CrashStealer on macOS, ModHeader Pulled & Russia Hits Poland's Grid (07/13/2026)

July 13, 2026
CrashStealer on macOS, ModHeader Pulled & Russia Hits Poland's Grid (07/13/2026)
Key Intel / TL;DR
  • CrashStealer is a new macOS infostealer that poses as Apple's crash-reporting tool and uses a notarized dropper to pass Gatekeeper, then steals credentials, keychain data, and crypto wallets.
  • Google and Microsoft pulled ModHeader, a header-editing extension with 1.6 million installs, after researchers found a hidden browsing-history collector.
  • MemGhost plants persistent false memories in an AI assistant through a single email, rewriting what the agent thinks it knows about you.
  • The EU and UK formally blamed Russian intelligence for a cyberattack on Poland's power grid that could have cut power to half a million people in winter.
  • Forg365, a new phishing-as-a-service kit, targets Microsoft 365 with device-code phishing and adversary-in-the-middle session theft.

Trust keeps getting borrowed and turned against the owner. A macOS stealer wears Apple’s own notarization to walk past Gatekeeper, a browser extension a million people trusted was quietly logging their history, and an AI assistant can be talked into believing a lie it will act on for weeks. On the same day, the EU put a name to the crew that tried to switch off Poland’s lights. Here is what to act on.

Top 5 Critical Security Alerts

1. CrashStealer Poses as Apple’s Crash Tool to Bypass Gatekeeper

CrashStealer is a new macOS infostealer that impersonates Apple’s crash-reporting tool and uses a notarized dropper to pass Gatekeeper checks, then harvests credentials, keychain data, and cryptocurrency wallets (The Hacker News, BleepingComputer). Notarization is supposed to be a trust signal, so abusing it means the malware arrives pre-approved, and the “Macs do not get malware” assumption keeps costing organizations that never staffed for it.

Operator Note: Put endpoint detection on your Macs, not just your Windows fleet. Notarization is a checkpoint an attacker can pass, not a guarantee.

2. Google and Microsoft Pull ModHeader Over Hidden History Collector

Google and Microsoft removed ModHeader, a header-editing extension with roughly 1.6 million installs across Chrome and Edge, after researchers found a dormant browsing-history collector hidden inside it (The Hacker News). A browser extension runs with deep access to everything you do in the tab, and a dormant collector that wakes up later is the extension version of a supply-chain time bomb.

Operator Note: Inventory the browser extensions on your fleet and remove the ones nobody can justify. Each one is code with a view of every page your people load.

3. MemGhost Plants False Memories in AI Agents Through One Email

Researchers detailed MemGhost, an attack that uses a single email to trick a memory-enabled AI assistant into saving a false fact about you, which it then treats as true across future sessions (The Hacker News). Give an agent a memory and access to your inbox and you have given an attacker a way to rewrite its beliefs, which is a new and durable form of the prompt-injection problem.

4. EU and UK Blame Russia for Attack on Poland’s Power Grid

The EU and UK formally attributed a cyberattack on Poland’s power grid to Russian intelligence, an operation that could have left half a million people without power in the depth of winter, and answered it with sweeping sanctions (The Register). Attribution plus sanctions raises the diplomatic cost, though it does not lower the exposure of any operator running similar grid technology.

5. Forg365 Phishing Kit Hunts Microsoft 365 Sessions

A new phishing-as-a-service operation called Forg365 targets Microsoft 365 using device-code phishing, adversary-in-the-middle session theft, antibot evasion, and AI-assisted lures (The Hacker News). Stealing a live session token sidesteps the password and often the multi-factor prompt, which is why session theft has become the phishing outcome that actually matters.

Additional Security Alerts

Threat Intelligence

  • Attacker Uses AI-Generated PowerShell to Map Active Directory: Researchers flagged an intrusion where a threat actor ran a vibe-coded PowerShell script to enumerate Active Directory, a sign that AI-assisted tooling is lowering the skill floor for post-compromise reconnaissance. The Hacker News

Security Standards & Frameworks

  • US Sanctions a Ransomware-Favored VPN Service: The US Treasury sanctioned First VPN Service and its Ukrainian administrator for aiding ransomware groups, an effort to raise the cost of the anonymizing infrastructure crews rely on. The Record

The Axe Report is a daily briefing from Grab The Axe. Need help assessing your organization’s security posture? Take our free Human Attack Surface Score assessment.

Distribute Intel
Chris Armour
Director of Information Security
Chris Armour
The Breaker & Builder.

Operating on the philosophy that 'you can't build a secure system if you don't know how to break it,' Chris leads our engineering division. A top 1% National Cyber League competitor, he hardens our digital infrastructure against the very exploits he has mastered.

View Profile →
Press & Media

Media Inquiries

For expert commentary, interview requests, or high-res assets regarding this announcement, initialize the terminal.

Initialize Terminal

Initiate
Deployment.

Whether you need a full adversarial facility audit or an executive resilience protocol for your leadership team.

Secure the Facility (Assessments)
Secure the Mind (Coaching/Speaking)