How an image could compromise your Mac: understanding an ExifTool vulnerability (CVE-2026-3102)

2026-05-20T20:52:19Z6a54f9d0d21a70287b54b35baae7ec8772044764de6378092651e91745f6503c
Amazon SESAppleSeedEDR evasionExifToolIoT threatsKimsukyOceanLotusPebbleDashPyPI supply-chainSecurelistZiChatBotexploitsmacOSmalicious imagemobile threatsphishingpre-auth RCEransomware trendsvulnerabilitiesxrdp

What happened

Kaspersky Securelist feed summarizing multiple security research posts from May 2026. Key items: an ExifTool flaw (CVE-2026-3102) that can lead to macOS compromise via a crafted image; discovery of a pre-auth remote code execution in xrdp (CVE-2025-68670) found during a Kaspersky USB Redirector assessment (maintainers patched it); Q1 2026 telemetry on mobile, PC and IoT threats including ransomware trends (EDR-killers, shift to data leak extortion); analyses of Kimsuky/AppleSeed PebbleDash tooling and OceanLotus use of malicious PyPI wheels delivering ZiChatBot; and a phishing campaign abusing

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
kaspersky_securelist
Record identifier
6a54f9d0d21a70287b54b35baae7ec8772044764de6378092651e91745f6503c
Enrichment time
2026-05-20T20:52:19Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · How an image could compromise your Mac: understanding an ExifTool vulnerability (CVE-2026-3102) · Baitaphish