Joined April 2010
1,001 Photos and videos
Pinned Tweet
📣 MAJOR ANNOUNCEMENT!! 📣 Our very first public training with @gergely_kalman will be at Zer0Con If you want to get into macOS Vulnerability Research, then: This Is The Way. 👇👇👇
[Zer0Con2026] TRAINING "macOS Vulnerability Research Training" by @theevilbit & @gergely_kalman 🗓️Date: 30th Mar ~ 1st April 2026 (3 DAYS) 📌Fairmont Ambassador Seoul, South Korea Sign up: zer0con.org/#training-sectio… #Zer0Con2026
1
6
40
7,969
Our next macOS Vulnerability Researcher trainings with @gergely_kalman will be: 📆 2026-10-12 - 15: Self-organized, 4 (!!!!) day training (Budapest, Hungary) 📆 2026-11-15 - 17: Objective by the Sea v9 (Hawaii, USA) More info here: macosvuln.training/
4
8
602
Csaba Fitzl retweeted
Apple open-sourced Darwin's #XZone allocator in libmalloc-792 late last year. #DFF Co-Founder & CTO Jonathan Levin (@Morpheus______) breaks it all down, expanded from his book Disarming Code: type isolation, the xzm_malloc() path, and walking the heap with memento(j). df-f.com/blog/darwin-libsyst… #DFFenders Blog
28
129
7,386
RT @_inside: VirtualBuddy 2.2 beta 1 is out with support for automatic macOS account provisioning in macOS 27 🥳 #wwdc26 t.co/7mhYek
6
Csaba Fitzl retweeted
Apple Filing Protocol (AFP) is officially dead in macOS 27 after 41 years!! RIP 1985-2026 🪦💐 Apple designed AFP protocol alongside the AppleTalk networking suite to handle plug-and-play file and printer sharing for early Macintosh computers. HT: u/Fish_Softron
20
106
897
46,279
Csaba Fitzl retweeted
Lineup for the next (free!) Objective for the We #OFTW is 🔥 📍 Berlin 🗓️ July 30–31, 2026 Join us! 🤩 Only ~2 weeks left to apply: objective-see.org/oftw/v4.ht…
Replying to @objective_see
🍎🐛🔬🛡️👩🏼‍💻👨🏻‍💻😍
7
22
3,977
Some thoughts on Fable\Mythos and the US government: 1. Regulation on software rarely works, and those models are an incremental step from Opus 4.6 (in my opinion). Nothing stops other companies from implementing similar models (as well as the latest open-weight models). 2. Where do you draw the line? Here it was clear since Anthropic's statements backfired, but future cases would not look like that. 3. With technology, once a genie is out of the bottle it's almost impossible to get it back in. We as an industry will have to accept the fact vulnerabilities (at least the low hanging ones) are going to be found en-masse - and thus, the next investment should be fixing those - at scale. 4. And lastly, my opinion is that hallucinations, prompt injection or any type of "convincing" of models will always be possible with *current* LLM architecture, unless done cryptographically (e.g. each prompt is signed with a certificate that Anthropic decided is to be trusted).
1
3
468
Csaba Fitzl retweeted
🔺NEW: Apple is expanding Private Cloud Compute (PCC) beyond our data centers. PCC on Google Cloud: NVIDIA Confidential Computing, Intel TDX, and Google's Titan chip, with capabilities that go far beyond a traditional confidential computing deployment. security.apple.com/blog/expa…
6
97
509
53,951
Now that Apple says Parental Control is critical - will those PC bypasses finally count as security issues? Because currently they are not.
3
24
2,149
Csaba Fitzl retweeted
4
104
586
15,462
Csaba Fitzl retweeted
MSRC woke up and decided to kill off all the good will it has built up over the last decade: microsoft.com/en-us/msrc/blo…
13
59
361
28,494
Csaba Fitzl retweeted
🔥 New (guest) blog just dropped! “When Good /bins Go Bad: A Remote Pre-Auth Overflow in LLDB’s debugserver” objective-see.org/blog/blog_… Mahalo to Nathan (@calysteon) for detailing his discovery of this bug, which has since been patched by Apple as CVE-2025-43504 🙏🏽
2
16
74
6,426
Csaba Fitzl retweeted
Offensivecon's talks are now available on our YouTube channel! 🔗 buff.ly/g63xgm5
1
100
340
24,544
After having 100 CVEs with Apple, and working with their security team even before ASB was a thing, this below is simply not how things work in real life. Mistakes happen, and duplicates happen (I always got credit even for those) but ASB is still one one the best BB programs out there.
