Newly discovered PamStealer isn't your typical macOS malware

2026-07-03T20:51:45Z4b9a9ef04c01076702601cd75e499c940f4433f5362ab03329ba28eb0bdfa444
AMDBeats-Studio-BudsCopilot-vulnerability 2FA theftCrypto ClipperLinux-kernelPamStealerPeopleSoftSecure-BootTorUSB-spreadcredential-theftcryptocurrencydata-breacheavesdroppinginfostealermacOSmalwarememory-encryptionpackage-malwarepost-quantum-cryptoprivilege-escalationquantum-migrationsupply-chainuse-after-freezero-day

What happened

Ars Technica's security feed highlights an active, high-risk threat landscape: a new macOS infostealer dubbed PamStealer uses stealthy tradecraft, Microsoft spotted a USB-spreading Crypto Clipper that steals cryptocurrency over Tor, and a massive credential breach exposed sensitive networks across major companies and contractors. Multiple high-impact software flaws and zero-days are reported — including a PeopleSoft 0-day siphoning gigabytes, a Linux kernel use-after-free allowing privilege escalation, and a Copilot bug that let attackers steal 2FA codes — alongside supply-chain/package-based/

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
arstechnica_security
Record identifier
4b9a9ef04c01076702601cd75e499c940f4433f5362ab03329ba28eb0bdfa444
Enrichment time
2026-07-03T20:51:45Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Newly discovered PamStealer isn't your typical macOS malware · Baitaphish