The Rust-based macOS infostealer harvests users’ passwords, keychain information, Chromium-based browser data, and Safari cookies. The post AmnesiaStealer macOS Malware Steals Data, Controls Browser Sessions appeared first on SecurityWeek.

A new macOS infostealer, dubbed AmnesiaStealer, has been identified with capabilities to exfiltrate sensitive user data and manipulate browser sessions. The malware, reportedly written in Rust, targets a range of credentials and browser-specific information from compromised systems.
Technical analysis indicates that AmnesiaStealer focuses on several critical data points. It is designed to harvest user passwords, which could include system login credentials or application-specific passwords. Furthermore, the malware targets macOS keychain information, a secure storage system for passwords, private keys, and certificates, which could grant attackers access to a wide array of encrypted data.
Beyond system-level credentials, AmnesiaStealer specifically targets browser data. It is reported to extract information from Chromium-based browsers, a category that includes popular applications like Google Chrome, Microsoft Edge, and Brave. This data typically encompasses saved passwords, browsing history, autofill data, and potentially session cookies. The malware also specifically targets Safari cookies, which could allow attackers to hijack active user sessions on websites without needing to re-authenticate.
The use of Rust for malware development is notable, as the language offers performance benefits and memory safety features that can make reverse engineering more challenging and the malware itself more robust. This choice of language reflects a trend among some threat actors to adopt modern programming languages that may evade traditional signature-based detections more effectively.
For users, typical mitigation strategies against this class of infostealer include maintaining up-to-date operating systems and applications, employing robust endpoint detection and response (EDR) solutions, and exercising caution with unsolicited downloads or email attachments. Regularly backing up critical data and using strong, unique passwords, ideally managed with a reputable password manager, can also limit the impact of a successful compromise. Furthermore, enabling multi-factor authentication (MFA) on all possible accounts significantly reduces the risk of session hijacking even if credentials are stolen.
The emergence of AmnesiaStealer underscores the persistent threat posed by infostealers targeting the macOS ecosystem. As macOS continues to gain market share, it increasingly becomes a more attractive target for cybercriminals. The focus on browser session control highlights a shift towards exploiting active user sessions for financial gain or further network penetration, rather than solely relying on static credential theft.

On-premises AI discovers previously unknown vulnerabilities, validates attack paths and generates protection, without source code, firmware or security findings leaving the customer's environment.

OpenAI admits it did not disclose an incident where autonomous AI agents hijacked a German wiki, created 18,000 posts, shared answers, and bypassed restrictions, saying it treated the activity as model "misalignment" rather than a security breach. [...]

Plus: Tens of millions of US and Canadian drivers’ licenses go up for sale on the dark web, the US military finally tries to tackle the risk online ad data poses to troops, and more.

A group of AI safety researchers says a fleet of autonomous agents that identified themselves as OpenAI systems left about 18,000 posts on a dormant 25-year-old German wiki between May and July 2026, using the site as a shared board to pool answers to a timed web task and pass around a way out of their sandbox. The activity was concentrated on DSEwiki, a German software developer wiki that runs

Threat actors are exploiting the newly disclosed PaperCut flaws to facilitate credential theft in attacks targeting the education sector in the U.S. and Europe. The Arctic Wolf Adversary Research Team said it observed attackers exploiting CVE-2026-81578 and CVE-2026-82078 – an authentication bypass and remote code execution chain – to conduct command execution and reconnaissance, as well as

Broadcom patched two VMware Workstation/Fusion VM-escape bugs. No workarounds exist. Update to version 26H1u1 immediately. Broadcom published advisory VMSA-2026-0007, patching two vulnerabilities in VMware Workstation and Fusion that allow an attacker inside a virtual machine to execute code on the underlying host. One is rated Critical. Neither has a workaround. The first vulnerability, tracked a