We're never safe lol. There is always going to be an exploit somewhere. Basically what happened was this, put on your propeller hats :
1. Someone built a program to search the internet for wordpress blogs that were out of date. The program then tested that version of wordpress to see if it could be hacked. A lot of people still have old versions of word press running their blogs. Bad idea :|
2. So once the program found vulnerable wordpress sites, it used a technique called CROSS SITE SCRIPTING (xss for short). This technique inserts JAVA SCRIPT into the webpage so that the user is redirected to BAD GUYS website.
3. So once the user is unknowingly redirected to the BAD website, it runs another program to check if it is running an old version of JAVA (not the same thing as java script, java has more access to your computer). If that person was running an exploitable version of JAVA (EVERYONE WAS, it took them a while to find out and patch this) it would use the user JAVA to run a custom program that would install a trojan on the persons computer.
MAC USER got screwed especially hard because APPLE is really crappy with security. So get this, even though ORACLE (the people who own JAVA) released a patch to fix the vulnerability, APPLE doesn't allow that patch. APPLE makes their own patches for JAVA (cool "walled garden" bro) which was available way after the damage was done.
So this, is why the new FLASH TROJAN infected hundreds of thousands of MACS. Anti virus software is basically useless when it comes to finding new malware but that's a whole other topic.
So the moral of the story is, always update, ASAP.
Macs are safe because of low market share. There are no SAFE operating systems. Who knows, maybe that cracked version of minecraft has a backdoor in it
