news.mlab.sh
Back to the feed
threat-intel

Researchers replace downloaded macOS apps with evil twins, Apple shrugs

Medium
Summary

Researchers have discovered a method to replace downloaded macOS applications with malicious 'evil twin' versions, while Apple has not responded to the issue. This highlights a significant vulnerability in how users obtain and install software, potentially exposing them to malware and data theft. The Register reported on similar phishing attacks targeting Signal users and the ongoing efforts to combat Iranian propaganda.

The Register reported on a concerning trend where researchers are successfully replacing downloaded macOS applications with malicious counterparts. This allows attackers to deliver malware disguised as legitimate software to users. Apple has not yet issued a response to this vulnerability, raising concerns about the lack of immediate action to address the issue. The Register also highlighted a phishing campaign where attackers impersonated Signal support to trick users into providing sensitive information. Additionally, the US government has taken down several Iranian propaganda websites, continuing a long-standing effort to counter disinformation efforts. The Register further noted that a significant number of Joomla websites are vulnerable due to flaws in the iCagenda and Balbooa Forms extensions, impacting a million sites worldwide. Finally, the Register mentioned that a new X11 server, implemented directly in assembly, joins existing options like yserver, Phoenix, and XLibre.

Read the full article at The Register