New CrashStealer malware poses as Apple crash reporting tool
2026-07-13T19:23:34Z•a018b240075112cdb8ad642924b41481fe3c62057f1c58f76c0488065a4ee1e2
AI securityAndroidAppleBalbooa FormsCISACMS exploitationCrashStealerGhostcommitJoomlaLidl breach','Russian GRU','sanctions','call spoofing','Russian-RCERedHookU-BootWireless ADBarbitrary file uploadcrypto walletsdata breachfirmwareiCagendainfo-stealerkeychainmacOSpersistenceprompt injectionsupply-chain breach
What happened
Multiple active threats and high-impact security developments reported: a macOS info-stealer named CrashStealer is masquerading as Apple’s crash reporter to exfiltrate credentials, keychain items, and crypto wallets; CISA warns of active remote code execution exploitation in Joomla extensions iCagenda and Balbooa Forms via arbitrary file upload; six U-Boot bootloader flaws were disclosed that could enable stealthy, persistent firmware attacks; RedHook Android malware now abuses Wireless ADB for shell access; researchers demonstrated a novel prompt-injection technique (‘Ghostcommit’) hiding in‑
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- bleepingcomputer
- Record identifier
- a018b240075112cdb8ad642924b41481fe3c62057f1c58f76c0488065a4ee1e2
- Enrichment time
- 2026-07-13T19:23:34Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.