#jamf — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #jamf, aggregated by home.social.
-
Fałszywy menedżer schowka kradnie hasła na Macu. Poznaj sprytnego PamStealera
Pobierasz z sieci niewielkie, przydatne narzędzie, instalator rzuca komunikatem o uszkodzonym pliku, a ty machasz na to ręką.
W tle jednak właśnie oddałeś hakerom klucze do swojego cyfrowego życia. Badacze do spraw cyberbezpieczeństwa z firmy Jamf natrafili na nowy, wysoce wyrafinowany złośliwy kod wymierzony w użytkowników macOS. Wirus o nazwie PamStealer udowadnia, że cyberprzestępcy wkładają coraz więcej wysiłku w omijanie zabezpieczeń komputerów Apple.
Pułapka ukryta w popularnej aplikacji
PamStealer rozprzestrzenia się pod postacią instalatora udającego Maccy – popularnego i cenionego menedżera schowka dla komputerów Mac. Zamiast właściwego programu, użytkownik pobiera obraz dysku zawierający złośliwy skrypt. Aby zainfekować system i pominąć wbudowane w macOS mechanizmy izolacji (tzw. kwarantannę blokującą nieznane pliki z sieci), fałszywy instalator wręcz prosi ofiarę o wciśnięcie kombinacji klawiszy Command-R.
Wykonanie tego polecenia uruchamia lawinę zdarzeń ukrytych głęboko przed okiem użytkownika. Skrypt bezszelestnie pobiera główny moduł wirusa, wykorzystując do tego natywne, systemowe narzędzia programistyczne Apple. Dzięki temu cały proces instalacji nie wzbudza najmniejszych podejrzeń programów antywirusowych.
Weryfikacja hasła prosto z systemu
Tym, co najbardziej wyróżnia PamStealera, jest sposób, w jaki przechwytuje dane logowania. Kod wirusa został napisany w języku Rust, co samo w sobie jest nietypowe dla złośliwego oprogramowania na macOS. Gdy program usadowi się już w systemie (często przebierając się za systemowego Findera), wyświetla fałszywe okienko z prośbą o podanie hasła administratora. Z pozoru wygląda ono jak standardowy, natywny monit autoryzacyjny Apple.
Zamiast jednak wysyłać wpisane dane w ciemno do hakera, PamStealer weryfikuje je lokalnie, korzystając z wbudowanego w macOS modułu uwierzytelniania PAM (Pluggable Authentication Modules). Jeśli wpiszesz błędne hasło, okienko pojawi się ponownie. Gdy podasz prawidłowe, wirus wyświetli fałszywy komunikat o „uszkodzonym pliku”, by uśpić twoją czujność. Dopiero wtedy poprawne dane logowania wędrują zaszyfrowanym kanałem prosto na serwer przestępców.
Cichy złodziej kryptowalut i danych
Twórcy tego zagrożenia włożyli mnóstwo wysiłku w to, by ich narzędzie działało jak duch. Wirus potrafi na przykład opóźnić systemową prośbę o pełny dostęp do dysku nawet o 40 minut. Dzięki temu użytkownik nie powiąże nagłego komunikatu z wcześniejszą próbą instalacji rzekomego menedżera schowka.
Gdy PamStealer uzyska już odpowiednie uprawnienia, nie ogranicza się tylko do kradzieży hasła głównego. W jego kodzie znaleziono również skrypty aktywnie poszukujące portfeli z kryptowalutą Ethereum. To kolejne, bolesne przypomnienie, że choć ekosystem macOS jest solidnie zabezpieczony, to najsłabszym ogniwem wciąż pozostaje użytkownik pobierający oprogramowanie z niezweryfikowanych źródeł.
#Apple #cyberbezpieczeństwo #Ethereum #Jamf #kradzieżHaseł #Maccy #macOS #malware #PamStealer #wirusOpenAI na celowniku hakerów. Sprytny atak i pilna aktualizacja aplikacji dla macOS
-
Fałszywy menedżer schowka kradnie hasła na Macu. Poznaj sprytnego PamStealera
Pobierasz z sieci niewielkie, przydatne narzędzie, instalator rzuca komunikatem o uszkodzonym pliku, a ty machasz na to ręką.
W tle jednak właśnie oddałeś hakerom klucze do swojego cyfrowego życia. Badacze do spraw cyberbezpieczeństwa z firmy Jamf natrafili na nowy, wysoce wyrafinowany złośliwy kod wymierzony w użytkowników macOS. Wirus o nazwie PamStealer udowadnia, że cyberprzestępcy wkładają coraz więcej wysiłku w omijanie zabezpieczeń komputerów Apple.
Pułapka ukryta w popularnej aplikacji
PamStealer rozprzestrzenia się pod postacią instalatora udającego Maccy – popularnego i cenionego menedżera schowka dla komputerów Mac. Zamiast właściwego programu, użytkownik pobiera obraz dysku zawierający złośliwy skrypt. Aby zainfekować system i pominąć wbudowane w macOS mechanizmy izolacji (tzw. kwarantannę blokującą nieznane pliki z sieci), fałszywy instalator wręcz prosi ofiarę o wciśnięcie kombinacji klawiszy Command-R.
Wykonanie tego polecenia uruchamia lawinę zdarzeń ukrytych głęboko przed okiem użytkownika. Skrypt bezszelestnie pobiera główny moduł wirusa, wykorzystując do tego natywne, systemowe narzędzia programistyczne Apple. Dzięki temu cały proces instalacji nie wzbudza najmniejszych podejrzeń programów antywirusowych.
Weryfikacja hasła prosto z systemu
Tym, co najbardziej wyróżnia PamStealera, jest sposób, w jaki przechwytuje dane logowania. Kod wirusa został napisany w języku Rust, co samo w sobie jest nietypowe dla złośliwego oprogramowania na macOS. Gdy program usadowi się już w systemie (często przebierając się za systemowego Findera), wyświetla fałszywe okienko z prośbą o podanie hasła administratora. Z pozoru wygląda ono jak standardowy, natywny monit autoryzacyjny Apple.
Zamiast jednak wysyłać wpisane dane w ciemno do hakera, PamStealer weryfikuje je lokalnie, korzystając z wbudowanego w macOS modułu uwierzytelniania PAM (Pluggable Authentication Modules). Jeśli wpiszesz błędne hasło, okienko pojawi się ponownie. Gdy podasz prawidłowe, wirus wyświetli fałszywy komunikat o „uszkodzonym pliku”, by uśpić twoją czujność. Dopiero wtedy poprawne dane logowania wędrują zaszyfrowanym kanałem prosto na serwer przestępców.
Cichy złodziej kryptowalut i danych
Twórcy tego zagrożenia włożyli mnóstwo wysiłku w to, by ich narzędzie działało jak duch. Wirus potrafi na przykład opóźnić systemową prośbę o pełny dostęp do dysku nawet o 40 minut. Dzięki temu użytkownik nie powiąże nagłego komunikatu z wcześniejszą próbą instalacji rzekomego menedżera schowka.
Gdy PamStealer uzyska już odpowiednie uprawnienia, nie ogranicza się tylko do kradzieży hasła głównego. W jego kodzie znaleziono również skrypty aktywnie poszukujące portfeli z kryptowalutą Ethereum. To kolejne, bolesne przypomnienie, że choć ekosystem macOS jest solidnie zabezpieczony, to najsłabszym ogniwem wciąż pozostaje użytkownik pobierający oprogramowanie z niezweryfikowanych źródeł.
#Apple #cyberbezpieczeństwo #Ethereum #Jamf #kradzieżHaseł #Maccy #macOS #malware #PamStealer #wirusOpenAI na celowniku hakerów. Sprytny atak i pilna aktualizacja aplikacji dla macOS
-
Great time co-presenting with Levi McCormick @ @OpenSourceNorth! We shared our #multicloud journey at @JamfSoftware across @awscloud & @azure.
-
Great time co-presenting with Levi McCormick @ @OpenSourceNorth! We shared our #multicloud journey at @JamfSoftware across @awscloud & @azure.
-
Wir verleihen #iPad an Schüler:innen.
Selbst bei Klasse 11 scheint es wohl sehr viel über die schulische Nutzung hinaus benutzt zu werden. Eltern fragen uns ob man bei verwalteten Geräten #MDM nicht auch sowas wie #Bildschirmzeit einschränken kann.
