⤷ Title: CVE-2025-31191: Microsoft Exposes macOS Vulnerability Allowing App Sandbox Escape
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 05 May 2025 00:13:19 +0000
════════════════════════
⌗ Tags: #Vulnerability #Keychain Exploit #macOS vulnerability #Microsoft Threat Intelligence #Sandbox Escape #Security_Scoped Bookmarks
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 05 May 2025 00:13:19 +0000
════════════════════════
⌗ Tags: #Vulnerability #Keychain Exploit #macOS vulnerability #Microsoft Threat Intelligence #Sandbox Escape #Security_Scoped Bookmarks
Daily CyberSecurity
CVE-2025-31191: Microsoft Exposes macOS Vulnerability Allowing App Sandbox Escape
Microsoft uncovers CVE-2025-31191, a macOS sandbox escape exploiting security-scoped bookmarks. Apple patched it in March 2025.
⤷ Title: Odyssey Stealer: macOS Under Attack by ClickFix-Driven Infostealer
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Sat, 28 Jun 2025 00:20:30 +0000
════════════════════════
⌗ Tags: #Malware #AppleScript #Browser Data #ClickFix #cryptocurrency #cybersecurity #Cyfirma #Infostealer #Keychain #macOS #malware #Odyssey Stealer #passwords
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Sat, 28 Jun 2025 00:20:30 +0000
════════════════════════
⌗ Tags: #Malware #AppleScript #Browser Data #ClickFix #cryptocurrency #cybersecurity #Cyfirma #Infostealer #Keychain #macOS #malware #Odyssey Stealer #passwords
Daily CyberSecurity
Odyssey Stealer: macOS Under Attack by ClickFix-Driven Infostealer
CYFIRMA uncovers "Odyssey Stealer," a new macOS malware using fake App Store prompts & typosquatting to steal crypto wallets, passwords, and browser data from Western users.
⤷ Title: PoC Available: macOS Sequoia Flaw Allows Keychain Dump and TCC Bypass (CVSS 9.8)
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 05 Sep 2025 03:20:11 +0000
════════════════════════
⌗ Tags: #Vulnerability #gcore vulnerability #Keychain #macOS Sequoia #privilege escalation #TCC Bypass
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 05 Sep 2025 03:20:11 +0000
════════════════════════
⌗ Tags: #Vulnerability #gcore vulnerability #Keychain #macOS Sequoia #privilege escalation #TCC Bypass
Daily CyberSecurity
PoC Available: macOS Sequoia Flaw Allows Keychain Dump and TCC Bypass (CVSS 9.8)
A critical macOS flaw (CVE-2025-24204) in gcore allows a user to read any process memory and bypass TCC. A PoC is public, and patching is urgent.
⤷ Title: “Can You Hear Me?” BlueNoroff Hackers Use Fake Audio Glitch to Breach macOS
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 05 Feb 2026 00:20:32 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #BlueNoroff #Crypto Heist #Daylight Security #GhostCall #Keychain Theft #Lazarus Group #macOS security #malware #Microsoft Teams #social engineering
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 05 Feb 2026 00:20:32 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #BlueNoroff #Crypto Heist #Daylight Security #GhostCall #Keychain Theft #Lazarus Group #macOS security #malware #Microsoft Teams #social engineering
Daily CyberSecurity
"Can You Hear Me?" BlueNoroff Hackers Use Fake Audio Glitch to Breach macOS
BlueNoroff hackers use fake "audio issues" on Teams calls to trick macOS users. The "fix" runs terminal commands that steal Keychains. Watch out.
⤷ Title: Deceptive “DeepSeek-Claw” Skill Hijacks OpenClaw Agents to Steal Credentials
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 07 May 2026 07:01:56 +0000
════════════════════════
⌗ Tags: #Malware #AI Agents #AI security #cybersecurity #DeepSeek_Claw #GhostLoader #infosec #Keychain Theft #malware #OpenClaw #Remcos RAT #social engineering #Zscaler ThreatLabz
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 07 May 2026 07:01:56 +0000
════════════════════════
⌗ Tags: #Malware #AI Agents #AI security #cybersecurity #DeepSeek_Claw #GhostLoader #infosec #Keychain Theft #malware #OpenClaw #Remcos RAT #social engineering #Zscaler ThreatLabz
Daily CyberSecurity
Deceptive "DeepSeek-Claw" Skill Hijacks OpenClaw Agents to Steal Credentials
Zscaler ThreatLabz exposes DeepSeek-Claw, a malicious AI skill targeting the OpenClaw framework to deploy GhostLoader and Remcos RAT. Secure your agents now!
