<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="/rss-style.xsl"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:media="http://search.yahoo.com/mrss/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/">
<channel>
<title><![CDATA[tsecurity.de - News Radar & Live Feeds]]></title>
<link><![CDATA[https://tsecurity.de/rss/0/Backdoor]]></link>
<description><![CDATA[Aktuelle Nachrichten und Updates auf tsecurity.de]]></description>
<language>de-DE</language>
<lastBuildDate>Tue, 06 Oct 2026 06:31:29 +0200</lastBuildDate>
<pubDate>Tue, 06 Oct 2026 06:31:29 +0200</pubDate>
<ttl>15</ttl>
<copyright>2026 tsecurity.de - News Radar &amp; Live Feeds</copyright>
<managingEditor>contact@tsecurity.de (tsecurity.de)</managingEditor>
<webMaster>contact@tsecurity.de (tsecurity.de)</webMaster>
<image>
<url>https://tsecurity.de/templates/mydraft-basis-tsecurity.de/media/logo.png</url>
<title><![CDATA[tsecurity.de - News Radar & Live Feeds]]></title>
<link><![CDATA[https://tsecurity.de/rss/0/Backdoor]]></link>
</image>
<atom:link href="https://tsecurity.de/rss/0/Backdoor" rel="self" type="application/rss+xml" />
<item>
<title><![CDATA[CloudSyncD Backdoor Spread Through Fake Zoom Installer Targeting macOS]]></title>
<description><![CDATA[Using fake Zoom installers, a macOS malware campaign distributes a backdoor known as CloudSyncD, a backdoor for MacOS.  Jamf Threat Labs first identified the malware during its development in mid-September, but later samples indicated it had moved to a live command-and-control infrastructure. It ...]]></description>
<link>https://tsecurity.de/de/4241546/malware-trojaner-viren/cloudsyncd-backdoor-spread-through-fake-zoom-installer-targeting-macos/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4241546/malware-trojaner-viren/cloudsyncd-backdoor-spread-through-fake-zoom-installer-targeting-macos/</guid>
<pubDate>Mon, 05 Oct 2026 21:37:55 +0200</pubDate>
<content:encoded><![CDATA[<p>Using fake Zoom installers, a macOS malware campaign distributes a backdoor known as CloudSyncD, a backdoor for MacOS.  Jamf Threat Labs first identified the malware during its development in mid-September, but later samples indicated it had moved to a live command-and-control infrastructure. It is initiated by the use of a disk image that is made... <a href="https://tsecurity.de/weiterlesen/1000018949/4241546/cloudsyncd-backdoor-spread-through-fake-zoom-installer-targeting-macos/" target="_blank" rel="noopener noreferrer">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Hackers Exploit 24 IoT Vulnerabilities to Install ClingSTUN Linux Backdoor]]></title>
<description><![CDATA[Meet ClingSTUN, a new Linux backdoor that exploits IoT vulnerabilities, gives attackers remote command access and turns infected devices into proxy nodes. This article has been indexed from Hackread – Cybersecurity News, Data Breaches, AI and More Read the original article: Hackers Exploit 24 IoT...]]></description>
<link>https://tsecurity.de/de/4241227/it-security-nachrichten/hackers-exploit-24-iot-vulnerabilities-to-install-clingstun-linux-backdoor/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4241227/it-security-nachrichten/hackers-exploit-24-iot-vulnerabilities-to-install-clingstun-linux-backdoor/</guid>
<pubDate>Mon, 05 Oct 2026 18:52:04 +0200</pubDate>
<content:encoded><![CDATA[<p>Meet ClingSTUN, a new Linux backdoor that exploits IoT vulnerabilities, gives attackers remote command access and turns infected devices into proxy nodes. This article has been indexed from Hackread – Cybersecurity News, Data Breaches, AI and More Read the original article: Hackers Exploit 24 IoT Vulnerabilities to Install ClingSTUN Linux Backdoor... <a href="https://tsecurity.de/weiterlesen/1000018630/4241227/hackers-exploit-24-iot-vulnerabilities-to-install-clingstun-linux-backdoor/" target="_blank" rel="noopener noreferrer">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[New Stealthy Linux Backdoors Target Telecoms, Masquerade as Email Traffic]]></title>
<description><![CDATA[Rapid7 has uncovered new BPFDoor, BPF Rekoobe and AVERAT malware variants targeting telecom and network-edge appliances in South Korea and Taiwan Weiterlesen]]></description>
