Category: Apple
-
Apple’s New Anti-Snatching Feature Will Auto-Lock iPhones When Stolen From Your Hand
Apple’s New Anti-Snatching Feature Will Auto-Lock iPhones When Stolen From Your Hand Apple is reportedly developing a new iPhone security feature designed to automatically lock the device the moment it detects a theft-in-progress, a significant upgrade to the company’s existing anti-theft protections that could close one of the most dangerous gaps in mobile security today.…
-
Apple blocked over $11 billion in App Store fraud in 6 years
Apple blocked over $11 billion in App Store fraud in 6 years Apple revealed that it blocked over $11 billion in fraudulent App Store transactions over the last six years, more than $2.2 billion in potentially fraudulent App Store transactions in 2025 alone. […] Sergiu Gatlan Go to bleepingcomputer
-
macOS Kernel Memory Corruption Exploit
macOS Kernel Memory Corruption Exploit A group used Anthropic’s Mythos AI model to help find a kernel memory corruption vulnerability and exploit on Apple’s M5. News article. Bruce Schneier Go to bruce schneier
-
Patch Tuesday, May 2026 Edition
Patch Tuesday, May 2026 Edition Artificial intelligence platforms may be just as susceptible to social engineering as human beings, but they are proving remarkably good at finding security vulnerabilities in human-made computer code. That reality is on full display this month with some of the more widely-used software makers — including Apple, Google, Microsoft, Mozilla…
-
DarkSword Malware
DarkSword Malware DarkSword is a sophisticated piece of malware—probably government designed—that targets iOS. Google Threat Intelligence Group (GTIG) has identified a new iOS full-chain exploit that leveraged multiple zero-day vulnerabilities to fully compromise devices. Based on toolmarks in recovered payloads, we believe the exploit chain to be called DarkSword. Since at least November 2025, GTIG…
-
Microsoft asks iPhone users to reauthenticate after Outlook outage
Microsoft asks iPhone users to reauthenticate after Outlook outage After addressing a widespread outage that affected Outlook.com users worldwide on Monday, Microsoft has asked iPhone users to re-enter their credentials to regain access to their Outlook and Hotmail accounts via the default Mail app. […] Sergiu Gatlan Go to bleepingcomputer
-
Apple fixes bug that let the FBI recover deleted Signal messages
Apple fixes bug that let the FBI recover deleted Signal messages Apple has released out-of-band security updates for iPhone and iPad devices to fix a Notification Services flaw that could allow notifications marked for deletion to remain stored on the device. […] Lawrence Abrams Go to bleepingcomputer
-
China’s Apple App Store infiltrated by crypto-stealing wallet apps
China’s Apple App Store infiltrated by crypto-stealing wallet apps A set of 26 malicious apps on Apple App Store impersonate popular wallets, such as Metamask, Coinbase, Trust Wallet, and OneKey, to steal recovery or seed phrases and drain them of cryptocurrency assets. […] Bill Toulas Go to bleepingcomputer
-
Apple account change alerts abused to send phishing emails
Apple account change alerts abused to send phishing emails Apple account change notifications are being abused to send fake iPhone purchase phishing scams within legitimate emails sent from Apple’s servers, increasing legitimacy and potentially allowing them to bypass spam filters. […] Lawrence Abrams Go to bleepingcomputer
-
Apple Works on Fix for iPhone Passcode Bug Linked to Missing Czech Keyboard Character
Apple Works on Fix for iPhone Passcode Bug Linked to Missing Czech Keyboard Character Apple is reportedly developing a software fix for a frustrating iOS 26 bug that has left some users entirely locked out of their iPhones for months. According to a recent report by The Register, Cupertino’s software engineers are scrambling to patch…
-
Singer loses life savings to fake wallet downloaded from the Apple App Store
