Discover how Apple gift card chips in iOS 27 will stop retail fraud. Learn about the new tap to redeem feature and enhanced security verifications.
Related Posts:
Google Photos Modifies Its Trash Retention Policy
Brave Search API Shifts Its New Plans to Prepaid Billing
Google Overhauls European Search Engine Results
The post Apple Embeds Security Chips to Combat Gift Card Fraud appeared first on Daily CyberSecurity.
Researchers built a WeChat worm that spreads through incoming calls without user action. Tencent has blocked the exploit.
Researchers at Calif created a WeChat worm that can take over an account through an incoming call, even if the victim never answers or touches the phone.
The attack works only when the caller already appears in the victim’s WeChat contacts. Calif reported the flaw to Tencent in July, and Tencent has blocked the exploit for all users. The good news is that researchers
Researchers built a WeChat worm that spreads through incoming calls without user action. Tencent has blocked the exploit.
Researchers at Calif created a WeChat worm that can take over an account through an incoming call, even if the victim never answers or touches the phone.
The attack works only when the caller already appears in the victim’s WeChat contacts. Calif reported the flaw to Tencent in July, and Tencent has blocked the exploit for all users. The good news is that researchers found no evidence that attackers used the flaw in real-world attacks, but the case shows how dangerous zero-click vulnerabilities can be.
“Simply by calling a victim, WeWorm can hijack their account and call their friends, spreading from phone to phone.” reads the report at Calif. “If exploited, actors can compromise over a billion phones (or accounts), upending livelihoods and breaking communities worldwide.”
Researchers built a demo WeChat worm that spread between three test phones without requiring any action from the victims. They started with a Pixel 10a and called an iPhone 17e, exploiting the flaw while the phone was still ringing. After taking control of the iPhone, they used it to call another Pixel 10a and compromise that device too. In other words, one compromised account can become the starting point for the next attack.
The exploit works within seconds and gives the attacker full control of the victim’s WeChat account. They can read and send messages, make calls and use the account as if they were the victim. The victim does not need to answer or touch the phone. Even answering the call does not stop the attack. Declining the call blocks that attempt, but the attacker can simply try again later.
The main limitation is that the attacker must already be a WeChat contact. However, compromising one of the victim’s friends could provide a way around that restriction.
“The victim does not need to answer the call, or interact with their phone at all. Even if they do answer, they hear nothing, and the exploit still succeeds. Declining the call stops that attempt, but the attacker can simply try again later, for example, while the victim is asleep.” the researchers explain. “This exploit requires the attacker to be on the victim’s friend list. But that’s not much of a barrier: an attacker can compromise one of your friends first and use their account to reach you.”
Calif published both Android and iOS RCE demos. The firm did not disclose technical details about the issue and will present the full analysis at a conference. For now, defenders have no clear indicators to search for, and users cannot tell if attackers targeted them with a call.
Combined with other Android and iOS flaws, the attack could also lead to full device control.
Researchers say AI helped them find the flaw and build an RCE exploit in about two days. They then built the worm in another week. They argue that AI is making advanced attack capabilities available to less-skilled attackers, increasing the risk of zero-click threats.
Researchers say the goal of publishing the findings is to raise awareness and encourage governments and technology companies to work together on AI security.
The WeChat flaw comes from a memory corruption bug in the app’s VoIP system. Researchers are keeping the technical details private for now and plan to present their full analysis at a future security conference.
The team believes this bug is just one example of the unusual attack surfaces found in messaging apps. They are researching similar weaknesses in other apps and working with developers to reduce these risks. Some changes may require cooperation from platform owners. Once the work progresses, they plan to publish more details about the WeChat flaw.
In August, Tencent released versions Android 8.0.77 and iOS 8.0.76 that addressed the issue.
WeChat is Tencent’s messaging and social platform, launched in 2011 and now much more than a chat app. It lets users send messages, make voice and video calls, create group chats and share content through Moments. It also includes official accounts, video channels, games, search and Mini Programs, which provide services such as shopping, bookings and deliveries without requiring separate apps.
In China, its local version, Weixin, also integrates Weixin Pay for mobile payments. Tencent reported 1.418 billion combined monthly active users for Weixin and WeChat at the end of 2025, making the platform one of the world’s largest messaging ecosystems.
