Google Search

Showing posts with label update. Show all posts
Showing posts with label update. Show all posts

Friday, August 23, 2013

Apple ships jolly uninteresting iOS 6.1.4 update

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Apple's operating system updates, even the point releases, usually have quite a lot going for them.

(A point release is when only the number after the rightmost dot, or point, in the version string changes.)

For example, when OS X 10.8.2 was superseded by 10.8.3, Apple patched 21 security vulnerabilities.

Eleven of these vulnerabilities offered the possibility of remote code execution (RCE) exploits.

RCE holes are what make drive-by downloads possible, where you may end up getting infected merely by looking at a website, reading an email or viewing a document.

And when iOS 6.1.3 came out, we recommended it because it closed the door on a lock-screen bug that allowed you unlock an iPhone 5 without the passcode.

Just over a month later, and Apple has shipped iOS 6.1.4.

This time, though, there don't seem to be any security fixes - not even for the lock-screen bug that was found in iOS 6.1.3, the update that fixed a lock-screen bug.

Note that this update is for the iPhone 5 only, so owners of iPods, iPads and earlier iPhones won't be getting anything.

By the way, even if you do have an iPhone 5 and apply the update, assume that the iOS 6.1.3 lock-screen bug persists.

With that in mind, let me repeat our advice from March.

Make sure voice dialling is turned off, since the bypass trick only works if it is turned on.

Mind you, does anyone still voluntarily use voice dialling?

Surely you gave it up after the first time this happened:

A: [gossiping in the car] You know that odious chap, don't you?

B: Who?

A: That bloke CALLed JOHNATHAN [*]

Mobile phone: [inaudible over car noise] Do you want to call Johnathan?

B: I know him, YES.

Mobile phone: [inaudible] Calling Johnathan

B: That guy who thinks butter wouldn't melt?

Jonathan: [tinny, inaudible] Hello, Johnathan here.

A: Well, let me tell you something you didn't know about JOHNATHAN.

Jonathan: [tinny, inaudible] Yes, this is Jonathan.

A: Are you listening, because this is juicy!

Jonathan: [tinny, inaudible] Go ahead.

Since the primary purpose of iOS 6.1.4 seems to be to improve speakerphone voice quality, there's one more reason to turn voice dialling off!

Follow @duckblog

[*] Name changed for security reasons.


View the original article here

Tuesday, March 26, 2013

Another Java update! Oracle brings Patch Tuesday forward to close in-the-wild hole...

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

I'll keep this one short, but I feel I ought to tell you.

"Yet another Java update! Get it while it's hot."

In calmer times, this update would have appeared on 19 February 2013.

Oracle's Critical Patch Updates for Java normally come out on the Tuesday closest to the 17th day in every fourth month. (Yes, I find that a little Byzantine, too.)

But Oracle brought its February 2013 Java patch forward, noting the "active exploitation 'in the wild' of one of the vulnerabilities affecting the Java Runtime Environment (JRE) in desktop browsers":

Oracle isn't saying which of the RCE (remote code execution) holes is the one that's actively being exploited, but bringing the patch forward is probably a good idea anyway.

According to the latest Oracle Risk Matrix there are 50 fixes, 49 of which might be remotely exploitable. That means merely visiting a web page might be enough to infect your computer.

The quick way to grab the latest version is to head over to Java.com and click the big red Free Java Download button.

That should work out your operating system and offer you the latest-and-greatest version. On my Mac, for example, I get this:

If you don't actually have Java installed, of course, you may not want to install it for the first time right now, but whether you're updating or installing for the first time, you need to remember that Java has two main functions on your computer:

1. Java lets you run applications that you install and download just like regular Windows or OS X software packages. Java applications don't run natively, so you need the Java system installed first.

There is no particular reason why a Java application puts your computer at any greater risk than an application based on Windows .EXE files or OS X native binaries.

