Sign in

golby

@golby.bsky.social
344 followers 255 following 43 posts

macOS Threat and Detections Researcher @ Jamf

PostsRepliesMedia
Reposted by golby
Scott Blake @mscottblake.bsky.social · 29/09/2026
My routine Claude Code skills now run on Haiku. Output quality didn't change. Opus plans the script, Sonnet writes it and wraps it in a skill, and Haiku runs it. If a skill breaks on Haiku, it's doing too much thinking. macadminmusings.com/blog/2026/09... #MacAdmins
macadminmusings.com
Reduce Your AI Skill Costs
Frontier models are for thinking, but you don’t need all the power for everything. Here is the workflow I use every day, and the skills that keep the costs down.
012
Reposted by golby
Casey Drottar @caseydrottar.bsky.social · 26/09/2026
My goodness, what an incredible moment. After Justin Verlander secured the final out of his career, Tigers manager A.J. Hinch came out of the dugout...to summon Verlander's daughter out to embrace her dad on the mound.
642334460
Reposted by golby
Binary Ninja @binary.ninja · 04/09/2026
A bird? A plane? NO! It's Binary Ninja 6.0, codename "Krypton". Major new stable with massive performance improvements, built-in MCP, Binary Similarity, Extension Manager, TMS320C6x, New User Wizard, and so much more: binary.ninja/2026/09/03/b...
binary.ninja
Binary Ninja - Binary Ninja 6.0 (Krypton)
Binary Ninja is a modern reverse engineering platform with a scriptable and extensible decompiler.
053
Reposted by golby
Wesley Shields @wxs.bsky.social · 24/08/2026
New release with lots of new features and bug fixes. Again, congratulations to Victor and everyone who contributed to making this happen! It’s great to see the continued progress. github.com/VirusTotal/y...
github.com
Release v1.20.0 · VirusTotal/yara-x
Implement SIMD-accelerated masked literal matching (#691). Improve atom extraction heuristics for better performance (#690, 1e14f60). Improve scan performance by applying file size and file header ...
032
Reposted by golby
Jason Broccardo @zoocoup.bsky.social · 20/08/2026
Weird Tiny Desk Al www.npr.org/2026/08/20/g...
npr.org
'Weird Al' Yankovic: Tiny Desk Concert
"Weird Al" Yankovic returns to the Tiny Desk with a couple parodies, a Weezer pastiche and the Emmy-losing closing-credits blues-rock jam to Weird: The Al Yankovic Story.
013
Reposted by golby
Virus Bulletin @virusbtn.bsky.social · 03/07/2026
Jamf's Thijs Xhaflaire analyses PamStealer, a Rust-based macOS infostealer disguised as the legitimate Maccy clipboard manager that uses a two-stage attack chain to silently harvest data and clipboard contents while evading detection. www.jamf.com/blog/pamstea...
021
Reposted by golby
MacAdmins Conference @macadminsconf.bsky.social · 14/04/2026
🎉 Registration for MacAdmins 2026 is now open! Workshops, sessions, and community, July 7–10 in State College, PA. Get the details and register 👇 conta.cc/4tLwJu6 #psumac #macadmins
conta.cc
MacAdmins 2026 registration is live 🎉
Email from MacAdmins Conference Come be part of it Registration; workshops; grants and more! View this Newsletter as Webpage Registration for the 2026 MacAdmins Conference is now open! Join us July 7
002
Reposted by golby
Ricky Mondello @rmondello.com · 12/04/2026
New to macOS 26.4, the menu extra for the Passwords app shares its unlock state with the full app. So if you use Touch ID or your Mac password to unlock the menu extra and then go to add a new password or open an item in the full app, you won't have to authenticate again to unlock the app.
Screenshot of the Settings window for the Passwords app. An arrow points to the “Show Passwords in Menu Bar” setting.Screenshots of the Passwords menu extra with a search.
