FlagThis — Daily Cybersecurity Intelligence Briefing

FILTERING BY: CLEAR FILTER

Apple macOS Screen Sharing Authentication Bypass CVE-2026-65400

CVE-2026-65400 is a high-severity state management vulnerability within the macOS screen sharing capability affecting macOS Tahoe, Sequoia, and Sonoma. Attackers targeting exposed Port 5900 can bypass authentication to gain immediate root-level access, enabling full remote takeover of the user interface, including screen visibility and input manipulation. The Netherlands National Cyber Security Centrum (NCSC) has confirmed active exploitation in the wild, primarily utilizing the flaw to deploy Monero cryptominers for resource theft. Immediate remediation requires updating to the latest macOS versions and implementing network restrictions to prevent direct internet exposure of VNC services.

Apple iOS Mercenary Spyware Threat Notifications

Apple has issued urgent threat notifications to hundreds of users across 110 countries, alerting them to targeted attacks by mercenary spyware vendors. These campaigns likely employ zero-click or one-click exploit chains leveraging zero-day vulnerabilities in iOS to gain unauthorized system access and exfiltrate sensitive data. Apple utilizes internal telemetry to detect indicators of compromise (IoCs) and associated command-and-control (C2) infrastructure. Affected users are advised to immediately enable Lockdown Mode to minimize the attack surface and disrupt the exploit delivery mechanism and ensure device integrity.

Coruna Exploit Kit and DarkSword iOS Full-Chain Proliferation

The proliferation of the Coruna exploit kit and the associated DarkSword full-chain exploit represents a systemic escalation in mobile threat capabilities. Utilizing a sequence of zero-day vulnerabilities, including CVE-2026-21385, DarkSword facilitates WebKit exploitation, kernel-level privilege escalation, and sandbox escapes to achieve total device compromise on iOS. Originally deployed by boutique actors, the kit has transitioned to a commoditized model, enabling multiple global threat groups to conduct unauthorized data exfiltration and maintain persistence on high-value targets. This shift highlights a critical transition toward widely distributed, high-end offensive capabilities targeting modern iOS security mitigations.

XCSSET v40: Evolution of the Xcode-Targeted Supply Chain Malware

XCSSET v40 is a specialized macOS malware family targeting the software development supply chain by compromising Xcode projects (.xcodeproj). The latest iteration employs advanced obfuscation and novel persistence mechanisms to bypass signature-based detection and embed malicious logic within developer IDEs. By poisoning the build process, XCSSET facilitates downstream supply chain attacks, enabling the delivery of compromised binaries to end-users. Security researchers from Unit 42 and Microsoft Security have identified a significant increase in the complexity of the malware's binary triage evasion, necessitating AI-assisted decoding to uncover its operational mechanics and persistence triggers.

MacOS.Gaslight: DPRK AI-Aware Malware Using Prompt Injection for Evasion

North Korean state-sponsored actors have deployed MacOS.Gaslight, a Rust-based information stealer and backdoor targeting macOS environments. The implant utilizes a novel evasion technique by embedding 38 adversarial prompt injection strings designed to manipulate LLM-based malware triage tools. By targeting the cognitive layer of analysis, the malware attempts to trigger AI safety guards or provide fabricated system context, inducing AI assistants to misclassify the payload as benign or refuse analysis. This strategy directly degrades the accuracy of AI-assisted SOC triage, increasing attacker dwell time by blinding automated security analysis pipelines.

AWS Continuum, Apple Beats, and the CrowdStrike-Delta Fallout

AWS has introduced Continuum, an automated security framework shifting from passive telemetry to a "reasoning-and-action" model designed for machine-speed vulnerability remediation. Simultaneously, Apple patched a critical firmware vulnerability in Beats Studio Buds that enabled remote audio surveillance, effectively turning devices into wiretaps. Finally, the U.S. Department of Transportation closed its probe into Delta Air Lines following the CrowdStrike content update outage, though the airline remains embroiled in class-action litigation regarding refund policies. These events highlight a critical pivot toward autonomous defense and the enduring legal risks associated with systemic operational failures.

Systematic Vulnerabilities in Apple AirDrop and Android Quick Share

Researchers from CISPA have identified critical, zero-click vulnerabilities in proximity-based file-transfer protocols, specifically Apple AirDrop and Google/Samsung Quick Share. Utilizing the custom "AIRFUZZ" protocol-aware fuzzer, the study uncovered systemic flaws in how privileged daemons process unauthenticated, complex serialized content such as Binary Plists, CPIO archives, and Protocol Buffers. Exploitation vectors include Swift-based Denial of Service (DoS), XML recursion, and memory corruption via Heap Use-After-Free (UAF). Most significantly, the research demonstrated a complete bypass of Device-to-Device (D2D) encryption in Samsung Quick Share. These vulnerabilities affect over 5 billion devices globally. All affected vendors—Apple, Google, and Samsung—have released patches to remediate these flaws.

AMOS Stealer Deployment via ClickFix Social Engineering on macOS

Threat actors are deploying the AMOS Stealer on macOS by adapting the "ClickFix" social engineering technique. The attack leverages browser-based lures masquerading as AI tool errors (e.g., ChatGPT, Grok), prompting users to manually copy and execute a malicious command in the macOS Terminal. This sequence bypasses browser security and Gatekeeper by utilizing curl or wget to download a DMG file, which is then silently mounted via hdiutil. The primary objective is the exfiltration of browser passwords, session cookies, and cryptocurrency wallets.

Gaslight Malware: Adversarial Prompt Injection Targeting macOS and LLM-Based SOC Triage

Gaslight (macOS.Gaslight) is a Rust-based backdoor attributed to North Korean (DPRK) state-sponsored actors, designed for browser credential harvesting from Chrome, Brave, Firefox, and Safari on macOS. The implant utilizes the Telegram Bot API for command-and-control (C2) communications. Its primary innovation is the integration of 38 adversarial prompt injection strings embedded within the binary. These strings are engineered to deceive Large Language Models (LLMs) used by SOC analysts during triage, inducing AI refusals or hallucinated benign classifications to bypass automated analysis and extend attacker dwell time. Detection was initially facilitated by an Apple XProtect update.

Apple iPhone BootROM Vulnerability usbliter8

A critical hardware-level vulnerability in the Apple SecureROM (BootROM) enables privileged execution on A12 and A13 chipsets via the 'usbliter8' exploit. The flaw stems from a design weakness in the Synopsys DesignWare USB 2 (DWC2) controller, where a mismatch between DMA pointer increments and resets during USB Setup transactions triggers a buffer underflow. Attackers can bypass Pointer Authentication Codes (PAC) on A13 devices using heap corruption and interrupt handler manipulation to achieve EL1 privileged execution in Device Firmware Update (DFU) mode. Because the vulnerability exists in the immutable BootROM, it is unpatchable via software updates, requiring hardware replacement for full remediation.


LINK COPIED TO CLIPBOARD