Jump to content

Apple Confirms Cyber Attack, Releases Java Update And Malware Removal Tool


Recommended Posts

Posted

Apple confirms cyber attack, releases Java update and malware removal tool

The words “Apple” and “security breach” don’t often appear together, but on Tuesday the company said that some computers belonging to its employees had been targeted by hackers originating from China—the same group, reportedly, that last week infiltrated computers belonging to Facebook employees. The story was first reported by Reuters.

In an email, Apple provided Macworld with a statement on the breach, saying:

Apple has identified malware which infected a limited number of Mac systems through a vulnerability in the Java plug-in for browsers. The malware was employed in an attack against Apple and other companies, and was spread through a website for software developers. We identified a small number of systems within Apple that were infected and isolated them from our network. There is no evidence that any data left Apple. We are working closely with law enforcement to find the source of the malware.

Since OS X Lion, Macs have shipped without Java installed, and as an added security measure OS X automatically disables Java if it has been unused for 35 days. To protect Mac users that have installed Java, today we are releasing an updated Java malware removal tool that will check Mac systems and remove this malware if found.

True to its word, Apple released a Java update late on Tuesday for Mac OS X 10.7 or later that patches a number of security vulnerabilities as well as scanning for the most common variants of the malware in question and removing them. If malware is found, the user will be notified of its removal.

The patch also updates Apple’s provided version of Java to 1.6.0_41; the update is available by choosing Software Update from the Apple menu or visiting the Mac App Store and clicking on Updates. Snow Leopard users can check Software Update or download Java for Mac OS X 10.6 Update 13, which patches the same vulnerability.

In line with the company’s recent policy on Java, these downloads will disable Apple’s built-in Java plugin; users who try to run applets in their browser will instead be prompted to download the latest version of the Java plug-in from Oracle. One additional casualty this time around, for 10.7 and later, is the Java Preferences app that usually lives in OS X’s Utilities folder—Apple says it’s no longer necessary for configuration.

Apple is only the latest target in a recent spate of cyber attacks that have hit institutions like the New York Times and the Wall Street Journal along with tech companies like Facebook and Twitter; most of those attacks have been traced back to China. The attack on Facebook, in particular, appears to have been committed via the same Java vulnerability as the Apple breach.

Historically, Macs have not been a popular target for security attacks of this sort, though the ecosystem has battled a few outbreaks of malware over the past few years. However, it seems likely—given the pattern of recent attacks—that the target was Apple itself, rather than its platform at large.

Updated at 2:23 p.m. PT with information about the Java update and malware removal tool.

Source: http://www.macworld....tml#tk.nl_macwk

-- macworld.com

  • Like 1
Posted

Thank you Webfact, I just looked and I am now updating Java, yet again... Funny we never had a problem with Java back before Larry Ellison bought the company!

  • Like 1
Posted

Java, Flash, and other plug-ins are just the lowest hanging fruit, once these are fixed they'll switch over to other technologies, probably QuickTime and lastly JS and the rendering engine, etc.

It's harder to break into Macs vs Windows but if somebody wants to do a targeted attack they will find a way in. Or a thousand. There's probably a limitless number of zero day exploits waiting to be discovered.

These hackers target macs because their goal is not to have as many infected machines as possible but rather to break into specific companies and steal IP. They seem to have a whole program set up to break into all the Fortune 500 companies etc....

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
  • Recently Browsing   0 members

    • No registered users viewing this page.



×
×
  • Create New...