-
A highly convincing malvertising campaign is targeting macOS users searching for “how to install Claude Code on Mac,” delivering the MacSync infostealer through a trusted-looking workflow that abuses legitimate infrastructure rather than exploiting sof…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A new macOS stealer, tracked as Gaslight and attributed to North Korean operators, demonstrates a worrying evolution in malware design: deliberate prompt-injection to mislead AI-driven security tools. Gaslight arrives as a standalone Mach-O executable …
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
The newly spotted PamStealer is spreading through a fake Maccy clipboard app and steal Mac passwords, browser data and clipboard content.
·
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A macOS XPC flaw let regular users disable CrowdStrike and Kandji tools, exposing security gaps that vendors patched after XM Cyber reported the security issue.
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
The binary tracked as macOS.Gaslight as a Rust-based macOS implant and infostealer whose most novel features are analyst-directed prompt injection and a hardened Telegram-based command-and-control (C2) channel. We assess with high confidence that macOS…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
There is no one-size-fits-all cybersecurity laptop. We’ll examine real-world work scenarios, tool compatibility, and trade-offs that impact a security professional’s day-to-day work.
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Sapphire Sleet’s latest macOS campaign uses crafted .scpt AppleScript lures that pipe curl output directly to osascript, enabling a compact, multi-stage payload chain that executes entirely within Script Editor and evades many built‑in macOS protection…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A recent surge in macOS-targeted campaigns shows threat actors favoring weaponized disk images (.dmg) as the primary delivery mechanism for infostealer malware. Attackers are leveraging convincing, branded DMG installers and social-engineering tricks t…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Operation FlutterBridge uses fake Google ads and shell companies to deploy FlutterShell, a new macOS backdoor targeting unsuspecting users.
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶


