Jul 2, 2026 · 32 min · 9 segments
``` Most security teams know Windows inside out, but not macOS. Beacon by Jamf Threat Labs hunts the Mac malware and attacker activity your team misses. In this episode of Jamf After Dark, hosts Kat…
Josh ThorntonHostKat GarbisHostFor those who haven't maybe listened to a prior episode or maybe don't even realize we have the Jamf Threat Labs, can you refresh on memory on the Jamf Threat Labs, what you're doing with the Threat Lab itself, your team, and kind of walk us through with a little overview of what it is and what you all do?
So in Threat Labs, we do really just a lot of monitoring of the threat landscape as well as kind of our own applied research into that threat landscape.
Our team wants to know what that malware does, who created it, why it works the way it does, what kind of trade secrets might it be holding on to in terms of its approach, right? And we'll, of course, be most interested in learning how to detect that malware in the future, to flag it, to block it, to ensure that, you know, if it ends up at any point, customers protected by Jamf that it's not going to be allowed to run.
And then outside of that, outside of that We do just a lot of our own research and presenting at different conferences when it comes to, again, particularly Apple devices of some sort, right? So we've spoken at various conferences, Black Hat, RSA, Objective by the Sea.
So we do a lot of research into where even vulnerabilities on the operating systems might exist and how we can help report those and solve some of those problems before attackers can even get to them, which is a good thing too.
I think my summary of all of that was we're professional hackers and we try to ethically break things.
But yeah, really, we're just doing some of the stuff that hackers do on a pretty regular basis, but we're being responsible with the findings, right?

Yeah, I think right now is such a pivotal time when it comes to vulnerabilities and attackers and the strategies that they're using because they have a lot more tools at their disposal for quickly finding them and exploiting them.

So that research and understanding of adversaries and their tactics has never been as important as it is today.

I guess, could you fill us in a little bit? What is the state of the landscape at the moment? And what are you seeing? Because I think we all often come to it knowing that our Apple devices, by and large, are a lot more secure than some of the alternatives out there.
Especially with, you know, the Mac OS platform continuing to grow and be adopted more as a platform used inside of the professional workplace, right? Like the more you have that occurring and the greater that market share grows, yeah, you're going to grow as a target as well, right? There's other factors that play into it as well.
And like you're saying, It's generally observed as a secure operating system overall, and that includes iOS, macOS, whatever.
But as you end up with more individuals holding on to good data on their systems, you're going to end up with more individuals that want access to that data.
So you're going to see more toolkits come out that are backdoors designed for Mac OS.
You're going to see more attempts and more social engineering campaigns that are geared specifically at that platform.
For those who haven't maybe listened to a prior episode or maybe don't even realize we have the Jamf Threat Labs, can you refresh on memory on the Jamf Threat Labs, what you're doing with the Threat Lab itself, your team, and kind of walk us through with a little overview of what it is and what you all do?
So in Threat Labs, we do really just a lot of monitoring of the threat landscape as well as kind of our own applied research into that threat landscape.
Our team wants to know what that malware does, who created it, why it works the way it does, what kind of trade secrets might it be holding on to in terms of its approach, right? And we'll, of course, be most interested in learning how to detect that malware in the future, to flag it, to block it, to ensure that, you know, if it ends up at any point, customers protected by Jamf that it's not going to be allowed to run.
And then outside of that, outside of that We do just a lot of our own research and presenting at different conferences when it comes to, again, particularly Apple devices of some sort, right? So we've spoken at various conferences, Black Hat, RSA, Objective by the Sea.
So we do a lot of research into where even vulnerabilities on the operating systems might exist and how we can help report those and solve some of those problems before attackers can even get to them, which is a good thing too.
I think my summary of all of that was we're professional hackers and we try to ethically break things.
But yeah, really, we're just doing some of the stuff that hackers do on a pretty regular basis, but we're being responsible with the findings, right?

Yeah, I think right now is such a pivotal time when it comes to vulnerabilities and attackers and the strategies that they're using because they have a lot more tools at their disposal for quickly finding them and exploiting them.

So that research and understanding of adversaries and their tactics has never been as important as it is today.

I guess, could you fill us in a little bit? What is the state of the landscape at the moment? And what are you seeing? Because I think we all often come to it knowing that our Apple devices, by and large, are a lot more secure than some of the alternatives out there.
Especially with, you know, the Mac OS platform continuing to grow and be adopted more as a platform used inside of the professional workplace, right? Like the more you have that occurring and the greater that market share grows, yeah, you're going to grow as a target as well, right? There's other factors that play into it as well.
And like you're saying, It's generally observed as a secure operating system overall, and that includes iOS, macOS, whatever.
But as you end up with more individuals holding on to good data on their systems, you're going to end up with more individuals that want access to that data.
So you're going to see more toolkits come out that are backdoors designed for Mac OS.
You're going to see more attempts and more social engineering campaigns that are geared specifically at that platform.
The rest of this transcript — segmented and speaker-labeled, so you land on the exact moment something was said
Search every transcript — by keyword, by phrase, or by meaning, across every show Radar indexes
Trends — what is surging across podcasts, measured against its own baseline
Alerts — when a name you follow appears in a newly indexed episode
No account is needed to search Radar.