Apple ships Java update, malware scrubber after confirming attacks on own Macs
And touts security moves that didn't prevent Java exploits from hijacking engineers' machines
Computerworld - The day it acknowledged company-owned Macs had been hacked using a "drive-by" Java exploit, Apple on Tuesday patched the Oracle software for older systems and released a malware detection tool.
The Apple-issued "Java for Mac OS X v10.6 Update 13" aimed at OS X Snow Leopard included patches for the same 30 vulnerabilities in Java 6 that were addressed in a special Feb. 1 update, as well as three fixes that had not been released earlier.
Also on Tuesday, Oracle updated Java 7. Like Apple, Oracle essentially bundled the Feb. 1 fixes with several new patches to create Java 7 Update 15.
Snow Leopard users can grab Apple's Java Update 13 by selecting "Software Update" from the Apple menu. Customers running OS X Lion or OS X Mountain Lion must update Java 7 themselves, either by manually downloading the update from Oracle's website or waiting for the Java update tool to do so.
The disparity in updating between Snow Leopard and later editions stems from Apple's decision in mid-2010 to stop bundling Java with OS X. Instead, it handed off development and maintenance of Java for OS X to Oracle. Patches for Java 7 are thus not delivered to Lion and Mountain Lion via Apple's Software Update service.
As it did when it shipped the Feb. 1 updates, Oracle again urged users to immediately deploy the patches. "Due to the threat posed by a successful attack, Oracle strongly recommends that customers apply CPU fixes as soon as possible," its Tuesday advisory stated.
Also in Apple's update was a malware detection and deletion tool the company pledged to release Tuesday.
"This update runs a malware removal tool that will remove the most common variants of malware," Apple said in the advisory. "If malware is found, it presents a dialog notifying the user that malware was removed. There is no indication to the user if malware is not found. This update is available for systems that installed Java 6."
That tool -- if not Tuesday's Java updates, which had been previously scheduled -- was promised when Apple confirmed that some company Macs had been hacked through Java exploits.
"We identified a small number of systems within Apple that were infected and isolated them from our network," Apple said Tuesday in a statement. "There is no evidence that any data left Apple."
Apple said that the machines had been compromised after their users visited an unnamed website for software developers. Multiple news sources, including the Wall Street Journal's All Things D blog, identified the site as iPhoneDevSDK.
The same infection tactic -- executing drive-by Java exploits against unpatched machines -- was cited by Facebook last week when it announced that some employees' computers had been infected prior to Feb. 1.
- Google I/O 2013's Coolest Products and Services
- 10 Star Trek Technologies That are Almost Here
- 19 Generations of Computer Programmers
- 25 Must-Have Technologies for SMBs
- A walking tour: 33 questions to ask about your company's security
- 15 social media scams
- The 7 elements of a successful security awareness program
- IT Certification Study Tips
- Register for this Computerworld Insider Study Tip guide and gain access to hundreds of premium content articles, cheat sheets, product reviews and more.
- Protection for Every Enterprise: How BlackBerry 10 Security Works Get an IT-level review of BlackBerry® 10 Security, addressing data leakage protection, certified encryption, containerization and much more.
- A Comprehensive Strategy to Leverage Mobile A successful mobile strategy begins with a common platform for integrating and managing mobile devices and the corporate assets that are stored on...
- IDC - SAP Enterprise Mobility: Bringing a Cohesive Approach to a Complex Market This IDC white paper discusses key mobility trends and examines how SAP's mobile enterprise solutions map to meet organization's mobile requirements.
- The App Happy Enterprise This Computerworld playbook explores key aspects of the enterprise mobile revolution and provides a set of step-by-step directions on how to productively manage...
- Live Webcast
Storage Validation at Go Daddy: Best Practices from the World's #1 Web Hosting Provider - Storage Validation at Go Daddy: Best Practices from the World's #1 Web Hosting Provider
- Live Webcast
MFT and FileXpress - An Overview - Business users and applications exchange files on a regular basis. File transfer is a core part of the flow of business activity.
- Live Webcast
Bridging HTTP and FTP with FileXpress Internet Server - What if you could take an FTP server on your internal network, and allow external users (partners or customers) to securely access it...
- Bridging HTTP and FTP with FileXpress Internet Server What if you could take an FTP server on your internal network, and allow external users (partners or customers) to securely access it...
- MFT and FileXpress - An Overview Business users and applications exchange files on a regular basis. File transfer is a core part of the flow of business activity. All Security White Papers | Webcasts