Apple hit by sophisticated cyberattack

Feb. 20: Cyberattacks, apparently, happen in threes.

After Facebook and Twitter announced that they were breached by sophisticated hackers in recent weeks, Apple said it had been attacked, too, in a rare admission for the technology giant.

In a statement to reporters yesterday, Apple said some of its computers were infected with the same malware that hit Twitter and Facebook. Like Facebook, Apple confirmed that its employees' computers were infected with malware when they visited a website for software developers.

Neither company has named the website. But according to a person with knowledge of Facebook's investigation, the compromised site, iPhonedevsdk, an online forum for software developers, is still infected. (In other words, unless you want to be owned by hackers, do not visit the site.)

"We identified a small number of systems within Apple that were infected and isolated them from our network," Apple said in a statement. "There is no evidence that any data left Apple. We are working closely with law enforcement to find the source of the malware."

Twitter said attackers may have briefly gained access to data for 250,000 user accounts and that it reset passwords for and alerted users whose data may have been vulnerable. Facebook said that no user data was taken in its attack. Both companies said that they were also working with law enforcement to trace the source of the attacks, which they described only as "sophisticated".

In all three cases, the attackers exploited a well-known security hole in Oracle's Java software. Java, a widely used programming language, is installed on more than three billion devices. It has long been hounded by security problems.

Last month, after a French security researcher and blogger named Kafeine exposed a serious vulnerability in the software, the department of homeland security issued a rare alert that warned users to disable Java on their computers. The vulnerability was particularly disconcerting because it let attackers download a malicious program onto its victims' machines without any prompting. Users did not even have to click on a malicious link, they only had to visit an infected site for their computers to get infected.

After Oracle initially patched the security hole in January, the department of homeland security said that the fix was not sufficient and recommended that, unless it was "absolutely necessary" to use Java, users should disable it on their computers completely. Oracle did not issue another fix until February 1.

Apple said yesterday that it was releasing an updated Java malware removal tool that will check Macs for malware and remove it if found.

But security researchers say the Java exploit only gave hackers a foothold into these companies' systems, and that the companies should be more forthcoming with what the attackers did once inside.

"Why is nobody asking what the payload is?" Sean Sullivan, a security adviser at the Finnish antivirus company F-Secure tweeted. "The Java exploit only opened the door. What walked in?" Social networks are a prime target for hackers, who look to use people's personal data and particularly their social connections in what are known as "spearphishing" attacks.

In this type of attack, a victim is sent an email, ostensibly from someone they know on Facebook or other social networking site, containing a malicious link or attachment.

Once the link is clicked or attachment opened, attackers take control of a user's computer. If the infected computer is inside a company's system, the attackers are able to gain a foothold. In many cases, they then extract passwords and gain access to sensitive data.

In an article published on Monday evening, The New York Times reported that one group of Chinese cyberattackers, which has been tied to a specific military unit of China's People's Liberation Army, leveraged the social connections of its targets to send malicious emails that eventually allowed them to compromise thousands of organisations, ranging from Coca-Cola to the International Olympic Committee.

Hackers have been attacking organisations inside the US at an alarming rate. The number of attacks reported by government agencies last year topped 48,500 ' a ninefold jump from the 5,500 attacks reported in 2006, according to the Government Accountability Office.

Matches

MORE TOP STORIES TODAY

Inspired England choke South Africa

Inspired England choke South Africa

Champions Trophy: Hosts thrash South Africa by seven wickets at The Oval. More »

Angelo Mathews has plans for India

Angelo Mathews has plans for India

Sri Lanka and India ready themselves for semifinal. More »

[SPECIAL] Is history repeating itself?

[SPECIAL] Is history repeating itself?

