Attackers Exploit macOS Weaknesses, CI/CD Flaws, and Ransomware in Latest Wave of Cyber Incidents
A wave of cybersecurity incidents includes a macOS attack that disables EDR agents, a new CI/CD weakness class called Cordyceps affecting 300+ repos, a KDDI breach exposing 14.2M email credentials, and a ransomware attack on Bajaj Auto.
Cybersecurity researchers disclosed a series of vulnerabilities and attacks this week, including a macOS technique that allows non-admin users to silently disable endpoint detection and response tools, a new class of CI/CD weakness affecting major tech companies, a ransomware incident at Indian auto manufacturer Bajaj Auto, and a breach at Japanese telecom KDDI that exposed millions of email credentials.
The macOS attack, detailed by XM Cyber and reported by SecurityWeek, uses legitimate OS behavior rather than software flaws to unload endpoint security agents. A standard non-admin account can exploit the code-signing trust cache to inject a malicious payload that impersonates a trusted app component, then invoke privileged XPC methods. The technique was successfully demonstrated against CrowdStrike Falcon Sensor and Kandji MDM.
MacOS Attack Targets EDR and MDM Agents
XM Cyber researcher Hillel Pinto showed that the attack chain can permanently disable endpoint security without triggering alerts. CrowdStrike paid a bug bounty and added detection for the technique. Kandji patched the issue and assigned CVE-2026-39118. A third unnamed enterprise EDR vendor is still working on a patch. Pinto plans to release an open-source discovery tool called XPC Hunter at Black Hat US in August 2026. Apple has not yet commented.
- CrowdStrike Falcon Sensor fully unloaded from a standard user account.
- Kandji MDM permanently deactivated via two-stage chain that cleared EDR guards.
- Attack exploits the kernel's code-signing trust cache persistence after a signed app executes.
- XPC Hunter will automate identification of exploitable XPC privilege escalation surfaces across macOS applications.
CI/CD Weaknesses and Ransomware Strike
Separately, researchers at Novee Security flagged a critical CI/CD workflow pattern named Cordyceps that affects over 300 GitHub repositories at organizations including Microsoft, Google, and Apache. The weakness allows attackers to hijack workflows and compromise open-source supply chains. In the same week, Indian auto giant Bajaj Auto reported a ransomware incident on Tuesday, taking precautionary measures to contain its impact. Japanese telecom KDDI disclosed a breach affecting six internet service providers that exposed 14.2 million email credentials; customers were advised to change passwords immediately. Critical vulnerabilities in Ubiquiti devices are also being actively targeted by attackers, allowing remote command injection and system changes.
The convergence of these incidents underscores persistent gaps in endpoint defense, supply chain security, and third-party risk management. As researchers release tools to find similar macOS weaknesses, enterprises should expect increased scrutiny of XPC interfaces and code-signing trust mechanisms. For CI/CD pipelines, the Cordyceps pattern adds to a growing catalog of exploitable workflow flaws that require immediate remediation.
Fact check
-
A standard non-admin macOS account can silently disable endpoint security tools like CrowdStrike Falcon Sensor using an attack that exploits the kernel's code-signing trust cache.
verified · source
-
Novee Security identified a CI/CD weakness codenamed Cordyceps affecting over 300 GitHub repositories at Microsoft, Google, and Apache.
verified · source
-
Indian auto manufacturer Bajaj Auto experienced a ransomware incident and took precautionary measures.
verified · source
-
KDDI breach affected six Japanese ISPs and exposed 14.2 million email credentials.
verified · source
-
Critical Ubiquiti vulnerabilities allow remote, unauthenticated attackers to execute commands and make system changes.
verified · source
Source reporting (9)
- SecurityWeek · macOS Weaknesses Chained to Silently Disable Endpoint Security Agents
- The Record by Recorded Future · Indian auto giant Bajaj Auto hit by ransomware incident
- The Hacker News · Cordyceps CI/CD Flaws Expose 300+ GitHub Repositories to Supply-Chain Attacks
- Infosecurity Magazine · KDDI Breach Affects Six Japanese ISPs, Exposes 14.2 Email Credentials
- SecurityWeek · Critical Ubiquiti Vulnerabilities in Attackers’ Crosshairs
- Help Net Security · Phishing attack on healthcare firm Xsolis impacts 1.4 million people
- TechRadar Pro · 87% of cybersecurity managers say quick compliance programs are actually increasing risk and making businesses less resilient
- TechRadar Pro · 'Organised crime operating like a tech startup': EvilToken PHaaS group ramp up AI-enabled attacks by 1,380% in 2026
- CyberScoop · In a first, a court takedown goes after two cybercrime tools at once
Join the conversation
You need to be registered and logged in to comment on blog articles.
Related Articles
LastPass, BeyondTrust, and Others Confirm Data Theft in Klue-Salesforce Supply Chain Attack
Jun 24, 2026
New tools emerge to govern AI-generated code and detect bot traffic as enterprise adoption accelerates
Jun 24, 2026
Four Cyber Incidents Hit Global Systems: Tata Breach, Samsung Flaw, Brazil Alert Hack, FortiBleed Campaign
Jun 24, 2026
0 Comments
No comments yet
Be the first to share your thoughts on this article.