Tag: macos
61 articles

Iranian Hackers Deploy Cross-Platform Malware via Coding Tests
Iranian hackers are using clever tactics to deploy cross-platform malware, disguising it as coding challenges on LinkedIn and other job search platforms to trick developers into installing the threat. This malware, tracked as NodeRabbit and PollCat, can infect Windows, Linux, and macOS workstations, allowing hackers to gain remote access.

Mac Malware Exploits Fake OpenAI Codex Ads
Beware of fake OpenAI Codex ads: hackers are using Google search results to trick Mac users into downloading malware by pasting a malicious Terminal command. This sneaky tactic unleashes a multi-stage malware infection, putting your device at risk.

Google Sites Abused to Deliver macOS Malware via Fake Codex Download
Malicious actors are tricking users into downloading macOS malware by hijacking Google searches for "Codex macOS download" and using fake Google Sites pages that mimic the real OpenAI Codex download portal. These convincing sites offer both macOS and Linux downloads, but only deliver a Mach-O payload to unsuspecting macOS users.

CISA Warns of Active Exploitation of Critical Flaws in macOS, SharePoint, vCenter, and Microsoft IKE
Critical flaws in macOS, SharePoint, vCenter, and Microsoft IKE are under active attack, with 361 victim IP addresses across 47 countries already compromised. CISA has sounded the alarm, adding these vulnerabilities to its Known Exploited Vulnerabilities catalog.

macOS Screen Sharing Flaw Exploited to Install Monero Miner
Apple just released emergency updates to fix a critical flaw in macOS Screen Sharing that hackers were using to secretly install Monero miners on vulnerable Macs. The updates, available for macOS Tahoe, Sequoia, and Sonoma, patch a vulnerability that allowed attackers to bypass authentication and gain unauthorized access.

Hackers exploit macOS flaw to deploy Monero miners
Hackers are exploiting a recently fixed macOS security flaw to secretly deploy Monero miners, and experts warn that public exploit code is now available, putting users at risk. This vulnerability, affecting macOS's built-in Screen Sharing feature, allows attackers to gain access without valid credentials.

AmnesiaStealer Targets macOS via ClickFix Social Engineering
Mac users beware: a new threat called AmnesiaStealer is targeting macOS devices through clever social engineering tactics known as ClickFix, tricking victims into installing malware via a fake GitHub download page. One wrong click could compromise your entire system.

OpenAI Introduces Keylogging Feature for ChatGPT Users
OpenAI's new Computer History feature for ChatGPT users raises some red flags, capturing a detailed stream of interactions like clicks, typing, and keyboard shortcuts from allowed apps and websites, and storing them as local memory files that could potentially be accessed by other programs on your macOS.

Go-Based Malware Targets macOS Crypto Wallets
Beware of a sneaky new scam targeting macOS crypto wallets: a fake CAPTCHA prompt tricks you into copying and pasting a malicious command that can download malware and compromise your wallet. One wrong click is all it takes to put your crypto at risk.

Malware Exploits ClickFix Attacks to Drain macOS Crypto Wallets
Beware: a sneaky malware called ClickFix is targeting macOS crypto wallets, slowly draining their contents into the pockets of cyber thieves. This cunning attack starts with a simple trick: victims are duped into pasting a malicious command into the Terminal app, unleashing a stealthy thief that siphons off cryptocurrency.

XCSSET Malware Targets macOS Devs Through Compromised Xcode Projects
macOS developers, beware: XCSSET malware is lurking in compromised Xcode projects, infecting unsuspecting victims through a sneaky four-stage infection chain that can deploy 17 distinct modules. This latest variant has been rewritten to dig deep into your workflow and browser, putting your entire development ecosystem at risk.

Russian Loader Service Exploits Browser Cache to Deliver Malware
Meet DOUBLECUP, a sneaky Russian loader service that's been hiding in plain sight since June 2026, using browser cache tricks to deliver malware to unsuspecting victims. Its clever ClickFix campaigns conceal malicious code within innocent-looking PNG images, deploying nasty payloads like CountLoader and DeviceManager RAT on Windows and macOS devices.