🚨APPLE ADVERTISES $2 MILLION FOR FINDING SECURITY BUGS.. THEN CALLS YOUR DISCOVERY A "DUPLICATE".. PATCHES IT SILENTLY.. GIVES YOU NOTHING.. AND BANS YOUR APPLE ID IF YOU COMPLAIN.. Two researchers found a critical macOS vulnerability that let attackers steal passwords, encrypted chats, and Safari data through Archive Utility.. Submitted it October 2025.. Apple took 5 months.. Patched it with zero credit.. Zero CVE.. Zero bounty.. Their reason.. "You were not the first person to report this issue".. That's the duplicate loophole.. Apple claims an internal engineer found it first.. But researchers can't verify that.. Apple controls the tracking system.. No audit.. No appeals.. The researcher said it felt like "doing charity work for a $3 trillion company".. Another researcher found apps could access your entire photo library even after you turned off access in settings.. Apple's own page lists that at $50,000.. They reported it.. Apple went silent.. Patched it quietly.. Said it was a duplicate.. $0.. When the researcher blogged about it.. Apple permanently banned their 12-year-old Apple ID.. Apple's brand new Passwords app in iOS 18 was sending data over unencrypted HTTP.. A credential manager transmitting password reset links in plaintext.. Any attacker on the same WiFi could intercept them.. Researchers reported it.. Apple let it sit 3 months.. Patched it quietly.. Said it "didn't meet the impact criteria".. Then there's the FaceTime disaster.. A 14-year-old discovered you could eavesdrop on anyone's iPhone.. Start a FaceTime call.. Add your own number before they answer.. Their microphone turns on.. If they hit the volume button.. Their camera activates too.. His mother spent a week trying to tell Apple.. Emails.. Faxes.. Social media.. Support told her to pay $99 for a developer account to file a bug report.. Apple did nothing until the exploit went viral and millions started eavesdropping on each other.. Then they panicked.. Took FaceTime offline globally.. Congress sent formal letters to Tim Cook demanding answers.. Then there's the researcher who got so fed up being ignored that they hacked Apple's own internal daily security call.. They'd reported a zero-click iMessage vulnerability.. Apple stonewalled them.. So they found another flaw.. Used it to infiltrate the internal FaceTime call where Apple engineers discuss bugs.. And dropped a screenshot proving the exploit live.. The team securing 2.35 billion devices couldn't secure their own meeting.. Apple's response.. A threatening legal letter.. Not a bounty.. A legal threat.. This is why the exploit black market thrives.. A zero-click iPhone exploit sells for $1.5 to $2.5 million on the gray market.. Guaranteed payment.. No bureaucracy.. No "duplicate" risk.. Submitting to Apple means NDAs.. 6-12 months of waiting.. Risk of $0.. Risk of your Apple ID being banned if you speak up.. Those gray market exploits end up with mercenary spyware vendors like NSO Group.. Deployed against journalists and human rights lawyers worldwide.. Apple pushes researchers toward the black market.. Then spends billions defending against the exploits those researchers could have sold them for a fraction of the price.. 2.35 billion devices.. And the company would rather send lawyers than pay what they owe.
6
11
116
26,600
Csaba Fitzl retweeted
While testing our ML detection models, we detected on a new cross-platform campaign we're tracking as SStar Agent. Most of the Mach-O samples were sitting at zero detections on virustotal. We have gone and analyzed the the macOS and Windows variants. iru.com/blog/sstar-agent?hs_… @officiallyiru @Declinee18

3
7
616
Csaba Fitzl retweeted
[#POC2026 NOTICE] Your offensive conference is BACK again in its shape! and POC2026 begins in a new home. ⏰ Date: November 12–13 📍 New Venue: The Westin Seoul Parnas, Korea 🇰🇷 👨‍🏫 CFT: June 1 – June 26 🎙️ CFP: June 1 – September 30 🎟️ Registration: September 1 – October 31 More info 👉 powerofcommunity.net
18
59
6,357
Csaba Fitzl retweeted
🔺NEW: Formally verified post-quantum ML-KEM and ML-DSA in corecrypto, with correctness proven from the FIPS spec down to hand-optimized ARM64 assembly — a world first at multi-billion device scale. And we're releasing our Isabelle libraries, ARM64 model, and Cryptol-to-Isabelle translator to advance the state of the art in verified cryptography! security.apple.com/blog/form…
10
103
438
47,644
Introduction to the Mach-O file structure, plus a bug I found in Apple's own Mach-O parser! Read about it here: github.com/yo-yo-yo-jbo/mach…
1
12
86
6,670
Csaba Fitzl retweeted
On macOS if you want to mitigate ImageIO bugs you can enable ImageIO out-of-process parsing (ImageIOXPCService sandbox) by exporting IIOEnableOOP=1 via launchctl github.com/0xmachos/dotfiles… github.com/0xmachos/dotfiles…
Uncovering an iOS 26.5 ImageIO Vulnerability zygosec.com/blog
3
14
115
12,817
Csaba Fitzl retweeted
If you're developing macOS user-mode network extensions and your users are reporting a kernel panic on macOS 26.5, this is of course a (now known) Apple macOS bug ...again 😭 See: developer.apple.com/forums/t…
1
6
76
5,558