Jamf's Thijs Xhaflaire analyses PamStealer, a Rust-based macOS infostealer disguised as the legitimate Maccy clipboard manager that uses a two-stage attack chain to silently harvest data and clipboard contents while evading detection. www.jamf.com/blog/pamstea...
🎉 Registration for MacAdmins 2026 is now open! Workshops, sessions, and community, July 7–10 in State College, PA. Get the details and register 👇 conta.cc/4tLwJu6 #psumac #macadmins
MacAdmins 2026 registration is live 🎉
Email from MacAdmins Conference Come be part of it Registration; workshops; grants and more! View this Newsletter as Webpage Registration for the 2026 MacAdmins Conference is now open! Join us July 7
conta.cc
New to macOS 26.4, the menu extra for the Passwords app shares its unlock state with the full app. So if you use Touch ID or your Mac password to unlock the menu extra and then go to add a new password or open an item in the full app, you won't have to authenticate again to unlock the app.
The world is stupid, but I just watched a squirrel break into a car in the parking lot below me, steal a package of crackers, and escape to a nearby tree. So at least somebody is winning.
Jamf Threat Labs details GhostClaw, a macOS credential-stealing campaign using malicious GitHub repositories and AI-assisted workflows. The analysis notes GhostClaw evolving from npm-style delivery into a GitHub distribution model. www.jamf.com/blog/ghostcl...
If you’ve been disappointed with the results of using #LLMs for #malware analysis, you might like this. 👇 The answer we found to getting reliable LLM output grounded in verifiable facts: a serial adversarial pipeline. #AI #security #macOS s1.ai/advers-llm
Building an Adversarial Consensus Engine | Multi-Agent LLMs for Automated Malware Analysis
Single-tool LLM analysis produces reports that look authoritative but aren't. A serial consensus pipeline catches artifacts and hallucinations at source.
s1.ai
Victor just released v1.14.0 - improvements in macho module, tighter code generation in the compiler and the new “deps” command. Congratulations to everyone involved! github.com/VirusTotal/y...
Browser based ES/Mac Monitor log analyzer - Story timelines - Sigma rule matching - In-depth process tree analyzer - Much much more! Amazing work by my coworker @txhaflaire.bsky.social Check it out! es.decompiler.dev #macos #malware #reverseengineering #threathunting #dfir
Without exaggeration, one of the most epic DPRK reports ever about.gitlab.com/blog/gitlab-...
GitLab Threat Intelligence Team reveals North Korean tradecraft
Gain threat intelligence about North Korea’s Contagious Interview and fake IT worker campaigns and learn how GitLab disrupted their operations.
about.gitlab.com
Some of the most popular packages on the OpenClaw official registry ClawHub are malicious @openclaw-x.bsky.social
Okay, this is friggin awesome! M.A.C.E is a great tool and I’m so proud of the work we’ve done on the #MSCP. I’ll be honest, my compatriots do way more work than me, I’m just a tiny bit in this project. Still super cool to see here. 9to5mac.com/2026/01/24/m...
Apple @ Work: M.A.C.E. app is a prime example of the Mac admins community at work - 9to5Mac
M.A.C.E. simplifies macOS compliance with a free GUI for the mSCP. It’s a prime example of the Mac admin community solving real IT problems.
9to5mac.com
Updated the tracking sheet I made last year now that it's been a year — National Averages After First Year of Trump's Second Term docs.google.com/spreadsheets...
National Averages After First Year of Trump's Second Term
docs.google.com
#100DaysofYARA - Day 11 In looking at automatic YARA generation, yarGen-Go is a must. Just released by @cyb3rops, it is a rewrite and advancement from the original yarGen. We'll look at the same malware from day 10; a targeted HavocC2 loader with decoy. rule at bottom 1/5
#100DaysofYARA - Day 9 YARA looks for the header used in a .SCPT file used by BlueNoroff (DPRK) to target MacOS systems. Script is delivered to victims disguised as a Zoom meeting launcher. e.g. a7c7d75c33aa809c231f1b22521ae680248986c980b45aa0881e19c19b7b1892 Rule at end 1/3
#100DaysofYARA - day 5 The Cert Graveyard project reports and documents abuse code-signing including Apple issued certificates. When reporting a certificate, we want to ensure Apple has all the identifiers they need to investigate and act. Rule at end 1/7
Jamf Threat Labs observed a revamped MacSync Stealer variant delivered as a code-signed and notarized app. Unlike earlier drag-to-Terminal/ClickFix chains, it uses a more deceptive, hands-off approach. www.jamf.com/blog/macsync...
I have created a website, where you can share your sample analysis (via links or posts) and search samples for training based on tags and difficulty. If you write analysis blogs, you can share them there. samplepedia.cc
#100DaysofYARA - Day 3 This relates to obfusheader discussed by @RussianPanda95 and @c0ner0ne. If the dev is going to use hard-coded strings, lets use them to our advantage. This thread will demo Malcat's YARA features. Rule at end of thread 1/5
🚨#100DaysofYARA lives!! 2 time reigning champ Yashraj has kindly offered to take the helm for this community effort! Give the homie a follow 👊 Check the repo to contribute: github.com/100DaysofYARA And gear up for Jan 1 when #100DaysofYARA will kick off!
a black and white photo of a man with a stethoscope around his neck screaming .
ALT: a black and white photo of a man with a stethoscope around his neck screaming .
media.tenor.com
If you like reading NIST special publications, I got a newly revved 800-70 for you. csrc.nist.gov/News/2025/dr...
Draft SP 800-70 Rev 5 is available for comment | CSRC
NIST Special Publication (SP) 800-70r5 ipd (Revision 5, initial public draft), National Checklist Program for IT Products – Guidelines for Checklist Users and Developers, is now available for public c...
csrc.nist.gov
Jamf Threat Labs warn that fake job assessments that ask you to run terminal commands could be a social engineering scheme to deploy the FlexibleFerret malware (a malware family attributed to DPRK-aligned operators) and steal your credentials. www.jamf.com/blog/flexibl...
Another great writeup from @txhaflaire.bsky.social on a new stealer that Jamf is calling digitstealer. www.jamf.com/blog/jtl-dig...
DigitStealer: In-Depth Analysis of a New macOS Infostealer
Jamf Threat Labs uncovers DigitStealer, a new macOS infostealer. Learn about its unique evasion techniques, multi-stage payload and how to protect your systems.
jamf.com
Oooh XProtect 5322 added XPScripts.yr. Guess they're going to start blocking malicious osascript and other interpreters now.
A year into Apple Intelligence, what do we know? Well your Mac knows the answers, just gotta ask the right questions. Read “IQ Check: On-Device vs PCC — Reading the Signals Hidden on Your Mac“ by Bob Gendler on Medium: boberito.medium.com/iq-check-on-...
IQ Check: On-Device vs PCC — Reading the Signals Hidden on Your Mac
Your Mac knows and can tell you specifically on device vs off device for Apple Intelligence
boberito.medium.com
Interested in Mac security research, reversing macOS malware, or detection engineering? Jamf Threat Labs is hiring! We're looking for passionate individuals to join our team and and help push the boundaries of Apple security. - Brno, Czechia - Austin, Eau Claire, Minneapolis
🍎 machofile 🍏 first official release is finally live: github.com/pstirparo/ma... It is a python module to parse #Mach-O binary files, with a focus on malware analysis and reverse engineering. machofile is self-contained. #macho #ios #reverseengineering #detection #threathunting #threatintel 1/3
GitHub - pstirparo/machofile: machofile is a module to parse Mach-O binary files
machofile is a module to parse Mach-O binary files - pstirparo/machofile
github.com