MacSync malware uses public iCloud calendars to deliver new payloads
2026-09-25T01:23:22Z•001d0262d23a0a4a6f98f2aa5f47cb762d6fe3016b0501238228b00317f71623
CVE-2026-85102CVE-2026-87902AI agentsAndroidCheck Point Security GatewayClickFixDockerGitLabJetBrains TeamCityRoundcubeWordPressactive exploitationbanking trojancloud infrastructurecontainer securitymacOSmalwarephishingransomwareremote code executionvulnerability managementweb skimming
What happened
A BleepingComputer security news feed covering active exploitation of critical vulnerabilities, malware campaigns, cloud and container abuse, supply-chain and developer-targeting attacks, AI-agent-enabled intrusion activity, and data theft. Notable items include active exploitation of Roundcube, JetBrains TeamCity, Check Point Security Gateway (CVE-2026-85102), and WordPress (CVE-2026-87902) vulnerabilities, along with MacSync, Carbonato, RemControl, ClickFix, and web-skimming campaigns.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- bleepingcomputer
- Record identifier
- 001d0262d23a0a4a6f98f2aa5f47cb762d6fe3016b0501238228b00317f71623
- Enrichment time
- 2026-09-25T01:23:22Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.