Security

1,183 'Security' stories July 2011 - June 2026
See All Stories

Apple collects every tap to deliver App Store personalized recommendations

๐Ÿ‘ Apple collects every tap to deliver App Store personalized recommendations | Screenshot shown of the data sent for a search for Tim Cook

Apple recently introduced Personalized Collections in the App Store, which provides users with individually tailored recommendations for new apps they might enjoy.

Two security researchers have highlighted the extremely extensive analytics data the company is capturing in order to compile these recommendations, logging every tap you make โ€ฆ

Expand Expanding Close

Security Bite: Appleโ€™s most impressive agentic AI feature yet is hiding in the Passwords app

๐Ÿ‘ Image

9to5Mac Security Bite is exclusively brought to you by Mosyle, the only Apple Unified Platform. Making Apple devices work-ready and enterprise-safe is all we do. Our unique integrated approach to management and security combines state-of-the-art Apple-specific security solutions for fully automated Hardening & Compliance, Next Generation EDR, AI-powered Zero Trust, and exclusive Privilege Management with the most powerful and modern Apple MDM on the market. The result is a totally automated Apple Unified Platform currently trusted by over 45,000 organizations to make millions of Apple devices work-ready with no effort and at an affordable cost. Request your EXTENDED TRIAL today and understand why Mosyle is everything you need to work with Apple.


While WWDC26 is winding down, Iโ€™ve had time to reflect on Mondayโ€™s keynote, where Apple spent most of its time preaching to parents about on-device Child Safety and, of course, Siri AI.

However, it also showcased something insanely neat and ingenious on Appleโ€™s part that is largely being overshadowed. Iโ€™m referring to the new agentic AI feature now in iOS 27โ€™s Passwords app.

Expand Expanding Close

Hackers tricked Instagram AI into letting them take over 20,000 accounts [U]

๐Ÿ‘ Hackers tricked Meta AI into letting them take over high-profile accounts | Low key photo shows the app opening on a smartphone placed on top of a MacBook keyboard

Hackers managed to trick Metaโ€™s AI-powered support bot into allowing them to take over a number of Instagram accounts, including some high-profile ones. This included accounts belonging to the White House, US Space Force, and security researcher Jane Wong.

Update: Meta has now revealed that around 20,000 accounts were compromised and has explained the steps it has taken in response โ€ฆ

Expand Expanding Close
๐Ÿ‘ A security breach means you must update the ChatGPT Mac app | Photo shows the OpenAI logo on a phone sitting on a laptop

PSA: A security breach means you must update the ChatGPT Mac app [U]

If you use the ChatGPT desktop app on Mac, youโ€™ll be forced to update it sometime between now and June 12. Thatโ€™s due to a security breach involving two OpenAI employee devices. As of June 2, the company is emailing users to remind them to accept the update when offered.

Expand Expanding Close

The FBI may have reset your wireless router remotely; if so, you should replace it

๐Ÿ‘ The FBI may have reset your wireless router remotely; if so, you should replace it | The image shows a 3D representation of a Wi-Fi icon

The FBI and NSA jointly announced that Russia has been systematically compromising the security of home and small office routers since at least 2024.

They obtained a court order to allow them to remotely reset thousands of affected devices in the US, but if yours is one of them, it needs to be urgently replaced โ€ฆ

Expand Expanding Close

Mosyle identifies two new macOS threats invisible to antivirus engines

๐Ÿ‘ Image

After exclusively sharing details with 9to5Mac last September on ModStealer, a cross-platform infostealer invisible to every major antivirus engine at the time, Mosyle, a leader in Apple device management and security, is back with two more macOS threats that are flying completely under the radar.

In new details again shared with 9to5Mac, the Mosyle Security Research Team says it has identified two previously undetected samples: Phoenix Worm, a cross-platform stager, and ShadeStager, a modular macOS implant built for credential theft. The two arenโ€™t directly connected in how they work, but together show just how sophisticated Mac malware is getting.

Expand Expanding Close

Netgear can now sell new wireless routers in the US but nobody knows why [U]

๐Ÿ‘ Netgear can now sell new wireless routers in the US but nobody knows why | A badge showing FCC approval for a Netgear router

Last month saw a surprise ban on almost every new wireless router intended for use in US homes. The FCC ruling described all foreign-made routers as a national security risk.