<link>https://tsecurity.de/de/4240890/malware-trojaner-viren/new-stealthy-linux-backdoors-target-telecoms-masquerade-as-email-traffic/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4240890/malware-trojaner-viren/new-stealthy-linux-backdoors-target-telecoms-masquerade-as-email-traffic/</guid>
<pubDate>Mon, 05 Oct 2026 16:48:21 +0200</pubDate>
<content:encoded><![CDATA[<p>Rapid7 has uncovered new BPFDoor, BPF Rekoobe and AVERAT malware variants targeting telecom and network-edge appliances in South Korea and Taiwan <a href="https://tsecurity.de/weiterlesen/1000018293/4240890/new-stealthy-linux-backdoors-target-telecoms-masquerade-as-email-traffic/" target="_blank" rel="noopener noreferrer">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Linux Backdoor Abuses STUN Protocol, Exploits Dozens of Flaws]]></title>
<description><![CDATA[ClingSTUN operates as a back-connect proxy backdoor, sets up persistence, and contains exploits for self-propagation. The post Linux Backdoor Abuses STUN Protocol, Exploits Dozens of Flaws appeared first on SecurityWeek. Weiterlesen]]></description>
<link>https://tsecurity.de/de/4240609/it-security-nachrichten/linux-backdoor-abuses-stun-protocol-exploits-dozens-of-flaws/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4240609/it-security-nachrichten/linux-backdoor-abuses-stun-protocol-exploits-dozens-of-flaws/</guid>
<pubDate>Mon, 05 Oct 2026 15:12:16 +0200</pubDate>
<content:encoded><![CDATA[<p>ClingSTUN operates as a back-connect proxy backdoor, sets up persistence, and contains exploits for self-propagation. The post Linux Backdoor Abuses STUN Protocol, Exploits Dozens of Flaws appeared first on SecurityWeek. <a href="https://tsecurity.de/weiterlesen/1000018012/4240609/linux-backdoor-abuses-stun-protocol-exploits-dozens-of-flaws/" target="_blank" rel="noopener noreferrer">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[One hidden Meta Muse setting could let attackers turn the AI assistant into a backdoor]]></title>
<description><![CDATA[Meta Muse is designed to act as a personal AI assistant across a Mac and connected devices – much like the new Siri AI released with… This article has been indexed from Panda Security Mediacenter Read the original article: One hidden Meta Muse setting could let attackers turn the AI assistant int...]]></description>
<link>https://tsecurity.de/de/4239923/it-security-nachrichten/one-hidden-meta-muse-setting-could-let-attackers-turn-the-ai-assistant-into-a-backdoor/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4239923/it-security-nachrichten/one-hidden-meta-muse-setting-could-let-attackers-turn-the-ai-assistant-into-a-backdoor/</guid>
<pubDate>Mon, 05 Oct 2026 10:24:51 +0200</pubDate>
<content:encoded><![CDATA[<p>Meta Muse is designed to act as a personal AI assistant across a Mac and connected devices – much like the new Siri AI released with… This article has been indexed from Panda Security Mediacenter Read the original article: One hidden Meta Muse setting could let attackers turn the AI assistant into a backdoor The post One hidden Meta Muse setting... <a href="https://tsecurity.de/weiterlesen/1000017326/4239923/one-hidden-meta-muse-setting-could-let-attackers-turn-the-ai-assistant-into-a-backdoor/" target="_blank" rel="noopener noreferrer">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Neue macOS-Backdoor "CloudSyncD" tarnt sich als Zoom-Installer]]></title>
<description><![CDATA[Die Experten der Jamf Threat Labs haben mit "CloudSyncD" eine neue zweistufige macOS-Backdoor analysiert. Die Malware tarnt sich als legitimer Zoom-Installer und fordert Nutzer dazu auf, die Sicherheitsfunktionen (Gatekeeper) von macOS zu umgehen und ihr Anmeldepasswort einzugeben. Die Jamf Threa...]]></description>
<link>https://tsecurity.de/de/4237704/malware-trojaner-viren/neue-macos-backdoor-cloudsyncd-tarnt-sich-als-zoom-installer/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4237704/malware-trojaner-viren/neue-macos-backdoor-cloudsyncd-tarnt-sich-als-zoom-installer/</guid>
<pubDate>Sun, 04 Oct 2026 00:17:45 +0200</pubDate>
