Apple has just released its regular update to XProtect, bringing it to version 5360, for all versions of macOS. Version 5359 doesn’t appear to have been released. As usual Apple doesn’t release information about what security issues this update might address.
This version adds six new Yara rules for MACOS.BONZAI.NCIMA, MACOS.LOATHESOMELABELMAKER.WHCO, MACOS.SHADYSHOELACE.AECRCOAR, MACOS.SHADYSHOELACE.LOADCO, MACOS.ANGRYORB.RUC2FO and MACOS.ANGRYORB.RUCOX8, and fixes whitespace in rules for MACOS.SHADYSHOELACE.OSLOSTA and MACOS.SHADYSHOELACE.LODLSYDEX8.
In the Osascript rules in XPScripts.yr it adds seven new rules for MACOS.OSASCRIPT.SHC2ST, MACOS.OSASCRIPT.SHLAMAA, MACOS.OSASCRIPT.SHCHEXHA, MACOS.OSASCRIPT.SHCOST, MACOS.OSASCRIPT.SHKEACRE, MACOS.ANGRYORB.JXDR and MACOS.OSASCRIPT.ANJXLO, amends MACOS.OSASCRIPT.SYPR, and fixes whitespace in MACOS.OSASCRIPT.DUEXKE.
In older versions of macOS you can check whether this update has been installed by opening System Information via About This Mac, and selecting the Installations item under Software.
A full listing of security data file versions is given by SilentKnight and SystHist for El Capitan to Golden Gate available from their product page. If your Mac hasn’t yet installed this update, you can force it using SilentKnight or at the command line.
If you want to install this as a named update in SilentKnight, its label is XProtectPlistConfigData_10_15-5360
Sequoia, Tahoe and Golden Gate systems only
This update has now been released for Sequoia and later via iCloud. If you want to check it manually, use the Terminal command
sudo xprotect check
then enter your admin password. If that returns version 5360 but your Mac still reports an older version is installed, you should be able to force the update using
sudo xprotect update
Overnight these commands have now started working again in macOS Sequoia 15.8, Tahoe 26.7 and Golden Gate 27.0, and should no longer return errors.
Updated 06:20 18 September 2026 with changes to xprotect commands.
