<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="/rss-style.xsl"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:media="http://search.yahoo.com/mrss/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/">
<channel>
<title><![CDATA[tsecurity.de - News Radar & Live Feeds]]></title>
<link><![CDATA[https://tsecurity.de/rss/0/Malware]]></link>
<description><![CDATA[Aktuelle Nachrichten und Updates auf tsecurity.de]]></description>
<language>de-DE</language>
<lastBuildDate>Tue, 06 Oct 2026 05:40:05 +0200</lastBuildDate>
<pubDate>Tue, 06 Oct 2026 05:40:05 +0200</pubDate>
<ttl>15</ttl>
<copyright>2026 tsecurity.de - News Radar &amp; Live Feeds</copyright>
<managingEditor>contact@tsecurity.de (tsecurity.de)</managingEditor>
<webMaster>contact@tsecurity.de (tsecurity.de)</webMaster>
<image>
<url>https://tsecurity.de/templates/mydraft-basis-tsecurity.de/media/logo.png</url>
<title><![CDATA[tsecurity.de - News Radar & Live Feeds]]></title>
<link><![CDATA[https://tsecurity.de/rss/0/Malware]]></link>
</image>
<atom:link href="https://tsecurity.de/rss/0/Malware" rel="self" type="application/rss+xml" />
<item>
<title><![CDATA[Recovering a removed npm malware file using Software Heritage and a surviving CDN digest]]></title>
<description><![CDATA[I wrote up my investigation into @goodjavascript/dotenv@1.0.0, including how to recover its entry-point file after the npm tarball and jsDelivr file URLs returned 404. The useful detail: Software Heritage’s latest snapshot contained only the security placeholder. An older snapshot retained the or...]]></description>
<link>https://tsecurity.de/de/4241947/malware-trojaner-viren/recovering-a-removed-npm-malware-file-using-software-heritage-and-a-surviving-cdn-digest/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4241947/malware-trojaner-viren/recovering-a-removed-npm-malware-file-using-software-heritage-and-a-surviving-cdn-digest/</guid>
<pubDate>Tue, 06 Oct 2026 03:12:40 +0200</pubDate>
<content:encoded><![CDATA[<p>I wrote up my investigation into @goodjavascript/dotenv@1.0.0, including how to recover its entry-point file after the npm tarball and jsDelivr file URLs returned 404. The useful detail: Software Heritage’s latest snapshot contained only the security placeholder. An older snapshot retained the original release and its 840-byte index.js. Its... <a href="https://tsecurity.de/weiterlesen/1000019350/4241947/recovering-a-removed-npm-malware-file-using-software-heritage-and-a-surviving-cdn-digest/" target="_blank" rel="noopener noreferrer">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Fake ChatGPT Helpers Are Spreading Malware. Here Is How to Spot Them.]]></title>
<description><![CDATA[Author: Katie Boquetti | Editorial: Craig Taylor Editorial by Craig Taylor: A CAPTCHA should test whether you’re human. It should not audition you for the IT department. If “prove you’re human” means opening PowerShell, the only command you need is: close the tab. Criminals call their instruction...]]></description>
<link>https://tsecurity.de/de/4241747/malware-trojaner-viren/fake-chatgpt-helpers-are-spreading-malware-here-is-how-to-spot-them/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4241747/malware-trojaner-viren/fake-chatgpt-helpers-are-spreading-malware-here-is-how-to-spot-them/</guid>
<pubDate>Mon, 05 Oct 2026 23:54:46 +0200</pubDate>
<content:encoded><![CDATA[<p>Author: Katie Boquetti | Editorial: Craig Taylor Editorial by Craig Taylor: A CAPTCHA should test whether you’re human. It should not audition you for the IT department. If “prove you’re human” means opening PowerShell, the only command you need is: close the tab. Criminals call their instructions a fix. Security researchers call the trick... <a href="https://tsecurity.de/weiterlesen/1000019150/4241747/fake-chatgpt-helpers-are-spreading-malware-here-is-how-to-spot-them/" target="_blank" rel="noopener noreferrer">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Gratis-Tool gegen Online-Betrug: Malwarebytes prüft verdächtige Links, bevor ihr klickt]]></title>
