macOS Security News

Security news specific to Apple macOS — vulnerabilities, malware and patches affecting Mac systems.

macOS has a smaller attack surface than Windows in raw volume but is an increasingly common target as adoption grows in enterprise environments. This feed tracks macOS-specific vulnerabilities, malware families targeting Macs, and Apple's security update releases as they are reported. It is useful for tracking a platform that gets proportionally less mainstream security coverage than it now deserves.

Recent macOS items

Hackers exploit macOS Screen Sharing flaw to deploy Monero minerhttps://ift.tt/xs3T0b2
@ctinow · Aug 14, 2026
AmnesiaStealer Gives Attackers Live Control of Victims’ macOS Browsershttps://securityaffairs.com/197190/malware/amnesiastealer-gives-attackers-live-control-of-victims-macos-browsers.html
@PentestingNews · Aug 14, 2026
AmnesiaStealer Gives Attackers Live Control of Victims’ macOS Browsershttps://ift.tt/5PkiFcU
@ctinow · Aug 14, 2026
New AmnesiaStealer Malware Targets macOS Users via ClickFix Attackshttps://gbhackers.com/new-amnesiastealer-malware-targets-macos-users/
@PentestingNews · Aug 14, 2026
AmnesiaStealer macOS Malware Steals Data, Controls Browser Sessionshttps://ift.tt/ZycenoI
@ctinow · Aug 14, 2026
CVE-2026-19764A vulnerability was identified in Raisecom Communication Command and Dispatch Management Platform up to 7.6.5. This affects an unknown part of the file /app/users/getpwd.php. Such manipu…
@cveNotify · Aug 14, 2026
CVE-2026-65400An authentication issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.9, macOS Sonoma 14.8.9, macOS Tahoe 26.6.1. An attacker on the network may…
@cveNotify · Aug 14, 2026
CVE-2026-73663FreePBX is an open source IP PBX. From 16.0.0 until 16.0.11 and 17.0.4, the FreePBX missedcall module places the inbound Caller ID name from crafted SIP From headers into the missedcalll…
@cveNotify · Aug 13, 2026
AmnesiaStealer gives attackers live control of authenticated browser sessions.macOS ClickFix lure → paste command in Terminal → steals passwords & browser data → opens a hidden Chromium browser attack…
@thehackernews · Aug 13, 2026
CVE-2026-11970This vulnerability allows a normal (non-admin) user to disable the Forcepoint One Endpoint SafariExtension and bypass DLP protection in F1E Mac OS before v26.04.5758.🎖@cveNotify
@cveNotify · Aug 13, 2026
CVE-2026-0299Local privilege escalation vulnerabilities in the Palo Alto Networks GlobalProtect™ app enable a local user to escalate their privileges to NT AUTHORITY\SYSTEM on Windows, and root on mac…
@cveNotify · Aug 13, 2026
CVE-2026-0298An improper input validation vulnerability exists in the Windows Pre-Logon Access Provider (PLAP) component of the Palo Alto Networks GlobalProtect™ app on Windows devices which enables a…
@cveNotify · Aug 13, 2026
CVE-2026-0297A buffer overflow vulnerability exists in the Palo Alto Networks GlobalProtect™ app that enables a man-in-the-middle (MitM) attacker or a rogue gateway to disrupt system processes and pot…
@cveNotify · Aug 13, 2026
CVE-2026-0295A race condition in the Palo Alto Networks GlobalProtect™ client on macOS enables a locally authenticated low-privileged attacker to escalate their privileges to root.The GlobalProtect ap…
@cveNotify · Aug 13, 2026
CVE-2026-0299Local privilege escalation vulnerabilities in the Palo Alto Networks GlobalProtect™ app enable a local user to escalate their privileges to NT AUTHORITY\SYSTEM on Windows, and root on mac…
@cveNotify · Aug 13, 2026
CVE-2026-0298An improper input validation vulnerability exists in the Windows Pre-Logon Access Provider (PLAP) component of the Palo Alto Networks GlobalProtect™ app on Windows devices which enables a…
@cveNotify · Aug 13, 2026
CVE-2026-0297A buffer overflow vulnerability exists in the Palo Alto Networks GlobalProtect™ app that enables a man-in-the-middle (MitM) attacker or a rogue gateway to disrupt system processes and pot…
