Skip to main content

Security

See All Stories

NSO zero-click iPhone hack accessed HomeKit, but blocked by Lockdown Mode

NSO zero-click iPhone hack | Screenshot of Lockdown Mode alert

An NSO zero-click iPhone hack worked by gaining access to HomeKit on the device, but it was blocked by those using Apple’s Lockdown Mode security feature, with the phone alerting them to the access attempt.

However, two other NSO zero-click attacks seemingly succeeded – both exploiting vulnerabilities in the Find My app …

Expand Expanding Close

PSA: AI voice cloning and call spoofing create scary convincing scams, here’s how to protect yourself

Protect against AI voice clone scams

As technology advances, scams are becoming quite sophisticated. One of the latest threats is AI voice cloning which a malicious party can use to make it seem like they have a loved one held hostage. Mix that with caller ID spoofing and it’s a very scary and convincing scam that can impact users on iPhone, Android, and really any phone. Read on for more details and how to protect against AI voice clone and caller ID spoofing scams.

Expand Expanding Close

Terrifying study shows how fast AI can crack your passwords; here’s how to protect yourself

AI cracks passwords this fast

Along with the positive aspects of the new generative AI services come new risks. One that’s surfaced is an advanced approach to cracking passwords called PassGAN. Using the latest AI, it was able to compromise 51% of passwords in under one minute with 71% of passwords cracked in less than a day. Read on for a look at the character thresholds that offer security against AI password cracking, how PassGAN works, and more.

Expand Expanding Close

Apple still a top spender on TikTok ads, despite growing controversy

TikTok ads | TikTok website viewed on a Mac

Apple remains one of the top-spending companies when it comes to TikTok ads, despite growing controversy about whether the app is a threat to US national security.

A separate report today reveals that the Chinese government engaged in an organized social media campaign to mock US concerns about the app, accusing Congress of technical illiteracy, hypocrisy, and xenophobia …

Expand Expanding Close

Microsoft announces Security Copilot, leveraging GPT-4 for ‘the new era of security’

Microsoft Security Copilot GPT-4

Microsoft has announced the latest way it’s integrating OpenAI’s GPT-4 into its services and software. With a fresh app called Security Copilot, Microsoft believes leveraging GPT-4’s AI will usher in “the new era of security” by helping infosec professionals save time, simplify the complex, catch what others miss, and address the talent gap.

Expand Expanding Close
iOS 16.4 beat Rapid Security Res

Apple pushes Rapid Security Response update for iOS 16.4 beta [Version ‘b’ now available]

Following up on releasing the second iOS 16.4 developer and public betas, Apple has pushed a Rapid Security Response update to those on the latest software in testing. It’s unclear for now if this is another test of the Rapid Security Response feature like we’ve seen before or potentially fixing a notable flaw.

Expand Expanding Close

Apple should really invest in anti-theft security features for iPhone and iPad

Apple should really invest in anti-theft security features for iPhone

Apple devices have always been known for their security features, which include the Find My network that has received major updates in recent years. However, a report from The Wall Street Journal on Friday revealed that these features are not enough to prevent thieves from accessing users’ data. With iOS 17, Apple should invest even more in anti-theft security features for iPhone and iPad.

Expand Expanding Close

Recent iPhone thefts highlight the danger of using passcodes in public

iPhone theft passcode security

A new report from The Wall Street Journal looks at a recent trend of iPhone thefts that have happened across the US. Instead of just looking to snatch devices, these thieves are watching for passcodes so they can immediately get into iPhones, change Apple ID passwords, access financial accounts, and more. Here’s a look at the risks of using an iPhone passcode in public, how much power the passcode wields, and some steps to keep yourself safer.

Expand Expanding Close

Well-hidden Mac cryptomining malware found in pirate copies of Final Cut Pro; expect more [U]

Mac cryptomining malware in FCP | Final Cut Pro desktop setup

Update: Apple has now commented on the findings – see the end of the piece.

Cybersecurity company Jamf Threat Labs has found Mac cryptomining malware in pirate copies of Final Cut Pro. The firm says that the cryptojacking malware was particularly well hidden, and not detected by most Mac security apps.

Jamf also warned that the power of Apple Silicon Macs is going to make them increasingly popular targets for cryptojacking – where malware uses your machine’s considerable processing power to mine cryptocurrencies for the benefit of attackers …

Expand Expanding Close

Researchers who discovered new class of iOS bugs still exploring ‘huge range’ of ‘potential vulnerabilities’

new iOS security bugs

About a month after Apple released iOS 16.3 and macOS 13.2, it detailed additional security fixes that came with the updates. Now Trellix, the team that found two of those flaws for iOS and macOS has revealed more about how they discovered what they’re calling a “large new class of bugs.” While the new exploits were quickly patched by Apple, Trellix says it’s “still exploring” a “huge range” of potential vulnerabilities that could put messages, photos, location data, and more at risk on iPhone and Mac.

Expand Expanding Close