Hacker Charlie Miller has exposed a security flaw in Apple's App Store. The flaw allows a LEGIT app to secretly download an unsigned, app without the knowledge of the user, or Apple through a backdoor entrance.
Remember, this is a signed, listed, inspected and fully authorized app from the App Store. The malicious code was not detected by Apple, and the only reason the app was pulled and his dev account cancelled was because he himself announced the presence of his virus in the app that he wrote.
This not only reveals a huge potential security flaw in iOS, but in Apple's App Store model as well. Any official app could potentially be a trojan horse carrying with it, full remote access to your iPhone/iPod Touch and its contents.
Currently, there is no way of protecting yourself from this type of threat... nor is there any way for the end user to know if any of their apps were actually made with this type of virus built in.
Although technical, this video is a proof of concept showing how he gains remote access into an iPhone that has downloaded the app.
It's a very wide spread misconception that Macs are immune to viruses (or virii if you're 1337). This is NOT (nor has it ever been) true. There are far fewer viruses that can infect Mac, yes... but they are still out there. The main issue is that the complacency of the end users make them the easier target.
The bigger immediate threat at the moment is a new backdoor trojan that has been detected out in the wild. Named Tsunami, it allows a cracker remote access to your Mac and make it do horrible things (Such as download porn!)
D3HXQ36UDJSH A warning to all Bank of the Philippine Islands users... Trend Micro has identified a new Phishing scam going around. Please DO NOT click on any links found in your email. Go directly to BPI's website.
Ok, this only applies to those who use the digital audio output on their Macs...
DO NOT UPDATE TO 10.6.8 just yet.
The update causes a digital audio glitch that disables your HDMI/Digital Out after watching a DD or DTS movie. The only way to get your audio back is to reboot the system.
If a friend of yours suddenly chats with you, with a message and link that look similar to this... do not bother clicking on the link. It will take you to a website that claims you can view the people that are viewing your Facebook site.
You will most likely receive an event invite as well "How to see who viewed your profile!!". Do not accept the invite and delete it as soon as possible.
Be careful with this link. Highly suspicious since it links to an app, and not a video. I saw the real vid of this and it's funny. Manually search for it on YouTube instead.
I will try an post as many regular warnings as I possibly can when I notice viral links going around FB or email. If you see a similar link in your newsfeed, avoid clicking on them without verifying their authenticity.