Showing posts with label os x. Show all posts
Showing posts with label os x. Show all posts

Monday, September 16, 2013

OS X Mountain Lion 10.8.5 update more than doubles 802.11ac file transfer speeds



Apple has just rolled out the latest update to Mountain Lion with fixes to a number of issues users have been experiencing lately. If you haven't already noticed the prompt, you'll find OS X version 10.8.5 is now available in your Software Update queue or directly from here.

The latest update is said to improve upon and fix a number of issues including file transfer performance over 802.11ac Wi-Fi. Some reports claim the 802.11ac file transfer speeds are more than doubled compared to in 10.8.4. Additionally, the update tackles recent problems with displaying messages in Mail and resolves an issue that was preventing screen savers from starting automatically on some machines.

Other updates with 10.8.5 include improved Xsan reliability, more stability with large file transfers over Ethernet, improved Open Directory server authentication, fixes with smart card integration in System Preferences and some of the additions that came along with the MacBook Air (Mid 2013) Software Update 1.0.

While today's offering brings some needed updates, most have their eye on OS X 10.9 Mavericks which Apple is widely expected to release as early as the end of next month.

Monday, July 30, 2012

Apple finally releases Java patches for Flashback malware


apple, oracle, java, trojan, malware, os x, exploits, os x 10.6, os x 10.7, flashba
Apple silently released security patches for Java, addressing 12 separate flaws yesterday after their OS X operating system was found to be vulnerable to the Flashback Trojan. In fact security experts were so worried about the potential for damage from the malware that they recommended ditching Java until it had been plugged.
While those using Microsoft’s Windows OS were at the highest level of risk initially, the Mac Security blog Intego found a new Flashback variant in the wild at the beginning of March, created to specifically target Apple OS X users.
The new update is available from the update manager for OS X 10.6 and 10.7 operating systems and is described by Apple as targeting “multiple vulnerabilities [that] exist in Java 1.6.0_29, the most serious of which may allow an untrusted Java applet to execute arbitrary code outside the Java sandbox. Visiting a web page containing a maliciously crafted untrusted Java applet may lead to arbitrary code execution with the privileges of the current user. “
Further investigations by Sucuri Security located a considerable number of infected websites using older releases of WordPress with the "ToolsPack" plugin installed. Analysis of this plugin revealed it was simply a backdoor that allowed hackers to execute any code on the infected website. It is believed these sites are re-directing the browsers of Mac OS X users to webpages containing the new strain of Flashback malware. 
Whilst it is good that Apple has finally patched the vulnerabilities that Windows users saw updates for back in February, it is rumored that one critical flaw remains, which F-Secure says is being actively discussed on underground forums where money is also being exchanged in return for the exploit code. 
"It is strongly recommended to update your Java client to the latest version, disable it when not needed, or better yet, remove it completely if you don’t really need it," the security firm said in a blog post yesterday.
Attacks are rarely as serious in nature on Apple’s OS X platform, but there is no doubt that exploits are increasing as hackers realize the value of targeting their OS. More alarmingly, the Flashback malware has also opened up another potential problem – Apple by all accounts has been very slow to respond to the security fixes that Oracle released for their affected software used on Windows back In February.

Tuesday, July 24, 2012

Apple patches CPU power consumption bug in 2012 MacBooks


apple, thunderbolt, macbook, mac, os
Apple has issued an update that addresses CPU-related power consumption issues with MacBook Air and MacBook Pro models released in June, including the 15-inch Retina display model. Details are slim on the 76.64MB update, but CNET reportsthat it contains new versions of the I/O kernel extensions and frameworks, the Dock application, and shared resources such as desktop pictures, user icons and system sounds. The patch also improves compatibility with certain USB devices interfering with Wi-Fi signals and causing other issues.
Unaddressed by today's update is an audio issue that arises when a 2012 MacBook is connected to an external display via Thunderbolt. A thread on Apple's support forum was created nearly a month ago and has accumulated over 100 replies with various related complaints. Users note that the MacBook's integrated speakers work fine, but they complain of intermittent static and crackling from the speakers in Apple's Thunderbolt Display.
Most of the complaints involve the 11 and 13-inch MacBook Air, though at least one person claims to have the issue with the Retina-equipped MacBook Pro. An exact cause remains unknown, but some folks believe that the adapter connecting Apple's new MagSafe 2 power connector to the Thunderbolt Display's power cord may be at fault. Others note that switching between audio outputs, reattaching all connections and/or restarting the offending program serves as a temporary workaround, but nobody has discovered a permanent solution.

Tuesday, July 10, 2012

Mac Flashback trojan exploits unpatched Java vulnerability, no password needed




The icon in the red box in this screenshot is PNG content returned by the remote sites exploiting an unpatched Java vulnerability. The image is dropped onto vulnerable Macs and can be changed any time the author wants.

Developers behind the Flashback trojan for the Mac have updated it to exploit a vulnerability in the Java software framework that has yet to be patched for machines running Mac OS X, an antivirus firm warned on Monday.


Flashback.K, as the latest variant is called, is able to hijack Macs even when users don't enter an administrative password. Instead, it does this by exploiting a critical Java vulnerability classified as CVE-2012-0507, F-Secure researchers wrote in a blog post. Although Oracle released a fix for the security threat in February, a patch has yet to be released for OS X users. That's because Apple distributes Java updates itself and the company has yet to make one for the specific flaw, or indicate when it plans to do so.
Flashback first surfaced in September as a trojan that masqueraded as an installer for Adobe's Flash Player. Over the past few months, it has taken on increasingly sophisticated features, including theability to bypass built-in OS X malware protections and attack code that exploits long-ago patched Java vulnerabilities. The version analyzed by F-Secure is the first known time Flashback has exploited a vulnerability for which no fix is currently available.
Although Apple stopped bundling Java by default in OS X 10.7 (Lion), it offers instructions for downloading and installing the Oracle-developed software framework when users access webpages that use it. Some security researchers have for years criticized Apple for lagging behind Microsoft and Linux distributors in releasing Java updates to its users. F-Secure has recently joined others in counseling Mac users to disable Java on machines that don't regularly use it. The antivirus provider also has provided instructions for checking if your Mac is infected.
Attacks that exploit CVE-2012-0507 recently went mainstream when they were added to automated exploit kits such as Blackhole. Once it infects a Mac, Flashback changes the contents of some of the webpages it displays.

Sunday, July 8, 2012

Apple App Store updates cause iOS OS X apps to crash



apple, ios, app store, os x, ap
Apple's servers appear to have pushed out corrupted binaries over the last few days according to Instapaper developer Marco Arment. The issue has caused OS X and iOS users to experience app crashes as a result of updating to new versions containing the corrupted binaries available from the iOS App Store and the Mac App Store.

Arment discovered the problem on Tuesday evening after pushing an update for his Instapaper app to Apple's App Store. "I was deluged by support e-mail and Twitter messages from customers saying that it crashed immediately on launch, even with a clean install," he wrote on his blog. The problem appears to have been caused by Apple's addition of FairPlay DRM when updated binaries are submitted to the company's servers for distribution.

Specifically, an error encoding the DRM to the uploaded binary causes those downloading them to experience crashes as soon as the app is started. Error logs point to a failure within "AppleFairplayTextCrypterSession::fairplayOpen()" -- the first step required to run any app downloaded from either of Apple's app stores.

It doesn't appear to be affecting all regions according to the developer, although it's currently unclear exactly which regions are or aren't having issues, or precisely how many apps are affected. So far, Apple appears to be fixing apps on a case-by-case basis right now as Arment's app is no longer crashing.

Developers that have submitted updates to their apps between July 3 and 5 may still be affected by the problem. "I'll repeat my warning to developers: if you can help it, do not release app updates today," Arment said viaTwitter. "The corruption is widespread and ongoing."

The unfortunate situation has resulted in users assuming developers are to blame for the crashes of newly updated apps, leading to a rise in negative comments from consumers unaware of the situation. Those that are affected can restore the apps by removing it and then downloading a working version, once Apple has resolved the problem.

Apple is yet to announce when it would be resolved and did not respond to requests for further comment.