Tag: macOS
-
Attackers hijack HBO Max’s Reddit account for 48-hour malvertising blitz
Attackers compromised the verified official HBO Max Reddit account, u/hbomax, and used its trusted advertising status to launch a ClickFix campaign targeting macOS and Windows … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/15/hbo-max-reddit-account-clickfix-infostealer-malware/
-
Product showcase: mSecure makes one vault do more than remember passwords
mSecure is a password manager and data vault for storing credentials and other sensitive information. It is available for iOS, Android, macOS, and Windows, with data … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/15/product-showcase-msecure-password-manager/
-
Product showcase: mSecure makes one vault do more than remember passwords
mSecure is a password manager and data vault for storing credentials and other sensitive information. It is available for iOS, Android, macOS, and Windows, with data … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/15/product-showcase-msecure-password-manager/
-
Homebrew 7.0.0 is out, here’s what changed for security
Homebrew installs command-line software and desktop applications from the terminal on macOS and Linux, and Mac developers use it to set up their machines. On Sunday the … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/15/homebrew-7-0-0-security-open-source/
-
Homebrew 7.0.0 is out, here’s what changed for security
Homebrew installs command-line software and desktop applications from the terminal on macOS and Linux, and Mac developers use it to set up their machines. On Sunday the … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/15/homebrew-7-0-0-security-open-source/
-
Homebrew 7.0.0 is out, here’s what changed for security
Homebrew installs command-line software and desktop applications from the terminal on macOS and Linux, and Mac developers use it to set up their machines. On Sunday the … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/15/homebrew-7-0-0-security-open-source/
-
Homebrew 7.0.0 is out, here’s what changed for security
Homebrew installs command-line software and desktop applications from the terminal on macOS and Linux, and Mac developers use it to set up their machines. On Sunday the … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/15/homebrew-7-0-0-security-open-source/
-
Hackers hijack HBO Max Reddit account to push malware in ClickFix ads
Hackers compromised HBO Max’s official Reddit account and used it to push malicious ads that launched ClickFix attacks to infect Windows and macOS devices with information-stealing malware. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/hackers-hijack-hbo-max-reddit-account-to-push-malware-in-clickfix-ads/
-
Contagious Interview Operators Move Beyond Git Hooks With Trojanized Mac Applications
North Korea-linked Contagious Interview operators have expanded their developer-targeting malware delivery operation beyond booby-trapped Git hooks and coding repositories, using trojanized macOS applications distributed as disk images and installer packages. Jamf Threat Labs identified 14 malicious DMG and PKG samples impersonating legitimate Mac software, all of which ultimately deliver an OtterCookie-aligned JavaScript implant designed for…
-
Three HP Easy Start Flaws Let Attackers Gain Root Privileges on macOS
Three high-severity vulnerabilities in HP Easy Start for macOS could allow both local and network-positioned attackers to disrupt the printer software installation process and, under certain conditions, gain privileged access or modify files with root permissions. These vulnerabilities, tracked as CVE-2026-12554, CVE-2026-12555, and CVE-2026-12556, were discovered by researcher Nir Yehoshua from Cipher Security Labs during…
-
Claude AI Can Now Control macOS and Windows Computers to Click, Type and Open Apps
Anthropic has enhanced Claude’s desktop automation capabilities, enabling the AI assistant to operate directly on macOS and Windows computers through Claude Cowork and Claude Code. When this feature is enabled, Claude can navigate a visible screen, click controls, type text, launch applications, open files, and work within browser-based or local tools if no dedicated connector…
-
Google Patches 26 Chrome Vulnerabilities, Including Critical WebGL and Shared Tab Groups Flaws
Google has released a new update for the Chrome Stable Channel on desktop platforms, addressing 26 security vulnerabilities. This includes two critical use-after-free flaws affecting WebGL and Shared Tab Groups. The update upgrades Chrome to version 152.0.7977.75 on Windows and macOS, while Linux users receive version 152.0.7977.76. Google stated that the update will be rolled…
-
CrowdStrike Adds Platform to Secure AI Agents Running on Endpoints
CrowdStrike today at its Fal.Con 2026 conference launched the Falcon Guardian platform that leverages a sensor to provide a live inventory of every active and dormant artificial intelligence (AI) agent running on a Windows or macOS endpoint. At the same time, CrowdStrike is launching Falcon Complete for Guardian, a managed service based on Guardian that..…
-
Iranian Hackers Pose as Recruiters to Deliver Cross-Platform RATs Through Coding Tests
The Iranian Nimbus Manticore hacking group has been attributed to two previously undocumented malware families that highlight the continued evolution of its toolset and likely expand its targeting footprint to infect Linux and Apple macOS systems using cross-platform remote access trojans (RATs) developed using Node.js and JavaScript.Russian cybersecurity company Kaspersky is tracking the First seen…
