Jamf Threat Labs flagged a new version of the PamStealer macOS infostealer that can only be unpacked with the attacker's server. Earlier variants embedded payload key material directly in the JavaScript for Automation dropper, but the latest completes a key exchange with the server before the payload unwraps, so it cannot be recovered from a static sample alone. The lure also changed: where July and August versions impersonated the Maccy, Scoppr, and Nancy Clipboard apps, victims are now drawn to a fake site advertising a non-existent cryptocurrency wallet called Wavel. Clicking Download for macOS retrieves a disk image whose AppleScript opens Script Editor with instructions to run the dropper.
AdaptHealth, a US network of more than 680 medical-equipment facilities, confirmed that a breach attributed to the ShinyHunters group exposed the personal, health, and insurance information of about 4.1 million people. The attackers got in by socially engineering a third-party contractor's privileged account, then reached AdaptHealth's cloud business applications, patient-management systems, and electronic health record portals, and stole a password file tied to insurance billing. It fits ShinyHunters' pattern of tricking a person into handing over access to connected cloud services, and it is the latest in a wave of large healthcare breaches this year alongside Aesto, CareCloud, and McKesson. Social security and financial data were reportedly not taken.
Microsoft Threat Intelligence detailed a macOS ClickFix operation spanning more than 250 domains that now fingerprints visitors before deciding whether to show a malware lure. The server-side gate hides the malicious page from crawlers and sandboxes while presenting selected Mac users with a fake software download, an anti-analysis layer rather than a change to the attack itself. The lure still requires the victim to copy and run an obfuscated command in Terminal, which fetches scripts and installs an infostealer, in this case Atomic Stealer, that targets credentials, browser data, authentication stores, and cryptocurrency wallets. Many domains follow a dictionary-word naming pattern using the word file.
Sophos detailed a campaign, tracked as STAC4749, in which attackers impersonate IT help desk staff over Microsoft Teams to talk employees into granting remote access, then deploy Chaos ransomware. Using external Teams accounts, the operators start chats and voice calls claiming to fix an urgent problem, persuade the target to open a remote support session, and run PowerShell to pull down a modular toolkit for persistence and lateral movement. Between February and June 2026 they hit dozens of North American organizations, about 95 percent in the US and Canada, across services, manufacturing, energy, and construction. In one case they went from first contact to encrypting files in under seventeen hours.
Okta warns of a campaign that phones Microsoft 365 users and talks them through what looks like setting up a passkey, but is actually a phishing kit that hands their account to the attacker. Active since April, the operators register passkey-themed domains and call targets, exploiting unfamiliarity with how passkeys really work. The kit mimics Microsoft's passkey enrollment without registering a real passkey, and pushes the victim to "save a recovery key" that the attacker controls, capturing the access needed to take over the account. The campaign, aimed at extortion, notably targets the passkey adoption process itself, turning a security upgrade into a social-engineering opening.
Dark Reading reports a ransomware campaign that leans on impersonating Interpol to pressure small businesses, using straightforward social engineering rather than sophisticated tooling. By dressing up their demands as communications from the international police organization, the attackers try to intimidate owners and staff who may lack dedicated security teams into believing they are in legal trouble and paying up. The campaign spans several regions, including the United States, Europe, and the Middle East. It is a reminder that authority-themed impersonation remains effective against smaller organizations, where a convincing-looking notice can short-circuit normal caution and verification.
Push Security reports that attackers are creating OpenAI organizations that impersonate legitimate companies and inviting employees, including at cybersecurity firms, to join them, aiming to trick people into entering sensitive company information into chats and projects under attacker control. The danger is that the invitations come from OpenAI's own infrastructure, so they are genuine messages and slip past email security controls that would catch ordinary phishing. It is a reminder that trusted SaaS platforms can be turned into phishing channels through their normal invitation features, where the message itself is legitimate even though the inviting organization is fraudulent. Verification of unexpected invites is the key defense.
The FBI and CISA have updated an earlier warning about Russian intelligence targeting Signal accounts, noting the operators have added a step: tricking targets into handing over their Signal backup recovery key. With that key, an attacker can restore the account's backup, read its private and group message history, and take over the account, and the key keeps working afterward. The campaign uses social engineering against high-value targets such as government officials, military personnel, and journalists. It reflects a broader shift toward stealing the recovery and session secrets that sit behind multi-factor authentication rather than attacking the login directly.
Attackers are abusing Shop, the order-tracking app from Shopify, by getting fake purchase receipts to appear in users' order histories, then using them to lure victims into callback phishing. Because the bogus orders show up inside a legitimate, trusted app rather than in an easily spotted scam email, they look convincing. The fake receipts typically reference an unexpected charge and a phone number to call to dispute it; when the victim calls, the scammers pose as support staff and walk them into handing over sensitive information or account access. It is a twist on callback phishing that borrows credibility from a real shopping platform.
Kaspersky is tracking an active campaign that spreads through WhatsApp by hijacking real accounts and sending their contacts a script file disguised as a business or financial document, with no accompanying message. If a Windows user opens it, the script disables User Account Control protections and silently installs ManageEngine Endpoint Central, a legitimate IT remote-management tool, configured to connect to attacker servers and hand them remote control of the machine. Using trusted contacts and signed, legitimate software helps the attack slip past suspicion and many security tools. The campaign spans several countries, with most confirmed victims in Malaysia, and how the WhatsApp accounts are compromised is still unknown.