Singer loses life savings to fake wallet downloaded from the Apple App Store If you hold cryptocurrency, there’s a very simple golden rule that you should always follow. Never hand over your seed phrase. Garrett Dutton, better known as G. Love – the front man of blues-hip-hop outfit G. Love & Special Sauce – has…
-
Possible US Government iPhone Hacking Tool Leaked
Possible US Government iPhone Hacking Tool Leaked Wired writes (alternate source): Security researchers at Google on Tuesday released a report describing what they’re calling “Coruna,” a highly sophisticated iPhone hacking toolkit that includes five complete hacking techniques capable of bypassing all the defenses of an iPhone to silently install malware on a device when it…
-
Apple expands iOS 18 updates to more iPhones to block DarkSword attacks
Apple expands iOS 18 updates to more iPhones to block DarkSword attacks Apple has now made it possible for more iPhones still running iOS 18 to receive security updates that protect against the actively exploited DarkSword exploit kit. […] Lawrence Abrams Go to bleepingcomputer
-
Apple’s Camera Indicator Lights
Apple’s Camera Indicator Lights A thoughtful review of Apple’s system to alert users that the camera is on. It’s really well-designed, and important in a world where malware could surreptitiously start recording. The reason it’s tempting to think that a dedicated camera indicator light is more secure than an on-display indicator is the fact that…
-
CISA orders feds to patch DarkSword iOS flaws exploited attacks
CISA orders feds to patch DarkSword iOS flaws exploited attacks CISA ordered U.S. government agencies to patch three iOS vulnerabilities targeted in cryptocurrency theft and cyberespionage attacks using the DarkSword exploit kit. […] Sergiu Gatlan Go to bleepingcomputer
-
CISA Warns of Apple Vulnerabilities Linked to DarkSword iOS Exploit Chain Exploited in Attacks
CISA Warns of Apple Vulnerabilities Linked to DarkSword iOS Exploit Chain Exploited in Attacks An urgent warning regarding three critical Apple vulnerabilities that threat actors are actively exploiting in the wild. These security flaws, officially tracked as CVE-2025-31277, CVE-2025-43510, and CVE-2025-43520, were recently added to CISA’s Known Exploited Vulnerabilities (KEV) catalog. Security researchers have linked…
-
Smashing Security podcast #459: This clever scam nearly hijacked a tech CEO’s Apple ID
Smashing Security podcast #459: This clever scam nearly hijacked a tech CEO’s Apple ID In episode 459 of Smashing Security, we dive into a chillingly clever account takeover attempt targeting WordPress co-founder Matt Mullenweg – involving MFA fatigue, real Apple alerts, a convincing support call, and a phishing page that oh-so-nearly worked. If a famous…
-
Apple pushes first Background Security Improvements update to fix WebKit flaw
Apple pushes first Background Security Improvements update to fix WebKit flaw Apple has released its first Background Security Improvements update to fix a WebKit flaw tracked as CVE-2026-20643 on iPhones, iPads, and Macs without requiring a full operating system upgrade. […] Lawrence Abrams Go to bleepingcomputer
-
iPhones and iPads Approved for NATO Classified Data
iPhones and iPads Approved for NATO Classified Data Apple announcement: …iPhone and iPad are the first and only consumer devices in compliance with the information assurance requirements of NATO nations. This enables iPhone and iPad to be used with classified information up to the NATO restricted level without requiring special software or settings—a level of…
-
CISA warns feds to patch iOS flaws exploited in crypto-theft attacks
CISA warns feds to patch iOS flaws exploited in crypto-theft attacks CISA ordered U.S. federal agencies to patch three iOS security flaws targeted in cyberespionage and crypto-theft attacks using the Coruna exploit kit. […] Sergiu Gatlan Go to bleepingcomputer
-
Predator spyware hooks iOS SpringBoard to hide mic, camera activity
Predator spyware hooks iOS SpringBoard to hide mic, camera activity Intellexa’s Predator spyware can hide iOS recording indicators while secretly streaming camera and microphone feeds to its operators. […] Bill Toulas Go to bleepingcomputer
