- 🗒️✅ Your Security Checklist
- 🏆🎖️ Test Your Security Skills
- 📰 Your Weekly Security Update
- 🤨 This Should Be on Your Radar 📡
- 🙈 Security Fail of the Week 👎
- 🍎📱 Security Updates from Apple 🍎
If you take nothing else from this newsletter, just do these three things to protect yourself:
- Employ a privacy-preserving web browser such as Safari or DuckDuckGo. Ditch Chrome.
- Don't use web browser extensions except for your ad-blocker, password manager, and possibly a VPN.
- Keep your devices up to date. Learn how to update to the latest OS.
What should you do in the following scenario?
You receive an email alert from a government agency warning you that you are liable for a mistake on your taxes. The email links to something that looks like a real government portal, like the IRS website, and urges you to log in immediately or face criminal charges. 🤔
- Delete the email and go on with your life.
- Act quickly to protect yourself and your family by logging in to see what's wrong.
- Delete the email and open the official government website in a separate window.
Scroll to the bottom to see how you did!
DraftKings is one of the largest sports betting platforms, according to Motley Fool, and a major driver of the sports betting industry. From the New York Times, it appears that DraftKings has been employing AI trained on customer usage data to target ads to the bettors most likely to place losing bets. Not just customers most likely to click an ad or place a bet, but customers most likely to lose. Engineers raised alarms when they began to suspect the AI was singling out those with destructive gambling habits. If this sounds familiar, you may be remembering the 2017 revelation that Facebook's algorithm could identify when teens were feeling depressed and reveal that to advertisers, so the vulnerable teens could be targeted, for example, with makeup ads, as later attested by a Facebook employee.
These are both forms of behavioral advertising: studying the specific behaviors of individual buyers to identify who is most likely to click an ad, and even when they're most likely to click. Highly targeted ads that seem to know everything about you may merely feel creepy, but ad-tech and behavioral advertising data has made its way outside of the advertising world and into decisions about who can be targeted for law enforcement and even military action. Such data can be collected and resold to private detectives, police, military, and also stalkers. That Ad-tech data is interesting to militaries is shown by the US Military disabling advertising identifiers out of concern they might reveal soldiers' locations. US Immigration and Customs Enforcement uses ad-tech data, and one data source for potential predictive policing. Commercial ad-tech data has been used by private Ukraine-linked firms to track Russian soldiers and locate strategic targets. We have not yet seen reporting of ad-tech data directly utilized to select military targets—we know it could be used, but we don't know yet wheter it actually has. Still, given the growing reliance on data-hungry algorithmic target priority systems, it seems only a matter of time.
The Bottom Line: It is possible to reduce how much ad-tech surveillance can learn about you personally by employing tools such as a privacy-preserving web browser (like Safari, Brave, or DuckDuckGo), iCloud Private Relay, email masking services such as Hide My Email, DNS cloaking such as NextDNS, and sometimes a consumer VPN. Each tool you employ reduces how much advertisers can surveil you in different ways, and collectively they reduce your exposure to this kind of targeted advertising and profiling.
However, it must be said that the internet does not need to be built so that merely browsing it gives up your privacy. To maintain the usefulness of the internet as a tool for the public good, reasonable restraints must be placed on how much personal profiling data companies can capture and retain for advertising or other purposes. Creating reasonable safeguards is the job of lawmakers. In some jurisdictions, your opinions may affect the decisions of your lawmakers, so consider reaching out to them with your concerns.
Meta Takes Out the Trash: 3 Million Scam Accounts
Periodically, major platforms like Meta or Apple's App Store will perform a purge, seeking out abusive accounts from malicious users and removing them. This round comes from Meta, which formed a relationship with the Singapore Police Force (SPF) to help identify transnational scam activity. Read Meta's blog on the purge.
The Bottom Line: International borders make scam operations hard to completely stop. A single scammer can run dozens or hundreds of scams a day, protected from consequences by jurisdictional barriers. International efforts like this are good, but the bottom line is there are still going to be a ton of scams on Facebook. Practice great caution when making new contacts, verify new contacts with video calls, and exercise caution when encountering exceptionally good deals.
Is Your Browser Extension Hacking Someone Else?
Cybersecurity firm Spur has a report on a collection of Chrome extensions compromised by a residential proxy called Mellowtail. The process is simple: Mellowtail is offered to web browser extension authors as a way to monetize their browser extension. If installed, it modifies the otherwise harmless extension to become a node that allows others, including criminals, to access the internet from your device. You might notice your internet operating slowly, but what's really happening is you're sharing your internet connection with any number of hidden others, who are often up to no good. Read more at Spur.
