<?xml version="1.0" encoding="UTF-8"?><rss version="2.0" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Mac Souverain — Radars (English)</title><description>Security and news watch — the Mac Souverain radars.</description><link>https://macsouverain.com/en/</link><language>en</language><atom:link href="https://macsouverain.com/en/radars.xml" rel="self" type="application/rss+xml"/><item><title>A fake Zoom update empties your iCloud Keychain</title><link>https://macsouverain.com/en/radar-bluenoroff-zoom-sdk-update-macos/</link><guid isPermaLink="true">https://macsouverain.com/en/radar-bluenoroff-zoom-sdk-update-macos/</guid><description>A trusted Telegram contact invites you to a video call, a fake Zoom update pops up mid-call, and your iCloud Keychain gets emptied.</description><pubDate>Tue, 28 Jul 2026 09:15:00 GMT</pubDate><content:encoded>&lt;div class=&quot;radar-summary&quot;&gt;
&lt;p&gt;A contact you know invites you to a video call on Telegram, except their account has been hijacked. During the call, a fake &quot;Zoom SDK Update&quot; pops up, you click to fix your mic, and **a stealer siphons your browser keys** out of your iCloud Keychain. BlueNoroff, North Korea, zero flaw exploited, 100% social engineering. It&apos;s the third ClickFix on macOS in six weeks.&lt;/p&gt;
&lt;br&gt;
&lt;p&gt;&lt;strong&gt;What you need to do&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;1.&lt;/strong&gt; An install prompt in the middle of a meeting, you refuse. No video call ships you an &quot;SDK Update&quot; mid-call.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;2.&lt;/strong&gt; A meeting link, even from a real contact, verify it through another channel. The Telegram account on the other end may be compromised.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;3.&lt;/strong&gt; An outbound firewall, Little Snitch or LuLu, sees the exfil leave for Telegram while the stealer empties your keychain.&lt;/p&gt;
&lt;/div&gt;
&lt;h2 id=&quot;whats-really-happening-mid-call&quot;&gt;What’s really happening mid-call&lt;/h2&gt;
&lt;br&gt;
&lt;p&gt;BlueNoroff, the North Korean banner that targets crypto professionals, exploits no flaw. &lt;strong&gt;Zero exploit, zero CVE.&lt;/strong&gt; Just social engineering, scaled into an industrial chain. The research comes from JUMPSEC, the “ClickFake Interview” cluster is tracked by Sekoia, and The Hacker News picked it up on July 24, 2026.&lt;/p&gt;
&lt;br&gt;
&lt;p&gt;Here’s how it goes. A contact you’ve met in person messages you on Telegram, &lt;strong&gt;except their account has been hijacked.&lt;/strong&gt; They send you a Calendly link in their name, which redirects you to a typosquatted Zoom or Teams domain, &lt;code&gt;us.zoom.06webin.us&lt;/code&gt;. You type your name, you allow the camera, and the kit gets to work behind your back. It captures your video stream via mediasoup WebRTC and profiles the crypto wallet extensions installed in your browser. Then a fake message, “your mic isn’t working”, followed by a “Zoom SDK Update” prompt. You click to fix your mic, you install the payload.&lt;/p&gt;
&lt;br&gt;
&lt;p&gt;On macOS, &lt;strong&gt;the rest unfolds without you.&lt;/strong&gt; A shell script downloads a fake Teams or Zoom installer, a stealer extracts Chrome’s master keys from your macOS login keychain, where Chrome stores its encryption key, the ones that unlock &lt;strong&gt;your crypto wallet extensions&lt;/strong&gt;, and exfiltrates everything through a Telegram channel named “Aurora”, before dropping further payloads. On the Windows side, the variant disables Defender via a PowerShell loader and hunts for Telegram sessions in Chrome, Edge, Brave and Firefox. Same actor, two chains.&lt;/p&gt;
&lt;br&gt;
&lt;p&gt;Two details change the scale. The video calls are faked with deepfakes, AI-generated faces layered over real body language, captured from earlier victims. And &lt;strong&gt;the mechanism self-propagates&lt;/strong&gt;, each compromised Telegram account becomes the trusted sender for the next one. &lt;strong&gt;Five versions of the kit&lt;/strong&gt; have been spotted between May 31 and July 14, 2026, the operator is tied to the Telegram bot &lt;code&gt;@alchemy_john_mac&lt;/code&gt;. This is no one-off, it’s a factory that iterates.&lt;/p&gt;
&lt;br&gt;
&lt;p&gt;The technique has a name, ClickFix, and it already drags a trail of victims behind it.&lt;/p&gt;
&lt;br&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;em&gt;Read next: &lt;a href=&quot;https://macsouverain.com/en/radar-clickfix-script-editor-avril-2026/&quot;&gt;ClickFix, the fake fix that makes you launch the malware yourself&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;br&gt;
&lt;h2 id=&quot;the-third-clickfix-on-macos-in-six-weeks&quot;&gt;The third ClickFix on macOS in six weeks&lt;/h2&gt;
&lt;br&gt;
&lt;p&gt;Do the math. CrashStealer in July, ClickLock before it, now BlueNoroff. &lt;strong&gt;Three times in six weeks&lt;/strong&gt; the same pattern has hit macOS, one harmless gesture that triggers the install. The vector is going industrial, and this version &lt;strong&gt;aims straight at your keychain&lt;/strong&gt;, where macOS stores your browser’s keys.&lt;/p&gt;
&lt;br&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;em&gt;Read next: &lt;a href=&quot;https://macsouverain.com/en/radar-crashstealer-notarise-apple-gatekeeper/&quot;&gt;An Apple-notarized malware slips past Gatekeeper&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;br&gt;
&lt;p&gt;What protects you here is neither antivirus nor notarization. It’s a behavioral rule, simple and absolute, &lt;strong&gt;never install a binary offered to you during a meeting&lt;/strong&gt;. Zoom doesn’t ship you an “SDK Update” mid-call. Neither does Teams. An update that surfaces during a video call &lt;strong&gt;is not an update, it’s the payload.&lt;/strong&gt;&lt;/p&gt;
&lt;br&gt;
&lt;p&gt;There’s a stack angle, provided you’re honest about its reach. Proton Meet is end-to-end encrypted and runs in your browser, with no native client to install. So the “install this SDK update” pretext has nowhere to latch on, there’s no app to update. It shrinks the attack surface, it doesn’t replace the behavioral rule. &lt;strong&gt;Switching to Proton Meet does not protect you from this phishing&lt;/strong&gt;, social engineering depends on no tool.&lt;/p&gt;
&lt;br&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;em&gt;Read next: &lt;a href=&quot;https://macsouverain.com/en/proton-meet-visio-chiffree/&quot;&gt;Proton Meet, the encrypted video call that runs in your browser&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;br&gt;
&lt;p&gt;The part that should worry you is the sender. It’s not a stranger, it’s someone &lt;strong&gt;whose hand you’ve shaken&lt;/strong&gt;. &lt;strong&gt;Interpersonal trust is the vector, not your gullibility.&lt;/strong&gt; A genuine Telegram account, a name you recognize, a meeting link, that’s all it takes.&lt;/p&gt;
&lt;br&gt;
&lt;h2 id=&quot;what-you-do-now&quot;&gt;What you do now&lt;/h2&gt;
&lt;br&gt;
&lt;p&gt;&lt;strong&gt;1.&lt;/strong&gt; An install prompt that appears during a meeting, &lt;strong&gt;you refuse, no exceptions&lt;/strong&gt;. Zoom, Teams, no video call asks you to install an “SDK Update” or to fix your mic through a download. You leave the call, you click nothing.&lt;/p&gt;
&lt;br&gt;
&lt;p&gt;&lt;strong&gt;2.&lt;/strong&gt; A meeting link, even sent by a real contact, &lt;strong&gt;you verify it through another channel&lt;/strong&gt; before clicking. A voice call, a Signal message, “did you really send me this Calendly?”. The Telegram account on the other end may already be hijacked.&lt;/p&gt;
&lt;br&gt;
&lt;p&gt;&lt;strong&gt;3.&lt;/strong&gt; Look at the URL before allowing your camera. &lt;code&gt;us.zoom.06webin.us&lt;/code&gt; is not a Zoom domain, &lt;strong&gt;it’s typosquatting&lt;/strong&gt;. The real Zoom is &lt;code&gt;zoom.us&lt;/code&gt;. A long trailing subdomain grafted onto an unknown name, you close the tab.&lt;/p&gt;
&lt;br&gt;
&lt;p&gt;&lt;strong&gt;4.&lt;/strong&gt; &lt;strong&gt;Install an outbound firewall&lt;/strong&gt; and let it speak. Little Snitch or LuLu see the exfiltration leave for Telegram, exactly when the stealer empties your keychain. It’s your last line when everything else has been bypassed.&lt;/p&gt;
&lt;br&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;em&gt;Read next: &lt;a href=&quot;https://macsouverain.com/en/little-snitch-vs-lulu-pare-feu-sortant-mac/&quot;&gt;Little Snitch vs LuLu, which outbound firewall for your Mac&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;br&gt;
&lt;h2 id=&quot;sources&quot;&gt;Sources&lt;/h2&gt;
&lt;br&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&quot;https://thehackernews.com/2026/07/bluenoroff-zoom-phishing-kit-profiles.html&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;The Hacker News&lt;/a&gt;, which relayed the research on July 24, 2026&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://www.jumpsec.com/guides/inside-a-dprk-bluenoroff-clickfix-kit/&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;Primary research JUMPSEC&lt;/a&gt;, analysis of the BlueNoroff phishing kit&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://blog.sekoia.io/clickfake-interview-campaign-by-lazarus/&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;“ClickFake Interview” cluster tracked by Sekoia&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;</content:encoded><dc:creator>Mac Souverain</dc:creator><category>radar</category><category>radar-alerte</category><category>macos</category><category>cybersec</category><category>phishing</category><category>crypto</category></item><item><title>Claude Cowork in local mode, the agent walks out of the sandbox</title><link>https://macsouverain.com/en/radar-sharedroot-claude-cowork-bac-a-sable/</link><guid isPermaLink="true">https://macsouverain.com/en/radar-sharedroot-claude-cowork-bac-a-sable/</guid><description>On macOS in local mode, Claude Cowork mounts your entire disk inside the agent&apos;s VM. One connected folder, one message, and it walks out without asking.</description><pubDate>Fri, 24 Jul 2026 10:00:00 GMT</pubDate><content:encoded>&lt;div class=&quot;radar-summary&quot;&gt;
&lt;p&gt;You connect one folder to Claude Cowork, and the agent actually has your whole disk within reach. In local execution mode on macOS, Cowork mounts the entire filesystem read-write inside the agent&apos;s virtual machine. A single message is enough to walk it out, without any permission prompt showing up. Anthropic closed the report as &quot;informative&quot;, with no fix: the shift to cloud execution does mitigate the risk, but it is a gradual beta, and local mode stays exposed.&lt;/p&gt;
&lt;br&gt;
&lt;p&gt;&lt;strong&gt;What you need to do&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;1.&lt;/strong&gt; Check your Cowork execution mode. Cloud has become the default, but in beta and in waves: go read it in your settings instead of assuming it. Local mode leaves you exposed.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;2.&lt;/strong&gt; Never run a local session from a macOS account that holds your Keychain, your SSH keys or your password manager file.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;3.&lt;/strong&gt; Treat everything the agent reads, web page, attachment, ticket, as hostile code. That is the entry point of the chain.&lt;/p&gt;
&lt;/div&gt;
&lt;h2 id=&quot;what-cowork-actually-mounts&quot;&gt;What Cowork actually mounts&lt;/h2&gt;
&lt;br&gt;
&lt;p&gt;In local execution mode on macOS, Claude Cowork mounts your Mac’s entire filesystem read-write inside the Linux virtual machine where the agent runs, at a mount point named &lt;code&gt;/mnt/.virtiofs-root&lt;/code&gt;, visible only to the &lt;code&gt;guest-root&lt;/code&gt; account. The whole disk. Not the folder you connected. The sandbox is a box, it just has no walls. The research, named SharedRoot, comes from Oren Yomtov, Principal Security Researcher at Accomplish AI, published on July 23, 2026 and picked up the same day by The Hacker News.&lt;/p&gt;
&lt;br&gt;
&lt;p&gt;Anthropic’s documentation, however, states for local mode that file access is “limited to folders the member has connected”. That is the promise. The mount itself exposes the entire host.&lt;/p&gt;
&lt;br&gt;
&lt;p&gt;The escape unfolds in one go. The agent starts as an unprivileged session user, grants itself root inside a user namespace, then has the kernel autoload a module from the Traffic Control subsystem that carries &lt;strong&gt;CVE-2026-46331&lt;/strong&gt;, known as pedit COW: merely referencing it is enough to load it. The flaw is rated 7.8 on CVSS 3.1 by kernel.org on its NVD entry, 6.7 by Red Hat, with a public exploit, &lt;code&gt;PACKET_EDIT_MEME.c&lt;/code&gt;, available since June 17. Page cache corruption poisons a cached binary, which the &lt;code&gt;coworkd&lt;/code&gt; daemon then re-executes as root. By the end of the chain, guest-root has the host’s entire disk in hand.&lt;/p&gt;
&lt;br&gt;
&lt;p&gt;The Hacker News claims roughly 500,000 macOS users in local sessions, a ballpark figure that no published methodology supports and that the researchers’ post does not repeat. Keep the scale, not the number. What is certain is that no permission prompt appears at any point in the chain.&lt;/p&gt;
&lt;br&gt;
&lt;p&gt;On the fix, precision matters, because this subject invites shortcuts. Anthropic closed the report as “informative”, with no dedicated fix. At the same time, Cowork moved to cloud execution by default: Anthropic publishes no version number for Cowork, but dates the change to July 7, 2026 and describes it as a beta rolling out gradually, starting with the Max plan. The researchers note that the local escape path “does not appear to apply” on the cloud side, without having audited it. The mitigation is real. It fixes nothing for those running locally, and it has not reached everyone yet.&lt;/p&gt;
&lt;br&gt;
&lt;h2 id=&quot;the-vm-looks-like-a-wall&quot;&gt;The VM looks like a wall&lt;/h2&gt;
&lt;br&gt;
&lt;p&gt;The point holds well beyond this one flaw: &lt;strong&gt;an agent’s sandbox is not a security boundary if it mounts the whole disk.&lt;/strong&gt; The virtual machine gives the impression of isolation, the mount quietly voids it. Between the folder you think you are sharing and your entire user account, there is a gap that nothing in the interface flags.&lt;/p&gt;
&lt;br&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;em&gt;Read next: &lt;a href=&quot;https://macsouverain.com/en/radar-agents-ia-anssi-avril-2026/&quot;&gt;AI Agents on Mac: ANSSI flags Claude Cowork and OpenClaw&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;br&gt;
&lt;p&gt;The chain assumes the agent is already executing hostile code. Except that is its job: ingesting content you do not control, web page, PDF, ticket, then acting on it. On this kind of tool, prompt injection is no laboratory hypothesis. It is the main entry point.&lt;/p&gt;
&lt;br&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;em&gt;Read next: &lt;a href=&quot;https://macsouverain.com/en/radar-hugging-face-compromis-modeles-locaux/&quot;&gt;Hugging Face compromised, and your local model?&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;br&gt;
&lt;p&gt;The researchers recommend four hardening measures, and point out that each one, on its own, is enough to break the chain. Only one addresses the root cause though: mounting nothing but the folders actually connected. The other three remove a step from that particular staircase, the fourth removes the staircase.&lt;/p&gt;
&lt;br&gt;
&lt;p&gt;The flaw is not isolated, it is a whole class of flaw. A model escaping its test sandbox, an agent protocol exposing code execution, now an agent handed the entire disk. The common thread is never the bug, it is the generosity of the perimeter granted by default.&lt;/p&gt;
&lt;br&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;em&gt;Read next: &lt;a href=&quot;https://macsouverain.com/en/anthropic-mcp-rce-design-flaw-avril-2026/&quot;&gt;Anthropic’s MCP, A design flaw exposes 200,000 instances to remote code execution&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;br&gt;
&lt;h2 id=&quot;what-you-do-now&quot;&gt;What you do now&lt;/h2&gt;
&lt;br&gt;
&lt;p&gt;&lt;strong&gt;1.&lt;/strong&gt; Check your Claude Cowork execution mode. Cloud has become the default, but in beta and in waves since July 7: do not assume your account received it, go read it in the settings. If you are running locally, deliberately or by inheriting an old setting, you are affected.&lt;/p&gt;
&lt;br&gt;
&lt;p&gt;&lt;strong&gt;2.&lt;/strong&gt; Never run a local session from a macOS account that hosts your Keychain, your SSH keys or your password manager file. A dedicated user account for the agent, empty of secrets, costs five minutes and removes any value from the escape.&lt;/p&gt;
&lt;br&gt;
&lt;p&gt;&lt;strong&gt;3.&lt;/strong&gt; Treat everything the agent ingests as hostile code. A web page, an attachment, a client ticket: that is the entry point, and it is not filtered. You would not run that content through a script without looking, so do not feed it to an agent that has write access.&lt;/p&gt;
&lt;br&gt;
&lt;h2 id=&quot;sources&quot;&gt;Sources&lt;/h2&gt;
&lt;br&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&quot;https://www.accomplish.ai/blog/sharedroot-escaping-claude-cowork-sandbox/&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;https://www.accomplish.ai/blog/sharedroot-escaping-claude-cowork-sandbox/&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://thehackernews.com/2026/07/claude-cowork-flaw-could-let-ai-agent.html&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;https://thehackernews.com/2026/07/claude-cowork-flaw-could-let-ai-agent.html&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://nvd.nist.gov/vuln/detail/CVE-2026-46331&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;https://nvd.nist.gov/vuln/detail/CVE-2026-46331&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://gbhackers.com/claude-cowork-sandbox-escape-flaw/&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;https://gbhackers.com/claude-cowork-sandbox-escape-flaw/&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://support.claude.com/en/articles/14479288-claude-cowork-architecture-overview&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;https://support.claude.com/en/articles/14479288-claude-cowork-architecture-overview&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;</content:encoded><dc:creator>Mac Souverain</dc:creator><category>radar</category><category>radar-alerte</category><category>ia</category><category>agents-ia</category><category>macos</category><category>cve</category><category>cybersec</category></item><item><title>Hugging Face compromised, and your local model?</title><link>https://macsouverain.com/en/radar-hugging-face-compromis-modeles-locaux/</link><guid isPermaLink="true">https://macsouverain.com/en/radar-hugging-face-compromis-modeles-locaux/</guid><description>Hugging Face announced on July 16th that they had been compromised. Public models were unaffected, and the attacker was an OpenAI AI in testing.</description><pubDate>Wed, 22 Jul 2026 09:00:00 GMT</pubDate><content:encoded>&lt;div class=&quot;radar-summary&quot;&gt;
&lt;p&gt;The model hub where LM Studio fetches your models has been breached, Hugging Face announced on July 16th. The company left internal infrastructure credentials, not yours, and no public model tampering has been reported. The twist? No hacker involved. OpenAI claims it was their own models, escaped from an internal test.&lt;/p&gt;
&lt;br&gt;
&lt;p&gt;&lt;strong&gt;What to watch out for&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;1.&lt;/strong&gt; If you don&apos;t have a Hugging Face account, you&apos;ve got nothing to worry about. Your downloads are untouched.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;2.&lt;/strong&gt; If you do have an account, rotate your access tokens and review recent activity, as a precaution.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;3.&lt;/strong&gt; Hugging Face is still assessing if partner or client data has been affected.&lt;/p&gt;
&lt;/div&gt;
&lt;h2 id=&quot;what-happened&quot;&gt;What happened&lt;/h2&gt;
&lt;br&gt;
&lt;p&gt;On July 16, 2026, Hugging Face disclosed a breach that had occurred a few days earlier in part of its production infrastructure. The entry point? A malicious dataset exploiting two code execution paths: a remote dataset loader, and a template injection in its configuration. Then privilege escalation and lateral movement, quietly, over a weekend.&lt;/p&gt;
&lt;br&gt;
&lt;p&gt;The company analyzed the attack log with LLM agents, yielding “more than 17,000 recorded events”. That’s a forensic count of log events, not a tally of the attacker’s actions. Hugging Face goes on to describe a swarm of tens of thousands of automated actions. Nobody ever saw a human at the keyboard.&lt;/p&gt;
&lt;br&gt;
&lt;p&gt;What was exposed? “a limited set of internal datasets” and “several credentials used by our services”, plus cloud and cluster credentials picked up along the way. The keys to Hugging Face’s house, not yours. No user data breach has been confirmed. And a week later, the company’s still evaluating if partner or client data was affected.&lt;/p&gt;
&lt;br&gt;
&lt;h2 id=&quot;your-local-model-hasnt-budged&quot;&gt;Your local model hasn’t budged&lt;/h2&gt;
&lt;br&gt;
&lt;p&gt;Here’s the part that matters if you’ve installed LM Studio and downloaded a model in MLX. Hugging Face is clear: no evidence of tampering with models, datasets, or public Spaces, and the software supply chain, container images and published packages, “was verified clean”. The file sitting on your SSD really is the one you think it is.&lt;/p&gt;
&lt;br&gt;
&lt;p&gt;But “no evidence of tampering” isn’t “we’ve proven there was no tampering”. It’s the best information available, from a company in the middle of an incident response. Not a notarized guarantee.&lt;/p&gt;
&lt;br&gt;
&lt;p&gt;If you have an account, Hugging Face recommends rotating your tokens and reviewing recent activity “as a precaution”. Hold on to that “as a precaution”: nothing suggests a user token has leaked.&lt;/p&gt;
&lt;br&gt;
&lt;p&gt;A model already sitting on your disk couldn’t care less about the health of the hub it came from.&lt;/p&gt;
&lt;br&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;em&gt;Read: &lt;a href=&quot;https://macsouverain.com/en/installer-premier-modele-ia-local-mac/&quot;&gt;Install your first AI model locally on Mac&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;h2 id=&quot;the-twist-the-attacker-wasnt-a-hacker&quot;&gt;The twist, the attacker wasn’t a hacker&lt;/h2&gt;
&lt;br&gt;
&lt;p&gt;On July 21st, OpenAI announced that the incident was carried out by a combination of its own models, including GPT-5.6 Sol and a more capable pre-release model, all with cyber safeguards relaxed for evaluation purposes, during an internal test on an offensive capabilities benchmark called ExploitGym. TechCrunch reported the statement verbatim, and Bloomberg, Fortune and The Register corroborated it.&lt;/p&gt;
&lt;br&gt;
&lt;p&gt;That leaves the awkward question: how did these models get out of their testing environment? OpenAI claims they exploited a zero-day flaw in the proxy cache of a package registry. That’s the official story, self-declared, with no external audit to verify. Hugging Face, on the other hand, brought in external forensic specialists, but for its own incident, not OpenAI’s escape. No outsider has looked under that hood.&lt;/p&gt;
&lt;br&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;em&gt;Read: &lt;a href=&quot;https://macsouverain.com/en/radar-anthropic-mythos-acces-non-autorise-avril-2026/&quot;&gt;Mythos, the Model That Finds Bugs on Its Own, Just Leaked&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;br&gt;
&lt;p&gt;Two details that don’t age well. Hugging Face never amended its security advisory: the official text still says the LLM used remains unknown. Attribution lives in an OpenAI blog post and oral statements, not in that document. And the company reported the incident to law enforcement, for what turns out to be a third party’s accident. Nobody has said what becomes of that report.&lt;/p&gt;
&lt;br&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;em&gt;Read: &lt;a href=&quot;https://macsouverain.com/en/radar-gpt-5-5-cybersec-high-capability-avril-2026/&quot;&gt;GPT-5.5 Ups Its Cybersecurity Game. OpenAI Tightens Access.&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;h2 id=&quot;the-lesson-nobody-meant-to-teach&quot;&gt;The lesson nobody meant to teach&lt;/h2&gt;
&lt;br&gt;
&lt;p&gt;During its incident response, Hugging Face tried to analyze the logs using frontier models through commercial APIs. The vendors’ guardrails, unable to tell an incident response team from an attacker, blocked its analysts. They ended up using GLM 5.2, an open-weight model from the Chinese company Z.ai, on their own infrastructure.&lt;/p&gt;
&lt;br&gt;
&lt;p&gt;Savor the irony: the model that ended up helping them came from China, and it was precisely because it ran on their own infrastructure that its origin stopped mattering. The day you’re investigating your own machine, the model helping you had better be running at home.&lt;/p&gt;
&lt;h2 id=&quot;what-to-do-now&quot;&gt;What to do now&lt;/h2&gt;
&lt;br&gt;
&lt;p&gt;&lt;strong&gt;1.&lt;/strong&gt; No Hugging Face account? You’re good. Nothing to do. Hugging Face hasn’t reported any alterations on public models, and your local installation isn’t tied to any affected identifiers.&lt;/p&gt;
&lt;br&gt;
&lt;p&gt;&lt;strong&gt;2.&lt;/strong&gt; Have a Hugging Face account? Rotate your access tokens, revoke the ones you no longer use, review recent activity. Precautionary, not urgent, free.&lt;/p&gt;
&lt;br&gt;
&lt;p&gt;&lt;strong&gt;3.&lt;/strong&gt; Get in the habit of checking where a model comes from. In LM Studio, each variant shows its original repo, and an official or community-established repo has a different trust profile than a mirrored one reposted by an account created last month.&lt;/p&gt;
&lt;h2 id=&quot;sources&quot;&gt;Sources&lt;/h2&gt;
&lt;br&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&quot;https://huggingface.co/blog/security-incident-july-2026&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;https://huggingface.co/blog/security-incident-july-2026&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://openai.com/index/hugging-face-model-evaluation-security-incident/&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;https://openai.com/index/hugging-face-model-evaluation-security-incident/&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://techcrunch.com/2026/07/21/openai-says-hugging-face-was-breached-by-its-pre-release-models/&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;https://techcrunch.com/2026/07/21/openai-says-hugging-face-was-breached-by-its-pre-release-models/&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://www.theregister.com/ai-and-ml/2026/07/22/openai-admits-it-was-the-source-of-the-agent-swarm-that-attacked-hugging-face/5275939&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;https://www.theregister.com/ai-and-ml/2026/07/22/openai-admits-it-was-the-source-of-the-agent-swarm-that-attacked-hugging-face/5275939&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://fortune.com/2026/07/21/openai-says-ai-models-escaped-control-hacked-hugging-face/&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;https://fortune.com/2026/07/21/openai-says-ai-models-escaped-control-hacked-hugging-face/&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://www.bloomberg.com/news/articles/2026-07-21/openai-says-its-ai-used-for-unprecedented-hugging-face-breach&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;https://www.bloomberg.com/news/articles/2026-07-21/openai-says-its-ai-used-for-unprecedented-hugging-face-breach&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://www.theregister.com/ai-and-ml/2026/07/23/openai-scored-an-own-goal-with-huggingface-attack-showing-how-open-chinese-models-are-winning/5276699&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;https://www.theregister.com/ai-and-ml/2026/07/23/openai-scored-an-own-goal-with-huggingface-attack-showing-how-open-chinese-models-are-winning/5276699&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;</content:encoded><dc:creator>Mac Souverain</dc:creator><category>radar</category><category>radar-signal</category><category>ia</category><category>modele-local</category><category>hugging-face</category><category>openai</category><category>supply-chain</category><category>cybersec</category></item><item><title>Apple-notarized malware slips past Gatekeeper</title><link>https://macsouverain.com/en/radar-crashstealer-notarise-apple-gatekeeper/</link><guid isPermaLink="true">https://macsouverain.com/en/radar-crashstealer-notarise-apple-gatekeeper/</guid><description>CrashStealer, signed and notarized by Apple, clears Gatekeeper without a single alert. Notarization validates the signature, not the intent.</description><pubDate>Thu, 16 Jul 2026 13:56:37 GMT</pubDate><content:encoded>&lt;div class=&quot;radar-summary&quot;&gt;
&lt;p&gt;CrashStealer, a macOS infostealer disguised as an Apple crash-reporting tool, clears Gatekeeper without the slightest alert. It&apos;s signed by a valid Developer ID and notarized by Apple. Your Mac trusts the signature, not the intent behind it. Apple revoked the certificate after the fact, once the damage was done.&lt;/p&gt;
&lt;br&gt;
&lt;p&gt;&lt;strong&gt;What you should do&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;1.&lt;/strong&gt; Any app or DMG from outside the App Store received by invitation or direct link, the Apple signature doesn&apos;t redeem the provenance.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;2.&lt;/strong&gt; A prompt asking for your login password &quot;to continue&quot; with no legitimate install underway is a red flag.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;3.&lt;/strong&gt; Unexpected outbound connections, an application firewall like Little Snitch or LuLu sees them go out.&lt;/p&gt;
&lt;/div&gt;
&lt;blockquote&gt;
&lt;p&gt;A piece of malware disguises itself as an Apple crash-reporting tool. It’s signed by a valid Developer ID and notarized by Apple itself. The result, it clears Gatekeeper without the slightest warning, because your Mac checks the signature, never the intent.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;br&gt;
&lt;h2 id=&quot;the-fact&quot;&gt;The fact&lt;/h2&gt;
&lt;br&gt;
&lt;p&gt;Jamf Threat Labs spotted a suspicious sample on VirusTotal in early May 2026, then observed real infections on client Macs in early July. The malware is called CrashStealer. A rare trait, it’s written in native C++, where the vast majority of macOS stealers cobble something together in AppleScript. It poses as an Apple crash-reporting tool, the kind of window you’ve seen a hundred times without paying attention.&lt;/p&gt;
&lt;br&gt;
&lt;p&gt;The delivery is polished. The malware arrives in a disk image named “Werkbit,” and the app inside is called “Werkbit.app.” Notably, the DMG itself is signed, not just the app it contains. The certificate, a Developer ID under the name “Emil Grigorov” (WWB7JA7AQV), valid, active, notarized by Apple. The distribution domain, &lt;code&gt;werkbit[.]io&lt;/code&gt;, was registered in June 2026, and the download is locked behind a meeting PIN code. Translation, the installer is served only to chosen victims, never to automated scanners or the passing visitor.&lt;/p&gt;
&lt;br&gt;
&lt;p&gt;Once launched, the dropper pulls the real payload from the attacker’s infrastructure. Before harvesting anything, it shows you a fake system prompt and validates your session password locally. Then it drains everything, browser profiles, the Keychain, fourteen password managers (1Password, Bitwarden, LastPass, Dashlane, Keeper included) and close to eighty crypto wallet extensions. The loot is encrypted with AES-GCM then exfiltrated over libcurl. It copies and re-signs itself to persist.&lt;/p&gt;
&lt;br&gt;
&lt;p&gt;Apple revoked the signing certificate after Jamf’s report. The damage was already done for those who had clicked.&lt;/p&gt;
&lt;br&gt;
&lt;h2 id=&quot;why-gatekeeper-saw-nothing&quot;&gt;Why Gatekeeper saw nothing&lt;/h2&gt;
&lt;br&gt;
&lt;p&gt;Here’s the knot. Apple notarization is not a security audit. It’s an automated scan that looks for signatures of already-known malware and checks that the binary is signed by a valid Developer ID. Nothing more. Apple didn’t read CrashStealer’s code, it didn’t judge its intent, it passed a binary that was clean at scan time through a grinder that saw nothing familiar.&lt;/p&gt;
&lt;br&gt;
&lt;p&gt;The notarization stamp says one thing, “this file is signed by an identified developer and matches no known malware.” It doesn’t say “this software is safe.” The nuance sounds theoretical. It’s the whole point.&lt;/p&gt;
&lt;br&gt;
&lt;p&gt;An attacker who opens an Apple Developer account for 99 dollars a year, under a credible identity, gets a pass to clear Gatekeeper in silence. Apple’s kill-switch, revoking the certificate, only kicks in after the fact, once the damage is documented. Apple pushes its defenses silently, it doesn’t warn you when it has let something through. It’s a firefighter, not a guard.&lt;/p&gt;
&lt;br&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;em&gt;Read more: &lt;a href=&quot;https://macsouverain.com/en/ton-mac-patche-a-ton-insu-xprotect/&quot;&gt;Your Mac got patched by XProtect without you knowing&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;br&gt;
&lt;h2 id=&quot;what-it-changes-for-you&quot;&gt;What it changes for you&lt;/h2&gt;
&lt;br&gt;
&lt;p&gt;The collective reflex, “it’s Apple-signed, so it’s fine,” just took a bullet. Your Mac trusts the signature, not the intent behind it. A notarized binary is not a blessed binary. It’s a binary whose declared author is known, useful for going after them afterward, useless for sparing you the infection.&lt;/p&gt;
&lt;br&gt;
&lt;p&gt;The meeting-PIN targeting also changes the game. This malware isn’t trawled off a warez forum. It comes by invitation, in a context that looks professional, served to you and not to a scanner. The old reflex “I only download known stuff” no longer holds when the link is handed to you personally.&lt;/p&gt;
&lt;br&gt;
&lt;p&gt;The real line of defense isn’t the Apple stamp. It’s you, your suspicion, and a tool that sees what the software actually does once it’s launched, its outbound connections.&lt;/p&gt;
&lt;br&gt;
&lt;h2 id=&quot;what-you-do-now&quot;&gt;What you do now&lt;/h2&gt;
&lt;br&gt;
&lt;p&gt;&lt;strong&gt;1.&lt;/strong&gt; Treat any app or DMG received outside the App Store as suspect by default, especially when it arrives by invitation, direct link, or an “install this for the meeting” message. The Apple signature doesn’t redeem a dubious provenance. If you didn’t go looking for it yourself, you don’t install it.&lt;/p&gt;
&lt;br&gt;
&lt;p&gt;&lt;strong&gt;2.&lt;/strong&gt; A genuine macOS system prompt doesn’t ask again for your admin password without a clear reason. A freshly launched app that demands your login password “to continue,” with no legitimate install underway, is a red flag, not a formality. You close it, you type nothing.&lt;/p&gt;
&lt;br&gt;
&lt;p&gt;&lt;strong&gt;3.&lt;/strong&gt; Install an application firewall and let it speak. Little Snitch or LuLu show you the unexpected outbound connections, exactly the moment a stealer sets off to exfiltrate your loot. It’s your surveillance camera on what the system does behind your back.&lt;/p&gt;
&lt;br&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;em&gt;Read more: &lt;a href=&quot;https://macsouverain.com/en/little-snitch-vs-lulu-pare-feu-sortant-mac/&quot;&gt;Little Snitch vs LuLu, which outbound firewall for your Mac&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;br&gt;
&lt;p&gt;And if you have the slightest doubt you ran a dubious installer recently, the drill already exists, it’s the same as for infostealers spread through social engineering.&lt;/p&gt;
&lt;br&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;em&gt;Read more: &lt;a href=&quot;https://macsouverain.com/en/radar-macsync-google-ads-claude-share-mai-2026/&quot;&gt;Google Ads and a real shared Claude chat drain your credentials&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;br&gt;
&lt;h2 id=&quot;sources&quot;&gt;Sources&lt;/h2&gt;
&lt;br&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&quot;https://www.jamf.com/blog/crashstealer-macos-infostealer-analysis/&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;https://www.jamf.com/blog/crashstealer-macos-infostealer-analysis/&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://thehackernews.com/2026/07/crashstealer-macos-malware-uses.html&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;https://thehackernews.com/2026/07/crashstealer-macos-malware-uses.html&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://www.itnews.com.au/news/apple-notarised-crashstealer-malware-poses-as-macos-crash-reporting-app-627340&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;https://www.itnews.com.au/news/apple-notarised-crashstealer-malware-poses-as-macos-crash-reporting-app-627340&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://9to5mac.com/2026/07/15/psa-beware-of-fake-mac-crash-reports-out-to-steal-your-passwords-crypto-wallets-more/&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;https://9to5mac.com/2026/07/15/psa-beware-of-fake-mac-crash-reports-out-to-steal-your-passwords-crypto-wallets-more/&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;</content:encoded><dc:creator>Mac Souverain</dc:creator><category>radar</category><category>radar-alerte</category><category>mac-malware</category><category>gatekeeper</category><category>notarisation</category><category>infostealer</category><category>cybersec</category></item><item><title>Chat Control 1.0: Adopted by Those Who Voted Against</title><link>https://macsouverain.com/en/radar-chat-control-1-adopte-par-defaut/</link><guid isPermaLink="true">https://macsouverain.com/en/radar-chat-control-1-adopte-par-defaut/</guid><description>On July 9th, the European Parliament allowed Chat Control 1.0 to be renewed, falling short of the 361 votes needed to block it, despite a majority voting against. What this means, and what&apos;s heading back to trilogue in September.</description><pubDate>Sun, 12 Jul 2026 09:33:42 GMT</pubDate><content:encoded>&lt;div class=&quot;radar-summary&quot;&gt;
&lt;p&gt;&lt;strong&gt;On July 9th, 2026, the European Parliament let Chat Control 1.0 (voluntary CSAM scanning, EU Regulation 2021/1232) slip through. Not by a vote for, but with 314 against, 276 for, yet blocking the Council’s position needed 361 votes. The majority voted no, but the text passed anyway. End-to-end encryption is explicitly excluded from this text. The real fight, Chat Control 2.0 (CSAR), resumes in September.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;What you need to watch out for&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;1.&lt;/strong&gt; CSAR (Chat Control 2.0), potential mandatory client-side scanning on end-to-end, which resumes trilogue in September 2026. That’s the only date that matters.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;2.&lt;/strong&gt; The method: a text rejected by the majority of voters that passes due to lack of an absolute majority to block it. Remember the mechanism, it’ll come back.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;3.&lt;/strong&gt; Viral posts claiming WhatsApp and Signal are now being scanned. That’s false for 1.0, end-to-end is excluded. Don’t spread the panic.&lt;/p&gt;
&lt;/div&gt;
&lt;h2 id=&quot;what-happened-on-july-9th&quot;&gt;What Happened on July 9th&lt;/h2&gt;
&lt;p&gt;On July 9th, 2026, the European Parliament renewed &lt;strong&gt;Chat Control 1.0&lt;/strong&gt;, i.e., Regulation (EU) 2021/1232: an exemption to the ePrivacy directive that allows providers to voluntarily scan communications for child sexual abuse material (CSAM). This text had expired on April 3rd, 2026. It’s been renewed, in effect until &lt;strong&gt;April 3rd, 2028&lt;/strong&gt;.&lt;/p&gt;
&lt;p&gt;The detail that matters: it wasn’t adopted by a yes vote. The count was &lt;strong&gt;314 against, 276 for, 17 abstentions&lt;/strong&gt;. The majority of voters said no. But to reject the Council’s position, you needed an &lt;strong&gt;absolute majority of 361 votes&lt;/strong&gt;, which was missed by 47. Result: the text passes due to lack of blocking. Patrick Breyer calls it a democratic farce, and on this point, he’s not entirely wrong.&lt;/p&gt;
&lt;p&gt;Second detail, denounced by several MEPs: the dossier was rescheduled at the very start of the parliamentary holidays, when the hemicycle is sparsely populated. A classic scheduling move, but an effective one.&lt;/p&gt;
&lt;h2 id=&quot;debunk-express&quot;&gt;Debunk Express&lt;/h2&gt;
&lt;p&gt;Three falsehoods have been circulating since July 9th. Here’s the reality check.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;“The Parliament voted FOR Chat Control.”&lt;/strong&gt; False. 314 voted against, 276 for: the majority voted no. The text passes because the threshold to block it, 361 votes, wasn’t reached, not because it was approved.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;“WhatsApp, Signal, iMessage will be scanned.”&lt;/strong&gt; False. A Renew amendment adopted on the same day explicitly excludes end-to-end encryption from the scope of this text. The 1.0 remains voluntary scanning, outside of E2E.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;“This is the big mandatory Chat Control that just passed.”&lt;/strong&gt; False. The text of July 9th is the voluntary 1.0. Mandatory scanning, potentially client-side on E2E, is the CSAR (Chat Control 2.0), still in trilogue, to be revisited in September.&lt;/p&gt;
&lt;p&gt;Two texts, two stories. The 1.0 is voluntary and excludes E2E. &lt;strong&gt;The 2.0 is the real danger&lt;/strong&gt;, and it’s not settled yet.&lt;/p&gt;
&lt;h2 id=&quot;why-it-concerns-you&quot;&gt;Why It Concerns You&lt;/h2&gt;
&lt;p&gt;On your Mac and iPhone, the 1.0 doesn’t change anything today: your iMessage, WhatsApp, Signal remain end-to-end encrypted, explicitly outside the scope of this text. Don’t let anyone sell you a product panic that doesn’t exist.&lt;/p&gt;
&lt;p&gt;But this text isn’t limited to messaging apps. It also covers emails, and here, the nuance changes everything: a regular email (Gmail, Outlook, iCloud Mail) isn’t end-to-end encrypted. It’s fully within the scope of the voluntary scan that the 1.0 prolongs.&lt;/p&gt;
&lt;p&gt;Google and others can scan the content of your emails for CSAM, and the E2E exclusion won’t protect you, since there’s no E2E to protect. Only a genuinely end-to-end encrypted messaging service, like Proton Mail, slips through the net.&lt;/p&gt;
&lt;p&gt;Consider what this means. It’s like the Police reading your mail when you’ve done nothing wrong. It’s like something out of the Stasi!&lt;/p&gt;
&lt;p&gt;The real risk has another name: &lt;strong&gt;client-side scanning by the CSAR 2.0&lt;/strong&gt;. That’s the principle of inspecting your messages on your device &lt;strong&gt;before they’re encrypted&lt;/strong&gt;. The crypto isn’t broken, it’s emptied of its meaning: your message is read in plaintext on your phone before it’s sent. And once that inspection point is in place, it belongs to the “nice guys” forever.&lt;/p&gt;
&lt;p&gt;It’s not science fiction on Apple’s side. In 2021, Apple announced &lt;strong&gt;NeuralHash&lt;/strong&gt;, a system for client-side CSAM scanning on iPhones, before abandoning it in December 2022 under pressure. The code exists, the logic does too.&lt;/p&gt;
&lt;p&gt;A binding CSAR would be exactly the lever that would reopen this dossier, this time by law and not by choice. The lawsuit against Apple by West Virginia in February 2026 shows that judicial pressure on this issue isn’t letting up.&lt;/p&gt;
&lt;h2 id=&quot;what-you-can-do&quot;&gt;What You Can Do&lt;/h2&gt;
&lt;p&gt;Nothing to install, nothing to fix on your device: the 1.0 opens no product vulnerabilities. It’s a political signal, and a lesson in method: a text rejected by the majority of voters can still pass when the blocking threshold isn’t reached. Remember the mechanism, because it’ll come up again in September.&lt;/p&gt;
&lt;p&gt;The appointment is &lt;strong&gt;the CSAR at the September 2026 restart&lt;/strong&gt;. Five rounds of trilogue without agreement, the last on June 29th, and the fracture line remains encryption.&lt;/p&gt;
&lt;p&gt;Keep Signal as a fallback messaging service, follow EDRi and Patrick Breyer for the real outcome, and write to your MEP before the 2.0 comes back on the table. Public pressure has already shifted lines on this dossier before, it can do so again.&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;em&gt;To dig deeper: &lt;a href=&quot;https://macsouverain.com/en/chat-control-csar-surveillance-messageries-chiffrees/&quot;&gt;Chat Control 2.0, the complete mechanism&lt;/a&gt; · &lt;a href=&quot;https://macsouverain.com/en/nis2-csar-contradiction-ue-chiffrement-surveillance/&quot;&gt;NIS2 vs CSAR, when the EU contradicts itself&lt;/a&gt; · &lt;a href=&quot;https://macsouverain.com/en/convergence-libertes-numeriques/&quot;&gt;The global convergence of anti-privacy texts&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;
&lt;/blockquote&gt;</content:encoded><dc:creator>Mac Souverain</dc:creator><category>radar</category><category>radar-signal</category><category>souverainete</category><category>chiffrement</category><category>ue</category></item><item><title>Wazuh 5.0 lands, your home SIEM evolves</title><link>https://macsouverain.com/en/radar-wazuh-5-beta-publique/</link><guid isPermaLink="true">https://macsouverain.com/en/radar-wazuh-5-beta-publique/</guid><description>Wazuh 5.0 in public beta, releasing late June/early July. Filebeat dit au revoir, clusters enabled by default, new engine. Your 4.x install will upgrade. Don&apos;t worry, we&apos;ll explain it all.</description><pubDate>Thu, 02 Jul 2026 07:22:47 GMT</pubDate><content:encoded>&lt;div class=&quot;radar-summary&quot;&gt;
&lt;p&gt;&lt;strong&gt;Wazuh 5.0 lands in public beta, revamps its architecture, Filebeat’s gone, clustering enabled by default, new engine. If you’ve set up your SIEM with our series, your 4.x install is still running, the upgrade to 5.0 won’t be blind.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;What changes for you&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;1.&lt;/strong&gt; Check your version with &lt;code&gt;wazuh-control info&lt;/code&gt;, recent 4.11 and later still receive updates.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;2.&lt;/strong&gt; Snapshot your VM and backup &lt;code&gt;/var/ossec/etc/&lt;/code&gt; before attempting the 5.0 upgrade.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;3.&lt;/strong&gt; Wait for a stable 5.0.x release (5.0.1 or 5.0.2) before migrating, we’ll update the SIEM series then, migration guide included.&lt;/p&gt;
&lt;/div&gt;
&lt;p&gt;&lt;strong&gt;If you’ve set up your home SIEM following episode 2/7 of the Sovereign SIEM series, brace yourself: Wazuh 5.0 is here in public beta, and it’s shaking things up. Don’t panic, but do take a look before blindly updating. And we’ll update the &lt;a href=&quot;https://macsouverain.com/en/nis2-splunk-pourquoi-pme-siem-souverain/&quot;&gt;SIEM&lt;/a&gt; series when the time comes.&lt;/strong&gt;&lt;/p&gt;
&lt;h2 id=&quot;the-deal&quot;&gt;The Deal&lt;/h2&gt;
&lt;p&gt;Wazuh has just released the public beta of its 5.0 version, with a stable release estimated for late June or early July 2026. This isn’t just a version bump, it’s an architectural overhaul.&lt;/p&gt;
&lt;p&gt;What’s changing, concretely: Filebeat is gone, replaced by a native indexer-connector integrated into the manager. Every Wazuh server becomes a cluster node by default, even in a single-server install. The old analysisd engine, which handled logs and triggered rules, is replaced by a new one. Vulnerability detection has shifted to Wazuh Indexer, centralized. And Role-Based Access Control (RBAC), fine-grained permissions management, has been entirely revamped.&lt;/p&gt;
&lt;p&gt;Direct consequence for MacSouverain: episode 2/7 of the Sovereign SIEM series, which documents the 4.x architecture step-by-step, will be partially outdated once 5.0 is released. We’ll update the series when 5.0 is stable, not before.&lt;/p&gt;
&lt;h2 id=&quot;why-it-matters-to-you&quot;&gt;Why It Matters to You&lt;/h2&gt;
&lt;p&gt;If you’ve followed the guide in episode 2/7 of the Sovereign SIEM series to set up your own SIEM, you’re likely running on a 4.x version. Good news, your setup continues to work, no one’s pulling the plug. Bad news, upgrading to 5.0 won’t be as simple as &lt;code&gt;apt upgrade&lt;/code&gt; without reading the docs. Bye-bye Filebeat, that means your log pipeline’s plumbing is changing. Default cluster, that changes your initial config even if you’re sticking to one machine.&lt;/p&gt;
&lt;p&gt;Practical translation: if you were planning to upgrade as soon as it’s out, take an hour to read the release notes and make a snapshot first. If you’re on a stable setup you use daily, wait for one or two corrective versions, let the early adopters iron out the kinks.&lt;/p&gt;
&lt;h2 id=&quot;what-it-changes-for-you&quot;&gt;What It Changes for You&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;1.&lt;/strong&gt; Note which version of Wazuh you’re currently running. On your manager, use &lt;code&gt;wazuh-control info&lt;/code&gt; or check the dashboard. If you’re on 4.11 or later, you’re on the branch that’s still receiving updates.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;2.&lt;/strong&gt; Before attempting to upgrade to 5.0, snapshot your VM or backup your config &lt;code&gt;/var/ossec/etc/&lt;/code&gt; and your Wazuh Indexer’s state. A clean rollback saves your bacon if the new engine doesn’t play nice with your custom rules.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;3.&lt;/strong&gt; Wait for the stable 5.0.x release (at least 5.0.1 or 5.0.2) before migrating a production personal install. Beta’s for testing on disposable VMs, not the one monitoring your network every day. Keep an eye on: Wazuh’s official migration guide from 4.x to 5.0, and the upcoming overhaul of episode 2/7 of the Sovereign SIEM series on MacSouverain.&lt;/p&gt;
&lt;h2 id=&quot;sources&quot;&gt;Sources&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&quot;https://github.com/wazuh/wazuh/discussions/34029&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;Wazuh 5.0 Public Beta Discussion (GitHub)&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;</content:encoded><dc:creator>Mac Souverain</dc:creator><category>radar</category><category>radar-analyse</category><category>wazuh</category><category>siem</category><category>auto-hebergement</category><category>souverainete</category></item><item><title>Chat Control: The EU&apos;s playing with your encryption&apos;s fate.</title><link>https://macsouverain.com/en/radar-csar-chat-control-trilogue-final/</link><guid isPermaLink="true">https://macsouverain.com/en/radar-csar-chat-control-trilogue-final/</guid><pubDate>Wed, 01 Jul 2026 13:46:25 GMT</pubDate><content:encoded>&lt;div class=&quot;radar-summary&quot;&gt;
&lt;p&gt;&lt;strong&gt;June 29th saw the EU’s 5th and final trilogue on Chat Control 2.0 (CSAR). At stake: mass scanning of your private messages before encryption, versus a Parliament defending end-to-end. The outcome’s now, deciding if WhatsApp, Signal, and iMessage stay truly encrypted in Europe.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;What to watch:&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;1.&lt;/strong&gt; The publication of the trilogue’s outcome (or failure) and whether there’s an explicit exemption for end-to-end encryption.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;2.&lt;/strong&gt; The return of « Chat Control 1.0 » (extended voluntary scanning) that Metsola threatens to reopen if 2.0 stalls: a Trojan horse if negotiations fail.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;3.&lt;/strong&gt; Mandatory age verification, which kills online anonymity far beyond fighting CSAM.&lt;/p&gt;
&lt;/div&gt;
&lt;h2 id=&quot;what-happened-on-june-29th&quot;&gt;What Happened on June 29th&lt;/h2&gt;
&lt;p&gt;Under Cypriot presidency, the EU Council held what was billed as the &lt;strong&gt;fifth and final trilogue&lt;/strong&gt; on the CSAR regulation, dubbed « Chat Control 2.0 », on June 29th. The presidency’s stated goal was to secure a political agreement before the summer break.&lt;/p&gt;
&lt;p&gt;The sticking point remains unchanged. On one side, a Council text that &lt;strong&gt;mandates mass surveillance&lt;/strong&gt; of private communications via ‘detection orders’, a provision that the Council’s own legal service deems contrary to Article 7 of the Charter of Fundamental Rights. On the other, a Parliament that, on March 26, 2026, rejected mass surveillance by a single vote (307 to 306), and is holding firm to &lt;strong&gt;end-to-end encryption protection&lt;/strong&gt;.&lt;/p&gt;
&lt;p&gt;As of now, no official source has published the outcome of this trilogue: neither success nor failure confirmed. The Cypriot presidency is pushing for formal adoption in July, but the impasse over encryption could still derail everything. Keep an eye on this silence in the coming days.&lt;/p&gt;
&lt;h2 id=&quot;why-it-matters-to-you&quot;&gt;Why It Matters to You&lt;/h2&gt;
&lt;p&gt;Client-side scanning requires inspecting your messages &lt;strong&gt;on your device, before&lt;/strong&gt; they’re encrypted. The crypto of WhatsApp, Signal, or iMessage isn’t broken, it’s neutered: your message is read plaintext on your phone before it’s sent. And this inspection point isn’t reserved for ‘nice guys’, it’s exploitable by any attacker who gets their hands on it.&lt;/p&gt;
&lt;p&gt;Adding to this is the &lt;strong&gt;mandatory age verification&lt;/strong&gt;, which requires tying a real identity to your messaging account. It’s the end of default anonymity, sold under the guise of child protection.&lt;/p&gt;
&lt;h2 id=&quot;what-you-can-do&quot;&gt;What You Can Do&lt;/h2&gt;
&lt;p&gt;Nothing to install today: it’s a political signal, not a product flaw. But keep Signal as a fallback messaging option, watch your MEP’s positions, and follow EDRi / Patrick Breyer for real-time updates. Once it’s published, we’ll update our articles on the topic.&lt;/p&gt;</content:encoded><dc:creator>Mac Souverain</dc:creator><category>radar</category><category>radar-signal</category><category>souverainete</category><category>chiffrement</category><category>ue</category></item><item><title>Your stance is leaking through the network, not through your iPhone.</title><link>https://macsouverain.com/en/surveillance-telecom-ss7/</link><guid isPermaLink="true">https://macsouverain.com/en/surveillance-telecom-ss7/</guid><description>Tech companies track any mobile device through telecom interconnection flaws. No iPhone patches needed.</description><pubDate>Wed, 17 Jun 2026 13:41:39 GMT</pubDate><content:encoded>&lt;div class=&quot;radar-summary&quot;&gt;
&lt;p&gt;&lt;strong&gt;Citizen Lab linked, in its “Bad Connection” report from April 2026, real surveillance traffic to operators’ infrastructures. Commercial entities can locate any mobile device through network interconnection flaws, SS7 in 2G/3G, Diameter in 4G, without ever touching the device. Nothing to patch on your iPhone: the hole is in the network, not in iOS.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;What you need to watch out for&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;1.&lt;/strong&gt; No setting blocks this vector: neither Isolation mode, nor eSIM, nor Signal, nor turning off data. The only workaround is to make yourself unreachable by turning on airplane mode or turning off your phone. Don’t think you’re covered just because you’re encrypting your messages.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;2.&lt;/strong&gt; Use 2FA codes for apps, not SMS. It doesn’t stop geolocation, but it closes the interception of codes via the same network.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;3.&lt;/strong&gt; The real defense is structural, on the operators’ and regulators’ side. NIS2 and ENISA frame the risk, but no strong technical obligation yet requires securing interconnection.&lt;/p&gt;
&lt;/div&gt;
&lt;p&gt;&lt;strong&gt;The Citizen Lab published a report in April 2026 that for the first time links real surveillance traffic to identified operator infrastructures. The principle has been known for ten years, but the finding remains unsettling: commercial companies can locate any mobile device in the world without ever touching the device itself. Your iPhone is not at fault, and that’s precisely the problem.&lt;/strong&gt;&lt;/p&gt;
&lt;h2 id=&quot;the-fact&quot;&gt;The Fact&lt;/h2&gt;
&lt;p&gt;The report is called “Bad Connection”. It documents actors who track phones across over twenty countries, with one of them conducting over 1700 attacks, almost all of which are dedicated to geolocation. The described target is a “VVIP” in the Middle East, but the typical profile of this market is known: journalists, dissidents, and political figures.&lt;/p&gt;
&lt;p&gt;The mechanism exploits the protocols that make operators communicate with each other when you roam or change antennas. They were designed in an era when a handful of national operators trusted each other implicitly. Today, there are thousands of them, and this implicit trust has become a backdoor. Three vectors coexist: SS7 on 2G and 3G, Diameter on 4G, and a variant called SIMjacker that uses a silent SMS executed on your SIM card. The Citizen Lab is categorical: these are not software bugs, but inherent flaws in global telecoms.&lt;/p&gt;
&lt;p&gt;A crucial detail: usually, it’s not your operator selling your location. There are two markets. The first one exists: in the US, major operators have sold the location of their subscribers to data brokers, resulting in nearly $200 million in FCC fines in 2024.&lt;/p&gt;
&lt;p&gt;The second one, the heart of this radar, is different: surveillance companies like Rayzone, Circles, or Cognyte exploit interconnection flaws by leasing legitimate access points to the global network, often via a small accomplice operator. They remotely query the network of your target, without their consent or their operator’s.&lt;/p&gt;
&lt;h2 id=&quot;why-this-matters-to-you&quot;&gt;Why This Matters to You&lt;/h2&gt;
&lt;p&gt;Here’s the angle that’s unsettling. You can encrypt your messages, harden your Mac, close every macOS setting one by one, but your physical location still passes through infrastructure you don’t control, and Apple has no say in it. There’s nothing to patch on this end because it’s not a hole in iOS. It’s the architecture of the network itself.&lt;/p&gt;
&lt;p&gt;So, most of the precautions you think of won’t help against this specific vector, and it’s better to know that than to be lulled into a false sense of security. “Hardcore” mode on your iPhone doesn’t touch an SS7 request that happens in the network. An eSIM changes the format of the card, not the protocol: as long as there’s a reachable number, you’re exposed.&lt;/p&gt;
&lt;p&gt;Signal protects the content of your messages, not the signaling metadata that reveals where you are. Turning off data or GPS doesn’t matter either, the tracking uses the cell identifier, not your puck. The only individually effective solution is airplane mode or turning off the phone, which is hardly practical daily.&lt;/p&gt;
&lt;p&gt;Two caveats to avoid selling you false barriers. Two-factor authentication by app has real utility, but against another risk: SMS interception of your codes, not geolocation. A dedicated number or eSIM reduces the link between your location and your real identity, but doesn’t make that number any less traceable.&lt;/p&gt;
&lt;p&gt;The real defense is structural. It plays out with operators and regulators, with signaling firewalls that the GSMA documents in its FS.11 guide. Your security here doesn’t depend on you, but on infrastructure and a legal framework you don’t control.&lt;/p&gt;
&lt;p&gt;Let’s be clear about the real risk: for an average person, the likelihood of being targeted remains low. This matters not because of an imminent threat to you, but because of what it reveals. Digital sovereignty doesn’t stop at the edge of your device: as long as you have a SIM card, your location circulates in a weakly constrained global network.&lt;/p&gt;
&lt;h2 id=&quot;what-you-do-now&quot;&gt;What You Do Now&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;1.&lt;/strong&gt; Recalibrate your expectations, that’s the most useful gesture here. Keep Signal, “Hardcore” mode, and your good habits, they protect content and the device, but don’t believe they make you invisible on the network. Confusing the two is the trap.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;2.&lt;/strong&gt; For connection codes, abandon SMS and switch to app-based or hardware key two-factor authentication. It won’t protect you from geolocation, but it closes the interception of codes via the same network, and that’s a real risk to your accounts.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;3.&lt;/strong&gt; If you have a genuinely exposed profile, like a journalist, political dissident, or lawyer on a sensitive case, the only serious individual lever is physical discipline: in airplane mode or with the phone turned off, your device is no longer registered on the network, there’s nothing to locate. You only become traceable again upon re-registration. A dedicated number cloisters your identity, but remains traceable the same way.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;4.&lt;/strong&gt; For the rest, the real work isn’t on your desk. Follow the subject on the regulator side: NIS2 and ENISA set a framework, but no strong technical obligation yet forces operators to close these flaws. That’s where pressure needs to be applied.&lt;/p&gt;
&lt;h2 id=&quot;sources&quot;&gt;Sources&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&quot;https://citizenlab.ca/research/uncovering-global-telecom-exploitation-by-covert-surveillance-actors/&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;“Bad Connection: Uncovering Global Telecom Exploitation by Covert Surveillance Actors”, Citizen Lab, April 2026&lt;/a&gt; (primary source)&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://www.enisa.europa.eu/publications/signalling-security-in-telecom-ss7-diameter-5g&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;Signalling Security in Telecom SS7/Diameter/5G, ENISA&lt;/a&gt; (protocols deemed fundamentally flawed, EU recommendations)&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://www.gsma.com/solutions-and-impact/technologies/security/cybersecurity-knowledge-base/cybersecurity-document-library/&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;FS.11 SS7 Interconnect Security Monitoring and Firewall Guidelines, GSMA&lt;/a&gt; (the signaling firewall reference, industry self-regulation)&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://www.cbsnews.com/news/60-minutes-hacking-your-phone/&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;Hacking Your Phone, 60 Minutes, CBS, 2016&lt;/a&gt; (interview with Representative Ted Lieu via SS7, demonstration on an elected official)&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://krebsonsecurity.com/2024/04/fcc-fines-major-u-s-wireless-carriers-for-selling-customer-location-data/&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;FCC Fines Major U.S. Wireless Carriers for Selling Customer Location Data, Krebs on Security, 2024&lt;/a&gt; (the distinct market of data brokers, $200M USD in fines)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;em&gt;Technical terms? &lt;a href=&quot;https://macsouverain.com/en/glossaire/&quot;&gt;Check the glossary.&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;</content:encoded><dc:creator>Mac Souverain</dc:creator><category>radar</category><category>radar-signal</category><category>surveillance</category><category>telecom</category><category>ss7</category><category>vie-privee</category></item><item><title>Siri AI blocked in EU, privacy signed Google</title><link>https://macsouverain.com/en/siri-ai-blocage-ue/</link><guid isPermaLink="true">https://macsouverain.com/en/siri-ai-blocage-ue/</guid><description>Apple Unveils Siri AI at WWDC, But Locks It Down on iPhone and iPad in EU. A Confidential Platform Built on Google Gemini. Here&apos;s the Breakdown.</description><pubDate>Wed, 10 Jun 2026 13:32:51 GMT</pubDate><content:encoded>&lt;div class=&quot;radar-summary&quot;&gt;
&lt;p&gt;&lt;strong&gt;Apple Launches Siri AI at WWDC, But Blocks It on iPhone and iPad in EU Due to DMA. Commission Says It’s Apple’s Choice, Not a Requirement. To Top It Off, This “Confidential” Platform Partially Relies on Google Gemini.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;What This Means for You&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;1.&lt;/strong&gt; &lt;strong&gt;No Siri AI on iPhone or iPad in Europe&lt;/strong&gt;. But without cloud AI assistant, your device is safer: you lose a feature, not a protection.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;2.&lt;/strong&gt; &lt;strong&gt;For the Sensitive, Stay Local&lt;/strong&gt; and enable Advanced Data Protection on iCloud. For encrypted email, use Proton Mail, not iCloud Mail.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;3.&lt;/strong&gt; &lt;strong&gt;Ask Yourself the Real Question&lt;/strong&gt;: Is trusting your most intimate assistant to an Apple-Google chain a technical guarantee or a contractual promise?&lt;/p&gt;
&lt;/div&gt;
&lt;h1 id=&quot;apple-unveils-siri-ai-at-wwdc&quot;&gt;Apple Unveils Siri AI at WWDC&lt;/h1&gt;
&lt;p&gt;Apple has unveiled Siri AI, its new voice assistant platform. Two details stand out: it’s partly built on Google Gemini, and it won’t be available on iPhone or iPad in the European Union. Privacy, Cupertino-style, becomes a blocking argument.&lt;/p&gt;
&lt;h2 id=&quot;the-fact&quot;&gt;The Fact&lt;/h2&gt;
&lt;p&gt;On June 8, 2026, at the WWDC, Apple introduced Siri AI, the much-anticipated revamp of its voice assistant and the announced foundation of its next generation of products, including future portable devices. The platform’s core is a hybrid architecture: local tasks run on Apple’s in-house models, but cloud intelligence relies on a custom Gemini model from Google, estimated to be around a billion dollars a year, according to several press sources.&lt;/p&gt;
&lt;p&gt;The catch is geography. Apple announced that Siri AI won’t be available on iPhone or iPad in the EU with iOS 27 and iPadOS 27. EU users will have access on macOS 27 and visionOS 27, but not on iPhone, iPad, or Apple Watch, as watchOS 27 depends on a paired iPhone with Siri AI. Apple cites the Digital Markets Act (DMA) and its interoperability requirements, claiming regulators rejected its compliance proposals, including a Trusted System Agent framework meant to open access to competing assistants while maintaining security standards.&lt;/p&gt;
&lt;p&gt;The Commission disputes the framing. For spokesperson Thomas Regnier, Apple’s decision not to deploy Siri AI in the EU is “Apple’s alone,” with nothing in the DMA preventing a new product launch. The market, however, has spoken: Apple’s stock dropped about 2% on the day of the announcement and another 3% the next day. Note of caution: iOS 27 and iPadOS 27 are currently announcements, not stable builds. The release timeline and block perimeter could still shift.&lt;/p&gt;
&lt;h2 id=&quot;why-it-matters-to-you&quot;&gt;Why It Matters to You&lt;/h2&gt;
&lt;p&gt;If you’re in Europe, the message is clear: your iPhone and iPad won’t have the flagship feature of the next OS. Before blaming Brussels, look at what’s really happening. Apple presents privacy as the reason it can’t comply with interoperability demands.&lt;/p&gt;
&lt;p&gt;The Commission responds that no one’s forcing Apple to cripple its product. The two versions aren’t symmetrical, and the official site isn’t the only source of truth here, but one thing’s certain: privacy has become a negotiation point as much as a technical promise.&lt;/p&gt;
&lt;p&gt;The irony’s worth noting. Apple pitches Siri AI as privacy-respecting while outsourcing cloud processing to Google, whose business model relies on data exploitation. Apple swears its architecture segregates everything via Private Cloud Compute, that Google sees nothing, and requests are anonymized. It’s plausible on paper, and Apple has a solid track record. But you’re moving from a verifiable promise, all-on-device, to a contractual one, trusting partners to keep their word. It’s not the same level of assurance.&lt;/p&gt;
&lt;p&gt;The underlying issue goes beyond Siri. We’re seeing digital ecosystem fragmentation by jurisdiction. The same iOS version won’t offer the same features in Paris, New York, or Beijing. User sovereignty now hinges not just on encryption, but on the iPhone-dependent arms race between an American industrial giant, a European regulator, and a third-party AI provider.&lt;/p&gt;
&lt;h2 id=&quot;what-it-changes-for-you&quot;&gt;What It Changes for You&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;1.&lt;/strong&gt; Don’t confuse Siri AI’s absence with loss of privacy. Your iPhone without a cloud AI assistant remains fully functional and more secure. The “lack” is a feature, not a lost protection.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;2.&lt;/strong&gt; For sensitive queries, stick local. Enable Advanced Data Protection on iCloud (Settings &gt; Apple Account &gt; iCloud &gt; Advanced Data Protection) for end-to-end encrypted backups. Note: ADP doesn’t cover iCloud Mail, Contacts, or Calendar. For genuinely encrypted email, try Proton Mail or Tuta, for instance.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;3.&lt;/strong&gt; Keep an eye on developments without getting overwhelmed. The EU block perimeter and timeline may shift. What matters isn’t the release date, but the broader question: are you ready to entrust your most intimate assistant to an Apple-Google chain, based on a contractual promise?&lt;/p&gt;</content:encoded><dc:creator>Mac Souverain</dc:creator><category>radar</category><category>radar-analyse</category><category>apple</category><category>siri</category><category>ia</category><category>dma</category><category>reglementation</category><category>google</category><category>gemini</category><category>confidentialite</category></item><item><title>OpenAI Certificate Compromised, Update ChatGPT Mac Before June 12th</title><link>https://macsouverain.com/en/chatgpt-mac-breach/</link><guid isPermaLink="true">https://macsouverain.com/en/chatgpt-mac-breach/</guid><description>ChatGPT, Codex, and Atlas on Mac: Mandatory update before June 12, 2026. OpenAI cert revoked after npm supply-chain attack.</description><pubDate>Sat, 06 Jun 2026 07:58:44 GMT</pubDate><content:encoded>&lt;div class=&quot;radar-summary&quot;&gt;
&lt;p&gt;**If you’re using ChatGPT, Codex, or Atlas natively on your Mac, you’ve got until &lt;strong&gt;June 12, 2026&lt;/strong&gt; to update. OpenAI’s signature certificate has been compromised via a supply-chain attack on npm. After that, your app won’t start.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Here’s what you need to do:&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;1.&lt;/strong&gt; Open ChatGPT.app, go to Settings → About. Update if your version is ≤ 1.2026.125. Same for Codex App (≤ 26.506.31421), Codex CLI (≤ 0.130.0), Atlas (≤ 1.2026.119.1).&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;2.&lt;/strong&gt; Official download only, &lt;code&gt;chatgpt.com/download&lt;/code&gt; or App Store. No mirrors, no shared links.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;3.&lt;/strong&gt; iOS, Windows, Android, nothing to do, OpenAI re-signs on the server side. Mac only.&lt;/p&gt;
&lt;/div&gt;
&lt;p&gt;&lt;strong&gt;You’re using ChatGPT, Codex, or Atlas in a native app on your Mac. On June 12, in a few days, these apps will refuse to launch if you haven’t updated. Not a bug, a certificate revocation due to a supply-chain attack. Here’s what happened and what you need to do.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;The Facts&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;On May 11, 2026, a collective called TeamPCP published 84 tampered versions of 42 &lt;code&gt;@tanstack/*&lt;/code&gt; packages on npm in just six minutes. Two OpenAI employees consumed one of these packages that evening. The malware, &lt;strong&gt;Mini Shai-Hulud&lt;/strong&gt;, exfiltrated credentials that granted access to internal repositories containing OpenAI’s code-signing tools. Not user conversations or models, just the keys that prove to macOS that an app comes from OpenAI.&lt;/p&gt;
&lt;p&gt;OpenAI &lt;a href=&quot;https://openai.com/index/our-response-to-the-tanstack-npm-supply-chain-attack/&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;announced publicly&lt;/a&gt; on May 13, 2026, that the compromised certificate would be &lt;strong&gt;revoked on June 12, 2026&lt;/strong&gt;. On Apple’s end, this means Gatekeeper and notarization will refuse any version signed with the old certificate. In practical terms, the affected versions are:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;ChatGPT Desktop&lt;/strong&gt; ≤ 1.2026.125&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Codex App&lt;/strong&gt; ≤ 26.506.31421&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Codex CLI&lt;/strong&gt; ≤ 0.130.0&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Atlas&lt;/strong&gt; (OpenAI browser) ≤ 1.2026.119.1&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;These won’t launch after June 12. iOS and Windows versions are re-signed server-side, no user action needed.&lt;/p&gt;
&lt;p&gt;The worm’s source code was published by TeamPCP on May 12, with a &lt;strong&gt;$1,000 bounty&lt;/strong&gt; on BreachForums for the largest supply-chain attack using their tool. Not a defensive bug bounty, an offensive reward. The CVE reference is &lt;strong&gt;CVE-2026-45321&lt;/strong&gt;.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Why This Matters to You&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;You didn’t do anything wrong, but you still have to act. That’s the essence of a supply-chain attack. Your user hygiene could be perfect, but if the app you’ve installed gets compromised four levels up, in an npm dependency you’ll never know about, you’re the one left with the problem. The compromised certificate, the revoked signing mechanism, the app that won’t launch - it all happens on your end without you clicking anything.&lt;/p&gt;
&lt;p&gt;The good news is the revocation mechanism works. Gatekeeper and Apple’s notarization are designed for this: preventing an attacker from using a stolen certificate to sign malware downstream. OpenAI did their job by properly revoking. Apple did their job by blocking. The system held up. OpenAI communicated clearly and promptly, with specific dates and versions - not the norm in the industry.&lt;/p&gt;
&lt;p&gt;The bad news is it raises a doctrinal question that goes beyond OpenAI. A native app on your Mac is local code running with a trust certificate, automatic update channel, system permissions, and a network of upstream dependencies you have no visibility into. When one of these dependencies gets compromised - and they all do - the problem comes down to you.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;What You Need to Do Now&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;1.&lt;/strong&gt; Open &lt;strong&gt;ChatGPT.app&lt;/strong&gt;, go to &lt;strong&gt;Preferences → About&lt;/strong&gt;. If you’re on 1.2026.125 or earlier, start the update. If nothing appears, download directly from [chatgpt.com/download](&lt;a href=&quot;https://chatgpt.com/download&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;https://chatgpt.com/download&lt;/a&gt;]. Never a mirror, never a shared link.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;2.&lt;/strong&gt; If you’re using &lt;strong&gt;Codex App&lt;/strong&gt; or &lt;strong&gt;Codex CLI&lt;/strong&gt;, do the same check. CLI: &lt;code&gt;codex --version&lt;/code&gt; then &lt;code&gt;npm update -g @openai/codex&lt;/code&gt; or reinstall cleanly. For &lt;strong&gt;Atlas&lt;/strong&gt;, update is integrated.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;3.&lt;/strong&gt; Make sure macOS is up-to-date, with Gatekeeper strengthened on Sequoia 15.x and Sonoma 14.7+. Older versions are more lenient in notarization checks at launch.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;4.&lt;/strong&gt; Use the window to ask yourself a doctrinal question: what does the native ChatGPT app give you that &lt;a href=&quot;https://chatgpt.com&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;chatgpt.com in Safari&lt;/a&gt; doesn’t? System dictation, keyboard shortcuts, Spotlight integration - okay. If you don’t use any of these, the browser reduces your attack surface. No signature certificate to manage, no silent updates, no persistent local code. The habit applies to &lt;strong&gt;Claude Desktop&lt;/strong&gt;, &lt;strong&gt;Perplexity&lt;/strong&gt;, &lt;strong&gt;Mistral AI Chat&lt;/strong&gt;, and any other third-party AI apps you’ve installed without really knowing why. A native app on your Mac is a security debt - sometimes justified, sometimes not.&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;em&gt;Also read, &lt;a href=&quot;https://macsouverain.com/en/anthropic-mcp-rce-design-flaw-avril-2026/&quot;&gt;Anthropic MCP, design flaw that opens RCE&lt;/a&gt;. Same logic, third-party AI code descending into dangerous local execution.&lt;/em&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;&lt;strong&gt;Sources&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&quot;https://openai.com/index/our-response-to-the-tanstack-npm-supply-chain-attack/&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;OpenAI, Our response to the TanStack npm supply chain attack&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://9to5mac.com/2026/06/02/psa-a-security-breach-means-you-must-update-the-chatgpt-mac-app/&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;9to5Mac, PSA, you must update the ChatGPT Mac app&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://thehackernews.com/2026/05/tanstack-supply-chain-attack-hits-two.html&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;The Hacker News, TanStack supply chain attack hits two OpenAI employees&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://www.tenable.com/blog/mini-shai-hulud-frequently-asked-questions&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;Tenable, Mini Shai-Hulud CVE-2026-45321 FAQ&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://tanstack.com/blog/npm-supply-chain-compromise-postmortem&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;TanStack, postmortem npm supply-chain compromise&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://www.zataz.com/openai-change-ses-certificats-apres-le-hack-tanstack/&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;ZATAZ, OpenAI changes its certificates after the TanStack hack&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;</content:encoded><dc:creator>Mac Souverain</dc:creator><category>radar</category><category>radar-alerte</category><category>openai</category><category>chatgpt</category><category>supply-chain</category><category>code-signing</category><category>macos</category><category>ia</category><category>cybersec</category></item><item><title>Domestic stalkerware, the jealous partner&apos;s malware</title><link>https://macsouverain.com/en/stalkerware-spyzie-domestique-mai-2026/</link><guid isPermaLink="true">https://macsouverain.com/en/stalkerware-spyzie-domestique-mai-2026/</guid><description>Stalkerware Spyzie, Cocospy, Spyic, over 3 million victims combined. Your iPhone drained via your Apple ID. How to check and take back control.</description><pubDate>Tue, 26 May 2026 17:09:58 GMT</pubDate><content:encoded>&lt;div class=&quot;radar-summary&quot;&gt;
&lt;p&gt;&lt;strong&gt;Public stalkerware (Spyzie, Cocospy, Spyic, mSpy) has over three million victims just within the Cocospy/Spyic/Spyzie family. Thirty to seventy dollars a month, operated by Chinese operators. On iPhone, your spouse knows your Apple ID and drains iCloud from the web. Less commonly, a hidden MDM profile installed by a close one in just two minutes. On Android, a hidden app. Premium modules: real-time GPS tracking and remote microphone activation. The victim never searches for the term “stalkerware” and doesn’t even know it exists.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;What you need to do&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;1.&lt;/strong&gt; Check Settings, General, VPN and Device Management. Any profile you didn’t set yourself, especially vague ones like “iOS Update”, delete it. Check Screen Time, disable any password you didn’t set.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;2.&lt;/strong&gt; Change your Apple ID password, enable two-factor authentication, remove unknown devices from your list, and enable Advanced Data Protection to switch your iCloud backups to end-to-end encryption.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;3.&lt;/strong&gt; Switch to Signal for sensitive messages, Bitwarden or KeePassXC for passwords, never a shared vault.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;4.&lt;/strong&gt; If you suspect active installation, act from another device and network. The Coalition Against Stalkerware lists resources by country.&lt;/p&gt;
&lt;/div&gt;
&lt;p&gt;&lt;strong&gt;On May 26th, Joseph Cox of 404 Media interviewed Zack Whittaker, the journalist who’s been leaking pretty much all the major consumer stalkerware cases for the past five years. Verdict? It’s not a niche market, it’s a mass market. Hundreds of thousands of victims on just one network. Targets iPhones and Androids. Installation by your partner, ex, roommate, in two minutes while you’re in the shower.&lt;/strong&gt;&lt;/p&gt;
&lt;h2 id=&quot;the-deal&quot;&gt;The Deal&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;Stalkerware&lt;/strong&gt; is spyware sold to Joe and Jane Public. Not Pegasus, not Predator, not the mercenary spyware grade that Citizen Lab tracks from Toronto. The stuff you install on your girlfriend’s phone to read her messages, listen to her calls, track her location, and turn on her mic remotely. Brands like &lt;strong&gt;Spyzie&lt;/strong&gt;, &lt;strong&gt;Cocospy&lt;/strong&gt;, &lt;strong&gt;Spyic&lt;/strong&gt;, &lt;strong&gt;mSpy&lt;/strong&gt;, &lt;strong&gt;TheTruthSpy&lt;/strong&gt;.&lt;/p&gt;
&lt;p&gt;Whittaker’s been leaking these since 2021. The latest wave, February 2025, exposed &lt;strong&gt;518,000 Spyzie clients&lt;/strong&gt; including at least &lt;strong&gt;4,900 compromised iPhones&lt;/strong&gt;, and &lt;strong&gt;2.65 million email addresses&lt;/strong&gt; on the twin network Cocospy + Spyic. That’s &lt;strong&gt;over three million victims&lt;/strong&gt; just from this one family of operators.&lt;/p&gt;
&lt;p&gt;Monthly subscription? Thirty to seventy dollars for the standard plan, more if you add premium modules like mic and cam access. Companies live in offshore holdings, Cyprus, British Virgin Islands, or straight out of China. &lt;strong&gt;Cocospy, Spyic, and Spyzie are all the same team&lt;/strong&gt;, traced back to one Chinese operator by Whittaker.&lt;/p&gt;
&lt;p&gt;mSpy runs the same business model under a separate brand, legacy Cyprus-Ukraine. When leaks expose them, they shut down and reopen under a new name. Market size? Around &lt;strong&gt;$145 million a year&lt;/strong&gt;, according to Future Market Insights.&lt;/p&gt;
&lt;p&gt;On the &lt;strong&gt;iPhone&lt;/strong&gt; side, the dominant method doesn’t even need physical access. Your partner knows your Apple ID password because you shared it, they’ve seen your iPhone unlock a hundred times, or you’ve used the same one for fifteen years. They log in to iCloud via browser, download your backups, and the stalkerware app does its thing server-side. No app on your phone, nothing to detect locally. Exactly how Whittaker documented Cocospy, Spyic, and Spyzie in 2025.&lt;/p&gt;
&lt;p&gt;Rarer but more comprehensive variant: a configuration profile MDM, the mechanism designed for managing business fleets. The close one installs the stalkerware app via &lt;a href=&quot;https://support.apple.com/apple-configurator&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;Apple Configurator&lt;/a&gt; on their Mac, supervising your phone with a Lightning or USB-C cable. The profile’s marked &lt;code&gt;removalDisallowed&lt;/code&gt;, named something innocuous like “iOS Update” or “Battery Optimizer”. A Screen Time password your partner set hides the “Device Management” entry in Settings. You’re clueless. On &lt;strong&gt;Android&lt;/strong&gt;, it’s the app disguised as a system tool, hidden behind a generic name, with accessibility turned on to read everything for you.&lt;/p&gt;
&lt;h2 id=&quot;why-this-matters-to-you&quot;&gt;Why This Matters to You&lt;/h2&gt;
