Cybersecurity News

Filters
Tag
Reset

Filtered by tag: macos × Clear

Fake Codex Download Uses Google Sites to Deliver macOS Malware

Attackers created fake codec download pages hosted on Google Sites to distribute macOS malware. The campaign used sponsored search results to drive traffic and employed a ClickFix-style social engineering technique, tricking users into manually running malicious commands. The use of Google's infrastructure helped bypass security warnings and lend the pages false legitimacy.

AmnesiaStealer Gives Hackers Hidden Control of Logged-In Browsers on Macs

Matched: cryptocurrency

AmnesiaStealer is a new macOS malware spread via fake GitHub pages that trick users into running a Terminal command. Beyond stealing passwords, cookies, and keychain data, it can silently mirror an active browser session in a hidden Chromium instance, giving attackers real-time control of already-authenticated accounts. This makes MFA protections ineffective. A LaunchDaemon ensures persistence after the initial infection.

Hackers Actively Exploiting macOS’s Built-in Screen Sharing Service Vulnerability in the Wild

Matched: cryptocurrency

Hackers are exploiting a flaw in macOS's built-in Screen Sharing service to gain root-level access to devices. Attackers are using the remote-access feature to place files, alter system settings, and deploy cryptocurrency mining malware. The threat is notable because Screen Sharing ships enabled on many Macs, giving attackers a widely available entry point on a limited number of targeted systems.

Apple macOS Screen Sharing Flaw Exploited on Internet-Exposed Macs to Install Monero Miner

Matched: cryptocurrency

A critical macOS vulnerability (CVE-2026-65400, CVSS 9.8) in the Screen Sharing component is being actively exploited to install Monero mining malware on internet-exposed Macs, according to the Netherlands NCSC. The flaw allows network-based attackers to bypass authentication. Users are urged to apply Apple's patch immediately and limit exposure of Screen Sharing services.

From Screen Share to Root Access: Breaking Down CVE-2026-43760 and CVE-2026-65400 on macOS

Two vulnerabilities in macOS's Screen Sharing server were patched in a recent Apple update. CVE-2026-43760 allows pre-authenticated remote code execution, meaning attackers need no credentials to exploit it. CVE-2026-65400 can grant root-level access. Together, the flaws present a serious risk to users with Screen Sharing enabled. Apple has released fixes and users are urged to update immediately.

ClickFix Attacks Deliver macOS Stealer That Can Drain Crypto Wallets

Matched: cryptocurrency

A ClickFix-style attack campaign is targeting macOS users with Go-based malware that steals cryptocurrency, browser passwords, Apple iCloud Keychain data, and cached credentials. The infection chain uses a shell script to profile the host before delivering a CPU-compatible payload, allowing attackers to drain crypto wallets and harvest sensitive data from compromised machines.

North Korean EtherHiding Campaign Targets Crypto Wallets and Developer Credentials

Matched: cryptocurrency

North Korean hackers are using fake macOS update screens to deploy malware targeting cryptocurrency wallets, browser data, and developer credentials. The campaign uses a ClickFix-style lure that makes browser pages appear broken, prompting users to run malicious commands. Entry points include routine web searches, making the attack difficult to detect.