Curated Cyber Threat Intelligence

Threat Feed

Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.

scheduleUpdated 2026-09-04 · 02:17 UTC
articleTotal: 1172 reports

Filtered Reports

20 / 20 results
Active filter:tag: #apple✕ clear
NSO Group Pegasus deployed via zero-click iMessage exploit in Serbiahighperson_alertThreat Actor
person_alertThreat Actor

NSO Group Pegasus deployed via zero-click iMessage exploit in Serbia

NSO Group is an Israeli cyber intelligence company that develops and sells Pegasus spyware to government clients. The company markets its surveillance technology as a tool for law enforcement and intelligence agencies to combat terrorism and crime.

Apple3 Sep · 06:43 UTC
AnonyMousKIT PhaaS automates iPhone passcode theft via voice AIhighperson_alertThreat Actor
person_alertThreat Actor

AnonyMousKIT PhaaS automates iPhone passcode theft via voice AI

AnonyMousKIT is a phishing-as-a-service (PhaaS) platform active since early 2024, operated by unknown threat actors who provide automated infrastructure for stealing iPhone passcodes and disabling Apple's Activation Lock.

Apple25 Aug · 18:25 UTC
CISA flags 4 critical flaws in macOS, SharePoint, vCenter, IKE under attackcriticalbug_reportVulnerability
bug_reportVulnerability

CISA flags 4 critical flaws in macOS, SharePoint, vCenter, IKE under attack

Apple macOS (CVE-2026-65400, Screen Sharing authentication bypass), Microsoft SharePoint (CVE-2026-55040, weak authentication), Broadcom VMware vCenter (CVE-2026-59310, path traversal RCE), Microsoft IKE Service Extensions (CVE-2026-33824, double fre…

CVE-2026-6540019 Aug · 09:01 UTC
macOS Screen Sharing auth bypass exploited to deploy Monero minershighbug_reportVulnerability
bug_reportVulnerability

macOS Screen Sharing auth bypass exploited to deploy Monero miners

macOS Screen Sharing feature on systems with TCP port 5900 exposed to the internet. Fixed in macOS Tahoe 26.6.1, Sequoia 15.7.9, and Sonoma 14.8.9. CVE-2026-65400 affects earlier versions of these releases.

Apple14 Aug · 12:59 UTC
ClickFix attacks deliver macOS stealer targeting crypto wallets and Keychainhighbug_reportVulnerability
bug_reportVulnerability

ClickFix attacks deliver macOS stealer targeting crypto wallets and Keychain

macOS systems (all CPU architectures). Users tricked into pasting malicious commands into Terminal. Targets cryptocurrency wallets (Bitcoin, Litecoin, Dogecoin, Monero, Ethereum, XRP), browser passwords, Apple iCloud Keychain, and cached credentials.

Apple7 Aug · 16:29 UTC
Apple iCloud Private Relay leaks real IP via WebKit proxy bypasseshighbug_reportVulnerability
bug_reportVulnerability

Apple iCloud Private Relay leaks real IP via WebKit proxy bypasses

Apple iCloud Private Relay on iOS 15+, macOS, and iPadOS. Affects Safari and all WebKit-based browsers (Chrome, Edge, Firefox, Brave) on Apple platforms. Impacts users with iCloud+ subscriptions using Private Relay for privacy protection.

Apple6 Aug · 09:33 UTC
ClickFix Campaign Uses Browser Fingerprinting to Target macOS Usershighperson_alertThreat Actor
person_alertThreat Actor

ClickFix Campaign Uses Browser Fingerprinting to Target macOS Users

ClickFix is a macOS-focused social engineering campaign tracked by Microsoft Threat Intelligence. The operators remain unidentified, but the campaign demonstrates sophisticated evasion capabilities through server-side browser fingerprinting across mo…

Apple5 Aug · 16:44 UTC
macOS ClickFix campaign adds fingerprinting to evade detectionhighbug_reportVulnerability
bug_reportVulnerability

macOS ClickFix campaign adds fingerprinting to evade detection

macOS users targeted via 250+ algorithmically generated domains (e.g., filecopperbasket, apricotfilepoint[.]com). Campaign delivers MacSync and Atomic Stealer (AMOS) infostealers. All macOS versions susceptible to social engineering technique.

Apple5 Aug · 13:48 UTC
XCSSET v40 malware targets macOS developers via poisoned Xcode projectshighbug_reportVulnerability
bug_reportVulnerability

XCSSET v40 malware targets macOS developers via poisoned Xcode projects

macOS developers using Xcode and downloading projects from compromised Git/GitHub repositories. XCSSET v40 observed in attacks mid-April and early May 2026. All macOS versions with Xcode are at risk; specific version details not provided.

