#macOS
25 stories taggedmacOS.

The macOS ClickFix Scam Learned to Hide From Researchers
Microsoft says the fake-fix lure now checks your browser before showing itself, and a related campaign is pushing a new remote-control tool called ChainScript.

Homebrew 7.0.0 ships a vulnerability scanner and locks down its sandbox
The macOS package manager now checks installed software against a public flaw database and blocks default access to your home folder.

Parallels Desktop Bug Hands Root to Any Mac User, and Older Macs Can't Get the Patch
A flaw in Parallels Desktop for Mac lets a normal user seize full control of the machine. The fix ships only in Parallels Desktop 27, which won't install on Intel-based Macs.

Iranian Hackers Nimbus Manticore Target Mac and Linux With Fake Job Tests
Kaspersky says the state-linked crew is now posing as recruiters and hiding remote-access malware inside coding challenges sent to job hunters.

Microsoft Ties 30+ Rotating Domains to MacSync, a New Mac Data-Stealing Malware
Defender Experts traced the macOS stealer across shifting web infrastructure by matching endpoint and network behaviour, not just domain names.

Apple Patches Dozens of WebKit Flaws That Could Let Attackers Crash or Spy on Your iPhone and Mac
A wave of security fixes landed for iPhones and Macs, closing holes in the browser engine that powers Safari. Some bugs were serious enough to let criminals steal data or break out of the software's built-in safety walls.

Dutch cyber agency warns of live attacks on macOS Screen Sharing flaw
Hackers are breaking into Mac computers exposed to the internet, seizing top-level control, and quietly mining Monero cryptocurrency.

AmnesiaStealer: New Mac Malware Quietly Drains Passwords and Browser Sessions
A newly identified piece of malicious software targeting Apple Mac computers can lift saved passwords, browser cookies, and sensitive keychain data, and it's written in a programming language that makes it harder for security tools to catch.

Microsoft and Apple Rush Out Patches for Flaws That Let Attackers In Without a Password
Several of the Microsoft bugs score a perfect 10 out of 10 for severity. Apple quietly fixed a flaw that lets someone access your screen without logging in.

Fake Mac Downloads Hide Behind 250+ Domains That Screen Visitors First
Microsoft says a large ClickFix network now checks who is knocking before showing macOS users a booby-trapped installer, keeping researchers and scanners out of view.

XCSSET Malware Returns With Chrome Hijacker and Fake Telegram App, Hitting Mac Developers
A refreshed version of the XCSSET macOS malware is spreading through poisoned Xcode projects on GitHub, stealing credentials and hijacking cryptocurrency payments.

Hackers Are Using a Legitimate Remote-Access Tool to Spy on Companies, and Your Antivirus Won't Notice
The Smoke#Screen campaign tricks employees into installing ScreenConnect, a genuine remote-support program, which then hands criminals full control of the victim's computer while looking completely normal to security software.

Apple Pushes Fixes for Hundreds of Security Flaws Across iPhones, Macs, and More
The latest software updates cover 87 flaws in iOS and 155 in macOS Tahoe, including one that lets a remote attacker corrupt the core of the operating system.

Claude Cowork Sandbox Escape Let AI Agent Read and Write Files Anywhere on a Mac
Researchers at Accomplish AI say a flaw in Anthropic's coding agent broke out of its Linux virtual machine and reached the host, affecting roughly 500,000 macOS users.

ClickLock Stealer Tricks Mac Users Into Handing Over Their Own Passwords
A newly discovered piece of Mac malware skips the usual hacking tricks and simply persuades victims to run it themselves, then locks the screen until they surrender their passwords.