Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
New macOS Exploit Silently Disables Security Tools

New macOS Exploit Silently Disables Security Tools

Posted on June 24, 2026 By CWS

Recent research by cybersecurity firm XM Cyber has unveiled a method by which a standard user account can disable macOS enterprise security tools subtly and without detection. This technique does not require administrative privileges or kernel exploits, making it a significant concern for enterprise security.

Understanding the Exploit

The method leverages weaknesses such as poorly validated XPC connections and malicious payload injections into application Interface Builder (NIB) files. Although these tactics have been known and partially mitigated by Apple, the introduction of a new exploit chain highlights persisting vulnerabilities. This chain relies on the persistence of the kernel’s code-signing trust cache, allowing attackers to masquerade as trusted applications and execute privileged XPC methods undetected.

Impact on Security Tools

This exploit was demonstrated against well-known security tools, including the CrowdStrike Falcon Sensor, which was completely disabled from a non-administrative account. Similarly, Kandji MDM was deactivated through a two-stage process that bypassed EDR protections and shut down the Endpoint Security Framework extension. Both companies have taken steps to address the vulnerabilities, with CrowdStrike enhancing detection measures and Kandji releasing a patch identified as CVE-2026-39118.

Responses and Future Developments

In response to these findings, CrowdStrike has offered a bug bounty, and Kandji has quickly patched the vulnerability. Meanwhile, another unnamed enterprise EDR provider affected by the exploit is currently developing a fix. Looking ahead, XM Cyber plans to release XPC Hunter, an open-source tool designed to identify exploitable XPC privilege escalation points across macOS applications. This tool will be showcased at Black Hat US in August 2026.

Efforts to reach Apple, CrowdStrike, and Kandji for further comments have been made by SecurityWeek, and updates will follow if additional information becomes available. The cybersecurity community continues to monitor these developments closely as similar vulnerabilities could pose significant risks to enterprise security worldwide.

Security Week News Tags:Apple, CrowdStrike, Cybersecurity, EDR, endpoint security, Kandji, macOS, MDM, Vulnerability, XPC connections

Post navigation

Previous Post: CI/CD Vulnerabilities Risk Supply Chain Security
Next Post: Public PoC Exploit for libssh2 RCE Vulnerability Unveiled

Related Posts

Microsoft Awards .3 Million at 2026 Hacking Event Microsoft Awards $2.3 Million at 2026 Hacking Event Security Week News
AI Firm Mercor Affected by LiteLLM Supply Chain Breach AI Firm Mercor Affected by LiteLLM Supply Chain Breach Security Week News
Cybersecurity M&A Roundup: 45 Deals Announced in October 2025 Cybersecurity M&A Roundup: 45 Deals Announced in October 2025 Security Week News
US Student to Plead Guilty Over PowerSchool Hack US Student to Plead Guilty Over PowerSchool Hack Security Week News
Call for Presentations Open for 2025 CISO Forum Virtual Summit Call for Presentations Open for 2025 CISO Forum Virtual Summit Security Week News
US Cybersecurity Worker Admits Role in Ransomware Scams US Cybersecurity Worker Admits Role in Ransomware Scams Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • AIVEX: A New Model to Mitigate Supply Chain Risks
  • Public PoC Exploit for libssh2 RCE Vulnerability Unveiled
  • New macOS Exploit Silently Disables Security Tools
  • CI/CD Vulnerabilities Risk Supply Chain Security
  • Securing Privileged Access: Strategies to Prevent Breaches

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • AIVEX: A New Model to Mitigate Supply Chain Risks
  • Public PoC Exploit for libssh2 RCE Vulnerability Unveiled
  • New macOS Exploit Silently Disables Security Tools
  • CI/CD Vulnerabilities Risk Supply Chain Security
  • Securing Privileged Access: Strategies to Prevent Breaches

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark