2025-12-09 06:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Attackers are exploiting user trust in AI and aggressive SEO to deliver an evolved Atomic macOS Stealer. Learn why this social engineering tradecraft bypasses traditional network controls and the future of macOS infostealer defense.
P0
2025-12-03 16:59 UTC
Vendor Research
Google Online Security Blog · Edward Fernandez · indexed 2026-08-15 14:33 UTC
Posted by Aden Haussmann, Associate Product Manager and Sumeet Sharma, Play Partnerships Trust & Safety Lead Android uses the best of Google AI and our advanced security expertise to tackle mobile scams from every angle. Over the last few years, we’ve launched industry-leading features to detect scams and protect users across phone calls, text messages and messaging app chat notifications. These efforts are making a real difference in the lives of Android users. According to a recent YouGov sur…
P0
2025-11-20 17:00 UTC
Vendor Research
Google Online Security Blog · Edward Fernandez · indexed 2026-08-15 14:33 UTC
Posted by Dave Kleidermacher, VP, Platforms Security & Privacy, Google Technology should bring people closer together, not create walls. Being able to communicate and connect with friends and family should be easy regardless of the phone they use. That’s why Android has been building experiences that help you stay connected across platforms. As part of our efforts to continue to make cross-platform communication more seamless for users, we've made Quick Share interoperable with AirDrop, allowin…
P0
2025-10-30 16:59 UTC
Vendor Research
Google Online Security Blog · Edward Fernandez · indexed 2026-08-15 14:33 UTC
Posted by Lyubov Farafonova, Product Manager, Phone by Google; Alberto Pastor Nieto, Sr. Product Manager Google Messages and RCS Spam and Abuse; Vijay Pareek, Manager, Android Messaging Trust and Safety As Cybersecurity Awareness Month wraps up, we’re focusing on one of today's most pervasive digital threats: mobile scams. In the last 12 months, fraudsters have used advanced AI tools to create more convincing schemes, resulting in over $400 billion in stolen funds globally.¹ For years, Android …
P0
2025-09-10 15:59 UTC
Vendor Research
Google Online Security Blog · Edward Fernandez · indexed 2026-08-15 14:33 UTC
Posted by Eric Lynch, Senior Product Manager, Android Security, and Sherif Hanna, Group Product Manager, Google C2PA Core At Made by Google 2025, we announced that the new Google Pixel 10 phones will support C2PA Content Credentials in Pixel Camera and Google Photos. This announcement represents a series of steps towards greater digital media transparency: The Pixel 10 lineup is the first to have Content Credentials built in across every photo created by Pixel Camera. The Pixel Camera app achie…
P0
2025-09-09 05:54 UTC
Other
Red Hunt Labs · Hariharan M · indexed 2026-09-07 17:30 UTC
Introduction A new wave of AI-powered investment scams is targeting Indian users on Facebook and Instagram, luring them with fake celebrity endorsements and deepfake interviews. Ads featuring figures like Nirmala Sitharaman, Sadhguru, and Neha Kakkar promote fraudulent schemes, directing users to counterfeit news websites mimicking The Times of India, IndiaTime, and NDTV. These sites claim celebrities have built fortunes using exclusive investment strategies, persuading victims to deposit ₹21,0…
P0
2025-06-18 05:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Learn how DPRK's BlueNoroff group executed a Web3 macOS intrusion. Explore the attack chain, malware, and techniques in our detailed technical report.
P0
2025-06-11 05:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Enhance Mac security with Huntress Managed EDR's new coverage for Apple XProtect and Microsoft Defender for Endpoint. Learn how we can protect your macOS.
P0
2025-05-10 00:00 UTC
Other
Cloud Vuln DB · indexed 2026-09-07 17:30 UTC
Security advisories were issued for FreeRTOS and coreSNTP releases containing unintended scripts that could potentially transmit AWS credentials if executed on Linux/macOS. Affected releases have been removed and users are advised to rotate credentials and delete downloaded copies.
P0
2025-04-22 05:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
In this month’s Tradecraft Tuesday, we talked about how threat actors are finetuning their macOS malware in order to maintain persistent access and avoid detection by Apple’s security features.
