Newly discovered PamStealer isn't your typical macOS malware

2026-07-03T08:51:51Zc5340a86514c1edd013d039ff9f4dbf7f1a96dea86dfc64fb207ed7d4145b210
2FA bypassAI securityAMD TSME/memory encryption issues','Beats Studio Buds','eavesdroCopilotCrypto ClipperLLM guardrailsLinux kernelPamStealerPeopleSoftSearchLeakSecure BootUSB infectioncredential theftcryptocurrency theftdata breachhardware securityinfostealermacOSmalwarepackage trojanpost-quantumquantum-safe cryptographysupply chainuse-after-freezero-day

What happened

Collection of Ars Technica security stories (June–July 2026) covering a broad surge in high-impact threats and defensive developments: a new macOS infostealer dubbed PamStealer, continued exploitation of zero‑days (notably a PeopleSoft 0‑day and a Linux kernel use‑after‑free allowing local root), credential and secrets exposure in a massive breach affecting many large vendors, a critical Copilot/SearchLeak issue that allowed 2FA theft, and a new crypto‑theft worm (Crypto Clipper) spreading via USB and Tor. The feed also highlights supply‑chain and package‑based credential stealers, hardware/h/

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
arstechnica_security
Record identifier
c5340a86514c1edd013d039ff9f4dbf7f1a96dea86dfc64fb207ed7d4145b210
Enrichment time
2026-07-03T08:51:51Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.