THE DAILY BRIEFING

A clearer view of today.

The stories that matter. The context you need.

INDEPENDENT PERSPECTIVEFree to read.
Every day.

Cybersecurity

Your briefing

2 min read

AI-assisted briefingHow we put it together ↗

AT A GLANCE

  • The reported MacSync variant combines credential, wallet-data and file theft with a persistent backdoor, spreading through a promoted crypto-wallet app.
  • Fake desktop apps impersonating browser-only payroll platforms install ScreenConnect configured for covert attacker control.
  • Rapid7 reports Zimbra flaws that could let attackers falsify email, documents and calendars, potentially undermining the records employees use to verify business requests.
01

MacSync variant hides commands in iCloud Calendar to steal Mac users’ data

Kaspersky researchers say a new MacSync variant combines an infostealer with a persistent backdoor targeting credentials, cryptocurrency wallet data and files. The malware was distributed through a crypto-wallet app called Toria, promoted on X and Telegram, and reportedly uses an iCloud calendar to conceal malicious commands.

Why it matters Mac users installing Toria risk exposing ordinary files and credentials, not just crypto assets. The reported persistent backdoor also makes the threat more than a one-time data theft.

HelpNet Security ↗
02

Fake payroll apps install ScreenConnect to give attackers remote access

Allure Security found attackers offering desktop apps impersonating three major U.S. payroll and HR platforms that, according to the report, have never released desktop apps. Running an installer deploys ScreenConnect, a legitimate remote-access tool configured to let the attacker control the computer without the user’s knowledge.

Why it matters For users seeking payroll software, the immediate exposure is control of their computer—not merely disclosure of payroll credentials. The legitimate remote-access tool is configured to give the attacker access without an obvious warning to the user.

HelpNet Security ↗
03

Rapid7 says Zimbra flaws can let attackers manipulate email, calendars and documents

Rapid7 reports uncovering more than 50 vulnerabilities in Zimbra, including flaws that it says can allow attackers to impersonate senders without credentials, control inbox visibility, and alter shared documents and calendars. The report describes how such access could support business email compromise through fabricated messages, documents and meeting entries; it also cites prior Zimbra vulnerabilities that CISA added to its Known Exploited Vulnerabilities catalog.

Why it matters For organizations using Zimbra, checking a suspicious email against a shared document or calendar may not provide independent confirmation: the reported flaws could let an attacker falsify those records too.

What to watch next Rapid7 says further installments will cover technical details and broader findings from its Zimbra research; the supplied report gives no publication schedule.

Rapid7 ↗
04

Cyble details telecom risks from SS7 abuse, route hijacking and compromised routers

Cyble describes how weaknesses in SS7 and BGP can enable subscriber tracking or traffic diversion, and says newer mobile protocols do not eliminate all related risks. The report also cites a 2025 joint advisory that PRC state-sponsored actors target telecom routers and use compromised devices and trusted connections to move into other networks.

Why it matters For telecom providers and connected organizations, router compromise can extend beyond the carrier: the cited advisory describes attackers exploiting trusted connections to enter other networks.

Cyble ↗
Cybersecurity — September 25, 2026 | Briefing24