How an image could compromise your Mac: understanding an ExifTool vulnerability (CVE-2026-3102)
2026-05-20T20:52:19Z•6a54f9d0d21a70287b54b35baae7ec8772044764de6378092651e91745f6503c
Amazon SESAppleSeedEDR evasionExifToolIoT threatsKimsukyOceanLotusPebbleDashPyPI supply-chainSecurelistZiChatBotexploitsmacOSmalicious imagemobile threatsphishingpre-auth RCEransomware trendsvulnerabilitiesxrdp
What happened
Kaspersky Securelist feed summarizing multiple security research posts from May 2026. Key items: an ExifTool flaw (CVE-2026-3102) that can lead to macOS compromise via a crafted image; discovery of a pre-auth remote code execution in xrdp (CVE-2025-68670) found during a Kaspersky USB Redirector assessment (maintainers patched it); Q1 2026 telemetry on mobile, PC and IoT threats including ransomware trends (EDR-killers, shift to data leak extortion); analyses of Kimsuky/AppleSeed PebbleDash tooling and OceanLotus use of malicious PyPI wheels delivering ZiChatBot; and a phishing campaign abusing
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- kaspersky_securelist
- Record identifier
- 6a54f9d0d21a70287b54b35baae7ec8772044764de6378092651e91745f6503c
- Enrichment time
- 2026-05-20T20:52:19Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.