<?xml version='1.0' encoding='utf-8'?>
<rss version="2.0"><channel><title>Cybersecurity Tracker: Apple Watch</title><link>https://cybersecuritytracker.ai/?stack=1</link><description>Stories and vulnerabilities involving Apple.</description><lastBuildDate>Sun, 26 Jul 2026 22:32:51 GMT</lastBuildDate><item><title>Inside Elastic InfoSec's agentic SOC: When to inline your agent's skills for a 5× cost reduction</title><link>https://elastic.co/security-labs/agentic-soc-token-budget-architecture</link><guid isPermaLink="false">cst-3189</guid><description>Elastic InfoSec compares two architectural approaches for agentic security operations centers: a single agent with a library of skills versus a fleet of specialized agents orchestrated through deterministic workflows. Testing on 36,822 real production investigations shows the specialized agent approach costs $0.69 per alert triage versus $3.42 for the single-agent method, a 5.7x difference at scale. The choice between architectures depends on investigation patterns, team maturity, and whether analysts need flexible on-demand skill loading or deterministic methodologies.</description><pubDate>Fri, 24 Jul 2026 00:00:00 GMT</pubDate></item><item><title>Claude Cowork Flaw Could Let AI Agent Escape Its VM and Access Mac Files</title><link>https://thehackernews.com/2026/07/claude-cowork-flaw-could-let-ai-agent.html</link><guid isPermaLink="false">cst-3104</guid><description>Researchers discovered a sandbox escape vulnerability in Anthropic's Claude Cowork that allows an AI agent to break out of its Linux VM and access files on the host macOS system. The flaw potentially affects approximately 500,000 macOS users running the software.</description><pubDate>Thu, 23 Jul 2026 13:27:59 GMT</pubDate></item><item><title>Apple Fixes Hide My Email Bug That Exposed Real Addresses in Mail Logs</title><link>https://thehackernews.com/2026/07/apple-fixes-hide-my-email-bug-that.html</link><guid isPermaLink="false">cst-2963</guid><description>Apple patched a vulnerability in its Hide My Email service that allowed real email addresses to be exposed in mail logs, bypassing the privacy feature's core function. The issue was discovered by a security researcher and disclosed to Apple over a year before the fix was deployed on July 3, 2026.</description><pubDate>Tue, 21 Jul 2026 18:46:32 GMT</pubDate></item><item><title>Captive Portal Detection</title><link>https://isc.sans.edu/diary/rss/33172</link><guid isPermaLink="false">cst-2928</guid><description>This article explains how modern operating systems and browsers detect captive portals on public WiFi networks by attempting to access specific HTTP URLs and checking for redirect responses. Different platforms use different detection URLs: Windows checks msftconnecttest.com, Apple uses captive.apple.com, Android and Chrome use generate_204 endpoints, and Firefox uses detectportal.firefox.com. Understanding these detection mechanisms can help network administrators and security analysts recognize benign traffic patterns and assist users who encounter connectivity issues.</description><pubDate>Tue, 21 Jul 2026 13:44:56 GMT</pubDate></item><item><title>Product showcase: ZoneAlarm Mobile Security adds customizable content filtering to mobile security</title><link>https://helpnetsecurity.com/2026/07/20/product-showcase-zonealarm-mobile-security-adds-customizable-content-filtering-to-mobile-security</link><guid isPermaLink="false">cst-2812</guid><description>Check Point released ZoneAlarm Mobile Security, a mobile protection app that defends against phishing, malicious websites, and fraudulent links across iOS, Android, and Apple silicon Macs. The application features customizable content filtering and a Safari extension that checks websites before loading.</description><pubDate>Mon, 20 Jul 2026 04:30:34 GMT</pubDate></item><item><title>In Other News: Iran Tracks US Military Phones, CrashStealer macOS Malware, CVD Blueprint</title><link>https://securityweek.com/in-other-news-iran-tracks-us-military-phones-crashstealer-macos-malware-cvd-blueprint</link><guid isPermaLink="false">cst-2768</guid><description>A roundup of security news includes OpenClaw artificial intelligence (AI) agents being exploited through WhatsApp, ransomware targeting naval defense contractor TKMS, and a data breach disclosure from Lidl. Additionally, reports cover Iranian tracking of US military phones, CrashStealer malware affecting macOS systems, and developments in coordinated vulnerability disclosure (CVD) practices.