Newly discovered PamStealer isn't your typical macOS malware
2026-07-03T08:51:51Z•c5340a86514c1edd013d039ff9f4dbf7f1a96dea86dfc64fb207ed7d4145b210
2FA bypassAI securityAMD TSME/memory encryption issues','Beats Studio Buds','eavesdroCopilotCrypto ClipperLLM guardrailsLinux kernelPamStealerPeopleSoftSearchLeakSecure BootUSB infectioncredential theftcryptocurrency theftdata breachhardware securityinfostealermacOSmalwarepackage trojanpost-quantumquantum-safe cryptographysupply chainuse-after-freezero-day
What happened
Collection of Ars Technica security stories (June–July 2026) covering a broad surge in high-impact threats and defensive developments: a new macOS infostealer dubbed PamStealer, continued exploitation of zero‑days (notably a PeopleSoft 0‑day and a Linux kernel use‑after‑free allowing local root), credential and secrets exposure in a massive breach affecting many large vendors, a critical Copilot/SearchLeak issue that allowed 2FA theft, and a new crypto‑theft worm (Crypto Clipper) spreading via USB and Tor. The feed also highlights supply‑chain and package‑based credential stealers, hardware/h/
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- arstechnica_security
- Record identifier
- c5340a86514c1edd013d039ff9f4dbf7f1a96dea86dfc64fb207ed7d4145b210
- Enrichment time
- 2026-07-03T08:51:51Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.