🛠 🍎 👾 Objective-See'ing & DoubleYou'ing

Maui, HI
Stoked for the next (ad)venture: "DoubleYou" techcrunch.com/2024/04/25/ex… Cofounded w/ long-time friend @hexlogic, we're empowering those building security tools for Apple devices 🍎🛡️ And by bootstrapping this venture, our core value of democratizing security remains our focus!
22
31
186
45,145
One of our favorite @objective_see tools (finally) got a much-needed update! 🙏🏽 ...was hesitant to (re)tweet about it though. It’s interface is SwiftUI now, not Objective-See, err... Objective-C. 😂
I've just (re)written TaskExplorer Think Process Monitor but for macOS, open source, & much more powerful 💪🏽 Highlights: • CLI + JSON export • On-device AI assistant • Code signing + VirusTotal context • Live process/file/dylib/network activity objective-see.com/products/t…
1
6
51
6,782
Learn macOS vulnerability research from Gergely (@gergely_kalman) & Csaba (@theevilbit) at #OBTS v9! More on their training + all our other #OBTS trainings: objectivebythesea.org/v9/tra…
Listen to the man, he knows's what he's talking about. Coincidentally this will be in our training. Just saying...
2
16
2,185
Our @patrickwardle recently joined host Alex Hurtado on "Detection Dispatch" to talk AI agent/assistant privacy & security risks (+detection)! 🤖 🧠 Plus, dylib hijacks, macOS malware, #OBTS & much more! Watch/listen: piped.video/watch?v=9ZPQTA0E…
1
3
11
1,570
Please don't install - it's trivial to turn Muse into the ultimate backdoor 💀👀 Ya, as an AI assistant built to manage your Mac, Muse needs broad access to your digital life. But serious 0-day flaw(s) can let local malware/attackers invisibly hijack it. Let me show you. 🧵
Introducing Muse, the personal agent that understands your goals and works 24/7 to get things done for you.
40
130
653
231,554
Personally, I’m a fan of full disclosure 😇 It gets bugs fixed faster, and well the last time I dealt indirectly with Facebook’s bug bounty program, its security chief mentioned involving law enforcement over my colleague’s research 😬 forbes.com/sites/thomasbrews…
3
6
31
4,155
@Meta has now patched this @Muse bug. Thanks for the quick fix! 🤩 And speaking of thanks, I’d be remiss not to thank my Muse @andyrozen ...especially since poking on @Muse was her idea in the first place! 💡🤓☝️💭🤔
5
698
Protecting Apple users from malware, hackers... & now insecure AI apps 😇 Mahalo to our @patrickwardle for finding a nasty Muse flaw & kudos @Meta for the speedy fix! 🙏 @Meta, come talk security w/ our community at #OBTS v9: objectivebythesea.org/ We'd be stoked to connect 😍
We appreciate this report and have issued a hotfix to the Muse Mac app. This was a local privilege escalation attack, not a remote exploit. Using it to do harm therefore requires malicious code already running on the user’s machine under their user account and the practical risk to users of the Muse Mac app was therefore quite low. Nonetheless, we have issued a hotfix to the app to address the issue. We take every report of a possible security problem very seriously, including those that arrive as published exploit code (like this one). We strive to be extremely transparent about privacy and security in Muse as we know this is important to maintain your trust. Therefore, here’s a little more detail on this issue: - Muse's dictation is powered by a server-side speech model. The app shipped with an internal setting that allows the endpoint used by this feature to be redirected to a different URL, which is useful during debugging and development. - The setting lives in the app's local preferences, which macOS allows any program running under your user account to modify. Changing this requires malicious code already running on your Mac. This is not remotely exploitable, and it does not involve Muse's servers or the Secure VM that isolates agent tasks. - Overriding this setting would let an attacker proxy audio dictation requests and capture the access tokens the Muse app uses to drive the Muse agent – expanding malware already present on your computer into the Muse agent. Our hotfix removes the endpoint setting from production builds entirely, which closes this vulnerability. - We are grateful for the work of the security research community and potential security issues can be responsibly disclosed via our bug bounty program, which pays up to $300,000 for exactly this class of finding. bugbounty.meta.com/
