
Apple Security Updates Address Core Graphics Vulnerability and Other Security Threats
Apple released security updates on September 29th for its operating systems, with only the last generation receiving actual security fixes. The updates patch a Core Graphics vulnerability currently being exploited in the wild, discovered by Meta's product security team, affecting iOS 26, macOS 26, and macOS 15. A proof of concept was published for a local privilege escalation vulnerability in macOS Core Services that was patched weeks earlier. Microsoft published a write-up on Nedi Mantis, a command and control tool linked to the Demon Tools supply chain compromise group, which uses legitimate DLLs from tools like TightVNC and curl, employs web sockets for data exfiltration, and loads additional modules as needed. Researchers from Graz University of Technology in Austria published findings on file notification systems in Windows, Linux, and macOS, demonstrating that attackers can receive notifications for files they cannot read if they know the filename, potentially enabling side-channel attacks to detect keystroke rhythms in editor files.