🚨 NEW FREE AI SECURITY COURSE: Closing the AI Exposure Gap 🚨 Right now, an attacker is running AI frameworks to attack your corporate networks at machine speed, exploiting the exact same CVEs and misconfigurations already sitting on your remediation list. While your team is still relying on human decision-making, automated threats are executing continuously. The gap between attacker velocity and your defensive response is compounding. In this course, Dr. Gerald Auger, Ph.D. breaks down the operational reality of today’s AI-driven threat landscape and what it takes for your security teams to defend at scale. Here’s what you’ll learn: ✔️ Machine-Speed Threat Dynamics: How autonomous AI frameworks target existing vulnerabilities without human intervention. ✔️ Operationalizing Defense: Bridging the chasm between rapid attack execution and traditional remediation cycles. ✔️ Pragmatic Exposure Reduction: Moving beyond traditional triage to proactively seal exposure windows before automated tools exploit them. 👇 Close the gap and strengthen your defense: https://lnkd.in/eiYe7miz #Cybersecurity #VulnerabilityManagement #AIsecurity #ExposureManagement
XM Cyber
Computer and Network Security
Tel Aviv-Yafo, Israel 36,727 followers
Continuously discover, prioritize, and fix every validated exposure in YOUR environment, with a fraction of the effort.
About us
XM Cyber is transforming the way organizations prevent attacks that put their business at risk with the most reliable Continuous Exposure Management platform. The platform discovers, prioritizes, and drives remediation of validated exposures across on-prem and cloud environments, from the external attack surface all the way to critical assets. With XM Cyber, you can see all the ways attackers might go, and all the best ways to stop them, pinpointing where to remediate exposures with a fraction of the effort.
- Website
-
https://www.xmcyber.com/
External link for XM Cyber
- Industry
- Computer and Network Security
- Company size
- 201-500 employees
- Headquarters
- Tel Aviv-Yafo, Israel
- Type
- Privately Held
- Founded
- 2016
- Specialties
- Cybersecurity, Breach and Attack Simulation, APT Simulation & Remediation, Purple Team, Automated Red Team, Risk-Based Vulnerability Management , RBVM, Attack-Centric Exposure Prioritization, Hybrid cloud, Attack Path Management, Exposure Management, and CTEM
Locations
-
Primary
Get directions
2 Leonardo da Vinci St.
Tel Aviv-Yafo, Israel 6473309, IL
-
Get directions
260 Madison Ave
New York, 10016, US
-
Get directions
11 York St
Sydney, New South Wales 2204, AU
