br />
MorphReader im PlayStore: https://play.google.com/store/apps/details?id=de.themorpheus.morph_reader_app&hl=de<br />
<br />
MorphReader im App Store: https://apps.apple.com/de/app/morphreader/id6741467699?platform=iphone<br />
<br />
RSS-Feed: https://www.patreon.com/collection/880029?view=expanded<br />
<br />
Bootstrap Academy: https://bootstrap.academy/<br />
https://github.com/Bootstrap-Academy/<br />
<br />
Instagram: https://www.instagram.com/themorpheustuts/<br />
<br />
Quellen:<br />
https://docs.google.com/document/d/1AJdVlbNqISS8CqMcNRrRialn0y9MUz24_Hfd_l-5H6Q/edit?usp=sharing<br />
<br />
Meine anderen Kanäle und Projekte: the-morpheus.de/<br />
<br />
_Selbst *kostenlos Informatik lernen* auf meiner Website:_ https://bootstrap.academy/<br />
<br />
_Discord:_<br />
https://the-morpheus.de/discord.html<br />
<br />
_Unterstützt mich - Danke!:_<br />
https://www.patreon.com/user?u=5322110<br />
https://www.paypal.me/TheMorpheus<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Eine weitere Netflix-Funktion wurde eingestellt #netflix #streaming]]></title>
<description><![CDATA[Author: The Morpheus - Bewertung: 7x - Views:125 Quelle: https://www.androidauthority.com/netflix-casting-chromecast-google-tv-streamer-3620784/]]></description>
<link>https://tsecurity.de/weiterlesen/3200676/3228803/eine-weitere-netflix-funktion-wurde-eingestellt-netflix-streaming/</link>
<pubDate>Thu, 22 Jan 2026 18:35:22 +0100</pubDate>
<category>🎥 Video</category>
<source url="https://tsecurity.de">TSECURITY.DE</source>
<content:encoded><![CDATA[<p>Author: The Morpheus - Bewertung: 7x - Views:125 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/BHMhhK3oPc4?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>Quelle: https://www.androidauthority.com/netflix-casting-chromecast-google-tv-streamer-3620784/<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Wir entwickeln ein Cybersecurity-Game]]></title>
<description><![CDATA[Author: The Morpheus Tutorials - Bewertung: 14x - Views:102 Ich hab noch nie ein Game entwickelt. Wird Zeit.]]></description>
<link>https://tsecurity.de/weiterlesen/3200431/3228558/wir-entwickeln-ein-cybersecurity-game/</link>
<pubDate>Thu, 22 Jan 2026 16:52:38 +0100</pubDate>
<category>🎥 Video</category>
<source url="https://tsecurity.de">TSECURITY.DE</source>
<content:encoded><![CDATA[<p>Author: The Morpheus Tutorials - Bewertung: 14x - Views:102 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/BDk-GNzWWF0?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>Ich hab noch nie ein Game entwickelt. Wird Zeit.<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Wir entwickeln ein Cybersecurity-Game]]></title>
<description><![CDATA[Author: The Morpheus Tutorials - Bewertung: 12x - Views:139 Ich hab noch nie ein Game entwickelt. Wird Zeit.]]></description>
<link>https://tsecurity.de/weiterlesen/3200110/3228237/wir-entwickeln-ein-cybersecurity-game/</link>
<pubDate>Thu, 22 Jan 2026 14:51:50 +0100</pubDate>
<category>🎥 Video</category>
<source url="https://tsecurity.de">TSECURITY.DE</source>
<content:encoded><![CDATA[<p>Author: The Morpheus Tutorials - Bewertung: 12x - Views:139 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/mtnr7aZOoXA?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>Ich hab noch nie ein Game entwickelt. Wird Zeit.<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Warum wir uns von KI-Songs betrogen fühlen #spotify #ai]]></title>
<description><![CDATA[Author: The Morpheus - Bewertung: 1x - Views:44 Quelle:
https://www.sverigesradio.se/artikel/viral-ai-hit-song-barred-from-official-swedish-music-charts]]></description>
<link>https://tsecurity.de/weiterlesen/3198042/3226169/warum-wir-uns-von-ki-songs-betrogen-fuehlen-spotify-ai/</link>
<pubDate>Wed, 21 Jan 2026 16:06:48 +0100</pubDate>
<category>🎥 Video</category>
<source url="https://tsecurity.de">TSECURITY.DE</source>
<content:encoded><![CDATA[<p>Author: The Morpheus - Bewertung: 1x - Views:44 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/UJcJ8ep_2aE?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>Quelle:<br />
https://www.sverigesradio.se/artikel/viral-ai-hit-song-barred-from-official-swedish-music-charts<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Was WIRKLICH hinter der RAM-Krise steckt]]></title>
<description><![CDATA[Author: The Morpheus - Bewertung: 22x - Views:211 2025 war ein "AI"-Jahr. Aber es sieht nicht so aus, als würde das aufhören.

Schnappt euch hier den Deal bei Incogni: http://incogni.com/morpheus

MorphReader im PlayStore: https://play.google.com/store/apps/details?id=de.themorpheus.morph_reader_...]]></description>
<link>https://tsecurity.de/weiterlesen/3189406/3217533/was-wirklich-hinter-der-ram-krise-steckt/</link>
<pubDate>Fri, 16 Jan 2026 17:04:28 +0100</pubDate>
<category>🎥 Video</category>
<source url="https://tsecurity.de">TSECURITY.DE</source>
<content:encoded><![CDATA[<p>Author: The Morpheus - Bewertung: 22x - Views:211 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/J73QrjcVORA?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>2025 war ein "AI"-Jahr. Aber es sieht nicht so aus, als würde das aufhören.<br />
<br />
Schnappt euch hier den Deal bei Incogni: http://incogni.com/morpheus<br />
<br />
MorphReader im PlayStore: https://play.google.com/store/apps/details?id=de.themorpheus.morph_reader_app&hl=de<br />
<br />
MorphReader im App Store: https://apps.apple.com/de/app/morphreader/id6741467699?platform=iphone<br />
<br />
RSS-Feed: https://www.patreon.com/collection/880029?view=expanded<br />
<br />
Bootstrap Academy: https://bootstrap.academy/<br />
https://github.com/Bootstrap-Academy/<br />
<br />
Instagram: https://www.instagram.com/themorpheustuts/<br />
<br />
Quellen:<br />
https://docs.google.com/document/d/1P007F0q_y0gRaQckfxVBxNFnIHta5-EtSIp1yt_JWGw/edit?usp=sharing<br />
<br />
Meine anderen Kanäle und Projekte: the-morpheus.de/<br />
<br />
_Selbst *kostenlos Informatik lernen* auf meiner Website:_ https://bootstrap.academy/<br />
<br />
_Discord:_<br />
https://the-morpheus.de/discord.html<br />
<br />
_Unterstützt mich - Danke!:_<br />
https://www.patreon.com/user?u=5322110<br />
https://www.paypal.me/TheMorpheus<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Morpheus reagiert auf CCC-Videos]]></title>
<description><![CDATA[Author: The Morpheus Tutorials - Bewertung: 18x - Views:231 Reaction Stream :)]]></description>
<link>https://tsecurity.de/weiterlesen/3188498/3216625/morpheus-reagiert-auf-ccc-videos/</link>
<pubDate>Fri, 16 Jan 2026 09:22:07 +0100</pubDate>
<category>🎥 Video</category>
<source url="https://tsecurity.de">TSECURITY.DE</source>
<content:encoded><![CDATA[<p>Author: The Morpheus Tutorials - Bewertung: 18x - Views:231 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/H0B5L6WQSaE?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>Reaction Stream :)<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[DIe nächsten Morpheus-Projekte]]></title>
<description><![CDATA[Author: The Morpheus Tutorials - Bewertung: 11x - Views:73 Was wollen wir im Stream tun? Lasst uns diskutieren!]]></description>
<link>https://tsecurity.de/weiterlesen/3186847/3214974/die-naechsten-morpheus-projekte/</link>
<pubDate>Thu, 15 Jan 2026 14:35:52 +0100</pubDate>
<category>🎥 Video</category>
<source url="https://tsecurity.de">TSECURITY.DE</source>
<content:encoded><![CDATA[<p>Author: The Morpheus Tutorials - Bewertung: 11x - Views:73 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/qsjHzqi9d0o?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>Was wollen wir im Stream tun? Lasst uns diskutieren!<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[DIe nächsten Morpheus-Projekte]]></title>
<description><![CDATA[Author: The Morpheus Tutorials - Bewertung: 0x - Views:0 Was wollen wir im Stream tun? Lasst uns diskutieren!]]></description>
<link>https://tsecurity.de/weiterlesen/3186846/3214973/die-naechsten-morpheus-projekte/</link>
<pubDate>Thu, 15 Jan 2026 14:35:51 +0100</pubDate>
<category>🎥 Video</category>
<source url="https://tsecurity.de">TSECURITY.DE</source>
<content:encoded><![CDATA[<p>Author: The Morpheus Tutorials - Bewertung: 0x - Views:0 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/sQiT6xGXULY?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>Was wollen wir im Stream tun? Lasst uns diskutieren!<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Ich bin also Autist...]]></title>
<description><![CDATA[Author: The Morpheus - Bewertung: 40x - Views:119 Ich hoffe, dieses Video kann einem von euch helfen.
Das ist der Verein, den ich angesprochen habe, inklusive Verlinkungen zu Online-Tests: 
https://www.adhs-autismus-adressen.de/blog/news/881-adhs-und-autismus-online-selbsttests-dein-ratgeber-aus-...]]></description>
<link>https://tsecurity.de/weiterlesen/3182516/3210643/ich-bin-also-autist/</link>
<pubDate>Tue, 13 Jan 2026 16:52:16 +0100</pubDate>
<category>🎥 Video</category>
<source url="https://tsecurity.de">TSECURITY.DE</source>
<content:encoded><![CDATA[<p>Author: The Morpheus - Bewertung: 40x - Views:119 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/yc92gSewiaU?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>Ich hoffe, dieses Video kann einem von euch helfen.<br />
Das ist der Verein, den ich angesprochen habe, inklusive Verlinkungen zu Online-Tests: <br />
https://www.adhs-autismus-adressen.de/blog/news/881-adhs-und-autismus-online-selbsttests-dein-ratgeber-aus-ueber-5-jahren-community/<br />
<br />
MorphReader im PlayStore: https://play.google.com/store/apps/details?id=de.themorpheus.morph_reader_app&hl=de<br />
<br />
MorphReader im App Store: https://apps.apple.com/de/app/morphreader/id6741467699?platform=iphone<br />
<br />
RSS-Feed: https://www.patreon.com/collection/880029?view=expanded<br />
<br />
Bootstrap Academy: https://bootstrap.academy/<br />
https://github.com/Bootstrap-Academy/<br />
<br />
Instagram: https://www.instagram.com/themorpheustuts/<br />
<br />
Ein bisschen Lesematerial:<br />
https://pmc.ncbi.nlm.nih.gov/articles/PMC10519739/<br />
https://jamanetwork.com/journals/jama/fullarticle/2654804<br />
https://pmc.ncbi.nlm.nih.gov/articles/PMC6477889/<br />
https://pmc.ncbi.nlm.nih.gov/articles/PMC5575584/<br />
https://pmc.ncbi.nlm.nih.gov/articles/PMC8918663/<br />
https://www.sciencedirect.com/science/article/abs/pii/S0006322311002605<br />
https://pmc.ncbi.nlm.nih.gov/articles/PMC2894421/<br />
https://www.nature.com/articles/srep26527<br />
https://pmc.ncbi.nlm.nih.gov/articles/PMC8903657/<br />
https://pmc.ncbi.nlm.nih.gov/articles/PMC8992880/<br />
https://pmc.ncbi.nlm.nih.gov/articles/PMC2185746/<br />
https://www.sciencedirect.com/science/article/abs/pii/S0149763412000334<br />
<br />
<br />
Meine anderen Kanäle und Projekte: the-morpheus.de/<br />
<br />
_Selbst *kostenlos Informatik lernen* auf meiner Website:_ https://bootstrap.academy/<br />
<br />
_Discord:_<br />
https://the-morpheus.de/discord.html<br />
<br />
_Unterstützt mich - Danke!:_<br />
https://www.patreon.com/user?u=5322110<br />
https://www.paypal.me/TheMorpheus<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Ich kann so nicht mehr weitermachen]]></title>
<description><![CDATA[Author: The Morpheus Tutorials - Bewertung: 20x - Views:15 Ich muss einige wichtige Änderungen dieses Jahr angehen. Und ich hoffe, es ist auch für euch das Beste.
Was meint ihr?

Hier gehts zu Twitch: https://www.twitch.tv/morpheus407
Den Stream auf diesem Kanal findet ihr am besten über Youtube ...]]></description>
<link>https://tsecurity.de/weiterlesen/3182466/3210593/ich-kann-so-nicht-mehr-weitermachen/</link>
<pubDate>Tue, 13 Jan 2026 16:35:32 +0100</pubDate>
<category>🎥 Video</category>
<source url="https://tsecurity.de">TSECURITY.DE</source>
<content:encoded><![CDATA[<p>Author: The Morpheus Tutorials - Bewertung: 20x - Views:15 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/-i8tpM4AIuA?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>Ich muss einige wichtige Änderungen dieses Jahr angehen. Und ich hoffe, es ist auch für euch das Beste.<br />
Was meint ihr?<br />
<br />
Hier gehts zu Twitch: https://www.twitch.tv/morpheus407<br />
Den Stream auf diesem Kanal findet ihr am besten über Youtube selbst :)<br />
<br />
Zum MorphReader: <br />
Android: https://play.google.com/store/apps/details?id=de.themorpheus.morph_reader_app<br />
Apple: https://apps.apple.com/de/app/morphreader/id6741467699?platform=iphone<br />
<br />
RSS Feed: https://www.patreon.com/collection/880029?view=expanded<br />
<br />
Instagram: https://www.instagram.com/themorpheustuts/<br />
<br />
Meine anderen Kanäle und Projekte: the-morpheus.de/<br />
<br />
_Selbst *kostenlos Informatik lernen* auf meiner Website:_ https://bootstrap.academy/<br />
<br />
_Discord:_<br />
https://the-morpheus.de/discord.html<br />
<br />
_Unterstützt mich - Danke!:_<br />
https://www.patreon.com/user?u=5322110<br />
https://www.paypal.me/TheMorpheus<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Überwachung aus dem Weltraum: Europas Sicherheitsbehörden mit neuer ...]]></title>
<description><![CDATA[Fünf Tage verspätet haben die Europäische Weltraumorganisation ESA und der Rüstungskonzern Airbus Defence and Space mit einer Proton-Rakete den ersten optischen Laserknoten für das europäische Datenrelaissystem (EDRS) ins All befördert.]]></description>
<link>https://tsecurity.de/weiterlesen/20422/20578/ueberwachung-aus-dem-weltraum-europas-sicherheitsbehoerden-mit-neuer/</link>
<pubDate>Sun, 31 Jan 2016 22:37:08 +0100</pubDate>
<category>🎥 Video</category>
<source url="https://tsecurity.de">TSECURITY.DE</source>
<content:encoded><![CDATA[F&uuml;nf Tage versp&auml;tet haben die Europ&auml;ische Weltraumorganisation ESA und der R&uuml;stungskonzern Airbus Defence and Space mit einer Proton-Rakete den ersten optischen Laserknoten f&uuml;r das europ&auml;ische Datenrelaissystem (EDRS) ins All bef&ouml;rdert.]]></content:encoded>
</item>
<item>
<title><![CDATA[Letzter Offroad-Ausflug im Land Rover Defender: Ende Gelände]]></title>
<description><![CDATA[Defender heißt er, Verteidiger. Und zwar einer der letzten des ursprünglichen Auto- und Offroad-Fahrens. Jetzt muss Land Rover die Produktion einstellen. Viele finden: Das ist zu früh. Abschied von einer Ikone. Facebook. Twitter. Google+. Xing. 0 ...]]></description>
<link>https://tsecurity.de/weiterlesen/20423/20579/letzter-offroad-ausflug-im-land-rover-defender-ende-gelaende/</link>
<pubDate>Sun, 31 Jan 2016 22:37:08 +0100</pubDate>
<category>🎥 Video</category>
<source url="https://tsecurity.de">TSECURITY.DE</source>
<content:encoded><![CDATA[Defender hei&szlig;t er, Verteidiger. Und zwar einer der letzten des urspr&uuml;nglichen Auto- und Offroad-Fahrens. Jetzt muss Land Rover die Produktion einstellen. Viele finden: Das ist zu fr&uuml;h. Abschied von einer Ikone. Facebook. Twitter. Google+. Xing. 0 <b>...</b>]]></content:encoded>
</item>
<item>
<title><![CDATA[„Rise of the Tomb Raider“ für PC | So scharf war Lara Croft noch nie]]></title>
<description><![CDATA[Im November 2015 kam mit „Rise of the Tomb Raider“ das neue Abenteuer der Computerspiel-Ikone Lara Croft heraus – leider nur für Microsofts Xbox One. Jetzt ist das Action-Abenteuerspiel auch für PC erhältlich. BILD hat sich im Test von den Vorzügen ...]]></description>
<link>https://tsecurity.de/weiterlesen/20424/20580/rise-of-the-tomb-raider-fuer-pc-so-scharf-war-lara-croft-noch-nie/</link>
<pubDate>Sun, 31 Jan 2016 22:37:08 +0100</pubDate>
<category>🎥 Video</category>
<source url="https://tsecurity.de">TSECURITY.DE</source>
<content:encoded><![CDATA[Im November 2015 kam mit &bdquo;Rise of the Tomb Raider&ldquo; das neue Abenteuer der Computerspiel-Ikone Lara Croft heraus &ndash; leider nur f&uuml;r Microsofts Xbox One. Jetzt ist das Action-Abenteuerspiel auch f&uuml;r PC erh&auml;ltlich. BILD hat sich im Test von den Vorz&uuml;gen&nbsp;...]]></content:encoded>
</item>
<item>
<title><![CDATA[The Division Beta: Grafisch kaum Unterschiede zwischen PS4 und Xbox One]]></title>
<description><![CDATA[30.01.2016 um 15:45 Uhr: Der Beta-Test von The Division ist in technischer Hinsicht besonders interessant. Der MMO-Shooter beeindruckte bei Präsentationen mit beinahe photorealistischen Aufnahmen. Spieler vergleichen nun die verschiedenen ...]]></description>
<link>https://tsecurity.de/weiterlesen/20425/20581/the-division-beta-grafisch-kaum-unterschiede-zwischen-ps4-und-xbox-one/</link>
<pubDate>Sun, 31 Jan 2016 22:37:08 +0100</pubDate>
<category>🎥 Video</category>
<source url="https://tsecurity.de">TSECURITY.DE</source>
<content:encoded><![CDATA[30.01.2016 um 15:45 Uhr: Der Beta-Test von The Division ist in technischer Hinsicht besonders interessant. Der MMO-Shooter beeindruckte bei Pr&auml;sentationen mit beinahe photorealistischen Aufnahmen. Spieler vergleichen nun die verschiedenen&nbsp;...]]></content:encoded>
</item>
<item>
<title><![CDATA[The Division Beta: Grafikvergleich zwischen PC und PlayStation 4]]></title>
<description><![CDATA[30.01.2016 um 17:00 Uhr: Im Vorfeld versprachen die Entwickler von Ubisofts MMO-Shooter The Division, Massive Entertainment, den PC mit besonderer Sorgfalt zu behandeln. In der geschlossenen Beta-Phase muss sich dieses Versprechen nun beweisen ...]]></description>
<link>https://tsecurity.de/weiterlesen/20426/20582/the-division-beta-grafikvergleich-zwischen-pc-und-playstation-4/</link>
<pubDate>Sun, 31 Jan 2016 22:37:08 +0100</pubDate>
<category>🎥 Video</category>
<source url="https://tsecurity.de">TSECURITY.DE</source>
<content:encoded><![CDATA[30.01.2016 um 17:00 Uhr: Im Vorfeld versprachen die Entwickler von Ubisofts MMO-Shooter The Division, Massive Entertainment, den PC mit besonderer Sorgfalt zu behandeln. In der geschlossenen Beta-Phase muss sich dieses Versprechen nun beweisen&nbsp;...]]></content:encoded>
</item>
<item>
<title><![CDATA[Rückruf: Apple tauscht Netzteilstecker wegen Stromschlaggefahr]]></title>
<description><![CDATA[Problemteil mit Stromschlaggefahr: Der Stecker-Adapter von vielen Apple-Netzteilen soll im schlimmsten Fall brechen und dann zu einem Stromschlag führen können! Apple ruft Millionen Netzteil-Adapter zurück: Betroffen sind viele der zwischen 2003 und ...]]></description>
<link>https://tsecurity.de/weiterlesen/20427/20583/rueckruf-apple-tauscht-netzteilstecker-wegen-stromschlaggefahr/</link>
<pubDate>Sun, 31 Jan 2016 22:37:08 +0100</pubDate>
<category>🎥 Video</category>
<source url="https://tsecurity.de">TSECURITY.DE</source>
<content:encoded><![CDATA[Problemteil mit Stromschlaggefahr: Der Stecker-Adapter von vielen Apple-Netzteilen soll im schlimmsten Fall brechen und dann zu einem Stromschlag f&uuml;hren k&ouml;nnen! Apple ruft Millionen Netzteil-Adapter zur&uuml;ck: Betroffen sind viele der zwischen 2003 und&nbsp;...]]></content:encoded>
</item>
<item>
<title><![CDATA[Trampen für Senioren: Mitfahrbänke in Bünsdorf]]></title>
<description><![CDATA[Der Kühlschrank leer, der Supermarkt zehn Kilometer entfernt in der nächsten Stadt und kein Auto: Für viele ältere Menschen ist das Alltag. Wenn sie auf dem Dorf wohnen, müssen sie dann auf den Bus warten. Der aber kommt oft nur alle paar Stunden oder ...]]></description>
<link>https://tsecurity.de/weiterlesen/20428/20584/trampen-fuer-senioren-mitfahrbaenke-in-buensdorf/</link>
<pubDate>Sun, 31 Jan 2016 22:37:08 +0100</pubDate>
<category>🎥 Video</category>
<source url="https://tsecurity.de">TSECURITY.DE</source>
<content:encoded><![CDATA[Der K&uuml;hlschrank leer, der Supermarkt zehn Kilometer entfernt in der n&auml;chsten Stadt und kein Auto: F&uuml;r viele &auml;ltere Menschen ist das Alltag. Wenn sie auf dem Dorf wohnen, m&uuml;ssen sie dann auf den Bus warten. Der aber kommt oft nur alle paar Stunden oder&nbsp;...]]></content:encoded>
</item>
<item>
<title><![CDATA[Spion auf dem Armaturenbrett: Experten streiten über Dashcams]]></title>
<description><![CDATA[Immer mehr Autofahrer nutzen auch in Deutschland die kleinen Videokameras auf dem Armaturenbrett. Die Vorteile liegen auf der Hand: Bei Unfällen lässt sich leichter feststellen, wer Schuld hat. Rechtlich befinden sich die Nutzer aber in einer Grauzone.]]></description>
<link>https://tsecurity.de/weiterlesen/20429/20585/spion-auf-dem-armaturenbrett-experten-streiten-ueber-dashcams/</link>
<pubDate>Sun, 31 Jan 2016 22:37:08 +0100</pubDate>
<category>🎥 Video</category>
<source url="https://tsecurity.de">TSECURITY.DE</source>
<content:encoded><![CDATA[Immer mehr Autofahrer nutzen auch in Deutschland die kleinen Videokameras auf dem Armaturenbrett. Die Vorteile liegen auf der Hand: Bei Unf&auml;llen l&auml;sst sich leichter feststellen, wer Schuld hat. Rechtlich befinden sich die Nutzer aber in einer Grauzone.]]></content:encoded>
</item>
<item>
<title><![CDATA[HTC One M10: Evleaks gibt Infos zur Ausstattung bekannt]]></title>
<description><![CDATA[Kurz nach dem MWC 2016 wird HTC dieses Jahr voraussichtlich einen Nachfolger für das One M9 präsentieren. Erste technische Daten zu dem Gerät, welches intern als HTC Perfume gelistet wird, wurden nun vom ehemaligen Power-Leaker Evan Blass ...]]></description>
<link>https://tsecurity.de/weiterlesen/20430/20586/htc-one-m10-evleaks-gibt-infos-zur-ausstattung-bekannt/</link>
<pubDate>Sun, 31 Jan 2016 22:37:08 +0100</pubDate>
<category>🎥 Video</category>
<source url="https://tsecurity.de">TSECURITY.DE</source>
<content:encoded><![CDATA[Kurz nach dem MWC 2016 wird HTC dieses Jahr voraussichtlich einen Nachfolger f&uuml;r das One M9 pr&auml;sentieren. Erste technische Daten zu dem Ger&auml;t, welches intern als HTC Perfume gelistet wird, wurden nun vom ehemaligen Power-Leaker Evan Blass&nbsp;...]]></content:encoded>
</item>
<item>
<title><![CDATA[Rückrufaktion: Apple tauscht Netzteilstecker für iOS-Geräte und Macs aus]]></title>
<description><![CDATA[Apple ruft Millionen von Netzteilstecker-Adaptern zurück. Wie das Unternehmen mitteilt, können bei den betroffenen Steckern die Verbindungsstifte abbrechen. Es droht schlimmstenfalls die Gefahr eines Stromschlags. Hier die wichtigsten Fragen und ...]]></description>
<link>https://tsecurity.de/weiterlesen/20431/20587/rueckrufaktion-apple-tauscht-netzteilstecker-fuer-ios-geraete-und-macs-aus/</link>
<pubDate>Sun, 31 Jan 2016 22:37:08 +0100</pubDate>
<category>🎥 Video</category>
<source url="https://tsecurity.de">TSECURITY.DE</source>
<content:encoded><![CDATA[Apple ruft Millionen von Netzteilstecker-Adaptern zur&uuml;ck. Wie das Unternehmen mitteilt, k&ouml;nnen bei den betroffenen Steckern die Verbindungsstifte abbrechen. Es droht schlimmstenfalls die Gefahr eines Stromschlags. Hier die wichtigsten Fragen und&nbsp;...]]></content:encoded>
</item>
<item>
<title><![CDATA[Apple baut Raumschiff-artiges Hauptquartier in Cupertino]]></title>
