< Back to situations

We’ll email you as it develops, and you can follow the whole thread from day one.

[SITUATION] · [ACTIVE]

3 clusters · 11 sources · 24 days · First seen · Last updated

Categories: TECHNOLOGY

macOS malware and security vulnerabilities

Entities: Apple Inc. · Wojciech Reguła · Gatekeeper · XProtect · macOS

Overview

In early July 2026, Jamf Threat Labs identified a social‑media campaign that used sponsored X posts to impersonate the macOS utility DynamicLake. The ads directed users to a counterfeit site that prompted a Terminal command, installing the “MacSync” variant of the Atomic Stealer malware, which harvests passwords, cookies and cryptocurrency wallet files.

Later that month, researchers disclosed a macOS Gatekeeper design flaw that lets a previously verified application bundle be silently replaced with a malicious version after the initial code‑signing check. Demonstrations showed replacements of Signal, Brave, Slack and VS Code, with the vulnerability affecting non‑Mac App Store apps and requiring only user‑level access.

Apple classified the behavior as non‑fixable and closed the case without a patch, urging users to keep macOS and apps up‑to‑date and to favor App Store software. In parallel, Apple announced macOS 27 “Golden Gate,” a new XProtect‑based sandbox extension that protects specific Application‑Support directories used by browsers, cryptocurrency wallets and other apps, preventing unauthorized terminal access and allowing dynamic addition of protected locations. The combined incidents highlight a growing macOS threat landscape that blends social engineering, systemic verification gaps, and evolving platform defenses.

Timeline

  1. 1 day ago

    [TECHNOLOGY] 2 sources
    Apple macOS Gatekeeper flaw lets verified apps be silently replaced

    macOS Gatekeeper can be bypassed to replace verified apps silently, while macOS 27 adds sandbox protection for key folders via XProtect.

  2. 4 days ago

    [TECHNOLOGY] 7 sources
    Apple macOS Gatekeeper flaw enables silent replacement of trusted apps

    Researchers found macOS Gatekeeper trusts apps after first launch, allowing silent replacement of downloaded apps without warnings; Apple deemed it non‑critical and closed the case.

  3. 25 days ago

    [TECHNOLOGY] 2 sources
    Jamf Threat Labs uncovers X ad campaign delivering macOS malware

    Jamf Threat Labs reports a malicious X ad campaign masquerading as the DynamicLake macOS app, redirecting users to a fake site that installs a variant of Atomic Stealer malware.

Sources

appletvitalia.it · blogspan.net · cincodias.elpais.com · cnmo.com · cyberinsider.com · diariobitcoin.com · it-boltwise.de · laverdadnoticias.com · mactechnews.de · pcauthority.com.au · theregister.com