</description><pubDate>Fri, 17 Jul 2026 14:27:54 GMT</pubDate></item><item><title>Scammers weaponize FaceTime to drain bank accounts</title><link>https://helpnetsecurity.com/2026/07/17/apple-facetime-calls-scams</link><guid isPermaLink="false">cst-2747</guid><description>Apple is warning users that scammers exploit FaceTime to conduct social engineering attacks, impersonating representatives of trusted organizations to extract login credentials, security codes, and financial information. Attackers use caller ID spoofing to mask their identity, making it difficult for victims to verify legitimacy.</description><pubDate>Fri, 17 Jul 2026 10:02:21 GMT</pubDate></item><item><title>San Francisco Demands Apple and Google Delete AI ‘Nudify’ Apps From App Stores</title><link>https://wired.com/story/san-francisco-demands-apple-and-google-delete-ai-nudify-apps-from-app-stores</link><guid isPermaLink="false">cst-2750</guid><description>San Francisco's City Attorney sent cease-and-desist letters to Apple and Google demanding they remove 13 face-swap applications from their app stores. The apps are designed to generate non-consensual intimate imagery targeting women and girls, generating revenue for the platforms hosting them.</description><pubDate>Fri, 17 Jul 2026 10:00:00 GMT</pubDate></item><item><title>Claude can now sign into websites with 1Password without exposing your credentials</title><link>https://helpnetsecurity.com/2026/07/17/1password-anthropic-claude-integration</link><guid isPermaLink="false">cst-2748</guid><description>1Password has released a beta integration for Claude that allows the AI assistant to complete authentication-required browser tasks while keeping user passwords and secrets protected. The feature is available to paid Claude subscribers using Claude Desktop on macOS and compatible with 1Password individual, family, and business plan customers. The integration requires specific software components including Claude Desktop, the 1Password desktop app, and browser extension.</description><pubDate>Fri, 17 Jul 2026 09:17:44 GMT</pubDate></item><item><title>‘ClickLock Stealer’ Bypasses macOS Security With Social Engineering, Process Killing</title><link>https://securityweek.com/clicklock-stealer-bypasses-macos-security-with-social-engineering-process-killing</link><guid isPermaLink="false">cst-2679</guid><description>A macOS malware called ClickLock Stealer has targeted at least 100 users by combining social engineering tactics with process killing techniques to bypass security protections and steal passwords and cryptocurrency. The attack method exploits user interaction to circumvent macOS defenses.</description><pubDate>Thu, 16 Jul 2026 12:43:59 GMT</pubDate></item><item><title>New ClickLock macOS Stealer Kills Apps Every 210ms Until Victims Type Their Password</title><link>https://thehackernews.com/2026/07/new-clicklock-macos-stealer-kills-apps.html</link><guid isPermaLink="false">cst-2671</guid><description>ClickLock Stealer is a new macOS infostealer that arrives via a Terminal command and displays a fake system dialog requesting the user's login password. When users decline, the malware installs LaunchAgents that repeatedly terminate core system applications like Finder, Dock, and Spotlight every 210 milliseconds until the victim relents and provides their credentials.</description><pubDate>Thu, 16 Jul 2026 12:33:42 GMT</pubDate></item><item><title>AI Has Enhanced Iran’s Asymmetric Playbook During the 2026 Conflict</title><link>https://recordedfuture.com/research/iran-ai-asymmetric-playbook</link><guid isPermaLink="false">cst-2691</guid><description>Between January and June 2026, Iran leveraged artificial intelligence to enhance its asymmetric warfare capabilities across cyber operations, information warfare, propaganda production, and domestic surveillance during military and political crises. AI functioned as a force multiplier that increased the speed, scale, and effectiveness of Iranian operations, particularly in information campaigns and cyber attacks, though its direct impact on battlefield tactics remains unconfirmed. Iran's hybrid approach, augmented by partnerships with Russia and China for military and surveillance technologies, demonstrates how AI amplifies existing capabilities rather than creating fundamentally new ones.