Hack On macOS Allows Attackers To Take Screenshots

Share post:

Hackers have exploited a weakness in updated versions of macOS that allowed them to take screenshots on infected Macs without obtaining victims’ permission.

The zero-day was exploited by XCSSET, a malware discovered last August by TrendMicro, a security firm.

XCSSET used two zero-days to infect Mac developers with malware that stole browser files and cookies.

The malware also injected backdoors into websites, stole data from Skype and other apps, took screenshots, and encrypted files.

The infections came in the form of a malicious project that the hacker wrote for Xcode.

Xcode is a tool that Apple makes available to developers who write apps for macOS or other Apple operating systems.

Once an XCSSET project was opened and built, the malicious code ran on the user’s Mac, according to TrendMicro.

It is unlikely that XCSSET will infect Macs unless it has carried out a malicious Xcode project.

The majority of users should not worry unless they are developers who have used one of the projects.

For more information, read the original story in arstechnica.

Featured Tech Jobs

SUBSCRIBE NOW

Related articles

The US government and Its Microsoft dependency: A cybersecurity dilemma

Microsoft's series of high-profile cybersecurity failures has once again spotlighted the complex relationship between the tech giant and...

Cyber Security Today, Week in Review for week ending Friday, April 12, 2024

This episode features a discussion on Microsoft's cybersecurity troubles, worries about open source, a warning about abusing IT help desks to launch attack

Cyber Security Today, April 12, 2024 – A warning to Sisense customers, a new tactic for spreading the Raspberry Robin worm, and more

A warning to Sisense customers, a new tactic for spreading the Raspberry Robin worm, and more. Welcome to Cyber Security Today. It’s Friday April 12th, 2024. I’m Howard Solomon. Organizations that use products from business analytics provider Sisense [SI-SENSE] are being told to reset user login credentials and digital keys. The warning comes from the

Become a member

New, Relevant Tech Stories. Our article selection is done by industry professionals. Our writers summarize them to give you the key takeaways