-
Apple fixes zero-day flaw used in ‘extremely sophisticated’ attacks
Apple fixes zero-day flaw used in ‘extremely sophisticated’ attacks Apple has released security updates to fix a zero-day vulnerability that was exploited in an “extremely sophisticated attack” targeting specific individuals. […] Lawrence Abrams Go to bleepingcomputer
-
North Korean hackers use new macOS malware in crypto-theft attacks
North Korean hackers use new macOS malware in crypto-theft attacks North Korean hackers are running tailored campaigns using AI-generated video and the ClickFix technique to deliver malware for macOS and Windows to targets in the cryptocurrency sector. […] Bill Toulas Go to bleepingcomputer
-
New Apple privacy feature limits location tracking on iPhones, iPads
New Apple privacy feature limits location tracking on iPhones, iPads Apple is introducing a new privacy feature that lets users limit the precision of location data shared with cellular networks on some iPhone and iPad models. […] Sergiu Gatlan Go to bleepingcomputer
-
New MacSync Stealer Uses Signed macOS App to Evade Gatekeeper and Steal Data
New MacSync Stealer Uses Signed macOS App to Evade Gatekeeper and Steal Data Cybersecurity researchers have discovered a new variant of the MacSync malware targeting macOS users. Unlike previous versions that relied on complex ClickFix techniques, this iteration masquerades as a legitimately signed, notarised Apple application, thereby bypassing macOS Gatekeeper security and stealing sensitive data.…
-
New MacSync malware dropper evades macOS Gatekeeper checks
New MacSync malware dropper evades macOS Gatekeeper checks The latest variant of the MacSync information stealer targeting macOS systems is delivered through a digitally signed, notarized Swift application. […] Bill Toulas Go to bleepingcomputer
-
Apple fixes two zero-day flaws exploited in ‘sophisticated’ attacks
Apple fixes two zero-day flaws exploited in ‘sophisticated’ attacks Apple has released emergency updates to patch two zero-day vulnerabilities that were exploited in an “extremely sophisticated attack” targeting specific individuals. […] Lawrence Abrams Go to bleepingcomputer
-
Google enables Pixel-to-iPhone file sharing via Quick Share, AirDrop
Google enables Pixel-to-iPhone file sharing via Quick Share, AirDrop Google has added interoperability support between Android Quick Share and Apple AirDrop, to let users share files between Pixel devices and iPhones. […] Bill Toulas Go to bleepingcomputer
-
Google Sues to Disrupt Chinese SMS Phishing Triad
Google Sues to Disrupt Chinese SMS Phishing Triad Google is suing more than two dozen unnamed individuals allegedly involved in peddling a popular China-based mobile phishing service that helps scammers impersonate hundreds of trusted brands, blast out text message lures, and convert phished payment card data into mobile wallets from Apple and Google. In a…
-
Google ads for fake Homebrew, LogMeIn sites push infostealers
Google ads for fake Homebrew, LogMeIn sites push infostealers A new malicious campaign is targeting macOS developers with fake Homebrew, LogMeIn, and TradingView platforms that deliver infostealing malware like AMOS (Atomic macOS Stealer) and Odyssey. […] Bill Toulas Go to bleepingcomputer
-
Apple’s Bug Bounty Program
Apple’s Bug Bounty Program Apple is now offering a $2M bounty for a zero-click exploit. According to the Apple website: Today we’re announcing the next major chapter for Apple Security Bounty, featuring the industry’s highest rewards, expanded research categories, and a flag system for researchers to objectively demonstrate vulnerabilities and obtain accelerated awards. We’re doubling…
-
Microsoft warns of new XCSSET macOS malware variant targeting Xcode devs
Microsoft warns of new XCSSET macOS malware variant targeting Xcode devs Microsoft Threat Intelligence reports that a new variant of the XCSSET macOS malware has been detected in limited attacks, incorporating several new features, including enhanced browser targeting, clipboard hijacking, and improved persistence mechanisms. […] Lawrence Abrams Go to bleepingcomputer
