<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="/rss-style.xsl"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:media="http://search.yahoo.com/mrss/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/">
<channel>
<title><![CDATA[tsecurity.de - News Radar & Live Feeds]]></title>
<link><![CDATA[https://tsecurity.de/rss/0/malware]]></link>
<description><![CDATA[Aktuelle Nachrichten und Updates auf tsecurity.de]]></description>
<language>de-DE</language>
<lastBuildDate>Mon, 05 Oct 2026 03:17:57 +0200</lastBuildDate>
<pubDate>Mon, 05 Oct 2026 03:17:57 +0200</pubDate>
<ttl>15</ttl>
<copyright>2026 tsecurity.de - News Radar &amp; Live Feeds</copyright>
<managingEditor>contact@tsecurity.de (tsecurity.de)</managingEditor>
<webMaster>contact@tsecurity.de (tsecurity.de)</webMaster>
<image>
<url>https://tsecurity.de/templates/mydraft-basis-tsecurity.de/media/logo.png</url>
<title><![CDATA[tsecurity.de - News Radar & Live Feeds]]></title>
<link><![CDATA[https://tsecurity.de/rss/0/malware]]></link>
</image>
<atom:link href="https://tsecurity.de/rss/0/malware" rel="self" type="application/rss+xml" />
<item>
<title><![CDATA[SniffDog: I built my job-hunting friend a sniffer dog that sniffs out malware in fake recruiter repos]]></title>
<description><![CDATA[This is a submission for the Hacktoberfest Weekend Challenge: Build for a Friend What I Built SniffDog checks a take-home coding assignment before you run it. It reads the repo, never executes it, and tells you in plain English whether it's safe to open. I built it for my friend Mayank Raj. Earli...]]></description>
<link>https://tsecurity.de/de/4239135/malware-trojaner-viren/sniffdog-i-built-my-job-hunting-friend-a-sniffer-dog-that-sniffs-out-malware-in-fake-recruiter-repos/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4239135/malware-trojaner-viren/sniffdog-i-built-my-job-hunting-friend-a-sniffer-dog-that-sniffs-out-malware-in-fake-recruiter-repos/</guid>
<pubDate>Mon, 05 Oct 2026 00:32:58 +0200</pubDate>
<content:encoded><![CDATA[<p>This is a submission for the Hacktoberfest Weekend Challenge: Build for a Friend What I Built SniffDog checks a take-home coding assignment before you run it. It reads the repo, never executes it, and tells you in plain English whether it&#039;s safe to open. I built it for my friend Mayank Raj. Earlier this year, Mayank, a final-year student hunting... <a href="https://tsecurity.de/weiterlesen/1000016538/4239135/sniffdog-i-built-my-job-hunting-friend-a-sniffer-dog-that-sniffs-out-malware-in-fake-recruiter-repos/" target="_blank" rel="noopener noreferrer">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 117]]></title>
<description><![CDATA[Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape Malware Newsletter Lunex Unmasked: A New Information Stealer Deployed Through BYOVD   Storm-3168: Agentic-driven cloud attacks using compromised service principals...]]></description>
<link>https://tsecurity.de/de/4238645/malware-trojaner-viren/security-affairs-malware-newsletter-round-117/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4238645/malware-trojaner-viren/security-affairs-malware-newsletter-round-117/</guid>
<pubDate>Sun, 04 Oct 2026 16:49:10 +0200</pubDate>
<content:encoded><![CDATA[<p>Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape Malware Newsletter Lunex Unmasked: A New Information Stealer Deployed Through BYOVD   Storm-3168: Agentic-driven cloud attacks using compromised service principals   Don’t Call Us, We’ll Call Your APIs |... <a href="https://tsecurity.de/weiterlesen/1000016048/4238645/security-affairs-malware-newsletter-round-117/" target="_blank" rel="noopener noreferrer">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Cracked open the Google IPTV malware APK and found its C2 domain]]></title>
<description><![CDATA[submitted by /u/acealter [link] [comments] Weiterlesen]]></description>
<link>https://tsecurity.de/de/4238176/malware-trojaner-viren/cracked-open-the-google-iptv-malware-apk-and-found-its-c2-domain/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4238176/malware-trojaner-viren/cracked-open-the-google-iptv-malware-apk-and-found-its-c2-domain/</guid>
<pubDate>Sun, 04 Oct 2026 10:22:17 +0200</pubDate>
<content:encoded><![CDATA[<p>submitted by /u/acealter [link] [comments] <a href="https://tsecurity.de/weiterlesen/1000015579/4238176/cracked-open-the-google-iptv-malware-apk-and-found-its-c2-domain/" target="_blank" rel="noopener noreferrer">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[WordPress Hacked: Malware Removal and Recovery Guide]]></title>
<description><![CDATA[If your WordPress site was hacked and is now showing pharmaceutical spam, redirecting visitors to somewhere unpleasant, or has been flagged by Google as deceptive, start here rather than with a plugin. The instinct is to install a security scanner and click clean. That removes the visible symptom...]]></description>
