This all went down late friday so most of us missed it if you did not hear about it over the weekend.
iOS 7.0.6 was released
Still no patch for 10.9 yet. The last word was the beta version of 10.9.2 was still vulnerable. Apple says the patch will be out "Very Soon". 10.8 does not look to be affected.
Data Security
Impact: An attacker with a privileged network position or on the same local or wifi network may capture or modify data in sessions protected by SSL/TLS.
Description: Secure Transport failed to validate the authenticity of the connection. This issue was addressed by restoring missing validation steps.
http://support.apple.com/kb/HT6147
http://www.reuters.com/article/2014/02/22/apple-encryption-idUSL2N0LR0GW20140222
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2014-1266
Test your OS
https://www.imperialviolet.org
From the site owner -"I coded up a very quick test site at https://www.imperialviolet.org:1266. Note the port number (which is the CVE number), the normal site is running on port 443 and that is expected to work. On port 1266 the server is sending the same certificates but signing with a completely different key. If you can load an HTTPS site on port 1266 then you have this bug."
gotofail.com