Post by Augustine Chiagozie (@pabloexchange)
Weekly cybersecurity roundup: macOS malware, GitHub breach, Interpol arrests and AI database flaw.
Security researchers reported a new crypto-stealing malware called Reaper, which bypasses macOS protections through fake Apple update prompts and malicious AppleScript links. The malware targets browser data, password managers, crypto wallets, Telegram/iCloud data and sensitive files, then exfiltrates them through a Telegram bot.
GitHub also disclosed a breach of 3,800 internal repositories after an employee installed a compromised version of the Nx Console VS Code extension. The attackers attempted to steal developer credentials and cloud secrets, but GitHub said it quickly isolated the device and rotated critical keys.
Meanwhile, Interpol arrested 201 suspects across the Middle East and North Africa during Operation Ramz and seized 53 servers used for phishing, malware and online fraud. Europol also dismantled First VPN, a service allegedly used in extortion and data theft cases.
Another major risk was found in ChromaDB, a vector database used in AI applications. Researchers said the flaw could allow malicious ML models to execute code before authentication checks are completed, putting exposed Python-based deployments at risk.

0 likes · 0 comments · 0 shares