Tech
Apple Warns of Two macOS Zero-Day Vulnerabilities
Apple has issued a critical security advisory after uncovering and addressing two Mac-OS zero-day vulnerabilities actively exploited in the wild. The vulnerabilities, identified as CVE-2024-44308 and CVE-2024-44309, affect macOS Sequoia and were patched in the latest update, macOS Sequoia version 15.1.1. These exploits underscore the growing cybersecurity threats targeting macOS devices, particularly as their adoption in corporate and personal environments continues to rise.
The vulnerabilities were discovered by Clément Lecigne and Benoît Sevens, researchers from Google’s Threat Analysis Group (TAG). Apple has credited them for their role in identifying these flaws, which highlight a growing trend of threat actors focusing on macOS as a target for sophisticated attacks.
The Mac-OS zero-day Exploitation
What Are the macOS Sequoia Vulnerabilities?
Apple has described the two vulnerabilities and their potential impact:
- CVE-2024-44308: This vulnerability resides in JavaScriptCore, the engine that powers web content in macOS. Exploitation of this flaw allows arbitrary code execution, enabling attackers to take control of an affected system. The exploit is triggered when a user interacts with a malicious webpage, making this a particularly dangerous vulnerability for users who browse the web without additional protections.
- CVE-2024-44309: Found in WebKit, the core engine for Safari and other Apple applications, this vulnerability enables cross-site scripting (XSS) attacks. Exploiting this flaw, attackers can inject malicious scripts into trusted websites, potentially stealing sensitive information or compromising user sessions. Apple identified the root cause as a cookie-related issue and resolved it by improving state management.
Both vulnerabilities are confirmed to have been exploited in the wild, particularly targeting Intel-based Mac systems, though Apple has not disclosed specific details about the attack campaigns.
Patches and Affected Versions
Apple has rolled out patches across its ecosystem to address these vulnerabilities. The updates include:
- macOS Sequoia 15.1.1
- Safari 18.1.1
- iOS 17.7.2 and 18.1
- iPadOS 18.1
- visionOS 2.1
Apple urges users and organisations to update their devices immediately to mitigate the risk of exploitation.
The Mac-OS zero-day Exploitation
macOS: A New Focus for Cyber Threats
macOS has long enjoyed a reputation as a secure platform, leading many users to believe it is immune to malware and cyberattacks. However, 2024 has shattered this myth, with a sharp rise in macOS-targeted attacks.
What’s Driving the Surge in macOS Threats?
- Increased Adoption: More organisations are deploying macOS devices for their workforce, making them attractive targets for cybercriminals.
- Sophisticated Threat Actors: Advanced persistent threat (APT) groups, such as Lazarus Group, have shifted their focus to macOS, particularly targeting sectors like cryptocurrency and finance.
- Rising Malware Variants: Security researchers have identified a surge in macOS-specific malware, including Atomic Stealer, Poseidon Stealer, and Cthulhu Stealer.
In a recent blog post, Trellix researchers highlighted how threat actors are adapting to exploit macOS vulnerabilities, particularly as corporate usage grows. They noted that threat actors are even using valid Apple developer accounts to notarise their malware, bypassing macOS’s built-in security protections.
Insights from the Cybersecurity Community
Cybersecurity experts have weighed in on the significance of these developments:
- Laura Brosnan, a senior information security specialist at Red Canary, emphasised the urgency of addressing misconceptions about macOS security:“Many people still hold the belief that macOS is immune to malware—a dangerous misconception. However, 2024 has shattered that illusion.”
- Researchers at SentinelOne observed that North Korea-affiliated threat actors are actively targeting macOS, particularly organisations in the cryptocurrency sector. Their analysis revealed a troubling trend: attackers are manipulating legitimate Apple developer accounts to bypass security measures.
Protecting macOS Users from Emerging Threats
With macOS under increasing attack, both individual users and organisations need to take proactive steps to safeguard their systems:
- Update All Devices Immediately: Ensure that macOS Sequoia, Safari, and all other Apple devices are updated to the latest versions. Updates include critical patches for the vulnerabilities described above.
- Implement Advanced Security Solutions: Use endpoint protection tools to detect and mitigate malware threats.
- Educate Teams on Security Risks: Organisations should conduct training sessions to inform employees about the rising risks of macOS-targeted malware.
- Adopt Additional Security Layers: Implement firewalls, sandboxing tools, and multi-factor authentication (MFA) to reduce attack surfaces.
- Monitor System Activity: Regularly review logs and system activity to identify unusual behaviour that might indicate a breach.
The Road Ahead for macOS Security
Apple’s swift response to these vulnerabilities demonstrates its commitment to addressing emerging threats, but it also highlights the need for vigilance among users and organisations. As macOS adoption continues to grow, so too will the interest of cybercriminals in exploiting the platform.
The increasing sophistication of attacks, coupled with the perception of macOS as a secure system, creates a dangerous scenario where users may underestimate risks. By staying informed, applying updates promptly, and adopting robust security practices, users can significantly reduce their exposure to these threats.
For more updates on technology and cybersecurity in the UAE, visit What’s Hot in UAE.
Tech
Mozilla Faces Backlash Over Firefox Privacy Changes
Mozilla, long celebrated for its privacy-first approach, is now facing intense criticism after making changes to Firefox’s Terms of Use and Privacy Notice. The open-source browser, which has historically positioned itself as an alternative to data-hungry tech giants, is now under fire for rewording its privacy commitments—prompting concern from longtime users.
The Controversy: What Changed?
Mozilla introduced its first-ever Terms of Use for Firefox, alongside updates to its Privacy Notice and FAQ page. While Mozilla claims these changes were meant to improve transparency, many users believe they signal a shift away from the company’s core privacy values.
🚨 The Original Terms of Use Stated:
“When you upload or input information through Firefox, you hereby grant us a nonexclusive, royalty-free, worldwide license to use that information to help you navigate, experience, and interact with online content as you indicate with your use of Firefox.”
This language implied that Mozilla had broad rights over user-submitted data, leading to fears that the company was claiming ownership over personal information.
After backlash from the open-source community, Mozilla removed this clause, stating it was misinterpreted legal boilerplate.
Mozilla’s Response: A Quick but Unconvincing Fix?
Following user outrage, Ajit Varma, Mozilla’s VP of Firefox Product, issued a statement clarifying that:
🛑 Mozilla does NOT own user data
🔍 The clause was only meant to explain Firefox’s basic functionality
📝 The wording has now been updated to avoid confusion
While this explanation may have calmed some users, another major change added fuel to the fire:
📝 Mozilla quietly removed its promise that Firefox does not sell user data.
Firefox’s Privacy Policy: What’s Missing?
Previously, Mozilla proudly stated:
“Firefox is the only major browser backed by a not-for-profit that doesn’t sell your personal data to advertisers.”
Now, this statement has been reworded to:
“Firefox, the only major browser backed by a not-for-profit, helps you protect your personal information.”
Similarly, Mozilla’s response to the FAQ question “Is Firefox free?” previously read:
“Yep! The Firefox Browser is free. Super free, actually. No hidden costs or anything. You don’t pay anything to use it, and we don’t sell your personal data.”
The new version completely omits the data-selling disclaimer, now reading:
“Yep! The Firefox Browser is free. Super free, actually. No hidden costs or anything. You don’t pay anything to use it.”
While Mozilla claims this change was made due to legal variations in how different jurisdictions define ‘selling data’, users see it as a red flag.
Mozilla’s Changing Leadership & Business Direction
Some are speculating that Mozilla’s shift in language may be connected to recent leadership changes. In December 2024, Mozilla brought in several new executives, including:
- Ajit Varma – Formerly with Meta & Google, now VP of Firefox Product
- Anthony Enzor-DeMeo – Ex-Wayfair & Better.com, now Senior VP of Firefox
- Girish Rao – Previously at Warner Bros, EA & Cisco, now SVP of Infrastructure
Mozilla’s CEO Laura Chambers, who took over in early 2024, has been making aggressive changes, including deep staffing cuts at the Mozilla Foundation.
Is Mozilla Heading Toward an Ad-Driven Future?
While Mozilla insists it is not selling user data, critics argue that these policy changes align with a shift toward monetization.
🔹 Mozilla already profits from search partnerships—Google reportedly pays Mozilla $450 million per year to make Google the default search engine in Firefox.
🔹 The company has invested heavily in ad-supported services like Mozilla VPN and Pocket (its content recommendation platform).
Users fear that Mozilla’s move away from clear anti-tracking promises could signal an increased focus on data monetization—bringing it closer to the business models of Google Chrome and Microsoft Edge.
The Fallout: What’s Next for Firefox?
The backlash has sparked heated discussions on Mozilla’s official forums, Reddit, and tech communities.
Some users are now exploring privacy-focused Firefox alternatives, such as:
🔹 Waterfox – A Firefox-based browser that removes telemetry and tracking
🔹 LibreWolf – A security-focused, open-source browser with enhanced privacy features
🔹 Floorp – A highly customizable, privacy-first alternative
While Firefox remains a strong competitor in the privacy browser market, the latest controversy raises serious concerns about its future direction.
Will Mozilla maintain its reputation as a privacy-first company, or is this the beginning of a more commercial approach?