<description><![CDATA[Ein neuer Dienst von Malwarebytes prüft verdächtige Links, bevor ihr sie öffnet. Das soll Phishing und andere Online-Betrugsmaschen schneller erkennbar machen. Dieser Artikel wurde einsortiert unter Datenschutz, Schutz vor Malware, Trojanern &amp; Spyware, Aktuelle Betrugswarnungen. Weiterlesen]]></description>
<link>https://tsecurity.de/de/4241531/malware-trojaner-viren/gratis-tool-gegen-online-betrug-malwarebytes-prueft-verdaechtige-links-bevor-ihr-klickt/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4241531/malware-trojaner-viren/gratis-tool-gegen-online-betrug-malwarebytes-prueft-verdaechtige-links-bevor-ihr-klickt/</guid>
<pubDate>Mon, 05 Oct 2026 21:31:54 +0200</pubDate>
<content:encoded><![CDATA[<p>Ein neuer Dienst von Malwarebytes prüft verdächtige Links, bevor ihr sie öffnet. Das soll Phishing und andere Online-Betrugsmaschen schneller erkennbar machen. Dieser Artikel wurde einsortiert unter Datenschutz, Schutz vor Malware, Trojanern &amp;amp; Spyware, Aktuelle Betrugswarnungen. <a href="https://tsecurity.de/weiterlesen/1000018934/4241531/gratis-tool-gegen-online-betrug-malwarebytes-prueft-verdaechtige-links-bevor-ihr-klickt/" target="_blank" rel="noopener noreferrer">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Malwarebytes Scam Link Check analyzes URLs and explains potential risks]]></title>
<description><![CDATA[Malwarebytes has launched the Malwarebytes Scam Link Check, a free web tool that lets anyone check whether a website link is safe or dangerous before clicking it. Users paste any suspicious URL, the kind that arrives by text, email, chat, or social media, and the tool returns a safety result, alo...]]></description>
<link>https://tsecurity.de/de/4240892/it-security-nachrichten/malwarebytes-scam-link-check-analyzes-urls-and-explains-potential-risks/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4240892/it-security-nachrichten/malwarebytes-scam-link-check-analyzes-urls-and-explains-potential-risks/</guid>
<pubDate>Mon, 05 Oct 2026 16:48:35 +0200</pubDate>
<content:encoded><![CDATA[<p>Malwarebytes has launched the Malwarebytes Scam Link Check, a free web tool that lets anyone check whether a website link is safe or dangerous before clicking it. Users paste any suspicious URL, the kind that arrives by text, email, chat, or social media, and the tool returns a safety result, along with the reasons behind it and recommended next... <a href="https://tsecurity.de/weiterlesen/1000018295/4240892/malwarebytes-scam-link-check-analyzes-urls-and-explains-potential-risks/" target="_blank" rel="noopener noreferrer">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[ClingSTUN Malware Turns Unpatched IoT Devices Into Proxy Nodes]]></title>
<description><![CDATA[ClingSTUN exploits known IoT flaws and abuses public STUN servers to keep proxy access to devices Weiterlesen]]></description>
<link>https://tsecurity.de/de/4240889/malware-trojaner-viren/clingstun-malware-turns-unpatched-iot-devices-into-proxy-nodes/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4240889/malware-trojaner-viren/clingstun-malware-turns-unpatched-iot-devices-into-proxy-nodes/</guid>
<pubDate>Mon, 05 Oct 2026 16:48:19 +0200</pubDate>
<content:encoded><![CDATA[<p>ClingSTUN exploits known IoT flaws and abuses public STUN servers to keep proxy access to devices <a href="https://tsecurity.de/weiterlesen/1000018292/4240889/clingstun-malware-turns-unpatched-iot-devices-into-proxy-nodes/" target="_blank" rel="noopener noreferrer">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[GlassWorm Supply Chain Attack Uses Fake VS Code Themes to Deliver Hidden Malware]]></title>
<description><![CDATA[GlassWorm is turning developer tools into malware delivery channels, this time through extensions advertised as attractive VS Code themes. The investigated cluster spans Visual Studio Marketplace and Open VSX, showing how appearance changes can provide cover for code that runs on developer machin...]]></description>