P0
2025-01-23 00:00 UTC
Other
Cloud Vuln DB · indexed 2026-09-07 17:30 UTC
A vulnerability in AWS IAM Sign-in login flow could allow attackers to enumerate IAM usernames by measuring server response times. This issue affected AWS Sign-in IAM User login flow prior to January 16, 2025. AWS has since introduced a delay in response times across all authentication failure scenarios to mitigate the vulnerability.
P0
2025-01-14 00:00 UTC
Government
CERT-FR Alerts · indexed 2026-09-07 17:35 UTC
\[Mise à jour du 28 janvier 2025\] Une preuve de concept permettant l'exploitation de cette vulnérabilité est disponible publiquement. Le 14 janvier 2025, Fortinet a publié un avis de sécurité concernant la vulnérabilité critique CVE-2024-55591 affectant FortiOS et FortiProxy. Elle permet à un...
P5
2024-10-23 18:18 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Learn about the importance of Full Disk Access for Mac, its role in macOS security, and how it affects app performance and functionality.
P0
2024-10-02 05:55 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
In this article, Group-IB specialists uncovered a large-scale fraud campaign involving fake trading apps targeting Apple iOS and Android users across multiple regions through the UniApp framework, and distributed through official app stores and phishing sites.
P0
2024-06-13 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Let Huntress debunk the biggest Mac security myths. macOS is now a popular target for hackers, so learn the truth about its vulnerabilities and discover practical steps to enhance protection against cyber threats.
P0
2024-06-05 09:01 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Learn how to protect your devices against evolving iOS threats
P0
2024-06-04 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
As macOS adoption rises, so too do cyber threats against it. That’s why Huntress developed our Managed EDR for macOS, a security solution tailored to the unique challenges of macOS environments.
P0
2024-04-25 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
There's a new variant of LightSpy malware targeting macOS. Here, Huntress' macOS researchers dive into the macOS variant of the LightSpy malware, after gaps in recent reports stating that the LightSpy malware strictly targets iOS.
P0
2024-03-15 08:04 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Pegasus infects mobile devices through zero-click exploits and silently harvests messages, calls, location, and microphone access. Learn how the spyware operates and the steps security teams can take to detect it on iOS and Android.
P0
2024-03-11 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
The primary goal of Apple's Transparency, Consent, and Control (TCC) is to empower users with transparency regarding how their data is accessed and used by applications. In this Part 2, dig even deeper into the mechanism that runs TCC and what's happening in the background.
P0
2024-02-15 08:02 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Group-IB uncovers the first iOS Trojan harvesting facial recognition data used for unauthorized access to bank accounts. The GoldDigger family grows
P0
2024-02-09 00:00 UTC
Government
CERT-FR Alerts · indexed 2026-09-07 17:35 UTC
\[Mise à jour du 19 mars 2024\] Le CERT-FR a connaissance de codes d'exploitation publics et de nouvelles tentatives d'exploitation. Le 8 février 2024, Fortinet a publié l'avis de sécurité concernant la vulnérabilité critique CVE-2024-21762 affectant le VPN SSL de FortiOS. Cette vulnérabilité...
P5
2024-01-16 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Dive into Apple's TCC framework, decoding its role in user privacy. Explore permissions, challenges, and the encryption safeguarding sensitive data.
P0
2023-11-30 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
A look inside the evolving landscape of macOS malware. Dive into the current state of macOS threats and learn from a glossary of essential macOS terms.
P0
2023-08-22 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Discover the truth about macOS security. The Huntress Mac Guy answers common macOS security questions like why you should protect your Mac computers.
P0
2023-06-28 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Do you need third-party security for macOS? Discover if Apple’s malware prevention products, XProtect and XProtect Remediator, are good enough solutions to keep users safe.
P0
2023-05-23 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Is RMM the same as MDM? Learn the key differences between RMM and MDM for macOS management and how Huntress works with both to keep your endpoints secure.
P0
2023-04-25 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
It would take hours to cover everything endpoint security can do, but this blog covers it in a few aspects: a high-level overview, a deeper dive and how detection engineers can leverage it.
P0
2023-03-21 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
In this blog, we dive into macOS notifications—and the intentional design behind them.
P0
2023-02-21 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
We discuss some of our favorite and most interesting built-in macOS security tools.
P0