96 episoder
- Most security teams know Windows inside out, but not macOS. Beacon by Jamf Threat Labs hunts the Mac malware and attacker activity your team misses.
In this episode of Jamf After Dark, hosts Kat Garbis and Josh Thornton talk with Jaron Bradley, Director of Jamf Threat Labs, about the state of the macOS threat landscape in 2026, and a new service that brings dedicated Mac threat hunting to your environment. If you run a Mac fleet and your team's expertise is mostly Windows or Linux, this one's for you.
What You'll Learn:
- Why macOS is now a real target: info stealers, malicious search ads, and fake app installers
- How Jamf Threat Labs researches malware like GhostClaw and builds detections into Jamf Protect
- What Beacon is, how telemetry feeds the hunt, and why human analysts review every alert
- Why dedicated macOS expertise matters when Windows-first tools fall short on Mac
CHAPTERS:
0:00 Mac Threats and the Jamf After Dark Crew
1:21 Meet Jaron Bradley: From Incident Response to macOS Threat Hunting
4:15 What Is Jamf Threat Labs? Team, Research and Mission
6:51 The State of the macOS Threat Landscape
7:33 Why Mac Is a Growing Target: Info Stealers and Malicious Ads
9:24 How AI Is Changing Both Attack and Defense
11:40 Jamf Threat Labs Research: GhostClaw, Predator and the Aftermath Tool
13:57 Jamf Protect and MI:RIAM: Real-Time Mac and Mobile Detection
14:43 How Attackers Masquerade Malware on macOS (DPRK Tactics)
17:21 Introducing Beacon by Jamf Threat Labs: What It Is and How It Works
19:37 Why Beacon Exists: macOS Threat Hunting as a Service
25:05 What to Expect as a Beacon Customer: Alerts, Detections and Reports
28:00 Real-World Story: Catching APT Activity on a Mac Fleet
29:25 How to Get Started with Beacon
30:47 Wrap-Up and Credits
🔔 Subscribe for more Apple security content from Jamf:
Who This Video Is For:
- Endpoint security specialists and SecOps analysts responsible for macOS compliance and detection
- Security stakeholders and CISOs building or scaling a Mac security program
- IT and security teams whose strength is Windows or Linux but who now manage a growing Mac fleet
Resources Mentioned:
- Beacon by Jamf Threat Labs: jamf.com/blog/beacon-jamf-threat-labs-mac-threat-hunting-service/
- Jamf Threat Labs: jamf.com/threat-labs/
- Jamf Protect: jamf.com/products/jamf-protect/
- Jamf Threat Labs on GhostClaw/GhostLoader: jamf.com/blog/ghostclaw-ghostloader-malware-github-repositories-ai-workflows/
Jamf After Dark is a podcast from Jamf. Reach us at info@jamf.com with the subject line "attention to the podcast."
#macsecurity #endpointsecurity #applesecurity #threatdetection #siem #endpointprotection #threathunting #Jamf - Travis County's Senior Systems Engineer explains why his team migrated 1,900+ Apple devices back to Jamf after trying a competing MDM, and how Jamf tools caught phishing test emails before users ever saw them.
Billy Roberts manages endpoints for Travis County government in Austin, Texas, a hybrid environment with 6,900 Windows devices and nearly 2,000 Apple devices including iPhone, iPad, and Mac computers. In this episode of Jamf After Dark, Billy shares why they left Jamf, what went wrong with their previous MDM, and what brought them back. He also walks through how Jamf Trust quarantined phishing emails before users could even open them, and how Jamf Security Center's detailed app reports eliminated the manual research from their technology assessment program.
🎙️ Jamf After Dark, a podcast from Jamf introducing you to the people, products, and stories behind Apple device management and security. Hosted by Kat Garbis and Josh Thornton.
What You'll Learn:
Why Travis County chose Jamf over a UEM for Apple device management
How Jamf Pro responds to configuration changes instantly compared to hours on a competing MDM
How Jamf caught internal phishing test emails before users could see them
How Jamf Security Center's app reports cut their technology assessment timeline by a third
🔔 Subscribe for more device management content from Jamf
Resources:
MDM Migration Checklist https://www.jamf.com/blog/mdm-migration-checklist/
Jamf Pro https://www.jamf.com/products/jamf-pro/
Jamf Protect https://www.jamf.com/products/jamf-protect/ - One K12 school was blocking roughly 1,000 phishing attacks per day, and had no idea it was happening. EDU Buying season is here, and security, classroom tools, parent controls, and teacher adoption all need answers before a single device gets ordered.
Mat Pullen, Jamf's Product Marketing Director for Education and a former classroom teacher, joins hosts Kat Garbis and Josh Thornton for a frank conversation about what K12 schools are dealing with in 2026.
Subscribe for more Edtech content from Jamf:
*CHAPTERS:*
1:51 Meet Mat Pullen: Product Marketing Director for Education at Jamf
2:51 Jamf Nation Live EDU: What Schools Are Actually Asking About
4:22 Top K12 Challenges in 2026: Budget, Security and Screen Time
6:57 Why Schools Are Easy Targets for Cyber Attacks
8:10 Student Privacy vs. Surveillance: How Jamf Balances Both
10:03 Jamf Parent: Giving Families Control of School Devices at Home
12:42 Technology in the Classroom Is an Education Problem, Not an IT Problem
14:58 MacBook Neo for K12: What It Changes for Schools on a Budget
20:05 Jamf Safe Internet: Content Filtering and Network Threat Prevention
22:12 Limited Privacy and Time-Based Policies: New Features Explained
25:58 Jamf for K12: One Solution for IT, Security, Teachers and Parents
29:05 Jamf Teacher in Action
31:46 K12 Buying Season 2026: How to Think Beyond the Device
37:23 Here's What Most Schools Are Missing - Mobile device security is the biggest blind spot in most organizations, and most IT teams have no way to investigate when something goes wrong.
Chris Deane, Senior Sales Engineer for Jamf Security Products, and Harry Jenkins, Senior Sales Manager for Jamf Mobile Forensics, sit down with hosts Kat Garbis and Josh Thornton to talk through what actually happens when a mobile device gets attacked.
They cover the full picture: why MDM alone isn't security, how mobile threat defense stops most attacks but not all, and where Jamf Mobile Forensics comes in for the ones that slip through. Plus a deep dive into spyware — Pegasus (NSO Group), Predator (Intellexa), zero-click attacks, why journalists are targeted just as often as executives, and how Jamf Threat Labs builds detection rules for threats that have never been seen before.
CHAPTERS:
0:00 Mobile devices are the #1 security blind spot
1:50 Meet the guests: Chris Deane and Harry Jenkins, Jamf Security
2:56 What makes Mobile Security different from endpoint security?
5:08 MDM, Mobile Threat Defense, and Mobile Forensics: the three layers explained
7:18 Why Only 15% of mobile devices are properly secured
9:49 Personal vs. Work: why the blurred lines make mobile security hard to enforce
15:36 Incident Response: what happens when an employee says their phone was attacked?
17:43 What Mobile Forensics actually means, and what Jamf is not looking at
19:57 iOS vs. Android CVEs: 90-120 Apple patches vs. 600-900 Android in 12 Months
22:43 Spyware: What Predator and Pegasus actually do to your mobile device
25:37 Targeted malvertising and the shift from One-Click to Zero-Click Attacks
29:07 Who gets targeted: executives, journalists, and travelers in High-Risk countries
33:20 How Jamf Threat Labs detects unknown threats using behavioral analysis
36:43 AI Analysis in Jamf Mobile Forensics: deeper insights without Forensic skills
Subscribe for Apple device management and security insights
#MobileSecurity #Spyware #EndpointSecurity #mobileforensics #cybersecurity #Jamf - Okta's Dan Hefley (https://www.linkedin.com/in/dan-hefley), Senior Product
Manager for Device Access, explains how Platform SSO brings enterprise identity
to the Mac. From day-zero Setup Assistant enrollment in macOS 26 to device
bound SSO using secure enclave keys, Dan covers what IT teams need to know
about deploying Platform SSO with Okta and Jamf.
Dan shares his perspective as a former MDM admin turned identity product
manager, discusses how device bound SSO prevents session hijacking with
hardware-backed keys, and explains why the Shared Signals Framework between
Okta and Jamf creates layered security. Hosts Josh Thornton and Kat Garbis
explore what this means for organizations managing Apple fleets.
1:44 Meet Dan Hefley - Senior Product Manager at Okta
5:00 What Is Okta? Vendor-Neutral Identity Provider Overview
6:23 Why Identity and Device Security Go Hand in Hand
7:21 What Is Platform SSO? Native macOS Framework Defined
8:07 Evolution from Jamf Connect Basic to Platform SSO
9:15 Why Platform SSO Was
9:47 Platform SSO in Setup Assistant
10:08 Day-Zero Enrollment Flow - ABM to Jamf to Okta MFA
11:43 Solving Enrollment Friction with Separated Device and User Registration
12:18 Password Syncing Benefits
16:40 How Device Bound SSO Prevents Session Hijacking
17:53 Identity Threat Protection and Continuous Authentication
18:06 Shared Signals Framework - Okta and Jamf Working Together 20:40 Okta FastPass and Passwordless Authentication on Mac
21:20 Device Bound SSO Completes the Day-Zero Story
22:30 Getting Started - Requirements and Deployment Considerations
26:26 Okta's Platform SSO Roadmap and Future Direction
27:43 Key Takeaway - Identity and Device Teams Belong in the Same Room
RESOURCES:
- Mac Admins Slack - Platform SSO Channel: https://macadmins.slack.com
- IAMSE Blog - Okta Integration Guides: https://iamse.blog
- Jamf Learning Hub: https://learn.jamf.com/
- Jamf and Okta integrations: https://www.jamf.com/integrations/okta/
Subscribe for Apple device management and security insights
WHO THIS IS FOR:
IT administrators and security teams managing Mac fleets in enterprise
environments. Relevant if you're evaluating Platform SSO with Okta, migrating
from Jamf Connect Basic, or planning identity integration for zero-touch Mac
deployment.
#Okta #Jamf #macossecurity #AppleSecurity #DeviceBoundSSO #macOS
#IdentityManagement #PlatformSSO #ZeroTouchDeployment #JamfAfterDark
#EnterpriseSecurity #MacAdmin #TrustedAccess #podcast
Flere Forretning podcasts
Trendige Forretning podcasts
Om Jamf After Dark
Device management is complex. Security threats are constant. Apple ecosystems are evolving fast. Who's managing these challenges? What does it actually take? And most importantly, how do you stay ahead? Welcome to Jamf After Dark, where IT leaders, security professionals and Apple experts tackle the real issues facing organisations today. Join our hosts as they uncover what works, what doesn't, and how to build technology strategies that actually stick. Hear honest conversations about managing devices at scale, securing endpoints, protecting data, and supporting hybrid workforces. New Jamf features and capabilities. Real stories from IT teams solving actual problems. For IT Admins, Mac admins,directors, security specialists, educators and Apple advocates.
Podcast-webstedLyt til Jamf After Dark, Børssnak og mange andre podcasts fra hele verden med radio.dk-appen

Hent den gratis radio.dk-app
- Bogmærke stationer og podcasts
- Stream via Wi-Fi eller Bluetooth
- Understøtter Carplay & Android Auto
- Mange andre app-funktioner
Hent den gratis radio.dk-app
- Bogmærke stationer og podcasts
- Stream via Wi-Fi eller Bluetooth
- Understøtter Carplay & Android Auto
- Mange andre app-funktioner


Jamf After Dark
Scan koden,
download appen,
begynd at lytte.
download appen,
begynd at lytte.

