Výsledky hledání

výrobce: Apple× typ: rozbor× v celém archivu zrušit filtry

9 karet z 9 položek CZ · EN/orig

1

Don’t Call Us, We’ll Call Your APIs | TraderTraitor Backdoors Resurface on Victim With No Crypto Ties

Executive Summary Following disclosure of the TraderTraitor attack against LayerZero in April 2026, SentinelOne identified an additional victim with the same macOS backdoors. Our analysis explores the mechanics of these backdoors and the expanded targeting against a victim in the IT services sector with no relationship to cryptocurrency trading. We also identified more weaponized GitHub repositories from the social engineering schemes used to target job seekers in these campaigns. This report…

Apple Terraform GitHub US

tg: incident tg: varování tg: rozbor tp: malware tp: phishing tp: dodavatelský řetězec tp: špionáž

· SentinelLabs · Don’t Call Us, We’ll Call Your APIs | TraderTraitor Backdoors Resurface on Victim With No Crypto Ties

1

The Apple Security Update Review for September 2026

Welcome back to our monthly look at Apple security patches. This release shows Apple is not immune to the new normal of AI-assisted vulnerability discovery as they release patches for 273 total CVEs.For the September 2026 release, Apple released 273 unique CVEs across macOS 27 (Golden Gate), macOS Sequoia 15.8, macOS Tahoe 26.7, iOS / iPadOS 27, visionOS 27, watchOS 27, tvOS 27, iOS / iPadOS 26.7, Safari 27, and Xcode 27. This patch release actually happened a couple of days ago, but since…

Apple US

tg: zneužíváno tg: zranitelnost tg: rozbor

· ZDI Blog · The Apple Security Update Review for September 2026

1

MacOS 27 - First Boot, (Tue, Sep 15th)

I have not done this type of diary in a while: What traffic will you see from a system on boot, before a user logs in? I just took a quick look at macOS 27 "Golden Gate" to see what traffic you should expect. Here are some of the highlights: I captured about 300 packets. This was likely inflated for this particular system as it connected via Wi-Fi and wired network interfaces. Each network interface will do its own DHCP/IP discovery during boot. I only used router advertisements for IPv6, not…

Apple US

tg: rozbor

· SANS Internet Storm Ctr. · MacOS 27 - First Boot, (Tue, Sep 15th)

1

Scammers are getting smarter about where they target you 

Scammers are becoming more strategic about where they target people. Nine in ten toll scams—the fake unpaid-toll messages that threaten fines or license suspension—arrive by email or text, while roughly six in ten romance scams show up first on social media. That’s no coincidence. Rather than blasting the same message everywhere, criminals are tailoring different scams to the platforms where they’re most likely to succeed. This finding comes from Malwarebytes’ own threat research systems and…

Google Microsoft Apple Amazon US

tg: rozbor tg: návod tg: propagace tp: phishing tp: podvod

· Malwarebytes Labs · Scammers are getting smarter about where they target you 

1

Hunting MacSync Stealer infrastructure through behavioral pivots

In this article Activity overview Discovery of additional rotating infrastructure Attack chain overviewMitigation and protection guidanceReferencesLearn more MacSync Stealer is a macOS-focused information stealer that relies on changing infrastructure to deliver payloads, communicate with compromised devices, and exfiltrate data. Earlier reporting by RST Cloud identified the threat through a limited set of domains and documented rapid command-and-control (C2) replacement after public disclosure…

Apple US

tg: varování tg: rozbor tp: malware tp: phishing tp: identita

· Microsoft Security Blog · Hunting MacSync Stealer infrastructure through behavioral pivots

1

Dissecting the JWR phishing framework

Cisco Talos recently identified an undocumented phishing framework, internally branded "JWR" by its developer, built to convincingly impersonate checkout and login pages across major payment and shopping platforms. The client engine of the JWR phishing framework is a real-time, operator-driven system that, rather than merely logging form submissions like a static credential-stealing page, keeps an AES-CTR encrypted WebSocket open to the threat actor so they can steer each victim's session live.…

Shopify PayPal Apple Klarna US

tg: varování tg: rozbor tp: phishing tp: podvod tp: identita

· Cisco Talos · Dissecting the JWR phishing framework

1

Living off the coding agent: Two tales of tunnels and LaunchAgents

Coding agents such as Claude Code and Cursor are vendor-signed, used all day on developer laptops, and routinely open shells, call APIs, edit files, and install helpers. That makes GenAI-adjacent alerts challenging to investigate. The parent looks trusted, while the children can still look a lot like classic high-severity activity. This article walks through one of those windows. On a macOS endpoint, Elastic Security endpoint telemetry showed shells under Claude Code that scripted a login to an…

Apple US

tg: rozbor tp: AI tp: identita

· Elastic Security · Living off the coding agent: Two tales of tunnels and LaunchAgents

1

Living off the coding agent: Two tales of tunnels and LaunchAgents

Coding agents such as Claude Code and Cursor are vendor-signed, used all day on developer laptops, and routinely open shells, call APIs, edit files, and install helpers. That makes GenAI-adjacent alerts challenging to investigate. The parent looks trusted, while the children can still look a lot like classic high-severity activity. This article walks through one of those windows. On a macOS endpoint, Elastic Security endpoint telemetry showed shells under Claude Code that scripted a login to an…

Cursor Apple Cloudflare US

tg: rozbor tp: AI tp: identita

· Elastic Security · Living off the coding agent: Two tales of tunnels and LaunchAgents

1

From open lures to cloaked gates: How a macOS ClickFix campaign learned to hide

In this article Activity overviewHow ClickFix works Campaign overviewClickFix moved from open pages to fingerprinting gatesThe fingerprinting gateMitigation and protection guidanceIndicators of compromise (IOC)ReferencesLearn more Microsoft Threat Intelligence observed a macOS ClickFix campaign distributing infostealers, including MacSync and Atomic Stealer (AMOS), through a large cluster of look-alike domains. The campaign evolved from broadly serving ClickFix lures to using a server-side…

Apple US

tg: varování tg: rozbor tp: malware tp: phishing

· Microsoft Security Blog · From open lures to cloaked gates: How a macOS ClickFix campaign learned to hide