Cyberveillecurated by Decio
Nuage de tags
Mur d'images
Quotidien
Flux RSS
  • Flux RSS
  • Daily Feed
  • Weekly Feed
  • Monthly Feed
Filtres

Liens par page

  • 20 links
  • 50 links
  • 100 links

Filtres

Untagged links
page 5 / 10
184 résultats taggé macos  ✕
Hackers can force iOS and macOS browsers to divulge passwords and much more https://arstechnica.com/security/2023/10/hackers-can-force-ios-and-macos-browsers-to-divulge-passwords-and-a-whole-lot-more/
25/10/2023 20:34:57
QRCode
archive.org
thumbnail

iLeakage is practical and requires minimal resources. A patch isn't (yet) available.

arstechnica EN 2023 ileakage macos ios speculative
macOS MetaStealer | New Family of Obfuscated Go Infostealers Spread in Targeted Attacks https://www.sentinelone.com/blog/macos-metastealer-new-family-of-obfuscated-go-infostealers-spread-in-targeted-attacks/
14/09/2023 14:48:30
QRCode
archive.org
thumbnail

The rise of macOS infostealers continues with the latest entrant aiming to compromise business environments with targeted social engineering lures.

sentinelone EN 2023 macOS infostealer MetaStealer
Last Week on My Mac: How quickly can Apple release a security update? https://eclecticlight.co/2023/09/10/last-week-on-my-mac-how-quickly-can-apple-release-a-security-update/#like-74253
10/09/2023 11:18:45
QRCode
archive.org
thumbnail

We seldom get much insight into how long Apple takes to release an urgent update to macOS, but last week must have seen one of the quickest in recent times. By my reckoning, Apple’s engineers accomplished that in 6-10 days, across four of its operating systems, and with two distinct vulnerabilities.

eclecticlight EN 2023 Apple security update macos release
Mac users targeted in new malvertising campaign delivering Atomic Stealer https://www.malwarebytes.com/blog/threat-intelligence/2023/09/atomic-macos-stealer-delivered-via-malvertising
07/09/2023 21:36:22
QRCode
archive.org
thumbnail
  • Malicious ads for Google searches are targeting Mac users
  • Phishing sites trick victims into downloading what they believe is the app they want
  • The malware is bundled in an ad-hoc signed app so it cannot be revoked by Apple
  • The payload is a new version of the recent Atomic Stealer for OSX
malwarebytes EN 2023 macos AtomicStealer stealer tradingview
Developers Warned of Malicious PyPI, NPM, Ruby Packages Targeting Macs - SecurityWeek https://www.securityweek.com/developers-warned-of-malicious-pypi-npm-ruby-packages-targeting-macs/
06/09/2023 15:01:22
QRCode
archive.org
thumbnail

Malicious packages uploaded to PyPI, NPM, and Ruby repositories are targeting macOS users with information stealing malware.

securityweek EN 2023 macos phylum PyPI NPM Ruby Supply-Chain-Attack
Nascent Malware Campaign Targets npm, PyPI, and RubyGems Developers https://blog.phylum.io/malware-campaign-targets-npm-pypi-and-rubygems-developers/
06/09/2023 15:00:06
QRCode
archive.org
thumbnail

Phylum has identified a malware campaign spanning PyPI, npm and RubyGems. Delivering early stage malware to users.

phylum EN 2023 Supply-Chain-Attack npm PyPI RubyGems macOS
Is macOS’s new XProtect behavioural security preparing to go live? https://eclecticlight.co/2023/09/04/is-macoss-new-xprotect-behavioural-security-preparing-to-go-live/
04/09/2023 20:56:50
QRCode
archive.org
thumbnail

Apple released its first update to its new behavioural security protection in XProtect Behaviour Service on 8 August, and again on 1 September. Here are the details.

eclecticlight EN 2023 macOS XProtect Behaviour Service
How NightOwl for Mac Added a Botnet https://gizmodo.com/how-nightowl-for-mac-added-a-botnet-1850740785
31/08/2023 09:48:59
QRCode
archive.org
thumbnail

NightOwl was supposed to make Macs work in dark mode. After a recent update, one developer discovered it was siphoning users’ data through a botnet.

gizmodo EN 2023 macOS App-Store NightOwl
macOS 0day: App Management https://lapcatsoftware.com/articles/2023/8/2.html
22/08/2023 21:26:42
QRCode
archive.org

App Management is a new macOS security feature in Ventura introduced at WWDC last year:

If an app is modified by something that isn't signed by the same development team and isn't allowed by an NSUpdateSecurityPolicy, macOS will block the modification and notify the user that an app wants to manage other apps. Clicking on the notification sends people to System Settings, where they can allow an app to update and modify other apps.

lapcatsoftware EN 2023 macOS 0-day AppManagement
XLoader's Latest Trick | New macOS Variant Disguised as Signed OfficeNote App https://www.sentinelone.com/blog/xloaders-latest-trick-new-macos-variant-disguised-as-signed-officenote-app/
22/08/2023 09:55:02
QRCode
archive.org
thumbnail

Notorious botnet and infostealer XLoader makes a return to macOS with a new dropper and malware payload.

sentinelone EN 2023 XLoader macOS dropper payload
Mac systems turned into proxy exit nodes by AdLoad https://cybersecurity.att.com/blogs/labs-research/mac-systems-turned-into-proxy-exit-nodes-by-adload
14/08/2023 15:51:24
QRCode
archive.org
thumbnail

AdLoad malware is still infecting Mac systems years after its first appearance in 2017. AdLoad, a package bundler, has been observed delivering a wide range of payloads throughout its existence. During AT&T Alien Labs’ investigation of its most recent payload, it was discovered that the most common component dropped by AdLoad during the past year has been a proxy application turning MacOS AdLoad victims into a giant, residential proxy botnet.

