Get alerts on this situation
We’ll email you as it develops, and you can follow the whole thread from day one.
Unsubscribe anytime.
[SITUATION] · [ACTIVE]
3 clusters · 11 sources · 24 days · First seen · Last updated
Categories: TECHNOLOGY
macOS malware and security vulnerabilities
Entities: Apple Inc. · Wojciech Reguła · Gatekeeper · XProtect · macOS
Overview
In early July 2026, Jamf Threat Labs identified a social‑media campaign that used sponsored X posts to impersonate the macOS utility DynamicLake. The ads directed users to a counterfeit site that prompted a Terminal command, installing the “MacSync” variant of the Atomic Stealer malware, which harvests passwords, cookies and cryptocurrency wallet files.
Later that month, researchers disclosed a macOS Gatekeeper design flaw that lets a previously verified application bundle be silently replaced with a malicious version after the initial code‑signing check. Demonstrations showed replacements of Signal, Brave, Slack and VS Code, with the vulnerability affecting non‑Mac App Store apps and requiring only user‑level access.
Apple classified the behavior as non‑fixable and closed the case without a patch, urging users to keep macOS and apps up‑to‑date and to favor App Store software. In parallel, Apple announced macOS 27 “Golden Gate,” a new XProtect‑based sandbox extension that protects specific Application‑Support directories used by browsers, cryptocurrency wallets and other apps, preventing unauthorized terminal access and allowing dynamic addition of protected locations. The combined incidents highlight a growing macOS threat landscape that blends social engineering, systemic verification gaps, and evolving platform defenses.
Timeline
-
1 day ago
[TECHNOLOGY] 2 sourcesApple macOS Gatekeeper flaw lets verified apps be silently replacedmacOS Gatekeeper can be bypassed to replace verified apps silently, while macOS 27 adds sandbox protection for key folders via XProtect.
-
4 days ago
[TECHNOLOGY] 7 sourcesApple macOS Gatekeeper flaw enables silent replacement of trusted appsResearchers found macOS Gatekeeper trusts apps after first launch, allowing silent replacement of downloaded apps without warnings; Apple deemed it non‑critical and closed the case.
-
25 days ago
[TECHNOLOGY] 2 sourcesJamf Threat Labs uncovers X ad campaign delivering macOS malwareJamf Threat Labs reports a malicious X ad campaign masquerading as the DynamicLake macOS app, redirecting users to a fake site that installs a variant of Atomic Stealer malware.
Sources
appletvitalia.it · blogspan.net · cincodias.elpais.com · cnmo.com · cyberinsider.com · diariobitcoin.com · it-boltwise.de · laverdadnoticias.com · mactechnews.de · pcauthority.com.au · theregister.com