How an image could compromise your Mac: understanding an ExifTool vulnerability (CVE-2026-3102)
2026-05-22T08:51:59Z•3a286eddd02db612e676b4e75434a2879d67391f61bb18ca5eb1bebfcf0a11c7
amazon-sesappleseedcve-2025-68670cve-2026-3102data-leakedr-evasionexiftoolimage-parsingkimsukymacosmobile-malwareoceanlotuspebbledashphishingpypiq1-2026ransomwarercesparkcatsupply-chaintriadavulnerabilitiesxrdpzichatbot
What happened
Kaspersky Securelist roundup (May 2026): multiple high-impact findings including an ExifTool image-parsing vulnerability that can compromise macOS (CVE-2026-3102), a pre-auth RCE in xrdp discovered during a Kaspersky assessment (CVE-2025-68670), PyPI-based supply-chain drops attributed to OceanLotus (ZiChatBot), and new PebbleDash tools used by Kimsuky/AppleSeed. Additional coverage includes Q1 2026 threat statistics for mobile/PC/IoT (notable SparkCat and Triada activity), ransomware trends (EDR-killers and data-leak focus), exploitation/vulnerability telemetry, and phishing abuse of Amazon S
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- kaspersky_securelist
- Record identifier
- 3a286eddd02db612e676b4e75434a2879d67391f61bb18ca5eb1bebfcf0a11c7
- Enrichment time
- 2026-05-22T08:51:59Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.