A sophisticated new malware targeting Mac users, named CrashStealer, has been discovered by security researchers at Jamf Threat Labs. It masquerades as Apple's legitimate crash-reporting software and was first identified in May 2026, with active attacks detected by early July. CrashStealer is designed to extract sensitive information, including browser credentials, password manager data, and cryptocurrency wallet information, and can copy the Mac login Keychain. It uses native C++ programming, encrypts collected files, and employs anti-debugging features.
The malware is distributed through a disk image labeled "Werkbit Setup," which features a polished installer that bypasses Mac security warnings by using a valid Apple Developer ID and notarization ticket. Once opened, it connects to GitHub for commands and downloads a script that installs a second disk image named CrashReporter.dmg, which mimics an Apple system component.
CrashStealer presents a fake password prompt resembling a legitimate macOS request, verifying entered passwords locally. It targets data linked to various browsers and password managers, scanning for approximately 80 cryptocurrency wallet extensions and 14 password managers. Stolen data is stored in hidden folders, encrypted using AES-256-GCM, and packaged into hidden ZIP archives before being uploaded.
Warning signs of infection include a website requiring a meeting PIN for download, unexpected password prompts, and unfamiliar apps requesting Full Disk Access. Users are advised to download apps from verified sources, avoid overriding security warnings, pause before entering passwords, review app permissions, install security updates, use antivirus software, and act quickly if they installed Werkbit Setup.
New research from Kaspersky surveyed 7,200 respondents globally and found that Generation Z spends 57% of their time online, primarily using smartphones (67% identify them as their main device). While 59% of Gen Z feel confident in navigating the digital landscape, only 28% consider their digital skills advanced. Alarmingly, only 27% use antivirus software on their mobile devices, and over half (52%) have encountered attacks on their devices or accounts. Significant data, such as personal photographs (38%) and passwords (30%), is stored on smartphones, yet only 28% regularly back up important data. Kaspersky recommends integrating cybersecurity into daily routines and has introduced an interactive game, “Case 404,” to educate Gen Z on recognizing digital threats.
Since June 23, Microsoft has been implementing a point-in-time restore feature on Windows 11, which is enabled by default for Home and Pro editions when the system drive exceeds 200 GB. This feature captures a complete snapshot of the machine approximately every 24 hours using the Volume Shadow Copy service, including system, applications, settings, and local files. Users can revert to a previous state in case of issues, but restoring from a snapshot older than 48 hours will erase all changes made since then, except for OneDrive data. The feature retains snapshots for up to 72 hours and reserves 2% of drive space, capped at 50 GB. If free space drops below 20 GB, older snapshots are deleted. Restoration occurs locally through WinRE, and users need a BitLocker recovery key if the drive is encrypted. After a restore, the feature pauses and requires user consent to resume. Snapshots from upgraded editions are not accessible, and only the Enterprise edition allows adjustments to snapshot settings. The feature can be disabled in system settings. It is not a backup solution, and users are advised to maintain separate backups for important files.
A cyber-espionage campaign has been identified involving a counterfeit Bahrain Alert Android application designed to surveil individuals in Bahrain and the Gulf region. The app masquerades as an official civil defense tool and employs social engineering tactics to compromise Android devices, extract sensitive data, and maintain remote access. It targets high-value individuals such as activists and journalists, particularly during civil unrest and missile alerts, leveraging trusted government branding to increase infection rates.
The malware features a complex, multi-stage architecture with advanced evasion techniques and is distributed through phishing links and malicious websites. It initiates a four-stage infection process, ultimately installing a remote access trojan (RAT) that enables covert surveillance and encrypted communications. The malware can monitor device activity, capture credentials, and intercept communications, while also employing mechanisms to avoid detection and maintain persistence.
The campaign primarily targets Bahraini citizens, exploiting fear during crises to encourage app installation. Although there are indications of Russian-speaking developers involved, there is no definitive attribution to a specific nation-state or APT group. Mitigation strategies include monitoring for suspicious app installations, user education on verifying app authenticity, and blocking known malicious domains.
The auditing process has traditionally been labor-intensive, requiring extensive document reviews. CLA (CliftonLarsonAllen LLP) partnered with the Databricks Forward Deployed Engineering team to develop a document processing application that reduces extraction time from hours to minutes while maintaining quality. The application is built on the Databricks platform, utilizing technologies like Lakebase Postgres, Databricks Apps, Lakeflow Jobs, MLflow, and Unity Catalog Volumes.
