View Ridge Security
Back to Cyber HoseActive Exploits & Incidents

New XCSSET malware variant targets macOS developers via compromised

๐Ÿšจ ACTIVE EXPLOITATION

  • New XCSSET malware variant targets macOS developers via compromised Xcode projects XCSSET malware infects macOS developers through compromised Xcode projects and GitHub repositories.
    • Targets macOS developers using Xcode projects and GitHub repositories
    • Malware spreads by injecting downloader scripts into benign Xcode project files
    • Version 40 includes Chrome hijacker and Telegram trojanizer modules
    • Uses evasion techniques like loader recompilation, encryption, and macOS security disabling
    • Infection chain enables credential theft, keystroke logging, browser hijacking, and data exfiltration ๐Ÿ“Ž Coverage: bleepingcomputer.com ยท ๐Ÿ‘ via BleepingComputer

๐Ÿ’ฅ BREACHES & INCIDENTS

  • Beacon CRM hacked, exposing contact data of multiple UK cultural and charity organisations Beacon CRM suffered a cyberattack exposing contact data of numerous cultural and charity organisations.

    • Applies to customers of Beacon CRM, including English National Ballet, Chiswick House and Gardens Trust, Centre for Sustainable Energy
    • Data exposed includes names, email addresses, business phone numbers, business addresses, donation dates and amounts
    • Attack involved unauthorized access via compromised credentials and likely downloading of database backups
    • No passwords, payment details, or bank account information were exposed
    • Incident discovered on July 29, 2026; forensic investigation and containment actions underway ๐Ÿ“Ž Coverage: artsprofessional.co.uk ยท ๐Ÿ“„ Original: cse.org.uk ยท ๐Ÿ‘ via @campuscodi@mastodon.social
  • Coinkite halts Coldcard wallet sales after $100M theft via hardware exploit Hackers exploited a bug in Coinkite Coldcard hardware wallets to steal nearly $100 million.

    • Applies to Coinkite Coldcard hardware crypto wallets with vulnerable firmware
    • Attack exploited a firmware bug allowing theft of funds from offline wallets
    • Coinkite destroyed all remaining vulnerable Coldcard inventory and halted shipments
    • Patched firmware prevents new seeds from being compromised but not existing ones
    • Other wallets like SATSCARD, OPENDIME, and TAPSIGNER are unaffected ๐Ÿ“Ž Coverage: blog.coinkite.com ยท ๐Ÿ“„ Original: blog.coinkite.com ยท ๐Ÿ‘ via @campuscodi@mastodon.social

๐Ÿ•ต๏ธ RESEARCH & DEEP DIVES

  • Smoke#Screen Campaign Uses ScreenConnect RMM for Persistent Phishing Attacks Attackers use phishing to deliver ScreenConnect RMM for persistent remote access.

    • Targets organizations using ScreenConnect Remote Monitoring and Management (RMM) tool
    • Employs diverse social engineering lures including fake Zoom and Adobe updates, document requests, and system maintenance prompts
    • Delivers rotating payloads such as VBScript droppers, batch loaders, .NET executables, and HTML phishing pages
    • Installs ScreenConnect agent silently to maintain legitimate-appearing remote access on Windows and macOS
    • Uses evasion techniques like Cloudflare tunnels, Dropbox, and ConnectWise-signed binaries to bypass detection ๐Ÿ“Ž Coverage: darkreading.com ยท ๐Ÿ‘ via Dark Reading
  • 77 Open VSX Extensions Impersonated Legitimate Tools to Harvest Developer Info 77 malicious Open VSX extensions harvested developer environment data.

    • Targets: Developers using Open VSX marketplace extensions
    • Malicious extensions impersonated legitimate tools with low version numbers (mostly 0.0.1)
    • Data exfiltration included system info, Git metadata, CI environment details, and workspace paths
    • Extensions communicated with mangorbit.com domains to send harvested data
    • No source code, credentials, or tokens were accessed, but extensive environment profiling was done ๐Ÿ“Ž Coverage: bleepingcomputer.com ยท ๐Ÿ‘ via BleepingComputer

๐Ÿ“Œ OTHER

  • Microsoft Defender isolates QNET endpoint in 128 seconds to stop ransomware attack Microsoft Defender automatically isolated a compromised QNET endpoint to stop a ransomware attack.
    • Applies to QNET, a global direct-selling company using Microsoft Defender with attack disruption enabled
    • Attack involved a multi-stage ransomware using living-off-the-land (LOL) techniques on a compromised Windows endpoint
    • Defender used new device isolation action to block all external network connectivity within 128 seconds
    • Isolation prevented second-stage payload persistence, lateral movement, credential theft, and data exfiltration
    • Device isolation is AI-driven, triggered at 99% confidence, and maintains access to security services during isolation ๐Ÿ“Ž Coverage: microsoft.com ยท ๐Ÿ“„ Original: microsoft.com ยท ๐Ÿ‘ via Microsoft Security Blog

๐Ÿ”“ CVEs & KEV

Need help assessing your exposure?

Start with the free Posture Self-Check to see where you stand against the current threat landscape.

Free Posture Self-Check