You've had your iPhone stolen. A day later, you get a text from Apple saying they've found it, and a very helpful woman called Alice from Apple Support calls to walk you through recovering it. She's polite. She's professional. But she is not from Apple. She's not even human. And she's about to break into your iPhone.
Meanwhile, OpenAI, Anthropic, and Meta have all announced - with varying degrees of drama - that their AI agents have "broken out of the sandbox" and gone hacking. James takes a
You've had your iPhone stolen. A day later, you get a text from Apple saying they've found it, and a very helpful woman called Alice from Apple Support calls to walk you through recovering it. She's polite. She's professional. But she is not from Apple. She's not even human. And she's about to break into your iPhone.
Meanwhile, OpenAI, Anthropic, and Meta have all announced - with varying degrees of drama - that their AI agents have "broken out of the sandbox" and gone hacking. James takes a step back and asks the awkward question: is this really an emergent AI apocalypse, or did they just leave the door open?
All this and more in episode 483 of the "Smashing Security" podcast with cybersecurity expert and keynote speaker Graham Cluley, and special guest James Ball.
The Apple OpenAI lawsuit intensifies as Apple accuses a former engineer of using stolen trade secrets to train AI agents and destroying digital evidence.
Related Posts:
Darwin-VM Enables Apple Silicon Security Research
Chrome Manifest V2 Removal: Legacy Extensions Are Now Gone
Anthropic Bolsters Security After Claude AI Escapes
The post Apple OpenAI Lawsuit Escalates Over AI Trade Secrets appeared first on Daily CyberSecurity.
The Apple OpenAI lawsuit intensifies as Apple accuses a former engineer of using stolen trade secrets to train AI agents and destroying digital evidence.
A newly uncovered phishing-as-a-service (PhaaS) platform called AnonyMousKIT automates the retrieval of codes used to unlock stolen Apple devices and disable the Activation Lock feature. [...]
A newly uncovered phishing-as-a-service (PhaaS) platform called AnonyMousKIT automates the retrieval of codes used to unlock stolen Apple devices and disable the Activation Lock feature. [...]
Apple sent a new wave of mercenary spyware threat notifications to targeted users in 110 countries, while making the warnings more visible on iPhones. The alerts signal suspected targeting, not confirmed compromise, and Apple is urging affected users to verify the warning, consider Lockdown Mode, and seek expert help.
The post Apple Warns Users in 110 Countries of Mercenary Spyware as iPhone Alerts Get Harder to Miss appeared first on TechRepublic.
Apple sent a new wave of mercenary spyware threat notifications to targeted users in 110 countries, while making the warnings more visible on iPhones. The alerts signal suspected targeting, not confirmed compromise, and Apple is urging affected users to verify the warning, consider Lockdown Mode, and seek expert help.
Apple has released security updates for macOS, iOS, and iPadOS, addressing 28 vulnerabilities that could expose users to data leakage, application crashes, kernel memory access, and arbitrary code execution.
The updates were released on August 17, 2026, and include macOS Tahoe 26.6.2, iOS 26.6.1, iPadOS 26.6.1, iOS 18.7.10, and iPadOS 18.7.10. The company said the patches include fixes that were previously delivered through iOS, iPadOS, and macOS beta releases.
Apple follows a policy of wi
Apple has released security updates for macOS, iOS, and iPadOS, addressing 28 vulnerabilities that could expose users to data leakage, application crashes, kernel memory access, and arbitrary code execution.
The updates were released on August 17, 2026, and include macOS Tahoe 26.6.2, iOS 26.6.1, iPadOS 26.6.1, iOS 18.7.10, and iPadOS 18.7.10. The company said the patches include fixes that were previously delivered through iOS, iPadOS, and macOS beta releases.
Apple follows a policy of withholding technical details about security flaws until it completes an investigation and security updates are broadly available.
Several flaws affect components that process media, web content, and graphics. Apple fixed an integer overflow in ImageIO that could allow a specially crafted image to trigger arbitrary code execution. A separate ImageIO issue could cause a denial-of-service condition when a vulnerable device processes a malicious image.
Apple Fixes 28 Security Vulnerabilities
The updates also address multiple issues in IOGPUFamily, an Apple graphics framework. Apple warned that malicious web content could cause memory corruption.
At the same time, other flaws could enable remote attackers to terminate a system unexpectedly or allow a local application to read kernel memory. Such bugs are significant because the kernel runs with high privileges and controls core operating-system functions.
