cm0002

joined 4 weeks ago
MODERATOR OF
13
www.cnbc.com (www.cnbc.com)
submitted 23 hours ago* (last edited 23 hours ago) by cm0002@libretechni.ca to c/world@quokk.au
 

The development suggests that the White House is planning a broader campaign against Venezuela’s oil exports. The U.S. seized a tanker on Wednesday that had allegedly transported oil from Venezuela to Iran.

The oil market has been focused on Ukraine peace talks and so far is not indicating a risk of a major supply disruption. U.S. crude oil was last down $1.04, 1.78%, to $57.42 a barrel. Global benchmark Brent was at $61.11, down $1.10, or 1.77%.

 

A new Atomic macOS Stealer (AMOS) attack vector weaponizes Google searches and a user's trust in AI chatbots, researchers have found. Once infected, the AMOS can collect data, passwords, and more from the infected Mac with alarming ease.

While AMOS attacks have been around since 2023, they normally involve people accidentally downloading a malicious file. But this new approach is different. Instead, it simply requires them to copy and paste a single command into the Terminal app.

Researchers at security outfit Huntress identified the new AMOS approach in early December 2025 after a victim reported the incident. Huntress found that the user had searched "Clear disk space on macOS" before choosing one of the two sponsored results.

Both of those results linked to a shared chatbot chat, one for ChatGPT, the other for Grok. It didn't matter which the victim clicked because they both ultimately did the same thing.

Huntress was able to repeat the infection steps, which boiled down to copying and pasting a command that was supposed to free up storage space. In reality, it downloaded a file that then set about gaining root privileges to allow it to access apps and data unchecked.

In fact, the route taken by this particular AMOS ensured it never triggered any of Apple's built-in macOS security features. Once the command was run, there was never any indication that something was amiss.

Once running, Huntress found that the Stealer had the ability to capture a number of high-value data types. Those include access to cryptocurrency wallets, browser credential databases, and even Apple Keychain.

All data collected by the attack is then uploaded to attacker-controlled servers. As for the Stealer itself, the attack ensures it is configured to run even after the Mac is restarted, meaning it's always ready to steal more data.

While AMOS isn't new, the key thing to note here is the new approach, and one that Mac users should absolutely be wary of. As people become more wary of files they download from the internet, attackers need new ways of getting malware onto devices.

In this instance, both the ChatGPT and Grok shared chats are legitimate and hosted on their respective services. They also give the air of a legitimate guide that will ultimately free up storage space as requested.

Even pasting a command into the Terminal window makes sense given the context. It's easy to see how people might fall for such an attack.

[–] cm0002@libretechni.ca 4 points 3 weeks ago

Lol just register for an LLC then sign up for like stripe or something so you can take card then BOOM done. Although you'd be losing a little money each time because transaction fees lol

[–] cm0002@libretechni.ca 1 points 3 weeks ago

It's quite convenient that all of your new posts have at least three votes in a very short time frame. You've long established yourself as desperate for upvotes with the sheer volume of posts you submit without any effort into any of the posts themselves. Finally having to boost your own material?

Everyone has access to lemvotes.org, prove it

[–] cm0002@libretechni.ca 0 points 3 weeks ago (2 children)

How does having alts erase past post history lmao

[–] cm0002@libretechni.ca 27 points 3 weeks ago (6 children)

Also, I can't imagine anyone who was actually close to someone being willing to actually use something this ghoulish.

Grief is a hell of a drug, someone who's just lost someone close to them might be willing to do a lot of things for just one more day, hour, minute with them

[–] cm0002@libretechni.ca 1 points 3 weeks ago (4 children)

What was the issue with lemmy.zip? It's well maintained and the blocklist is quite short

If you want an instance not federated with hexbear, grad and ml, then infosec.pub should do it

.zip is on the short list for sure, the Triad federation though is a detractor for me, but not necessarily a deal breaker. I also don't want to just default to one of the big instances that every one is on

