Smugness won’t protect Mac Users from this new threat
In this week’s cybersecurity roundup, we break down a stark reminder that macOS users are no longer safe under the radar of modern cybercriminals. A sophisticated new threat called PamStealer is targeting Apple devices by masking itself as a legitimate clipboard manager, utilizing a compiled AppleScript and a Rust-based payload that carefully fingerprints a victim's machine before striking. Once active, the malware deploys a counterfeit macOS authorization dialog to trick users into entering their login credentials, then brilliantly abuses the native Pluggable Authentication Modules (PAM) API to validate the stolen password locally, allowing it to quietly bypass traditional security alerts and exfiltrate sensitive browser data, cookies, and keychain contents without raising red flags.
A new and unusually sophisticated strain of malware, dubbed "PamStealer," is actively targeting macOS users. Discovered by researchers at security firm Jamf Threat Labs, this credential-stealing software employs a multi-stage attack and a bag of clever tricks to bypass macOS security features and remain hidden, posing a significant threat to unsuspecting users.
https://www.shadowfetch.com/blog/tech-pamstealer-malware-targets-macos-users-with-devious-new-stealth-tactics
Nissan has joined the growing list of Oracle customers cleaning up after a cyberattack, warning employees that payroll records, bank details, Social Security numbers, and other personal data may have been stolen. In a filing submitted to the California Attorney General on Friday, Nissan Americas said Oracle had informed it of "a cyber event" involving the personnel records of "hundreds of companies." The automaker said it later learned Nissan had been "specifically targeted" in the attack.
https://www.theregister.com/security/2026/06/29/nissan-says-oracle-peoplesoft-break-in-may-have-spilled-payroll-records-ssns/5263534
Fresh claims emerging from underground cybercrime forums have once again placed one of the world’s largest artificial intelligence platforms under scrutiny. A threat actor has allegedly advertised what they describe as a database containing information belonging to users of Google Gemini. The post quickly attracted attention across the cybersecurity community after screenshots appeared online showing a sample containing email addresses and associated phone numbers.
https://undercodenews.com/alleged-google-gemini-user-database-appears-on-underground-forum-raising-fresh-cybersecurity-questions-dark-web-recent-claims-video
Cybersecurity investigations rarely begin with a complete picture. More often than not, they start with a single suspicious indicator that appears insignificant on its own. A lone IP address, a malware hash, or an unusual network connection can become the thread that unravels a far larger cybercriminal ecosystem. That is exactly what happened during a recent threat intelligence investigation. What initially appeared to be another ordinary RedLine Stealer command-and-control server quickly evolved into the discovery of a carefully planned Business Email Compromise (BEC) campaign targeting Kangrim Heavy Industries, one of South Korea’s most influential maritime engineering companies. The investigation demonstrates how modern threat intelligence goes far beyond malware analysis by exposing attacker infrastructure, phishing operations, and the broader strategies used by cybercriminal groups to infiltrate high-value organizations.
https://undercodenews.com/redline-clue-exposes-sophisticated-maritime-cyber-espionage-campaign-targeting-south-korean-industry-video/?utm_source=bluesky&utm_medium=jetpack_social
Google, working alongside the FBI, Lumen Technologies, and other industry partners, has taken action to dismantle the NetNut residential proxy network, also tracked as “Popa,” which is estimated to have compromised at least 2 million home devices worldwide. Google disabled Google accounts and services that NetNut used for malware command-and-control, a direct violation of its Terms of Service and Acceptable Use Policy.
https://cybersecuritynews.com/google-dismantles-netnut-residential-proxy/
Security firm runZero has revealed seven security vulnerabilities in FatFs, a lightweight filesystem library widely used by embedded devices to read and write FAT and exFAT storage formats found on USB drives and SD cards. The vulnerabilities are considered significant because FatFs is integrated into the firmware powering a broad range of products, including security cameras, drones, industrial control systems, hardware cryptocurrency wallets, and devices running real-time operating systems (RTOS).
https://www.cysecurity.news/2026/07/runzero-uncovers-seven-fatfs.html
A new hack can trick AI browsers into breaking their guardrails by constructing a false reality around them where the rules are made up and actions don't have consequences. Put another way, they're basically hypnotized into doing stuff that could have devastating consequences for the user. These were the findings of new research from the cybersecurity firm LayerX, and they further illustrate the dangers posed by weaving autonomous AI agents into the software we use to navigate the internet.
