Security Affairs newsletter Round 598 by Pierluigi Paganini – INTERNATIONAL EDITION
Overview
The latest Security Affairs newsletter covers a range of cybersecurity issues, including a new macOS backdoor disguised as a fake Zoom installer. This backdoor, known as CloudSyncD, poses a significant risk to macOS users who may unknowingly install this malicious software. Additionally, a critical vulnerability in GitLab's AI Gateway, identified as CVE-2026-90970, has been patched, addressing a serious security flaw that could have been exploited by attackers. The newsletter also highlights the Antino backdoor, which has been linked to various cyberattacks. These incidents emphasize the need for users and organizations to remain vigilant about the software they install and to apply security updates promptly.
Key Takeaways
- Affected Systems: macOS users, GitLab AI Gateway
- Action Required: Users are advised to avoid downloading software from unverified sources, specifically to not install fake Zoom installers.
- Timeline: Newly disclosed
Original Article Summary
A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box. Enjoy a new round of the weekly SecurityAffairs newsletter, including international press. Fake Zoom installer hides macOS backdoor CloudSyncD CVE-2026-90970: Critical GitLab AI Gateway Flaw Fixed Antino Backdoor Lets […]
Impact
macOS users, GitLab AI Gateway
Exploitation Status
No active exploitation has been reported at this time. However, organizations should still apply patches promptly as proof-of-concept code may exist.
Timeline
Newly disclosed
Remediation
Users are advised to avoid downloading software from unverified sources, specifically to not install fake Zoom installers. GitLab users should apply the security patch related to CVE-2026-90970 as soon as possible to protect their systems.
Additional Information
This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.
Related Topics: This incident relates to macOS, CVE, Apple, and 2 more.