The Bottom Line: We recommend avoiding web browser extensions. Any browser extension capable of doing anything useful requires access to virtually everything you do on the internet. The only browser extensions we recommend are an ad blocker, your password manager (if applicable), and possibly a VPN.
This Phishing Campaign Can Hack iPhones
Cybersecurity firm D3Lab reports discovering a new iOS phishing campaign targeting Italians. The hackers impersonate pagoPA, an Italian government service that lets users pay their taxes and other government fees. Impersonating a government alert message is just the start; once the user clicks the message, the malware silently tries to bypass the iPhone's defenses and steal the owner's identity and credit card information. This exploit appears to target phones running iOS 17.2.1 and older but does not work on newer operating systems. Read more from D3Lab.
The Bottom Line: Exploits targeting iPhones are on the rise, but the vast majority of them cannot target the latest operating systems. That's why it's important to keep your device up to date.
AI Dangers: Superintelligent or Super Unreliable?
In mid-September, a US intelligence report suggested that a specific Chinese ship traveling in the Middle East was carrying components of a nuclear weapon, according to CNN. The US military made plans to intercept and board the ship—an action which some US military sources feared would be viewed by China as an act of war. At the last minute it came out that the report was completely fictional—it was generated by an AI chatbot, and the detail about nuclear weapons parts was a hallucination. The US attack was called off. The Guardian has written a thoughtful breakdown of why the threat posed by this technology may have less to do with its much-hyped "super-intelligence," and more to do with people believing the marketing hype and using it for jobs for which it is dangerously unsuited. Read more at The Guardian.
The Bottom Line: Work produced by generative AI must be fact-checked. It works best in cases where the fact-checking is automatic, such as when generating an itinerary for a trip: You'll have to make the actual reservations, so you'll automatically end up fact-checking the list. It must never be used to help decide matters of critical importance.
Apple Patches Vulnerabilities for iOS 26 Devices
Apple's iOS 26.7.1 update is available for devices still running last year’s operating system. It fixes an exploit known to be in use by hackers, so go grab it if you’re still on the older OS. Since they did not push a similar patch for iOS 27, it is likely that the exploit was already patched in iOS 27 updates.
The Bottom Line: You can update your device by going to Settings > General > Software Update.
New macOS Infostealer: MacSync Steals Your Crypto and Info
Cybersecurity company Kaspersky discovered a new evolution of infostealer malware targeting Macs. This malware, called MacSync by its creators, is rented to criminals as a malware-as-a-service. It may reach you through compromised versions of free or open-source programs, or in a clickfix-type attack that prompts you to run code in your own terminal (don’t do that). Once installed, it bypasses macOS protections and seeks to steal keychain information, as well as crypto wallet contents and other materials. Read more at Securelist.
The Bottom Line: Beware of free software. While there are many great free apps, make sure to download them from their official source, never a third party. Be wary of prompts asking for your Mac’s admin password—this should only happen when you initiate an action. Finally, you can run a reputable malware scanner for additional protection, such as Malwarebytes.
Meta Muse AI: Advanced Tech or Underpaid People in a Call Center?
We mentioned this last week, but we still think it's funny: Internal Meta documentation obtained by 404 Media shows how they tested a feature to let Muse AI make phone calls on behalf of its user, such as to make a dinner reservation. However, the AI was not making the call, it was delegating that task to a human-operated call center. This is not the first time that tools advertised as being powered by AI were secretly achieved by human labor. Read more at 404 Media.
The Bottom Line: The presence of human decision-makers in the loop, and human review, is not necessarily a bad thing when it comes to critical decision-making such as military target selection. However, it does highlight that these tools are not private. Assume that any prompt you send to an AI agent will be reviewed by a human, and that human may not have gone through any security screening or background check.
- The most recent iOS and iPadOS is 27
- The most recent macOS is 27
- The most recent tvOS is 27
- The most recent watchOS is 27
- The most recent visionOS is 27
Read about the latest updates from Apple.
There is far too much security and privacy news for us to cover it all. When building this newsletter, we look for scams, hacks, trouble, and news to illustrate the kinds of problems Apple enthusiasts may encounter in our private lives, and the self-defense we can practice to keep our devices, accounts, and lives secure. Our commentary focuses on practical advice for everyday people. This newsletter was written by Cullen Thomas and edited by August Garry.
Concerned about viruses on your iPhone? Check out:
|