2
4
12
2,931
Patrick Wardle retweeted
New #Mac #stealer in the wild: Sonoma. Crazy Evil's 2026 kit. Same crew we wrote about in 2024. Impersonated brands we saw so far: StreamYard, Zoom, Slack, DocSend, Brave Talk, Toria, Waaako, Meendo, CavePay, Crystal Flip, Cốc Cốc. Some fun facts: - one chain fetched the next stage from Apple Calendar. - the first loaders still used /tmp/osalogging.zip. That's a MacSync leftover. They borrowed pieces. - it talks to PAM, so it looked like Avenger (PamStealer), but it isn't Read more: hackernoon.com/downloading-z…
12
37
2,900
Patrick Wardle retweeted
Thank you for this write-up! Super technical and exactly the kind of research that gets better when teams add context to each other 🤝 We looked at the same Swift stealer and track it as Sonoma, that's the name operators use underground and it matches the SONOMAC1 tag we pulled from the binary. Our notes on this campaign can be found here: nitter.net/moonlock_lab/status/21…
Jamf Threat Labs investigates a newer variant of PamStealer, the third known variant of the family, distributed as a fake application installer that uses a purpose-built decryption utility to ensure the payload cannot be recovered without server cooperation and the stealer itself being rewritten from Rust into Swift. Some interesting techniques, have a read! jamf.com/blog/pamstealer-wav… #macos #malware #infostealer #ioc
2
4
23
2,677
Hooray, hot-fixed! 😍 Kudos on the quick patch (& full disclosure FTW) 🙏🏽 But there was a 'remote' exploit vector: a simple ClickFix attack could deliver the hijack giving a *remote* attacker complete access then to every victim device running Muse See: arstechnica.com/security/202…
We appreciate this report and have issued a hotfix to the Muse Mac app. This was a local privilege escalation attack, not a remote exploit. Using it to do harm therefore requires malicious code already running on the user’s machine under their user account and the practical risk to users of the Muse Mac app was therefore quite low. Nonetheless, we have issued a hotfix to the app to address the issue. We take every report of a possible security problem very seriously, including those that arrive as published exploit code (like this one). We strive to be extremely transparent about privacy and security in Muse as we know this is important to maintain your trust. Therefore, here’s a little more detail on this issue: - Muse's dictation is powered by a server-side speech model. The app shipped with an internal setting that allows the endpoint used by this feature to be redirected to a different URL, which is useful during debugging and development. - The setting lives in the app's local preferences, which macOS allows any program running under your user account to modify. Changing this requires malicious code already running on your Mac. This is not remotely exploitable, and it does not involve Muse's servers or the Secure VM that isolates agent tasks. - Overriding this setting would let an attacker proxy audio dictation requests and capture the access tokens the Muse app uses to drive the Muse agent – expanding malware already present on your computer into the Muse agent. Our hotfix removes the endpoint setting from production builds entirely, which closes this vulnerability. - We are grateful for the work of the security research community and potential security issues can be responsibly disclosed via our bug bounty program, which pays up to $300,000 for exactly this class of finding. bugbounty.meta.com/
9
7
67
7,913
And once a Mac is exploited, you can interact with any of the users "connected" devices also running Muse. ...meaning you remotely task their mobile (iOS) Muse client ...invisibly 📲🔓👀 What can you do? Welll, some very neat iOS stuff!
Please don't install - it's trivial to turn Muse into the ultimate backdoor 💀👀 Ya, as an AI assistant built to manage your Mac, Muse needs broad access to your digital life. But serious 0-day flaw(s) can let local malware/attackers invisibly hijack it. Let me show you. 🧵
12
51
334
282,212
Remote iOS BLE scans! 😅
1
11
7,289
I don't have any HomeKit accessories set up, but this looks fun, right?
11
5,627
Used it to hack itself? 💀 But please fix, its trivial to exploit and (locally) take over the agent 😭 github.com/pwardle/not-a-mus…
what’s the most ambitious project you’ve handed off to your Muse? we want to see ‘em 👇
10
4
154
61,347