Microsoft Tracks MacSync Stealer by Its Behavior, Not Its Domains
2026-08-19T14:51:38Z•c140193b495b3cd767e0878e9095733f3f174cc563396fb7349e822bebd21c0f
CVE-2025-62593CVE-2026-19478CVE-2026-33824API-keysCISA-KEVDDoSEvooo1BotGitLabGraphQLLinux-IoTLiteLLMMacSync-StealerMicrosoft-SharePointMiraiRayStripeVMware-vCenterWindows-IKEactive-exploitationbotnetcloud-securitycredential-exposurecritical-vulnerabilitiesdata-breachmacOSremote-code-executionsupply-chain-attacksurveillance-AI
What happened
Security news covering active exploitation of critical vulnerabilities, malware campaigns, exposed credentials, supply-chain compromise, botnets, and major data breaches. Key items include a critical unauthenticated GitLab GraphQL flaw (CVE-2026-19478), an actively exploited Ray vulnerability (CVE-2025-62593), and additional macOS, SharePoint, VMware vCenter, and Windows IKE flaws added to CISA’s KEV catalog. Other reports describe MacSync Stealer, the Evooo1Bot Mirai-based Linux botnet, a LiteLLM supply-chain attack, 50,000 exposed Stripe keys, and breaches affecting Heights Finance and SafeP
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityaffairs
- Record identifier
- c140193b495b3cd767e0878e9095733f3f174cc563396fb7349e822bebd21c0f
- Enrichment time
- 2026-08-19T14:51:38Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.