Skip to main content

Security

See All Stories

Future AirPods may verify your identity by checking the shape of your ear canal

Future AirPods may verify your identity

While most current Apple devices can verify your identity by fingerprint or face recognition, Apple is also considering adding biometric identification to future AirPods.

A patent application describes two potential ways that AirPods could confirm your identity before allowing access to sensitive data, like asking Siri to read your messages…

Expand Expanding Close

DazzleSpy Mac malware enabled key-logging, screen captures, file extraction, more

DazzleSpy Mac malware

Security researchers have released details of DazzleSpy – Mac malware that enabled key-logging, screen captures, microphone access, and more.

DazzleSpy was used to target Hong Kong democracy activists, initially through a fake pro-democracy website, and later through a real one, in a so-called watering hole attack …

Expand Expanding Close

Student who hijacked iPhone camera did the same to the Mac; Apple paid bug bounty of $100K

Site default logo image

Apple paid a bug bounty of $100K after a cyber security student who successfully hijacked the iPhone camera back in 2019 did the same with the Mac camera.

Ryan Pickren used an imaginative approach that allowed him to run arbitrary code on a target Mac, and received what he believes to be the largest bug bounty Apple has ever paid …

Expand Expanding Close

SysJoker shows that even Mac malware runs natively on M1 Macs now

SysJoker Mac malware

We may still be waiting for some developers to update their apps to run natively on M1 Macs, but the developer of SysJoker Mac malware is already on the case.

Security researcher Patrick Wardle points to what he says is the first Mac malware of 2022, and it runs on both Intel and M1 Macs. SysJoker can be controlled remotely by an attacker, allowing it to be used in many different ways …

Expand Expanding Close

Mandatory Chinese Olympics app collects personal data, has two security holes

Site default logo image

Use of the Chinese Olympics app, MY2022, is mandatory for everyone attending this year’s Olympic Games in Beijing, whether as an athlete or simply watching from the stadium.

The app collects sensitive personal data – like passport details, medical data, and travel history – and analysis by security researchers reveals that the code has two security holes that could expose this information …

Expand Expanding Close

Apple and other big tech companies to attend White House meeting to talk software security

Apple White House promises broadband for all

Apple, Google, Amazon, Meta, and IBM will attend a meeting at the White House to discuss software security after the US suffered several major cyberattacks in 2021. As reported by Reuters, this meeting will take place today and will be hosted by deputy national security advisor for cyber and emerging technology Anne Neuberger.

Expand Expanding Close

Latest suspected NSO phone hack: Journalists and activists in El Salvador

Another suspected NSO phone hack has come to light, this of journalists and activists in El Salvador. Most of the journalists were working for an online news service that has been reporting extensively on alleged government corruption.

Two journalists contacted Citizen Lab after suspecting that their phones had been compromised, and an investigation confirmed their suspicions, and found that they weren’t the only ones …

Expand Expanding Close

New report suggests Uganda used NSO spyware to hack State Department iPhones

Uganda used NSO spyware to hack State Department iPhones

We learned earlier this month that NSO’s Pegasus spyware was used to hack US State Department iPhones in Uganda, with no clue at the time who the attacker was.

A new report strongly suggests that the Ugandan government was behind the attacks, as the country – which has an appalling human rights record – is now known to have purchased the spyware. It also appears that this was, indirectly, the tipping point that led to NSO’s downfall…

Expand Expanding Close

After US ban and Apple action, Pegasus spyware maker NSO running out of cash

Pegasus spyware maker NSO running out of cash

Pegasus spyware maker NSO Group is reportedly running out of cash following actions by both the US government and Apple. This has led the company to explore options to put itself up for sale.

Two US funds have expressed an interest, claiming that they would change the company’s mission from offensive to defensive, though skepticism has been expressed about this …

Expand Expanding Close

Apple alerted Polish prosecutor that her iPhone has likely been compromised by NSO

Site default logo image

As part of hitting back at spyware company NSO, Apple alerted a Polish prosecutor that her iPhone appears to have been compromised by Pegasus. This also gives us our first look at the text of Apple’s security alerts.

Although Poland has not admitted purchasing and using the spyware, there is significant evidence that it has done so …

Expand Expanding Close

Apple will alert customers who may have been targeted by NSO

Apple will alert customers who may have been targeted by NSO

Journalists, lawyers, politicians, and human rights activists have all been targeted by NSO’s Pegasus software, and Apple has now said that it will send security alerts to customers whose devices may be been compromised. It has already done so for at least five Thai activists and researchers.

It follows Apple’s announcement yesterday that it is suing NSO for attacking iOS users …

Expand Expanding Close

Charges against alleged member of REvil ransom group that obtained MacBook Pro designs

REvil ransom group charges

An alleged member of the REvil ransom group has been charged, with $6.1M in funds seized from another suspect, according to the US Department of Justice.

Back in April, we learned that the REvil group accessed systems belonging to Mac assembler Quanta and obtained schematics of the upcoming MacBook Pro models, which accurately revealed the HDMI, MagSafe, and SD card slot …

Expand Expanding Close

NSO – whose Pegasus spyware hacks iPhones – officially named by US as a national security risk

Pegasus spyware sees NSO named as US national security risk

The NSO group, whose Pegasus spyware is used to hack iPhones and Android smartphones, has been officially named by the US government as a threat to national security.

The Commerce Department’s Bureau of Industry and Security (BIS) has added the Israeli company to the Entity List, which bans the company’s products from being imported, exported or passed from one organization to another within the US.

Expand Expanding Close

NYT journalist describes his iPhone being hacked, and the precautions he now takes

NYT journalist describes his iPhone being hacked

A New York Times journalist covering the Middle East has described the experience of his iPhone being hacked, and the security precautions he now takes as a result.

Ben Hubbard says there were four attempts to hack his iPhone, and that two of them succeeded, with all the signs pointing to the use of NSO’s Pegasus spyware.

Expand Expanding Close