Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
New macOS Exploit Silently Disables Security Tools

New macOS Exploit Silently Disables Security Tools

Posted on June 24, 2026 By CWS

Recent research by cybersecurity firm XM Cyber has unveiled a method by which a standard user account can disable macOS enterprise security tools subtly and without detection. This technique does not require administrative privileges or kernel exploits, making it a significant concern for enterprise security.

Understanding the Exploit

The method leverages weaknesses such as poorly validated XPC connections and malicious payload injections into application Interface Builder (NIB) files. Although these tactics have been known and partially mitigated by Apple, the introduction of a new exploit chain highlights persisting vulnerabilities. This chain relies on the persistence of the kernel’s code-signing trust cache, allowing attackers to masquerade as trusted applications and execute privileged XPC methods undetected.

Impact on Security Tools

This exploit was demonstrated against well-known security tools, including the CrowdStrike Falcon Sensor, which was completely disabled from a non-administrative account. Similarly, Kandji MDM was deactivated through a two-stage process that bypassed EDR protections and shut down the Endpoint Security Framework extension. Both companies have taken steps to address the vulnerabilities, with CrowdStrike enhancing detection measures and Kandji releasing a patch identified as CVE-2026-39118.

Responses and Future Developments

In response to these findings, CrowdStrike has offered a bug bounty, and Kandji has quickly patched the vulnerability. Meanwhile, another unnamed enterprise EDR provider affected by the exploit is currently developing a fix. Looking ahead, XM Cyber plans to release XPC Hunter, an open-source tool designed to identify exploitable XPC privilege escalation points across macOS applications. This tool will be showcased at Black Hat US in August 2026.

Efforts to reach Apple, CrowdStrike, and Kandji for further comments have been made by SecurityWeek, and updates will follow if additional information becomes available. The cybersecurity community continues to monitor these developments closely as similar vulnerabilities could pose significant risks to enterprise security worldwide.

Security Week News Tags:Apple, CrowdStrike, Cybersecurity, EDR, endpoint security, Kandji, macOS, MDM, Vulnerability, XPC connections

Post navigation

Previous Post: CI/CD Vulnerabilities Risk Supply Chain Security

Related Posts

Malicious Crypto Apps Target iOS Users on App Store Malicious Crypto Apps Target iOS Users on App Store Security Week News
CyberNut Closes M Growth Capital for K-12 Security Awareness Training CyberNut Closes $5M Growth Capital for K-12 Security Awareness Training Security Week News
DOJ Antitrust Review Clears Google’s  Billion Acquisition of Wiz DOJ Antitrust Review Clears Google’s $32 Billion Acquisition of Wiz Security Week News
Cylake Secures M Funding for On-Premises Cybersecurity Cylake Secures $45M Funding for On-Premises Cybersecurity Security Week News
Private Sector Vital in Cybersecurity Battle Private Sector Vital in Cybersecurity Battle Security Week News
Cyera Raises 0 Million at  Billion Valuation Cyera Raises $400 Million at $9 Billion Valuation Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • New macOS Exploit Silently Disables Security Tools
  • CI/CD Vulnerabilities Risk Supply Chain Security
  • Securing Privileged Access: Strategies to Prevent Breaches
  • DraftKings Hacker Sentenced to 18 Months in Prison
  • Rise of AI-Powered Cyber Threats Shifts Security Landscape

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • New macOS Exploit Silently Disables Security Tools
  • CI/CD Vulnerabilities Risk Supply Chain Security
  • Securing Privileged Access: Strategies to Prevent Breaches
  • DraftKings Hacker Sentenced to 18 Months in Prison
  • Rise of AI-Powered Cyber Threats Shifts Security Landscape

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark