All the latest UK technology news, reviews and analysis

A week in security: Apple releases slew of fixes

by Phil Muncaster

20 Jun 2010

Be the first to comment

  • Tweet this
Apple
Apple has fixed a number of vulnerabilities in its products

While most of the week’s news has been focused on the forthcoming iPhone 4, in the security space it has been a relatively quiet seven days, with Apple issuing more updates and yet more Facebook click-jacking woes.

First up, UK security firm Veritape released a new device which it claimed can help protect banks and consumers from credit card fraud committed through call centres.

The company said that CallGuard could save hundreds of millions of pounds a year by limiting so-called "audio data thefts" which involve the eavesdropping and analysis of recorded phone calls which contain personal and banking information.

Next up, more click-jacking on Facebook. Security vendor Sophos warned that the scam spreads through the site's news feed and 'Like' feature. The attack appears as a link to a web page offering photos of the '101 hottest women in the world.' The link presents a page which, when clicked, forwards the victim to a third-party site, and accesses their news feed without notification.

Apple, meanwhile, posted security updates for Mac OS X and iTunes. The OS X update covers flaws in 10.5 Leopard and 10.6 Snow Leopard.

The fixes will be released as an Apple security update for Leopard users, while Snow Leopard users will get the updates as part of the OS X 10.6.4 update. The update includes 23 fixes for security issues in the operating system, including flaws which can allow remote code execution, man-in-the-middle attacks and elevation of privileges.

It was a good week for RIM, with the revelation that government ministers have been told that Apple's iPhone is not approved as a work device, because of security concerns, although BlackBerry smartphones have been sanctioned for official use.

The iPad AT&T breach rumbled on this week with one of the researchers connected to the case arrested following a police raid. The FBI conducted a search of the home of Andrew 'Escher' Auernheimer, a member of the Goatse Security group. The 24 year-old was arrested for possession of drugs, including cocaine, LSD and ecstasy.

Finally, a new report from consultancy PwC this week found that a company's employees are its best defence against security threats, and should be empowered and educated about technology risk. The consulting firm said in its Protecting your Business report that organisations are too complacent about security, and assume that they will not be affected.

Do you agree?

 

Add your comment

We won't publish your address
By submitting a comment you agree to abide by our Terms & Conditions. Your comment will be moderated before publication.

Poll

Flame virus poll

Are you confident that the UK's IT infrastructure is secure from attack in the wake of the Flame malware revelations?

25%

1%

12%

62%

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

Riso

Colour printing: why the bill keeps outstripping the budget

The wrong printers, for the wrong tasks on the wrong contracts

Qlikview

Magic quadrant for business intelligence platforms

Who leads the BI pack and who should we be watching out for?

X2 PMO lead, Investment Banking, London up to £495 per day

X2 PMO lead, Investment Banking, London up to £495 per...

SEO analyst - Retail ecommerce - Hertfordshire. £35-55k

SEO analyst - Retail E-commerce - c35-55k - Hertfordshire...

ICT Technician

ICT Technician Leicester £10,000 per annum...

Oracle Performance Tuning, Oracle, Engineering

Oracle Performance Tuning, Oracle, Tuning, Engineering...

To send to more than one email address, simply separate each address with a comma.