Stoked for the next (ad)venture: "DoubleYou" https://t.co/DpPe5fQxzV
Cofounded w/ long-time friend @hexlogic, we're empowering those building security tools for Apple devices ππ‘οΈ
And by bootstrapping this venture, our core value of democratizing security remains our focus!
macOS 26: the leaf cert. used to sign π -binaries is now "macOS Software Signing" (prev. "Software Signing").
Intermediate ("Apple Code Signing Certification Authority") & root ("Apple Root CA") unchanged.
Relevant to some security tools (e.g. LuLu) that cared about this! π
My team at Apple SEAR is hiring an offensive security researcher focused on wireless security!
Apply here: https://t.co/sGXxU9pFqs
We're looking for talented researchers who love breaking wireless stacks and protocols like cellular/baseband, Wi-Fi, Bluetooth, or other wireless technologies.
Feel free to reach out if you have any questions.
#infosec
Sometimes simple bugs are the best! ππΌ
"the PasswordManagerBrowserExtensionHelper binary logged the session PIN to the system log via os_log" ππ«
Thanks for sharing your research/writeup @joshparnham ππ½
Published a writeup on CVE-2025-24169, a macOS vulnerability which allowed a malicious app to enumerate a user's saved account data in the Passwords app - contravening TCC protections.
Example PoC + full details here: https://t.co/rEHIk4y09N
π¨ The CFP for #OBTS v9 closes this Friday (July 31)!
Have some novel or innovative Apple security research to share? We'd love to see your submission:
https://t.co/7Sb2N54gZd
Welcoming submissions on any Apple security topic (offensive & defensive)! πππ‘οΈ
1/ New #macOS bash dropper - 0 hits on VT. Shared by @malwrhunterteam.
Self-deletes on launch. Delivers a binary from weekly-up[.]online while pushing a fake Zoom, Teams, or SystemApp as cover.
Might be related to Contagious Interview, however no strong confirmation yet. π§΅
Also, have posted a sample of PamStealer to our free/public Mac Malware repo! ππ
PamStealer:
https://t.co/uj0wVy0kiO (pw: infect3d)
#SharingIsCaring
One of the most time consuming parts of macOS research is identifying what you're looking at - AMOS, NovaStealer, DigitStealer, MacSync, or maybe Shlayer or Adload.
You can now pull in this Malware Research skill to help you classify malware quickly.
https://t.co/rPFZGnGuwD
Apple SEAR is hiring an offensive security researcher focused on wireless security!
We're looking for talented researchers to help find and exploit vulnerabilities across wireless technologies.
Apply here: https://t.co/sGXxU9pFqs
If you love digging into wireless stacks and protocols like cellular/baseband, or Wi-Fi and Bluetooth, my team would especially like to hear from you.
Feel free to reach out if you have any questions.
#infosec
Didn't realize @HexRaysSA's IDA has a config to decrypt Apple-protected binaries - neat!
Even better, Hopper does it automatically ππΌ
btw π is : "ourhardworkbythesewordsguardedpleasedontsteal(c)AppleComputerInc"
@ninja_binary, this would be a great feature to add ππ
Our next macOS Vulnerability Researcher trainings with @gergely_kalman will be:
π 2026-10-12 - 15: Self-organized, 4 (!!!!) day training (Budapest, Hungary)
π 2026-11-15 - 17: Objective by the Sea v9 (Hawaii, USA)
More info here:
https://t.co/SQ4zNuVa6T
Worried about losing your coding skills due to AI?
...don't if you're using Xcode π« Its AI integration is beyond flakey so you'll (still) be writing lots of code! π΅βπ«
Seems related to session handling, but signing in/out (e.g, into Claude), restarting Xcode, super hit & miss π€·ββοΈ
@keskinonur@objective_see Yes, macOS is very chatty network-wise, which is why LuLu ignores Apple-signed programs by default π«£
Unfortunately, on macOS 27 beta there appears to be an Apple bug that breaks this behavior. Hoping for a fix from Apple in the next beta! π€πΌ
https://t.co/G8V6cL6PGV