Some Java applications you might have heard of are: Eclipse, a powerful IDE (integrated/interactive development environment) for programmers; Weka, a data mining and machine learning toolkit; and Tomcat, a web server platform.

2. Java lets you run applets that are delivered in web pages, directly into your browser. There's obviously a huge security risk here, so applets run in controlled environment called a sandbox to contain that risk.

The Java sandbox has suffered from numerous holes over the years. These have allowed malicious applets to escape from your browser and install malware on your computer without your knowledge or permission.

As a result, cybercrooks have especially targeted Java as a vehicle for infection. Java is inherently cross-browser and cross-platform, so attacking it is a high-yield exercise for the Bad Guys.

Ironically, however, browser-based software these days tends to use a mixture of JavaScript (which is not related to Java at all, despite the name), Flash and HTML5 to achieve the sort of results that would have needed Java a decade or more ago.

Fortunately, you can have Java installed so you can run applications, but shut the door on applets by disabling it in your browser.

Our recommendations are therefore simple:

Don't install any software you don't actually need or use. That includes Java.By all means, install Java if you want or need to. But keep it up-to-date.Turn Java support off in your browser, unless you are sure that you need it and cannot manage without it.

Some Naked Security readers who need Java applets, but only occasionally, install two browsers and enable Java support in one, but not the other.

This adds complexity, since there is more to update, but it means that simply by making the non-Java-enabled browser your default, you greatly reduce the risk of innocently ending up in harm's way when you spend time on the web.

The latest official updates are Java 7 Update 13 (the latest-and-greatest flavour), and Java 6 Update 39 (the previous version, still needed by some applications).

As I said, "Grab it while it's hot."

Follow @duckblog

Apple OS X 10.6 (Snow Leopard) users who have Apple's own version of Java should use Apple Menu | Software Update...

Confusingly, Apple's latest update is called Java for Mac OS X 10.6 Update 12.

The "6" refers to OS X 10.6, not to Java 6, and the "Update 12" refers to Apple's internal sequence numbering. It isn't one short of Oracle's Update 13.

Indeed, Apple's latest Update 12 takes OS X 10.6 users to Java 6 Update 39, if that doesn't leave you even more bewildered.


View the original article here

Monday, March 11, 2013

It's really important you update your Foxit PDF Reader, but unfortunately their website is down

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Foxit ReaderThere's something to be said for not going with the crowd, when it comes to securing your computer.

Just think about it - substantially more malware is written for Windows than there is for Mac or Linux.

Similarly, we see frequent attacks against the likes of Java, Adobe Flash and Adobe's Acrobat PDF reader because they are so widely used. The malicious attackers like it when the whole world is using the same software, as it increases their chances of a successful attack.

And for that reason, some people use alternative software - such as Foxit Software's PDF reader.

Foxit PDF reader

The thinking is that if online criminals exploit a security vulnerability in Adobe's PDF software, it may not be also present in the Foxit reader.

That doesn't mean, of course, that alternative software is immune from security vulnerabilities. As a case in point, a vulnerability was found in Foxit's browser plugin earlier this month.

No malware appeared in the wild that exploited the bug, but Naked Security's Paul Ducklin examined and explained the vulnerability in some detail. He wrote that "the [bug], which is a side-effect of a stack overflow, pretty much lets you write to a memory location of your choice. That's not good."

But there is good news now, namely that Foxit has responded to the vulnerability with an update.

You can either go to Help|Check for Updates in the Foxit reader software, or download the latest version (5.4.5) directly from Foxit's website.

When I tried, however, I couldn't reach Foxit's website to download the software:

Foxit Software's website is inaccessible

It's unclear quite what the problem is with Foxit Software's website, but hopefully they will be able to fix it soon for the benefit of their users. Of course, just because the website is down doesn't necessarily mean that updates requested from within the product are necessarily impacted.

(If you are having trouble getting the update, don't forget that Duck's article includes instructions for a simple mitigation you can use to tide you over.)

An advisory from Foxit is allegedly published here, but I can't get to it.

