Install
Please confirm you are human
This browser or connection looks automated. Press and continuously hold the control for 3 seconds to enable Google-hosted web results and, when separately allowed, AI-assisted answers.
A successful check enables 100 search requests. Interactive access does not authorize scraping, systematic collection, or reuse of search output.
News
Hackers Use Fake Claude and ChatGPT Installers to Infect Mac Users With Password-Stealing Malware
3+ day, 22+ hour ago (629+ words) Mac users seeking AI tools face a malware trap. Attackers are using fake Claude and ChatGPT installers and sponsored search results to push MacSync, a macOS password stealer. The campaign relies on persuasion instead of a software flaw. A visitor…...
Hackers Use ClickFix Lures to Deploy MacSync Stealer and Bypass macOS Security.
4+ day, 1+ hour ago (593+ words) The campaigns do not require a macOS vulnerability; instead, they abuse user trust by persuading victims to paste attacker-controlled commands into Terminal, sidestepping traditional file-centric protections. However, Russian-language artifacts observed in some samples do not establish attribution to a particular…...
ClickFix moves into the browser and onto WebDAV, Cisco Talos finds
5+ day, 22+ hour ago (448+ words) UPDATED 06:00 EDT / SEPTEMBER 08 2026 Cisco Systems Inc.’s Talos Threat Intelligence group today detailed two ClickFix campaigns that push the technique past the copy-and-paste PowerShell prompt it is known for, one that never touches the operating system at all and one…...
14 Fake macOS Installers Linked to DPRK Campaign Deliver Credential-Stealing RAT
1+ week, 3+ day ago (612+ words) Mac users are being targeted with 14 fake application installers that appear to offer familiar software but instead start a credential-stealing remote-access trojan. The files were distributed as macOS disk images and installer packages, giving attackers another route into systems used…...
Scanners posing as ClaudeBot hunt credential files from 824 addresses
2+ week, 20+ hour ago (803+ words) Six forged names crossed 795 separate networks in a month, and allowlists keyed on names cannot see them. What replaces the user agent as proof of identity now? Security firm GreyNoise reported on August 28, 2026 that automated scanners spread across 824 internet addresses…...
Hackers Place Fake Codex Download Above Legitimate OpenAI Result to Infect Mac Users
2+ week, 6+ day ago (542+ words) Threat actors are using sponsored Google Search ads to place a fake OpenAI Codex download page above the legitimate result, steering macOS users into manually executing malware through Terminal. The operation begins when users search for Codex-related terms, including “codex…...
Fake Codex Download Uses Google Sites to Deliver macOS Malware
2+ week, 6+ day ago (501+ words) A fake Codex download campaign has used sponsored search results, legitimate Google Sites pages and ClickFix instructions to trick macOS users into executing malware. In a technical write-up published on August 24, Cato Networks researchers said they found the campaign directing…...
WordlistLoader Delivers Amatera via ClickFix, SynkLoader Phishes Windows Passwords
2+ week, 6+ day ago (732+ words) Cybersecurity researchers have flagged two new malware families called WordlistLoader and SynkLoader that's used to deliver next-stage payloads and likely sell access to ransomware groups. According to findings from Gen Digital, WordlistLoader is being used to deliver Amatera Stealer (aka…...
AmnesiaStealer Gives Hackers Hidden Control of Logged-In Browsers on Macs
2+ week, 6+ day ago (574+ words) AmnesiaStealer is a newly identified macOS information stealer that does more than copy saved passwords. It can give criminals quiet control of a browser that is already signed in, turning an infected Mac into a gateway to email, business apps,…...
Fake CAPTCHA Tricks Mac Users Into Installing a Backdoor That Steals Passwords and Mines Crypto
2+ week, 6+ day ago (631+ words) Mac users are being lured into a ClickFix campaign that turns a routine CAPTCHA check into a path for password theft, remote control, and cryptocurrency mining. It persuades a visitor to run an attackers’ command in Terminal rather than download…...