Newsletters
News & Information for Technology Purchasers NewsFactor Sites:       NewsFactor.com     Enterprise Security Today     CRM Daily     Business Report     Sci-Tech Today  
   
Home Enterprise I.T. Cloud Computing Applications Hardware More Topics...
Get Recognized.
Let an ISACA® certification
enhance your career.

Register for an Exam Today
Network Security
Register for a certification exam.
Average Rating:
Rate this article:  
Security Firm Says Apple Asking for Assessment
Security Firm Says Apple Asking for Assessment

By Barry Levine
May 14, 2012 2:39PM

    Bookmark and Share
To help battle the growing malware problem on Macs and OS X, Kaspersky Labs has recommended creating a non-administrator account for everyday activities, using a sandboxed Mac Web browser such as Chrome, uninstalling the standalone Flash Player, uninstalling Java or disabling it in browsers, and using Office 2011 instead of 2008.
 



Apple's Macs have been subject to a variety of high-profile security threats in recent months. Now, according to Kaspersky Labs, Apple has asked the security firm for a vulnerability analysis.

According to the chief technology officer for Kaspersky, Apple has approached his company to analyze its platform. Nikolay Grebrennikov told reporters about this development and added that, in his opinion, the computer maker had not previously taken security issues "seriously enough." Apple has not confirmed the arrangement.

'10 Years Behind Microsoft'

As one example, Grebrennikov cited a vulnerability in Java, which was exploited by the Flashback Trojan earlier this year and which infected a reported 600,000 Macs. Apple, he said, released its Java fix several months after Oracle did.

In April, shortly after the extent of the widely distributed Flashback Trojan on Macs became known, Kaspersky Lab CEO and co-founder Eugene Kaspersky charged that Apple was "10 years behind Microsoft in security," and he predicted that Apple products would increasingly become a more inviting target for malware.

While the comments of Kaspersky executives could well be seen as self-serving, Apple appears to have gotten at least some of this message. In February, developer previews of the new OSX 10.8 Mountain Lion included a new feature called Gatekeeper. This optional setting will enable Mac owners to allow only apps that have a free, signed certificate provided to legitimate developers by Apple.

For years, Macs have enjoyed a reputation -- undeserved, according to most experts -- of being virtually impervious to malware. But, as their sales have increased, so has their appeal as a target.

Last month, security firm Sophos reported that it had conducted a study which showed that as many as 20 percent of all Macs had some form of malware -- which had actually been designed for Windows machines. In addition, the study, which surveyed 100,000 Macs, found that 2.7 percent of Macs had malware targeted at the OS X platform.

'A Wake-Up Call'

At the time that the study was announced, Graham Cluley, senior technology consultant at Sophos, noted in a statement that "some Mac users may be relieved that they are seven times more likely to have Windows viruses, spyware and Trojans" than Mac ones, but "Mac users need a wake-up call about the growing malware problem."

Windows-targeted malware cannot do harm on a Mac platform, but it can cause damage if the user runs Windows as a secondary operating system, or if the infected files are shared with a Windows machine.

Seventy-five percent of the Macs that had OS X malware had the Flashback Trojan, which Sophos refers to as OSX/Flshplyr.

To help battle the growing malware problem on Macs, Kaspersky Labs has recommended creating a non-administrator account for everyday activities, using a sandboxed Web browser such as Chrome, uninstalling the standalone Flash Player, uninstalling Java or at least disabling it in browsers, and using Office 2011 instead of 2008.

Sophos has recommended an up-to-date anti-virus program, up-to-date OS and application security patches, and caution about which programs are installed, which links are clicked, and which attachments are opened.
 

Tell Us What You Think
Comment:

Name:



Salesforce.com is the market and technology leader in Software-as-a-Service. Its award-winning CRM solution helps 82,400 customers worldwide manage and share business information over the Internet. Experience CRM success. Click here for a FREE 30-day trial.


 Network Security
1.   Chinese Hackers Hit U.S. Officials
2.   Russian Hacker's Charges Revealed
3.   Another IE-Focused Patch Tuesday
4.   Russian Arrested in Hacking Case
5.   Most Networks Not Ready for IoT


advertisement
Android SMS Worm on the Loose
Malware lets bad actors cash in.
Average Rating:
Another IE-Focused Patch Tuesday
One critical for Internet Explorer.
Average Rating:
Most Networks Not Ready for IoT
But most enterprises are prepared.
Average Rating:


advertisement
Product Information and Resources for Technology You Can Use To Boost Your Business

Network Security Spotlight
Report: Chinese Hackers Hit U.S. Personnel Networks
Hackers from China broke into the computer networks of the U.S. Office of Personnel Management earlier this year with the intention of accessing the files of tens of thousands of federal employees.
 
Charges: Russian Stole Data from U.S. Restaurants, Zoo
A Russian man arrested on bank fraud and other charges hacked into computers at restaurants in Washington, hundreds of other retail businesses, and even the Phoenix Zoo, authorities say.
 
Another Month, Another IE-Focused Patch Tuesday
Microsoft rolled out 59 vulnerabilities for Internet Explorer in June. But the IE-patching party is not over yet. Redmond published six new security bulletins on Tuesday; two, critical; three, important.
 

Navigation
NewsFactor Network
Home/Top News | Enterprise I.T. | Cloud Computing | Applications | Hardware | Mobile Tech | Big Data | Communications
World Wide Web | Network Security | Data Storage | Small Business | Microsoft/Windows | Apple/Mac | Linux/Open Source | Personal Tech
Press Releases
NewsFactor Network Enterprise I.T. Sites
NewsFactor Technology News | Enterprise Security Today | CRM Daily

NewsFactor Business and Innovation Sites
Sci-Tech Today | NewsFactor Business Report

NewsFactor Services
FreeNewsFeed | Free Newsletters | XML/RSS Feed

About NewsFactor Network | How To Contact Us | Article Reprints | Careers @ NewsFactor | Services for PR Pros | Top Tech Wire | How To Advertise

Privacy Policy | Terms of Service
© Copyright 2000-2014 NewsFactor Network. All rights reserved. Article rating technology by Blogowogo. Member of Accuserve Ad Network.