Handler on Duty: Didier Stevens
Threat Level: green
Podcast Detail
SANS Stormcast Tuesday, September 29th, 2026: MacOS/iOS 0-Day Patch; macOS priv. escalation 0-day; File Notification Attacks
If you are not able to play the podcast using the player below: Use this direct link to the audio file: https://traffic.libsyn.com/securitypodcast/10114.mp3
My Next Class
Click HERE to learn more about classes Johannes is teaching for SANS
Apple Emergency Patch for iOS 26, macOS26, macOS15 (CVE-2026-86950)
https://isc.sans.edu/diary/Apple%20Emergency%20Patch%20for%20iOS%2026%2C%20macOS26%2C%20macOS15%20%28CVE-2026-86950%29/33376
https://support.apple.com/en-us/100100
Proof of concept for macOS CoreServices Priv. Escalation (CVE-2026-43786)
https://github.com/Malwation/CVE-2026-43786
NeedyMantis: Unpacking a post-compromise malware family used in targeted operations
https://www.microsoft.com/en-us/security/blog/2026/09/28/needymantis-unpacking-a-post-compromise-malware-family-used-in-targeted-operations/
File Notification Attacks https://inoti.fyi/pubs/file-notification-attacks.pdf
My Upcoming Classes
https://www.sans.org/profiles/dr-johannes-ullrich
| Network Monitoring and Threat Detection In-Depth | Amsterdam | Oct 12th - Oct 17th 2026 |
| Application Security: Securing Web Applications, APIs, and Microservices | Washington | Dec 14th - Dec 18th 2026 |
| Application Security: Securing Web Applications, APIs, and Microservices | Online | US Eastern | Feb 8th - Feb 12th 2027 |
| Application Security: Securing Web Applications, APIs, and Microservices | Online | India Standard Time | Mar 15th - Mar 19th 2027 |
| Application Security: Securing Web Applications, APIs, and Microservices | Orlando | Apr 12th - Apr 16th 2027 |
| Application Security: Securing Web Applications, APIs, and Microservices | Online | US Mountain | Apr 21st - Apr 25th 2027 |
| Application Security: Securing Web Applications, APIs, and Microservices | Baltimore | May 17th - May 21st 2027 |
Podcast Transcript
Hello and welcome to the Tuesday September 29th edition of the SANS Internet Storm Center's Stormcast. My name is Johannes Ullrich, recording today from Ottawa, Canada. And this episode is brought to you by the SANS.edu Graduate Certificate Program in Incident Response. Well today we got some interesting patches from Apple. Apple released patches or updates for pretty much all of its operating systems, but only the last generation of its operating systems actually got security fixes. These security fixes do apply a patch for one individual vulnerability in core graphics. It's exploited currently in the wild and Apple has been notified of this exploitation by the Meta Product Security Team. So this is a patch that you want to apply if you're still running iOS 26 or macOS 26. They even released an update for macOS 15. The updates that were released for the 27 versions of the operating systems, again, they do not include any security content, but just functional issues. So that's the usual cleanup release that we often have seen sort of a couple weeks after a particular major version of the operating system was released by Apple. And then let's stick with Apple here for another story. We do have a proof of concept for a local privilege escalation vulnerability. This vulnerability was patched two weeks ago. So in the last security update that we got for macOS, it's a privilege escalation vulnerability in macOS core services. The reason I mention it is that I don't see a lot of proof of concept code like this being published for these macOS vulnerabilities. And core services has had issues with privilege escalations in the past. So assumption is it will have privilege escalations in the future, which of course means with a proof of concept like this being available, it may be easier for attackers to then exploit these future vulnerabilities. So take them a bit more serious. Microsoft published something that definitely the threat hunters in the audience will like, and that's a write-up of Needy Mantis. Needy Mantis is one of these more sophisticated command control tools that's being deployed as an implant after the initial compromise. Microsoft believes this sort of came out of the same group that also is associated with a daemon tool, some of the supply chain compromises. Kaspersky apparently did write about it. Now a couple interesting things here, and again, particular from sort of a detection and response point of view, this malware does use some legitimate DLLs it will find on the system. So if you have, for example, tight VNC or curl and other tools like this installed on the system, it will use the features via the DLLs that are deployed by the tools. So if you are finding that this implant uses some of these DLLs, well, don't just simply erase them. Double check first whether or not these tools are supposed to be installed and whether these DLLs are still legitimate that you're finding. Also again, more use of WebSocket here for data exfiltration. Interesting, some little twist here where it does send a set cookie header that also exfiltrates some details about the system it's installed on. The first install of the malware is very basic, only has a couple different commands, but most importantly, it has the ability to load additional modules. And that's something that we have definitely seen quite commonly these days in more advanced malware that they basically don't want to give away everything the malware can do right away, but then only sort of load specific modules as needed. And then we got a really interesting research paper, probably not the most critical attack, but one of those neat things that I think makes you think a little bit deeper about operating systems, at least that I ever so often like these types of attacks. This comes from several research researchers at the Graz University of Technology in Austria. And it's about file notifications. So all operating systems, Windows, Linux, Mac OS have to some extent the ability to notify software whenever a file changes. And that's quite important. If you, for example, have an editor or so that changes a file, you automatically want to, for example, recompile software whenever the file changes. And so you can subscribe to these file notifications. But what surprised me is that it's possible for an attacker to receive notifications for files that the attacker actually doesn't even have read access to. So in this case, the attacker just has to know what the file is being called, and then they're able to subscribe to these events. And that's, of course, particularly interesting when you're talking about editor files, where the file may be updated as the user types. And that, of course, gives you then some insight into keystroke rhythms and maybe potentially into the content of specific file. So one of those interesting sort of site channel attacks emerges then out of the ability to actually receive these file notifications. More details in the paper. Well, and this is it for today. So thanks for listening. Thanks for liking. Thanks for subscribing to this podcast and talk to you again tomorrow. Bye.