<content:encoded><![CDATA[<p>Die Experten der Jamf Threat Labs haben mit &quot;CloudSyncD&quot; eine neue zweistufige macOS-Backdoor analysiert. Die Malware tarnt sich als legitimer Zoom-Installer und fordert Nutzer dazu auf, die Sicherheitsfunktionen (Gatekeeper) von macOS zu umgehen und ihr Anmeldepasswort einzugeben. Die Jamf Threat … Weiterlesen → Quelle <a href="https://tsecurity.de/weiterlesen/1000015107/4237704/neue-macos-backdoor-cloudsyncd-tarnt-sich-als-zoom-installer/" target="_blank" rel="noopener noreferrer">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Fake Zoom installer hides macOS backdoor CloudSyncD]]></title>
<description><![CDATA[Jamf Threat Labs details CloudSyncD, a fake macOS Zoom installer that hides a phished password using invisible zero-width Unicode characters. Jamf Threat Labs found CloudSyncD while doing routine scanning on VirusTotal, buried inside a disguised Zoom client. They first spotted it on September 15,...]]></description>
<link>https://tsecurity.de/de/4237391/it-security-nachrichten/fake-zoom-installer-hides-macos-backdoor-cloudsyncd/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4237391/it-security-nachrichten/fake-zoom-installer-hides-macos-backdoor-cloudsyncd/</guid>
<pubDate>Sat, 03 Oct 2026 18:45:53 +0200</pubDate>
<content:encoded><![CDATA[<p>Jamf Threat Labs details CloudSyncD, a fake macOS Zoom installer that hides a phished password using invisible zero-width Unicode characters. Jamf Threat Labs found CloudSyncD while doing routine scanning on VirusTotal, buried inside a disguised Zoom client. They first spotted it on September 15, clearly still under construction, and within two... <a href="https://tsecurity.de/weiterlesen/1000014794/4237391/fake-zoom-installer-hides-macos-backdoor-cloudsyncd/" target="_blank" rel="noopener noreferrer">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Fake Zoom installer hides macOS backdoor CloudSyncD]]></title>
<description><![CDATA[Jamf Threat Labs details CloudSyncD, a fake macOS Zoom installer that hides a phished password using invisible zero-width Unicode characters. Jamf Threat Labs found CloudSyncD while doing routine scanning on VirusTotal, buried inside a disguised Zoom client. They first spotted it on September 15,...]]></description>
<link>https://tsecurity.de/de/4237346/hacking-pentesting/fake-zoom-installer-hides-macos-backdoor-cloudsyncd/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4237346/hacking-pentesting/fake-zoom-installer-hides-macos-backdoor-cloudsyncd/</guid>
<pubDate>Sat, 03 Oct 2026 18:32:10 +0200</pubDate>
<content:encoded><![CDATA[<p>Jamf Threat Labs details CloudSyncD, a fake macOS Zoom installer that hides a phished password using invisible zero-width Unicode characters. Jamf Threat Labs found CloudSyncD while doing routine scanning on VirusTotal, buried inside a disguised Zoom client. They first spotted it on September 15, clearly still under construction, and within two... <a href="https://tsecurity.de/weiterlesen/1000014749/4237346/fake-zoom-installer-hides-macos-backdoor-cloudsyncd/" target="_blank" rel="noopener noreferrer">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CloudSyncD MacOS Backdoor Used Fake Zoom Installer to Steal Passwords]]></title>
<description><![CDATA[Cybersecurity researchers have identified a new macOS backdoor called CloudSyncD that uses a fake Zoom installer to trick users into providing their computer passwords. The malware was discovered by Jamf Threat Labs and uses a two-stage infection process to gain elevated access and communicate wi...]]></description>
<link>https://tsecurity.de/de/4237172/malware-trojaner-viren/cloudsyncd-macos-backdoor-used-fake-zoom-installer-to-steal-passwords/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4237172/malware-trojaner-viren/cloudsyncd-macos-backdoor-used-fake-zoom-installer-to-steal-passwords/</guid>
<pubDate>Sat, 03 Oct 2026 16:02:18 +0200</pubDate>
<content:encoded><![CDATA[<p>Cybersecurity researchers have identified a new macOS backdoor called CloudSyncD that uses a fake Zoom installer to trick users into providing their computer passwords. The malware was discovered by Jamf Threat Labs and uses a two-stage infection process to gain elevated access and communicate with attacker-controlled servers. One of the most... <a href="https://tsecurity.de/weiterlesen/1000014575/4237172/cloudsyncd-macos-backdoor-used-fake-zoom-installer-to-steal-passwords/" target="_blank" rel="noopener noreferrer">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Antino Backdoor Lets China-Linked UAT-11587 Turn Microsoft 365 Into a C2 Channel]]></title>
<description><![CDATA[Cisco Talos details UAT-11587, a China-linked group using the Antino backdoor and Microsoft 365 as cover to spy on Asian governments. Cisco Talos has been tracking a cluster of espionage activity since September 2025 that it calls UAT-11587, and by July 2026 the group had hit at least 16 governme...]]></description>
<link>https://tsecurity.de/de/4236907/it-security-nachrichten/antino-backdoor-lets-china-linked-uat-11587-turn-microsoft-365-into-a-c2-channel/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4236907/it-security-nachrichten/antino-backdoor-lets-china-linked-uat-11587-turn-microsoft-365-into-a-c2-channel/</guid>
<pubDate>Sat, 03 Oct 2026 12:23:42 +0200</pubDate>
<content:encoded><![CDATA[<p>Cisco Talos details UAT-11587, a China-linked group using the Antino backdoor and Microsoft 365 as cover to spy on Asian governments. Cisco Talos has been tracking a cluster of espionage activity since September 2025 that it calls UAT-11587, and by July 2026 the group had hit at least 16 government and policy organizations across eight Asian... <a href="https://tsecurity.de/weiterlesen/1000014310/4236907/antino-backdoor-lets-china-linked-uat-11587-turn-microsoft-365-into-a-c2-channel/" target="_blank" rel="noopener noreferrer">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Antino Backdoor Lets China-Linked UAT-11587 Turn Microsoft 365 Into a C2 Channel]]></title>
<description><![CDATA[Cisco Talos details UAT-11587, a China-linked group using the Antino backdoor and Microsoft 365 as cover to spy on Asian governments. Cisco Talos has been tracking a cluster of espionage activity since September 2025 that it calls UAT-11587, and by July 2026 the group had hit at least 16 governme...]]></description>
<link>https://tsecurity.de/de/4236887/hacking-pentesting/antino-backdoor-lets-china-linked-uat-11587-turn-microsoft-365-into-a-c2-channel/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4236887/hacking-pentesting/antino-backdoor-lets-china-linked-uat-11587-turn-microsoft-365-into-a-c2-channel/</guid>
<pubDate>Sat, 03 Oct 2026 12:16:55 +0200</pubDate>
<content:encoded><![CDATA[<p>Cisco Talos details UAT-11587, a China-linked group using the Antino backdoor and Microsoft 365 as cover to spy on Asian governments. Cisco Talos has been tracking a cluster of espionage activity since September 2025 that it calls UAT-11587, and by July 2026 the group had hit at least 16 government and policy organizations across eight Asian... <a href="https://tsecurity.de/weiterlesen/1000014290/4236887/antino-backdoor-lets-china-linked-uat-11587-turn-microsoft-365-into-a-c2-channel/" target="_blank" rel="noopener noreferrer">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CloudSyncD: Fake Zoom Installer Hides Password with Zero-Width Unicode and Launches macOS Backdoor]]></title>
<description><![CDATA[1. Basic Information Original Title: CloudSyncD: a two-stage macOS backdoor that hides a phished password in zero-width Unicode Source: Jamf Threat Labs Publication Date: 2026-09-30 Update Date: None Severity: High Basis of Severity: Exploitation requires the victim to bypass Gatekeeper and enter...]]></description>
<link>https://tsecurity.de/de/4236228/sichere-programmierung/cloudsyncd-fake-zoom-installer-hides-password-with-zero-width-unicode-and-launches-macos-backdoor/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4236228/sichere-programmierung/cloudsyncd-fake-zoom-installer-hides-password-with-zero-width-unicode-and-launches-macos-backdoor/</guid>
<pubDate>Sat, 03 Oct 2026 02:57:33 +0200</pubDate>
