Wojciech Reguła (@_r3ggi) 's Twitter Profile
Wojciech Reguła

@_r3ggi

iOS/macOS app security researcher & blogger. 🍎 Black Hat / DEF CON / TyphoonCon speaker. Head of mobile appsec @SecuRingPL

ID: 3420050055

linkhttps://wojciechregula.blog/ calendar_today13-08-2015 13:08:19

2,2K Tweet

5,5K Followers

863 Following

Wojciech Reguła (@_r3ggi) 's Twitter Profile Photo

Today Apple updated their security advisory for Xcode with my CVE-2024-44228 which allowed malicious apps inheriting Xcode's TCC permissions.

Today Apple updated their security advisory for Xcode with my CVE-2024-44228 which allowed malicious apps inheriting Xcode's TCC permissions.
Oh My Hack (@omhconf) 's Twitter Profile Photo

Wojciech Wojciech Reguła omówi założenia izolacji na macOS oraz techniki exploitacji. Na przykładzie kilku popularnych menedżerów haseł pokaże, jak nieuprzywilejowane złośliwe aplikacje mogą wykorzystywać triki i luki, by wykradać hasła. 🔜 omhconf.pl

Wojciech <a href="/_r3ggi/">Wojciech Reguła</a> omówi założenia izolacji na macOS oraz techniki exploitacji. Na przykładzie kilku popularnych menedżerów haseł pokaże, jak nieuprzywilejowane złośliwe aplikacje mogą wykorzystywać triki i luki, by wykradać hasła. 🔜 omhconf.pl
Csaba Fitzl (@theevilbit) 's Twitter Profile Photo

🍎🐛🎙️Following my #poc2024 talk we are releasing a blogpost series Kandji detailing the vulnerabilities of diskarbitrationd and storagekitd I discussed in my "Apple Disk-O Party" talk. First part is out, and covers CVE-2024-44175. kandji.io/blog/macos-aud…

Wojciech Reguła (@_r3ggi) 's Twitter Profile Photo

PL: Już w przyszłym tygodniu będziecie mogli mnie zobaczyć na konferencji Oh My Hack gdzie opowiem o bezpieczeństwie menedżerów haseł na platformie macOS.

PL: Już w przyszłym tygodniu będziecie mogli mnie zobaczyć na konferencji <a href="/OMHconf/">Oh My Hack</a> gdzie opowiem o bezpieczeństwie menedżerów haseł na platformie macOS.
Mussy (@mu55sy) 's Twitter Profile Photo

🔐 “Broken Isolation - Draining your Credentials from Popular macOS Password Managers” is the last talk before the afternoon break, and it’s a wake-up call we all need. Imagine your trusted vault—built to guard your most precious secrets—suddenly turning into the thief, leaking

🔐 “Broken Isolation - Draining your Credentials from Popular macOS Password Managers” is the last talk before the afternoon break, and it’s a wake-up call we all need. Imagine your trusted vault—built to guard your most precious secrets—suddenly turning into the thief, leaking
Doc Dave (@forensicdave) 's Twitter Profile Photo

Wojciech Regula(Wojciech Reguła) from Securing examined several popular password managers at #OBTS7 - MacPass/Bitwarden/Nordpass/ProtonPass/KeepassXC -showed how low-privileged malware can trick them to share their secrets! Checkout his iOS security training: courses.securing.pl

Wojciech Regula(<a href="/_r3ggi/">Wojciech Reguła</a>) from <a href="/SecuRingPL/">Securing</a> examined several popular password managers at #OBTS7 - MacPass/Bitwarden/Nordpass/ProtonPass/KeepassXC -showed how low-privileged malware can trick them to share their secrets! Checkout his iOS security training: courses.securing.pl
NULLCON (@nullcon) 's Twitter Profile Photo

Is macOS security really as strong as it seems? 🤔 In theory, macOS apps should be fully isolated thanks to notarisation and sandboxing, but in practice, these protections often fall short. Join Wojciech Reguła at #NullconGoa2025 👉 nullcon.net/goa-2025/speak… #macOS #passwordmanager

Is macOS security really as strong as it seems? 🤔

In theory, macOS apps should be fully isolated thanks to notarisation and sandboxing, but in practice, these protections often fall short.

Join <a href="/_r3ggi/">Wojciech Reguła</a> at #NullconGoa2025 

👉 nullcon.net/goa-2025/speak…

#macOS #passwordmanager
noah (@thesubtlety) 's Twitter Profile Photo

OBTS v7 "Broken isolation: Draining your Credentials from Popular macOS Password Managers" by Wojciech Reguła Workstation compromise -> game over. youtube.com/watch?v=DqYyw2…

Wojciech Reguła (@_r3ggi) 's Twitter Profile Photo

Apple fixed 4 my vulnerabilities in macOS 15.4 (support.apple.com/en-us/122373). I believe that the libnetcore and Quick Look issues will also have CVEs assigned as they are not informative severity issues (e.g. full iOS/macOS parental control bypass). 🍎🔐

Apple fixed 4 my vulnerabilities in macOS 15.4 (support.apple.com/en-us/122373). I believe that the libnetcore and Quick Look issues will also have CVEs assigned as they are not informative severity issues (e.g. full iOS/macOS parental control bypass). 🍎🔐