An additional kernel-level issue in the older iOS 18.7.10 and iPadOS 18.7.10 releases could allow a malicious application to execute arbitrary code with kernel privileges via a buffer overflow. Apple resolved the flaw through improved size validation.
Apple patched an Audio logic issue that could allow an application to leak sensitive user information. The company addressed the problem by adding improved checks. This vulnerability affects both macOS Tahoe 26.6.2 and the newer iOS and iPadOS releases.
The mobile updates also include an Accessibility fix for devices running iOS 18.7.10 and iPadOS 18.7.10. Apple said an attacker with physical access could potentially access sensitive data during iPhone Mirroring. This feature links an iPhone with a Mac. The issue was fixed through improved state management.
CVE
Component
Affected release(s)
Impact
Vulnerability type / remediation
CVE-2026-65339
Audio
iOS/iPadOS 26.6.1; macOS Tahoe 26.6.2
An app may leak sensitive user information
Logic issue; improved checks
CVE-2026-65347
ImageIO
iOS/iPadOS; macOS
Processing an image may cause DoS
Improved checks
CVE-2026-65346
ImageIO
iOS/iPadOS; macOS
Processing an image may enable arbitrary code execution
Integer overflow; improved input validation
CVE-2026-64788
IOGPUFamily
iOS/iPadOS; macOS
Crafted web content may cause memory corruption
Improved memory handling
CVE-2026-65343
Kernel
iOS/iPadOS; macOS
Remote attacker may terminate the system
Use-after-free; improved memory management
CVE-2026-65349
Kernel
iOS/iPadOS; macOS
App may terminate the system or read kernel memory
Out-of-bounds read; improved input validation
CVE-2026-65330
Kernel
iOS/iPadOS; macOS
App may terminate the system or corrupt kernel memory
Improved memory handling
CVE-2026-65329
Telephony
iOS 26.6.1 only; iPhone 11 and later
Privileged network attacker may bypass IPSec authentication and intercept traffic
Authentication issue; improved state management
CVE-2026-64784
WebKit
iOS/iPadOS; macOS
Crafted web content may crash Safari
Out-of-bounds access; improved bounds checking
CVE-2026-43795
WebKit
iOS/iPadOS; macOS
Crafted web content may crash Safari
Improved memory handling
CVE-2026-65338
WebKit
iOS/iPadOS; macOS
Crafted web content may crash Safari
Improved memory handling
CVE-2026-65341
WebKit
iOS/iPadOS; macOS
Crafted web content may cause memory corruption
Improved memory handling
CVE-2026-64782
WebKit
iOS/iPadOS; macOS
Crafted web content may crash Safari
Memory-corruption flaw; improved locking
CVE-2026-64781
WebKit
iOS/iPadOS; macOS
Crafted web content may crash Safari
Improved input validation
CVE-2026-65351
WebKit
iOS/iPadOS; macOS
Crafted web content may crash Safari
Improved state management
CVE-2026-65340
WebKit
iOS/iPadOS; macOS
Crafted web content may crash Safari
Improved state management
CVE-2026-65337
WebKit
iOS/iPadOS; macOS
Crafted web content may crash Safari
Improved state management
CVE-2026-65336
WebKit
iOS/iPadOS; macOS
Crafted web content may crash Safari
Improved state management
CVE-2026-65335
WebKit
iOS/iPadOS; macOS
Crafted web content may crash Safari
Improved state management
CVE-2026-65333
WebKit
iOS/iPadOS; macOS
Crafted web content may crash Safari
Improved state management
CVE-2026-65332
WebKit
iOS/iPadOS; macOS
Crafted web content may crash Safari
Improved state management
CVE-2026-65331
WebKit
iOS/iPadOS; macOS
Crafted web content may crash Safari
Improved state management
CVE-2026-64715
WebKit
iOS/iPadOS; macOS
Crafted web content may cause an unexpected process crash
Use-after-free; improved memory management
CVE-2026-64780
WebKit
iOS/iPadOS; macOS
Crafted web content may crash Safari
Improved checks
CVE-2026-65334
WebKit
iOS/iPadOS; macOS
Crafted web content may crash Safari
Memory-corruption flaw; improved state management
CVE-2026-43794
WebKit
iOS/iPadOS; macOS
Crafted web content may cause memory corruption
Memory-corruption flaw; improved memory handling
CVE-2026-64787
WebKit
iOS/iPadOS; macOS
Crafted web content may terminate a process
Use-after-free; improved memory management
CVE-2026-64778
WebKit History
iOS/iPadOS; macOS
Visiting a crafted website may leak sensitive data
Improved checks
CVE-2026-64779
WebKit Storage
iOS/iPadOS; macOS
Crafted web content may crash Safari
Memory-corruption flaw; improved locking
Apple also corrected an IPSec authentication issue in iOS 26.6.1 and iPadOS 26.6.1. A threat actor in a privileged network position could bypass IPSec authentication and intercept network traffic, posing a risk to users on hostile or compromised networks.