<link>https://tsecurity.de/de/4240649/malware-trojaner-viren/glassworm-supply-chain-attack-uses-fake-vs-code-themes-to-deliver-hidden-malware/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4240649/malware-trojaner-viren/glassworm-supply-chain-attack-uses-fake-vs-code-themes-to-deliver-hidden-malware/</guid>
<pubDate>Mon, 05 Oct 2026 15:19:08 +0200</pubDate>
<content:encoded><![CDATA[<p>GlassWorm is turning developer tools into malware delivery channels, this time through extensions advertised as attractive VS Code themes. The investigated cluster spans Visual Studio Marketplace and Open VSX, showing how appearance changes can provide cover for code that runs on developer machines. The campaign first surfaced in October 2025 and... <a href="https://tsecurity.de/weiterlesen/1000018052/4240649/glassworm-supply-chain-attack-uses-fake-vs-code-themes-to-deliver-hidden-malware/" target="_blank" rel="noopener noreferrer">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[ClickFix Fake CAPTCHA Attack Executes Malware Hidden Inside Browser Cache]]></title>
<description><![CDATA[A new ClickFix campaign is turning a web safety check into a route for malware. Visitors to compromised websites see a fake CAPTCHA or repair message and are told to open the Windows Run dialog, paste copied text, and press Enter. The instruction looks simple, but it makes the victim run the atta...]]></description>
<link>https://tsecurity.de/de/4240647/malware-trojaner-viren/clickfix-fake-captcha-attack-executes-malware-hidden-inside-browser-cache/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4240647/malware-trojaner-viren/clickfix-fake-captcha-attack-executes-malware-hidden-inside-browser-cache/</guid>
<pubDate>Mon, 05 Oct 2026 15:19:05 +0200</pubDate>
<content:encoded><![CDATA[<p>A new ClickFix campaign is turning a web safety check into a route for malware. Visitors to compromised websites see a fake CAPTCHA or repair message and are told to open the Windows Run dialog, paste copied text, and press Enter. The instruction looks simple, but it makes the victim run the attacker’s command. The campaign is concerning because... <a href="https://tsecurity.de/weiterlesen/1000018050/4240647/clickfix-fake-captcha-attack-executes-malware-hidden-inside-browser-cache/" target="_blank" rel="noopener noreferrer">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Alleged dev of Ploutus ATM malware appears in US court after arrest]]></title>
<description><![CDATA[The U.S. Department of Justice has announced the arrest of the alleged developer of Ploutus malware, used to steal millions of dollars in ATM jackpotting attacks across the United States. [...] Weiterlesen]]></description>
<link>https://tsecurity.de/de/4240612/malware-trojaner-viren/alleged-dev-of-ploutus-atm-malware-appears-in-us-court-after-arrest/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4240612/malware-trojaner-viren/alleged-dev-of-ploutus-atm-malware-appears-in-us-court-after-arrest/</guid>
<pubDate>Mon, 05 Oct 2026 15:12:40 +0200</pubDate>
<content:encoded><![CDATA[<p>The U.S. Department of Justice has announced the arrest of the alleged developer of Ploutus malware, used to steal millions of dollars in ATM jackpotting attacks across the United States. [...] <a href="https://tsecurity.de/weiterlesen/1000018015/4240612/alleged-dev-of-ploutus-atm-malware-appears-in-us-court-after-arrest/" target="_blank" rel="noopener noreferrer">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Malicious VS Code Themes Hide GlassWorm Malware Targeting Developers]]></title>
<description><![CDATA[A group of VS Code theme extensions linked to GlassWorm, a malware campaign targeting developers. Their investigation identified two confirmed malicious extensions and several related themes across the Visual Studio Marketplace and Open VSX registry. Two suspicious themes, Coca-Cola Christmas and...]]></description>
<link>https://tsecurity.de/de/4239782/malware-trojaner-viren/malicious-vs-code-themes-hide-glassworm-malware-targeting-developers/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4239782/malware-trojaner-viren/malicious-vs-code-themes-hide-glassworm-malware-targeting-developers/</guid>
<pubDate>Mon, 05 Oct 2026 09:23:41 +0200</pubDate>