-
Apple’s New Memory Integrity Enforcement
Apple’s New Memory Integrity Enforcement Apple has introduced a new hardware/software security feature in the iPhone 17: “Memory Integrity Enforcement,” targeting the memory safety vulnerabilities that spyware products like Pegasus tend to use to get unauthorized system access. From Wired: In recent years, a movement has been steadily growing across the global tech industry to…
-
Apple Warns Of Series Mercenary Spyware Attacks Targeting Users’ Devices
Apple Warns Of Series Mercenary Spyware Attacks Targeting Users’ Devices Apple has issued a warning regarding highly sophisticated “mercenary spyware” attacks targeting a select group of its users. The company’s threat notification system is designed to alert and support individuals who may have been targeted due to their profession or public profile, such as journalists,…
-
Microsoft Patch Tuesday, September 2025 Edition
Microsoft Patch Tuesday, September 2025 Edition Microsoft Corp. today issued security updates to fix more than 80 vulnerabilities in its Windows operating systems and software. There are no known “zero-day” or actively exploited vulnerabilities in this month’s bundle from Redmond, which nevertheless includes patches for 13 flaws that earned Microsoft’s most-dire “critical” label. Meanwhile, both…
-
The UK May Be Dropping Its Backdoor Mandate
The UK May Be Dropping Its Backdoor Mandate The US Director of National Intelligence is reporting that the UK government is dropping its backdoor mandate against the Apple iPhone. For now, at least, assuming that Tulsi Gabbard is reporting this accurately. Bruce Schneier Go to bruce schneier
-
Fake Mac fixes trick users into installing new Shamos infostealer
Fake Mac fixes trick users into installing new Shamos infostealer A new infostealer malware targeting Mac devices, called ‘Shamos,’ is targeting Mac devices in ClickFix attacks that impersonate troubleshooting guides and fixes. […] Bill Toulas Go to bleepingcomputer
-
Apple fixes new zero-day flaw exploited in targeted attacks
Apple fixes new zero-day flaw exploited in targeted attacks Apple has released emergency updates to patch another zero-day vulnerability that was exploited in an “extremely sophisticated attack.” […] Sergiu Gatlan Go to bleepingcomputer
-
Surveilling Your Children with AirTags
Surveilling Your Children with AirTags Skechers is making a line of kid’s shoes with a hidden compartment for an AirTag. Bruce Schneier Go to bruce schneier
-
Kali Linux can now run in Apple containers on macOS systems
Kali Linux can now run in Apple containers on macOS systems Cybersecurity professionals and researchers can now launch Kali Linux in a virtualized container on macOS Sequoia using Apple’s new containerization framework. […] Lawrence Abrams Go to bleepingcomputer
-
Microsoft: macOS Sploitlight flaw leaks Apple Intelligence data
Microsoft: macOS Sploitlight flaw leaks Apple Intelligence data Attackers could use a recently patched macOS vulnerability to bypass Transparency, Consent, and Control (TCC) security checks and steal sensitive user information, including Apple Intelligence cached data. […] Sergiu Gatlan Go to bleepingcomputer
-
Senator Chides FBI for Weak Advice on Mobile Security
Senator Chides FBI for Weak Advice on Mobile Security Agents with the Federal Bureau of Investigation (FBI) briefed Capitol Hill staff recently on hardening the security of their mobile devices, after a contacts list stolen from the personal phone of the White House Chief of Staff Susie Wiles was reportedly used to fuel a series…
-
Graphite spyware used in Apple iOS zero-click attacks on journalists
Graphite spyware used in Apple iOS zero-click attacks on journalists Forensic investigation has confirmed the use of Paragon’s Graphite spyware platform in zero-click attacks that targeted Apple iOS devices of at least two journalists in Europe. […] Bill Toulas Go to bleepingcomputer
-