ATT Alien AT&T-Alien-Labs EN 2023 macOS AdLoad
An Apple Malware-Flagging Tool Is ‘Trivially’ Easy to Bypass https://www.wired.com/story/apple-mac-background-task-management-flaw/
14/08/2023 07:20:04
QRCode
archive.org
thumbnail

The macOS Background Task Manager tool is supposed to spot potentially malicious software on your machine. But a researcher says it has troubling flaws.

wired EN 2023 Apple macOS Task-Manager PatrickWardle bypass
Apple Crimeware | Massive Rust Infostealer Campaign Aiming for macOS Sonoma Ahead of Public Release https://www.sentinelone.com/blog/apple-crimeware-massive-rust-infostealer-campaign-aiming-for-macos-sonoma-ahead-of-public-release/
31/07/2023 14:57:55
QRCode
archive.org
thumbnail

Crimeware actors have launched an extensive campaign to target macOS users with malware disguised in multiple fake blockchain games.

sentinelone EN 2023 Apple Crimeware Rust Infostealer Campaign macOS Sonoma
ShadowVault is the latest Mac data-stealer malware, reportedly https://www.intego.com/mac-security-blog/shadowvault-is-the-latest-mac-data-stealer-malware-reportedly/
14/07/2023 23:03:01
QRCode
archive.org
thumbnail

ShadowVault data stealer Mac malware made headlines in the Apple press this week. Here is what we know about it so far.

intego EN 2023 macOS ShadowVault Mac malware
Uncovering weaknesses in Apple macOS and VMWare vCenter: 12 vulnerabilities in RPC implementation https://blog.talosintelligence.com/weaknesses-mac-os-vmware-msrpc/
14/07/2023 09:47:57
QRCode
archive.org
thumbnail

Cisco Talos discovered 12 memory corruption vulnerabilities in MSRPC implementations on Apple macOS and VMWare vCenter.
      - Seven vulnerabilities affect Apple macOS only.
      - Two vulnerabilities affect VMWare vCenter.
      - Three vulnerabilities affect both.

talosintelligence EN 2023 MSRPC macOS VMWare vCenter vulnerabilities
Apple confirms WebKit security updates break browsing on some sites https://www.bleepingcomputer.com/news/security/apple-confirms-webkit-security-updates-break-browsing-on-some-sites/
12/07/2023 09:31:45
QRCode
archive.org
thumbnail

Apple confirmed today that emergency security updates released on Monday to address a zero-day bug exploited in attacks break browsing on some websites, and new ones will be released soon to address this known issue.

bleepingcomputer Apple iOS macOS Rapid-Security-Response Security-Update WebKit
Apple releases emergency update to fix zero-day exploited in attacks https://www.bleepingcomputer.com/news/apple/apple-releases-emergency-update-to-fix-zero-day-exploited-in-attacks/
12/07/2023 09:09:39
QRCode
archive.org
thumbnail

Apple has issued a new round of Rapid Security Response (RSR) updates to address a new zero-day bug exploited in attacks and impacting fully-patched iPhones, Macs, and iPads.

bleepingcomputer EN 2023 CVE-2023-37450 Apple iOS iPad iPhone Mac macOS Rapid-Security-Response Zero-Day
BlueNoroff | How DPRK’s macOS RustBucket Seeks to Evade Analysis and Detection - https://www.sentinelone.com/blog/bluenoroff-how-dprks-macos-rustbucket-seeks-to-evade-analysis-and-detection/
05/07/2023 21:58:26
QRCode
archive.org
thumbnail

Threat actors are using increasingly sophisticated forms of evasion and anti-analysis as they respond to increased attention to macOS security in the enterprise.

sentinelone EN 2023 BlueNoroff DPRK macOS RustBucket Evade analysis
Emerging Threat! Exposing JOKERSPY https://www.elastic.co/fr/security-labs/inital-research-of-jokerspy
22/06/2023 21:36:02
QRCode
archive.org
thumbnail

Explore JOKERSPY, a recently discovered campaign that targets financial institutions with Python backdoors. This article covers reconnaissance, attack patterns, and methods of identifying JOKERSPY in your network.

elastic.co EN 2023 JOKERSPY macOS Python backdoor
Fragments of Cross-Platform Backdoor Hint at Larger Mac OS Attack https://www.bitdefender.com/blog/labs/fragments-of-cross-platform-backdoor-hint-at-larger-mac-os-attack/
22/06/2023 21:18:20
QRCode
archive.org

During routine detection maintenance, our Mac researchers stumbled upon a small set of files with backdoor capabilities that seem to form part of a more complex malware toolkit. The following analysis is incomplete, as we are trying to identify the puzzle pieces that are still missing.

bitdefender EN 2023 macOS malware Cross-Platform Backdoor
page 5 / 10
4508 links
Shaarli - The personal, minimalist, super-fast, database free, bookmarking service par la communauté Shaarli - Theme by kalvn - Curated by Decio