@cveNotify · Aug 13, 2026
CVE-2026-0295A race condition in the Palo Alto Networks GlobalProtect™ client on macOS enables a locally authenticated low-privileged attacker to escalate their privileges to root.The GlobalProtect ap…
@cveNotify · Aug 13, 2026
CVE-2026-0294A privilege escalation (PE) vulnerability in the Palo Alto Networks Prisma® Access Agent app on Windows and macOS devices enables a local user to execute code with elevated privileges. Th…
@cveNotify · Aug 13, 2026
CVE-2026-0293A vulnerability in Palo Alto Networks Prisma® Access Agent on Windows enables a local attacker with administrator privileges to bypass the anti-tamper protection, enabling unauthorized ac…
@cveNotify · Aug 13, 2026
CVE-2026-0292An authentication bypass vulnerability in the network driver of Palo Alto Networks Prisma® Access Agent on Windows enables a local administrator to bypass security inspection, subsequentl…
@cveNotify · Aug 13, 2026
CVE-2026-0291An improper link resolution before file access vulnerability exists in the Palo Alto Networks Prisma® Access Agent on Linux platforms that enables a local low privileged user to delete sy…
@cveNotify · Aug 13, 2026
CVE-2026-73218Cursor is a code editor built for programming with AI. Prior to 3.0.0, Cursor IDE for macOS allows an agent running in Auto-Run Sandbox mode, when Docker Desktop and the Dev Containers C…
@cveNotify · Aug 11, 2026
CVE-2026-73217Cursor is a code editor built for programming with AI. Prior to 3.1.2, Cursor IDE for macOS allows an agent running in Auto-Run Sandbox mode to replace a virtual environment's Python exe…
@cveNotify · Aug 11, 2026
CVE-2026-48790Turso CLI is the command line interface (CLI) to the open-source database Turso. Versions prior to 1.0.26 persist the user's Turso platform JWT to `settings.json` using Viper's default `…
@cveNotify · Aug 11, 2026
CVE-2026-66411DEEBOT PRO M1 and DEEBOT PRO K1VAC incorrectly implement authentication algorithm in Websocket communications.An unauthenticated attacker may connect and operate the affected robot.🎖@cve…
@cveNotify · Aug 10, 2026
CVE-2026-66409DEEBOT PRO M1 and DEEBOT PRO K1VAC are configured with weak passwords for their Wi-Fi hotspot networks.The password may be analyzed and obtained to connect to the access point of an affe…
@cveNotify · Aug 10, 2026
CVE-2026-66408The root accounts of DEEBOT PRO M1 and DEEBOT PRO K1VAC are configured with weak passwords.Physical access to an affected product may allow to obtain the password of the root account.🎖@c…
@cveNotify · Aug 10, 2026
CVE-2026-66407DEEBOT PRO M1 and DEEBOT PRO K1VAC improperly implement authentication in WebSocket communication.The WebSocket private key may be retrieved through analyzing the traffic data via a man-…
@cveNotify · Aug 10, 2026
CVE-2026-66406DEEBOT PRO M1 and DEEBOT PRO K1VAC use wget command with server certificate validation disabled.A man-in-the-middle attack may allow to obtain and/or alter communications of the affected…
@cveNotify · Aug 10, 2026

Other topics

CVE
Recent CVE identifiers and vulnerability disclosures aggregated from security feeds — new CVE IDs, published advisories, and the vendors and products they affect.
Ransomware
Ransomware attacks, extortion group activity, victim disclosures and decryptor releases tracked as they are reported.
Phishing
Phishing campaigns, credential-harvesting kits, and social-engineering techniques used to compromise users and organizations.
Zero-Day
Zero-day vulnerabilities being actively exploited before a patch exists, and the fixes that follow.
Data Breach
Confirmed and reported data breaches — what was exposed, which organizations were affected, and how the incident came to light.
Exploit
Public exploit code, proof-of-concept releases, and technical exploitation write-ups for known vulnerabilities.