staff macOS security researcher @jamfsoftware views are my own
Mar 30 • 12 tweets • 3 min read
Apple added another layer of ClickFix paste protection in macOS Tahoe that went mostly unnoticed. This one runs inside the XProtect daemon, scans what you actually paste, and checks domains against Safari's Safe Browsing Service in real time. Here's how it works 🧵
This was initially observed by @MalforsHQ. My first thread covered Terminal's behavioral checks which don't analyze paste content at all. This second system is the opposite. It analyzes the paste content itself.
Mar 26 • 10 tweets • 3 min read
In macOS Tahoe 26.4 Apple added a new security feature to Terminal that warns users of potentially malicious pastes with a "Possible malware, Paste blocked" prompt. Here how it actually works 🧵
ClickFix attacks have surged over the years. The scam is simple: a fake website tells you to open Terminal and paste a command that installs malware. Apple's new feature blocks this, but not the way you'd expect.