Apple finds apps infected with malicious code – XcodeGhost

You’ve probably heard the news: Potentially millions of Apple iPhone and iPad users may be at risk after the first-ever major Apple hack — a breach made possible by fake developer tools used to create iOS apps that made their way onto the Apple App Store.

Developers in China sought to reduce software download times by downloading a copy of the Xcode developer tools hosted on a Chinese server instead of the official version available from Apple. Unknown to developers, this counterfeit version of Xcode automatically embedded some malware, called ‘XcodeGhost’, into their apps. According to Apple this may have led to a number of infected iOS apps leaking, “some general information such as the apps and general system information.”

Apple, which prides itself as one of the most secure OS platforms in the world, quickly responded and apparently removed over 300 pieces of malware-infected software from the App Store. It also simultaneously began working with developers to make sure they were using the correct version of Xcode, and not the fake developer code used to create the infected apps.

The full list of affected apps has not yet been disclosed, but Apple has published a list of the most popular currently-known impacted apps.

Ironically, the Apple hack occurred just as Chinese leader President Xi Jinping was arriving in the U.S. to attend a summit with President Barack Obama to discuss concerns about China’s slowing economy and cooperation on cyber security; as well as meet with top tech firms including Apple.

If you feel you’re at risk of having downloaded any infected apps, here are some things you can do:

  • Check the Apple breach list for the known infected apps and delete any of the iOS apps noted above.
  • Be on the look out of prompts asking for your name, password or other information, such as your social security number or other sensitive information from a source you cannot verify.
  • Change your passwords, including your Apple account password.
  • Make sure your apps are up to date.

AVG launches its next generation consumer products

AMSTERDAM September 30th, 2015 – AVG® Technologies N.V. (NYSE: AVG), the online security company™ for more than 200 million monthly active users, today announced the availability of its next generation consumer product releases for PC and mobile. AVG’s products and suites will now be auto-updated on a continual basis, so users will always have the latest features and capabilities and will no longer need to worry about keeping their products up to date.  This is AVG’s first step towards Security as a Service.

As well as including AVG’s latest protection and performance products for Windows, Android, iOS and Mac OSX devices, both suites feature AVG’s flagship AVG Zen® platform, which makes it easy for users to monitor and manage protection and performance across an unlimited number of their own devices, and those of family members, from a single dashboard on any PC or Android device.

AVG has coordinated these releases with two, industry initiatives: European Cyber Security Month and National Cyber Security Awareness Month, to underscore its leadership in online security and its strong commitment to protecting devices, data and people, at home and at work.

“From the number of devices we own, to the types of apps we use, the digital world is now more intrinsically linked with our lives than ever before; and this dependency shows no sign of stopping,” said Andrew Reid, SVP, Products at AVG Technologies. “However, with the online landscape getting more complicated on a daily basis, we know that consumers and businesses cannot afford to be left unprepared. That is why we are constantly evolving our products – giving our customers peace of mind that their devices will always be protected and performing at their best, no matter how their device use changes.”

New features of the updated AVG Protection and AVG Performance suites include:

AVG Protection

Available in FREE or PRO versions, AVG Protection includes AVG’s leading AVG AntiVirus software for Windows, Android or Mac, and features the following updates:

AVG AntiVirus for Windows

  • Real-Time Cloud Detection: helps instantly spot new malware outbreaks using up-to-the-minute cloud-based crowd intelligence.
  • AI Detection: uses advanced artificial intelligence and crowd-sourced data to proactively identify new threats in real-time, before our AVG VirusLab team has catalogued the threats.
  • Improved Online Shield: in the PRO version includes cloud-based detection to identify dangerous downloads faster than ever.

AVG AntiVirus for Android

  • Better malware protection: Better protect your phone or tablet, thanks to new smart cloud scanning, shortened scan times, and improved detection.
  • Improved Anti-Theft: Improved algorithms make remote location faster on FREE and PRO.
  • More informative: To make scan results easier to understand, we’ve integrated with AVG VirusLab to provide more information about the threats we find.
  • Improved Battery Save mode: We’ve made it easier to improve your battery life by allowing you to turn on Battery Save mode from directly within the low-battery notifications in your phone’s notification panel.

AVG AntiVirus for Mac

  • New Quarantine: in AVG AntiVirus for Mac now lets users isolate infected files from the rest of their Mac devices, so they can decide how to handle them at a later time.

 

AVG Performance

Comprising AVG’s three tuneup products – AVG PC TuneUp, AVG Cleaner for Android and AVG Cleaner for Mac – the upgraded AVG Performance suite includes the following:

AVG PC Tune Up 

  • New Tuning Dashboard: giving users faster access to all tuning features and better visibility of potential performance issues.
  • Enhanced PC cleaning: now cleans up more games from Steam, the Download folder and additional applications such as VMware.
  • Enhanced Browser Cleaner: removes 60 types of browser traces from the latest browsers such as Internet Explorer, Google Chrome and Firefox.

AVG Cleaner for Android

  • New App Manager: gives users an immediate overview of the most draining apps from a single screen and helps to get rid of them once and for all.

AVG Cleaner for Mac

  • New iPhoto Cache cleaning: to stop iPhoto ‘cache’ folders taking up space and preventing photo deletion over time.