4667
Reposted by golby
Surprised Eel Historian, PhD @greenleejw.bsky.social · 31/03/2026
The world is stupid, but I just watched a squirrel break into a car in the parking lot below me, steal a package of crackers, and escape to a nearby tree. So at least somebody is winning.
Photograph of a car with a squirrel inside of it, perched on the steering wheel. The car is the color of champaign at a beige convention, and the squirrel is the color of squirrels. The squirrel is holding a package of crackers in it's mouth. They are the kind like you get at a restaurant, where you get two crackers wrapped in plastic.

The driver's side window is slightly cracked. This is how the squirrel got in, and how it got out. It threw the crackers out first, and then climbed out after them. Everything in this operation suggested that this was not the squirrel's first rodeo.A closeup of the squirrel sitting on the steering wheel. The squirrel deserves a name, so we'll call her Anjeloma, and she's what you might call a winner. She is still squirrel colored. The crackers are white, and labeled "Zest." As if Anjeloma needed more zest. Squirrel, please.

You can't see much of the car, but you can see smudges of grunge at the edges of the windshield, where the wipers have cast aside the debris of previous rains and pollen-falls.
14690181574
Reposted by golby
Virus Bulletin @virusbtn.bsky.social · 23/03/2026
Jamf Threat Labs details GhostClaw, a macOS credential-stealing campaign using malicious GitHub repositories and AI-assisted workflows. The analysis notes GhostClaw evolving from npm-style delivery into a GitHub distribution model. www.jamf.com/blog/ghostcl...
011
Reposted by golby
Phil Stokes ⫍🐠⫎ @philofishal.bsky.social · 19/03/2026
If you’ve been disappointed with the results of using #LLMs for #malware analysis, you might like this. 👇 The answer we found to getting reliable LLM output grounded in verifiable facts: a serial adversarial pipeline. #AI #security #macOS s1.ai/advers-llm
s1.ai
Building an Adversarial Consensus Engine | Multi-Agent LLMs for Automated Malware Analysis
Single-tool LLM analysis produces reports that look authoritative but aren't. A serial consensus pipeline catches artifacts and hallucinations at source.
031
Reposted by golby
Wesley Shields @wxs.bsky.social · 06/03/2026
Victor just released v1.14.0 - improvements in macho module, tighter code generation in the compiler and the new “deps” command. Congratulations to everyone involved! github.com/VirusTotal/y...
032
golby @golby.bsky.social · 24/02/2026
Browser based ES/Mac Monitor log analyzer - Story timelines - Sigma rule matching - In-depth process tree analyzer - Much much more! Amazing work by my coworker @txhaflaire.bsky.social Check it out! es.decompiler.dev #macos #malware #reverseengineering #threathunting #dfir
000
Reposted by golby
Sean @flyingwalruss.bsky.social · 22/02/2026
Ah man this got a tear out of me
06621
Reposted by golby
Daniel Gordon @validhorizon.bsky.social · 20/02/2026
Without exaggeration, one of the most epic DPRK reports ever about.gitlab.com/blog/gitlab-...
about.gitlab.com
GitLab Threat Intelligence Team reveals North Korean tradecraft
Gain threat intelligence about North Korea’s Contagious Interview and fake IT worker campaigns and learn how GitLab disrupted their operations.
22912
Reposted by golby
Mac Admins Foundation @macadmins.org · 14/02/2026
Hello world! #MacAdmins #MacAdmin
0106
Reposted by golby
6mile @6mile.githax.com · 01/02/2026
Some of the most popular packages on the OpenClaw official registry ClawHub are malicious @openclaw-x.bsky.social
011
Reposted by golby
John @jmahlman.bsky.social · 24/01/2026
Okay, this is friggin awesome! M.A.C.E is a great tool and I’m so proud of the work we’ve done on the #MSCP. I’ll be honest, my compatriots do way more work than me, I’m just a tiny bit in this project. Still super cool to see here. 9to5mac.com/2026/01/24/m...
