- 🗒️✅ Your Security Checklist
- 🏆🎖️ Test Your Security Skills
- 📰 Your Weekly Security Update
- 🤨 This Should Be on Your Radar 📡
- 🙈 Security Fail of the Week 👎
- 🍎📱 Security Updates from Apple 🍎
If you take nothing else from this newsletter, just do these three things to protect yourself:
- Use multi-factor authentication wherever possible. You can set up the Passwords app to generate six-digit codes for two/multi-factor authentication.
- Remove your location from photos before sharing. Whenever you take photos, your location is recorded in the photo's metadata. Luckily, you can easily remove your location from any photo.
- Turn off location history in Apple Maps. Apple Maps keeps a record of every location you visit, but you can turn off Visited Places easily.
What is the most secure way to send a message? 🤔
- iMessage
- Signal
Scroll to the bottom to see how you did!
Investigative journalist Brian Krebs recently discovered a massive identity theft service on the dark web. The service, called Nexus, contained over 153 million driver's licenses from the US and Canada, all for sale to the highest bidder. With the help of friends and family members whose IDs showed up in the database, Krebs was able to determine that the source of these ID scans was likely a company called IDScan, which provides ID scanning services to a variety of companies including car rental companies and major retailers. Krebs suspects there was a breach at IDScan, and someone with persistent access stole the company's database of scanned driver's licenses over the course of years without anyone noticing until now. Read the full investigative report at KrebsOnSecurity.
The Bottom Line: Since Krebs published his article, Nexus has vanished completely, though the stolen IDs are still out there. It's difficult to defend against this specific type of situation. After all, you can't exactly refuse to hand over your ID if you want to rent a car. It's up to the companies collecting your ID to protect it. The best thing you can do is freeze your credit. This will at least protect your identity even if it is stolen from a third-party company.
In this case, IDScan could have avoided this if it was not storing IDs indefinitely. That's just one of many reasons why using IDs for age verification is such a risky idea. Companies can claim they'll only keep your ID long enough to verify your age, but it's impossible to know if they're being truthful. And if they're not, all it takes is a single data breach for everyone's IDs to end up on the dark web.
More States Turn Against Flock
We finally have some good news about the infamous surveillance company Flock. TechSpot is reporting that at least 90 jurisdictions have canceled contracts with Flock in August alone. However, Flock itself claims that new contracts are outpacing cancellations at a ratio of roughly 10 to 1. Still, animosity against automated license plate readers (ALPRs) continues to grow, with both the governor of Texas, Greg Abbott, and the governor of Florida, Ron DeSantis, condemning the technology. On September 1, the Florida Department of Transportation ordered the removal of all ALPRs from state highways.
The Bottom Line: Regardless of the reasoning, the discontinuation of ALPRs can only be seen as a step in the right direction for privacy. We've extensively covered the potential for misuse when it comes to ALPRs, like this Florida deputy who stalked his ex-girlfriend using his access to Flock cameras. The sooner this technology falls by the wayside, the better.
Apple Presents New Evidence in Lawsuit Against OpenAI
Last month, Apple launched a lawsuit against OpenAI, alleging that the AI giant had stolen trade secrets by hiring former Apple staff and taking advantage of company equipment those employees had in their possession. Former Apple employee Chang Liu turned over his work laptop for investigation. Apple claims that schematics and files that match ones used by OpenAI were stolen from Apple by Liu. Check out the full story at TechCrunch.
The Bottom Line: OpenAI denies that it used any stolen secrets from Apple and says Liu only used his old Apple files to help a work colleague. OpenAI is also blaming Apple for not properly revoking employee access to internal files after they left the company.
Australia Could Ban the Import of Smart Glasses
Lawmakers in Australia are planning to propose a bill which would temporarily ban the import of all smart glasses (or "pervert glasses" as the internet has dubbed them) for a year. The goal is to prevent more smart glasses from entering the country while the government can figure out how to implement stricter privacy protections. Head over to the ABC for more information.
The Bottom Line: The likelihood of this bill passing is not immediately clear, as it appears there are only a few lawmakers backing it. However, we support any effort to curb the privacy violations created by smart glasses.
Be Careful Updating Your Web Browser
There's a scam going around that works by informing the user that their browser needs to be updated. Clicking the button downloads a malicious file that, when opened, will infect your computer with a virus. The update prompt originates from a malicious Chrome extension. It could be a new extension that you downloaded recently or one that you downloaded ages ago and forgot about. Seemingly harmless extensions can become malicious later if the extension is acquired by another developer who then implements the malicious code. Read more about this scam at Fox News.
The Bottom Line: Modern web browsers typically update in the background, which means updates will be downloaded while you are using your browser and will be installed the next time you re-open it. If you're ever prompted to update your browser, do not click the prompt. Instead, you can manually check for updates in the browser's settings. In Chrome, you can click the three-dot "more" button in the upper right, select Help, and then About Google Chrome. In Firefox on a Mac, click Firefox in the upper left, then About Firefox.
Man Fakes NFL Career & Scams Women
A man named Daejon Love has been arrested after he posed as a member of the San Francisco 49ers NFL team and scammed several victims out of millions of dollars. Love sought victims through dating apps, but took the time and effort to construct a fake social media presence that showed him playing football, training, giving speeches, and more. This made him look legitimate to anyone who looked deeper than his dating profiles and allowed him to gain the trust of multiple victims, whom he then convinced to send him money for supposed investments. Check out the full story at Yahoo Sports.