AVG Protection and AVG Performance are available to download now* via the AVG website. PRO versions of both suites, which include features such as AVG Internet Security, are also available for 30-day trials, or to purchase as annual subscriptions for $59.99 (Protection) or $39.99 (Performance). * The upgraded products will be available in Brazil in Q4 2015

To view our Press Kit, which includes product screenshots, video content and further details on this news, please visit http://now.avg.com/avg-new-protection-performance-press-kit/

 

About AVG Technologies (NYSE: AVG)

AVG is the online security company providing leading software and services to secure devices, data and people. AVG’s award-winning technology is delivered to over 200 million monthly active users worldwide. AVG’s Consumer portfolio includes internet security, performance optimization, and personal privacy and identity protection for mobile devices and desktops. The AVG Business portfolio – delivered by managed service providers, VARs and resellers – offers IT administration, control and reporting, integrated security, and mobile device management that simplify and protect businesses.

All trademarks are the property of their respective owners.

www.avg.com

 

Contacts:

North America:
Deanna Contreras
Tel: +1 415 371 2001
Email: [email protected]

Rest of World:
Zena Martin
Tel: +44 7496 638 342
Email: [email protected]

Press information: http://now.avg.com

USN-2747-1: NVIDIA graphics drivers vulnerability

Ubuntu Security Notice USN-2747-1

28th September, 2015

nvidia-graphics-drivers-304, nvidia-graphics-drivers-304-updates, nvidia-graphics-drivers-340, nvidia-graphics-drivers-340-updates, nvidia-graphics-drivers-346, nvidia-graphics-drivers-346-updates, jockey vulnerability

A security issue affects these releases of Ubuntu and its
derivatives:

  • Ubuntu 15.04
  • Ubuntu 14.04 LTS
  • Ubuntu 12.04 LTS

Summary

NVIDIA graphics drivers could be made to run programs as an administrator.

Software description

  • jockey
    – user interface and desktop integration for driver management

  • nvidia-graphics-drivers-304
    – NVIDIA binary X.Org driver

  • nvidia-graphics-drivers-304-updates
    – NVIDIA binary X.Org driver

  • nvidia-graphics-drivers-340
    – NVIDIA binary X.Org driver

  • nvidia-graphics-drivers-340-updates
    – NVIDIA binary X.Org driver

  • nvidia-graphics-drivers-346
    – NVIDIA binary X.Org driver

  • nvidia-graphics-drivers-346-updates
    – NVIDIA binary X.Org driver

Details

Dario Weisser discovered that the NVIDIA graphics drivers incorrectly
handled certain IOCTL writes. A local attacker could use this issue to
possibly gain root privileges.

Update instructions

The problem can be corrected by updating your system to the following
package version:

Ubuntu 15.04:
nvidia-346 346.96-0ubuntu0.1
nvidia-346-updates 346.96-0ubuntu0.1
nvidia-340-updates 340.93-0ubuntu0.1
nvidia-340 340.93-0ubuntu0.1
nvidia-304-updates 304.128-0ubuntu0.1
nvidia-304 304.128-0ubuntu0.1
Ubuntu 14.04 LTS:
nvidia-346 346.96-0ubuntu0.0.1
nvidia-346-updates 346.96-0ubuntu0.0.1
nvidia-340-updates 340.93-0ubuntu0.0.1
nvidia-340 340.93-0ubuntu0.0.1
nvidia-304-updates 304.128-0ubuntu0.0.1
nvidia-304 304.128-0ubuntu0.0.1
Ubuntu 12.04 LTS:
jockey-common

0.9.7-0ubuntu7.16
nvidia-304 304.128-0ubuntu0.0.0.1
nvidia-304-updates 304.128-0ubuntu0.0.0.1
nvidia-340-updates 340.93-0ubuntu0.0.0.1
nvidia-340 340.93-0ubuntu0.0.0.1

To update your system, please follow these instructions:
https://wiki.ubuntu.com/Security/Upgrades.

After a standard system update you need to reboot your computer to make
all the necessary changes.

References

CVE-2015-5950

USN-2748-1: Linux kernel vulnerabilities

Ubuntu Security Notice USN-2748-1

28th September, 2015

linux vulnerabilities

A security issue affects these releases of Ubuntu and its
derivatives:

  • Ubuntu 14.04 LTS

Summary

Several security issues were fixed in the kernel.

Software description

  • linux
    – Linux kernel

Details

Benjamin Randazzo discovered an information leak in the md (multiple
device) driver when the bitmap_info.file is disabled. A local privileged
attacker could use this to obtain sensitive information from the kernel.
(CVE-2015-5697)

Marc-André Lureau discovered that the vhost driver did not properly
release the userspace provided log file descriptor. A privileged attacker
could use this to cause a denial of service (resource exhaustion).
(CVE-2015-6252)

Update instructions

The problem can be corrected by updating your system to the following
package version:

Ubuntu 14.04 LTS:
linux-image-3.13.0-65-powerpc-e500

3.13.0-65.105
linux-image-3.13.0-65-powerpc64-smp

3.13.0-65.105
linux-image-3.13.0-65-powerpc-smp

3.13.0-65.105
linux-image-3.13.0-65-powerpc64-emb

3.13.0-65.105
linux-image-3.13.0-65-generic

3.13.0-65.105
linux-image-3.13.0-65-generic-lpae

3.13.0-65.105
linux-image-3.13.0-65-powerpc-e500mc

3.13.0-65.105
linux-image-3.13.0-65-lowlatency

3.13.0-65.105

To update your system, please follow these instructions:
https://wiki.ubuntu.com/Security/Upgrades.

After a standard system update you need to reboot your computer to make
all the necessary changes.

ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed. If
you use linux-restricted-modules, you have to update that package as
well to get modules which work with the new kernel version. Unless you
manually uninstalled the standard kernel metapackages (e.g. linux-generic,
linux-server, linux-powerpc), a standard system upgrade will automatically
perform this as well.

References

CVE-2015-5697,

CVE-2015-6252