Cybersecurity News
Filters
Filtered by tag: macos × Clear
Fake Codex Download Uses Google Sites to Deliver macOS Malware
Attackers created fake codec download pages hosted on Google Sites to distribute macOS malware. The campaign used sponsored search results to drive traffic and employed a ClickFix-style social engineering technique, tricking users into manually running malicious commands. The use of Google's infrastructure helped bypass security warnings and lend the pages false legitimacy.
AmnesiaStealer Gives Hackers Hidden Control of Logged-In Browsers on Macs
Matched: cryptocurrency
AmnesiaStealer is a new macOS malware spread via fake GitHub pages that trick users into running a Terminal command. Beyond stealing passwords, cookies, and keychain data, it can silently mirror an active browser session in a hidden Chromium instance, giving attackers real-time control of already-authenticated accounts. This makes MFA protections ineffective. A LaunchDaemon ensures persistence after the initial infection.
Hackers Actively Exploiting macOS’s Built-in Screen Sharing Service Vulnerability in the Wild
Matched: cryptocurrency
Hackers are exploiting a flaw in macOS's built-in Screen Sharing service to gain root-level access to devices. Attackers are using the remote-access feature to place files, alter system settings, and deploy cryptocurrency mining malware. The threat is notable because Screen Sharing ships enabled on many Macs, giving attackers a widely available entry point on a limited number of targeted systems.
MacOS users warned to beware screen-sharing bug which can turn Macs into cryptomining slaves
Apple has patched a critical vulnerability in macOS Screen Sharing that could allow attackers to gain unauthorized access to devices and use them for cryptomining. The flaw posed significant risk to affected users. MacOS users are urged to update their systems immediately to protect against potential exploitation.
Apple macOS Screen Sharing Flaw Exploited on Internet-Exposed Macs to Install Monero Miner
Matched: cryptocurrency
A critical macOS vulnerability (CVE-2026-65400, CVSS 9.8) in the Screen Sharing component is being actively exploited to install Monero mining malware on internet-exposed Macs, according to the Netherlands NCSC. The flaw allows network-based attackers to bypass authentication. Users are urged to apply Apple's patch immediately and limit exposure of Screen Sharing services.
From Screen Share to Root Access: Breaking Down CVE-2026-43760 and CVE-2026-65400 on macOS
Two vulnerabilities in macOS's Screen Sharing server were patched in a recent Apple update. CVE-2026-43760 allows pre-authenticated remote code execution, meaning attackers need no credentials to exploit it. CVE-2026-65400 can grant root-level access. Together, the flaws present a serious risk to users with Screen Sharing enabled. Apple has released fixes and users are urged to update immediately.
ClickFix Attacks Deliver macOS Stealer That Can Drain Crypto Wallets
Matched: cryptocurrency
A ClickFix-style attack campaign is targeting macOS users with Go-based malware that steals cryptocurrency, browser passwords, Apple iCloud Keychain data, and cached credentials. The infection chain uses a shell script to profile the host before delivering a CPU-compatible payload, allowing attackers to drain crypto wallets and harvest sensitive data from compromised machines.
Mac Malware Drains Crypto Wallets Via Fake CAPTCHA Scam
A Mac user was tricked by a fake CAPTCHA prompt into running a Terminal command that installed Go-based malware. The attack, a variant of the ClickFix scam, gave attackers access to macOS Keychain passwords and cryptocurrency wallets. Security researchers warn the technique is growing more common and targets users across platforms.
North Korean EtherHiding Campaign Targets Crypto Wallets and Developer Credentials
Matched: cryptocurrency
North Korean hackers are using fake macOS update screens to deploy malware targeting cryptocurrency wallets, browser data, and developer credentials. The campaign uses a ClickFix-style lure that makes browser pages appear broken, prompting users to run malicious commands. Entry points include routine web searches, making the attack difficult to detect.
