Verified X ad spreads Mac malware, while ConsentFix steals Microsoft accounts


Cybercriminals are finding new ways to trick people into compromising their own devices and accounts. One campaign used a sponsored ad on X to target Mac users, while another technique, dubbed ConsentFix, steals Microsoft 365 accounts without installing malware.

Researchers have discovered a ClickFix-style attack running as a sponsored advertisement on X. The ad was posted from a verified account, adding an extra layer of credibility to the scam.

ClickFix campaigns use convincing lures—historically fake “human verification” screens, and now a fake download for DynamicLake, a legitimate macOS utility that turns your MacBook’s notch into an unofficial but functional version of Apple’s Dynamic Island. This type of attack requires the user to paste a command from the clipboard, making it depend heavily on user interaction.

Read more…
Source:  MalwareBytes Labs


Sign up for the Cyber Security Review Newsletter
The latest cyber security news and insights delivered right to your inbox


Related:

  • Australia: Rogue AI agents worked together for months to gain access to government health data

    September 24, 2026

    A swarm of OpenAI rogue AI agents appear to have gone on a spree of trying to access Australian government health data, in what some researchers say is the first autonomous hack of a government website. Communications between AI agents and other traces of their efforts found by researchers from US non-profit Transluce show how hundreds ...

  • CVE-2026-94127: Critical Unauthenticated RCE in F5 BIG-IP APM

    September 23, 2026

    On September 22, 2026, F5 published a security advisory for CVE-2026-94127, a critical heap-based buffer overflow vulnerability affecting F5 BIG-IP Access Policy Manager (APM). The vulnerability has a CVSS v3.1 score of 9.8. An unauthenticated attacker with network access to an affected virtual server may be able to achieve remote code execution (RCE) by sending ...

  • ShinyHunters hackers say they breached FBI, stole data on bureau employees

    September 22, 2026

    The digital extortion group known as “ShinyHunters” said on Tuesday that it had breached the Federal Bureau of Investigation and stolen data on a huge number of current and former FBI employees. The bureau did not respond to repeated messages seeking comment on Tuesday. In a statement posted to its dark-web site and during an online chat ...

  • Meta Muse already has a majorly worrying zero-day security issue

    September 22, 2026

    Meta’s new Artificial Intelligence (AI) assistant Muse reportedly carried a zero-day vulnerability that allowed attackers to gain access to people’s apps, such as WhatsApp or email. However, it’s not as straightforward as your usual zero-day – to exploit it, simply deploying malware will not suffice. Certain features need to be enabled, and certain integrations established before ...

  • Unmasking EvilTokens: Getting to the root of device code phishing

    September 22, 2026

    Following its emergence in February 2026, EvilTokens quickly became one of the most widely used phishing-as-a-service (PhaaS) platforms, providing cybercriminals with AI capabilities for tailoring phishing lures and analyzing compromised inboxes to identify high-value targets. This AI-powered cybercrime platform facilitated sophisticated business email compromise (BEC) campaigns that compromised more than 12,000 inboxes in over 10,000 ...

  • Google’s Gemini is the latest AI model to hack other companies

    September 19, 2026

    Google’s Gemini accessed the protected systems of three other companies in what The Wall Street Journal reports were the AI model’s first autonomous hacks. Similar to OpenAI’s breach of Hugging Face, the Gemini hacks were less noteworthy for being particularly sophisticated and more for the fact that they were conducted by an AI model. These breaches ...