Apple’s Private Cloud Compute Flaw Rewarded
Apple paid a bounty for a vulnerability in Private Cloud Compute's darwin-init component, tracked as CVE-2026-20685.
Apple paid a bounty for a vulnerability in Private Cloud Compute's darwin-init component, tracked as CVE-2026-20685.
This week's ThreatsDay Bulletin covers a wide range of cybersecurity developments, including new attack techniques, data breaches, and product updates. Key highlights…
Apple paid a $150,000 bounty for a path traversal vulnerability in darwin-init, tracked as CVE-2026-20685, which could allow privileged network attackers to…
Security researcher Malcolm Stagg has disclosed a new attack class called NatJack that exploits network address translation (NAT) connection state to hijack…
404 Media received a statement from Apple indicating that the company is investigating the researchers' report about WebKit proxy bypasses that can…
XProtect is Apple's built-in malware protection that can trace process trees from pasted terminal commands, check network artifacts against Safe Browsing, and…
macOS 26.4, released on March 24, 2026, includes protections against ClickFix-style attacks, such as a confirmation prompt for Terminal when pasting commands…