Apple ‘AirBorne’ flaws can lead to zero-click AirPlay RCE attacks
Apple ‘AirBorne’ flaws can lead to zero-click AirPlay RCE attacks A set of security vulnerabilities in Apple’s AirPlay Protocol and AirPlay Software Development Kit (SDK) exposed unpatched third-party and Apple devices to various attacks, including remote code execution. […] Sergiu Gatlan Go to bleepingcomputer
-
Apple fixes two zero-days exploited in targeted iPhone attacks
Apple fixes two zero-days exploited in targeted iPhone attacks Apple released emergency security updates to patch two zero-day vulnerabilities that were used in an “extremely sophisticated attack” against specific targets’ iPhones. […] Lawrence Abrams Go to bleepingcomputer
-
Apple fined €150 million over App Tracking Transparency issues
Apple fined €150 million over App Tracking Transparency issues Autorité de la concurrence, France’s antitrust watchdog, has fined Apple €150 million ($162 million) for using the App Tracking Transparency privacy framework to abuse its dominant market position in mobile app advertising on its devices. […] Sergiu Gatlan Go to bleepingcomputer
-
Apple Warns of Three 0-Day Vulnerabilities Actively Exploited in Attacks
Apple Warns of Three 0-Day Vulnerabilities Actively Exploited in Attacks Apple has issued an urgent security advisory concerning three critical zero-day vulnerabilities CVE-2025-24200, CVE-2025-24201, and CVE-2025-24085 that have been actively exploited in sophisticated attacks. These vulnerabilities affect a wide range of Apple devices, including iPhones, iPads, Macs, and other platforms. Users are strongly advised to…
-
Apple fixes WebKit zero-day exploited in ‘extremely sophisticated’ attacks
Apple fixes WebKit zero-day exploited in ‘extremely sophisticated’ attacks Apple has released emergency security updates to patch a zero-day bug the company describes as exploited in “extremely sophisticated” attacks. […] Sergiu Gatlan Go to bleepingcomputer
-
Apple WebKit Zero-Day Vulnerability Actively Exploit in High Profile Cyber Attacks
Apple WebKit Zero-Day Vulnerability Actively Exploit in High Profile Cyber Attacks Apple has released emergency security updates addressing a critical zero-day vulnerability in its WebKit browser engine, identified as CVE-2025-24201, which has been actively exploited in targeted attacks. The flaw, described as an out-of-bounds write issue, could enable attackers to craft malicious web content capable…
-
An iCloud Backdoor Would Make Our Phones Less Safe
An iCloud Backdoor Would Make Our Phones Less Safe Last month, the UK government demanded that Apple weaken the security of iCloud for users worldwide. On Friday, Apple took steps to comply for users in the United Kingdom. But the British law is written in a way that requires Apple to give its government access…
-
Apple pulls iCloud end-to-end encryption feature in the UK
Apple pulls iCloud end-to-end encryption feature in the UK Apple will no longer offer iCloud end-to-end encryption in the United Kingdom after the government requested a backdoor to access Apple customers’ encrypted cloud data. […] Sergiu Gatlan Go to bleepingcomputer
-
New FrigidStealer infostealer infects Macs via fake browser updates
New FrigidStealer infostealer infects Macs via fake browser updates The FakeUpdate malware campaigns are increasingly becoming muddled, with two additional cybercrime groups tracked as TA2726 and TA2727, running campaigns that push a new macOS infostealer malware called FrigidStealer. […] Bill Toulas Go to bleepingcomputer
-
Microsoft spots XCSSET macOS malware variant used for crypto theft
Microsoft spots XCSSET macOS malware variant used for crypto theft A new variant of the XCSSET macOS modular malware has emerged in attacks that target users’ sensitive information, including digital wallets and data from the legitimate Notes app. […] Bill Toulas Go to bleepingcomputer
-
KASLR Exploited: Breaking macOS Apple Silicon Kernel Hardening Techniques
