Cyberveillecurated by Decio
Nuage de tags
Mur d'images
Quotidien
Flux RSS
  • Flux RSS
  • Daily Feed
  • Weekly Feed
  • Monthly Feed
Filtres

Liens par page

  • 20 links
  • 50 links
  • 100 links

Filtres

Untagged links
page 7 / 10
184 résultats taggé macos  ✕
Hard-to-spot Mac crypto-mining threat, XMRig, hits Pirate Bay https://www.computerworld.com/article/3689149/hard-to-spot-mac-crypto-mining-threat-xmrig-hits-pirate-bay.html
27/02/2023 21:14:56
QRCode
archive.org
thumbnail

Jamf Threat Labs has spotted a family of Mac malware, XMRig, that spreads through pirated versions of Final Cut Pro, Photoshop and Logic Pro X.

computerworld EN 2023 apple macos jamf XMRig malware pirated FinalCutPro
Beware of macOS cryptojacking malware. https://www.jamf.com/blog/cryptojacking-macos-malware-discovered-by-jamf-threat-labs/
24/02/2023 23:10:33
QRCode
archive.org
thumbnail

You may have heard about the cryptojacking malware on macOS. Read about a new one spotted by Jamf Threat Labs.

jamf EN 2023 macOS cryptojacking malware
Can you rely on macOS Ventura for malware protection? https://eclecticlight.co/2023/01/03/can-you-rely-on-macos-ventura-for-malware-protection/
18/01/2023 13:41:10
QRCode
archive.org
thumbnail

Samples of four malicious software downloaded and run on macOS 13.1. Could it detect and block them effectively? Or do you need 3rd party protection?

eclecticlight EN 2023 macOS malware protection Ventura
7 Ways Threat Actors Deliver macOS Malware in the Enterprise https://www.sentinelone.com/blog/7-ways-threat-actors-deliver-macos-malware-in-the-enterprise/
18/01/2023 13:38:11
QRCode
archive.org
thumbnail

Stay ahead of the game with our review on macOS malware threats. Learn about the top techniques used by threat actors to deliver malware and how to build more resilient defenses.

sentinelone EN 2023 macOS Malware Enterprise threats
Zoom Patches High Risk Flaws on Windows, MacOS Platforms https://www.securityweek.com/zoom-patches-high-risk-flaws-windows-macos-platforms
11/01/2023 09:23:06
QRCode
archive.org

Video messaging giant Zoom has released patches for multiple security vulnerabilities that expose both Windows and macOS users to malicious hacker attacks.

securityweek EN 2023 CVE-2022-36930 CVE-2022-36929 CVE-2022-36927 patch-tuesday zoom zoom-rooms windows macos video-conferencing video-messaging privilege-escalation vulnerability
How do you know when macOS detects and remediates malware? https://eclecticlight.co/2023/01/04/how-do-you-know-when-macos-detects-and-remediates-malware/
04/01/2023 21:12:28
QRCode
archive.org
thumbnail

macOS may alert you when you’re trying to open or run a file, with an alert informing you that malware was detected. But what about in scans?

eclecticlight EN 2023 malware alert macos XProtect Remediator
The Mac Malware of 2022 👾 https://objective-see.org/blog/blog_0x71.html
02/01/2023 19:48:36
QRCode
archive.org
thumbnail

A comprehensive analysis of the year's new malware

objective-see 2022 EN malware macos analysis
Shlayer Malware: Continued Use of Flash Updates https://www.crowdstrike.com/blog/shlayer-malvertising-campaigns-still-using-flash-update-disguise/
28/12/2022 02:49:09
QRCode
archive.org
thumbnail

Although Flash Player reached end of life for macOS in 2020, this has not stopped Shlayer operators from continuing to abuse it for malvertising campaigns.

crowdstrike EN 2021 Flash Player macOS Shlayer malvertising analysis IoCs
Shlayer malware abusing Gatekeeper bypass on macOS https://www.jamf.com/blog/shlayer-malware-abusing-gatekeeper-bypass-on-macos/
28/12/2022 02:48:09
QRCode
archive.org
thumbnail

Shlayer malware bypasses Gatekeeper security protections on macOS to execute unauthorized software without requiring approval.

jamf EN 2021 Gatekeeper bypass macOS Shlayer malware
L’art de l’évasion How Shlayer hides its configuration inside Apple proprietary DMG files https://objective-see.org/blog/blog_0x70.html
28/12/2022 02:46:15
QRCode
archive.org
thumbnail

While conducting routine threat hunting for macOS malware on Ad networks, I stumbled upon an unusual Shlayer sample. Upon further analysis, it became clear that this variant was different from the known Shlayer variants such as OSX/Shlayer.D, OSX/Shlayer.E, or ZShlayer. We have dubbed it OSX/Shlayer.F.

objective-see 2022 EN Shlayer macos malware IoCs analysis
Get root on macOS 13.0.1 with CVE-2022-46689, the macOS Dirty Cow bug https://worthdoingbadly.com/macdirtycow/
19/12/2022 11:39:02
QRCode
archive.org

