A Go-based malware delivered in ClickFix attacks targeting macOS users is stealing cryptocurrency assets, browser-stored passwords, Apple Keychain data, and cached credentials. [...]

A new macOS infostealer, delivered through "ClickFix" attacks, is targeting cryptocurrency assets, browser-stored passwords, Apple Keychain data, and cached credentials. The malware, written in Go, has the capability to intercept and redirect cryptocurrency transactions, either fully draining wallets or diverting a percentage of funds to the attacker.
Security researchers at Huntress discovered the payload during an incident response. The attack begins with a targeted email containing a link that directs the user to a page instructing them to execute a command in Terminal. This command downloads a Bash script that acts as a profiler and malware loader.
The Bash script first collects system information, such as CPU and RAM details. It then retrieves a Mach-O payload specifically matched to the victim system's processor architecture. The profiler also identifies the currently logged-in user's account name and creates a directory named "trustd," a reference to the macOS process responsible for validating cryptographic certificates and code signatures.
The infostealing and crypto-draining payload is then copied into this newly created directory as "com.apple.verified." To bypass macOS Gatekeeper security alerts, the script removes the "com.apple.quarantine" extended attribute from the file.
For persistence and privilege escalation, the malware employs the `osascript` utility to create a fake error dialog box, prompting the user for their administrator password. Once executed, the stealer payload scans the system for files containing credentials, identifying them by both name and extension. This includes browser password databases, the Apple Keychain, and cached credentials stored in browser cookies.
A notable feature of this Go-based malware is its ability to modify cryptocurrency transactions before they are signed. It can be configured to redirect only a percentage of the funds to the attacker, rather than the entire amount. Huntress researchers observed functions within the malware that calculate the value of 1% of a wallet's content, tailored to specific cryptocurrency types.
Cryptocurrencies targeted by the malware include Bitcoin, Litecoin, Dogecoin, Monero, Ethereum, and Ripple's XRP. The malware communicates with command-and-control servers via shared IP addresses within Autonomous System (AS) 210644, which is operated by the Aeza Group, a Russian corporation. The Aeza Group and its affiliates have been sanctioned by the US and UK for providing "bulletproof hosting" services to ransomware groups.
A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host causes os command injection. The attack can be initiated remotely.
A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in os command injection. It is possible to launch the attack remotely.

OpenAI has announced a $1 billion commitment to provide subsidized access to its Daybreak AI cybersecurity tools for under-resourced critical infrastructure defenders. The initiative, named Daybreak for Frontline Defenders, will offer AI models, training, and technical support over the next six months, prioritizing water and wastewater utilities, electric grid operators, and local government entities. This move aims to equip organizations with limited budgets and staff against increasingly sophisticated cyber threats.

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is publishing early
In BPF instructions that load/store a value from/to a scratch memory register the register index is an unsigned 32-bit integer and must not exceed 15, but libpcap BPF interpreter does not validate the value. In particular uncommon use cases a crafted filter program can cause the interpreter to try reading and writing the OS process memory in the 16GiB starting at the current stack frame on 64-bit architectures and in the entire address space on 32-bit architectures.

Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-2026-82078, in attacks targeting schools and other education organizations in the U.S. and Europe, as reported by TheHackerNews. Arctic Wolf researchers observed