Skip to content
Thoughtful, detailed coverage of everything Apple for 36 years
and the TidBITS Content Network for Apple professionals

Category: Security

Adam Engst 40 comments

WWDC26 Keynote Shows Apple’s Tacit Acknowledgment of External Pressures

Apple spent the entirety of its WWDC26 keynote responding to external pressures, including user complaints about Liquid Glass, community and regulatory worries regarding child safety, and the embarrassment of Siri delays and Apple Intelligence weaknesses.

Adam Engst 10 comments

Fighting a Denial of Service Attack with AI Assistance

Troubleshooting an inaccessible server is challenging at the best of times and doubly so when you are out of practice. Read how Claude guided Adam Engst through troubleshooting and mitigating a denial of service attack.

Adam Engst 8 comments

Gift Card Scam Funnels Millions in Apple Devices Through New Hampshire Warehouses

Criminals are stealing gift card numbers from retail shelves, replacing them, draining them when purchasers load funds, and using the proceeds to buy Apple products for export—yet another reason to avoid physical gift cards.

Adam Engst 37 comments

AppBITS: EyesOff Alerts You to Shoulder Surfing

Worried about prying eyes at the coffee shop? EyesOff uses your Mac’s webcam to detect when someone’s watching your screen and can alert you, hide your work, or lock your Mac.

Adam Engst 2 comments

Apple Extends Notification Privacy Fix to iOS 15, iOS 16, and iPadOS 17

If your iPhone or iPad is too old to run iOS 18 or later, Apple hasn’t forgotten you—new updates for iOS and iPadOS 15, iOS and iPadOS 16, and iPadOS 17 patch the notification retention flaw that could expose deleted messages.

Adam Engst 4 comments

OS 26.5 Adds Encrypted RCS Messaging, Fixes Bugs

The OS 26.5 updates bring end-to-end encrypted RCS messaging to iPhones, a Pride Luminance wallpaper and watch face, and Suggested Places recommendations in Maps. Otherwise, expect a few bug fixes and numerous security updates.

Adam Engst 20 comments

Beware Greeting Card Scams from Trusted Senders

Scammers are hijacking email accounts to send fake party invitations that look like they’re from friends, and even experienced users are falling for them. Learn the red flags, how to alert an affected friend, and what to do if you’re caught.

Adam Engst 13 comments

iOS 26.4.2 and iOS 18.7.8 Address Notification Privacy Flaw Highlighted by FBI Case

The FBI extracted Signal messages from an iPhone by exploiting a notification database flaw. Apple has now released iOS 18.7.8 and iOS 26.4.2 to fix a bug that allowed deleted notifications to persist on devices.

Adam Engst 9 comments

Shutting Down SlackBITS After Impersonation-Based Malware Attack

A convincing impersonation of TidBITS contributor Glenn Fleishman on our public Slack group fooled an experienced IT professional into installing the OSX.Odyssey infostealer. Because Slack is designed for internal groups, its identity controls and logging aren’t sufficient for safe public use, so we’re shutting down SlackBITS and moving to Discourse Chat.

Rich Mogull 59 comments

What Anthropic’s Mythos and Project Glasswing Mean for Your Apple Devices

AI is accelerating the discovery of security vulnerabilities, transforming the landscape of digital security. But Apple users are in a good spot, thanks to Apple’s focus on security and control over the entire ecosystem. TidBITS Security Editor Rich Mogull explains Anthropic’s Mythos and Project Glasswing.

Adam Engst 32 comments

Apple Offers iOS 18.7.7 Security Update as Alternative to iOS 26.4 Upgrade

To address the DarkSword exploit, Apple now lets iOS 18 users install the iOS 18.7.7 security update instead of upgrading to iOS 26.4. If you’re still using iOS 18, update immediately.

Adam Engst 25 comments

The Verge Explains the US Government’s Router Ban

Sean Hollister’s lively Q&A explains why the FCC’s foreign router ban won’t recall existing routers, audit new ones, or do much of anything to improve security—it just blocks future imports unless manufacturers commit to US production.

Adam Engst 44 comments

OS 26.4 Adds AI-Generated Playlist Playground, Separates Family Sharing Purchases

Apple’s OS 26.4 updates add Apple Intelligence-generated playlists in Apple Music, image creation and editing tools in Freeform, easier marking of Reminders as urgent, and independent payment methods for adult members of Family Sharing groups. Oh, and eight new emoji you didn’t know how you were living without.

Adam Engst 73 comments

DarkSword Exploit Threatens iPhones Still Running iOS 18

Security researchers have discovered DarkSword, a sophisticated exploit chain targeting iOS 18.4 through 18.7.2. Unlike past spyware aimed at high-profile targets, DarkSword is being surreptitiously deployed on legitimate websites against ordinary users.

Adam Engst 16 comments

When Face ID Helps iPhone Security—And When to Turn It Off

Heading to a protest or crossing a border? Your iPhone’s Face ID—which is normally a boon with Stolen Device Protection—could become a liability. Learn when to disable biometrics and what other steps you can take to protect your privacy and data from compelled access.