Lazarus Group Malware Targets Crypto, Business Execs via macOS | News World

Browse the world's leading international and domestic Airlines. Compare rates and availabilty for any destination and route.

Security researchers have linked a new macOS malware campaign to the Lazarus Group, the North Korea-linked hacking operation behind some of the crypto industry’s biggest thefts.

Flagged on Tuesday, the new “Mach-O Man” malware kit is distributed via “ClickFix” social engineering schemes across traditional businesses and crypto companies, according to Mauro Eldritch, offensive security expert and founder of threat intelligence company BCA Ltd.

Victims are lured into a fake Zoom or Google Meet call where they are prompted to execute commands that download the malware in the background, allowing attackers to bypass traditional controls without detection to gain access to credentials and corporate systems, the security researcher said in a Tuesday report.

Researchers said the…

more
Source cointelegraph.com

FTC: We use income earning affiliate links. More on Sposored links.
Terms of use and third-party services. More here.

lyrics2.me  | Billboard |  Rolling Stone |  K-Pop

Related Posts

npm Adds 2FA-Gated Publishing and Package Install Controls Against Supply Chain Attacks | Cybersecurity

Ravie LakshmananMay 23, 2026Software Supply Chain / DevSecOps GitHub has rolled out new controls for npm to improve the security of the software supply chain, giving maintainers the ability to…

Read more

Laravel-Lang PHP Packages Compromised to Deliver Cross-Platform Credential Stealer | Cybersecurity

Ravie LakshmananMay 23, 2026Supply Chain Attack / Malware Cybersecurity researchers have flagged a fresh software supply chain attack campaign that has targeted multiple PHP packages belonging to Laravel-Lang to deliver…

Read more

First VPN Dismantled in Global Takedown Over Use by 25 Ransomware Groups | Cybersecurity

Authorities in Europe and North America have announced the dismantling of a criminal virtual private network (VPN) service used by criminal actors to obscure the origins of ransomware attacks, data…

Read more

Update Chrome now: Critical bugs could let attackers run code | Malware

Google has issued updates for the Chrome browser patching a number of high‑severity vulnerabilities.  The update includes fixes for two critical vulnerabilities that can be used for remote code execution…

Read more

Megalodon GitHub Attack Targets 5,561 Repos with Malicious CI/CD Workflows | Cybersecurity

Cybersecurity researchers have disclosed details of a new automated campaign called Megalodon that has pushed 5,718 malicious commits to 5,561 GitHub repositories within a six-hour window. “Using throwaway accounts and…

Read more

Kimwolf DDoS Botnet Operator Arrested in Canada Over DDoS-for-Hire Attacks | Cybersecurity

Ravie LakshmananMay 22, 2026Cybercrime / Law Enforcement The U.S. Department of Justice (DoJ) on Thursday announced the arrest of a Canadian man in connection with allegedly operating a distributed denial-of-service…

Read more

Researchers left AI agents alone in a virtual town and watched it all unravel | Malware

Tech leaders have spent the past year telling everyone that AI agents are about to run financial systems, file your tax returns, and quietly buy your groceries. Just leave them…

Read more

Cisco Patches CVSS 10.0 Secure Workload REST API Flaw Enabling Data Access | Cybersecurity

Ravie LakshmananMay 22, 2026Vulnerability / Network Security Cisco has rolled out updates for a maximum-severity security flaw impacting Secure Workload that could allow an unauthenticated, remote attacker to access sensitive…

Read more

Mini Shai-Hulud worm injects disk wiper into Microsoft Azure PyPI package | News World

Supply chain attacks with a Dune sci-fi saga branding continue to spread across the open-source ecosystem, with a Microsoft package being among the latest target of worm-like malware that steals…

Read more

Catch spyware in the act with Windows Webcam Monitoring | Malware

You’re working hard late at night, replying to emails and planning the week ahead. Then suddenly, a PDF file requests access to your camera.  Why would a PDF need camera access?  Cybercriminals often disguise spyware…

Read more

Microsoft Defender vulnerabilities are being exploited in the wild | Malware

Two Microsoft Defender vulnerabilities are being actively exploited in the wild. On May 20, 2026, the Cybersecurity and Infrastructure Security Agency (CISA) added a notable set of actively exploited vulnerabilities…

Read more

Showboat Linux Malware Hits Middle East Telecom with SOCKS5 Proxy Backdoor | Cybersecurity

Ravie LakshmananMay 21, 2026Cyber Espionage / Threat Intelligence Cybersecurity researchers have disclosed details of a new Linux malware dubbed Showboat that has been put to use in a campaign targeting…

Read more

TikTok, YouTube, and Roblox face scrutiny, but age gates won’t fix child safety | Malware

A damaging new report from Ofcom, the UK’s communications regulator, has delivered a stark verdict: TikTok and YouTube’s content feeds are “not safe enough” for children. This isn’t just another regulatory…

Read more

9-Year-Old Linux Kernel Flaw Enables Root Command Execution on Major Distros | Cybersecurity

