Skip to content
zarza zarza
Advertisement

macOS Weaknesses Chained to Silently Disable Endpoint Security Agents

24/06/2026 0 min

Listen "macOS Weaknesses Chained to Silently Disable Endpoint Security Agents"

Episode Synopsis

Cybersecurity firm XM Cyber has demonstrated a technique that allows a standard macOS user without administrative privileges to silently disable enterprise endpoint security tools like EDR and MDM agents without triggering alerts. The attack chains together known macOS behaviors, including exploiting kernel code-signing trust cache persistence and injecting malicious payloads into application files, to impersonate trusted components and invoke privileged system functions. The technique was successfully used against CrowdStrike Falcon Sensor, Kandji MDM, and a third unnamed vendor, prompting patches and bug bounty payments, while the researcher plans to release an open source tool called XPC Hunter to help identify similar vulnerabilities across macOS applications.

More episodes of the podcast Security Stuff

ZARZA Studio — Your station on air today: library, music clock, schedule, studio and reports, from the browser.

Meet ZARZA Studio
on air now stations in the catalogue 1,829,025 podcasts countries