Objective-See Foundation

5K posts

Objective-See Foundation banner
Objective-See Foundation

Objective-See Foundation

@objective_see

🍎 🛡️ 🛠️ Open-Source Tools 📚 "The Art of Mac Malware" books 🫂 "Objective by the Sea" conference Support us on https://t.co/tuGceSeyiC 🙏

Maui, Hawaii Katılım Ekim 2011
1 Takip Edilen18.7K Takipçiler
Sabitlenmiş Tweet
Objective-See Foundation
Objective-See Foundation@objective_see·
Our Valentine's Day gift 💝 objectivebythesea.org/v9/index.html Announcing Objective by the Sea (#OBTS) v9.0: 👩🏻‍💼 Train: Nov 15-17 👩🏻‍🏫 Talks: Nov 18-20 📍 Maui, Hawaii, 2026 CFP (talks & trainings) and tickets are now officially open! Hope to see you by the sea 🏝️ Special 🙏🏽 to @andyrozen!!
Objective-See Foundation tweet media
English
2
9
38
9.1K
Objective-See Foundation retweetledi
pablito.eth 🦇🔊 @ EthCC 🇫🇷
BlockBlock v2.4.1 is out: Malware often installs itself persistently to ensure it is automatically executed upon restart or login. BlockBlock monitors common persistence locations and alerts whenever a new persistent component is added. It also alerts when pasting dangerous content in the terminal. By @objective_see @patrickwardle
pablito.eth 🦇🔊 @ EthCC 🇫🇷 tweet mediapablito.eth 🦇🔊 @ EthCC 🇫🇷 tweet media
English
2
7
18
2.9K
Objective-See Foundation retweetledi
Patrick Wardle
Patrick Wardle@patrickwardle·
Apple: “3rd-party security tools can’t run in the kernel because they might panic.” Also Apple: kicks us out and replaces us with their EndpointSecurity kext ...which can be trivially panicked from userland, taking down every security tool + the whole system (macOS 26.3.1)! 🙄
Patrick Wardle tweet media
English
18
35
283
21.3K
Objective-See Foundation retweetledi
Jamie Levy🦉
Jamie Levy🦉@gleeda·
sanity checks by using known bodies of work is very powerful
Jamie Levy🦉 tweet media
English
1
2
16
3K
Objective-See Foundation retweetledi
Moonlock Lab
Moonlock Lab@moonlock_lab·
Beware fake VCs on LinkedIn ❗️ Our latest Moonlock Lab report tracks a new #ClickFix campaign using fake Zoom/Meet links + a bogus Cloudflare CAPTCHA to trick victims into pasting malicious commands - cross-platform for macOS & Windows. Featuring findings by @malwrhunterteam and analysis by @L0Psec 🔎 Give it a read 👉 moonlock.com/fake-vcs-targe…
English
0
9
23
6.7K
Objective-See Foundation retweetledi
Dan Guido
Dan Guido@dguido·
seatbelt-sandboxer > Generate minimal macOS Seatbelt sandbox configurations for applications github.com/trailofbits/sk…
Dan Guido tweet media
English
3
9
53
9.1K
Objective-See Foundation retweetledi
Kyle Avery
Kyle Avery@kyleavery·
I'm not sure when this started, but macOS seems to scan JXA scripts at runtime using the Yara rules in: /var/protected/xprotect/XProtect.bundle/Contents/Resources/XPScripts.yr
English
3
9
64
6.5K
Objective-See Foundation retweetledi
Andy Greenberg (@agreenberg at the other places)
A full iOS exploit toolkit, "Coruna," has been found in the wild, hacking iPhones that visited infected websites, used by Russian spies targeting Ukrainians and thieves targeting Chinese crypto holders. And it may have been created for the US government. wired.com/story/coruna-i…
English
8
312
720
99.4K
Objective-See Foundation retweetledi
Mandiant (part of Google Cloud)
Coruna exploit kit is targeting iOS. Coruna leverages 23 exploits against Apple devices running iOS 13-17.2.1. It is being used for espionage, and by financially motivated actors to steal crypto. Update your iOS devices, and learn more about this threat: bit.ly/4rbeltc
Mandiant (part of Google Cloud) tweet media
English
6
119
359
116.6K
Objective-See Foundation retweetledi
Patrick Wardle
Patrick Wardle@patrickwardle·
A few weeks ago, Apple announce that "iPhone and iPad [are] approved to handle *classified* NATO information" 😂 Turns out even lowly cybercriminals were (ab)using 0days to hack Apple devices 🙈 wired.com/story/coruna-i…
English
7
14
48
5.2K
Objective-See Foundation
Objective-See Foundation@objective_see·
Just released: BlockBlock v2.4 🆕 Notarization Mode ('All') Blocks any non-notarized program (even those w/o quarantine attributes). 🆕 Heuristics for 'ClickFix' Applies heuristics against pastes into terminals, blocking those deemed suspicious. objective-see.org/products/block…
Objective-See Foundation tweet media
English
0
11
32
5.2K
Objective-See Foundation
Objective-See Foundation@objective_see·
Just released: RansomWhere? v2.0 By monitoring file entropy in real time, RansomWhere? can generically thwart ransomware! Version 2.0 is a full rewrite leveraging Apple’s Endpoint Security framework, plus a host of other improvements. Read more: patreon.com/posts/152088413
Objective-See Foundation tweet media
English
3
15
82
8.7K
Objective-See Foundation
Objective-See Foundation@objective_see·
Stoked to see our #OBTS scholars crushing it! 🤩 Congrats to Pablo Redondo & Ismael Esquilichi on their recent talk, "macOS XPC Exploiting n-days for !(😄 && 💸)" at Hackon (@hackonurjc)!
Objective-See Foundation tweet mediaObjective-See Foundation tweet mediaObjective-See Foundation tweet media
English
0
3
20
1.6K
Objective-See Foundation retweetledi
Csaba Fitzl
Csaba Fitzl@theevilbit·
🏝️🍎CFP and CFT is submitted. Regardless of the results, see you there!
Objective-See Foundation@objective_see

Our Valentine's Day gift 💝 objectivebythesea.org/v9/index.html Announcing Objective by the Sea (#OBTS) v9.0: 👩🏻‍💼 Train: Nov 15-17 👩🏻‍🏫 Talks: Nov 18-20 📍 Maui, Hawaii, 2026 CFP (talks & trainings) and tickets are now officially open! Hope to see you by the sea 🏝️ Special 🙏🏽 to @andyrozen!!

English
1
3
16
2.5K
Objective-See Foundation retweetledi
xiu
xiu@osint_barbie·
🧵 1/ What a funny story how @g0njxa and I decided to start trading and download TradingView Premium for FREE! (freaking AI is gonna replace us, so...) xD Check this macOS stealer campaign that is using @Reddit karma-farming, allegedly compromised Indian tech company as a redirect, and a ClickFix trick to deliver the SHub Stealer that steals sensitive data, trojans your crypto wallets, and tries to persist disguised as Google Updater. But don't worry - if you have a Russian keyboard, it won't touch you :3
xiu tweet media
English
3
11
48
7K
Objective-See Foundation retweetledi
Moonlock Lab
Moonlock Lab@moonlock_lab·
1/ We just triaged a #macOS sample that looks like a full-featured RAT with a twist - it uses the #Solana blockchain as part of its C2 workflow. Kindly shared by @malwrhunterteam. More below 🧵
Moonlock Lab tweet media
English
1
12
63
7.8K