Csaba Fitzl @theevilbit.bsky.social · 07/10/2025🍎 Thank you @macsysadmin.bsky.social for having me! It was a blast as always! I'm already waiting for 2026. #msa2025 /photos by Jonas Jöreskog/ 130
Reposted by Csaba Fitzlkandji.bsky.social @kandji.bsky.social · 20/02/2025Did you see the news last week? 👀 Kandji announced Vulnerability Management to help IT and security teams identify, assess, prioritize, and remediate vulnerabilities on Mac devices - all through a unified workflow in a unified platform. Read more about it here: buff.ly/432J9E6buff.lyVulnerability Management: First Unified Platform to Detect & Remediate on MacKandji announces Kandji Vulnerability Management, which helps IT and security teams identify and remediate vulnerabilities through a unified workflow. 022
Reposted by Csaba FitzlArmin Briegel @scriptingosx.com · 21/02/2025This week's news summary, we look briefly at the new phone before we look some beefy malware and vulnerabilities, some nice configuration profiles and updates. macadmins.news/issues/349 #Mac #MacAdmins #Applemacadmins.news#349new iPhone: it's a 16e 001
Csaba Fitzl @theevilbit.bsky.social · 21/02/2025🍎🪳My last blog post in the storagekitd - diskarbitrationd vulnerability series, which I presented at #POC2024 and @blackhatevents.bsky.social #BHEU2024 as part of my "Apple Disk-O Party" talk, is up @kandji.bsky.social 's site: www.kandji.io/blog/macos-a...kandji.ioUncovering Apple Vulnerabilities: diskarbitrationd and storagekitd Audit Part 3Exploring CVE-2024-27848 & CVE-2024-44210: How macOS vulnerabilities in storagekitd allowed privilege escalation, how they were exploited & Apple’s patch. 011
Csaba Fitzl @theevilbit.bsky.social · 08/01/2025First Apple🍎 macOS 💻 vulnerability of 2025 is submitted. 🥳 Full access to your iCloud documents... 060
Csaba Fitzl @theevilbit.bsky.social · 29/12/2024Year In Sport 2024. Wasn't that good due to my lingering plantar fasciitis issue. But that is life, sometimes there are low moments, and coming out of those will make you stronger. Hopefully things will get better next year. ⛰️🏃 020
Csaba Fitzl @theevilbit.bsky.social · 21/12/2024🏝️🥾🏃🌋I wrote about my hiking and trail running adventures in Maui, Hawaii, which I did right before #OBTS Enjoy! trails.exposure.co/maui-hawaii-...trails.exposure.coMaui, Hawaii (ENG) by Csaba Fitzl on ExposureHUNGARIAN / MAGYAR 020
Csaba Fitzl @theevilbit.bsky.social · 12/12/2024🍎🪳Second part of the diskarbitrationd - storagekitd vulnerability blog series is out on @kandji.bsky.social 's blog. These vulnerabilities were presented at @blackhatevents.bsky.social #BHEU2024 and #POC2024 conferences as part of my "Apple Disk-O Party" talk. www.kandji.io/blog/macos-a...kandji.ioUncovering Apple Vulnerabilities: diskarbitrationd and storagekitd Audit Part 2Part 2 of the audit Kandji's Threat Research team performed on the macOS diskarbitrationd & storagekitd system daemons, uncovering several vulnerabilities. 010
Csaba Fitzl @theevilbit.bsky.social · 09/12/2024📣I’m happy to announce that I’m planning to write a brand new “macOS Vulnerability Research” training. 🥳 Considering the amount of work the writing requires it will be available late 2025 or early 2026. It will be Live class only, and likely only once or twice a year. 0205
Csaba Fitzl @theevilbit.bsky.social · 06/12/2024☀️🏝️This is the day! Don’t miss it if you want to learn how to talk with launchd and how to generically detect XPC exploits. 🔥🔥🔥 #OBTS 080
Reposted by Csaba FitzlXPN @xpnsec.com · 02/12/2024Good lineup of books! www.humblebundle.com/books/hackin...humblebundle.comHumble Tech Book Bundle: Hacking 2024 by No StarchLevel up your hacking and skills with this tech bundle from No Starch. Learn to protect yourself and others! Pay what you want & support charity! 1208
Reposted by Csaba FitzlBrandon Dalton @partyd0lphin.bsky.social · 05/12/2024Extremely excited to be giving a talk titled "Mac, Wheres My Bootstrap" tomorrow at #OBTS with @theevilbit.bsky.social! Join us live on YouTube or in-person at 2:40pm HST / 7:40pm EST. We'll be dropping a tool you can walk away with :) 093
Csaba Fitzl @theevilbit.bsky.social · 05/12/2024We are doing again a community run tomorrow. We will meet at the lobby, at the “Aloha” sign at 8AM, and run about 5k north on the beach and then back. #OBTS10k #OBTS 000
Csaba Fitzl @theevilbit.bsky.social · 04/12/2024Entering last day of trainings with my colleagues from @kandji.bsky.social . There is always something new to learn in this field, and it’s great to learn directly from iOS experts @naehrdine.bsky.social and Sn0wfreeze #OBTS 060
Reposted by Csaba FitzlPhil Stokes ⫍🐠⫎ @philofishal.bsky.social · 30/11/2024@sentinelone.com is hiring - #macOS detection engineer. www.sentinelone.com/jobs/?gh_jid...sentinelone.comCareers at SentinelOneTake a look at the open positions at SentinelOne. We're dedicated to defending enterprises across endpoints, containers, cloud workloads, and IoT devices in a single cybersecurity platform. 067
Csaba Fitzl @theevilbit.bsky.social · 01/12/2024A dream came true. My first ever Sea To Summit climb, here on Maui. Climbed the 3055m high Haleakala volcano’s highest summit, Red Hill, from the ocean over 30kms. #OBTS 0130
Reposted by Csaba FitzlPhil Stokes ⫍🐠⫎ @philofishal.bsky.social · 25/11/2024@vxundergroundre.bsky.social has been kind enough to host Banshee Stealer's leaked source code here. #macOS #InfoStealer #apple #malware github.com/vxundergroun...github.comGitHub - vxunderground/MalwareSourceCode: Collection of malware source code for a variety of platforms in an array of different programming languages.Collection of malware source code for a variety of platforms in an array of different programming languages. - vxunderground/MalwareSourceCode 0193
Csaba Fitzl @theevilbit.bsky.social · 25/11/2024🥾🏃⛰️ It was long time ago I last wrote about my runs or hikes. Below is a post about the trails I explored when I was in South Korea for the POC2024 conference. Enjoy! trails.exposure.co/on-the-trail...trails.exposure.coOn the Trails of Seoul by Csaba Fitzl on ExposureTrail running story from South Korea. 000
Reposted by Csaba FitzlPhil Stokes ⫍🐠⫎ @philofishal.bsky.social · 21/11/2024Been a while since we've seen #macOS #malware abusing osacompile rather than plain osascript, but #Amos Atomic Stealer is nothing if not adaptable. SHA1: 51ef05c84eea3dde149a5dd3ea9916a824e95afc. A reminder that it's possible (didn't say easy 😅) to reverse compiled #applescript. s1.ai/fadedeads1.aiFADE DEAD | Adventures in Reversing Malicious Run-Only AppleScripts - SentinelLabsWe show how to statically reverse run-only AppleScripts for the first time, and in the process reveal new IoCs of a long-running macOS Cryptominer campaign. 02311
Reposted by Csaba Fitzljiska @naehrdine.bsky.social · 17/11/2024How does the new iOS inactivity reboot work? What does it protect from? I reverse engineered the kernel extension and the secure enclave processor, where this feature is implemented. naehrdine.blogspot.com/2024/11/reve...naehrdine.blogspot.comReverse Engineering iOS 18 Inactivity RebootWireless and firmware hacking, PhD life, Technology 12277106
Reposted by Csaba FitzlGynvael Coldwind @gynvael.bsky.social · 19/11/2024Paged Out! #5 is out – enjoy! pagedout.institute And if you like the cover, we have wallpapers! 03616
Csaba Fitzl @theevilbit.bsky.social · 19/11/2024I was featured in PagedOut Issue #5 with my macOS notification forensics article (page 25). I find the whole idea of this magazine pretty cool. Lot's of interesting stuff in there! 081
Reposted by Csaba FitzlPhil Stokes ⫍🐠⫎ @philofishal.bsky.social · 17/11/2024Excellent stuff even though i’m not really a phone guy. Love the reversing and the detailed explanation of the process. 👏 👏 naehrdine.blogspot.com/2024/11/reve...naehrdine.blogspot.comReverse Engineering iOS 18 Inactivity RebootWireless and firmware hacking, PhD life, Technology 0104
Reposted by Csaba Fitzltypealias @typealias.bsky.social · 17/11/2024@theevilbit.bsky.social 's Apple Disk-O Party powerofcommunity.net/poc2024/Csab...powerofcommunity.net 131
Reposted by Csaba FitzlPhil Stokes ⫍🐠⫎ @philofishal.bsky.social · 15/11/2024#Apple added three new rules for XCSSET - a #malware we’ve not seen since 2021 - to #XProtect this week as DubRobber F, G & H in v5282. Curious, to say the least. 251
Reposted by Csaba FitzlPhil Stokes ⫍🐠⫎ @philofishal.bsky.social · 15/11/2024Bunch of new Amos/Atomic #macOS #infostealers if you pivot off ```behaviour_processes:"sh -c curl -s https[:]//api.ipify[.]org/?format=text" tag:macho``` Low detections on V(h/t x.com/malwrhuntert...) #malware #apple #cybersecurity 2237
Csaba Fitzl @theevilbit.bsky.social · 14/11/2024Apple M4 devices can't virtualize macOS versions prior to 13.4. Hopefully this will get fixed. More info here: developer.apple.com/forums/threa...developer.apple.comM4 devices - VMs pre 13.4 fail to … | Apple Developer Forums 001
Reposted by Csaba FitzlPhil Stokes ⫍🐠⫎ @philofishal.bsky.social · 12/11/2024Last week, we released new research about new Mac #malware with TTPs consistent with suspected DPRK #APT BlueNoroff. s1.ai/BNThief. This week, friends-of-NK say we’re shills for US gov. 😂 easternherald.com/2024/11/10/s... Hate to break it to ‘em, but that ain’t how we roll. 😆s1.aiBlueNoroff Hidden Risk | Threat Actor Targets Macs with Fake Crypto News and Novel PersistenceSentinelLabs has observed a suspected DPRK threat actor targeting Crypto-related businesses with novel multi-stage malware. 094
Csaba Fitzl @theevilbit.bsky.social · 12/11/2024Looks like there is an issue running Monterey VMs on M4 devices. I tried both UTM and VirtualBuddy, and UTM have an open issue on this: github.com/utmapp/UTM/i...github.comApple M4 - Mac UTM open to black screen · Issue #6794 · utmapp/UTMBlack Screen upon UTM Build. When trying to spin up a NEW Mac Monterey UTM, I can see the percentage indicator loading up to and then at 100% the screen changes from the rolling circular lines to a... 000
Csaba Fitzl @theevilbit.bsky.social · 12/11/2024Finder hangs (with the beachball) for a few seconds every time I delete an app. This happens even on a brand new Mac. Anyone knows why is that and how to fix it (if possible)? 110
Reposted by Csaba FitzlNorth Pole Security @northpolesec.bsky.social · 11/11/2024Last week we made our first Open Source release of Santa version 2024.10 github.com/northpolesec... Highlights: 1. Streamlined UI with silencing options and added a button to copy relevant data to the clipboard to help users report issues / blocks to security 102
Csaba Fitzl @theevilbit.bsky.social · 08/11/2024🍎🐛🎙️Following my #poc2024 talk we are releasing a blogpost series at Kandji, detailing the vulnerabilities of diskarbitrationd and storagekitd I discussed in my "Apple Disk-O Party" talk. First part is out, and covers CVE-2024-44175. www.kandji.io/blog/macos-a...kandji.ioUncovering Apple Vulnerabilities: The diskarbitrationd and storagekitd Audit Story Part 1Kandji's Threat Research team performed an audit on the macOS diskarbitrationd & storagekitd system daemons, uncovering several (now fixed) vulnerabilities 001
Csaba Fitzl @theevilbit.bsky.social · 08/11/2024Thank you POC for having me! It was an awesome conference! #poc2024 000
Csaba Fitzl @theevilbit.bsky.social · 25/10/2024🍎Another awesome blogpost from my colleagues Chris and Adam about a recently discovered macOS malware. 🎉 www.kandji.io/blog/fake-cl...kandji.ioIt’s About The Journey: Fake Cloudflare AuthenticatorA suspicious looking file on VirusTotal named Cloudflare Security Authenticator/cloudflare-auth-tauri was found 10/15/24 & uploaded from China the same day 000
Reposted by Csaba FitzlDan Underwood @underwood.digital · 24/10/2024Proud of my colleagues who have driven the work on this - we just launched a huge amount of security material for PCC (Private Cloud Compute), including a new security guide, Virtual Research Environment, and source code security.apple.com/blog/pcc-securit… 052
Csaba Fitzl @theevilbit.bsky.social · 24/10/2024As always, Hacktivity Conference in Budapest was a blast! Great talks, and was good to see old friends and meet new people. See you in 2025! /photos by Dávid Tóth - thanks! 🙏/ 000
Csaba Fitzl @theevilbit.bsky.social · 18/10/2024👏 Kudos to the Apple engineers who worked on my storagekitd - diskarbitrationd vuln patches. The patch: ⭕️ had to be applied across multiple components ⭕️ had to account for multiple vulns, where the patches could have messed up each other ⭕️ involved a very complex process flaw 100
Csaba Fitzl @theevilbit.bsky.social · 15/10/2024🍎🗒️ New macOS persistence blog post. 🎉 ➡️ Persist through the NVRAM - The 'apple-trusted-trampoline' Meet the rc.trampoline launchd 🚀 boot task. theevilbit.github.io/beyond/beyon...theevilbit.github.ioBeyond the good ol' LaunchAgents - 35 - Persist through the NVRAM - The 'apple-trusted-trampoline'This is part 35 in the series of “Beyond the good ol’ LaunchAgents”, where I try to collect various persistence techniques for macOS. For more background check the introduction. TL;DR - This is a prac... 021
Csaba Fitzl @theevilbit.bsky.social · 21/03/2024I pushed a massive update to @axelexic 's CSOps project, doing bug fixes and adding new functionality. I plan to add even more stuff later. If you want to play with the csops system call on macOS, this is the tool 👇 github.com/axelexic/CSOps 000
Csaba Fitzl @theevilbit.bsky.social · 19/03/2024🆕🍎 My new blogpost at Kandji about how Apple attempts to mitigate some installer script vulnerabilities using "Install Script Actions" and "Install Script Mutations" in the PackageKit framework. blog.kandji.io/apple-mitiga... 000