An actively exploited authentication flaw (CVE-2026-65400) in macOS Screen Sharing allows attackers to access devices without valid credentials, so organizations should patch affected systems immediately.
CISA has added four critical, actively exploited vulnerabilities in macOS, SharePoint, vCenter and Microsoft IKE to the KEV catalog, including CVE-2026-65400 with a CVSS score…
A ClickFix campaign spanning over 250 domains now employs browser fingerprinting to lock out security researchers and display a fake malware lure exclusively to genuine…
A North Korean hacking group expands its macOS attacks with a new ClickFix tactic that leads to malware installation through fake system crash notifications and…
TeamViewer users on macOS must expect that attackers may be able to bypass their 2FA protection measures under certain conditions and gain remote access.
Under certain conditions, attackers can replace code in macOS apps and execute them without triggering security warnings, undermining the system’s security mechanisms.
Security researchers demonstrated manipulation of macOS apps through local package tampering without Gatekeeper blocking it, but Apple does not classify this as a security vulnerability.