Employees at XM Cyber
Updates
-
𝗧𝗵𝗲 𝗠𝗼𝗯𝗶𝗹𝗶𝘇𝗮𝘁𝗶𝗼𝗻 𝗧𝗿𝗮𝗽: 𝗪𝗵𝘆 𝗘𝘅𝗽𝗼𝘀𝘂𝗿𝗲 𝗠𝗮𝗻𝗮𝗴𝗲𝗺𝗲𝗻𝘁 𝗕𝗿𝗲𝗮𝗸𝘀 𝗗𝗼𝘄𝗻 𝗔𝗳𝘁𝗲𝗿 𝗗𝗶𝘀𝗰𝗼𝘃𝗲𝗿𝘆 Most security programs have gotten remarkably good at discovering and prioritizing exposures. Where do they consistently fail? 𝗧𝗵𝗲 𝗠𝗼𝗯𝗶𝗹𝗶𝘇𝗮𝘁𝗶𝗼𝗻 𝗦𝘁𝗮𝗴𝗲. A security team validates a finding, routes it to IT/Operations, and... it stalls. Security has its urgency; Operations has its change windows and competing priorities. The ticket is assigned, but practically? It's completely un-owned. While exploitation moves at 𝗺𝗮𝗰𝗵𝗶𝗻𝗲 𝘀𝗽𝗲𝗲𝗱, mobilization still moves at 𝗼𝗿𝗴𝗮𝗻𝗶𝘇𝗮𝘁𝗶𝗼𝗻𝗮𝗹 𝘀𝗽𝗲𝗲𝗱. 📊 𝗧𝗵𝗲 𝗗𝗮𝘁𝗮 𝗦𝗽𝗲𝗮𝗸𝘀 𝗳𝗼𝗿 𝗜𝘁𝘀𝗲𝗹𝗳 𝟮𝟵 𝗠𝗶𝗻𝘂𝘁𝗲𝘀: The average eCrime breakout time (Crowdstrike 2026). 𝟰𝟯 𝗗𝗮𝘆𝘀: The median time organizations take to remediate KEVs (Verizon DBIR 2026). 𝟰𝟵,𝟬𝟬𝟬+: Expected new CVEs in 2026 alone (FIRST). 𝟴𝟮%: Of threat detections are malware-free, relying on compromised valid credentials rather than exploits (Crowdstrike 2026). 𝗢𝗻𝗹𝘆 𝟯𝟲% of I&O teams are actively engaged as part of a standing committee on vulnerability remediation (Gartner’s 2024 Designing and Building Modern Security Operations Survey). No amount of raw automation will solve a broken handoff. Mobilization is an 𝗼𝗿𝗴𝗮𝗻𝗶𝘇𝗮𝘁𝗶𝗼𝗻𝗮𝗹 𝗱𝗶𝘀𝗰𝗶𝗽𝗹𝗶𝗻𝗲, not just a tech stack layer. 🛠️ 𝟱 𝗕𝗲𝘀𝘁 𝗣𝗿𝗮𝗰𝘁𝗶𝗰𝗲𝘀 𝗳𝗼𝗿 𝗘𝗳𝗳𝗲𝗰𝘁𝗶𝘃𝗲 𝗠𝗼𝗯𝗶𝗹𝗶𝘇𝗮𝘁𝗶𝗼𝗻 To bridge the gap between discovery and remediation, security programs must adopt these core principles: 𝗧𝗮𝗿𝗴𝗲𝘁 𝗖𝗵𝗼𝗸𝗲 𝗣𝗼𝗶𝗻𝘁𝘀, 𝗡𝗼𝘁 𝗩𝗼𝗹𝘂𝗺𝗲: One strategic fix at a convergence point can collapse dozens of attack paths simultaneously. (This focus on choke points is precisely why XM Cyber won Best Vulnerability Management Solution at the SC Awards Europe 2026!) 𝗣𝗿𝗼𝘃𝗲 𝗘𝘅𝗽𝗹𝗼𝗶𝘁𝗮𝗯𝗶𝗹𝗶𝘁𝘆 𝗕𝗲𝗳𝗼𝗿𝗲 𝗔𝗰𝘁𝗶𝗻𝗴: Swap generic severity scores for concrete proof. A team that receives evidence of exploitability handles a ticket with far greater urgency. 𝗢𝗳𝗳𝗲𝗿 𝗔𝗹𝘁𝗲𝗿𝗻𝗮𝘁𝗶𝘃𝗲𝘀 𝗪𝗵𝗲𝗻 𝗣𝗮𝘁𝗰𝗵𝗶𝗻𝗴 𝗜𝘀𝗻'𝘁 𝗮𝗻 𝗢𝗽𝘁𝗶𝗼𝗻: Identify compensating controls and workarounds before creating a ticket, preventing instant rejection. 𝗠𝗲𝗲𝘁 𝗧𝗲𝗮𝗺𝘀 𝗪𝗵𝗲𝗿𝗲 𝗧𝗵𝗲𝘆 𝗪𝗼𝗿𝗸: Route validated findings natively into existing tools like Jira or ServiceNow and align with the organization’s specific workflows. 𝗩𝗲𝗿𝗶𝗳𝘆 𝗙𝗶𝘅𝗲𝘀 𝘄𝗶𝘁𝗵 𝗖𝗼𝗻𝘁𝗶𝗻𝘂𝗼𝘂𝘀 𝗥𝗲𝘁𝗲𝘀𝘁𝗶𝗻𝗴: A closed ticket does 𝗻𝗼𝘁 mean a closed exposure. Assumed closure isn't closure - always validate. 💡 𝗧𝗵𝗲 𝗕𝗼𝘁𝘁𝗼𝗺 𝗟𝗶𝗻𝗲: Effective exposure management isn't to fix more - but proving what matters, routing it seamlessly, and confirming it's actually closed. Get the mobilization eBook here: https://lnkd.in/d8n33f5B
-
-