<link>https://tsecurity.de/de/4237455/malware-trojaner-viren/wordpress-hacked-malware-removal-and-recovery-guide/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4237455/malware-trojaner-viren/wordpress-hacked-malware-removal-and-recovery-guide/</guid>
<pubDate>Sat, 03 Oct 2026 20:04:37 +0200</pubDate>
<content:encoded><![CDATA[<p>If your WordPress site was hacked and is now showing pharmaceutical spam, redirecting visitors to somewhere unpleasant, or has been flagged by Google as deceptive, start here rather than with a plugin. The instinct is to install a security scanner and click clean. That removes the visible symptom and leaves the way in, which is why so many sites... <a href="https://tsecurity.de/weiterlesen/1000014858/4237455/wordpress-hacked-malware-removal-and-recovery-guide/" target="_blank" rel="noopener noreferrer">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Google’s Android 17 Locks Accessibility Services to Verified Apps as Malware Threat Branches Out]]></title>
<description><![CDATA[Google is tightening restrictions on one of mobile malware's most persistent entry points. With Android 17, the company is limiting access to its AccessibilityService API to verified Accessibility Tools only, a change that takes effect the moment a user switches on Advanced Protection. The move, ...]]></description>
<link>https://tsecurity.de/de/4237445/malware-trojaner-viren/googles-android-17-locks-accessibility-services-to-verified-apps-as-malware-threat-branches-out/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4237445/malware-trojaner-viren/googles-android-17-locks-accessibility-services-to-verified-apps-as-malware-threat-branches-out/</guid>
<pubDate>Sat, 03 Oct 2026 19:47:12 +0200</pubDate>
<content:encoded><![CDATA[<p>Google is tightening restrictions on one of mobile malware&#039;s most persistent entry points. With Android 17, the company is limiting access to its AccessibilityService API to verified Accessibility Tools only, a change that takes effect the moment a user switches on Advanced Protection. The move, announced Thursday, targets a problem that has... <a href="https://tsecurity.de/weiterlesen/1000014848/4237445/googles-android-17-locks-accessibility-services-to-verified-apps-as-malware-threat-branches-out/" target="_blank" rel="noopener noreferrer">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Cling Malware Masquerades as Google STUN Traffic to Control Compromised IoT Devices]]></title>
<description><![CDATA[A newly identified IoT botnet, Cling, disguises its command-and-control communications as legitimate STUN traffic, including packets that appear to originate from Google’s public STUN infrastructure. The technique enables attackers to manage compromised internet-facing devices while blending acti...]]></description>
<link>https://tsecurity.de/de/4236734/malware-trojaner-viren/cling-malware-masquerades-as-google-stun-traffic-to-control-compromised-iot-devices/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4236734/malware-trojaner-viren/cling-malware-masquerades-as-google-stun-traffic-to-control-compromised-iot-devices/</guid>
<pubDate>Sat, 03 Oct 2026 10:06:53 +0200</pubDate>
<content:encoded><![CDATA[<p>A newly identified IoT botnet, Cling, disguises its command-and-control communications as legitimate STUN traffic, including packets that appear to originate from Google’s public STUN infrastructure. The technique enables attackers to manage compromised internet-facing devices while blending activity into routine NAT-traversal traffic used by... <a href="https://tsecurity.de/weiterlesen/1000014137/4236734/cling-malware-masquerades-as-google-stun-traffic-to-control-compromised-iot-devices/" target="_blank" rel="noopener noreferrer">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Cling IoT Malware Masquerades as Google STUN Traffic to Hide C2 Communications]]></title>
<description><![CDATA[A newly observed IoT botnet named Cling exploits vulnerable internet-facing devices and disguises its command-and-control communications as legitimate STUN traffic, including packets that appear to originate from Google’s public STUN infrastructure. The technique lets operators hide malicious ins...]]></description>
<link>https://tsecurity.de/de/4236436/malware-trojaner-viren/cling-iot-malware-masquerades-as-google-stun-traffic-to-hide-c2-communications/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4236436/malware-trojaner-viren/cling-iot-malware-masquerades-as-google-stun-traffic-to-hide-c2-communications/</guid>
<pubDate>Sat, 03 Oct 2026 06:55:42 +0200</pubDate>