iOS 26.6.1 and iPadOS 26.6.1 are available for iPhone 11 and later, supported iPad Pro models, iPad Air 3rd generation and later, iPad 8th generation and later, and iPad mini 5th generation and later.
The iOS 18.7.10 and iPadOS 18.7.10 updates protect older iPhone XS, iPhone XS Max, iPhone XR, and iPad 7th-generation devices. Users should install the updates promptly. Apple notes that iPhone, iPad, Apple TV, Apple Watch, and Vision Pro software cannot be downgraded after an update is installed.
AmnesiaStealer malware targets macOS with data theft and remote browser-session control, potentially exposing accounts already open on compromised Macs.
The post Apple Mac Malware Lets Attackers Control Browser Sessions After Infection appeared first on TechRepublic.
AmnesiaStealer malware targets macOS with data theft and remote browser-session control, potentially exposing accounts already open on compromised Macs.
Apple has released security updates for iPhones, iPads, and Macs to address 28 vulnerabilities across its latest operating systems. These updates, issued on August 17, 2026, include iOS 26.6.1, iPadOS 26.6.1, macOS Tahoe 26.6.2, and security fixes for older devices with iOS 18.7.10 and iPadOS 18.7.10. The patches impact a wide range of supported Apple […]
The post Apple Addresses 28 Security Flaws Across macOS, iOS, and iPadOS appeared first on GBHackers Security | #1 Globally Trusted Cyber Secu
Apple has released security updates for iPhones, iPads, and Macs to address 28 vulnerabilities across its latest operating systems. These updates, issued on August 17, 2026, include iOS 26.6.1, iPadOS 26.6.1, macOS Tahoe 26.6.2, and security fixes for older devices with iOS 18.7.10 and iPadOS 18.7.10. The patches impact a wide range of supported Apple […]
Apple warns users of credible, targeted attacks and urges immediate verification, stronger protections, and expert assistance.
Apple has sent a new round of threat notifications to users it believes may have been singled out by mercenary spyware. The company told TechCrunch the latest alerts reached people in 110 countries, adding to notifications it has already issued in more than 150 countries since the programme began in 2021.
“Apple threat notifications are designed to inform and assi
Apple warns users of credible, targeted attacks and urges immediate verification, stronger protections, and expert assistance.
Apple has sent a new round of threat notifications to users it believes may have been singled out by mercenary spyware. The company told TechCrunch the latest alerts reached people in 110 countries, adding to notifications it has already issued in more than 150 countries since the programme began in 2021.
“Apple threat notifications are designed to inform and assist users who may have been individually targeted by mercenary spyware attacks, likely because of who they are or what they do. Such attacks are vastly more sophisticated than regular cybercriminal activity, as mercenary spyware attackers apply exceptional resources to target a very small number of specific individuals and their devices.” reads the alert. “Mercenary spyware attacks cost millions of dollars and often have a short shelf life, making them much harder to detect and prevent. The vast majority of users will never be targeted by such attacks.”
That alone should reset the usual mental model. This isn’t about a suspicious app, a recycled phishing email, or the kind of opportunistic malware that lands wherever it can. Apple’s alerts concern highly targeted attacks against particular people, often because of their role, their work, or the people they know.
The people most likely to receive these notifications include journalists, activists, politicians, diplomats, lawyers, and others whose devices may hold valuable conversations, contacts, documents, or location data. That does not mean every recipient has been fully compromised, but it does mean Apple has observed enough to treat the risk as credible.
Apple has also changed how it delivers those alerts. A recipient may see a push notification directly on the iPhone lock screen and in Settings, receive an email from threat-notifications@email.apple.com, and find a warning banner after signing in to their Apple Account. The company says genuine notices will never ask users to click a link, open a file, install a profile, or provide a password or verification code by email or phone.
“Apple relies solely on internal threat-intelligence information and investigations to detect such attacks. Although our investigations can never achieve absolute certainty, Apple threat notifications are high-confidence alerts that a user has been individually targeted by a mercenary spyware attack, and should be taken very seriously.” continues the report. “We are unable to provide information about what causes us to issue threat notifications, as that may help mercenary spyware attackers adapt their behavior to evade detection in the future.”
That lack of detail can frustrate recipients. They want to know who targeted them, how the device was approached, and whether the attacker got in. Apple can’t safely answer most of those questions in public, because publishing the detection logic would give spyware vendors a free quality-assurance report. Nobody needs to make Pegasus-style operators more efficient.
If you receive the warning, don’t panic and don’t start improvising. First, verify it by signing in directly at account.apple.com: a genuine Apple threat notification appears at the top of the page. Then preserve the device, avoid unnecessary resets or changes until you have spoken to someone qualified, and seek expert help, such as the Digital Security Helpline run by Access Now.
Apple recommends enabling Lockdown Mode, its high-security setting designed to reduce the attack surface available to sophisticated spyware. It also advises keeping devices updated, using a strong passcode with Touch ID or Face ID, turning on two-factor authentication, enabling Stolen Device Protection, using strong and unique passwords or passkeys, installing apps only through the App Store, and treating unexpected links or attachments as hostile until proven otherwise.
“Since 2021, we have sent Apple threat notifications multiple times a year as we have detected these attacks, and to date we have notified users in over 150 countries in total. The extreme cost, sophistication, and worldwide nature of mercenary spyware attacks make them some of the most advanced digital threats in existence today.” states the alert. “As a result, Apple does not attribute the attacks or resulting threat notifications to any specific attackers or geographical regions.”
The wider value of these alerts goes beyond the device in front of the recipient. Citizen Lab researcher John Scott-Railton told TechCrunch that notifications can reveal that an entire community is being targeted, because people who receive them often seek help and their cases lead investigators to others.
Most people will never receive one of these warnings. Apple says that plainly, and it is worth repeating because not every cybersecurity story needs to become a universal panic. But if your phone shows an Apple notice saying it detected a targeted mercenary spyware attack, assume it matters until an expert tells you otherwise.
The Netherlands' National Cyber Security Centre (NCSC) is warning that hackers are actively exploiting a macOS authentication bypass vulnerability after public exploit code emerged. [...]
The Netherlands' National Cyber Security Centre (NCSC) is warning that hackers are actively exploiting a macOS authentication bypass vulnerability after public exploit code emerged. [...]
Apple has issued a new set of high-confidence Apple Threat Notification alerts, warning selected iPhone users in 110 countries that they may be targets of government-grade mercenary spyware. These notifications are not routine phishing messages or general security advisories. According to Apple, these alerts are sent when internal threat intelligence indicates that a sophisticated and […]
The post Apple Warns iPhone Users in 110 Countries of Mercenary Spyware Attacks appeared first on GBHackers
Apple has issued a new set of high-confidence Apple Threat Notification alerts, warning selected iPhone users in 110 countries that they may be targets of government-grade mercenary spyware. These notifications are not routine phishing messages or general security advisories. According to Apple, these alerts are sent when internal threat intelligence indicates that a sophisticated and […]
Os usuários de Mac historicamente confiaram na segurança de seu sistema operacional. Essa tranquilidade vem principalmente do controle estrito da Apple sobre o ecossistema e do fato de que o macOS sempre enfrentou menos ataques em massa do que o Windows. No entanto, isso não significa que os computadores Mac não tenham vulnerabilidades: as ameaças existem, e novas surgem o tempo todo. Nas últimas semanas, pesquisadores de segurança publicaram relatórios sobre pelo menos duas novas campanhas dire
Os usuários de Mac historicamente confiaram na segurança de seu sistema operacional. Essa tranquilidade vem principalmente do controle estrito da Apple sobre o ecossistema e do fato de que o macOS sempre enfrentou menos ataques em massa do que o Windows. No entanto, isso não significa que os computadores Mac não tenham vulnerabilidades: as ameaças existem, e novas surgem o tempo todo. Nas últimas semanas, pesquisadores de segurança publicaram relatórios sobre pelo menos duas novas campanhas direcionadas a dispositivos Apple.
O malware usado em uma das campanhas foi apelidado de CrashStealer, enquanto o outro é conhecido como ClickLock. Ambos usam truques diferentes para forçar usuários a inserir a senha do Mac, que os invasores usam para roubar credenciais de contas, ativos de criptomoedas, documentos e muito mais. No post de hoje, analisamos em detalhes como o CrashStealer funciona e como evitar ser vítima dele.
Um aplicativo de videoconferência com o CrashStealer embutido
Em maio de 2026, pesquisadores identificaram os primeiros sinais de desenvolvimento desse malware e, no início de julho, detectaram sua atuação em ambiente real. O malware recebeu esse nome devido ao seu mecanismo principal: ele se disfarça da ferramenta integrada de geração de relatórios de falhas do macOS (CrashReporter), enquanto funciona como um infostealer criado para sequestrar dados confidenciais.
Os pesquisadores conseguiram rastrear um dos sites que os usuários visitaram para baixar o malware. O site se passa por uma plataforma legítima de distribuição da ferramenta de videoconferência Werkbit.
Segundo os pesquisadores, esse foi o site usado pelas vítimas para baixar o Werkbit, que continha, sem que elas soubessem, o malware loader CrashStealer. Fonte
No entanto, você não pode simplesmente visitar o site e baixar o software. Antes de iniciar o download, a pessoa precisa informar um PIN de reunião. Essa configuração provavelmente permite que os invasores limitem o alcance da campanha, direcionando-a apenas a vítimas específicas previamente selecionadas. Ainda não se sabe exatamente como os cibercriminosos escolhem seus alvos nem como entregam o PIN.
As pessoas “sortudas” que recebem um código acabam instalando a carga maliciosa inicial, chamada Werkbit Setup. Curiosamente, a carga maliciosa possui um certificado de desenvolvedor da Apple válido e foi aprovada no processo de autenticação de aplicativos da empresa, o que indica que passou pela verificação automatizada destinada a detectar código malicioso. Como resultado, os invasores conseguem contornar o Gatekeeper, mecanismo de proteção integrado do sistema operacional. Isso permite que a carga útil seja iniciada sem acionar os avisos usuais de software não confiável.
[caption] O instalador Werkbit Setup é assinado com um certificado válido de desenvolvedor da Apple e passou pelo processo de autenticação de aplicativos da empresa. Fonte
[/caption]Depois de iniciado, o Werkbit Setup primeiro se conecta ao GitHub. Pesquisadores acreditam que o uso dessa plataforma ajuda os invasores a passar despercebidos, fazendo com que as solicitações iniciais de rede pareçam muito menos suspeitas para as ferramentas de segurança. Depois de obter instruções de um repositório no GitHub, o programa se conecta diretamente ao servidor dos invasores para baixar o próprio CrashStealer.
Em seguida, o carregador salva o malware em uma pasta temporária do macOS, executa-o e apaga a maioria dos arquivos intermediários da instalação. Como resultado, em poucos segundos após a execução do Werkbit Setup, um infostealer totalmente funcional está em operação. Vale destacar que o usuário nunca recebe o aplicativo de videoconferência prometido.
Como o CrashStealer funciona
Ao contrário do carregador Werkbit Setup, o malware CrashStealer em si não é assinado com um certificado de desenvolvedor da Apple. Para evitar que os usuários desconfiem, o malware se disfarça da ferramenta de relatório de falhas do macOS, o CrashReporter, usando exatamente o mesmo nome, identificador de aplicativo e um ícone semelhante.
Depois de executado, o CrashStealer realiza uma sequência de etapas para obter acesso a dados confidenciais, estabelecer persistência no sistema e ocultar rastros:
Remove metadados, incluindo o atributo que identifica o aplicativo como um arquivo baixado da Internet.
Exibe uma solicitação falsa do sistema pedindo a senha do macOS do usuário.
Usa as credenciais capturadas anteriormente para acessar o Keychain, o gerenciador de senhas integrado do macOS.
Verifica se há ferramentas de segurança e softwares de análise de malware instalados no computador.
Coleta senhas salvas nos navegadores, cookies, dados do Keychain e informações de outros gerenciadores de senhas e carteiras de criptomoedas.
