Iru A.I CyberSecurity Scoring
Iru
Company Information
Website:http://iru.com
Employees number:388
Number of followers:33,820
NAICS:5112
Industry Type:Software Development
Homepage:iru.com
Iru Risk Score (AI oriented)
Between 700 and 749
IruSoftware Development
Updated:
24/06/2026
24/06/2026
742/1000
Moderate
Ba
Iru Global Score (TPRM)
xxxx
IruSoftware Development
Score locked

IruModerate
Current Score
742Ba (MODERATE)
01000
1 incidents
0 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
AUGUST 2026
743
JULY 2026
743
JUNE 2026
742
MAY 2026
742
APRIL 2026
742
MARCH 2026
741
FEBRUARY 2026
741
JANUARY 2026
740
DECEMBER 2025
740
NOVEMBER 2025
739
OCTOBER 2025
739
SEPTEMBER 2025
738
AUGUST 2025
755
Cyber Attack
01 Aug 2025 • Iru
Kandji and CrowdStrike: macOS Weaknesses Chained to Silently Disable Endpoint Security Agents
macOS Attack Technique Silently Disables EDR and MDM Tools Without Admin Privileges
737
CRITICAL-18
CROOFF1782312102
macOS Attack Technique Silently Disables EDR and MDM Tools Without Admin Privileges
Cybersecurity firm XM Cyber has uncovered a novel macOS attack method that allows a standard, non-administrative user to disable enterprise endpoint security tools including EDR and MDM agents without triggering alerts or requiring kernel exploits. The technique leverages legitimate macOS behaviors rather than software vulnerabilities, making detection difficult.
The attack exploits weakly validated XPC connections and the injection of malicious payloads into application Interface Builder (NIB) files, techniques previously documented but never chained in this way. A key component involves abusing the persistence of the kernel’s code-signing trust cache after a signed application executes, enabling attackers to impersonate trusted app components and invoke privileged XPC methods undetected.
XM Cyber demonstrated the technique against CrowdStrike Falcon Sensor, which was fully unloaded from a standard user account, and Kandji MDM, which was permanently deactivated via a two-stage exploit that cleared EDR protections and terminated the Endpoint Security Framework extension. A third, unnamed enterprise EDR vendor was also successfully targeted and is working on a patch.
Vendor Responses:
- CrowdStrike paid a bug bounty and implemented detection measures.
- Kandji patched the flaw and assigned CVE-2026-39118.
- Apple has not yet publicly commented.
Researcher Hillel Pinto will release an open-source tool, XPC Hunter, to automate the detection of exploitable XPC privilege escalation surfaces across macOS applications. A full presentation is scheduled for Black Hat US in August 2026. The findings highlight persistent risks in macOS security, even as Apple continues to address legacy attack vectors.
INCIDENT DETAILS -
TYPE
IMPACT
REFERENCES
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for Iru ??
What was Iru's A.I Rankiteo Cyber Score in July 2026 ??
What was Iru's A.I Rankiteo Cyber Score in June 2026 ??
What was Iru's A.I Rankiteo Cyber Score in May 2026 ??
What was Iru's A.I Rankiteo Cyber Score in April 2026 ??
What was Iru's A.I Rankiteo Cyber Score in March 2026 ??
What was Iru's A.I Rankiteo Cyber Score in February 2026 ??
What was Iru's A.I Rankiteo Cyber Score in January 2026 ??
What was Iru's A.I Rankiteo Cyber Score in December 2025 ??
What was Iru's A.I Rankiteo Cyber Score in November 2025 ??
What was Iru's A.I Rankiteo Cyber Score in October 2025 ??
What was Iru's A.I Rankiteo Cyber Score in September 2025 ??
What is the average per-incident point impact on Iru's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with Iru ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view Iru's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?