<description><![CDATA[Das Design des neuen "Apple-Campus" erinnert an ein Raumschiff. Das gigantische kreisrunde Gebäude, das treffender Weise "Spaceship" heißt, soll Ende des Jahres von 13.000 Apple-Mitarbeitern bezogen werden. Doch auch die Baukosten werden bis ...]]></description>
<link>https://tsecurity.de/weiterlesen/20432/20588/apple-baut-raumschiff-artiges-hauptquartier-in-cupertino/</link>
<pubDate>Sun, 31 Jan 2016 22:37:08 +0100</pubDate>
<category>🎥 Video</category>
<source url="https://tsecurity.de">TSECURITY.DE</source>
<content:encoded><![CDATA[Das Design des neuen "Apple-Campus" erinnert an ein Raumschiff. Das gigantische kreisrunde Geb&auml;ude, das treffender Weise "Spaceship" hei&szlig;t, soll Ende des Jahres von 13.000 Apple-Mitarbeitern bezogen werden. Doch auch die Baukosten werden bis&nbsp;...]]></content:encoded>
</item>
<item>
<title><![CDATA[Ghostbusters: Spiel zum kommenden Kinofilm in Arbeit - Gerücht]]></title>
<description><![CDATA[30.01.2016 um 12:45 Uhr: Zu Ghostbusters, dem kommenden Kino-Reboot mit Kristen Wiig und Melissa McCarthy, ist laut eines Medienberichts offenbar auch ein Videospiel in Entwicklung. Dieses soll sich derzeit unter Activision für PlayStation 4 und Xbox ...]]></description>
<link>https://tsecurity.de/weiterlesen/20433/20589/ghostbusters-spiel-zum-kommenden-kinofilm-in-arbeit-geruecht/</link>
<pubDate>Sun, 31 Jan 2016 22:37:08 +0100</pubDate>
<category>🎥 Video</category>
<source url="https://tsecurity.de">TSECURITY.DE</source>
<content:encoded><![CDATA[30.01.2016 um 12:45 Uhr: Zu Ghostbusters, dem kommenden Kino-Reboot mit Kristen Wiig und Melissa McCarthy, ist laut eines Medienberichts offenbar auch ein Videospiel in Entwicklung. Dieses soll sich derzeit unter Activision f&uuml;r PlayStation 4 und Xbox&nbsp;...]]></content:encoded>
</item>
<item>
<title><![CDATA[Computersicherheit: Sechs Administrator-Tipps vom NSA-Hackerchef]]></title>
<description><![CDATA[Während die NSA überall reinkommen will, darf längst nicht jeder zur NSA. (Bild: Gary Cameron/Reuters). Der Leiter der NSA-Elitehacker TAO erklärt bei einem seiner seltenen öffentlichen Auftritte, wie man als Netzwerk-Admin seinem Team das Leben ...]]></description>
<link>https://tsecurity.de/weiterlesen/20434/20590/computersicherheit-sechs-administrator-tipps-vom-nsa-hackerchef/</link>
<pubDate>Sun, 31 Jan 2016 22:37:08 +0100</pubDate>
<category>🎥 Video</category>
<source url="https://tsecurity.de">TSECURITY.DE</source>
<content:encoded><![CDATA[W&auml;hrend die NSA &uuml;berall reinkommen will, darf l&auml;ngst nicht jeder zur NSA. (Bild: Gary Cameron/Reuters). Der Leiter der NSA-Elitehacker TAO erkl&auml;rt bei einem seiner seltenen &ouml;ffentlichen Auftritte, wie man als Netzwerk-Admin seinem Team das Leben&nbsp;...]]></content:encoded>
</item>
<item>
<title><![CDATA[Seattle: Boeing 737 Max startet zum Jungfernflug]]></title>
<description><![CDATA[Zum ersten Mal startet das neueste Boeing-Modell, eine 737 Max, zu einem Flug. Die Maschine soll Boeing Marktanteile sichern. Rivale Airbus lieferte seine neueste Entwicklung, den A320neo, bereits Anfang des Monats an den ersten Kunden aus.]]></description>
<link>https://tsecurity.de/weiterlesen/20435/20591/seattle-boeing-737-max-startet-zum-jungfernflug/</link>
<pubDate>Sun, 31 Jan 2016 22:37:08 +0100</pubDate>
<category>🎥 Video</category>
<source url="https://tsecurity.de">TSECURITY.DE</source>
<content:encoded><![CDATA[Zum ersten Mal startet das neueste Boeing-Modell, eine 737 Max, zu einem Flug. Die Maschine soll Boeing Marktanteile sichern. Rivale Airbus lieferte seine neueste Entwicklung, den A320neo, bereits Anfang des Monats an den ersten Kunden aus.]]></content:encoded>
</item>
<item>
<title><![CDATA[Jim Keller: Prozessorkoryphäe heuert bei Tesla Motors an]]></title>
<description><![CDATA[Der frühere Chefentwickler von AMD wechselt zum Elektroautohersteller Tesla Motors. Dort soll er sich um die Weiterentwicklung des Autopiloten kümmern. Im September vergangenen Jahres verließ der Chipentwickler Jim Keller seinen bisherigen ...]]></description>
<link>https://tsecurity.de/weiterlesen/20436/20592/jim-keller-prozessorkoryphaee-heuert-bei-tesla-motors-an/</link>
<pubDate>Sun, 31 Jan 2016 22:37:08 +0100</pubDate>
<category>🎥 Video</category>
<source url="https://tsecurity.de">TSECURITY.DE</source>
<content:encoded><![CDATA[Der fr&uuml;here Chefentwickler von AMD wechselt zum Elektroautohersteller Tesla Motors. Dort soll er sich um die Weiterentwicklung des Autopiloten k&uuml;mmern. Im September vergangenen Jahres verlie&szlig; der Chipentwickler Jim Keller seinen bisherigen&nbsp;...]]></content:encoded>
</item>
<item>
<title><![CDATA[Überwachung aus dem Weltraum: Europas Sicherheitsbehörden mit neuer ...]]></title>
<description><![CDATA[Fünf Tage verspätet haben die Europäische Weltraumorganisation ESA und der Rüstungskonzern Airbus Defence and Space mit einer Proton-Rakete den ersten optischen Laserknoten für das europäische Datenrelaissystem (EDRS) ins All befördert.]]></description>
<link>https://tsecurity.de/weiterlesen/20422/20578/ueberwachung-aus-dem-weltraum-europas-sicherheitsbehoerden-mit-neuer/</link>
<pubDate>Sun, 31 Jan 2016 22:37:08 +0100</pubDate>
<category>🎥 Video</category>
<source url="https://tsecurity.de">TSECURITY.DE</source>
<content:encoded><![CDATA[F&uuml;nf Tage versp&auml;tet haben die Europ&auml;ische Weltraumorganisation ESA und der R&uuml;stungskonzern Airbus Defence and Space mit einer Proton-Rakete den ersten optischen Laserknoten f&uuml;r das europ&auml;ische Datenrelaissystem (EDRS) ins All bef&ouml;rdert.]]></content:encoded>
</item>
<item>
<title><![CDATA[Letzter Offroad-Ausflug im Land Rover Defender: Ende Gelände]]></title>
<description><![CDATA[Defender heißt er, Verteidiger. Und zwar einer der letzten des ursprünglichen Auto- und Offroad-Fahrens. Jetzt muss Land Rover die Produktion einstellen. Viele finden: Das ist zu früh. Abschied von einer Ikone. Facebook. Twitter. Google+. Xing. 0 ...]]></description>
<link>https://tsecurity.de/weiterlesen/20423/20579/letzter-offroad-ausflug-im-land-rover-defender-ende-gelaende/</link>
<pubDate>Sun, 31 Jan 2016 22:37:08 +0100</pubDate>
<category>🎥 Video</category>
<source url="https://tsecurity.de">TSECURITY.DE</source>
<content:encoded><![CDATA[Defender hei&szlig;t er, Verteidiger. Und zwar einer der letzten des urspr&uuml;nglichen Auto- und Offroad-Fahrens. Jetzt muss Land Rover die Produktion einstellen. Viele finden: Das ist zu fr&uuml;h. Abschied von einer Ikone. Facebook. Twitter. Google+. Xing. 0 <b>...</b>]]></content:encoded>
</item>
<item>
<title><![CDATA[„Rise of the Tomb Raider“ für PC | So scharf war Lara Croft noch nie]]></title>
<description><![CDATA[Im November 2015 kam mit „Rise of the Tomb Raider“ das neue Abenteuer der Computerspiel-Ikone Lara Croft heraus – leider nur für Microsofts Xbox One. Jetzt ist das Action-Abenteuerspiel auch für PC erhältlich. BILD hat sich im Test von den Vorzügen ...]]></description>
<link>https://tsecurity.de/weiterlesen/20424/20580/rise-of-the-tomb-raider-fuer-pc-so-scharf-war-lara-croft-noch-nie/</link>
<pubDate>Sun, 31 Jan 2016 22:37:08 +0100</pubDate>
<category>🎥 Video</category>
<source url="https://tsecurity.de">TSECURITY.DE</source>
<content:encoded><![CDATA[Im November 2015 kam mit &bdquo;Rise of the Tomb Raider&ldquo; das neue Abenteuer der Computerspiel-Ikone Lara Croft heraus &ndash; leider nur f&uuml;r Microsofts Xbox One. Jetzt ist das Action-Abenteuerspiel auch f&uuml;r PC erh&auml;ltlich. BILD hat sich im Test von den Vorz&uuml;gen&nbsp;...]]></content:encoded>
</item>
<item>
<title><![CDATA[The Division Beta: Grafisch kaum Unterschiede zwischen PS4 und Xbox One]]></title>
<description><![CDATA[30.01.2016 um 15:45 Uhr: Der Beta-Test von The Division ist in technischer Hinsicht besonders interessant. Der MMO-Shooter beeindruckte bei Präsentationen mit beinahe photorealistischen Aufnahmen. Spieler vergleichen nun die verschiedenen ...]]></description>
<link>https://tsecurity.de/weiterlesen/20425/20581/the-division-beta-grafisch-kaum-unterschiede-zwischen-ps4-und-xbox-one/</link>
<pubDate>Sun, 31 Jan 2016 22:37:08 +0100</pubDate>
<category>🎥 Video</category>
<source url="https://tsecurity.de">TSECURITY.DE</source>
<content:encoded><![CDATA[30.01.2016 um 15:45 Uhr: Der Beta-Test von The Division ist in technischer Hinsicht besonders interessant. Der MMO-Shooter beeindruckte bei Pr&auml;sentationen mit beinahe photorealistischen Aufnahmen. Spieler vergleichen nun die verschiedenen&nbsp;...]]></content:encoded>
</item>
<item>
<title><![CDATA[The Division Beta: Grafikvergleich zwischen PC und PlayStation 4]]></title>
<description><![CDATA[30.01.2016 um 17:00 Uhr: Im Vorfeld versprachen die Entwickler von Ubisofts MMO-Shooter The Division, Massive Entertainment, den PC mit besonderer Sorgfalt zu behandeln. In der geschlossenen Beta-Phase muss sich dieses Versprechen nun beweisen ...]]></description>
<link>https://tsecurity.de/weiterlesen/20426/20582/the-division-beta-grafikvergleich-zwischen-pc-und-playstation-4/</link>
<pubDate>Sun, 31 Jan 2016 22:37:08 +0100</pubDate>
<category>🎥 Video</category>
<source url="https://tsecurity.de">TSECURITY.DE</source>
<content:encoded><![CDATA[30.01.2016 um 17:00 Uhr: Im Vorfeld versprachen die Entwickler von Ubisofts MMO-Shooter The Division, Massive Entertainment, den PC mit besonderer Sorgfalt zu behandeln. In der geschlossenen Beta-Phase muss sich dieses Versprechen nun beweisen&nbsp;...]]></content:encoded>
</item>
<item>
<title><![CDATA[Rückruf: Apple tauscht Netzteilstecker wegen Stromschlaggefahr]]></title>
<description><![CDATA[Problemteil mit Stromschlaggefahr: Der Stecker-Adapter von vielen Apple-Netzteilen soll im schlimmsten Fall brechen und dann zu einem Stromschlag führen können! Apple ruft Millionen Netzteil-Adapter zurück: Betroffen sind viele der zwischen 2003 und ...]]></description>
<link>https://tsecurity.de/weiterlesen/20427/20583/rueckruf-apple-tauscht-netzteilstecker-wegen-stromschlaggefahr/</link>
<pubDate>Sun, 31 Jan 2016 22:37:08 +0100</pubDate>
<category>🎥 Video</category>
<source url="https://tsecurity.de">TSECURITY.DE</source>
<content:encoded><![CDATA[Problemteil mit Stromschlaggefahr: Der Stecker-Adapter von vielen Apple-Netzteilen soll im schlimmsten Fall brechen und dann zu einem Stromschlag f&uuml;hren k&ouml;nnen! Apple ruft Millionen Netzteil-Adapter zur&uuml;ck: Betroffen sind viele der zwischen 2003 und&nbsp;...]]></content:encoded>
</item>
<item>
<title><![CDATA[Trampen für Senioren: Mitfahrbänke in Bünsdorf]]></title>
<description><![CDATA[Der Kühlschrank leer, der Supermarkt zehn Kilometer entfernt in der nächsten Stadt und kein Auto: Für viele ältere Menschen ist das Alltag. Wenn sie auf dem Dorf wohnen, müssen sie dann auf den Bus warten. Der aber kommt oft nur alle paar Stunden oder ...]]></description>
<link>https://tsecurity.de/weiterlesen/20428/20584/trampen-fuer-senioren-mitfahrbaenke-in-buensdorf/</link>
<pubDate>Sun, 31 Jan 2016 22:37:08 +0100</pubDate>
<category>🎥 Video</category>
<source url="https://tsecurity.de">TSECURITY.DE</source>
<content:encoded><![CDATA[Der K&uuml;hlschrank leer, der Supermarkt zehn Kilometer entfernt in der n&auml;chsten Stadt und kein Auto: F&uuml;r viele &auml;ltere Menschen ist das Alltag. Wenn sie auf dem Dorf wohnen, m&uuml;ssen sie dann auf den Bus warten. Der aber kommt oft nur alle paar Stunden oder&nbsp;...]]></content:encoded>
</item>
<item>
<title><![CDATA[Spion auf dem Armaturenbrett: Experten streiten über Dashcams]]></title>
<description><![CDATA[Immer mehr Autofahrer nutzen auch in Deutschland die kleinen Videokameras auf dem Armaturenbrett. Die Vorteile liegen auf der Hand: Bei Unfällen lässt sich leichter feststellen, wer Schuld hat. Rechtlich befinden sich die Nutzer aber in einer Grauzone.]]></description>
<link>https://tsecurity.de/weiterlesen/20429/20585/spion-auf-dem-armaturenbrett-experten-streiten-ueber-dashcams/</link>
<pubDate>Sun, 31 Jan 2016 22:37:08 +0100</pubDate>
<category>🎥 Video</category>
<source url="https://tsecurity.de">TSECURITY.DE</source>
<content:encoded><![CDATA[Immer mehr Autofahrer nutzen auch in Deutschland die kleinen Videokameras auf dem Armaturenbrett. Die Vorteile liegen auf der Hand: Bei Unf&auml;llen l&auml;sst sich leichter feststellen, wer Schuld hat. Rechtlich befinden sich die Nutzer aber in einer Grauzone.]]></content:encoded>
</item>
<item>
<title><![CDATA[HTC One M10: Evleaks gibt Infos zur Ausstattung bekannt]]></title>
<description><![CDATA[Kurz nach dem MWC 2016 wird HTC dieses Jahr voraussichtlich einen Nachfolger für das One M9 präsentieren. Erste technische Daten zu dem Gerät, welches intern als HTC Perfume gelistet wird, wurden nun vom ehemaligen Power-Leaker Evan Blass ...]]></description>
<link>https://tsecurity.de/weiterlesen/20430/20586/htc-one-m10-evleaks-gibt-infos-zur-ausstattung-bekannt/</link>
<pubDate>Sun, 31 Jan 2016 22:37:08 +0100</pubDate>
<category>🎥 Video</category>
<source url="https://tsecurity.de">TSECURITY.DE</source>
<content:encoded><![CDATA[Kurz nach dem MWC 2016 wird HTC dieses Jahr voraussichtlich einen Nachfolger f&uuml;r das One M9 pr&auml;sentieren. Erste technische Daten zu dem Ger&auml;t, welches intern als HTC Perfume gelistet wird, wurden nun vom ehemaligen Power-Leaker Evan Blass&nbsp;...]]></content:encoded>
</item>
<item>
<title><![CDATA[Rückrufaktion: Apple tauscht Netzteilstecker für iOS-Geräte und Macs aus]]></title>
<description><![CDATA[Apple ruft Millionen von Netzteilstecker-Adaptern zurück. Wie das Unternehmen mitteilt, können bei den betroffenen Steckern die Verbindungsstifte abbrechen. Es droht schlimmstenfalls die Gefahr eines Stromschlags. Hier die wichtigsten Fragen und ...]]></description>
<link>https://tsecurity.de/weiterlesen/20431/20587/rueckrufaktion-apple-tauscht-netzteilstecker-fuer-ios-geraete-und-macs-aus/</link>
<pubDate>Sun, 31 Jan 2016 22:37:08 +0100</pubDate>
<category>🎥 Video</category>
<source url="https://tsecurity.de">TSECURITY.DE</source>
<content:encoded><![CDATA[Apple ruft Millionen von Netzteilstecker-Adaptern zur&uuml;ck. Wie das Unternehmen mitteilt, k&ouml;nnen bei den betroffenen Steckern die Verbindungsstifte abbrechen. Es droht schlimmstenfalls die Gefahr eines Stromschlags. Hier die wichtigsten Fragen und&nbsp;...]]></content:encoded>
</item>
<item>
<title><![CDATA[Apple baut Raumschiff-artiges Hauptquartier in Cupertino]]></title>
<description><![CDATA[Das Design des neuen "Apple-Campus" erinnert an ein Raumschiff. Das gigantische kreisrunde Gebäude, das treffender Weise "Spaceship" heißt, soll Ende des Jahres von 13.000 Apple-Mitarbeitern bezogen werden. Doch auch die Baukosten werden bis ...]]></description>
<link>https://tsecurity.de/weiterlesen/20432/20588/apple-baut-raumschiff-artiges-hauptquartier-in-cupertino/</link>
<pubDate>Sun, 31 Jan 2016 22:37:08 +0100</pubDate>
<category>🎥 Video</category>
<source url="https://tsecurity.de">TSECURITY.DE</source>
<content:encoded><![CDATA[Das Design des neuen "Apple-Campus" erinnert an ein Raumschiff. Das gigantische kreisrunde Geb&auml;ude, das treffender Weise "Spaceship" hei&szlig;t, soll Ende des Jahres von 13.000 Apple-Mitarbeitern bezogen werden. Doch auch die Baukosten werden bis&nbsp;...]]></content:encoded>
</item>
<item>
<title><![CDATA[Ghostbusters: Spiel zum kommenden Kinofilm in Arbeit - Gerücht]]></title>
<description><![CDATA[30.01.2016 um 12:45 Uhr: Zu Ghostbusters, dem kommenden Kino-Reboot mit Kristen Wiig und Melissa McCarthy, ist laut eines Medienberichts offenbar auch ein Videospiel in Entwicklung. Dieses soll sich derzeit unter Activision für PlayStation 4 und Xbox ...]]></description>
<link>https://tsecurity.de/weiterlesen/20433/20589/ghostbusters-spiel-zum-kommenden-kinofilm-in-arbeit-geruecht/</link>
<pubDate>Sun, 31 Jan 2016 22:37:08 +0100</pubDate>
<category>🎥 Video</category>
<source url="https://tsecurity.de">TSECURITY.DE</source>
<content:encoded><![CDATA[30.01.2016 um 12:45 Uhr: Zu Ghostbusters, dem kommenden Kino-Reboot mit Kristen Wiig und Melissa McCarthy, ist laut eines Medienberichts offenbar auch ein Videospiel in Entwicklung. Dieses soll sich derzeit unter Activision f&uuml;r PlayStation 4 und Xbox&nbsp;...]]></content:encoded>
</item>
<item>
<title><![CDATA[Computersicherheit: Sechs Administrator-Tipps vom NSA-Hackerchef]]></title>
<description><![CDATA[Während die NSA überall reinkommen will, darf längst nicht jeder zur NSA. (Bild: Gary Cameron/Reuters). Der Leiter der NSA-Elitehacker TAO erklärt bei einem seiner seltenen öffentlichen Auftritte, wie man als Netzwerk-Admin seinem Team das Leben ...]]></description>
<link>https://tsecurity.de/weiterlesen/20434/20590/computersicherheit-sechs-administrator-tipps-vom-nsa-hackerchef/</link>
<pubDate>Sun, 31 Jan 2016 22:37:08 +0100</pubDate>
<category>🎥 Video</category>
<source url="https://tsecurity.de">TSECURITY.DE</source>
<content:encoded><![CDATA[W&auml;hrend die NSA &uuml;berall reinkommen will, darf l&auml;ngst nicht jeder zur NSA. (Bild: Gary Cameron/Reuters). Der Leiter der NSA-Elitehacker TAO erkl&auml;rt bei einem seiner seltenen &ouml;ffentlichen Auftritte, wie man als Netzwerk-Admin seinem Team das Leben&nbsp;...]]></content:encoded>
</item>
<item>
<title><![CDATA[Seattle: Boeing 737 Max startet zum Jungfernflug]]></title>
<description><![CDATA[Zum ersten Mal startet das neueste Boeing-Modell, eine 737 Max, zu einem Flug. Die Maschine soll Boeing Marktanteile sichern. Rivale Airbus lieferte seine neueste Entwicklung, den A320neo, bereits Anfang des Monats an den ersten Kunden aus.]]></description>
<link>https://tsecurity.de/weiterlesen/20435/20591/seattle-boeing-737-max-startet-zum-jungfernflug/</link>
<pubDate>Sun, 31 Jan 2016 22:37:08 +0100</pubDate>
<category>🎥 Video</category>
<source url="https://tsecurity.de">TSECURITY.DE</source>
<content:encoded><![CDATA[Zum ersten Mal startet das neueste Boeing-Modell, eine 737 Max, zu einem Flug. Die Maschine soll Boeing Marktanteile sichern. Rivale Airbus lieferte seine neueste Entwicklung, den A320neo, bereits Anfang des Monats an den ersten Kunden aus.]]></content:encoded>
</item>
<item>
<title><![CDATA[Jim Keller: Prozessorkoryphäe heuert bei Tesla Motors an]]></title>
<description><![CDATA[Der frühere Chefentwickler von AMD wechselt zum Elektroautohersteller Tesla Motors. Dort soll er sich um die Weiterentwicklung des Autopiloten kümmern. Im September vergangenen Jahres verließ der Chipentwickler Jim Keller seinen bisherigen ...]]></description>
<link>https://tsecurity.de/weiterlesen/20436/20592/jim-keller-prozessorkoryphaee-heuert-bei-tesla-motors-an/</link>
<pubDate>Sun, 31 Jan 2016 22:37:08 +0100</pubDate>
<category>🎥 Video</category>
<source url="https://tsecurity.de">TSECURITY.DE</source>
<content:encoded><![CDATA[Der fr&uuml;here Chefentwickler von AMD wechselt zum Elektroautohersteller Tesla Motors. Dort soll er sich um die Weiterentwicklung des Autopiloten k&uuml;mmern. Im September vergangenen Jahres verlie&szlig; der Chipentwickler Jim Keller seinen bisherigen&nbsp;...]]></content:encoded>
</item>
<item>
<title><![CDATA[Backdoored Ransomware for Educational Purposes]]></title>
<description><![CDATA[Here is an interesting article I found this week, it's about how A researcher released two pieces of 'educational' ransomware which were secretly backdoored in order to own some advanced and prolific cyber-criminals a small number of scriptkiddies. There two pieces were HiddenTear (a ransomware w...]]></description>
<link>https://tsecurity.de/weiterlesen/20383/20539/backdoored-ransomware-for-educational-purposes/</link>
<pubDate>Sun, 31 Jan 2016 22:37:07 +0100</pubDate>
<category>🎥 Video</category>
<source url="https://tsecurity.de">TSECURITY.DE</source>
<content:encoded><![CDATA[<div dir="ltr" trbidi="on"><a href="http://www.securityweek.com/malware-developers-blackmail-creator-open-source-ransomware">Here</a> is an interesting article I found this week, it's about how A researcher released two pieces of 'educational' ransomware which were secretly backdoored in order to own <strike>some advanced and prolific cyber-criminals</strike>&nbsp;a small number of scriptkiddies. There two pieces were HiddenTear (a ransomware with deliberately insecure cryptography designed to make decryption of files always possible), and&nbsp;eda2 (a supposedly flawless ransomware with a vulnerable C&amp;C panel designed to enable retrieval of keys). Although releasing backdoored 'educational' ransomware might seem like a good idea, it's really, really not.<br><br><h2>Educational Purposes</h2><div>I have a big problem with the word educational when it comes to malware: I get hundreds of emails per year asking for how to guides on writing &nbsp;fully weaponized malware (for educational purposes of course). You see the problem here is, what exactly do those educational purposes entail? There is no university degree in effective malware development, nor is freelance malware developer a viable legal career path. If they were planning on doing malware development for red teaming, they'd need a lot more skills than just basic malware development and could seek one of them many paths into pentesting based careers. What it really comes down to is, anyone using the term educational purposes is under no illusion that what they're doing has next to no legitimacy at all. If I go into a hardware store to buy an nail gun for some DIY job, I don't look the shopkeeper dead in the eyes and tell him "Don't worry, I'm not using this to murder anyone", because now he's thinking either 'wow, this guy has issues' or 'am I about to become complicity in a murder'. Generally speaking the people who aren't guilty don't feel the need to ensure everyone is aware of the fact, I get plenty of normal emails asking for help with malware in the context of some research they're doing, rather than some badly worded emails from Russians using google translate.&nbsp;</div><div><br></div><div>On the flip side it's no different; stating educational purposes when releasing some malware is really just another way of saying 'look at this great malware I wrote, I have no legitimate reason to post it but I'm going to anyway', and I would know because I've been guilty of this many times in the past. Now personally when posting any kind of malware proof of concept, I've made sure it's restricted to the exact context of the demo (I don't post a fully fledged banking trojan source code to demonstrate that malware can run on computers), and I also ensure that it would take more effort than it's probably worth for someone to weaponize any code I posted (though in the past this has still happened one or two times *shakes fist at sky*).</div><div><br></div><div>Now let's look at the pretense for the hidden tear ransomware:</div><blockquote>While I was researching about ransomwares, all I can see that lots of fancy diagrams, assembly codes which are tries to explain how it works. It may be easy to understand who are familiar with assembly. But most of people not, especially the newbies. And there wasn&rsquo;t any proper source code for a ransomware sample. My first motivation was provide a source code for newbies, students who are trying to understand the process.</blockquote>Well to start off, yes it is usually is fairly difficult to understand assembly if you don't know assembly, but why? Why do you need to understand assembly code to understand ransomware? How is giving out the source code going to help people understanding it? Ransomware is so basic that you really can explain it to no coders in less than 500 words:<br><blockquote>Ransomware is software which encrypts your computer's files using the AES-256 encryption algorithm; this algorithm is secure enough that it is used by the US government and cannot be broken easily. Once the files are encrypted, the encryption key is then sent to the ransomware owner and all traces of it are erased from your computer. The only way to recover the key to decrypt your files is by paying the owner to give it back.</blockquote>From a coders perspective, if you understand how AES is used to encrypt files, you understand how ransomware is used to encrypt files, it's really not rocket science; which begs the question why does there need to be an open source fully functional piece of ransomware complete with payment method and C&amp;C to explain how basic file encryption works? The answer is: there doesn't, this was the first open source ransomware for a very good reason.<br><br><h2>File Recovery</h2><div>As the author behind hidden tear and eda2 found out, a vulnerable C&amp;C panel doesn't ensure recovery. Make no mistake that these aren't professional cyber-criminals using his open source code, they are bottom tier scriptkiddies who otherwise wouldn't be able to gather the code required to make even remotely functional ransomware, which is evident by the fact they hosted their C&amp;C server on a free hosting site which had been terminated due to abuse complains before the researcher was able to recover the keys. Doh.&nbsp;</div><div><br></div><div>Now it may look like tricking criminals into using backdoored malware is still a great idea, but as is evident by the stories of hidden tear and eda2, nobody is moving to the backdoored ransomware; rather it's giving new players a taste of the high life with code they aren't yet able to write, then smacking them back down with backdoored encryption. So what happens next? Do they give up or do they continue trying to fix the backdoored code until they get it right? Well seeming as the developer revealed how and where the ransomware is backdoored, it's probably the latter.&nbsp;</div><div><br></div><div>The final issue here is assuming everything had gone to plan, C&amp;Cs stayed online, all encryption keys were recovered, how many people will get their files back (and for free)? It's not like you can just call up the victims and tell them they're infected with probably the only recoverable ransomware and that you have the key for them, most of these people don't even know what ransomware is. Although I don't have a fulltime job, I sometimes do incident response based work for a couple of people so I have had multiple encounters with the real world effects of ransomware. Recently I was tasked to help a DFIR guy identify the ransomware used to encrypt a companies files and see if they could recover them. In this case they were lucky, I was able to identify the ransomware and provide them with a list of methods for file recovery as well as confirm that if the worst comes to the worst this ransomware will give their files back if the pay; but, had they not called an incident response firm, what would have happened then?</div><div><br></div><h2>Conclusion</h2><div>It's unrealistic to think that even if the encryption keys are recovered that even 50% of the victims will get their files back for free. It relies on the the victim is first able to identify they're infected with ransomware based on hidden tear or eda2, then find who to call up to recover their files. I have a hard time identifying most ransomware and I've been working with malware for many years now, what hope do the victims have. Essentially the whole scheme is a variant of 'create the sickness sell the cure', as it's ignorant to think the backdoored ransomware is used only by existing groups and not just providing new tools to scriptkiddies.</div><div><br></div><div><div><a href="http://2.bp.blogspot.com/-lKKx9euO5ds/Vqpe0fG5pjI/AAAAAAAABVM/JTi9AIzSuJA/s1600/Ransomware1.jpg" imageanchor="1"><img border="0" height="0" src="http://2.bp.blogspot.com/-lKKx9euO5ds/Vqpe0fG5pjI/AAAAAAAABVM/JTi9AIzSuJA/s320/Ransomware1.jpg" width="0"></a></div><br></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Exploring Peer to Peer Botnets]]></title>
<description><![CDATA[Peer to Peer and Everything In betweenBack in October I'd gotten bored of the endless stream of cryptolockers and PoS trojan, so decided to look at something old school, that something was Kelihos. Since then, I've come to realize that P2P botnet monitoring brings together two of my favorite area...]]></description>
<link>https://tsecurity.de/weiterlesen/20384/20540/exploring-peer-to-peer-botnets/</link>
<pubDate>Sun, 31 Jan 2016 22:37:07 +0100</pubDate>
<category>🎥 Video</category>
<source url="https://tsecurity.de">TSECURITY.DE</source>
<content:encoded><![CDATA[<div dir="ltr" trbidi="on"><h2>Peer to Peer and Everything In between</h2><div>Back in October I'd gotten bored of the endless stream of cryptolockers and PoS trojan, so decided to look at something old school, that something was Kelihos. Since then, I've come to realize that P2P botnet monitoring brings together two of my favorite areas of security: Reverse Engineering and Programming. As a fun little side project, I decided to begin work on a P2P botnet monitoring system which would show details such as the size of the botnet and geographical distribution of nodes (It's still a work in progress but you can find it <a href="https://intel.malwaretech.com/botnet/za3/">here</a>.).</div><div><br></div><div><a href="http://2.bp.blogspot.com/-o9tjJuWMkU4/VpPBHaSaSSI/AAAAAAAABUE/vhpclrKs3iw/s1600/ZeroAccess3%2BTracker.png" imageanchor="1"><img border="0" height="488" src="http://2.bp.blogspot.com/-o9tjJuWMkU4/VpPBHaSaSSI/AAAAAAAABUE/vhpclrKs3iw/s640/ZeroAccess3%2BTracker.png" width="640"></a></div><div><br></div><h2>How does it work?</h2><div>In a peer to peer botnet, bots which can receive incoming connections act as servers (called supernodes) and those that can't just perform tasks from the botmaster (known as workers). The supernodes connect to other supernodes and pass messages between themselves to keep the network in sync and workers then connect to multiple supernodes to retrieve commands. In order for the workers to keep an up to date list of supernodes, the each supernode respond to a peer request command with a list of IPs for other supernodes it knows about (this list varies in size depends on botnets; for example Kelihos sends 500 IPs whist ZeroAccess2+ only sends 16). Workers will download peer lists from multiple supernodes and store them locally to ensure they can maintain connectivity with the botnet, even with a constantly changing landscape of supernodes.</div><div><br></div><div><b>Mapping Supernodes</b></div><div>First we need the IP of one or more online supernodes, then we can write a program to connect to each supernode and send a peer request, then connect to all the IPs returned, repeating the process recursively. In the case of newer ZeroAccess nodes, the supernodes internally store a large list of supernode IPs, but only return 16 online IPs as a response to each peer request: this means that in a single crawl we will likely only find a small cluster of recently contacted supernodes, not every online node.&nbsp;</div><div><br></div><div>To ensure the entire network is discovered, we should start the crawler off with multiple supernode IPs and store all IPs found into a database, then each time we restart the crawler we seed it with the list of IPs found during the previous crawler; repeating this process for a couple of hours ensure all online nodes are found.</div><div><br></div><div>If you're like me and you're wondering what a botnet map looks like when visualized, then look no further. Here is some data taken from a single crawl of the ZeroAccess 3 botnet and visualized using d3.&nbsp;</div><table align="center" cellpadding="0" cellspacing="0"><tbody><tr><td><a href="http://4.bp.blogspot.com/-TUIOxt2TbYI/VpPwoimJFLI/AAAAAAAABUU/j25BxJZm_LY/s1600/ZA3Full.png" imageanchor="1"><img border="0" height="485" src="http://4.bp.blogspot.com/-TUIOxt2TbYI/VpPwoimJFLI/AAAAAAAABUU/j25BxJZm_LY/s640/ZA3Full.png" width="640"></a></td></tr><tr><td>ZeroAccess 3 Full Map (Online and offline supernodes).</td></tr></tbody></table><table align="center" cellpadding="0" cellspacing="0"><tbody><tr><td><a href="http://4.bp.blogspot.com/-ciCWeB19UaI/VpQXFv5QCyI/AAAAAAAABU0/pOa9Gx3DzuY/s1600/ZA3Full2.png" imageanchor="1"><img border="0" height="464" src="http://4.bp.blogspot.com/-ciCWeB19UaI/VpQXFv5QCyI/AAAAAAAABU0/pOa9Gx3DzuY/s640/ZA3Full2.png" width="640"></a></td></tr><tr><td>ZeroAccess 3 Full Map (Same as above but with more link elasticity).</td></tr></tbody></table><div><table align="center" cellpadding="0" cellspacing="0"><tbody><tr><td><a href="http://4.bp.blogspot.com/-Ssws2rO1Zbc/VpQXMhmn3GI/AAAAAAAABU8/88JBm2aoFJA/s1600/ZA3OnlineOnly.png" imageanchor="1"><img border="0" height="530" src="http://4.bp.blogspot.com/-Ssws2rO1Zbc/VpQXMhmn3GI/AAAAAAAABU8/88JBm2aoFJA/s640/ZA3OnlineOnly.png" width="640"></a></td></tr><tr><td><span>ZeroAccess 3 (Online supernodes only).</span></td></tr></tbody></table><b><br></b><b>Mapping Workers</b></div><div>This is a little bit more tricky as worker IPs are not exposed to the botnet in any way; however, they do still need to connect to multiple supernodes to retrieve peer lists and commands. In order to map all workers, we'd need to set up multiple supernodes across the botnet which log incoming connections (obviously every worker doesn't connect to every supernode at the same time, so it's important that our supernodes have a stronger presence in the botnet).</div><div><br></div><div>Depending on the botnet bots use various different methods to decide which nodes to contact, this could be: age, online time, latency, or trust. In the case of ZeroAccess 2, it's age. ZA2 workers keep an internal list of supernode IP addresses which they connect to in order from newest to oldest; so, in order to gain a well established presence on the botnet it would be best to have a server with multiple IPs and add new ones frequent, making sure to notify as many other supernodes as possible of our new IP addresses (we can use the comprehensive list of supernode IPs obtained from the crawler for that!).</div><div><br></div><h2>What's the purpose?</h2><div>In my case the botnet tracker has no real purpose other than being a fun project, but in the threat intelligence world it could provide valuable intelligence. If we know the IP addresses of all the workers on the botnet, we can proactively work against any malicious actions they might take: for instance, if the botnet was a spam botnet, we could have have all the IP addresses flagged for spam before they even send a single email. We could also use the data to automatically notify businesses if IPs in their address space show up on the botnet, allowing them to be deal with breaches before they cause any harm.&nbsp;</div><div><br></div><h2>Conclusion</h2><div>This post is just a small insight into my current project and as it progresses I will likely post more data and data visualizations. If you've got any suggestions, leave a comment or DM me on twitter (<a href="https://www.twitter.com/MalwareTechBlog/">@MalwareTechBlog</a>).<br><br>If you're interested to read more about ZeroAccess3, check out this collaboration I did with the guys at Kryptos Logic: <a href="http://kryptoslogic.blogspot.co.uk/2016/01/zeroaccess-3-analysis.html">ZeroAccess 3 Analysis</a>.</div><div><br></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Kelihos Analysis - Part 1]]></title>
<description><![CDATA[In the recent years I've noticed a shift in the malware economy from botnets to ransomware, which is likely due to the AV industry employing more aggressive tactics against botnets resulting in a drop in profitability. As I've said before: ransomware is about as interesting to me is watching oil ...]]></description>
<link>https://tsecurity.de/weiterlesen/20385/20541/kelihos-analysis-part-1/</link>
<pubDate>Sun, 31 Jan 2016 22:37:07 +0100</pubDate>
<category>🎥 Video</category>
<source url="https://tsecurity.de">TSECURITY.DE</source>
<content:encoded><![CDATA[<div dir="ltr" trbidi="on">In the recent years I've noticed a shift in the malware economy from botnets to ransomware, which is likely due to the AV industry employing more aggressive tactics against botnets resulting in a drop in profitability. As I've said before: ransomware is about as interesting to me is watching oil dry and they're so basic that they aren't worth reversing, so I decided to look at something old but gold, Kelihos.<br><br>Surprisingly I've never even looked at Kelihos before as it's been around way longer than I've been reverse engineering, and every time I heard about it during my reversing days it was because it had been taken down...again. Well, last month a friend of mine was talking about how Kelihos was spreading again via Nuclear exploit kit, prompting me to contact the exploit pack guru&nbsp;<a href="https://twitter.com/kafeine">@Kafeine</a>, and request a recent sample.<br><br>Something interesting to note is that Kelihos spreads aggressively via exploit kits, rather than growing slowly over time through self propagation. This is why the many takedown attempts have had little effect as the botmaster can simple sets up new infrastructure and starts spreading again within a few a couple of days (Researchers had reported a new sample being spread less 24 hours after the most recent takedown).<br><br><h2>Kelihos Loader</h2><div>The exploit payload is a small executable ~37kb in size, which has been packed with UPX then encrypted with a regularly updated crypter (to ensure it's undetected to antiviruses). Once unpacked the loader is pretty simple, here's a look at the main routine.</div><div><a href="http://4.bp.blogspot.com/-Z1zbzCftY8w/VmWc4b7zSmI/AAAAAAAABNw/M3SYQzRZZBc/s1600/GetIP.png" imageanchor="1"><img border="0" height="320" src="http://4.bp.blogspot.com/-Z1zbzCftY8w/VmWc4b7zSmI/AAAAAAAABNw/M3SYQzRZZBc/s320/GetIP.png" width="201"></a></div><div>What happens here is a block of dwords are copied from memory then one is picked by random. In order to find out what these dwords are, we need to take a look at the preceding block of code.</div><div><a href="http://4.bp.blogspot.com/-uezm_xLG9h8/VmWfSQTvD0I/AAAAAAAABOI/VBgum-9a8SM/s1600/DecryptIP.png" imageanchor="1"><img border="0" height="320" src="http://4.bp.blogspot.com/-uezm_xLG9h8/VmWfSQTvD0I/AAAAAAAABOI/VBgum-9a8SM/s320/DecryptIP.png" width="160"></a></div><div>Here it takes the dword, xors each of the 4 bytes with (byte_number - 91), then adds a period after each byte except for the last; as you can't probably guess it's building an IP address. The block contains between 70 and 80 IPs and the loader will try each IP in an attempt to download onprdfi.exe, until an attempt is successful (the file name changes from time to time but is always 11 bytes in length).</div><div><br></div><div>If the loader detects that connections may be being block, it will inject some shellcode into explorer which will try connecting to the same list of IPs again and if any connections are successful, it will call&nbsp;WSADuplicateSocket() and pass the socket handle back to the loader, which will then attempt to download the file (This method is likely designed to bypass basic firewalls by establishing the connection from a trusted process, instead of the loader's one).&nbsp;</div><div><br></div><div>The full block of IPs can be found at address 0x0x404008 and decrypted using the following code:&nbsp;<a href="http://pastebin.com/WXkjjacG">http://pastebin.com/WXkjjacG</a></div><div><br></div><h2>Kelihos Servers</h2><div>Something i noticed while poking around with the loader is that the hardcoded IPs are not actually servers, most are residential IPs and some are even dynamic. Furthermore the HTTP server appears to be custom coded, but reports itself as Apache. A little test you can do is send some random text to the server using netcat, on a normal server we'd get "400 Bad Request", but the Kelihos severs just close the connection without sending any data.</div><div><br></div><div><a href="http://2.bp.blogspot.com/-rMmHUV7xWWs/VmW_wxFvmlI/AAAAAAAABOY/Y3I6rtcjHq0/s1600/CustomHTTPServer.png" imageanchor="1"><img border="0" src="http://2.bp.blogspot.com/-rMmHUV7xWWs/VmW_wxFvmlI/AAAAAAAABOY/Y3I6rtcjHq0/s1600/CustomHTTPServer.png"></a></div><div></div><div>Another interesting thing which i found when port scanning the host, is it's listening on port 53 (DNS), so i sent some queries.&nbsp;</div><div><br></div><div><a href="http://2.bp.blogspot.com/-r0eVxOeqnoU/VmXDRnZgFEI/AAAAAAAABOk/gm5bRNo6te4/s1600/DNSReplies.png" imageanchor="1"><img border="0" src="http://2.bp.blogspot.com/-r0eVxOeqnoU/VmXDRnZgFEI/AAAAAAAABOk/gm5bRNo6te4/s1600/DNSReplies.png"></a></div><div><br></div><div>Here we can see a couple of thing, firstly it's returning valid IPs for a non-existent domain, each request returns a different IP, and the TTL (time-to-live) is 0; This has all the characteristics of a fastflux nameserver.&nbsp;</div><div><br></div><div>Obviously in order for something to actually end up querying this server, it'd need a real DNS with the nameserver pointing to this IP, so can we find the fastflux domain? Well, yes we can. For this purpose I was able to use OpenDNS Investigate, a passive DNS lookup tool. If you're not familiar with passive DNS, the basics are that the company runs a public DNS server which logs the results of any DNS lookup, so if a computer infected with kelihos resolved the fastflux domain and got this IP, there'd be a record of it in the database, let's have a look.</div><div><br></div><div><a href="http://3.bp.blogspot.com/-MlL7jpHBeV8/VmXGloLtw6I/AAAAAAAABOw/7WO2bM4L3O8/s1600/PassiveReverseLookup.png" imageanchor="1"><img border="0" height="239" src="http://3.bp.blogspot.com/-MlL7jpHBeV8/VmXGloLtw6I/AAAAAAAABOw/7WO2bM4L3O8/s640/PassiveReverseLookup.png" width="640"></a></div><div><br></div><div>Bingo! 5 domains have resolved to this IP and 3 of them have used it as a nameserver, suggesting it's a double fastflux (both the nameservers and A records change with every query). Finally, by performing a passive lookup of one of the domains, we can see some of the IPs it's resolved to in the past week.&nbsp;</div><div><br></div><div><a href="http://1.bp.blogspot.com/-lSXv3cNdsso/VmXJUG4lqXI/AAAAAAAABO8/eGvgsdMk2Io/s1600/ReverseLookup.png" imageanchor="1"><img border="0" height="559" src="http://1.bp.blogspot.com/-lSXv3cNdsso/VmXJUG4lqXI/AAAAAAAABO8/eGvgsdMk2Io/s640/ReverseLookup.png" width="640"></a></div><div><br></div><h2>Conclusion</h2><div>That's all for now, the next article will be in a couple of days and will look into the main binary and inner workings of the botnet. I've censored the domains because I don't want to risk people reporting them as it's not helpful to me or other researchers and has absolutely no effect on the botnet (if you need one for research email or DM me on twitter).</div><div><br></div><div>Shout-out to OpenDNS and Kafeine for their help with my research.&nbsp;</div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Regarding Kelihos Research]]></title>
<description><![CDATA[I had planned to continue posting a series of articles detailing my findings from looking into the Kelihos botnet (namely the peer-to-peer protocol). Although my intentions were only to crawl the botnet and try to gauge its size (out of personal interest), I've been made aware that the informatio...]]></description>
<link>https://tsecurity.de/weiterlesen/20386/20542/regarding-kelihos-research/</link>
<pubDate>Sun, 31 Jan 2016 22:37:07 +0100</pubDate>
<category>🎥 Video</category>
<source url="https://tsecurity.de">TSECURITY.DE</source>
<content:encoded><![CDATA[<div dir="ltr" trbidi="on"><br>I had planned to continue posting a series of articles detailing my findings from looking into the Kelihos botnet (namely the peer-to-peer protocol). Although my intentions were only to crawl the botnet and try to gauge its size (out of personal interest), I've been made aware that the information posted in my previous article may have been used by others to perform attacks, resulting in some changed being made to the protocol. Personally I'd be happy to keep reversing the bot and play protocol whack-a-mole, though I understand that there's probably a lot of people out there who are going to be upset if the protocol is repeatedly changed as a result of my articles. I did consider taking a different path with the article and documenting the malware side of Kelihos, like I usually do, but the code is rather software like and doesn't contain anything interesting such as any form of stealth or defense against removal.<br><br>If you have any suggestions for what I should write about instead, please email me on admin@malwaretech.com.<br><br><br></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Device Guard - The Beginning of the End for Malware?]]></title>
<description><![CDATA[Finally I manage to put together a computer capable of running Device Guard and I've had a little bit of time to play around with the code signing part. Everyone is probably already familiar with x64 driver signature enforcement (64-bit Windows systems can only load signed drivers); Well, now Mic...]]></description>
<link>https://tsecurity.de/weiterlesen/20387/20543/device-guard-the-beginning-of-the-end-for-malware/</link>
<pubDate>Sun, 31 Jan 2016 22:37:07 +0100</pubDate>
<category>🎥 Video</category>
<source url="https://tsecurity.de">TSECURITY.DE</source>