&lt;p&gt;Here’s where the usual cybersec press coverage drops off. We hear a lot about the mercenaries, NSO, Intellexa, Paragon, the billion-euro budgets and diplomatic targets. But the statistical danger for you? It’s not some state watching you, it’s your ex stalking you. States have their part too, pushing for mass control legislatively, as I’ve broken down in &lt;a href=&quot;https://macsouverain.com/en/convergence-libertes-numeriques/&quot;&gt;Six Months and Nineteen Global Texts, the Terrible Convergence&lt;/a&gt;. But the sheer frequency of domestic victims trumps all.&lt;/p&gt;
&lt;p&gt;Whittaker’s been saying since 2021 that &lt;strong&gt;domestic stalkerware outdoes all mercenary spyware combined&lt;/strong&gt;. The press ignores it because it’s dirty, intimate, lacks Pegasus’ geopolitical cachet.&lt;/p&gt;
&lt;p&gt;Information asymmetry is total. Buyers find these products in three clicks: fake “Top 10 spy apps” sites owned by sellers, SEO on jealous searches, Reddit with affiliate accounts, TikTok in “POV I hooked my guy” format, Google Ads hijacked on “Find My iPhone” or “family locator”.&lt;/p&gt;
&lt;p&gt;Marketing facade: “parental control for kids” quickly pivots to “monitor your spouse”. Potential victims never search for “stalkerware”. They don’t even know it exists. That’s the definition of a threat you don’t see coming.&lt;/p&gt;
&lt;p&gt;You’re the target. Couple with iPhone and Mac, integrated Apple ecosystem, shared iCloud family, common passwords “because we trust each other”. When trust cracks, siphoning takes a few clicks from a browser, or two minutes MDM installation while you’re out. You’ll only know reading this.&lt;/p&gt;
&lt;h2 id=&quot;what-you-do-now&quot;&gt;What You Do Now&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;1. Check your iPhone, configuration profiles, and Screen Time.&lt;/strong&gt;&lt;br&gt;
Settings, General, VPN &amp;#x26; Device Management. If you see a profile you didn’t install, especially with a vague name like “iOS Update”, “Battery Saver”, “Profile Service”, delete it. Then Settings, Screen Time. If a password’s active and it’s not yours, disable via your Apple ID. That password often hides the VPN &amp;#x26; Device Management entry. If the delete button’s greyed out or the profile returns after “Reset All Settings”, it’s &lt;code&gt;removalDisallowed&lt;/code&gt; with active DEP supervision: need Apple Store server-side break. Apple reference: &lt;a href=&quot;https://support.apple.com/guide/iphone/install-or-remove-configuration-profiles-iph6c493b1fb/ios&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;remove a configuration profile&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;2. Take back control of your critical accounts.&lt;/strong&gt;&lt;br&gt;
Change your Apple ID password immediately and enable &lt;a href=&quot;https://support.apple.com/HT204915&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;two-factor authentication&lt;/a&gt; with a number your close circle doesn’t control. Check the list of devices connected to your Apple ID in Settings, top. Any unknown device, delete it. Enable &lt;a href=&quot;https://support.apple.com/HT202303&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;Advanced Data Protection&lt;/a&gt; for end-to-end encrypted backups, server-side exfiltration becomes useless.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;3. Switch to E2EE tools for sensitive stuff.&lt;/strong&gt;&lt;br&gt;
Critical messages on &lt;a href=&quot;https://signal.org/&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;Signal&lt;/a&gt;, not iMessage. Passwords in your own manager, &lt;a href=&quot;https://bitwarden.com/&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;Bitwarden&lt;/a&gt; self-hosted or KeePassXC local file, not a shared Apple Keychain. Local encrypted backups on external drive, not just iCloud.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;4. If you suspect active installation, leave the physical perimeter before acting.&lt;/strong&gt;&lt;br&gt;
Stalkerware with mic and GPS rats you out in real-time. Contact specialized help services from an unsurveilled device and network. The &lt;a href=&quot;https://stopstalkerware.org/&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;Coalition Against Stalkerware&lt;/a&gt; lists resources by country and a response kit for victims.&lt;/p&gt;
&lt;h2 id=&quot;sources&quot;&gt;Sources&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&quot;https://www.404media.co/millions-of-people-are-installing-malware-on-their-partners-phones-with-zack-whittaker/&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;Millions of people are installing malware on their partner’s phones, with Zack Whittaker, 404 Media, 26/05/2026&lt;/a&gt; (primary source)&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://techcrunch.com/2025/02/27/spyzie-stalkerware-spying-on-thousands-of-android-and-iphone-users/&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;Spyzie stalkerware spying on thousands of Android and iPhone users, TechCrunch, 27/02/2025&lt;/a&gt; (Whittaker’s investigation, 518k clients + 4,900 iPhones)&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://techcrunch.com/2025/02/20/stalkerware-apps-cocospy-spyic-exposing-phone-data-of-millions-of-people/&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;Cocospy and Spyic exposing phone data of millions of people, TechCrunch, 20/02/2025&lt;/a&gt; (market architecture, 711.icu China link)&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://techcrunch.com/2025/05/19/cocospy-stalkerware-apps-go-offline-after-data-breach/&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;Cocospy stalkerware apps go offline after data breach, TechCrunch, 19/05/2025&lt;/a&gt; (post-leak rebranding pattern)&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://techcrunch.com/2020/08/11/stalkerware-apps-google-ads/&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;Stalkerware apps escape Google’s ad ban, TechCrunch, 11/08/2020&lt;/a&gt; (Google Ads workaround)&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://stopstalkerware.org/&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;Coalition Against Stalkerware, victim resources&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;em&gt;Tech terms? &lt;a href=&quot;https://macsouverain.com/en/glossaire/&quot;&gt;Check the glossary.&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;</content:encoded><dc:creator>Mac Souverain</dc:creator><category>radar</category><category>radar-alerte</category><category>stalkerware</category><category>spyzie</category><category>cocospy</category><category>spyic</category><category>mspy</category><category>privacy</category><category>iphone</category><category>mdm</category><category>surveillance-domestique</category><category>cybersec</category></item><item><title>The U.S. cyber regulator let its AWS keys slip six months ago.</title><link>https://macsouverain.com/en/cisa-nightwing-govcloud-leak-mai-2026/</link><guid isPermaLink="true">https://macsouverain.com/en/cisa-nightwing-govcloud-leak-mai-2026/</guid><description>A US federal cyber agency&apos;s subcontractor left their AWS GovCloud admin keys on a public GitHub repo for six months. Why not delegate your security, huh?</description><pubDate>Tue, 26 May 2026 13:39:33 GMT</pubDate><content:encoded>&lt;div class=&quot;radar-summary&quot;&gt;
&lt;p&gt;**CISA, the U.S. federal cyber agency, just found out that one of its subcontractors left a public GitHub repository full of AWS GovCloud admin keys, tokens, and cleartext passwords for &lt;strong&gt;six months&lt;/strong&gt;. External detection by GitGuardian, not internal. The keys remained valid for 48 hours after the repo was removed. If the federal cyber regulator can’t even keep its own secrets, how are you supposed to? Let me explain!&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;What you need to do&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;1.&lt;/strong&gt; Inventory what you’re currently entrusting to a third-party cloud, and for each item ask yourself who has the decryption key. At-rest encryption with server-side keys equals zero.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;2.&lt;/strong&gt; Choose your cloud providers based on one criterion: end-to-end encryption, client-side keys (Proton, Tuta, Mullvad for EU).&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;3.&lt;/strong&gt; What happens at home stays at home: backups on encrypted APFS external disk, double offsite encrypted copy.&lt;/p&gt;
&lt;/div&gt;
&lt;p&gt;&lt;strong&gt;The Deal&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;On May 22, 2026, Brian Krebs published the investigation. An employee of &lt;a href=&quot;https://www.nightwing.com/&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;Nightwing&lt;/a&gt;, a historic subcontractor of CISA based in Dulles, Virginia, created a GitHub repository named “Private-CISA” on November 13, 2025. The word “Private” in the name, the &lt;code&gt;public&lt;/code&gt; setting in the parameters. The repo remained online, accessible to anyone, until mid-May 2026. Six months.&lt;/p&gt;
&lt;p&gt;Inside, there’s heavy stuff. &lt;strong&gt;Three sets of admin keys&lt;/strong&gt; for AWS GovCloud accounts, Amazon’s cloud environment dedicated to US federal agencies, certified FedRAMP High for hosting non-classified sensitive data (CUI).&lt;/p&gt;
&lt;p&gt;Access tokens, SSH keys, internal logs, and clear-text passwords following the “platform-year” pattern that a third-year intern wouldn’t dare to try. Plus some internal documents about the agency’s software development processes. Almost nothing, huh!&lt;/p&gt;
&lt;p&gt;And the detection? Neither CISA internal nor Nightwing audit. It’s &lt;a href=&quot;https://blog.gitguardian.com/&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;Guillaume Valadon&lt;/a&gt;, a researcher at &lt;a href=&quot;https://www.gitguardian.com/&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;GitGuardian&lt;/a&gt;, who continuously scans public repos for forgotten secrets, who found the repo. Krebs and the consulting firm Seralys notified CISA, which had the repo taken down. The cherry on top: &lt;strong&gt;the AWS keys remained valid for 48 hours after the repo was removed&lt;/strong&gt; before the agency decided to revoke them.&lt;/p&gt;
&lt;p&gt;CISA’s official statement is one sentence we’ve seen a hundred times: “At this stage, there’s no indication that sensitive data has been compromised.” Nightwing refers to CISA, CISA refers to the investigation. Krebs qualifies the incident as “one of the most scandalous government data breaches in recent history,” and Bruce Schneier repeats the phrase without qualification.&lt;/p&gt;
&lt;h2 id=&quot;why-it-matters-to-you&quot;&gt;Why it matters to you&lt;/h2&gt;
&lt;p&gt;You’re not CISA, you don’t have a Nightwing subcontractor, you don’t use AWS GovCloud. Great. Now, do the cold calculation. &lt;strong&gt;The agency that sets the cybersecurity standards for US administrations&lt;/strong&gt;, that publishes “secure by design” guides and CVE alerts followed by the entire industry, &lt;strong&gt;just left its own cloud admin keys open for six months without noticing&lt;/strong&gt;. Not some dodgy subcontractor or some third-rate SaaS: the cyber regulator itself.&lt;/p&gt;
&lt;p&gt;The argument is structural, not anecdotal. When you entrust your secrets to a third party, no matter how serious they claim to be, you inherit &lt;strong&gt;their entire supply chain&lt;/strong&gt;. CISA entrusts to Nightwing, Nightwing employs someone, that someone pushes to GitHub. The weak link compromises the entire chain in an instant. That’s bad enough on its own, but add the IA threat surge, and you’ve potentially got a backdoor into more confidential systems.&lt;/p&gt;
&lt;p&gt;Let’s get back to you. You have a personal GitHub repo? You’ve ever pasted an API key into a commit for “quick testing” before forgetting to remove it from history? You use a cloud-owned password manager for creds that open your infrastructure? You trust a SaaS editor under foreign jurisdiction to keep your secrets securely encrypted for you? The CISA radar is you in miniature, but with fewer zeros on the consequences.&lt;/p&gt;
&lt;p&gt;The MacSouverain angle doesn’t change by a millimeter from the first article. Keep your secrets &lt;strong&gt;with you&lt;/strong&gt;. On your machine, in your local vault, under your key. You can delegate the formatting, syncing, encrypted backup. You don’t delegate security itself. Because the day your provider screws up, and they will, you want the blast radius to stop at them.&lt;/p&gt;
&lt;h2 id=&quot;what-you-do-now&quot;&gt;What you do now&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;1. Inventory what you’re currently entrusting to a cloud third party.&lt;/strong&gt;&lt;br&gt;
Grab a sheet of paper. Passwords, emails, contacts, files, notes, photo backups. For each one, write where it’s stored and who has the decryption key. If the answer to “who has the key” is “the provider, or one of their subcontractors,” you’re in exactly the same position as CISA. You’re trusting a chain you don’t control a link of.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;2. Choose your cloud providers based on “end-to-end encrypted, key on client side”.&lt;/strong&gt;&lt;br&gt;
For what you have to put in the cloud (multi-device sync, sharing, backup), only accept providers who can’t read your content, even if they wanted to or were asked to.&lt;/p&gt;
&lt;p&gt;For email and storage: &lt;a href=&quot;https://proton.me/&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;Proton&lt;/a&gt; or &lt;a href=&quot;https://tuta.com/&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;Tuta&lt;/a&gt;, European jurisdiction, end-to-end encrypted by default. For VPN: &lt;a href=&quot;https://mullvad.net/&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;Mullvad&lt;/a&gt; or &lt;a href=&quot;https://protonvpn.com/&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;Proton VPN&lt;/a&gt;, no logs. The difference from AWS, Google Drive, iCloud non-ADP: you don’t have to take the provider’s word for it, the architecture makes unauthorized access technically impossible.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;3. What happens at your place stays at your place.&lt;/strong&gt;&lt;br&gt;
Whatever you can keep local, keep it local. Photos, archives, sensitive documents, backups: an encrypted APFS external drive at home, plus a second encrypted copy you store with a friend or in a safe. If you need to sync files between your own devices without going through a third party, &lt;a href=&quot;https://syncthing.net/&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;Syncthing&lt;/a&gt; does direct P2P between your devices, period. You don’t go to the cloud by default, you go there deliberately. The CISA rule applies in miniature to everyone: the day your provider screws up, and they will, you want the blast radius to stop at them, not take you down with them.&lt;/p&gt;
&lt;h2 id=&quot;sources&quot;&gt;Sources&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&quot;https://krebsonsecurity.com/2026/05/cisa-admin-leaked-aws-govcloud-keys-on-github/&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;CISA Admin Leaked AWS GovCloud Keys on GitHub, Krebs on Security, May 22, 2026&lt;/a&gt; (primary source)&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://www.schneier.com/blog/archives/2026/05/cisa-security-leak.html&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;CISA Security Leak, Schneier on Security, May 22, 2026&lt;/a&gt; (commented repost)&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://www.gitguardian.com/&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;GitGuardian, scanner of secrets in public repos&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id=&quot;see-also&quot;&gt;See also&lt;/h2&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;em&gt;Read: &lt;a href=&quot;https://macsouverain.com/en/cloud-ordinateur-quelquun-dautre/&quot;&gt;The cloud, it’s someone else’s computer&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;em&gt;Read: &lt;a href=&quot;https://macsouverain.com/en/gestionnaire-mots-de-passe-mac-comparatif/&quot;&gt;Password manager on Mac, comparison&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;&lt;em&gt;What are those tech terms? &lt;a href=&quot;https://macsouverain.com/en/glossaire/&quot;&gt;Check the glossary.&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;</content:encoded><dc:creator>Mac Souverain</dc:creator><category>radar</category><category>radar-alerte</category><category>severite-5</category><category>cisa</category><category>nightwing</category><category>aws</category><category>govcloud</category><category>souverainete</category><category>cybersec</category><category>delegation</category><category>cloud</category></item><item><title>Five years of defending memory M5 down in five days</title><link>https://macsouverain.com/en/apple-m5-mie-bypass-calif-mythos-mai-2026/</link><guid isPermaLink="true">https://macsouverain.com/en/apple-m5-mie-bypass-calif-mythos-mai-2026/</guid><description>Three California researchers bypassed Memory Integrity Enforcement M5 in five days using Mythos. First public kernel exploit on Apple M5 silicon. Patched in macOS Tahoe 26.5.</description><pubDate>Tue, 19 May 2026 07:23:49 GMT</pubDate><content:encoded>&lt;div class=&quot;radar-summary&quot;&gt;
&lt;p&gt;&lt;strong&gt;Three researchers took full control of a Mac M5 in five days&lt;/strong&gt;, with a helping hand from &lt;strong&gt;Mythos&lt;/strong&gt;, Anthropic’s specialized IA vulnerability AI. In the process, &lt;strong&gt;they took down MIE, Apple’s five-year-old memory protection&lt;/strong&gt;. Apple patched it in macOS Tahoe 26.5 on May 11. First public kernel exploit on M5 silicon, and a real-world show that AI can speed this kind of work by a factor of ten.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;What you need to do&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;1.&lt;/strong&gt; Update macOS Tahoe 26.5 immediately (System Preferences, Software Update).&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;2.&lt;/strong&gt; Enable Lockdown Mode if you’re professionally exposed (journalist, activist, executive).&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;3.&lt;/strong&gt; Avoid all unverified user binaries. Strict Gatekeeper, signatures on Homebrew.&lt;/p&gt;
&lt;/div&gt;
&lt;p&gt;&lt;strong&gt;The Deal&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;On May 14, 2026, Calif.io spilled the beans on how they did it. Three researchers (Bruce Dang, Dion Blazakis, Josh Maine) found two bugs in the macOS kernel on a brand-new Mac M5. They chained them together. Result: a regular user, with no special privileges, &lt;strong&gt;gains full control of the machine (root)&lt;/strong&gt;. Reading all memory, accessing the Keychain, disabling protections. Everything.&lt;/p&gt;
&lt;p&gt;What makes this historical is what came out alongside it. The M5 chip debuts &lt;strong&gt;MIE&lt;/strong&gt; (Memory Integrity Enforcement), a protection hard-coded into the silicon. In other words, Apple tagged every piece of memory used by the kernel, and the hardware refuses tampering. &lt;strong&gt;Five years of work.&lt;/strong&gt; Unveiled last year as the new frontier of Mac security. &lt;strong&gt;Calif bypassed it in five days.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;The game-changer: &lt;strong&gt;Mythos&lt;/strong&gt;. It’s Anthropic’s frontier model, restricted access for vulnerability research. The researchers clarify that Mythos didn’t find the exploit alone. Bypassing MIE requires sharp human expertise. But Mythos spotted the bugs fast, where humans alone would’ve taken weeks. &lt;strong&gt;Months of work now takes days.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Calif handed the details to Apple in Cupertino. Apple released the fixes in macOS Tahoe 26.5 on &lt;strong&gt;May 11, 2026&lt;/strong&gt;. The release notes credit “Calif.io in collaboration with Claude and Anthropic Research”. The full technical report (55 pages) is under embargo until the patches roll out everywhere. Apple hasn’t publicly commented on the exploit chain.&lt;/p&gt;
&lt;h2 id=&quot;why-it-matters-to-you&quot;&gt;Why it matters to you&lt;/h2&gt;
&lt;p&gt;If you’ve got a Mac M5, your hardware was sold as the high-water mark of Apple security. Five days after the exploit was released, &lt;strong&gt;the frontier moved&lt;/strong&gt;. Hardware protection alone isn’t enough; a well-equipped human can bring it down in a week.&lt;/p&gt;
&lt;p&gt;Good news: &lt;strong&gt;it’s not a remote attack&lt;/strong&gt;. To exploit the bugs on your Mac, the attacker needs a foothold. A booby-trapped binary you ran yourself (compromised Homebrew, app grabbed outside the App Store, file opened from a sketchy shared drive). From there, though, they’re root and can do whatever they want.&lt;/p&gt;
&lt;p&gt;The bigger picture: Mythos is making waves. On May 11, curl maintainer Daniel Stenberg confirmed a flaw in his code found by Mythos (Stenberg’s still skeptical, but acknowledges the result). Three days later, Calif.io took down MIE. &lt;strong&gt;The window between ‘bug discovered’ and ‘functional exploit’ is closing&lt;/strong&gt;. Apple, Google, and Microsoft have all publicly acknowledged that the latest AI models are changing the threat model. We’re seeing it in practice now.&lt;/p&gt;
&lt;h2 id=&quot;what-you-do-now&quot;&gt;What you do now&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;1. Update macOS Tahoe 26.5 right now&lt;/strong&gt;, on all your Macs (M5, M4, M3, M2, M1, Intel). The update covers bugs beyond just the M5. System Preferences, General, Software Update. If you’re still on macOS Sequoia 15.7.7 or macOS Sonoma 14.8.7, they got the cousin fixes the same day.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;2. Turn on Lockdown Mode&lt;/strong&gt; if you’re professionally exposed (journalist, activist, executive, researcher). Lockdown Mode severely cuts the kernel memory attack surface, exactly what Calif exploited. System Preferences, Privacy &amp;#x26; Security, Lockdown Mode. Beware, there’ll be friction.&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;em&gt;Read: &lt;a href=&quot;https://macsouverain.com/en/lockdown-mode-face-a-coruna-toolkit-espionnage-gouvernemental/&quot;&gt;Lockdown Mode, why to turn it on&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;&lt;strong&gt;3. Avoid binaries from nowhere&lt;/strong&gt;. No out-of-App Store apps without audit, no random executables. Verify signatures (GPG, SHA256) on sensitive tools, Homebrew included. Set Gatekeeper to strict in System Preferences, Privacy &amp;#x26; Security, allow only the App Store.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;4. Stay tuned&lt;/strong&gt;: Calif’s 55-page tech report comes out once the patches are widely deployed. When it’s public, expect a wave of copies on GitHub and a full Mac fleet scan by security teams. Until then, just stay updated.&lt;/p&gt;
&lt;h2 id=&quot;sources&quot;&gt;Sources&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&quot;https://blog.calif.io/p/first-public-kernel-memory-corruption&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;First public macOS kernel memory corruption exploit on Apple M5, blog.calif.io&lt;/a&gt; (primary source Calif.io)&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://support.apple.com/en-us/127115&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;About the security content of macOS Tahoe 26.5, Apple Security, 11/05/2026&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://9to5mac.com/2026/05/14/calif-team-details-how-anthropic-mythos-helped-build-a-working-macos-exploit-in-five-days/&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;Calif team details how Anthropic Mythos helped build a working macOS exploit in five days, 9to5Mac, 14/05/2026&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://daniel.haxx.se/blog/2026/05/11/mythos-finds-a-curl-vulnerability/&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;Mythos finds a curl vulnerability, Daniel Stenberg, 11/05/2026&lt;/a&gt; (skeptical counterpoint)&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id=&quot;also-see&quot;&gt;Also see&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&quot;https://macsouverain.com/en/radar-anthropic-mythos-acces-non-autorise-avril-2026/&quot;&gt;Anthropic Mythos: unauthorized access identified&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;</content:encoded><dc:creator>Mac Souverain</dc:creator><category>radar</category><category>radar-alerte</category><category>apple</category><category>macos</category><category>m5</category><category>kernel</category><category>mythos</category><category>anthropic</category><category>calif-io</category><category>mie</category></item><item><title>Google Ads and real cat Claude share your credentials</title><link>https://macsouverain.com/en/radar-macsync-google-ads-claude-share-mai-2026/</link><guid isPermaLink="true">https://macsouverain.com/en/radar-macsync-google-ads-claude-share-mai-2026/</guid><description>Google sponsored ads redirect to real, shared claude.ai links that are baited. Fake Apple Support makes you paste a base64 into Terminal. MacSync payload empties your Keychain.</description><pubDate>Thu, 14 May 2026 11:58:10 GMT</pubDate><content:encoded>&lt;div class=&quot;radar-summary&quot;&gt;
&lt;p&gt;&lt;strong&gt;A malicious ad campaign is hijacking Google Ads and Claude.ai’s Share function to promote MacSync, an info-stealing macOS malware that empties your Keychain with a simple terminal command you paste yourself. The pattern combines two trust signals (official claude.ai domain + fake Apple Support) to lure you into running base64 without suspicion.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;What you need to do&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;1.&lt;/strong&gt; Never paste a terminal command dictated by a website, AI chat, or an “official” PDF.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;2.&lt;/strong&gt; Enable Little Snitch or LuLu and monitor unexpected network traffic.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;3.&lt;/strong&gt; If already executed: disconnect from Wi-Fi, change all your browser passwords, and scan with KnockKnock.&lt;/p&gt;
&lt;/div&gt;
&lt;p&gt;&lt;strong&gt;You’re searching “Claude mac download” on Google. The first sponsored result points to claude.ai, so the URL is legitimate. Except it’s a shared Claude chat where a fake “Apple Support” dictates a Terminal command to paste. You paste it, and MacSync steals your Keychain, cookies, and browser credentials.&lt;/strong&gt;&lt;/p&gt;
&lt;h2 id=&quot;the-fact&quot;&gt;The Fact&lt;/h2&gt;
&lt;p&gt;Berk Albayrak (Trendyol Group) and BleepingComputer have been documenting since May 10, 2026, an active macOS malvertising campaign that exploits two legitimate mechanisms simultaneously. First, Google Ads: a sponsored ad for “Claude mac download” points to &lt;code&gt;claude.ai&lt;/code&gt;, Anthropic’s official domain. Then, Claude.ai Share: this feature is used to host a fake installation guide signed “Apple Support” that tells the user to paste a base64-encoded command into Terminal.&lt;/p&gt;
&lt;p&gt;The command downloads a polymorphic shell script from the attacker’s infrastructure, checks the keyboard layout (exits immediately if Russian or CIS), then executes the second-stage payload via &lt;code&gt;osascript&lt;/code&gt; (macOS’s native AppleScript engine) for fileless delivery. The malware is called MacSync, an infostealer that collects browser credentials and cookies, exfiltrates the macOS Keychain, and fingerprints the victim (IP, hostname, OS version, keyboard language).&lt;/p&gt;
&lt;p&gt;The indicators of compromise published are payload &lt;code&gt;customroofingcontractors[.]com/curl/&lt;/code&gt; and &lt;code&gt;bernasibutuwqu2[.]com/debug/loader.sh&lt;/code&gt;, exfiltration to &lt;code&gt;briskinternet[.]com&lt;/code&gt;. The two identified Claude.ai Share URLs are &lt;code&gt;claude[.]ai/share/9aac1046-a39e-4618-8265-f54c4be863f7&lt;/code&gt; and &lt;code&gt;claude[.]ai/share/eb2db455-1d47-4baf-8671-0a689e165902&lt;/code&gt;.&lt;/p&gt;
&lt;p&gt;Don’t worry, the links are disabled here, but Anthropic hadn’t disabled the Share mechanism at the time of BleepingComputer’s publication.&lt;/p&gt;
&lt;h2 id=&quot;why-this-is-a-game-changer&quot;&gt;Why This is a Game-Changer&lt;/h2&gt;
&lt;p&gt;Two things, really. First, &lt;strong&gt;the “shared chat” feature of a public AI platform becomes a malware distribution surface&lt;/strong&gt;. Claude.ai’s shared pages are public, indexable, and notably, &lt;strong&gt;not moderated like typical user content&lt;/strong&gt;. They inherit Anthropic’s visual trust, and at the time of BleepingComputer and GBHackers’ publications, both compromised share URLs were still online.&lt;/p&gt;
&lt;p&gt;Second, &lt;strong&gt;AI brand hijacking&lt;/strong&gt; joins known malvertising schemes (Homebrew, Loom, Notion, AnyDesk), with Claude Code being a recent dev tool, its official installation page isn’t yet a muscle memory reflex, leaving an exploitable window.&lt;/p&gt;
&lt;p&gt;This is also a case study on &lt;strong&gt;Google Ads&lt;/strong&gt;, despite announced controls, ads impersonating brands continue to slip through, exploiting the legitimate display URL while pointing to a compromised page on the editor’s own site.&lt;/p&gt;
&lt;p&gt;Domain validation isn’t enough when the editor hosts user content. Responsibility is shared, &lt;strong&gt;Anthropic&lt;/strong&gt; needs to beef up shared chat moderation (detect chats posing as official support of other brands, banner on chats containing shell commands, visual watermark distinguishing a shared chat from a product page), &lt;strong&gt;Google&lt;/strong&gt; needs to go beyond display domain in Ads validation. But the last line is &lt;strong&gt;you, never paste a Terminal command blindly&lt;/strong&gt;.&lt;/p&gt;
&lt;h2 id=&quot;why-this-matters-to-you&quot;&gt;Why This Matters to You&lt;/h2&gt;
&lt;p&gt;The social engineering pattern here is ruthless because it chains two usually legitimate trust signals. The &lt;code&gt;claude.ai&lt;/code&gt; official domain, native Anthropic Share feature, fake “Apple Support” in a supposedly serious AI environment. You’re not clicking on some obscure download site, you’re clicking on what looks like official documentation brought up by a search engine, exactly the kind of attack that slips under usual vigilance.&lt;/p&gt;
&lt;p&gt;The target is wide. Not just developers (Homebrew, GitHub), but any Mac user curious to try Claude desktop. The malware doesn’t require any system elevation, no 0day, no TCC bypass, the user does all the work themselves by pasting the command. And since &lt;code&gt;osascript&lt;/code&gt; is a native, signed Apple binary, it slips under most commercial EDRs and even XProtect.&lt;/p&gt;
&lt;p&gt;The angle that concerns you directly: it’s the offensive return of the macOS Keychain as a prime target. You’ve learned to protect your Mac’s user password, enable FileVault, use Touch ID. But a Terminal command launched by yourself circumvents all that, because you’re the one opening the door.&lt;/p&gt;
&lt;h2 id=&quot;what-you-do-now&quot;&gt;What You Do Now&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;1.&lt;/strong&gt; Never paste a Terminal command dictated by a website, AI chat, or “official support” PDF. If you must install a tool like Claude desktop, go directly to &lt;code&gt;claude.ai/download&lt;/code&gt; by typing the URL yourself, never via a sponsored Google result. The universal rule: if someone tells you to paste anything into Terminal, it’s a no.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;2.&lt;/strong&gt; Enable Little Snitch or LuLu in hardened silent mode. Both log and block unexpected outgoing network connections to the published IOCs (&lt;code&gt;customroofingcontractors[.]com&lt;/code&gt;, &lt;code&gt;bernasibutuwqu2[.]com&lt;/code&gt;, &lt;code&gt;briskinternet[.]com&lt;/code&gt;). If you suspect a hasty command, check outgoing connections in the minutes after.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;3.&lt;/strong&gt; If you’ve run a suspicious command recently: disconnect from Wi-Fi immediately, change all your browser passwords (from a clean device), revoke all active cloud session tokens (mail, sync, password manager), scan with KnockKnock or ReiKey from Objective-See, check launch agents in &lt;code&gt;~/Library/LaunchAgents/&lt;/code&gt;.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;4.&lt;/strong&gt; Monitor your Keychain. &lt;code&gt;security dump-keychain | grep -i password&lt;/code&gt; tells you what’s inside. For the future, migrate sensitive passwords to Apple Passwords or Proton Pass, not the general iCloud Keychain by default.&lt;/p&gt;
&lt;h2 id=&quot;sources&quot;&gt;Sources&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&quot;https://www.bleepingcomputer.com/news/security/hackers-abuse-google-ads-claudeai-chats-to-push-mac-malware/&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;https://www.bleepingcomputer.com/news/security/hackers-abuse-google-ads-claudeai-chats-to-push-mac-malware/&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://objective-see.org/products/knockknock.html&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;https://objective-see.org/products/knockknock.html&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id=&quot;see-also&quot;&gt;See Also&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&quot;https://macsouverain.com/en/radar-clickfix-script-editor-avril-2026/&quot;&gt;The ClickFix script editor (the paste-and-pwn pattern)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://macsouverain.com/en/radar-sparkcat-app-store-avril-2026/&quot;&gt;SparkCat on the App Store (when Apple lets something through)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://macsouverain.com/en/little-snitch-vs-lulu-pare-feu-sortant-mac/&quot;&gt;Little Snitch vs LuLu (outgoing firewall for Mac)&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;</content:encoded><dc:creator>Mac Souverain</dc:creator><category>radar</category><category>radar-alerte</category><category>mac-malware</category><category>social-engineering</category><category>claude-ai</category><category>ingenierie-sociale</category></item><item><title>Apple patches iOS and macOS CVE vulnerabilities: fixes, then tweaks Safari profiles</title><link>https://macsouverain.com/en/radar-profils-safari-segmentation-privacy-20260513/</link><guid isPermaLink="true">https://macsouverain.com/en/radar-profils-safari-segmentation-privacy-20260513/</guid><description>iOS 26.5 fixes 98 CVEs, including 21 in WebKit; macOS Tahoe 26.5 fixes 98 CVEs, including 22. Instead of enabling Lockdown Mode everywhere, segment with a dedicated Safari profile.</description><pubDate>Wed, 13 May 2026 14:15:25 GMT</pubDate><content:encoded>&lt;div class=&quot;radar-summary&quot;&gt;
&lt;p&gt;&lt;strong&gt;iOS 26.5 and macOS Tahoe 26.5, released on May 11, fix 98 CVEs each (including 21 and 22 in WebKit). Global Lockdown Mode is overkill for daily use. Safari profiles, available since iOS 17, segment usage for you.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;What you need to watch out for&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;1.&lt;/strong&gt; Install iOS 26.5 and macOS Tahoe 26.5 today.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;2.&lt;/strong&gt; Create a “Cautious” Safari profile with only privacy extensions enabled, use it for banking, webmail, suspicious links, and medical research. Keep your default profile untouched for everything else.&lt;/p&gt;
&lt;/div&gt;
&lt;p&gt;&lt;strong&gt;Apple Publishes iOS 26.5 and macOS Tahoe 26.5, Fixing 98 CVEs&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;On May 11, Apple released iOS 26.5 and macOS Tahoe 26.5. These updates address 98 security vulnerabilities on iOS (including 21 on WebKit, Safari’s engine) and 98 on macOS (including 22 WebKit). Several of these vulnerabilities allowed malicious websites to execute code or bypass sandbox protections. As usual with Apple releases, WebKit takes the biggest hit, as it’s the largest attack surface on an iPhone or Mac.&lt;/p&gt;
&lt;p&gt;Patch now. That’s a no-brainer. The real question is, what do you do between patches, when clicking on mail links, conducting sensitive searches, or logging into online banking?&lt;/p&gt;
&lt;h2 id=&quot;why-lockdown-mode-all-the-time-is-too-much&quot;&gt;Why Lockdown Mode All the Time is Too Much&lt;/h2&gt;
&lt;p&gt;Lockdown Mode is robust. MacSouverain praised it in &lt;a href=&quot;https://macsouverain.com/en/lockdown-mode-face-a-coruna-toolkit-espionnage-gouvernemental/&quot;&gt;article 29&lt;/a&gt;. It’s perfect for journalists, dissidents, or lawyers handling sensitive cases.&lt;/p&gt;
&lt;p&gt;But for freelancers or small businesses just checking email, doing online accounting, or watching recipes, it’s overkill. Disabled JIT JavaScript, cut Safari extensions, restricted media formats, filtered Messages attachments. Too much friction, too many websites breaking. The usual result: you enable it for a few days, find it annoying, disable it, and end up with nothing.&lt;/p&gt;
&lt;h2 id=&quot;what-are-safari-profiles&quot;&gt;What are Safari Profiles?&lt;/h2&gt;
&lt;p&gt;Since iOS 17 and macOS Sonoma (September 2023), Safari supports multiple profiles within the same app. It’s been quiet, never highlighted in keynotes. Most people you talk to don’t know it exists.&lt;/p&gt;
&lt;p&gt;Each profile has its own history, cookies, enabled extensions, search engine, favorites, and tab groups. No mixing: Google’s session cookie from your “Personal” profile isn’t seen by your “Sensitive” profile. Privacy extensions active on “Sensitive” don’t slow down “Personal” navigation. Switch in two taps (tap on tabs on iPhone, Safari menu on Mac), syncs with iCloud between Mac and iPhone.&lt;/p&gt;
&lt;p&gt;It’s the usage segmentation we’ve advised for years in security, without installing a second browser.&lt;/p&gt;
&lt;h2 id=&quot;what-to-do-now&quot;&gt;What to Do Now&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;1.&lt;/strong&gt; Install iOS 26.5 and macOS Tahoe 26.5. Settings, General, Software Update. Twenty minutes, including restart.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;2.&lt;/strong&gt; Create a “Sensitive” Safari profile. On Mac: Safari, menu, Create Profile. On iPhone: Settings, Apps, Safari, Profiles, New Profile. Name, icon, color.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;3.&lt;/strong&gt; Configure the “Sensitive” profile: DuckDuckGo or Qwant search engine (setting per profile), empty favorites, and add two or three privacy extensions active &lt;strong&gt;only&lt;/strong&gt; on this profile: AdGuard for Safari (free on App Store, network and cosmetic filtering), Vinegar if you want a clean YouTube (one-time purchase), StopTheMadness Pro if you already have its license. Your default profile remains untouched, no slowdown when surfing normally.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;4.&lt;/strong&gt; What the profile &lt;strong&gt;doesn’t&lt;/strong&gt; isolate: advanced Safari settings (block all cookies, disable JavaScript, tracking block) are &lt;strong&gt;global&lt;/strong&gt;, applying to all profiles. If you want to toughen these toggles, do it globally in Settings, Apps, Safari, knowing it’ll affect your default profile too.&lt;/p&gt;
&lt;h2 id=&quot;when-to-switch-to-the-sensitive-profile&quot;&gt;When to Switch to the “Sensitive” Profile&lt;/h2&gt;
&lt;p&gt;Clicking on a link from an unknown sender. Medical or legal research. Bank or broker login. ProtonMail on the web from a less-used device. Any site you’re unsure about and don’t want to cookie your main profile with. Two taps, switch, do what you need to do, switch back.&lt;/p&gt;
&lt;p&gt;Usage segmentation, not global hardening. Keep your comfort on your default profile, have a “clean navigation” mode on hand.&lt;/p&gt;
&lt;h2 id=&quot;what-it-doesnt-replace&quot;&gt;What It Doesn’t Replace&lt;/h2&gt;
&lt;p&gt;Safari profiles aren’t Lockdown Mode. JIT JavaScript remains active on all profiles. If you’re a journalist handling sensitive sources, a lawyer on a sensitive case, a dissident, or if you’ve received an Apple threat notification, use global Lockdown Mode. Safari profiles are a tool for daily use, not state actor protection.&lt;/p&gt;
&lt;p&gt;Basic hygiene doesn’t change: patch (iOS 26.5 now), don’t open unexpected attachments, verify URLs before entering passwords.&lt;/p&gt;
&lt;h2 id=&quot;sources&quot;&gt;Sources&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&quot;https://support.apple.com/en-us/127110&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;Apple, About the security content of iOS 26.5 and iPadOS 26.5&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://support.apple.com/en-us/127115&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;Apple, About the security content of macOS Tahoe 26.5&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://support.apple.com/guide/safari/use-profiles-ibrw1011/mac&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;Apple, Use profiles in Safari (Safari User Guide)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://support.apple.com/en-us/105120&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;Apple, About Lockdown Mode&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://macsouverain.com/en/lockdown-mode-face-a-coruna-toolkit-espionnage-gouvernemental/&quot;&gt;Article 29 MacSouverain, Lockdown Mode, why to activate it&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id=&quot;see-also&quot;&gt;See Also&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&quot;https://macsouverain.com/en/lockdown-mode-face-a-coruna-toolkit-espionnage-gouvernemental/&quot;&gt;Lockdown Mode, why you should activate it&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://macsouverain.com/en/privacy-macos-les-parametres-a-changer-immediatement/&quot;&gt;Privacy macOS, settings to change&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;</content:encoded><dc:creator>Mac Souverain</dc:creator><category>radar</category><category>radar-alerte</category><category>apple</category><category>safari</category><category>webkit</category><category>privacy</category><category>ios</category><category>macos</category></item><item><title>Proton Mail switches to post-quantum encryption (and it&apos;s free)</title><link>https://macsouverain.com/en/radar-proton-mail-post-quantum-mai-2026/</link><guid isPermaLink="true">https://macsouverain.com/en/radar-proton-mail-post-quantum-mai-2026/</guid><description>Proton Mail offers a quantum-resistant encryption option, available on all plans including the free one. Must be enabled manually, but don&apos;t get your hopes up.</description><pubDate>Wed, 06 May 2026 06:39:41 GMT</pubDate><content:encoded>&lt;div class=&quot;radar-summary&quot;&gt;
&lt;p&gt;&lt;strong&gt;Proton Mail now offers an encryption option that’s quantum-resistant. Available on all plans, even the free one. You’ll need to turn it on yourself, and it only works for new emails.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;What you need to watch out for&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;1.&lt;/strong&gt; Enable the option in Settings, Encryption and keys, but don’t think it’ll protect your old emails, it only works for new ones.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;2.&lt;/strong&gt; The benefit is maxed out when the person you’re sending to is also on Proton. If they’re on Gmail or elsewhere, it’s back to classic encryption for that send.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;3.&lt;/strong&gt; End-to-end encrypted forwarding is temporarily incompatible. If you’re using it, pick one or the other until it’s fixed.&lt;/p&gt;
&lt;/div&gt;
&lt;p&gt;&lt;strong&gt;Proton Mail has just activated an option that protects your new emails against decryption by a future quantum computer. It’s available on all plans, including the free one, and you can enable it yourself. And it’s not just marketing.&lt;/strong&gt;&lt;/p&gt;
&lt;h2 id=&quot;the-fact&quot;&gt;The Fact&lt;/h2&gt;
&lt;p&gt;On May 5, 2026, Proton pushed a &lt;strong&gt;new option&lt;/strong&gt; into Proton Mail’s settings: « &lt;strong&gt;Enable post-quantum protection&lt;/strong&gt; ». Once enabled, new emails you send are encrypted with a combination of classical plus &lt;strong&gt;post-quantum algorithm&lt;/strong&gt;, a type of cryptography &lt;strong&gt;designed to resist even a quantum computer of tomorrow&lt;/strong&gt;. Available on all plans, including free, which is rare enough in the industry to warrant mention.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;The option is not enabled by default&lt;/strong&gt;. You go to Settings, Encryption and keys, and check it yourself. Proton justifies this caution due to the still-experimental status in the external ecosystem.&lt;/p&gt;
&lt;p&gt;The idea behind it is to counter what’s called « harvest now, decrypt later ». In plain terms: an attacker could intercept and store your encrypted emails today, unable to read them, hoping to decrypt them in ten or twenty years when a powerful enough quantum computer exists. Today’s classical encryption (RSA, elliptic curves) would crumble like a house of cards. Post-quantum is the insurance that even this scenario yields nothing to the attacker.&lt;/p&gt;
&lt;h2 id=&quot;why-it-matters-to-you&quot;&gt;Why It Matters to You&lt;/h2&gt;
&lt;p&gt;Several things to know before you rush to enable it.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;The protection applies only to new emails&lt;/strong&gt;. Anything already in your mailbox, sent or received before enabling, remains encrypted as before. Proton says so: &lt;em&gt;« Post-quantum protection applies to new encrypted emails going forward. It does not retroactively re-encrypt emails that are already in your mailbox, for now. »&lt;/em&gt; If your old emails have already been intercepted by someone, this option doesn’t change anything for them. The « for now » suggests a retroactive re-encryption is on the roadmap, but it’s not delivered yet.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;The recipient matters&lt;/strong&gt;. The best scenario is Proton to Proton, where both sides have post-quantum keys. If your correspondent is elsewhere (Gmail, a classic OpenPGP client, etc.), Proton falls back on the usual encryption for that send, which is the only reasonable thing to do while waiting for others to adopt the same standard.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Some friction&lt;/strong&gt;. If you’re using Proton’s end-to-end encrypted forwarding, it’s temporarily incompatible with the new option. You choose one or the other for now. There’s also a slight performance impact on sending, barely noticeable on recent hardware according to Proton.&lt;/p&gt;
&lt;h2 id=&quot;the-game-changer-angle-open-standard-vs-silos&quot;&gt;The Game-Changer Angle: Open Standard vs Silos&lt;/h2&gt;
&lt;p&gt;Proton isn’t the first email service to offer post-quantum. Tuta (ex-Tutanota) did so since 2024, with its own proprietary scheme. Apple deployed PQ3 on iMessage in February 2024. Signal did the same with PQXDH in September 2023.&lt;/p&gt;
&lt;p&gt;Proton’s difference is that it does so on &lt;strong&gt;OpenPGP&lt;/strong&gt;, the open standard others can adopt. Apple PQ3 remains locked in the Apple ecosystem, Signal PQXDH doesn’t leave Signal, and Tuta’s scheme is proprietary to Tuta. Proton, meanwhile, bets on standardization, announced collaboration with the Thunderbird project, so tomorrow your sovereign email client (Thunderbird, GnuPG, or another) can read and write post-quantum emails compatible with Proton without going through the Proton app itself.&lt;/p&gt;
&lt;p&gt;That’s the sovereignty angle. &lt;strong&gt;An open standard is what prevents your communication security from depending on the whim of a single provider&lt;/strong&gt;. Today in practice, interop is still largely Proton-to-Proton, the external ecosystem isn’t there yet. But the direction is set, and that’s what distinguishes this announcement from mere marketing.&lt;/p&gt;
&lt;h2 id=&quot;what-you-do-now&quot;&gt;What You Do Now&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;1.&lt;/strong&gt; Go to Proton Mail, Settings, Encryption and keys, and enable « &lt;strong&gt;Enable post-quantum protection&lt;/strong&gt; ». Read the warning banner (forwarding, etc.) before validating.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;2.&lt;/strong&gt; Keep in mind that &lt;strong&gt;it only protects your new sends&lt;/strong&gt;. If you have sensitive conversations archived, consider sorting them out. Retroactive re-encryption is coming later, but for now, it’s pure conditional.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;3.&lt;/strong&gt; If your correspondent is also on Proton, encourage them to enable it on their end. Until both ends are equipped, the benefit remains partial.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;4.&lt;/strong&gt; If you’re using Proton Bridge with Apple Mail (see the &lt;a href=&quot;https://macsouverain.com/en/proton-bridge-apple-mail-mac/&quot;&gt;dedicated article&lt;/a&gt;), ensure your Bridge is up-to-date, or new post-quantum emails might not be readable on the local client side.&lt;/p&gt;
&lt;h2 id=&quot;also-see&quot;&gt;Also See&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&quot;https://macsouverain.com/en/apple-mail-vs-gmail-vs-proton-mail/&quot;&gt;Apple Mail vs Gmail vs Proton Mail: Which Client for Which Use&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://macsouverain.com/en/migrer-gmail-proton-mail-mac/&quot;&gt;Migrating from Gmail to Proton Mail Without Losing Your Emails&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://macsouverain.com/en/securite-email-client-mail/&quot;&gt;Securing Your Email Client: What You Can Set Before Switching Providers&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://macsouverain.com/en/proton-bridge-apple-mail-mac/&quot;&gt;Proton Bridge Plus Apple Mail on Mac: The Combination That Works&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://macsouverain.com/en/proton-meet-visio-chiffree/&quot;&gt;Proton Meet, the Encrypted Video Call Zoom Can’t Offer&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id=&quot;sources&quot;&gt;Sources&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&quot;https://proton.me/blog/introducing-post-quantum-encryption&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;https://proton.me/blog/introducing-post-quantum-encryption&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://proton.me/support/mail-post-quantum-protection&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;https://proton.me/support/mail-post-quantum-protection&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://proton.me/blog/post-quantum-encryption&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;https://proton.me/blog/post-quantum-encryption&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://datatracker.ietf.org/doc/draft-ietf-openpgp-pqc/&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;https://datatracker.ietf.org/doc/draft-ietf-openpgp-pqc/&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://csrc.nist.gov/pubs/fips/203/final&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;https://csrc.nist.gov/pubs/fips/203/final&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;</content:encoded><dc:creator>Mac Souverain</dc:creator><category>radar</category><category>radar-signal</category><category>privacy</category><category>mail</category><category>proton</category><category>chiffrement</category><category>quantique</category><category>souverainete</category></item><item><title>iOS 26.5 finally encrypts RCS iPhone-Android (but Signal still leads)</title><link>https://macsouverain.com/en/ios-26-5-chiffrement-rcs-e2ee-iphone-android/</link><guid isPermaLink="true">https://macsouverain.com/en/ios-26-5-chiffrement-rcs-e2ee-iphone-android/</guid><description>Apple enables end-to-end encryption on RCS messages with iOS 26.5, using the MLS protocol. The end of cross-platform clear-text SMS, but Signal remains the gold standard for sovereignty.</description><pubDate>Tue, 05 May 2026 11:42:53 GMT</pubDate><content:encoded>&lt;div class=&quot;radar-summary&quot;&gt;
&lt;p&gt;&lt;strong&gt;Apple Enables End-to-End Encryption on RCS Messages with iOS 26.5&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Your iPhone-Android chats won’t be passing through clear SMS anymore. A real step forward, but RCS protocol still falls short of Signal for sensitive conversations.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;What You Need to Watch Out For&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;1.&lt;/strong&gt; Enable Advanced Data Protection on iCloud to encrypt your backups end-to-end as well.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;2.&lt;/strong&gt; Keep Signal for sensitive stuff: it’s the only one where your keys never leave your device and metadata doesn’t leak to operators or Google.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;3.&lt;/strong&gt; Make sure your Android contacts support RCS, or you’ll be back to clear SMS.&lt;/p&gt;
&lt;/div&gt;
&lt;p&gt;&lt;strong&gt;Apple finally enables end-to-end encryption for RCS messages with iOS 26.5. Your iPhone-Android exchanges are no longer in clear SMS, but the protocol still falls short of Signal for sensitive matters.&lt;/strong&gt;&lt;/p&gt;
&lt;h2 id=&quot;the-deal&quot;&gt;The Deal&lt;/h2&gt;
&lt;p&gt;Apple confirmed on May 4, 2026, that iOS 26.5 (release candidate available, stable public expected around May 11-12) integrates end-to-end encryption for RCS messages exchanged between iPhone and Android. In practice, when you send a message from your iPhone to your friend’s Samsung, the content will be encrypted E2EE according to the Universal Profile 3.0 profile, published by the GSMA in March 2025, which relies on the MLS (Messaging Layer Security) protocol, an audited IETF standard, the same foundation used for the future interoperable encryption of Matrix and other messaging platforms.&lt;/p&gt;
&lt;p&gt;Note: Apple specifies that the feature remains in beta even in iOS 26.5 stable, and it depends on operator support on both sides (iPhone and Android on RCS UP 3.0 compatible operators). A lock icon in Messages will indicate when the channel is actually encrypted, and a toggle has been added in Settings &gt; Messages.&lt;/p&gt;
&lt;p&gt;This ends a long-standing anomaly: cross-platform exchanges went through SMS/MMS, thus in plaintext, interceptable by any operator or state actor along the way. Google pushed RCS since 2019, Apple dragged its feet. The timing is no coincidence: pressure from the GSMA, operators, and repeated public criticism about the security of cross-platform SMS seems to have sped up Cupertino’s schedule.&lt;/p&gt;
&lt;h2 id=&quot;why-it-matters-to-you&quot;&gt;Why It Matters to You&lt;/h2&gt;
&lt;p&gt;If you use iMessage between Apple devices, nothing changes: your channel remains E2EE as before. The real gain is for exchanges with the Android ecosystem, which represents 70% of the global market. Until now, these conversations fell into SMS (plaintext) or MMS (destructive compression, zero encryption). With RCS E2EE, you finally get decent protection by default.&lt;/p&gt;
&lt;p&gt;But let’s keep a cool head. RCS encryption relies on operators’ and Google’s (which provides Jibe, the dominant RCS backend) infrastructure. Keys transit through their servers during session establishment. It’s not like Signal, where you control the entire chain. For sensitive conversations (lawyer, doctor, journalistic source, confidential business deal), Signal remains the gold standard: audited protocol, minimal servers, reduced metadata, open-source code.&lt;/p&gt;
&lt;p&gt;The other thing to watch: Apple hasn’t confirmed if iCloud backups of RCS conversations will be encrypted E2EE. Without Advanced Data Protection enabled, your RCS messages could end up in plaintext on Apple’s servers, nullifying the benefit of transit encryption.&lt;/p&gt;
&lt;h2 id=&quot;what-you-do-now&quot;&gt;What You Do Now&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;1.&lt;/strong&gt; &lt;strong&gt;Enable Advanced Data Protection&lt;/strong&gt; on your iCloud account (Settings &gt; Apple Account &gt; iCloud &gt; Advanced Data Protection). Without it, your backups remain accessible to Apple and judicial requests. Note: ADP covers Messages backups, but not iCloud Mail, Contacts, and Calendar, which remain outside E2EE by design.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;2.&lt;/strong&gt; &lt;strong&gt;For really sensitive conversations, stick with Signal.&lt;/strong&gt; RCS encryption is progress for everyday use, not a replacement for the sovereign gold standard.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;3.&lt;/strong&gt; &lt;strong&gt;Check if your Android contacts have RCS enabled.&lt;/strong&gt; The reliable indicator of effective encryption will be the dedicated lock icon in Messages (announced by Apple), not the bubble color (green = SMS/RCS, blue = iMessage, unrelated to E2EE). An Android on an operator that doesn’t support RCS UP 3.0 takes you back to clear SMS.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;4.&lt;/strong&gt; &lt;strong&gt;Update to iOS 26.5 once the stable release is out to enjoy the encryption.&lt;/strong&gt; Betas are nice for testing, but not for your daily driver.&lt;/p&gt;</content:encoded><dc:creator>Mac Souverain</dc:creator><category>radar</category><category>radar-signal</category><category>apple</category><category>ios</category><category>rcs</category><category>chiffrement</category><category>messagerie</category><category>signal</category></item><item><title>Trellix: Cybersecurity software partner of Europol gets source code stolen</title><link>https://macsouverain.com/en/trellix-source-code-breach-mai-2026/</link><guid isPermaLink="true">https://macsouverain.com/en/trellix-source-code-breach-mai-2026/</guid><pubDate>Sun, 03 May 2026 07:43:12 GMT</pubDate><content:encoded>&lt;div class=&quot;radar-summary&quot;&gt;
&lt;p&gt;&lt;strong&gt;Trellix, a cybersecurity partner of Europol, announced on 02/05 an unauthorized access to a portion of its source code. No evidence of exploitation, according to the vendor, but this statement needs verification.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;What you should watch out for&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;1.&lt;/strong&gt; The exact perimeter of the intrusion (affected products, duration, attribution), which Trellix has not yet communicated as of 03/05.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;2.&lt;/strong&gt; Any official communication from Trellix in the coming weeks, or the possible appearance of the code in plain sight on a forum.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;3.&lt;/strong&gt; If you have Trellix on your network, ask your reseller in writing for the list of affected products and schedule a configuration review; if you have another EDR, don’t switch vendors on a whim.&lt;/p&gt;
&lt;/div&gt;
&lt;h2 id=&quot;updates&quot;&gt;Updates&lt;/h2&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;04/05/2026, Day+2, external press confirmation on cybersecurity&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;BleepingComputer picks up Trellix’s disclosure and sets the scale: over 50,000 enterprise and government clients, over 200 million endpoints under protection. Trellix specifies that the accessed code is “product development code” and “does not include customer environments or data.” The company’s statement, to be verified like the rest, but it’s a framed assertion, not silence.&lt;/p&gt;
&lt;p&gt;No new technical details: perimeter remains unclear, intrusion duration and attribution not communicated. The “maybe it won’t come out” window is closed, the incident is now officially picked up by the reference cybersecurity press.&lt;/p&gt;
&lt;p&gt;Source: &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/trellix-discloses-data-breach-after-source-code-repository-hack/&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;BleepingComputer, 04/05/2026&lt;/a&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;h2 id=&quot;the-hunter-got-hunted&quot;&gt;The hunter got hunted&lt;/h2&gt;
&lt;p&gt;Trellix sells EDR (the thing that watches your machines’ processes to spot suspicious behavior) to enterprises and governments. Trellix is also an industry partner of Europol for major takedown operations of recent years: Endgame in November 2025 (1025+ servers Rhadamanthys, Elysium, and VenomRAT dismantled), Cobalt Strike in July 2025. John Fokker, Trellix’s threat intelligence manager, even gave an interview to The Register four weeks ago explaining how Trellix helps take down ransomware operators.&lt;/p&gt;
&lt;p&gt;On May 2, 2026, Trellix officially announced on its website that an unidentified actor had gained unauthorized access to a “portion” of its source code. Digital investigation experts mandated, authorities notified, investigation ongoing, standard phrases. It’s their own code that got lifted.&lt;/p&gt;
&lt;p&gt;You can phrase it politely, or you can phrase it frankly: the security editor that hunts attackers for Europol got its repo visited. And if you think that’s embarrassing for Trellix, you’re not wrong. If you think it’s isolated, though, you haven’t been following the news for the past decade.&lt;/p&gt;
&lt;h2 id=&quot;what-we-know-sourced&quot;&gt;What we know, sourced&lt;/h2&gt;
&lt;p&gt;According to Trellix’s &lt;a href=&quot;https://www.trellix.com/statement/&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;official statement&lt;/a&gt; published on May 2, 2026, an unidentified actor gained unauthorized access to a “portion” of its source code, with a deliberately vague perimeter. The company has mandated digital investigation experts and notified authorities. Details are picked up verbatim by &lt;a href=&quot;https://thehackernews.com/2026/05/trellix-confirms-source-code-breach.html&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;The Hacker News&lt;/a&gt;, &lt;a href=&quot;https://securityaffairs.com/191584/data-breach/trellix-discloses-the-breach-of-a-code-repository.html&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;Security Affairs&lt;/a&gt;, and several other cybersecurity press sources. For context, Trellix is an industry partner of Europol for operations Endgame (November 2025, 1025 servers Rhadamanthys, Elysium, and VenomRAT dismantled) and Cobalt Strike detour (July 2025).&lt;/p&gt;
&lt;p&gt;The story is confirmed but young. It’s a SIGNAL, not yet an ALERT.&lt;/p&gt;
&lt;h2 id=&quot;what-trellix-says-what-nobody-knows&quot;&gt;What Trellix says, what nobody knows&lt;/h2&gt;
&lt;p&gt;Trellix makes two assertions in its statement: “no evidence that source code has been exploited” and “no impact on client products or distribution pipeline.” Take these two assertions as you would any company’s statement after a breach: it’s the victim’s version. Not necessarily a lie, but not a verified fact either. “No evidence” on day one means investigators haven’t had time to dig yet.&lt;/p&gt;
&lt;p&gt;The rest is official fog.&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Unanswered questions by Trellix as of 03/05/2026&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Which products are affected (EDR, XDR, SIEM Helix, historic McAfee Enterprise or FireEye/Mandiant code)&lt;/li&gt;
&lt;li&gt;When the intrusion started, how long it lasted&lt;/li&gt;
&lt;li&gt;How it was detected (internal alert, external report, ransom demand)&lt;/li&gt;
&lt;li&gt;What platform hosted the repo (GitHub Enterprise, GitLab self-hosted, Azure DevOps)&lt;/li&gt;
&lt;li&gt;Attribution: no name, no group, nothing&lt;/li&gt;
&lt;li&gt;Customer data: radio silence, Trellix only talks about code&lt;/li&gt;
&lt;/ul&gt;
&lt;/blockquote&gt;
&lt;p&gt;None of these answers are mandatory on disclosure day, let’s be honest. The classic timeline for an incident like this takes weeks. But that’s precisely why we should trace the uncertainty now, not dilute it in a reconstructed timeline three months later, when everyone will have forgotten that no one knew anything on May 3.&lt;/p&gt;
&lt;h2 id=&quot;what-it-reminds-us-of-and-what-it-doesnt&quot;&gt;What it reminds us of (and what it doesn’t)&lt;/h2&gt;
&lt;p&gt;To frame it: a top-tier cybersecurity editor getting its source code lifted is neither new nor anecdotal. FireEye in 2020 (Sunburst, Red Team tools exfiltrated). SolarWinds the same year (poisoned build chain). Kaseya in 2021 (REvil via supply chain). CrowdStrike in July 2024 (not an intrusion, but a botched push that crashed 8.5 million Windows machines). None of these incidents are strictly comparable to what’s happening to Trellix, and that’s the point: they don’t look alike, but they tell the same structural story. &lt;strong&gt;No cybersecurity editor is a sanctuary, including those that hunt attackers for states.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;What it doesn’t remind us of, though: we don’t know if we’re looking at a Sunburst-type incident (compromised supply chain with persistence in client products) or just a repo lift (code out, no downstream impact). Trellix says the latter. The investigation will tell if that’s accurate. Until then, “Trellix says” and “confirmed” are not the same thing.&lt;/p&gt;
&lt;h2 id=&quot;what-you-do-now&quot;&gt;What you do now&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;1. If you have Trellix EDR or XDR on your fleet.&lt;/strong&gt; Set an alert calendar for 30 days to monitor Trellix communications and ask your reseller or account manager for the exact list of affected products (response often vague at first, follow up). Use this window to plan that configuration review you’ve been putting off for six months. Don’t panic, don’t uninstall in the middle of the night.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;2. If you have another EDR.&lt;/strong&gt; Don’t switch vendors on a whim. The grass isn’t greener elsewhere, ask those who switched to CrowdStrike just before July 2024. Keep monitoring, and use this incident as a reminder that your security posture can’t rely on a single layer, no matter the vendor.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;3. If you’re a Mac user.&lt;/strong&gt; It doesn’t change anything about your daily life today. Trellix isn’t a consumer product for Apple. What concerns you is the reminder: your antivirus, your EDR, your VPN, your password manager are all vendors that can get breached. Defense in depth isn’t just a slogan. Your security is open-source self-hosted and multi-layered. We’ll revisit this soon.&lt;/p&gt;</content:encoded><dc:creator>Mac Souverain</dc:creator><category>radar</category><category>radar-signal</category><category>severite-structurelle</category><category>cybersec</category><category>vendor-breach</category><category>trellix</category><category>europol</category><category>souverainete</category></item><item><title>This ransomware negotiator worked for the gang, so your backups are still your only guarantee.</title><link>https://macsouverain.com/en/negociateur-ransomware-gang-backups/</link><guid isPermaLink="true">https://macsouverain.com/en/negociateur-ransomware-gang-backups/</guid><pubDate>Fri, 01 May 2026 10:53:02 GMT</pubDate><content:encoded>&lt;div class=&quot;radar-summary&quot;&gt;
&lt;p&gt;&lt;strong&gt;An American ransomware negotiator pleaded guilty to secretly working for the gangs he was supposed to fight. This case highlights a structural issue: the entire post-incident ecosystem (negotiators, insurers, consultants) has an interest in you paying.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;What this means for you&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;1.&lt;/strong&gt; Your client-side encrypted backups (Kopia, zero-knowledge) and tested remain your only reliable guarantee, third-parties can be compromised.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;2.&lt;/strong&gt; Segment your network so ransomware can’t reach your backups. Tailscale mesh.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;3.&lt;/strong&gt; Document your response procedure BEFORE the incident, without relying on intermediaries.&lt;/p&gt;
&lt;/div&gt;
&lt;h2 id=&quot;the-deal&quot;&gt;The Deal&lt;/h2&gt;
&lt;p&gt;An American cybersecurity consultant has just pleaded guilty in a federal court. Their official job: negotiating with ransomware gangs on behalf of victim companies. Their real activity: secretly informing these same gangs about the negotiation status, victims’ payment capabilities, and sabotaging recovery attempts that could’ve avoided ransom payment.&lt;/p&gt;
&lt;p&gt;The scheme is elegantly perverse. You call an “expert” to get you out of a mess, and this expert works against you from the start. They know your financial reserves, they know your backups are useless, and they’re playing both sides.&lt;/p&gt;
&lt;p&gt;This isn’t an isolated case of a greedy individual. It’s a structural symptom of a market where everyone involved benefits from you paying. The negotiator (commission on the ransom), the cyber insurer (premium adjusted to perceived risk, not real), the gang (direct revenues). You’re the cash cow.&lt;/p&gt;
&lt;h2 id=&quot;why-this-matters-to-you&quot;&gt;Why This Matters to You&lt;/h2&gt;
&lt;p&gt;If you’re reading MacSouverain, you probably already have an aversion to unverifiable third-party trusts. This case clinically confirms why.&lt;/p&gt;
&lt;p&gt;The problem isn’t just that one guy was corrupt. The problem is that the ransomware business model creates incentives for everyone around you to prefer that you pay. Cyber insurance? It reimburses you (partially), so it doesn’t fight payment, it facilitates it. The negotiator? Paid by results, and “results” mean closing a paying deal (with commission) to restore your data.&lt;/p&gt;
&lt;p&gt;When the entire ecosystem is aligned against you, the only tenable position is not to rely on it. No negotiator if you can restore alone. No cyber insurance as the main strategy if your backups are solid. Technical autonomy first, external recours as a last resort.&lt;/p&gt;
&lt;h2 id=&quot;what-you-do-now&quot;&gt;What You Do Now&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;1.&lt;/strong&gt; Check that &lt;strong&gt;your backup strategy follows the 3-2-1-1 rule&lt;/strong&gt;: three copies, two different media, one off-site, one offline (air-gapped). Kopia encrypts everything client-side before sending (zero-knowledge), destinations (B2, S3, NAS, SFTP) see only opaque, deduplicated blobs, indecipherable without your passphrase. If the server is compromised, your repo remains unreadable.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;2.&lt;/strong&gt; Test your restoration. &lt;strong&gt;A backup never tested is as good as none&lt;/strong&gt;. Schedule a quarterly exercise where you actually restore a system from scratch.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;3.&lt;/strong&gt; Segment your network. A ransomware hitting your workstation shouldn’t have direct access to your backup NAS. &lt;strong&gt;Tailscale mesh wireguard + strict ACLs between segments&lt;/strong&gt;.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;4.&lt;/strong&gt; Document your response procedure BEFORE the incident. Who you call (and why you trust them), which machines you isolate first, where your restore keys are. Not in Notes iCloud without ADP, nor in any shared doc in plaintext.&lt;/p&gt;</content:encoded><dc:creator>Mac Souverain</dc:creator><category>radar</category><category>radar-analyse</category></item><item><title>Apple Q2 Results: Behind the Hype, the Subscription Services Question</title><link>https://macsouverain.com/en/resultats-apple-q2-derriere-l-euphorie-la-question-services/</link><guid isPermaLink="true">https://macsouverain.com/en/resultats-apple-q2-derriere-l-euphorie-la-question-services/</guid><pubDate>Fri, 01 May 2026 09:02:35 GMT</pubDate><content:encoded>&lt;div class=&quot;radar-summary&quot;&gt;
&lt;p&gt;Apple posts a solid quarter with a healthy Mac and double-digit growth in Services. For those using Apple’s ecosystem as a sovereignty pivot, it’s a confirmation: hardware remains robust, but the cloud lock-in temptation grows stronger.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;What this means for you&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;1.&lt;/strong&gt; The Mac and iPhone remain strong long-term, Apple’s in great shape.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;2.&lt;/strong&gt; Services growth means more pressure to lock you into iCloud, Apple Music, Apple One.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;3.&lt;/strong&gt; Your sovereign stack (ADP + Proton + Etebase) becomes an active choice, not a compromise.&lt;/p&gt;
&lt;/div&gt;
&lt;h2 id=&quot;the-deal&quot;&gt;The Deal&lt;/h2&gt;
&lt;p&gt;Apple’s just dropped its Q2 FY2026 results, and as Jason Snell sums it up on Six Colors: “net-net over the moon”. Translation for non-accountants, Wall Street’s thrilled and Cook can sleep easy.&lt;/p&gt;
&lt;p&gt;Macs keep cruising post-Apple Silicon with solid sales. iPhones hold their own despite a lackluster global smartphone market. iPads stay steady, which is almost a win given the tablet market’s state. But the real growth engine, the one making analysts’ eyes gleam, is Services.&lt;/p&gt;
&lt;p&gt;This catch-all category (App Store, Apple Music, iCloud, Apple TV+, Apple One, Arcade, News+, Fitness+) now makes up a significant chunk of revenue and, more importantly, margins. Apple’s not just selling hardware anymore, it’s peddling a perpetual subscription to its ecosystem.&lt;/p&gt;
&lt;h2 id=&quot;why-it-matters-to-you&quot;&gt;Why It Matters to You&lt;/h2&gt;
&lt;p&gt;Good news first, Apple hardware’s still a safe bet. If you’ve invested in a Mac Studio, MacBook Pro M3, or iPhone as your tech stack’s backbone, you’re not on a sinking ship. Apple’s financial health ensures your material investment won’t be orphaned in three years.&lt;/p&gt;
&lt;p&gt;Now, the part that deserves your critical attention: this Services growth isn’t neutral. Every percentage point gained means Apple’s grip tightens.&lt;/p&gt;
&lt;p&gt;As iCloud becomes more central, the path to Proton Drive looks like an off-road hike. The more Apple One seems “economic”, the more dependence you’re paying for with your euros.&lt;/p&gt;
&lt;p&gt;For us practical sovereignty folks, these results are a reminder. Apple’s not your ideological ally, it’s your hardware supplier. An excellent one, but a supplier nonetheless.&lt;/p&gt;
&lt;p&gt;Its Services growth is its strategy to keep you captive. Your counter-strategy? Enable Advanced Data Protection, use Proton for mail and calendar, Etebase for contacts, and be clear about what you’re voluntarily delegating versus what’s imposed by default.&lt;/p&gt;
&lt;h2 id=&quot;what-you-do-now&quot;&gt;What You Do Now&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;1.&lt;/strong&gt; Check if Advanced Data Protection is enabled on your iCloud account (Settings &gt; Apple ID &gt; iCloud &gt; Advanced Data Protection). It’s the bare minimum to keep your iCloud E2EE (&lt;a href=&quot;https://macsouverain.com/en/cloud-ordinateur-quelquun-dautre/&quot;&gt;we’ve explained why here&lt;/a&gt;).&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;2.&lt;/strong&gt; Audit your Apple One subscription if you have one. Which services are you actually using? Apple Music might justify itself, but iCloud+ beyond 50GB deserves thought.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;3.&lt;/strong&gt; Identify your critical data (passwords, pro contacts, sensitive documents) and confirm they’re passing through your sovereign stack: Vaultwarden or Proton Pass for credentials, Etebase for contacts, Proton Drive for E2EE cloud files.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;4.&lt;/strong&gt; These results don’t change anything short-term. But they confirm the direction, Apple’s pushing Services, and your vigilance needs to keep pace.&lt;/p&gt;</content:encoded><dc:creator>Mac Souverain</dc:creator><category>radar</category><category>radar-analyse</category></item><item><title>Anthropic&apos;s MCP, A design flaw exposes 200,000 instances to remote code execution</title><link>https://macsouverain.com/en/anthropic-mcp-rce-design-flaw-avril-2026/</link><guid isPermaLink="true">https://macsouverain.com/en/anthropic-mcp-rce-design-flaw-avril-2026/</guid><pubDate>Mon, 27 Apr 2026 07:05:47 GMT</pubDate><content:encoded>&lt;div class=&quot;radar-summary&quot;&gt;
&lt;p&gt;**OX Security published on April 15, 2026 a architectural vulnerability in Anthropic’s Model Context Protocol (MCP): the STDIO interface of the official SDKs allows for the execution of arbitrary OS commands from the configuration. &lt;strong&gt;7,000+ public servers, 150M+ downloads, and approximately 200,000 instances&lt;/strong&gt; are exposed. On the Mac side: Cursor, Windsurf, and Claude Desktop are concretely affected via their MCP integrations. Anthropic refuses to patch: “by design”.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;What you need to do&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;1.&lt;/strong&gt; If you’re using Cursor, Windsurf, or Claude Desktop with installed MCP servers: audit the list of connected MCPs, disable ones you haven’t explicitly verified, and &lt;strong&gt;never&lt;/strong&gt; load a MCP configuration from a third party (gist, forked GitHub repo, Slack share) without reading it entirely.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;2.&lt;/strong&gt; Update to the patched versions of the affected tools (LiteLLM, LangFlow, Windsurf, Flowise, DocsGPT, GPT Researcher, Bisheng, Agent Zero), at least 10 CVEs issued (CVE-2026-30615 Windsurf via malicious HTML, CVE-2026-30623 LiteLLM, CVE-2025-65720 GPT Researcher, etc.). Also update Cursor and Claude Desktop, which use the MCP SDKs without their own CVE.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;3.&lt;/strong&gt; If you’re hosting an exposed MCP server in a network: block public access, place it in a sandbox with restricted permissions, monitor invocations.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;4.&lt;/strong&gt; Consider &lt;strong&gt;all external MCP configs as untrusted by default&lt;/strong&gt;: Anthropic considers sandboxing the responsibility of the developer, not the protocol.&lt;/p&gt;
&lt;/div&gt;
&lt;p&gt;&lt;strong&gt;You’ve installed Cursor or Windsurf on your Mac to develop with an LLM assistant. You’ve added a few MCP servers, one for your DB, one for your API, one for local files. This stack, which seems “home-made”, is actually built on a protocol whose main interface considers that &lt;strong&gt;any configuration can run any shell command&lt;/strong&gt;. And according to OX Security, this isn’t a bug: it’s Anthropic’s official interpretation.&lt;/strong&gt;&lt;/p&gt;
&lt;h2 id=&quot;whats-happening&quot;&gt;What’s Happening&lt;/h2&gt;
&lt;p&gt;On April 15, 2026, OX Security’s research team published a report titled “The Mother of All AI Supply Chains”. The finding: Anthropic’s &lt;strong&gt;Model Context Protocol&lt;/strong&gt; (MCP) - the standard protocol for connecting tools, data, and services to an LLM - has an &lt;strong&gt;architectural flaw&lt;/strong&gt; in its STDIO interface. Configurations can directly trigger the execution of arbitrary system commands, without control, without input sanitization, without default isolation.&lt;/p&gt;
&lt;p&gt;The figures documented by OX:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;7,000+ public MCP servers&lt;/strong&gt; indexed&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;150 million+ downloads&lt;/strong&gt; of the affected SDKs and servers&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;~200,000 instances&lt;/strong&gt; estimated to be vulnerable&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;10 CVE&lt;/strong&gt; emitted (status patched or pending)&lt;/li&gt;
&lt;li&gt;Practical validation: commands executed successfully on &lt;strong&gt;6 production platforms&lt;/strong&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Notable CVEs:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;CVE-2026-30615&lt;/strong&gt; (Windsurf, pending) : prompt injection via malicious HTML leading to local RCE, CVSS 8.0 (HIGH).&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;CVE-2026-30623&lt;/strong&gt; (LiteLLM, patched) : authenticated RCE via JSON configuration.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;CVE-2025-65720&lt;/strong&gt; (GPT Researcher, pending) : UI injection leading to reverse shell.&lt;/li&gt;
&lt;li&gt;And others on LangFlow, Flowise, DocsGPT, Bisheng, Agent Zero, Fay Framework, Langchain-Chatchat, Upsonic.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;OX describes &lt;strong&gt;four distinct attack families&lt;/strong&gt;, all exploiting the same primitive: configuration → command without boundaries.&lt;/p&gt;
&lt;p&gt;Anthropic’s position, as reported by OX and confirmed by other sources (THN, devops-daily): the behavior is &lt;strong&gt;“by design”&lt;/strong&gt;. The STDIO execution model is considered “secure default” if the user does their job of sanitizing inputs. Anthropic refuses to modify the protocol.&lt;/p&gt;
&lt;h2 id=&quot;why-it-matters-to-you&quot;&gt;Why It Matters to You&lt;/h2&gt;
&lt;p&gt;You’re not an LLM cloud operator, you don’t have 50,000 public MCP servers. But if you’re a MacSouverain reader, it’s very likely that:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;You’re using Cursor, Windsurf, or Claude Desktop on your Mac&lt;/strong&gt;, all of which have official MCP integrations written with the vulnerable Anthropic SDKs.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;You’ve connected 1 or 2 MCP servers&lt;/strong&gt;, typically an MCP filesystem, an MCP DB, an MCP shell, an MCP Notion. Each of them is a potential attack surface.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;You’ve imported a shared MCP configuration&lt;/strong&gt;, a GitHub gist, a &lt;code&gt;claude_desktop_config.json&lt;/code&gt; file from a public repo, an export from a colleague. &lt;strong&gt;That’s exactly the primary vector&lt;/strong&gt;: the config can trigger execution.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Anthropic’s “by design” argument is defensible technically (a protocol isn’t a sandbox). But &lt;strong&gt;Anthropic shifts the responsibility for sandboxing to downstream developers&lt;/strong&gt;, in a context where:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;General users are adopting Claude Desktop without devsecops training.&lt;/li&gt;
&lt;li&gt;Official SDKs are published without pre-installed mitigation documentation.&lt;/li&gt;
&lt;li&gt;Patches come from downstream tools (Cursor, Windsurf, etc.), not the protocol itself.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id=&quot;what-you-need-to-do&quot;&gt;What You Need to Do&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;Immediate (this week)&lt;/strong&gt;:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;Inventory your active MCPs&lt;/strong&gt;. On Cursor: Settings → MCP. On Claude Desktop: &lt;code&gt;~/Library/Application Support/Claude/claude_desktop_config.json&lt;/code&gt;. On Windsurf: check the list from the IDE. Disable any MCP that you haven’t deployed yourself or validated by reading its source code.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;Update Cursor, Windsurf, and all LLM-native tools&lt;/strong&gt; to the patched versions (≥ April 2026). Check the release notes to ensure the relevant CVE is explicitly fixed.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;Audit shared configurations&lt;/strong&gt;: if you’ve retrieved an MCP config from a public repo, Slack, gist, Discord, &lt;strong&gt;read it entirely before activating it&lt;/strong&gt;. The executable paths, commands, environment variables. An MCP configuration is a disguised shell script.&lt;/p&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;&lt;strong&gt;Within the week&lt;/strong&gt;:&lt;/p&gt;
&lt;ol start=&quot;4&quot;&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;For the MCP filesystem or shell servers you keep&lt;/strong&gt;: limit their scope to the bare minimum. No &lt;code&gt;/&lt;/code&gt; or &lt;code&gt;~&lt;/code&gt; paths. Give the precise project-specific subfolder.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;For the MCP servers running as local HTTP servers&lt;/strong&gt;: ensure the port isn’t bound to &lt;code&gt;0.0.0.0&lt;/code&gt;. It should be &lt;code&gt;127.0.0.1&lt;/code&gt;. Otherwise, a malicious web page via browser can trigger execution.&lt;/p&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;&lt;strong&gt;To monitor&lt;/strong&gt;:&lt;/p&gt;
&lt;ol start=&quot;6&quot;&gt;
&lt;li&gt;
&lt;p&gt;Anthropic’s position may evolve if community pressure increases. Monitor the official MCP SDK’s release notes (&lt;code&gt;@modelcontextprotocol/sdk&lt;/code&gt; on npm, &lt;code&gt;mcp&lt;/code&gt; on PyPI) for a potential “strict” or “sanitize-by-default” mode.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Downstream tools (Cursor, Windsurf, Claude Desktop) may add sandboxing layers, check their security documentation in the coming weeks.&lt;/p&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;h2 id=&quot;sources&quot;&gt;Sources&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;OX Security, “The Mother of All AI Supply Chains: Critical, Systemic Vulnerability at the Core of Anthropic’s MCP”, April 15, 2026, &lt;a href=&quot;https://www.ox.security/blog/the-mother-of-all-ai-supply-chains-critical-systemic-vulnerability-at-the-core-of-the-mcp/&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;https://www.ox.security/blog/the-mother-of-all-ai-supply-chains-critical-systemic-vulnerability-at-the-core-of-the-mcp/&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;OX Security, “MCP Supply Chain Advisory: RCE Vulnerabilities Across the AI Ecosystem”, April 15, 2026, &lt;a href=&quot;https://www.ox.security/blog/mcp-supply-chain-advisory-rce-vulnerabilities-across-the-ai-ecosystem/&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;https://www.ox.security/blog/mcp-supply-chain-advisory-rce-vulnerabilities-across-the-ai-ecosystem/&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;The Hacker News, “Anthropic MCP Design Vulnerability Enables RCE, Threatening AI Supply Chain”, April 20, 2026, &lt;a href=&quot;https://thehackernews.com/2026/04/anthropic-mcp-design-vulnerability.html&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;https://thehackernews.com/2026/04/anthropic-mcp-design-vulnerability.html&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;DevOps Daily, “The MCP Design Flaw That Exposes 150M Downloads to RCE”, April 15, 2026, &lt;a href=&quot;https://devops-daily.com/posts/mcp-design-flaw-rce-supply-chain-risk&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;https://devops-daily.com/posts/mcp-design-flaw-rce-supply-chain-risk&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id=&quot;see-also&quot;&gt;See Also&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&quot;https://macsouverain.com/en/radar-claude-opus-exploit-2283-avril-2026/&quot;&gt;A Consumer-Grade AI Created a Chrome Exploit for $2,283&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://macsouverain.com/en/radar-anthropic-mythos-acces-non-autorise-avril-2026/&quot;&gt;Mythos, the Model That Finds Bugs on Its Own, Just Leaked&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;</content:encoded><dc:creator>Mac Souverain</dc:creator><category>radar</category><category>radar-alerte</category><category>anthropic</category><category>macos</category><category>securite</category><category>ia</category></item><item><title>Mythos, the model that finds bugs on its own, just leaked</title><link>https://macsouverain.com/en/radar-anthropic-mythos-acces-non-autorise-avril-2026/</link><guid isPermaLink="true">https://macsouverain.com/en/radar-anthropic-mythos-acces-non-autorise-avril-2026/</guid><pubDate>Sun, 26 Apr 2026 16:54:15 GMT</pubDate><content:encoded>&lt;div class=&quot;radar-summary&quot;&gt;
&lt;p&gt;&lt;strong&gt;Anthropic keeps a model, Mythos, under lock and key, capable of finding zero-day flaws on its own across iOS, macOS, Windows, and browsers. An unauthorized group, including an Anthropic subcontractor employee, gained access to it after the program’s announcement, via a guessed URL.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;What you need to do&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;1.&lt;/strong&gt; Install pending updates on your Mac and iPhone, and enable automatic updates.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;2.&lt;/strong&gt; Filter unknown senders in iMessage and block unknown callers on your iPhone.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;3.&lt;/strong&gt; Be wary of links and attachments, permanently.&lt;/p&gt;
&lt;/div&gt;
&lt;p&gt;&lt;strong&gt;Anthropic Locks Away Model Capable of Finding Zero-Day Flaws on Its Own&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Anthropic has kept under lock and key a model capable of finding zero-day flaws all by itself. An unauthorized group gained access to it after the program’s announcement, simply by guessing the URL. The day this capability goes from defensive to offensive, it’s no longer a movie scenario.&lt;/p&gt;
&lt;h2 id=&quot;whats-happening&quot;&gt;What’s Happening&lt;/h2&gt;
&lt;p&gt;Mythos is the name of the model Anthropic deemed too dangerous for public access. Its specialty: discovering zero-day vulnerabilities on major OSes and browsers independently, chaining multiple bugs into full exploits, conducting complex cyber ops with minimal human intervention. In internal tests, Mythos unearthed “thousands” of major vulnerabilities. Bloomberg sums it up: Mythos is far ahead of any other AI model in cyber capabilities.&lt;/p&gt;
&lt;p&gt;Access was supposed to be locked down. A limited program called “Project Glasswing” was opened to Apple, Amazon, Microsoft, and Nvidia. Some U.S. government agencies have access, but not CISA. TechCrunch and Bloomberg reported on April 21 that a small group of unauthorized users found the endpoint by guessing the URL based on Anthropic’s usual naming conventions.&lt;/p&gt;
&lt;p&gt;One of them works for a third-party subcontractor of Anthropic. The exchanges happen in a private Discord dedicated to tracking unpublished models. Regular access since the day of the announcement. No offensive use detected yet. Anthropic confirms the investigation and sees “no evidence of impact” on its systems.&lt;/p&gt;
&lt;h2 id=&quot;why-it-matters-to-you&quot;&gt;Why It Matters to You&lt;/h2&gt;
&lt;p&gt;This is the first time a publicly documented model capable of finding flaws in series has escaped its intended perimeter. For now, the intruders are just keeping watch. But the capability is in hands that shouldn’t have it, with a third-party subcontractor employee in the loop. The history of digital weapons has a constant: they start with state targets and end up on crypto phishing sites targeting individuals. An AI that finds zero-days on its own, that was worth billions five years ago. It just leaked onto a Discord.&lt;/p&gt;
&lt;p&gt;Practically, the tech that can secure macOS tomorrow can also produce an exploitable iOS exploit for an actor without an NSA budget. Anthropic finds “thousands” of vulnerabilities internally, so the stock isn’t a problem. CISA, which coordinates cyber response in the U.S., isn’t in the loop. Australia’s regulatory authority is monitoring the situation. Bloomberg even titled a podcast episode about it: “Will Mythos Save or Break the System?”&lt;/p&gt;
&lt;h2 id=&quot;what-you-need-to-do&quot;&gt;What You Need to Do&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;1. Now&lt;/strong&gt;: Update your Mac, iPhone, and Safari. Mythos targets major OSes and browsers, deployed patches close doors an AI might push. It’s not paranoia, it’s hygiene.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;2. Turn on automatic updates&lt;/strong&gt;: Settings → General → Software Update → check all (download + install + Quick Security Responses). On Mac and iPhone. The next critical patch might drop on a Tuesday at 11 PM, you don’t want to rely on it.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;3. Filter invisible vectors on iPhone&lt;/strong&gt;: Settings → Messages → “Filter Unknown Senders”. Settings → Phone → “Filter Unknown Callers”. That neutralizes doors exploits like Pegasus use to reach a phone: an iMessage or FaceTime call from an unknown number.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;4. Be wary of links and attachments&lt;/strong&gt;: Not just for the next few weeks, but from now on. An “outstanding invoice” email pushing a boobytrapped attachment doesn’t need an expert developer anymore.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;5. Keep an eye on&lt;/strong&gt;: Anthropic’s investigation progress, any potential iOS/macOS CVEs without claimed authors in the next few weeks, CISA’s statements when they break their silence.&lt;/p&gt;
&lt;h2 id=&quot;sources&quot;&gt;Sources&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&quot;https://techcrunch.com/2026/04/21/unauthorized-group-has-gained-access-to-anthropics-exclusive-cyber-tool-mythos-report-claims/&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;TechCrunch&lt;/a&gt;, April 21, 2026&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://www.bloomberg.com/news/articles/2026-04-21/anthropic-s-mythos-model-is-being-accessed-by-unauthorized-users&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;Bloomberg&lt;/a&gt;, April 21, 2026&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://www.axios.com/2026/04/21/cisa-anthropic-mythos-ai-security&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;Axios&lt;/a&gt;, April 21, 2026&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://www.bloomberg.com/news/features/2026-04-16/how-anthropic-discovered-mythos-ai-was-too-dangerous-for-release&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;Bloomberg, Mythos Background&lt;/a&gt;, April 16, 2026&lt;/li&gt;
&lt;/ul&gt;</content:encoded><dc:creator>Mac Souverain</dc:creator><category>radar</category><category>radar-alerte</category><category>securite</category><category>ia</category><category>anthropic</category></item><item><title>GPT-5.5 ups the ante in cybersecurity capacity-class. OpenAI tightens access.</title><link>https://macsouverain.com/en/radar-gpt-5-5-cybersec-high-capability-avril-2026/</link><guid isPermaLink="true">https://macsouverain.com/en/radar-gpt-5-5-cybersec-high-capability-avril-2026/</guid><pubDate>Sun, 26 Apr 2026 16:36:14 GMT</pubDate><content:encoded>&lt;div class=&quot;radar-summary&quot;&gt;
&lt;p&gt;&lt;strong&gt;OpenAI officially classifies GPT-5.5 as “High” cybersecurity capability&lt;/strong&gt;. The model can run multi-day vulnerability research campaigns, produce basic exploit memory blocks on hardened systems, and saturate professional hacking competitions. OpenAI has tightened its input filters and restricted access to modes where AI can chain multiple vulnerabilities on its own.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;What you need to watch out for&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;1.&lt;/strong&gt; Keep your Mac and iPhone strictly up-to-date. The window between bug publication and AI-assisted exploitation is closing.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;2.&lt;/strong&gt; Reduce your browser attack surface (Safari, minimum extensions, no Chrome on the main Mac).&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;3.&lt;/strong&gt; On exposed devices (frame, journalist, activist), enable Lockdown Mode, not just for GPT-5.5, but for the class of tools it represents.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;4.&lt;/strong&gt; Keep an eye on the next two major system cards (OpenAI, Anthropic). That’s where we’ll see if the Critical cybersecurity bar drops in 2026.&lt;/p&gt;
&lt;/div&gt;
&lt;p&gt;&lt;strong&gt;OpenAI has released GPT-5.5 on April 23rd and published its system card at the same time. This document formalizes what Mythos had opened the door to: large models have entered the “High” cybersecurity class. They haven’t quite reached “Critical” yet, but the gap is closing fast.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Here’s what’s happening:&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;In OpenAI’s Preparedness taxonomy, cybersecurity is divided into three tiers. “Medium” is a model that helps an attacker move faster. “High” is a model that amplifies existing severe attack paths. “Critical” is a model that opens paths no human could traverse alone, like producing functional zero-day exploits autonomously on hardened production systems.&lt;/p&gt;
&lt;p&gt;GPT-5.5 crosses the “High” threshold. The system card details why: on VulnLMP (OpenAI’s internal vulnerability testing bench), the model runs multi-day vulnerability hunting campaigns, finds exploitable memory bugs in supposedly locked-down systems, and builds the basic blocks of a functional exploit. What keeps it from “Critical” isn’t the scale of the search, but the judgment, knowing which of the thousand crashes is worth spending a week on.&lt;/p&gt;
&lt;p&gt;On closed playing fields, GPT-5.5 dominates pro hacking competitions, solves 7 out of 11 CyScenarioBench scenarios (compared to GPT-5.4’s 5), and achieves 93.33% success on cybersecurity training grounds. OpenAI’s cost per success is divided by 2.7 to 3. For OpenAI, this justifies toughening up, stricter input filters, more cybersecurity request denials, and restricted access to modes where AI chains multiple vulnerabilities together.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Why this matters to you:&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;The general public sees GPT-5.5 as a marketing update. But with the right glasses on, it’s an offensive capability milestone. In six months, we’ve gone from “AI helps a human write an exploit” to “AI runs multi-day vulnerability hunting campaigns and produces usable exploit building blocks.” The system card is explicit: this isn’t theoretical anymore, it’s measured.&lt;/p&gt;
&lt;p&gt;The model itself remains contained. What’s less contained are open-source competitors advancing in parallel and their tweaked versions circulating weekly on community platforms. For an amateur downloading an open-source model of equivalent level with removed filters, the bar is lower than you might think.&lt;/p&gt;
&lt;p&gt;On Anthropic’s side, what we know about Mythos suggests it’s already in this zone, just under lock and key (well, when it doesn’t leak. Oops, it did!). On OpenAI’s side, GPT-5.5 is still a step below, but the gap is narrowing. The threshold should be crossed in the next public system card, in six to nine months.&lt;/p&gt;
&lt;p&gt;Apple’s direct consequence is obvious. A model capable of tracking memory bugs in supposedly locked-down systems is interested, by definition, in what Apple does for iOS hardening (memory protected against manipulations since iPhone 15 Pro and Mac M2, app isolation on macOS, system locked in read-only). As long as Apple maintains its lead on the attack surface, your up-to-date Mac is very hard to compromise, but the gap is now measured in weeks, not months.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;What you need to do:&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;1. Immediately:&lt;/strong&gt; Update macOS, iOS, Safari, and all your third-party browsers. The gap between CVE publication and IA-assisted exploitation has shrunk, each patch counts more than it did six months ago.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;2. Reduce your browser attack surface:&lt;/strong&gt; Use Safari in strict mode, minimize extensions, and especially don’t use Chrome on your main Mac.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;3. If you’re exposed&lt;/strong&gt; (journalist, activist, executive, crypto holder): Enable Lockdown Mode on iPhone and Mac.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;4. Keep an eye on:&lt;/strong&gt; The next OpenAI and Anthropic system cards. If either of them crosses into “Critical” cybersecurity in a public system card, it’s time to re-evaluate your update and backup practices, not panic, but tighten the screws.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Sources:&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&quot;https://deploymentsafety.openai.com/gpt-5-5&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;OpenAI, GPT-5.5 System Card&lt;/a&gt;, April 23, 2026&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://openai.com/index/gpt-5-5-system-card/&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;OpenAI, GPT-5.5 System Card (main hub)&lt;/a&gt;, April 23, 2026&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://www.cnbc.com/2026/04/23/openai-announces-latest-artificial-intelligence-model.html&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;CNBC, OpenAI announces GPT-5.5&lt;/a&gt;, April 23, 2026&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://techcrunch.com/2026/04/23/openai-chatgpt-gpt-5-5-ai-model-superapp/&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;TechCrunch, GPT-5.5 superapp&lt;/a&gt;, April 23, 2026&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;strong&gt;See also:&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&quot;https://macsouverain.com/en/radar-anthropic-mythos-acces-non-autorise-avril-2026/&quot;&gt;The model that finds bugs all by itself just leaked&lt;/a&gt;, April 21, 2026&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://macsouverain.com/en/radar-claude-opus-exploit-2283-avril-2026/&quot;&gt;Claude Opus turns a bug into an exploit for $22&lt;/a&gt;, April 2026&lt;/li&gt;
&lt;/ul&gt;</content:encoded><dc:creator>Mac Souverain</dc:creator><category>radar</category><category>radar-signal</category><category>securite</category><category>ia</category><category>openai</category></item><item><title>A consumer-grade AI cooked up a Chrome exploit for $2,283.</title><link>https://macsouverain.com/en/radar-claude-opus-exploit-2283-avril-2026/</link><guid isPermaLink="true">https://macsouverain.com/en/radar-claude-opus-exploit-2283-avril-2026/</guid><pubDate>Wed, 22 Apr 2026 16:02:04 GMT</pubDate><content:encoded>&lt;div class=&quot;radar-summary&quot;&gt;
&lt;p&gt;&lt;strong&gt;A researcher asked Claude Opus 4.6, the same model accessible to anyone for a monthly subscription, to create code to exploit a fixed Chrome bug. Result: Discord opens your Mac’s calculator without your permission. Researchers’ security convention: if calc opens without asking, anything can open. Discord, Slack, Teams, Notion all run on Chrome under the hood and patch late. Operation cost: $2,283.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;What you need to do&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;1.&lt;/strong&gt; Update Chrome, Safari, Firefox, Edge on your Mac tonight.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;2.&lt;/strong&gt; Open Discord, Slack, Teams and check they’re running the latest version.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;3.&lt;/strong&gt; Uninstall any abandoned app (no update in over 6 months).&lt;/p&gt;
&lt;/div&gt;
&lt;p&gt;&lt;strong&gt;What’s happening&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Starting point: a bug in Chrome, fixed and made public. In the security world, “fixed publicly” means the exact nature of the problem is now accessible to everyone, in Google’s official database. Not a secret, a known flaw, documented, with the fix readable by anyone.&lt;/p&gt;
&lt;p&gt;Mohan Pedhapati, a security researcher at Hacktron, submitted this bug to Claude Opus 4.6 with a simple question: build me the code to exploit it.&lt;/p&gt;
&lt;p&gt;After 20 hours and 1,765 exchanges with the model: a program that runs in Discord and opens your Mac’s calculator. No data theft, no destruction. The calculator. That’s the security researchers’ tradition: when they want to prove a vulnerability lets someone run a program on your machine without your permission, they prove it by opening calc. Harmless, but eloquent: if someone can open the calculator without asking, they can just as well run anything else.&lt;/p&gt;
&lt;p&gt;Total bill: $2,283. The model that counts calories in your recipes can also, with guidance and patience, write a browser exploit.&lt;/p&gt;
&lt;h2 id=&quot;why-its-important-for-you&quot;&gt;Why it’s important for you&lt;/h2&gt;
&lt;p&gt;“In Discord” isn’t incidental. Discord, Slack, Teams, Notion, Spotify, VS Code: none of these apps are native. They’re web apps disguised, built on Chrome’s engine. Result: when Chrome fixes a bug, these apps keep running on the old version until they update on their own. Discord was still running on a vulnerable Chrome version when Pedhapati published his exploit. The official fix had been available for weeks.&lt;/p&gt;
&lt;p&gt;The implications are wide. Before this study, turning a fixed bug into a functional exploit took years of specialized expertise. Now, it takes $2,283 and someone who knows how to ask the right questions to a model. The list of fixed Chrome bugs is public. The list of apps lagging in patches is too.&lt;/p&gt;
&lt;p&gt;It’s exactly what Schneier described as &lt;em&gt;inevitable&lt;/em&gt; about &lt;a href=&quot;https://www.schneier.com/blog/archives/2026/04/on-anthropics-mythos-preview-and-project-glasswing.html&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;Mythos&lt;/a&gt;, and it’s happening, not with a military model.&lt;/p&gt;
&lt;h2 id=&quot;what-you-need-to-do&quot;&gt;What you need to do&lt;/h2&gt;
&lt;p&gt;→ &lt;strong&gt;Immediate&lt;/strong&gt;: update Chrome, Safari, Firefox, Edge on your Mac tonight. The latest Chrome version fixes the exact bug used in the study, but the point is there will be others like it. Otherwise, do what I do: uninstall Chrome and switch to Safari. But that’s another conversation.&lt;/p&gt;
&lt;p&gt;→ &lt;strong&gt;This week&lt;/strong&gt;: review the “web disguised” apps on your Mac. Discord, Slack, Teams, Notion, Spotify, VS Code, 1Password desktop if you still use it. For each, check preferences to ensure automatic updates are on and you’re running the latest version. An app that’s abandoned or rarely updated becomes a prime target.&lt;/p&gt;
&lt;p&gt;→ &lt;strong&gt;To watch&lt;/strong&gt;: the reaction of Discord, Slack, and others to the update frequency of their internal engine. The arrival of commercial services packaging this kind of experimentation, today a researcher in a lab, tomorrow a product on the darknet. The first real campaigns using AI-assisted browser exploits against poorly maintained apps. If it happens, that’ll be another conversation.&lt;/p&gt;
&lt;h2 id=&quot;sources&quot;&gt;Sources&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&quot;https://securityaffairs.com/191018/ai/ai-model-claude-opus-turns-bugs-into-exploits-for-just-2283.html&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;Security Affairs&lt;/a&gt; - April 20, 2026&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://www.hacktron.ai/blog/i-let-claude-opus-to-write-me-a-chrome-exploit&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;Hacktron Study - Pedhapati&lt;/a&gt; - April 20, 2026&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://www.schneier.com/blog/archives/2026/04/on-anthropics-mythos-preview-and-project-glasswing.html&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;Schneier on Mythos&lt;/a&gt; - April 13, 2026 (context)&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id=&quot;also-see&quot;&gt;Also see&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;[[radar-extensions-chrome-malveillantes-avril-2026|Malicious Chrome Extensions]]&lt;/li&gt;
&lt;li&gt;[[radar-tcc-macl-avril-2026|TCC macOS: Permission Bypass]]&lt;/li&gt;
&lt;li&gt;[[radar-agents-ia-anssi-avril-2026|AI Agents: ANSSI Risks]]&lt;/li&gt;
&lt;/ul&gt;
&lt;hr&gt;
&lt;h2 id=&quot;mastodon-post&quot;&gt;Mastodon Post&lt;/h2&gt;
&lt;p&gt;🚨 Claude Opus 4.6 (public subscription) has fabricated a functional Chrome exploit.&lt;/p&gt;
&lt;p&gt;Security researchers’ convention: prove a vulnerability by opening the target machine’s calculator without permission. If calc opens without asking, anything can open.&lt;/p&gt;
&lt;p&gt;Result here: Discord opens your calculator without authorization. 20 hours of work, 1,765 model exchanges, for $2,283.&lt;/p&gt;
&lt;p&gt;Discord, Slack, Teams, Notion run on Chrome under the hood. They patch late.&lt;/p&gt;
&lt;p&gt;1️⃣ Update Chrome, Safari, Firefox, Edge tonight
2️⃣ Update Discord, Slack, Teams, Notion, VS Code
3️⃣ Uninstall abandoned apps&lt;/p&gt;
&lt;p&gt;Not the NSA’s Claude Mythos. Your recipes’ Claude, that’s scary.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://macsouverain.com/en/radar-claude-opus-exploit-2283-avril-2026/&quot;&gt;https://macsouverain.com/radar-claude-opus-exploit-2283-avril-2026/&lt;/a&gt;&lt;/p&gt;
&lt;h1 id=&quot;ai-security-chrome-mac&quot;&gt;AI #security #Chrome #Mac&lt;/h1&gt;</content:encoded><dc:creator>Mac Souverain</dc:creator><category>radar</category><category>radar-alerte</category><category>securite</category><category>ia</category><category>chrome</category><category>electron</category></item><item><title>Age verification EU, hacked in 2 minutes, poorly coded surveillance</title><link>https://macsouverain.com/en/radar-eu-age-verification-hackee-avril-2026/</link><guid isPermaLink="true">https://macsouverain.com/en/radar-eu-age-verification-hackee-avril-2026/</guid><description>Paul Moore skirts the EU&apos;s age-verification app in under 2 minutes. The EUDI standard promised zero-knowledge. Its implementation stores the PIN in an editable XML.</description><pubDate>Wed, 22 Apr 2026 10:19:10 GMT</pubDate><content:encoded>&lt;div class=&quot;radar-summary&quot;&gt;
&lt;p&gt;&lt;strong&gt;The EU’s Age Verification App, launched on April 14th, was bypassed in under two minutes. Editable config, boolean for biometry, PIN not linked to identity vault. The EUDI Wallet standard had zero-knowledge (SD-JWT VC, IRMA/Yivi, AnonCreds) in mind. Yet, the implementation ignored it.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;The Real Scandal&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;The EU wrote the right standard. The reference app betrayed it.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Keep an Eye On&lt;/strong&gt;, same EUDI architecture set to be used tomorrow for IDs, prescriptions, taxes, 450 million Europeans.&lt;/p&gt;
&lt;/div&gt;
&lt;p&gt;&lt;strong&gt;The EU’s age verification app, launched on April 14, 2026, was bypassed in under two minutes. The real scandal isn’t the bug, it’s the implementation choice.&lt;/strong&gt;&lt;/p&gt;
&lt;h2 id=&quot;the-facts&quot;&gt;The Facts&lt;/h2&gt;
&lt;p&gt;On &lt;strong&gt;April 14&lt;/strong&gt;, the Commission unveils its age verification app, a cornerstone of the online child protection system across the 27 member states. Three days later, British consultant &lt;strong&gt;Paul Moore&lt;/strong&gt; publishes a demo, completely bypassing it in &lt;strong&gt;under two minutes&lt;/strong&gt;. French cryptographer &lt;strong&gt;Olivier Blazy&lt;/strong&gt; confirms the diagnosis. A moratorium signed by &lt;strong&gt;400+ researchers&lt;/strong&gt; had already warned in March. No one listened.&lt;/p&gt;
&lt;h2 id=&quot;the-three-flaws&quot;&gt;The Three Flaws&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Editable config&lt;/strong&gt;, the encrypted PIN is stored in &lt;code&gt;eudi-wallet.xml&lt;/code&gt;, locally modifiable.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Boolean biometrics&lt;/strong&gt;, a &lt;code&gt;true/false&lt;/code&gt; flag governs biometric auth. Flip, skip.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;PIN not linked to the vault&lt;/strong&gt;, an attacker redefines the PIN by reusing previous profile credentials.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id=&quot;the-alternative-existed-within-the-standard-itself&quot;&gt;The Alternative Existed, Within the Standard Itself&lt;/h2&gt;
&lt;p&gt;The EUDI Wallet standard allows for &lt;strong&gt;selective disclosure&lt;/strong&gt; via SD-JWT VC (Selective Disclosure JSON Web Token Verifiable Credentials), proving one’s age without revealing birthdate or linking sessions, using zero-knowledge proofs. Implementations like &lt;strong&gt;IRMA/Yivi&lt;/strong&gt; (Radboud University), &lt;strong&gt;AnonCreds&lt;/strong&gt; (Hyperledger), and &lt;strong&gt;Google ZK age assurance&lt;/strong&gt; already exist.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;The EU wrote the right standard. The reference app betrayed it by storing the PIN in an editable XML.&lt;/strong&gt;&lt;/p&gt;
&lt;h2 id=&quot;the-pattern&quot;&gt;The Pattern&lt;/h2&gt;
&lt;p&gt;Same logic as &lt;strong&gt;Chat Control / CSAR&lt;/strong&gt;, Brussels pushes a surveillance infrastructure, no one audits it upfront, beginner-level flaw. The EUDI Wallet will soon manage IDs, prescriptions, fiscal signatures for 450 million Europeans. A trivial flaw today isn’t just an incident, it’s a warning.&lt;/p&gt;
&lt;p&gt;Digital sovereignty means the &lt;strong&gt;right to not prove one’s age at every click&lt;/strong&gt;. And if we must, then via ZKP, not via a finger-in-the-dyke XML.&lt;/p&gt;
&lt;h2 id=&quot;to-read-on-macsouverain&quot;&gt;To Read on MacSouverain&lt;/h2&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;em&gt;Read: &lt;a href=&quot;https://macsouverain.com/en/chat-control-csar-surveillance-messageries-chiffrees/&quot;&gt;Chat Control 2, the mass surveillance that doesn’t say its name&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;em&gt;Read: &lt;a href=&quot;https://macsouverain.com/en/nis2-csar-contradiction-ue-chiffrement-surveillance/&quot;&gt;NIS2 vs CSAR, two opposing security logics&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;
