macOS Users Targeted by Fake Zoom Installer Carrying CloudSyncD Backdoor
The dropper “carries a complete universal Mach-O inside itself, roughly 756 KB in the development build, and extracts it at runtime.
Excerpt from the primary source: SecurityWeek
Who is affected
Home users · Small businesses · Enterprises
What you should do · Be aware
No immediate action is indicated. Share this with the relevant teams and watch for updates.
Automated guidance based on this story's classification. Check the linked advisories for specifics.
Sources
We link to original and authoritative sources. Headlines and excerpts belong to their publishers.
Original reporting
Related
Apple Multiple Products Out-of-Bounds Write Vulnerability (CVE-2026-86950) is being actively exploited, CISA warns
CISA added CVE-2026-86950 (Apple Multiple Products) to its Known Exploited Vulnerabilities catalog on September 29, 2026, which means there is reliable evidence of exploitation in the wild. Apple iOS, macOS, and iPadOS contain an out-of-bounds write vulnerability in CoreGraphics that may lead to arbitrary code execution.
CISA lists this as exploited in the wild. Unpatched macOS and iOS & iPadOS systems are exposed to active attacks now.
Treat this as an emergency.
Alleged dev of Ploutus ATM malware appears in US court after arrest
The U.S. Department of Justice has announced the arrest of the alleged developer of Ploutus malware, used to steal millions of dollars in ATM jackpotting attacks across the United States.
Linux Backdoor Abuses STUN Protocol, Exploits Dozens of Flaws
ClingSTUN operates as a back-connect proxy backdoor, sets up persistence, and contains exploits for self-propagation.
Judge dismisses spyware case brought by Salvadoran journalists targeted with Pegasus
The plaintiffs, who all worked for the independent and Salvadoran news outlet El Faro, failed to convince the court that their case had jurisdiction in California, according to the judge’s order.