The application addresses challenges in document parsing, including unpredictable per-task latency, rate-limit-aware throttling, workload prioritization, cost attribution per task, and real-time progress visibility. It eliminates the need for multiple specialized systems by integrating components such as a web application for user interaction, Lakebase for state management, an orchestrator for task management, and AI agents for document processing.
The task queue is supported by two Postgres tables in Lakebase, tracking task status and execution attempts. Concurrency safety is ensured through a locking mechanism, and crash recovery is facilitated by lease-based locking. The orchestrator implements rate-limit-aware throttling and idempotent webhook callbacks to manage task processing effectively.
An operator dashboard provides real-time metrics on task status, agent performance, and workload costs, with live updates through Postgres LISTEN/NOTIFY events. Cost attribution is managed at the application level, allowing for detailed monitoring of expenditures. Lakebase enhances the orchestration process with features like autoscaling compute, OAuth-rotated authentication, Unity Catalog integration, and support for branching and snapshots.
An attacker is testing stolen passwords against a company with inadequate firewall protection, highlighting the flaws in traditional security measures. Modern attacks, including ransomware and phishing, have evolved, necessitating advanced threat protection (ATP) that incorporates artificial intelligence (AI) for improved threat detection and response. AI-driven ATP identifies attacks that conventional tools miss, such as fileless malware and targeted phishing, by learning normal operating patterns and flagging deviations. Traditional security relies on known malware signatures, which are ineffective against zero-day attacks and polymorphic malware that changes its identity. Cloud misconfigurations and hybrid security gaps further complicate security. AI enhances detection by focusing on malicious behaviors rather than just file signatures, allowing for rapid identification of threats. Automated incident response can isolate affected endpoints and terminate malicious processes quickly. Behavioral analytics and threat intelligence integration improve ATP effectiveness by understanding user behavior and recognizing attack patterns. AI-powered ATP significantly reduces breach containment time and false positives, shifting the focus from reactive cleanup to proactive prevention. Best practices for maximizing ATP include integrating it into existing security operations, keeping machine learning models updated, and regularly testing defenses against real-world threats.
An attacker is testing stolen passwords against a company that incorrectly believes its firewall is sufficient protection. Traditional defenses have become inadequate due to the speed and sophistication of modern attacks, including ransomware groups renting tools and phishing kits being easily accessible. Advanced threat protection (ATP) was designed to address these challenges, especially with the integration of artificial intelligence (AI). AI-powered ATP identifies attacks that conventional tools overlook, such as fileless malware and targeted phishing attempts, by learning the normal behavior of an organization’s environment and flagging anomalies.
Traditional security relies on identifying known malware through established fingerprints, which fails against novel threats like zero-day attacks and polymorphic malware. The rise of remote work and cloud services has introduced new risks due to misconfigurations and inconsistent security rules. AI enhances threat detection by focusing on malicious behavior rather than matching files against known threats, allowing for rapid detection and automated incident response.
Behavioral analytics establishes a baseline for users and devices, flagging deviations that may indicate insider threats or credential theft. Integrating threat intelligence provides insights into emerging threats and helps prioritize alerts. AI-driven ATP can contain breaches faster, significantly reducing the financial impact and dwell time of attackers. Best practices for maximizing ATP include integrating with security operations, ensuring comprehensive coverage, updating models regularly, conducting real-world testing, securing AI systems, and maintaining human oversight.
Google has introduced a passive sign-in feature for YouTube, allowing users to stay logged in across devices without actively entering their credentials.
Windows 11 is currently operating on 78.8% of Windows devices, while Windows 10 holds a 16.9% share. Microsoft ceased support for Windows 10 on October 14, 2025, making it vulnerable to security threats. Eligible Windows 10 devices can receive Extended Security Updates (ESU) until October 12, 2027, through a paid program, with free ESU available for users in the European Economic Area until October 14, 2026. Approximately 21.4% of devices in small and medium-sized businesses and 16.6% in large organizations still run Windows 10, often due to budget constraints. Devices in industries like healthcare and manufacturing are particularly slow to adopt Windows 11. Windows 10 devices face nearly three times the number of active vulnerabilities compared to Windows 11, with 66.6% rated as high or critical. About 2.8% of Windows 10 systems do not meet the hardware requirements for Windows 11. A total of 18.7% of Windows devices are running unsupported operating systems, with 22.2% on versions that will reach end of support within six months, totaling 40.9% of systems that are unsupported or soon to be. The consumer ESU program will expire on October 12, 2027, after which many devices will transition to unsupported status.