Good info to be aware of but has this been actually documented in "the wild"???
It requires that the user download a file and give it permission that one normally wouldn't do. When a "Software Security" company makes announcements like this, it usually is a PR attempt.
Dave McGuire
"What if the Hokey Pokey really IS what it's all about?"