Tech News
← Home  ·  All topics

Edr

4 GoKawiil briefs on this topic

Apple Implements New Controls for Mac Full Disk Access Permissions

Apple announced plans to introduce additional restrictions on Full Disk Access for Mac applications, a permission allowing apps to access nearly all data on a user’s drive. The company provided details on what is changing and the reasons behind these updates, though some specifics remain unclear. The move aims to enhance security and user privacy on macOS devices.

Report: browser-based SaaS attacks slip past EDR tools, NordLayer finds

NordLayer, citing its Browser Security Report 2026, says attackers increasingly compromise SaaS accounts via browser sessions—OAuth token theft, adversary-in-the-middle phishing, malicious extensions—without triggering endpoint detection and response (EDR) alerts because no malicious process or executable touches the host. It cites the 2025 Salesloft Drift breach, where group UNC6395 used stolen OAuth tokens to pull data from Salesforce via API calls, and a 2026 Microsoft-tracked campaign by Storm-2755 using search ads to phish Canadian employees. NordLayer's report found browser access present in all 504 reviewed applications, with 79% accessible only via browser.

Flashpoint Validates Windows EDR Bypass via Process Parameter Poisoning

Flashpoint researchers confirmed a Windows evasion technique called 'process parameter poisoning,' first disclosed in July by Max Hirschberger and Ogulcan Ugur, which hides malicious payloads inside standard process initialization structures rather than using memory APIs like VirtualAllocEx and WriteProcessMemory that EDR tools typically monitor. Flashpoint built its own Rust implementation of the method and found it evaded detection when paired with additional evasion techniques, echoing the original researchers' finding that code injection succeeded against four major EDR products without triggering alerts.

Fake LastPass Authenticator GitHub repos spread new Rapuncel infostealer

LastPass and Delphos Labs identified a malware campaign that uses SEO-optimized GitHub repositories impersonating LastPass and at least 39 other companies to distribute a previously unseen infostealer called Rapuncel. Victims searching for tools like LastPass Authenticator are led to fake repos where oversized ZIP files hide a renamed Microsoft debugger that sideloads the malicious payload and a Microsoft-signed kernel driver capable of killing 145 different antivirus and EDR products.