<content:encoded><![CDATA[<p>1. Basic Information Original Title: CloudSyncD: a two-stage macOS backdoor that hides a phished password in zero-width Unicode Source: Jamf Threat Labs Publication Date: 2026-09-30 Update Date: None Severity: High Basis of Severity: Exploitation requires the victim to bypass Gatekeeper and enter a valid administrator password. If successful, the... <a href="https://tsecurity.de/weiterlesen/1000013631/4236228/cloudsyncd-fake-zoom-installer-hides-password-with-zero-width-unicode-and-launches-macos-backdoor/" target="_blank" rel="noopener noreferrer">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Antino-Backdoor nutzt Outlook und OneDrive als C2-Kanal für Espionage]]></title>
<description><![CDATA[LONDON (IT BOLTWISE) – Eine neue Espionage-Kampagne setzt auf eine bislang undokumentierte Rust-basierte Windows-Backdoor namens Antino. Laut Cisco Talos läuft der Command-and-Control-Kanal ausschließlich über Microsoft 365: Outlook dient dem Nachrichtenaustausch, OneDrive als Speicher für Datei-...]]></description>
<link>https://tsecurity.de/de/4235742/sichere-programmierung/antino-backdoor-nutzt-outlook-und-onedrive-als-c2-kanal-fuer-espionage/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4235742/sichere-programmierung/antino-backdoor-nutzt-outlook-und-onedrive-als-c2-kanal-fuer-espionage/</guid>
<pubDate>Fri, 02 Oct 2026 20:52:16 +0200</pubDate>
<content:encoded><![CDATA[<p>LONDON (IT BOLTWISE) – Eine neue Espionage-Kampagne setzt auf eine bislang undokumentierte Rust-basierte Windows-Backdoor namens Antino. Laut Cisco Talos läuft der Command-and-Control-Kanal ausschließlich über Microsoft 365: Outlook dient dem Nachrichtenaustausch, OneDrive als Speicher für Datei- und Status-Updates. Der Einstieg erfolgt über... <a href="https://tsecurity.de/weiterlesen/1000013145/4235742/antino-backdoor-nutzt-outlook-und-onedrive-als-c2-kanal-fuer-espionage/" target="_blank" rel="noopener noreferrer">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Antino Backdoor Uses Outlook and OneDrive for C2 in China-Nexus Espionage Campaign]]></title>
<description><![CDATA[Government and policy organizations across Asia have become the target of a new campaign orchestrated by a China-nexus threat actor. The activity, which has targeted government and policy organizations in Taiwan, India, the Philippines, Cambodia, Pakistan, Thailand, and Myanmar, involves the depl...]]></description>
<link>https://tsecurity.de/de/4235637/it-security-nachrichten/antino-backdoor-uses-outlook-and-onedrive-for-c2-in-china-nexus-espionage-campaign/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4235637/it-security-nachrichten/antino-backdoor-uses-outlook-and-onedrive-for-c2-in-china-nexus-espionage-campaign/</guid>
<pubDate>Fri, 02 Oct 2026 19:49:39 +0200</pubDate>
<content:encoded><![CDATA[<p>Government and policy organizations across Asia have become the target of a new campaign orchestrated by a China-nexus threat actor. The activity, which has targeted government and policy organizations in Taiwan, India, the Philippines, Cambodia, Pakistan, Thailand, and Myanmar, involves the deployment of a previously undocumented backdoor... <a href="https://tsecurity.de/weiterlesen/1000013040/4235637/antino-backdoor-uses-outlook-and-onedrive-for-c2-in-china-nexus-espionage-campaign/" target="_blank" rel="noopener noreferrer">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[New CloudSyncD macOS Backdoor Uses Fake Zoom Installer to Steal Passwords]]></title>
<description><![CDATA[CloudSyncD macOS backdoor uses a fake Zoom installer to steal Mac passwords, bypass Gatekeeper and connect infected devices to remote C2 servers. Weiterlesen]]></description>
<link>https://tsecurity.de/de/4235543/it-security-nachrichten/new-cloudsyncd-macos-backdoor-uses-fake-zoom-installer-to-steal-passwords/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4235543/it-security-nachrichten/new-cloudsyncd-macos-backdoor-uses-fake-zoom-installer-to-steal-passwords/</guid>
<pubDate>Fri, 02 Oct 2026 19:26:12 +0200</pubDate>
<content:encoded><![CDATA[<p>CloudSyncD macOS backdoor uses a fake Zoom installer to steal Mac passwords, bypass Gatekeeper and connect infected devices to remote C2 servers. <a href="https://tsecurity.de/weiterlesen/1000012946/4235543/new-cloudsyncd-macos-backdoor-uses-fake-zoom-installer-to-steal-passwords/" target="_blank" rel="noopener noreferrer">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[SC-Backdoor: WordPress-Persistenz über Dateien, DB und Shared Memory neu gebaut]]></title>
