Aggregator
New Clickfix Variant ‘Matryoshka’ Attacking Users to Deploy macOS Stealer Malware
A sophisticated social engineering campaign targeting macOS users has emerged, deploying a dangerous stealer malware through an evolved version of the ClickFix attack technique. Named “Matryoshka” after the Russian nesting dolls, this variant uses nested obfuscation layers to hide malicious code from security scanners and automated analysis systems. The attack tricks victims into executing Terminal […]
The post New Clickfix Variant ‘Matryoshka’ Attacking Users to Deploy macOS Stealer Malware appeared first on Cyber Security News.
CVE-2026-20624 | Apple macOS up to 14.7/15.6/26.2 App information disclosure (Nessus ID 298657)
CVE-2026-20609 | Apple macOS/watchOS/visionOS/iOS/iPadOS/tvOS up to 26.2 File memory corruption (Nessus ID 298657)
CVE-2026-20620 | Apple macOS up to 14.7/15.6/26.2 Kernel Memory out-of-bounds (Nessus ID 298657)
CVE-2026-20611 | Apple macOS/watchOS/visionOS/iOS/iPadOS/tvOS up to 26.2 Media File out-of-bounds (Nessus ID 298657)
CVE-2025-46283 | Apple macOS up to 26.1 App access control (Nessus ID 298658)
CVE-2025-43338 | Apple iOS/iPadOS/macOS Media File out-of-bounds (Nessus ID 298658 / WID-SEC-2025-2475)
CVE-2025-43533 | Apple tvOS/iOS/iPadOS/visionOS/macOS/watchOS up to 26.1 HID Device memory corruption (EUVD-2025-203980 / Nessus ID 298658)
Microsoft equips CISOs and AI risk leaders with a new security tool
Microsoft released Security Dashboard for AI in public preview for enterprise environments. The dashboard aggregates posture and real-time risk signals from Microsoft Defender, Microsoft Entra, and Microsoft Purview into a single view within security tools. Security Dashboard for AI in browser (Source: Microsoft) “The dashboard equips CISOs and AI risk leaders with a governance tool to discover agents and AI apps, track AI posture and drift, and correlate risk signals to investigate and act across … More →
The post Microsoft equips CISOs and AI risk leaders with a new security tool appeared first on Help Net Security.