-
A Google-sponsored search result for Claude installation instructions is being used to deliver a sophisticated macOS stealer and remote-access trojan (RAT) named MacSync. The campaign abuses a legitimate Claude shared-conversation page on the claude.ai…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A newly identified macOS infostealer, named AmnesiaStealer, targets users via ClickFix social-engineering campaigns that impersonate GitHub download pages. This malware combines various malicious features, including password theft, browser data collect…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A macOS Keychain implementation weakness in Anthropic’s Claude Code CLI could allow any process running as the logged-in user including a Claude Code-spawned child process to retrieve the tool’s OAuth credential bundle silently. The issue underscores h…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A recently disclosed privilege-related vulnerability in the Common UNIX Printing System (CUPS) on macOS could allow an unprivileged local user to create attacker-controlled files in arbitrary locations outside the protection of System Integrity Protect…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
macOS users are facing a new, highly polished ClickFix campaign that abuses fake CAPTCHAs to execute Terminal commands, silently deploy Atomic macOS Stealer (AMOS), and systematically loot crypto wallets and browser‑stored credentials. This evolution o…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A highly convincing malvertising campaign is targeting macOS users searching for “how to install Claude Code on Mac,” delivering the MacSync infostealer through a trusted-looking workflow that abuses legitimate infrastructure rather than exploiting sof…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A new macOS stealer, tracked as Gaslight and attributed to North Korean operators, demonstrates a worrying evolution in malware design: deliberate prompt-injection to mislead AI-driven security tools. Gaslight arrives as a standalone Mach-O executable …
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
The newly spotted PamStealer is spreading through a fake Maccy clipboard app and steal Mac passwords, browser data and clipboard content.
·
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A macOS XPC flaw let regular users disable CrowdStrike and Kandji tools, exposing security gaps that vendors patched after XM Cyber reported the security issue.
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
The binary tracked as macOS.Gaslight as a Rust-based macOS implant and infostealer whose most novel features are analyst-directed prompt injection and a hardened Telegram-based command-and-control (C2) channel. We assess with high confidence that macOS…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶


