Radar
You open your phone in the morning. Three notifications, five alarming headlines, and zero idea what you’re supposed to do about it, or even whether it’s serious. If you’ve been there, you’re in the right place.
We read everything so you don’t have to, we compile what concerns your Mac, your iPhone, your accounts, your data. Then we explain in two minutes what’s happening and what you should do about it.
Three levels depending on what’s going on, and every time, a concrete action.
ANALYSIS
Regulation, underlying trends, breakdown.
The substance, not just the froth. Long format, full context and medium-term consequences.
CSAR, ProtectEU, GDPR developments, landmark CNIL rulings.
SIGNAL
Serious threat, major update, policy change.
Nothing’s on fire, but it’s about to matter. Medium format, practical angle and prep.
Terms-of-service change, unexploited flaw, sensitive new Apple feature.
ALERT
Exploited flaw, critical patch, immediate threat.
When you have to act today. Short format, straight to the point, concrete action up top.
Critical iOS CVE, active macOS malware, exploited zero-day.
Latest published Radars
Canada signed the UN Cybercrime Convention. A cross-border evidence-sharing channel that, once ratified, can launder data stolen by spyware.
A large share of iCloud+ subscribers take Private Relay for a tunnel. Three WebKit leaks say otherwise, and Apple is being sued for fraud.
Apple is challenging a British order targeting your iCloud backups. Narrowed to the UK, the precedent knows no border.
A trusted Telegram contact invites you to a video call, a fake Zoom update pops up mid-call, and your iCloud Keychain gets emptied.
On macOS in local mode, Claude Cowork mounts your entire disk inside the agent's VM. One connected folder, one message, and it walks out without asking.
Hugging Face announced on July 16th that they had been compromised. Public models were unaffected, and the attacker was an OpenAI AI in testing.
CrashStealer, signed and notarized by Apple, clears Gatekeeper without a single alert. Notarization validates the signature, not the intent.
On July 9th, the European Parliament allowed Chat Control 1.0 to be renewed, falling short of the 361 votes needed to block it, despite a majority voting against. What this means, and what's heading back to trilogue in September.
Wazuh 5.0 in public beta, releasing late June/early July. Filebeat dit au revoir, clusters enabled by default, new engine. Your 4.x install will upgrade. Don't worry, we'll explain it all.
June 29th saw the EU's 5th and final trilogue on Chat Control 2.0 (CSAR). At stake: mass scanning of your private messages before encryption, versus a Parliament defending end-to-end. The outcome's now, deciding if WhatsApp, Signal, and iMessage stay truly encrypted in Europe.
Tech companies track any mobile device through telecom interconnection flaws. No iPhone patches needed.
Apple Unveils Siri AI at WWDC, But Locks It Down on iPhone and iPad in EU. A Confidential Platform Built on Google Gemini. Here's the Breakdown.
ChatGPT, Codex, and Atlas on Mac: Mandatory update before June 12, 2026. OpenAI cert revoked after npm supply-chain attack.
Stalkerware Spyzie, Cocospy, Spyic, over 3 million victims combined. Your iPhone drained via your Apple ID. How to check and take back control.
A US federal cyber agency's subcontractor left their AWS GovCloud admin keys on a public GitHub repo for six months. Why not delegate your security, huh?
Three California researchers bypassed Memory Integrity Enforcement M5 in five days using Mythos. First public kernel exploit on Apple M5 silicon. Patched in macOS Tahoe 26.5.
Google sponsored ads redirect to real, shared claude.ai links that are baited. Fake Apple Support makes you paste a base64 into Terminal. MacSync payload empties your Keychain.
iOS 26.5 fixes 98 CVEs, including 21 in WebKit; macOS Tahoe 26.5 fixes 98 CVEs, including 22. Instead of enabling Lockdown Mode everywhere, segment with a dedicated Safari profile.
Proton Mail offers a quantum-resistant encryption option, available on all plans including the free one. Must be enabled manually, but don't get your hopes up.
Apple enables end-to-end encryption on RCS messages with iOS 26.5, using the MLS protocol. The end of cross-platform clear-text SMS, but Signal remains the gold standard for sovereignty.
Trellix, a cybersecurity partner of Europol, announced on 02/05 an unauthorized access to a portion of its source code. No evidence of exploitation, according to the vendor, but this statement needs verification.
An American ransomware negotiator pleaded guilty to secretly working for the gangs he was supposed to fight. This case highlights a structural issue: the entire post-incident ecosystem (negotiators, insurers, consultants) has an interest in you paying.
Apple posts a solid quarter with a healthy Mac and double-digit growth in Services. For those using Apple's ecosystem as a sovereignty pivot, it's a confirmation: hardware remains robust, but the cloud lock-in temptation grows stronger.
OX Security published on April 15, 2026 a architectural vulnerability in Anthropic's Model Context Protocol (MCP): the STDIO interface of the official SDKs allows for the execution of arbitrary OS commands from the configuration. 7,000+ public servers, 150M+ downloads, and approximately 200,000 instances are exposed. On the Mac side: Cursor, Windsurf, and Claude Desktop are concretely affected via their MCP integrations. Anthropic refuses to patch: "by design".
Anthropic keeps a model, Mythos, under lock and key, capable of finding zero-day flaws on its own across iOS, macOS, Windows, and browsers. An unauthorized group, including an Anthropic subcontractor employee, gained access to it after the program's announcement, via a guessed URL.
OpenAI officially classifies GPT-5.5 as "High" cybersecurity capability. The model can run multi-day vulnerability research campaigns, produce basic exploit memory blocks on hardened systems, and saturate professional hacking competitions. OpenAI has tightened its input filters and restricted access to modes where AI can chain multiple vulnerabilities on its own.
A researcher asked Claude Opus 4.6, the same model accessible to anyone for a monthly subscription, to create code to exploit a fixed Chrome bug. Result: Discord opens your Mac's calculator without your permission. Researchers' security convention: if calc opens without asking, anything can open. Discord, Slack, Teams, Notion all run on Chrome under the hood and patch late. Operation cost: $2,283.
Paul Moore skirts the EU's age-verification app in under 2 minutes. The EUDI standard promised zero-knowledge. Its implementation stores the PIN in an editable XML.
The FBI reassembled deleted Signal messages via iPhone push notification metadata. End-to-end encryption didn't make a difference.
macOS secretly logs access to your files whenever you use the Open/Save dialog. The Privacy & Security interface doesn't show this. Since 2019.
108 malicious Chrome extensions identified in the Chrome Web Store by Socket researchers. Google OAuth theft, backdoors, Telegram exfiltration. Google notified, extensions still online at publication. If you're using Chrome on Mac, you're affected.
On a simple administrative subpoena from ICE, Google handed over a journalist's data without prior notice, breaking a decade-old promise.
ANSSI issues official warning about autonomous AI agents on workstations. Cowork Claude and OpenClaw named. Here's what you need to do.
The European Parliament amended the AI Act on March 26, 2026: rules constraining companies deploying high-risk systems are pushed back by 16 months. On the surface, it looks like a step back. In practice, what directly concerns you as a user is sped up or already in effect.
Citizen Lab has documented Webloc, a mass surveillance tool that exploits mobile advertising data to continuously geolocate 500 million devices worldwide, with a 3-year history, without any judicial warrant. Its clients include ICE, the US military, police forces, and intelligence services. The source? The public advertising network that all your apps swim in.
Under the guise of protecting children, the EU is rushing to set up mass surveillance infrastructure for all encrypted messaging platforms.
Russian military intelligence is exploiting unpatched routers to silently intercept your Office OAuth tokens. What you need to do.
Apple added an anti-ClickFix warning in the Terminal with macOS 26.4. Attackers promptly switched to Script Editor to distribute Atomic Stealer without friction.
SparkCat accesses your Photos gallery, scans everything with OCR, and extracts crypto seed phrases. Never store a mnemonic phrase as a screenshot.
Coruna exploits 23 iOS 13 to 17.2.1 flaws, installs silently. Already in Russian criminals' hands. Activate Lockdown Mode now.
The source code of DarkSword is on GitHub. Apple releases iOS 18.7.7 to fix WebKit, Kernel, and Keychain. Mandatory update.
Why a Radar rather than a news feed
Because nobody needs yet another aggregator. What you want is to know what deserves your attention and what to do about it. Nothing else.
Getting the Radars
- Dedicated RSS feed: macsouverain.com/en/tag/radar/rss/, add it to NetNewsWire, Reeder, or any RSS reader.
- Full archive: macsouverain.com/en/tag/radar/
How the Radars are made
- Automated watch every morning across some fifty sources (institutional, Apple-centric, privacy, cybersec, French-language blogs, Reddit, Mastodon).
- Selective sorting: we keep only what can genuinely affect your Mac, your iPhone or your everyday digital life.
- Manual fact-check on every topic we keep: CVEs verified in the NVD, iOS/macOS versions confirmed on Apple Security Updates, multi-source mandatory.
- Writing in a direct tone, no empty jargon, sources cited inline.
- Editorial sign-off before publishing. Zero articles slapped up in a hurry.
Spot something that deserves a Radar, or an error in an article? Write to me, @[email protected], the Radar gets better with reader feedback.