<content:encoded><![CDATA[<p>A newly observed IoT botnet named Cling exploits vulnerable internet-facing devices and disguises its command-and-control communications as legitimate STUN traffic, including packets that appear to originate from Google’s public STUN infrastructure. The technique lets operators hide malicious instructions amid common NAT-traversal traffic used by... <a href="https://tsecurity.de/weiterlesen/1000013839/4236436/cling-iot-malware-masquerades-as-google-stun-traffic-to-hide-c2-communications/" target="_blank" rel="noopener noreferrer">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Free malware analysis, reverse engineering and exploit development resources]]></title>
<description><![CDATA[submitted by /u/Potential-Couple-745 [link] [comments] Weiterlesen]]></description>
<link>https://tsecurity.de/de/4236345/malware-trojaner-viren/free-malware-analysis-reverse-engineering-and-exploit-development-resources/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4236345/malware-trojaner-viren/free-malware-analysis-reverse-engineering-and-exploit-development-resources/</guid>
<pubDate>Sat, 03 Oct 2026 05:04:26 +0200</pubDate>
<content:encoded><![CDATA[<p>submitted by /u/Potential-Couple-745 [link] [comments] <a href="https://tsecurity.de/weiterlesen/1000013748/4236345/free-malware-analysis-reverse-engineering-and-exploit-development-resources/" target="_blank" rel="noopener noreferrer">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Where to get resources and get started with malware dev?]]></title>
<description><![CDATA[So, I am a student persuing b tech cybersecurity course, and am pretty good in networkings and Linux systems. I also have some experience in pentesting, have solved some vulnhub machines on my own and have practiced on tryhackme. For programming, I can code in python, c, and c++. I want to get in...]]></description>
<link>https://tsecurity.de/de/4236342/malware-trojaner-viren/where-to-get-resources-and-get-started-with-malware-dev/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4236342/malware-trojaner-viren/where-to-get-resources-and-get-started-with-malware-dev/</guid>
<pubDate>Sat, 03 Oct 2026 05:04:26 +0200</pubDate>
<content:encoded><![CDATA[<p>So, I am a student persuing b tech cybersecurity course, and am pretty good in networkings and Linux systems. I also have some experience in pentesting, have solved some vulnhub machines on my own and have practiced on tryhackme. For programming, I can code in python, c, and c++. I want to get into malware development, but am not getting any solid... <a href="https://tsecurity.de/weiterlesen/1000013745/4236342/where-to-get-resources-and-get-started-with-malware-dev/" target="_blank" rel="noopener noreferrer">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[This new ChatGPT scam tricks you into installing malware – how to spot the trap]]></title>
<description><![CDATA[This authentic-looking scam starts with a sponsored Google link – and it’s catching people off-guard. Weiterlesen]]></description>
<link>https://tsecurity.de/de/4235706/malware-trojaner-viren/this-new-chatgpt-scam-tricks-you-into-installing-malware-how-to-spot-the-trap/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4235706/malware-trojaner-viren/this-new-chatgpt-scam-tricks-you-into-installing-malware-how-to-spot-the-trap/</guid>
<pubDate>Fri, 02 Oct 2026 20:24:53 +0200</pubDate>
<content:encoded><![CDATA[<p>This authentic-looking scam starts with a sponsored Google link – and it’s catching people off-guard. <a href="https://tsecurity.de/weiterlesen/1000013109/4235706/this-new-chatgpt-scam-tricks-you-into-installing-malware-how-to-spot-the-trap/" target="_blank" rel="noopener noreferrer">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Software Supply Chain Attacks Use Malicious npm Updates to Steal Credentials and Spread Malware]]></title>
<description><![CDATA[Software supply chain attacks are turning trusted developer tools into channels for credential theft and malware delivery. Campaigns involving S1ngularity, Shai-Hulud, and TeamPCP show how compromised packages can expose developer workstations, build systems, and cloud infrastructure through rout...]]></description>
<link>https://tsecurity.de/de/4235537/malware-trojaner-viren/software-supply-chain-attacks-use-malicious-npm-updates-to-steal-credentials-and-spread-malware/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4235537/malware-trojaner-viren/software-supply-chain-attacks-use-malicious-npm-updates-to-steal-credentials-and-spread-malware/</guid>
<pubDate>Fri, 02 Oct 2026 19:26:10 +0200</pubDate>
<content:encoded><![CDATA[<p>Software supply chain attacks are turning trusted developer tools into channels for credential theft and malware delivery. Campaigns involving S1ngularity, Shai-Hulud, and TeamPCP show how compromised packages can expose developer workstations, build systems, and cloud infrastructure through routine software updates. Rather than attacking each... <a href="https://tsecurity.de/weiterlesen/1000012940/4235537/software-supply-chain-attacks-use-malicious-npm-updates-to-steal-credentials-and-spread-malware/" target="_blank" rel="noopener noreferrer">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[SLTT C2 Traffic Tied to Remus Malware Distribution Operation]]></title>
