Many macOS computer users are still confident that their machines do not need protection. Worse, system administrators at companies where employees work on Apple hardware often hold the same opinion. At the Black Hat USA 2020 conference, researcher Patrick Wardle tried to disabuse the audience of this misconception by presenting his analysis of malware for macOS and building an … [Read more...] about Attacking macOS using a Microsoft Office macro
macOS
4 Tips to Protect your macOS Environments
Over the past year, CrowdStrike® Services has observed threat actors increasingly targeting macOS environments — and using relatively unsophisticated methods to gain access. Even though workplace macOS systems have become increasingly popular, organizations often lack adequate macOS endpoint monitoring and management capabilities, compared to their Windows systems — making Macs … [Read more...] about 4 Tips to Protect your macOS Environments
A New Ransomware Targeting Apple macOS Users Through Pirated Apps
Cybersecurity researchers this week discovered a new type of ransomware targeting macOS users that spreads via pirated apps.According to several independent reports from K7 Lab malware researcher Dinesh Devadoss, Patrick Wardle, and Malwarebytes, the ransomware variant — dubbed "EvilQuest" — is packaged along with legitimate apps, which upon installation, disguises itself as … [Read more...] about A New Ransomware Targeting Apple macOS Users Through Pirated Apps
New Privacy Features Added to the Upcoming Apple iOS 14 and macOS Big Sur
Unprecedented times call for unprecedented measures.No, we're not talking about 'coronavirus,' the current global pandemic because of which Apple—for the very first time in history—organized its Worldwide Developer Conference (WWDC) virtually.Here we're talking about a world in which we are all connected and constantly sharing data, also known as the new oil, with something … [Read more...] about New Privacy Features Added to the Upcoming Apple iOS 14 and macOS Big Sur
New Bundlore adware targets macOS with updated Safari extensions
Browser add-ons are a common source of privacy and security concerns. While they are usually legitimate software products with real companies behind them, these plug-ins can also be used by unscrupulous software developers as a way to turn downloads of free software into a revenue stream–dropping browser add-ons that gather information from the user, inject … [Read more...] about New Bundlore adware targets macOS with updated Safari extensions
7-Year-Old Critical RCE Flaw Found in Popular iTerm2 macOS Terminal App
A 7-year-old critical remote code execution vulnerability has been discovered in iTerm2 macOS terminal emulator app—one of the most popular open source replacements for Mac's built-in terminal app.Tracked as CVE-2019-9535, the vulnerability in iTerm2 was discovered as part of an independent security audit funded by the Mozilla Open Source Support Program (MOSS) and conducted by … [Read more...] about 7-Year-Old Critical RCE Flaw Found in Popular iTerm2 macOS Terminal App
Reconstructing Command-Line Activity on MacOS
In Mac OSX Lion (10.7), Apple introduced a feature called “User Interface (UI) Preservation”, intended to save the state of application windows and restore them upon future launches. Like many features intended to enhance the user experience, UI Preservation can also provide immense forensic value to an investigator. In the case of anti-forensic measures taken by an adversary, … [Read more...] about Reconstructing Command-Line Activity on MacOS
FinSpy is spyware for Android, iOS, Windows, and macOS
What happens when spyware is developed not by underground malware coders, but by a serious IT firm? The result can be a nasty thing like FinSpy (also known as FinFisher), which has been developed and sold perfectly legally for quite some time now. Over the past year, we’ve detected this spyware on dozens of mobile devices. What FinSpy gets up to Although a desktop version of … [Read more...] about FinSpy is spyware for Android, iOS, Windows, and macOS
Zoom Video Conferencing for macOS Also Vulnerable to Critical RCE Flaw
The chaos and panic that the disclosure of privacy vulnerability in the highly popular and widely-used Zoom video conferencing software created earlier this week is not over yet.As suspected, it turns out that the core issue—a locally installed web server by the software—was not just allowing any website to turn on your device webcam, but also could allow hackers to take … [Read more...] about Zoom Video Conferencing for macOS Also Vulnerable to Critical RCE Flaw
Introducing Voice Control on Mac and iOS (with Audio Descriptions) — Apple
Version without audio descriptions: https://apple.co/2XueAm8 Voice Control gives your voice the power to navigate, dictate, and work your devices in a new way. Coming Fall 2019. Song: “Jump In” by Atomic Drum Assembly: http://apple.co/JumpIn … [Read more...] about Introducing Voice Control on Mac and iOS (with Audio Descriptions) — Apple