- ποΈβ Your Security Checklist
- πποΈ Test Your Security Skills
- π° Your Weekly Security Update
- π€¨ This Should Be on Your Radar π‘
- π Security Fail of the Week π
- ππ± Security Updates from Apple π
If you take nothing else from this newsletter, just do these three things to protect yourself:
- Delete and report scam texts. Phishing texts are a common way for scammers to trick you into handing over private information. Learn how to identify USPS and other scam texts.
- Use a password manager. Password managers are great tools that can save your passwords and create secure ones instantaneously. Here are our password manager recommendations.
- When possible, sign in to apps and websites using your Apple Account. Signing in with your Apple Account avoids the need to create a new password and can also hide your email to prevent spam.
What should you do in the following scenario?
You receive a text telling you that there is an issue with a recent order you placed. It provides a link and a phone number, urging you to update your credit card details or risk losing the order. You remember that you did recently order something online. What should you do? π€Β
- Open the link and enter your credit card details.
- Call the number to see if you can find out more information.
- Report the text as spam and delete it.
- Double-check your order details on the app or website that you ordered from.
Scroll to the bottom to see how you did!
Back in April, we reported that Booking.com had been breached and that customer reservation data had been leaked. Now, that leaked data is being used in reservation hijack scams. Scammers are using real reservation information to send out phishing texts and emails to trick Booking.com customers into handing over sensitive information like credit card numbers. The scam works by telling the victim there is a problem with their reservation and urging them to open a link to fix it. Read more at Wired.
The Bottom Line: If you have used Booking.com and you receive a text or email about your reservation, do not click on any links or respond to the message. Instead, reach out to the hotel directly. If there really is an issue with your reservation, the hotel will be able to help.
Executive Order Seeks to Bolster Cybersecurity with AI
President Trump has signed an executive order requesting that developers of new large language models submit their work to the US government for review before making their LLMs public. The order has also directed the Department of Defense, the Department of Homeland Security, and the Cybersecurity and Infrastructure Security Agency (CISA) to find new ways to enhance cyber defenses with the assistance of AI. Previously, under the Trump Administration, CISA was subjected to stringent cuts by the Department of Government Efficiency. Read more at Reuters or check out the executive order itself.
The Bottom Line: This order is unlikely to change anything day-to-day for most of us. The order doesn't address the concerns of AI enthusiasts or skeptics, such as the environmental effects or user privacy.
Third-Party UK Visa Website Breached
An online visa-processing platform called UK Visa Portal has exposed the data of at least 100,000 of its customers. The leaked data includes passports and photos of applicants. The website, which is a third-party website not associated with the UK government, was storing the images on an Amazon-hosted server. While the server itself was not publicly accessible, the images could be accessed just by entering the web address containing each file. According to TechCrunch, the customer selfies contained location metadata, revealing exact addresses to anyone with access to the images.
The Bottom Line: If you used UK Visa Portal to apply for a UK visa, your data may have been exposed. The company will likely soon begin notifying customers of the breach with information on next steps.
Signal Users' Chats Targeted by Phishing Attacks
A new phishing campaign is targeting Signal users, attempting to steal their chat history. Attackers impersonate Signal support and send a message to users, warning that their backed-up chats could be lost due to a sync issue. To fix it, "Signal Support" needs the user's account recovery key. Of course, sending the recovery key to the attacker gives them full access to the user's Signal account. According to Washington Post analyst Josh Rogin, the main targets of this campaign are anti-Chinese Communist Party activists. Read more at TechCrunch.
The Bottom Line: Signal customer support will never ask you for your password, 2FA codes, or recovery codes. If you're a Signal user and receive a message purportedly from Signal Support asking for any type of credentials, you're likely being targeted by a phishing attack. All you need to do is block the sender and delete the message.
