Skip to main content

Threats Affecting Germany

View all threats affecting or targeting Germany. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Country:GermanyGermany

Threats Affecting Germany

Click on any threat for detailed analysis and mitigation recommendations

Analysis reveals HEAVYGRAM, a multi-stage Windows backdoor attributed to Iran-linked threat actor Handala Hack, deployed since Fall 2023 targeting Iranian dissidents, journalists, and government opponents. The surveillance tool uses Telegram bot API for command-and-control operations, enabling remote command execution, screen capture, data exfiltration, and persistent access. Victims receive social-engineered files masquerading as legitimate applications like Telegram, KeePass, or Pictory. The implant supports DLL side-loading, registry persistence, and system reconnaissance. Infrastructure analysis identified 29 samples utilizing networks of Telegram bots and groups for operations. The malware aligns with activity disclosed by U.S. Department of Justice regarding Iran's Ministry of Intelligence and Security infrastructure seizures, with tradecraft including Vultr Object Storage and Persian-language decoys targeting specific victim profiles including academics and media personnel.

Join the discussion

It was discovered that libsoup incorrectly handled certain URLs when using an HTTP proxy. A remote attacker could possibly use this issue to inject arbitrary HTTP headers. (CVE-2026-1467) It was discovered that libsoup did not remove proxy authentication credentials when following HTTP redirects. A remote attacker could possibly use this issue to obtain sensitive information. (CVE-2026-1539) Ahmed Lekssays discovered that libsoup incorrectly parsed certain HTTP requests. A remote attacker could possibly use this issue to obtain sensitive information. (CVE-2026-1801)

Join the discussion
0

A previously unknown modular multi-stage framework named MovieReaper has been discovered targeting users through compromised torrent files. Attackers compromised the public torrent repository itorrents[.]org, enabling them to distribute malicious loaders disguised as popular movies, including "The Odyssey." The campaign began in mid-August 2026 and affected hundreds of victims across multiple countries. The malware employs a sophisticated infection chain with fileless execution, utilizing blockchain network Solana for C2 infrastructure resilience. The framework includes multiple stages: an initial loader with anti-sandbox checks, shellcode that retrieves C2 addresses from Solana blockchain, UAC bypass with persistence mechanisms, and a final file manager module providing comprehensive file system access. The campaign demonstrates advanced evasion techniques including manual API resolution, vectored exception handling, and in-memory execution.

Join the discussion

VectraRAT is a previously undocumented Malware-as-a-Service platform combining a Go-based control server (VectraHub) with a native C++ Windows implant, renting from $250 monthly. The developer, operating under the handle 'Vectra' (formerly 'Nyxel'), has been active since August 2022 without prior public documentation. The platform offers hidden desktop control, keylogging, clipboard hijacking with cryptocurrency address replacement, browser credential theft, and a UAC bypass achieving elevation without user prompts. Delivered through Amadey loader and ClickFix campaigns targeting tax-themed lures, 48% of observed victims run corporate Windows editions including Windows Server 2025. Infrastructure analysis revealed exposed directories and operational panels across multiple hosting providers, with victims spanning the United States, Russia, Germany, and other nations.

Join the discussion

Mbed TLS before 3.6.4 has a race condition in AESNI detection if certain compiler optimizations occur. An attacker may be able to extract an AES key from a multithreaded program, or perform a GCM forgery.

Join the discussion

A threat actor exploited CVE-2026-15409, a critical unauthenticated server-side request forgery vulnerability in SonicWall SMA1000 appliances, to gain command execution and steal credentials. The attacker used a modified public proof-of-concept exploit to access internal Erlang services on the appliance, enabling remote code execution. This allowed extraction of LDAP configurations, Active Directory credentials, and deployment of tools to dump secrets from internal Windows systems. The campaign targeted at least 250 SonicWall SMA1000 devices across multiple countries and sectors, with confirmed credential theft in France, India, Italy, and the US. The attack leveraged compromised appliances as pivots into internal networks, exposing sensitive Active Directory data and enabling DCSync attacks against domain controllers. The targeting was opportunistic and technology-driven rather than sector-specific. The campaign was uncovered through an open directory left exposed by the attacker, providing a comprehensive view of the operation.

Join the discussion

MacSync Stealer is a macOS information stealer and remote-access stager delivered through ClickFix social engineering and malvertising campaigns. Operating under a malware-as-a-service model, it employs sophisticated evasion techniques including process daemonization, single-byte XOR obfuscation, and in-memory AppleScript execution to bypass Apple Gatekeeper, XProtect, and EDR solutions. The malware exfiltrates credentials, browser data, cryptocurrency wallets, and SSH keys through fault-tolerant 10MB chunked uploads to command-and-control infrastructure. MacSync targets professionals in software engineering, cryptocurrency, fintech, and corporate environments across North America, Europe, and Asia-Pacific regions, with campaigns impersonating legitimate services like Google Meet, Claude AI, Docker, and TradingView to trick victims into executing malicious Terminal commands.

Join the discussion

An unpatched zero-day vulnerability dubbed StyleSmuggler affects all current versions of Magento and Adobe Commerce, including 2.4.9, enabling unauthenticated remote code execution. Active exploitation began on September 4th, 2026. The attack operates in two stages: injecting malicious PHP code into Magento's template system using styles properties to evade safeguards, then executing the poisoned code via failed payment emails. Upon successful compromise, attackers deploy a Rust-based backdoor disguised as legitimate system processes (kworker, fc-cache, or chronyd) that connects to command and control servers. The backdoor uses NTP-shaped UDP traffic for C2 communication to evade detection. A second unrelated attacker has also been observed exploiting the same vulnerability to deploy PHP web shells. Affected merchants should deploy immediate mitigation measures, scan for compromise, and temporarily disable GraphQL until an official patch is released.

Join the discussion

In June 2026, researchers uncovered BigBear 2.0, a rebranded Evilginx2-based phishing-as-a-service framework targeting Microsoft 365 credentials globally. The operation, managed by operator 'General Boss', deployed 42 VPS nodes primarily hosted on Vultr infrastructure, utilizing the 'offy' phishlet configuration. The platform employed adversary-in-the-middle techniques with geo-matched residential proxy pools across 69 countries, real-time Telegram exfiltration, and automated cookie replay to bypass MFA. The campaign exfiltrated 5,137 credential records including 474 complete MFA-bypassed authentications, 1,032 plaintext passwords, and 4,148 session cookies, affecting 3,331 unique victim IPs across 40+ countries. The multi-user PhaaS panel was leased to at least five identified affiliate operators. Custom JavaScript injections disabled FIDO2/WebAuthn MFA while residential proxies bypassed anti-bot detection, enabling persistent access to compromised Microsoft 365 environments.

Join the discussion

Google has updated the Chrome browser to address an actively exploited high-severity zero-day flaw in the V8 engine and 11 other vulnerabilities. [...]

Join the discussion

Showing 1 to 10 of 37463 results

Filters:Country: Germany
Page 1 of 3747
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses