Podcast Detail

SANS Stormcast Tuesday, September 29th, 2026: MacOS/iOS 0-Day Patch; macOS priv. escalation 0-day; File Notification Attacks

If you are not able to play the podcast using the player below: Use this direct link to the audio file: https://traffic.libsyn.com/securitypodcast/10114.mp3

Podcast Logo
MacOS/iOS 0-Day Patch; macOS priv. escalation 0-day; File Notification Attacks
00:00

My Next Class

Click HERE to learn more about classes Johannes is teaching for SANS

Podcast Transcript

 Hello and welcome to the Tuesday September 29th edition
 of the SANS Internet Storm Center's Stormcast. My name is
 Johannes Ullrich, recording today from Ottawa, Canada. And
 this episode is brought to you by the SANS.edu Graduate
 Certificate Program in Incident Response. Well today
 we got some interesting patches from Apple. Apple
 released patches or updates for pretty much all of its
 operating systems, but only the last generation of its
 operating systems actually got security fixes. These security
 fixes do apply a patch for one individual vulnerability in
 core graphics. It's exploited currently in the wild and
 Apple has been notified of this exploitation by the Meta
 Product Security Team. So this is a patch that you want to
 apply if you're still running iOS 26 or macOS 26. They even
 released an update for macOS 15. The updates that were
 released for the 27 versions of the operating systems,
 again, they do not include any security content, but just
 functional issues. So that's the usual cleanup release that
 we often have seen sort of a couple weeks after a
 particular major version of the operating system was
 released by Apple. And then let's stick with Apple here
 for another story. We do have a proof of concept for a local
 privilege escalation vulnerability. This
 vulnerability was patched two weeks ago. So in the last
 security update that we got for macOS, it's a privilege
 escalation vulnerability in macOS core services. The
 reason I mention it is that I don't see a lot of proof of
 concept code like this being published for these macOS
 vulnerabilities. And core services has had issues with
 privilege escalations in the past. So assumption is it will
 have privilege escalations in the future, which of course
 means with a proof of concept like this being available, it
 may be easier for attackers to then exploit these future
 vulnerabilities. So take them a bit more serious. Microsoft
 published something that definitely the threat hunters
 in the audience will like, and that's a write-up of Needy
 Mantis. Needy Mantis is one of these more sophisticated
 command control tools that's being deployed as an implant
 after the initial compromise. Microsoft believes this sort
 of came out of the same group that also is associated with a
 daemon tool, some of the supply chain compromises.
 Kaspersky apparently did write about it. Now a couple
 interesting things here, and again, particular from sort of
 a detection and response point of view, this malware does use
 some legitimate DLLs it will find on the system. So if you
 have, for example, tight VNC or curl and other tools like
 this installed on the system, it will use the features via
 the DLLs that are deployed by the tools. So if you are
 finding that this implant uses some of these DLLs, well,
 don't just simply erase them. Double check first whether or
 not these tools are supposed to be installed and whether
 these DLLs are still legitimate that you're
 finding. Also again, more use of WebSocket here for data
 exfiltration. Interesting, some little twist here where
 it does send a set cookie header that also exfiltrates
 some details about the system it's installed on. The first
 install of the malware is very basic, only has a couple
 different commands, but most importantly, it has the
 ability to load additional modules. And that's something
 that we have definitely seen quite commonly these days in
 more advanced malware that they basically don't want to
 give away everything the malware can do right away, but
 then only sort of load specific modules as needed.
 And then we got a really interesting research paper,
 probably not the most critical attack, but one of those neat
 things that I think makes you think a little bit deeper
 about operating systems, at least that I ever so often
 like these types of attacks. This comes from several
 research researchers at the Graz University of Technology
 in Austria. And it's about file notifications. So all
 operating systems, Windows, Linux, Mac OS have to some
 extent the ability to notify software whenever a file
 changes. And that's quite important. If you, for
 example, have an editor or so that changes a file, you
 automatically want to, for example, recompile software
 whenever the file changes. And so you can subscribe to these
 file notifications. But what surprised me is that it's
 possible for an attacker to receive notifications for
 files that the attacker actually doesn't even have
 read access to. So in this case, the attacker just has to
 know what the file is being called, and then they're able
 to subscribe to these events. And that's, of course,
 particularly interesting when you're talking about editor
 files, where the file may be updated as the user types. And
 that, of course, gives you then some insight into
 keystroke rhythms and maybe potentially into the content
 of specific file. So one of those interesting sort of site
 channel attacks emerges then out of the ability to actually
 receive these file notifications. More details in
 the paper. Well, and this is it for today. So thanks for
 listening. Thanks for liking. Thanks for subscribing to this
 podcast and talk to you again tomorrow. Bye.