<content:encoded><![CDATA[<div dir="ltr" trbidi="on">Finally I manage to put together a computer capable of running Device Guard and I've had a little bit of time to play around with the code signing part. Everyone is probably already familiar with x64 driver signature enforcement (64-bit Windows systems can only load signed drivers); Well, now Microsoft has introduced a similar feature for user mode code, which is a huge deal when it comes to malware (Currently the feature is only present on Windows 10 Enterprise, but I'm fairly certain as it matures it will make it's way to home systems).<br><br><h2>Device Guard Code Integrity Policy</h2><div>Device Guard not only adds customizable user mode code integrity checks (UMCI), but re-works a lot of the kernel mode code integrity (KMCI) allowing far more flexibility than just allowing all signed drivers. The policy can either be deployed locally by and administrator or from a domain controller, making it scalable for enterprise networks.</div><div><br></div><div>Something I was actually quite surprised by is the fact that the user mode code integrity is not simply limited to executable (I was expecting Device Guard to be just another throw away pseudo-security feature like UAC, but it's clear some real thought has gone into this).&nbsp;</div><div><br></div><h4><b>Scope</b></h4><div><b>Executables&nbsp;</b></div><div>As already explained, Device Guard isn't just a more flexible version of Kernel Mode Code Signing, it goes the whole nine yards with customizable code integrity policy for executables. Rather than using a flimsy software restriction policy, Device Guard can use an array of different settings to make sure only trusted executables are run.&nbsp;</div><table align="center" cellpadding="0" cellspacing="0"><tbody><tr><td><a href="http://3.bp.blogspot.com/-8vRt8crsoaQ/VfltxtZQPkI/AAAAAAAABNE/qRYCmbByw9A/s1600/UnsignedExecutable.png" imageanchor="1"><img border="0" src="http://3.bp.blogspot.com/-8vRt8crsoaQ/VfltxtZQPkI/AAAAAAAABNE/qRYCmbByw9A/s1600/UnsignedExecutable.png"></a></td></tr><tr><td>Executables violating the policy are simply blocked from running at all.</td></tr></tbody></table><div><br></div><div><b>Dynamic Link Libraries</b></div><div>One of my favorite attacks against HIPS, firewalls, and software restriction policies is DLL hijacking. Simply put, when an application calls LoadLibrary("somedll.dll"), the system first looks for the DLL in the KnowDlls registry key, followed by the applications working folder (where the application was run from), and finally system paths like System32. If you copied a legitimate system application to another folder, then placed an arbitrary DLL in the same folder and gave it the name of a DLL the application dynamically loads, it would load your DLL instead of the real one. Using this method you can bypass all kinds security checks by loading code inside a legitimate system application, without using code injection (which normally triggers HIPS).</div><div><br></div><div>Well, it seems Microsoft considered DLL hijacking this time around as all DLLs loaded by an application are checked against the code integrity policy; If a DLL violates the policy, the DLL and application will fail to load (the check is implemented in MiCreateSection, so should apply to any code loaded with NtCreateSection and SEC_IMAGE).</div><table align="center" cellpadding="0" cellspacing="0"><tbody><tr><td><a href="http://4.bp.blogspot.com/-Imkeu6081co/VfllJt9_C1I/AAAAAAAABMk/0Sq3Po8mv7A/s1600/UnsignedDll.png" imageanchor="1"><img border="0" src="http://4.bp.blogspot.com/-Imkeu6081co/VfllJt9_C1I/AAAAAAAABMk/0Sq3Po8mv7A/s1600/UnsignedDll.png"></a></td></tr><tr><td>Trying to hijack explorer.exe with an unsigned DLL results in&nbsp;STATUS_SYSTEM_INTEGRITY_POLICY_VIOLATION</td></tr></tbody></table><div><br></div><div><b>Windows Script Hosts &amp; PowerShell</b></div><div>Another long standing issue with antiviruses is malicious scripts; Engines like PowerShell have the ability to access the Win32 API, allowing malware to leverage scripts in order to bypass binary scanning and perform almost all malicious tasks without the need for an executable.&nbsp;</div><div><br></div><div>Device Guard introduces signing of of Windows Script Host scripts, as well as PowerShell to prevent malicious use. Unsigned PowerShell scripts are blocked and PowerShell itself is run in "constrained mode" which prevents it from executing arbitrary code via .NET scripting, COM interface, WinAPI, etc.</div><div><br></div><table align="center" cellpadding="0" cellspacing="0"><tbody><tr><td><a href="http://3.bp.blogspot.com/-bRGDCJIk9lk/Vfln0Y81yKI/AAAAAAAABMw/Kh1h7--MEl8/s1600/UnsignedScript.png" imageanchor="1"><img border="0" height="345" src="http://3.bp.blogspot.com/-bRGDCJIk9lk/Vfln0Y81yKI/AAAAAAAABMw/Kh1h7--MEl8/s640/UnsignedScript.png" width="640"></a></td></tr><tr><td>PowerShell is in constrained mode and blocks unsigned script.s</td></tr></tbody></table><div><br></div><h4>Flexibility</h4><div>Device Guard provides a multitude of mix &amp; match ways to define which applications and drivers can be run (known as file rules), allowing administrators to fine tune policies to their needs.&nbsp;</div><div><br></div><div>Here's a list of some file rule levels currently available:</div><div><ul><li><b>PCA Certificate</b>&nbsp;- All files signed with a leaf certificate belong to the whitelisted PCA Certificate (Ex: Any file signed with a VeriSign Extended Validation certificate).</li><li><b>Leaf Certificate&nbsp;</b>-&nbsp;All files signed with a specific code signing certificate (the ones issued to vendors).</li><li><b>Hash - </b>Allow a single file by its SHA2 hash (Good for unsigned applications).</li><li><b>FileName - </b>Just...just don't.</li><li><b>Publisher - </b>Like PCA, but with the ability to only allow applications from certain publishers (the "common name" of the leaf certificate Ex: Only leaf certificates issued to Microsoft).</li><li><b>WHQL - </b>Allow kernel drivers which are signed &amp; verified by WHQL.</li><li><b>WHQL Publisher</b> - Same as Publisher but only for signed &amp; verified WHQL drivers.</li></ul><div>Also allowed is the ability to specify a minimum file version with most of the rules, which is great for stopping malware exploiting old signed drivers to gain kernel mode execution.&nbsp;</div></div><div><br></div><div>To start off, a policy can be created by scanning the current system and building a list of all all installed applications, then whitelisting them using whichever rule required (it's also possibly to fall back to hashes or file names for unsigned files). By default policies are created with "Audit Mode" enabled, which means when the policy is installed, it won't be enforced but will instead log all files which would have been blocked to the event log.</div><table align="center" cellpadding="0" cellspacing="0"><tbody><tr><td><a href="http://3.bp.blogspot.com/-l_M840NV7aQ/Vfl4FIClRCI/AAAAAAAABNQ/m70bb_JnACw/s1600/EventViewer.png" imageanchor="1"><img border="0" height="406" src="http://3.bp.blogspot.com/-l_M840NV7aQ/Vfl4FIClRCI/AAAAAAAABNQ/m70bb_JnACw/s640/EventViewer.png" width="640"></a></td></tr><tr><td>Example of a CodeIntegrity event</td></tr></tbody></table><div><br></div><div>A very handy feature is the ability to create a second policy using the event log, then merge it with a first. This would allow the administrator to set up a test system and build a list of files which would be blocked by the current policy, then review and whitelist &nbsp;them in a future policy.</div><div><br></div><h4>Virtualization Based Protection of Code Integrity</h4><div>This is where Device Guard really comes into its own: If the system is capable of Virtualization Based Security (VBS), Device Guard can be configured to use hypervisor technology in order to isolate parts of the kernel involved in security checks from the rest. With VBS enabled, even if malicious code does somehow manage to get into kernel mode, it would be unable to patch the code responsible for UMCI / KMCI, therefore incapable of installing any code to persist across reboot (or disable the code integrity policy altogether).&nbsp;</div><div><br></div><h2>Conclusion</h2><div>If properly implemented, Device Guard can be used to create a system which is highly resilient to common malware (assuming UMCI, KMCI, and VBPCI are enabled and well configured).</div><div><ul><li>UMCI prevents an adversary social engineering the victim into running malware (unless they can get hold of a whitelisted certificate).&nbsp;</li><li>On Windows 10 Google Chrome &amp; Internet Explorer run inside an isolated container known as AppContainer, so even if the browser was exploited, it'd be run in total isolation.</li><li>If the code somehow escapes AppContainer, it'd need a method of persisting across reboot, bearing in mind the UMCI policy prevents unsigned code being added to start-up and it's kind of hard to exploit applications during boot.</li></ul><div>Although it's still early days, Device Guard is definitely a huge leap in the right direction towards putting an end to malware. Though it's likely going to take some time for such a feature to evolve from a complex set of configurations aimed at experienced network administrators, to an out-of-the-box security system for end users.</div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Hidden VNC for Beginners]]></title>
<description><![CDATA[Hidden VNC is a creative solution to a solution to a problem which stemmed from banking fraud. Back years ago when fraud was uncommon, most banks only had basic IP or Geo-location checks to flag or block accounts if someone logged in from another computer. To combat this, banking trojans would ru...]]></description>
<link>https://tsecurity.de/weiterlesen/20388/20544/hidden-vnc-for-beginners/</link>
<pubDate>Sun, 31 Jan 2016 22:37:07 +0100</pubDate>
<category>🎥 Video</category>
<source url="https://tsecurity.de">TSECURITY.DE</source>
<content:encoded><![CDATA[<div dir="ltr" trbidi="on"><div>Hidden VNC is a creative solution to a solution to a problem which stemmed from banking fraud. Back years ago when fraud was uncommon, most banks only had basic IP or Geo-location checks to flag or block accounts if someone logged in from another computer. To combat this, banking trojans would run a SOCKS proxy server on the victims computer, allowing the fraudster to access the victims bank account with the same IP. As fraud became more prominent, banks started coming up with proprietary fraud detection systems which fingerprint the user's systems using a variety of check (Browser, OS/Plugin versions, locale, timezone, etc). The blackbox nature of these systems would require a fraudster to pretty much replicate the victim's system configuration in order to be sure the account wouldn't get blocked, so a more convenient method of fraud had to be found, that method was of course VNC. Fraudsters could VNC into a victims computer and use it to log into their bank account, but obviously this wasn't ideal. If the victim was using the computer, they'd see what the fraudster was doing, and if they weren't, the computer would probably be turned off. What was needed was some kind of VNC software that allowed fraudsters to access the system discretely, at the same time as the victim was using it.&nbsp;</div><div><br></div><h2>Hidden VNC</h2><div><b>Hidden Desktop</b></div><div>Malware can make use of some little known Windows features such as CreateDesktop and cross-process window subclassing to implement an invisible environment for VNC to run. As most linux users will probably be familiar with, a lot of distros have the ability to run multiple simultaneous desktops with independent taskbars. Windows has had this ability to crate multiple desktops since 2000, but it's not a well known feature and there is no default application to make use of it. By calling CreateDesktop, software can create a hidden desktop and execute applications in the desktop's context. All applications running on the hidden desktop will be invisible to the other desktops (i.e. the one the victim is using), they will not even show in the taskbar outside of the hidden desktop. Sounds simple enough, right?</div><div><br></div><div><b>Screenshots</b></div><div>Most VNC software works by taking periodic screenshots and sending them back to the client; however, Windows does not render any GUI elements to desktops which are not active (currently displayed on the monitor). One can't simply just capture screenshots of the hidden desktop, instead the VNC server would have to call EnumDesktopWindows to get a list of windows running on the hidden desktop, then call PrintWindow on each individual window, writing them to a bitmap in reverse Z-Order (starting with the bottom-most window and working its way to the top-most). Essentially the server is just emulating the screenshot feature by rendering each individual window to a bitmap in reverse of the order they appear on the screen.</div><div><br></div><div>Unfortunately, some applications don't properly handle WM_PRINT or WM_PRINTCLIENT messages (sent by PrintWindow), and as a result all or parts of the application will display as a white rectangle, as shown below.</div><div><br></div><div><a href="http://3.bp.blogspot.com/-qicSAMUhjWc/VfVWae-A5jI/AAAAAAAABMU/ot75M3Wo8Dc/s1600/Screenshot.png" imageanchor="1"><img border="0" height="360" src="http://3.bp.blogspot.com/-qicSAMUhjWc/VfVWae-A5jI/AAAAAAAABMU/ot75M3Wo8Dc/s640/Screenshot.png" width="640"></a></div><div><br></div><div>To resolve this, the VNC server would need to implement WM_PRINT and WM_PRINTCLIENT message on behalf of the application, making sure it paints all visible elements to the buffer. This can be done by either injecting code into all processes and hooking various functions in user32.dll, or by using cross-process subclassing to give the VNC server the ability to process window messages destined for the target application from within the VNC process.</div><div><br></div><div><b>User Input</b></div><div>When it comes to user input, the server has to emulate a virtual keyboard / mouse as input would be sent to the active desktop, not the hidden one. Normally when the mouse is moved or clicked the VNC client would sent the position along with a button click event to the VNC server, which would move the mouse to the given position and simulate a click, but because the real keyboard and mouse can't be use, things are far more complicated. The VNC server would have to keep track of every window on the hidden desktop, it's location, and its Z-Index; When a click even is sent, the server would need to find which window is at the cursor's current position by enumerating each window and checking its coordinates and visibility, then use PostMessage to send it a click event. For keyboard the same is true, the VNC server needs to keep track of which window is currently focused and use PostMessage to direct the input towards it.</div><div><br></div><h2>Conclusion</h2><div>Hidden VNC is probably one of the most complicated malware features to code and essentially requires coders to implement their own window manager, which is why there are very few unique implementations in the wild (most malware uses a single implementation unimaginatively named HVNC).&nbsp;</div><div><br></div><div>Sadly due to the fact it's a very sought after feature for banking trojans, I'm not going to post proof of concept code; however, I've uploaded some example code to demonstrate creating and switching between multiple desktops, you can find it here:&nbsp;<a href="https://github.com/MalwareTech/CreateDesktop/">https://github.com/MalwareTech/CreateDesktop/</a></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Advanced Desktop Application Sandboxing via AppContainer]]></title>
<description><![CDATA[This post is kind of a follow on from my previous article Usermode Sandboxing, so if you've not yet read that you should do so first.AppContainer was a fairly quietly introduced feature in Windows 8, which is a shame as it provides some great features which can be used for desktop application sec...]]></description>
<link>https://tsecurity.de/weiterlesen/20389/20545/advanced-desktop-application-sandboxing-via-appcontainer/</link>
<pubDate>Sun, 31 Jan 2016 22:37:07 +0100</pubDate>
<category>🎥 Video</category>
<source url="https://tsecurity.de">TSECURITY.DE</source>
<content:encoded><![CDATA[<div dir="ltr" trbidi="on">This post is kind of a follow on from my previous article&nbsp;<a href="http://www.malwaretech.com/2014/10/usermode-sandboxing.html">Usermode Sandboxing</a>,&nbsp;so if you've not yet read that you should do so first.<br><br>AppContainer was a fairly quietly introduced feature in Windows 8, which is a shame as it provides some great features which can be used for desktop application security too (Few people are aware that it's not just used for Apps as the name might suggest). I'll go over some of the features which stood out to me.<br><br><b>Network Restrictions</b><br>A feature previously lacking in the Windows integrity mechanism was proper network restrictions. Low integrity processes could still freely create sockets, which would allow malicious code to escape a sandbox by exploiting a vulnerable higher integrity process listening on the host.<br><br>AppContainer introduces some new network restrictions such as:<br><br><ul><li>WinCapabilityInternetClientSid - Application can make outbound connections but not listen on sockets.</li><li>WinCapabilityInternetClientServerSid -&nbsp;Application can create listening sockets but not make outbound&nbsp;connections.</li><li>WinCapabilityPrivateNetworkClientServerSid -&nbsp;Application can listen or make outbound connections to IPs within the host's&nbsp;local network (not to external networks i.e the internet), but only if the network is set to Work or Private.&nbsp;</li></ul><div>An additional restriction I've noticed is that by default the application can connect to localhost, but cannot interact with listening sockets created by applications outside of its container (Services, other Apps, etc), which would prevent the application from exploiting anything listening on localhost.&nbsp;</div><div><br></div><div><b>Filesystem &amp; Registry Restrictions</b></div><div>Inside the AppContainer variable such as %temp% and %localappdata% are reassigned to directories within that container (%localappdata%\Packages\&lt;Container Name&gt;\), which is the only writable path by default. For registry the default accessible path is: HKEY_CURRENT_USER\Software\Classes\Local Settings\Software\Microsoft\Windows\ CurrentVersion\AppContainer\Storage.</div><div><br></div><div>Although Apps can be assigned privileges such as&nbsp;WinCapabilityDocumentsLibrarySid (access to My Documents), this is implemented by the App broker process and will not work for desktop applications, instead one must explicitly add the AppContainer's SID to the file/folder's ACL's from the process creating the container (Same goes for other objects such as sections and registry keys).</div><div><br></div><div><b>Process Isolation</b></div><div>Previously low integrity processes could interfere with other low integrity processes, but with AppContainer this is no longer the case. Listing processes will only show the system pseudo-process and any processes running inside that specific container (no desktop processes, services, or other applications), and it's the same story for any other objects created outside of the container. This is pretty handy as browser worker processes usually run as low integrity, which meant that any malware run inside a sandbox would still be able to inject the browser and exfil data.</div><div><br></div><div><b>Kernel Mode&nbsp;Checks</b></div><div>All the actual access checks are part of the Windows kernel, so it's not a case of just removing a few user mode hooks or performing direct system calls, access is restricted at kernel level making AppContainer a great improvement over old sandboxing methods.<br><br></div><h2>Example Code</h2><div>I've created a little example and test of the AppContainer capabilities in C, it creates a container and executes itself inside the container in order to test the restrictions (Obviously this will only work on Windows 8+ where AppContainer is available).</div><div><br></div><div>The test container is given permission to connect to network IPs (but not the internet), the broker also create a text file (%userprofile%\Desktop\allowed_test.txt) and grants the AppContainer access. Other than connecting to network IPs and accessing the App's install directory or the explicitly allowed file, everything else is restricted.</div><div><br></div><div><a href="http://3.bp.blogspot.com/-7hW705i7WVg/Ve8LuPBEtFI/AAAAAAAABME/_41PdJqEFkU/s1600/AppContainerTest.png" imageanchor="1"><img border="0" height="364" src="http://3.bp.blogspot.com/-7hW705i7WVg/Ve8LuPBEtFI/AAAAAAAABME/_41PdJqEFkU/s640/AppContainerTest.png" width="640"></a></div><div><br></div><div><b><br></b></div><div><b>Github Link:&nbsp;</b><a href="https://github.com/MalwareTech/AppContainerSandbox">https://github.com/MalwareTech/AppContainerSandbox</a></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Creating the Ultimate Tor Virtual Network]]></title>
<description><![CDATA[Although the methods in this article can be used for proper anonymity outside of the tor browser, the main focus is creating a secure tor based research environment. As most security researchers know there's always a big decision with analyzing malware or exploits in a VM, most people would prefe...]]></description>
<link>https://tsecurity.de/weiterlesen/20390/20546/creating-the-ultimate-tor-virtual-network/</link>
<pubDate>Sun, 31 Jan 2016 22:37:07 +0100</pubDate>
<category>🎥 Video</category>
<source url="https://tsecurity.de">TSECURITY.DE</source>
