Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
New macOS Exploit Silently Disables Security Tools

New macOS Exploit Silently Disables Security Tools

Posted on June 24, 2026 By CWS

Recent research by cybersecurity firm XM Cyber has unveiled a method by which a standard user account can disable macOS enterprise security tools subtly and without detection. This technique does not require administrative privileges or kernel exploits, making it a significant concern for enterprise security.

Understanding the Exploit

The method leverages weaknesses such as poorly validated XPC connections and malicious payload injections into application Interface Builder (NIB) files. Although these tactics have been known and partially mitigated by Apple, the introduction of a new exploit chain highlights persisting vulnerabilities. This chain relies on the persistence of the kernel’s code-signing trust cache, allowing attackers to masquerade as trusted applications and execute privileged XPC methods undetected.

Impact on Security Tools

This exploit was demonstrated against well-known security tools, including the CrowdStrike Falcon Sensor, which was completely disabled from a non-administrative account. Similarly, Kandji MDM was deactivated through a two-stage process that bypassed EDR protections and shut down the Endpoint Security Framework extension. Both companies have taken steps to address the vulnerabilities, with CrowdStrike enhancing detection measures and Kandji releasing a patch identified as CVE-2026-39118.

Responses and Future Developments

In response to these findings, CrowdStrike has offered a bug bounty, and Kandji has quickly patched the vulnerability. Meanwhile, another unnamed enterprise EDR provider affected by the exploit is currently developing a fix. Looking ahead, XM Cyber plans to release XPC Hunter, an open-source tool designed to identify exploitable XPC privilege escalation points across macOS applications. This tool will be showcased at Black Hat US in August 2026.

Efforts to reach Apple, CrowdStrike, and Kandji for further comments have been made by SecurityWeek, and updates will follow if additional information becomes available. The cybersecurity community continues to monitor these developments closely as similar vulnerabilities could pose significant risks to enterprise security worldwide.

Security Week News Tags:Apple, CrowdStrike, Cybersecurity, EDR, endpoint security, Kandji, macOS, MDM, Vulnerability, XPC connections

Post navigation

Previous Post: CI/CD Vulnerabilities Risk Supply Chain Security
Next Post: Public PoC Exploit for libssh2 RCE Vulnerability Unveiled

Related Posts

Ukrainian Nefilim Ransomware Affiliate Pleads Guilty in US Ukrainian Nefilim Ransomware Affiliate Pleads Guilty in US Security Week News
Cyera Raises 0 Million to Expand AI-Powered Data Security Platform Cyera Raises $540 Million to Expand AI-Powered Data Security Platform Security Week News
ClickFix Attacks Against macOS Users Evolving ClickFix Attacks Against macOS Users Evolving Security Week News
Payment System Vendor Took Year+ to Patch Infinite Card Top-Up Hack: Security Firm Payment System Vendor Took Year+ to Patch Infinite Card Top-Up Hack: Security Firm Security Week News
161,000 People Impacted by Krispy Kreme Data Breach 161,000 People Impacted by Krispy Kreme Data Breach Security Week News
Censys Secures M to Boost Internet Intelligence Censys Secures $70M to Boost Internet Intelligence Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Critical Flaw in Progress Kemp LoadMaster Listed by CISA
  • Atlassian Rovo AI Vulnerability Exposes Sensitive Data
  • N-central Hotfix 2 Released Amid Security Concerns
  • Revival of Bugtraq: Original Cybersecurity Forum Returns
  • CSS Vulnerabilities Threaten Webmail Security

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Critical Flaw in Progress Kemp LoadMaster Listed by CISA
  • Atlassian Rovo AI Vulnerability Exposes Sensitive Data
  • N-central Hotfix 2 Released Amid Security Concerns
  • Revival of Bugtraq: Original Cybersecurity Forum Returns
  • CSS Vulnerabilities Threaten Webmail Security

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark