Patrick Wardle is the Cofounder of the Objective-See Foundation, the CEO/Cofounder of DoubleYou, and the author of The Art of Mac Malware book series. Having worked at NASA and the NSA, as well as presenting at countless security conferences, he is intimately familiar with aliens, spies, and talking nerdy.
Passionate about macOS security, Patrick spends his days discovering Apple 0-days, studying macOS malware, and releasing free open-source security tools to protect Mac users.
- AppSec teams, your backlog is growing faster than you can fix it. SAST and DAST tools are flooding you with findings, developers are pushing back, and prioritizing what actually matters in code is getting harder.So how do you reduce risk without slowing releases?Join the Vulnerability Management Virtual Cybersecurity Summit to learn how teams are prioritizing real exploitable issues, reducing noise, and integrating remediation into modern development workflows.Security Weekly listeners can register for free at https://securityweekly.com/vulnmanagement using the promo code: CSS26-SW
- CyberRisk TV is proud to be an official media partner of Black Hat USA 2026! We'll be broadcasting live from the Black Hat LIVEWIRE Studio, where application security innovators can showcase the technologies, research, and strategies shaping the future of secure software development.Our Executive Interviews and Event Momentum Packages help you stay in front of developers and AppSec teams long after Black Hat ends. Fewer than 10 interview opportunities remain, so visit https://securityweekly.com/exec today and reserve your spot before they're gone.
Mike Shema
- Reverse Engineering A Commercial AI Cheat: How AI Agents Changed The Way We Work (Part 1)
- Cursor 0day: When Full Disclosure Becomes the Only Protection Left – Mindgard
- VulnHunter: an open-source, agentic AI code security tool | Capital One Tech
Check out the vulnhunter repo.
- My First Month as AI Security Engineer in Residence at the Rust Foundation
This article is relatively brief. It doesn't go into technical detail about Rust-specific security concerns nor technical details about the security scanning. And those aren't the key points anyway.
It's a story that's likely very familiar and very relevant for all the SMBs out there dealing with application security challenges from supply chain to agent-based vuln discovery. It just happens to be about Rust and AI adoption.
The key points in the article are about starting with something simple, in this case the Scrutineer tool, working with the tool's maintainers to improve its reliability and coverage, then working with the project owners impacted by the tool's findings.
It reads like a nascent appsec team trying to figure out where to have the most impact and how to build a collaborative relationship with all of its partners.
- Rustifying Image Codecs in Chromium | Microsoft Browser Vulnerability Research
If you're diving into more Rust development, Trail of Bits have updated their Testing Handbook with a new chapter on Rust security.
John Kinsella
- Build your own vulnerability harness
We've mentioned harnesses a bunch in the last six months - but what exactly is one? Can you grab an open source "harness" project, or do you have to create one from scratch? Cloudflare has a good blog post showing how they built theirs.
- Secure boot shimms have been broken for a decade
ESET finds a collection of 11 secure boot shims that had vulnerabilities, but Microsoft never revoked their certificates - until the July Patch Tuesday. (h/t Ars Technica)