Wir nutzen #JAMF #Pro als MDM
Hat jemand Erfahrungen damit, ob die zugehörige JAMF #Parent #App diese Einschränkungen ermöglichen würde und wie aufwändig die Administration dafür ist?https://www.jamf.com/de/ressourcen/produktdokumentation/jamf-parent-leitfaden-fur-eltern/
-
Wir verleihen #iPad an Schüler:innen.
Selbst bei Klasse 11 scheint es wohl sehr viel über die schulische Nutzung hinaus benutzt zu werden. Eltern fragen uns ob man bei verwalteten Geräten #MDM nicht auch sowas wie #Bildschirmzeit einschränken kann.
Wir nutzen #JAMF #Pro als MDM
Hat jemand Erfahrungen damit, ob die zugehörige JAMF #Parent #App diese Einschränkungen ermöglichen würde und wie aufwändig die Administration dafür ist?https://www.jamf.com/de/ressourcen/produktdokumentation/jamf-parent-leitfaden-fur-eltern/
-
Forschende von Jamf Threat berichten heute über eine neue Variante einer bekannten Cyberangriffsmethode. Der Angriff zielt auf Mac-Nutzende ab und nutzt eine ziemlich geschickte Täuschung, um Schadsoftware auf den Mac zu schleusen.
Mehr: https://digiprax.maniabel.work/archiv/1248
#infostealer #AtomicStealer #jamf #infosec #up2date #macOS #ScriptEditor #ClickFix
-
The 2026 Security 360 Mobile report is here!
As part of this year’s research, #Jamf partnered with NowSecure to analyze 135 widely used mobile apps used in enterprises today.
The analysis, grounded in #OWASP standards, highlights how pervasive app vulnerabilities are.
See the report findings: https://loom.ly/P761XRY
@jamfsoftware #Jamf #MobileSecurity#Cybersecurity #MobileApps
-
RE: https://mastodon.social/@richcampbell/116131632906487922
I’m back on @RunAsRadio for round 3! 🎧
It was great to catch up with @richcampbell about #multicloud #SaaS.
We dig into:
🔹 Getting SaaS workloads to #Azure #AKS
🔹 #Kubernetes as the bridge
🔹 #OpenTofu, #Prometheus, & more -
RE: https://mastodon.social/@richcampbell/116131632906487922
I’m back on @RunAsRadio for round 3! 🎧
It was great to catch up with @richcampbell about #multicloud #SaaS.
We dig into:
🔹 Getting SaaS workloads to #Azure #AKS
🔹 #Kubernetes as the bridge
🔹 #OpenTofu, #Prometheus, & more -
ffs
The “Developer 16" MacBook Pro” that my employer sent me does not give me admin privileges and I am not in its sudoers file, so I cannot accept the license terms for #Apple’s #Xcode Command Line Tools, preventing me from running such basics as git.
Also, #Docker Desktop for Mac is not available via the #Jamf “Self Service+” app, only #Podman. Even though the former is available from the #Microsoft #Intune Company Portal on #Windows and I have a license for it.
And even Podman Desktop can’t be set up fully because of the lack of admin privileges.
I repeat: ffs
-
ffs
The “Developer 16" MacBook Pro” that my employer sent me does not give me admin privileges and I am not in its sudoers file, so I cannot accept the license terms for #Apple’s #Xcode Command Line Tools, preventing me from running such basics as git.
Also, #Docker Desktop for Mac is not available via the #Jamf “Self Service+” app, only #Podman. Even though the former is available from the #Microsoft #Intune Company Portal on #Windows and I have a license for it.
And even Podman Desktop can’t be set up fully because of the lack of admin privileges.
I repeat: ffs
-
I’m presenting at next week's University of Utah Mac Admins Meeting:
Platform Single Sign-on (Platform SSO) is Apple’s identity management offering for Macs. It promises:
• Integration with an identity provider at the login window
• A single sign-on experience with native and web apps
• Local user account password synchronization with the identity providerLet’s explore what Platform SSO can do and what it takes to configure it using Jamf Pro.
-
I’m presenting at next week's University of Utah Mac Admins Meeting:
Platform Single Sign-on (Platform SSO) is Apple’s identity management offering for Macs. It promises:
• Integration with an identity provider at the login window
• A single sign-on experience with native and web apps
• Local user account password synchronization with the identity providerLet’s explore what Platform SSO can do and what it takes to configure it using Jamf Pro.
