Showing posts with label iMac. Show all posts
Showing posts with label iMac. Show all posts

Thursday, 25 June 2015

New Flash Player Flaw Attacked Through The Link In Emails


A critical vulnerability exists in Adobe Flash Player which yesterday an emergency patch released was attacked from links in emails. That informs the American security company FireEye that the zero-day vulnerability discovered and reported to Adobe.

A China-based group, according to FireEye behind the attack. The attacks were aimed at companies and organizations in different sectors, such as aerospace, defense, telecom, engineering and transport. The targets were emails sent with a link.Remarkably, there is no targeted emails were used, but messages that seemed almost on spam. "Save between $ 200-450 by purchasing an Apple Certified Refurbished iMac through this link. Refurbished iMacs come with the same one-year extendable warranty as new iMacs. Supplies are limited, but updated frequently. Do not hesitate...> Go to Sale , "the text in the message.

The link in the email pointed to a compromised server where the target was profiled via JavaScript. Once the victim was determined downloaded a malicious SWF and FLV file. Eventually this led to the installation of a backdoor. Through this backdoor received the attackers access to the system and the network of the organization was infiltrated. In announcing the emergency patch let Adobe know that IE users on Windows 7 and older and Firefox users on Windows XP were the target of the attack.

Wednesday, 11 March 2015

Apple Fixes FREAK Vulnerability In Mac OS X And iOS


Apple has released updates for Mac OS X, Apple TV and iOS that it " FREAK leak fixes "in SSL / TLS.Through the vulnerability, an attacker who is between a target and the Internet is in some cases the encryption of the encrypted connection to downgrade to a weak encryption to crack then that and to see the encrypted traffic.

Further resolves Security Update 2015-002 for Mac OS X four other vulnerabilities. It involves leakage and malicious app could execute arbitrary code with system privileges, memory addresses in the kernel were determined and could allow an attacker on the network arbitrary code via iCloud Keychain. iOS 8.2 fixes beside FREAK leak five other vulnerabilities.

Through these vulnerabilities, an attacker could iPods and iPads remote reboots and an attacker with physical access could see the home screen, even though the device was not activated. Furthermore, the same vulnerabilities resolved in Mac OS X, allowing attackers to execute arbitrary code. The same applies to AppleTV 7.1 , where a total of three leaks were patched.Finally, there is also an update for Xcode appeared, the development software from Apple for OS X and iOS. This five leaks were patched.