- ποΈβ Your Security Checklist
- πποΈ Test Your Security Skills
- π° Your Weekly Security Update
- π€¨ This Should Be on Your Radar π‘
- π Security Fail of the Week π
- ππ± Security Updates from Apple π
If you take nothing else from this newsletter, just do these three things to protect yourself:
- Do not respond to scam texts. Scammers like to send texts about undeliverable packages, unpaid tolls, wrong numbers, impersonating family members, and more. Even responding to say you know the text is a scam lets the scammers know your phone number is active and you're responsive.
- Learn how to spot scam emails. A common scam tactic is to email you fake invoices about expensive memberships and products, with a phone number to call to dispute the charge. You should never call these numbers.
- Avoid clicking or tapping on scam ads. Occasionally, you might come across pop-ups online that warn you that your iPhone has been infected with a virus. This is a scam, and you should close the tab right away.
What should you do in the following scenario?
Your friend is having trouble AirDropping you a photo, so you turn on the "Everyone for 10 minutes" setting. Then, you receive an AirDrop request for a file you don't recognize. What should you do? π€
- Accept it. It could be a funny meme.
- Decline it. It could be a malicious file.
Scroll to the bottom to see how you did!
Hide My Email is an iCloud+ feature that allows you to create a dummy email address that will forward messages to your primary email address. This allows you to sign up with websites and services without giving out your actual email address, which, in theory, should keep your identity anonymous. However, new reports from EasyOptOuts and 404 Media claim that Hide My Email is not as anonymous as it seems. The vulnerability, which was discovered and reported to Apple over a year ago but hasnβt been fixed yet, allows an attacker to see the primary email address linked to a Hide My Email address. Both parties are publicizing the existence of this vulnerability in the hope that it will pressure Apple to patch it, but details of the vulnerability itself are being kept under wraps since it can still be exploited by attackers. Head over to 404 Media for the full story.
The Bottom Line: While Hide My Email has always been great for keeping your email address off of mailing lists, Apple can connect your real account to the dummy accounts, so it has never been a tool for true anonymity online. However, this is still extremely disappointing news coming from Apple, a company that has traditionally emphasized the privacy of its users. We hope that Apple will respond to this story and find a way to patch the vulnerability.
This Is Why You Should Never Enable AirDrops from Everyone
A second Apple vulnerability emerged in the past week. This time, the affected feature is AirDrop. Researchers Arash Ale Ebrahim and Nils Ole Tippenhauer at the CISPA Helmholtz Center for Information Security discovered that a Wi-Fi-enabled laptop can push malicious code to both iPhone and Android phones through AirDrop and Android's Quick Share and cause a crash. For iPhones, this will only work if AirDrop's "Everyone for 10 Minutes" option is enabled. Get more details at Cybernews.
The Bottom Line: iPhone users can combat this vulnerability by ensuring they do not enable "Everyone for 10 Minutes" when out in public. Thankfully, the attacker needs to be within 30 feet of the phone for this vulnerability to be exposed, which means you don't need to worry about hackers on the other side of the world breaching your device via AirDrop.
Did Your Child Get a New Phone Number or Are You Being Scammed?
A new text scam has emerged, similar to wrong-number text scams. How it differs is that the scammer pretends to be the victim's adult child, texting from a different phone because they dropped theirs in the sink. They tell the victim that if they need to reach them, to text them at a new number. The scam is effective since it gives the victim a plausible reason why they wouldn't be able to reach their child and why their child might have a new phone number. Check out the full details of the scam and how it works over at Fox News.
The Bottom Line: If you receive a text like this, do not respond to it, and definitely do not text the supposed new number. More than likely, the scammer will attempt to convince you to send money for a new phone or something similar. Call or text your child at their original phone number and wait for a response before moving forward.
How a Police Officer Stalked a Woman Using License Plate Readers
While working security on the set of a TV show, a police officer became infatuated with a woman who was also working on the set. After pressuring her into giving him her name and social media, the officer decided that if she was not going to tell him, he would find out for himself by looking up her license plate number using Florida's Driver and Vehicle Information Database (DAVID). DAVID is a law enforcement tool that can be used to locate where a specific vehicle is at any given moment. The officer put the woman's license plate on a surveillance hotlist that would give him an alert any time she drove past an automated license plate reader (ALPR) camera, like the ones used by Flock. The officer used this information to stalk the woman, drove recklessly through traffic to get to her, nearly causing multiple accidents, and eventually pulled her over just to talk to her. Check out 404 Media for more.
The Bottom Line: This story is yet another example of how surveillance systems like ALPRs can be abused. We continue to recommend that concerned individuals express their concerns to their local representatives to rein in the spread of Flock ALPRs.
Texas to Enforce Age Verification for App Stores
Last year, Texas passed a law requiring app stores to verify users' ages before they can download apps or make in-app purchases. It was later temporarily blocked by a federal judge, but the Supreme Court has now unblocked it and is allowing the law to go into effect. CNN has the full story.
