Csaba Fitzl (@theevilbit) 's Twitter Profile
Csaba Fitzl

@theevilbit

macOS Security -- Trail running ๐Ÿƒ -- Mountains โ›ฐ -- Tolkien fan

ID: 131942687

linkhttps://theevilbit.github.io/ calendar_today11-04-2010 20:36:20

14,14K Tweet

7,7K Followers

996 Following

Mykola Grymalyuk (@khronokernel) 's Twitter Profile Photo

Have some really exciting news to share: I'm joining Apple's Bug Bounty team out in Seattle next week! Unfortunately I will have to step down from my role with OpenCore Legacy Patcher, but super excited for what's to come. Thank you everyone who've helped make OCLP what is!

MacDevOpsYVR (@macdevopsyvr) 's Twitter Profile Photo

Weekend video drop - 2025 talks from Day 1 (June 12) of MacDevOps YVR. A lot of GitOps and Munki talks, and awesome Quick Talks. Check out the 2025 playlist: youtube.com/playlist?list=โ€ฆ

Weekend video drop - 2025 talks from Day 1 (June 12) of MacDevOps YVR. A lot of GitOps and Munki talks, and awesome Quick Talks. Check out the 2025 playlist: youtube.com/playlist?list=โ€ฆ
Patrick Wardle (@patrickwardle) 's Twitter Profile Photo

โณ Just one week left to submit your talk to #OBTS v8 objectivebythesea.org/v8/cfp.html (CFP closes June 30th). Weโ€™ve expanded toย 3 daysย of talks this year, making room for even more cutting-edge researchย + ย first-time speakers. So submit your Apple security-themed proposal today!

Jeremy Boone (@uffeux) 's Twitter Profile Photo

Hello friends. Check out this awesome and unique role that just opened up on my team in SEAR. Wanna secure Apple silicon, ROMs, iBoot, and more? jobs.apple.com/en-us/details/โ€ฆ

Technologeeks (@technologeeks) 's Twitter Profile Photo

Are you a textbook or technical author, but don't want traditional publishers to leave you with a paltry $2 or so for a book which sells for $50+? Technologeeks Press can get your book printed in B&W or Color, and - most importantly - YOU keep 70% of the profit! DM for details!

Kandji (@kandjiofficial) 's Twitter Profile Photo

Our rockstar Principal macOS Security Researcher Csaba Fitzl back at it again - this time speaking at this year's MacDevOpsYVR conference on "Finding Vulnerabilities in Apple Packages at Scale." ๐Ÿ”ฅ

Our rockstar Principal macOS Security Researcher <a href="/theevilbit/">Csaba Fitzl</a> back at it again - this time speaking at this year's <a href="/MacDevOpsYVR/">MacDevOpsYVR</a> conference on "Finding Vulnerabilities in Apple Packages at Scale." ๐Ÿ”ฅ
Dillon Franke (@dillon_franke) 's Twitter Profile Photo

I lightly mentioned CVE-2025-31235, a double-free I found in coreaudiod/CoreAudio, during my OffensiveCon presentation last month. It's been derestricted now, so enjoy my writeup which includes a PoC and dtrace script to help understand the vulnerability! project-zero.issues.chromium.org/issues/4062711โ€ฆ

iRunFar (@irunfar) 's Twitter Profile Photo

Six men over the age of 70 will race the Western States 100 this weekend! This is the race we'll be watching! #WS100 Learn more about "The Gang:" i-rn.fr/25WS100-AJW-Toโ€ฆ

Six men over the age of 70 will race the Western States 100 this weekend! This is the race we'll be watching! #WS100

Learn more about "The Gang:" i-rn.fr/25WS100-AJW-Toโ€ฆ
x64dbg (@x64dbg) 's Twitter Profile Photo

We're excited to announce a major new release of x64dbg! The main new feature is support for bitfields, enums and anonymous types, which allows all types in the Windows SDK to be represented and displayed ๐Ÿ”ฅ

Patrick Wardle (@patrickwardle) 's Twitter Profile Photo

Weekends are for LuLu! ๐Ÿ‘จ๐Ÿปโ€๐Ÿ’ป๐Ÿ›ก๏ธ๐ŸŽ Been working hard to add a top requested feature to LuLu: Profiles Please give the latest beta a whirl and report any Profile-related issues ๐Ÿ™๐Ÿฝ๐Ÿ™๐Ÿฝ๐Ÿ™๐Ÿฝ github.com/objective-see/โ€ฆ Learn more about LuLu's profile here: objective-see.org/products/lulu.โ€ฆ

Weekends are for LuLu! ๐Ÿ‘จ๐Ÿปโ€๐Ÿ’ป๐Ÿ›ก๏ธ๐ŸŽ

Been working hard to add a top requested feature to LuLu: Profiles 

Please give the latest beta a whirl and report any Profile-related issues ๐Ÿ™๐Ÿฝ๐Ÿ™๐Ÿฝ๐Ÿ™๐Ÿฝ
github.com/objective-see/โ€ฆ

Learn more about LuLu's profile here: objective-see.org/products/lulu.โ€ฆ
Jonathan Bar Or (JBO) ๐Ÿ‡ฎ๐Ÿ‡ฑ๐Ÿ‡บ๐Ÿ‡ธ๐Ÿ‡บ๐Ÿ‡ฆ๐ŸŽ—๏ธ (@yo_yo_yo_jbo) 's Twitter Profile Photo

๐Ÿ’ฅ๐ŸŽ Offensive security on macOS is totally different than Windows or Linux, mostly because the *identity* of a process is quite strong. Injection ๐Ÿ’‰ is almost nonexistent due to hardened runtime and sandbox, and the capabilities ๐Ÿฅท of a process (entitlements) are bound to a

Karol Mazurek (@karmaz95) 's Twitter Profile Photo

Thanks @8ksec for the recent #ARM64 #CTF. I wish to see Battleground continue to grow! In the blog below, I have gathered some learning resources about ARM64 that will save others' time. Additionally, you'll find a write-up about one of the challenges. patreon.com/posts/arm64-reโ€ฆ