MacSync malware uses public iCloud calendars to deliver new payloads

2026-09-25T07:23:21Z•ab0a57e6d614100588552910e92e745b2a0d41898c058d43510887c1215577a0
CVE-2026-85102CVE-2026-87902AI agentsAndroid banking malwareCarbonatoCheck Point Security GatewayClickFixDockerGitLabMacSyncPowerShellRoundcubeTeamCityVPNWordPressactive exploitationiCloud calendarsmacOSmalvertisingmalwarenetwork management systemspayment card theftransomwarevulnerability managementweb skimming

What happened

A BleepingComputer security feed covering active exploitation, malware campaigns, exposed services, supply-chain and web application attacks, and AI-assisted cyber operations. Notable threats include MacSync payload delivery via public iCloud calendars, Carbonato targeting exposed Docker hosts, actively exploited Roundcube, TeamCity, Check Point Security Gateway (CVE-2026-85102), and WordPress (CVE-2026-87902) vulnerabilities, ClickFix PowerShell attacks, Android banking malware, and payment-card skimming campaigns.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
ab0a57e6d614100588552910e92e745b2a0d41898c058d43510887c1215577a0
Enrichment time
2026-09-25T07:23:21Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.