Skip to main content

Security

See All Stories

AirDrop cracked by China, revealing phone number and email address of sender

AirDrop cracked by China | AirDrop on two iPhones, against Chinese flag

In a significant breach of Apple’s privacy measures, a new report says that AirDrop was cracked by the Chinese government, to reveal the phone number and email address of senders.

The anonymity of AirDrop was one of the reasons it has been commonly used by activists to share information about protests, and other information censored by the government …

Expand Expanding Close

Mac: How to scan for malware and remove it with free and paid tools

virus scanner for Mac

Macs are more protected from malicious software like viruses, Trojans, adware, etc. than Windows and Linux. However, they aren’t immune, and more and more malware is being designed specifically for Mac. Whether you just want to do a checkup or think your (or someone else’s) machine might be affected, here’s a look at 6 valuable malware/virus scanner Mac tools including free and paid options.

Expand Expanding Close

‘Most sophisticated’ iPhone attack chain ‘ever seen’ used four 0-days to create a 0-click exploit

apple zero-day exploit spyware security iOS macOS patches fixes

Between 2019 and December 2022, an extremely advanced iMessage vulnerability was in the wild that was eventually named “Operation Triangulation” by security researchers at Kasperksy who discovered it. Now, they’ve shared everything they know about the “most sophisticated attack chain” they’ve “ever seen.”

Expand Expanding Close

Xfinity data breach revealed: Names, contact info, security Q&As, and more at risk

Xfinity data breach revealed | Low-key photo of keyboard

An Xfinity data breach has been revealed by the company, in which hackers were able to obtain a wide range of customer information.

Data obtained for at least some Xfinity customers “may” include usernames, hashed passwords, real names, contact information, date of birth, last four digits of social security numbers, and security questions and answers …

Expand Expanding Close

Apple vs Corellium virtual iPhone lawsuit settled after 4-year battle

Apple vs Corellium virtual iPhone lawsuit settled | Conceptual illustration of virtual circuit board

The on-off Apple vs Corellium legal battle has been going on now for four years, but the final case has now been settled out of court, according to a report today.

The dispute had an amusing moment when Apple failed in its claim that Corellium had breached copyright by replicating iOS – and responded by claiming copyright infringement of Apple wallpapers …

Expand Expanding Close

Stolen Device Protection is a great move by Apple; Activation Lock next, please

Stolen Device Protection | iPhone 15 shown

One of the key features added in the iOS 17.3 beta is Stolen Device Protection. This is a thoughtful and creative solution to balancing out the need for protecting iPhone users without stopping them do the things they want to do with their devices.

What I love about Apple’s solution here is that someone has clearly put a lot of thought into that balancing act …

Expand Expanding Close

PSA: It’s a good time to turn on ADP; Apple study reveals 2.6B personal records stolen in data breaches

Apple Advanced Data Protection

Following up on last year’s report “The Rising Threat to Consumer Data in the Cloud”, Apple has shared a new study from MIT’s Dr. Madnick that looks at how cyber threats are growing worldwide. Read on for a look at the state of online security and what we can do to limit our exposure and risk like using Apple’s Advanced Data Protection.

Expand Expanding Close
Proton Sentinel

Proton Sentinel arrives for Proton Pass Plus users, secures accounts even when credentials are stolen

Continuing with its mission to provide the most private and secure services, Proton is out today with the expansion of its Proton Sentinel security program. The feature comes to Proton Pass Plus users for free and delivers the company’s highest level of protection that can secure your Proton account even if your login credentials are compromised.

Expand Expanding Close

PSA: Update Chrome on Mac, as security flaw is being actively exploited

Update Chrome on Mac | 3D representations of Chrome logo

If you use Chrome on Mac, it’s strongly recommended to update it immediately, as a security flaw discovered by Google is being actively exploited by attackers. It could potentially allow personal data to be extracted from your Mac (the same issue also affects Chrome on Windows and Linux).

Google says it is aware of at least one real-life case of the exploit being used by a bad actor …

Expand Expanding Close

Bluetooth security flaws allow connections to be hijacked; AirDrop unlikely to be affected [U]

Bluetooth security flaws BLUFFS | iPhones showing Bluetooth on and Airdrop request

Update: Whether AirDrop is vulnerable to this exploit is unclear, but the odds are against it. See the update at the end.

Two newly-discovered Bluetooth security flaws allow attackers to hijack the connections of all devices using Bluetooth 4.2 to 5.4 inclusive – that is, all devices between late 2014 and now.

Six separate exploits have been demonstrated, allowing both device impersonations and man-in-the-middle attacks …

Expand Expanding Close

Windows Hello fingerprint security tests failed on top three laptops

Windows Hello fingerprint security | Microsoft Surface keyboard cover with fingerprint reader

While Windows laptop users like to think they have their own version of Touch ID, it appears not to offer the same level of security. The Windows Hello fingerprint authentication system on the top three laptops to use it has been put to the test by security researchers – and all three failed.

To be fair, the team was carrying out the penetration tests at the request of Microsoft – but it was a Microsoft Surface product that turned out to be easiest to bypass …

Expand Expanding Close

PSA: Watch out for these fake Safari and Chrome updates infecting Macs with AMOS

Mac malware fake Safari Chrome updates

A powerful new malware launched in early 2023 called Atomic macOS Stealer (AMOS) targets Apple users and has become a growing threat. Now, with the latest iteration of the malware, malicious parties are planting AMOS inside fake Safari and Chrome browser updates for Mac. We’ll cover how it works and how to avoid this threat.

Expand Expanding Close

Flipper Zero can still crash iPhones running the latest version of iOS 17

flipper zero iphone ios 17 bluetooth exploit attack

In September, 9to5Mac reported that Flipper Zero, a popular and cheap hacking tool, was being used to wreak havoc on nearby iPhones and iPads, spamming them with fake Bluetooth pop-ups until they eventually crashed.

Despite many iOS 17 updates since, including last week’s release of new iOS 17.2 betas, Apple has yet to implement safeguards to prevent the attack. So, what gives?

Expand Expanding Close

Apple’s head of security speaks out against iPhone app sideloading in new interview

A new report from The Independent this weekend offers an interesting look at why and how Apple is “working hard to break into its own iPhones.” Ivan Krstić, Apple’s head of security engineering and architecture, spoke to The Independent for the report and explained why Apple feels the need to invest so heavily in security.

Notably, Krstić also addressed the possibility of Apple opening up the iPhone to third-party app stores and sideloading due to impending regulation in the European Union.

Expand Expanding Close

Manage push notifications

notification icon
We would like to show you notifications for the latest news and updates.
notification icon
Please wait...processing
notification icon
We would like to show you notifications for the latest news and updates.
notification icon
Please wait...processing