/
Navigation
C
Chronicles
Browse all articles
C
E
Explore
Semantic exploration
E
R
Research
Entity momentum
R
N
Nexus
Correlations & relationships
N
~
Story Arc
Topic evolution
S
Drift Map
Semantic trajectory animation
D
P
Posts
Analysis & commentary
P
Browse
@
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
?
Concept Search
Semantic similarity search
!
High Impact Stories
Top coverage by position
+
Sentiment Analysis
Positive/negative coverage
*
Anomaly Detection
Unusual coverage patterns
Analysis
vs
Rivalry Report
Compare two entities head-to-head
/\
Semantic Pivots
Narrative discontinuities
!!
Crisis Response
Event recovery patterns
Connected
Nav: C E R N
Search: /
Command: ⌘K
Embeddings: large
VOICE ARCHIVE

Patrick Wardle

@patrickwardle
61 posts
2026-03-04
A few weeks ago, Apple announce that “iPhone and iPad [are] approved to handle *classified* NATO information” 😂 Turns out even lowly cybercriminals were (ab)using 0days to hack Apple devices 🙈 https://www.wired.com/...
2026-03-04 View on X
Wired

Google details Coruna, an exploit kit used to hijack iPhones via malicious websites; iVerify suggests it may have been originally built for the US government

A highly sophisticated set of iPhone hijacking techniques has likely infected tens of thousands of phones or more.

2025-08-30
Maybe we should all be taking closer looks at our iOS/macOS WhatsApp crash reports!? 😬 (TBD if related to CVE-2025-55117) [image]
2025-08-30 View on X
TechCrunch

WhatsApp fixed a zero-click bug in its iOS and Mac apps that was being used, alongside a now-fixed Apple flaw, to hack into devices of “specific targeted users”

“Incomplete authorization of linked device synchronization messages … Matt Suiche : New WhatsApp advisory (CVE-2025-55177) just came out.  Amnesty International says they have been...

2024-09-20
Ah, what did Apple break now? 🤦🏻‍♂ ️ Not sure yet if this is indeed a macOS 15 bug, but it appears so? (as multiple unrelated products affected, that were working seamlessly on macOS 14.*) 🤔 Any insight much appreciated. More info here: https://developer.apple.com/ ...
2024-09-20 View on X
TechCrunch

macOS 15 Sequoia appears to have broken security tools made by CrowdStrike, SentinelOne, Microsoft, and others; CrowdStrike had to delay support for Sequoia

On Monday, Apple released its latest computer operating system update called macOS 15, or Sequoia.

ughh, so Apple knew about the macOS 15 firewall/networking issues?!  😭🫠 [Screenshot from a comment “I work for a large tech company, and we (our IT org) opened an issue and notified Apple directly during the beta program.  Unfortunately the issue is still present in both the 15.0 RC and 15.1 beta."]
2024-09-20 View on X
TechCrunch

macOS 15 Sequoia appears to have broken security tools made by CrowdStrike, SentinelOne, Microsoft, and others; CrowdStrike had to delay support for Sequoia

On Monday, Apple released its latest computer operating system update called macOS 15, or Sequoia.

Worth stressing this was reported to Apple before the GA was released (by multiple people, to multiple teams/orgs within Apple) so Apple 100% knew about this, and shipped macOS 15 anyways 🤦🏻‍♂️🫠
2024-09-20 View on X
TechCrunch

macOS 15 Sequoia appears to have broken security tools made by CrowdStrike, SentinelOne, Microsoft, and others; CrowdStrike had to delay support for Sequoia

On Monday, Apple released its latest computer operating system update called macOS 15, or Sequoia.

2024-08-13
@objective_see's free open-source tools are supported by many amazingly generous patrons (via @Patreon) 🥰 On the other hand, @Apple (the most valuable company in the world w/ a $3+ trillion market cap) is now wanting a massive % cut 😒 ...greedy much!? https://techcrunch.com/...
2024-08-13 View on X
TechCrunch

After Apple's threats, Patreon memberships via its iOS app will be subject to Apple's 30% fee from November 2024; creators must switch to subscription billing

if you're paying with iPhone Hamish McKenzie / On Substack : The price of payments  —  Today, Patreon is in the unenviable position of explaining to creators … Ashley King / Digita...