There's something to be said for not going with the crowd, when it comes to securing your computer.

But you best have your fingers crossed that your alternative providers' websites don't fall over when you need a security update.

Good luck to those of you who are Foxit users. Update as soon as you can.

Follow @gcluley

View the original article here

Thursday, March 7, 2013

Firefox update 18 gets an update, but no security problems this time

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Firefox users will probably notice that the recently-released version 18 has received a mini-update.

Mozilla's flagship product thus hits 18.0.1.

The good news is that the 21 security fixes that appeared in version 18 haven't needed any fixes of their own.

The new point release mops up three bugs, all of them no doubt annoying to those affected, but none of them security related.

The first fix is for a fault that could prevent automatic proxy configuration.

Proxies are widely deployed in the corporate world as a powerful web security tool. Instead of letting your browser fetch content directly from external websites, many organisations make you connect to a proxy server at the edge of the network instead. The proxy fetches the content, weeds out the dodgy or unwanted stuff, and passes on the rest.

If your browser can't find the right proxy to use, it probably won't be able to browse at all. So proxy autoconfiguration is vital in the business world. Not surprising that Mozilla fixed this fault fast.

The second fix sorts out a bug that can cause the Unity3D browser plugin to crash.

Unity is a games ecosystem, so this fix is much more important at home than at work.

Unless you work for a games company, of course.

The last fix deals with a problem in the newly-added support for Apple's super-high-resolution screens. If you had two screens, one of which wasn't hi-res, browser content could appear on the wrong one.

That's the lot.

It's nice to have a browser update that largely deals with cosmetics rather than patching against known vulnerabilities or in-the-wild exploits.

Having said that, the Unity-related bug was a crash in the strlen() function. Almost certainly not an exploitable crash, but it does sound like incorrect memory usage.

Might as well apply the fix, then, even if you are neither a corporate user nor a gamer.

Follow @duckblog


View the original article here

Tuesday, February 19, 2013

Oracle releases patch for latest Java hole - update now!

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

The big - no, the vast! the enormous! - security news over the weekend has been CVE-2013-0422.

That's the recent Java security hole that lets Java applets in your browser escape from Java's security strictures.

That means a Java applet (which is usually very limited in the sort of changes it can make to your PC) can infect your PC with malware without so much as a pop-up or an are-you-sure.

This vulnerability became a huge problem in short order because it was quickly included in exploit packs such as Cool EK and Nuclear Pack. Exploit packs are pre-packaged crimeware-as-a-service tools you can rent in order to have your malware distributed for you.

So here's some good news: Oracle has been on the ball and has already come out with a patch. Java 7 Update 11 fixes both CVE-2013-0422 and a second vulnerability.

Oracle's offical repository for the latest version is the Java Downloads for All Operating Systems page.

In the database behemoth's own words:

Due to the severity of these vulnerabilities, the public disclosure of technical details and the reported exploitation of CVE-2013-0422 "in the wild," Oracle strongly recommends that customers apply the updates provided by this Security Alert as soon as possible.

This update also changes the default Java Security Level setting from Medium to High.

As Oracle explains, at the High setting, you are "always prompted before any unsigned Java applet or Java Web Start application is run."

There's not an enormous amount to say about the patch beyond that. Fix early, fix often!

Note that the vulnerabilities Oracle just patched don't apply to standalone Java applications or server-side Java installs. They apply only to applets, which run inside your browser.

Your browser routinely and unavoidably puts you in harm's way, since it inevitably downloads and attempts to parse, process and display, untrusted content.

So, even after updating, I recommend that you turn Java off inside your browser unless you know you need it.

If there are only one or two specific sites for which you need Java, it can be a pain to keep remembering to turn it on, and it's easy to forget to turn it off again afterwards.

In such cases, you may want to consider running two browsers, one with Java enabled and one without.

Of course, if you do this, you need to keep both browsers patched - even (or perhaps especially, since it's the one with Java turned on) the one you only use infrequently.

