:

MACSYNC MALWARE NOW SPREADS VIA ICLOUD CALENDARS

SECURITY DESK■ 1 MIN READ
THU, SEP 24, 2026

■ AI-SUMMARIZED FROM 1 SOURCE ▸ TIMELINE

A new MacSync malware variant targeting macOS systems exploits public iCloud calendar events to deliver updated native payloads. The technique represents a shift in the malware's distribution strategy.

Security researchers identified the updated MacSync variant using Apple's iCloud calendar service as a command-and-control mechanism. The malware creates or accesses publicly shared calendar events to retrieve instructions for downloading and executing new payloads on infected systems. This method leverages legitimate Apple infrastructure, potentially evading network-based detection systems that typically flag suspicious domains and servers. By embedding malicious instructions within calendar event metadata, attackers can update compromised machines without traditional server communication patterns. MacSync primarily targets macOS users through trojanized applications and malicious downloads. Previous versions relied on conventional distribution channels and C2 servers. Apple users should verify calendar sharing settings and monitor for unexpected calendar invitations or modifications. Security teams recommend maintaining current system patches and using endpoint detection tools capable of analyzing calendar service activity.

■ SOURCES

► Bleeping Computer

■ SUMMARY WRITTEN BY AI FROM THE LINKS ABOVE

■ MORE FROM THE SECURITY DESK

A new botnet called Carbonato is exploiting exposed Docker daemons to install the Hermes Agent AI framework and commandeer infected systems. The malware targets insecure Docker configurations to establish control over hosts.

JUST NOW— AI Desk

GitHub has failed to remove malicious imitation software from its platform three weeks after being reported, raising concerns about the platform's security response times.

2H AGO— Dev Desk

Darktrace CEO Ed Jennings warns that autonomous AI agents represent an emerging insider threat as companies deploy systems with access to sensitive data. The cybersecurity firm is launching new tools to monitor shadow AI, agent identities, and behavioral patterns.

2H AGO— AI Desk

Private GitLab project email addresses designed for developers to push code are being publicly exposed in README files and contribution guides, creating a security vulnerability for attackers to inject malicious code.

3H AGO— AI Desk

■ SUBSCRIBE TO THE DAILY BRIEF

ONE EMAIL, 5 STORIES, 06:00 UTC. UNSUBSCRIBE ANYTIME.