9to5mac.com
Apple @ Work: M.A.C.E. app is a prime example of the Mac admins community at work - 9to5Mac
M.A.C.E. simplifies macOS compliance with a free GUI for the mSCP. It’s a prime example of the Mac admin community solving real IT problems.
041
Reposted by golby
Jason Broccardo @zoocoup.bsky.social · 21/01/2026
Hide your couches, Twin Cities
021
Reposted by golby
Jason Broccardo @zoocoup.bsky.social · 19/01/2026
Updated the tracking sheet I made last year now that it's been a year — National Averages After First Year of Trump's Second Term docs.google.com/spreadsheets...
docs.google.com
National Averages After First Year of Trump's Second Term
001
Reposted by golby
Squiblydoo @squiblydoo.bsky.social · 12/01/2026
#100DaysofYARA - Day 11 In looking at automatic YARA generation, yarGen-Go is a must. Just released by @cyb3rops, it is a rewrite and advancement from the original yarGen. We'll look at the same malware from day 10; a targeted HavocC2 loader with decoy. rule at bottom 1/5
162
Reposted by golby
Squiblydoo @squiblydoo.bsky.social · 10/01/2026
#100DaysofYARA - Day 9 YARA looks for the header used in a .SCPT file used by BlueNoroff (DPRK) to target MacOS systems. Script is delivered to victims disguised as a Zoom meeting launcher. e.g. a7c7d75c33aa809c231f1b22521ae680248986c980b45aa0881e19c19b7b1892 Rule at end 1/3
132
Reposted by golby
Squiblydoo @squiblydoo.bsky.social · 05/01/2026
#100DaysofYARA - day 5 The Cert Graveyard project reports and documents abuse code-signing including Apple issued certificates. When reporting a certificate, we want to ensure Apple has all the identifiers they need to investigate and act. Rule at end 1/7
173
Reposted by golby
Virus Bulletin @virusbtn.bsky.social · 06/01/2026
Jamf Threat Labs observed a revamped MacSync Stealer variant delivered as a code-signed and notarized app. Unlike earlier drag-to-Terminal/ClickFix chains, it uses a more deceptive, hands-off approach. www.jamf.com/blog/macsync...
011
Reposted by golby
Karsten Hahn @struppigel.bsky.social · 04/01/2026
I have created a website, where you can share your sample analysis (via links or posts) and search samples for training based on tags and difficulty. If you write analysis blogs, you can share them there. samplepedia.cc
0147
Reposted by golby
Squiblydoo @squiblydoo.bsky.social · 03/01/2026
#100DaysofYARA - Day 3 This relates to obfusheader discussed by @RussianPanda95 and @c0ner0ne. If the dev is going to use hard-coded strings, lets use them to our advantage. This thread will demo Malcat's YARA features. Rule at end of thread 1/5
143
Reposted by golby
Greg Lesnewich @greg-l.bsky.social · 28/12/2025
🚨#100DaysofYARA lives!! 2 time reigning champ Yashraj has kindly offered to take the helm for this community effort! Give the homie a follow 👊 Check the repo to contribute: github.com/100DaysofYARA And gear up for Jan 1 when #100DaysofYARA will kick off!
media.tenor.com
a black and white photo of a man with a stethoscope around his neck screaming .
ALT: a black and white photo of a man with a stethoscope around his neck screaming .
1104
Reposted by golby
The Bob @theboberito.bsky.social · 09/12/2025
If you like reading NIST special publications, I got a newly revved 800-70 for you. csrc.nist.gov/News/2025/dr...
csrc.nist.gov
Draft SP 800-70 Rev 5 is available for comment | CSRC
NIST Special Publication (SP) 800-70r5 ipd (Revision 5, initial public draft), National Checklist Program for IT Products – Guidelines for Checklist Users and Developers, is now available for public c...
021
Reposted by golby
Virus Bulletin @virusbtn.bsky.social · 26/11/2025
Jamf Threat Labs warn that fake job assessments that ask you to run terminal commands could be a social engineering scheme to deploy the FlexibleFerret malware (a malware family attributed to DPRK-aligned operators) and steal your credentials. www.jamf.com/blog/flexibl...
