
Two new Mac malware from Wild – fixed this week
Wild has two new reports on Mac malware, with the first report being blocked by an expected update this week.
There’s no word yet about the second fix, but you’ll have to be a pretty naive Mac user to fall into it…
Mac malware exploitation is similar to vulnerabilities
MacWorld Security researcher Mickey Zinn reports that it was published by security researcher Mickey Zinn after spending seven months trying to get similarities to fix it.
The exploit contains similarities, which are virtual machines that allow Macs to run Windows, Linux, and older versions of MacOS. The vulnerability runs similarities on Intel Macs, allowing attackers to gain root access by drilling holes in similarities in VM creation routines.
Certainly, that wasn’t a major threat as the attacker needs physical access to your Mac to apply it, but the company says it’s closing the hole this week.
Parallels has posted a knowledge-based article about its flaws and says it will be published later this week, including Desktop 20.2.2 and Parallels Desktop 19.4.2.
Fairly cold teal
The second example, FrigidStealer, can be exploited remotely and is intended to steal passwords. However, only Naive Mac users fall into it as they must first click on the link and then follow the instructions to bypass the gatekeeper.
The attack occurs when a user gets an email containing a URL, and when the user opens it, the web page launches with an alert indicating that the browser needs to be refreshed. When the (Refresh) button is clicked, the installer is saved to your Mac and the user is told to control the app icon and choose to open it from the pop-up menu. GateKeeper opens files this way is Macos’ built-in security that checks for malicious apps. This will install the malware.
Normal safety precautions apply. Don’t click on the link you didn’t expect. Additionally, confidential sites can always be accessed using their own bookmarks. Install the software only from the Mac App Store or from a trusted developer website.
Photography by photo
(TagStoTRASSLATE) Malware