threat-intel Microsoft Links 30+ Rotating Domains to MacSync Stealer Infrastructure Microsoft has linked over 30 web domains to MacSync Stealer, a macOS information stealer, after observing recurring network behaviors and endpoint activity. The malware uses various techniques, including AppleScript, to collect sensitive data like credentials, browser history, and SSH keys, and then exfiltrates it thro… The Hacker News · Aug 19, 2026 High macmacosstealer
vulnerability Dozens of WebKit Vulnerabilities Patched With Fresh macOS, iOS Security Updates Apple released security updates for macOS, iOS, and iPadOS addressing dozens of vulnerabilities primarily within the WebKit browser engine. These updates fix issues ranging from crashes and data exposure to potential sys… SecurityWeek · Aug 18, 2026 Medium webkitsecuritypatch
threat-intel Multiples vulnérabilités dans les produits Apple (18 août 2026) Multiple vulnerabilities have been discovered in Apple products, including potential for arbitrary code execution, privilege escalation, and denial-of-service attacks. These vulnerabilities affect various iOS and macOS v… CERT-FR · Aug 18, 2026 High CVE-2026-28947CVE-2026-28958CVE-2026-28973vulnerabilitysecurityapple
vulnerability Apple Patches iOS and macOS, (Mon, Aug 17th) Apple released security updates for iOS, iPadOS, and macOS to address 108 vulnerabilities, primarily targeting the WebKit component. This update follows a smaller macOS patch and represents a significant effort to bolste… SANS Internet Storm Center · Aug 17, 2026 Medium CVE-2026-28958CVE-2026-28973CVE-2026-28984webkitsecuritypatch
vulnerability Recent macOS Screen Sharing Vulnerability Exploited in Attacks A recently patched macOS Screen Sharing vulnerability is being actively exploited in the wild by threat actors to gain root access and deploy cryptominers. The flaw allows attackers to authenticate without credentials si… SecurityWeek · Aug 17, 2026 High CVE-2026-65400macosscreen sharingroot access
vulnerability Apple macOS Screen Sharing Flaw Exploited on Internet-Exposed Macs to Install Monero Miner A critical vulnerability in Apple's macOS Screen Sharing component has been actively exploited in the wild to install a cryptocurrency miner. Researchers have discovered a pre-authentication vulnerability (CVE-2026-65400… The Hacker News · Aug 15, 2026 Critical CVE-2026-65400CVE-2026-43779CVE-2026-43777USmacosscreen sharingvulnerability
threat-intel AmnesiaStealer macOS Malware Steals Data, Controls Browser Sessions A new multi-stage Rust-based macOS information stealer, dubbed AmnesiaStealer, is being distributed through a fake GitHub download page as part of ClickFix attacks. The malware steals user data, including passwords and b… SecurityWeek · Aug 14, 2026 High CVE-2020-9771macosrustinformation stealer
vulnerability Vulnérabilité dans les produits Sophos (14 août 2026) A critical vulnerability has been identified in Sophos products, allowing attackers to escalate privileges on macOS systems. This affects older versions of Intercept X Endpoint and Sophos Home, requiring immediate patchi… CERT-FR · Aug 14, 2026 Critical CVE-2026-18367macosvulnerabilityprivilege escalation
threat-intel AmnesiaStealer Hijacks Chromium Sessions to Give Attackers Live Browser Control on macOS A new macOS information stealer, dubbed AmnesiaStealer, is targeting Chromium-based browsers to steal user credentials and provide live, interactive control over victim's web sessions. Developed by a Rust-based threat ac… The Hacker News · Aug 13, 2026 High CVE-2020-9771macosrustchromium
threat-intel ClickFix Attacks Deliver macOS Stealer That Can Drain Crypto Wallets ClickFix-style attacks are being used to deliver a Go-based macOS stealer that can drain cryptocurrency wallets and steal browser-stored passwords and Apple iCloud Keychain data. The malware, developed by the Aeza Group… The Hacker News · Aug 7, 2026 High USUKAUmacoscryptocurrencystealer