002
golby @golby.bsky.social · 14/11/2025
Another great writeup from @txhaflaire.bsky.social on a new stealer that Jamf is calling digitstealer. www.jamf.com/blog/jtl-dig...
jamf.com
DigitStealer: In-Depth Analysis of a New macOS Infostealer
Jamf Threat Labs uncovers DigitStealer, a new macOS infostealer. Learn about its unique evasion techniques, multi-stage payload and how to protect your systems.
050
golby @golby.bsky.social · 04/11/2025
Oooh XProtect 5322 added XPScripts.yr. Guess they're going to start blocking malicious osascript and other interpreters now.
010
golby @golby.bsky.social · 13/10/2025
OBTS bound! #obtsv8
010
Reposted by golby
The Bob @theboberito.bsky.social · 06/10/2025
A year into Apple Intelligence, what do we know? Well your Mac knows the answers, just gotta ask the right questions. Read “IQ Check: On-Device vs PCC — Reading the Signals Hidden on Your Mac“ by Bob Gendler on Medium: boberito.medium.com/iq-check-on-...
boberito.medium.com
IQ Check: On-Device vs PCC — Reading the Signals Hidden on Your Mac
Your Mac knows and can tell you specifically on device vs off device for Apple Intelligence
012
golby @golby.bsky.social · 24/09/2025
Interested in Mac security research, reversing macOS malware, or detection engineering? Jamf Threat Labs is hiring! We're looking for passionate individuals to join our team and and help push the boundaries of Apple security. - Brno, Czechia - Austin, Eau Claire, Minneapolis
132
Reposted by golby
Pasquale Stirparo 🇺🇦 🇪🇺 @pstirparo.bsky.social · 30/07/2025
🍎 machofile 🍏 first official release is finally live: github.com/pstirparo/ma... It is a python module to parse #Mach-O binary files, with a focus on malware analysis and reverse engineering. machofile is self-contained. #macho #ios #reverseengineering #detection #threathunting #threatintel 1/3
github.com
GitHub - pstirparo/machofile: machofile is a module to parse Mach-O binary files
machofile is a module to parse Mach-O binary files - pstirparo/machofile
11514
golby @golby.bsky.social · 16/07/2025
A great writeup by my coworker, @txhaflaire.bsky.social about a new variant (signed and notarized) of odyssey stealer. www.jamf.com/blog/signed-...
jamf.com
Evolution of macOS Odyssey Stealer: New Techniques & Signed Malware
Discover new technical insights into the Odyssey Stealer malware, including signed & notarized variants, SwiftUI-based social engineering, and advanced persistence techniques.
020
Reposted by golby
The Bob @theboberito.bsky.social · 04/07/2025
Forgot to post this here the other day Compliance updatepalooza. Newly released updated mSCP compliance information for macOS Sequoia, macOS Sonoma, macOS Ventura, iOS 18, iOS 17, iOS 16, and visionOS. github.com/usnistgov/ma...
github.com
Releases · usnistgov/macos_security
macOS Security Compliance Project. Contribute to usnistgov/macos_security development by creating an account on GitHub.
043
Reposted by golby
Thomas Roccia :verified: @fr0gger.infosec.exchange.ap.brid.gy · 26/06/2025
🤓 My talk at AUSCERT has been released! In this session, I break down: - How threat actors are using generative AI, - How to respond to AI-related breaches, - And how to improve your AI security maturity with AI-specific incident response, Indicators of Prompt Compromise, and NOVA for […]
infosec.exchange
Original post on infosec.exchange
001
golby @golby.bsky.social · 25/06/2025
Well this is new 🙃
011
Reposted by golby
Jeff Bakalar @jerf.xyz · 21/06/2025
ugh could you imagine if there wasn't a new Turnstile album
10785
Reposted by golby
Rob Friedman @pitchingninja.com · 19/06/2025
So you wanna be a Hitter??! This is what 101 mph Fastball & a 91 mph Slider looks like (from Chase Shores)
713427
Reposted by golby
alden @re.wtf · 18/06/2025
excited bc today @huntress.com is releasing our analysis of a gnarly intrusion into a web3 company by the DPRK's BlueNoroff!! 🤠 we've observed 8 new pieces of macOS malware from implants to infostealers! and they're actually good (for once)! www.huntress.com/blog/inside-...
