Bill (@billpr0) 's Twitter Profile
Bill

@billpr0

Researcher

ID: 1621438010867712000

calendar_today03-02-2023 09:19:10

45 Tweet

17 Followers

246 Following

Zhongquan Li (@guluisacat) 's Twitter Profile Photo

The blog post on my talk "Unveiling Mac Security: A Comprehensive Exploration of Sandboxing and AppData TCC," presented at BlackHat USA 2024 and KCon 2024, is now available on imlzq.com/apple/macos/20… Thanks for reading.

Max_Malyutin (@max_mal_) 's Twitter Profile Photo

Unpacking #Latrodectus DLL #MalwareAnalysis🕷️ [+] BP VirtualAlloc; ret value RAX This is a useful indicator that the code is about to be unpacked [+] Internal name (unpacked): UpdaterTag.dll [+] Export func: extra, follower, run, scub Sample VT (37/74): virustotal.com/gui/file/1db68…

Unpacking #Latrodectus DLL #MalwareAnalysis🕷️

[+] BP VirtualAlloc; ret value RAX
This is a useful indicator that the code is about to be unpacked

[+] Internal name (unpacked): UpdaterTag.dll
[+] Export func: extra, follower, run, scub

Sample VT (37/74):
virustotal.com/gui/file/1db68…
Mr. OS (@ksg93rd) 's Twitter Profile Photo

#exploit 1. CVE-2024-36974: Linux Kernel taprio_parse_mqprio_opt injection ssd-disclosure.com/ssd-advisory-l… 2. CVE-2024-5274: Type Confusion in V8 in Google Chrome github.com/mistymntncop/C…

Ferdous Saljooki (@malwarezoo) 's Twitter Profile Photo

Our latest research details a Gatekeeper bug we reported to Apple that affects Launch Services. While exploring this issue, we also found ways to bypass Gatekeeper using the “The Unarchiver”, a popular archiving application on macOS. Check out our blog: jamf.com/blog/gatekeepe…

Csaba Fitzl (@theevilbit) 's Twitter Profile Photo

🍎🪳 => Possibly one of my hardest logic vulnerability ever to exploit. So many obstacles to overcome. In collaboration with Gergely Kalman Both of us found the issue and both of us thought it was not exploitable. We happened to discussing it, and a ray of light came through..

Karol Mazurek (@karmaz95) 's Twitter Profile Photo

I finished the promised article about System Integrity Protection #SIP, which introduces the #Apple idea of #rootless on #macOS. The article is for anyone interested in: #Programming #Re #Cybersecurity karol-mazurek.medium.com/system-integri… Enjoy reading!

BleepingComputer (@bleepincomputer) 's Twitter Profile Photo

Hackers exploit 52 zero-days on the first day of Pwn2Own Ireland - Bill Toulas bleepingcomputer.com/news/security/… bleepingcomputer.com/news/security/…

Csaba Fitzl (@theevilbit) 's Twitter Profile Photo

🍎🐛 macOS 15.1 is out, update your Macs. Some of the bugs regarding diskarbitrationd and storagekitd which were patched are not in the advisory...

🍎🐛 macOS 15.1 is out, update your Macs. Some of the bugs regarding diskarbitrationd and storagekitd which were patched are not in the advisory...
Binni Shah (@binitamshah) 's Twitter Profile Photo

Uncovering Apple Vulnerabilities : The diskarbitrationd and storagekitd Audit Story (Part 1) : kandji.io/blog/macos-aud… credits Csaba Fitzl Kandji #CVE-2024-44175

Uncovering Apple Vulnerabilities : The diskarbitrationd and storagekitd Audit Story (Part 1) : kandji.io/blog/macos-aud…  credits <a href="/theevilbit/">Csaba Fitzl</a> <a href="/KandjiMDM/">Kandji</a>  #CVE-2024-44175
Karol Mazurek (@karmaz95) 's Twitter Profile Photo

This article explains how #macOS handles #exceptions on #Apple Silicon (#arm64), transitions between #user - #kernel mode, dives into #syscalls, #interrupts, and fault handling details, and includes a breakdown with a visual Exception Handling Map. Enjoy! karol-mazurek.medium.com/exceptions-on-…

Mussy (@mu55sy) 's Twitter Profile Photo

🔄 We’re switching back to macOS at #OBTS with “Endless Exploits: The Saga of a macOS Vulnerability Exploited Seven Times” by Mickey Jin (Mickey Jin). Imagine a vulnerability so stubborn it plays like a soap opera—patch after patch, bypass after bypass, with privilege escalation

🔄 We’re switching back to macOS at #OBTS with “Endless Exploits: The Saga of a macOS Vulnerability Exploited Seven Times” by Mickey Jin (<a href="/patch1t/">Mickey Jin</a>).

Imagine a vulnerability so stubborn it plays like a soap opera—patch after patch, bypass after bypass, with privilege escalation
Mickey Jin (@patch1t) 's Twitter Profile Photo

My slides for the OBTS is here: github.com/jhftss/jhftss.… Exploits: github.com/jhftss/POC Blog will be posted after the fix of the variant issue.

Winslow (@senzee1984) 's Twitter Profile Photo

Armed with the knowledge learned from OSMR OffSec, I successfully identified several vulnerabilities, covering XPC local privilege escalation and TCC bypass. All programs are still actively maintained and updated , some of them have huge user bases.

Armed with the knowledge learned from OSMR <a href="/offsectraining/">OffSec</a>, I successfully identified several vulnerabilities, covering XPC local privilege escalation and TCC bypass. 

All programs are still actively maintained and updated , some of them have huge user bases.
Hichem Maloufi (@hichem_ifpdz) 's Twitter Profile Photo

New writeup: CVE-2025-24104 – Apple’s bug allowed arbitrary file reads outside the sandbox. While iOS 18.3 added a mitigation, it doesn’t fully fix the issue. I even bypassed it since my recommended fix wasn’t followed. Read more 👉 github.com/ifpdz/CVE-2025… #AppleSecurity

Mr. OS (@ksg93rd) 's Twitter Profile Photo

#exploit 1. Windows LNK - Analysis & PoC zeifan.my/Windows-LNK 2. CVE-2025-0927: Linux Distros Unpatched Vulnerability ssd-disclosure.com/ssd-advisory-l… 3. CVE-2025-24071: github.com/shacojx/CVE-20…

Csaba Fitzl (@theevilbit) 's Twitter Profile Photo

🍎🪳Some new CVEs to the list. 🎉 quarantine Impact: An app may be able to break out of its sandbox CVE-2025-31244 Sandbox Impact: An app may be able to bypass certain Privacy preferences CVE-2025-31224 XProtect We would like to acknowledge ... for their assistance.

Dillon Franke (@dillon_franke) 's Twitter Profile Photo

A bunch of new Apple patches just dropped, including another one found with my Mach message fuzzer 🎉 Fixed in Sequoia 15.5, Sonoma 14.7.6, and Ventura 13.7.6. More details to come soon!

A bunch of new Apple patches just dropped, including another one found with my Mach message fuzzer 🎉 Fixed in Sequoia 15.5, Sonoma 14.7.6, and Ventura 13.7.6. More details to come soon!