https://tech.yahoo.com/cybersecurity/articles/ai-browsers-basically-hypnotized-turning-110100835.html
China now has an open-weight model that does the kind of long-horizon, repository-scale coding work U.S. officials spent the spring treating as a national-security problem when it came from American labs. GLM-5.2, released by Z.ai last week under an MIT license, is downloadable by anyone, runs on private hardware, and leaves no provider-side record of how it's used. That last detail is the governance problem. The control regime Washington built around frontier cyber-AI assumes a vendor sits between the model and the user. Open weights remove the vendor.
https://www.forbes.com/sites/craigsmith/2026/06/28/buckle-up-the-bad-guys-now-have-a-model-as-powerful-as-mythos/
A newly disclosed Linux kernel flaw called Bad Epoll (CVE-2026-46242) lets an ordinary user with no special access take full control of a machine as root. It affects Linux desktops, servers, and Android, and a fix is out. Bad Epoll sits in the same small stretch of kernel code where Anthropic's most powerful AI model, Mythos, recently found a different bug. The AI caught one flaw and missed this one. A researcher, Jaeyoung Chung, found it and built a working attack.
https://thehackernews.com/2026/07/new-bad-epoll-linux-kernel-flaw-lets.html
Japanese police have arrested a 15-year-old high school student on suspicion of obstruction of business following alleged cyberattacks on Bandai Channel, a subscription-based anime and tokusatsu streaming service owned by Bandai Namco.
https://automaton-media.com/en/news/15-year-old-arrested-in-japan-over-alleged-cyberattacks-on-bandai-namco-anime-streaming-service-using-chatgpt-generated-malware/
Alex Karp, CEO of well-known AI data analytics company Palantir, delivered quite the bombshell of an interview to CNBC's Squawk Box. Although the interview's topic was about the firm's partnership with Nvidia, apropos the recently launched Sovereign AI OS Architecture, Karp bluntly claimed that frontier AI companies like OpenAI and Anthropic siphon customers' valuable information while delivering questionable value.
https://www.tomshardware.com/tech-industry/artificial-intelligence/palantir-ceo-alex-karp-claims-ai-companies-are-stealing-customers-data-while-charging-them-for-unproductive-tokens-says-livid-businesses-are-paying-for-tokens-that-create-no-value
Microsoft previously told Windows Latest that it added jailbreak or root detection (iOS/Android) for work or school accounts in Microsoft Authenticator. At that time, Microsoft did not clarify who is actually affected, and it pointed us to a support document that still says all work and school accounts are affected: “Microsoft introduced jailbreak/root detection for work or school accounts in Microsoft Authenticator,” Microsoft’s original documentation reads. “If Authenticator detects that your device is jailbroken or rooted, all existing and new work or school accounts will be blocked to protect your organization.”
https://www.windowslatest.com/2026/06/30/microsoft-warns-authenticator-now-blocks-rooted-android-and-jailbroken-ios-verify-if-youre-affected/
”Hide My Email users deserve to know that it may be possible for attackers to discover their hidden email addresses,” the person who reported the issue said.
https://www.404media.co/apple-hide-my-email-vulnerability-reveals-peoples-real-email-addresses/
A teenager has been arrested for alleged involvement with the Scattered Spider hacking group, the US Department of Justice (DoJ) has said. Peter Stokes, 19, was arrested in Finland in April and extradited to the US following an Interpol Red Notice. He has been charged with computer intrusion, conspiracy and fraud, which the DoJ said came after "years of work". Scattered Spider has been involved in hacks resulting in more than $100m (£75m) in ransom payments, according to the DoJ. The charges come after two young men pleaded guilty to offences connected to the £39m 2024 Transport for London cyber-attack, which the UK National Crime Agency (NCA) believed was conducted by the group.
https://www.bbc.com/news/articles/cwy0we4yw1lo
The tip line for the news outlet The Intercept was taken over by an unknown actor purporting to work for the publication—an extraordinary breach of operational security that put prospective whistleblowers at significant risk. The third party with control of the tip line on the encrypted messaging app Signal has been communicating with prospective sources; at least one fraudulent social media account has been soliciting tips since February.
https://www.dropsitenews.com/p/intercept-signal-tip-line-breach-hack
A Google Deepmind developer ported "Command & Conquer: Generals Zero Hour" to iPhone and iPad. Ammaar Reshi, Lead Product and Design for Google AI Studio, used Anthropic's Claude Code with Fable 5. The 2003 real-time strategy game runs natively on ARM64 with no emulator. Campaign, skirmish, and "Generals Challenge" all work with touch controls. The graphics pipeline translates DirectX 8 to Apple's Metal API through several intermediate steps.
https://the-decoder.com/claude-code-and-fable-5-ported-the-2003-pc-game-command-conquer-to-native-ios-in-a-few-hours/
WhatsApp this week started rolling out username reservations ahead of the broader launch planned later this year. The feature — which lets people find and message each other by handle instead of phone number — is already raising impersonation concerns, drawing scrutiny from security experts and regulators in India, the app’s largest market, with more than 500 million users.