The FCC offered a pathway to approval, and today Netgear has received that โ€“ but nobody knows why. Not even Netgear itself was able to offer an explanation โ€ฆ

Expand Expanding Close

FBI says cyber fraud cost Americans $21B last year โ€“ hereโ€™s what you need to know

๐Ÿ‘ FBI says cyber fraud cost Americans $21B last year โ€“ here's what you need to know | FBI meeting at a field office

The FBI says that a sharp rise in scams saw cybersecurity crime cost US victims a total of almost $21 billion last year. The most common example was investment scams, with cryptocurrency fraud responsible for the largest losses.

The report includes AI-related scams for the first time. The agency says that the use of voice cloning, forged documents, and deepfake videos were responsible for ยฃ893m in losses โ€ฆ

Expand Expanding Close

Apple products using Lockdown Mode have never been hacked, company confirms

๐Ÿ‘ iPhone Lockdown Mode

iPhone security has been in the news this month as Apple patches known exploits. As promised, the company has alerted customers using iPhones on older software to update this week. Meanwhile, Apple states on-the-record that its Lockdown Mode has proven effective against hack attempts so far.

Expand Expanding Close

Reddit CEO highlights a hidden benefit of Face ID and Touch ID

๐Ÿ‘ Reddit CEO highlights a hidden benefit of Face ID and Touch ID | Image shows the Face ID icon on a blue-purple background

The tech industry is currently in the middle of a rather gradual security transition from usernames and passwords to passkeys.

Passkeys are far more secure as online services donโ€™t store your username and password, but Reddit CEO Steve Huffman says that the use of Face ID and Touch ID has an additional benefit โ€ฆ

Expand Expanding Close

TikTok says it wonโ€™t introduce end-to-end encryption for DMs [U]

๐Ÿ‘ TikTok says it won't introduce end-to-end encryption for DMs | TikTok logo seen on a smartphone screen

TikTok is setting itself apart from most other online platforms that offer messaging by stating that it wonโ€™t be introducing end-to-end encryption to ensure the privacy of direct messages.

This means that the company will be able to read messages sent between users, which is likely to cause concerns even after its US operations were separated from its Chinese owner โ€ฆ

Update: Added comment from TikTok below

Expand Expanding Close

PSA: Most Wi-Fi routers vulnerable to AirSnitch attack โ€“ hereโ€™s what to do

๐Ÿ‘ Most Wi-Fi routers vulnerable to AirSnitch attack โ€“ here's what to do | A wireless penetration testing tool is shown

You may recall that way back in 2017, the WPA2 encryption standard used by most Wi-Fi routers at the time was cracked and had to be replaced with a new version, WPA3. Now a new attack method dubbed AirSnitch means that Wi-Fi encryption on most networks can be bypassed in order to access all of the traffic passing through the router.

Almost all routers are vulnerable, so there are three steps you should take in order to protect yourself, with the greatest risk occurring through use of public Wi-Fi hotspots โ€ฆ

Expand Expanding Close

Security Bite: What Apple does with your spam reports

๐Ÿ‘ report junk and delete imessage iphone mac macbook security bite arin waichulis

9to5Mac Security Bite is exclusively brought to you by Mosyle, the only Apple Unified Platform. Making Apple devices work-ready and enterprise-safe is all we do. Our unique integrated approach to management and security combines state-of-the-art Apple-specific security solutions for fully automated Hardening & Compliance, Next Generation EDR, AI-powered Zero Trust, and exclusive Privilege Management with the most powerful and modern Apple MDM on the market. The result is a totally automated Apple Unified Platform currently trusted by over 45,000 organizations to make millions of Apple devices work-ready with no effort and at an affordable cost. Request your EXTENDED TRIAL today and understand why Mosyle is everything you need to work with Apple.


Much like the infamously useless โ€œclose doorโ€ button in an elevator, reporting spam on an iPhone or Mac often feels like a placebo. This skepticism isnโ€™t exclusive to Apple either. There is widespread distrust of reporting features in general. The issue largely stems from a lack of transparency. Because users rarely see a noticeable decline in junk mail after hitting โ€œreport,โ€ many assume the button does nothing and eventually stop using it altogether.

While Apple does provide a great support document for how to make reports, it doesnโ€™t explain exactly what it does with these reports to improve its security prowess. Allow me to shed some light hereโ€ฆ

Expand Expanding Close

Millions of passwords and Social Security numbers exposed as old hacks remain a threat

๐Ÿ‘ Millions of passwords and Social Security numbers exposed as old hacks remain a threat | Close-up photo of hard drive platters

An unsecured database that likely contains tens of millions of unique Social Security numbers, alongside email addresses and passwords, has been discovered by security researchers.

While the database appears to have been collated from a number of separate data breaches over approximately a decade, the researchers explain why even very old personal data remains a live threat โ€ฆ

Expand Expanding Close