LIVE · cybersecurity feed
Live wire
Metabase Zero-Day Exploited in the Wild, Exposing Admin Access and Sensitive DataCritical One-Click Vulnerability in Atlassian’s Rovo AI Exposed Enterprise DataCVE-2026-8037 · CISA Adds Progress LoadMaster Command Injection Flaw to KEV CatalogSensitive Info Goes Into ‘No Reply’ Emails Constantly. This Guy Sees It AllAtlassian Rovo Can Be Tricked Into Sending Jira and Confluence Data to AttackersNew CSS Attacks Can Break Webmail Defenses to Steal Passwords and TokensCVE-2023-38646 · Metabase Zero-Day Exploited in Wild Allows Admin Access Without AuthenticationCVE-2026-18577 · N-able Issues N-central Hotfix 2 as Attackers Reach Managed Systems and PersistCVE-2026-8037 · Progress Kemp LoadMaster Flaw Hits CISA KEV After 792 Reported Exploit AttemptsLiving off the coding agent: Two tales of tunnels and LaunchAgents
macoshigh

ClickFix Attacks Deliver macOS Stealer That Can Drain Crypto Wallets

A new Go-based malware targeting macOS is being distributed through ClickFix-style attacks. This malware is capable of stealing browser passwords, Apple Keychain data, and cached credentials. Notably, it also includes a function to gradually drain cryptocurrency wallets, siphoning funds into attacker-controlled accounts across various cryptocurrencies like Bitcoin, Ethereum, and XRP.

zeroday.news ·

Reports indicate the emergence of a new macOS-targeting malware, dubbed "ClickFix Attacks," which is being distributed through a method described as "ClickFix-style attacks." This Go-based malware is designed to exfiltrate sensitive user data, including browser passwords, Apple Keychain information, and cached credentials. A particularly concerning feature of this new threat is its ability to systematically drain cryptocurrency wallets, transferring funds to attacker-controlled accounts.

The malware's distribution mechanism, referred to as "ClickFix-style attacks," suggests a social engineering component, likely involving deceptive user interaction to initiate the infection chain. While the specifics of this distribution method are not detailed, such attacks typically leverage user trust or curiosity to trick them into executing malicious payloads, often disguised as legitimate software updates, installers, or documents. The use of Go for the malware's development indicates a cross-platform capability, though in this reported instance, it is specifically targeting macOS systems.

Once active on a compromised macOS system, the malware focuses on data exfiltration. It targets common repositories of sensitive user information, such as web browser password managers and the macOS Keychain. The Keychain stores a variety of credentials, including Wi-Fi passwords, application passwords, and secure notes, making it a valuable target for attackers seeking to gain broader access to a victim's digital life. The theft of cached credentials further expands the attacker's potential access to services the user has recently authenticated to.

A distinctive and highly damaging capability of this malware is its function to drain cryptocurrency wallets. This suggests the malware actively monitors or interacts with cryptocurrency wallet applications or browser extensions. It is reported to gradually siphon funds, indicating a potential strategy to avoid immediate detection by transferring smaller amounts over time, rather than a single large transaction. The malware is reported to target various cryptocurrencies, including Bitcoin, Ethereum, and XRP, suggesting a broad capability to interact with different blockchain assets.

Mitigation for such threats typically involves a multi-layered approach. Users should exercise extreme caution with unsolicited downloads, email attachments, and links, especially those prompting software installations or updates. Keeping macOS and all installed applications up to date is crucial to patch known vulnerabilities that malware might exploit. Employing reputable antivirus or anti-malware solutions specifically designed for macOS can help detect and block such threats. Furthermore, users with cryptocurrency holdings should consider hardware wallets or multi-factor authentication for their software wallets to add an extra layer of security against unauthorized transactions.

The emergence of this Go-based macOS stealer, with its specialized cryptocurrency draining capabilities, highlights the evolving threat landscape faced by macOS users. As digital assets like cryptocurrencies become more prevalent, attackers are increasingly developing sophisticated tools to target them. This incident underscores the importance of robust security practices, user vigilance, and continuous adaptation of defensive strategies to counter emerging and financially motivated cyber threats.

macosmalwarestealercryptocurrencyclickfix
ShareXLinkedInWhatsAppFacebook

More News

view all →
breach

Hackers breach TrueConf to trojanize client installers with backdoors

The Head Mare hacktivist group has been exploiting vulnerabilities in unpatched TrueConf video conferencing servers to replace client installers with malicious versions that deliver backdoors. [...]

cybersecurity

China Launches Cybersecurity Review of Palo Alto Networks Products

China's Cyberspace Administration has initiated a cybersecurity review of Palo Alto Networks' products sold within the country, citing national security concerns. The review, based on national security and cybersecurity laws, lacks specific details regarding the reasons or potential impact. Palo Alto Networks has stated that its operations and product delivery in the region remain unaffected for now.

ai

Devs to Anthropic, OpenAI, Cursor, and friends: Make security and privacy the default

Researchers scour social media to measure developer concerns about AI coding tools

vulnerabilityhigh

Metabase Zero-Day Exploited in the Wild, Exposing Admin Access and Sensitive Data

Attackers exploited a CVSS 10 Metabase zero-day to gain admin access and steal sensitive data. Framework confirmed it was among the victims. Metabase just confirmed something no analytics vendor wants to write: attackers found and used an unpatched, maximum-severity flaw against Metabase Cloud before anyone on the defense side knew it existed. The company’s own […]

breachcritical

Critical One-Click Vulnerability in Atlassian’s Rovo AI Exposed Enterprise Data

The RovoBlast attack method identified by Varonis researchers could have been exploited to steal Confluence, Jira and SharePoint data. The post Critical One-Click Vulnerability in Atlassian’s Rovo AI Exposed Enterprise Data appeared first on SecurityWeek.

CVE-2026-8037critical

CISA Adds Progress LoadMaster Command Injection Flaw to KEV Catalog

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical vulnerability in Progress LoadMaster products to its Known Exploited Vulnerabilities catalog. This OS command injection flaw, tracked as CVE-2026-8037, allows unauthenticated attackers to execute arbitrary commands remotely. Exploitation attempts were observed as early as June 29, 2026, shortly after a proof-of-concept exploit became available.