A new Go-based malware targeting macOS is being distributed through ClickFix-style attacks. This malware is capable of stealing browser passwords, Apple Keychain data, and cached credentials. Notably, it also includes a function to gradually drain cryptocurrency wallets, siphoning funds into attacker-controlled accounts across various cryptocurrencies like Bitcoin, Ethereum, and XRP.

Reports indicate the emergence of a new macOS-targeting malware, dubbed "ClickFix Attacks," which is being distributed through a method described as "ClickFix-style attacks." This Go-based malware is designed to exfiltrate sensitive user data, including browser passwords, Apple Keychain information, and cached credentials. A particularly concerning feature of this new threat is its ability to systematically drain cryptocurrency wallets, transferring funds to attacker-controlled accounts.
The malware's distribution mechanism, referred to as "ClickFix-style attacks," suggests a social engineering component, likely involving deceptive user interaction to initiate the infection chain. While the specifics of this distribution method are not detailed, such attacks typically leverage user trust or curiosity to trick them into executing malicious payloads, often disguised as legitimate software updates, installers, or documents. The use of Go for the malware's development indicates a cross-platform capability, though in this reported instance, it is specifically targeting macOS systems.
Once active on a compromised macOS system, the malware focuses on data exfiltration. It targets common repositories of sensitive user information, such as web browser password managers and the macOS Keychain. The Keychain stores a variety of credentials, including Wi-Fi passwords, application passwords, and secure notes, making it a valuable target for attackers seeking to gain broader access to a victim's digital life. The theft of cached credentials further expands the attacker's potential access to services the user has recently authenticated to.
A distinctive and highly damaging capability of this malware is its function to drain cryptocurrency wallets. This suggests the malware actively monitors or interacts with cryptocurrency wallet applications or browser extensions. It is reported to gradually siphon funds, indicating a potential strategy to avoid immediate detection by transferring smaller amounts over time, rather than a single large transaction. The malware is reported to target various cryptocurrencies, including Bitcoin, Ethereum, and XRP, suggesting a broad capability to interact with different blockchain assets.
Mitigation for such threats typically involves a multi-layered approach. Users should exercise extreme caution with unsolicited downloads, email attachments, and links, especially those prompting software installations or updates. Keeping macOS and all installed applications up to date is crucial to patch known vulnerabilities that malware might exploit. Employing reputable antivirus or anti-malware solutions specifically designed for macOS can help detect and block such threats. Furthermore, users with cryptocurrency holdings should consider hardware wallets or multi-factor authentication for their software wallets to add an extra layer of security against unauthorized transactions.
The emergence of this Go-based macOS stealer, with its specialized cryptocurrency draining capabilities, highlights the evolving threat landscape faced by macOS users. As digital assets like cryptocurrencies become more prevalent, attackers are increasingly developing sophisticated tools to target them. This incident underscores the importance of robust security practices, user vigilance, and continuous adaptation of defensive strategies to counter emerging and financially motivated cyber threats.
A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host causes os command injection. The attack can be initiated remotely.
A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in os command injection. It is possible to launch the attack remotely.

OpenAI has announced a $1 billion commitment to provide subsidized access to its Daybreak AI cybersecurity tools for under-resourced critical infrastructure defenders. The initiative, named Daybreak for Frontline Defenders, will offer AI models, training, and technical support over the next six months, prioritizing water and wastewater utilities, electric grid operators, and local government entities. This move aims to equip organizations with limited budgets and staff against increasingly sophisticated cyber threats.

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is publishing early
In BPF instructions that load/store a value from/to a scratch memory register the register index is an unsigned 32-bit integer and must not exceed 15, but libpcap BPF interpreter does not validate the value. In particular uncommon use cases a crafted filter program can cause the interpreter to try reading and writing the OS process memory in the 16GiB starting at the current stack frame on 64-bit architectures and in the entire address space on 32-bit architectures.

Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-2026-82078, in attacks targeting schools and other education organizations in the U.S. and Europe, as reported by TheHackerNews. Arctic Wolf researchers observed