🚨 𝗙𝗿𝗼𝗺 𝗦𝘁𝗮𝗻𝗱𝗮𝗿𝗱 𝗗𝗼𝗺𝗮𝗶𝗻 𝗨𝘀𝗲𝗿 𝘁𝗼 𝗘𝗻𝘁𝗲𝗿𝗽𝗿𝗶𝘀𝗲 𝗖𝗼𝗻𝘁𝗿𝗼𝗹: 𝗔 𝗡𝗲𝘄 𝟰-𝗦𝘁𝗲𝗽 𝗘𝘅𝗽𝗹𝗼𝗶𝘁 𝗖𝗵𝗮𝗶𝗻 𝗶𝗻 𝗠𝗶𝗰𝗿𝗼𝘀𝗼𝗳𝘁 𝗦𝗖𝗖𝗠 🚨 Can an unprivileged Active Directory user with 𝘇𝗲𝗿𝗼 SCCM permissions take over your entire infrastructure in seconds? According to new research from senior security researcher Omri Baso, the answer is yes. SCCM manages OS deployments, patching, and compliance for over 𝟭𝟬𝟬 𝗺𝗶𝗹𝗹𝗶𝗼𝗻 𝗮𝗰𝘁𝗶𝘃𝗲 𝘂𝘀𝗲𝗿𝘀. XM Cyber discovered a multi-vulnerability exploit chain targeting the primary site server that grants full `NT AUTHORITY\SYSTEM` code execution. Here is a breakdown of how the exploit chain works - and why organizations are still at risk: 💥 𝗧𝗵𝗲 𝟰-𝗦𝘁𝗮𝗴𝗲 𝗘𝘅𝗽𝗹𝗼𝗶𝘁 𝗖𝗵𝗮𝗶𝗻 1. Broken RBAC in AdminService (`CVE-2026-47301`) The `UploadExtensionInChunks` REST API endpoint completely lacked permission checks (`CheckAccess()`), letting *any* authenticated domain user upload arbitrary `.cab` packages without an admin role or user interaction. 2. Weak Code-Signing Verification SCCM checks `.cab` signatures without verifying Certificate Revocation Lists (CRL) or checking identity ownership. An attacker can sign malicious archives with a cheap $58 commercial certificate - or an expired/revoked cert - and SCCM treats it as fully trusted. 3. "CabSlip" Path Traversal During extraction, `CabinetUtils.GetFileName` fails to sanitize relative directory traversal sequences. This gives attackers a full Arbitrary File Write primitive across the site server's file system. 4. DLL Hijacking in SMS Executive The primary background service (`SMS Executive`) executes `adsysdis.dll`, which dynamically loads `adsource.dll` without signature verification. Overwriting `adsource.dll` via CabSlip leads to immediate RCE as `NT AUTHORITY\SYSTEM`. ⚠️ 𝗧𝗵𝗲 𝗖𝗮𝘁𝗰𝗵: 𝗪𝗵𝘆 𝗬𝗼𝘂'𝗿𝗲 𝗦𝘁𝗶𝗹𝗹 𝗘𝘅𝗽𝗼𝘀𝗲𝗱 Microsoft released a patch for CVE-2026-47301 in July 2026 to stop standard domain users from abusing the unauthenticated endpoint. However, the rest of the chain remains unpatched until ConfigMgr 2609 (expected October 2026). Crucial Warning: Any lower-privileged SCCM user assigned the built-in Operations Administrator role (or custom roles with `Create` permissions on `SMS_ConsoleExtensionData`) can still trigger the identical downstream chain via standard endpoints today. 🛡️ 𝗛𝗼𝘄 𝘁𝗼 𝗗𝗲𝘁𝗲𝗰𝘁 & 𝗠𝗶𝘁𝗶𝗴𝗮𝘁𝗲 🔍 Monitor Logs: Check `<InstallationDir>\Logs\AdminService.log`. Failed cleanup caused by CabSlip triggers a`System.IO.DirectoryNotFoundException` followed by an `HTTP 500` error. 🛡️ Network Isolation: Restrict network access to the AdminService API port via firewall rules. 🔐 Audit RBAC Roles: Heavily restrict assignments for the Operations Administrator role and any roles with `Create` permissions on `SMS_ConsoleExtensionData`. Read the full breakdown here: https://lnkd.in/d9vrKBEH
-
-
Tired of chasing exposures after they were announced and exploited? It’s time to move from reactive vulnerability scanning to proactive exposure hunting. We just announced several powerful automated exposure discovery engines designed by our research experts Hillel Pinto and Eli Shparaga to uncover hidden architectural flaws across both local endpoints and distributed cloud environments. Here is a breakdown of the new open-source tools with github links: 𝟭. 𝗫𝗣𝗖 𝗛𝘂𝗻𝘁𝗲𝗿: officially debuted at BlackHat USA 26 - 𝗔𝘂𝘁𝗼𝗺𝗮𝘁𝗲𝗱 𝗺𝗮𝗰𝗢𝗦 𝗫𝗣𝗖 𝗔𝘁𝘁𝗮𝗰𝗸 𝗦𝘂𝗿𝗳𝗮𝗰𝗲 𝗗𝗶𝘀𝗰𝗼𝘃𝗲𝗿𝘆 Enterprise security often assumes only vendor-signed software can communicate with privileged background processes. But what happens when trust is established the wrong way? Enter 𝗙𝗔𝗶𝗻𝗱 𝗺𝘆 𝗫𝗣𝗖 - an automated framework that discovers macOS XPC attack surfaces and validates privilege escalations end-to-end without modifying any signed executables: https://lnkd.in/de_yaEtt 𝟮. 𝗢𝗳𝗳𝗲𝗻𝘀𝗶𝘃𝗲 𝗢𝗖𝗜 𝗧𝗼𝗼𝗹𝗶𝗻𝗴: 𝗜𝗱𝗲𝗻𝘁𝗶𝘁𝘆 & 𝗡𝗲𝘁𝘄𝗼𝗿𝗸 𝗘𝘅𝗽𝗼𝘀𝘂𝗿𝗲 𝗗𝗶𝘀𝗰𝗼𝘃𝗲𝗿𝘆 𝗶𝗻 𝗢𝗿𝗮𝗰𝗹𝗲 𝗖𝗹𝗼𝘂𝗱 𝗜𝗻𝗳𝗿𝗮𝘀𝘁𝗿𝘂𝗰𝘁𝘂𝗿𝗲 𝗜𝗔𝗠: In the cloud, IAM is your primary security perimeter. To equip security teams with the offensive tooling needed to assess OCI IAM configurations, two dedicated engines were released at DEF CON 26: 🔍 𝗽𝗢𝗹𝗶𝗖𝗜: Parses OCI IAM policies to identify over-privileged users and compute effective permissions, showing you exactly what a compromised identity can do: https://lnkd.in/d2wzTUx3 🛠️ 𝗖𝗟𝗜 𝗦𝗶𝗴𝗻𝗶𝗻𝗴 𝗛𝗲𝗹𝗽𝗲𝗿: A fork of the OCI CLI enhanced with offensive capabilities (like instance principal authentication) for off-instance exploitation: https://lnkd.in/d2e-EMHk Here’s the OCIguana Workshop, as presented at DEF CON 26: https://lnkd.in/d4NPE_49 Read the full deep-dive and learn how to leverage these open-source tools here: https://lnkd.in/dTPhxXWq
-
-
Security teams are drowning in raw, uncontextualized alerts - while the exposures that actually matter hide in how trust, identity, and privilege behave once an attacker starts chaining them together. That's why we're releasing two open-source exposure hunting engines at Black Hat USA and DEF CON 2026 - built to shift left and hunt deep. 🎯𝗙𝗔𝗜𝗻𝗱 𝗺𝘆 𝗫𝗣𝗖 - macOS XPC attack surface discovery. Many macOS apps ship privileged root XPC services that trust a caller based on its code-signing identity alone. Our research shows that it's bypassable end-to-end from an unprivileged, non-admin account - by priming the AMFI code-signing cache and swapping a sealed NIB resource, attacker code runs inside a trusted signed app and inherits its identity. The result: unauthenticated root code execution demonstrated in shipping endpoint-security software. What makes the tool different: it proves exploitability across a full pipeline: 🔹 Inventory → ranks injectable, root-hosting targets. 