New XCSSET variant targets macOS devs via compromised Xcode projects

2026-08-04T19:23:22Z634a65cd3be96369745df061c2f59f6db20f119b4c6cc0c328577bfd7915e360
CVE-2026-18577APT29Android malwareClickFixMicrosoft 365Midnight BlizzardN-able N-centralOpen VSXRATRuby on RailsXCSSETXcodeactive exploitationcredential theftcryptocurrency walletdata breachdeveloper targetinginfostealermacOSnpmpasskeysremote code executionsoftware supply chain

What happened

BleepingComputer security feed containing reports on active exploitation, malware campaigns, supply-chain attacks, credential and passkey theft, data breaches, and critical vulnerabilities. Notable items include exploitation of N-able N-central authentication bypass CVE-2026-18577, a critical Rails Active Storage flaw with potential RCE, XCSSET targeting macOS developers through compromised Xcode projects, a large npm supply-chain compromise, and attacks against Microsoft 365, Google-synced passkeys, and developer environments.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
634a65cd3be96369745df061c2f59f6db20f119b4c6cc0c328577bfd7915e360
Enrichment time
2026-08-04T19:23:22Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.