🛠 🍎 👾 Objective-See'ing & DoubleYou'ing

Joined October 2013
937 Photos and videos
Pinned Tweet
Stoked for the next (ad)venture: "DoubleYou" techcrunch.com/2024/04/25/ex… Cofounded w/ long-time friend @hexlogic, we're empowering those building security tools for Apple devices 🍎🛡️ And by bootstrapping this venture, our core value of democratizing security remains our focus!
21
32
182
42,461
Didn't realize @HexRaysSA's IDA has a config to decrypt Apple-protected binaries - neat! Even better, Hopper does it automatically 🙌🏼 btw 🔑 is : "ourhardworkbythesewordsguardedpleasedontsteal(c)AppleComputerInc" @ninja_binary, this would be a great feature to add 🍎🔓
5
31
334
22,755
However, both IDA and Hopper don't get it quite right 👀 ...and so malware that leverages this can remain partially encrypted in the disassembler 😫 Had to explain the reason to AI 🤖😅
2
1
13
2,595
Lineup for the next (free!) Objective for the We #OFTW is 🔥 📍 Berlin 🗓️ July 30–31, 2026 Join us! 🤩 Only ~2 weeks left to apply: objective-see.org/oftw/v4.ht…
Replying to @objective_see
🍎🐛🔬🛡️👩🏼‍💻👨🏻‍💻😍
7
22
3,920
Fable: "a short, fictional story intended to teach a moral lesson." Maybe the moral? Don't wholly trust Claude Fable (or AI in general) just yet. 🤔😂
1
10
1,832
Patrick Wardle retweeted
I think the scope may be a bit narrower here: the events seem to fire only when the parent/descendant chain are the instigators, not when they’re merely the targets. I just tested this on macOS 27 and that appears to match the behavior. gist.github.com/teodorsoresc…
2
2
1,812
<insert happy noises> 🤩 Looking forward to seeing y'all at @defcon!! 😍
1
2
80
3,452
Neat bug and solid payout! 🙌🏼 And much better than their previous approach, which involved calling your boss and threatening to involve the FBI ...true story! 🫣🤦🏻‍♂️ forbes.com/sites/thomasbrews…
A very cool vuln chain found by @prebenve leading to exposed secrets, GitHub tokens, and 507 private repositories of Meta which got them a #bugbounty of $157k sectricity.com/blog/misconfi…
2
13
2,433
Patrick Wardle retweeted
The SEP plugin now supports iOS 27. You can try it with a decrypted SEP sep-firmware.d38.RELEASE.im4p fc4c4c25e2720a3ef8c424abb30919a1bdbcdcf50bb92d16b9292704085b5338340e717c957585ff62654ec4e12ce2d0
Added a triage view for the SEP plugin
1
7
47
6,057
Patrick Wardle retweeted
If you are experiencing this, it is probably related to this known issue: “Devices configured with Reduced Security … might also be prevented from allowing kernel extensions or disabling System Integrity Protection.” See workaround there. developer.apple.com/document…
Can we no longer disable SIP in MacOS 27, or what is going on here?
1
3
7
3,407
Patrick Wardle retweeted
ℹ️ BlockBlock v2.5.0 adds a new feature that can alert you whenever a downloaded script is about to execute. Designed to complement "Notarization" Mode, it provides an additional layer of protection against potentially unsafe content before it runs. 🛡️ objective-see.org/products/b…
5
21
1,604
yasss, this is delightful 🤩 Handling ES deadlines has always been complex(ish) (e.g. don't forget to use a mach_timebase_info when converting "mach time" to nanoseconds on Apple Silcon!) 😵‍💫 ...and if you got it wrong (and missed a deadline) the kernel would just kill you! ☠️
Neat addition to EndpointSecurity with deadline manipulation in the macOS 27 beta
1
3
19
3,369
I mean, @Apple always just straight up asks for advance copies of slides ...under the guise "to provide researchers with feedback"?! 😂 Still better than the time they showed up in person and asked me to pull a talk 🙄😂
MSRC couldn’t possibly do anything worse this week… oh. Oh ok.
5
10
188
33,269
Patrick Wardle retweeted
Coding assembly == CRIME @AnthropicAI @claudeai
41
65
1,185
86,763
Patrick Wardle retweeted
I just found this old macos EDR evasion persistency office sandbox bypass technique I made like 5 years ago Crazy to look back to how we worked security before AI I literally: - Found a similar article mentioning this persistency by the o.g. @patrickwardle in python, but no poc was published and my target environment had blocked python - DM'd the guy, picked his brain - Spent something like an entire day getting 4 lines of code to work (javascript->objective c bridge, such a mess of a syntax) I bet today this would've be possible to generate within a single prompt if it was properly baked. Anyway I open-sourced it github.com/forefy/JXA-Persis…
2
2
17
2,057
RT @MarceloRivero: Fake LumaNotch macOS app = #NovaStealer (#MioLab) 🧐 🎭 site = near 1:1 clone of dynamichorizon[.]app 🧾 #ClickFix shows a…
11
New macOS Backdoor "FlutterShell" 🍎🐛 Discovered & analyzed by @PaloAltoNtwks @Unit42_Intel 🙌🏼 "weaponizes AI summarization features for data exfiltration by routing documents through an attacker-controlled server before processing them " 👀🔥 unit42.paloaltonetworks.com/…
15
49
5,589