-
macOS: Warum von Apple beglaubigte Schadsoftware zum wachsenden Problem wird
Unter macOS taucht zunehmend Schadsoftware auf, die trotz Apples Schutzmechanismen ungehindert startet. Grund sind Apps, die korrekt signiert und von Apple beglaubigt wurden.https://www.apfeltalk.de/magazin/news/macos-warum-von-apple-beglaubigte-schadsoftware-zum-wachsenden-problem-wird/
#Mac #News #Sicherheit #Apple #Beglaubigung #CodeSignierung #Gatekeeper #Jamf #macOS #MacSyncStealer #Malware #Sicherheit -
macOS: Warum von Apple beglaubigte Schadsoftware zum wachsenden Problem wird
Unter macOS taucht zunehmend Schadsoftware auf, die trotz Apples Schutzmechanismen ungehindert startet. Grund sind Apps, die korrekt signiert und von Apple beglaubigt wurden.https://www.apfeltalk.de/magazin/news/macos-warum-von-apple-beglaubigte-schadsoftware-zum-wachsenden-problem-wird/
#Mac #News #Sicherheit #Apple #Beglaubigung #CodeSignierung #Gatekeeper #Jamf #macOS #MacSyncStealer #Malware #Sicherheit -
Hi Fedi friends! I’m having a bit of a philosophical difference of opinion with my current employer (both technical and ethical) I am seeking a new role and would appreciate your support. If you hear of any opportunities or just want to catch up, please send me a message or comment in thread. I’d love to connect.
About me & what I’m looking for:
💼 I’m looking for System Administrator, Information Technology, or Solutions Engineer roles. I would be open to pivoting to Information Security roles.
🌎 I’m open to roles in Iowa, Wisconsin, remote or hybrid.
⭐ I’ve previously worked at The University of Iowa Health Care, Grinnell College. I have extensive experience with Apple platform administration and integration of Apple devices and services in heterogeneous environments.
#macadmins #appleinenterprise #systemadministration #jamf #opentowork
-
Hi Fedi friends! I’m having a bit of a philosophical difference of opinion with my current employer (both technical and ethical) I am seeking a new role and would appreciate your support. If you hear of any opportunities or just want to catch up, please send me a message or comment in thread. I’d love to connect.
About me & what I’m looking for:
💼 I’m looking for System Administrator, Information Technology, or Solutions Engineer roles. I would be open to pivoting to Information Security roles.
🌎 I’m open to roles in Iowa, Wisconsin, remote or hybrid.
⭐ I’ve previously worked at The University of Iowa Health Care, Grinnell College. I have extensive experience with Apple platform administration and integration of Apple devices and services in heterogeneous environments.
#macadmins #appleinenterprise #systemadministration #jamf #opentowork
-
MacOS DigitStealer malware poses as DynamicLake, targets Apple Silicon M2/M3 devices https://www.helpnetsecurity.com/2025/11/20/macos-digitstealer-malware-poses-as-dynamiclake-targets-apple-silicon-m2-m3-devices/ #Don'tmiss #datatheft #Hotstuff #malware #macOS #News #Jamf #tips
-
MacOS DigitStealer malware poses as DynamicLake, targets Apple Silicon M2/M3 devices https://www.helpnetsecurity.com/2025/11/20/macos-digitstealer-malware-poses-as-dynamiclake-targets-apple-silicon-m2-m3-devices/ #Don'tmiss #datatheft #Hotstuff #malware #macOS #News #Jamf #tips
-
Jamf to Go Private Following $2.2 Billion Acquisition by Francisco Partners https://www.securityweek.com/jamf-to-go-private-following-2-2-billion-acquisition-by-francisco-partners/ #FranciscoPartners #privateequity #Acquisition #M&ATracker #Jamf #MA
-
Jamf to Go Private Following $2.2 Billion Acquisition by Francisco Partners https://www.securityweek.com/jamf-to-go-private-following-2-2-billion-acquisition-by-francisco-partners/ #FranciscoPartners #privateequity #Acquisition #M&ATracker #Jamf #MA
-
Jamf adds AI forensics to help organizations detect and respond to mobile threats https://www.helpnetsecurity.com/2025/10/20/jamf-ai-analysis-executive-threat-protection/ #Industrynews #Jamf
-
Jamf adds AI forensics to help organizations detect and respond to mobile threats https://www.helpnetsecurity.com/2025/10/20/jamf-ai-analysis-executive-threat-protection/ #Industrynews #Jamf
-
Jamf designa Exclusive Networks para ampliar la seguridad de los dispositivos Apple en el Reino Unido 🇬🇧 e Irlanda 🇮🇪
-
Moin #FediLZ, weiß jemand von euch ob man bei verwalteten #iPads (mit #jamf) verhindern kann, dass die S*S sich in #classroom einen eigenen Namen geben bzw. den ändern?
