Apple product owners have long taken pride in the fact that their devices are free from viruses and malware. However, this may soon all change as a recent research done by Palo Alto Networks indicate that a new form of malware called “Wirelurker” have been found to be capable of attacking Mac OS and iOS systems.


According to the report, the malware is capable of automatically generating malicious iOS applications through binary file replacement and is the first known malware that can infect even non-jailbroken devices.

The malware was first observed 6 months ago and is believed to be contracted through third-party Mac and IOS application stores from China and has so far infected 467 applications that were downloaded over 300,000 times.

Wirelurker monitors any iOS device connected via USB with an infected Mac computer and installs downloaded third-party apps or automatically generates applications into the device. But other than installing apps into the device, Wirelurker is also capable of stealing information stored on devices including financial data.

The Palo Alto Networks team says the malware is still under active development and recommends iOS and Mac users to observe certain actions in order to avoid infection. These include employing an antivirus of security protection on their Mac OS X system, avoiding apps from third-party sources and avoiding connecting their device with untrusted or unknown sources.

Connect with The Techie Lifestyle on your favorite social networking sites

Twitter Facebook Pinterest Subscribe to RSS Feeds Google Plus Follow via Email

Twitter-owned Tweetdeck experienced a massive technical issue today as the platform experienced an XSS (cross site scripting) security flaw that enabled hackers to access users’ account and remotely access or implant JavaScript code.


So far, the hackers were able to add annoying pop-ups on a user’s Twitter feed or automatically tweet or retweet from a hacked account. Twitter has then advised users who were affected by the issue to log in and log out of Tweetdeck and check if the issue persists.

Unfortunately, there are still reports from users that the problem hasn’t been fixed. Twitter has momentarily taken down Tweetdeck in order to “assess” the security breach. A few hours after, the social networking site has issued a security fix and re-activated Tweetdeck for all users and issued an apologetic tweet.

Connect with The Techie Lifestyle on your favorite social networking sites

Twitter Facebook Pinterest Subscribe to RSS Feeds Google Plus Follow via Email


Facebook has been under the spotlight in terms of security issues these past few weeks due to the company’s alleged involvement in the NSA’s Project Prism. And although the company has explicitly denied such allegations, a recent security bug discovered on its website may have caused some doubts on whether or not the social giant has a backdoor access for the NSA or other US government agencies to sneak into.

Just this weekend, a security bug on Facebook has exposed account information (email and phone number) of some 6 million users to other people who were connected to them.

According to Facebook’s security team, the social network checks uploaded contact lists and address books of users in order to make friend recommendations. The problem caused by the bug was that some uploaded information (email addresses and phone numbers) were inadvertently saved to other people’s profile. So in case a person downloaded an archive of their account through the company’s Download Your Information tool, that person may get the additional information from people who are in his network.
Moreover, there was also information from non-Facebook users included in the download from tools that invite contacts to join Facebook. A Facebook representative has admitted that the bug has been on the website since last year, but it was only discovered last week. The company has also said that the bug has not been exploited maliciously and the company is reaching out to the affected users.

The social giant has also added that the exposed information wasn’t tied to any Facebook accounts in particular and wasn’t structured nor was it identifiable. Furthermore, each individual email address or telephone number was only included in a download once or twice so the information was only exposed to one person. And lastly, no other types of personal of financial information were included and only people on Facebook have access to the DYI tool.
For those affected by the bug, Facebook has already issued warning emails to users whose personal information have been compromised 
Connect with The Techie Lifestyle on your favorite social networking sites

Twitter Facebook Pinterest Subscribe to RSS Feeds Google Plus Follow via Email

One of the problems that have long plagued popular platforms in history is its susceptibility to threats and attacks. In the computer industry, Microsoft’s Windows, being the dominant operating system in the market for the past few years have faced numerous viruses, Trojans, bugs and malwares in contrast to Apple’s Mac OS or Linux.

And if that’s not enough, the threat of malicious software is even greater if the platform in question is of the open source nature. And this is exactly what happened to Google’s Play Store, Android’s digital application distribution platform.


Yesterday, mobile security firm Lookout announced that they have discovered a new family of malware distributed over the Google Play store. The bug which was fittingly named as “BadNews” appears to have been distributed as an ad framework for developers. Hence, it is unclear how many of the infected apps were made to specifically carry the bug for malicious reasons and how many were just tricked into putting it into their codes.

There were a total of 32 applications from four separate developer accounts that had the malware, most of which were questionable Russian clone apps. And since Google Play only gives download data in ranges, it’s also hard to determine exactly how many devices were affected. But base on the number of installs of the 32 known applications, an estimated 2-9 million devices might have been affected.

The BadNews bug has been known to do two things. First, it fakes alerts encouraging users to download other infected apps, including an app called AlphaSMS that hijacks a user’s phone and silently signs it up for premium SMS services. The malware can also send user information such as phone number and IMEI to the malware’s server.

Google has already removed the 32 applications from Google Play. As for those affected by the bug, there were no resolution given on how to reverse any damages done to a device but Lookout encourages users to disable the “Install from Unknown Sources” option in their phones and tablets and install a mobile security app as a first line of defense.

Any thoughts about this recent development in the Android scene? Share with us your thoughts be leaving a comment below.

Connect with The Techie Lifestyle on your favorite social networking sites

2013-2015 © The Techie Lifestyle
Planer theme
Powered by Jasper Roberts Consulting - Widget