Apple4 Aug · 17:03 UTC
DOUBLECUP loader-as-a-service delivers malware via ClickFix attackshighperson_alertThreat Actor
person_alertThreat Actor

DOUBLECUP loader-as-a-service delivers malware via ClickFix attacks

DOUBLECUP is a Russian loader-as-a-service platform that has operated since early June 2026. The service provides customers with licenses and a Go-based Windows tool for creating malicious ClickFix campaigns.

Microsoft3 Aug · 18:01 UTC
Chinese-Speaking Actor Deploys GHOSTBLADE via Leaked DarkSword iOS Kithighperson_alertThreat Actor
person_alertThreat Actor

Chinese-Speaking Actor Deploys GHOSTBLADE via Leaked DarkSword iOS Kit

An unidentified Chinese-speaking threat actor conducting mobile exploitation campaigns against iOS devices. The actor operates extensive infrastructure spanning over 100 web properties concentrated in Hong Kong with reach into Japan, the United State…

Apple3 Aug · 08:49 UTC
Lazarus Deploys Crypto-Stealing Malware via macOS Malvertising Campaignhighperson_alertThreat Actor
person_alertThreat Actor

Lazarus Deploys Crypto-Stealing Malware via macOS Malvertising Campaign

Lazarus is a North Korea-linked APT group with a sustained focus on financial gain, particularly targeting cryptocurrency assets. Operating under DPRK state sponsorship, the group has evolved its tactics to include sophisticated social engineering ca…

Apple30 Jul · 16:18 UTC
Fraudulent Sparrow Wallet App on Apple App Store Steals $1.8M in Bitcoinhighperson_alertThreat Actor
person_alertThreat Actor

Fraudulent Sparrow Wallet App on Apple App Store Steals $1.8M in Bitcoin

The threat actor behind this campaign remains unidentified. The operation involved publishing fraudulent cryptocurrency wallet applications on Apple's App Store that impersonated the legitimate Sparrow Wallet.

Apple27 Jul · 15:29 UTC
Apple fixes Hide My Email flaw exposing real addresses in mail logshighbug_reportVulnerability
bug_reportVulnerability

Apple fixes Hide My Email flaw exposing real addresses in mail logs

Apple Hide My Email service (all users prior to July 3, 2026 patch). The vulnerability affected the privacy relay feature that masks user email addresses, causing real email addresses to leak in mail server logs.

Apple21 Jul · 16:46 UTC
PamStealer: macOS Info Stealer Masquerades as Maccy Clipboard Managerhighperson_alertThreat Actor
person_alertThreat Actor

PamStealer: macOS Info Stealer Masquerades as Maccy Clipboard Manager

PamStealer is a newly discovered macOS information stealer malware family identified by Jamf Threat Labs. The malware is distributed through social engineering, masquerading as a legitimate Maccy clipboard manager application to deceive users into in…

Apple3 Jul · 06:03 UTC
AirDrop and Quick Share flaws enable wireless DoS and security bypasshighbug_reportVulnerability
bug_reportVulnerability

AirDrop and Quick Share flaws enable wireless DoS and security bypass

Apple AirDrop and Google Quick Share wireless file transfer features on iOS, macOS, and Android devices. Specific affected versions not disclosed. Attack requires physical proximity (wireless range).

Apple30 Jun · 07:27 UTC
ClickFix Targets macOS with Terminal-Based Infostealer Campaignhighperson_alertThreat Actor
person_alertThreat Actor

ClickFix Targets macOS with Terminal-Based Infostealer Campaign

ClickFix is a threat actor conducting social engineering campaigns that trick users into executing malicious commands. The actor leverages deceptive techniques to convince victims to manually run Terminal commands on macOS systems, facilitating the d…

Apple23 Jun · 16:30 UTC
Unpatchable SecureROM exploit for Apple A12/A13 chips publishedcriticalbug_reportVulnerability
bug_reportVulnerability

Unpatchable SecureROM exploit for Apple A12/A13 chips published

Apple devices with A12 and A13 chips (iPhone XS/XR/11 series, iPad Air 3rd gen, iPad mini 5th gen, iPad 8th gen). SecureROM vulnerability is permanent and cannot be patched via software updates.

Apple19 Jun · 16:37 UTC
Apple Beats Studio Buds Bluetooth flaw allows unauthorized pairinghighbug_reportVulnerability
bug_reportVulnerability

Apple Beats Studio Buds Bluetooth flaw allows unauthorized pairing

Apple Beats Studio Buds using Airoha Bluetooth audio SDK. Vulnerability affects devices prior to firmware update released by Apple. Attackers must be within Bluetooth range (typically <10 meters).

CVE-2025-2070119 Jun · 04:36 UTC
Apple patches Bluetooth eavesdropping flaw in Beats Studio Budshighbug_reportVulnerability
bug_reportVulnerability

Apple patches Bluetooth eavesdropping flaw in Beats Studio Buds

Apple Beats Studio Buds wireless earbuds. Specific firmware versions not disclosed. Vulnerability requires attacker to be within Bluetooth range (typically 10-30 meters).

Apple18 Jun · 10:23 UTC