Search
Find merged stories by title or summary.
Apple Upgrade plan to preload your data nixed over privacy optics
Apple reportedly evaluated giving Apple Upgrade buyers with iPhones that came with all their previous iPhone's data preloaded, but that didn't make the final cut. Apple Upgrade could have had more options for the iPhone Apple Upgrade is a lease in the US rather than a loan and so it's different to the iPhone Upgrade Program it replaces, but it could have been more different still. According to Bloomberg , Apple at least considered preloading a user's data. It's been described as a "white-glove component" of the program. That means it was to mark out Apple Upgrade as a premier service, just as you could once have had the 20th Anniversary Mac delivered and set up for you. Continue Reading on AppleInsider • Discuss on our Forums
ClickFix Attacks Deliver macOS Stealer That Can Drain Crypto Wallets
ClickFix-style attacks are being used to deliver a Go-based malware capable of stealing cryptocurrency assets, as well as browser-stored passwords, Apple iCloud Keychain data, and cached credentials. The macOS-focused infection chain is designed to deliver a shell script that profiles the host and then fetches a macOS malware payload that's compatible with the computer's CPU architecture. "
In Other News: AI Slop Limits Apple Bounties, North Carolina Port Attacks, Hackers Target Wall Street
Noteworthy stories that might have slipped under the radar: ban on Chinese data center tech, QuickFox VPN supply chain attack, IEH Corporation mailbox breached via phishing. The post In Other News: AI Slop Limits Apple Bounties, North Carolina Port Attacks, Hackers Target Wall Street appeared first on SecurityWeek .
Paying for AI, freezing iPhones, & avoiding scams on the AppleInsider Podcast
Someone has to pay for all this AI, nothing is foolproof, and Apple's lawsuit with OpenAI is only just beginning, all on the AppleInsider Podcast. The cost of iPhone components is only getting higher. As Wesley briefly covered on the previous episode, artificial intelligence is costing companies billions with very little return. Every new tool comes with a new cost, sometimes money, sometimes privacy. It's a grab bag of topics with people putting iPhones in freezers, getting Uber email scams, and Google Health gaining Apple Health syncing capabilities. There's also talk about Apple's lawsuit with OpenAI, which doesn't seem to be going well for OpenAI even though court hasn't even convened yet. Continue Reading on AppleInsider • Discuss on our Forums
Microsoft, Apple Release Fresh Security Updates
Microsoft fixed critical vulnerabilities across Azure, Entra, and SharePoint, while Apple patched a high-severity authentication bypass. The post Microsoft, Apple Release Fresh Security Updates appeared first on SecurityWeek .
ClickFix attack pushes macOS infostealer for crypto theft attacks
A Go-based malware delivered in ClickFix attacks targeting macOS users is stealing cryptocurrency assets, browser-stored passwords, Apple Keychain data, and cached credentials. [... ]
Jon Prosser's baby forces another extension to Apple's legal battle
Jon Prosser was sued by Apple over the alleged theft of pre-release information, saw a default ruling due to inaction, had that overturned, and is once again failing to provide discovery materials. There's a reason this time. Jon Prosser in his latest video about Apple. Image source: FPT Life hasn't been easy for Jon Prosser since a July 2025 lawsuit from Apple accused him and Michael Ramacciotti of stealing information from Apple employee Ethan Lipnik's test device. He says he's not guilty, but has created roadblocks at every possible point in this case. According to a new filing, Jon Prosser has not been responding to requests for discovery since he rejoined the case in June. Apple last heard from Prosser's counsel on July 6, 2026. Continue Reading on AppleInsider • Discuss on our Forums
Apple issues another round of macOS security updates as patch frequency increases
Apple has rolled out another round of security updates for macOS Tahoe , macOS Sequoia, and macOS Sonoma. Apple releases security updates for Mac operating system lineup Thursday's update is the second round of macOS updates to be released in less than two weeks. According to Apple, the patch solves an issue with Screen Sharing. The patch note reads, "An attacker on the network may be able to authenticate to Screen Sharing without valid credentials." Apple says that the issue was addressed with improved state management. Continue Reading on AppleInsider • Discuss on our Forums
One pasted Terminal command opens the door to Mac crypto wallet theft
Researchers have uncovered Mac malware that can steal credentials and drain all or a selected percentage of a cryptocurrency wallet, in yet another reminder not to paste random commands from the internet into Terminal. New malware via ClickFix The Go-based malware arrived through a ClickFix attack , which disguises a malicious instruction as a CAPTCHA or error message. Instead of exploiting macOS , the attackers persuaded the victim to run the command that installed their malware for them. Once executed, a Bash script profiled the Mac and downloaded a payload built for either Apple Silicon or Intel hardware. It then deleted its temporary file, cleared the Terminal window and removed the command from shell history.
