Advertisement
Apple Patches iOS/iPadOS 18 and macOS: 108 Vulnerabilities Addressed
Apple has released significant security updates for iOS/iPadOS 18 and macOS, fixing 108 vulnerabilities, none exploited in the wild.
Apple Screen Sharing Exploits: Secure Your macOS Systems Now
Critical vulnerabilities in Apple Screen Sharing are actively exploited, allowing system compromise. Learn how to secure macOS against these threats.
AmnesiaStealer macOS Malware Hijacks Browser Sessions via Remote Control
AmnesiaStealer targets macOS users via ClickFix attacks, cloning Chromium profiles to enable live remote control of authenticated browser sessions.
macOS Screen Sharing Flaw Exploited to Deploy Monero Miner
The Netherlands NCSC warns that hackers are actively exploiting an authentication bypass flaw in macOS Screen Sharing to deploy cryptocurrency miners.
ClickFix Attacks Deliver macOS Stealer Targeting Crypto
ClickFix social engineering campaigns target macOS users with Go-based infostealers designed to drain cryptocurrency wallets and credentials.
NatJack Attacks: Exploiting NAT Trust in Windows, Linux, macOS
Synack's research reveals NatJack attacks, a new class of NAT exploitation affecting Windows, Linux, and macOS, leveraging trust assumptions.
Advertisement
XCSSET v40 Malware Targets macOS Developers via Xcode
Discover how XCSSET v40 targets macOS developers using fileless persistence, memory execution, and Xcode project supply chain attacks.
ClickFix Attack Deploys macOS Infostealer for Crypto Theft
The ClickFix attack leverages a Go-based macOS infostealer to pilfer cryptocurrency, browser data, and Apple Keychain credentials via a Bash script loader.
ClickFix Campaign Uses Server-Side Fingerprinting to Hide macOS Malware
Over 250 ClickFix domains utilize server-side browser fingerprinting to evade security sandboxes and distribute macOS infostealers like AMOS.
DPRK-Linked macOS Malvertising Uses Fake Updates for Crypto Theft
North Korean threat actors are using deceptive full-screen macOS update pages to distribute crypto-stealing malware in a new Contagious Interview campaign.
Apple July 2026 Security Updates: Patching macOS 26 and Safari
Apple releases widespread security updates for macOS 26, legacy macOS 14 and 15, iOS, and Safari. Organizations must patch to mitigate remote execution risks.
Claude Cowork Sandbox Escape: VM to macOS File Access
A critical sandbox escape vulnerability in Anthropic's Claude Cowork allows AI agents to break out of their Linux VM, gaining full file access on macOS hosts, affecting…
ClickLock macOS Malware: Password Theft via Forced Login Prompt
ClickLock macOS malware terminates processes, simulating a system crash to force users into revealing their login password.
ClickLock macOS Stealer: How Attackers Coerce Victims via App Kill Loops
ClickLock is a new macOS infostealer that terminates essential system processes every 210ms to force users into disclosing their login passwords.
PamStealer: New macOS Malware Targets PAM for Password Exfiltration
Jamf Threat Labs identifies PamStealer, a macOS malware using fake sites and AppleScript to steal login passwords through PAM exploitation.
June Apple Security Updates for iOS, macOS, Safari: Patch Now
Apple released essential security updates for iOS/iPadOS, macOS, and Safari in June. Learn why timely patching is critical for protecting your devices and data.
AirDrop and Quick Share: Proximity Flaws Cause Crashes and Bypass Checks
Researchers found six security flaws in AirDrop and Quick Share, enabling nearby attackers to crash devices and bypass security checks without user interaction.
JINX-0164 Targets Crypto Firms with macOS Malware and Fake Lures
The JINX-0164 threat actor targets cryptocurrency firms via recruitment-themed social engineering, macOS-specific malware, and CI/CD infrastructure exploits.
AI-Assisted macOS Kernel Exploit on Apple M5 Hardware
Security researchers used Anthropic’s Mythos AI to develop a macOS kernel memory corruption exploit for the Apple M5 chip in just five days. Patch now.
SHub Reaper Stealer Backdoors macOS via Spoofed Apps
SHub Reaper stealer targets macOS, using fake Google, Microsoft, Apple, WeChat, and Miro installers for Apple script-based execution and backdooring.
SHub macOS Infostealer Spoofs Apple Security Updates, Installs Backdoor
A new SHub macOS infostealer variant employs fake Apple security update prompts via AppleScript to install a backdoor, threatening user data and system integrity.
CVE-2024-38812: How to Mitigate VMware Fusion Privilege Escalation
VMware Fusion 13.6 fixes a high-severity local privilege escalation flaw (CVE-2024-38812) that allows attackers to gain root access on macOS hosts.
Apple macOS Sonoma 14.5 and iOS 17.5 Patch Technical Analysis
Apple addresses critical security flaws in macOS and iOS, including kernel-level RCE and a privacy bug causing deleted media to reappear on devices.
Apple May 2024 Security Updates Address 84 Vulnerabilities
Apple's May 2024 security updates patch 84 vulnerabilities across iOS, macOS, watchOS, tvOS, and visionOS. Immediate patching is crucial for all users.