MACSYNC MALWARE NOW SPREADS VIA ICLOUD CALENDARS
■ AI-SUMMARIZED FROM 1 SOURCE ▸ TIMELINE
A new MacSync malware variant targeting macOS systems exploits public iCloud calendar events to deliver updated native payloads. The technique represents a shift in the malware's distribution strategy.
■ MORE FROM THE SECURITY DESK
A new botnet called Carbonato is exploiting exposed Docker daemons to install the Hermes Agent AI framework and commandeer infected systems. The malware targets insecure Docker configurations to establish control over hosts.
GitHub has failed to remove malicious imitation software from its platform three weeks after being reported, raising concerns about the platform's security response times.
Darktrace CEO Ed Jennings warns that autonomous AI agents represent an emerging insider threat as companies deploy systems with access to sensitive data. The cybersecurity firm is launching new tools to monitor shadow AI, agent identities, and behavioral patterns.
Private GitLab project email addresses designed for developers to push code are being publicly exposed in README files and contribution guides, creating a security vulnerability for attackers to inject malicious code.