<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>defended. - Blog</title>
    <link>https://defended.net/blog/</link>
    <atom:link href="https://defended.net/rss.xml" rel="self" type="application/rss+xml" />
    <description>Release notes, signature updates and announcements from the defended open source security projects.</description>
    <language>en</language>
    <lastBuildDate>Fri, 04 Sep 2026 00:00:00 GMT</lastBuildDate>
    <item>
      <title>malwatch 1.5.3</title>
      <link>https://defended.net/blog/malwatch-153/</link>
      <guid isPermaLink="true">https://defended.net/blog/malwatch-153/</guid>
      <pubDate>Fri, 04 Sep 2026 00:00:00 GMT</pubDate>
      <description>Skip handling is now zero alloc. Performance gains of approximately 5% faster scan times along with over 5% cpu and 1% memory reductions.</description>
      <category>malwatch</category>
    </item>
    <item>
      <title>malwatch 1.5.2</title>
      <link>https://defended.net/blog/malwatch-152/</link>
      <guid isPermaLink="true">https://defended.net/blog/malwatch-152/</guid>
      <pubDate>Sat, 25 Jul 2026 00:00:00 GMT</pubDate>
      <description>Flag and callback handling with yara scanner c binding optimised for our use case. The larger the files are, the more this improvement shines.</description>
      <category>malwatch</category>
    </item>
    <item>
      <title>malwatch 1.5.1</title>
      <link>https://defended.net/blog/malwatch-151/</link>
      <guid isPermaLink="true">https://defended.net/blog/malwatch-151/</guid>
      <pubDate>Sat, 13 Jun 2026 00:00:00 GMT</pubDate>
      <description>Version 1.5.1 just got published. This release focuses on adding optimisations and extending concurrency safety as well as adding even more test coverage.</description>
      <category>malwatch</category>
    </item>
    <item>
      <title>malwatch 1.5.0</title>
      <link>https://defended.net/blog/malwatch-150/</link>
      <guid isPermaLink="true">https://defended.net/blog/malwatch-150/</guid>
      <pubDate>Sat, 16 May 2026 00:00:00 GMT</pubDate>
      <description>Today's release 1.5.0 is large at 10 000 line changes. It introduces powerful features, paired with rigid security hardening. Malware cleaning is now sandboxed and file handling is more secure with integration of os.Root. Users with our developer time have already had their integrations uplifted before this version, please contact us if we can help. Alerting now has slack added as an integration and the sysd install process has been converted to be template driven. Recent cPanel vulnerabilities have demonstrated our solutions. Everyone can be protected.</description>
      <category>malwatch</category>
    </item>
    <item>
      <title>malwatch 1.4.2</title>
      <link>https://defended.net/blog/malwatch-142/</link>
      <guid isPermaLink="true">https://defended.net/blog/malwatch-142/</guid>
      <pubDate>Sat, 14 Mar 2026 00:00:00 GMT</pubDate>
      <description>Vulnerability with cloudflare/circl **[GO-2026-4550](https://pkg.go.dev/vuln/GO-2026-4550)** resolved. This project was unaffected by these third party vulnerabilities.</description>
      <category>malwatch</category>
    </item>
    <item>
      <title>malwatch 1.4.1</title>
      <link>https://defended.net/blog/malwatch-141/</link>
      <guid isPermaLink="true">https://defended.net/blog/malwatch-141/</guid>
      <pubDate>Sun, 01 Mar 2026 00:00:00 GMT</pubDate>
      <description>Following our engineering tradition, major new releases are followed by refactors with added test coverage for other packages. In this version path validation has been refactored with emphasis on path traversal. We have also improved scan worker file descriptor stat handling. We care greatly about code quality, features are a secondary priority. Feedback is always welcome.</description>
      <category>malwatch</category>
    </item>
    <item>
      <title>malwatch 1.4.0</title>
      <link>https://defended.net/blog/malwatch-140/</link>
      <guid isPermaLink="true">https://defended.net/blog/malwatch-140/</guid>
      <pubDate>Sat, 07 Feb 2026 00:00:00 GMT</pubDate>
