AI Security Research443 Beyond Prompt Injection: Hacking Apple’s Private Cloud Compute (CVE-2026-20685)
A path traversal in darwin-init, the PID 1 process that provisions every Apple Private Cloud Compute node, gave a researcher an arbitrary…
AI Security Research443 A path traversal in darwin-init, the PID 1 process that provisions every Apple Private Cloud Compute node, gave a researcher an arbitrary…
MacOS250 Mysk research details CVE-2026-28910 — a chain of three macOS design flaws that turns the built-in Archive Utility plus a single drag-and-drop…
MacOS202 CVE-2024-32002 turns git clone --recursive into RCE on case-insensitive filesystems. A crafted submodule + symlink can plant a Git hook in .git…
MacOS279 A bug in macOS’s TCP stack causes networking to fail after about 49.7 days of uptime. A 32-bit timer overflow freezes the…
MacOS145 A macOS Recovery Mode Safari flaw allowed attackers to write arbitrary files to system partitions. By placing a malicious LaunchDaemon in /Library/LaunchDaemons,…
Apple Silicon349 The article analyzes the macOS secure boot chain on Apple Silicon, showing how Boot ROM, cryptographic verification, Secure Enclave, and staged bootloaders…
EDR193 The article examines how EDR agents monitor macOS and Linux systems by collecting telemetry from OS security frameworks, kernel interfaces, and tools…