Apple's MacOS Gap Lets Users Disable Security Tools

2026-06-24T14:51:45Z96e81ff8b80655555d2de0b39273fcc4207c191b15649676e86d84ed055f4d67
AI-security-vulnerabilitiesAndroid-trojanCopilot-SearchLeakCordycepsDifyTapFortiBleedFortinetHTTP/2-bomb-DoSIvanti-exploitKlueOAuth-token-theftOracle-zero-dayPhantom-StealerRokarollaSIM-swap-account-takeoverSalesforceSprySOCKSWindows-Defender-exploitcredential-harvestingdisable-security-toolsfileless-malwarekernel-driver-evasionmacOS security bypassmalicious-pull-requestssupply-chain-security

What happened

A cluster of high-impact incidents and vulnerabilities across platforms and supply chains: attackers are actively exploiting zero-days and configuration gaps (Ivanti, Oracle, Windows Defender, macOS) and weaponizing supply-chain vectors (malicious pull requests, compromised apps like Klue) to steal credentials and customer data. Large-scale campaigns include credential harvesting against Fortinet devices (FortiBleed/credential sniffer), expanded Salesforce data theft via abused OAuth tokens, and diverse malware threats (fileless Phantom stealer, Android Rokarolla, TDS-powered SocGholish). The報

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
darkreading
Record identifier
96e81ff8b80655555d2de0b39273fcc4207c191b15649676e86d84ed055f4d67
Enrichment time
2026-06-24T14:51:45Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.