So I turned on my MacBook this morning, went to grab coffee, and came back to a Software Update notification I almost dismissed without reading. Glad I didn't, because it turned out to be Apple quietly patching up the Flashback mess. If you havent been following this, back at the start of the month a Russian antivirus outfit called Doctor Web said something like 600,000 Macs were infected with this Flashback trojan thing, just sitting there in botnets, and a decent chunk of those were apparently in the US. Yesterday Apple finally shipped a Java update that scrubs the common variants off your machine and, more importantly, turns off the thing that let it spread in the first place: Java applets running automatically in the browser without you clicking anything.
Im not going to pretend I fully understand the exploit chain here, something about an unpatched Java vulnerability that Oracle had already fixed months earlier and Apple just hadnt gotten around to pushing out on their end. But the headline is simple enough. Youd go to some compromised WordPress site, a bit of Java would run in the background, and boom, your Mac is part of a botnet and you never saw a popup or a warning or anything. No download-and-click-yes-to-install moment, which is usually the part people blame when they get infected with stuff on Windows.
Ive been running Macs since 2009 and Ill admit Id gotten a little smug about the whole "Macs dont get viruses" thing, not because I actually believed it in some technical sense but because in practice nothing had ever really hit me. This is the first time Ive felt like maybe I should actually run something to check my own machine instead of just trusting the marketing. I ran the update, then also grabbed one of those free detection tools going around just to double check, and thankfully came up clean. But it was a weirdly uncomfortable ten minutes waiting for it to scan.
What bugs me is how long the gap was. Oracle patched their Java vulnerability back in February. Apple doesnt let you install Java updates straight from Oracle though, they insist on repackaging it and pushing it through their own Software Update channel, which means every Mac user was sitting exposed for weeks while Apple did whatever internal process they do. I get wanting control over your own platform. I do not get sitting on a known hole for that long while the exploit is actively being used in the wild. If youre going to insist on being the gatekeeper for Java updates you kind of have to actually be fast about it.
Anyway, in a weird bit of timing, this all happened in the same week Facebook announced they're buying Instagram for something like a billion dollars, which is a wild number for a company that as far as I can tell has something like thirteen people working there. I dont have a ton to say about the deal itself except that a billion dollars for an app that puts a fake vintage filter on your lunch photos still doesnt sit right with me, no matter how many times I hear "it's about mobile, it's about the users, it's about where things are headed." Maybe Im just cranky about the malware thing and taking it out on an unrelated story, thats entirely possible.
If you havent run Software Update yet today, go do it. It downloads a decent-sized Java package, something around 70MB if I remember what I saw, so dont start it right before you need to hop on a call. And if youre one of those people running a five year old MacBook without ever touching Software Update because "it just works," this is exactly the kind of week that should change your mind about that habit. Mine's staying on for the rest of the afternoon just running updates in the background while I catch up on some reading.