I did! pretty much as soon as I found the bug๐ ...along with a detailed description and even PoC exploit code ๐ฅ twitter.com/tomjirinec/sta
Conversation
Maybe if you stopped hacking Macs we wouldn't realize they aren't as secure as they tell us
1
2
Discover more
Sourced from across Twitter
3
17
58
Show this thread
And speaking of the supply chain attack, I'm stoked at the opportunity to talk more about this at ๐คฉ
Specifically diving into the technical details of the three unique macOS payloads used in what many are calling the first "chained" supply chain attack๐๐๐
Quote Tweet
The @3CX supply chain attack resulted in trojanized installers signed w/ @3CX's Dev ID which were then naively notarized by @Apple
TIL, Apple did not revoke @3CX's signing cert just the notarization ticket of the installer(s)
So technically they're still validly signed 
Show this thread
2
7




