Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Attacks/Breaches

Apple App Store Suffers Hack Attack

Company insists user data has not been compromised, but is nonetheless advising customers to watch for suspicious transactions.

Apple said Tuesday that it removed a seller from its online applications store after discovering that he gamed the store's sales ranking system to make it appear as though his e-books accounted for 42 of the site's top 50 electronics books.

Apple said the hack was carried about by a developer named Thuat Nguyen.

"His apps were removed from the App Store for violating the developer Program License Agreement, including fraudulent purchase patterns," Apple said in a statement.

The company did not provide details about how Nguyen managed to rig its sales data. Some observers are speculating that he merely manipulated sales figures, while others believe Nguyen may have actually gained access to App Store user accounts to make unauthorized purchases.

Nguyen listed his Web site as "mycompany", an Internet address that reportedly leads to a domain name parking page.

Apple insisted App Store or iTunes users' information is not at risk as a result of the incident. "Developers do not receive any iTunes confidential customer data when an app is downloaded," the company said.

Still, Apple cautioned its customers to be vigilant for suspicious transactions.

"If your credit card or iTunes password is stolen and used on iTunes we recommend that you contact your financial institution and inquire about cancelling the card and issuing a chargeback for any unauthorized transactions," Apple said.

"We also recommend that you change your iTunes account password immediately," Apple added. Investors shrugged off news about the breach. Apple shares were up .69%, to $248.65, in midday trading Tuesday.

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
COVID-19: Latest Security News & Commentary
Dark Reading Staff 5/22/2020
How an Industry Consortium Can Reinvent Security Solution Testing
Henry Harrison, Co-founder & Chief Technology Officer, Garrison,  5/21/2020
10 iOS Security Tips to Lock Down Your iPhone
Kelly Sheridan, Staff Editor, Dark Reading,  5/22/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: This comment is waiting for review by our moderators.
Current Issue
How Cybersecurity Incident Response Programs Work (and Why Some Don't)
This Tech Digest takes a look at the vital role cybersecurity incident response (IR) plays in managing cyber-risk within organizations. Download the Tech Digest today to find out how well-planned IR programs can detect intrusions, contain breaches, and help an organization restore normal operations.
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-5537
PUBLISHED: 2020-05-25
Cybozu Desktop for Windows 2.0.23 to 2.2.40 allows remote code execution via unspecified vectors.
CVE-2020-13438
PUBLISHED: 2020-05-24
ffjpeg through 2020-02-24 has an invalid read in jfif_encode in jfif.c.
CVE-2020-13439
PUBLISHED: 2020-05-24
ffjpeg through 2020-02-24 has a heap-based buffer over-read in jfif_decode in jfif.c.
CVE-2020-13440
PUBLISHED: 2020-05-24
ffjpeg through 2020-02-24 has an invalid write in bmp_load in bmp.c.
CVE-2020-13433
PUBLISHED: 2020-05-24
Jason2605 AdminPanel 4.0 allows SQL Injection via the editPlayer.php hidden parameter.