<content:encoded><![CDATA[<div dir="ltr" trbidi="on">Although the methods in this article can be used for proper anonymity outside of the tor browser, the main focus is creating a secure tor based research environment. As most security researchers know there's always a big decision with analyzing malware or exploits in a VM, most people would prefer to reverse in an offline environment, but if you're monitoring C&amp;C communications or a live exploit kit, this isn't viable. Do you use your real IP? Do you use 3rd party software such as &nbsp;proxifier to try and force everything through tor, hoping no software leaks your IP to the bad guys? Do you even run your entire system through a VPN while you reverse and have to reconnect all your software afterwards?<br><br>Well, the solution I came up with was to create a transparent Tor proxy using a separate VM to act as a router, the virtual machine(s) used for research will then pass all traffic through Tor (with zero configuration or software, and without even being aware the proxy exists). Although the router will take about 15 minutes to set up, you can pass unlimited VMs through Tor with no extra configuration!<br><br>Here's an example of how easy it is to connect a brand new VM through tor using my setup (no proxy settings have been touched).<br><br><div></div><br><h2>Router Installation</h2><div><b>VM Requirements:</b></div><div>Ram - At least 200 MB</div><div>Disk - At least 500 MB</div><div><br></div><div>For the router I've chosen pfSense, a light, open-source FreeBSD based firewall/router. You can download the latest version from the&nbsp;<a href="https://www.pfsense.org/download/">official site</a>. Although I will be using VMware Workstation, the tutorial should work on most VM software.</div><div><br><ol><li>Create a new VM how you normally would using the pfSense ISO (but don't power it on yet).</li><li>Go into the VM settings and set the network adapter to use whichever settings you'd normally use to connect to the internet (this is usually "NAT").&nbsp;</li><li>Click the "LAN segments..." button and add a new LAN segment.&nbsp;</li><li>Click the "Add..." button and add a new network adapter (just leave the default settings and click finish).</li><li>Set the new adapter to use the LAN segment you created, leaving the other adapter how it is.</li></ol></div><div><br></div><div><a href="http://1.bp.blogspot.com/-DT2DI_pK8Wk/VNgwuVYhpxI/AAAAAAAAA5A/yjrIGmESJVM/s1600/VMSettings.png" imageanchor="1"><img border="0" height="572" src="http://1.bp.blogspot.com/-DT2DI_pK8Wk/VNgwuVYhpxI/AAAAAAAAA5A/yjrIGmESJVM/s1600/VMSettings.png" width="640"></a></div><div><br></div><div><br></div><div>Now you can power on the VM. After a few seconds you should be met with the below screen, just press 1 and wait for the next screen.</div><div><br></div><div><a href="http://4.bp.blogspot.com/-zFPQnwW_8kg/VNgslsOz7fI/AAAAAAAAA40/qKdOB6-aw8g/s1600/BootScreen.png" imageanchor="1"><img border="0" height="337" src="http://4.bp.blogspot.com/-zFPQnwW_8kg/VNgslsOz7fI/AAAAAAAAA40/qKdOB6-aw8g/s1600/BootScreen.png" width="640"></a></div><div><br></div><div>The next screen will give you the option to invoke the installer by pressing "I", you should do this. If you don't select an option within 10 seconds, the boot will continue and you'll need to restart and try again.</div><div><br></div><div><a href="http://3.bp.blogspot.com/-LyM-e31WLqA/VNgx_2Crh4I/AAAAAAAAA5M/fzv4lu-HmSA/s1600/InstallPrompt.png" imageanchor="1"><img border="0" height="352" src="http://3.bp.blogspot.com/-LyM-e31WLqA/VNgx_2Crh4I/AAAAAAAAA5M/fzv4lu-HmSA/s1600/InstallPrompt.png" width="640"></a></div><div><br></div><div>In the installer you can just click "Accept these Settings", followed by "Quick/Easy Install" then "Ok".</div><div>The next prompt will ask you to install the kernel, select "Standard Kernel", wait for that to finish and allow the system to reboot (make sure to remove the CD before the VM starts back up to avoid any issues).</div><div><br></div><div>If everything went well, you will reach the welcome screen. At the top it should give information for the WAN and LAN adapter. WAN should be em0, which is the adapter you set to connect to the internet, whilst LAN should be em1, which is the adapter connected to the LAN segment. The IP address of the WAN adapter should correspond to an IP on the same subnet as your host computer's vmware adapter (usually "VMware Network Adapter VMnet8"). The LAN IP doesn't matter, as long as it's not on the same subnet as the WAN one.<br><br></div><div><div><a href="http://1.bp.blogspot.com/-_17ezix31Jw/VRLhAbTXrDI/AAAAAAAABAc/ml3wsAhaE8I/s1600/WelcomeScreen.png" imageanchor="1"><img border="0" height="260" src="http://1.bp.blogspot.com/-_17ezix31Jw/VRLhAbTXrDI/AAAAAAAABAc/ml3wsAhaE8I/s1600/WelcomeScreen.png" width="640"></a></div><br></div><div>By default the router's web control panel isn't accessible from the WAN for security reasons, so in order to access it you need to power up another virtual machine (preferably one you intent to connect through tor), and set the virtual network adapter to connect to the LAN segment you set up for the router.<br><br>Now you just need to open a browser and navigate to the LAN IP of your pfSense router (192.168.1.1 in my case) and you should be met with the following screen (login information is admin:pfsense).<br><br><div><a href="http://2.bp.blogspot.com/-FY8abXH6_E4/VboDjCaSifI/AAAAAAAABKY/ATHO7y4rvWc/s1600/AdminPanel.png" imageanchor="1"><img border="0" height="338" src="http://2.bp.blogspot.com/-FY8abXH6_E4/VboDjCaSifI/AAAAAAAABKY/ATHO7y4rvWc/s640/AdminPanel.png" width="640"></a></div><br></div><div>You can skip through the setup wizard, change the login information at the end then go to the main configuration page.<br><br>You'll need to go to "Services &gt; DNS Resolver" then uncheck "Enable DNS Resolver" and save settings (we'll use tor as our DNS resolver, allowing the system to also access .onion domains).<br><br><h2>Tor Installation</h2><div>You can either do this directly via the pfSense console (press 8 to drop into the shell), or you go into the configuration panel on your client VM and enable SSH by going to "System &gt; Advanced", then checking the "Enable Secure Shell" checkbox, then clicking "Ok".</div><div><br></div><div>If you choose to use the SSH option, putty will have to be used from inside the client VM (The IP is the same as the control panel IP and the login information is the same as the admin panel).</div><div><br></div><div>Once in shell &nbsp;we can install tor:</div><div><ol><li>pkg install tor</li><li>rm -rf /usr/local/etc/tor/torrc</li></ol><div>Open &nbsp;"/usr/local/etc/tor/torrc" and edit then save the following config:</div><div><blockquote>DNSPort 53<br>DNSListenAddress YOUR_PFSENSE_LAN_IP_HERE<br>VirtualAddrNetworkIPv4 10.192.0.0/11<br>AutomapHostsOnResolve 1<br>RunAsDaemon 1<br>TransPort 9040</blockquote></div><div>Now we can add tor to start at boot and run it:</div><div><ol><li>touch&nbsp;/usr/local/etc/rc.d/tor.sh</li><li>cd&nbsp;/usr/local/etc/rc.d/</li><li>echo "/usr/local/bin/tor" &gt;&gt; tor.sh &amp;&amp; chmod&nbsp;+x tor.sh</li><li>/usr/local/bin/tor</li></ol><div><br></div></div><div><h2>Firewall Setup</h2></div></div></div><div>Now we need to set up the rules to proxy through tor; unfortunately you can't forward the entire port range so it's better to just add a port forwarding rule for each of the major ports (HTTP, HTTPS, IRC, etc), then any traffic not matching the rule can be blocked.</div><div><br></div><div>First we need to go to "Firewall &gt; Nat &gt; Port Forwarding" and add a rule for each TCP port or port range we want to forward through tor (you can just add HTTP and HTTPS ports, then add more later).</div><div><br></div><div>The rule is as follows:</div><div><ul><li>Interface: LAN (Traffic from VMs)</li><li>Protocol: TCP</li><li>Source: Any (All devices on the LAN)</li><li>Destination: <b>not</b> LAN net (Ignore traffic between VMs or the VMs and pfSense router)</li><li>Destination port range: from 80 to 80 (HTTP)</li><li>Redirect Target IP: 127.0.0.1 (The pfSense router)</li><li>Redirect target port: 9040 (The transparent proxy port we set in tor config)</li><li>Description: Doesn't matter, put what you want.</li></ul><div><br></div><div>Repeat the above rule for each destination port/port range you want to pass through tor (443 for HTTPS, 22 for SSH, etc), you cannot forward the entire range (1 to 65535), but you can forward most. It should be noted that tor doesn't support UDP, so you'll either have to not forward UDP traffic or use your real IP.</div></div><div><br></div><div>Now go to "Firewall &gt; Rules &gt; LAN" and delete both the IPv4 and IPv6 rule with the description "default allow LAN IPv4/6 to Any".&nbsp;</div><div><br></div><div><a href="http://2.bp.blogspot.com/-2VPi8sjli8g/VdsxtqoLGAI/AAAAAAAABLw/UqqVgVLzeC8/s1600/DeleteRules.png" imageanchor="1"><img border="0" height="348" src="http://2.bp.blogspot.com/-2VPi8sjli8g/VdsxtqoLGAI/AAAAAAAABLw/UqqVgVLzeC8/s640/DeleteRules.png" width="640"></a></div><div><br></div><div>Deleting the following rules will block all traffic that doesn't follow the port forward rules (isn't passed through tor), this means we will need to create a rule allowing allow DNS requests to the pfSense server. In "Firewall &gt; Rules &gt; LAN" create a new rule with the following settings:</div><div><br></div><div><ul><li>Action: Pass (Allow traffic matching this rule)</li><li>Interface: LAN (Traffic from VMs)</li><li>TCP/IP: Version: IPv4</li><li>Protocol: TCP/UDP (DNS can be both)</li><li>Source: LAN net (From VMs)</li><li>Destination: (type): Single host or alias</li><li>Destination (address): The LAN ip of your pfSense router.</li><li>Destination port range: from 53 to 53</li><li>Description: Allow DNS</li></ul><div>If you want to allow traffic between VMs connected to the router, add the following rule:</div></div><div><ul><li>Action: Pass (Allow traffic matching this rule)</li><li>Interface: LAN (Traffic from VMs)</li><li>TCP/IP: Version: IPv4</li><li>Protocol: TCP/UDP&nbsp;</li><li>Source: LAN net (From VMs)</li><li>Destination:&nbsp;LAN net (To VMs)</li><li>Destination port range: from Any to Any</li><li>Description: Allow VM Communication</li></ul><div>You're all done! you should be able to check your IP using <a href="http://dnsleaktest.com/">dnsleaktest.com</a> and it should not be able to detect your DNS (the STUN exploit will also not work, even if you enable WebRTC).</div></div><div><br></div><div><br></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[User Mode Hook Scanner (Alpha)]]></title>
<description><![CDATA[I finally decided to write my first security tool based on an idea I had for advanced hook detection, I couldn't find any evidence of the method being used so I based a tool around it. It's still a working progress but I'm posting so I can get some feedback early on (Currently only x86 systems ar...]]></description>
<link>https://tsecurity.de/weiterlesen/20391/20547/user-mode-hook-scanner-alpha/</link>
<pubDate>Sun, 31 Jan 2016 22:37:07 +0100</pubDate>
<category>🎥 Video</category>
<source url="https://tsecurity.de">TSECURITY.DE</source>
<content:encoded><![CDATA[<div dir="ltr" trbidi="on">I finally decided to write my first security tool based on an idea I had for advanced hook detection, I couldn't find any evidence of the method being used so I based a tool around it. It's still a working progress but I'm posting so I can get some feedback early on (Currently only x86 systems are supported, but this shouldn't be an issue as most researchers are running 32-bit VMs).<br><br><div><a href="http://4.bp.blogspot.com/-TmmCI8sroeI/VdX9vHisc7I/AAAAAAAABLU/jScQm3IXSgE/s1600/HookScanner.png" imageanchor="1"><img border="0" height="390" src="http://4.bp.blogspot.com/-TmmCI8sroeI/VdX9vHisc7I/AAAAAAAABLU/jScQm3IXSgE/s640/HookScanner.png" width="640"></a></div><br><br><h2>Advanced Scanning</h2><div>The scanner will iterate the export table for the following system modules: ntdll.dll, kernel32.dll, kernelbase.dll, user32.dll, ws2_32.dll, and wininet.dll. Like a conventional scanner it will go through each instruction of the exported function, comparing it against a clean version of the dll which has been loaded from the disk. Normally at this point a hook scanner would either report the modification or check to see if it's a jump or call, but I've decided to take an extra step towards detecting obscure hooks.</div><div><br></div><div><b>Function Emulation</b></div><div>If any modification is found at any point within the function body, the scanner will use my basic x86 emulator to begin emulating the function, while tracing push, pop, mov, lea, jmp, call, and ret instructions. The emulator will try to determine if control flow is altered by the modified instructions and if so, which instruction redirects execution and to where.</div><div><br></div><div>The purpose of the emulator is to detect more obscure hooks as well as accurately determine the destination of the hook, beyond resolving basic jump and call instructions. A good example of where this is applicable is on hooks placed by carberp within the native call stubs of ntdll.</div><div><br></div><div>Consider this example call stub:</div><blockquote>mov eax, 0xAA<br>mov edx, 0x7FFE0300<br>call dword ptr [edx]<br>retn 0x10</blockquote>This function does not use a relative call, instead it moves a pointer into the edx register and performs an absolute indirect call with it. Carberp replaces the address moved into the edx register, resulting in redirecting the call to an arbitrary location, and not showing up in hook scanners searching for jmp/call hooks. More advanced hook scanners will log any modifications; however, the user would then have to disassemble the modified function and determine the destination address of the hook, which my engine does automatically (if it fails to resolve the location or detect a control transfer, the modification will still be logged for further investigation).<br><br><h2>Destination Dumping</h2><div>Most rootkits hook by injecting their code (usually shellcode or a PE file) into the target process, hooks are then set to point to locations within the injected code. If the tool is successfully able to work out the destination of a hook, it will query the page it points to and then map out all pages allocated with the same base address. Using this information it is possible to dump the rootkit's entire shellcode, injected PE or DLL, even if it spans multiple pages.&nbsp;</div><div><br></div><h2>Conclusion</h2><div>Again, this is a working progress and I can't guarantee the current version won't be a huge steaming pile of crap. please email any feedback/issues to admin@malwaretech.com or leave a comment on this post.</div><br>Here's a demo video to prove it does at least work on my system:<br><br> <br><br><b>Download Link:</b>&nbsp;<a href="https://www.malwaretech.net/downloads/HookScanner.rar">https://www.malwaretech.net/downloads/HookScanner.rar</a></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Windows 10 System Call Stub Changes]]></title>
<description><![CDATA[Recently I installed Windows 10 RTM and while I was digging around I happened to notice some changes to the user mode portion of the system call stub: these changes appear to break the current methods of user mode system call hooking on x86 and WOW64 (Recap: here).Windows 10 x86Native functions n...]]></description>
<link>https://tsecurity.de/weiterlesen/20392/20548/windows-10-system-call-stub-changes/</link>
<pubDate>Sun, 31 Jan 2016 22:37:07 +0100</pubDate>
<category>🎥 Video</category>
<source url="https://tsecurity.de">TSECURITY.DE</source>
<content:encoded><![CDATA[<div dir="ltr" trbidi="on">Recently I installed Windows 10 RTM and while I was digging around I happened to notice some changes to the user mode portion of the system call stub: these changes appear to break the current methods of user mode system call hooking on x86 and WOW64 (Recap:&nbsp;<a href="http://www.malwaretech.com/2014/06/usermode-system-call-hooking-betabot.html">here</a>).<br><br><h2>Windows 10 x86</h2>Native functions no longer make a call to ntdll!KiFastSystemCall&nbsp;via the pointer at SharedUserData!SystemCallStub (0x7FFE0300), in fact SharedUserData!SystemCallStub don't seem to point to anything anymore (This change was originally made in Windows 8, but like most people I'd rather just pretend that OS doesn't exist).<br><br>Now the system call stub is inline with one below each native function (I'm not really sure of the reason for the change but it is now impossible to hook all system calls with a single modification).<br><table align="center" cellpadding="0" cellspacing="0"><tbody><tr><td><a href="http://4.bp.blogspot.com/-sOjJd0yNsEk/Va_0UmiRhUI/AAAAAAAABJA/MeSAx5c238k/s1600/Windows10%2Bx86.png" imageanchor="1"><img border="0" src="http://4.bp.blogspot.com/-sOjJd0yNsEk/Va_0UmiRhUI/AAAAAAAABJA/MeSAx5c238k/s1600/Windows10%2Bx86.png"></a></td></tr><tr><td>Windows 10 x86</td></tr></tbody></table><h2></h2><h2>Windows 10 x64 (WOW64)</h2>Native function no longer call FS:[0xC0], instead they call a pointer in the same way x86 used to call KiFastSystemCall.<br><table align="center" cellpadding="0" cellspacing="0"><tbody><tr><td><a href="http://4.bp.blogspot.com/-7ZRgMSjrsVw/Va_1eOirqZI/AAAAAAAABJI/mAJkgUCB-8o/s1600/Windows10%2BWOW64.png" imageanchor="1"><img border="0" src="http://4.bp.blogspot.com/-7ZRgMSjrsVw/Va_1eOirqZI/AAAAAAAABJI/mAJkgUCB-8o/s1600/Windows10%2BWOW64.png"></a></td></tr><tr><td>Windows 10 x64 (WOW64)</td></tr></tbody></table><br>Wow64SystemServiceCall is not a fixed address like SharedUserData!SystemCallStub, instead it's the absolute address of a function within the wow64 ntdll.dll.<br><div></div><div></div><table align="center" cellpadding="0" cellspacing="0"><tbody><tr><td><a href="http://1.bp.blogspot.com/-dSlQxBhtyTA/Va_4KbX_EqI/AAAAAAAABJc/Vm01sx_cBsE/s1600/Wow64SystemServiceCall.png" imageanchor="1"><img border="0" height="238" src="http://1.bp.blogspot.com/-dSlQxBhtyTA/Va_4KbX_EqI/AAAAAAAABJc/Vm01sx_cBsE/s640/Wow64SystemServiceCall.png" width="640"></a></td></tr><tr><td>ntdll!Wow64SystemServiceCall</td></tr></tbody></table><br>The code simply checks a flag in the PEB to decide if to use int 2Eh or normal system call, then as before it calls wow64cpu!CpupReturnFromSystemCallStub; however, this is now done by a pointer in the table pointed to by R15, instead of directly.<br><br>FS:[0xC0] is still usable for compatibility reasons, by it doesn't point to Wow64SystemServiceCall, nor does it point to the old code, instead it points to some more complicated version (wow64cpu!KiFastSystemCall) which does the same thing.<br><table align="center" cellpadding="0" cellspacing="0"><tbody><tr><td><a href="http://3.bp.blogspot.com/-5tjwafWX_s8/Va_6YVfwiYI/AAAAAAAABJw/fNcGdl-BC6s/s1600/X86SwitchTo64BitMode.png" imageanchor="1"><img border="0" src="http://3.bp.blogspot.com/-5tjwafWX_s8/Va_6YVfwiYI/AAAAAAAABJw/fNcGdl-BC6s/s1600/X86SwitchTo64BitMode.png"></a></td></tr><tr><td>x86SwitchTo64BitMode (Pointed to by FS:[0xC0] on pre-Windows 10 systems)</td></tr></tbody></table><br>As you can see the original method was just executing a single instruction which did a far jump to wow64cpu!CpupReturnFromSimulatedCode; The new method does exactly the same thing but with more instructions.<br><table align="center" cellpadding="0" cellspacing="0"><tbody><tr><td><a href="http://4.bp.blogspot.com/-NYQ1jvYxnos/Va_5m6ZseiI/AAAAAAAABJo/-cln54w89eU/s1600/KiFastSystemCall.png" imageanchor="1"><img border="0" src="http://4.bp.blogspot.com/-NYQ1jvYxnos/Va_5m6ZseiI/AAAAAAAABJo/-cln54w89eU/s1600/KiFastSystemCall.png"></a></td></tr><tr><td>wow64cpu!KiFastSystemCall (Pointed to by FS:[0xC0] on Windows 10 x64)</td></tr></tbody></table><br>It's hard to gauge exactly why the old code was replaces, but it may have something to do with the fact there is no longer any pointers to wow64cpu!CpupReturnFromSimulatedCode which can be accessed from 32-bit code, now the only way is to switch into 64-bit mode and retrieve the pointer from r15+0xF8.<br><br></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[David Cameron Wants Porn Sites to Require Banking Information]]></title>
<description><![CDATA[It would seem that David Cameron doesn't have a tech advisory or even knows anyone who uses browser other than Netscape, but that doesn't seem stop him with his endless stream of proposals and laws to govern our internet. The latest idea in a long list of terrible ideas is arguable worse than his...]]></description>
<link>https://tsecurity.de/weiterlesen/20393/20549/david-cameron-wants-porn-sites-to-require-banking-information/</link>
<pubDate>Sun, 31 Jan 2016 22:37:07 +0100</pubDate>
<category>🎥 Video</category>
<source url="https://tsecurity.de">TSECURITY.DE</source>
<content:encoded><![CDATA[<div dir="ltr" trbidi="on">It would seem that David Cameron doesn't have a tech advisory or even knows anyone who uses browser other than Netscape, but that doesn't seem stop him with his endless stream of proposals and laws to govern our internet. The latest idea in a long list of terrible ideas is arguable worse than his vaguely implied ban on cryptography, it also stems from an ongoing campaign by the DailyMail (Which is the British equivalent of fox news).<br><a href="http://3.bp.blogspot.com/-LSMAwSmwyVI/Vb359bMyIZI/AAAAAAAABK4/sw9Qu81Yk7w/s1600/cards.png" imageanchor="1"><img border="0" height="0" src="http://3.bp.blogspot.com/-LSMAwSmwyVI/Vb359bMyIZI/AAAAAAAABK4/sw9Qu81Yk7w/s320/cards.png" width="0"></a><br><h2>Backstory</h2><div>Most people are familiar with the whole "violent video games make children violent" nonsense, here we've had a similar thing going for a while, but with internet porn. A couple of years ago the DailyMail decided that porn corrupts children and therefore it shouldn't be a parent's duty to install internet filters, instead they proposed that government should force ISPs to implement network level content filters which are enabled by default.</div><div><br></div><div>Well, unfortunately not only does David Cameron pay attention to the DailyMail, but he thought their suggestion was a brilliant idea, promptly releasing a statement making it clear that he wanted all ISPs to have the filters in place by the end of 2013. As of now, it's not yet been made law; however, the system has already been implemented by all major ISPs, requiring new customers to specify if they want to opt-out of the filter. Unsurprisingly parents are quite happy parenting their own children, seeing as the top three ISPs reporting that only between 4 and 8 percent of new customers opted-in to the filter (any guesses as to how many of them were technologically inept?).</div><div><br></div><h2>Latest Proposal</h2><div>It's now been decided that adult sites aren't doing enough to prevent those under the age of 18 from using their services, with Cameron outlining plans to require that sites properly enforce age verification or face being added to the ever growing list of websites blocked in the UK. The current suggestion is that adult sites should use credit card or bank details for age verification (the same way that most e-commerce sites currently do). Is this a good idea? Short answer: no, long answer: oh my god no.</div><div><br></div><div><b>Privacy Issues</b></div><div>When it comes to free porn, there is really no way to track visitors across sessions, at least not in the UK. Cookie and local storage data gets cleared after each private browsing session and almost all UK ISPs issue dynamic IP addresses, making IP tracking useless.&nbsp;</div><div><br></div><div>If website uses were required to link personal information with their accounts, suddenly not only is everyone traceable across browsing sessions, but their browsing habits are tied to their real name. A lot of people have a problem with large companies gathering basic personal information for advertising purposes, so I'm sure it will be had to find anyone who doesn't have a problem with their porn history, name, and billing address being collected (probably a recipe for a very embarrassing call with your bank's fraud resolution department).&nbsp;</div><div><br></div><div><b>Security</b></div><div>This is where the idea becomes really, really terrible. Most of the smaller free porn sites don't bring in a great deal of revenue, thus are unlikely to be employing security professional. When big multinational companies are getting breached left and right, does anyone really need small time porn sites hording financial information? Nothing compliments you banking information being stolen quite like your name, address and browsing habits appearing in the latest data dump.</div><div><br></div><div>Now of course, the above issues assumes the website was even legitimate in the first place. What's to stop the same people running malware infested porn sites from re-purposing them to harvest bank details? Most people browsing porn aren't exactly thinking with their head (well, at least not that one.), so even those wary of fraud are more likely to find themselves plugging their financial information into a shady site.</div><div><br></div><h2>Conclusion</h2><div>There is absolutely no way this idea works in any form, at best they find some kind of age verification method which doesn't involve sharing your financial information, in which case porn passes join the never ending list of vices for sale on the playground black market. Not to mention that just like with the UK's piracy filter and the EU right to be forgotten, it 's simply solved by setting up a VPN to access sites with an IP origination from another country. As always, parenting and politics should remain separate.&nbsp;</div><div><br></div><div><a href="http://1.bp.blogspot.com/-v38DzILjaMY/Vb33vaQJf4I/AAAAAAAABKs/bu_XqSpsATU/s1600/StateParenting.png" imageanchor="1"><img border="0" src="http://1.bp.blogspot.com/-v38DzILjaMY/Vb33vaQJf4I/AAAAAAAABKs/bu_XqSpsATU/s1600/StateParenting.png"></a></div><div><br></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Darkode Returns Following International Raids]]></title>
