Newly discovered PamStealer isn't your typical macOS malware
2026-07-06T20:51:45Z•0568b3728c8fa4724ad289735e7c2dbb6795243da22489faa45065563062ba57
2FA compromiseAMD memory encryptionBeats Studio Buds eavesdroppingCopilot/SearchLeakFedExFortinetLenovoLinux kernel UAFOraclePamStealerPeopleSoft 0-daySecure Boot keysUSB infectioncredential theftcredentials leakcrypto clipperexecutive orderinfostealerlaw enforcement disruption of cybercrime networks','Russia-statemacOS malwaremass breachoperation endgamepost-quantum cryptosandbox escapesupply-chain packages
What happened
Collection of Ars Technica security items (June–July 2026) highlighting a surge in high-impact incidents and evolving tradecraft: newly discovered PamStealer macOS infostealer using stealthy techniques; Microsoft and others observe self‑propagating crypto stealers (Crypto Clipper) and packages laced with credential stealers; a PeopleSoft 0‑day is actively exfiltrating gigabytes from hundreds of organizations; a Linux kernel use‑after‑free bug enables sandbox escape/root; a critical Copilot/SearchLeak flaw exposed 2FA codes; a massive breach leaked credentials for many sensitive networks (incl.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- arstechnica_security
- Record identifier
- 0568b3728c8fa4724ad289735e7c2dbb6795243da22489faa45065563062ba57
- Enrichment time
- 2026-07-06T20:51:45Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.