Articles tagged "Apple"

Found 103 articles

A new phishing-as-a-service platform named AnonyMousKIT has been discovered, which automates the process of stealing passcodes from iPhones. This service utilizes voice AI agents to trick users into providing their unlock codes, specifically targeting those who have had their Apple devices stolen. Once attackers obtain the passcodes, they can disable the Activation Lock, allowing them to access and potentially resell the stolen devices. This poses a significant risk to iPhone users, as it could lead to increased theft and exploitation of stolen devices. Users are urged to remain vigilant and skeptical of unsolicited calls requesting sensitive information.

Read Original

A security researcher known as Zerotistic has found a way to enroll a Linux device in Apple's Find My network, which typically only supports Apple products. By deceiving Apple's systems, the researcher managed to send location data from the network to a Linux machine. This discovery raises concerns about the security of Apple's location services, as it indicates that unauthorized devices could potentially gain access to sensitive location information. Users of Apple's ecosystem should be aware of this vulnerability, as it could lead to unauthorized tracking of devices. The implications extend to privacy and security, prompting a need for Apple to examine its protocols to prevent similar exploits in the future.

Read Original

On August 18, 2026, Apple addressed a significant security vulnerability in its image handling framework that could allow malicious images to execute harmful code on both desktop and mobile devices. This vulnerability is identified as CVE-2026-65346 and poses a risk to users who may unknowingly open compromised image files. The issue could potentially lead to unauthorized access or control over affected devices, making it crucial for users to update their systems promptly. Apple has released patches to fix this vulnerability, emphasizing the importance of keeping software up to date to protect against such threats. Users of both macOS and iOS devices should ensure they are running the latest versions to mitigate this risk.

Read Original

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has identified four critical vulnerabilities that are currently being exploited in the wild, adding them to its Known Exploited Vulnerabilities (KEV) catalog. Among these is CVE-2026-65400, a serious authentication flaw in Apple macOS that could allow unauthorized access. Other vulnerabilities affect Microsoft SharePoint, VMware vCenter, and Microsoft IKE, all of which pose significant risks to organizations using these platforms. With a CVSS score of 9.8 for CVE-2026-65400, it’s crucial for users and companies to act quickly to mitigate these risks. The exploitation of these vulnerabilities could lead to severe data breaches or unauthorized access, making it essential for affected parties to stay informed and apply necessary updates and patches.

Read Original

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added several vulnerabilities to its Known Exploited Vulnerabilities catalog, specifically targeting flaws in Apple macOS, Microsoft SharePoint, Broadcom VMware vCenter, and Microsoft IKE. One notable vulnerability, CVE-2026-33824, relates to the Windows Internet Key Exchange (IKE) Service Extensions and poses a risk of remote code execution. These vulnerabilities could allow attackers to exploit systems running the affected software, potentially leading to unauthorized access or data breaches. It's crucial for users and organizations utilizing these platforms to take immediate action to mitigate the risks associated with these vulnerabilities. Keeping software updated and applying any available patches is essential to protect against potential exploitation.

Read Original
Actively Exploited

The Cybersecurity and Infrastructure Security Agency (CISA) has added four new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, indicating that they are actively being targeted by cybercriminals. The vulnerabilities include a double free flaw in Microsoft Internet Key Exchange (CVE-2026-33824), a weak authentication issue in Microsoft SharePoint (CVE-2026-55040), a path traversal vulnerability in Broadcom's VMware vCenter (CVE-2026-59310), and an improper authentication vulnerability in Apple macOS (CVE-2026-65400). These vulnerabilities pose significant risks, especially for federal agencies, which are required to prioritize their remediation under Binding Operational Directive 26-04. Although this directive specifically targets federal agencies, CISA encourages all organizations to adopt similar practices to enhance their security posture against these threats.

Read Original

Hackers are exploiting a recently patched vulnerability in macOS, known as CVE-2026-65400, which allows unauthorized access to the macOS Screen Sharing feature. This flaw enables attackers to bypass authentication and gain root access to affected systems, leading to the installation of cryptominers without user consent. The Netherlands’ National Cyber Security Centre has issued a warning about this active exploitation, emphasizing the need for users to update their systems. Apple has released patches for macOS Sequoia (15.7.9), Sonoma (14.8.9), and Tahoe (26.6.1) to address this issue, urging all macOS users to upgrade promptly to protect their devices. Failure to do so could leave systems vulnerable to further attacks and unauthorized resource usage.

Read Original

Recently, a vulnerability in macOS screen sharing has been exploited by attackers to gain root access to affected systems. Once inside, they deployed a Monero miner, which utilizes the system's resources to mine the cryptocurrency without the owner's consent. This incident raises concerns for macOS users, particularly those who rely on screen sharing features for remote work or support. The exploitation of this vulnerability not only compromises the integrity of the systems involved but also highlights the need for users to stay vigilant about software updates and security practices. As the attacks are ongoing, users should be particularly cautious and monitor their systems for unusual activity.

Read Original

A newly discovered vulnerability in macOS, identified as CVE-2026-65400, has a severity rating of 7.1 out of 10 and is being actively exploited for unauthorized cryptocurrency mining. This flaw affects the screen sharing feature of macOS, allowing attackers to hijack resources from targeted machines without user consent. Users of macOS devices should be particularly vigilant, as this vulnerability poses a risk to system performance and could lead to increased electricity costs due to the mining activities. It's crucial for users to stay updated on any patches or updates released by Apple to mitigate this issue and protect their devices from exploitation.

Read Original

A new macOS malware called AmnesiaStealer has been identified, which is written in Rust and targets users' sensitive data. This infostealer can extract passwords, keychain information, and data from Chromium-based browsers as well as Safari cookies. Users of macOS devices are particularly at risk, as the malware can also control browser sessions, making it potentially dangerous for online activities. The emergence of this malware is concerning for individuals who might unknowingly expose their personal information, as attackers can exploit this data for fraudulent purposes. It's important for macOS users to be vigilant about their security practices to protect against such threats.

Read Original

Apple has begun notifying users of targeted mercenary spyware attacks aimed at their iPhones. These notifications alert individuals that sophisticated spyware, often used by state-sponsored groups or private companies, may be attempting to compromise their devices. The alerts are part of Apple's efforts to enhance user security and raise awareness about potential threats. Users who receive these notifications are advised to update their devices and remain vigilant about their online security practices. This development is significant as it highlights the increasing prevalence of spyware and the need for users to be informed about the risks to their personal data and privacy.

Read Original

Researchers have identified a new information-stealing malware targeting macOS users, named AmnesiaStealer. This Rust-based malware can hijack Chromium web browsers, allowing attackers to access and steal session data. AmnesiaStealer is distributed through a fake GitHub download page that pretends to offer legitimate software, misleading users into downloading it. This poses a significant risk to users who might unknowingly provide sensitive information, as attackers gain live control of their browsing sessions. It’s crucial for users to be vigilant about where they download software and to ensure they are using official sources to avoid falling victim to such scams.

Read Original
Actively Exploited

Recent reports reveal that advanced exploit chains targeting iPhones, initially believed to be exclusive to nation-state actors, are now being adopted by organized cybercrime groups. This shift raises concerns as these exploits, which can compromise iOS devices, are becoming more accessible to a broader range of attackers. Users of iPhones, especially those in sensitive sectors, may find themselves at increased risk as these exploits spread. The proliferation of such sophisticated tools could lead to more targeted attacks and data breaches. It's crucial for individuals and organizations to stay vigilant and ensure their devices are updated to mitigate potential risks.

Read Original
Actively Exploited

A new variant of malware targeting macOS systems has been discovered, designed to steal cryptocurrency, passwords, and other sensitive information. This malware is particularly concerning for users involved in cryptocurrency transactions, as it can easily siphon off digital assets. Researchers have identified that the malware is capable of harvesting a wide array of personal data, raising alarms about the security of macOS users. With the growing popularity of cryptocurrencies, this incident underscores the need for enhanced security measures among users to protect their digital wallets and personal information. Users should remain vigilant and consider implementing additional security practices to safeguard against such attacks.

Read Original

Researchers have discovered a vulnerability in Apple's iCloud Private Relay, a tool designed to protect user privacy by masking IP addresses when using Safari. This feature, which uses a dual-hop system to route traffic through two relays, can potentially expose users' real IP addresses due to certain bypasses in the WebKit proxy. This issue affects anyone using iCloud Private Relay on devices running iOS 15 or later. The revelation raises concerns about user privacy, as the very purpose of the service is to prevent third parties, including Apple, from tracking user locations. Users should be aware of this flaw and consider additional privacy measures until a fix is implemented.

Read Original
Page 1 of 7Next