Two new Mac exploits recently discovered are good reminders of best practices to stay safe, such as not let foreigners access your computer, stay up to date with software updates and get your software from known sources of trust.
The first feat implies parallels, the virtual machine which allows the Mac to carry out Windows, Linux and older MacOS versions. The vulnerability is on the Mac Intel running parallels and allows an attacker to obtain root access by using holes in the parallel VM creation routine. The striker must however have access to the Mac to perform this.
The researcher Mickey Jin decided to publish on the vulnerability which was reported to parallels seven months ago, in order to bring the company to issue a fix. Parallels published an article from KnowledgeBase on the fault, declaring that the parallel office 20.2.2 and the parallel office 19.4.2, which will include fixes, will be issued during this week. Apple silicon macs are not affected.
The other new feat, reported by the Proofpoint security company, implies a new malicious software called Frigidstealer. The attack occurs when a user receives an email containing an URL, and when the user opens it, a web page launches with an alert indicating that the browser must be updated. When the update button is clicked, an installation program is saved on the Mac and the user is invited to open it by clicking on the application icon and selecting Open from the context menu. Opening the file in this way Gatekeeper, the integrated security of macOS which checks malware. This then installs malware.
The malicious attacks of Frigidstealer targeted users outside of North America. If it is installed, it records information and files related to passwords, browser cookie data and everything that is created in Apple notes.
How to protect yourself
The easiest way to protect yourself from malware is to avoid downloading software from benchmarks such as Github and other download sites. Apple has checked software in the Mac App Store and is the safest way to get applications. If you prefer not to frequent the Mac App Store, buy software directly from the developer and their website. If you emphasize the use of Cracked software, you will always risk exposure to malware.
Never open the links in emails or SMS that you receive from unknown and unexpected sources. If you receive a message that seems to come from an entity with which you do business, see the sender's email address and carefully inspect the URL. If you see a link or button, you can control it, select Copy the link, then paste it in a text editor to see the real URL and check it.
Apple publishes security fixes via updates to the operating system, therefore installing them as soon as possible is important. It is also important to update applications on your Mac, which you can do via the App Store or via the application settings. igamesnews has several guides to help, including a guide on the question of knowing if you need antivirus software, a list of Mac virus, malware and Trojan horses, and a comparison of Mac security software.



