
Apple has released a security update for Mac OS X that removes the Flashback Trojan, a persistent piece of malware that used a known flaw to infect an estimated 600,000 Macs in the past month.
In a security bulletin posted this afternoon (April 12) on the Apple Support website, Apple said the update “removes the most common variants of the Flashback malware” and “also configures the Java web plug-in to disable the automatic execution of Java applets.”
Apple has been criticized in the security community for failing to stop Flashback from infecting so many machines using a known vulnerability in Oracle’s Java software. The malware has existed in various forms since last fall.
The Java flaw was discovered in late January, and Oracle patched it on Windows and Linux machines Feb. 17. But Apple, which does its own Java updates, did not come out with a patch until April 3, after more than half a million Macs worldwide had been infected.
[FAQ: The New Mac Virus and Apple Anti-Virus Options]
Java, in effect, creates an operating system inside an operating system in order to run Web-based apps and other functions across different platforms. It has a history of serious vulnerabilities. Many security experts recommend that it be disabled on both Macs and PCs unless absolutely necessary.
Apple seems to have heeded that advice. The security bulletin released today said: “Users may re-enable automatic execution of Java applets using the Java Preferences application. If the Java web plug-in detects that no applets have been run for an extended period of time it will again disable Java applets.”
The security update will be pushed out automatically today to all Macs running Mac OS X 10.6 Snow Leopard and OS X 10.7 Lion.
Apple no longer supports Macs running OS X 10.5 Leopard, which includes all Macs based on the PowerPC architecture.
Late yesterday (April 11), and without any announcement, Apple began boosting security in the iTunes Store and the App Store to combat a persistent problem of hijacked Apple customer accounts.
Article provided by SecurityNewsDaily, a sister site to Laptopmag.com.
From Laptopmagazine. Visit Amazon Computer and Notebook Center Here
We couldn't find anything truly wrong with Avira Internet Security Suite 2012 ($60 for one year, one PC as of January 29, 2012), which ranked 11th in our 2012 roundup of Internet security suites. After all, the package protects against malware adequately, and although the interface isn't perfect, it's certainly usable. But in a year when so many suites are excellent performers, being adequate isn't enough to keep pace.
If you can tolerate some sluggishness, F-Secure Internet Security 2012 ($60 for one year and three PCs as of January 25, 2012), which placed eighth in our 2012 roundup of security suites, will protect your PC pretty well.
A solid choice for keeping you safe, Avast Internet Security 6 ($50 for one year and one PC as of January 25, 2012) finished sixth in our 2012 roundup of security suites. Although it ranked in the bottom half of our Top 10, the Avast package is easy to use, and in general it will protect your PC quite capably.
The largest-ever Android malware campaign may have duped as many as 5 million users into downloading infected apps from Google's Android Market, Symantec said today.
Some of the 13 apps that Symantec identified as infected have been on the Android Market for at least a month, according to the revision dates posted on the e-store. Symantec, however, discovered them only yesterday. 