Ravie LakshmananMay 21, 2026Linux / Vulnerability Cybersecurity researchers have disclosed details of a vulnerability in the Linux kernel that remained undetected for nine years. The vulnerability, tracked as CVE-2026-46333 (CVSS…

Read more

GitHub Internal Repositories Breached via Malicious Nx Console VS Code Extension | Cybersecurity

Ravie LakshmananMay 21, 2026Supply Chain Attack / Developer Tools GitHub on Wednesday officially confirmed that the breach of its internal repositories was the result of a compromise of an employee…

Read more

Firefox 151 packs big privacy upgrades into a small update | Malware

Mozilla has published release notes for Firefox browser version 151.0, and this update includes several genuinely meaningful privacy and security improvements. Three changes stand out in particular: Stronger anti‑fingerprinting Broader…

Read more

Microsoft Open-Sources RAMPART and Clarity to Secure AI Agents During Development | Cybersecurity

Ravie LakshmananMay 20, 2026Artificial Intelligence / Security Testing Microsoft has unveiled two new open-source tools called RAMPART and Clarity to assist developers in better testing the security of artificial intelligence…

Read more

Fake malware-signing service Fox Tempest dismantled by Microsoft | Malware

Microsoft says it dismantled a malware-signing-as-a-service (MSaaS) called Fox Tempest, which helped cybercriminals make malware appear legitimate. The service let customers submit malicious files to be digitally signed with short-lived…

Read more

Webworm Deploys EchoCreep and GraphWorm Backdoors Using Discord and MS Graph API | Cybersecurity

Cybersecurity researchers have flagged fresh activity from a China-aligned threat actor known as Webworm in 2025, deploying custom backdoors that employ Discord and Microsoft Graph API for command-and-control (C2 or…

Read more

Grafana GitHub Breach Exposes Source Code via TanStack npm Attack | Cybersecurity

Ravie LakshmananMay 20, 2026Supply Chain Attack / Cloud Security Grafana Labs, on May 19, 2026, said an investigation into its recent breach found no evidence of customer production systems or…

Read more

Facebook scam promises cheap Aldi meat boxes, steals payment info instead | Malware

Sometimes you spot posts on social media that make you wonder if any moderation takes place at all. Which is concerning, because two–thirds of all online shopping scams now start…

Read more

Biometrics, diagnoses, and bank details exposed in major healthcare breach | Malware

NYC Health + Hospitals (NYC H+H) posted a data breach notice about a months‑long breach via a third‑party vendor that exposed highly sensitive patient and employee data for at least…

Read more

Trapdoor Android Ad Fraud Scheme Hit 659 Million Daily Bid Requests Using 455 Apps | Cybersecurity

Ravie LakshmananMay 19, 2026Malvertising / Mobile Security Cybersecurity researchers have disclosed details of a new ad fraud and malvertising operation dubbed Trapdoor targeting Android device users. The activity, per HUMAN’s…

Read more

The New Phishing Click: How OAuth Consent Bypasses MFA | Cybersecurity

In February 2026, a phishing-as-a-service (PhaaS) platform called EvilTokens went live. Within five weeks, it had compromised more than 340 Microsoft 365 organizations across five countries.  The targets of the…

Read more

YouTube wants your face to fight deepfakes | Malware

If you’re worried about deepfake likenesses of yourself showing up online, you’re not alone; YouTube is worried for you. It wants to protect you by having you upload a selfie…

Read more

Popular GitHub Action Tags Redirected to Imposter Commit to Steal CI/CD Credentials | Cybersecurity

Ravie LakshmananMay 19, 2026Software Security / Malware In yet another software supply chain attack, threat actors have compromised the popular GitHub Actions workflow, actions-cool/issues-helper, to run malicious code that harvests…

Read more

AI is distorting the Holocaust (Lock and Code S07E10) | Malware

This week on the Lock and Code podcast… In May of last year, a warning about AI came from somewhere unexpected: The Auschwitz-Birkenau State Museum. Posting publicly on social media,…

Read more

INTERPOL Operation Ramz Disrupts MENA Cybercrime Networks with 201 Arrests | Cybersecurity

INTERPOL has coordinated a first-of-its-kind cybercrime crackdown across the Middle East and North Africa (MENA) that led to 201 arrests and the identification of an additional 382 suspects. The initiative…

Read more

⚡ Weekly Recap: Exchange 0-Day, npm Worm, Fake AI Repo, Cisco Exploit and More | Cybersecurity

Ravie LakshmananMay 18, 2026Cybersecurity / Hacking Monday opens with a trust problem. A mail server flaw is under active use. A network control system was targeted. Trusted packages were poisoned….

Read more

Microsoft is changing Edge’s plaintext password behavior | Malware

Microsoft said it will change Edge’s password handling as a “defense‑in‑depth” measure. Originally, Edge decrypted the entire saved‑password store on startup and kept all credentials resident in process memory in…

Read more
Update cookies preferences