huntress.com
Inside the BlueNoroff Web3 macOS Intrusion Analysis | Huntress
Learn how DPRK's BlueNoroff group executed a Web3 macOS intrusion. Explore the attack chain, malware, and techniques in our detailed technical report.
13019
Reposted by golby
John @jmahlman.bsky.social · 13/06/2025
Cotton Bureau, is celebrating their 12th anniversary and they’re running a free shipping promo! All products ship for free (inside the US) with the code Happy12. Int’l shipping is half-off. Promo ends 6/20. So head to macadmins.org/store and upport the #macAdmins Foundation!
011
Reposted by golby
🇺🇦 Xorhex 🇺🇦 @xorhex.bsky.social · 12/06/2025
#mlget has been updated - your 1 stop shop for finding malware across different services! Grab an updated copy at github.com/xorhex/mlget... Happy to add additional services if folks know of more! Some services I no longer have access to for testing - see the Alt text for more info.
Latest test run: For the ones that failed, I either don’t have a current API key to test with or an instance of the service to test against.  

If folks can test and let me know, I’d be very grateful!   Please submit an issue in GitHub if it’s broken. Thanks! 😀
264
Reposted by golby
The Bob @theboberito.bsky.social · 10/06/2025
I published my first app on the App Store! macOS, iPadOS, and visionOS! apps.apple.com/us/app/unive...
apps.apple.com
‎Universal STIG Browser
‎Universal STIG Browser is a native Apple platform app that allows users to open, view, filter, and export Security Technical Implementation Guides (STIGs) for all supported platforms as published by ...
024
Reposted by golby
Game Informer @gameinformer.com · 06/06/2025
Game Informer magazine subscriptions are back! 🎉 Lock in early bird pricing by joining today and receive a full year of 10 issues featuring more pages and improved paper. gameinformer.com/subscribe 📽️ youtu.be/xB-wxCebt1U?... #GameInformer #Subscribe
youtu.be
Game Informer Magazine Print Subscriptions Are Available Now
Today, we’re thrilled to unveil the new Game Informer subscription program. We relaunched Game Informer in March so we could return to covering the games we ...
35290106
Reposted by golby
Jason Broccardo @zoocoup.bsky.social · 26/05/2025
Example of a website that entirely lives up to its name owlsintowels.org/gallery/
owlsintowels.org
GALLERY – Owls in Towels
001
golby @golby.bsky.social · 23/05/2025
Cross-posting @malwarezoo@bird.makeup Modified versions of Termius (SSH client) were uploaded to VirusTotal. Contains a persistent downloader which fetches and decodes Khepri (an open-source post-exploitation tool). /Applications/Termius.app/Contents/Fra... Helper .app/Contents/MacOS/.localized
110
Reposted by golby
pancake @trufae.bsky.social · 16/05/2025
Today I presented at #hackbcn some practical usecases integrating language models for reverse engineering purposes with #radare2 Check out my slides at radare.org/get/r2ai-hac...
0105
Reposted by golby
Tom Bridge @tombridge.com · 16/05/2025
Human-Centric IT Systems Here are the slides and presentation notes from my talk today at MacAD in Brighton. We need to do better about building human-centric IT systems that serve your business goals, and your people.
tombridge.com
Human-Centric IT Systems
Here are the slides and presentation notes from my talk today at MacAD in Brighton. We need to do better about building human-centric IT systems that serve your business goals, and your people.
062