Radar
You open your phone in the morning. Three notifications, five alarming headlines, and zero idea what you’re supposed to do about it, or even whether it’s serious. If you’ve been there, you’re in the right place.
We read everything so you don’t have to, we compile what concerns your Mac, your iPhone, your accounts, your data. Then we explain in two minutes what’s happening and what you should do about it.
Three levels depending on what’s going on, and every time, a concrete action.
ANALYSIS
Regulation, underlying trends, breakdown.
The substance, not just the froth. Long format, full context and medium-term consequences.
CSAR, ProtectEU, GDPR developments, landmark CNIL rulings.
SIGNAL
Serious threat, major update, policy change.
Nothing’s on fire, but it’s about to matter. Medium format, practical angle and prep.
Terms-of-service change, unexploited flaw, sensitive new Apple feature.
ALERT
Exploited flaw, critical patch, immediate threat.
When you have to act today. Short format, straight to the point, concrete action up top.
Critical iOS CVE, active macOS malware, exploited zero-day.
Latest published Radars
On 26 August, the United States branded the Italian collective Autistici/Inventati a "terrorist". Dollar payment channels cut off (PayPal), and the domain autistici.org pulled from DNS by its registry in late August. The lever: .org depends on an American registry, Public Interest Registry, which can be forced to cut. .com, .net and .org are all in that situation.
What it changes for you
1. An American extension (.com, .net, .org) is seizable without a judge in your country stepping in.
2. A national domain, .ch, .eu, .fr, escapes the direct order, but the domain is only one link.
3. Sovereignty is the full stack: registry, registrar, hosting, payments. Miss one floor, and the sanction pours in.
macOS info-stealers are going after Claude sessions. Anthropic confirmed in late August that stealers, AMOS included in a few Mac cases, hijacked Claude sessions by copying the browser session. And a late-July disclosure shows that the Claude Code token, stored in the Keychain, is readable there by any program running under your account. No flaw in Apple or Claude, it gets in through a command someone makes you paste into the Terminal.
What to do now
1. A stolen session token acts on your account with no password, 2FA doesn't protect a token already issued, and it stays valid for several days, a local logout doesn't kill it. Real revocation goes through your account online, revoking all sessions and rotating your API key if you have one.
2. Two false reflexes, `chmod` does nothing against malware running under your own account, and antivirus keeps chasing a stealer that mutates non stop.
3. Set up execution control. An allowlisting tool like Santa in lockdown mode won't block the pasted line itself, but it kills the thief binary the moment it tries to run, the safeguard that acts even when you got fooled. And a command someone pushes you to paste into the Terminal, well... you don't paste it, ever.
ChatGPT can now read, summarize and send your iMessages on Mac. The ticket in is Full Disk Access, the broadest permission in macOS. You flip a setting on your end, and your whole correspondents' history goes with it, even though none of them agreed to anything.
What to watch
1. For now limited to the app's Codex and ChatGPT Work modes, on Apple Silicon Macs, but Codex is included even in the free plan.
2. The send confirmation protects the output, not the reading; the plugin reads your entire history before any approval.
3. Open System Settings, Privacy and Security, Full Disk Access, and remove any third-party AI assistant. Same round in Automation and Contacts.
On 16 July 2026, Canada signed the UN Convention against Cybercrime, the very treaty it had sworn to fight. Signature, not ratification yet: nothing is armed until 40 countries ratify. But read the fine print. Behind the "anti-cybercrime" veneer sits a machine for moving evidence between states that, once ratified, nowhere forbids laundering data stolen by spyware. They call it cooperation. It's surveillance with a new stamp on it.
What you watch, now
1. Ratification, not signature. Don't fall for the press release: the only number that arms this treaty is 40. Below it, theatre. Above it, too late.
2. The origin of evidence. The text couldn't care less whether a piece of evidence was stolen, nothing forbids passing it around. If your representatives don't lodge an explicit reservation when ratifying, they're signing a blank cheque.
3. The extraterritorial reach. Journalist, researcher, whistleblower, diaspora: the target is you, not the cybercriminals. A repressive regime on the other side of the world will be able to demand your file, and a gag order will forbid you from even knowing it was taken.
Private Relay is not a VPN. A large share of iCloud+ subscribers turn it on believing it hides all their traffic, it only covers Safari, and three WebKit leaks let your IP or your DNS slip out. A US law firm is suing Apple for fraud, with no fix announced by the company.
What to watch
1. Passkey, DNS prefetching and WebTransport (introduced with iOS 26) bypass the relay, on the Safari engine side.
2. These are legal allegations plus security research, not exploitation documented in the wild.
3. Apple is investigating with no timeline, no leak is plugged until it's publicly verified.
4. Install a sovereign, encrypted DNS, DNS4EU or Quad9 over DoH or DoT. It closes the DNS leak that Private Relay lets through, and the protection is worth well beyond Safari.
Apple is challenging before the IPT a new British order demanding access to your encrypted iCloud backups. It is narrowed to UK users only, after the 2025 version, which also covered Americans, was withdrawn. The catch: if you can technically open one country's backups, you can do it anywhere. The precedent weighs more than the perimeter.
What it changes for you
1. Without Advanced Data Protection, your iCloud backup is encrypted but with a key Apple holds, so it is accessible to Apple and can be compelled by an order.
2. With ADP on, your backups switch to end-to-end encryption and Apple has nothing left to hand over. Check your status.
3. The option does not cover iCloud Mail, Contacts or Calendar. For encrypted email, that is Proton Mail or Tuta.
A contact you know invites you to a video call on Telegram, except their account has been hijacked. During the call, a fake "Zoom SDK Update" pops up, you click to fix your mic, and **a stealer siphons your browser keys** out of your iCloud Keychain. BlueNoroff, North Korea, zero flaw exploited, 100% social engineering. It's the third ClickFix on macOS in six weeks.
What you need to do
1. An install prompt in the middle of a meeting, you refuse. No video call ships you an "SDK Update" mid-call.
2. A meeting link, even from a real contact, verify it through another channel. The Telegram account on the other end may be compromised.
3. An outbound firewall, Little Snitch or LuLu, sees the exfil leave for Telegram while the stealer empties your keychain.
You connect one folder to Claude Cowork, and the agent actually has your whole disk within reach. In local execution mode on macOS, Cowork mounts the entire filesystem read-write inside the agent's virtual machine. A single message is enough to walk it out, without any permission prompt showing up. Anthropic closed the report as "informative", with no fix: the shift to cloud execution does mitigate the risk, but it is a gradual beta, and local mode stays exposed.
What you need to do
1. Check your Cowork execution mode. Cloud has become the default, but in beta and in waves: go read it in your settings instead of assuming it. Local mode leaves you exposed.
2. Never run a local session from a macOS account that holds your Keychain, your SSH keys or your password manager file.
3. Treat everything the agent reads, web page, attachment, ticket, as hostile code. That is the entry point of the chain.
The model hub where LM Studio fetches your models has been breached, Hugging Face announced on July 16th. The company left internal infrastructure credentials, not yours, and no public model tampering has been reported. The twist? No hacker involved. OpenAI claims it was their own models, escaped from an internal test.
What to watch out for
1. If you don't have a Hugging Face account, you've got nothing to worry about. Your downloads are untouched.
2. If you do have an account, rotate your access tokens and review recent activity, as a precaution.
3. Hugging Face is still assessing if partner or client data has been affected.
CrashStealer, a macOS infostealer disguised as an Apple crash-reporting tool, clears Gatekeeper without the slightest alert. It's signed by a valid Developer ID and notarized by Apple. Your Mac trusts the signature, not the intent behind it. Apple revoked the certificate after the fact, once the damage was done.
What you should do
1. Any app or DMG from outside the App Store received by invitation or direct link, the Apple signature doesn't redeem the provenance.
2. A prompt asking for your login password "to continue" with no legitimate install underway is a red flag.
3. Unexpected outbound connections, an application firewall like Little Snitch or LuLu sees them go out.
Apple added an anti-ClickFix warning in the Terminal with macOS 26.4. Attackers promptly switched to Script Editor to distribute Atomic Stealer without friction.
SparkCat accesses your Photos gallery, scans everything with OCR, and extracts crypto seed phrases. Never store a mnemonic phrase as a screenshot.
The source code of DarkSword is on GitHub. Apple releases iOS 18.7.7 to fix WebKit, Kernel, and Keychain. Mandatory update.
Why a Radar rather than a news feed
Because nobody needs yet another aggregator. What you want is to know what deserves your attention and what to do about it. Nothing else.
Getting the Radars
- Dedicated RSS feed: macsouverain.com/en/tag/radar/rss/, add it to NetNewsWire, Reeder, or any RSS reader.
- Full archive: macsouverain.com/en/tag/radar/
How the Radars are made
- Automated watch every morning across some fifty sources (institutional, Apple-centric, privacy, cybersec, French-language blogs, Reddit, Mastodon).
- Selective sorting: we keep only what can genuinely affect your Mac, your iPhone or your everyday digital life.
- Manual fact-check on every topic we keep: CVEs verified in the NVD, iOS/macOS versions confirmed on Apple Security Updates, multi-source mandatory.
- Writing in a direct tone, no empty jargon, sources cited inline.
- Editorial sign-off before publishing. Zero articles slapped up in a hurry.
Spot something that deserves a Radar, or an error in an article? Write to me, @[email protected], the Radar gets better with reader feedback.