You once told me that power posters like me are essentially de facto advertisers for an instance, so I'm keeping that in mind as I go through these instances. I would like to promote small instances through my posting, so eventually I'll probably just starting posting from random instance accounts that I've already made

Infosec.pub is decent, but was having issues when I went through it. That was either the one that was sporadically going down or the one that was taking 45+ seconds to post every post (I'd have to check my notes). But I discovered, like you said, it defederates from the entire Triad so that's a big plus. I'll revisit it for sure to see if the issues I encountered were just bad timing

If you are using alts to federate communities, that's fine, but keeping posting from one account would be better, those are two different things

Because I post such a wide variety of content, simply posting is an effective way to discover what comms are and are not federated on an instance (short of writing a bot to do it ofc, but whats the fun in that?)

Also, if an instance is missing big communities, the admins probably didn't bother setting up Lemmy-federate , and users didn't bother to ask either, so it's probably a quite low population instance

That's true for at least one instance I've been on, but I honestly think that bot is not as reliable as it seems...

[–] cm0002@libretechni.ca 2 points 3 weeks ago (6 children)

For other people blocking me, I don't really care if they do or don't, it's just unfortunate unintended side effects for the actual reasons:

Shopping for a new home instance

Exploring the Threadiverse from different perspectives (the "hot" feed you see can vary quite a bit depending on the instance you're on lol)

Trolling .ml (or Why am I cross-posting .ml content?

I cross-post from .ml to the nearest relevant non-.ml comm to reduce the influence of .ml comms and indirectly, the instance as a whole, to make it an easier decision for other instance admins to defederate because one key reason I identified that admins don't want to defederate is because .ml still has some very large comms and some niche comms.

Megathread on the issue

Some highlights from the link:

"Don't worry guys, the Uyghur Genocide was REALLY just birth control! ~dessalines, .ml admin, dev https://lemmy.world/post/30580167

"See! nobody died IN Tiananmen Square, just AROUND it, so it doesn't count!!" ~ Davel, .ml admin https://lemmy.world/post/30673342

.ml admin, Nutomics continued transphobia https://lemmy.world/post/29222558 The original transphobic Comment from Nutomic: https://lemmy.world/post/18236068

"NK is actually good and anything counter to that is Western propaganda!" ~dessalines, .ml admin, dev https://lemmy.world/post/31595035

General negative sentiment to other instances who haven't "seen the way" yet ~davel, .ml admin https://lemmy.world/post/27426510

"If you don't support Russia then you just don't understand geopolitics" ~dessalines, .ml admin, dev https://lemmy.world/post/27352415

And so so much documentation on clear heavy handed censorship and bias also on the link. So much I can't even put them all here because this comment would be really long.

I believe the behavior of its admins (the main admins are Lemmy devs) does harm to the overall growth of the Lemmy-verse and maybe even the Thrediverse (since Lemmy kinda kicked off the Thrediverse) because of its association with the devs of Lemmy and their insistence to use .ml as their personal political platform to spread harmful propaganda

On the outside, bringing up Lemmy frequently leads to comments like "Lemmy? Isn't that the place with a bunch of tankies?" Or "Tried Lemmy, but found it full of pro Russia crap so I left". The best way forward from that I see is to either widely defederate from .ml like the rest of the Triad, or pressure them to put a fair and unbiased as possible admin team.

)

Learning that the bot intended to better interconnect instance comms may not be doing as good of a job

Interconnecting wayward or much smaller instances, a couple of them are missing even the big comms, one I was on the other day I needed to manual have it federate with every comm I posted to

For the creation of comms on fitting instances or just among a regular rotation of general instances so I'm not making a whole bunch on any one instance

[–] cm0002@libretechni.ca -2 points 3 weeks ago (4 children)

Lol I post a wide range of content sometimes it just naturally clusters

At least I have a post history ¯⁠\⁠_⁠(⁠ツ⁠)⁠_⁠/⁠¯

Be the change you want in the Threadiverse feed

[–] cm0002@libretechni.ca 12 points 3 weeks ago (14 children)

Um, this is a mozilla foundation link LMAO

view more: ‹ prev next ›