Skip to content

Cybersecurity News Everyday

Stay Ahead of Cyber Threats – Daily Security Insights, Powered by AI

    • Cyber Attack & Data Breach
    • Daily Recap
    • Disclaimer
    • Hacked: Web Defacement
    • My Bookmarks
    • Security Report
    • User Bookmark Dashboard
    • Web Statistics
    • YouTube Overview
    • Welcome!
    • Threat Research
    • Security News
    • Ransom Monitor
    • Interesting Stuff

Tag: MACOS

Threat Research

Attackers Use Containers for Profit via TrafficStealer

April 21, 2023October 15, 2025 Securonix

TrafficStealer uses Docker containers to generate revenue by proxying users’ traffic and manipulating ad engagement, turning honeypots into monetization machines. Attackers leverage public container images and automation via YAML to scale the operation, while …

Read More
Threat Research

Critical Vulnerabilities in PaperCut Print Management Software

April 18, 2023October 16, 2025 Securonix

Researchers observed in-the-wild exploitation of zero-day vulnerabilities in PaperCut MF/NG that allow unauthenticated remote code execution via an authentication bypass. The campaign uses post-exploitation payloads (including Atera and Syncro RMM installers) …

Read More
Threat Research

Linux malware strengthens links between Lazarus and the 3CX supply-chain attack

April 17, 2023October 14, 2025 Securonix

ESET researchers link Lazarus to the 3CX supply-chain attack, detailing Operation DreamJob’s Linux payload OdicLoader delivering the SimplexTea backdoor via OpenDrive. The findings reinforce Lazarus’s cross-OS toolkit (Windows, macOS, Linux) and its engagement…

Read More
Threat Research

Not just an infostealer: Gopuram backdoor deployed through 3CX supply chain attack

April 4, 2023October 14, 2025 Securonix

Security researchers анализed a 3CX supply-chain attack and found that manipulated MSI installers of 3CXDesktopApp deliver a malicious DLL which decrypts and executes shellcode, dropping a backdoor named Gopuram along with an infostealer. Attribution points to…

Read More
Threat Research

Verblecon: Sophisticated New Loader Used in Low-level Attacks

March 31, 2023October 15, 2025 Securonix

Symantec tracks a new loader called Verblecon (Trojan.Verblecon) used in low-reward attacks to install cryptocurrency miners and potentially steal Discord access tokens, with greater danger if leveraged in ransomware or espionage. First spotted in January 2022…

Read More
Threat Research

3CX Supply Chain Compromise Leads to ICONIC Incident

March 30, 2023October 13, 2025 Volexity

Volexity analyzed a supply-chain compromise of the 3CX Desktop App in which a malicious ffmpeg library inserted into signed installers decoded encrypted blobs, fetched staged payloads, and reflectively loaded a 64-bit information-stealer dubbed ICONIC/ICONICST…

Read More
Threat Research

SmoothOperator | Ongoing Campaign Trojanizes 3CXDesktopApp in Supply Chain Attack

March 24, 2023October 14, 2025 Securonix

SentinelOne details a multi-stage supply-chain campaign that trojanizes the 3CXDesktopApp, loading shellcode and pulling ICO data from GitHub to deliver a 3rd-stage infostealer DLL. The operation also extends to macOS with separate stages (libffmpeg.dylib and …

Read More
Threat Research

Session Cookies, Keychains, SSH Keys and More | 7 Kinds of Data Malware Steals from macOS Users

March 20, 2023October 16, 2025 Securonix

MacOS threat actors are increasingly focusing on data theft rather than ransom, exfiltrating session cookies, keychains, SSH keys, and other sensitive data to monetize or enable espionage. The article outlines where these data assets reside, how attackers acce…

Read More
Threat Research

MacStealer: New MacOS-based Stealer Malware Identified

March 20, 2023October 16, 2025 Securonix

MacStealer is a macOS stealer distributed via DMG that is controlled over Telegram, marking a new platform for stealer operations. It exfiltrates browser credentials, Keychain data, and files, sending stolen data via HTTP POST to a C2 and to Telegram channels/…

Read More
Threat Research

Cyble – Titan Stealer: The Growing Use Of GoLang Among Threat Actors

January 20, 2023October 18, 2025 Securonix

Threat actors are increasingly using Go (Golang) to develop cross‑platform information stealers, with Titan Stealer highlighted as a recent example. The article covers Titan Stealer’s Go-based builder, its C2 infrastructure and dashboards, the data it collects…

Read More
Threat Research

Phylum Detects Ongoing Typosquat/Ransomware Campaign in PyPI and NPM

December 9, 2022October 17, 2025 Securonix

Phylum reports an ongoing typosquatting campaign targeting Python and JavaScript developers on PyPI and NPM, delivering a ransomware payload when executed. The attacker publishes typosquatted packages (notably around the Python requests package) that fetch a l…

Read More
Threat Research

DeimosC2: What SOC Analysts and Incident Responders Need to Know About This C&C Framework

November 1, 2022October 13, 2025 Securonix

DeimosC2 is presented as an open-source post-exploitation C2 framework that attackers may consider alongside Cobalt Strike, with details on how it operates, how its traffic and binaries can be identified, and defensive recommendations. The report covers Deimos…

Read More
Threat Research

Two Weeks of Monitoring ProxyNotShell (CVE-2022-41040 & CVE-2022-41082) Threat Activity

October 13, 2022October 15, 2025 Securonix

Two zero-day Exchange vulnerabilities, CVE-2022-41040 and CVE-2022-41082 (ProxyNotShell), are being actively exploited in the wild, with over 1.6 million exploit attempts observed across 4 million protected websites. The activity shows GET-based probing agains…

Read More
Threat Research

Alchimist: A new attack framework in Chinese for Mac, Linux and Windows

October 7, 2022October 18, 2025 Securonix

Cisco Talos uncovers a new all-in-one offensive framework, Alchimist, with a GoLang-based C2 and a companion RAT called Insekt that targets Windows, Linux, and Mac, featuring a Chinese web UI and remote administration. The dropper/c2 stack includes MacOSX expl…

Read More
Threat Research

Lazarus ā€˜Operation In(ter)ception’ Targets macOS Users Dreaming of Jobs in Crypto

September 26, 2022October 15, 2025 Securonix

Operation In(ter)ception continues Lazarus’ macOS malware activity, using decoy job postings for Coinbase and Crypto.com to lure victims and install a multi-stage payload. The campaign features persistence via a LaunchAgent, staged download components, and har…

Read More

Posts pagination

Previous 1 … 69 70 71 Next

What are you looking for ?

  • šŸ–„ļø [ D A S H B O A R D ]
  • šŸ•µļøā€ā™‚ļø Threat Research
  • šŸ“° Security News
  • 🚨 Attack & Data Breach
  • šŸ›‘ Ransomware Monitor
  • šŸ’€ Hacked! Web Defacement
  • ✨ Interesting Stuff
  • šŸ“ŗ Youtube Overview
  • šŸ” Google Cybersecurity
  • šŸ“¢ Telegram Notification
  • šŸ“° News Daily Recap
  • šŸ“° Security Report
  • X / T W I T T E R
  • B L U E S K Y
  • L I N K E D . I N
  • T H R E A D S
  • T E L E G R A M
  • F A C E B O O K

Website Disclaimer

Proudly powered by WordPress | Theme: Fairy Dark by Candid Themes.