- ποΈβ Your Security Checklist
- πποΈ Test Your Security Skills
- π° Your Weekly Security Update
- π€¨ This Should Be on Your Radar π‘
- π Security Fail of the Week π
- ππ± Security Updates from Apple π
If you take nothing else from this newsletter, just do these three things to protect yourself:
- Be sure to use a password manager. Password managers are the most secure way to manage your passwords and keep your accounts secure. Your iPhone has a password manager pre-installed: the Passwords app.
- Stay wary of scam texts. Scammers often send out texts about undeliverable packages, unpaid tolls, fake job offers, and more. Know how to spot them so you can avoid them.
- Consider switching to DuckDuckGo. Google is the most popular search engine but is notorious for failing to respect user privacy. DuckDuckGo, on the other hand, is a search engine that is built with privacy in mind.
What should you do in the following scenario?
Which of these types of accounts makes sense to sign in to using Hide My Email, and which ones should you give your real email address? π€
- Your doctor's office's online portal.
- A local grocery store's rewards program.
- A Public Wi-Fi sign-in page.
- A streaming service like Netflix.
Scroll to the bottom to see how you did!
Cyberattacks against water infrastructure are becoming increasingly common in the US, with at least seven states being targeted. Most water facilities are connected to the internet in some shape or form, which makes them vulnerable to attack. Minnesota is one state that has been hit relentlessly with disruptions to its water supply, thanks to attackers breaching the facilities' computers to change passwords and lock out operators.
With America's water supply at risk, Senators Adam Schiff and Amy Klobuchar have introduced a bill aimed at strengthening the cyber defense capabilities of water infrastructure nationwide. The bill would require cybersecurity assessments and corrective action at water facilities, expanded federal cyber-incident reporting, additional funds to improve cybersecurity, and much more. Check out the full announcement for details, or read the bill itself.
The Bottom Line: It goes without saying that water is a vital resource, and cyberattacks against water infrastructure put everyone at risk. We're hopeful that this bill will help water supply facilities defend against cyberattacks.
Popular Ad Blocker Gives Up on Facebook
One of the most popular and effective ad-blocking browser extensions on the market is uBlock Origin. However, uBlock recently announced that it is giving up the fight against Facebook ads. According to uBlock, Facebook watches open-source ad blockers carefully and is quick to change the site's code to get around their ad-blocking capabilities. Since uBlock's team is made up of voluntary programmers, they just don't have the resources to keep up with Facebook. Read more at Digital Escape Tools.
The Bottom Line: uBlock Origin is still effective against Facebook ads for the time being, but once the social media giant finds a way around uBlock's current capabilities, the ad blocker's Facebook-specific filters will not work anymore. Even without being able to block Facebook ads, uBlock is still a great ad blocker.
More Cities Turn Their Backs on Flock
In this week's roundup of Flock news, the city of Chandler, Arizona decided not to renew its contract with the surveillance company after an audit suggested police may have been misusing its network of automated license plate readers. The audit found an "anomaly that could not be explained through standard police work," though no further details were provided. Those Chandler officers were not alone, as police in Savannah, Georgia were also found to be abusing the department's access to Flock. Six Savannah police officers have been fired while the Georgia Bureau of Investigation looks into the matter.
Meanwhile, the town of Littleton, Massachusetts discovered that the Flock cameras it had disabled were quietly reactivated by the company without notifying the town. We reported on a similar story in Cleveland, Ohio a few weeks back, where the city's Flock cameras continued surveilling despite the city canceling its contract.
The Bottom Line: You can use sites like DeFlock to find out if there are any Flock cameras in your area. Using DeFlock can help you plan a route that avoids any Flock cameras. But be wary, as the government has begun monitoring social media to flag anti-Flock content. It is not against the law to criticize a company, though encouraging vandalism or violence is. That's why we always encourage you to contact your representatives instead. If the presence of these surveillance devices concerns you, be sure to voice your opinions to your local representatives. In some jurisdictions, citizens' negative reception of Flock has proven successful in shutting the cameras down.
Another AI Goes Rogue & Hacks Three Companies
Just weeks after OpenAI let a rogue AI hack a rival company, Anthropic has confirmed that its AI models have also escaped containment and hacked three undisclosed organizations. Anthropic says that a misconfiguration during testing of its AI models is to blame. The AI was able to gain access to the internet when it wasn't supposed to, which allowed it to take advantage of weak passwords and unpatched vulnerabilities. Read more at Wired.
The Bottom Line: AI models capable of hacking on their own sound like a major threat at first. However, in reality they pose little to no threat to the average individual. These AI models are expensive to produce and consume a lot of energy to work, so this isn't the type of tool your run-of-the-mill hackers or scammers are going to be using.
What Happens When Your Doctor Wears Meta Glasses?