Get root on macOS 13.0.1 with CVE-2022-46689 (macOS equivalent of the Dirty Cow bug), using the testcase extracted from Apple’s XNU source.

worthdoingbadly EN 2022 CVE-2022-46689 macOS dirtycow
Top 10 macOS Malware Discoveries in 2022 https://www.sentinelone.com/blog/top-10-macos-malware-discoveries-in-2022/
07/12/2022 21:20:49
QRCode
archive.org
thumbnail

Learn about all the new malware targeting macOS users in 2022 and how to stay safe from the latest Mac-focused campaigns.

sentinelone EN 2022 top10 malware macOS
Cryptex: how a custom iPhone is changing macOS updates – The Eclectic Light Company https://eclecticlight.co/2022/11/16/cryptex-how-a-custom-iphone-is-changing-macos-updates/#like-68812
16/11/2022 20:58:19
QRCode
archive.org
thumbnail

Expected in Ventura 13.1 is a new lightweight system for applying security patches. This article explains how it uses cryptexes, already being used in macOS 13.

eclecticlight 2022 macOS updates security Cryptex patches cryptexes
Attacking Apple's Neural Engine https://github.com/0x36/weightBufs/blob/main/attacking_ane_poc2022.pdf
12/11/2022 21:59:41
QRCode
archive.org
thumbnail

WeightBufs is a kernel r/w exploit for all Apple devices with Neural Engine support. Bugs and Exploit by @simo36, you can read my presentation slides at POC for more details about the vulnerabilities and the exploitation techniques.

0x36 EN 2022 WeightBufs GitHub Apple ios macos exploit NeuralEngine exploitation CVE-2022-32845 CVE-2022-32948 CVE-2022-42805 CVE-2022-32899
Last Week on My Mac: Home truths about macOS https://eclecticlight.co/2022/11/06/last-week-on-my-mac-home-truths-about-macos/
06/11/2022 11:40:49
QRCode
archive.org
thumbnail

True or false? Apple supports macOS for three years. Apple’s security updates are sufficient. New versions of macOS are full of bugs. It’s safer to delay upgrading.

eclecticlight EN 2022 macos apple security patching updates delay support
Apple's Poor Patching Policies Potentially Make Users' Security and Privacy Precarious https://www.intego.com/mac-security-blog/apples-poor-patching-policies-potentially-make-users-security-and-privacy-precarious/
06/11/2022 10:00:29
QRCode
archive.org
thumbnail

Apple's practices regarding security updates are frustrating and perplexing, and may endanger users.

Intego 2021 EN Apple macOS patching policy endanger
Unmasking WindTape - Speaker Deck https://speakerdeck.com/patrickwardle/unmasking-windtape
02/11/2022 09:12:22
QRCode
archive.org
thumbnail

The offensive macOS cyber capabilities of the WINDSHIFT APT group provide us with the opportunity to gain insight into the Apple-specific approaches employed by an advanced adversary.

In this talk we’ll comprehensively dissect OSX.WindTape, a second-stage tool utilized by the WINDSHIFT APT group when targeting Apple systems.

First we’ll discuss the malware’s anti-analysis mechanisms, and then once these have been thwarted, we’ll explore its capabilities. To conclude, we’ll present heuristic methods that can generically both detect and prevent WindTape, as well as other advanced macOS threats.

patrickwardle EN 2022 WINDSHIFT APT macOS
Reverse Engineering the Apple MultiPeer Connectivity Framework https://www.evilsocket.net/2022/10/20/Reverse-Engineering-the-Apple-MultiPeer-Connectivity-Framework/
22/10/2022 18:38:55
QRCode
archive.org
thumbnail

Some time ago I was using Logic Pro to record some of my music and I needed a way to start and stop the recording from an iPhone, so I found about Logic Remote and was quite happy with it.

evilsocket EN 2022 Apple MultiPeer Connectivity Framework mDNS analysis macOS LogicPro network reverse-engineering
Jamf Threat Labs identifies macOS Archive Utility vulnerability allowing for Gatekeeper bypass (CVE-2022-32910) https://www.jamf.com/blog/jamf-threat-labs-macos-archive-utility-vulnerability/
08/10/2022 22:24:01
QRCode
archive.org
thumbnail

Read how macOS vulnerability in Archive Utility could lead to the execution of an unsigned and unnotarized application without displaying security prompts.

jamf EN 2022 Archive Utility macOS vulnerability CVE-2022-32910 Gatekeeper bypass
Lazarus ‘Operation In(ter)ception’ Targets macOS Users Dreaming of Jobs in Crypto https://www.sentinelone.com/blog/lazarus-operation-interception-targets-macos-users-dreaming-of-jobs-in-crypto/
28/09/2022 15:24:54
QRCode
archive.org
thumbnail

First Coinbase, now Crypto.com. Lazarus campaign targets more crypto exchange platform job seekers with multi-stage malware.

sentinelone EN 2022 Lazarus Lazarus-Group crypto macOS operation APT38
page 7 / 10
4508 links
Shaarli - The personal, minimalist, super-fast, database free, bookmarking service par la communauté Shaarli - Theme by kalvn - Curated by Decio