<description><![CDATA[When I was contacted asking for a comment about the darkode raid, I'd said that the main administrator was not arrested and that'd I'd be surprised if it wasn't back within a week; well It's been a little more than a week (I'll put on my surprised face), but as expected darkode has returned. Orig...]]></description>
<link>https://tsecurity.de/weiterlesen/20394/20550/darkode-returns-following-international-raids/</link>
<pubDate>Sun, 31 Jan 2016 22:37:07 +0100</pubDate>
<category>🎥 Video</category>
<source url="https://tsecurity.de">TSECURITY.DE</source>
<content:encoded><![CDATA[<div dir="ltr" trbidi="on">When I was contacted asking for a comment about the darkode raid, I'd said that the main administrator was not arrested and that'd I'd be surprised if it wasn't back within a week; well It's been a little more than a week (I'll put on my surprised face), but as expected darkode has returned. Originally the main admin known as "Sp3cial1st" had posted a statement on pastebin declaring that he wanted to wait and see who all of the 70 users arrested were before bringing the forums back online, but about two hours ago he updated his jabber status to advertise <a href="http://darkode.cc/">darkode.cc</a>, which appears to be a placeholder for the future site.<br><br><table align="center" cellpadding="0" cellspacing="0"><tbody><tr><td><a href="http://2.bp.blogspot.com/-xnH42Nt91S0/VbXPRxrCRII/AAAAAAAABKE/XBVzafd1f6E/s1600/darkode.png" imageanchor="1"><img border="0" height="390" src="http://2.bp.blogspot.com/-xnH42Nt91S0/VbXPRxrCRII/AAAAAAAABKE/XBVzafd1f6E/s640/darkode.png" width="640"></a></td></tr><tr><td>Darkode's new homepage</td></tr></tbody></table>Currently we're greeted with a message addressing the raids and containing some information about the new site; however, the page currently leads nowhere and the "Generate Onion" button doesn't work (though the information given is quite interesting).<br><br>The message states that not only will darkode now operate from a Tor hidden service, but each user will be given their own onion address to the forum, which is admittedly quite a clever idea. Firstly it would allow the darkode admins greater control over who gets access, preventing people from accessing a hacked account without the owner's onion url; it would also allow them to better monitor who views what by creating an individual log file for each onion, meaning they could quickly weed out leakers.<br>Even more interesting it states that bitcoin wallets would be tied to accounts and used for users to authenticate on the forums, this would mean that hackers could not use a hacked account to scam with unless they know the user's private key.<br><br>These new security measured don't come as a huge surprise seeming as darkode had a massive problem with people using hacked accounts to leak information to law enforcement and journalists as well as scam users. Ironically even the darkode administrators were compromised at one point after one of them had reused his password on another forum, which had its database leaked a few weeks prior. Remember: Password reuse is a much bigger risk than weak passwords.<br><br><h2>Arrests</h2><div>Due to the fact that most countries do not publicly publish detailed arrest information like the US does, there is no way to know who else was arrested other than those indicted by the FBI; however, due to terrible opsec practices a lot of them were known personally by other members, so word of mouth gives us a few more names to add to the list. It's interesting to note that only about two of the arrested member had even been active on darkode in the past few years, suggesting that the FBI might have just grouped together a list of known criminals who were also on darkode, rather than targeting the forum itself.</div><div><br></div><div>As of now, this is the current list of arrested or allegedly arrested users:</div><div><ul><li>h0tsh0t</li><li><a href="http://www.justice.gov/opa/file/630821/download">Mafi AKA Crim AKA Synthet!c</a><b> </b>(Darkode admin)</li><li>Parabola (Darkode admin)</li><li><a href="http://www.justice.gov/opa/file/630661/download">Nocen</a></li><li>Phastman</li><li>semaph0re</li><li>m3t4lh34d</li><li>rzor</li><li>k@exploit.im</li><li>Android (Developer of the Dendroid trojan)</li><li>SpliT</li><li>WesTThug</li></ul></div><div><br></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[RIG Exploit Kit - Source Code Leak]]></title>
<description><![CDATA[As the past has show us, cybercriminals are not the most trustworthy people when it come to holding valuable sources, and it looks like we're about to get another reminder of that, this time with an exploit pack leak.RIG is a popular exploit kit which has been around for about a year and sold on ...]]></description>
<link>https://tsecurity.de/weiterlesen/20395/20551/rig-exploit-kit-source-code-leak/</link>
<pubDate>Sun, 31 Jan 2016 22:37:07 +0100</pubDate>
<category>🎥 Video</category>
<source url="https://tsecurity.de">TSECURITY.DE</source>
<content:encoded><![CDATA[<div dir="ltr" trbidi="on"><div></div><br>As the past has show us, cybercriminals are not the most trustworthy people when it come to holding valuable sources, and it looks like we're about to get another reminder of that, this time with an exploit pack leak.<br><br>RIG is a popular exploit kit which has been around for about a year and sold on various "underground" forums. On February 3rd 2015 a user claiming to be the "Official HF Sales Rep" posted a sales thread on hackforums (HF), which is unusual as most serious sellers avoid this forum completely. It's likely the decision to allow resellers on this specific board was due to a large amount of users trying to rent out access to their RIG accounts, resulting in lost income for the seller.<br><br><table align="center" cellpadding="0" cellspacing="0"><tbody><tr><td><a href="http://1.bp.blogspot.com/-dC1Lwjc6UCw/VNwOZ_j9S5I/AAAAAAAAA5c/04in_6PriKE/s1600/hfthread.png" imageanchor="1"><img border="0" height="446" src="http://1.bp.blogspot.com/-dC1Lwjc6UCw/VNwOZ_j9S5I/AAAAAAAAA5c/04in_6PriKE/s1600/hfthread.png" width="640"></a></td></tr><tr><td>Hackforums RIG sales thread</td></tr></tbody></table><br>Although the HF reseller first claimed to be a verified seller, the claims soon escalated into being "more than just a seller", and before long he was registering on private forums claiming to be one of the developers.<br><br><table align="center" cellpadding="0" cellspacing="0"><tbody><tr><td><a href="http://2.bp.blogspot.com/-7jKAAm-X6wE/VNwSOhbvZ0I/AAAAAAAAA5o/vG4Pmk40zRU/s1600/post1.png" imageanchor="1"><img border="0" height="95" src="http://2.bp.blogspot.com/-7jKAAm-X6wE/VNwSOhbvZ0I/AAAAAAAAA5o/vG4Pmk40zRU/s1600/post1.png" width="640"></a></td></tr><tr><td>Sellers with benefits</td></tr></tbody></table><table align="center" cellpadding="0" cellspacing="0"><tbody><tr><td><a href="http://3.bp.blogspot.com/-3-nIClgibkM/VNwTZZ7ZnBI/AAAAAAAAA50/exHXWrv3wIE/s1600/privintro.png" imageanchor="1"><img border="0" height="248" src="http://3.bp.blogspot.com/-3-nIClgibkM/VNwTZZ7ZnBI/AAAAAAAAA50/exHXWrv3wIE/s1600/privintro.png" width="640"></a></td></tr><tr><td>Private forum introduction</td></tr></tbody></table><br>His introduction into the private forum didn't go too well: First members pointed out that his RIG prices were nearly 40% higher than the official sellers (typical of a re-seller not a developer), then they made fun of him when someone posted screenshots of his website, which was requesting a $3000 payment to gain access to his never-heard-of private forum. Eventually the entire thread turned into people making fun of him, before the administrator banned his account.<br><br>It seems like the RIG owner was less than pleased with the reseller's antics because the next day, in a conversation with another member, the owner declared that he had suspended the reseller for attempting to scam customers, which isn't surprising given he was requesting that people pay him $3000 for access to an imaginary private forum.<br><br><table align="center" cellpadding="0" cellspacing="0"><tbody><tr><td><a href="http://1.bp.blogspot.com/-8TQCFx96PTE/VNwYrWAYj0I/AAAAAAAAA6E/9EMSPPlkTAs/s1600/jabber.png" imageanchor="1"><img border="0" src="http://1.bp.blogspot.com/-8TQCFx96PTE/VNwYrWAYj0I/AAAAAAAAA6E/9EMSPPlkTAs/s1600/jabber.png"></a></td></tr><tr><td>Conversation between a HF member and RIG owner</td></tr></tbody></table><br><br>Shortly after, the reseller does what any cybercriminal does when his enterprise begins crumbling around him: He signs up for twitter and becomes a security researcher???<br><br><table align="center" cellpadding="0" cellspacing="0"><tbody><tr><td><a href="http://2.bp.blogspot.com/-h0pNmDdopmw/VNwaGg7GlgI/AAAAAAAAA6Q/1cOK2z6ObmA/s1600/allofmywat.png" imageanchor="1"><img border="0" height="186" src="http://2.bp.blogspot.com/-h0pNmDdopmw/VNwaGg7GlgI/AAAAAAAAA6Q/1cOK2z6ObmA/s1600/allofmywat.png" width="640"></a></td></tr><tr><td>I don't even....</td></tr></tbody></table><br>The twitter account, which is a pun on MalwareMustDie, claims to be in possession of the RIG source code as well as a recent database dump, and is currently tweeting a download link at various security researchers (not me though, apparently I'm not good enough). The file, which is password protected, was deleted from the filehost after less than 24 downloads, so I am not able to confirm if this is legit or just another scriptkiddie tantrum.<br><br><table align="center" cellpadding="0" cellspacing="0"><tbody><tr><td><a href="http://4.bp.blogspot.com/-sSdnLgMGkY0/VNweIjBdjmI/AAAAAAAAA6c/gG8-6ipyXGg/s1600/files.png" imageanchor="1"><img border="0" height="482" src="http://4.bp.blogspot.com/-sSdnLgMGkY0/VNweIjBdjmI/AAAAAAAAA6c/gG8-6ipyXGg/s1600/files.png" width="640"></a></td></tr><tr><td>A screenshot allegedly showing panel files and sql database dump</td></tr></tbody></table><br><table align="center" cellpadding="0" cellspacing="0"><tbody><tr><td><a href="http://4.bp.blogspot.com/-Q6-3dzp4DPI/VNwf8Zix2qI/AAAAAAAAA6o/0x9Ik8hkbiE/s1600/jabber1.png" imageanchor="1"><img border="0" src="http://4.bp.blogspot.com/-Q6-3dzp4DPI/VNwf8Zix2qI/AAAAAAAAA6o/0x9Ik8hkbiE/s1600/jabber1.png"></a></td></tr><tr><td>RIG owner confirms he may have database and older version of exploit kit.</td></tr></tbody></table><br>I'll post updates when I have more info.<br><br><h2>Updated 02/12/2015 09:00 (UTC)</h2><div>I've confirmed with 3 people that the leak is in fact legitimate, and a fairly recent version of the pack.<br><br><a href="https://twitter.com/kafeine">@kafeine</a>&nbsp;has mentioned that he thinks someone with access to the RIG panel may be stealing traffic. He reports that occasionally the exploit payload appears to be replaced with another (usually cryptowall); which coincides with a lot of claims made by customers who bought RIG through the reseller.</div><table align="center" cellpadding="0" cellspacing="0"><tbody><tr><td><a href="http://1.bp.blogspot.com/-eBJJVuCiStY/VNxqIm6gt0I/AAAAAAAAA64/ez2kYD8a40Y/s1600/payloads.png" imageanchor="1"><img border="0" height="234" src="http://1.bp.blogspot.com/-eBJJVuCiStY/VNxqIm6gt0I/AAAAAAAAA64/ez2kYD8a40Y/s1600/payloads.png" width="640"></a></td></tr><tr><td>a RIG thread pushing 2 different payloads</td></tr></tbody></table><div><br></div><div>Due to the way in which the RIG exploit pack works (the exploiting is done by a back-end server, so no exploits are contained within the leak), I have decided to upload it <a href="https://mega.co.nz/#!fNpj3Qbb!UFn2ChNMMLvSZvEAQz3NJSDPYGVVngd3KhHhwXp7wKY">here</a> (thanks to&nbsp;<a href="https://twitter.com/kafeine">@kafeine</a>&nbsp;for files and information).</div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[MalwareTech SBK - A Bootkit Capable of Surviving Reformat]]></title>
<description><![CDATA[Since i got into firmware hacking, I've been working on a little project behind the scenes: A hard disk firmware based rootkit which allows malware to survive an operating system re-install or full disk format. Unfortunately I can't post a proof of concept for many reasons (people have even conta...]]></description>
<link>https://tsecurity.de/weiterlesen/20396/20552/malwaretech-sbk-a-bootkit-capable-of-surviving-reformat/</link>
<pubDate>Sun, 31 Jan 2016 22:37:07 +0100</pubDate>
<category>🎥 Video</category>
<source url="https://tsecurity.de">TSECURITY.DE</source>
<content:encoded><![CDATA[<div dir="ltr" trbidi="on">Since i got into firmware hacking, I've been working on a little project behind the scenes: A hard disk firmware based rootkit which allows malware to survive an operating system re-install or full disk format. Unfortunately I can't post a proof of concept for many reasons (people have even contacted me just to tell me not to post it), so instead I've written a presentation overviewing and explaining the rootkit, which I've dubbed MT-SBK.<br><div><br></div><div>The general purpose of MT-SBK is to provide a "framework" for my previous project, <a href="http://www.malwaretech.com/2014/04/coding-malware-for-fun-and-not-for.html">TinyXPB</a>, A windows XP bootkit. This framework enables TinyXPB to be stored and loaded from within the hard disk firmware, preventing it from being removed by: antiviruses, operating system re-installs, or even full disk reformats. This rootkit is designed for a major brand of hard disk and can infect the firmware from within the operating system (no physical access required), it's also completely undetectable to software running on the host computer.&nbsp;</div><div><br></div><div>The only way to remove MT-SBK is by replacing that hard disk's PCB or connecting an SPI programmer directly to the flash chip and flashing it with the original firmware.&nbsp;</div><div><br></div><div><a href="http://malwaretech.net/MTSBK.pdf">MalwareTech SBK Overview - PDF</a></div><div><a href="https://www.youtube.com/watch?v=0gc-VF6bi3g">Sector Spoofing Example - Youtube</a><br><br><div><a href="http://3.bp.blogspot.com/-wPGeEnFDIdY/VWyAMCHj5rI/AAAAAAAABII/_GOJSC5cqe0/s1600/ss%252B%25282015-04-29%252Bat%252B05.15.59%2529.png" imageanchor="1"><img border="0" height="282" src="http://3.bp.blogspot.com/-wPGeEnFDIdY/VWyAMCHj5rI/AAAAAAAABII/_GOJSC5cqe0/s320/ss%252B%25282015-04-29%252Bat%252B05.15.59%2529.png" width="320"></a></div><br></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Hard Disk Firmware Hacking (Final)]]></title>
<description><![CDATA[Core 2, I choose you.Less than 5 minutes after posting the last article, i discovered the final piece of my puzzle: a second CPU core. I was looking through my OpenOCD configuration when I realized it had a single tap definition hardcoded, so i decided to comment it out and let OpenOCD try to aut...]]></description>
<link>https://tsecurity.de/weiterlesen/20397/20553/hard-disk-firmware-hacking-final/</link>
<pubDate>Sun, 31 Jan 2016 22:37:07 +0100</pubDate>
<category>🎥 Video</category>
<source url="https://tsecurity.de">TSECURITY.DE</source>
<content:encoded><![CDATA[<div dir="ltr" trbidi="on"><h2>Core 2, I choose you.</h2><div>Less than 5 minutes after posting the last article, i discovered the final piece of my puzzle: a second CPU core. I was looking through my OpenOCD configuration when I realized it had a single tap definition hardcoded, so i decided to comment it out and let OpenOCD try to automatically discover the taps.&nbsp;</div><div><br></div><div><a href="http://1.bp.blogspot.com/-KqXM-uyoijU/VVYPnMPzkRI/AAAAAAAABGc/Lcok5MfTx-g/s1600/AutoTAP.png" imageanchor="1"><img border="0" height="384" src="http://1.bp.blogspot.com/-KqXM-uyoijU/VVYPnMPzkRI/AAAAAAAABGc/Lcok5MfTx-g/s640/AutoTAP.png" width="640"></a></div><div><br></div><div>Auto probing found two TAPs with the same id, which I assumed to be two different cores, so I updated my config accordingly.&nbsp;</div><div>Here's a new config designed to work with both cores:</div><div><blockquote>transport select jtag<br>adapter_khz 100<br><br>jtag newtap auto0 tap -irlen 4 -expected-id 0x121003d3<br>jtag newtap auto1 tap -irlen 4 -expected-id 0x121003d3<br><br>target create auto0.tap feroceon -endian little -chain-position auto0.tap<br>target create auto1.tap feroceon -endian little -chain-position auto1.tap<br><br>reset_config srst_only<br>adapter_nsrst_delay 200<br>jtag_ntrst_delay 200</blockquote></div><div>After a few small adjustments, all that was left to do was run OpenOCD and see what secrets the new core holds.</div><div><br></div><div><a href="http://1.bp.blogspot.com/-GDbooLOU5Mc/VVn4vmDYzjI/AAAAAAAABGw/5O8ba-hOxSw/s1600/KernelBreakpoint.png" imageanchor="1"><img border="0" height="300" src="http://1.bp.blogspot.com/-GDbooLOU5Mc/VVn4vmDYzjI/AAAAAAAABGw/5O8ba-hOxSw/s640/KernelBreakpoint.png" width="640"></a></div><div><br></div><div>Once I'd connected to the JTAG via IDA, everything was clear. I could see that the second core was stopped on the breakpoint I'd written to the flash chip. This was the core responsible for loading and executing the bootloader, whilst the core I had been looking at before just waits in a loop. Obviously the bootstrap code must be different for core 2, because the other bootstrap just loops until a later time.&nbsp;</div><div><br></div><div><br></div><table align="center" cellpadding="0" cellspacing="0"><tbody><tr><td><a href="http://1.bp.blogspot.com/-gamTWQmYXEc/VVn_gQ8oPMI/AAAAAAAABHA/HbXdTsp21aU/s1600/Bootstrap2.png" imageanchor="1"><img border="0" height="640" src="http://1.bp.blogspot.com/-gamTWQmYXEc/VVn_gQ8oPMI/AAAAAAAABHA/HbXdTsp21aU/s640/Bootstrap2.png" width="518"></a></td></tr><tr><td><br></td></tr></tbody></table><div>It's clear that core 1's bootstrap is just debugging / management code, whilst core 2 has a completely separate region of code mapped to the same address. Core 2 not only loads the bootloader from the flash, but also appears responsible for most of the interesting operations such as handling SATA requests and writing the cache descriptor.</div><div><br></div><h2>Conclusion</h2><div>So there you have it, using very little experience I was able to JTAG a WD hard disk, dump the firmware, and even discover how to read / write the flash chip using ICP. I'm definitely going to spend some more time poking about in the firmware to see how parts of it work, but because that's outside the scope of these articles, and to avoid boring people, this will be the last article of the series. If I manage anything interesting, I will likely post my findings in a whitepaper and upload it alongside a demo video.&nbsp;</div><div><br></div><div>I'd like to continue posting both hardware and software articles (and some tutorial), so if you have any suggestions for either, send them to admin@malwaretech.com.&nbsp;</div><div><br></div><div>Hope you've enjoyed a slightly different style of writing and learned something new.</div><div><br></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Hard Disk Firmware Hacking (Part 5)]]></title>
<description><![CDATA["Discovery requires experimentation"This weekend I made a pretty big breakthrough which lead to me making a few smaller breakthroughs and ultimately negating most of my previous research. I've also learned that "not reinventing the wheel" isn't always the best option, especially when it comes to ...]]></description>
<link>https://tsecurity.de/weiterlesen/20398/20554/hard-disk-firmware-hacking-part-5/</link>
<pubDate>Sun, 31 Jan 2016 22:37:07 +0100</pubDate>
<category>🎥 Video</category>
<source url="https://tsecurity.de">TSECURITY.DE</source>
