Skip to main content

Security

See All Stories

Apple Hide My Email bug seemingly allows 100% of real email addresses to be discovered

Apple Hide My Email (screenshot shown) bug seemingly allows 100% of real email addresses to be discovered

A privacy flaw in Apple’s Hide My Email feature means that your real email address can be discovered. A security researcher said that tests found 100% of generated addresses allowed an attacker to reveal the real email associated with the Apple account.

Tyler Murphy said that he discovered and reported the issue to Apple more than a year ago, but it still hasn’t been fixed, and he has now made the decision to go public …

Expand Expanding Close

Three AirDrop vulnerabilities discovered, with Apple working on a full fix

Three AirDrop vulnerabilities discovered, with Apple working on a full fix | Two iPhones exchanging contact details via AirDrop

Three AirDrop vulnerabilities have been discovered by security researchers, affecting both iPhone and Mac, with similar ones found in Android’s Quick Share.

An attacker could easily exploit the vulnerabilities to cause AirDrop, AirPlay, Handoff, Universal Clipboard, and Continuity Camera to crash and remain unavailable for as long as the attack continues …

Expand Expanding Close

Apple collects every tap to deliver App Store personalized recommendations

Apple collects every tap to deliver App Store personalized recommendations | Screenshot shown of the data sent for a search for Tim Cook

Apple recently introduced Personalized Collections in the App Store, which provides users with individually tailored recommendations for new apps they might enjoy.

Two security researchers have highlighted the extremely extensive analytics data the company is capturing in order to compile these recommendations, logging every tap you make …

Expand Expanding Close

Security Bite: Apple’s most impressive agentic AI feature yet is hiding in the Passwords app

9to5Mac Security Bite is exclusively brought to you by Mosyle, the only Apple Unified Platform. Making Apple devices work-ready and enterprise-safe is all we do. Our unique integrated approach to management and security combines state-of-the-art Apple-specific security solutions for fully automated Hardening & Compliance, Next Generation EDR, AI-powered Zero Trust, and exclusive Privilege Management with the most powerful and modern Apple MDM on the market. The result is a totally automated Apple Unified Platform currently trusted by over 45,000 organizations to make millions of Apple devices work-ready with no effort and at an affordable cost. Request your EXTENDED TRIAL today and understand why Mosyle is everything you need to work with Apple.


While WWDC26 is winding down, I’ve had time to reflect on Monday’s keynote, where Apple spent most of its time preaching to parents about on-device Child Safety and, of course, Siri AI.

However, it also showcased something insanely neat and ingenious on Apple’s part that is largely being overshadowed. I’m referring to the new agentic AI feature now in iOS 27’s Passwords app.

Expand Expanding Close

Hackers tricked Instagram AI into letting them take over 20,000 accounts [U]

Hackers tricked Meta AI into letting them take over high-profile accounts | Low key photo shows the app opening on a smartphone placed on top of a MacBook keyboard

Hackers managed to trick Meta’s AI-powered support bot into allowing them to take over a number of Instagram accounts, including some high-profile ones. This included accounts belonging to the White House, US Space Force, and security researcher Jane Wong.

Update: Meta has now revealed that around 20,000 accounts were compromised and has explained the steps it has taken in response …

Expand Expanding Close

Mosyle identifies two new macOS threats invisible to antivirus engines

After exclusively sharing details with 9to5Mac last September on ModStealer, a cross-platform infostealer invisible to every major antivirus engine at the time, Mosyle, a leader in Apple device management and security, is back with two more macOS threats that are flying completely under the radar.

In new details again shared with 9to5Mac, the Mosyle Security Research Team says it has identified two previously undetected samples: Phoenix Worm, a cross-platform stager, and ShadeStager, a modular macOS implant built for credential theft. The two aren’t directly connected in how they work, but together show just how sophisticated Mac malware is getting.

Expand Expanding Close

Netgear can now sell new wireless routers in the US but nobody knows why [U]

Netgear can now sell new wireless routers in the US but nobody knows why | A badge showing FCC approval for a Netgear router

Last month saw a surprise ban on almost every new wireless router intended for use in US homes. The FCC ruling described all foreign-made routers as a national security risk.

The FCC offered a pathway to approval, and today Netgear has received that – but nobody knows why. Not even Netgear itself was able to offer an explanation …

Expand Expanding Close

FBI says cyber fraud cost Americans $21B last year – here’s what you need to know

FBI says cyber fraud cost Americans $21B last year – here's what you need to know | FBI meeting at a field office

The FBI says that a sharp rise in scams saw cybersecurity crime cost US victims a total of almost $21 billion last year. The most common example was investment scams, with cryptocurrency fraud responsible for the largest losses.

The report includes AI-related scams for the first time. The agency says that the use of voice cloning, forged documents, and deepfake videos were responsible for £893m in losses …

Expand Expanding Close