🔹 Inject & Prove → confirms payload execution inside a trusted app. 🔹 Recon → maps reachable privileged services. 🔹 Reverse → an AI agent (Claude) recovers each daemon's methods, signatures, protocols, and acceptance rules. 🔹 Fire & Verify → issues a real privileged call and verifies the concrete outcome from system evidence. Crucially, it distinguishes genuinely exploitable services from those protected by per-action authorization or launch constraints - automatically. 📍 Black Hat Arsenal - Wednesday, August 5th at 11:20 a.m. PT, Arsenal station 4, Business Hall ☁️ 𝗢𝗳𝗳𝗲𝗻𝘀𝗶𝘃𝗲 𝗢𝗖𝗜 𝗧𝗼𝗼𝗹𝗶𝗻𝗴 - identity & network exposure in Oracle Cloud IAM. OCI IAM layers policy language, compartment hierarchies, dynamic groups, verb-based permissions, and instance/resource principals - creating privilege escalation paths no single-policy review will surface. 🔹 𝗽𝗢𝗹𝗶𝗖𝗜 parses OCI policy, expands it against Oracle's permission reference data, and computes effective permissions per principal - exposing over-privileged identities and what a compromised one can really do 🔹 𝗖𝗟𝗜 𝗦𝗶𝗴𝗻𝗶𝗻𝗴 𝗛𝗲𝗹𝗽𝗲𝗿 extends the OCI CLI with offensive capabilities, including instance-principal authentication for off-instance exploitation 📍 Hands-on Offensive OCI workshop at DEF CON 2026, August 8th at 4:00 p.m. PT, Zone A room 312 The goal: turn deep, adversarial research that used to take extensive manual reverse engineering into something repeatable - so defenders go from blind spot to verified exposure in minutes. Led by senior security researchers Hillel Pinto and Eli Shparaga. Read the full blog post here: https://lnkd.in/d_F88wRU 📩 Join the waitlist for availability and download links: https://lnkd.in/dFnjsPFb
-
-
Some of the most dangerous exposures can't be found by scanning a config or running a vulnerability check. They live in how trust, identity, and privileges actually behave once an attacker starts connecting the pieces. At 𝗕𝗹𝗮𝗰𝗸 𝗛𝗮𝘁 𝗨𝗦𝗔 and 𝗗𝗘𝗙 𝗖𝗢𝗡 𝟯𝟰, we're releasing two open-source tools that automate exactly that kind of deep, adversarial analysis - and putting it in defenders' hands. 