- ποΈβ Your Security Checklist
- πποΈ Test Your Security Skills
- π° Your Weekly Security Update
- π€¨ This Should Be on Your Radar π‘
- π Security Fail of the Week π
- ππ± Security Updates from Apple π
If you take nothing else from this newsletter, just do these three things to protect yourself:
- Consider enabling Advanced Data Protection. This optional security setting allows you to encrypt your iCloud data. Be careful, though: if you lose your password, Apple cannot help you recover your account.
- Enable iCloud Private Relay. If you are an iCloud Plus subscriber and use Safari as your default web browser, Private Relay allows you to stay private while visiting your favorite websites.
- Lock sensitive apps with Face ID. While some apps allow you to use Face ID to log in, you can also lock apps so that they cannot be opened without first scanning your face or entering your passcode.
What should you do in the following scenario?
You download a game from the App Store, and upon opening it, it requests access to your location. What should you do? π€
- Don't allow it to access your location.
- Allow it to access your location.
- Close the app and delete it.
Scroll to the bottom to see how you did!
Back in May, we reported that the US Supreme Court would be deliberating the legality of geofencing warrants. As a quick refresher, geofencing is the practice of using location data to detect when a device enters or exits a certain area on a map. Law enforcement has been able to request this customer location data from companies like Google without a warrant. When the Supreme Court deliberations began, some of the justices argued that location data recorded by Google could not be considered private since it was collected by a third party. However, the Supreme Court has now decided that "an individual has a reasonable expectation of privacy in his cell-phone location information." Read more at TechCrunch.
The Bottom Line: This is a huge win for privacy. Law enforcement will now need a search warrant to obtain location data from Google and similar vendors and will need to be more specific about the data they request. By extension, this also means that police will need to establish probable cause before obtaining a warrant.
How Scammers Are Using AI to Their Advantage
With the advent of artificial intelligence, scammers' jobs have become much easier than ever before. With the help of AI, scammers are building new tools to target the most vulnerable individuals. AI allows them to do things like impersonate the voice of a victim's loved one or use automated chatbots to trick victims into thinking they're simply chatting with someone who texted the wrong number, making it harder to identify scams. ABC News has a great write-up on how scammers are taking advantage of AI.
The Bottom Line: Scams are becoming more sophisticated thanks to AI. It's important to stay informed about the latest scams and be cautious when it comes to online transactions. Never send money to people you've never met before, never pay for deals that seem too good to be true, and never respond to texts or emails that claim you owe money.
Your Windows 10 PC Has Been Given Another Year of Life
Last year, Microsoft announced that it was ending support for Windows 10 and that users would need to upgrade to Windows 11 to continue receiving software updates. The company later decided that users who enrolled in the Extended Security Updates program would continue receiving important security updates through October 2026. Microsoft recently updated its ESU documentation to show that ESU support has been extended another year, with updates currently scheduled to end in October 2027. Read more at Windows Latest.
The Bottom Line: If you're a Windows 10 user, we strongly recommend either enrolling in the ESU program or upgrading to Windows 11. You can find out more about the ESU and how to enroll your computer at Microsoft.
Nissan Employees Exposed in Data Breach
Car manufacturer Nissan is the latest victim of a data breach, in an incident related to the Oracle PeopleSoft breach we reported on a couple of weeks back. The breach appears to affect both current and former employees of the company, exposing a trove of private information, including banking details, social security numbers, tax records, and more. The company is working with Oracle to respond to the breach and will be offering affected employees credit monitoring services. Read more about the data breach at The Register.
The Bottom Line: If you are a past or current employee of Nissan, you have likely already been informed about this data breach. If the company has offered you credit monitoring, we recommend taking advantage of it. We also recommend freezing your credit whether or not you are impacted by this data breach, as it can protect your identity if your personal information is exposed in other data breaches.
Gemini in Google Chrome Can See Your Screen
Google Chrome is moving toward becoming an AI-focused web browser. While it can be disabled in the browser settings, Gemini's integration in Google Chrome runs deep. A new "select from screen" tool allows you to show Gemini the contents on your screen and ask it questions or get help. Of course, this means revealing whatever is on your screen at the time, whether it's something inconsequential like an Amazon product page or something as sensitive as your banking details. Cybernews has more information.
The Bottom Line: If you use Gemini, we don't recommend sharing your screen with Gemini. If you want to disable Gemini completely, you can turn it off in Chrome's settings, or you can try out a privacy-focused web browser, such as Firefox or DuckDuckGo.
Data Breach at Japanese Telecom
A Japanese telecom company, KDDI Corporation, was breached last week. Hackers exploited a vulnerability in the company's email system, which is used by five internet service providers (ISPs). While the exact number of affected customers is unknown, KDDI suspects that millions of email and password combinations may have been exposed. Impacted customers are being urged to change their account passwords and enable two-factor authentication wherever possible. Read more at Bleeping Computer.
The Bottom Line: If you live in Japan and have an account with any of the five affected ISPs listed in the Bleeping Computer article, you likely have already been contacted about this data breach. We recommend following KDDI's advice and changing your password as soon as possible.
Woman Surprised By Flock Device in Her Front Yard
As if the mere existence of Flock cameras was not bad enough, it seems that now the company can install devices on a homeowner's property without permission. A woman in Roanoke, VA, was surprised to find that a Flock "gunshot detection device" had been installed in the front yard of her home. She did not receive any notice and was not asked prior to the device being installed, but now there is a microphone sitting in front of her house monitoring the area 24/7. Check out the full story at WSLS News.
The Bottom Line: Thankfully, it appears that this listening device was installed in error. Flock devices had been approved for installation in several areas throughout the city, and mistyped addresses and street numbers resulted in many of these devices being incorrectly installed. This is just one of many reasons to oppose Flock devices. There's no telling when they'll end up somewhere they shouldn't or when they might be used against innocent people.
Redesign of Government Websites Bypasses Privacy Protections
Last year, President Trump established the National Design Studio (NDS), a government department responsible for web design. The department has redesigned multiple government websites. An analysis by The Guardian found that these redesigned websites could now bypass privacy-preserving tools, like tracking protection and ad blockers, and do not have the necessary public filings required by federal privacy law. The Guardian has a more detailed breakdown.
The Bottom Line: After The Guardian reached out to the White House with questions about these websites, the NDS removed the tracking software it had been using, though it is still concerning that it was there in the first place. Citizens should be able to trust government websites and not have to worry about their activity being tracked.
Secret Society Leaks Its Members List
Dialog, the secretive invite-only organization headed up by Peter Thiel, experienced a data leak last week. Dialog claims it was breached by a well-known criminal hacker; however, according to Wired, the leaked files were publicly accessible via the organization's website. The leaked data included the names of at least 113 individuals who had attended Dialog events in the past. Check out the full story at Wired.
The Bottom Line: Cybersecurity is difficult to get right, but it's one of the most important parts of maintaining a secret organization. Dialog leaking participants' names is certainly not ideal and likely does not inspire confidence in its members.
- The most recent iOS and iPadOS is 26.5.2
- The most recent macOS is 26.5.2
- The most recent tvOS is 26.5
- The most recent watchOS is 26.5
- The most recent visionOS is 26.5
Read about the latest updates from Apple.
In most cases, the answer will be A. Don't allow it to access your location. Of course, this isn't a one-size-fits-all solution. A location-based game, such as PokΓ©mon Go, requires access to your location to function, in which case it would make more sense to allow it. However, if the game you have downloaded is something simpler, like a puzzle game, there's no need for it to have access to your location, so you should not allow it.
There is far too much security and privacy news for us to cover it all. When building this newsletter, we look for scams, hacks, trouble, and news to illustrate the kinds of problems Apple enthusiasts may encounter in our private lives, and the self-defense we can practice to keep our devices, accounts, and lives secure. Our commentary focuses on practical advice for everyday people. This newsletter was written byΒ Cullen ThomasΒ andΒ Rhett IntriagoΒ and edited byΒ August Garry.
Interested in getting started with a password manager? Check out:
|