KASLR Exploited: Breaking macOS Apple Silicon Kernel Hardening Techniques Security researchers from Korea University have unveiled a new vulnerability in macOS systems running on Apple Silicon processors. Dubbed “SysBumps,” this attack successfully circumvents Kernel Address Space Layout Randomization (KASLR), a critical security mechanism designed to protect kernel memory from exploitation. The findings, presented at the…
-
Apple fixes zero-day exploited in ‘extremely sophisticated’ attacks
Apple fixes zero-day exploited in ‘extremely sophisticated’ attacks Apple has released emergency security updates to patch a zero-day vulnerability that the company says was exploited in targeted and “extremely sophisticated” attacks. […] Sergiu Gatlan Go to bleepingcomputer
-
UK Is Ordering Apple to Break Its Own Encryption
UK Is Ordering Apple to Break Its Own Encryption The Washington Post is reporting that the UK government has served Apple with a “technical capability notice” as defined by the 2016 Investigatory Powers Act, requiring it to break the Advanced Data Protection encryption in iCloud for the benefit of law enforcement. This is a big…
-
Experts Flag Security, Privacy Risks in DeepSeek AI App
Experts Flag Security, Privacy Risks in DeepSeek AI App New mobile apps from the Chinese artificial intelligence (AI) company DeepSeek have remained among the top three “free” downloads for Apple and Google devices since their debut on Jan. 25, 2025. But experts caution that many of DeepSeek’s design choices — such as using hard-coded encryption…
-
First Apple-notarized porn app available to iPhone users in Europe
First Apple-notarized porn app available to iPhone users in Europe The first Apple-notarized porn app, “Hot Tub,” is now available to iPhone users in Europe through the alternative app marketplace, AltStore PAL. […] Lawrence Abrams Go to bleepingcomputer
-
New Apple CPU side-channel attacks steal data from browsers
New Apple CPU side-channel attacks steal data from browsers A team of security researchers has disclosed new side-channel vulnerabilities in modern Apple processors that could steal sensitive information from web browsers. […] Bill Toulas Go to bleepingcomputer
-
Apple fixes this year’s first actively exploited zero-day bug
Apple fixes this year’s first actively exploited zero-day bug Apple has released security updates to fix this year’s first zero-day vulnerability, tagged as actively exploited in attacks targeting iPhone users. […] Sergiu Gatlan Go to bleepingcomputer
-
Fake Homebrew Google ads target Mac users with malware
Fake Homebrew Google ads target Mac users with malware Hackers are once again abusing Google ads to spread malware, using a fake Homebrew website to infect Macs and Linux devices with an infostealer that steals credentials, browser data, and cryptocurrency wallets. […] Bill Toulas Go to bleepingcomputer
-
Microsoft: macOS bug lets hackers install malicious kernel drivers
Microsoft: macOS bug lets hackers install malicious kernel drivers Apple recently addressed a macOS vulnerability that allows attackers to bypass System Integrity Protection (SIP) and install malicious kernel drivers by loading third-party kernel extensions. […] Sergiu Gatlan Go to bleepingcomputer
-
Phishing texts trick Apple iMessage users into disabling protection
Phishing texts trick Apple iMessage users into disabling protection Cybercriminals are exploiting a trick to turn off Apple iMessage’s built-in phishing protection for a text and trick users into re-enabling disabled phishing links. […] Lawrence Abrams Go to bleepingcomputer
-
Privacy of Photos.app’s Enhanced Visual Search
Privacy of Photos.app’s Enhanced Visual Search Initial speculation about a new Apple feature. Bruce Schneier Go to bruce schneier
-
Details about the iOS Inactivity Reboot Feature
Details about the iOS Inactivity Reboot Feature I recently wrote about the new iOS feature that forces an iPhone to reboot after it’s been inactive for a longish period of time. Here are the technical details, discovered through reverse engineering. The feature triggers after seventy-two hours of inactivity, even it is remains connected to Wi-Fi.…