</description><pubDate>Thu, 16 Jul 2026 00:00:00 GMT</pubDate></item><item><title>ClickFix is changing the economics of social engineering</title><link>https://helpnetsecurity.com/2026/07/15/clickfix-social-engineering-attacks-report</link><guid isPermaLink="false">cst-2586</guid><description>ClickFix, a social engineering technique that emerged in late 2023, has evolved into an industrialized attack ecosystem that bypasses traditional antivirus and endpoint defenses by tricking users into executing malicious commands via fake error pages styled as CAPTCHA checks or browser updates. The method avoids exploits and vulnerabilities altogether, instead relying on social manipulation to compromise systems. Security researchers at ReversingLabs report that this approach is outpacing conventional defense mechanisms.</description><pubDate>Wed, 15 Jul 2026 10:44:03 GMT</pubDate></item><item><title>Nearly 300 GitHub repos pose as legit software to push malware</title><link>https://bleepingcomputer.com/news/security/nearly-300-github-repos-pose-as-legit-software-to-push-malware</link><guid isPermaLink="false">cst-2512</guid><description>A threat actor created hundreds of fake GitHub repositories that impersonate legitimate software and security projects to distribute infostealer malware. These repositories are designed to deceive developers searching for authentic tools and libraries.</description><pubDate>Tue, 14 Jul 2026 19:15:17 GMT</pubDate></item><item><title>Apple says former employee exploited ‘rare’ bug to download confidential files after leaving for OpenAI</title><link>https://techcrunch.com/2026/07/13/apple-says-former-employee-exploited-rare-bug-to-download-confidential-files-after-leaving-for-openai</link><guid isPermaLink="false">cst-2449</guid><description>Apple says a former employee who departed for OpenAI exploited a rare bug to download confidential files from Apple's network after leaving the company. Apple declined to comment further on the incident.</description><pubDate>Mon, 13 Jul 2026 20:00:17 GMT</pubDate></item><item><title>New CrashStealer malware poses as Apple crash reporting tool</title><link>https://bleepingcomputer.com/news/security/new-crashstealer-malware-poses-as-apple-crash-reporting-tool</link><guid isPermaLink="false">cst-2431</guid><description>CrashStealer is a new macOS information stealer that masquerades as Apple's crash-reporting tool to harvest credentials, keychain data, and cryptocurrency wallet information. The malware achieves persistence through social engineering by disguising itself as a legitimate system component.</description><pubDate>Mon, 13 Jul 2026 19:04:02 GMT</pubDate></item><item><title>Compromised jscrambler 8.14.0 npm Release Drops Rust Infostealer During Install</title><link>https://thehackernews.com/2026/07/compromised-jscrambler-8140-npm-release.html</link><guid isPermaLink="false">cst-2367</guid><description>Version 8.14.0 of the jscrambler npm package contained a malicious preinstall hook that silently deployed a Rust-based infostealer on Windows, macOS, and Linux systems during installation. The package required no manual import or command line invocation to execute the malware. Socket security detected the compromised release approximately six minutes after its publication on July 11, 2026.</description><pubDate>Sat, 11 Jul 2026 17:59:26 GMT</pubDate></item><item><title>Weekly Metasploit Update: Exploits for FlowiseAI CSV Agent and MacOS Package Kit</title><link>https://rapid7.com/blog/post/pt-weekly-metasploit-update-exploits-for-flowiseai-csv-agent-and-macos-package-kit</link><guid isPermaLink="false">cst-2357</guid><description>Metasploit released new exploit modules for three vulnerabilities: FlowiseAI CSV Agent (CVE-2026-41264), an unauthenticated remote code execution flaw allowing attackers to upload malicious CSV files; macOS PackageKit (CVE-2024-27822), a privilege escalation vulnerability in ZSH environment handling; and Apache .htaccess persistence for Linux systems. The update also includes enhancements to FTP fingerprinting, library reloading, MCP Server tools, and certificate tracing functionality.