-
CVE-2026-65400: macOS Screen Sharing Authentication Bypass Under Active Exploitation
First seen on resecurity.com Jump to article: www.resecurity.com/blog/article/cve-2026-65400-macos-screen-sharing-authentication-bypass-under-active-exploitation
-
CVE-2026-65400: macOS Screen Sharing Authentication Bypass Under Active Exploitation
First seen on resecurity.com Jump to article: www.resecurity.com/blog/article/cve-2026-65400-macos-screen-sharing-authentication-bypass-under-active-exploitation
-
Google Chrome 152 Patches 327 Security Flaws, Including 10 Critical Vulnerabilities
Google has released Chrome version 152 for Windows, macOS, and Linux, addressing 327 security vulnerabilities, including 10 rated as Critical. This stable-channel update is being rolled out as version 152.0.7977.64 for Linux and 152.0.7977.64/.65 for Windows and macOS. This update is significant due to the sheer number and severity of memory-safety issues fixed across Chrome’s…
-
Fake OpenAI Codex download tricks macOS users into installing malware
A malware campaign using a sponsored search ad and a fake OpenAI Codex download page to trick macOS users into pasting a malicious command into Terminal has been uncovered by … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/08/25/fake-openai-codex-download-macos-users/
-
Hackers Place Fake Codex Download Above Legitimate OpenAI Result to Infect Mac Users
Threat actors are using sponsored Google Search ads to place a fake OpenAI Codex download page above the legitimate result, steering macOS users into manually executing malware through Terminal. The operation begins when users search for Codex-related terms, including “codex macos download.” Instead of selecting OpenAI’s legitimate listing, victims may encounter a sponsored result that…
-
5 Palo Alto GlobalProtect Flaws Let Attackers Gain SYSTEM/Root Access and Steal AD Passwords
Security researcher Martijn van Ramesdonk has disclosed five vulnerabilities affecting Palo Alto Networks’ GlobalProtect, an enterprise VPN and endpoint agent widely used across corporate environments on Windows, macOS, and Linux. The issues include local privilege escalation vulnerabilities that could allow a low-privileged attacker with access to an endpoint to gain full SYSTEM privileges on Windows…
-
Fake Codex Download Uses Google Sites to Deliver macOS Malware
Fake Codex pages used Google Sites, sponsored search and ClickFix to target Mac users First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/fake-codex-download-google-sites/
-
MacSync Stealer Uses 30+ Rotating Domains to Steal macOS Credentials and Exfiltrate Data
MacSync Stealer is expanding its macOS-focused theft operation through a rotating network of more than 30 domains, using stable execution and network patterns to steal credentials, browser data, cloud access keys, SSH material, and sensitive user files. Earlier research by RST Cloud identified MacSync infrastructure and observed command-and-control replacement after public disclosure. Microsoft’s subsequent telemetry-led…
-
Sequoia, Sonoma und Tahoe betroffen – Screen-Sharing-Schwachstelle in macOS wird aktiv ausgenutzt
First seen on security-insider.de Jump to article: www.security-insider.de/macos-screen-sharing-authentifizierungsfehler-cve-2026-65400-a-38474d316feea9b4b2b602026bb358ce/
-
Critical macOS, SharePoint, vCenter, and Microsoft IKE Flaws Under Active Exploitation
Tags: apple, authentication, cve, cybersecurity, exploit, flaw, infrastructure, kev, macOS, microsoft, vcenter, vulnerabilityThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added four critical vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, stating they are being exploited in the wild.The shortcomings added to the KEV catalog are listed below – CVE-2026-65400 (CVSS score: 9.8) – An improper authentication vulnerability impacting Apple macOS that could allow an…
-
Critical macOS, SharePoint, vCenter, and Microsoft IKE Flaws Under Active Exploitation
Tags: apple, authentication, cve, cybersecurity, exploit, flaw, infrastructure, kev, macOS, microsoft, vcenter, vulnerabilityThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added four critical vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, stating they are being exploited in the wild.The shortcomings added to the KEV catalog are listed below – CVE-2026-65400 (CVSS score: 9.8) – An improper authentication vulnerability impacting Apple macOS that could allow an…
-
Microsoft Links 30+ Rotating Domains to MacSync Stealer Infrastructure
Microsoft Defender Experts have linked more than 30 web domains to MacSync Stealer, a macOS-focused information stealer, after correlating recurring endpoint and network behaviors across changing infrastructure, tracing the malware from payload retrieval through data collection, staging, and exfiltration.The tech giant said it required multiple endpoint and network behaviors to align before First seen on…
-
Microsoft Links 30+ Domains to MacSync Stealer’s Credential-Theft and Data-Exfiltration Infrastructure
More than 30 domains tied to MacSync Stealer, exposing a rotating macOS-focused infrastructure that supports payload delivery, command-and-control, credential theft, staging, and chunked data exfiltration. The investigation shows why defenders should prioritize repeatable endpoint and network behavior over static domain-based detections. Observed executions originate from interactive zsh sessions and use curl to fetch payloads from…

