Microsoft Tracks MacSync Stealer by Its Behavior, Not Its Domains

2026-08-19T14:51:38Zc140193b495b3cd767e0878e9095733f3f174cc563396fb7349e822bebd21c0f
CVE-2025-62593CVE-2026-19478CVE-2026-33824API-keysCISA-KEVDDoSEvooo1BotGitLabGraphQLLinux-IoTLiteLLMMacSync-StealerMicrosoft-SharePointMiraiRayStripeVMware-vCenterWindows-IKEactive-exploitationbotnetcloud-securitycredential-exposurecritical-vulnerabilitiesdata-breachmacOSremote-code-executionsupply-chain-attacksurveillance-AI

What happened

Security news covering active exploitation of critical vulnerabilities, malware campaigns, exposed credentials, supply-chain compromise, botnets, and major data breaches. Key items include a critical unauthenticated GitLab GraphQL flaw (CVE-2026-19478), an actively exploited Ray vulnerability (CVE-2025-62593), and additional macOS, SharePoint, VMware vCenter, and Windows IKE flaws added to CISA’s KEV catalog. Other reports describe MacSync Stealer, the Evooo1Bot Mirai-based Linux botnet, a LiteLLM supply-chain attack, 50,000 exposed Stripe keys, and breaches affecting Heights Finance and SafeP

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
c140193b495b3cd767e0878e9095733f3f174cc563396fb7349e822bebd21c0f
Enrichment time
2026-08-19T14:51:38Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Microsoft Tracks MacSync Stealer by Its Behavior, Not Its Domains · Baitaphish