</description><pubDate>Sat, 11 Jul 2026 00:32:34 GMT</pubDate></item><item><title>Risky Bulletin: India bans app used to hack e-rickshaws in viral videos</title><link>https://risky.biz/risky-bulletin-india-bans-app-used-to-hack-e-rickshaws-in-viral-videos</link><guid isPermaLink="false">cst-2299</guid><description>The Indian government ordered Apple and Google to remove a battery management app that was weaponized to remotely disable electric rickshaws in a viral social media trend called the Tirri Challenge. Videos documented the attacks, which stranded drivers and caused traffic disruptions across the country over a two to three week period.</description><pubDate>Fri, 10 Jul 2026 03:53:46 GMT</pubDate></item><item><title>Product showcase: Protect your iPhone with McAfee Mobile Security</title><link>https://helpnetsecurity.com/2026/07/09/product-showcase-mcafee-mobile-security-ios</link><guid isPermaLink="false">cst-2219</guid><description>McAfee Mobile Security for iOS offers scam protection, web protection, VPN, Wi-Fi security, and device security checks in one app, with availability on Android as well. The app provides an onboarding process, notification options, and Smart Scan functionality that checks device configuration and Wi-Fi network status.</description><pubDate>Thu, 09 Jul 2026 05:00:52 GMT</pubDate></item><item><title>macOS is becoming a proving ground for AI agents</title><link>https://helpnetsecurity.com/2026/07/08/macos-ai-agents-automation</link><guid isPermaLink="false">cst-2132</guid><description>macOS is increasingly being used as a testing platform for AI agents capable of autonomous task execution, with examples including agents that can perform multi-application workflows without direct human supervision. These agents demonstrate the ability to operate across system interfaces like Terminal and Safari to complete routine tasks that would normally require manual user intervention.</description><pubDate>Wed, 08 Jul 2026 05:00:59 GMT</pubDate></item><item><title>More Odd DNS Records: NIMLOC</title><link>https://isc.sans.edu/diary/rss/33128</link><guid isPermaLink="false">cst-2083</guid><description>DNS resource record type 32 (NIMLOC) is historically assigned to obsolete protocols but continues to appear in network logs, particularly from macOS systems broadcasting NetBIOS name announcements on port 137. The record type was originally designated for Nimrod routing architecture but is now primarily associated with legacy NetBIOS traffic, a protocol largely replaced by modern DNS and SMB implementations on contemporary networks.</description><pubDate>Tue, 07 Jul 2026 18:09:04 GMT</pubDate></item><item><title>Savi’s app aims to protect consumers from realistic AI scams like kidnappers demanding ransom</title><link>https://techcrunch.com/2026/07/07/savis-app-aims-to-protect-consumers-from-realistic-ai-scams-like-kidnappers-demanding-ransom</link><guid isPermaLink="false">cst-531</guid><description>Savi, a startup focused on protecting consumers from AI-generated scams such as deepfake kidnapping extortion, has raised $7 million in seed funding and is launching its mobile app for iPhone and Android.</description><pubDate>Tue, 07 Jul 2026 12:00:00 GMT</pubDate></item><item><title>Apple Container: Open-source tool for Linux containers on the Mac</title><link>https://helpnetsecurity.com/2026/07/07/apple-container-open-source-linux-mac</link><guid isPermaLink="false">cst-505</guid><description>Apple has released an open-source container tool called Container that runs Linux containers as lightweight virtual machines on Apple silicon Macs. The tool is written in Swift, optimized for Apple hardware, and supports OCI-compatible images from standard registries.</description><pubDate>Tue, 07 Jul 2026 05:00:58 GMT</pubDate></item><item><title>RCS and DNS: The NAPTR Record</title><link>https://isc.sans.edu/diary/rss/33124</link><guid isPermaLink="false">cst-156</guid><description>RCS (Rich Communication Services) is increasingly used on modern iOS and Android devices as a potential replacement for SMS, featuring optional end-to-end encryption and digital signing. The article explains how NAPTR (Naming Authority Pointer) DNS records, defined in RFC 2915, are being used to locate RCS servers by enabling clients to discover SIP-based service endpoints rather than just IP addresses.