<content:encoded><![CDATA[<p>A group of VS Code theme extensions linked to GlassWorm, a malware campaign targeting developers. Their investigation identified two confirmed malicious extensions and several related themes across the Visual Studio Marketplace and Open VSX registry. Two suspicious themes, Coca-Cola Christmas and Aurora Borealis Studio Theme, had collected more... <a href="https://tsecurity.de/weiterlesen/1000017185/4239782/malicious-vs-code-themes-hide-glassworm-malware-targeting-developers/" target="_blank" rel="noopener noreferrer">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[GlassWorm Supply Chain Attack Hides Malware Inside VS Code Color Themes]]></title>
<description><![CDATA[A GlassWorm-linked software supply chain campaign has abused seemingly harmless Visual Studio Code color themes to distribute malicious loaders across the Visual Studio Marketplace and Open VSX Registry. The activity demonstrates how extensions designed only to change editor colors can become hig...]]></description>
<link>https://tsecurity.de/de/4239660/malware-trojaner-viren/glassworm-supply-chain-attack-hides-malware-inside-vs-code-color-themes/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4239660/malware-trojaner-viren/glassworm-supply-chain-attack-hides-malware-inside-vs-code-color-themes/</guid>
<pubDate>Mon, 05 Oct 2026 08:27:04 +0200</pubDate>
<content:encoded><![CDATA[<p>A GlassWorm-linked software supply chain campaign has abused seemingly harmless Visual Studio Code color themes to distribute malicious loaders across the Visual Studio Marketplace and Open VSX Registry. The activity demonstrates how extensions designed only to change editor colors can become high-impact initial-access vectors when they include... <a href="https://tsecurity.de/weiterlesen/1000017063/4239660/glassworm-supply-chain-attack-hides-malware-inside-vs-code-color-themes/" target="_blank" rel="noopener noreferrer">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[SniffDog: I built my job-hunting friend a sniffer dog that sniffs out malware in fake recruiter repos]]></title>
<description><![CDATA[This is a submission for the Hacktoberfest Weekend Challenge: Build for a Friend What I Built SniffDog checks a take-home coding assignment before you run it. It reads the repo, never executes it, and tells you in plain English whether it's safe to open. I built it for my friend Mayank Raj. Earli...]]></description>
<link>https://tsecurity.de/de/4239135/malware-trojaner-viren/sniffdog-i-built-my-job-hunting-friend-a-sniffer-dog-that-sniffs-out-malware-in-fake-recruiter-repos/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4239135/malware-trojaner-viren/sniffdog-i-built-my-job-hunting-friend-a-sniffer-dog-that-sniffs-out-malware-in-fake-recruiter-repos/</guid>
<pubDate>Mon, 05 Oct 2026 00:32:58 +0200</pubDate>
<content:encoded><![CDATA[<p>This is a submission for the Hacktoberfest Weekend Challenge: Build for a Friend What I Built SniffDog checks a take-home coding assignment before you run it. It reads the repo, never executes it, and tells you in plain English whether it&#039;s safe to open. I built it for my friend Mayank Raj. Earlier this year, Mayank, a final-year student hunting... <a href="https://tsecurity.de/weiterlesen/1000016538/4239135/sniffdog-i-built-my-job-hunting-friend-a-sniffer-dog-that-sniffs-out-malware-in-fake-recruiter-repos/" target="_blank" rel="noopener noreferrer">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 117]]></title>
<description><![CDATA[Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape Malware Newsletter Lunex Unmasked: A New Information Stealer Deployed Through BYOVD   Storm-3168: Agentic-driven cloud attacks using compromised service principals...]]></description>
<link>https://tsecurity.de/de/4238645/malware-trojaner-viren/security-affairs-malware-newsletter-round-117/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4238645/malware-trojaner-viren/security-affairs-malware-newsletter-round-117/</guid>
<pubDate>Sun, 04 Oct 2026 16:49:10 +0200</pubDate>