<description><![CDATA[LONDON (IT BOLTWISE) – Sicherheitsforscher beschreiben eine WordPress-Backdoor, die sich nach Bereinigung selbst neu aufbaut. Laut Bericht verteilt sie identische Komponenten über Dateien, Datenbankeinträge und System-V-Shared-Memory, sodass keine einzelne Maßnahme das Ganze zuverlässig stoppt. D...]]></description>
<link>https://tsecurity.de/de/4235529/it-security-nachrichten/sc-backdoor-wordpress-persistenz-ueber-dateien-db-und-shared-memory-neu-gebaut/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4235529/it-security-nachrichten/sc-backdoor-wordpress-persistenz-ueber-dateien-db-und-shared-memory-neu-gebaut/</guid>
<pubDate>Fri, 02 Oct 2026 19:26:07 +0200</pubDate>
<content:encoded><![CDATA[<p>LONDON (IT BOLTWISE) – Sicherheitsforscher beschreiben eine WordPress-Backdoor, die sich nach Bereinigung selbst neu aufbaut. Laut Bericht verteilt sie identische Komponenten über Dateien, Datenbankeinträge und System-V-Shared-Memory, sodass keine einzelne Maßnahme das Ganze zuverlässig stoppt. Der Angreifer nutzt zudem eine Decoder-Logik mit... <a href="https://tsecurity.de/weiterlesen/1000012932/4235529/sc-backdoor-wordpress-persistenz-ueber-dateien-db-und-shared-memory-neu-gebaut/" target="_blank" rel="noopener noreferrer">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[macOS Users Targeted by Fake Zoom Installer Carrying CloudSyncD Backdoor]]></title>
<description><![CDATA[The dropper “carries a complete universal Mach-O inside itself, roughly 756 KB in the development build, and extracts it at runtime. The post macOS Users Targeted by Fake Zoom Installer Carrying CloudSyncD Backdoor appeared first on SecurityWeek. Weiterlesen]]></description>
<link>https://tsecurity.de/de/4235330/it-security-nachrichten/macos-users-targeted-by-fake-zoom-installer-carrying-cloudsyncd-backdoor/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4235330/it-security-nachrichten/macos-users-targeted-by-fake-zoom-installer-carrying-cloudsyncd-backdoor/</guid>
<pubDate>Fri, 02 Oct 2026 19:22:17 +0200</pubDate>
<content:encoded><![CDATA[<p>The dropper “carries a complete universal Mach-O inside itself, roughly 756 KB in the development build, and extracts it at runtime. The post macOS Users Targeted by Fake Zoom Installer Carrying CloudSyncD Backdoor appeared first on SecurityWeek. <a href="https://tsecurity.de/weiterlesen/1000012733/4235330/macos-users-targeted-by-fake-zoom-installer-carrying-cloudsyncd-backdoor/" target="_blank" rel="noopener noreferrer">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[WordPress Backdoor Rebuilds Itself After Cleanup Using Files, Database, and Shared Memory]]></title>
<description><![CDATA[Cybersecurity researchers have shed light on a WordPress compromise in which threat actors deployed multiple persistence mechanisms to ensure that the final payload kept returning without having to infect the site again. The backdoor has been codenamed SC after the "SC_" markers present in the in...]]></description>
<link>https://tsecurity.de/de/4235302/malware-trojaner-viren/wordpress-backdoor-rebuilds-itself-after-cleanup-using-files-database-and-shared-memory/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4235302/malware-trojaner-viren/wordpress-backdoor-rebuilds-itself-after-cleanup-using-files-database-and-shared-memory/</guid>
<pubDate>Fri, 02 Oct 2026 19:22:11 +0200</pubDate>
<content:encoded><![CDATA[<p>Cybersecurity researchers have shed light on a WordPress compromise in which threat actors deployed multiple persistence mechanisms to ensure that the final payload kept returning without having to infect the site again. The backdoor has been codenamed SC after the &quot;SC_&quot; markers present in the injected content. Sucuri has described the malware as... <a href="https://tsecurity.de/weiterlesen/1000012705/4235302/wordpress-backdoor-rebuilds-itself-after-cleanup-using-files-database-and-shared-memory/" target="_blank" rel="noopener noreferrer">Weiterlesen</a></p>]]></content:encoded>
</item>
</channel>
</rss>
<!-- Generated in 3,68ms -->