Why AMOS matters: The macOS malware stealing data at scale
2026-05-17T08:51:40Z•56074346869964cca489b5872cc83109e7b9e51cded3feefc460e327714ed534
AIAMOSBeagleCVEClaudeDLL-sideloadingDonutsEDRGPT-5.5MDRSophosX-Opsbackdoorendpointidentity-securityinfostealermacOSpatch-tuesdayransomwaresupply-chainsupply-chain-attackthreat-researchvulnerabilities
What happened
Aggregation of Sophos blog posts (May 2026) covering multiple active threats and security developments: a new macOS infostealer named AMOS (Atomic macOS Stealer) exfiltrating data at scale; a heavy Microsoft Patch Tuesday with 132 CVEs (nearly 300 when including advisories); a supply‑chain attack blocked by Sophos Endpoint; a DLL‑sideloading backdoor delivered via a fake Claude site (“Donuts and Beagles”); and guidance on reducing blast radius for AI agent deployments. Also included: Sophos’ State of Identity Security 2026 findings, commentary on GPT‑5.5‑Cyber for defenders, ransomware trends,
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- sophos_news
- Record identifier
- 56074346869964cca489b5872cc83109e7b9e51cded3feefc460e327714ed534
- Enrichment time
- 2026-05-17T08:51:40Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.