A Mac stealer is going after your Claude sessions AMOS and other macOS stealers are going after your Claude sessions. The weak link is neither Apple nor Claude, it's the command you paste into the Terminal.
A fake Zoom update empties your iCloud Keychain A trusted Telegram contact invites you to a video call, a fake Zoom update pops up mid-call, and your iCloud Keychain gets emptied.
Claude Cowork in local mode, the agent walks out of the sandbox On macOS in local mode, Claude Cowork mounts your entire disk inside the agent's VM. One connected folder, one message, and it walks out without asking.
Apple-notarized malware slips past Gatekeeper CrashStealer, signed and notarized by Apple, clears Gatekeeper without a single alert. Notarization validates the signature, not the intent.
OpenAI Certificate Compromised, Update ChatGPT Mac Before June 12th ChatGPT, Codex, and Atlas on Mac: Mandatory update before June 12, 2026. OpenAI cert revoked after npm supply-chain attack.
Domestic stalkerware, the jealous partner's malware Stalkerware Spyzie, Cocospy, Spyic, over 3 million victims combined. Your iPhone drained via your Apple ID. How to check and take back control.
The U.S. cyber regulator let its AWS keys slip six months ago. A US federal cyber agency's subcontractor left their AWS GovCloud admin keys on a public GitHub repo for six months. Why not delegate your security, huh?
Five years of defending memory M5 down in five days Three California researchers bypassed Memory Integrity Enforcement M5 in five days using Mythos. First public kernel exploit on Apple M5 silicon. Patched in macOS Tahoe 26.5.
Google Ads and real cat Claude share your credentials Google sponsored ads redirect to real, shared claude.ai links that are baited. Fake Apple Support makes you paste a base64 into Terminal. MacSync payload empties your Keychain.
Apple patches iOS and macOS CVEs: fix, then tune your Safari profiles iOS 26.5 fixes 98 CVEs, including 21 in WebKit; macOS Tahoe 26.5 fixes 98 CVEs, including 22. Instead of enabling Lockdown Mode everywhere, segment with a dedicated Safari profile.
"No Access", and the app still reads your files macOS secretly logs access to your files whenever you use the Open/Save dialog. The Privacy & Security interface doesn't show this. Since 2019.
108 Chrome extensions trapped, your Google and Telegram too 108 malicious Chrome extensions identified in the Chrome Web Store by Socket researchers. Google OAuth theft, backdoors, Telegram exfiltration. Google notified, extensions still online at publication. If you're using Chrome on Mac, you're affected.
AI Agents on Mac: ANSSI flags Claude Cowork and OpenClaw ANSSI issues official warning about autonomous AI agents on workstations. Cowork Claude and OpenClaw named. Here's what you need to do.
APT28 steals your Microsoft tokens without touching your Mac Russian military intelligence is exploiting unpatched routers to silently intercept your Office OAuth tokens. What you need to do.
ClickFix macOS, Script Editor bypasses the Terminal warning Apple added an anti-ClickFix warning in the Terminal with macOS 26.4. Attackers promptly switched to Script Editor to distribute Atomic Stealer without friction.
SparkCat is back on the App Store, scanning your gallery. SparkCat accesses your Photos gallery, scans everything with OCR, and extracts crypto seed phrases. Never store a mnemonic phrase as a screenshot.
Coruna: a US state toolkit, fallen into Russian cybercriminals' hands Coruna exploits 23 iOS 13 to 17.2.1 flaws, installs silently. Already in Russian criminals' hands. Activate Lockdown Mode now.
DarkSword: iOS update 18.7.7 mandatory The source code of DarkSword is on GitHub. Apple releases iOS 18.7.7 to fix WebKit, Kernel, and Keychain. Mandatory update.