Only time will tell.
Read more in our online magazine: 😎
https://whatshotinuae.com
Tech
How to Hide Files and Folders on macOS
Keeping your private files secure on a Mac is essential, especially when you share your device with family or friends. While macOS has built-in security features like password protection, Touch ID, and Apple Watch authorization, there’s always a chance that someone might stumble upon sensitive files while browsing through your system. We look into How to Hide Files on macOS.
Fortunately, macOS provides several ways to hide files and folders, ensuring that your personal data remains out of sight. Whether you use Finder, Terminal, or third-party encryption software, here’s how to keep your data private on macOS.
Method 1: Hide Files and Folders Using Finder
macOS allows you to hide files and folders by renaming them with a period (.) at the beginning of the file name. However, before you start hiding files, you’ll need to enable visibility for hidden files so you can see what’s already concealed.
Step 1: View Hidden Files in Finder
🔹 Press Shift + Cmd + . (period) in Finder.
🔹 Hidden files and folders will appear faded but visible.
Step 2: Hide a File or Folder in Finder
1️⃣ Select the file or folder you want to hide.
2️⃣ Click on the name to edit it.
3️⃣ Add a period (.) at the beginning of the name.
4️⃣ Press Enter, then select Use Dot to confirm.
🔹 The file or folder will remain visible but faded. To fully hide it, press Shift + Cmd + . (period) again.
Step 3: Unhide Files in Finder
🔹 Rename the file or folder removing the period.
🔹 Restart Finder by opening Terminal and typing:
bashCopyEditkillall Finder
🔹 Press Enter to apply the changes.
Method 2: Hiding Files Using Terminal
If you prefer not to rename files manually, macOS Terminal provides a command-based method to hide and unhide files.
Step 1: Hide a File or Folder
1️⃣ Open Terminal (Cmd + Space, type “Terminal,” and press Enter).
2️⃣ Type the following command:
bashCopyEditchflags hidden
3️⃣ Drag the file or folder you want to hide into the Terminal window (this automatically adds the file path).
4️⃣ Press Enter to hide it.
5️⃣ Restart Finder using:
bashCopyEditkillall Finder
🔹 The file is now hidden.
Step 2: Unhide a File or Folder
1️⃣ Open Terminal and enter:
bashCopyEditchflags nohidden
2️⃣ Drag the hidden file or folder into Terminal and press Enter.
3️⃣ If the file remains hidden, press Shift + Cmd + . (period) to reveal it in Finder.
🔹 Note: This method is quick and easy but not entirely secure—anyone familiar with macOS can still reveal hidden files.
Method 3: Using Third-Party Software for Extra Security
If you need stronger protection than Finder or Terminal, consider third-party tools that offer password-protected file encryption.
1️⃣ Funter (Basic File Hiding Tool – Free)
Funter is a menu bar utility that allows you to hide and unhide files with a single toggle switch.
🔹 Key Features:
✔️ Quickly hide/unhide files from the menu bar.
✔️ Search for hidden files on your Mac.
✔️ Works similarly to the Shift + Cmd + . shortcut but with a simpler interface.
🔹 Limitations:
❌ Files can still be revealed without a password, meaning it’s not a fully secure solution.
2️⃣ Encrypto (Password-Protected File Encryption – Free)
For maximum security, Encrypto allows you to encrypt and lock files with a password.
How to Use Encrypto to Secure Files on macOS
1️⃣ Download and install Encrypto.
2️⃣ Open the Encrypto app.
3️⃣ Drag and drop the file or folder you want to hide into the app.
4️⃣ Enter a password to encrypt the file.
5️⃣ Click Encrypt to lock it.
6️⃣ Save the encrypted file anywhere on your system.
🔹 To decrypt the file, simply double-click it, enter the password, and retrieve your data.
💡 Pro Tip: For extra security, use Finder or Terminal to hide the Encrypto-protected file so that even if someone finds it, they won’t be able to open it without the password.
Final Thoughts: Which Method Should You Use?
🔹 If you just want to temporarily hide files, use Finder or Terminal.
🔹 If you need quick access to hidden files, try Funter.
🔹 If you require serious security and password protection, Encrypto is the best option.
By following these methods, you can effectively hide and secure your files on macOS, ensuring your privacy remains intact. Whether you’re protecting personal documents, sensitive work files, or private media, macOS offers multiple ways to keep your data safe from prying eyes.
