Conversation

Thanks for clarifying, I didnโ€™t get that impression from โ€œHigh Sierra 0-dayโ€. Not an infosec person, just worried about privacyโ€ฆ

Discover more

Sourced from across Twitter
The supply chain attack resulted in trojanized installers signed w/ 's Dev ID which were then naively notarized by ๐Ÿคฆ๐Ÿปโ€โ™‚๏ธ TIL, Apple did not revoke 's signing cert just the notarization ticket of the installer(s) ๐Ÿ‘€ So technically they're still validly signed ๐Ÿ”
Image
3
58
Show this thread
And speaking of the supply chain attack, I'm stoked at the opportunity to talk more about this at ๐Ÿคฉ Specifically diving into the technical details of the three unique macOS payloads used in what many are calling the first "chained" supply chain attack๐ŸŽ๐Ÿ›๐Ÿ›
Image
Quote Tweet
Image
The @3CX supply chain attack resulted in trojanized installers signed w/ @3CX's Dev ID which were then naively notarized by @Apple ๐Ÿคฆ๐Ÿปโ€โ™‚๏ธ TIL, Apple did not revoke @3CX's signing cert just the notarization ticket of the installer(s) ๐Ÿ‘€ So technically they're still validly signed ๐Ÿ”
Show this thread
7