<description><![CDATA[The CIS CTI team identified Remus infostealer distribution activity spanning March through September 2026. Read its analysis. Weiterlesen]]></description>
<link>https://tsecurity.de/de/4235437/malware-trojaner-viren/sltt-c2-traffic-tied-to-remus-malware-distribution-operation/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4235437/malware-trojaner-viren/sltt-c2-traffic-tied-to-remus-malware-distribution-operation/</guid>
<pubDate>Fri, 02 Oct 2026 19:25:27 +0200</pubDate>
<content:encoded><![CDATA[<p>The CIS CTI team identified Remus infostealer distribution activity spanning March through September 2026. Read its analysis. <a href="https://tsecurity.de/weiterlesen/1000012840/4235437/sltt-c2-traffic-tied-to-remus-malware-distribution-operation/" target="_blank" rel="noopener noreferrer">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Malwarebytes Download - Schutz vor Schadsoftware]]></title>
<description><![CDATA[Der Download von Malwarebytes installiert einen starken Schutz vor Schadprogrammen wie Viren oder Ransomware und wehrt selbst die neuesten Bedrohungen ab. Hierzu kombiniert Malwarebytes 5.7.2 verschiedene ... (Weiter lesen) Weiterlesen]]></description>
<link>https://tsecurity.de/de/4235186/malware-trojaner-viren/malwarebytes-download-schutz-vor-schadsoftware/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4235186/malware-trojaner-viren/malwarebytes-download-schutz-vor-schadsoftware/</guid>
<pubDate>Fri, 02 Oct 2026 19:21:23 +0200</pubDate>
<content:encoded><![CDATA[<p>Der Download von Malwarebytes installiert einen starken Schutz vor Schadprogrammen wie Viren oder Ransomware und wehrt selbst die neuesten Bedrohungen ab. Hierzu kombiniert Malwarebytes 5.7.2 verschiedene ... (Weiter lesen) <a href="https://tsecurity.de/weiterlesen/1000012589/4235186/malwarebytes-download-schutz-vor-schadsoftware/" target="_blank" rel="noopener noreferrer">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Hackers Are Turning Trusted Software Updates Into Credential-Stealing Malware]]></title>
<description><![CDATA[A growing wave of supply-chain attacks is proving the opposite: attackers are compromising legitimate open-source packages and using trusted update channels to deploy credential-stealing malware directly into developer and enterprise environments. Malicious Nx releases, published after attackers ...]]></description>
<link>https://tsecurity.de/de/4234530/malware-trojaner-viren/hackers-are-turning-trusted-software-updates-into-credential-stealing-malware/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4234530/malware-trojaner-viren/hackers-are-turning-trusted-software-updates-into-credential-stealing-malware/</guid>
<pubDate>Fri, 02 Oct 2026 19:17:35 +0200</pubDate>
<content:encoded><![CDATA[<p>A growing wave of supply-chain attacks is proving the opposite: attackers are compromising legitimate open-source packages and using trusted update channels to deploy credential-stealing malware directly into developer and enterprise environments. Malicious Nx releases, published after attackers stole an npm publishing token through a GitHub... <a href="https://tsecurity.de/weiterlesen/1000011933/4234530/hackers-are-turning-trusted-software-updates-into-credential-stealing-malware/" target="_blank" rel="noopener noreferrer">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Fake Zoom installer tries to trick Mac users into installing hidden malware]]></title>
<description><![CDATA[A new Mac threat is hiding inside something that looks like a normal Zoom installer, according to security researchers at Jamf Threat Labs. The file opens as a disk named Zoom and looks like the usual Mac installer: an app icon on the left, a shortcut to the Applications folder on the right. The ...]]></description>
<link>https://tsecurity.de/de/4234430/malware-trojaner-viren/fake-zoom-installer-tries-to-trick-mac-users-into-installing-hidden-malware/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4234430/malware-trojaner-viren/fake-zoom-installer-tries-to-trick-mac-users-into-installing-hidden-malware/</guid>
<pubDate>Fri, 02 Oct 2026 19:16:50 +0200</pubDate>
<content:encoded><![CDATA[<p>A new Mac threat is hiding inside something that looks like a normal Zoom installer, according to security researchers at Jamf Threat Labs. The file opens as a disk named Zoom and looks like the usual Mac installer: an app icon on the left, a shortcut to the Applications folder on the right. The catch is a set of instructions printed on the... <a href="https://tsecurity.de/weiterlesen/1000011833/4234430/fake-zoom-installer-tries-to-trick-mac-users-into-installing-hidden-malware/" target="_blank" rel="noopener noreferrer">Weiterlesen</a></p>]]></content:encoded>
</item>
</channel>
</rss>
<!-- Generated in 3,02ms -->