:

MACSYNC MALWARE NOW SPREADS VIA ICLOUD CALENDARS

SECURITY DESK■ 1 MIN READ
THU, SEP 24, 2026

■ AI-SUMMARIZED FROM 1 SOURCE ▸ TIMELINE

A new MacSync malware variant targeting macOS systems exploits public iCloud calendar events to deliver updated native payloads. The technique represents a shift in the malware's distribution strategy.

Security researchers identified the updated MacSync variant using Apple's iCloud calendar service as a command-and-control mechanism. The malware creates or accesses publicly shared calendar events to retrieve instructions for downloading and executing new payloads on infected systems. This method leverages legitimate Apple infrastructure, potentially evading network-based detection systems that typically flag suspicious domains and servers. By embedding malicious instructions within calendar event metadata, attackers can update compromised machines without traditional server communication patterns. MacSync primarily targets macOS users through trojanized applications and malicious downloads. Previous versions relied on conventional distribution channels and C2 servers. Apple users should verify calendar sharing settings and monitor for unexpected calendar invitations or modifications. Security teams recommend maintaining current system patches and using endpoint detection tools capable of analyzing calendar service activity.

■ SOURCES

► Bleeping Computer

■ SUMMARY WRITTEN BY AI FROM THE LINKS ABOVE

■ MORE FROM THE SECURITY DESK

A cross-site request forgery (CSRF) vulnerability in the popular Elementor WordPress plugin could allow unauthenticated attackers to create administrator accounts on affected sites.

1H AGO— Industry Desk

The Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning about active exploits targeting critical vulnerabilities in SharePoint, WSO2, and Adobe Commerce. Attackers are actively leveraging these flaws in real-world attacks.

2H AGO— Security Desk

Multiple Supabase customers have inadvertently exposed sensitive user data online due to misconfiguration and inadequate security settings. The incidents underscore risks inherent in rapidly deployed AI-generated and minimally-configured applications.

2H AGO— Industry Desk

File transfer platform Kiteworks has urged customers to shut down their servers after receiving a credible threat of an imminent cyberattack from law enforcement.

4H AGO— Security Desk

■ SUBSCRIBE TO THE DAILY BRIEF

ONE EMAIL, 5 STORIES, 06:00 UTC. UNSUBSCRIBE ANYTIME.