A malware signature list that every Mac consults before opening a file has taken one of its largest single-step additions in months.
Build 5362 replaces 5360, which shipped on 18 September. The new list has reached machines through iCloud alone, and only on macOS Sequoia and later. Apple never says what a signature refresh is designed to stop, so the contents have to be reconstructed by comparing the versioned data files. Six of the incoming entries sit under the MACOS.CONFUSEDCABAL heading, the largest group in the batch; three extend the MACOS.SHADYSHOELACE line; and singles cover MACOS.BRUSQUEBARNACLE.AEZLPAST, MACOS.REGRESSIVESALMON.B6OSST, MACOS.BOATLOAD.GAPRDO, the MACOS.ANGRYORB variants KECO and LOITHE, and MACOS.ADLOAD.FOST. Fifteen in all, with MACOS.ADLOAD.FMT retired and ShadyShoelace and AngryOrb entries rewritten.
Script checks move too
The script-level side saw its own churn. XPScripts.yr, which governs AppleScript droppers, picked up checks for MACOS.OSASCRIPT.COTA, RELABYSH, REETRE, COIMA, COLOA and SYPR, and one older entry, MACOS.OSASCRIPT.SHLAMAA, was amended.
Owners can confirm the installed build by running sudo xprotect check in Terminal and reading the version string it returns; the data files behind it are catalogued by third-party utilities covering every macOS from El Capitan onward.