Csaba Fitzl

@theevilbit.bsky.social

macOS Security -- Trail running 🏃 -- Mountains ⛰ -- Tolkien fan

Did you see the news last week? 👀 Kandji announced Vulnerability Management to help IT and security teams identify, assess, prioritize, and remediate vulnerabilities on Mac devices - all through a unified workflow in a unified platform. Read more about it here: buff.ly/432J9E6

Vulnerability Management: First Unified Platform to Detect & Remediate on Mac

Kandji announces Kandji Vulnerability Management, which helps IT and security teams identify and remediate vulnerabilities through a unified workflow.

buff.ly

Year In Sport 2024. Wasn't that good due to my lingering plantar fasciitis issue. But that is life, sometimes there are low moments, and coming out of those will make you stronger. Hopefully things will get better next year. ⛰️🏃

BildBildBildBild

📣I’m happy to announce that I’m planning to write a brand new “macOS Vulnerability Research” training. 🥳 Considering the amount of work the writing requires it will be available late 2025 or early 2026. It will be Live class only, and likely only once or twice a year.

Bild

Been a while since we've seen #macOS #malware abusing osacompile rather than plain osascript, but #Amos Atomic Stealer is nothing if not adaptable. SHA1: 51ef05c84eea3dde149a5dd3ea9916a824e95afc. A reminder that it's possible (didn't say easy 😅) to reverse compiled #applescript. s1.ai/fadedead

FADE DEAD | Adventures in Reversing Malicious Run-Only AppleScripts - SentinelLabs

We show how to statically reverse run-only AppleScripts for the first time, and in the process reveal new IoCs of a long-running macOS Cryptominer campaign.

s1.ai

Last week, we released new research about new Mac #malware with TTPs consistent with suspected DPRK #APT BlueNoroff. s1.ai/BNThief. This week, friends-of-NK say we’re shills for US gov. 😂 easternherald.com/2024/11/10/s... Hate to break it to ‘em, but that ain’t how we roll. 😆

BlueNoroff Hidden Risk | Threat Actor Targets Macs with Fake Crypto News and Novel Persistence

SentinelLabs has observed a suspected DPRK threat actor targeting Crypto-related businesses with novel multi-stage malware.

s1.ai