𝗙𝗔𝗜𝗻𝗱 𝗺𝘆 𝗫𝗣𝗖 - Many macOS apps rely on privileged XPC services that trust callers based on code-signing identity. Our researchers showed that trust model can be bypassed from an unprivileged account, letting attacker-controlled code inherit a trusted app's identity and invoke privileged methods with no further authentication. FAInd my XPC automates the discovery and validation of this vulnerability class, using AI-assisted reverse engineering to map exposed methods and protocols - then issues a real privileged call and verifies the system evidence. No more guessing whether a weakness is theoretical or a demonstrated path to root. 📍 Black Hat Arsenal - Station 4, Business Hall - Wednesday, Aug 5, 11:20 a.m. PT 𝗢𝗳𝗳𝗲𝗻𝘀𝗶𝘃𝗲 𝗢𝗖𝗜 𝗧𝗼𝗼𝗹𝗶𝗻𝗴 - Oracle Cloud IAM layers policies, compartments, dynamic groups, and resource principals until it's genuinely hard to know what an identity can really do. pOliCI parses OCI policies and calculates effective permissions per principal, surfacing overprivileged identities and post-compromise actions. The 𝗖𝗟𝗜 𝗦𝗶𝗴𝗻𝗶𝗻𝗴 𝗛𝗲𝗹𝗽𝗲𝗿 extends the OCI CLI to test instance-principal authentication from an attacker's perspective. 📍 DEF CON 34, Cloud Village - Zone A, Room 312 - Friday, Aug 8, 4:00 p.m. PT The goal is simple: make deep attack-path research repeatable, so defenders don't have to start from scratch every time. Big credit to Senior Security Researchers Hillel Pinto and Eli Shparaga, and the XM Cyber research team behind this work. Read the full press release here: https://lnkd.in/dBw5ZxGe Want early access? Join the waitlist for availability updates: https://lnkd.in/dFnjsPFb At Black Hat? Come find us at 𝗕𝗼𝗼𝘁𝗵 #𝟱𝟭𝟰𝟳.
-
-
Stop asking your dev teams to fix 5,000 vulnerabilities. 𝗔𝘀𝗸 𝘁𝗵𝗲𝗺 𝘁𝗼 𝗳𝗶𝘅 𝟯. Trying to patch everything without context creates two massive leadership challenges: 🛑 𝗗𝗲𝘃 𝗙𝗿𝗶𝗰𝘁𝗶𝗼𝗻: Developers feel overwhelmed by endless SLA tickets. 🛑 𝗙𝗮𝗹𝘀𝗲 𝗦𝗲𝗰𝘂𝗿𝗶𝘁𝘆: Fixing 1,000 low-risk flaws feels like progress, but it actually leaves critical attack paths open. The solution? 𝗖𝗼𝗻𝘁𝗲𝘅𝘁 𝗼𝘃𝗲𝗿 𝘃𝗼𝗹𝘂𝗺𝗲. Effective vulnerability management is a prioritization game. Here’s the 3-Step Mindset Shift for SOC Leaders: 𝟭. 𝗗𝗶𝘁𝗰𝗵 𝗿𝗮𝘄 𝗖𝗩𝗦𝗦 𝗮𝘀 𝘆𝗼𝘂𝗿 𝘀𝗼𝗹𝗲 𝗺𝗲𝘁𝗿𝗶𝗰: Context (reachability, asset criticality, active exploits) matters more than base severity. 𝟮. 𝗦𝗲𝘁 𝗿𝗲𝗮𝗹𝗶𝘀𝘁𝗶𝗰 𝗰𝗮𝗱𝗲𝗻𝗰𝗲𝘀: Focus engineering teams on their top 3 needle-moving fixes every week. 𝟯. 𝗠𝗲𝗮𝘀𝘂𝗿𝗲 𝗿𝗶𝘀𝗸 𝗿𝗲𝗱𝘂𝗰𝘁𝗶𝗼𝗻, 𝗻𝗼𝘁 𝗽𝗮𝘁𝗰𝗵 𝗰𝗼𝘂𝗻𝘁: Celebrate closing actual exposure windows over arbitrary ticket volume. So, instead of dumping a 500-page scanner report on your engineering lead, give them 𝟯 𝗰𝗿𝗶𝘁𝗶𝗰𝗮𝗹, 𝗵𝗶𝗴𝗵-𝗰𝗼𝗻𝘁𝗲𝘅𝘁 𝗳𝗶𝘅𝗲𝘀 per week that actually impact business risk. How are you currently solving the "vulnerability overwhelm" paradox?
