A reported macOS campaign linked to the ClickFix playbook shows how a large domain footprint can make a social-engineering operation harder to pin down.
A reported campaign turns job-interview code repositories and Terraform lock files into a delivery path for macOS implants, showing how infrastructure-as-code can be abused as a trust anchor.
A SentinelOne disclosure links Jade Sleet to an India-based IT services provider and two macOS backdoors, showing how developer-facing environments can matter far beyond one workstation.
A macOS backdoor tied to a GitHub job-lure chain shows how attackers can use ordinary-looking profile metadata to mask command-and-control infrastructure.
A critical Parallels Desktop flaw shows how a local helper service and sloppy command handling can turn an ordinary Mac account into full host control.
The iOS, iPadOS, and macOS updates released on September 14, 2026, point to a layered risk picture: WebKit, kernel, and privilege-boundary flaws that can matter most when chained together.
A new Apple security release cycle closes more than 100 vulnerabilities across iOS, macOS, and other devices, underscoring how many security boundaries can move at once in a single patch day.
A large Apple security release closes hundreds of holes, but the most telling part is where the highest-risk bugs sit: in code that can shape the behavior of the entire device.
A compromised Reddit identity tied to HBO Max was used in a ClickFix-style lure that tried to push macOS and Windows users into running attacker-controlled commands.
A hijacked HBO Max Reddit identity was used to push ClickFix-style malicious ads, showing how trust signals can be repurposed into an execution path for Windows and macOS users.
A security update for Parallels Desktop for Mac puts a spotlight on the software that sits between macOS and the virtual machines it runs.
A dedicated Gemini app has arrived for Windows after its earlier macOS release, turning a product move into a broader reminder that AI tools now live directly on the endpoint.
ClickFix-style lures and search-engine malvertising are being used to push MacSync Stealer by persuading victims to run attacker-controlled commands in Terminal.
A macOS stealer campaign built around social engineering shows how copy-paste deception can matter more than a software bug.
A new buyer’s guide puts familiar names in the spotlight, but the real story on macOS is how much protection users already have, and how much they still have to buy.
Trojanized DMG and PKG files are being used to push OtterCookie RAT through a Contagious Interview-linked campaign, turning ordinary software trust into the attack path.
A developer-targeting campaign is reportedly shifting from booby-trapped Git paths to trojanized Mac installers, turning routine software distribution into a stealthier delivery channel.
Three high-severity flaws in HP’s macOS setup flow show how a routine installer can become a privileged target when software is trusted to do too much.
Three CVEs in HP Easy Start for macOS show how a routine onboarding utility can become a privilege-boundary problem, with potential impact ranging from installation disruption to root-level file access under certain conditions.
Anthropic’s assistant is moving from answers to actions on macOS and Windows, turning a chat interface into a screen-driving agent with a much larger security footprint.