#macOS
25 stories taggedmacOS · page 2 of 2.

CrashStealer: the new Mac malware that slips past Apple's own safety checks
Researchers at Jamf Threat Labs say the C++-based stealer used an Apple-notarised installer to bypass Gatekeeper and grab passwords, browser data and crypto wallets from macOS users.

PamStealer: Fake Maccy App Hides Mac Password-Grabbing Script
Researchers say the AppleScript malware poses as a popular clipboard tool, tricks users into typing their Mac password, then quietly ships browser data and crypto wallets to its operators.

ClickFix: Emerging Favorite for Cybercriminals in Malware Delivery
New ReliaQuest research shows ClickFix drove nearly 28% of defense-evasion activity between March and May 2026, and it's now hitting macOS for the first time.

Apple Pushes Emergency Fixes for Two Flaws Already Being Used to Attack iPhones and Macs
Two previously unknown security holes, one in the heart of Apple's operating system and one in its browser engine, are being actively exploited. Every iPhone, iPad, and Mac owner should update today.

Apple Ships Multi-Component Patch Round Covering iOS, macOS, and Safari
Fixes land for WebKit, the kernel, WebRTC, and Web Extensions, touching every major Apple platform in a single release cycle.

Apple Ships Three Dozen Fixes, Including WebKit Bugs Surfaced by LLM-Assisted Review
Four of the patched WebKit flaws were found with help from Claude and Codex, a quiet data point on how vendors are folding AI into vulnerability discovery.

North Korean Malware Tells AI Analyzers to Look Away
A macOS sample attributed to Pyongyang-linked actors contains prompts designed to make LLM-assisted security tools abandon their analysis. Defenders are starting to notice the pattern.

Week in Brief: Russia's Cellebrite Use, Five Eyes AI Warning, macOS Backdoor, Scattered Spider Pleas
State-backed mobile forensics against an activist, an intelligence alliance's AI advisory, a new Mac implant, and a cybercrime case moving toward sentencing.

Gaslight: A Rust macOS Stealer That Tries to Talk Your AI Analyst Out of Looking
The implant ships with an embedded prompt injection payload aimed at LLM-assisted reverse engineering tools, a small but telling escalation in adversarial tradecraft.

Non-Admin macOS Accounts Can Chain Native OS Features to Blind Endpoint Security Tools
No exploit required. Researchers found that standard user privileges are enough to chain macOS weaknesses and silently kill endpoint security agents without touching a vulnerability.