Apple finally patches critical SSL flaw in OS X
Apple has released an update for OS X that, among other things, patches the infamous “gotofail” bug whose existence was publicly revealed last Friday. The flaw was …
Apple users hit with “Update using new SSL servers” phishing email
Users with Apple Accounts are again being targeted with legitimate-looking phishing emails that are after their account credentials, personal and financial information. …
MacBook webcam indicator light can be disabled to aid spying
Two researchers from Johns Hopkins University have proved, without a doubt, that it is possible to activate internal iSight webcams included in some legacy Apple machines …
The iCloud keychain and iOS 7 data protection
When Apple announced iOS 7, iCloud Keychain was one of its key features. It is no doubt great for usability, but what about security? What kind of access does Apple have to …
Safari, Chrome and Samsung Galaxy S4 taken down in Mobile Pwn2Own
Results from the second annual Mobile Pwn2Own competition ending today at PacSec Applied Security Conference in Tokyo, Japan, are in: the successful compromises include …
Apple releases cleverly framed report on government data requests
Apple has released what will be the first of many biannual reports on government information requests it receives, and has included a statement saying that “Apple has …
Malicious “Apple ID Information Updated” notification doing rounds
An unimaginative but likely relatively successful phishing campaign is targeting Apple users once again, trying to get them to share their login and financial information. The …
Apple’s iCloud protocols cracked and analyzed
Smartphones carry a lot of sensitive data that in theory should be accessible only to their owners. In practice, a lot of it can be exfiltrated from the devices and from the …
Apple Dev Center was hacked via remote code execution bug
Apple’s ever expanding article listing researchers’ credits for finding and reporting potential security issues in Apple’s web servers has some new entries, …
Apple Dev Center partially back online, still no details about the hack
Parts of the Apple Developer Center are back online after a week long outage caused by an unnamed intruder that has “attempted to secure” personal information of …
Apple developer center hacked by security researcher?
The mystery of why Apple’s Developer Center has been inaccessible for users since last Thursday has apparently been solved, as UK-based security researcher Ibrahim Balic …
Featured news
Resources
Don't miss
- ClickFix campaign delivers Mac malware via fake Apple page
- Poisoned “Office 365” search results lead to stolen paychecks
- What vibe hunting gets right about AI threat hunting, and where it breaks down
- Health insurance lead sites sell personal data within seconds of form submission
- Claude helps researcher dig up decade-old Apache ActiveMQ RCE vulnerability (CVE-2026-34197)