The Bottom Line: This is yet another variation of a romance scam, in which a scammer contacts the victim, builds a friendship or relationship with them, and eventually convinces them to send money. When making new contacts online, we usually recommend video calls early and often to verify that the person you're getting to know is who they say they are. However, in this case, video calls would not have outed him, or protected his victims, as his appearance and voice were not faked. We still think video calls early and often are a good idea, and so is checking into a new contact's social media accounts. But even when they seem to pass those checks, you've still got to be very suspicious of anyone offering investment advice or asking for money. If someone claims to be an NFL player while trying to date you, just remember that NFL rosters are publicly available—or ask your uncle if he's ever seen this guy on TV.
Judge Dismisses Google's Attempts to Avoid Accountability
Last year, a class action lawsuit was brought against Google, alleging that the company violated user privacy by gathering smartphone analytics even after users turned off data collection. The case was brought before a jury, which ruled against Google. The search giant has now tried two times to have the verdict thrown out, and both times a federal judge has declined. Read more at MediaPost.
The Bottom Line: We think the judge's words on this matter sum it up nicely: "Google can poke holes in all that evidence, but the decision to credit it or not is the province of the jury. Google took a shot at trial, and it lost."
Journalists Track a Scammer to His Home
A pair of investigative journalists, Erin West and Paul Raffile, managed to track a scammer to his home in Nigeria. The pair started their investigation by creating a fake Instagram profile of a teenager to lure in "sextortion" scammers. Sextortion is a type of scam that involves tricking someone into sending explicit photos or videos and then threatening to release them to the public unless the victim pays the scammer. Sure enough, the fake profile was soon contacted by scammers pretending to be young women. Once they had one scammer on the hook, the journalists successfully deduced the scammer's location and tracked him down. We recommend checking out the full story at 404 Media.
The Bottom Line: Sextortion scams are all too common. When it comes to sending photos or videos of any kind, it's good practice to assume that anything you send digitally will be around forever. Never send anything you wouldn't want to be seen publicly. Also, we do not recommend trying to track scammers to their homes or confronting them. The journalists in this story are experienced in their field and were prepared to meet the scammer face to face.
Members of Hacking Group Arrested in Australia
The Australian Federal Police (AFP) arrested two men who are allegedly part of the hacking group TeamPCP. One of the men arrested had been contacted by journalist Brian Krebs back in June. Krebs communicated with and interviewed the suspect over several months, compiling communications, including the details that led to the suspect's arrest, into a single article. We recommend checking it out over at KrebsOnSecurity.
The Bottom Line: Krebs' article is a meticulous deep dive into how cybercriminals are caught. It's certainly an informative read.
New Legislation Would Require More Government Transparency
In the US, the government can subpoena data like phone records and is not legally required to notify the person being investigated. This means you can have your records searched without ever knowing about it. However, new legislation from US House Representative Scott Fitzgerald would change that. Fitzgerald's NDO Fairness Act would require anyone whose records are subpoenaed to be notified after 90 days, ensuring they're aware of it and giving them an opportunity to challenge it if necessary. Read more at Fitzgerald's website.
The Bottom Line: The NDO Fairness Act has passed the House of Representatives and is now on the way to the Senate. We hope it passes and becomes law. More transparency is always a good thing.
Guy Who Violates the Privacy of Others Has His Privacy Violated
Garrett Langley, CEO of the surveillance company Flock, recently said in an interview that people talking about privacy and safety in regards to ALPR cameras are focusing on the wrong thing, and that people should instead focus on "compromise." Many social media users took these comments to mean that Langley wanted the public to compromise on its own privacy. In response, the public treated Langley's privacy with the same respect he showed theirs and posted his home address on social media. In response, social media platforms began mass removing posts with the address and Google Maps blurred Langley's house in Google Street View. Read more at Gadget Review.
The Bottom Line: We don't condone doxxing anyone, but it's hard to sympathize with someone who advocates for violating the privacy of others. Will this experience teach Langley anything? We doubt it.
- The most recent iOS and iPadOS is 26.6.1
- The most recent macOS is 26.6.2
- The most recent tvOS is 26.6
- The most recent watchOS is 26.6
- The most recent visionOS is 26.6.1
Read about the latest updates from Apple.
The correct answer is C. Signal. Signal is the only platform on this list that offers true end-to-encryption. iMessages are encrypted as well, but are still vulnerable to surveillance unless Advanced Data Protection is enabled for both the sender and the recipient. WhatsApp falls into a similar category. Signal, on the other hand, cannot access its users' messages even if ordered to do so by law enforcement.
There is far too much security and privacy news for us to cover it all. When building this newsletter, we look for scams, hacks, trouble, and news to illustrate the kinds of problems Apple enthusiasts may encounter in our private lives, and the self-defense we can practice to keep our devices, accounts, and lives secure. Our commentary focuses on practical advice for everyday people. This newsletter was written by Cullen Thomas and Rhett Intriago and edited by August Garry.
Want to secure your iPhone and your Apple Account? Check out:
|