2024-07-25
I was rather skeptical that this wasn't an elaborate joke, but yes, @CrowdStrike has apparently emailed its customers & offered a ~$10 UberEats gift card/coupon for any “inconvenience” ...and yes, it errors out when one goes to redeem it, saying it has been cancelled 🫠 [image]
2024-07-25 View on X
The Guardian

Insurer Parametrix estimates that the global outage sparked by CrowdStrike's faulty update will cost US Fortune 500 companies, excluding Microsoft, $5.4B

Banking and healthcare firms, major airlines expected to suffer most losses, according to insurer Parametrix

2024-07-24
Update from @CrowdStrike provides details on content of the problematic Channel Files pointing to a problematic “IPC Template Instance” Also confirms our analysis that crash was due to OOB memory read of invalid memory (not a NULL pointer deref. as some erroneously claimed) 👀 [image]
2024-07-24 View on X
The Register

CrowdStrike says the problematic July 19 software update that brought down 8.5M Windows PCs was deployed into production due to “a bug in the Content Validator”

CrowdStrike has blamed a bug in its own test software for the mass-crash-event it caused last week.

2024-07-22
I don't do Windows but here are some (initial) details about why the CrowdStrike's CSAgent.sys crashed Faulting inst: mov r9d, [r8] R8: unmapped address ...taken from an array of pointers (held in RAX), index RDX (0x14 * 0x8) holds the invalid memory address @_JohnHammond [image]
2024-07-22 View on X
Reuters

Reeling from CrowdStrike-related outages, Delta has canceled 5,000+ flights, including 1,384 on Sunday and 700+ for Monday so far, according to FlightAware

Delta Air Lines (DAL.N) struggled to restore normal operations on Sunday after last week's crippling global cyber outage …

I don't do Windows but here are some (initial) details about why the CrowdStrike's CSAgent.sys crashed Faulting inst: mov r9d, [r8] R8: unmapped address ...taken from an array of pointers (held in RAX), index RDX (0x14 * 0x8) holds the invalid memory address @_JohnHammond [image]
2024-07-22 View on X
CrowdStrike

CrowdStrike says a Falcon sensor configuration update on Windows triggered a logic error that resulted in a system crash and BSOD, remediated after 78 minutes

Thankfully, Macs weren't affected by last week's catastrophic … Anthony Ha / TechCrunch : TechCrunch Minute: What caused last week's major tech outage? CrowdStrike : Likely eCrime ...

2024-07-21
I don't do Windows but here are some (initial) details about why the CrowdStrike's CSAgent.sys crashed Faulting inst: mov r9d, [r8] R8: unmapped address ...taken from an array of pointers (held in RAX), index RDX (0x14 * 0x8) holds the invalid memory address @_JohnHammond [image]
2024-07-21 View on X
CrowdStrike

CrowdStrike says a sensor configuration update to Windows systems triggered a logic error that resulted in a system crash and BSOD on impacted systems

What Happened?  —  On July 19, 2024 at 04:09 UTC, as part of ongoing operations, CrowdStrike released a sensor configuration update to Windows systems.

I don't do Windows but here are some (initial) details about why the CrowdStrike's CSAgent.sys crashed Faulting inst: mov r9d, [r8] R8: unmapped address ...taken from an array of pointers (held in RAX), index RDX (0x14 * 0x8) holds the invalid memory address @_JohnHammond [image]
2024-07-21 View on X
The Official Microsoft Blog

Microsoft estimates that CrowdStrike's update affected 8.5M Windows devices, or less than 1% of all Windows machines

On July 18, CrowdStrike, an independent cybersecurity company, released a software update that began impacting IT systems globally.  Although this was not a Microsoft incident …

