
ClickFix attack pushes macOS infostealer for crypto theft attacks
Security researchers at Huntress discovered a Go-based malware delivered in ClickFix attacks targeting macOS users that steals cryptocurrency assets and other sensitive data.
Stories tagged “Macos.”
30 stories

Security researchers at Huntress discovered a Go-based malware delivered in ClickFix attacks targeting macOS users that steals cryptocurrency assets and other sensitive data.

Cybersecurity researchers have discovered a security issue with Apple's iCloud Private Relay tool that can expose a user's real IP address. The issue is rooted in three features in Apple's WebKit: DNS prefetching, WebAuthn Related Origin Requests, and WebTransport.

A new version of the XCSSET malware targets thousands of macOS users through compromised Xcode projects and GitHub repositories. The malware features enhanced evasion techniques and introduces two new components.
Apple and Bynario Agree GPT-5.5 Found a Real macOS Bug, but They Disagree on the Report Cap
Apple and Bynario agree that GPT-5.5 found a real macOS bug, but they disagree on the report cap. The two companies have different opinions on how to handle the bug report.
Kakehashi is an experimental userspace to run macOS binaries on Linux ARM64. It provides a translation layer for Linux ARM64 to load Darwin Mach-O on Linux aarch64, map a freestanding libSystem, translate BSD syscalls, and run real guests.

macOS 27, also known as Golden Gate, is coming this fall with various improvements for the Mac. Five new features have been added, including file name suggestions, swipe to refresh, iPhone Mirroring improvements, video support in Apple Podcasts, and Siri and Spotlight upg…
Gemma 4 26B-A4B inference in ~2 GB of RAM on any M-series Mac
A custom Swift + Metal runtime for any Apple Silicon Mac, even the 8 GB ones, that runs the instruction-tuned Gemma 4 26B-A4B without loading the entire 14.3 GB model into memory.

Cybersecurity researchers have uncovered a sandbox escape vulnerability in Anthropic's Claude Cowork that makes it possible to break out of the confines of a Linux virtual machine (VM) within which the agent runs to read or write files anywhere on the Mac.

Apple has updated its macOS 28 migration guidance to include a new option for users with encrypted HFS+ drives. Instead of decrypting the drive, users can now convert it directly to encrypted APFS without decrypting it first.

Users experiencing beach balls on Mac when running macOS 26.5 and unresponsive trackpad have found a reliable solution by deleting the ~/Library/Metadata/CoreSpotlight folder.

A new macOS malware is stealing credentials to hijack Telegram sessions and compromise cryptocurrency wallets, according to blockchain security firm SlowMist.

A new macOS information-stealing malware dubbed ClickLock terminates all visible processes to force users into entering their system login password. The malware is designed to steal cryptocurrency assets, login credentials, password-manager data, browser information, and …

A new macOS infostealer called ClickLock Stealer has been discovered, which kills apps every 210 milliseconds until victims type their password. The malware arrives as a command pasted into Terminal and asks for the password behind a fake system dialog.
New Mac malware masquerades as Apple's crash reporter: 3 ways to dodge the threat
A new form of malware is masquerading as Apple's crash reporting tool to target MacOS users and harvest their data, account credentials, keychain entries, and cryptocurrency wallets.

Jamf Threat Labs has identified a new native C++ macOS information stealer called CrashStealer that uses an Apple-notarized dropper to bypass Gatekeeper. It harvests browser credentials, crypto wallets, password managers, and keychain data.

Cybersecurity researchers have flagged a novel Java-based remote access trojan (RAT) called QuimaRAT targeting Windows, Linux, and macOS. The malware is advertised under a MaaS model with various subscription tiers.

Cybersecurity firm Jamf Threat Labs identified a new Rust-based macOS infostealer, PamStealer, disguised as the Maccy clipboard manager, which can steal user passwords and crypto wallet keys.
A curated list of awesome applications and tools for macOS. Includes apps for audio, backup, chat, data recovery, and more.

This guide shows how to create a macOS Golden Gate USB install drive. Having a USB installer is useful for upgrading from macOS Tahoe or earlier versions across multiple Macs.
Adrafinil is a macOS menu bar app that prevents the system from sleeping while an AI coding agent is active. It only intervenes when an agent is mid-task and gets out of the way when the work finishes.
Aurora: Mac Notch Command Center for Productivity
Aurora is a Mac app that turns the notch into a productivity layer. It offers media controls, clipboard, calendar, focus timers, notes, widgets, and writing actions.

A new macOS malware called Gaslight embeds fake errors to confuse AI analysis tools. The malware contains strings that attempt to gaslight AI-assisted analysis tools into believing there is an analysis error.

A new macOS malware, codenamed Gaslight, uses prompt injection to trick AI-assisted analysis tools. It's believed to be the work of North Korea-aligned threat actors.

A new macOS ClickFix campaign uses Terminal commands to download and launch info-stealing malware from malicious DMG files. The campaign infects Mac devices with the Atomic macOS Stealer, which steals browser credentials and cryptocurrency wallet data.

Apple has released the second developer beta of macOS 27 Golden Gate. The update brings improvements to Liquid Glass and standardizes rounded corners across system windows and apps.

Apple releases new betas for its current software lineup, including macOS 26.6, iPadOS 26.6, and watchOS 26.6. The updates are focused on bug fixes and performance improvements.
Container made it easy to run Linux on my MacBook - here's how I set it up
Container is a command-line tool that allows running Linux containers on Apple silicon Macs. It's free and optimized for Apple Silicon Mac hardware.

Researchers say a malicious site can infer what other sites and apps a user opens by measuring SSD timing from inside the browser.

macOS 27 adds resizable iPhone Mirroring windows with fixed aspect ratios and Control Center access.

Researchers say a macOS malvertising campaign is delivering FlutterShell, a backdoor that can run commands, manipulate files, and hijack browser traffic.