article thumbnail

Apple accidentally approved malware disguised as Flash, new report finds

The Verge

Apple accidentally approved common malware disguised as an update for Adobe Flash Player to run on macOS, according to a new report. According to security researcher Patrick Wardle, Apple approved an app that contained code used by a well-known malware called Shlayer. Apple announced the macOS notarizing process in 2019.

Malware 132
article thumbnail

Malware-packed Chinese apps found on Mac App Store

TechSpot

Researcher Privacy 1st (Alex Kleber) analyzed seven different Apple developer accounts, all managed by the same Chinese dev. They note that the apps abuse the Mac App Store in several ways, the most common being that they contain hidden malware able to receive commands from a server (command-and-control). This allows.

Malware 145
Insiders

Sign Up for our Newsletter

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

article thumbnail

Judge says Apple may be ‘stretching the truth’ on Mac malware concerns

The Verge

During the Apple v. Epic trial, Apple software leader Craig Federighi argued that tight control over the App Store was necessary for securing the iPhone. Federighi’s Mac malware opinions may appear plausible, they appear to have emerged for the first time at trial which suggests he is stretching the truth for the sake of the argument.

Malware 68
article thumbnail

iOS Malware Spoofs Shutdown to Avoid Removal

SecureWorld News

Researchers from security firm ZecOps recently developed a trojan proof of concept (PoC) tool that can fake a shutdown on iPhones, allowing malware to secretly continue living on the device. If malware stays on the device, threat actors can utilize microphones and receive sensitive data via a live network connection.

Malware 78
article thumbnail

Stealthy Mac malware spies on encrypted browser traffic

Network World

A new malware program that targets macOS users is capable of spying on encrypted browser traffic to steal sensitive information. The malware was attached to the email as a file called Dokument.zip. What makes OSX/Dok interesting is that it was digitally signed with a valid Apple developer certificate.

Malware 96
article thumbnail

Apple responds to privacy concerns over Mac software security process

The Verge

Last week, a number of Mac users had trouble opening apps — a problem that seemed to be caused by an Apple security protocol responsible for checking that software comes from trusted sources. It goes on to clarify how Apple currently uses the data, and outlines new safeguards that are being introduced over the next year.

Apple 136
article thumbnail

Apple Unveils 'Lockdown Mode' to Defend Against Spyware

SecureWorld News

Apple announced plans to launch a new security feature called "Lockdown Mode" that will be available this fall when Apple releases its annual iOS update. The NSO Group, and others, are helping cybercriminals and nation-states accomplish this, but Apple has a plan to defend against these attacks.

Spyware 84