Apple Accidentally Notarizes Shlayer Malware Used in Adware Campaign
#1
Information 
Quote:Apple accidentally approved one of the most popular Mac malware threats – OSX.Shlayer – as part of its security notarization process.
 
The Apple notary service is an automated system on recent macOS versions that scans software (ranging from macOS apps, kernel extensions, disk images and installer packages) for malicious content and checks for code-signing issues. Then, when a macOS user installs the software, Apple’s Gatekeeper security feature notifies them about whether any malicious code was detected before they open it.
 
Security researchers Peter Dantini and Patrick Wardle recently discovered that Apple inadvertently notarized malicious payloads that were utilized in a recent adware campaign.
 
“Unfortunately a system that promises trust, yet fails to deliver, may ultimately put users at more risk,” said Wardle in a Sunday analysis. “How so? If Mac users buy into Apple’s claims, they are likely to fully trust any and all notarized software. This is extremely problematic as known malicious software (such as OSX.Shlayer) is already (trivially?) gaining such notarization.”

Read more: https://threatpost.com/apple-accidentall...re/158818/
[-] The following 1 user says Thank You to silversurfer for this post:
  • harlan4096
Reply


Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
QOwnNotes
26.4.18  Fixed th...Kool — 07:21
Mozilla Firefox 150 Released With Fixes...
Claude Mythos Expose...harlan4096 — 06:11
Mozilla Firefox 150 Released With Fixes ...
Mozilla has releas...harlan4096 — 06:10
AV-Comparatives - Performance Test - Apr...
Impact of Consumer...harlan4096 — 06:09
Java Runtime Environment 8.0 Update 491
Java Runtime Envir...harlan4096 — 06:55

[-]
Birthdays
Today's Birthdays
No birthdays today.
Upcoming Birthdays
avatar (51)steakelask
avatar (45)Termoplenka
avatar (51)Toligo

[-]
Online Staff
harlan4096's profile harlan4096
Administrator

>