The Bottom Line: If you live in Texas, you will soon need to verify your age before you can download any apps or make in-app purchases. On the iPhone, you can verify your age either by having an account that was created more than 18 years ago, by adding a credit card to your account, or by scanning your ID. If you don't want to verify your age, you can try using a VPN to spoof your location to a different state.
Flock Continues Recording Despite Contract Cancellation
In another ALPR-related story, the city of Cleveland voted against renewing its contract with Flock, which normally should have meant that the cameras would be shut off. However, once the city's contract expired at the end of June, a local journalist discovered that the cameras were still operational and that law enforcement was still using them. Cleveland isn't an isolated incident either. It appears other cities in Massachusetts and Oregon have experienced a similar issue. Head over to Gadget Review for more.
The Bottom Line: It seems that even if a city installs Flock cameras and later decides to discontinue them, the company often feels free to continue recording. The best way to fight against Flock is to ensure your city never installs the cameras in the first place. In some jurisdictions, the power to vote or even just contact your local representative can influence decisions such as these.
How Hackers Used TV Boxes to Hide Their Activity
Google and the FBI have worked together to bring down a massive botnet. The botnet, known as NetNut, was using Android-based smart TVs and TV boxes as proxies, which essentially means malicious actors could route internet traffic through these devices, making it harder to track their activity. NutNet had access to over 2 million devices worldwide, all belonging to normal everyday individuals who had no idea their TV boxes were being used by hackers. Find out how Google and the FBI accomplished this monumental effort at TechSpot.
The Bottom Line: The devices affected by NutNet were off-brand TVs and TV boxes that had been jailbroken to include modified apps (for example, a version of the YouTube app that blocks ads). While this botnet has already been brought down, it does demonstrate the danger of purchasing these types of devices. Stick to well-known, reputable brands, and avoid offers that sound too good to be true.
Is That a Normal Pair of Glasses or Are You Being Recorded?
Smart glasses are spreading and the odds of coming across someone recording you without your knowledge increase every day. Cybersecurity journalist Zack Whittaker wrote a great opinion piece on the rise of smart glasses, the dangers that they pose to privacy, and how the internet is dubbing them "pervert glasses." We recommend checking out his write-up.
The Bottom Line: Smart glasses are a frightening technology, especially now that Meta in particular seems interested in implementing facial recognition technology into its wearable. We should all be wary of them.
The UK to Use AI to Check Ages of Asylum Seekers
The UK government has announced that it will begin using AI facial recognition technology to determine the ages of asylum seekers. The Home Office claims this move is to make it easier to identify adults who are pretending to be children to make getting into the country easier. However, human rights groups are questioning the accuracy of this technology, due to a report from last year in which AI facial recognition incorrectly identified children as adults and vice versa. Additionally, the Home Office is using AI to summarize the transcripts of asylum seeker interviews and process applications. Many of these AI summaries have proven to be inaccurate to the point that they were removed from the transcripts.
The Bottom Line: The Home Office's use of AI summaries has been called unlawful by some legal experts, and human rights organizations have called on the government to pull any plans to use facial recognition. Whether the UK government will take action to ensure asylum seekers are not denied entry based on the opinions of an artificial intelligence remains to be determined.
Can Claude Get You Free Concert Tickets?
What if you could use AI to get into any concert you wanted? A security researcher named Ian Carroll discovered a vulnerability that allowed him to do just that. Carroll found that using Claude, he could access the backend of Front Gate Tickets, a vendor used by nearly all major music festivals in the US. If he had wanted to, Carroll could have given himself any number of tickets or backstage passes, some worth thousands of dollars, even if they were marked as being sold out. Ultimately, Carroll did not do that, and instead disclosed the vulnerability to Front Gate, which was then patched. Check out the full story at Wired.
The Bottom Line: Thankfully, Front Gate was quick on the draw and patched the vulnerability in less than 24 hours. The company also clarified that no customer data was exposed, since the exploit only allowed access to its internal application programming interface (API).
- The most recent iOS and iPadOS is 26.5.2
- The most recent macOS is 26.5.2
- The most recent tvOS is 26.5
- The most recent watchOS is 26.5
- The most recent visionOS is 26.5
Read about the latest updates from Apple.
The correct answer is B. Decline it. It could be a malicious file. AirDrop can be used to send malicious code to your iPhone, so you should only accept AirDrops from people you know.
There is far too much security and privacy news for us to cover it all. When building this newsletter, we look for scams, hacks, trouble, and news to illustrate the kinds of problems Apple enthusiasts may encounter in our private lives, and the self-defense we can practice to keep our devices, accounts, and lives secure. Our commentary focuses on practical advice for everyday people. This newsletter was written byΒ Cullen ThomasΒ andΒ Rhett IntriagoΒ and edited byΒ August Garry.
Worried about your iPhone being infected with a virus? Check out:
|
