Home / Technology / New tools expose macOS & Oracle Cloud attack paths

New tools expose macOS & Oracle Cloud attack paths

Summary

  • Tools automate discovery of hidden attack paths.
  • macOS XPC trust model bypasses can be exploited.
  • OCI IAM policies create complex privilege escalation.
New tools expose macOS & Oracle Cloud attack paths

XM Cyber has introduced new open-source exposure hunting tools designed to automate the identification and validation of complex attack paths. These tools focus on privileged macOS services and Oracle Cloud Infrastructure (OCI) identity environments. The FAInd my XPC tool specifically targets macOS, automating the discovery and validation of vulnerabilities in privileged XPC services that rely on code-signing identities.

The Offensive OCI toolset addresses the complexity of Oracle Cloud Infrastructure's IAM. It parses policies to reveal overprivileged identities and potential post-compromise actions. A CLI Signing Helper extends the OCI command-line interface for testing instance principal authentication. These tools, demonstrated at Black Hat USA and DEF CON 34 respectively, aim to provide defenders with repeatable methods for deep, adversarial analysis.

Disclaimer: This story has been auto-aggregated and auto-summarised by a computer program. This story has not been edited or created by the Feedzop team.

Read more news on

Property Code: 5571