Newly discovered PamStealer isn't your typical macOS malware

2026-07-02T20:51:53Z96c6e3a49061a92c0946bed0919ceab4e8c4351b006ea8a16b51551d343a7ad2
2FAAMDBeats eavesdroppingCopilotLinux kernelOperation EndgamePamStealerPeopleSoftSecure BootSignalTorUSB-spreadWhatsAppcredential theftcrypto-clipperinfostealermacOSmalwaremass breachmemory encryptionnation-statepost-quantum-cryptosupply-chainuse-after-freezero-day

What happened

Ars Technica security feed (Jun–Jul 2026) reporting a string of high-impact cybersecurity developments: discovery of PamStealer, a stealthy macOS infostealer using clever tradecraft to exfiltrate credentials; multiple high-severity/vulnerable disclosures and zero-days (PeopleSoft 0-day exfiltrating gigabytes; a Linux kernel use-after-free allowing sandbox escape); a critical Copilot vulnerability that exposed 2FA codes; a massive breach leaking credentials for numerous sensitive networks (Oracle, Lenovo, FedEx, a NATO contractor, Fortinet); new crypto-focused malware (Crypto Clipper) spreading

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
arstechnica_security
Record identifier
96c6e3a49061a92c0946bed0919ceab4e8c4351b006ea8a16b51551d343a7ad2
Enrichment time
2026-07-02T20:51:53Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Newly discovered PamStealer isn't your typical macOS malware · Baitaphish