Iran Tracks US Troops via Ad Tech, New macOS CrashStealer Malware Emerges
Foreign threat actors linked to Iran are exploiting advertising technology metadata and global cellular roaming protocols to track and target the smartphones of US military personnel, according to reporting from the Financial Times. The operation leverages legitimate ad network infrastructure and roaming signaling data to geolocate service members, raising significant privacy checkup concerns for defense personnel and prompting renewed scrutiny of mobile ad ecosystems. Researchers warn that the same techniques could be repurposed against executives, journalists, and other high-value targets, making mobile metadata hygiene a frontline defensive priority.
Security researchers have uncovered a novel macOS information stealer written in C++ and dubbed CrashStealer, which masquerades as a legitimate system crash reporter to evade detection. The malware exfiltrates credentials, sensitive documents, and system information from compromised Apple devices while mimicking native password prompts to harvest user secrets. Its stealthy design allows it to bypass standard macOS defenses, underscoring the need for users to verify password checker integrity and avoid granting Keychain access to unverified applications.
Beyond these threats, several high-impact incidents underscored broader risks across sectors. Dutch authorities suspect local cybercriminals in the recent network intrusion at telecom operator Odido, while supermarket giant Lidl confirmed customer data exposure following a breach at an external IT service provider affecting consumers in Belgium and the Netherlands. In Germany, textile finisher ZEGO Textilveredelungszentrum filed for insolvency after a cyberattack forced a six-week production shutdown, and Japan's largest taxi operator, Nihon Kotsu, took IT and dispatch systems offline following an intrusion analysts attribute to the AiLock ransomware group. Readers concerned about exposure in any of these incidents can search the email breach checker to verify whether their credentials appear in known leaks tied to these and other recent compromises.