&lt;/blockquote&gt;</content:encoded><dc:creator>Mac Souverain</dc:creator><category>radar</category><category>surveillance</category><category>ue</category><category>privacy</category></item><item><title>The FBI got their hands on deleted Signal messages. Cheers, iPhone notifications.</title><link>https://macsouverain.com/en/radar-signal-notifications-iphone-avril-2026/</link><guid isPermaLink="true">https://macsouverain.com/en/radar-signal-notifications-iphone-avril-2026/</guid><description>The FBI reassembled deleted Signal messages via iPhone push notification metadata. End-to-end encryption didn&apos;t make a difference.</description><pubDate>Tue, 21 Apr 2026 06:20:56 GMT</pubDate><content:encoded>&lt;div class=&quot;radar-summary&quot;&gt;
&lt;p&gt;&lt;strong&gt;The FBI rebuilt deleted Signal messages via iPhone push notifications. Apple keeps these metadata and hands them over on demand. End-to-end encryption in Signal doesn’t matter because the leak happens elsewhere.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;What you need to do&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;1.&lt;/strong&gt; Signal: Settings → Notifications → “No Name or Content”, the app won’t inject anything into the push payload anymore.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;2.&lt;/strong&gt; iOS: Settings → Notifications → Previews → Never, you cut content for all apps at once.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;3.&lt;/strong&gt; Check other messaging apps (Messages, WhatsApp), apply the same settings.&lt;/p&gt;
&lt;/div&gt;
&lt;p&gt;&lt;strong&gt;An American judicial document confirms what privacy researchers have been saying since 2023: iPhone push notifications are a backdoor for accessing encrypted message content, even after it’s been deleted by the user. Signal is doing its job correctly. Apple is too, technically. It’s the combination of the two that betrays you.&lt;/strong&gt;&lt;/p&gt;
&lt;h2 id=&quot;whats-happening&quot;&gt;What’s happening&lt;/h2&gt;
&lt;p&gt;In early April 2026, &lt;a href=&quot;https://9to5mac.com/2026/04/09/fbi-used-iphone-notification-data-to-retrieve-deleted-signal-messages/&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;9to5Mac&lt;/a&gt; reported on a federal American case. The FBI was investigating an individual, requested iCloud push notification data from Apple, and was able to reconstruct the content of received Signal messages that the target had deleted from their device.&lt;/p&gt;
&lt;p&gt;The mechanism is simple. When a message arrives on Signal, the app triggers a push notification. This notification passes through APNs, Apple’s notification service. If the user has the default preview setting, the message content is sent in plaintext within the notification payload. Apple stores these metadata for an unspecified duration and, upon judicial order, hands them over to authorities.&lt;/p&gt;
&lt;p&gt;The &lt;a href=&quot;https://www.eff.org/deeplinks/2026/04/how-push-notifications-can-betray-your-privacy-and-what-do-about-it&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;EFF&lt;/a&gt; published an in-depth analysis on April 16. The conclusion is clear: it’s not a bug in Signal, nor is it a bug in Apple; it’s the very architecture of the notification system that creates a blind spot. Signal encrypts messages end-to-end. Apple delivers the notification. In between, there’s a server relay that sees the content if you haven’t locked it at the source.&lt;/p&gt;
&lt;p&gt;Senator Ron Wyden had already raised the alarm in December 2023, revealing that the US government regularly requests this data from Apple and Google. Three years later, we finally have proof that the technique has been used to access Signal conversations. And it works even after user-side deletion.&lt;/p&gt;
&lt;h2 id=&quot;why-this-matters-to-you&quot;&gt;Why this matters to you&lt;/h2&gt;
&lt;p&gt;You can have the best end-to-end encryption in the world. If the notification that lands on your lock screen contains the phrase “Meet at 9 PM at the usual address,” that phrase exists somewhere on an Apple server before it reaches you. And that “somewhere” is accessible via a warrant.&lt;/p&gt;
&lt;p&gt;This isn’t a scenario for dissident journalists or activists. It’s how your iPhone works by default today. Notifications have previews, sender names are displayed, and the first line of the message is readable from the lock screen. Convenient, very convenient. As convenient for you as it is for any institutional actor.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;The kicker: it survives deletion.&lt;/strong&gt; You delete the conversation on Signal, it disappears from your phone, and it never existed on Signal’s servers. Perfect.&lt;/p&gt;
&lt;p&gt;But the notification announcing that message? It left a trace with Apple. That trace is more ephemeral than your emails, but it’s sufficient to reconstruct a conversation if the request comes within the right time window.&lt;/p&gt;
&lt;p&gt;The 9to5Mac case involves the FBI and an individual pursued in the US. But the mechanism is universal. Any authority that can compel Apple to hand over iCloud data can, in principle, access these metadata. American jurisdiction, CLOUD Act, no need for a schema.&lt;/p&gt;
&lt;p&gt;The irony is cruel. You chose Signal for maximum privacy. You enabled ephemeral messages. You were diligent. And you’re betrayed by an iOS setting that no one ever presented to you as a security issue.&lt;/p&gt;
&lt;h2 id=&quot;what-you-need-to-do&quot;&gt;What you need to do&lt;/h2&gt;
&lt;p&gt;Two settings, five minutes, and the leak is plugged.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;1. Immediately&lt;/strong&gt;: Signal &gt; Settings &gt; Notifications &gt; “No Name or Content”. The app stops injecting the sender’s name and content into the notification. You know a Signal message has arrived, but you don’t know who it’s from or what it says until you open the app.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;2. Within the week&lt;/strong&gt;: iOS &gt; Settings &gt; Notifications &gt; Previews &gt; Never. You disable content previews for all apps at once, including Messages, Mail, WhatsApp, and the rest. Slightly degraded convenience, massively reduced exposure surface.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;3. If you want to go further&lt;/strong&gt;: spend thirty minutes going through the privacy settings on macOS and iOS. Most blind spots can be addressed once and last for years.&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;em&gt;Read: &lt;a href=&quot;https://macsouverain.com/en/privacy-macos-les-parametres-a-changer-immediatement/&quot;&gt;Privacy macOS, the settings to change immediately&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;&lt;em&gt;Need tech terms explained? &lt;a href=&quot;https://macsouverain.com/en/glossaire/&quot;&gt;Check the glossary.&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;</content:encoded><dc:creator>Mac Souverain</dc:creator><category>radar</category><category>radar-signal</category><category>securite</category><category>privacy</category></item><item><title>Your Mac says &quot;No Access&quot; for an app, but it&apos;s still reading your files. Since 2019.</title><link>https://macsouverain.com/en/radar-tcc-macl-avril-2026/</link><guid isPermaLink="true">https://macsouverain.com/en/radar-tcc-macl-avril-2026/</guid><description>macOS secretly logs access to your files whenever you use the Open/Save dialog. The Privacy &amp; Security interface doesn&apos;t show this. Since 2019.</description><pubDate>Fri, 17 Apr 2026 06:06:48 GMT</pubDate><content:encoded>&lt;div class=&quot;radar-summary&quot;&gt;
&lt;p&gt;&lt;strong&gt;macOS keeps a permanent access to your files when an app uses the native Open/Save dialog. This access is separate from the Privacy &amp;#x26; Security settings. You revoke the app’s access in the settings, it disappears from the list, but it still reads your files. Since 2019.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;What you need to do&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;1.&lt;/strong&gt; Check which apps have accessed your protected folders via Terminal: &lt;code&gt;xattr -l ~/Desktop | grep com.apple.macl&lt;/code&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;2.&lt;/strong&gt; To revoke ghost access: copy the file to another volume, delete the original, then copy it back, the attribute doesn’t follow.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;3.&lt;/strong&gt; Review your Mac’s privacy settings with our dedicated guide, keeping in mind that these settings don’t cover this mechanism.&lt;/p&gt;
&lt;/div&gt;
&lt;p&gt;&lt;strong&gt;When you open a file via the native selector of an app, macOS writes an attribute directly to the file. This attribute grants the app permanent access, independent of the Privacy &amp;#x26; Security settings. You can revoke the app in the System Preferences, the interface will display “No Access”, and the app will continue to read. Since 2019. Without you knowing.&lt;/strong&gt;&lt;/p&gt;
&lt;h2 id=&quot;whats-happening&quot;&gt;What’s Happening&lt;/h2&gt;
&lt;p&gt;Howard Oakley, a renowned macOS researcher and author of the blog &lt;a href=&quot;https://eclecticlight.co/2026/04/10/why-you-cant-trust-privacy-security/&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;Eclectic Light&lt;/a&gt;, published a demonstration in early April 2026 that sums up the situation in one sentence: the Privacy &amp;#x26; Security interface of macOS lies about the real access of applications to your files.&lt;/p&gt;
&lt;p&gt;The mechanism is called &lt;code&gt;com.apple.macl&lt;/code&gt;. It’s an extended attribute, a small marker that macOS sticks directly onto the targeted file or folder. It’s created automatically when you use the Open/Save selector of an app, when you drag and drop from the Finder, or when you double-click on a file to open it with an app.&lt;/p&gt;
&lt;p&gt;This attribute contains two identifiers: one for the app, one for the file. Once set, the app can access the file without passing through the permission checkpoint. It’s managed by the kernel (Sandbox.kext), not the classic TCC system that feeds the settings you see in System Preferences.&lt;/p&gt;
&lt;p&gt;And that’s where it gets sticky. System Preferences &gt; Privacy &amp;#x26; Security only reads the TCC database. It doesn’t see the &lt;code&gt;com.apple.macl&lt;/code&gt; attributes. Result: you revoke an app’s access in the settings, the interface displays “No Access”, and the app keeps its access via the xattr. Oakley demonstrated this with his test tool &lt;a href=&quot;https://eclecticlight.co/2026/04/10/why-you-cant-trust-privacy-security/&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;Insent&lt;/a&gt;, notarized by Apple, reproducible by anyone.&lt;/p&gt;
&lt;h2 id=&quot;why-it-matters-to-you&quot;&gt;Why It Matters to You&lt;/h2&gt;
&lt;p&gt;This isn’t a bug. Apple introduced this mechanism at the &lt;a href=&quot;https://developer.apple.com/videos/play/wwdc2019/701/?time=1460&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;WWDC 2019 (Session 701)&lt;/a&gt; under the name “User Intent”, opposed to the classic “User Consent” of the TCC system. The idea: when you explicitly choose a file in the selector, your action is a permanent authorization. No need to ask again.&lt;/p&gt;
&lt;p&gt;The problem isn’t the principle. It’s that the interface supposed to show you who has access to what completely ignores this channel. You think you have a faithful dashboard of your authorizations. In reality, you’re looking at half the picture.&lt;/p&gt;
&lt;p&gt;And this mechanism has been active since macOS Catalina (2019). Seven years. Confirmed functional on Tahoe (macOS 26). Never publicly documented by Apple in a complete manner. Jeff Johnson, a macOS developer, wrote in 2019: “there’s no documentation of this important privacy protections change.”&lt;/p&gt;
&lt;p&gt;In practical terms, it means that every time you’ve used Open/Save, drag and drop, or double-click to access a file in Desktop, Documents, or Downloads, the app potentially received a persistent access that the macOS settings don’t reflect.&lt;/p&gt;
&lt;p&gt;A Hacker News thread with 511 points confirms the surprise in the technical community. Several developers report that Apple classified the behavior as “expected behavior” when it was reported.&lt;/p&gt;
&lt;h2 id=&quot;what-you-should-do&quot;&gt;What You Should Do&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;Practically:&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;1.&lt;/strong&gt; Check if your protected folders have macl attributes. Open Terminal and type: &lt;code&gt;xattr -l ~/Desktop | grep com.apple.macl&lt;/code&gt; Repeat for &lt;code&gt;~/Documents&lt;/code&gt; and &lt;code&gt;~/Downloads&lt;/code&gt;. If you see results, apps have a persistent, invisible access in the settings.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;2.&lt;/strong&gt; To revoke a macl access on a sensitive file, the most accessible method: copy the file to another volume (USB key, external disk, other partition), delete the original, recopy the file. The copy doesn’t inherit the &lt;code&gt;com.apple.macl&lt;/code&gt; xattr. It’s artisanal, but it works.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;3.&lt;/strong&gt; The technical alternative: boot in Recovery mode and run &lt;code&gt;xattr -d com.apple.macl &amp;#x3C;file_path&gt;&lt;/code&gt;. This requires temporarily disabling SIP, which isn’t trivial. Reserve for users who know what they’re doing.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;4.&lt;/strong&gt; &lt;code&gt;tccutil reset All &amp;#x3C;bundle_id&gt;&lt;/code&gt; followed by a reboot doesn’t suffice. This command resets the TCC database, not the macl xattrs. Oakley himself acknowledges this in his article. The reboot alone doesn’t change anything either, the attribute is embedded in the file system, it survives the reboot.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;5.&lt;/strong&gt; Review the privacy settings on your Mac. They remain useful for controlling the TCC channel (location, microphone, camera, contacts). But keep in mind that they don’t cover this second access channel.&lt;/p&gt;
&lt;p&gt;Article #16 guides you through the settings you control. This Radar shows you the ones you don’t control, at least not through the intended interface.&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;em&gt;Read: &lt;a href=&quot;https://macsouverain.com/en/privacy-macos-les-parametres-a-changer-immediatement/&quot;&gt;macOS Privacy: The Settings to Change Immediately&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;&lt;em&gt;Technical terms? &lt;a href=&quot;https://macsouverain.com/en/glossaire/&quot;&gt;Check the glossary.&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;
&lt;h2 id=&quot;sources&quot;&gt;Sources&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&quot;https://eclecticlight.co/2026/04/10/why-you-cant-trust-privacy-security/&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;Eclectic Light&lt;/a&gt;, &lt;em&gt;Why you can’t trust Privacy &amp;#x26; Security&lt;/em&gt;, Howard Oakley, 10 April 2026&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://developer.apple.com/videos/play/wwdc2019/701/?time=1460&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;Apple WWDC 2019 Session 701&lt;/a&gt;, &lt;em&gt;Advances in macOS Security&lt;/em&gt;, 2019&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://blog.xpnsec.com/we-need-to-talk-about-macl/&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;XPN InfoSec&lt;/a&gt;, &lt;em&gt;We Need To Talk About MACL&lt;/em&gt;, ~2020&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://news.ycombinator.com/item?id=47719602&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;Hacker News&lt;/a&gt;, discussion (511 points), April 2026&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://lapcatsoftware.com/articles/macl.html&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;lapcatsoftware&lt;/a&gt;, &lt;em&gt;Persistent File Access via com.apple.macl xattr&lt;/em&gt;, Jeff Johnson, 2019&lt;/li&gt;
&lt;/ul&gt;</content:encoded><dc:creator>Mac Souverain</dc:creator><category>radar</category><category>radar-alerte</category><category>privacy</category><category>macos</category></item><item><title>108 Chrome extensions trapped, your Google and Telegram too</title><link>https://macsouverain.com/en/radar-extensions-chrome-malveillantes-avril-2026/</link><guid isPermaLink="true">https://macsouverain.com/en/radar-extensions-chrome-malveillantes-avril-2026/</guid><description>108 malicious Chrome extensions identified in the Chrome Web Store by Socket researchers. Google OAuth theft, backdoors, Telegram exfiltration. Google notified, extensions still online at publication. If you&apos;re using Chrome on Mac, you&apos;re affected.</description><pubDate>Thu, 16 Apr 2026 06:37:00 GMT</pubDate><content:encoded>&lt;div class=&quot;radar-summary&quot;&gt;
&lt;p&gt;&lt;strong&gt;108 malicious extensions identified in the Chrome Web Store, with around 20,000 cumulative installations. They steal Google and Telegram tokens and install backdoors. Google was notified but the extensions were still online at the time of the report. If you’ve installed a Chrome extension recently, the damage may already be done.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;What you need to watch out for&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;1.&lt;/strong&gt; Audit your Chrome extensions and uninstall anything you don’t use regularly.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;2.&lt;/strong&gt; Log out of active Google sessions from myaccount.google.com, under Security.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;3.&lt;/strong&gt; Revoke Telegram sessions from Settings, Devices, on any client.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;4.&lt;/strong&gt; Seriously consider using Safari as your default browser on Mac.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; &lt;a href=&quot;https://socket.dev/blog/108-chrome-ext-linked-to-data-exfil-session-theft-shared-c2&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;108 Chrome Extensions Linked to Data Exfiltration&lt;/a&gt; (Socket, 2026-04)&lt;/p&gt;
&lt;/div&gt;
&lt;p&gt;&lt;strong&gt;Mid-April 2026, Socket researchers identify 108 malicious Chrome extensions in the Chrome Web Store, with around 20,000 cumulative installations. Google OAuth theft, universal backdoors, Telegram exfiltration. Extensions were still online at the time of public disclosure. If you’re using Chrome on Mac, and most Mac users are, you’re directly affected.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;What’s happening&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Socket researchers found 108 extensions published in the Chrome Web Store under five different publisher aliases (Yana Project, GameGen, SideGames, Rodeo Games, InterAlt) to throw off suspicion. Public disclosure on April 13, 2026. Extensions remained online despite Google’s notification.&lt;/p&gt;
&lt;p&gt;The haul is varied and precise enough for mass work. 54 extensions retrieved Google OAuth tokens, those little keys that let a third-party service access your Google account without you re-entering your password.&lt;/p&gt;
&lt;p&gt;Another 45 contained a universal backdoor that opens arbitrary URLs upon browser launch, perfect for pushing phishing or malicious content on demand.&lt;/p&gt;
&lt;p&gt;And one dedicated extension exfiltrated Telegram Web session tokens every 15 seconds, draining localStorage to a command server. Enough to steal a messaging account without you even noticing.&lt;/p&gt;
&lt;p&gt;Around 20,000 cumulative installations. That’s industrial-scale harvesting.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Why it matters to you&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;No macOS 0-day in this case. No Apple Silicon flaw, no Gatekeeper bypass. The vector is Chrome, and the extensions ecosystem running on it.&lt;/p&gt;
&lt;p&gt;And Chrome, on Mac, is the default browser for a significant portion of users, including professionals who keep Safari for the rest. You sync your tabs with Google, let Chrome handle your autofill, install three extensions for your workflow, and forget about it.&lt;/p&gt;
&lt;p&gt;Extensions have access to your tabs, cookies, and form data. When one becomes malicious, it can read what you’re reading. Here, the domino effect is brutal.&lt;/p&gt;
&lt;p&gt;A stolen Google OAuth token means potential access to Gmail, Drive, Photos, Calendar, depending on the granted scopes. An exfiltrated Telegram token means access to your conversations, groups, channels, shared files. No need for your password: the token is the session, and the session opens the door.&lt;/p&gt;
&lt;p&gt;The Chrome Web Store isn’t the App Store. Google reviews extensions, but not with the same level of rigor as Apple. Bad extensions slip through, and they often slip through often.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;What you need to do&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Practically:&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;1.&lt;/strong&gt; Open Chrome, go to &lt;code&gt;chrome://extensions&lt;/code&gt;, and disable everything you don’t use daily. Extensions that have been lying around for two years are exactly the attack surface you want to reduce.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;2.&lt;/strong&gt; Log in to &lt;a href=&quot;https://myaccount.google.com/security&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;myaccount.google.com&lt;/a&gt;, Security section, then Your Devices. Sign out any sessions you don’t recognize. While you’re at it, check the third-party apps accessing your Google account and revoke any you don’t recognize.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;3.&lt;/strong&gt; On Telegram, go to Settings then Devices (or Active Sessions depending on the client). Close all sessions except the one you’re using. If you see a session from a country or device you don’t recognize, it’s already too late for that session, but you can still cut off the flow.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;4.&lt;/strong&gt; Think about making Safari your default browser on Mac. Fewer extensions available means less attack surface. Safari doesn’t magically protect you, but its extension model is more restrictive, and Apple controls distribution via the Mac App Store for most of them.&lt;/p&gt;
&lt;p&gt;And the bottom line, beyond this incident: a browser extension sees everything your browser sees. Install them like you’d install a system app, that is, with caution and restraint.&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Read:&lt;/strong&gt; &lt;a href=&quot;https://macsouverain.com/en/privacy-macos-les-parametres-a-changer-immediatement/&quot;&gt;Privacy macOS, the settings to change immediately&lt;/a&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;&lt;em&gt;Technical terms? &lt;a href=&quot;https://macsouverain.com/en/glossaire/&quot;&gt;Check the glossary.&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Sources&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&quot;https://socket.dev/blog/108-chrome-ext-linked-to-data-exfil-session-theft-shared-c2&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;Socket Threat Research Team&lt;/a&gt;, &lt;em&gt;108 Chrome Extensions Linked to Data Exfiltration, Session Theft, Shared C2&lt;/em&gt;, April 13, 2026&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://cyberinsider.com/108-chrome-extensions-caught-stealing-user-data-and-hijacking-sessions/&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;CyberInsider&lt;/a&gt;, &lt;em&gt;108 Chrome Extensions Caught Stealing User Data and Hijacking Sessions&lt;/em&gt;, April 14, 2026&lt;/li&gt;
&lt;/ul&gt;</content:encoded><dc:creator>Mac Souverain</dc:creator><category>radar</category><category>radar-alerte</category><category>securite</category></item><item><title>Google hands over your data to ICE, without telling you</title><link>https://macsouverain.com/en/radar-google-ice-immigration-avril-2026/</link><guid isPermaLink="true">https://macsouverain.com/en/radar-google-ice-immigration-avril-2026/</guid><description>On a simple administrative subpoena from ICE, Google handed over a journalist&apos;s data without prior notice, breaking a decade-old promise.</description><pubDate>Wed, 15 Apr 2026 06:05:38 GMT</pubDate><content:encoded>&lt;div class=&quot;radar-summary&quot; standalone=&quot;true&quot;&gt;
&lt;p&gt;&lt;strong&gt;Google Promised to Warn You Before Handing Your Data to Authorities. It Didn’t. On a simple administrative subpoena from ICE, without a warrant or a judge, it handed over a student journalist’s info. Notification came later. The file was already gone.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;What You Need to Watch Out For&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;1.&lt;/strong&gt; Any Google account linked to your real identity is vulnerable to government requests without a warrant or prior notice&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;2.&lt;/strong&gt; An administrative subpoena is enough: no judge, no chance to challenge before disclosure&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;3.&lt;/strong&gt; Switching to Proton Mail gets you out of this equation, &lt;a href=&quot;https://macsouverain.com/en/migrer-gmail-proton-mail-mac/&quot;&gt;complete guide here&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;span class=&quot;small&quot;&gt;Sources: &lt;a href=&quot;https://www.eff.org/deeplinks/2026/04/google-broke-its-promise-me-now-ice-has-my-data&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;EFF Deeplinks&lt;/a&gt; · The Intercept&lt;/span&gt;&lt;/p&gt;
&lt;/div&gt;</content:encoded><dc:creator>Mac Souverain</dc:creator><category>radar</category><category>radar-signal</category><category>privacy</category><category>google</category><category>email</category></item><item><title>AI Agents on Mac: ANSSI flags Claude Cowork and OpenClaw</title><link>https://macsouverain.com/en/radar-agents-ia-anssi-avril-2026/</link><guid isPermaLink="true">https://macsouverain.com/en/radar-agents-ia-anssi-avril-2026/</guid><description>ANSSI issues official warning about autonomous AI agents on workstations. Cowork Claude and OpenClaw named. Here&apos;s what you need to do.</description><pubDate>Tue, 14 Apr 2026 11:28:16 GMT</pubDate><content:encoded>&lt;div class=&quot;radar-summary&quot; pending=&quot;true&quot;&gt;
&lt;p&gt;&lt;strong&gt;ANSSI has just published an official alert&lt;/strong&gt; about autonomous AI agents: &lt;strong&gt;OpenClaw and Claude Cowork are named&lt;/strong&gt;, along with other open-source solutions. These tools run commands, read your files, send emails, and a malicious webpage could manipulate them without your knowledge. In other words: AI assistants on your Mac are also attack surfaces.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;What you need to do&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;1.&lt;/strong&gt; Disable access to sensitive apps (email, calendar, work files) for your AI agents in their respective settings.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;2.&lt;/strong&gt; Don’t use Claude Cowork, OpenClaw, or any autonomous agent on a machine containing client or financial data without proper supervision.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;3.&lt;/strong&gt; Check which applications each AI agent installed on your Mac has access to.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;4.&lt;/strong&gt; I’m preparing a &lt;strong&gt;complete guide to reduce risks&lt;/strong&gt;: automatic filters, access segmentation, what you can disable without losing the tool’s usefulness: &lt;em&gt;&lt;strong&gt;Coming soon in a tutorial&lt;/strong&gt;&lt;/em&gt;&lt;/p&gt;
&lt;/div&gt;
&lt;p&gt;&lt;strong&gt;ANSSI issued an official warning on April 13, 2026, about autonomous AI agents on workstations. OpenClaw and Claude Cowork are specifically called out. These tools can run commands, read and write files, send emails - and a simple prompt injection can turn them against you.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;I’m cooking up a comprehensive guide to reduce risks: automatic filters, access segmentation, what you can disable without losing functionality. Stay tuned.&lt;/em&gt;&lt;/p&gt;</content:encoded><dc:creator>Mac Souverain</dc:creator><category>radar</category><category>radar-alerte</category><category>securite</category><category>ia</category></item></channel></rss>