A woman took to social media after noticing that her friend's doctor was wearing Meta smart glasses during their appointment. This was especially concerning because the doctor was a cosmetic surgeon, meaning many of his appointments involve patients stripping down in front of him. The doctor claimed that the glasses were not recording, but many Meta glasses users are able to find ways to disable the recording light, making it impossible for others to tell whether or not the glasses are recording. Read more at Fashion Times.
The Bottom Line: Meta glasses are not HIPAA compliant, and a doctor using them to record while a patient is in the room is illegal. However, this situation is a bit complicated since the doctor claims that he does not use the recording feature with patients. If you encounter a doctor wearing Meta smart glasses and feel uncomfortable, you can request that they be removed.
Researcher Tricks Flock Cameras by Wrapping Car in Bizarre Pattern
Cybersecurity researcher Bill Swearingen, tired of Flock and other types of automated license plate reader cameras, decided to do something about it. He developed an AI model that can generate patterns and test them against camera-detection software until it creates a pattern that cannot be detected. Swearingen then covered a car with the pattern and drove it past a Flock camera. Due to the very specific pattern of the car wrap, the camera's software does not even recognize that a car has passed by, meaning no details of the car's make, model, or license plate number are recorded. Read more at TechSpot.
The Bottom Line: Using goofy patterns to trick camera detection software is a fun idea but isn't very practical in real-world scenarios. Camera detection software can easily be updated to recognize patterns like the one used in Swearingen's experiment.
Popular Video Game Company Affected by Breach
Video game company Valve Corporation has begun emailing customers about a possible data breach at one of its third-party distribution partners. CEVA Logistics, which handles Valve hardware distribution in Europe, was breached by hackers at the end of July. Data that was potentially stolen includes names, addresses, phone numbers, email addresses, and more. Head over to Neowin for more on this story.
The Bottom Line: If you are a Valve customer living in Europe, you should have already been notified about this data breach with next steps.
Site Offering Human Writing Services Found to be AI-Generated
A website offering 100% human-written services to medical researchers was found to be completely AI-generated. 404 Media reports that, despite claiming that it doesn't use AI, everything about the company is AI-generated. The phone line, email address, and chat are all monitored by an AI bot, while the PhD reviewers that the site claims to have hired are all either AI-generated or are the names and photos of real people who were completely unaware their identities were being used. The names and photos of real researchers have since been removed from the site.
The Bottom Line: When scam sites like this pop up, claiming to offer writing services that use no AI at all, it erodes trust in actual, credible sites that offer the same services. Unfortunately, it is now more important than ever to stay cautious about possible AI-generated content.
Can Hackers Use Zoom to Take Control of Your Computer?
Researchers at the security firm A Security used AI to find a vulnerability in Zoom that allowed attackers to silently take over a user's machine while on a video call. Thankfully, once the researchers discovered the vulnerability, they reported it to Zoom, which quickly rolled out a patch to fix the exploit. Read more at Wired.
The Bottom Line: If you have Zoom installed on your computer, be sure that the app is up-to-date so that you are protected against this vulnerability.
Hacker Hijacks Airplane Wi-Fi Network
Last week was DEF CON, a conference for hackers and security researchers, held annually in Las Vegas. On Sunday, after the conference had ended, a Delta flight departing Vegas was hit by a cyberattack. A hacker on board the plane managed to remotely disable the plane's onboard Wi-Fi router. They then set up their own Wi-Fi router with the name Delta WiFi Fast, which many passengers connected to. The hacker set up a phishing page with a Google login, allowing them to collect the credentials of anyone who connected to the network. However, unbeknownst to the hacker, the crew of the plane caught on to their scheme right away and alerted federal agents, who were waiting when the plane landed and seized the hacker's equipment and arrested them. Check out the full story at View from the Wing.
The Bottom Line: If you intend to commit cybercrimes, doing them on an airplane is probably not the smartest idea. A plane is a confined space, which makes it easy to identify the source of an attack, since the perpetrator would have to be onboard. It was only a matter of finding out which passenger had a Wi-Fi router.
- The most recent iOS and iPadOS is 26.6
- The most recent macOS is 26.6.1
- The most recent tvOS is 26.6
- The most recent watchOS is 26.6
- The most recent visionOS is 26.6
Read about the latest updates from Apple.
There is far too much security and privacy news for us to cover it all. When building this newsletter, we look for scams, hacks, trouble, and news to illustrate the kinds of problems Apple enthusiasts may encounter in our private lives, and the self-defense we can practice to keep our devices, accounts, and lives secure. Our commentary focuses on practical advice for everyday people. This newsletter was written byΒ Cullen ThomasΒ andΒ Rhett IntriagoΒ and edited byΒ August Garry.
Want to learn more about the Passwords app? Check out:
|
