securityaffairs.com 4 Oct 2026, 07:58 UTC

CloudSyncD Mac Backdoor Hides Inside Fake Zoom Installer

CloudSyncD Mac Backdoor Hides Inside Fake Zoom Installer
CyberSIXT Evidence Panel Source marked as original reporting
CISA KEV Listed in KEV
Patch Patch Status Unknown
Threat Actor
KillSec

SECURITY Affairs’ Round 598 newsletter, published on 4 October 2026, is a roundup rather than a report on a single incident. Its featured coverage includes malware, vulnerabilities, cybercrime, artificial intelligence and state-linked activity.

Topics include the CloudSyncD macOS backdoor hidden in a fake Zoom installer; the critical GitLab AI Gateway flaw CVE-2026-90970; the Antino backdoor, which reportedly uses Microsoft 365 as a command-and-control channel; and vulnerabilities added to the US Cybersecurity and Infrastructure Security Agency’s Known Exploited Vulnerabilities catalogue.

The roundup also highlights several reports of confirmed or alleged active exploitation, including Roundcube SQL injection flaw CVE-2026-48842, two Citrix NetScaler zero-days, and Apple CoreGraphics zero-day CVE-2026-86950. Other items cover the dismantling of the KillSec ransomware group, breaches affecting Japanese railway operators and a Pentagon personnel agency, a reported exposure involving nearly 400,000 Medicaid beneficiaries, and investigations into ShinyHunters and Russian-linked surveillance activity.

The international press section links to external reporting on these subjects, as well as research into AI agents attempting SQL injection, conducting reconnaissance and targeting government websites. The newsletter itself does not provide detailed technical guidance or additional evidence beyond summarising and linking to the individual reports.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline