Csaba Fitzl's Avatar

Csaba Fitzl

@theevilbit.bsky.social

macOS Security -- Trail running ๐Ÿƒ -- Mountains โ›ฐ -- Tolkien fan

751 Followers  |  57 Following  |  27 Posts  |  Joined: 06.02.2024  |  1.6153

Latest posts by theevilbit.bsky.social on Bluesky

Preview
Vulnerability Management: First Unified Platform to Detect & Remediate on Mac Kandji announces Kandji Vulnerability Management, which helps IT and security teams identify and remediate vulnerabilities through a unified workflow.

Did you see the news last week? ๐Ÿ‘€

Kandji announced Vulnerability Management to help IT and security teams identify, assess, prioritize, and remediate vulnerabilities on Mac devices - all through a unified workflow in a unified platform.

Read more about it here: buff.ly/432J9E6

20.02.2025 15:57 โ€” ๐Ÿ‘ 1    ๐Ÿ” 2    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
#349 new iPhone: it's a 16e

This week's news summary, we look briefly at the new phone before we look some beefy malware and vulnerabilities, some nice configuration profiles and updates.

macadmins.news/issues/349

#Mac #MacAdmins #Apple

21.02.2025 14:52 โ€” ๐Ÿ‘ 0    ๐Ÿ” 1    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
Uncovering Apple Vulnerabilities: diskarbitrationd and storagekitd Audit Part 3 Exploring CVE-2024-27848 & CVE-2024-44210: How macOS vulnerabilities in storagekitd allowed privilege escalation, how they were exploited & Appleโ€™s patch.

๐ŸŽ๐ŸชณMy last blog post in the storagekitd - diskarbitrationd vulnerability series, which I presented at #POC2024 and @blackhatevents.bsky.social #BHEU2024 as part of my "Apple Disk-O Party" talk, is up @kandji.bsky.social 's site:

www.kandji.io/blog/macos-a...

21.02.2025 15:20 โ€” ๐Ÿ‘ 0    ๐Ÿ” 1    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

First Apple๐ŸŽ macOS ๐Ÿ’ป vulnerability of 2025 is submitted. ๐Ÿฅณ Full access to your iCloud documents...

08.01.2025 11:18 โ€” ๐Ÿ‘ 5    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Post image Post image Post image Post image

Happy New Year! โ„๏ธ

01.01.2025 15:19 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Post image Post image Post image Post image

Year In Sport 2024.

Wasn't that good due to my lingering plantar fasciitis issue. But that is life, sometimes there are low moments, and coming out of those will make you stronger. Hopefully things will get better next year. โ›ฐ๏ธ๐Ÿƒ

29.12.2024 09:13 โ€” ๐Ÿ‘ 2    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
Maui, Hawaii (ENG) by Csaba Fitzl on Exposure HUNGARIAN / MAGYAR

๐Ÿ๏ธ๐Ÿฅพ๐Ÿƒ๐ŸŒ‹I wrote about my hiking and trail running adventures in Maui, Hawaii, which I did right before #OBTS

Enjoy!

trails.exposure.co/maui-hawaii-...

21.12.2024 15:13 โ€” ๐Ÿ‘ 2    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
Uncovering Apple Vulnerabilities: diskarbitrationd and storagekitd Audit Part 2 Part 2 of the audit Kandji's Threat Research team performed on the macOS diskarbitrationd & storagekitd system daemons, uncovering several vulnerabilities.

๐ŸŽ๐ŸชณSecond part of the diskarbitrationd - storagekitd vulnerability blog series is out on @kandji.bsky.social 's blog.

These vulnerabilities were presented at @blackhatevents.bsky.social #BHEU2024 and #POC2024 conferences as part of my "Apple Disk-O Party" talk.

www.kandji.io/blog/macos-a...

12.12.2024 15:50 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Post image

๐Ÿ“ฃIโ€™m happy to announce that Iโ€™m planning to write a brand new โ€œmacOS Vulnerability Researchโ€ training. ๐Ÿฅณ

Considering the amount of work the writing requires it will be available late 2025 or early 2026. It will be Live class only, and likely only once or twice a year.

09.12.2024 12:00 โ€” ๐Ÿ‘ 20    ๐Ÿ” 5    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

โ˜€๏ธ๐Ÿ๏ธThis is the day! Donโ€™t miss it if you want to learn how to talk with launchd and how to generically detect XPC exploits. ๐Ÿ”ฅ๐Ÿ”ฅ๐Ÿ”ฅ #OBTS

06.12.2024 20:18 โ€” ๐Ÿ‘ 8    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
Humble Tech Book Bundle: Hacking 2024 by No Starch Level up your hacking and skills with this tech bundle from No Starch. Learn to protect yourself and others! Pay what you want & support charity!

Good lineup of books! www.humblebundle.com/books/hackin...

02.12.2024 20:58 โ€” ๐Ÿ‘ 20    ๐Ÿ” 8    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 1
Post image

Extremely excited to be giving a talk titled "Mac, Wheres My Bootstrap" tomorrow at #OBTS with @theevilbit.bsky.social! Join us live on YouTube or in-person at 2:40pm HST / 7:40pm EST. We'll be dropping a tool you can walk away with :)

05.12.2024 19:34 โ€” ๐Ÿ‘ 9    ๐Ÿ” 3    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 1

We are doing again a community run tomorrow. We will meet at the lobby, at the โ€œAlohaโ€ sign at 8AM, and run about 5k north on the beach and then back. #OBTS10k #OBTS

05.12.2024 19:08 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Post image

Entering last day of trainings with my colleagues from @kandji.bsky.social . There is always something new to learn in this field, and itโ€™s great to learn directly from iOS experts @naehrdine.bsky.social and Sn0wfreeze #OBTS

04.12.2024 20:22 โ€” ๐Ÿ‘ 6    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
Careers at SentinelOne Take a look at the open positions at SentinelOne. We're dedicated to defending enterprises across endpoints, containers, cloud workloads, and IoT devices in a single cybersecurity platform.

@sentinelone.com is hiring - #macOS detection engineer.

www.sentinelone.com/jobs/?gh_jid...

30.11.2024 12:41 โ€” ๐Ÿ‘ 6    ๐Ÿ” 7    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Post image Post image

A dream came true. My first ever Sea To Summit climb, here on Maui. Climbed the 3055m high Haleakala volcanoโ€™s highest summit, Red Hill, from the ocean over 30kms. #OBTS

01.12.2024 06:20 โ€” ๐Ÿ‘ 13    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
GitHub - vxunderground/MalwareSourceCode: Collection of malware source code for a variety of platforms in an array of different programming languages. Collection of malware source code for a variety of platforms in an array of different programming languages. - vxunderground/MalwareSourceCode

@vxundergroundre.bsky.social has been kind enough to host Banshee Stealer's leaked source code here. #macOS #InfoStealer #apple #malware
github.com/vxundergroun...

25.11.2024 21:07 โ€” ๐Ÿ‘ 19    ๐Ÿ” 3    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
On the Trails of Seoul by Csaba Fitzl on Exposure Trail running story from South Korea.

๐Ÿฅพ๐Ÿƒโ›ฐ๏ธ It was long time ago I last wrote about my runs or hikes. Below is a post about the trails I explored when I was in South Korea for the POC2024 conference. Enjoy!
trails.exposure.co/on-the-trail...

25.11.2024 23:58 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
FADE DEAD | Adventures in Reversing Malicious Run-Only AppleScripts - SentinelLabs We show how to statically reverse run-only AppleScripts for the first time, and in the process reveal new IoCs of a long-running macOS Cryptominer campaign.

Been a while since we've seen #macOS #malware abusing osacompile rather than plain osascript, but #Amos Atomic Stealer is nothing if not adaptable. SHA1: 51ef05c84eea3dde149a5dd3ea9916a824e95afc.
A reminder that it's possible (didn't say easy ๐Ÿ˜…) to reverse compiled #applescript.
s1.ai/fadedead

21.11.2024 11:26 โ€” ๐Ÿ‘ 23    ๐Ÿ” 11    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
Reverse Engineering iOS 18 Inactivity Reboot Wireless and firmware hacking, PhD life, Technology

How does the new iOS inactivity reboot work? What does it protect from?

