Newly discovered PamStealer isn't your typical macOS malware

2026-07-06T20:51:45Z0568b3728c8fa4724ad289735e7c2dbb6795243da22489faa45065563062ba57
2FA compromiseAMD memory encryptionBeats Studio Buds eavesdroppingCopilot/SearchLeakFedExFortinetLenovoLinux kernel UAFOraclePamStealerPeopleSoft 0-daySecure Boot keysUSB infectioncredential theftcredentials leakcrypto clipperexecutive orderinfostealerlaw enforcement disruption of cybercrime networks','Russia-statemacOS malwaremass breachoperation endgamepost-quantum cryptosandbox escapesupply-chain packages

What happened

Collection of Ars Technica security items (June–July 2026) highlighting a surge in high-impact incidents and evolving tradecraft: newly discovered PamStealer macOS infostealer using stealthy techniques; Microsoft and others observe self‑propagating crypto stealers (Crypto Clipper) and packages laced with credential stealers; a PeopleSoft 0‑day is actively exfiltrating gigabytes from hundreds of organizations; a Linux kernel use‑after‑free bug enables sandbox escape/root; a critical Copilot/SearchLeak flaw exposed 2FA codes; a massive breach leaked credentials for many sensitive networks (incl.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
arstechnica_security
Record identifier
0568b3728c8fa4724ad289735e7c2dbb6795243da22489faa45065563062ba57
Enrichment time
2026-07-06T20:51:45Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.