vulnerability Vulnérabilité dans Apple macOS (07 août 2026) Apple has disclosed a security vulnerability in macOS that allows attackers to bypass security policies. This vulnerability could lead to unauthorized access and potential compromise of user systems. Users of affected ma… CERT-FR · Aug 7, 2026 Medium CVE-2026-65400macossecurityvulnerability
threat-intel Over 250 ClickFix Domains Use Browser Fingerprinting to Hide macOS Malware Lures A macOS ClickFix operation is using browser fingerprinting to deliver malware lures to a targeted subset of Mac users. The operation, involving over 250 domains and distributing malware like MacSync and AMOS, hides the m… The Hacker News · Aug 5, 2026 High browser fingerprintingmacosclickfix
threat-intel Atomic MacOS (AMOS) stealer infection, (Sun, Aug 2nd) A researcher at the SANS Internet Storm Center identified an Atomic MacOS (AMOS) stealer infection campaign originating from a web page at getmacouscloud[.]com. The campaign involved tricking users into pasting malicious… SANS Internet Storm Center · Aug 2, 2026 High macosstealerc2
threat-intel The Xcode Assassin Returns: A Deep Dive Into the Latest XCSSET Version The XCSSET malware family has returned with version 40, exhibiting enhanced stealth and persistence techniques to evade detection and compromise macOS systems, particularly those of software developers. This latest itera… Palo Alto Unit 42 · Jul 31, 2026 High SOmacossupply chainmalware
threat-intel DPRK-Linked macOS Malvertising Uses Fake Updates to Deliver Crypto-Stealing Malware North Korean-linked threat actors are using a sophisticated macOS malvertising campaign to deliver crypto-stealing malware. The campaign mimics a fake software update sequence to trick users into executing a malicious co… The Hacker News · Jul 30, 2026 High KPmacosmalvertisingcrypto-stealer
vulnerability Apple Patches Everything (July 2026), (Wed, Jul 29th) Apple released a substantial security update addressing 187 vulnerabilities across its macOS, iOS, and Safari operating systems. The update focuses on patching a range of issues, including DoS attacks, privilege escalati… SANS Internet Storm Center · Jul 29, 2026 Medium CVE-2026-28849CVE-2026-28900CVE-2026-28914macosiossafari
vulnerability Apple Patches 87 Vulnerabilities in iOS, 155 in macOS Tahoe Apple has released security updates addressing a significant number of vulnerabilities across its iOS, macOS, Safari, watchOS, tvOS, and visionOS operating systems. These patches address a wide range of issues, including… SecurityWeek · Jul 28, 2026 High CVE-2026-43810securitypatchvulnerabilities
vulnerability Multiples vulnérabilités dans les produits ESET (24 juillet 2026) Multiple vulnerabilities have been discovered in ESET’s security products, primarily for macOS, allowing attackers to potentially elevate their privileges. These vulnerabilities require immediate patching to prevent expl… CERT-FR · Jul 24, 2026 Medium CVE-2026-10610CVE-2026-7483macosvulnerabilitypatch
threat-intel Researchers replace downloaded macOS apps with evil twins, Apple shrugs Researchers have discovered a method to replace downloaded macOS applications with malicious 'evil twin' versions, while Apple has not responded to the issue. This highlights a significant vulnerability in how users obta… The Register · Jul 23, 2026 Medium IRUSmacosmalwarephishing
vulnerability Claude Cowork Flaw Could Let AI Agent Escape Its VM and Access Mac Files Researchers at Accomplish AI discovered a sandbox escape vulnerability in Anthropic's Claude Cowork for macOS, allowing the AI agent to access and modify files on the host Mac. Approximately 500,000 macOS users running l… The Hacker News · Jul 23, 2026 High CVE-2026-46331sandboxmacoslinux