'Shrootless' macOS Bug Could Bypass System Integrity Protection

Microsoft reported a macOS vulnerability it calls Shrootless. It could let an attacker bypass SIP and perform arbitrary operations on the device. It has been patched by Apple with the most recent Mac updates this week.

We found that the vulnerability lies in how Apple-signed packages with post-install scripts are installed. A malicious actor could create a specially crafted file that would hijack the installation process. After bypassing SIP’s restrictions, the attacker could then install a malicious kernel driver (rootkit), overwrite system files, or install persistent, undetectable malware, among others.

Twitter 'Super Follows' is Now Available for All iPhone Users

Super Follows is a new Twitter feature that lets creators make money through subscriptions. It has now rolled out to all iPhone users.

The feature launched in September after first being announced in February. Super Follows are another tool for creators to earn money through the social media platform. Eligible accounts are able to set the price for Super Follow subscriptions, with the option of charging $2.99, $4.99 or $9.99 per month. Creators can choose to mark some tweets for subscribers only while continuing to reach their unpaid follower base in regular tweets.