A now routine task for a Tuesday, pinging Apple until they reply. (Context: Bug disclosed and fixed by Apple, promised credit on multiple occasions.. nothing for 12 months+) 🤣
🚨 Apple has not shared the security content of the latest iOS & macOS Rapid Security Response Updates.
IMO update details should be shared for any Mac or iOS update that requires a restart.🖥
If you agree, please file feedback with Apple.📝
What's the best security talk/blog post title you've seen? I think my favorite is @patrickwardle Cache Me Outside. Sick.
In the egomaniac category, I'm pretty proud of Lawyers, Bugs, and Money.
https://t.co/KJx2vTkPEE
patrickwardle: RT @DennisF: What's the best security talk/blog post title you've seen? I think my favorite is @patrickwardle Cache Me Outside. Sick.
In the egomaniac category, I'm pretty proud of Lawyers, Bugs, and Money.
https://t.co/fjwysSGzW5
patrickwardle: RT @objective_see: Stoked to support @Ekoparty's Hackademy by donating scholarships through our "Objective-We" program 🙌🏽
Our goal is to encourage & empower individuals from underrepresented communities to pursue careers in technology whi… https://t.co/UohGZUysdz
La Fundación Objective-See ha lanzado el programa Objective-We con la misión de hacer que la industria de seguridad sea más inclusiva y accesible. 💪
Como parte de este programa, se suma a Ekoparty Hackademy para donar becas para el curso " FUNDAMENTALS OF HACKING & DEFENSE " con el fin de empoderar y equipar a las personas para un futuro mejor. 🚀
Para saber más sobre Objective-See ingresá a ➡ https://t.co/eDOkVfVnyA
¡Conocé más sobre el programa de becas! ➡ https://t.co/5zDTkfxE8I
📲 Por cualquier duda o consulta, podés escribirnos a [email protected] o vía WhatsApp al 011-1534479336
patrickwardle: Packing for the🏖️ calls for: 🕶️ / 🍫 / 💻 / 📚
Given Apple's "all in" on Arm if you're an iOS/macOS security researcher Maria's (@Fox0x01) book "Arm Assembly" is a must!
And as a bonus the last chapter (written by yours truly 🤭) covers …
patrickwardle: RT @billpollock: The 2023 grant cycle for Hacker Initiative is underway with the aim of giving out at least $100,000 in grants of $10,000 each. Please share, encourage your brilliant friends or colleagues to apply, or apply yourself! https://t.co/xl6DwhkNQK
patrickwardle: RT @jmtrivedi: What if the macOS dock and its icons were more dynamic and fluid?
Made a little demo that shows message previews, live music, download progress, and more.
Pretty happy with how this turned out!
patrickwardle: Seems so:
"The second paragraph of the comment is most likely bogus ...A quick peek at the lipo source confirms the size checks are actually against UINT32_MAX"
https://t.co/DvYRABn2mz
patrickwardle: Seeking clarification 🙋🏻♂️
In fat.h, Apple notes that the fat_arch_64 structure will be used for slices/offsets greater than 4mb.
I'm guessing they meant 4GB (not MB)? Or? 🤔
patrickwardle: @cedriclnx@PartyD0lphin Good question!
It's actually up to each app, which can either:
1️⃣ Add the quarantine attribute to its downloads manually
2️⃣ Specify that the OS should add the attribute to each of the app's downloads (by adding LSFileQuarnatineEnabled …
patrickwardle: Great research & writeup by @PartyD0lphin
Looks like you could fully bypass Gatekeeper by simply prefixing a Mach-O binary (within an archive) with "._" 😅🤦🏻♂️
Now fixed as CVE-2023-27951 🙌🏽 https://t.co/wsCYd5J3yN
Apple recently patched CVE-2023-27951 and CVE-2023-2794: two Gatekeeper bypass vulnerabilities Red Canary’s @partyd0lphin disclosed with help from our new Mac Monitor collection tool. https://t.co/P28L5QS2LY
patrickwardle: RT @redcanary: Apple recently patched CVE-2023-27951 and CVE-2023-2794: two Gatekeeper bypass vulnerabilities Red Canary’s @partyd0lphin disclosed with help from our new Mac Monitor collection tool. https://t.co/TV41Yokjbu
patrickwardle: RT @ClassicII_MrMac: Study this image, and tell me what you think is going on.🧐
Might seem straightforward, but I think the user has have multiple things going on here.🔍
I will share my thoughts later in a 🧵 but want to hear from you…
patrickwardle: RT @ESETresearch: #ESETResearch warns about a CPIO archive named “Jump Crypto Investment https://t.co/5Uv0owqxTq” uploaded to VirusTotal from the USA 🇺🇸. It is another malicious PDF viewer distributed by #Lazarus#APT for #macOS …