Apple sweetens its trade-in deals, but you can still do better
Apple has significantly increased how much it pays you to trade in most devices, but you should compare carrier offerings, other trade-in vendors, and private sale values to get the most for your hardware. Apple has increased its trade-in values for many, but not all, iPhones - image credit: Apple There's no question but that Apple is looking down the barrel of weaker than usual sales for the forthcoming iPhone 18 Pro . No matter how good that smartphone is, it comes at a time when the global chip shortage has forced prices up. Apple's plans to beat those component cost increases have not gone well, but it is doing better fighting the battle on other fronts. First it launched the leasing program Apple Upgrade so that up-front device costs are lower , and now it's stepped up its trade-in game . Continue Reading on AppleInsider • Discuss on our Forums
Apple WebKit vulnerabilities reveal your IP address, despite Private Relay
Three WebKit mechanisms have been discovered to bypass Apple’s iCloud Private Relay. In fact, the mechanisms can bypass any browser‑level proxy configuration, including Psylo’s proxy, Tor-on-iOS proxy setups, and so on. Private Relay is a VPN-like system for Safari on iOS which is meant to prevent websites from viewing the visitor’s IP address and location. But because all three methods described by the researchers occur outside WebKit’s normal page loading path, Apple’s iCloud Private Relay never sees them and, as a result, means you can’t hide your IP address or Domain Name System (DNS) path in these cases. The three features are: • DNS prefetching Modern browsers try to be faster by looking up the IP addresses of links on a page before you click them, a feature known as DNS prefetching.
AirPods Pro 3 plunge to $189 at Amazon, 30-day best price
Amazon has launched a steeper AirPods Pro 3 discount this August, dropping the earbuds to a 30-day low of $189.99. Grab AirPods Pro 3 at a 30-day low price of $189. 99. Amazon has dropped AirPods Pro 3 down to $189. 99 , reflecting a $60 discount off the premium earbuds. This is the lowest price we've seen since Prime Day 2026. Buy AirPods Pro 3 for $189.99 Continue Reading on AppleInsider • Discuss on our Forums
'The Bonfire of the Vanities' series dropped by Apple TV
The high-profile television version of Tom Wolfe's "The Bonfire of the Vanities" will reportedly no longer be made for Apple TV because of creative differences. Apple TV will not go ahead with a series dramatization of "The Bonfire of the Vanities." This would have been the third version of Wolfe's famous 1980s novel about greed and Wall Street, and it was to be made by "Ally McBeal" and "The Practice" writer/producer David E. Kelley. Now according to Deadline , the deal is off and the production team will shop the series around to other streamers and networks. Neither Apple nor the production team at Warner Bros. Television officially announced the series was in development, but it was first reported to be in the works in April 2026. Now unspecified sources say that Apple TV and Warner Bros were not creatively aligned over the project.
Amazon and Apple impersonated in “$149.99 unauthorized charge” scam
If you’ve spent any time browsing lately, you may have run into a full-screen popup warning you that your Apple ID or Amazon account was just used for a mysterious $149. 99 purchase. It looks urgent. It looks official. And if you look at two examples side by side, it becomes obvious that it’s neither. Below are two popups pulled from real pages—one dressed up as Apple Support, one as Amazon. Same con, two costumes Below, one popup is skinned as Apple Support, the other as Amazon. Swap the logo and color palette and the structure is identical: a warning icon, a claim that a $149. 99 purchase was just made “via Pre-Authorization,” and a phone number to call immediately. That phone number is exactly the same in both. Fake Apple alert Fake Amazon alert That reused phone number is the tell.
Apple’s bug bounty program is drowning in so much AI slop, it is in danger of missing serious exploits
Apple has imposed strict new submission limits on its bug bounty portal after finding itself overwhelmed by low-quality, AI generated vulnerability reports - many of which were found to be describing security flaws that simply didn't exist. Read more in my article on the Hot for Security blog.
