Meta Muse flaw widens local attack surface
Researcher says a local attacker can redirect Meta's Muse dictation traffic through an undocumented app setting, with no special privileges.
30 results for “mac”
Researcher says a local attacker can redirect Meta's Muse dictation traffic through an undocumented app setting, with no special privileges.
SentinelOne tied North Korea's Jade Sleet to an India-based IT services breach that deployed two Rust macOS backdoors on a DevOps engineer's MacBook.
The Hacker News explains how unregistered accounts and machine credentials keep IAM blind spots open across cloud estates.
Two Docker Sandboxes vulnerabilities let malicious guest code read or modify macOS host files, with fixes shipped in version 0.42.0.
Attackers used the verified HBO Max Reddit account to run 108 malicious ads in 48 hours, driving users to a fake download page.
Homebrew 7.0.0 ships a native GUI, a Homebrew-specific advisory database, and stronger sandboxing as attackers keep targeting the package manager.
Sysdig says a hand-built toolkit let a human operator exploit a Marimo flaw in eight seconds, without any sign of LLM use.
ClickFix attacks have spread from exotic to mainstream, infecting Windows and macOS users via fake CAPTCHAs and terminal commands.
AI is inventing a new vocabulary. Here's a plain-English guide to the terms you need to know.
BraZetsu framework turns compromised Windows machines into commercial inventory for Intermediary access brokers.
The researcher known as Nightmare Eclipse has released FalconFlank, a privilege escalation exploit targeting CrowdStrike Falcon via a Windows Office macro feature.
A human attacker used AI agents to breach a network in under 10 hours, leaving an 80-page audit.
Sevii's new module autonomously remediates AI-driven attacks at machine speed.
Autonomous AI attackers can chain cloud misconfigurations at machine speed, forcing CISOs to rethink defense.
Critics slam Omarchy's security, but backers put up $10M as Omacom Foundation launches.
Cato Networks found a campaign abusing Google Sites to spread macOS malware through ClickFix tactics.
Microsoft's Defender Experts linked 30+ domains via behavioral patterns, shifting Mac malware defense strategy.
CISA adds four actively exploited vulnerabilities affecting macOS, SharePoint, vCenter, and Windows IKE to its KEV catalog.
Apple ships 28-security-fix updates for macOS and iOS, covering two dozen WebKit bugs.
Researchers say a suspected China-nexus APT used a VMware flaw to deploy ransomware as a smoke screen.
New macOS infostealer AmnesiaStealer combines credential theft with silent remote browser control, researchers report.
A high-severity macOS bug is under attack, with hackers placing Monero miners via port 5900.
Marco Arment's new app makes reminders impossible to dismiss, scaling snooze intervals to keep tasks visible until done.
Researchers have uncovered a new macOS infostealer that uses ClickFix social engineering and has stealthy remote browser control capabilities.
Huntress discovers macOS stealer via ClickFix, targeting crypto wallets and credentials.
A newly identified Go-based malware targets macOS users by leveraging social engineering to steal credentials and crypto assets.
An experimental project allows full macOS to run on jailbroken iPads, highlighting significant technical friction and functional barriers.
An unauthenticated remote code execution vulnerability in Nuxt DevTools allows attackers to run arbitrary commands on developer machines via the HMR port.
Recent updates address hundreds of vulnerabilities across iOS and macOS platforms, highlighting significant risks in kernel security.
A critical vulnerability in Anthropic's Claude Cowork allows AI agents to escape their Linux virtual environment and access host macOS data.