Why AMOS matters: The macOS malware stealing data at scale

2026-05-17T08:51:40Z56074346869964cca489b5872cc83109e7b9e51cded3feefc460e327714ed534
AIAMOSBeagleCVEClaudeDLL-sideloadingDonutsEDRGPT-5.5MDRSophosX-Opsbackdoorendpointidentity-securityinfostealermacOSpatch-tuesdayransomwaresupply-chainsupply-chain-attackthreat-researchvulnerabilities

What happened

Aggregation of Sophos blog posts (May 2026) covering multiple active threats and security developments: a new macOS infostealer named AMOS (Atomic macOS Stealer) exfiltrating data at scale; a heavy Microsoft Patch Tuesday with 132 CVEs (nearly 300 when including advisories); a supply‑chain attack blocked by Sophos Endpoint; a DLL‑sideloading backdoor delivered via a fake Claude site (“Donuts and Beagles”); and guidance on reducing blast radius for AI agent deployments. Also included: Sophos’ State of Identity Security 2026 findings, commentary on GPT‑5.5‑Cyber for defenders, ransomware trends,

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
sophos_news
Record identifier
56074346869964cca489b5872cc83109e7b9e51cded3feefc460e327714ed534
Enrichment time
2026-05-17T08:51:40Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.