- ποΈβ Your Security Checklist
- πποΈ Test Your Security Skills
- π° Your Weekly Security Update
- π€¨ This Should Be on Your Radar π‘
- π Security Fail of the Week π
- ππ± Security Updates from Apple π
If you take nothing else from this newsletter, just do these three things to protect yourself:
- Look out for signs of phishing emails. Scammers love to send out emails with fake invoices, alerts about an account under your name, job offers, and more. Thankfully, there are some signs you can look out for when it comes to phishing scams.
- Do not interact with fake virus alerts. A common scam tactic is to display a pop-up in your web browser claiming your device is infected with a virus. These are almost always fake and can be dismissed by simply closing the tab or window.
- Remove your location from photos before sharing. If you have Location Services enabled for your camera and photos, every snapshot you take has a location tagged. You can easily remove it before sharing a photo to ensure you're not giving away your location.
What should you do in the following scenario?
You're selling something online, and a buyer offers to pay over Zelle. You agree, since transactions over Zelle cannot be reversed. The buyer sends you the payment but overpays by about $500. They ask you to send back the $500 in a second Zelle transaction. What do you do? π€
- Block the buyer; they are probably a scammer.
- Contact your bank to find out if there's a way to reverse the charge.
- Send the money; it was probably an honest mistake.
Scroll to the bottom to see how you did!
Last year, an activist named Sam Tunick was detained at the border after returning from a trip to the Dominican Republic. Customs and Border Protection held him for "suspected terrorism activities" and demanded that he turn over his phone passcode. The CBP agents threatened to seize his phone if he did not comply, so Tunick relented and provided a passcode. Except, when the agents entered the passcode, the phone restarted, wiping all data. Now, the US Department of Justice is prosecuting Tunick for destroying evidence.
The case is centered around the operating system installed on Tunick's phone. Tunick was using GrapheneOS, a privacy-focused version of Android. An optional feature of GrapheneOS is a "duress password," which is a dummy passcode that erases the device instead of unlocking it. Whether or not Tunick broke the law by providing the duress password instead of his actual passcode is the question. Read more at The Verge.
The Bottom Line: Everyone has a right to privacy, and GrapheneOS is designed to protect that right. The use of the duress PIN is what is legally questionable in this case, and we are very interested to see the outcome.
LG Strengthening Security Requirements for Smart TV Apps
Earlier this month, we reported on a botnet called NetNut that used Android-based smart TVs and TV boxes as proxies, allowing attackers to route their internet traffic through these devices and make it harder to track them. LG is now taking action to prevent attackers from using its smart TVs as proxies. App developers are being ordered to remove any residential proxy options from their apps or be suspended. LG has also committed to strengthening the app review process to ensure no apps with built-in proxies are allowed on the platform. Read more at KrebsOnSecurity.
The Bottom Line: We're grateful that LG is fighting back against the threat of residential proxies on its smart TVs. However, we still would not recommend LG's smart TVs after last week's change in its Terms of Service around voice recording.
Is Your Mac Safe From Claude Cowork?
Claude Cowork is an AI tool that is designed to help you automate tasks on your Mac. The program is supposed to run in a "sandbox" environment. This essentially means that the program runs inside a virtual machine and is only able to access the files you specify, not the rest of your Mac. However, a new exploit called ShareRoot grants an attacker read and write access, which means they can see files, modify them, and create new data. ShareRoot also allows attackers to see login credentials. Read more at 9to5Mac, or check out the more technical breakdown at The Hacker News.
The Bottom Line: This exploit appears to only affect locally run versions of Claude Cowork. If you use Claude Cowork, you may want to consider running it on the cloud. The 9to5Mac article offers some steps you can take to safely run the program locally as well, but requires a bit more legwork.
Police Detective Uses Flock to Stalk Husband's Ex
Yet another law enforcement officer has abused their access to the automated license plate reader tech company Flock. This time, a detective in Florida used Flock, along with two other law enforcement databases, to track and stalk her husband's ex-wife. In addition to Flock's database, the detective used the Comprehensive Case Information System (CCIS) and the Driver and Vehicle Information Database (DAVID) to look up information about her husband's ex-wife, falsifying case numbers and justifications to avoid suspicion. Read more at Gadget Review.
The Bottom Line: Ultimately, the detective at the center of this story was caught, terminated, and charged. One silver lining in this story is that the sheriff has suspended all Flock cameras in the county until a full investigation can be completed.
Watch Out! Scammers Are Trying to Phish Password Managers
There's a new phishing scam going around attempting to gain access to password managers, in particular LastPass and Bitwarden. While neither of these password managers has been breached, scammers have started sending out phishing emails that look like legitimate messages from LastPass and Bitwarden notifying the user of changes to their security policies. The emails link to fake DocuSign pages that try to trick users into installing malware. Read more at Fox News.
The Bottom Line: If you receive any emails that claim to be from your password manager about changes to security policies or your account, don't click on any links or respond to the email. Go to the official website of your password manager and contact customer support to find out if there are actually any changes to your account.
Are Your Claude Chats on the Web for All to See?
Last year, ChatGPT inadvertently leaked hundreds of thousands of private chats onto the internet. ChatGPT and other AI assistants allow you to share your chats with others by creating a unique URL. OpenAI had allowed Google and other search engines to index these URLs, meaning they would appear in search results. Now, it looks like the same thing is happening to Claude. Claude has the same sharing feature, and its URLs have also been indexed by search engines. Read more at 404 Media.
The Bottom Line: As always, when talking to AI assistants, avoid telling them too much personal information, and, if you can, avoid sharing chats with the public URL feature. You can also unshare chats as needed.
Data Breach at Coca-Cola
Fairlife, a brand of Coca-Cola, halted production last week following a ransomware attack. The hacking group Anubis claimed responsibility for the attack and says that it has stolen more than 1 TB of data. Coca-Cola refused to pay the ransom, and it appears Anubis released the data. Read more at Tech Times.
The Bottom Line: Production has since resumed at Fairlife. It is currently unknown what type of data was stolen and leaked online. While it is unfortunate that Anubis leaked the data, cybersecurity experts recommend against paying ransoms as it encourages ransomware hackers to continue extorting people and companies, so Coca-Cola made the right move in this situation.
Windows Releases Massive Security Patch Only for Another Hole to Appear
Microsoft recently patched a whopping 570 security vulnerabilities in Windows. The same day, the security researcher NightmareEclypse released details for a new zero-day exploit (an exploit that was previously unknown, thus there are "0 days" to patch it). Essentially, the exploit, called HiveLegacy, allows low-level Windows accounts to gain administrative privileges. Head over to Ars Technica for more.
The Bottom Line: The article does not mention any real-life instances HiveLegacy has been used, so it does not look like it is being actively exploited at the moment. Microsoft is aware of the vulnerability and will likely release a patch soon. If you have a Windows machine, be sure to keep it up to date.
- The most recent iOS and iPadOS is 26.6
- The most recent macOS is 26.6
- The most recent tvOS is 26.6
- The most recent watchOS is 26.6
- The most recent visionOS is 26.6
Read about the latest updates from Apple.
The correct answer is A. Block the buyer; they are probably a scammer. A common scam tactic is to overpay with Zelle and request the seller to send the difference back. In reality, the scammer's bank does not have the funds needed to complete the transaction, so Zelle will reverse it later, meaning you lose the buyer's payment plus the extra money you sent back to them. If you would like extra peace of mind, you can contact your bank for help with suspicious transactions. Be sure to only contact your bank using customer support emails or phone numbers found on the official website.
There is far too much security and privacy news for us to cover it all. When building this newsletter, we look for scams, hacks, trouble, and news to illustrate the kinds of problems Apple enthusiasts may encounter in our private lives, and the self-defense we can practice to keep our devices, accounts, and lives secure. Our commentary focuses on practical advice for everyday people. This newsletter was written byΒ Cullen ThomasΒ andΒ Rhett IntriagoΒ and edited byΒ August Garry.
Worried about your iPhone being tracked? Check out:
|

