| By Maureen O'Gara | Article Rating: |
|
| February 20, 2013 08:45 AM EST | Reads: |
2,039 |
Tuesday when a report by American security firm Mandiant that's been six years in the making was circulating tracing an "overwhelming percentage" of Communist China's far-flung corporate and governmental cyber espionage to a 12-story building in Shanghai connected with the People's Liberation Army know as PLA 61398, the usually secure Apple disclosed that its Macs had been hacked and infected with malware by bad guys leveraging the known vulnerabilities that Oracle doesn't seen to be able to eradicate from the Java software used as a browser plug-in.
Facebook last Friday confessed to experiencing the same infestation.

The Apple hack hit a "small number" of internal Macs belonging to Apple developers who visited a developer site purposely infected with malicious code designed specifically to attack Macs.
It also attacked Mac computers at corporate accounts outside the company.
Reuters, which described it as the "highest-profile cyber attack to date on businesses running Mac computers," said it attacked "hundreds of companies including defense contractors."
It is unclear if the Apple and Facebook attacks had anything to do with Building 61398 although there have been reports that the Facebook attack on some laptops on its network traced back to China.
Both companies have denied any data loss. Law enforcement has been called in. When last heard from Apple was working on some repair code. The Mac OS disables Java if it hasn't been used for 35 days.
Meanwhile, besides its 60-page report Mandiant has released a video that's supposed to show actual attacks. The New York Times, which suffered a weeks-long secret attack a couple of weeks ago along with the Wall Street Journal and the Washington Post, ran a big story about the Mandiant report, which concludes that the attacks are government-sponsored and stealing US, Canadian and UK IP.
President Barak Obama just signed an executive order encouraging companies to share confidential information such as hackers' unique signatures with intelligence agencies.
Published February 20, 2013 Reads 2,039
Copyright © 2013 SYS-CON Media, Inc. — All Rights Reserved.
Syndicated stories and blog feeds, all rights reserved by the author.
More Stories By Maureen O'Gara
Maureen O'Gara the most read technology reporter for the past 20 years, is the Cloud Computing and Virtualization News Desk editor of SYS-CON Media. She is the publisher of famous "Billygrams" and the editor-in-chief of "Client/Server News" for more than a decade. One of the most respected technology reporters in the business, Maureen can be reached by email at maureen(at)sys-con.com or paperboy(at)g2news.com, and by phone at 516 759-7025. Twitter: @MaureenOGara
- Cloud Expo New York | Danger Ahead: Why File Sync Is NOT Endpoint Backup
- Session Topics: 12th Cloud Expo / Cloud Expo New York
- Cloud Expo New York: Aligning Your Cloud Security with the Business
- Overview of the OpenStack Cloud
- Cloud Expo NY: Best Practices for Architecting Your Cloud Infrastructure
- Cloud Expo New York: Managing Legal Risks in Cloud Computing
- Cloud Expo NY: Environmental Pressures Drive an Evolution in File Storage
- Is Cloud Safer Than Your Traditional Datacenter?
- Apple’s Key Rubber-Band Patent Found Invalid Again
- Cloud Expo NY: Accelerating Cloud Computing with Intel SSD Technology
- NIST to Sponsor FFRDC Widespread Adoption of Integrated CyberSecurity
- Cloud Expo New York: Anatomy of an Internet Scale Application
- Cloud Expo New York Speaker Profile: Jill T. Singer – NRO
- Cloud Expo New York | CEO Insider: Overcoming Cloud Barriers
- Cloud Expo New York | Danger Ahead: Why File Sync Is NOT Endpoint Backup
- SAML Finds Its Cloud Legs
- Session Topics: 12th Cloud Expo / Cloud Expo New York
- Cloud Expo New York: Aligning Your Cloud Security with the Business
- Overview of the OpenStack Cloud
- Cloud Expo NY: Best Practices for Architecting Your Cloud Infrastructure
- Cloud Expo New York: Managing Legal Risks in Cloud Computing
- Five Steps Toward Achieving Better Compliance with Identity Analytics
- Cloud Expo NY: The Promise of an End-to-End SDN Solution - Can It Be Done?
- Guest Post: Typical CIO Conversation
- Effective Page Authorization In JavaServer Faces
- The Top 250 Players in the Cloud Computing Ecosystem
- Cloud Expo New York Call for Papers Now Open
- SOA Focus - Web Services Security in Java EE
- IBM Security Report Predicts Mobile/Satellite Attacks in 2005
- Industry Experts Discuss the State of Cloud Computing
- The Cloud Computing Kettle Heats Right Up
- The Top 100 Bloggers on Cloud Computing
- The Next Chapter in the Virtualization Story Begins
- Java Application Security in the Corporate World
- ColdFusion Security Best Practices
- Cloud Expo 2011 East To Attract 10,000 Delegates and 200 Exhibitors
























