Apple Accidentally Notarizes Shlayer Malware Used in Adware Campaign
#1
Information 
Quote:Apple accidentally approved one of the most popular Mac malware threats – OSX.Shlayer – as part of its security notarization process.
 
The Apple notary service is an automated system on recent macOS versions that scans software (ranging from macOS apps, kernel extensions, disk images and installer packages) for malicious content and checks for code-signing issues. Then, when a macOS user installs the software, Apple’s Gatekeeper security feature notifies them about whether any malicious code was detected before they open it.
 
Security researchers Peter Dantini and Patrick Wardle recently discovered that Apple inadvertently notarized malicious payloads that were utilized in a recent adware campaign.
 
“Unfortunately a system that promises trust, yet fails to deliver, may ultimately put users at more risk,” said Wardle in a Sunday analysis. “How so? If Mac users buy into Apple’s claims, they are likely to fully trust any and all notarized software. This is extremely problematic as known malicious software (such as OSX.Shlayer) is already (trivially?) gaining such notarization.”

Read more: https://threatpost.com/apple-accidentall...re/158818/
[-] The following 1 user says Thank You to silversurfer for this post:
  • harlan4096
Reply


Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
uBOLite 2026.426.1626 & uBOLite 2026.426...
uBOLite 2026.426.1...harlan4096 — 12:18
QOwnNotes
26.4.21  Added a ...Kool — 08:48
Notepad++ release 8.9.4
Notepad++ release ...harlan4096 — 07:26
Google Is Redesigning Gmail, Drive, Cale...
Google is developi...harlan4096 — 07:25
Kaspersky\VPN\KSOS 21.26 (MR26) & KES 14...
harlan4096 — 11:58

[-]
Birthdays
Today's Birthdays
No birthdays today.
Upcoming Birthdays
avatar (51)Toligo

[-]
Online Staff
There are no staff members currently online.

>