-
TL;DR - Advancing to Exposure Management is a must. Here’s how we make it easier. Regain Defenders’ Home Advantage with the new set of XM Agents! Meet the new set of AI Agents from XM Cyber that streamline preemptive security for your overloaded teams: XM Researcher, XM Detector, XM Operator, and XM Orchestrator. With threat actors using AI to exploit exposures faster than ever, the only way to protect your critical business assets is to shrink the exposure window. Rather than build AI agents to cover for missing features, we’re launching the assistants that can help our customers where they struggle most: ⚡XM Researcher: Cuts exposure research time to 1-2 hours to protect your critical assets from the latest threats 🎯XM Detector: Automatically tags business-critical assets (like VIP accounts) and generates attack scenarios that compromise them 📋XM Operator: Turns prioritized threats into a ready-to-go, step-by-step remediation blueprint 🤝XM Orchestrator: Simulates workflows between IT, Security, and Governance to eliminate cross-team friction and speed up MTTR Stop chasing vulnerabilities—start closing exposure windows. 🔗 Read the full blog post from our AI Security lead Marina Kidron https://lnkd.in/dDgx_ZJB #Cybersecurity #ExposureManagement #AIAgents #XMCyber #InfoSec #Automation
-
-
Marking a major milestone in exposure management, CrowdStrike will acquire the intellectual property of XM Cyber as part of an expanded strategic partnership with Schwarz Digits. This step reflects the strength of what our team has built. Over the years, XM Cyber pioneered a new way to think about exposure, showing organizations the paths attackers take to their most critical assets. This milestone puts what we built on a global stage and opens the door for our sovereign approach to reach organizations far beyond what any single company could serve alone. None of this would have been possible without our customers, partners and employees. Thank you for the trust you placed in us and the work we did together to get here. XM Cyber will continue to operate and support our customers as we always have. #Cybersecurity #ExposureManagement #CrowdStrike #XMCyber #TechNews #StrategicPartnership
-
-
🚨 What if any standard user could elevate his privileges from user mode without any alerts? That's not a hypothetical. Our research team just demonstrated a novel macOS privilege escalation technique that breaks one of the platform's most trusted assumptions: that only a vendor's own signed software can talk to its privileged background processes. By chaining CDHash kernel-cache exploitation with NIB payload injection, an unprivileged user (UID 502 - no root) can impersonate a trusted app component and invoke arbitrary privileged XPC methods with 𝘇𝗲𝗿𝗼 𝗮𝘂𝘁𝗵𝗲𝗻𝘁𝗶𝗰𝗮𝘁𝗶𝗼𝗻. The result? Security agents that unload, disable, and remove themselves - using their own self-defense mechanisms against them. We've already validated this against major enterprise endpoint tools and the Kandji MDM agent (CVE-2026-39118). Bounties paid. Fixes shipped. Detections in place. To map how deep this goes, XM Cyber Senior Security Researcher Hillel Pinto built 𝗫𝗣𝗖 𝗛𝘂𝗻𝘁𝗲𝗿 - an open-source framework that automatically discovers exploitable XPC privilege escalation surfaces across every installed macOS app, at scale. 📍Full technical breakdown + tool release: 𝗕𝗹𝗮𝗰𝗸 𝗛𝗮𝘁 𝗨𝗦, 𝗔𝘂𝗴𝘂𝘀𝘁 𝟮𝟬𝟮𝟲. If your macOS fleet runs privileged XPC services (spoiler: it does), you'll want to be in that room. Want access to the XPC Hunter? Full breakdown and link in the comments
-