Criptografa os dados roubados e os prepara para envio ao servidor dos invasores.
Cria uma cópia de si mesmo e estabelece persistência para ser executado automaticamente sempre que o macOS é inicializado.
Exclui arquivos temporários e outros vestígios da instalação para dificultar ainda mais a detecção.
A segunda etapa merece uma análise mais detalhada. A solicitação de senha exibida ao usuário é extremamente convincente. Além disso, o malware verifica imediatamente se as credenciais estão corretas: se a pessoa cometer um erro de digitação e inserir uma senha inválida, o CrashStealer exibirá a janela novamente para que ela tente outra vez.
[caption] Depois de ser executado, o CrashStealer exibe uma janela pop-up que simula a solicitação padrão de senha do macOS. Fonte
[/caption]
Quais dados o CrashStealer tenta roubar?
A lista de alvos do CrashStealer é extensa. O principal alvo é o Keychain, o gerenciador de credenciais integrado do macOS, onde o sistema armazena credenciais de contas, chaves criptográficas, certificados, tokens e outros dados confidenciais.
Os usuários de gerenciadores de senhas de terceiros também não estão protegidos: o malware rouba dados de 14 desses serviços, incluindo 1Password, Bitwarden, LastPass, Dashlane, Keeper, KeePassXC, NordPass, Enpass e RoboForm.
Além disso, o malware coleta todas as credenciais e cookies armazenados em navegadores baseados no Chromium (Chrome, Brave, Edge, Opera, Opera GX, Vivaldi, Chromium e NAVER Whale) bem como no Firefox. Os invasores demonstram ter um grande interesse em ativos de criptomoedas: o CrashStealer tem como alvo específico os dados de 80 extensões diferentes de carteiras de criptomoedas, incluindo MetaMask, Phantom, Coinbase Wallet, Trust Wallet, Rabby, Exodus, Keplr e Solflare.
Por fim, o malware verifica as pastas Documentos e Downloads em busca de arquivos que possam ser de interesse dos cibercriminosos. O CrashStealer criptografa todos os dados roubados com o algoritmo AES-256-GCM, os compacta em um arquivo ZIP e os envia ao servidor dos invasores.
Como proteger seu dispositivo
O aumento dos ataques direcionados ao macOS é um claro sinal de alerta: quem usa dispositivos Apple precisa adotar uma postura mais proativa em relação à segurança. Recomendamos:
Pesquisar sobre os aplicativos na Internet antes de instalá-los
Dar preferência a utilitários disponíveis nas lojas de aplicativos oficiais sempre que possível
As soluções de segurança da Kaspersky detectam o malware descrito nesta publicação e atribuem a ele os veredictos HEUR:Trojan-Downloader.OSX.Agent.gen e HEUR:Trojan-PSW.OSX.Agent.gen.
CVE-2026-20685 is a path traversal vulnerability affecting Apple’s Private Cloud Compute (PCC), potentially allowing attackers to write files as root during node boot and redirect sensitive AI inference telemetry to an external server.
Sentry Security researcher Drinor received a $150,000 Apple Security Bounty for discovering and reporting CVE-2026-20685, a flaw that could expose sensitive data and allow unauthorized access.
PCC is Apple’s server-side platform for Apple Intelligence reques
CVE-2026-20685 is a path traversal vulnerability affecting Apple’s Private Cloud Compute (PCC), potentially allowing attackers to write files as root during node boot and redirect sensitive AI inference telemetry to an external server.
Sentry Security researcher Drinor received a $150,000 Apple Security Bounty for discovering and reporting CVE-2026-20685, a flaw that could expose sensitive data and allow unauthorized access.
PCC is Apple’s server-side platform for Apple Intelligence requests that are too complex to run entirely on an iPhone, iPad, or Mac. Apple describes the system as an extension of device-level privacy protections into the cloud.
Its design relies on stateless request processing, cryptographic attestation of approved software, and tightly controlled logging systems.
The flaw was found in darwin-init, the first userspace process launched on a PCC node. Running as PID 1 with root privileges, darwin-init downloads, extracts, personalizes, and installs cryptex packages before triggering a userspace reboot into the normal operating environment.
Apple Private Cloud Compute Vulnerability
According to the Sentry Security research, darwin-init selected an archive extractor by examining only the first 4 bytes of an incoming file. A malicious tar archive did not match known Apple archive signatures and was passed to a generic extraction function.
