A background scanner that sweeps Macs for known malware has been retuned to watch the way programs reach for location data, screen contents, audio hardware and input devices, the behaviors spyware needs in order to work.
XProtect Remediator is the half of Apple’s Mac defenses that runs on a daily schedule, and it has moved to build 163. Machines from Catalina onward sat on 157, while Golden Gate had already advanced to 159. Nothing in the revision is explained.
The rule list grows while the scan modules stay put
The roster of scanning modules itself is untouched. What shifted sits in the Bastion rule set, which gains entries numbered 25 to 29: runs of screencapture, input monitoring through IOHIDLibUserClient, the cmio registerassistantservice, and the audiohald and replayd daemons each now draw an immediate report, with CoreLocation access folded in alongside. Signal and Keybase join Rule 2 coverage in the same pass.
Rules written against behavior rather than a sample fire on any process that reaches for the same resources, so the additions point at capabilities stalkerware and infostealers rely on instead of one named family. Apple ships no advisory with these payloads, leaving rule names as the only public trace of what its analysts chase.
Checking a Mac for the new version
The installed build appears in System Information, under the Installations item in the Software pane. SilentKnight and SystHist report security data versions from El Capitan through Golden Gate.
The refresh lands in a busy week for the same security data. The signature list moved to 5360 on September 17, and Macs on Sequoia or later can pick that file up through iCloud instead of Software Update, so a settings pane may show nothing while the rules underneath are current.