June 5, 2023, 2:01 a.m. | Sergiu Gatlan

The RISKS Digest catless.ncl.ac.uk

Sergiu Gatlan, *BleepingComputer, 30 May 2023 via ACM Tech News

Apple has patched a vulnerability discovered by Microsoft security
researchers, dubbed Migraine, that would have allowed attackers with root
privileges to install *undeleteable* malware and access the victim's private
data. The researchers said, “By focusing on system processes that are
signed by Apple and have the com.apple.rootless.install.heritable
entitlement, we found two child processes that could be tampered with to
gain arbitrary code execution in a security context that bypasses SIP …

access apple attackers bleepingcomputer bug bypass data hackers install macos malware may may 2023 microsoft microsoft security migraine private private data privileges processes researchers restrictions root security security researchers sergiu gatlan sip system tech victim vulnerability

Senior Security Specialist, Forsah Technical and Vocational Education and Training (Forsah TVET) (NEW)

@ IREX | Ramallah, West Bank, Palestinian National Authority

Consultant(e) Junior Cybersécurité

@ Sia Partners | Paris, France

Senior Network Security Engineer

@ NielsenIQ | Mexico City, Mexico

Senior Consultant, Payment Intelligence

@ Visa | Washington, DC, United States

Corporate Counsel, Compliance

@ Okta | San Francisco, CA; Bellevue, WA; Chicago, IL; New York City; Washington, DC; Austin, TX

Security Operations Engineer

@ Samsara | Remote - US