📌 Read more in our online magazine: 😎
👉 https://whatshotinuae.com
Tech
Akai And Native Instruments Collab for MPC 3
Native Instruments has just made a groundbreaking announcement at NAMM 2025, unveiling its Native Kontrol Standard (NKS) Hardware Partner Program. Designed to streamline and enhance music production, this initiative bridges the gap between hardware and software, offering music producers unparalleled creative possibilities. Major industry players like Akai Professional, Novation, Nektar, Korg, and M-Audio have joined the program, ensuring seamless integration of their renowned controllers with Native Instruments’ software ecosystem.
This marks a significant evolution for Native Instruments’ vision of creating an open and connected platform for music creators. With over 2,000 NKS-compatible instruments and effects from 250+ brands, producers now have access to a diverse and premium library of sounds—all at their fingertips.
Pioneering a Unified Music Production Ecosystem
At the core of this development is the Native Kontrol Standard (NKS), a technology that unifies virtual instruments, effects, and hardware. This integration allows music makers to bypass complex setups, delivering an intuitive workflow that keeps their focus squarely on creativity.
Simon Cross, Chief Product Officer at Native Instruments, underscores the collaborative spirit of this expansion, stating:
“This expansion highlights the impact of collaboration. It marks an important milestone in our mission to provide musicians with an open, connected platform, making professional-grade tools, instruments, and technology more accessible to creators everywhere.”
What the NKS Hardware Partner Program Offers
The NKS Hardware Partner Program enables basic integration for partner controllers, giving users access to Native Instruments’ Komplete Kontrol desktop software. With this, musicians can fully explore the 2,000+ NKS-compatible instruments and effects library. Supported hardware now benefits from:
- Intuitive Mappings: Supported controllers offer plug-and-play functionality, allowing hands-on control without the need for extensive configuration.
- Future-Ready Features: The program sets the stage for advanced functionality in upcoming products, ensuring creators remain at the forefront of innovation.
- Streamlined Workflows: Producers can stay immersed in their music-making process without unnecessary distractions.
Industry Leaders Joining the NKS Ecosystem
The partnership with Akai Professional, Novation, Nektar, Korg, and M-Audio is a game-changer for music production. Here’s how each brand’s hardware integrates with NKS:
- Akai Professional:
The MPK Mini Series (MPK Mini, MPK Mini Play, and MPK Mini Plus) now features NKS compatibility, bringing Akai’s widely loved compact controllers into the Native Instruments fold. - Novation:
NKS integration enhances the Launchkey MK3 and MK4, FLkey, and SL MK3 controllers, expanding their already exceptional DAW workflows. The addition of NKS compatibility means creators can now combine Novation’s ease of use with Komplete Kontrol’s powerful sound library. - Nektar:
The LX MK3 Series gains velocity-sensitive NKS functionality, enabling producers to enjoy expressive control and streamlined creative workflows. - Korg:
With MIDI 2.0-ready Keystage controllers, Korg brings its signature innovation into the NKS ecosystem. These controllers cater to both live performers and studio producers, offering advanced sound design possibilities. - M-Audio:
The Oxygen Series keyboards now boast NKS integration, empowering music makers with cutting-edge tools for studio and stage performances alike.
Why This Matters
For producers, this expansion eliminates the frustration of incompatible hardware and software. By integrating their favourite controllers with Native Instruments’ Komplete Kontrol platform, music makers gain a seamless and expressive workflow that fosters creativity and innovation. The addition of industry-leading hardware ensures that the NKS ecosystem continues to set the standard for music production.
What’s Next for Native Instruments?
This launch is just the beginning. Native Instruments has hinted at upcoming advanced features and hardware updates within the NKS framework, promising even greater possibilities for musicians. As the ecosystem grows, users can expect enhanced tools to further connect their creative processes.
Explore the future of music production with Native Instruments and its NKS Hardware Partner Program.
Read more in our online magazine: 😎
https://whatshotinuae.com
- Nightlife2 weeks ago
ANTS at Ushuaïa Dubai Harbour Experience: The Ibiza Vibes Hit Dubai
- Lifestyle2 weeks ago
Why Stüssy Is Still Cool: The Evolution of a Streetwear Icon
- CRYPTOCURRENCY3 weeks ago
Breaking News: Hackers Steal $1.4 Billion from Bybit in the Largest Crypto Heist Ever
- Lifestyle2 weeks ago
Pharrell Williams Reinvents the Adidas Superstar 92 with Pusha T
- Entertainment1 week ago
How to Get Invited to Red Carpet Movie Premieres in the UAE
- Lifestyle1 week ago
Tom Ford Debuts Its First-Ever Ramadan Collection, Exclusively in the GCC
- Music2 weeks ago
Why Vinyl Will Never Make a Comeback
- Lifestyle1 day ago
The Incredibly Rare Air Jordan 11 “Purple Rain” Made for Prince Is Up for Sale for $100,000