macOS Users Targeted by Fake Zoom Installer Carrying CloudSyncD Backdoor
The dropper “carries a complete universal Mach-O inside itself, roughly 756 KB in the development build, and extracts it at runtime.
The dropper “carries a complete universal Mach-O inside itself, roughly 756 KB in the development build, and extracts it at runtime.
Hi everyone! We've just released Chrome Beta 156 (156.0.8078.3) for iOS; it'll become available on App Store in the next few days. You can see a partial list of the changes in the Git log . If you find a new issue, please let us know by filing a bug . Chrome Release Team Google Chrome…
Hi everyone! We've just released Chrome Stable 155 (155.0.8059.24) for iOS; it'll become available on App Store in the next few hours. This release includes stability and performance improvements. You can see a full list of the changes in the Git log . If you find a new issue, please let us know by filing a bug . Chrome Release Team Google Chrome…
'Hit and run' iPhone malware known as DarkSword is part of a wave of Russian attacks on iOS and Android devices, according to Ukraine's SSSCIP.
CISA added CVE-2026-86950 (Apple Multiple Products) to its Known Exploited Vulnerabilities catalog on September 29, 2026, which means there is reliable evidence of exploitation in the wild. Apple iOS, macOS, and iPadOS contain an out-of-bounds write vulnerability in CoreGraphics that may lead to arbitrary code execution.
CISA lists this as exploited in the wild. Unpatched macOS and iOS & iPadOS systems are exposed to active attacks now.
Treat this as an emergency.
Apple released security updates to fix a zero-day vulnerability exploited in "extremely sophisticated" targeted attacks on iOS devices.
Source reporting says attackers are already exploiting this, so exposed iOS & iPadOS systems are at immediate risk.
Treat this as an emergency.
Hi everyone! We've just released Chrome Beta 155 (155.0.8059.16) for iOS; it'll become available on App Store in the next few days. You can see a partial list of the changes in the Git log . If you find a new issue, please let us know by filing a bug . Chrome Release Team Google Chrome…
Hi everyone! We've just released Chrome Stable 154 (154.0.8037.55) for iOS; it'll become available on App Store in the next few hours. This release includes stability and performance improvements. You can see a full list of the changes in the Git log . If you find a new issue, please let us know by filing a bug . Chrome Release Team Google Chrome…
CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2026-7273 Zyxel GS1900 Series Switches Stack-Based Buffer Overflow Vulnerability This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise. Binding Operational Directive (BOD) 26-04: Prioritizing…
CISA lists this as exploited in the wild. Unpatched BIG-IP and Multiple Products systems are exposed to active attacks now.
Treat this as an emergency.
The latest developments from the last 30 days, newest first.
macOS Users Targeted by Fake Zoom Installer Carrying CloudSyncD Backdoor
Basis: Reporting by SecurityWeek
Chrome Beta for iOS Update
Basis: Google Chrome Releases (vendor advisory)
Chrome Stable for iOS Update
Basis: Google Chrome Releases (vendor advisory)
Mobile malware warning from Ukrainian researchers includes iPhone exploit kit
Basis: Reporting by The Record by Recorded Future News
UPDATE: severity raised to critical: Apple Multiple Products Out-of-Bounds Write Vulnerability (CVE-2026-86950) is being actively exploited, CISA warns
Basis: CISA Known Exploited Vulnerabilities (government advisory)
Apple Multiple Products Out-of-Bounds Write Vulnerability (CVE-2026-86950) is being actively exploited, CISA warns
Basis: CISA Known Exploited Vulnerabilities (government advisory)
CVE-2026-86950 added to CISA KEV: Apple Multiple Products, Apple Multiple Products Out-of-Bounds Write Vulnerability
Basis: CISA Known Exploited Vulnerabilities catalog
Apple patches CoreGraphics zero-day flaw exploited in attacks
Basis: Reporting by BleepingComputer
Apple Multiple Products
Apple Multiple Products Out-of-Bounds Write Vulnerability
Apple macOS
Apple macOS Improper Authentication Vulnerability
Apple Multiple Products
Apple Multiple Products Buffer Overflow Vulnerability
Apple Multiple Products
Apple Multiple Products Improper Locking Vulnerability
Apple Multiple Products
Apple Multiple Products Classic Buffer Overflow Vulnerability
Apple Multiple Products
Apple Multiple products Use-After-Free Vulnerability
Apple Multiple Products
Apple Multiple Products Integer Overflow or Wraparound Vulnerability
Apple iOS and iPadOS
Apple iOS and iPadOS Use-After-Free Vulnerability
Apple Multiple Products
Apple Multiple Buffer Overflow Vulnerability
Apple Multiple Products
Apple Multiple Products Use-After-Free WebKit Vulnerability
Apple Multiple Products
Apple Multiple Products Unspecified Vulnerability
Apple iOS, iPadOS, and macOS
Apple iOS, iPadOS, and macOS Out-of-Bounds Write Vulnerability
Apple Multiple Products
Apple Multiple Products Unspecified Vulnerability
Apple Multiple Products
Apple Multiple Products Memory Corruption Vulnerability
Apple Multiple Products
Apple Multiple Products Arbitrary Read and Write Vulnerability
Apple Multiple Products
Apple Multiple Products WebKit Out-of-Bounds Write Vulnerability
Apple iOS and iPadOS
Apple iOS and iPadOS Incorrect Authorization Vulnerability
Apple Multiple Products
Apple Multiple Products Use-After-Free Vulnerability
Apple Multiple Products
Apple Multiple Products Code Execution Vulnerability
Apple Multiple Products
Apple Multiple Products Cross-Site Scripting (XSS) Vulnerability