Security Issue: Audacity

Posted by: Mr Underhill on 05 August 2016

I thought I would post this on here as I believe there are other users who, like me, use Audacity.

http://www.theregister.co.uk/2..._audicity_infection/

The shortened version:

Hacker(s) used compromised accounts to access two popular applications and inject malware into them that overwrites the MBR.

The hosts claim they were onto the event quickly and have changed the code ...and are applying due diligence/recovery procedures to the servers.

For me the most important part of the briefing, and the reason I have posted this, is the way of recognising whether the application has been properly signed during install - towards the bottom of the page.

Like everything this is not full-proof, if a hacker managed to steal the coders certificate for instance, or as happened a number of years ago Microsoft sent out a code signing certificate to a ne'erdowell! But, worth noting I think.

Personally I feel sorry for all concerned. The hosts are, I believe, non-profit and are doing their best for 'the community', only to be attacked by some bottom dwellers.

M