By the way, if you do turn Java off in your browser, or think you did, it's worth checking.

A handy place to do so is Javatester.org, a web page that attempts to launch a tiny applet to get the answer "from the horse's mouth", as it puts it.

If you have Java turned off, it will confirm this for you.

If you have Java turned on, it will confirmation the precise version number from the Java Runtime Environment (JRE) itself. This means you can be sure you're running the version you expect.

And now? Stop reading, start patching!

Follow @duckblog


View the original article here

Tuesday, February 5, 2013

Java 7 update 10 introduces important new security controls

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Oracle only patches Java for security vulnerabilities three (?) times a year, but that doesn't mean it doesn't release other bug fix and feature releases of the nearly ubiquitous runtime environment.

Last week Oracle shipped Java 7 update 10 (Java 7u10), the latest in the Java 7 series, which includes new security controls in addition to a bug fix and updated timezone data.

What are these new controls?

Java control panelThe first one, my favourite, allows you to disable the Java web plugin by unchecking a single tick-box. After installing Java 7u10 you can open the Java control panel and uncheck the option "Enable Java content in the browser".

For users who have Java-based applications (like me!) disabling the web plugin eliminates most of the risk associated with having Java installed.

Java will also now check to see if it is at the latest security "baseline". What does that mean? Well, it means the latest Java version that was released with fixes for known vulnerabilities, which as of this posting is Java 7u9.

Oracle states:

If the JRE is deemed expired or insecure, additional security warnings are displayed. In most of these dialogs, the user has the option to block running the app, to continue running the app, or to go to java.com to download the latest release.

In my opinion that is a bit of a security fail. Don't allow users to choose options that will knowingly place them in harms way. As security professionals we have to stop expecting users to make important security decisions (browser certificate warnings anyone?).

Java 7u10 also introduces the concept of security levels. The default level is Medium which allows untrusted apps to run if your Java is patched, but will only allow signed applications to run if you are out of date.

This is a terrible default. In my opinion you should never run Java applications without notification and certainly should not run unsigned applications.

Even signed applications might not be safe if your Java is vulnerable. Fortunately there is a custom option that allows you to fine tune this behaviour.

Java control panel customize settingsYou can control whether to Run without prompt, Prompt user or Don't run for three different situations.

I prefer to disable Java in your browser entirely, but if you can't then I recommend Don't run for untrusted applications whether your Java is up to date or not.

For local applets the prompt user setting will alert you to the fact that something that uses Java is trying to run and provide an opportunity to block it if you aren't intentionally executing Java code.

I think it is great that Oracle is making Java more configurable and perhaps they will further strengthen the default settings in a future release. I recommend everyone update and choose the settings most appropriate for their environment.

System administrators should pay special attention to Oracle's release notes as there are command line options for Windows deployments to control these new settings. It would behoove you to lock them down as tightly as you dare.

Follow @chetwisniewski

View the original article here

Saturday, December 29, 2012

Microsoft pushes IE 9 tweak via Windows Update to close three critical security holes

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Internet Explorer 9Microsoft has reminded Internet Explorer users of the importance of keeping their browser updated against security threats.

Microsoft said on Thursday that it had pushed an update to its Internet Explorer Version 9 web browser through its Windows Update feature earlier in the week in an effort to quickly close three, critical security holes.

If unpatched and exploited by cybercriminals, the vulnerabilities could allow an attacker to use a webpage to install and run malicious code on vulnerable systems.

The company announced the release of IE Version 9.0.11 via Windows Update in a blog post, and advised users of IE 9 to apply it immediately.

The update fixes security holes associated with the recently released MS12-071 Security Bulletin.

The vulnerabilities affected the IE 9 browser running on every supported version of Windows. However, earlier versions of Internet Explorer were not affected, nor was IE 10, the latest version of Microsoft's popular web browser.

Microsoft blog post

Microsoft has described the security vulnerabilities as caused by a flaw in the way that IE 9 accesses an object that has been deleted or not correctly initialized. It affects three Internet Explorer components, named CFormElement, CTreePos and CTreeNode.