<content:encoded><![CDATA[<p>Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape Malware Newsletter Lunex Unmasked: A New Information Stealer Deployed Through BYOVD   Storm-3168: Agentic-driven cloud attacks using compromised service principals   Don’t Call Us, We’ll Call Your APIs |... <a href="https://tsecurity.de/weiterlesen/1000016048/4238645/security-affairs-malware-newsletter-round-117/" target="_blank" rel="noopener noreferrer">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Cracked open the Google IPTV malware APK and found its C2 domain]]></title>
<description><![CDATA[submitted by /u/acealter [link] [comments] Weiterlesen]]></description>
<link>https://tsecurity.de/de/4238176/malware-trojaner-viren/cracked-open-the-google-iptv-malware-apk-and-found-its-c2-domain/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4238176/malware-trojaner-viren/cracked-open-the-google-iptv-malware-apk-and-found-its-c2-domain/</guid>
<pubDate>Sun, 04 Oct 2026 10:22:17 +0200</pubDate>
<content:encoded><![CDATA[<p>submitted by /u/acealter [link] [comments] <a href="https://tsecurity.de/weiterlesen/1000015579/4238176/cracked-open-the-google-iptv-malware-apk-and-found-its-c2-domain/" target="_blank" rel="noopener noreferrer">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[WordPress Hacked: Malware Removal and Recovery Guide]]></title>
<description><![CDATA[If your WordPress site was hacked and is now showing pharmaceutical spam, redirecting visitors to somewhere unpleasant, or has been flagged by Google as deceptive, start here rather than with a plugin. The instinct is to install a security scanner and click clean. That removes the visible symptom...]]></description>
<link>https://tsecurity.de/de/4237455/malware-trojaner-viren/wordpress-hacked-malware-removal-and-recovery-guide/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4237455/malware-trojaner-viren/wordpress-hacked-malware-removal-and-recovery-guide/</guid>
<pubDate>Sat, 03 Oct 2026 20:04:37 +0200</pubDate>
<content:encoded><![CDATA[<p>If your WordPress site was hacked and is now showing pharmaceutical spam, redirecting visitors to somewhere unpleasant, or has been flagged by Google as deceptive, start here rather than with a plugin. The instinct is to install a security scanner and click clean. That removes the visible symptom and leaves the way in, which is why so many sites... <a href="https://tsecurity.de/weiterlesen/1000014858/4237455/wordpress-hacked-malware-removal-and-recovery-guide/" target="_blank" rel="noopener noreferrer">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Google’s Android 17 Locks Accessibility Services to Verified Apps as Malware Threat Branches Out]]></title>
<description><![CDATA[Google is tightening restrictions on one of mobile malware's most persistent entry points. With Android 17, the company is limiting access to its AccessibilityService API to verified Accessibility Tools only, a change that takes effect the moment a user switches on Advanced Protection. The move, ...]]></description>
<link>https://tsecurity.de/de/4237445/malware-trojaner-viren/googles-android-17-locks-accessibility-services-to-verified-apps-as-malware-threat-branches-out/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4237445/malware-trojaner-viren/googles-android-17-locks-accessibility-services-to-verified-apps-as-malware-threat-branches-out/</guid>
<pubDate>Sat, 03 Oct 2026 19:47:12 +0200</pubDate>
<content:encoded><![CDATA[<p>Google is tightening restrictions on one of mobile malware&#039;s most persistent entry points. With Android 17, the company is limiting access to its AccessibilityService API to verified Accessibility Tools only, a change that takes effect the moment a user switches on Advanced Protection. The move, announced Thursday, targets a problem that has... <a href="https://tsecurity.de/weiterlesen/1000014848/4237445/googles-android-17-locks-accessibility-services-to-verified-apps-as-malware-threat-branches-out/" target="_blank" rel="noopener noreferrer">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Cling Malware Masquerades as Google STUN Traffic to Control Compromised IoT Devices]]></title>