I reverse engineered the kernel extension and the secure enclave processor, where this feature is implemented.

naehrdine.blogspot.com/2024/11/reve...

17.11.2024 21:42 โ€” ๐Ÿ‘ 282    ๐Ÿ” 107    ๐Ÿ’ฌ 12    ๐Ÿ“Œ 11

Paged Out! #5 is out โ€“ย enjoy! pagedout.institute
And if you like the cover, we have wallpapers!

19.11.2024 09:31 โ€” ๐Ÿ‘ 36    ๐Ÿ” 16    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 2

I was featured in PagedOut Issue #5 with my macOS notification forensics article (page 25). I find the whole idea of this magazine pretty cool. Lot's of interesting stuff in there!

19.11.2024 10:20 โ€” ๐Ÿ‘ 8    ๐Ÿ” 1    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
Reverse Engineering iOS 18 Inactivity Reboot Wireless and firmware hacking, PhD life, Technology

Excellent stuff even though iโ€™m not really a phone guy. Love the reversing and the detailed explanation of the process. ๐Ÿ‘ ๐Ÿ‘
naehrdine.blogspot.com/2024/11/reve...

17.11.2024 22:25 โ€” ๐Ÿ‘ 10    ๐Ÿ” 4    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

@theevilbit.bsky.social 's Apple Disk-O Party

powerofcommunity.net/poc2024/Csab...

17.11.2024 16:16 โ€” ๐Ÿ‘ 3    ๐Ÿ” 1    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0
Post image

#Apple added three new rules for XCSSET - a #malware weโ€™ve not seen since 2021 - to #XProtect this week as DubRobber F, G & H in v5282. Curious, to say the least.

15.11.2024 00:02 โ€” ๐Ÿ‘ 5    ๐Ÿ” 1    ๐Ÿ’ฌ 2    ๐Ÿ“Œ 1
low detection rates on macOS Amos malware on virustotal

low detection rates on macOS Amos malware on virustotal

Bunch of new Amos/Atomic #macOS #infostealers if you pivot off ```behaviour_processes:"sh -c curl -s https[:]//api.ipify[.]org/?format=text" tag:macho```
Low detections on V(h/t x.com/malwrhuntert...) #malware #apple #cybersecurity

15.11.2024 16:01 โ€” ๐Ÿ‘ 23    ๐Ÿ” 7    ๐Ÿ’ฌ 2    ๐Ÿ“Œ 0
M4 devices - VMs pre 13.4 fail to โ€ฆ | Apple Developer Forums

Apple M4 devices can't virtualize macOS versions prior to 13.4. Hopefully this will get fixed. More info here:
developer.apple.com/forums/threa...

14.11.2024 20:22 โ€” ๐Ÿ‘ 0    ๐Ÿ” 1    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
BlueNoroff Hidden Risk | Threat Actor Targets Macs with Fake Crypto News and Novel Persistence SentinelLabs has observed a suspected DPRK threat actor targeting Crypto-related businesses with novel multi-stage malware.

Last week, we released new research about new Mac #malware with TTPs consistent with suspected DPRK #APT BlueNoroff. s1.ai/BNThief. This week, friends-of-NK say weโ€™re shills for US gov. ๐Ÿ˜‚ easternherald.com/2024/11/10/s...
Hate to break it to โ€˜em, but that ainโ€™t how we roll. ๐Ÿ˜†

12.11.2024 14:39 โ€” ๐Ÿ‘ 9    ๐Ÿ” 4    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
Apple M4 - Mac UTM open to black screen ยท Issue #6794 ยท utmapp/UTM Black Screen upon UTM Build. When trying to spin up a NEW Mac Monterey UTM, I can see the percentage indicator loading up to and then at 100% the screen changes from the rolling circular lines to a...

Looks like there is an issue running Monterey VMs on M4 devices. I tried both UTM and VirtualBuddy, and UTM have an open issue on this:
github.com/utmapp/UTM/i...

12.11.2024 13:58 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

It was due to Apparency app.

12.11.2024 13:58 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

@theevilbit is following 18 prominent accounts