Attackers could exploit the so-called "use after free" vulnerabilities using a variety of techniques: websites, malicious ActiveX controls embedded in an application or Office document or malicious advertisements displayed on legitimate sites.

Attacks would still require users to click on the malicious content, and the attackers would be limited by the victim's permission levels on his or her own machine.

As we noted in our coverage of the November Patch Tuesday release, "use after free" bugs happen when software gives back memory to the operating system in order to free up resources it no longer needs, but then carries on using that memory anyway.

The update closes the security holes. Microsoft said that most IE9 users will get the upgrade automatically using Microsoft's Automatic Update feature. (A description of how to configure automatic updates can be found in a Microsoft knowledgebase article.)

Those who haven't enabled the Auto Update feature were advised to use the Microsoft Update service to download and install it.

The IE 9 update was released on Tuesday, one of six security bulletins released with Microsoft's monthly security patch release.

Follow @PaulFRoberts
Follow @NakedSecurity


View the original article here

Tuesday, June 19, 2012

Flame malware used man-in-the-middle attack against Windows Update

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Microsoft update revoking Flame compromised certificatesMicrosoft has released an emergency update for all versions of Windows to address a certificate flaw that was used to spread the Flame malware from machine to machine.

Of course you have to trust that your connection to Windows Update is not being attacked while you're retrieving the update that prevents you from being attacked.

This is not the first time we have seen malware abusing digital certificates, but this one is a bit more advanced than previous attacks.

What happened? The Flame malware needed a way to silently infect machines in the target environment, without making the mistake of spreading where it shouldn't like Stuxnet did.

Flame-infected computers can be instructed to impersonate a Web Proxy Autodiscovery Protocol (WPAD) server. Windows machines set for automatic proxy detection (the default) will try to contact a server called wpad.(company domain name) to check for instructions for when to use a HTTP proxy.

Windows Update logoFlame would tell machines on the network that the infected computer was to be used for proxying requests to Microsoft's Windows Update service. Ordinarily this would not work, as Microsoft signs updates with their special digital certificates to ensure you only receive updates that are tamper proof.

But the Flame authors had discovered a critical flaw in Microsoft's certificate infrastructure. The Microsoft Terminal Server Licensing service is used for license management and authorization in many enterprise environments. Microsoft had been mistakenly issuing certificates for use on these servers that could be used to digitally sign code.

Flame appears to have used one of these certificates to sign its payload and perform a man-in-the-middle attack to inject it onto additional machines on the same network. It isn't clear whether it was a certificate obtained legitimately from Microsoft or whether weak ciphers were targeted.

Two of the three certificates Microsoft revoked in this update used the MD5 hashing scheme. It has been demonstrated in the past that MD5 is prone to collisions, which may have also aided the Flame authors in successfully making it look like the malware was from Microsoft.

Managing encryption, ciphers and digital signatures is no easy task and a simple mistake like Microsoft accidentally issuing certificates that can be used to sign code using outdated ciphers is enough to put everyone at risk.

The idea of someone with malicious intent impersonating Windows Update has been discussed for years in the security community. It is sort of a nightmare scenario and I suppose it is good news that it was being used in such a limited way.

Few computers were compromised using this malware compared to the impact we would see if traditional opportunistic malware exploited this flaw. Fortunately the average user will now be protected from this attack moving forward.

These certificates can also be used for signing software for Microsoft's Windows Mobile and Windows Phone 7 devices, but no patch is available as of yet.

I think a friend of mine in the local Vancouver security community put it best: "Maybe 'Genuine Microsoft Advantage' should check the *other* side of the transaction?"

http://twitter.com/chetwisniewski

View the original article here

Sunday, April 22, 2012

Apple pumps out yet another Java update

Over 100,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Apple has delivered - or so it says - on its promise to provide a Flashback malware removal tool.

