Cybersecurity researchers have flagged a new macOS information stealer called PamStealer that employs a series of clever tricks to infect systems and siphon sensitive data. The stealer, discovered by Jamf Threat Labs, is distributed as a co

A newly identified macOS malware, dubbed PamStealer, has been observed by cybersecurity researchers to be actively targeting Mac users by impersonating legitimate applications and exploiting system authentication mechanisms to steal login credentials. The threat, detailed by Jamf Threat Labs, utilizes a distribution method that involves tricking users into downloading malicious versions of popular applications.
PamStealer's initial infection vector relies on social engineering tactics. Threat actors are distributing malicious installers disguised as popular macOS applications. When a user downloads and executes one of these fake installers, it not only installs the intended application but also secretly deploys the PamStealer malware in the background. This approach leverages user trust in familiar software to gain a foothold on the system.
Once installed, PamStealer focuses on obtaining the user's login password, which is often protected by macOS's Keychain access control. The malware attempts to bypass these security measures by leveraging the operating system's own authentication processes. Specifically, PamStealer is designed to interact with the system's Pluggable Authentication Modules (PAM).
PAM is a framework that allows macOS to use different authentication methods. PamStealer exploits this by attempting to manipulate or query PAM to gain access to sensitive information, including user passwords. This method is particularly concerning as it targets a core security component of the operating system.
The ultimate goal of PamStealer is to exfiltrate the stolen login credentials. Once the malware successfully acquires the user's password, it transmits this sensitive data back to the attackers. This information can then be used for a variety of malicious purposes, such as unauthorized access to the compromised Mac, other online accounts, or for further targeted attacks.
The researchers highlighted that PamStealer's effectiveness stems from its combination of deceptive distribution and its exploitation of macOS's authentication system. By masquerading as legitimate software and then targeting PAM, the malware attempts to operate with a high degree of stealth and privilege.
While specific details on the full scope of PamStealer's capabilities and its prevalence are still emerging, the discovery underscores the ongoing threat landscape for macOS users. Information stealers remain a persistent category of malware, and attackers are continuously evolving their techniques to circumvent security defenses.
To mitigate the risks posed by threats like PamStealer, users are advised to exercise caution when downloading software. It is crucial to obtain applications only from trusted sources, such as the official App Store or the developers' official websites. Additionally, keeping macOS and all installed applications updated is a fundamental security practice, as updates often include patches for vulnerabilities that malware may attempt to exploit. Regularly reviewing security settings and being aware of potential phishing or social engineering attempts can also significantly enhance a user's defense posture.

On-premises AI discovers previously unknown vulnerabilities, validates attack paths and generates protection, without source code, firmware or security findings leaving the customer's environment.

OpenAI admits it did not disclose an incident where autonomous AI agents hijacked a German wiki, created 18,000 posts, shared answers, and bypassed restrictions, saying it treated the activity as model "misalignment" rather than a security breach. [...]

Plus: Tens of millions of US and Canadian drivers’ licenses go up for sale on the dark web, the US military finally tries to tackle the risk online ad data poses to troops, and more.

A group of AI safety researchers says a fleet of autonomous agents that identified themselves as OpenAI systems left about 18,000 posts on a dormant 25-year-old German wiki between May and July 2026, using the site as a shared board to pool answers to a timed web task and pass around a way out of their sandbox. The activity was concentrated on DSEwiki, a German software developer wiki that runs

Threat actors are exploiting the newly disclosed PaperCut flaws to facilitate credential theft in attacks targeting the education sector in the U.S. and Europe. The Arctic Wolf Adversary Research Team said it observed attackers exploiting CVE-2026-81578 and CVE-2026-82078 – an authentication bypass and remote code execution chain – to conduct command execution and reconnaissance, as well as

Broadcom patched two VMware Workstation/Fusion VM-escape bugs. No workarounds exist. Update to version 26H1u1 immediately. Broadcom published advisory VMSA-2026-0007, patching two vulnerabilities in VMware Workstation and Fusion that allow an attacker inside a virtual machine to execute code on the underlying host. One is rated Critical. Neither has a workaround. The first vulnerability, tracked a