Macs older than a year are vulnerable to exploits that remotely overwrite the firmware that boots up the machine, a feat that allows attackers to control vulnerable devices from the very first instruction. . The attack, according to a blog post published Friday by well-known OS X security researcher Pedro Vilaca, affects Macs shipped prior to the middle of 2014 that are allowed to go into sleep mode. He found a way to reflash a Mac's BIOS using functionality contained in userland, which is the part of an operating system where installed applications and drivers are executed. By exploiting vulnerabilities such as those regularly found in Safari and other Web browsers, attackers can install malicious firmware that survives hard drive reformatting and reinstallation of the operating system.. Older Mac models face increased risks from firmware exploits due to outdated software and lack of updates, enabling remote attacks and data breaches. Mac Security,Firmware Exploits,Remote Control Attacks,OS X Vulnerabilities. . LinuxSecurity.com Team
It's easy for administrators and computing professionals to get frustrated with users for all kinds of reasons, but security has to be one of the biggest reasons these days. . . .. It's easy for administrators and computing professionals to get frustrated with users for all kinds of reasons, but security has to be one of the biggest reasons these days. Let's consider the recent release of a malicious script for Mac OS X. This script itself is not really much of a threat because it has no means of propagation, but as a Mac admin I'd take that as small comfort. The script is a tool for building genuine worms with social engineering as the front door. So what if the script requires admin/root access? Even if the Mac user is running as a less-privileged user, all the attack has to do is to ask for the root password. Unless you have an actual separate administrator for your computer, you have to have the root password handy for certain tasks that inevitably come up, such as installing programs and devices. The link for this article located at Larry Seltzer is no longer available. . Threat levels escalate as harmful code seeks out Mac and Linux platforms, causing system administrators to be vigilant about potential user weaknesses.. Malware Risk, Linux Administration, Mac Security Threats. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.