Endpoint/Device Security macOS attack technique bypasses endpoint security tools June 24, 2026 Share By SC Staff (Adobe Stock) A new macOS attack technique has been demonstrated by cybersecurity firm XM Cyber, allowing standard user accounts to disable enterprise security tools without detection. This method exploits legitimate macOS behavior rather than software vulnerabilities, posing a significant risk to organizations, Security Week reports. The attack technique leverages weakly-validated XPC connections and the injection of malicious payloads into application Interface Builder files. A novel chain exploits the persistence of the kernel’s code-signing trust cache after a legitimate application executes, enabling an attacker to impersonate a trusted app component and invoke privileged XPC methods. XM Cyber successfully demonstrated this against CrowdStrike Falcon Sensor, completely unloading it from a standard user account. The technique also permanently deactivated Kandji MDM by clearing EDR guards and terminating the Endpoint Security Framework extension. CrowdStrike has issued a bug bounty and added detection, while Kandji has patched the issue, assigning it CVE-2026-39118. A third unnamed EDR vendor is also working on a patch. XM Cyber researcher Hillel Pinto will release an open-source tool, XPC Hunter, to identify exploitable XPC privilege escalation surfaces. Source: Security Week SC Staff Related Endpoint/Device Security GhostTree technique uses NTFS junctions to evade security scans SC Staff June 16, 2026 GhostTree leverages NTFS junctions, a file system feature that allows one directory to point to another. Endpoint/Device Security Microsoft Defender for Endpoint to automatically isolate compromised devices SC Staff May 26, 2026 The new feature automatically disconnects compromised endpoints from the network, limiting the risk of further impact while maintaining connectivity to the Defender for Endpoint service for continued monitoring. Endpoint/Device Security Windows 10 KB5087544 update fixes Remote Desktop warnings and Secure Boot reporting SC Staff May 13, 2026 The KB5087544 update for Windows 10, available for Enterprise LTSC and ESU program participants, primarily delivers security fixes and bug resolutions, addressing 120 vulnerabilities patched in May 2026. Get daily email updates SC Media's daily must-read of the most current and pressing daily news Business Email By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy . Subscribe Related Terms Anti-Malware Antivirus Software Bring Your Own Device (BYOD) Ephemeral Port Extranet Endpoint Security Firmware Keylogger Registry You can skip this ad in 5 seconds