</description><pubDate>Mon, 06 Jul 2026 13:35:58 GMT</pubDate></item><item><title>New Java-Based QuimaRAT MaaS Built to Run on Windows, Linux, and macOS</title><link>https://thehackernews.com/2026/07/new-java-based-quimarat-maas-built-to.html</link><guid isPermaLink="false">cst-20</guid><description>Researchers have identified QuimaRAT, a Java-based remote access trojan (RAT) marketed as a malware-as-a-service (MaaS) offering that targets Windows, Linux, and macOS. The malware is sold through subscription tiers ranging from $150 per month to $1,200 for lifetime access.</description><pubDate>Mon, 06 Jul 2026 08:13:33 GMT</pubDate></item><item><title>Product showcase: Is that text a scam? Malwarebytes Mobile Security can help you find out</title><link>https://helpnetsecurity.com/2026/07/06/product-showcase-malwarebytes-mobile-security-ios</link><guid isPermaLink="false">cst-153</guid><description>Malwarebytes Mobile Security for iPhone offers scam prevention, privacy protection, and identity monitoring across multiple platforms including Windows, macOS, Android, iOS, and ChromeOS. The app evaluates device security posture and provides recommendations for improvement through features such as Web Protection, Call Protection, Scam Guard, and a VPN.</description><pubDate>Mon, 06 Jul 2026 05:00:44 GMT</pubDate></item><item><title>Security Roundup: Apple’s Hide My Email Service Fails to Hide Your Email</title><link>https://wired.com/story/security-roundup-apples-hide-my-email-service-fails-to-hide-your-email</link><guid isPermaLink="false">cst-443</guid><description>Apple's Hide My Email service failed to properly mask user email addresses in certain scenarios. The roundup also covers the extradition of an alleged Scattered Spider member, multiple errors in license plate reader systems, and Indian regulatory concerns about WhatsApp's username feature rollout.</description><pubDate>Sat, 04 Jul 2026 10:30:00 GMT</pubDate></item><item><title>PamStealer Uses Fake Maccy Sites and PAM Checks to Steal Mac Login Passwords</title><link>https://thehackernews.com/2026/07/pamstealer-uses-fake-maccy-sites-and.html</link><guid isPermaLink="false">cst-31</guid><description>Security researchers identified PamStealer, a macOS information stealer distributed as a compiled AppleScript file masquerading as Maccy, a legitimate clipboard manager. The malware uses deceptive techniques to trick users into installation and extract sensitive data from infected systems.</description><pubDate>Fri, 03 Jul 2026 08:03:37 GMT</pubDate></item><item><title>Newly discovered PamStealer isn't your typical macOS malware</title><link>https://arstechnica.com/security/2026/07/new-pamstealer-macos-malware-uses-clever-tradecraft-to-remain-stealthy</link><guid isPermaLink="false">cst-422</guid><description>Researchers discovered PamStealer, a previously unknown macOS malware distributed as a fake Maccy clipboard manager through a disk image containing malicious AppleScript. The malware uses a two-stage delivery mechanism and is written in Rust, leveraging macOS Pluggable Authentication Modules (PAM) interface to intercept and exfiltrate login credentials to attacker-controlled servers.</description><pubDate>Thu, 02 Jul 2026 19:38:57 GMT</pubDate></item><item><title>Apple Reverses Age-Old Patch Policy to Keep Up With AI</title><link>https://darkreading.com/cybersecurity-operations/apple-patch-policy-ai</link><guid isPermaLink="false">cst-77</guid><description>Apple is accelerating its patching cycles in response to attackers using artificial intelligence to develop exploits more quickly. The shift represents a departure from Apple's historical approach to software updates.</description><pubDate>Thu, 02 Jul 2026 19:31:58 GMT</pubDate></item><item><title>ThreatsDay: AI Compute Hijacking, Apple Email Flaw, BlueHammer Ransomware + 14 Stories</title><link>https://thehackernews.com/2026/07/threatsday-ai-compute-hijacking-apple.html</link><guid isPermaLink="false">cst-34</guid><description>This week's security news covers multiple vulnerability categories spanning browsers, bots, sandboxes, AI systems, and email infrastructure, with a common theme of small permission gaps and weak validation checks rather than dramatic exploits. The incidents demonstrate how attackers leverage incremental weaknesses and normal system behaviors that fall outside security assumptions. Common exposure patterns include insufficient access controls, inadequate verification mechanisms, and overly permissive system configurations.