#macos
11 articles
Between April and August 2026, ZCyberNews published 14 articles tagged macOS, spanning April 10 to August 19. Coverage documented activity by Lazarus Group, ClickFix, and Sapphire Sleet, with technical detail on CVE-2026-65400 (CVSS 9.8), CVE-2024-54529, and CVE-2025-31235. Reporting focused on technology, cryptocurrency, artificial-intelligence, finance, and individual users across Global, Asia, Europe, North America, and South Asia. The severity mix included two critical and nine high-severity incidents, with two rated medium.
CRITICALCVE-2026-65400 macOS Flaw Added to CISA KEV, Actively Exploited
CISA added CVE-2026-65400, a 9.8-CVSS macOS authentication bypass, to its KEV catalog on August 18, confirming active exploitation. No patch yet.
HIGHXCSSET v40 Returns: macOS Malware Hits Xcode Developers
XCSSET v40, a macOS malware targeting Xcode developers, has resurfaced with 17 modules, including a Chrome hijacking backdoor and Telegram trojanizer, after months of dormancy.
CRITICALApple Patches Everything: 0-Days, RCS Encryption Rollout
Apple released emergency patches for two zero-days exploited in the wild alongside the beta rollout of end-to-end encrypted RCS messaging for iOS and macOS.
HIGHGoogle Ads, Claude Chats Push MacSync Infostealer to macOS Users
Attackers abuse Google Ads linking to real claude.ai and shared Claude chats to deliver MacSync infostealer, harvesting browser credentials and Keychain data.
HIGHGoogle Project Zero Details macOS coreaudiod Exploit Chain
Google Project Zero published exploit details for CVE-2024-54529, a type confusion in macOS coreaudiod allowing sandbox escape via knowledge-driven fuzzing.
HIGHLazarus Hijacks macOS via ClickFix to Target Executives
Lazarus APT uses ClickFix social engineering to deliver macOS malware — fake browser update prompts trick executives into running AppleScript payloads that steal credentials and…
HIGHSapphire Sleet Targets macOS Users with Fake Zoom SDK Update
North Korean threat actor Sapphire Sleet is distributing a new macOS malware via a fake Zoom SDK installer, stealing passwords, crypto wallets, and personal data through a multi-stage social engineering campaign.
HIGHFake Ledger Live App on Apple App Store Steals $9.5M in Cryptocurrency
A malicious Ledger Live app distributed via Apple's official App Store for macOS stole approximately $9.5 million from 50 victims by harvesting recovery phrases.
MEDIUMClickFix Mac Malware Campaign Uses Fake Apple Page to Deliver Payloads
A new ClickFix-style campaign targets macOS users with fake Apple instructions to run malicious commands.
HIGHNorth Korean Lazarus Group Compromises OpenAI via Axios Supply Chain Attack
North Korea's Lazarus Group compromised OpenAI's internal systems via a supply chain attack on the Axios client library, using a stolen macOS code-signing certificate to sign malware.
HIGHClickFix Malware Campaign Evades macOS Defenses via Script Editor
A ClickFix social engineering campaign bypasses macOS security warnings by using Script Editor to execute malicious commands, marking a significant evolution in Mac-targeting malware.
Stay Updated
Get the latest cybersecurity news delivered to your inbox.