ITPRO

Printed from www.itpro.co.uk

Register to receive our regular email newsletter at http://www.itpro.co.uk/reg/register.

The newsletter contains links to our latest IT news, product reviews, features and how-to guides, plus special offers and competitions.

Skip to navigation

    Apple accused of clandestine security update

Sophos has suggested that Apple was a little surreptitious about introducing a security update for Mac OS X this week.

By Tom Brewster, 18 Jun 2010 at 15:22

Secretive

Apple “secretly” updated anti-malware protection in Mac OS X when it launched a new version this week, IT security firm Sophos has claimed.

The Cupertino company allegedly added “limited protection” against a backdoor Trojan known to Apple as HellRTS, Sophos suggested, but the iPhone and MacBook manufacturer did not mention the update either in a security advisory or in the release notes accompanying Mac OS X 10.6.4.

This piece of malware can allow malicious attackers to gain control over Mac systems, the security company said.

Sophos claimed that Apple updated a file named XProtect.plist, which contained "elementary signatures" of a number of Mac threats, to detect HellRTS.

“It's almost as if they [Apple] don't want to acknowledge that there could be a malware threat on Mac OS X,” said Graham Cluley, senior technology consultant at Sophos, in a statement.

Cluley did point out, however, that it was positive Apple had updated Mac OS X security, as the Trojan can allow hackers to send spam email from a victim’s computer, take screenshots of what they are doing and access files.

“Unfortunately, many Mac users seem oblivious to security threats which can run on their computers, even though Apple has now built-in some elementary protection," Cluley added.

"This lack of awareness isn't helped when Apple issues an anti-malware security update by stealth, rather than informing the public what it has done.”

Apple told IT PRO that it had nothing further to say on the matter, other than what was on its security update page. At the time of publication, the company had not given a response as to whether the updated protection is “limited”, as Sophos has claimed.

As for how the security is lacking, Cluley told IT PRO that he believes that the anti-virus on Mac OS X will only intercept malware if a user has downloaded it to their computer and then tried to run the file from their desktop.

If the malware comes via a USB stick, for example, the protection misses the threat, Cluley claimed.

Email to a friend

Print this page

< Previous   Security : News Next >

Be the first to comment on this article

You need to Login or Register to comment.

    You may also like...

 Sponsored Links

advertisement

    You may also like...

advertisement

    Register for IT PRO

You'll get exclusive member benefits including free whitepapers, downloads, Webinars and weekly newsletters full of the latest IT PRO news, reviews, insight and expertise.

Sponsored Links
Advertisement