      <description>Version 1.4.0 introduces hot reloads for malware signature changes. The design is with concurrency carefully considered using an implementation of reference accounting for worker threads as to ensure no interruptions as well as safe garbage collection given cgo. Real time monitoring no longer requires a service restart to recognise those changes. Feedback is always welcome.</description>
      <category>malwatch</category>
    </item>
    <item>
      <title>malwatch 1.3.4</title>
      <link>https://defended.net/blog/malwatch-134/</link>
      <guid isPermaLink="true">https://defended.net/blog/malwatch-134/</guid>
      <pubDate>Wed, 07 Jan 2026 00:00:00 GMT</pubDate>
      <description>This project was unaffected by these third party vulnerabilities. Feedback is always welcome.</description>
      <category>malwatch</category>
    </item>
    <item>
      <title>malwatch 1.3.3</title>
      <link>https://defended.net/blog/malwatch-133/</link>
      <guid isPermaLink="true">https://defended.net/blog/malwatch-133/</guid>
      <pubDate>Fri, 17 Oct 2025 00:00:00 GMT</pubDate>
      <description>Release 1.3.3 further tightens filesystem permissions and includes an updated yara library to 4.5.4. Feedback is always welcome.</description>
      <category>malwatch</category>
    </item>
    <item>
      <title>malwatch 1.3.2</title>
      <link>https://defended.net/blog/malwatch-132/</link>
      <guid isPermaLink="true">https://defended.net/blog/malwatch-132/</guid>
      <pubDate>Sun, 05 Oct 2025 00:00:00 GMT</pubDate>
      <description>Release 1.3.2 provides minor improvements with signal handling and better cli help output. Feedback is always welcome.</description>
      <category>malwatch</category>
    </item>
    <item>
      <title>malwatch 1.3.1</title>
      <link>https://defended.net/blog/malwatch-131/</link>
      <guid isPermaLink="true">https://defended.net/blog/malwatch-131/</guid>
      <pubDate>Sat, 27 Sep 2025 00:00:00 GMT</pubDate>
      <description>This release brings minor improvements in terms of panic error handling. It also resolves a toctou race condition regarding the lockfile.</description>
      <category>malwatch</category>
    </item>
    <item>
      <title>malwatch signatures 1.1.1</title>
      <link>https://defended.net/blog/malwatch-signatures-1-1-1/</link>
      <guid isPermaLink="true">https://defended.net/blog/malwatch-signatures-1-1-1/</guid>
      <pubDate>Thu, 18 Sep 2025 00:00:00 GMT</pubDate>
      <description>Users will automatically receive these updates. Keep submitting samples for our analysis ❤️</description>
      <category>signatures</category>
    </item>
    <item>
      <title>malwatch signatures 1.1.0</title>
      <link>https://defended.net/blog/malwatch-signatures-1-1-0/</link>
      <guid isPermaLink="true">https://defended.net/blog/malwatch-signatures-1-1-0/</guid>
      <pubDate>Sat, 13 Sep 2025 00:00:00 GMT</pubDate>
      <description>Introduces a new exp family is the starting point to represents exploit frameworks that use more advanced techniques such as manipulating memory. There is now also clearer bd classification with an rce category added.</description>
      <category>signatures</category>
    </item>
    <item>
      <title>malwatch signatures 1.0.7</title>
      <link>https://defended.net/blog/malwatch-signatures-1-0-7/</link>
      <guid isPermaLink="true">https://defended.net/blog/malwatch-signatures-1-0-7/</guid>
      <pubDate>Sat, 06 Sep 2025 00:00:00 GMT</pubDate>
      <description>Users will automatically receive these updates. Keep submitting samples for our analysis ❤️</description>
      <category>signatures</category>
    </item>
    <item>
      <title>malwatch 1.3.0</title>
      <link>https://defended.net/blog/malwatch-130/</link>
      <guid isPermaLink="true">https://defended.net/blog/malwatch-130/</guid>
      <pubDate>Tue, 02 Sep 2025 00:00:00 GMT</pubDate>
      <description>The switch to musl for extended compatibility predictably created a small performance decline. That can however be regained as well as unlock a meaningful reduction in memory usage by pairing mimalloc.</description>
