XCSSET evolves again: Analyzing the latest updates to XCSSET’s inventory


Microsoft Threat Intelligence has identified yet another XCSSET variant in the wild that introduces further updates and new modules beyond those detailed in our March 2025 blog post.

The XCSSET malware is designed to infect Xcode projects, typically used by software developers, and run while an Xcode project is being built. We assess that this mode of infection and propagation banks on project files being shared among developers building Apple or macOS-related applications. This new variant of XCSSET brings key changes related to browser targeting, clipboard hijacking, and persistence mechanisms.

Read more…
Source: Microsoft


Sign up for the Cyber Security Review Newsletter
The latest cyber security news and insights delivered right to your inbox


Related:

  • Scammers target OnlyFans users with deepfakes

    August 6, 2026

    OnlyFans creators are used to posting adult videos of themselves online, but what happens if someone takes control of their images and uses them for fraud? This week, USA Today revealed how criminals are impersonating OnlyFans creators using AI tools. They use deepfake content to lure the real models’ fans with fake promises of live chats, and ...

  • Token Jacking: Cybercriminals Could Be Stealing Your AI Resources

    August 6, 2026

    It’s three a.m., do you know what your AI agent is doing? Unit 42 has responded to a growing number of AI token jacking cases resulting in staggering financial losses. The financial loss comes from criminals gaining access to API keys used by legitimate developers for access to popular AI platforms. These keys are known ...

  • TP-Link router owners update now — 15 flaws patched to stop hackers hijacking your devices

    August 5, 2026

    TP-Link has patched more than a dozen vulnerabilities across multiple business networking products which could have been chained to achieve remote code execution (RCE). Security researchers at Vedere Labs from Forescout found the flaws and published an in-depth report on the issues, which particularly affect TP-Link Omada, the company’s business networking platform for centrally managing enterprise and small-business ...

  • How legitimate cloud platforms enable phishers to bypass MFA

    August 4, 2026

    Threat actors are increasingly exploiting legitimate cloud services to evade detection and streamline the deployment of their scam infrastructure. Cloud hosting services and decentralized networks have become primary platforms for hosting phishing pages and sites. Throughout 2025 and 2026, Kaspersky researchers have observed phishing operators steadily migrate toward platforms like Cloudflare Workers, Vercel, Netlify, GitHub ...

  • CVE-2026-18577: N-able N-central Authentication Bypass Exploited in the Wild

    August 4, 2026

    On August 2, 2026, N-able published a security advisory for CVE-2026-18577, an authentication bypass vulnerability affecting N-central that was discovered being exploited in-the-wild after an incomplete fix for an earlier authentication bypass issue, CVE-2026-18556 was disclosed. CVE-2026-18577 allows a remote unauthenticated attacker to bypass authentication and obtain administrative control of vulnerable N-central servers in affected deployments. N-able N-central is a widely deployed Remote ...

  • Over 100,000 UK Police and staff have personal data leaked in attack on national database

    August 4, 2026

    The UK’s Police National Legal Database (PNLD) suffered a cyberattack recently, in which it allegedly lost sensitive data on more than 100,000 criminal justice professionals. In a short press release, PNLD confirmed the breach, saying it happened over a weekend. The threat actors, which were not named in the announcement, were said to have taken names, organizations, and ...