Data Brokers Selling Location Data of US Troops' Phones
Since at least 2016, the Pentagon has been aware that US military troops can be tracked using commercially available location data. Data brokers sell this information to advertisers and foreign agencies alike. It doesn't help that the Army recently instructed soldiers to use their personal phones for government work, making it easier than ever to track military devices. Read more at Wired.
The Bottom Line: If you want to keep your device as private as possible, we recommend using a reliable VPN, like Proton or Mullvad, along with a privacy-focused web browser like Firefox or Safari. You should also disable location tracking for all apps that do not require it in Settings > Privacy & Security > Location Services.
Online Therapy Service Wants to Scan Clients' Faces
An online therapy platform called Headway announced that it will require clients to upload an image of their driver's license and submit to a facial scan to continue using the service. There is no option to opt out, and it is a requirement for all users going forward. The company is partnering with Persona, a third-party vendor commonly used for identity verification. Head over to 404 Media for more details.
The Bottom Line: Headway doesn't seem to have any particular reason for requiring its clients to submit a biometric scan, other than calling it a "safety issue." We'd recommend against using Headway and seeking therapy elsewhere.
This Company Will Clean Your Home in Exchange for Training AI
A new cleaning service called Shift has launched in New York City. The service will send cleaners to your home and provide a variety of services from basic organization to toilet cleaning, all free of charge. Well, maybe not completely free. In exchange for this service, your cleaner will wear a camera while completing their tasks, recording the entire process to train household AI-powered robots. Shift claims the video footage will be kept private, and any personal information and faces will be blurred. Read more at The Verge.
The Bottom Line: We always recommend approaching tech startups with skepticism. Privacy and security are hard to get right, and at this early stage, it's impossible to know what might happen to the footage captured by Shift workers. Regardless of Shift's promises, having a recording of the entire layout of your home on a private company's servers should give anyone pause.
Hackers Steal Passwords by Politely Asking Meta AI
Hackers discovered an innovative new way to steal Facebook and Instagram login credentials: just ask Meta AI for them. Okay, maybe it's not that simple, but it's close. Meta launched its AI support bot in March, and hackers recently found out they can just ask the bot to reset the password of any account and instruct the bot to send the reset link to the hackers' email address. This allowed hackers to access high-profile Instagram accounts, including Barack Obama's account. Check out the full story at 404 Media.
The Bottom Line: Meta has thankfully resolved the issue with its support bot, and hackers can no longer use this exploit. Even still, this highlights that replacing customer support with AI might not be the smartest solution.
- The most recent iOS for the iPhone 17 lineup and iPhone Air is 26.5.1
- The most recent iOS for the iPhone 11 through 16e is 26.5
- The most recent iPadOS is 26.5
- The most recent macOS is 26.5.1
- The most recent tvOS is 26.5
- The most recent watchOS is 26.5
- The most recent visionOS is 26.5
Apple released iOS 26.5.1 for the iPhone 17 lineup and iPhone Air to fix a bug that prevented the phones from wired charging when the battery was too low. Meanwhile, macOS 26.5.1 was released to fix a bug for enterprise users in which the M5 chip could cause unexpected shutdowns.Β Read about the latest updates from Apple.
The correct answer is C. Report the text as spam and delete it. More than likely, this text is a phishing scam. The link provided in the text is likely a malicious web page, and once you enter your credit card details, the information will be sent to the scammer. The phone number in the text will likely connect to a line controlled by the scammers who will try to coax your credit card number out of you. For your own peace of mind, you can also D. Double-check your order details on the app or website that you ordered from to make sure your order is still on its way.
There is far too much security and privacy news for us to cover it all. When building this newsletter, we look for scams, hacks, trouble, and news to illustrate the kinds of problems Apple enthusiasts may encounter in our private lives, and the self-defense we can practice to keep our devices, accounts, and lives secure. Our commentary focuses on practical advice for everyday people. This newsletter was written byΒ Cullen ThomasΒ andΒ Rhett IntriagoΒ and edited byΒ August Garry.
Interested in browsing the web privately? Check out:
|