      <category>malwatch</category>
    </item>
    <item>
      <title>malwatch signatures 1.0.5</title>
      <link>https://defended.net/blog/malwatch-signatures-1-0-5/</link>
      <guid isPermaLink="true">https://defended.net/blog/malwatch-signatures-1-0-5/</guid>
      <pubDate>Thu, 28 Aug 2025 00:00:00 GMT</pubDate>
      <description>Further information is available at the **[GitHub release](https://github.com/defended-net/malwatch-signatures/releases/tag/v1.0.5)** or **[project page](/malwatch)**.</description>
      <category>signatures</category>
    </item>
    <item>
      <title>malwatch signatures 1.0.6</title>
      <link>https://defended.net/blog/malwatch-signatures-1-0-6/</link>
      <guid isPermaLink="true">https://defended.net/blog/malwatch-signatures-1-0-6/</guid>
      <pubDate>Thu, 28 Aug 2025 00:00:00 GMT</pubDate>
      <description>This update also includes a significant prune of unnecessary third party signatures. Our newly developed in house malware signature base delivers a higher detection rate for a footprint which is 50x smaller.</description>
      <category>signatures</category>
    </item>
    <item>
      <title>malwatch signatures 1.0.4</title>
      <link>https://defended.net/blog/malwatch-signatures-1-0-4/</link>
      <guid isPermaLink="true">https://defended.net/blog/malwatch-signatures-1-0-4/</guid>
      <pubDate>Fri, 22 Aug 2025 00:00:00 GMT</pubDate>
      <description>Further information is available at the **[GitHub release](https://github.com/defended-net/malwatch-signatures/releases/tag/v1.0.4)** or **[project page](/malwatch)**.</description>
      <category>signatures</category>
    </item>
    <item>
      <title>malwatch signatures 1.0.3</title>
      <link>https://defended.net/blog/malwatch-signatures-1-0-3/</link>
      <guid isPermaLink="true">https://defended.net/blog/malwatch-signatures-1-0-3/</guid>
      <pubDate>Sun, 17 Aug 2025 00:00:00 GMT</pubDate>
      <description>Further information is available at the **[GitHub release](https://github.com/defended-net/malwatch-signatures/releases/tag/v1.0.3)** or **[project page](/malwatch)**.</description>
      <category>signatures</category>
    </item>
    <item>
      <title>malwatch signatures 1.0.2</title>
      <link>https://defended.net/blog/malwatch-signatures-1-0-2/</link>
      <guid isPermaLink="true">https://defended.net/blog/malwatch-signatures-1-0-2/</guid>
      <pubDate>Wed, 13 Aug 2025 00:00:00 GMT</pubDate>
      <description>Further information is available at the **[GitHub release](https://github.com/defended-net/malwatch-signatures/releases/tag/v1.0.2)** or **[project page](/malwatch)**.</description>
      <category>signatures</category>
    </item>
    <item>
      <title>malwatch signatures 1.0.1</title>
      <link>https://defended.net/blog/malwatch-signatures-1-0-1/</link>
      <guid isPermaLink="true">https://defended.net/blog/malwatch-signatures-1-0-1/</guid>
      <pubDate>Tue, 22 Jul 2025 00:00:00 GMT</pubDate>
      <description>Further information is available at the **[GitHub release](https://github.com/defended-net/malwatch-signatures/releases/tag/v1.0.1)** or **[project page](/malwatch)**.</description>
      <category>signatures</category>
    </item>
    <item>
      <title>malwatch 1.2.2</title>
      <link>https://defended.net/blog/malwatch-122/</link>
      <guid isPermaLink="true">https://defended.net/blog/malwatch-122/</guid>
      <pubDate>Wed, 16 Jul 2025 00:00:00 GMT</pubDate>
      <description>Scan worker iterative errors and file read offsets are now reused. The file read buffer is also no longer reallocated per offset.</description>
      <category>malwatch</category>
    </item>
    <item>
      <title>malwatch 1.2.1</title>
      <link>https://defended.net/blog/malwatch-121/</link>
      <guid isPermaLink="true">https://defended.net/blog/malwatch-121/</guid>
      <pubDate>Fri, 13 Jun 2025 00:00:00 GMT</pubDate>
      <description>Cloudflare disclosed [GHSA-2x5j-vhc8-9cwm](https://github.com/golang/vulndb/issues/3754), this project was unaffected.</description>
