Newly discovered PamStealer isn't your typical macOS malware
2026-07-03T20:51:45Z•4b9a9ef04c01076702601cd75e499c940f4433f5362ab03329ba28eb0bdfa444
AMDBeats-Studio-BudsCopilot-vulnerability 2FA theftCrypto ClipperLinux-kernelPamStealerPeopleSoftSecure-BootTorUSB-spreadcredential-theftcryptocurrencydata-breacheavesdroppinginfostealermacOSmalwarememory-encryptionpackage-malwarepost-quantum-cryptoprivilege-escalationquantum-migrationsupply-chainuse-after-freezero-day
What happened
Ars Technica's security feed highlights an active, high-risk threat landscape: a new macOS infostealer dubbed PamStealer uses stealthy tradecraft, Microsoft spotted a USB-spreading Crypto Clipper that steals cryptocurrency over Tor, and a massive credential breach exposed sensitive networks across major companies and contractors. Multiple high-impact software flaws and zero-days are reported — including a PeopleSoft 0-day siphoning gigabytes, a Linux kernel use-after-free allowing privilege escalation, and a Copilot bug that let attackers steal 2FA codes — alongside supply-chain/package-based/
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- arstechnica_security
- Record identifier
- 4b9a9ef04c01076702601cd75e499c940f4433f5362ab03329ba28eb0bdfa444
- Enrichment time
- 2026-07-03T20:51:45Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.