A new variant of the XCSSET malware has emerged, specifically targeting macOS developers by exploiting compromised Xcode projects and GitHub repositories. This malware is designed to infiltrate the development environment, potentially affecting thousands of users who download these compromised projects. Researchers have identified that the malware can steal sensitive information, including user credentials and private data, which poses a significant risk to both developers and their end users. As this malware spreads, it raises concerns about the security of development tools and the integrity of software supply chains. Developers are urged to be vigilant about the sources of their code and to implement security measures to protect their environments.
Articles tagged "Apple"
Found 103 articles
Cybersecurity Blog | SentinelOne
In a recent cybersecurity effort, police have flagged around 4,000 URLs associated with a group known as The Com, aiming to disrupt their activities. This group is linked to various cybercrimes, but specific details on their operations were not disclosed. In another incident, victims of a $1.8 million cryptocurrency wallet scam are suing Apple, claiming the company failed to protect them from fraudulent apps in its App Store. Meanwhile, research from OpenAI and Anthropic indicates that their AI models are being tested in real-world systems, raising concerns about how these technologies could be used in cyber attacks. These incidents illustrate the ongoing challenges in cybersecurity, where both technological advancements and criminal activities continue to evolve rapidly.
The Hacker News
Researchers have linked a new macOS malvertising campaign to North Korean actors, who are using deceptive tactics to deliver malware. The attackers redirect users to fake web pages that mimic legitimate macOS update screens, tricking them into thinking they need to install an update. Once users interact with these screens, malware is installed on their devices, specifically designed to steal cryptocurrency. This campaign is a continuation of the ongoing Contagious Interview campaign, raising concerns about the security of macOS users who may fall victim to these tactics. It serves as a reminder for users to be cautious of unexpected update prompts and to verify the legitimacy of software updates before proceeding.
Apple is facing a lawsuit from three individuals who claim they lost nearly $1.8 million in Bitcoin due to a fraudulent app called Sparrow Wallet, which was available on the App Store. The plaintiffs downloaded the app, believing it to be a legitimate cryptocurrency wallet, only to discover that it was a scam designed to steal their funds. This incident raises serious concerns about the vetting process for apps on major platforms like Apple's App Store. Users need to be vigilant when downloading financial apps, as scammers are finding new ways to exploit unsuspecting individuals. The lawsuit could have implications for how Apple manages app security and user protection in the future.
Researchers have discovered a serious vulnerability in Anthropic's Claude Cowork that allows the AI agent to escape its Linux virtual machine (VM) environment. This flaw could enable the agent to access and manipulate files stored on the host Mac, potentially compromising user data. Approximately 500,000 macOS users are affected by this issue, as the vulnerability could be exploited by malicious actors. The implications are significant because it undermines the security measures designed to isolate applications from sensitive information on users' machines. Users are advised to stay alert for updates and patches that address this vulnerability.
SCM feed for Latest
Lookout has introduced a new tool aimed at assessing the security of mobile applications on both Android and iOS platforms. This tool works by analyzing the apps at the binary level, producing a software bill of materials that lists the components used in each application. It then cross-references these components with existing vulnerability databases and threat intelligence feeds to identify potential security risks. This development is significant as it helps developers and organizations understand the exposure risks associated with the software they deploy, which is crucial for protecting user data and maintaining application integrity. By providing insights into vulnerabilities, Lookout's tool aims to enhance the overall security posture of mobile applications.
Apple has addressed a significant security flaw in its Hide My Email service that allowed users' actual email addresses to be revealed in mail logs. This vulnerability was reported to Apple by Tyler Murphy, co-founder of EasyOptOuts, and the company rolled out a fix on July 3, 2026, after it had been known for over a year. The flaw undermined the privacy that the service is designed to provide, potentially exposing users to unwanted communications and privacy breaches. This incident serves as a reminder of the importance of robust privacy measures in digital services, particularly as more people rely on such tools to protect their personal information. Users of Apple's Hide My Email service are the primary individuals affected by this issue, as it directly impacts their privacy and security.