</description><pubDate>Thu, 02 Jul 2026 15:24:18 GMT</pubDate></item><item><title>AI-Generated Browser Ransomware Abuses Chromium API on Windows, Linux, macOS, Android</title><link>https://thehackernews.com/2026/07/ai-generated-browser-ransomware-abuses.html</link><guid isPermaLink="false">cst-49</guid><description>Researchers discovered ransomware generated by DeepSeek that exploits Chromium APIs to execute a ransomware attack directly within the browser on Windows, Linux, macOS, and Android platforms. The malware combines novel attack concepts with legitimate browser capabilities to operate entirely in the browser environment. This represents the first documented case of a frontier AI model being used to generate functional ransomware code.</description><pubDate>Wed, 01 Jul 2026 12:59:19 GMT</pubDate></item><item><title>Browser-Only Ransomware: From LLM Hallucinations to a Practical Attack Technique</title><link>https://research.checkpoint.com/2026/browser-only-ransomware-from-llm-hallucinations-to-a-practical-attack-technique</link><guid isPermaLink="false">cst-595</guid><description>Researchers demonstrated a practical ransomware attack that operates entirely within a web browser on Android devices using the File System Access API, bypassing traditional malware defenses. The attack leverages social engineering through a fake image-enhancement workflow to trick users into granting file system permissions, enabling attackers to encrypt photos and other files. The research highlights how large language models like DeepSeek, with lower refusal rates for harmful requests than competitors, can convert malicious concepts into working attack code more easily than other AI platforms.</description><pubDate>Wed, 01 Jul 2026 10:05:35 GMT</pubDate></item><item><title>Iran-Nexus TAG-182 Disseminates MarkiRAT Surveillance Tool</title><link>https://recordedfuture.com/research/nexus-tag182-disseminates-markirat</link><guid isPermaLink="false">cst-1941</guid><description>Insikt Group identified new infrastructure used by TAG-182, an Iran-linked threat cluster, to distribute MarkiRAT malware through fake Android applications disguised as VPNs and media tools targeting Iranians both domestically and abroad. The malware samples share technical similarities with previously attributed Ferocious Kitten activity, suggesting a possible operational connection. Following Iran's internet restoration in May 2026, surveillance operations using these tools are expected to intensify as Iranian authorities seek to monitor perceived dissidents.</description><pubDate>Wed, 01 Jul 2026 00:00:00 GMT</pubDate></item><item><title>​​What’s new in Microsoft Security: June 2026</title><link>https://microsoft.com/en-us/security/blog/2026/06/30/whats-new-in-microsoft-security-june-2026</link><guid isPermaLink="false">cst-326</guid><description>Microsoft announced security updates for June 2026 including MDASH, a multi-model AI scanning system for discovering and remediating vulnerabilities, extended endpoint protection for local AI agents, and new capabilities for identity backup and recovery. Additional releases include database threat protection for open-source AWS RDS instances and customizable reporting features in Microsoft Purview for data security posture management.</description><pubDate>Tue, 30 Jun 2026 16:00:00 GMT</pubDate></item><item><title>282 iOS AI Apps Leak API Keys and Open AI Proxy Access in Network Traffic Study</title><link>https://thehackernews.com/2026/06/282-ios-apps-found-leaking-llm-api-keys.html</link><guid isPermaLink="false">cst-62</guid><description>A study of 444 AI chatbot applications on iOS found that 282 apps exposed API keys and backend authentication tokens in plaintext network traffic, allowing attackers to intercept credentials and make requests on the developer's account without authorization.</description><pubDate>Tue, 30 Jun 2026 13:49:34 GMT</pubDate></item><item><title>June 2026 Apple Updates</title><link>https://isc.sans.edu/diary/rss/33114</link><guid isPermaLink="false">cst-159</guid><description>Apple released security updates for iOS, iPadOS, macOS, and Safari on June 30, 2026, addressing 26 vulnerabilities. The majority of issues affect web browsing components including WebKit, libxslt, WebRTC, and Web Extensions, with four vulnerabilities impacting the kernel and GPU family drivers. None of the CVEs are currently marked as exploited in the wild.