The new update is packaged in two flavours:

* Java for Mac OS X 10.6 Update 8, documented in HT5243.

* Java for OS X Lion 2012-003, documented in HT5242.

Both updates claim that "this Java security update removes the most common variants of the Flashback malware. "

The one for Lion goes a little further:

This update also configures the Java web plug-in to disable the automatic execution of Java applets. Users may re-enable automatic execution of Java applets using the Java Preferences application. If the Java web plug-in detects that no applets have been run for an extended period of time it will again disable Java applets.

The updates also include the latest Java version all over again, 1.6.0_31.

So if you missed the previous update, jumping to this one will effectively patch against Exp/20120507-A and fix problems with the Flashback malware (e.g. OSX/Flshplyr-D) in one go.

If you're using Snow Leopard, disabling Java in your browser won't happen automatically. It looks as though the Java applet autodisabler is Lion-only.

I'd love to tell you more about the Flashback remover supplied by Apple, but I'm afraid I don't know how.

There's no documentation about it; there's no information about how to run it by hand in the future, or how it works, or what variants of the malware it finds; and - at least on my uninfected 10.6 computer - it didn't give any visual indication that it had run at all. (Three words for Apple about security bulletins: promptness, clarity and openness.)

(Update. HT5247 has a bit more story about the removal tool. It's documented to say nothing if it finds nothing. Thanks to François for pointing this out.)

Also, of course, it won't protect you against reinfection, and it won't protect you against any other Mac malware.

So there you have it. Apple's Java distribution and the Flashback malware addressed in one go. Unless you have OS X Leopard (10.5) or earlier. If you do, you're still out of luck - no patches for you.

Follow @duckblog
-

PS. See how I resisted the urge to mention the free Sophos Anti-Virus for Mac Home Edition, complete with detection, prevention and remediation of Flashback and heaps of other malware, at any point in the above article :-)


View the original article here

Saturday, October 1, 2011

Flashback Mac Trojan poses as Adobe Flash update, opens backdoor

Over 100,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Mac users are once again being reminded to keep their anti-virus software up-to-date, following the discovery of a Trojan horse that poses as an update to Adobe Flash.

The OSX/Flshplyr-A Trojan horse (called "Flashback" by our friends at Intego, who first publicised it), is disguised as an installer for the popular Adobe Flash program.

Mac backdoor Trojan

Once in place, Trojan horse could allow a remote hacker to gain access to your computer or download further malicious code to your Mac.

Sophos products, including Sophos's free anti-virus for Mac home users, detects the Flashback malware as OSX/FlshPlyr-A.

Sophos Anti-Virus detecting the Mac malware

It's easy to imagine how cybercriminals could trick Mac users into infecting their computers with this malware.

For instance, it would be child's play to create a website which pretends to show something salacious ("Scarlett Johansson nude video!" would probably do well at the moment, for instance) and then when you try to view it, you're prompted to install an update to Adobe Flash. Of course, rather than the genuine Flash you would be installing the Trojan horse.

Similar tricks have certainly worked well in the past - against both Windows and Mac users.

Here's a video of another malware attack that tripped up Mac and Windows users, by duping them into installing a fake update to watch a sex movie of Leighton Meester:


(Enjoy this video? You can check out more on the SophosLabs YouTube channel and subscribe if you like)

Maybe now you can see just how easy it is for some folks to fall for this kind of trick. This is just one example of if happening in real life, there have been plenty of others.

Flashback is just the latest example of Mac malware follows hot on the heels of another Trojan horse for the OS X platform. The OSX/Revir-B Trojan was discovered, displaying a political hot potato of a PDF as a distraction while it did its dirty work.

We all know that there is much much more malware written for Windows than there is for Mac OS X. But that doesn't mean it's non-existent, and it's no excuse for leaving Apple Macs unprotected.

Sophos Anti-Virus for Mac Home Edition is fully-functioning and free for home use. What have you got to lose?

Follow @gcluley

View the original article here