Apple devices expose real user IPs despite the use of Private Relay, Tor, or other proxy connections - Cybernews
Apple devices expose real user IPs despite the use of Private Relay, Tor, or other proxy connections Cybernews
Meta's Muse Code is yet another AI coding agent on macOS
A one-line command in your macOS terminal can get you access to Meta's Muse Code, which aims to be a transparent AI coding tool that can work across large repositories. Meta's Muse Code is a new AI coding tool for macOS. Image source: Meta There are already coding agents like Claude Code and ChatGPT Codex available for macOS, but Meta wants to enter the ring with its latest AI toolset. Unlike the others, it doesn't have an app interface and runs through the Terminal. According to an announcement post from Meta, Muse Code can take on complex software engineering tasks across large repositories. It is capable of planning changes, writing code, and validating the results while coordinating multiple persistent subagents. Continue Reading on AppleInsider • Discuss on our Forums
Unsafe iMessage for Android app Sunbird just will not die
Even though Apple now supports RCS to let Android users join in iMessage conversations, the risky Sunbird app is back to persuade them to route everything through its servers anyway. Don't do it to yourself. That would be Android phones it's talking about. You're on an iPhone, you're fine. Image credit: Sunbird Previously on Sunbird... it was an Android app that let users partake in Apple iMessage conversations without a green bubble , and with myriad security problems. It came and it went, and then Apple added RCS support so that Android users could do exactly this without the privacy issues. Sunbird tried coming back in 2024 having promised to have fixed its security problems, but it really didn't because it really can't.
RAM production worldwide is sold out through 2027
Apple's memory supply woes are going to continue, as suppliers have already sold their entire production capacity of memory at high prices for all of 2027. Expect iPhone upgrades to cost more this year, and next. A Samsung LPDDR5X memory chip - Image Credit: Samsung The tech industry's ongoing nightmare of memory pricing is expected to be a long-term problem. It seems that it will still be an issue until the end of 2027 at a minimum. According to industry insider sources of DigiTimes on Tuesday , the three major producers of DRAM and HBM have already sold out their production capacity for the entirety of 2027. Furthermore, while supply of NAND Flash SSD media is a little less tight, it's still expected to be fully booked before the end of August. Continue Reading on AppleInsider • Discuss on our Forums
Apple battles it out again with the UK over encrypted iCloud access
The UK Home Office has once again demanded Apple allows it access to encrypted iCloud data. The Guardian reports that the Home Office issued a Technical Capability Notice to Apple, this time targeting only British users. A Technical Capability Notice is a formal government order that compels tech and telecommunications companies to build or maintain specific technical functions—such as intercepting data or removing encryption protections—so law enforcement can access communications. In the last round of this ongoing battle , the UK secretly ordered Apple to provide blanket access to protected iCloud backups around the world. Advanced Data Protection (ADP) is Apple’s opt‑in end‑to‑end encryption for iCloud backups, which even Apple itself cannot read.
Apple fights UK's latest push for encrypted user data access - Cybernews
Apple fights UK's latest push for encrypted user data access Cybernews
What’s in the SOSS? Podcast #67 – S3E19 Funding the Future: Community Collaboration and the Spirit of Open Source with Mila Zhou
Summary Join host Yesenia as she sits down with Mila Zhou, Open Source Program Manager at AWS, to explore the fascinating intersection of finance, strategy, and security in the open source ecosystem. Mila shares her unique journey from forensic auditing to spearheading AWS funding initiatives, breaking down how strategic financial backing transforms vulnerable “long tail” projects and empowers dedicated security champions. Discover how full-time security engineers at foundations are securing critical repositories like PyPI, why community-driven forks like Valkey represent the true spirit of collaboration, and how the OpenSSF Ambassador Program is helping close the gap between developers and security experts. Listen on Apple Podcasts Listen on Spotify Listen on Overcast Listen on Pocket Casts Conversation Highlights 00:25 – Welcome & Introductions 01:03 – From Accounting to AWS OSPO
Apple removes Telegram from App Store over child abuse material - Cybernews
Apple removes Telegram from App Store over child abuse material Cybernews
Apple files fresh claim against Home Office move to access encrypted cloud data
Apple has filed another legal complaint over a secret Home Office order requiring the supplier to provide access to encrypted iCloud data stored by UK customers
A week in security (July 27 – August 2)
Last week on Malwarebytes Labs: • Fake Fortnite rewards are stealing players’ accounts • Fake Flash Player installs AtlasRAT • Malwarebytes for Windows, now available on the Microsoft Store • Hims & Hers sued over alleged health data privacy failures • Hidden prompt turns Microsoft Copilot into an AI worm • Apple accused of letting fake crypto app steal $1.8 million • Buying TikTok views or followers?
