Skip to main content

Security

See All Stories

Microsoft staff in China must use iPhone for authentication, not Android phones

Microsoft staff in China must use iPhone | Authenticator app seen here on an Android phone

Microsoft staff in China have been told that they must use an iPhone for authentication when logging in to company systems. From September, the use of Android smartphones as multi-factor authentication devices will be banned.

This will create a situation where an Apple device will be required despite the fact that staff are using Windows PCs …

Expand Expanding Close

Security Bite: Mac Malware wreaking the most havoc in 2024

apple security release page

It is a long-standing misconception that Macs are impervious to malware. This has never been the case. And while Apple might secretly hope people continue the preconceived notion, Mac users continue to be caught off guard by cybercriminals whose attack methods are becoming increasingly sophisticated. Below, you’ll find the most common macOS malware strains in 2024…


9to5Mac Security Bite is exclusively brought to you by Mosyle, the only Apple Unified Platform. Making Apple devices work-ready and enterprise-safe is all we do. Our unique integrated approach to management and security combines state-of-the-art Apple-specific security solutions for fully automated Hardening & Compliance, Next Generation EDR, AI-powered Zero Trust, and exclusive Privilege Management with the most powerful and modern Apple MDM on the market. The result is a totally automated Apple Unified Platform currently trusted by over 45,000 organizations to make millions of Apple devices work-ready with no effort and at an affordable cost. Request your EXTENDED TRIAL today and understand why Mosyle is everything you need to work with Apple.


Expand Expanding Close

Apple Intelligence privacy sets a new standard, but it’s not perfect – Inrupt

Apple Intelligence privacy isn't perfect thanks to ChatGPT integration | ChatGPT voice interface shown

Apple Intelligence privacy is stronger than that of any other AI company, but even its security protections aren’t perfect once ChatGPT gets involved.

That’s the argument made by the security chief at Inrupt, the privacy-focused company co-founded by the inventor of the world wide web, Tim Berners-Lee …

Expand Expanding Close

Identity verification company AU10TIX – used by tech giants – left photo IDs exposed

Identity verification company AU10TIX exposed photo ID | Sample driver's license shown

If there’s one type of company you definitely don’t want to see left vulnerable to hackers it’s an identity verification service with access to photo ID documents like driver’s licenses – but that’s exactly what appears to have happened with AU10TIX.

The cybersecurity company’s past or present clients include PayPal, Coinbase, X, TikTok, Uber, LinkedIn, Upwork, and Fiverr …

Expand Expanding Close

Vision Pro bug fixed; websites can no longer fill your room with bats

Vision Pro bug fixed | Bat seen on tabletop

Apple has fixed a Vision Pro bug which would have allowed a website to fill your room with an unlimited number of virtual 3D objects. Those objects – flying bats in the proof of concept – would then persist even after you quit Safari.

The bug was discovered by a cybersecurity researcher who says Apple took a lot of care to protect against this type of exploit, but it forgot one thing …

Expand Expanding Close

Europe and Australia both back down on CSAM scanning that would break encryption

Governments back down on CSAM scanning | Close-up photo of eye

Both the EU and Australia have backed down on separate proposals to force tech companies to carry out CSAM scanning within messaging apps, which would have meant breaking end-to-end encryption.

It’s the latest development in the ongoing battle between tech companies and politicians who don’t understand how encryption works

Expand Expanding Close

Apple Intelligence privacy can be independently verified thanks to an ‘extraordinary step’

Apple Intelligence privacy | Wall of CCTV cameras

Apple Intelligence privacy is a key differentiator for the company’s own AI initiative, with the company taking a three-step approach to safeguard personal data.

But Apple says we won’t have to take the company’s word for it: It is taking an “extraordinary step” to enable third-party security researchers to fully and independently verify the privacy protections in place …

Expand Expanding Close

iOS 18 includes these new privacy features: Lock and hide apps, improved contact permissions, more

iOS 18 Private Cloud Compute

Today at WWDC 2024, Apple introduced a slew of new iPhone features that will be available on all compatible devices later this Fall. While Apple Intelligence and enhanced customization were among the most heavily showcased, iOS 18 will also introduce some nice new privacy features, including improved Contacts permissions, the ability to lock and hide apps, Private Cloud Compute, a standalone Passwords app, and more.

Expand Expanding Close

Microsoft Recall was a security disaster, but I’d love to see Apple do it properly

Microsoft Recall screenshot

Microsoft Recall sounded like a very cool idea, but was very quickly revealed to be a security disaster. Instead of helping you recall everything you’ve done on your Windows PC, it was found that it could easily help a hacker do the same.

However, as much as the company messed-up the implementation, I do think there’s mileage in the concept, and if there’s one company I’d trust to do it with proper privacy protections, it’s Apple

Expand Expanding Close

Frontier hack affects over 750k customers; company waits two months to notify them

Frontier hack | Abstract image of fiber cables

A Frontier hack exposed the personal data of at least 750,000 customers, including full names and social security numbers, which places them at significant risk of identity theft. The ransomware group said to be behind the attack claims that the actual number is two million.

The company has now notified the customers it believes to have been impacted by the security breach, but waited almost two months to do so …

Expand Expanding Close

Security Bite: Apple refused to pay bounty to Kaspersky for uncovering vulnerability part of ‘Operation Triangulation’

Apple breached PERM rules | Drone shot of Apple Park campus

Kaspersky, the renowned Russian cybersecurity firm, made headlines at this time last year after uncovering an attack chain using four iOS zero-day vulnerabilities to create a zero-click exploit. Kaspersky was able to identify and report one of the vulnerabilities to Apple. However, in an unfortunate update, Apple reportedly refuses to pay the security bounty for the firm’s contribution.


9to5Mac Security Bite is exclusively brought to you by Mosyle, the only Apple Unified Platform. Making Apple devices work-ready and enterprise-safe is all we do. Our unique integrated approach to management and security combines state-of-the-art Apple-specific security solutions for fully automated Hardening & Compliance, Next Generation EDR, AI-powered Zero Trust, and exclusive Privilege Management with the most powerful and modern Apple MDM on the market. The result is a totally automated Apple Unified Platform currently trusted by over 45,000 organizations to make millions of Apple devices work-ready with no effort and at an affordable cost. Request your EXTENDED TRIAL today and understand why Mosyle is everything you need to work with Apple.


Expand Expanding Close

Apple promises fewer years of iPhone security updates than Samsung and Google on paper, but reality is a different story

iPhone loses sole smartphone satisfaction crown

Historically, Apple has been hesitant to commit to solid timelines of how long it will support its devices with security and software updates. Now, thanks to a particular UK legal requirement, that has changed. And what the company is promising on paper is surprisingly less than what Samsung and Google commit to—but that’s not the full story.

Expand Expanding Close
TicketMaster hack | Live concert

TicketMaster hack sees personal data of 560M for sale [U: Snowflake statement]

Update: After reports that cloud storage provider Snowflake may have been compromised, the company said there is no evidence of this. Reading between the lines, the attack may have been made via Snowflake, but it appears to have been TicketMaster credentials that were compromised.

A TicketMaster hack has been confirmed by the company in an SEC security filing, stating that personal data of its users has been offered for sale on the dark web. The agency has not confirmed the scale of what appears to have been a massive breach …

Expand Expanding Close

The M4 iPad Pro has a new privacy feature Apple hasn’t told anyone about

Apple M4 chip AI

Over the last few years, Apple has built a reputation for being strong on user privacy. Its marketing likes to emphasize this point often as a way of distinguishing the company from its competitors.

Interestingly though, a new discovery reveals that the just-released M4 iPad Pro includes a new security feature that Apple hasn’t told anyone about.

Expand Expanding Close

Security Bite: Here’s the iOS 17.5 bug that resurfaced deleted photos

apple security release page

After reports of deleted photos resurfacing years later following the installation of iOS 17.5, Apple released iOS 17.5.1 last week to address the issue. But what caused it in the first place? Thanks to some clever reverse engineering by researchers, we have a glimpse at the rare bug responsible.


9to5Mac Security Bite is exclusively brought to you by Mosyle, the only Apple Unified Platform. Making Apple devices work-ready and enterprise-safe is all we do. Our unique integrated approach to management and security combines state-of-the-art Apple-specific security solutions for fully automated Hardening & Compliance, Next Generation EDR, AI-powered Zero Trust, and exclusive Privilege Management with the most powerful and modern Apple MDM on the market. The result is a totally automated Apple Unified Platform currently trusted by over 45,000 organizations to make millions of Apple devices work-ready with no effort and at an affordable cost. Request your EXTENDED TRIAL today and understand why Mosyle is everything you need to work with Apple.


Expand Expanding Close

Manage push notifications

notification icon
We would like to show you notifications for the latest news and updates.
notification icon
You are subscribed to notifications
notification icon
We would like to show you notifications for the latest news and updates.
notification icon
You are subscribed to notifications