Newly discovered PamStealer isn't your typical macOS malware
2026-07-02T20:51:53Z•96c6e3a49061a92c0946bed0919ceab4e8c4351b006ea8a16b51551d343a7ad2
2FAAMDBeats eavesdroppingCopilotLinux kernelOperation EndgamePamStealerPeopleSoftSecure BootSignalTorUSB-spreadWhatsAppcredential theftcrypto-clipperinfostealermacOSmalwaremass breachmemory encryptionnation-statepost-quantum-cryptosupply-chainuse-after-freezero-day
What happened
Ars Technica security feed (Jun–Jul 2026) reporting a string of high-impact cybersecurity developments: discovery of PamStealer, a stealthy macOS infostealer using clever tradecraft to exfiltrate credentials; multiple high-severity/vulnerable disclosures and zero-days (PeopleSoft 0-day exfiltrating gigabytes; a Linux kernel use-after-free allowing sandbox escape); a critical Copilot vulnerability that exposed 2FA codes; a massive breach leaking credentials for numerous sensitive networks (Oracle, Lenovo, FedEx, a NATO contractor, Fortinet); new crypto-focused malware (Crypto Clipper) spreading
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- arstechnica_security
- Record identifier
- 96c6e3a49061a92c0946bed0919ceab4e8c4351b006ea8a16b51551d343a7ad2
- Enrichment time
- 2026-07-02T20:51:53Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.