<description><![CDATA[A newly identified IoT botnet, Cling, disguises its command-and-control communications as legitimate STUN traffic, including packets that appear to originate from Google’s public STUN infrastructure. The technique enables attackers to manage compromised internet-facing devices while blending acti...]]></description>
<link>https://tsecurity.de/de/4236734/malware-trojaner-viren/cling-malware-masquerades-as-google-stun-traffic-to-control-compromised-iot-devices/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4236734/malware-trojaner-viren/cling-malware-masquerades-as-google-stun-traffic-to-control-compromised-iot-devices/</guid>
<pubDate>Sat, 03 Oct 2026 10:06:53 +0200</pubDate>
<content:encoded><![CDATA[<p>A newly identified IoT botnet, Cling, disguises its command-and-control communications as legitimate STUN traffic, including packets that appear to originate from Google’s public STUN infrastructure. The technique enables attackers to manage compromised internet-facing devices while blending activity into routine NAT-traversal traffic used by... <a href="https://tsecurity.de/weiterlesen/1000014137/4236734/cling-malware-masquerades-as-google-stun-traffic-to-control-compromised-iot-devices/" target="_blank" rel="noopener noreferrer">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Cling IoT Malware Masquerades as Google STUN Traffic to Hide C2 Communications]]></title>
<description><![CDATA[A newly observed IoT botnet named Cling exploits vulnerable internet-facing devices and disguises its command-and-control communications as legitimate STUN traffic, including packets that appear to originate from Google’s public STUN infrastructure. The technique lets operators hide malicious ins...]]></description>
<link>https://tsecurity.de/de/4236436/malware-trojaner-viren/cling-iot-malware-masquerades-as-google-stun-traffic-to-hide-c2-communications/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4236436/malware-trojaner-viren/cling-iot-malware-masquerades-as-google-stun-traffic-to-hide-c2-communications/</guid>
<pubDate>Sat, 03 Oct 2026 06:55:42 +0200</pubDate>
<content:encoded><![CDATA[<p>A newly observed IoT botnet named Cling exploits vulnerable internet-facing devices and disguises its command-and-control communications as legitimate STUN traffic, including packets that appear to originate from Google’s public STUN infrastructure. The technique lets operators hide malicious instructions amid common NAT-traversal traffic used by... <a href="https://tsecurity.de/weiterlesen/1000013839/4236436/cling-iot-malware-masquerades-as-google-stun-traffic-to-hide-c2-communications/" target="_blank" rel="noopener noreferrer">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Free malware analysis, reverse engineering and exploit development resources]]></title>
<description><![CDATA[submitted by /u/Potential-Couple-745 [link] [comments] Weiterlesen]]></description>
<link>https://tsecurity.de/de/4236345/malware-trojaner-viren/free-malware-analysis-reverse-engineering-and-exploit-development-resources/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4236345/malware-trojaner-viren/free-malware-analysis-reverse-engineering-and-exploit-development-resources/</guid>
<pubDate>Sat, 03 Oct 2026 05:04:26 +0200</pubDate>
<content:encoded><![CDATA[<p>submitted by /u/Potential-Couple-745 [link] [comments] <a href="https://tsecurity.de/weiterlesen/1000013748/4236345/free-malware-analysis-reverse-engineering-and-exploit-development-resources/" target="_blank" rel="noopener noreferrer">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Where to get resources and get started with malware dev?]]></title>
<description><![CDATA[So, I am a student persuing b tech cybersecurity course, and am pretty good in networkings and Linux systems. I also have some experience in pentesting, have solved some vulnhub machines on my own and have practiced on tryhackme. For programming, I can code in python, c, and c++. I want to get in...]]></description>
