macos news
5 stories
Google Gemini could soon get full access to your Mac’s files, apps and the web
Google appears to be developing a feature for its Gemini AI that would grant it extensive access to macOS systems, including the ability to read, modify, and delete files, interact with applications, and browse the web. This potential functionality was identified by TestingCatalog on X, which observed references to a hidden "Additional sandbox options" setting within the Gemini Desktop…
Hunting MacSync Stealer infrastructure through behavioral pivots
Microsoft Defender Experts have reportedly identified and are actively tracking the infrastructure supporting the MacSync Stealer, an information-stealing malware targeting macOS systems. The malware is characterized by its use of rapidly rotating command-and-control (C2) domains, a tactic designed to evade detection and make tracking difficult. However, researchers have found that despite…

macOS Screen Sharing Flaw Exploited to Deploy Monero Miners
Hackers are actively exploiting a recently patched vulnerability in macOS Screen Sharing to gain root access on compromised systems and deploy Monero cryptocurrency miners. The Dutch National Cyber Security Centre (NCSC-NL) has confirmed reports of this exploitation, noting that affected systems typically have port 5900, used by Screen Sharing, exposed to the internet.

ClickFix Attacks Deliver macOS Stealer That Can Drain Crypto Wallets
Reports indicate the emergence of a new macOS-targeting malware, dubbed "ClickFix Attacks," which is being distributed through a method described as "ClickFix-style attacks." This Go-based malware is designed to exfiltrate sensitive user data, including browser passwords, Apple Keychain information, and cached credentials. A particularly concerning feature of this new threat is its ability to…

macOS Backdoor Uses Fake Messages to Evade AI Analysis
A newly identified macOS backdoor, tracked as macOS.Gaslight, employs a sophisticated technique to evade security analysis by embedding fabricated system messages designed to mislead AI-powered security tools. Researchers have assessed with high confidence that this implant is linked to North Korean state-aligned threat activity.