</description><pubDate>Tue, 30 Jun 2026 09:31:27 GMT</pubDate></item><item><title>AirDrop and Quick Share Flaws Let Nearby Attackers Trigger Crashes and Bypass Checks</title><link>https://thehackernews.com/2026/06/airdrop-and-quick-share-flaws-let.html</link><guid isPermaLink="false">cst-65</guid><description>Researchers discovered six security vulnerabilities in Apple's AirDrop and Google's Quick Share features that allow nearby attackers to crash the sharing services and bypass security checks without any interaction from the target user. An attacker within wireless range can exploit these flaws on Mac, iPhone, and devices running Quick Share simply by having basic equipment like a laptop, with no prior connection or authentication required.</description><pubDate>Tue, 30 Jun 2026 09:27:58 GMT</pubDate></item><item><title>What's Trending: Top Cyber Attacker Techniques, March - May 2026</title><link>https://reliaquest.com/blog/threat-spotlight-whats-trending-top-cyber-attacker-techniques-march-may-2026</link><guid isPermaLink="false">cst-2120</guid><description>A threat report covering March through May 2026 finds that ClickFix (a social engineering delivery technique) has become the dominant initial access method, driving 14.9% of spearphishing attacks and nearly 28% of defense-evasion activity while reaching macOS for the first time. The malware leaderboard underwent near-complete turnover for a second consecutive period, with defenders advised to focus on attacker behavior patterns rather than malware family names. Ransomware operators like Qilin continue exploiting unpatched internet-facing firewalls and VPNs using a consistent playbook.</description><pubDate>Tue, 30 Jun 2026 09:00:00 GMT</pubDate></item><item><title>Microsoft a Leader in The Forrester Wave™ for Endpoint Management Platforms</title><link>https://microsoft.com/en-us/security/blog/2026/06/25/microsoft-a-leader-in-the-forrester-wave-for-endpoint-management-platforms</link><guid isPermaLink="false">cst-330</guid><description>Microsoft Intune has been recognized as a Leader in Forrester's Q2 2026 Endpoint Management Platforms report, reflecting its integration of identity, security, compliance, and AI governance across multiple platforms and device types. The platform consolidates Windows, macOS, iOS, and Android management in a single console and incorporates AI-powered capabilities such as Endpoint Privilege Management, Security Copilot, and a Vulnerability Remediation Agent to assist administrators with policy enforcement and threat response. Forrester also highlighted Microsoft's partner strategy and bundled licensing model as competitive advantages.</description><pubDate>Thu, 25 Jun 2026 16:00:00 GMT</pubDate></item><item><title>Cellebrite said it cut off Russia, but Russia used its tools anyway</title><link>https://techcrunch.com/2026/06/25/cellebrite-said-it-cut-off-russia-but-russia-used-is-tools-anyway</link><guid isPermaLink="false">cst-469</guid><description>Security researchers discovered that Russian authorities used a Cellebrite phone-unlocking device to access an iPhone belonging to a political opponent, despite Cellebrite's stated decision to cease business with Russia. The finding suggests the company's export controls or enforcement mechanisms may be insufficient to prevent continued access to its tools by sanctioned actors.</description><pubDate>Thu, 25 Jun 2026 10:00:00 GMT</pubDate></item><item><title>Apple's MacOS Gap Lets Users Disable Security Tools</title><link>https://darkreading.com/application-security/apple-macos-security-gap-users-disable-security-tools</link><guid isPermaLink="false">cst-115</guid><description>A vulnerability in Apple's macOS allows attackers to disable built-in security and browser tools without requiring administrator privileges or kernel exploits. This represents a gap in the operating system's security architecture that could be leveraged for malicious purposes.</description><pubDate>Wed, 24 Jun 2026 12:00:00 GMT</pubDate></item><item><title>macOS.Gaslight | Rust Backdoor Turns Prompt Injection on the Analyst, Not the Sandbox</title><link>https://sentinelone.com/labs/macos-gaslight-rust-backdoor-turns-prompt-injection-on-the-analyst-not-the-sandbox</link><guid isPermaLink="false">cst-602</guid><description>SentinelLabs has identified macOS.Gaslight, a Rust-based macOS implant attributed to North Korean threat actors that uses Telegram Bot API for command-and-control communications. The implant's notable capability is an embedded payload of fabricated system messages designed to deceive LLM-assisted security analysis tools into aborting their analysis. Communications are hardened with AES-GCM encryption, certificate pinning, and the implant self-redacts sensitive tokens from its runtime output.