Apple's Spyware Alerts Reach 110 Countries (08/15/2026)
- › Apple sent mercenary spyware threat notifications to users in 110 countries on August 13, part of a program running since 2021 that has now reached more than 150 countries.
- › The ChainDrop worm poisoned 444 npm packages carrying roughly 2 billion monthly downloads, and it spreads through rebuilt tarballs rather than commits, so source review shows nothing.
- › AmnesiaStealer is a Rust infostealer for macOS delivered by a counterfeit GitHub page that talks the user into pasting a command into Terminal.
- › Seven people were arrested or charged over a 30 million euro Commerzbank fraud that ran for four days in November 2023.
- › Fortinet found Evooo1Bot converting exposed gateway devices from six vendors into SOCKS5 relay nodes.
Two of today’s five stories work by asking the target to help. AmnesiaStealer puts a counterfeit GitHub page in front of a developer and lets them paste the command themselves, and ChainDrop waits for someone to open an infected branch in their editor. The third is the opposite problem: Apple told users in 110 countries that they were individually targeted by mercenary spyware, and the hard part there is getting people to believe a warning that names them.
Top 5 Critical Security Alerts
1. Apple Notifies Spyware Targets in 110 Countries
Apple sent a new round of Threat Notifications on August 13 to users across 110 countries. The program has run multiple times a year since 2021 and has now reached people in more than 150 countries. Apple calls these high-confidence alerts that a user has been individually targeted, and recommends enabling Lockdown Mode, updating the device, and getting expert help. BleepingComputer
Operator Note: Apple does not send these speculatively, and it does not send them in bulk to a region. The historical target set was journalists, activists, politicians, and diplomats, which is exactly why a business reader files it as somebody else’s problem. Litigation, an acquisition, or a government contract puts your executives adjacent to that set, and the notification lands on a personal device your program does not manage.
2. ChainDrop Poisons 444 Packages Without Touching a Commit
The ChainDrop worm, a variant of Shai-Hulud, compromised 444 npm packages carrying roughly 2 billion monthly downloads. It self-replicates by rebuilding the package tarball around its own payload, so it never appears in the repository and reviewing the source shows nothing. It also writes startup hooks into repository configuration files, which means opening an infected branch in an editor kicks off background tasks that harvest credentials and keep the cycle going. Microsoft and other researchers identified it on August 4. The Register
Operator Note: Every supply chain control most teams bought reads the repository. This one lives in the artifact, so code review, branch protection, and commit signing all pass while the package you install is dirty. Verify what you pull from the registry rather than what you read on the web, and treat “opened the branch” as execution, because for this worm it is.
3. A Rust Infostealer Talks macOS Users Into Running It
Jamf published analysis on August 13 of AmnesiaStealer, a multi-stage Rust infostealer for macOS. Delivery is a counterfeit GitHub page showing a Terminal installation box: the user clicks copy, gets a base64 blob, and pastes a command that pulls a short, silent, self-deleting script. It takes Apple Notes and Telegram data, Keychain files, cookies from seven Chromium-family browsers, and system reconnaissance. Infosecurity Magazine
Operator Note: The lure is framed as a convenience for advanced users, which is the tell. It targets the developer who would rather solve it than open a ticket, so the people most likely to run it are the ones with credentials worth taking. We wrote about why capable employees run these commands in ClickFix: Why Good Employees Run Malicious Commands.
4. Seven Arrested Over a 30 Million Euro Commerzbank Fraud
Brazil’s federal police arrested four people and German prosecutors charged three more in Spain and Bulgaria over a fraud that pulled roughly 30 million euros, about $34.6 million, from Commerzbank accounts across four days in November 2023. The crew exploited a flaw introduced by a faulty software update in a payment and transaction processing system. Brazil’s Operation Klonen ran 21 search and seizure warrants on August 14 and seized assets worth about R$106 million. Commerzbank says customers lost nothing. BleepingComputer
Operator Note: Note the interval. Four days of fraud in November 2023, arrests in August 2026. The money moved in 96 hours and the accountability took 33 months, which is the ratio that makes this category worth attacking.
5. Evooo1Bot Turns Gateway Devices Into Relay Nodes
Fortinet researchers tracked Evooo1Bot exploiting known vulnerabilities in internet-facing gateway devices from Alcatel, NETGEAR, Tenda, Mitsubishi Electric, Telesquare, and D-Link, with newer builds reaching Hikvision cameras, Atlassian Confluence, Zyxel firewalls, and TP-Link routers. A successful hit pulls one of 12 builds matched to the host CPU architecture and installs a SOCKS5 relay module. It has been running since at least July. BleepingComputer
Operator Note: A relay does not encrypt your files or announce itself, so nothing on your side goes wrong in a way anyone reports. What changes is that your address starts appearing in somebody else’s incident, and the branch office router nobody has logged into since installation is the likeliest candidate in your estate.
Additional Security Alerts
Threat Intelligence
- Ukraine shut down 94 fraudulent call centers: Authorities seized millions in cash from operations running investment scams and bank account takeovers. BleepingComputer
- New Zealand says China used space investments to collect on local affairs: The intelligence service also reported that finding domestic threats has gotten harder. The Register
Cloud & Network Security
- Google Workspace attacks do not always start with phishing: Stolen OAuth tokens open a separate path into Gmail, Drive, and connected systems, which is a chain most Workspace defenses do not cover end to end. BleepingComputer
Emerging Security Technologies
- Anthropic will offer a watermark detection interface for Claude output: It builds on Google’s SynthID approach, adjusting randomness during word selection, and the company says fact-heavy short text is where it works least well. The Decoder
- Google published its work on making homomorphic encryption practical for private AI: Computing on encrypted data without decrypting it has been the long-standing answer to sending sensitive records to a model. Google
- OpenAI’s Computer History records clicks and typing to build memories: The company moved away from periodic screenshots toward capturing input directly. The Register
The Axe Report is a daily briefing from Grab The Axe. Need help assessing your organization’s security posture? Take our free Human Attack Surface Score assessment.
Operating on the philosophy that 'you can't build a secure system if you don't know how to break it,' Chris leads our engineering division. A top 1% National Cyber League competitor, he hardens our digital infrastructure against the very exploits he has mastered.
View Profile →Media Inquiries
For expert commentary, interview requests, or high-res assets regarding this announcement, initialize the terminal.