That function appended archive entry names to the intended output path without properly validating path traversal sequences such as ../../../../.
As a result, a crafted archive could escape its extraction folder and write attacker-controlled files to persistent locations on the PCC node’s writable data volume, including /var/db/.
Because darwin-init runs as root before steady-state security services load, those files could remain available after the userspace reboot. The researcher built a malicious archive that contained both traversal entries and a structurally valid cryptex bundle.
This was important because an invalid cryptex installation would prevent the system from completing its boot process. By combining a legitimate-looking bundle with malicious file paths, the archive could pass installation checks while placing files outside the intended extraction directory.
One demonstrated impact involved PCC’s internal splunkloggingd service. The service checks for a configuration file on the writable data volume and starts when that file exists.
By using the root file write to create a malicious logging configuration, the researcher redirected PCC telemetry to a controlled endpoint.
The redirected data reportedly included CloudBoard daemon activity, node events, and metadata associated with AI inference requests.
During test inference activity in Apple’s Virtual Research Environment, the logs exposed values such as application bundle identifiers, workload types, request identifiers, device-grouping metadata, token counts, output-token metrics, and latency measurements.
These details could reveal information about how a PCC node processes AI requests. For example, input token counts corresponded to prompt length.
At the same time, other values exposed first-token latency, speculative decoding information, and model-related telemetry. Apple’s source code reportedly identifies some of the affected metadata as information that should not be logged publicly.
The Sentry Security research also found an attestation gap. Apple’s PCC attestation process appeared to confirm that approved software and cryptotex components were installed.
However, it did not measure writable data volume files that could influence daemon behavior at runtime. A modified node could therefore appear identical to a clean node during software attestation checks.
Apple classified CVE-2026-20685 as an information disclosure issue with a CVSS score of 6.5. The company fixed the vulnerability in PCC releases 5E290.3 and later. The testing was conducted solely in Apple’s official Virtual Research Environment, with no production PCC infrastructure involved.
Security researcher Drinor Selmanaj has disclosed a path traversal vulnerability (CVE-2026-20685) in Apple’s Private Cloud Compute (PCC) that allows a privileged network attacker to write attacker-controlled files as root during node boot. This flaw affects the Apple Intelligence cloud-inference infrastructure. Apple has addressed the issue in PCC Release 5E290.3 and later, rating it as an […]
The post Apple Private Cloud Compute Path Traversal Flaw Lets Attackers Write Files as Root appeared fi
Security researcher Drinor Selmanaj has disclosed a path traversal vulnerability (CVE-2026-20685) in Apple’s Private Cloud Compute (PCC) that allows a privileged network attacker to write attacker-controlled files as root during node boot. This flaw affects the Apple Intelligence cloud-inference infrastructure. Apple has addressed the issue in PCC Release 5E290.3 and later, rating it as an […]
Apple’s Photos biometric privacy case will proceed after an appeals court declined to review class certification. Here’s what remains unresolved.
The post Apple Photos Privacy Case Advances, With Up to $32.5 Billion Alleged Exposure appeared first on TechRepublic.
Apple has imposed strict new submission limits on its bug bounty portal after finding itself overwhelmed by low-quality, AI generated vulnerability reports - many of which were found to be describing security flaws that simply didn't exist.
Read more in my article on the Hot for Security blog.
Apple has imposed strict new submission limits on its bug bounty portal after finding itself overwhelmed by low-quality, AI generated vulnerability reports - many of which were found to be describing security flaws that simply didn't exist.
Read more in my article on the Hot for Security blog.
Apple briefly removed Telegram from the App Store over reported CSAM, highlighting moderation failures and the distribution power held by app-store operators.
The post Apple Briefly Removes Telegram From App Store Over Reported CSAM Violation appeared first on TechRepublic.
Apple briefly removed Telegram from the App Store over reported CSAM, highlighting moderation failures and the distribution power held by app-store operators.
Apple is challenging a UK order reportedly requiring access to encrypted iCloud data, reviving a wider dispute over privacy, security, and lawful access.
The post Apple Challenges UK Demand For Access To Encrypted iCloud Data appeared first on TechRepublic.
Apple is challenging a UK order reportedly requiring access to encrypted iCloud data, reviving a wider dispute over privacy, security, and lawful access.