https://techcrunch.com/2026/07/01/whatsapp-usernames-are-already-raising-impersonation-red-flags/
EU Politicians Investigated Pegasus Spyware. Then It Ended Up on One of Their Phones. Greek politician Stelios Kouloglou was investigating how intrusive spyware had been used to hack business leaders, law enforcement officials, and politicians. As part of the European Parliament’s PEGA Committee, set up to investigate the use of the notorious Pegasus spyware and other variants, Kouloglou travelled to interview spyware victims and probe high-profile cases. That fall, according to a new forensic analysis, Kouloglou’s iPhone was hacked with the very same Pegasus spyware at the center of the investigations.
https://www.wired.com/story/eu-politicians-investigated-pegasus-spyware-then-it-ended-up-on-one-of-their-phones/
A five-star hotel in Co Wicklow has cancelled bookings for a “secretive” conference which was to be hosted in August by a group cofounded by US tech billionaire Peter Thiel. The planned event at the Powerscourt Hotel Resort and Spa, scheduled to be attended by a senior Nato commander and Trump administration officials, will not now go ahead at the venue. Thiel was a cofounder of payments group PayPal and Palantir, a defence contractor known for mass surveillance and criticised heavily for its “strategic partnership” with the Israel Defense Forces (IDF) in its assault on Gaza. A leaked schedule for the “retreat” hosted by Dialog, an invitation-only group cofounded 20 years ago by Thiel and entrepreneur Auren Hoffman, featured discussions on topics including preparations for a third world war, battlefield technologies, nuclear energy and cult-building.
https://www.irishtimes.com/ireland/2026/07/03/wicklow-hotel-cancels-secretive-peter-thiel-conference/
The US is increasingly treating frontier artificial intelligence as a strategic national security asset, with Central Intelligence Agency Director John Ratcliffe likening the most capable AI models to nuclear weapons. “In conversations with many of the president’s other national security and economic security advisors, we’re talking about the impact of these frontier AI models,” Ratcliffe said at the Amazon Web Services Summit in Washington.
https://thedefensepost.com/2026/07/03/cia-ai-nuclear-weapons/
Microsoft caves after Teams AI backlash, will let you turn off Copilot, Facilitator and Recap mid-meeting.
https://www.windowslatest.com/2026/07/05/microsoft-caves-after-teams-ai-backlash-will-let-you-turn-off-copilot-facilitator-and-recap-mid-meeting/
How Gaslight Stealer Tricks AI Security Tools. Artificial intelligence has become an essential tool for cybersecurity teams. From detecting suspicious files to speeding up malware investigations, AI is helping defenders respond faster than ever. But what happens when attackers start targeting the AI itself? That’s exactly what researchers discovered with Gaslight Stealer, a newly identified macOS malware campaign linked to North Korean threat actors. Rather than relying solely on stealth, the malware attempts to mislead AI-powered security tools by embedding fake system messages designed to influence automated analysis.
https://medium.com/@casi.borg/gaslight-stealer-uses-fake-ai-messages-to-evade-detection-why-macos-and-crypto-users-should-care-0214e9d37cad
A post published by the threat monitoring account Dark Web Intelligence (@DailyDarkWeb) claims that Bumble has suffered a data breach exposing user information. The announcement quickly attracted attention among cybersecurity observers despite providing very limited technical details regarding the alleged compromise. At the time of writing, the post does not include evidence such as sample datasets, attacker statements, database screenshots, or indicators proving that Bumble’s internal systems were successfully breached. The claim simply states that a Bumble data breach has occurred, leaving many unanswered questions regarding the scale and authenticity of the incident.
https://undercodenews.com/bumble-data-breach-allegedly-exposes-user-information-dark-web-recent-claims-video/
Ransomware groups have long relied on disabling endpoint detection and response (EDR) tools before deploying their payloads, and in recent years have utilized bring-your-own-vulnerable-driver (BYOVD) attacks to do so. The use of BYOVD by ransomware groups began trending as a result of the discovery of a major vulnerability in GIGABYTE’s gdrv.sys. Although the vulnerability was responsibly disclosed by SecureAuth, the vendor refused to acknowledge the issue, resulting in a public proof-of-concept being made available. In February 2020, the exploit was picked up by RobinHood ransomware group, who weaponized it into an EDR killer. This marked the first known case of ransomware actors abusing BYOVD to disable security software.
https://expel.com/blog/not-very-gentlemanly-analyzing-a-zero-day-exploit-used-by-the-gentlemen-ransomware-to-disable-targets-edrs/