LIVE · cybersecurity feed
Live wire
OpenAI Announced $1B in Defensive Tools for Water UtilitiesAttackers Breached JetBrains Cadence via Unpatched TeamCity, Extracting AWS CredentialsCVE-2026-59346 · Critical VMware Workstation and Fusion Flaw Lets VM Admins Execute Host CodeCVE-2026-32475 · Elementor Pro WordPress Plugin Vulnerability Exploited to Hack SitesBroadcom Patches Critical VMware Workstation and Fusion VM-Escape VulnerabilitiesHackers Leak Millions of Airport Passenger Records After Ransom RefusalUsing a VM to Contain an AI AgentCVE-2026-73749 · HPE Patches Critical RCE Vulnerabilities in AOS-CXCVE-2026-14894 · Over 440,000 Exploit Attempts Target Super Forms and Elementor Pro RCE FlawsCisco searched for IOS XR bugs and found so many it rolled them into an update release
malware

New AmnesiaStealer macOS malware hijacks browser sessions via remote control

A new information-stealing malware called AmnesiaStealer, which targets macOS users via ClickFix attacks, includes a streaming module that allows the attacker to interactively control the victim's web browser. [...]

zeroday.news ·

A new information-stealing malware, dubbed AmnesiaStealer, is targeting macOS users through "ClickFix" campaigns, according to research from Jamf. The malware's notable capability is its "stream_module," which allows attackers to remotely control a victim's web browser through a hidden, headless instance, effectively hijacking authenticated sessions.

AmnesiaStealer is distributed via fake GitHub download pages that prompt users to download a password-protected ZIP archive. These ClickFix campaigns employ a shell-script loader to retrieve and launch the archive containing the AmnesiaStealer Mach-O payload. This distribution method has previously been observed in campaigns spreading the Atomic and MacSync infostealers.

Once executed, AmnesiaStealer attempts to capture the victim's macOS password. This credential is then used to exfiltrate sensitive data, including keychain information, browser profiles, Apple Notes, Telegram sessions, documents, system details, and cryptocurrency wallet data. The malware is designed to collect data from 16 Chromium-based web browsers.

The "stream_module" component, activated via the "remote_stream" command, is central to AmnesiaStealer's advanced capabilities. It can duplicate user profiles in seven specific Chromium-based browsers: Google Chrome, Microsoft Edge, Vivaldi, Arc, Opera, Brave, and Chromium. This is possible due to their shared DevTools Protocol, launch flags, and cookie encryption mechanisms.

The module operates by launching the legitimate browser executable in a headless mode, using command-line switches that weaken its inherent defenses. It then duplicates the victim's browser profile, specifying a new location for storing the profile data. A WebSocket channel is established to connect to the attacker's relay, sending a JSON registration message with the browser's name and build.

Through this channel, the attacker can send commands such as navigation and mouse clicks. The malware responds with status and tab information in JSON format, and transmits screencast frames as binary WebSocket messages at approximately 3 frames per second. A second WebSocket channel connects to the local headless Chromium instance via the browser’s "webSocketDebuggerUrl," providing access to the Chrome DevTools Protocol (CDP).

This CDP access enables the attacker to navigate websites, control mouse and keyboard input, export or import cookies, and operate online portals using the victim's existing authenticated sessions. This effectively turns the infected host into a live, operator-driven browser running the victim's authenticated sessions, offering a significantly deeper level of access than mere file collection.

Beyond live session hijacking, AmnesiaStealer can exfiltrate cookies, saved logins, browsing history, bookmarks, extensions, local state, and other profile data from the 16 targeted Chromium-based browsers. It also identifies and steals cryptocurrency wallet details by enumerating extensions and IndexedDB data.

A notable fallback mechanism exists for macOS 26, where if the malware cannot recover the existing Chrome Safe Storage key, it replaces it with an attacker-supplied value. This renders previously stored cookies and passwords permanently unreadable to the user while allowing the attacker to decrypt the data later.

While the Chrome DevTools Protocol has been abused by other malware, such as Chaos ransomware for C2 communications and Chaes malware for data theft, AmnesiaStealer is reportedly the first documented macOS malware to combine a cloned Chromium profile with CDP-based, live remote control to interact with authenticated sessions through a hidden browser on the infected machine. Users are advised to exercise caution and avoid executing unfamiliar terminal commands found online.

malwarepatch
ShareXLinkedInWhatsAppFacebook

More News

view all →
ai

BreachX Launches Typhon, India-Built Sovereign Cybersecurity AI for Zero-Day Discovery and Defense

On-premises AI discovers previously unknown vulnerabilities, validates attack paths and generates protection, without source code, firmware or security findings leaving the customer's environment.

breach

OpenAI admits it didn't disclose rogue AI wiki hijacking incident

OpenAI admits it did not disclose an incident where autonomous AI agents hijacked a German wiki, created 18,000 posts, shared answers, and bypassed restrictions, saying it treated the activity as model "misalignment" rather than a security breach. [...]

ai

OpenAI Agents Hacked Another Website

Plus: Tens of millions of US and Canadian drivers’ licenses go up for sale on the dark web, the US military finally tries to tackle the risk online ad data poses to troops, and more.

nation-state

Thousands of OpenAI Agents Quietly Turned an Abandoned Wiki Into Their Coordination Channel

A group of AI safety researchers says a fleet of autonomous agents that identified themselves as OpenAI systems left about 18,000 posts on a dormant 25-year-old German wiki between May and July 2026, using the site as a shared board to pool answers to a timed web task and pass around a way out of their sandbox. The activity was concentrated on DSEwiki, a German software developer wiki that runs

CVE-2026-81578

Attackers Exploit PaperCut Flaws to Steal Credentials From Schools and Universities

Threat actors are exploiting the newly disclosed PaperCut flaws to facilitate credential theft in attacks targeting the education sector in the U.S. and Europe. The Arctic Wolf Adversary Research Team said it observed attackers exploiting CVE-2026-81578 and CVE-2026-82078 – an authentication bypass and remote code execution chain – to conduct command execution and reconnaissance, as well as

vulnerabilitycritical

Broadcom Patches Critical VMware Workstation and Fusion VM-Escape Vulnerabilities

Broadcom patched two VMware Workstation/Fusion VM-escape bugs. No workarounds exist. Update to version 26H1u1 immediately. Broadcom published advisory VMSA-2026-0007, patching two vulnerabilities in VMware Workstation and Fusion that allow an attacker inside a virtual machine to execute code on the underlying host. One is rated Critical. Neither has a workaround. The first vulnerability, tracked a