The latest Malware Newsletter from Security Affairs includes several notable malware threats. One of these is CrashStealer, a C++ infostealer for macOS that masquerades as a crash reporter, targeting users to extract sensitive information. Another threat, Lucide Proxy, is exploiting student web proxies to create DDoS bots, potentially impacting educational institutions. Additionally, the AsyncAPI npm organization has been compromised, affecting about 2 million weekly downloads, which raises concerns for developers relying on these packages. Lastly, OkoBot is a sophisticated malware framework specifically designed to target cryptocurrency users, highlighting the ongoing risks in the digital currency space. These developments illustrate the evolving tactics of cybercriminals and the need for users and organizations to stay vigilant.
Apple has issued a warning to iPhone and iPad users about a new scam that utilizes FaceTime calls to deceive people into giving away their financial information. Scammers impersonate trusted organizations, such as banks or Apple itself, using a technique called caller ID spoofing, which makes the call appear to come from a legitimate source. This manipulation aims to extract sensitive details like account credentials and security codes. Users need to be vigilant and verify any unexpected calls requesting personal information, as this scam can lead to significant financial loss. This situation is particularly concerning as it exploits a widely used communication tool, making it crucial for users to remain cautious and informed.
The Hacker News
A new piece of malware known as ClickLock Stealer is targeting macOS users by forcing them to input their login passwords. This infostealer operates by running a command in the Terminal that creates a fake system dialog asking for the password. If the victim cancels this request, the malware repeatedly kills various applications—including Finder and Terminal—every 210 milliseconds until the password is provided. Once the victim logs in again, the malware installs two LaunchAgents, allowing it to operate silently in the background. This type of attack is particularly concerning as it manipulates user behavior to extract sensitive information, highlighting the need for users to be cautious about unexpected prompts and commands.
Researchers have identified a new malware targeting macOS systems called CrashStealer, designed to steal sensitive information from compromised devices. What sets CrashStealer apart from other malware is its use of native C++ for implementation, rather than the more common AppleScript or Objective-C methods. This malware can validate the victim's login password locally, making it harder to detect. The use of a notarized dropper allows it to bypass Apple's Gatekeeper security checks, increasing its chances of successfully infecting systems. Users of macOS should be cautious and ensure their devices are protected against such threats, as this malware can lead to significant data breaches.
The Cybersecurity and Infrastructure Security Agency (CISA) has added a new vulnerability, CVE-2008-4128, to its Known Exploited Vulnerabilities Catalog. This vulnerability affects Cisco IOS and is associated with cross-site request forgery, which allows attackers to exploit vulnerable systems. It poses significant risks, particularly for federal agencies, as it can lead to total control over affected assets after exploitation. CISA's Binding Operational Directive 26-04 emphasizes the need for federal agencies to prioritize rapid remediation of such high-risk vulnerabilities. While this directive primarily applies to federal agencies, CISA encourages all organizations to adopt similar practices for managing vulnerabilities effectively. Agencies are also urged to check for any compromises before applying patches to mitigate risks.
SCM feed for Latest
QuimaRAT is a new type of malware that can target multiple operating systems, including Windows, Linux, and macOS. It operates on a modular architecture, which means it can expand its capabilities through encrypted plugins that are delivered via a command-and-control infrastructure. This flexibility allows attackers to adapt the malware for various malicious purposes. The versatility of QuimaRAT raises concerns for users across different platforms, as it poses a significant risk to both personal and organizational security. Companies and individuals should be vigilant and consider implementing security measures to protect their systems from this evolving threat.
Researchers from Jamf Threat Labs have identified a new malware targeting macOS users, named PamStealer. This information stealer masquerades as a legitimate application called Maccy, which is a popular open-source clipboard manager. By distributing a compiled AppleScript file that looks legitimate, PamStealer tricks users into downloading it. Once installed, it seeks to extract sensitive information, including Mac login passwords. This incident is concerning for Mac users, as it highlights the ongoing risks posed by malware that exploits trusted applications to gain access to personal data.
The Hacker News
This week's security updates reveal a series of vulnerabilities across various systems, including browsers, AI tools, and email services. Researchers discovered that many of these weaknesses stem from small permission gaps and inadequate security checks, which attackers can exploit. Notably, the article mentions the BlueHammer ransomware, which targets businesses by leveraging these types of vulnerabilities. This situation underscores the need for organizations to regularly assess their security measures and patch any identified weaknesses to prevent potential breaches. Overall, the findings serve as a reminder that even seemingly secure systems can harbor significant risks if not properly maintained.