Principal @HuntressLabs | Former Detection & Response Principal @CrowdStrike | macOS Security Enthusiast

Australia
Pinned Tweet
I finally got around to blogging about this, and a separate bug (CVE-2024-44219). If you're interested in homedir TCC protections, enforcement via `sandboxd` or the sandbox kernel extension, I'd be pleased if you took a quick look! rdowd.com/castles-made-of-sa…
I doubt that I was the first to find this quirky bug, however the impact of basically having tccd fail open was very easy to overlook. Remains unpatched in Ventura and Sonoma unfortunately.
5
9
48
8,858
You have gotta love a conference run in the sun. Only hanging at the back for the group photos, I swear! 😅 Thanks @mdowd for organising. @UnpromptedAU
1
2
15
1,567
A stand-out talk on the first day of @UnpromptedAU by @clearbluejar. Great insights and food for thought when it comes to finding 0day using frontier models.
1
17
2,248
It looks like these changes were reverted overnight. No official comm’s around what the initial issue was, however.
This report is long since resolved and is one of many marked a duplicate of an internal finding. A bounty was paid two years ago and CVE already issued in my name. I hope Apple has an undo button available for the changes made to ASB overnight.
18
1,454
This report is long since resolved and is one of many marked a duplicate of an internal finding. A bounty was paid two years ago and CVE already issued in my name. I hope Apple has an undo button available for the changes made to ASB overnight.
Very weird times at the ASB - opened my pending vulnerabilities, all are acknowledged, but all of the sudden 60% of them are now marked as "duplicates with internal findings". The problem is that there's no way to know that besides taking Apple's word as it is.
2
2
47
6,564
Ryan Dowd retweeted
Reminder: 🍎-security tools subscribing to ES AUTH_* events must respond before an ES deadline (~15s) or the kernel kills them ...& they stay ☠️ Privileged attacker? SIGSTOP the tool ...⏳💥😂 Mitigation (per @PeteMarkowsky) subscribe to/block signals! docs.google.com/presentation…
1
4
43
10,806
Found that 3 of my bug submissions had been rolled up into CVE-2026-84589. I’ll aim to get a blog released when they’ve formally been resolved by Apple ProdSec.
4
2
36
2,300
Props to @theevilbit and @eisw0lf, among others!
2
188
Ryan Dowd retweeted
Come join our training in Budapest! As it stands we will be able to spend some quality time with the trainees, so if that's your jam there's still room left!
Our next training with @gergely_kalman will be in Budapest between the 12th and 15th of October. This is our only training in Europe for this year, and this is the only time we will teach the 4 day version of the training. If you are looking getting into Apple vuln research then this is Your training. Although we don't do iOS here, many of the concepts we teach are applicable there as well. macosvuln.training/
2
18
1,835
Ryan Dowd retweeted
MioLab MAC Stealer FontConverter_1.4.2.dmg f40932599dbb2499d527cb12474fe841 C2 lewokodwqko[.]icu #MioLab #MAC #Stealer #IOC
8
21
1,673
Ryan Dowd retweeted
Thrilled to announce I will be speaking in Sydney! Hope to catch some of you out at @UnpromptedAU
Ok! The schedule is live as! Check it out: unprompted.au
1
2
17
841
Ryan Dowd retweeted
#PamStealer macOS infostealer · new JXA loader 🧐 🎭 fake CleanDev clones DevCleaner → cleandev[.]cc ⛓️ one char-code .js = whole kill-chain: 🎣 ClickFix → curl → osascript 🧬 self-decodes at runtime · Function('return') 👇 img 🕵️ gauntlet first → anti-VM · ptrace · SIP · CIS ×11 🔑 then RC4 → C2, env-keyed (cracked offline 🤷‍♂️) 📥 only now → stage-2 Mach-O 🥸 fake Finder[.app (real .icns) → com[.apple.finder.agent 🎬 fake "Installation failed" = already infected 📡 notification-portal[.]com 🎯 catch by @ValeryMarchive
2
8
24
1,794
So much knowledge and talent over 3 days. This is going to be 🔥.
Just announced: talks for #OBTS v9 🥳 Stoked on an epic lineup of cutting-edge 🍎- security research, covering exploitation, malware, reversing, security tools, AI, & more! Check out the full lineup: objectivebythesea.org/v9/tal… Which one(s) are you most looking forward to!? 🤔
1
1
8
1,752
Ryan Dowd retweeted
This was interesting. I hadn't seen Google Docs weaponized like that before. @_rdowd @JSemonSecurity and @threatresearch spent some time hunting everything down and it turned out a little more interesting than I previously thought. We never got that linux lure though 🤣 huntress.com/blog/defcon-phi…
20
51
3,300
Ryan Dowd retweeted
My last scan shown around 40k open screen sharing hosts on the internet, almost half in the US, most are residential IPs but there are many juicy hosts in Murican universities, some companies, a server from BBEdit company. Party hard, never expose those services unless behind ssh
3
23
2,447
Ryan Dowd retweeted
Apple’s latest macOS update addresses two Screen Sharing vulnerabilities, including one enabling pre-authenticated remote code execution. Huntress recommends all macOS users update systems immediately. @_rdowd shares detection details and more: okt.to/fW1KFu
1
8
53
4,767
Ryan Dowd retweeted
Kudos to the poor souls at Cupertino who spent last week reviewing and fixing the screensharingd garbage. Now you have something for that next RSU refresh ;-)
2
8
1,708
Ryan Dowd retweeted
Apparently full disclosure works guys
Apple released macOS Tahoe 26.6.1 today (August 6 2026) support.apple.com/en-us/1481…
6
32
6,372
A mystery solved for me, but not before I purchased a cheaper Mac Neo to run the betas while I rebuilt my primary device. Maybe that was Apple’s plan all along 🧐
1
6
1,699