⤷ Title: The Terminal Trap: How the “ClickFix” Scam Tricks Mac Users into Self-Infecting with Data-Stealing Malware
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 11 May 2026 03:25:10 +0000
════════════════════════
⌗ Tags: #Malware #AMOS #Apple XProtect #ClickFix #Cryptocurrency Theft #Cybersecurity 2026 #Data Stealer #Keychain Security #macos #MacSync #malware #Shub Stealer #Terminal
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 11 May 2026 03:25:10 +0000
════════════════════════
⌗ Tags: #Malware #AMOS #Apple XProtect #ClickFix #Cryptocurrency Theft #Cybersecurity 2026 #Data Stealer #Keychain Security #macos #MacSync #malware #Shub Stealer #Terminal
Penetration Testing Tools
The Terminal Trap: How the "ClickFix" Scam Tricks Mac Users into Self-Infecting with Data-Stealing Malware
macOS users are once again being enticed by “simplistic remedies” for system optimization or disk purification, yet following
⤷ Title: The Script Editor Trap: New macOS “Reaper” Malware Bypasses Terminal Defenses to Steal Keychains
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 20 May 2026 07:22:37 +0000
════════════════════════
⌗ Tags: #Malware #applescript URI Scheme #Gatekeeper xattr Evasion #Keychain Exfiltration #LaunchAgent Persistence #macOS Reaper Malware #macOS Tahoe Security Bypass #Remote Access Trojan #Script Editor Exploit #SentinelOne Threat Intel #SHub Infostealer
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 20 May 2026 07:22:37 +0000
════════════════════════
⌗ Tags: #Malware #applescript URI Scheme #Gatekeeper xattr Evasion #Keychain Exfiltration #LaunchAgent Persistence #macOS Reaper Malware #macOS Tahoe Security Bypass #Remote Access Trojan #Script Editor Exploit #SentinelOne Threat Intel #SHub Infostealer
Information Security News
The Script Editor Trap: New macOS "Reaper" Malware Bypasses Terminal Defenses to Steal Keychains - Information Security News
A novel exploitation technique has surfaced on macOS, designed to deceive users via a counterfeit “security update.” The malicious payload, designated as Reaper—an advanced iteration of the SHub information stealer—no longer relies on social...
⤷ Title: Amos Stealer Targets macOS Keychain Files and Browser Passwords
════════════════════════
𐀪 Author: Deeba Ahmed
════════════════════════
ⴵ Time: Tue, 16 Jun 2026 16:27:00 +0000
════════════════════════
⌗ Tags: #Security #Malware #AMOS Stealer #CyberProof #Cybersecurity #Infostealer #Keychain #macOS #Scam #Social Engineering
════════════════════════
𐀪 Author: Deeba Ahmed
════════════════════════
ⴵ Time: Tue, 16 Jun 2026 16:27:00 +0000
════════════════════════
⌗ Tags: #Security #Malware #AMOS Stealer #CyberProof #Cybersecurity #Infostealer #Keychain #macOS #Scam #Social Engineering
Hackread
Amos Stealer Targets macOS Keychain Files and Browser Passwords
Amos Stealer targets macOS users through fake downloads, stealing Keychain files, browser passwords, cookies, and developer configs for data theft.
⤷ Title: Stop leaving API keys in .env files
════════════════════════
𐀪 Author: nickelnox
════════════════════════
ⴵ Time: Tue, 11 Aug 2026 02:23:09 GMT
════════════════════════
⌗ Tags: #ai #secretmanagement #api_security #keychain
════════════════════════
𐀪 Author: nickelnox
════════════════════════
ⴵ Time: Tue, 11 Aug 2026 02:23:09 GMT
════════════════════════
⌗ Tags: #ai #secretmanagement #api_security #keychain
Medium
Stop leaving API keys in .env files
Plaintext .env files are a narrow but real exposure — committed to git, synced to cloud storage, indexed by backup tools.