[ODDBALL THEORIES] Startling similarities connect India’s twin ODI triumphs of 1983 and 1985 with their performances in the 2011 World Cup and 2013 Champions… More »

India vs Sri Lanka: The road to Champions Trophy semis

How India and Sri Lanka reached the last four to set up a repeat of the 2011 World Cup final.ALSO READ: Resurgent India impress Jayawardene More »

Resurgent India impress Jayawardene

Resurgent India impress Jayawardene

Sri Lanka's Mahela Jayawardene is under no illusions about the scale of the task confronting his side when they face India in a Champions Trophy semi-… More »

Dalmiya or Srini, song remains the same on DRS

Dalmiya or Srini, song remains the same on DRS

After much speculation, the cricket board will decide on Thursday who will represent BCCI at International Cricket Council's annual conference from June… More »

The secret behind Dhoni's massive sixes

The secret behind Dhoni's massive sixes

Watching MS Dhoni hit sixes is a visual delight that touches a chord at a primeval level. It's instinctive, it's visceral. More »

Pakistan court orders interim board chief

Pakistan court orders interim board chief

KARACHI, June 19, 2013 (AFP) - A Pakistani court Wednesday ordered the government to appoint an interim head of the cricket board, after the current chairman… More »

Ahmed, Sandhu in Australia A tour of Africa

Ahmed, Sandhu in Australia A tour of Africa

Pakistan-born leg-spinner Fawad Ahmed was Wednesday named on the Australia A squad for a tour of Africa beginning next month, despite also being in contention… More »

Whatmore eyes WC after Pak flop

Whatmore eyes WC after Pak flop

The former Australian batsman turned coach rejected the suggestion his players lacked in effort. More »

Cummins set for return to action

Cummins set for return to action

Rising Australia fast bowling hope Pat Cummins is to make an unusual return to action from injury by playing for the Northern Ireland Cricket Academy on… More »

Lankans ready for another tough match

Lankans ready for another tough match

Sri Lanka barged into the Champions Trophy semi-finals with a 20-run victory over holders Australia. More »

Hughes and Wade join Aus A side

Hughes and Wade join Aus A side

Australia said on Tuesday that captain Michael Clarke will stay in London as he recovers from a back problem. More »

Don't write off Aussies, says Inverarity

Don't write off Aussies, says Inverarity

Australia's chairman of selectors has told England now is not the time to dismiss his side's chances of regaining the Ashes, despite the controversy currently… More »

I am 'happy to be alive': Harbhajan

I am 'happy to be alive': Harbhajan

Harbhajan Singh, who was amongst the many pilgrims and tourists stranded in the upper reaches of Uttarakhand due to the landslides and heavy rains, on… More »

Bhuvneshwar Kumar: Swinging in the rain

Bhuvneshwar Kumar: Swinging in the rain

Cardiff, June 17 -- Swing bowling is a complex science and not an absolute one. The basics are simple enough.Swing occurs due to the uneven distribution… More »

[RUN MACHINES] Mahela passes Dravid on way to 11,000th run

The Sri Lankan became the eighth man to pass 11,000 runs in one-day internationals. More »

Inverarity: Fawad Ahmed is a lovely lad

Inverarity: Fawad Ahmed is a lovely lad

LONDON, June 17, 2013 (AFP) - John Inverarity, Australia's chairman of selectors, indicated Monday that Pakistan-born leg-spinner Fawad Ahmed could yet… More »

Hesson laments NZ's failure to grab chances

Hesson laments NZ's failure to grab chances

The New Zealand coach rued the Black Caps' exit from the Champions Trophy. More »

Chandila sent to 3-day police custody

Chandila sent to 3-day police custody

Police sought fresh custody of Chandila saying he was required to corroborate evidence collected from other accused after invoking the stringent MCOCA… More »

Abdullah objects to IMG faux pas

Abdullah objects to IMG faux pas

Senior Union Minister Farooq Abdullah on Monday strongly objected to a prominent sports management company unilaterally altering the map of Jammu and Kashmir… More »

The prodigal son

The prodigal son

If Sreesanth did what he is accused of, it is doubtful he realised he was doing something wrong. More »

Who'll watch the administrators?

Who'll watch the administrators?

It's rich to accuse players of being selfish when administrators seem concerned solely with the bottom line. More »

BCCI using fixing video to warn juniors

BCCI using fixing video to warn juniors

With spot-fixing under the scanner in India, the cricket Board is showing video clips of the scandal involving Aamer to educate its under-19 and under-25… More »