</description><pubDate>Tue, 23 Jun 2026 21:59:42 GMT</pubDate></item><item><title>Tata Electronics, a major tech supplier to Apple and Tesla, confirms data breach</title><link>https://techcrunch.com/2026/06/22/tata-electronics-a-major-tech-supplier-to-apple-and-tesla-confirms-data-breach</link><guid isPermaLink="false">cst-473</guid><description>Tata Electronics, a significant supplier to Apple and Tesla, has confirmed a data breach. The breach occurs during a period of expansion for the company in global technology supply chains.</description><pubDate>Mon, 22 Jun 2026 19:25:00 GMT</pubDate></item><item><title>A new unpatchable flaw in Apple chips opens the door to an iPhone jailbreak</title><link>https://techcrunch.com/2026/06/22/a-new-unpatchable-flaw-in-apple-chips-opens-the-door-to-an-iphone-jailbreak</link><guid isPermaLink="false">cst-474</guid><description>Paradigm Shift, a European offensive cybersecurity firm, disclosed an unpatchable flaw in Apple chips that enables exploitation techniques for compromising older iPhones. The vulnerability presents a persistent attack vector that cannot be remediated through traditional patching mechanisms.</description><pubDate>Mon, 22 Jun 2026 18:50:24 GMT</pubDate></item><item><title>Hackers Claim to Leak Stolen Madison Square Garden Data</title><link>https://wired.com/story/security-news-this-week-hackers-claim-to-leak-stolen-madison-square-garden-data</link><guid isPermaLink="false">cst-455</guid><description>Hackers claim to have leaked stolen data from Madison Square Garden. The article also covers developments including face scanner use at San Francisco gay bars, France's decision to discontinue Palantir services, and Apple's plans to modify its private email service.</description><pubDate>Sat, 20 Jun 2026 09:30:00 GMT</pubDate></item><item><title>Apple patches high-severity eavesdropping vulnerability in Beats Studio Buds</title><link>https://arstechnica.com/apple/2026/06/apple-patches-high-severity-eavesdropping-vulnerability-in-beats-studio-buds</link><guid isPermaLink="false">cst-430</guid><description>Apple released a firmware update (1B211) for Beats Studio Buds to address CVE-2025-20701, a high-severity vulnerability in Bluetooth authentication that allowed nearby attackers to impersonate paired devices and eavesdrop on user conversations. The vulnerability affected the firmware on Bluetooth-related chips and has been patched through automatic updates delivered when headphones are connected to Apple devices.</description><pubDate>Thu, 18 Jun 2026 19:41:35 GMT</pubDate></item><item><title>From Stars to Upvotes: Fake Reputation Fueling a Crypto Clipboard Hijacker</title><link>https://research.checkpoint.com/2026/from-stars-to-upvotes-fake-reputation-fueling-a-crypto-clipboard-hijacker</link><guid isPermaLink="false">cst-596</guid><description>A threat actor is distributing a Rust-based clipboard hijacker disguised as cryptocurrency trading bots and game prediction tools across multiple platforms, including fake GitHub and SourceForge repositories, a YouTube channel with AI-generated content, and compromised news sites. The operation uses coordinated fake accounts, inflated engagement metrics, and manipulated VirusTotal reputation signals to create a false appearance of legitimacy and trustworthiness. Once installed, the malware monitors the clipboard for cryptocurrency wallet addresses and replaces them with attacker-controlled addresses, generating illicit cryptocurrency transactions.</description><pubDate>Wed, 17 Jun 2026 13:38:55 GMT</pubDate></item><item><title>Tracing Digital Intent: New MacOS Tahoe 26 Artifact Discovered</title><link>https://unit42.paloaltonetworks.com/new-macos-artifact-discovered</link><guid isPermaLink="false">cst-341</guid><description>Unit 42 has identified a new forensic artifact in macOS Tahoe 26 that records user menu selections across the operating system. This discovery expands the range of digital artifacts available for forensic analysis and investigation on Apple's latest platform.</description><pubDate>Fri, 12 Jun 2026 22:00:14 GMT</pubDate></item></channel></rss>