Home
News
Tech Grid
Interviews
Anecdotes
Think Stack
Press Releases
Articles
  • Home
  • /
  • News
  • /
  • AI
  • /
  • AI Cloud
  • /
  • XM Cyber Unveils Open-Source Exposure Hunting Tools for macOS and Oracle Cloud
  • AI Cloud

XM Cyber Unveils Open-Source Exposure Hunting Tools for macOS and Oracle Cloud


XM Cyber Unveils Open-Source Exposure Hunting Tools for macOS and Oracle Cloud
  • by: GlobeNewswire
  • |
  • August 3, 2026

XM Cyber, a leader in Continuous Exposure Management, has announced new open-source exposure hunting tools designed to help security teams uncover and validate complex attack paths across macOS endpoints and Oracle Cloud Infrastructure (OCI). The tools automate technical research that often requires extensive manual reverse engineering.

Quick Intel

  • XM Cyber released FAInd my XPC, an open-source tool that automates discovery and validation of privileged XPC service vulnerabilities on macOS.

  • The company also released Offensive OCI, a toolset that analyzes Oracle Cloud IAM policies to expose overprivileged identities and potential privilege escalation paths.

  • FAInd my XPC uses AI-assisted reverse engineering to recover exposed methods, protocols, and connection requirements.

  • Offensive OCI includes pOliCI for parsing OCI policies and a CLI Signing Helper for offensive testing of instance principal authentication.

  • FAInd my XPC will be demonstrated at Black Hat Arsenal (August 5, 11:20 a.m. PT).

  • Offensive OCI tooling will be presented at DEF CON 34, Cloud Village (August 8, 4:00 p.m. PT).

XM Cyber Unveils Open-Source Exposure Hunting Tools for macOS and Oracle Cloud

XM Cyber, a leader in Continuous Exposure Management, today announced new open-source exposure hunting tools designed to help security teams uncover and validate complex attack paths across macOS endpoints and Oracle Cloud Infrastructure (OCI). The tools automate technical research that often requires extensive manual reverse engineering.

Senior Security Researcher Perspective

"Some of the most consequential exposures cannot be found by reviewing a configuration or running a conventional vulnerability scan. Researchers have to examine how trust, identity and privilege truly behave when an attacker begins connecting the pieces," said Hillel Pinto, Senior Security Researcher at XM Cyber. "We created these tools to make that deep, adversarial analysis more accessible and repeatable, giving defenders a practical way to investigate complex attack paths without starting from scratch each time."

FAInd my XPC at Black Hat USA

Many macOS applications use privileged XPC services that authorize callers based primarily on the code-signing identity of trusted software. XM Cyber researchers demonstrated that this trust model can be bypassed from an unprivileged account, allowing attacker-controlled code to inherit a trusted application's identity and potentially invoke privileged methods without further authentication.

XM Cyber's open-source tool, FAInd my XPC, automates the discovery and validation of this vulnerability class. The framework identifies injectable applications and reachable privileged services, then uses AI-assisted reverse engineering to recover exposed methods, protocols and connection requirements. It issues a real privileged call and verifies the resulting system evidence, helping defenders distinguish theoretical weaknesses from demonstrated exposures such as root code execution.

The tool will be demonstrated at Black Hat Arsenal (Arsenal station 4, Business Hall) on Wednesday, August 5th at 11:20 a.m. PT. Attendees are also encouraged to stop by booth #5147 to meet the team behind the innovation.

Offensive OCI Tooling at DEF CON 34

Oracle Cloud Infrastructure IAM combines policy statements, compartment hierarchies, dynamic groups and resource principals, making it difficult to determine what an identity can actually access or control. These relationships can create privilege escalation paths that are not apparent from reviewing individual policies or permissions in isolation.

XM Cyber's new Offensive OCI open-source toolset helps security teams analyze those paths from an attacker's perspective. pOliCI parses OCI policies and calculates effective permissions for each principal, exposing overprivileged identities and potential post-compromise actions. The accompanying CLI Signing Helper extends the OCI command-line interface to support offensive testing of instance principal authentication, including exploitation attempts launched from outside the associated instance.

XM Cyber will provide a full technical breakdown of its Offensive OCI Tooling at DEF CON 34, in Zone A room 312, on August 8th at 4:00 p.m. PT.

Security teams, researchers and application vendors interested in trying FAInd my XPC and XM Cyber's Offensive OCI toolset can join the waitlist to receive availability updates and access information ahead of the tools' launch.

About XM Cyber

XM Cyber is a pioneer in exposure management, transforming how organizations approach cyber risk by continuously validating their hybrid attack surface against real-world threats. By modeling how attackers combine misconfigurations, vulnerabilities, identity exposures, AI exposures, and more across cloud and on-premises environments, XM Cyber shows enterprises every path an attacker might take, and the most effective ways to block them. This enables security leaders to communicate risk effectively and prove security ROI with confident, data-driven reporting.

  • Exposure HuntingOracle CloudBlack Hat
News Disclaimer
  • Share