macOS

New “Daemon Ex Plist” Vulnerability Gives Attackers Root Access on macOS

A critical vulnerability in macOS allows attackers to escalate privileges to root access through misconfigured daemon services.  The vulnerability, dubbed…

4 months ago

Atomic macOS Info-Stealer Upgraded With New Backdoor to Maintain Persistence

The notorious Atomic macOS Stealer (AMOS) malware has received a dangerous upgrade that significantly escalates the threat to Mac users…

5 months ago

macOS SMBClient Vulnerability Allows Remote Code Execution and Kernel Crash

Multiple vulnerabilities in macOS SMBClient that could allow attackers to execute arbitrary code remotely and crash systems.  The vulnerabilities affecting…

5 months ago

PoC Exploit Released for macOS CVE-2025-31258 Vulnerability Bypassing Sandbox Security

A proof-of-concept (PoC) exploit has been released for a recently patched vulnerability in Apple's macOS operating system, tracked as CVE-2025-31258. …

6 months ago

Researchers Details macOS Remote Code Execution Vulnerability – CVE-2024-44236

A critical remote code execution vulnerability identified in Apple's macOS operating system, tracked as CVE-2024-44236. The vulnerability, which carries a…

7 months ago

macOS Sandbox Escape Vulnerability Allows Keychain Deletion and Replacement

A security vulnerability in macOS has been discovered. It allows malicious actors to escape the App Sandbox protection by manipulating security-scoped bookmarks. …

7 months ago

Docker Registry Vulnerability Lets MacOS Users Pull Images from Any Registry

A newly disclosed vulnerability in Docker Desktop’s Registry Access Management (RAM) feature has left macOS users vulnerable to unauthorized image…

7 months ago

Speed­i­fy VPN ma­cOS Vulnerability Let Attackers Escalate Privilege

A significant security vulnerability, tracked as CVE-2025-25364, was discovered in Speedify VPN’s macOS application, exposing users to local privilege escalation…

7 months ago

ClickFake Interview – Lazarus Hackers Exploit Windows and macOS Users Fake Job Campaign

The Lazarus Group, a North Korean state-sponsored hacking collective, has launched a new campaign dubbed ClickFake Interview, targeting job seekers…

8 months ago

Hackers Leveraging x86-64 Binaries on Apple Silicon to Deploy macOS Malware

Advanced threat actors increasingly leverage x86-64 binaries and Apple’s Rosetta 2 translation technology to bypass execution policies and deploy malware…

9 months ago