<link>https://tsecurity.de/de/4236342/malware-trojaner-viren/where-to-get-resources-and-get-started-with-malware-dev/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4236342/malware-trojaner-viren/where-to-get-resources-and-get-started-with-malware-dev/</guid>
<pubDate>Sat, 03 Oct 2026 05:04:26 +0200</pubDate>
<content:encoded><![CDATA[<p>So, I am a student persuing b tech cybersecurity course, and am pretty good in networkings and Linux systems. I also have some experience in pentesting, have solved some vulnhub machines on my own and have practiced on tryhackme. For programming, I can code in python, c, and c++. I want to get into malware development, but am not getting any solid... <a href="https://tsecurity.de/weiterlesen/1000013745/4236342/where-to-get-resources-and-get-started-with-malware-dev/" target="_blank" rel="noopener noreferrer">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[This new ChatGPT scam tricks you into installing malware – how to spot the trap]]></title>
<description><![CDATA[This authentic-looking scam starts with a sponsored Google link – and it’s catching people off-guard. Weiterlesen]]></description>
<link>https://tsecurity.de/de/4235706/malware-trojaner-viren/this-new-chatgpt-scam-tricks-you-into-installing-malware-how-to-spot-the-trap/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4235706/malware-trojaner-viren/this-new-chatgpt-scam-tricks-you-into-installing-malware-how-to-spot-the-trap/</guid>
<pubDate>Fri, 02 Oct 2026 20:24:53 +0200</pubDate>
<content:encoded><![CDATA[<p>This authentic-looking scam starts with a sponsored Google link – and it’s catching people off-guard. <a href="https://tsecurity.de/weiterlesen/1000013109/4235706/this-new-chatgpt-scam-tricks-you-into-installing-malware-how-to-spot-the-trap/" target="_blank" rel="noopener noreferrer">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Software Supply Chain Attacks Use Malicious npm Updates to Steal Credentials and Spread Malware]]></title>
<description><![CDATA[Software supply chain attacks are turning trusted developer tools into channels for credential theft and malware delivery. Campaigns involving S1ngularity, Shai-Hulud, and TeamPCP show how compromised packages can expose developer workstations, build systems, and cloud infrastructure through rout...]]></description>
<link>https://tsecurity.de/de/4235537/malware-trojaner-viren/software-supply-chain-attacks-use-malicious-npm-updates-to-steal-credentials-and-spread-malware/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4235537/malware-trojaner-viren/software-supply-chain-attacks-use-malicious-npm-updates-to-steal-credentials-and-spread-malware/</guid>
<pubDate>Fri, 02 Oct 2026 19:26:10 +0200</pubDate>
<content:encoded><![CDATA[<p>Software supply chain attacks are turning trusted developer tools into channels for credential theft and malware delivery. Campaigns involving S1ngularity, Shai-Hulud, and TeamPCP show how compromised packages can expose developer workstations, build systems, and cloud infrastructure through routine software updates. Rather than attacking each... <a href="https://tsecurity.de/weiterlesen/1000012940/4235537/software-supply-chain-attacks-use-malicious-npm-updates-to-steal-credentials-and-spread-malware/" target="_blank" rel="noopener noreferrer">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[SLTT C2 Traffic Tied to Remus Malware Distribution Operation]]></title>
<description><![CDATA[The CIS CTI team identified Remus infostealer distribution activity spanning March through September 2026. Read its analysis. Weiterlesen]]></description>
<link>https://tsecurity.de/de/4235437/malware-trojaner-viren/sltt-c2-traffic-tied-to-remus-malware-distribution-operation/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4235437/malware-trojaner-viren/sltt-c2-traffic-tied-to-remus-malware-distribution-operation/</guid>
<pubDate>Fri, 02 Oct 2026 19:25:27 +0200</pubDate>