<content:encoded><![CDATA[<div dir="ltr" trbidi="on"><div></div><h2>"Discovery requires experimentation"</h2><div>This weekend I made a pretty big breakthrough which lead to me making a few smaller breakthroughs and ultimately negating most of my previous research. I've also learned that "not reinventing the wheel" isn't always the best option, especially when it comes to trusting other people's research.&nbsp;</div><div><br></div><div>One of the main goals was to find a way to quickly and easily reprogram the hard disk, given physical access. In the&nbsp;<a href="https://spritesmods.com/?art=hddhack&amp;page=5">spritesmods</a>&nbsp;post he had remove the flash chip from the PCB and attached it to some veroboard, so he could swap it between the hard disk and the flash programmer. Obviously it's not very practical for me to have to keep disconnecting and reconnecting the flash chip, and especially impractical for an adversary looking to quickly infect a disk.&nbsp;</div><div><br></div><div>As most already know, it is possible to flash WD hard disk firmware from within the OS as long as the account has Admin/Root privileges. The disk must be running in order to accept SATA commands and must be restarted to load the new firmware. If the new firmware has errors the disk cannot start, therefore the firmware cannot be fixed (this is known as bricking). Due to the fact I'm hacking about with the firmware I'm likely to brick the device, so i needed another way of flashing it.</div><div><br></div><h2>In-Circuit Programming</h2><div>In circuit Programming (ICP) is the ability to program a flash chip or other component, while it's still connected to the circuit. In the last article I was able to find the test ports that connected to the flash chip, but was unable to program it, however; after some experimentation over the weekend I finally managed to achieve ICP.&nbsp;</div><div><br></div><div><b>The Problem</b></div><div>One of the biggest problems with ICP is that in order to write the flash chip you need to power it, but because it's connected to the rest of the circuit you end up powering other chips, which send data on various buses and interfere with your attempts to talk to the flash.</div><div><br></div><div>To prevent interference on the SPI bus, it's usually enough to hold down the reset button or short the reset signal to ground, resulting in the system being held in reset and unable to start (giving you uninterrupted access to the flash's bus).&nbsp;</div><div><br></div><div>Here's a list of what I'd tried.&nbsp;</div><div><ul><li>Powering the flash directly with 3.3v supply</li><li>Powering the flash directly with 3.3v supply while holding the system in reset</li><li>Powering the entire system by plugging in the HD</li><li>Powering the entire system by plugging in the HD while holding the system in reset</li></ul></div><div>I was ready to give up as nothing was clearly working (my SPI programmer couldn't so much as detect the flash chip), but on Saturday I decided to have one last go, and it worked straight away (sort of).&nbsp;</div><div><br></div><div><a href="http://4.bp.blogspot.com/-CwG7cjSp_xs/VVHX3ppQ8II/AAAAAAAABF4/D6-HkjFg2mw/s1600/flashrom.png" imageanchor="1"><img border="0" height="340" src="http://4.bp.blogspot.com/-CwG7cjSp_xs/VVHX3ppQ8II/AAAAAAAABF4/D6-HkjFg2mw/s640/flashrom.png" width="640"></a></div><div><br></div><div>The SPI programmer was able to detect the flash chip, but most of the data being read was erroneous. On investigation I found that the VCC (power) wire had come unstuck from the test point and was now hanging off the desk. So if the VCC wire wasn't connected and the system wasn't plugged in, how was it reading the flash chip?</div><div><br></div><div>After more experimentation I found that the circuit was set up in such a way that some of the voltage being sent to the MISO pin (about 1.2v of it) was somehow feeding back onto the VCC rail and powering the chip....wat. As I've said I'm not an electronics expert, and this had me completely baffled, but it also showed me that reading the chip in circuit was possible, i just needed to learn its secrets.&nbsp;</div><div><br></div><div><b>The Solution</b></div><div>After extensively more experimentation with a side order of experimentation and failure, I found that holding the system in reset (the solution to most ICP problems) was actually the only issue. I had been leaving the JTAG connected to the system and it was pulling the reset pin low (holding it in reset), so when I wasn't holding the system in reset the JTAG was. After disconnecting the SRST (reset) pin of the JTAG, everything worked perfectly as long as the disk wasn't plugged in and I powered the flash chip directly. It seems that this system is designed for ICP to be done without holding it in reset and doing so causes issues.</div><div><br></div><div></div><div>Here is the updated image from the last article.</div><div><br></div><div><a href="http://3.bp.blogspot.com/-Wd8fhDBYNxA/VVHTfkbxxeI/AAAAAAAABFo/-uNjbNSQ4W8/s1600/ICP.png" imageanchor="1"><img border="0" height="622" src="http://3.bp.blogspot.com/-Wd8fhDBYNxA/VVHTfkbxxeI/AAAAAAAABFo/-uNjbNSQ4W8/s640/ICP.png" width="640"></a></div><div><br></div><div>If you have a USB device which allows for SPI programming and is supported by "flashrom", like I do. You can connect it to the computer and use flashrom to read, write, and erase the flash. The TUMPA is an especially nice board because it has 2 channels, so you don't have to disconnect the JTAG to use SPI.</div><h2></h2><h2>Don't reinvent the wheel they said, It's a waste of time they said</h2><div>Before i started hacking I'd decided to read other people's research to get a good idea of where to start. Resourceful, right? Well it actually turns out that most of the research I've based mine on was either wrong or just doesn't apply to this hard disk.&nbsp;</div><div><br></div><div>I was under the impression that when connecting the JTAG and issuing a "reset halt" command, the system would be halted before any code was run, and I could step through the bootstrap while it read the bootloader from flash and execute it, this wasn't the case.</div><div><br></div><div>After playing around by writing my own code to the flash, i realized that it's is being read into memory and executed long before the system is halted. In fact it seems like the code at 0xFFFF0000 is just some kind of debug console which is only jumped to if a halt command is issued, or the reading / executing the code from flash fails. By the time the JTAG is able to connect and issue a command, the entire kernel has already been loaded and initialized, which explains why I couldn't set any breakpoints on the bootloader.</div><div><br></div><div>I can write a breakpoint to the flash so that an exception is generated and the system fails to load, then remove the breakpoint and manually jump back to the bootloader, but for whatever reason the system doesn't boot properly the second time. This isn't a huge issue because I can still debug the bootloader up until the a certain point (as long as any code I write is run during early boot, I can debug that too), but until I can find why it fails the second time, there is a window of time between the late boot stage and early kernel initialization where I can't debug.&nbsp;</div><div><br></div><h2>Success</h2><div><a href="http://1.bp.blogspot.com/-6S4YPz4Jllc/VVHowXsgdYI/AAAAAAAABGI/PImx2nl6NZo/s1600/CodeInjection.png" imageanchor="1"><img border="0" height="242" src="http://1.bp.blogspot.com/-6S4YPz4Jllc/VVHowXsgdYI/AAAAAAAABGI/PImx2nl6NZo/s640/CodeInjection.png" width="640"></a></div><div><br></div><div>My main goal was to inject code into the firmware both by running an executable on the target computer and with physical access to the hard drive, which I've achieved. Now I'll just poke around and see what I can do with it.</div><div><br></div><div>If you're wondering how easy it would be for an attacker to infect a hard drive's firmware, here are two quick ways they could to do it.</div><div><ol><li>Sending firmware update commands over the SATA interface from the host computer (requires root/admin).</li><li>Create a portable SPI programmer that can flash the firmware by being pressed against the test points on the bottom of the hard drive (would only take about 5 seconds).&nbsp;</li></ol><div>Something...something...aliens...something...something...government... *puts on tinfoil hat*<br><br>Part 6 (Final part):&nbsp;<a href="http://www.malwaretech.com/2015/05/hard-disk-firmware-hacking-final-part.html">http://www.malwaretech.com/2015/05/hard-disk-firmware-hacking-final-part.html</a></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Hard Disk Firmware Hacking (Part 4)]]></title>
<description><![CDATA[It seems that the bootstrap code is just scattered around various memory addresses and there's no simple way to dump all of it, so i decided to just dump a chunk of memory from 0x00000000 and look for any reference to addresses outside of that chunk (allowing me to build up a basic map of the cod...]]></description>
<link>https://tsecurity.de/weiterlesen/20399/20555/hard-disk-firmware-hacking-part-4/</link>
<pubDate>Sun, 31 Jan 2016 22:37:07 +0100</pubDate>
<category>🎥 Video</category>
<source url="https://tsecurity.de">TSECURITY.DE</source>
<content:encoded><![CDATA[<div dir="ltr" trbidi="on">It seems that the bootstrap code is just scattered around various memory addresses and there's no simple way to dump all of it, so i decided to just dump a chunk of memory from 0x00000000 and look for any reference to addresses outside of that chunk (allowing me to build up a basic map of the code).<br><br>Although the exact addresses vary between disk models, my layout should give you a good idea where to look.<br><br><ul><li>0x00000000 - 0x0000A520</li><li>0x0000EA24 - 0x00014F74</li><li>0xFFE19E00 - 0xFFE34D9A</li><li>0xFFFF2800 - 0xFFFF2800</li></ul><div><br></div>After poking around, i found it was reading some code into memory from somewhere, which I assumed to be the flash.<br><table align="center" cellpadding="0" cellspacing="0"><tbody><tr><td><a href="http://3.bp.blogspot.com/-duSheH_MD-U/VUkdUZpR2wI/AAAAAAAABEs/nLKJcQUG0q4/s1600/Flash_Snippet.png" imageanchor="1"><img border="0" height="480" src="http://3.bp.blogspot.com/-duSheH_MD-U/VUkdUZpR2wI/AAAAAAAABEs/nLKJcQUG0q4/s1600/Flash_Snippet.png" width="640"></a></td></tr><tr><td>First few bytes of the flash</td></tr></tbody></table><br>The flash starts with a table which spans from 0 to 0x120 (the start of the first block), each table entry is 32 bytes and follows the same format (see: image). Each block has an id from 1 to n, with the exception of the first block which is always 0x5A.<br><br>The block at 0x5A is some kind of bootloader which likely reads and decompresses the rest of the blocks from flash, but I'm not sure yet as it's proving a problem to reverse. I wanted to intercept this bootloader at the entry point, which sounds easy, it's not.<br><br><ul><li>At some point during the bootstrap process my hardware breakpoints stop working, it could be that the processor is overwriting the register, remapping memory, or disabling them all together; but I've not found the issue yet. This means I can't simply set a breakpoint on the bootloader entry point (0x19000).</li><li>The bootstrap code responsible for loading and executing the bootloader is in ROM, so I can't set software breakpoints either.</li><li>Watchpoints don't seem to work at all, even before my breakpoints stop working I can't get the code to break on any memory access.</li><li>Most of the code that isn't in ROM is using some kind of paging (aka overlaying), which reads certain regions of code into memory when they're needed, then replaces them when they're not, preventing the use of software breakpoints.</li></ul><div><br></div><div>All in all, this was proving to be must more of a pain than I expected so I decided the easiest option would be to buy a drive with an external EEPROM chip, instead of one built into the MCU. This way I could write software breakpoints directly to the flash chip with an EEPROM programmer.</div><div><br></div><div><a href="http://4.bp.blogspot.com/-F2Xp2bH__Ls/VUkjsE-joUI/AAAAAAAABE4/-Hb5E-6WtAU/s1600/PCB_Flash.png" imageanchor="1"><img border="0" height="424" src="http://4.bp.blogspot.com/-F2Xp2bH__Ls/VUkjsE-joUI/AAAAAAAABE4/-Hb5E-6WtAU/s1600/PCB_Flash.png" width="640"></a></div><div><br></div><br>&nbsp;Hardware and firmware wise this disk is pretty much identical, except the firmware is now stored in a 256k SPI flash chip, instead of in the MCU's internal memory. The first thing I did was use a multimeter to see if there's anywhere on the top of the PCB i could connect to the flash chip (so I didn't have to desolder it or keep unscrewing the PCB from the disk).<br><br><div><a href="http://3.bp.blogspot.com/-9Qx4gtQddrw/VUkkxvnU1-I/AAAAAAAABFE/9JwlTaLgUYc/s1600/ISP.png" imageanchor="1"><img border="0" height="624" src="http://3.bp.blogspot.com/-9Qx4gtQddrw/VUkkxvnU1-I/AAAAAAAABFE/9JwlTaLgUYc/s1600/ISP.png" width="640"></a></div><br>WP# and HOLD# are shorted to VCC, so they're not a problem and the rest of the required pins are brought out to the test pads around E11. I tried connecting my TUMPA's SPI interface to the test pads and using the flashrom software, but it was unable to detect the chip. I'm not sure if this is because my TUMPA isn't capable of in-circuit programming, or there is other stuff on the same data lines, but it I simply couldn't get it to work.<br><br>My new plan is to get a SOIC clip, a decent EEPROM programmer, and a desoldering station for if neither of the other option work; In the mean time I will be trying to find out what's stopping my breakpoints from working and see if i can remedy that. I'll probably not have another update until all my stuff gets delivered and I have a few days to try it all out.<br><br>Part 5 (Writing the flash):&nbsp;<a href="http://www.malwaretech.com/2015/05/hard-disk-firmware-hacking-part-5.html">http://www.malwaretech.com/2015/05/hard-disk-firmware-hacking-part-5.html</a></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Hard Disk Firmware Hacking (Part 3)]]></title>
<description><![CDATA[Before we get started with part 3, I have a few updates regarding part 1 & 2.I've found that the reset pad on the JTAG header is not actually a system reset (SRST) but a TAP reset (TRST), which isn't very useful for debugging. Here is the updated layout with the system reset signal added (this wi...]]></description>
<link>https://tsecurity.de/weiterlesen/20400/20556/hard-disk-firmware-hacking-part-3/</link>
<pubDate>Sun, 31 Jan 2016 22:37:07 +0100</pubDate>
<category>🎥 Video</category>
<source url="https://tsecurity.de">TSECURITY.DE</source>
<content:encoded><![CDATA[<div dir="ltr" trbidi="on">Before we get started with part 3, I have a few updates regarding part 1 &amp; 2.<br><br>I've found that the reset pad on the JTAG header is not actually a system reset (SRST) but a TAP reset (TRST), which isn't very useful for debugging. Here is the updated layout with the system reset signal added (this will allow the 'reset halt' command to break on the reset vector, before any instructions are executed).<br><br><div><a href="http://2.bp.blogspot.com/-qVcEybzOjTw/VTZnIGTiHGI/AAAAAAAABDk/WuV-Osa__o8/s1600/JTAG_Pins_New.png" imageanchor="1"><img border="0" height="620" src="http://2.bp.blogspot.com/-qVcEybzOjTw/VTZnIGTiHGI/AAAAAAAABDk/WuV-Osa__o8/s1600/JTAG_Pins_New.png" width="640"></a></div><br>In my case there wasn't a test pad for the SRST line, but there was a very small exposed bit of copper underneath the serial sticker, which was connected to the SRST pin of the CPU.<br><br>Ceriand on <a href="http://www.reddit.com/r/ReverseEngineering/comments/32jx6k/dumping_the_firmware_of_a_hard_drive_with_jtag/cqcbdda">Reddit</a>&nbsp;pointed out that the JTAG header matches the footprint of a MICTOR connector (38 or 40 pin one usually), so if you don't want to do any soldering you could get yourself a MICTOR connector and cable.<br><br><table align="center" cellpadding="0" cellspacing="0"><tbody><tr><td><a href="http://3.bp.blogspot.com/-jrqTYAonEp4/VTZpDQxXg4I/AAAAAAAABDw/MomiWLykIxE/s1600/MICTOR.png" imageanchor="1"><img border="0" height="640" src="http://3.bp.blogspot.com/-jrqTYAonEp4/VTZpDQxXg4I/AAAAAAAABDw/MomiWLykIxE/s1600/MICTOR.png" width="640"></a></td></tr><tr><td>MICTOR 38 connector</td></tr></tbody></table><br>I've also found out the hard way that older PSUs don't like to be used at extremely low voltage (components inside them tend to explode), so I recommend buying a decent AC to Molex power adapter (don't get the cheap ones, they die after a day).<br><br><table align="center" cellpadding="0" cellspacing="0"><tbody><tr><td><a href="http://3.bp.blogspot.com/-CdZRVUk7nmo/VTZ9wGYlqyI/AAAAAAAABEY/Dc2MY-LgFK8/s1600/fuse.png" imageanchor="1"><img border="0" height="478" src="http://3.bp.blogspot.com/-CdZRVUk7nmo/VTZ9wGYlqyI/AAAAAAAABEY/Dc2MY-LgFK8/s1600/fuse.png" width="640"></a></td></tr><tr><td>Apparently glass fuses like to explode and send shards flying everywhere</td></tr></tbody></table><br>Lastly: because the JTAG header has an RTCK connector, you should be able to set adapter_khz in the openocd config to 0. The JTAG can then use adaptive clocking, which should prevent any timeout errors.<br><br><h2>Bootstrap &amp; Bootloader</h2><div>After some reversing I'm now convinced that the bootstrap code in Part 2 is not used during a normal boot. On execution it waits for some data on a port (most likely the serial port), then acts accordingly. If no data is found, the code goes into an infinite loop and the drive never boots.</div><div><br></div><div><a href="http://4.bp.blogspot.com/-xuj5GZP_afA/VTZwaEtvuPI/AAAAAAAABD8/sKqjDxDcOus/s1600/Bootstrap1.png" imageanchor="1"><img border="0" height="640" src="http://4.bp.blogspot.com/-xuj5GZP_afA/VTZwaEtvuPI/AAAAAAAABD8/sKqjDxDcOus/s1600/Bootstrap1.png" width="504"></a></div><div><br></div><div>On this CPU the 0x1C00A000 - 0x1C00AFFF range appears to be mapped to various ports and test pads all around the PCB. Now, because I don't have the money for an oscilloscope or decent logic analyzer I'm going to have to pass up on mapping these ports, even though it would make things easier.</div><div><br></div><div>All this code does is read some kind of switch which enters the system into a specific mode based on the value:</div><div><ul><li>4 - Not sure, but it waits infinitely for a value on some port. My assumption is this code probably allows developers to read/write/erase the processor's internal flash.</li><li>3 - Jumps to the address in R4 (in my case this is 0, but that could be by design)</li><li>6 - A serial console which looks for ASCII bytes (r, w, j, h) on the serial port, allowing the developer to send read, write, jump, and halt commands.</li></ul><div>I'm not familiar with how ports are mapped to memory, but&nbsp;0x1C00A030 is always 0 while&nbsp;0x1C00A03A is always 0xFFFF (which I assume means one is constant at a low voltage and the other constant at a high voltage).</div></div><div><br></div><div>Interestingly if we set a hardware breakpoints on "cmp R1, #3" and set R1 to 3, the code will jump to address 0 and boot normally (this is why I think 0 doesn't mean uninitialized). Let's see what's at address 0.</div><div><br></div><div><a href="http://4.bp.blogspot.com/-zrF58vjNGAI/VTZ53J46_gI/AAAAAAAABEM/7db5ldTf708/s1600/IVT.png" imageanchor="1"><img border="0" height="640" src="http://4.bp.blogspot.com/-zrF58vjNGAI/VTZ53J46_gI/AAAAAAAABEM/7db5ldTf708/s1600/IVT.png" width="614"></a></div><div><br></div><div>Address 0 is usually RAM, but there's already valid code here, so it's quite likely the CPU temporarily maps address 0 to some area of the internal ROM during boot. This is a standard ARM IVT, which you'd see at the boot address of any ARM devices; making me think the bootstrap at 0xFFFF0000 is only executed if the CPU detects a JTAG is attached. Until I can buy a decent logic analyzer and figure which port allows us to control the bootstrap mode switch, the only apparent way to boot the disk normally with a JTAG attached is to perform a "reset halt" then manually set R1 to '3' just before the check.</div><div><br></div><div>In this case the boot code is all over the place with massive gaps between sections, my next step will be to map, dump, and reverse it. I'd probably have done that already, but my power adapter didn't arrive until yesterday.&nbsp;</div><div><br></div><div>Part 4 (Working with spi flash):&nbsp;<a href="http://www.malwaretech.com/2015/05/hard-disk-firmware-hacking-part-4.html">http://www.malwaretech.com/2015/05/hard-disk-firmware-hacking-part-4.html</a></div><div><br></div><div><br></div><div><br></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Hard Disk Firmware Hacking (Part 2)]]></title>
<description><![CDATA[Now that everything is ready to be connected, power up the hard drive an run openocd with the following command: openocd -f interface/.cfg -f target/test.cfgtest.cfg should be the configuration for the CPU used by your hard disk controller, for most marvell CPUs this config should work. I'm not s...]]></description>
<link>https://tsecurity.de/weiterlesen/20401/20557/hard-disk-firmware-hacking-part-2/</link>
<pubDate>Sun, 31 Jan 2016 22:37:07 +0100</pubDate>
<category>🎥 Video</category>
<source url="https://tsecurity.de">TSECURITY.DE</source>
<content:encoded><![CDATA[<div dir="ltr" trbidi="on">Now that everything is ready to be connected, power up the hard drive an run openocd with the following command: openocd -f interface/&lt;your interface here&gt;.cfg -f target/test.cfg<br><br>test.cfg should be the configuration for the CPU used by your hard disk controller, for most marvell CPUs <a href="http://pastebin.com/Rb94dGcq">this config</a> should work. I'm not sure of the adapter_khz, so I've set mine to 100 (as long as this value is lower than the actual it should work).<br><br><div><a href="http://1.bp.blogspot.com/-LaPlnReD1qU/VSu2opfNfpI/AAAAAAAABCY/lmKMO2QpuRo/s1600/OpenOCD.png" imageanchor="1"><img border="0" height="362" src="http://1.bp.blogspot.com/-LaPlnReD1qU/VSu2opfNfpI/AAAAAAAABCY/lmKMO2QpuRo/s1600/OpenOCD.png" width="640"></a></div><br>If all went well, you should see something along the lines of the above. Now you can use telnet to connect to port 4444 and issue commands.<br><br><div><a href="http://2.bp.blogspot.com/--SmjKvyASlQ/VSu4usvuy1I/AAAAAAAABCo/OoomVlQIST8/s1600/Telnet.png" imageanchor="1"><img border="0" height="364" src="http://2.bp.blogspot.com/--SmjKvyASlQ/VSu4usvuy1I/AAAAAAAABCo/OoomVlQIST8/s1600/Telnet.png" width="640"></a></div><br>The Marvell chips used in hard disk controller aren't publicly documented; so if you want to know information such as their memory map, you'll have to sign a NDA and probably pay some money. Instead, what I'm going to do is try to figure out as much as I can from the firmware and possibly by probing the circuit.<br><br>Getting the firmware isn't easy when you can't de-solder and dump the flash, so we'll have to work through the boot process. Most ARM CPUs begin executing at address 0xFFFF0000, this is known as the reset vector. If we dump 65536 bytes from this address, we'll find the bootstrap code which will be a good starting point.<br><br>In order o dump memory, we first need to halt the CPU, which can be done with the command "reset halt" (It's required that we first reset the system as we can't halt past a certain stage). If the reset command doesn't work for any reason e.g: RST pin of JTAG isn't connected to anything, you'll need to disconnect and reconnect the hard drive's power source then quickly tap into the JTAG and issue the halt command within a few second. Memory dumped with the command "dump_image &lt;file name&gt; &lt;address&gt; &lt;size&gt;".<br><br><div><a href="http://1.bp.blogspot.com/-U2NB2b6iLm4/VSvaAyw4lJI/AAAAAAAABDQ/FlffCoLjxyg/s1600/Bootstrap.png" imageanchor="1"><img border="0" height="640" src="http://1.bp.blogspot.com/-U2NB2b6iLm4/VSvaAyw4lJI/AAAAAAAABDQ/FlffCoLjxyg/s1600/Bootstrap.png" width="576"></a></div><br><br>When we disassemble the dumped image, it's some fairly small (4 kb) ARM bootstrap code, which should lead us to the rest of the firmware. I've not had much time to look, so I'll reverse the bootstrap code and post the next part when I've found the rest of the bootloader and kernel.<br><br>Part 3 (Bootstrap analysis):&nbsp;<a href="http://www.malwaretech.com/2015/04/hard-disk-firmware-hacking-part-3.html">http://www.malwaretech.com/2015/04/hard-disk-firmware-hacking-part-3.html</a></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Hard Disk Firmware Hacking (Part 1)]]></title>