2024-07-20
I don't do Windows but here are some (initial) details about why the CrowdStrike's CSAgent.sys crashed Faulting inst: mov r9d, [r8] R8: unmapped address ...taken from an array of pointers (held in RAX), index RDX (0x14 * 0x8) holds the invalid memory address @_JohnHammond [image]
2024-07-20 View on X
The Verge

The outage appears to have been caused by CrowdStrike pushing a faulty update to its Falcon software that causes Windows machines to get stuck in a boot loop

I don't do Windows but here are some (initial) details about why the CrowdStrike's CSAgent.sys crashed Faulting inst: mov r9d, [r8] R8: unmapped address ...taken from an array of pointers (held in RAX), index RDX (0x14 * 0x8) holds the invalid memory address @_JohnHammond [image]
2024-07-20 View on X
Wall Street Journal

A profile of CrowdStrike, founded in 2011 and used by 300 companies in the Fortune 500; Gartner: CrowdStrike has ~15% of the global security software market

The little-known company is very popular in Corporate America, contributing to the severity of the global IT outage

2024-02-10
Bypass Apple's App Store review by ....changing one letter!? 🤦🏻‍♂️ 😓 “The fake app uses a similar name to the genuine [LastPass] app, a similar icon, and a red-themed interface ...however, the fake app's name is ‘LassPass,’ instead of ‘LastPass’” https://www.bleepingcomputer.com/ ...
2024-02-10 View on X
BleepingComputer

LastPass warns users about a fake copy of its app on Apple's App Store, with a similar name and logo, likely used as a phishing app to steal users' credentials

2024-02-09
Bypass Apple's App Store review by ....changing one letter!? 🤦🏻‍♂️ 😓 “The fake app uses a similar name to the genuine [LastPass] app, a similar icon, and a red-themed interface ...however, the fake app's name is ‘LassPass,’ instead of ‘LastPass’” https://www.bleepingcomputer.com/ ...
2024-02-09 View on X
BleepingComputer

LastPass warns users about a fake copy of its app on Apple's App Store, with a similar name and logo, likely used as a phishing app to steal users' credentials

what you need to know Amrita Khalid / The Verge : Fake LastPass phishing app nabs a five-star rating on Apple's App Store.The slyly named “LassPass” … Heinrich Long / RestorePrivac...

2024-01-13
This is the blog post to read, if you want to a (slightly) higher-level but still technically sound discussion + additional context about the Chinese govt. capabilities + what Apple knew/should do now: https://blog.cryptographyengineering.co m/ ...
2024-01-13 View on X
CNN

Security researchers say they warned Apple as early as 2019 about AirDrop vulnerabilities that Chinese authorities claim they recently used to identify users

2023-08-14
Stoked for @BlackHatEvents & @defcon, and hope to see y'all 🥰🤗 I'll be presenting 3 brand new talks on: 1️⃣ macOS tools 🛠️ 2️⃣ macOS malware 👾 3️⃣ macOS bypasses 😈 Also: 📚 2 book signings w/ @Fox0x01 🧰 A BH Arsenal tool presentation Details with times & locations below ⬇️
2023-08-14 View on X
Wired

Mac security researcher Patrick Wardle says Apple's macOS Background Task Management tool is “trivially” bypassed by “any malware that's somewhat sophisticated”

Lily Hay Newman / Wired :

This talk will be presented at @defcon ℹ️ Sat. Aug. 12th @ 10:00 (Track 2) https://forum.defcon.org/...
2023-08-14 View on X
Wired

Mac security researcher Patrick Wardle says Apple's macOS Background Task Management tool is “trivially” bypassed by “any malware that's somewhat sophisticated”

Lily Hay Newman / Wired :

2023-08-13
This talk will be presented at @defcon ℹ️ Sat. Aug. 12th @ 10:00 (Track 2) https://forum.defcon.org/...
2023-08-13 View on X
Wired

Mac security researcher Patrick Wardle says Apple's macOS Background Task Management tool is “trivially” bypassed by “any malware that's somewhat sophisticated”

The macOS Background Task Manager tool is supposed to spot potentially malicious software on your machine. Bluesky: @couts.bsky.social . X: @patrickwardle and @patrickwardle Bluesk...