DPRK Hackers Target macOS Users with Crypto-Stealing Malware via Fake Updates
DPRK hackers have launched a sneaky attack on macOS users, using fake update screens to trick them into installing crypto-stealing malware. The clever tactic involves a full-screen fake update that quietly copies an attack command to the clipboard, making it look like the computer is frozen or rebooting.

Gatekeeper Flaw Lets Attackers Swap macOS Apps with Malicious Twins
A newly discovered flaw in macOS Gatekeeper could let attackers secretly swap your downloaded apps with malicious versions, putting your device and data at risk. Researchers have found a way to bypass Gatekeeper's security checks, allowing them to replace apps with tampered versions without needing special privileges.

ClickLock Malware Forces macOS Users to Reveal Login Passwords
Beware: a sneaky new malware called ClickLock has already compromised over 100 macOS systems in 33 countries, tricking users into revealing their login passwords. This stealthy threat has been hiding in plain sight since May, leaving a trail of vulnerable systems in its wake.

ClickLock Malware Targets macOS Users with Coercive Password Theft Tactic
Beware: a new malware called ClickLock is coercing macOS users into handing over their login passwords by rendering their desktop unusable until they comply. This sneaky tactic has already hit at least 100 targets across 33 countries since May.

PamStealer Targets Mac Users with Fake Maccy Sites and PAM Checks
Researchers have uncovered PamStealer, a sneaky macOS information stealer that tricks users into downloading it from fake Maccy sites, and it can even slip past Apple's security measures. This clever malware uses a two-stage delivery method to steal sensitive info from unsuspecting Mac users.

Cybercriminals Exploit ClickFix to Deliver Malware
Don't assume macOS is safe from cyber threats - a recent report warns that it now requires the same level of monitoring and protection as Windows to prevent malware attacks. Cybercriminals are using the ClickFix technique to deliver malware, tricking victims into running malicious commands.

Apple Bolsters Security with AI-Discovered WebKit Flaw Patches
Apple is stepping up its security game by releasing patches for over three dozen WebKit flaws, discovered with the help of AI, to protect its users from potential hacking threats. By speeding up its update process, Apple aims to outpace malicious hackers who are leveraging AI to develop exploits at an alarming rate.

macOS Flaw Enables Users to Disable EDR, MDM Tools
A security flaw in macOS has been discovered that allows users to quietly disable crucial enterprise security tools, including EDR and MDM, without needing administrator privileges. This gap in endpoint security models could leave businesses vulnerable to attacks.

MacOS Update Exposes New Artifact for Tracing Digital Intent
The latest macOS update has introduced a game-changing digital trail: the App.MenuItem stream, which meticulously logs every menu selection you make, complete with exact timestamps. This new artifact reveals a detailed narrative of your interactions with the operating system interface.

Malvertising Campaign Spreads FlutterShell Backdoor to macOS Users
macOS users beware: a sneaky malware called FlutterShell is spreading through malicious ads and infected desktop apps, allowing hackers to take control of your device and steal sensitive data. This stealthy backdoor can execute commands, access files, and even siphon off browser session info - all while masquerading as legitimate software.

Malvertising Campaign Targets macOS with FlutterShell Backdoor
Google swiftly suspended advertiser accounts linked to a massive malvertising campaign that spread a new macOS backdoor, known as FlutterShell, after researchers sounded the alarm. The culprits, tracked by Palo Alto Networks as CL-CRI-1089, used hundreds of verified Google ads and a web of shell companies to deceive ad networks.

Google Chrome Bolsters Defenses with Cookie Theft Protection Rollout
Google's new Cookie Theft Protection is a game-changer, tying session cookies to device hardware to prevent hackers from using stolen cookies to access your accounts. This cutting-edge tech binds user sessions to a machine's security chip, making it virtually impossible for thieves to get in.