1. X
  2. Patrick Wardle
Log inSign up
Patrick Wardle
10.5K posts
Image
user avatar
Patrick Wardle
@patrickwardle
πŸ›  🍎 πŸ‘Ύ Objective-See'ing & DoubleYou'ing
Maui, HI
objective-see.org
Joined October 2013
987
Following
40.6K
Followers
RepliesRepliesMediaMedia
  • Pinned
    user avatar
    Patrick Wardle
    @patrickwardle
    Apr 25, 2024
    Stoked for the next (ad)venture: "DoubleYou" techcrunch.com/2024/04/25/ex-… Cofounded w/ long-time friend @hexlogic, we're empowering those building security tools for Apple devices πŸŽπŸ›‘οΈ And by bootstrapping this venture, our core value of democratizing security remains our focus!
    Image
    Ex-NSA hacker and ex-Apple researcher launch startup to protect Apple devices | TechCrunch
    From techcrunch.com
  • user avatar
    Patrick Wardle
    @patrickwardle
    Aug 5
    Stoked to be presenting today at #BlackHat Arsenal! "Practical Ransomware Detection (via Math, not AI)" 😁 πŸ—“οΈ Today, Aug 4th πŸ“ Arsenal Station 4 Stop by if you're at Black Hat! More info: πŸ”— blackhat.com/us-26/arsenal/…
  • user avatar
    Patrick Wardle
    @patrickwardle
    Jul 29
    Wonder if this is what caused SentinelOne to start flagging Apple system binaries on macOS 26.6 as "suspicious threats" πŸ‘€πŸ€” H/T Matt Lee via LinkedIn: lnkd.in/p/dGFmbTr8
    Image
    user avatar
    Patrick Wardle
    @patrickwardle
    Jul 27
    macOS 26: the leaf cert. used to sign 🍎 -binaries is now "macOS Software Signing" (prev. "Software Signing"). Intermediate ("Apple Code Signing Certification Authority") & root ("Apple Root CA") unchanged. Relevant to some security tools (e.g. LuLu) that cared about this! πŸ‘€
  • user avatar
    Patrick Wardle
    @patrickwardle
    Jul 27
    macOS 26: the leaf cert. used to sign 🍎 -binaries is now "macOS Software Signing" (prev. "Software Signing"). Intermediate ("Apple Code Signing Certification Authority") & root ("Apple Root CA") unchanged. Relevant to some security tools (e.g. LuLu) that cared about this! πŸ‘€
  • user avatar
    Patrick Wardle
    @patrickwardle
    Jul 27
    Sometimes simple bugs are the best! πŸ™ŒπŸΌ "the PasswordManagerBrowserExtensionHelper binary logged the session PIN to the system log via os_log" πŸ”“πŸ«  Thanks for sharing your research/writeup @joshparnham πŸ™πŸ½
    Image
    user avatar
    Josh Parnham
    @joshparnham
    Jul 18
    Published a writeup on CVE-2025-24169, a macOS vulnerability which allowed a malicious app to enumerate a user's saved account data in the Passwords app - contravening TCC protections. Example PoC + full details here: joshparnham.com/2026/07/access…

Log in or sign up for X

See what’s happening and join the conversation

Continue with phone
or
Log in with username or email
TermsΒ·PrivacyΒ·CookiesΒ·AccessibilityΒ·Ads InfoΒ·Β© 2026 X Corp.
Advertisement
Advertisement