VU#293714: Arbitrary File Overwrite in Develar app-builder (zipx.Unzip) via Symlink Following on macOS (APFS)
Overview A vulnerability in the zipx. Unzip extraction routine of Develar’s app-builder allows an attacker to overwrite arbitrary files on macOS using Apple File System (APFS). The issue arises from a combination of Unicode normalization collisions and unsafe symlink-following behavior. APFS treats certain Unicode equivalent filenames as identical (e. g. , ß ↔ ss), while app builder performs no canonical normalization before validating or writing paths. Description Develar’s app-builder is a command‑line build tool used heavily in the Electron ecosystem to package, sign, notarize, and produce distributable application bundles for macOS, Windows, and Linux. It is popular because it is a transitive dependency of electron-builder, one of the most widely used packaging tools for Electron apps. The vulnerability arises from how the zipx.
Passware Kit 2026 v3: BitLocker PIN Recovery For TPM-Protected Devices
Passware Kit 2026 v3 is here with BitLocker PIN recovery for TPM-protected devices via Magic Drive, expanded file support, enhanced hashcat rules, usability upgrades, and native Apple silicon support in beta.
From Indirect Prompt Injection to DNS Exfiltration in macOS Terminal
This is a follow-up to my previous Terminal DiLLMa research , and there is a positive outcome: Apple fixed a macOS Terminal behavior that enabled a DNS-based data exfiltration technique. DNS Requests via ANSI Escape Codes David Leadbeater originally discovered an interesting behavior in the macOS Terminal app that allowed a special sequence of ANSI escape codes to issue DNS requests. In short, this triggered a DNS request from the macOS Terminal app:
Smashing Security podcast #475: JadePuffer – the AI that ran a ransomware attack all by itself
A 15-year-old boy asked a chatbot for help - and cancelled nearly 47,000 anime streaming subscriptions in under four hours. Meanwhile, researchers have documented the first fully autonomous, agentic AI-driven ransomware attack, "JadePuffer". What does this tell us about the future of cybersecurity? Also, Apple's "Hide My Email" feature turns out to hide rather less than it promises - despite Apple knowing it has a problem for over a year. All this and more in this episode of the "Smashing Security" podcast with cybersecurity expert and keynote speaker Graham Cluley, and special guest Zoë Rose.
macOS.Gaslight | Rust Backdoor Turns Prompt Injection on the Analyst, Not the Sandbox
Executive Summary • SentinelLABS has analyzed a Rust macOS implant that embeds a 3.5 KB prompt-injection payload of 38 fabricated “system” messages, built to steer an LLM-assisted triage pipeline into aborting or refusing its analysis. • Command-and-control runs over a Telegram Bot API polling loop, with AES-GCM payloads over certificate-pinned TLS. • The implant self-redacts its Telegram bot token in its own runtime output, denying it to anyone who captures logs or crash artifacts. • We assess with high confidence that the implant, which we track as macOS.Gaslight, belongs to a cluster of DPRK-aligned macOS activity. Introduction In early June, an Apple XProtect update surfaced a Mach-O sample that had been uploaded to VirusTotal on May 22.
Apache ActiveMQ Exploit Leads to LockBit Ransomware
Key Takeaways An audio version of this report can be found on Spotify, Apple, YouTube, Audible, & Amazon. This intrusion began in mid-February 2024 after a threat actor exploited a vulnerability (CVE-2023-46604) on an exposed Apache ActiveMQ server. The threat actor was able to perform remote code execution (RCE) by using a Java Spring class and a custom Java Spring […] The post Apache ActiveMQ Exploit Leads to LockBit Ransomware appeared first on The DFIR Report .
Breaking the Sound Barrier, Part II: Exploiting CVE-2024-54529
In the first part of this series , I detailed my journey into macOS security research, which led to the discovery of a type confusion vulnerability ( CVE-2024-54529 ) and a double-free vulnerability ( CVE-2025-31235 ) in the coreaudiod system daemon through a process I call knowledge-driven fuzzing . While the first post focused on the process of finding the vulnerabilities, this post dives into the intricate process of exploiting the type confusion vulnerability. I’ll explain the technical details of turning a potentially exploitable crash into a working exploit: a journey filled with dead ends, creative problem solving, and ultimately, success. The Vulnerability: A Quick Recap If you haven’t already, I highly recommend reading my detailed writeup on this vulnerability before proceeding. As a refresher, CVE-2024-54529 is a type confusion vulnerability within the com. apple. audio.