Es würde wohl gehen, wenn die Klassen aus JAMF kämen, wir wollen aber beibehalten, dass K*K selbst Klassen anlegen können, was dann nicht mehr ginge. -
Moin #FediLZ, weiß jemand von euch ob man bei verwalteten #iPads (mit #jamf) verhindern kann, dass die S*S sich in #classroom einen eigenen Namen geben bzw. den ändern?
Es würde wohl gehen, wenn die Klassen aus JAMF kämen, wir wollen aber beibehalten, dass K*K selbst Klassen anlegen können, was dann nicht mehr ginge. -
I broke the laptop somehow, it's in an infinite loop of uselessness…. and such is today’s "work”. lol
-
I broke the laptop somehow, it's in an infinite loop of uselessness…. and such is today’s "work”. lol
-
It must be Wednesday!
#Patching / #MacAdmins / #Jamf
-
It must be Wednesday!
#Patching / #MacAdmins / #Jamf
-
Seeking #hivemind #macadmins help: I want to disable all browser.ml.* AI nonesense in #firefox, but i do not find any preferences for this in https://mozilla.github.io/policy-templates/ any idea how to set this with #jamf ?
-
Seeking #hivemind #macadmins help: I want to disable all browser.ml.* AI nonesense in #firefox, but i do not find any preferences for this in https://mozilla.github.io/policy-templates/ any idea how to set this with #jamf ?
-
-
-
Heading back home on Amtrak from a nice visit to NYC for the 11th anniversary of the #jamf User Group there.
-
Heading back home on Amtrak from a nice visit to NYC for the 11th anniversary of the #jamf User Group there.
-
Jamf to Acquire Identity Automation for $215 Million https://www.securityweek.com/jamf-to-acquire-identity-automation-for-215-million/ #Identity&Access #Acquisition #M&ATracker #identity #Jamf
-
Jamf to Acquire Identity Automation for $215 Million https://www.securityweek.com/jamf-to-acquire-identity-automation-for-215-million/ #Identity&Access #Acquisition #M&ATracker #identity #Jamf
-
Jamf to Acquire Identity Automation for $215 Million https://www.securityweek.com/jamf-to-acquire-identity-automation-for-215-million/ #Identity&Access #Acquisition #M&ATracker #identity #Jamf
-
Jamf to Acquire Identity Automation for $215 Million https://www.securityweek.com/jamf-to-acquire-identity-automation-for-215-million/ #Identity&Access #Acquisition #M&ATracker #identity #Jamf
-
If you're a Jamf customer (or not) interested in attending the Jamf Nation User Conference in Denver, CO, next year, Super Early Bird pricing ends December 31.
Super Early Bird pricing:
Commercial: $1199.00
Education: $999.00Super Early Bird: 10/01/24 to 12/31/24
Early Bird: 1/01/25 to 3/31/25 (+$200)
Just in Time: 4/01/25 to 7/31/25 (+$100)
Standard: 8/01/25 to 10/09/25 (+$200)https://reg.jnuc.jamf.com/flow/jamf/jnuc2025/home25/page/jnuc2025faq
-
Session videos (126 in all) from this year's Jamf Nation User Conference in Nashville are now live on YouTube. No registration or login required.
Playlist:
https://www.youtube.com/playlist?list=PLlxHm_Px-Ie1NYs8E3zHEL0ktmM-Mrgzn -
In yet another Apple in the enterprise move you’d never have imagine a few years ago, Jamf has announced that select products are now available on the Azure Cloud through Azure Marketplace.
#Apple #Jamf
https://www.applemust.com/jamf-wins-microsoft-top-status-jamf-pro-hits-azure-marketplace/