- ποΈβ Your Security Checklist
- πποΈ Test Your Security Skills
- π° Your Weekly Security Update
- π€¨ This Should Be on Your Radar π‘
- π Security Fail of the Week π
- ππ± Security Updates from Apple π
If you take nothing else from this newsletter, just do these three things to protect yourself:
- Share passwords using the Passwords app. Whenever you need to share a password (such as for a joint streaming account) with a friend or family member, create a password sharing group in the Passwords app.
- Turn off location history in Apple Maps. If you use Apple Maps for navigation, it keeps a record of every place you visit and creates a searchable timeline. You can turn off Visited Places in Settings.
- Take a few minutes to review who has access to your data. In the Settings app, you can review which apps and contacts you have granted access to certain data, and what data they have access to.
What should you do in the following scenario?
You're browsing the web on your Mac when suddenly your screen locks up, a siren sounds, and a full-page pop-up appears telling you that your computer has a virus. It says you need to call Apple for help and has a phone number listed. π€
- Call the phone number.
- Use your phone to look up the number for Apple Support and call that number instead.
- Restart your computer and run a malware scan.
- Take your Mac to the Apple Store.
Scroll to the bottom to see how you did!
California residents can now take extra steps to protect their privacy through the Delete Request and Opt-out Platform (DROP). If you live in California, you can submit a DROP request, which requires any data broker registered in the state to delete any data they have about you. You'll also be opted out of having your data sold to those same brokers in the future. You can submit DROP requests now, and starting August 1, data brokers will have 45 days to comply with the request. Read more at the Electronic Frontier Foundation, or, if you live in California, check out the DROP website.
The Bottom Line: We think it's great that California has implemented this law, and hope that other states will take action to pass similar legislation. In the meantime, if you're a resident of California, we definitely recommend that you submit a DROP request.
Apple Fixes Hide My Email Bug
A couple of weeks ago, security researchers revealed that Hide My Email was not as effective at hiding your email address as it claimed. According to the researchers, they had informed Apple over a year ago about a vulnerability that could allow anyone to find out the real email address associated with a Hide My Email address. Since Apple had failed to address the exploit since its discovery, the researchers decided to make it public. Now, with the extra pressure brought on by the publicity of 404 Media's original report, Apple has finally fixed the vulnerability.
The Bottom Line: Now that the vulnerability has been fixed, you can continue to use Hide My Email without worrying about your real email address being exposed. Keep in mind that Hide My Email is not 100% anonymous, as every dummy address is still connected to your Apple account.
Have an LG TV? It Might Be Listening to You
Smart TVs present an inherent risk to privacy, especially since the remotes usually have built-in microphones. LG is taking this to the next level with a recent update to its terms of service. LG smart TVs now record your voice and use it for AI training, and the updated terms of service make it the user's responsibility to obtain permission from anyone who enters their home before having their voice recorded. Read more at Notebook Check.
The Bottom Line: We recommend turning off the microphone on your smart TV if it has one. You can usually find this somewhere in the settings, but if you're having trouble, Tom's Guide has detailed instructions to help you out. If you want smart capabilities for your TV, an Apple TV can offer the same benefits with the added bonus of user privacy.
Can Flock Watch You Wherever You Go?
Surveillance company Flock has introduced a new type of camera called the Condor. Normally, Flock's automated license plate readers (ALPRs) only capture the license plates of passing cars. The Condor camera, on the other hand, is designed to track people. It can lock onto specific people to follow their precise movements, identify them with facial recognition, and even zoom in on their phone screens to see what they're looking at.
The public has become increasingly antagonistic toward Flock and its cameras. The Los Angeles Police Department recently declined to renew its contract with Flock due to concerns related to privacy. Flock itself also decided against rolling out a new feature that would have placed microphones all over cities listening for audio that indicated distress (such as people screaming or calling for help).
The Bottom Line: Flock's Condor camera is a disturbing invasion of privacy. These cameras treat the entire general public like crime suspects. Thankfully, the LAPD's refusal to renew its contract shows that public scrutiny can affect policymaking decisions in some jurisdictions. However, as we've seen in the past, canceling contracts with Flock does not always mean that the cameras are deactivated.