<content:encoded><![CDATA[<p>The CIS CTI team identified Remus infostealer distribution activity spanning March through September 2026. Read its analysis. <a href="https://tsecurity.de/weiterlesen/1000012840/4235437/sltt-c2-traffic-tied-to-remus-malware-distribution-operation/" target="_blank" rel="noopener noreferrer">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Malwarebytes Download - Schutz vor Schadsoftware]]></title>
<description><![CDATA[Der Download von Malwarebytes installiert einen starken Schutz vor Schadprogrammen wie Viren oder Ransomware und wehrt selbst die neuesten Bedrohungen ab. Hierzu kombiniert Malwarebytes 5.7.2 verschiedene ... (Weiter lesen) Weiterlesen]]></description>
<link>https://tsecurity.de/de/4235186/malware-trojaner-viren/malwarebytes-download-schutz-vor-schadsoftware/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4235186/malware-trojaner-viren/malwarebytes-download-schutz-vor-schadsoftware/</guid>
<pubDate>Fri, 02 Oct 2026 19:21:23 +0200</pubDate>
<content:encoded><![CDATA[<p>Der Download von Malwarebytes installiert einen starken Schutz vor Schadprogrammen wie Viren oder Ransomware und wehrt selbst die neuesten Bedrohungen ab. Hierzu kombiniert Malwarebytes 5.7.2 verschiedene ... (Weiter lesen) <a href="https://tsecurity.de/weiterlesen/1000012589/4235186/malwarebytes-download-schutz-vor-schadsoftware/" target="_blank" rel="noopener noreferrer">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Hackers Are Turning Trusted Software Updates Into Credential-Stealing Malware]]></title>
<description><![CDATA[A growing wave of supply-chain attacks is proving the opposite: attackers are compromising legitimate open-source packages and using trusted update channels to deploy credential-stealing malware directly into developer and enterprise environments. Malicious Nx releases, published after attackers ...]]></description>
<link>https://tsecurity.de/de/4234530/malware-trojaner-viren/hackers-are-turning-trusted-software-updates-into-credential-stealing-malware/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4234530/malware-trojaner-viren/hackers-are-turning-trusted-software-updates-into-credential-stealing-malware/</guid>
<pubDate>Fri, 02 Oct 2026 19:17:35 +0200</pubDate>
<content:encoded><![CDATA[<p>A growing wave of supply-chain attacks is proving the opposite: attackers are compromising legitimate open-source packages and using trusted update channels to deploy credential-stealing malware directly into developer and enterprise environments. Malicious Nx releases, published after attackers stole an npm publishing token through a GitHub... <a href="https://tsecurity.de/weiterlesen/1000011933/4234530/hackers-are-turning-trusted-software-updates-into-credential-stealing-malware/" target="_blank" rel="noopener noreferrer">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Fake Zoom installer tries to trick Mac users into installing hidden malware]]></title>
<description><![CDATA[A new Mac threat is hiding inside something that looks like a normal Zoom installer, according to security researchers at Jamf Threat Labs. The file opens as a disk named Zoom and looks like the usual Mac installer: an app icon on the left, a shortcut to the Applications folder on the right. The ...]]></description>
<link>https://tsecurity.de/de/4234430/malware-trojaner-viren/fake-zoom-installer-tries-to-trick-mac-users-into-installing-hidden-malware/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4234430/malware-trojaner-viren/fake-zoom-installer-tries-to-trick-mac-users-into-installing-hidden-malware/</guid>
<pubDate>Fri, 02 Oct 2026 19:16:50 +0200</pubDate>
<content:encoded><![CDATA[<p>A new Mac threat is hiding inside something that looks like a normal Zoom installer, according to security researchers at Jamf Threat Labs. The file opens as a disk named Zoom and looks like the usual Mac installer: an app icon on the left, a shortcut to the Applications folder on the right. The catch is a set of instructions printed on the... <a href="https://tsecurity.de/weiterlesen/1000011833/4234430/fake-zoom-installer-tries-to-trick-mac-users-into-installing-hidden-malware/" target="_blank" rel="noopener noreferrer">Weiterlesen</a></p>]]></content:encoded>
</item>
</channel>
</rss>
<!-- Generated in 2,60ms -->