      <category>malwatch</category>
    </item>
    <item>
      <title>malwatch 1.2.0</title>
      <link>https://defended.net/blog/malwatch-120/</link>
      <guid isPermaLink="true">https://defended.net/blog/malwatch-120/</guid>
      <pubDate>Tue, 10 Jun 2025 00:00:00 GMT</pubDate>
      <description>We receive many questions concerning compatibility with different platforms / control panels. This a major release with focus on cleaner implementation for new integrations. It comes bundled with newly added seamless support for DirectAdmin.</description>
      <category>malwatch</category>
    </item>
    <item>
      <title>malwatch 1.1.2</title>
      <link>https://defended.net/blog/malwatch-112/</link>
      <guid isPermaLink="true">https://defended.net/blog/malwatch-112/</guid>
      <pubDate>Sat, 24 May 2025 00:00:00 GMT</pubDate>
      <description>We receive many questions concerning compatibility with older versions of glibc, in particular CentOS 7. Certain default older AlmaLinux or Ubuntu / Debian systems can encounter errors based on the installed version of glibc.</description>
      <category>malwatch</category>
    </item>
    <item>
      <title>malwatch 1.1.0</title>
      <link>https://defended.net/blog/malwatch-110/</link>
      <guid isPermaLink="true">https://defended.net/blog/malwatch-110/</guid>
      <pubDate>Tue, 01 Apr 2025 00:00:00 GMT</pubDate>
      <description>Release 1.1.0 introduces a major feature, the ability to submit malware samples by means of our new API. No signup is needed to use this service and everyone has one upload permitted per week, with additional available to project **[Sponsors](https://defended.net/sponsor)**.</description>
      <category>malwatch</category>
    </item>
    <item>
      <title>malwatch 1.1.1</title>
      <link>https://defended.net/blog/malwatch-111/</link>
      <guid isPermaLink="true">https://defended.net/blog/malwatch-111/</guid>
      <pubDate>Tue, 01 Apr 2025 00:00:00 GMT</pubDate>
      <description>Go disclosed **[GO-2025-3595](https://pkg.go.dev/vuln/GO-2025-3595)**, this project was unaffected.</description>
      <category>malwatch</category>
    </item>
    <item>
      <title>malwatch 1.0.3</title>
      <link>https://defended.net/blog/malwatch-103/</link>
      <guid isPermaLink="true">https://defended.net/blog/malwatch-103/</guid>
      <pubDate>Mon, 17 Mar 2025 00:00:00 GMT</pubDate>
      <description>Go disclosed **[GO-2025-3503](https://pkg.go.dev/vuln/GO-2025-3503)**, this project was unaffected.</description>
      <category>malwatch</category>
    </item>
    <item>
      <title>malwatch 1.0.2</title>
      <link>https://defended.net/blog/malwatch-102/</link>
      <guid isPermaLink="true">https://defended.net/blog/malwatch-102/</guid>
      <pubDate>Mon, 10 Mar 2025 00:00:00 GMT</pubDate>
      <description>Further information is available at the **[GitHub release](https://github.com/defended-net/malwatch/releases/tag/v1.0.2)** or **[project page](/malwatch)**.</description>
      <category>malwatch</category>
    </item>
    <item>
      <title>malwatch 1.0.1</title>
      <link>https://defended.net/blog/malwatch-101/</link>
      <guid isPermaLink="true">https://defended.net/blog/malwatch-101/</guid>
      <pubDate>Wed, 05 Mar 2025 00:00:00 GMT</pubDate>
      <description>Small performance gain from optimisations special thank you to go team's 1.24 release.</description>
      <category>malwatch</category>
    </item>
    <item>
      <title>Announcing malwatch</title>
      <link>https://defended.net/blog/announcing-malwatch/</link>
      <guid isPermaLink="true">https://defended.net/blog/announcing-malwatch/</guid>
      <pubDate>Wed, 12 Feb 2025 00:00:00 GMT</pubDate>
      <description>Today marks the inaugural release of malwatch, an open source malware scanning solution designed for web server environments which is currently in production with some of the internet's busiest websites. It is remarkably performant and lightweight in equal measure.</description>
      <category>announcement</category>
    </item>
  </channel>
</rss>
