Important Security Patch For Mac

 admin  

Unclear behaviour of a mysql container running with. Dubbed 'Trident,' the security holes were used to create spyware (surveillance malware) called ' that was apparently used to target human rights activist Ahmed Mansoor in the United Arab Emirates. Pegasus could allow an attacker to access an incredible amount of data on a target victim, including text messages, calendar entries, emails, WhatsApp messages, user's location, microphone. Pegasus Spyware could even allow an attacker to fully download victim's passwords and steal the stored list of WiFi networks, as well as passwords the device connected to. Apple is now patching the same 'Trident' bugs in Safari web browser on its desktop operating system, with for Safari 9 as well as OS X Yosemite and OS X El Capitan. However, this is not a surprise because iOS and OS X, and mobile and desktop version of Safari browser share much of the same codebase. Therefore, zero-days in Apple’s iOS showed up in OS X as well. Pegasus exploit takes advantage of Trident bugs to remotely jailbreak and install a collection of spying software onto a victim's device, without the user’s knowledge.

One of the key tools of the exploit takes advantage of a memory corruption bug in Safari WebKit, allowing hackers to deliver the malicious payload when a target victim clicks on a malicious link and initiate the process of overtaking the operating system. In an advisory, Apple warned that visiting a 'maliciously crafted website' via Safari browser could allow attackers to execute arbitrary code on a victim's computer. The patch updates that Apple released on Thursday fix the nasty Trident bugs, including CVE-2016-4654, CVE-2016-4655, and CVE-2016-4656, which were initially discovered and reported by mobile security startup Lookout and the University of Toronto’s Citizen Lab. Based on a link sent to UAE human rights activist Ahmed Mansoor, Lookout Security, and Citizen Lab traced the three programming blunders and its Pegasus spyware kit to Israeli 'cyber war' organization, which sells hacking exploits to governments like the UAE. Users can install security patches for, via the usual software update mechanisms.

Security

Security Patch Download

​ Patch Tuesday: Microsoft Releases Important Office 2011 for Mac Update Posted on June 11th, 2013 by For Patch Tuesday, Microsoft released important security updates for Office 2011 for Mac, resolving one privately reported vulnerability in Microsoft Office. The software update addresses a remote code execution vulnerability that affects Microsoft Office for Mac 2011 and Microsoft Office 2003 Service Pack 3.

Free Security For Mac

In addition to Microsoft’s Patch Tuesday update, software. Microsoft’s (MS13-051) describes the vulnerability resolved in this update as follows: The vulnerability could allow remote code execution if a user opens a specially crafted Office document using an affected version of Microsoft Office software, or previews or opens a specially crafted email message in Outlook while using Microsoft Word as the email reader. An attacker who successfully exploited this vulnerability could gain the same user rights as the current user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights. Microsoft addressed the vulnerability by correcting the way that Microsoft Office parses specially crafted Office files. We recommend that all users running Microsoft Office 2011 for Mac apply these updates as soon as possible. Office users can update your software using Microsoft’s AutoUpdate application, or you can visit Microsoft’s Download Center to get the for Mac.

This entry was posted in and tagged,. Bookmark the.

   Coments are closed