<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/an-apple-malware-flagging-tool-is-trivially-easy-to-bypass-nimmcvr6d" -->

---
title: An Apple malware-flagging tool is “trivially” easy to bypass
description: An Apple malware-flagging tool is “trivially” easy to bypass, says Patrick Wardle. Wardle presented findings on Saturday at Defcon hacker conference in Las...
canonical: https://daily.dev/posts/an-apple-malware-flagging-tool-is-trivially-easy-to-bypass-nimmcvr6d
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: An Apple malware-flagging tool is “trivially” easy to bypass | daily.dev
og:description: An Apple malware-flagging tool is “trivially” easy to bypass, says Patrick Wardle. Wardle presented findings on Saturday at Defcon hacker conference in Las...
og:url: https://daily.dev/posts/an-apple-malware-flagging-tool-is-trivially-easy-to-bypass-nimmcvr6d
og:image: https://api.daily.dev/og/posts/nImMCvr6D.png
og:image:alt: An Apple malware-flagging tool is “trivially” easy to bypass
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# An Apple malware-flagging tool is “trivially” easy to bypass

**[Ars Technica](https://daily.dev/sources/arstechnica)** · 4 min read · 0 upvotes · 0 comments

## Summary

An Apple malware-flagging tool is “trivially” easy to bypass, says Patrick Wardle. Wardle presented findings on Saturday at Defcon hacker conference in Las Vegas. He found two paths that don't require root access to disable the persistence notifications Background Task Manager is supposed to send to the user and to security monitoring products.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://arstechnica.com/?p=1960742>

## Similar posts on daily.dev

- [Don’t just attend KubeCon \+ CloudNativeCon, Merge Forward your experience\!](https://daily.dev/posts/don-t-just-attend-kubecon-cloudnativecon-merge-forward-your-experience--l0rpp73x8) · CNCF · 1 upvotes · 0 comments
- [Announcing H2 2026 KCDs](https://daily.dev/posts/announcing-h2-2026-kcds-m96goajm1) · CNCF · 1 upvotes · 0 comments
- [Two months of Open Community Groups](https://daily.dev/posts/two-months-of-open-community-groups-asf52zhbs) · CNCF · 0 upvotes · 0 comments

---

Tags: [#apple](https://daily.dev/tags/apple), [#defcon](https://daily.dev/tags/defcon), [#mac](https://daily.dev/tags/mac), [#malware](https://daily.dev/tags/malware), [#monitoring](https://daily.dev/tags/monitoring), [#security](https://daily.dev/tags/security), [#tools](https://daily.dev/tags/tools)

[View this post on daily.dev](https://daily.dev/posts/an-apple-malware-flagging-tool-is-trivially-easy-to-bypass-nimmcvr6d)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"An Apple malware-flagging tool is “trivially” easy to bypass","url":"https://daily.dev/posts/an-apple-malware-flagging-tool-is-trivially-easy-to-bypass-nimmcvr6d","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/an-apple-malware-flagging-tool-is-trivially-easy-to-bypass-nimmcvr6d"},"datePublished":"2023-08-14T19:46:33.543Z","dateModified":"2025-09-06T02:51:48.511Z","description":"An Apple malware-flagging tool is “trivially” easy to bypass, says Patrick Wardle. Wardle presented findings on Saturday at Defcon hacker conference in Las...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/e603070522a2235fa4787f61c907aab9?_a=AQAEufR","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/e603070522a2235fa4787f61c907aab9?_a=AQAEufR","isAccessibleForFree":true,"articleSection":"Ars Technica","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"Ars Technica","logo":"https://media.daily.dev/image/upload/t_logo,f_auto/v1/logos/80883e0e48a34b5ebcf93777016cb3fe","url":"https://daily.dev/sources/arstechnica"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/an-apple-malware-flagging-tool-is-trivially-easy-to-bypass-nimmcvr6d","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":0},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"apple,defcon,mac,malware,monitoring,security,tools","timeRequired":"PT4M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"Ars Technica","item":"https://daily.dev/sources/arstechnica"},{"@type":"ListItem","position":3,"name":"An Apple malware-flagging tool is “trivially” easy to bypass"}]}
```

