Newly discovered PamStealer isn't your typical macOS malware

2026-07-04T20:51:45Z5ba9eb3bf55adf197d3b618fd4660aa04906488e16ff3854a3bc5d21bae0cdd9
AMDLinux-kernelPamStealerPeopleSoftTorUSB-propagationbeatsbydrecredential-theftcrypto-clipperhardware-securityinfostealerlaw-enforcementmacOSmalwarememory-encryptionnation-stateoperation-endgamepost-quantum-cryptoransomwaresecure-bootsignalsupply-chainvulnerabilitywhatsappzero-day

What happened

A roundup of Ars Technica security and tech reporting (June–July 2026) highlighting multiple high-impact incidents and trends: a newly discovered macOS infostealer called PamStealer using stealthy tradecraft; widespread credential theft and a massive breach exposing credentials for Oracle, Lenovo, FedEx, a NATO contractor, Fortinet and others; supply-chain and package attacks (including Microsoft packages laced with credential stealers and malware that propagates via AI agents); a self‑propagating crypto clipper spreading over USB and using Tor; several high‑severity/zero‑day vulnerabilities (

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
arstechnica_security
Record identifier
5ba9eb3bf55adf197d3b618fd4660aa04906488e16ff3854a3bc5d21bae0cdd9
Enrichment time
2026-07-04T20:51:45Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.