Surveillance Toolkit for Defense Attorneys
With surveillance tech like ALPRs becoming so prevalent in the US, the American Civil Liberties Union (ACLU) has created a toolkit to help defense attorneys protect their clients. The toolkit contains resources for attorneys to use to find out what surveillance technology law enforcement may have used against their clients. Read more at the ACLU.
The Bottom Line: Attorneys can email the ACLU using the linked page above to request access to the toolkit. This is a good resource for defense attorneys to take advantage of amid the increase in police reliance on surveillance tech, which has been known to get the wrong person detained.
Watch Out for This New Mac Infostealer
Security researchers at Jamf Threat Labs discovered a new type of Mac infostealer malware called CrashStealer. The malware works by tricking the user into downloading a disk image called Werkbit Setup. When opening Werkbit, a malicious file called CrashReporter is downloaded, which causes a password prompt to appear. The prompt is designed to look like a legitimate macOS prompt, so that the user is more likely to enter their password willingly. The malware will then use the password to access Keychain and steal any stored passwords. Read more at Fox News, or check out Jamf's write-up on the infostealer.
The Bottom Line: The linked Fox News article has some excellent advice for avoiding this infostealer, but in general, avoid downloading suspicious-looking apps, don't open apps with strange names, and be careful about where you enter your Mac password.
Did You Know Credit Bureaus Sell Your Information to Data Brokers?
Not many people realize just how much of their data is given away whenever they open a credit card in the US. Opening a credit card requires you to provide credit bureaus with your personal information. The credit bureaus sell that information to companies like Thomson Reuters, which incorporates it into its investigative data platform CLEAR. CLEAR can be used by law enforcement and government agencies, such as Immigration and Customs Enforcement, to warrantlessly target and track anyone in its database. Read more at 404 Media.
The Bottom Line: There isn't too much that can be done to defend against this abuse of your personal data. It's not all bad news, though: As 404 Media reports, an employee of Thomson Reuters claims that CLEAR's data is not always the most accurate or organized.
OpenAI "Accidentally" Hacks Rival AI Platform
Hugging Face, an AI development platform, was hacked this week. The hacker uploaded malicious code to the site, which allowed them to exploit a vulnerability and access Hugging Face's internal systems. The hacker was able to steal a set of credentials, which Hugging Face has since rotated. The hacker responsible for this data breach? OpenAI. According to OpenAI, the company was testing the cyber capabilities of its large language models when the LLM breached Hugging Face. Essentially, OpenAI is saying the AI model acted on its own and hacked Hugging Face without any instruction from the company.
The Bottom Line: It would appear that OpenAI is trying to dodge accountability by claiming that the AI acted of its own volition, but the fact is that it wouldn't have done so if it hadn't been designed to behave that way in the first place.
- The most recent iOS and iPadOS is 26.5.2
- The most recent macOS is 26.5.2
- The most recent tvOS is 26.5
- The most recent watchOS is 26.5
- The most recent visionOS is 26.5
Read about the latest updates from Apple.
The correct answer is probably C. Restart your computer and run a malware scan. This is a common scam that hijacks your computer screen by locking the window in full screen and playing a siren to make you panic so that you're more likely to call the phone number on the screen without thinking. Usually, when you call the phone number, you'll be connected to a scammer who will provide you with instructions to install a screen-sharing tool that allows them to take over your computer.
If you ever encounter a pop-up like this, restart your computer by pressing and holding the power button until it shuts down. Once you have it powered back on, use a malware scanner, such as Malwarebytes, to double-check that your computer has not been infected with any viruses. It likely hasn't, but it's best to stay on the safe side. Looking up the real phone number for Apple Support and calling them is also an option for your peace of mind, though they will likely provide you with similar instructions.
There is far too much security and privacy news for us to cover it all. When building this newsletter, we look for scams, hacks, trouble, and news to illustrate the kinds of problems Apple enthusiasts may encounter in our private lives, and the self-defense we can practice to keep our devices, accounts, and lives secure. Our commentary focuses on practical advice for everyday people. This newsletter was written byΒ Cullen ThomasΒ andΒ Rhett IntriagoΒ and edited byΒ August Garry.
Interested in learning more about the Passwords app? Check out:
|