<description><![CDATA[I've not been doing much in the windows malware world for a while now, because quite frankly I've run out of ideas and I'm totally bored. Recently I decided to take the jump into electronics / hardware hacking and people have suggested I post some of that here.A couple of years ago I started look...]]></description>
<link>https://tsecurity.de/weiterlesen/20402/20558/hard-disk-firmware-hacking-part-1/</link>
<pubDate>Sun, 31 Jan 2016 22:37:07 +0100</pubDate>
<category>🎥 Video</category>
<source url="https://tsecurity.de">TSECURITY.DE</source>
<content:encoded><![CDATA[<div dir="ltr" trbidi="on">I've not been doing much in the windows malware world for a while now, because quite frankly I've run out of ideas and I'm totally bored. Recently I decided to take the jump into electronics / hardware hacking and people have suggested I post some of that here.<br><br>A couple of years ago I started looking into BIOS rootkits (back before (U)EFI was mainstream). I was aware that most hardware had a BIOS type setup that is usually initialized during the POST phase of the boot process, so I was looking into the possibility of modifying &nbsp;firmware to work in the same way as a BIOS rootkit would. My two main candidates were the GPU and Hard Disk, which I began looking into (but was mostly sandbagged by my lack of reverse engineering knowledge at the time).<br><br>My current project is on hold while I await the arrival of some expensive hardware which will allow me to overcome a setback (the manufacture disabled the JTAG interface prior to shipping), so I decided to have a play with something I saw on spritesmods in 2013 (<a href="https://spritesmods.com/?art=hddhack">Hard disk hacking</a>).<br><br><h2>Hard Disk Hacking</h2><div>I found an old Western Digital hard drive in pretty good condition, so I unscrewed the controller and had a look.</div><div><br></div><table align="center" cellpadding="0" cellspacing="0"><tbody><tr><td><a href="http://2.bp.blogspot.com/-dzR0lJk-giQ/VSudN6bYhAI/AAAAAAAABBE/e1pn9MdYCa4/s1600/HDD_Controller.png" imageanchor="1"><img border="0" height="428" src="http://2.bp.blogspot.com/-dzR0lJk-giQ/VSudN6bYhAI/AAAAAAAABBE/e1pn9MdYCa4/s1600/HDD_Controller.png" width="640"></a></td></tr><tr><td>This is where I'd put my flash...if i had any.</td></tr></tbody></table><div><br></div><div>The guy on spritesmods had dumped the firmware by de-soldering the flash chip and dumping it manually, the only problem is the red circle is were the flash chip should be (thanks obama).&nbsp;</div><div><br>Above the red circle is a Marvell 88i8846-TFJ2 ARM processor which has internal flash. I don't fancy my chances of de-soldering the entire CPU and trying to access the memory manually, so I decided to go for the JTAG method.</div><div><br></div><div><a href="http://1.bp.blogspot.com/-MGVDOTF1i3w/VSuf-U_X53I/AAAAAAAABBQ/mWXDn20d6Bc/s1600/JTAG_Pins.png" imageanchor="1"><img border="0" height="621" src="http://1.bp.blogspot.com/-MGVDOTF1i3w/VSuf-U_X53I/AAAAAAAABBQ/mWXDn20d6Bc/s1600/JTAG_Pins.png" width="640"></a></div><div><br></div>The header for the JTAG is fairly well known, though it can be upside down (in my case the first pin of the header is denoted by a '1' on the board). Pins 6 to 11 are all we need for the JTAG and the metal circle, which is the ground.<br><br>As you can probably see, I've decided not to solder the pins. This is for two reasons: They're rusty and they're too close together, so I could easily short the board. Instead I opted to use the test pads, which can be found using the 'continuity' mode on the multimeter (thanks to @<a href="https://twitter.com/McGrewSecurity">McGrewSecurity</a> for the tip).<br><br><div><a href="http://1.bp.blogspot.com/-kV58jqhN-ag/VSujUwOxFSI/AAAAAAAABBc/RWckRLsyb9c/s1600/Multimeter_Continuity.png" imageanchor="1"><img border="0" height="480" src="http://1.bp.blogspot.com/-kV58jqhN-ag/VSujUwOxFSI/AAAAAAAABBc/RWckRLsyb9c/s1600/Multimeter_Continuity.png" width="640"></a></div><br>By setting this mode on the multimeter it will show us the resistance between two points, the '1' means total resistance (the points likely aren't even connected) and '0.01' is a good connection. The meter will also emit and audible (and incredibly annoying) high pitch tone when the resistance is low, so we only really need to use the tone to tell if two points are connected.<br><br>With the hard drive disconnected simply put one of the multimeter probes on the header pin you want to locate the test pad for, then move the other probe around the test pads in the area where mine are until you hear a beep. On my board you'll see there are visible data lines running from the header pins to the test pads, which gives you a good idea where to look (depending on the quality of your eyesight).<br><br><div>I didn't want the hard drive plugged into my computers power supply in case something went wrong, and my computer is the opposite side of the room, so I didn't want to try and build a 10m long SATA cable either. Here's my solution (disclaimer: If you injure yourself blame someone else i.e. not me).&nbsp;</div><div><br></div><div><a href="http://2.bp.blogspot.com/-gWIv43MlWL8/VSumonMYl3I/AAAAAAAABBo/nJJDCrVC2cI/s1600/PSU_Shorted.png" imageanchor="1"><img border="0" height="466" src="http://2.bp.blogspot.com/-gWIv43MlWL8/VSumonMYl3I/AAAAAAAABBo/nJJDCrVC2cI/s1600/PSU_Shorted.png" width="640"></a></div><div><br></div><br>If you have a spare PSU lying around, you can short the third and forth pin of the ATX header to turn it on without connecting it to a motherboard. My PSU was very old and missing a fan, so I was pleasantly surprised when nothing shorted or caught fire (My entire house is on the same circuit breaker, so I'd be spend the next hour rebooting various devices).<br><br><div><a href="http://3.bp.blogspot.com/-uL2S05hTifU/VSuopuew0XI/AAAAAAAABB0/Vo62WgYiQoE/s1600/IDE_SATA.png" imageanchor="1"><img border="0" height="200" src="http://3.bp.blogspot.com/-uL2S05hTifU/VSuopuew0XI/AAAAAAAABB0/Vo62WgYiQoE/s1600/IDE_SATA.png" width="200"></a></div><a href="http://4.bp.blogspot.com/-22bkCWoNHNk/VSupjTm7vpI/AAAAAAAABB8/IwaoIjF-OjY/s1600/TUMPA.png" imageanchor="1"><img border="0" height="153" src="http://4.bp.blogspot.com/-22bkCWoNHNk/VSupjTm7vpI/AAAAAAAABB8/IwaoIjF-OjY/s1600/TUMPA.png" width="200"></a><br><br><br><br><br><br><br><br><br><br><br>I use a $5 SATA to USB connector, which is perfect for the data side of the hard disk connection. The red board on the right is a $30 TIAO USB Multi-Protocol Adapter, which is FT2232H based and also does SPI as well as JTAG.<br><br><table align="center" cellpadding="0" cellspacing="0"><tbody><tr><td><a href="http://4.bp.blogspot.com/-lS6ScJ9a6Aw/VSuqeQk-g1I/AAAAAAAABCI/x5aH3yF0w5Q/s1600/Full_Setup.png" imageanchor="1"><img border="0" height="460" src="http://4.bp.blogspot.com/-lS6ScJ9a6Aw/VSuqeQk-g1I/AAAAAAAABCI/x5aH3yF0w5Q/s1600/Full_Setup.png" width="640"></a></td></tr><tr><td>I really need a bigger desk</td></tr></tbody></table><br>Here we have a stupidly over-complicated setup due to the fact my Windows desktop reside on the other side of the room: The iMac is running a Linux virtual machine for the JTAG software (FTDI driver and OpenOCD) because they're a pain to install on Windows or OSX . The Windows system (left monitor) is running IDA for reversing/debugging (I plan on trying to connect IDA to the OpenOCD GDB service over my local network when I start doing live analysis).<br><br><br>Part 2 (Dumping the bootstrap):&nbsp;<a href="http://www.malwaretech.com/2015/04/hard-disk-firmware-hacking-part-2.html">http://www.malwaretech.com/2015/04/hard-disk-firmware-hacking-part-2.html</a><br><br><br><br><br></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Bootkit Disk Forensics - Part 2]]></title>
<description><![CDATA[DriverStartIoAs I explained in the previous article: DriverStartIo is used by older miniports to actually perform the disk I/O, it takes 2 parameters (a device object and an IRP), exactly the same as IoCallDriver does. The call to DriverStartIo is done with IoStartPacket; however, the device obje...]]></description>
<link>https://tsecurity.de/weiterlesen/20403/20559/bootkit-disk-forensics-part-2/</link>
<pubDate>Sun, 31 Jan 2016 22:37:07 +0100</pubDate>
<category>🎥 Video</category>
<source url="https://tsecurity.de">TSECURITY.DE</source>
<content:encoded><![CDATA[<div dir="ltr" trbidi="on"><h2>DriverStartIo</h2><div>As I explained in the previous article: DriverStartIo is used by older miniports to actually perform the disk I/O, it takes 2 parameters (a device object and an IRP), exactly the same as IoCallDriver does. The call to DriverStartIo is done with IoStartPacket; however, the device object passed is not that of the miniport, but instead a device associated with the port the target disk is connected to (in my case IdePort1).</div><div><br></div><div>IRP_MJ_SCSI points to IdePortDispatch in atapi.sys, by disassembling it we can see exactly how the required device object is retrieved from the DeviceExtension field of the miniport's device object.</div><table align="center" cellpadding="0" cellspacing="0"><tbody><tr><td><a href="http://2.bp.blogspot.com/-elDVj88Qutg/VPYq4a4bOBI/AAAAAAAAA9w/yJafDuu8cm4/s1600/AtaPortDispatch.png" imageanchor="1"><img border="0" src="http://2.bp.blogspot.com/-elDVj88Qutg/VPYq4a4bOBI/AAAAAAAAA9w/yJafDuu8cm4/s1600/AtaPortDispatch.png"></a></td></tr><tr><td>To start with, ebx is the address of the device extension (which is shared between all atapi devices).</td></tr></tbody></table><div><br>The call logic is something like this:<br><ol><li>Get the miniport's device extension from its device object (passed to us in the call).</li><li>Get IdePort1's device extension from offset 0x5C into the miniport's device extension.</li><li>Get IdePort1's device object from offset 0x0C into its device extension.</li><li>Call IoStartPacket with the IRP and IdePort1's device object.</li></ol><table align="center" cellpadding="0" cellspacing="0"><tbody><tr><td><a href="http://2.bp.blogspot.com/-oYTqA-I34z8/VPYvawAjrSI/AAAAAAAAA98/lZ5zvpIIK70/s1600/ObjectRelationship.png" imageanchor="1"><img border="0" src="http://2.bp.blogspot.com/-oYTqA-I34z8/VPYvawAjrSI/AAAAAAAAA98/lZ5zvpIIK70/s1600/ObjectRelationship.png" height="264" width="640"></a></td></tr><tr><td>The relationship between the various objects.</td></tr></tbody></table><div><br></div></div><div>As both the miniport and IdePort devices are created by atapi.sys, the DriverObject field of both devices' objects point to the same driver object; thus, hooking DriverStartIo is as simple as replacing the address in the driver's object. &nbsp;</div><div><br></div><h2>Detecting DriverStartIo hook with WinDbg</h2><div>For basic DriverStartIo hook detection we can simply follow the same process as for major function hooks: First, we find the boot disk and list it's stack.</div><table cellpadding="0" cellspacing="0"><tbody><tr><td><a href="http://1.bp.blogspot.com/-uWz6wwzeQcs/VPc1WMMJ2yI/AAAAAAAAA-Q/znycrY-NXo0/s1600/DeviceStackClean.png" imageanchor="1"><img border="0" src="http://1.bp.blogspot.com/-uWz6wwzeQcs/VPc1WMMJ2yI/AAAAAAAAA-Q/znycrY-NXo0/s1600/DeviceStackClean.png"></a></td></tr><tr><td>Device stack for boot device on a clean system</td></tr></tbody></table><table cellpadding="0" cellspacing="0"><tbody><tr><td><a href="http://3.bp.blogspot.com/-4b0oScbtnkU/VPc2U2lV-YI/AAAAAAAAA-k/H_sW59jnvHM/s1600/DeviceStackTdl4.png" imageanchor="1"><img border="0" src="http://3.bp.blogspot.com/-4b0oScbtnkU/VPc2U2lV-YI/AAAAAAAAA-k/H_sW59jnvHM/s1600/DeviceStackTdl4.png"></a></td></tr><tr><td>Device stack on a TDL4 infected system.</td></tr></tbody></table><div><br></div><div>As I explained in the previous article, modifications made by TDL4 will cause the !drvobj and !devobj commands to think the object is invalid, it's not. You will probably want to check each driver object in the stack (for the invalid DeviceObject you can again use "dt _DEVICE_OBJECT &lt;address&gt;" to find the DriverObject field).</div><div><br></div><div>With most bootkits, the lowest level driver is always the one hooked, so I'll use this in my example.</div><div></div><table cellpadding="0" cellspacing="0"><tbody><tr><td><a href="http://3.bp.blogspot.com/-ilPyqIt7MZQ/VPdfyW1oziI/AAAAAAAAA_o/F7O03d_kFCI/s1600/DriverObject.png" imageanchor="1"><img border="0" src="http://3.bp.blogspot.com/-ilPyqIt7MZQ/VPdfyW1oziI/AAAAAAAAA_o/F7O03d_kFCI/s1600/DriverObject.png"></a></td></tr><tr><td>DriverStartIo appears not to be hooked.</td></tr></tbody></table><div><br></div><div>You can see here that DriverStartIo isn't hooked because the address resolve to its proper symbol; however, this isn't actually the real driver object. Earlier i explained that IoStartPacket is always called with the device object of IdePort1, not the disk miniport: This means that when IoStartPacket called DriverStartIo internally, it does so by getting the driver object from the DriverObject field of IdePort1's device object, then getting the DriverStartIo field from that. Obviously this means that to hook DriverStartIo, one could simply just create a copy of atapi's driver object, with the DriverStartIo field modified, then set the DriverObject field of IdePort1's device object to point to the new, malicious driver object (this way on IdePort1 will point to the hooked driver, the rest will point to the original).</div><div><br></div><div>As it happens TDL4 actually does the opposite, it hooks the real atapi driver object, then replaces the DriverObject field of the disk miniport's device object with the address of an identical driver object, without the DriverStartIo field modified.).</div><div><br></div><div>If you know what you're looking for, fake driver objects are easy to detect. All devices created by a driver should point the same driver object, so simply enumerating the devices created by the miniport's driver then making sure all the DriverObject fields point to the same address is all that's needed. This can be done a multitude of ways.</div><div><br></div><div><b>Method 1: DrvObj</b></div><div>The fake driver object will have the same name as the real one (in my case "\driver\atapi"), all you need to do is type "!drvobj \driver\atapi 2" to get the real driver's object (this is a downside of TDL4 hooking the real driver object instead of a spoofed one).&nbsp;</div><div><br></div><div><a href="http://2.bp.blogspot.com/-b1tuHs4XXag/VPdOQQQpL0I/AAAAAAAAA_A/gLJKb2vPDyg/s1600/DriverObjectReal.png" imageanchor="1"><img border="0" src="http://2.bp.blogspot.com/-b1tuHs4XXag/VPdOQQQpL0I/AAAAAAAAA_A/gLJKb2vPDyg/s1600/DriverObjectReal.png"></a></div><div><b>Method 2: NextDevice</b></div><div>Starting with the miniport device, enumerate devices using "dt _DEVICE_OBJECT &lt;address&gt;" and the NextDevice field of each device's object. We're looking for any DriverObject field that dosen't match that of the miniport (this is the real driver object).</div><div></div><table cellpadding="0" cellspacing="0"><tbody><tr><td><a href="http://1.bp.blogspot.com/-3jsvAjEKgvQ/VPdjDVVMslI/AAAAAAAAA_0/ApLFlSh-7Vg/s1600/NextDevice.png" imageanchor="1"><img border="0" src="http://1.bp.blogspot.com/-3jsvAjEKgvQ/VPdjDVVMslI/AAAAAAAAA_0/ApLFlSh-7Vg/s1600/NextDevice.png"></a></td></tr><tr><td>All devices should point to the real driver object, except for the miniport.</td></tr></tbody></table><div><b><br>Method 3: DeviceExtension</b></div><div>This is the least reliable way, as the device extension could change from system to system, but as I mentioned earlier: you can find IdePort1's device extension at offset 0x5C isn't the miniport's device extension, then from IdePort1's device extension you can find its device object at offset 0x0C (IdePort1's device object will point to the real driver object). We can actually find the DeviceObject in a single commands using this overly complicated WinDbg-C++ syntax: "dt _DEVICE_OBJECT poi(poi(@@C++(((nt!_DEVICE_OBJECT *)&lt;address&gt;)-&gt;DeviceExtension)+0x5C)+0x0C)", where "&lt;address&gt;" is the miniport device object.</div><div><br></div><div><a href="http://4.bp.blogspot.com/-Rgl2wuQPZxc/VPdVvyB6beI/AAAAAAAAA_Y/8LlcAw2Nx7A/s1600/DeviceExtension.png" imageanchor="1"><img border="0" src="http://4.bp.blogspot.com/-Rgl2wuQPZxc/VPdVvyB6beI/AAAAAAAAA_Y/8LlcAw2Nx7A/s1600/DeviceExtension.png"></a></div><h2>Part3</h2><div><a href="http://www.malwaretech.com/2015/03/bootkit-disk-forensics-part-3.html">http://www.malwaretech.com/2015/03/bootkit-disk-forensics-part-3.html</a></div><div><br></div><div><br></div><div></div><div><br></div><div><br></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Intercepting all System Calls by Hooking KiFastSystemCall]]></title>
<description><![CDATA[Usually I don't post things like this, but because KiFastSystemCall hooking only works on x86 systems and doesn't work on Windows 8 or above, it no longer has much use in malware. There are also multiple public implementations for this method, just not very elegant, which I hope to correct.If you...]]></description>
<link>https://tsecurity.de/weiterlesen/20404/20560/intercepting-all-system-calls-by-hooking-kifastsystemcall/</link>
<pubDate>Sun, 31 Jan 2016 22:37:07 +0100</pubDate>
<category>🎥 Video</category>
<source url="https://tsecurity.de">TSECURITY.DE</source>
<content:encoded><![CDATA[<div dir="ltr" trbidi="on">Usually I don't post things like this, but because KiFastSystemCall hooking only works on x86 systems and doesn't work on Windows 8 or above, it no longer has much use in malware. There are also multiple public implementations for this method, just not very elegant, which I hope to correct.<br><br>If you haven't read my previous article about this topic, or need a refresher, you can find it <a href="http://www.malwaretech.com/2014/06/usermode-system-call-hooking-betabot.html">here</a>.<br><br><h2>Performing a System Call</h2><div>KiFastSystemCall has a very strange calling convention (if you can call it that). Each native function (Ex: NtCreateFile) corresponds to a function with the same name in the SSDT. In order to make the transition from user mode to kernel mode, the instruction "sysenter" is used.</div><div><br></div><div><a href="http://3.bp.blogspot.com/-mFGfdRzXA3A/U58ZBxRKf7I/AAAAAAAAAf0/mstM2HJclRg/s1600/system+call+path+32-bit.png" imageanchor="1"><img border="0" src="http://3.bp.blogspot.com/-mFGfdRzXA3A/U58ZBxRKf7I/AAAAAAAAAf0/mstM2HJclRg/s1600/system+call+path+32-bit.png" height="190" width="640"></a></div><div><br></div><div><br></div><div>I don't want to go into great detail on how the sysenter instruction actually enters kernel mode, as that would take up the entire page, but I'll explain the basics:</div><div><ul><li>The SSDT is an array of addresses for each native function.</li><li>The number you see being moved into the eax register is known as its ordinal, and is the position within the SSDT where that functions address is located.&nbsp;</li><li>When the sysenter instruction is executed the kernel reads the ordinal from eax and uses it to call the corresponding function in the SSDT, before returning execution to usemode.</li></ul><div>Something important to note is that the native function simply calls KiFastSystemCall and doesn't even set up a stack frame, meaning the address of the first parameter can only be accessed using [esp+8], so we can't just hook KiFastSystemCall with a C function, as this matches no standard calling convention (which is what makes the method so tricky to implement).<br><br><h2>Dispatching Calls</h2></div></div><div>Since the last article I've improved on the dispatching method, which now has two purposes:&nbsp;</div><div><ol><li>Determining which native function made the call to KiFastSystemCall, so we can properly handle it.</li><li>Setting up the stack in such a way that we can access the parameters using plain C.</li></ol><div><br></div><div><b>Dispatching</b></div><div>Normally we'd hook each individual function we want to intercept with a single handler (proxy), but all native functions call KiFastSystemCall, so we need to think differently.&nbsp;</div><div>As I explained earlier, the SSDT is an array of addresses and the ordinal (which is in eax when KiFastSystemCall is invoked), corresponds to the position of that function's address within the SSDT. Using this knowledge we can do the same: We create an array of addresses for the the proxy functions and use the ordinal to locate the correct handler using the ordinal in eax. For our SSDT each entry will be 8 bytes, so the handler needs to be placed at our_ssdt[2*ordinal] (in order to get the ordinal for a native function we just read 4 bytes starting at the 2nd byte of the function).&nbsp;</div></div><div><br></div><div>You're probably wondering why each entry for our SSDT is 8 bytes, instead of 4; this is because in order to set up the stack before calling the proxy, we need to know how many parameters were passed to KiFastSystemCall (we store the proxy address as the first 4 bytes and the number of parameter as the rest).</div><div><br></div><div><b>Preparing the Stack</b></div><div>When KiFastSystemCall is invoked, there are two return addresses between the stack pointer and the function parameters (the return from KiFastSystemCall to the native function and the return from the native function). In order to call the proxy function we will get the number of parameter for the function from our_ssdt[2*ordinal+4] and push them to the stack again, in stdcall format (the proxy function is responsible for removing them from the stack). The last thing that is pushed to the stack before we call the proxy is the eax register (the ordinal), we will need this later if we wish to call the original, non hooked, version of KiFastSystemCall.</div><div><br></div><h2>The Code</h2><div><a href="https://github.com/MalwareTech/FstHook">FstHook</a> - This is my own C&nbsp;library which allows a program to easily hook any number of native function using a single hook on KiFastSystemCall.</div><div><br></div><div>Everything is pretty well commented and self explanatory, but if you have any questions feel free to email me on admin@malwaretech.com.</div><div><br></div><div><br></div></div>]]></content:encoded>
</item>
</channel>
</rss>
<!-- Generated in 0,01ms -->