One American order was enough to make autistici.org disappear The US branded the Autistici collective a terrorist group, and its .org domain was pulled from DNS by its registry. What it says about the sovereignty of your own services.
A Mac stealer is going after your Claude sessions AMOS and other macOS stealers are going after your Claude sessions. The weak link is neither Apple nor Claude, it's the command you paste into the Terminal.
ChatGPT Reads Your Messages, and the Price Is Your Whole Disk ChatGPT reads and sends your iMessages on Mac. The ticket in is Full Disk Access, the broadest permission in macOS.
The UN Treaty That Can Launder Spyware Evidence Canada signed the UN Cybercrime Convention. A cross-border evidence-sharing channel that, once ratified, can launder data stolen by spyware.
Apple Private Relay protects you from nothing A large share of iCloud+ subscribers take Private Relay for a tunnel. Three WebKit leaks say otherwise, and Apple is being sued for fraud.
London demands your encrypted iCloud backups Apple is challenging a British order targeting your iCloud backups. Narrowed to the UK, the precedent knows no border.
A fake Zoom update empties your iCloud Keychain A trusted Telegram contact invites you to a video call, a fake Zoom update pops up mid-call, and your iCloud Keychain gets emptied.
Claude Cowork in local mode, the agent walks out of the sandbox On macOS in local mode, Claude Cowork mounts your entire disk inside the agent's VM. One connected folder, one message, and it walks out without asking.
Hugging Face compromised, and your local model? Hugging Face announced on July 16th that they had been compromised. Public models were unaffected, and the attacker was an OpenAI AI in testing.
Apple-notarized malware slips past Gatekeeper CrashStealer, signed and notarized by Apple, clears Gatekeeper without a single alert. Notarization validates the signature, not the intent.
Chat Control 1.0: Adopted by Those Who Voted Against On July 9th, the European Parliament allowed Chat Control 1.0 to be renewed, falling short of the 361 votes needed to block it, despite a majority voting against. What this means, and what's heading back to trilogue in September.
Wazuh 5.0 lands, your home SIEM evolves Wazuh 5.0 in public beta, releasing late June/early July. Filebeat dit au revoir, clusters enabled by default, new engine. Your 4.x install will upgrade. Don't worry, we'll explain it all.
Your stance is leaking through the network, not through your iPhone. Tech companies track any mobile device through telecom interconnection flaws. No iPhone patches needed.
Siri AI blocked in EU, privacy signed Google Apple Unveils Siri AI at WWDC, But Locks It Down on iPhone and iPad in EU. A Confidential Platform Built on Google Gemini. Here's the Breakdown.
OpenAI Certificate Compromised, Update ChatGPT Mac Before June 12th ChatGPT, Codex, and Atlas on Mac: Mandatory update before June 12, 2026. OpenAI cert revoked after npm supply-chain attack.
Domestic stalkerware, the jealous partner's malware Stalkerware Spyzie, Cocospy, Spyic, over 3 million victims combined. Your iPhone drained via your Apple ID. How to check and take back control.
The U.S. cyber regulator let its AWS keys slip six months ago. A US federal cyber agency's subcontractor left their AWS GovCloud admin keys on a public GitHub repo for six months. Why not delegate your security, huh?
Five years of defending memory M5 down in five days Three California researchers bypassed Memory Integrity Enforcement M5 in five days using Mythos. First public kernel exploit on Apple M5 silicon. Patched in macOS Tahoe 26.5.
Google Ads and real cat Claude share your credentials Google sponsored ads redirect to real, shared claude.ai links that are baited. Fake Apple Support makes you paste a base64 into Terminal. MacSync payload empties your Keychain.
Apple patches iOS and macOS CVEs: fix, then tune your Safari profiles iOS 26.5 fixes 98 CVEs, including 21 in WebKit; macOS Tahoe 26.5 fixes 98 CVEs, including 22. Instead of enabling Lockdown Mode everywhere, segment with a dedicated Safari profile.
Proton Mail switches to post-quantum encryption (and it's free) Proton Mail offers a quantum-resistant encryption option, available on all plans including the free one. Must be enabled manually, but don't get your hopes up.
iOS 26.5 finally encrypts RCS iPhone-Android (but Signal still leads) Apple enables end-to-end encryption on RCS messages with iOS 26.5, using the MLS protocol. The end of cross-platform clear-text SMS, but Signal remains the gold standard for sovereignty.
Age verification EU, hacked in 2 minutes, poorly coded surveillance Paul Moore skirts the EU's age-verification app in under 2 minutes. The EUDI standard promised zero-knowledge. Its implementation stores the PIN in an editable XML.
The FBI got their hands on deleted Signal messages. Cheers, iPhone notifications. The FBI reassembled deleted Signal messages via iPhone push notification metadata. End-to-end encryption didn't make a difference.
"No Access", and the app still reads your files macOS secretly logs access to your files whenever you use the Open/Save dialog. The Privacy & Security interface doesn't show this. Since 2019.
108 Chrome extensions trapped, your Google and Telegram too 108 malicious Chrome extensions identified in the Chrome Web Store by Socket researchers. Google OAuth theft, backdoors, Telegram exfiltration. Google notified, extensions still online at publication. If you're using Chrome on Mac, you're affected.
Google hands over your data to ICE, without telling you On a simple administrative subpoena from ICE, Google handed over a journalist's data without prior notice, breaking a decade-old promise.
AI Agents on Mac: ANSSI flags Claude Cowork and OpenClaw ANSSI issues official warning about autonomous AI agents on workstations. Cowork Claude and OpenClaw named. Here's what you need to do.
Chat Control 2.0: The EU wants to scan all your private messages Under the guise of protecting children, the EU is rushing to set up mass surveillance infrastructure for all encrypted messaging platforms.
APT28 steals your Microsoft tokens without touching your Mac Russian military intelligence is exploiting unpatched routers to silently intercept your Office OAuth tokens. What you need to do.
ClickFix macOS, Script Editor bypasses the Terminal warning Apple added an anti-ClickFix warning in the Terminal with macOS 26.4. Attackers promptly switched to Script Editor to distribute Atomic Stealer without friction.
SparkCat is back on the App Store, scanning your gallery. SparkCat accesses your Photos gallery, scans everything with OCR, and extracts crypto seed phrases. Never store a mnemonic phrase as a screenshot.
Coruna: a US state toolkit, fallen into Russian cybercriminals' hands Coruna exploits 23 iOS 13 to 17.2.1 flaws, installs silently. Already in Russian criminals' hands. Activate Lockdown Mode now.
DarkSword: iOS update 18.7.7 mandatory The source code of DarkSword is on GitHub. Apple releases iOS 18.7.7 to fix WebKit, Kernel, and Keychain. Mandatory update.