The most blatant security backdoor yet seen in an internet router has been found in a range of models sold under multiple brand names. A firmware implant phones home to cloud servers in China to ask for instructions, and can then be remotely controlled …
The Consumer Federation of America (CFA) estimates that online scams cost Americans almost $150 billion last year – seven times the amount reported to the FBI.
The organization says that the number of cyber scams is increasing dramatically, and that most victims never report their losses to law enforcement …
Security researchers demonstrated that Claude Cowork could escape the sandbox intended to control the access it gets to your Mac. The exploit, dubbed ShareRoot, could allow an attacker to read and write files stored anywhere on your Mac, as well as access login credentials for online services.
Around half a million Mac users had co-work sessions exposed, and some still remain vulnerable to the exploit today …
Jamf Threat Labs, the company’s security research arm, recently shared details of a ClickFix-style attack it spotted running as a sponsored ad on the social media site X. Originating from a well-known verified account, it promoted a malicious domain under the guise of a popular Mac app.
A privacy flaw in Apple’s Hide My Email feature means that your real email address can be discovered. A security researcher said that tests found 100% of generated addresses allowed an attacker to reveal the real email associated with the Apple account.
Tyler Murphy said that he discovered and reported the issue to Apple more than a year ago, but it still hasn’t been fixed, and he has now made the decision to go public …
Three AirDrop vulnerabilities have been discovered by security researchers, affecting both iPhone and Mac, with similar ones found in Android’s Quick Share.
An attacker could easily exploit the vulnerabilities to cause AirDrop, AirPlay, Handoff, Universal Clipboard, and Continuity Camera to crash and remain unavailable for as long as the attack continues …
Today’s iOS, iPadOS, and macOS 26.5.2 updates include security fixes that Apple had originally planned to release with version 26.6 of each operating system. Here’s why the company pushed them out early.
Researchers at Paradigm Shift have published the technical details of usbliter8, a new unpatchable iPhone BootROM vulnerability that enables arbitrary code execution on devices powered by Apple’s A12 and A13 chips. Here are the details.
Apple recently introduced Personalized Collections in the App Store, which provides users with individually tailored recommendations for new apps they might enjoy.
Two security researchers have highlighted the extremely extensive analytics data the company is capturing in order to compile these recommendations, logging every tap you make …
9to5Mac Security Bite is exclusively brought to you by Mosyle, the only Apple Unified Platform.Making Apple devices work-ready and enterprise-safe is all we do. Our unique integrated approach to management and security combines state-of-the-art Apple-specific security solutions for fully automated Hardening & Compliance, Next Generation EDR, AI-powered Zero Trust, and exclusive Privilege Management with the most powerful and modern Apple MDM on the market. The result is a totally automated Apple Unified Platform currently trusted by over 45,000 organizations to make millions of Apple devices work-ready with no effort and at an affordable cost. Request your EXTENDED TRIAL today and understand why Mosyle is everything you need to work with Apple.
While WWDC26 is winding down, I’ve had time to reflect on Monday’s keynote, where Apple spent most of its time preaching to parents about on-device Child Safety and, of course, Siri AI.
However, it also showcased something insanely neat and ingenious on Apple’s part that is largely being overshadowed. I’m referring to the new agentic AI feature now in iOS 27’s Passwords app.
If you’re thinking about installing the shiny new iOS 27 developer beta 1 on your iPhone, be aware that the RCS end-to-end encryption option is missing. There’s no need to panic, though. Apple is not phasing out the feature.
Hackers managed to trick Meta’s AI-powered support bot into allowing them to take over a number of Instagram accounts, including some high-profile ones. This included accounts belonging to the White House, US Space Force, and security researcher Jane Wong.
Update: Meta has now revealed that around 20,000 accounts were compromised and has explained the steps it has taken in response …
If you use the ChatGPT desktop app on Mac, you’ll be forced to update it sometime between now and June 12. That’s due to a security breach involving two OpenAI employee devices. As of June 2, the company is emailing users to remind them to accept the update when offered.
Apple is working on a new iPhone security feature that can automatically lock the device when it detects that it has been snatched from the user’s hand. Here are the details.
Apple today updated the security content pages for several macOS, iOS, iPadOS, visionOS, and watchOS releases, adding new CVE details for vulnerabilities addressed in each update. Here are the details.
The FBI and NSA jointly announced that Russia has been systematically compromising the security of home and small office routers since at least 2024.
They obtained a court order to allow them to remotely reset thousands of affected devices in the US, but if yours is one of them, it needs to be urgently replaced …
Apple released iOS 26.5, iPadOS 26.5, macOS 26.5, watchOS 26.5, and more today. In addition to new features, the updates also include security fixes, including for over 50 vulnerabilities in iOS 26.5 alone. Here are the details.
After exclusively sharing details with 9to5Mac last September on ModStealer, a cross-platform infostealer invisible to every major antivirus engine at the time, Mosyle, a leader in Apple device management and security, is back with two more macOS threats that are flying completely under the radar.
In new details again shared with 9to5Mac, the Mosyle Security Research Team says it has identified two previously undetected samples: Phoenix Worm, a cross-platform stager, and ShadeStager, a modular macOS implant built for credential theft. The two aren’t directly connected in how they work, but together show just how sophisticated Mac malware is getting.
Last month saw a surprise ban on almost every new wireless router intended for use in US homes. The FCC ruling described all foreign-made routers as a national security risk.
The FCC offered a pathway to approval, and today Netgear has received that – but nobody knows why. Not even Netgear itself was able to offer an explanation …
OpenAI has announced a new AI model called GPT-5.4-Cyber. Similar to Anthropic’s Claude Mythos, this new “cyber-permissive” variant of its GPT-5.4 is built for defensive cybersecurity and not public use.
The FBI says that a sharp rise in scams saw cybersecurity crime cost US victims a total of almost $21 billion last year. The most common example was investment scams, with cryptocurrency fraud responsible for the largest losses.
The report includes AI-related scams for the first time. The agency says that the use of voice cloning, forged documents, and deepfake videos were responsible for £893m in losses …