home.social

#applesecurity — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #applesecurity, aggregated by home.social.

fetched live
  1. Apple's latest "security" #update for #macOS #Tahoe 26.6 is like a magician revealing the secrets of a magic trick - except they forgot to do the big reveal 🎩✨. Apparently, the only 'security' improvement was adding more padding to their walled garden 🏰🔒. But hey, at least we've got a new list of #CVEIDs to admire! 📜🤷‍♂️
    support.apple.com/en-us/128067 #AppleSecurity #WalledGarden #TechNews #HackerNews #ngated

  2. Apple may also be preparing a “Malicious Message Detected” warning for iOS 26.6.

    The feature was found in beta code and appears designed to warn users about suspicious messages and let them share the message with Apple. Its exact detection capabilities haven’t yet been confirmed.

    Researchers also have a new open-source macOS Malware Knowledge Base for identifying known malware families and indicators.

    #AppleSecurity #macOS #iOS #Cybersecurity

  3. 🔓 Security researchers at Paradigm Shift say “usbliter8” is a new SecureROM/BootROM exploit impacting Apple A12–A13 chips (and some Apple Watch S4/S5). The PoC chains a USB controller DMA bug with a SecureROM config weakness to reach code execution. An unpatchable risk—details: cyberinsider.com/unpatchable-b #AppleSecurity #BootROM #Exploitation #Vulnerability #CyberSecurity 🔍🚨

  4. Apple published a detailed write-up on formal verification in corecrypto, including their ML-KEM and ML-DSA implementations for post-quantum cryptography.

    This goes to the next level, beyond “we tested this carefully” to “we proved key parts equivalent to the FIPS specs, including optimized C and ARM64 assembly paths.”

    This crypto library ships across billions of devices. This is the difficult, expensive assurance work that makes platform security real. security.apple.com/blog/formal #AppleSecurity #Cryptography #PostQuantum #InfoSec

  5. 🎉 Oh joy, another mind-numbing Apple security "update" that confirms absolutely nothing until it's too late! 🕵️‍♂️ Good old Apple, keeping everyone in suspense with their cryptic vulnerability haikus. 📱✨
    support.apple.com/en-us/127115 #AppleSecurity #UpdateCrypticVulnerabilities #TechHumor #SoftwareUpdates #HackerNews #ngated

  6. 🚨 Just when you thought Apple's memory defenses were tighter than a hipster's skinny jeans, a tiny startup with an AI sidekick casually waltzes through their fortress in under a week. 🤖🔑 Five years of design and fancy new silicon, yet it still can't keep out a trio armed with two bugs and a "clever idea." 🤦‍♂️ Keep those PhDs on hold, folks.
    ironpeak.be/blog/bypassing-app #AppleSecurity #AIStartup #MemoryBreach #Cybersecurity #Hackers #HackerNews #ngated

  7. In part 2 of my macOS security internals series, I demystify System Integrity Protection (SIP), breaking down how the kernel enforces Apple-signed entitlements over POSIX root privileges, the mechanics of rootless.conf, and why the hardware always has the final veto.

    Includes a small C program to audit your own CSR bitfield configuration.

    Read the full deep dive here:
    bytearchitect.io/macos-securit

    #macOS #infosec #cybersecurity #ReverseEngineering #XNU #AppleSecurity #Kernel #OSInternals #Rootless

  8. Apple ha rilasciato il primo aggiornamento Background Security Improvement (BSI) per macOS Tahoe 26.3.1, iOS 26.3.1 e iPadOS 26.3.1.

    #applesecurity #webkit

  9. Apple utilizza i rapporti sui messaggi spam segnalati dagli utenti per identificare caratteristiche comuni e migliorare i filtri di sicurezza server-side. 📡🔒

    #spamreports #applesecurity #macos

  10. Apple's iOS 18.7.5 patches 30+ critical vulnerabilities including sandbox escapes and kernel flaws. AdwaitX breaks down every security fix for iPhone XS and iPad 7th gen users. Install now 🔗 #AdwaitX #iOS1875 #AppleSecurity #iPhone

    adwaitx.com/ios-18-7-5-securit

  11. 🔒 iOS 26.3 beta rilascia un aggiornamento di sicurezza per testare nuovi miglioramenti di sistema in background. Apple continua l’evoluzione della sua piattaforma.

    #ios26 #applesecurity #betaupdate

  12. 🚨 BREAKING: TechCrunch discovers that, shockingly, an iPhone isn't invincible to hacking! 😱 In related news, water is wet, and Apple remains an easy target for government spyware because, you know, it's made for "security" and all. 😂🔒
    techcrunch.com/2025/10/21/appl #iPhoneHacking #AppleSecurity #TechNews #GovernmentSpyware #Cybersecurity #HackerNews #ngated

  13. Apple podwaja nagrodę w programie Bug Bounty do 2 mln USD za ataki na poziomie szpiegowskim

    Apple ogłosiło nową, ulepszoną wersję swojego programu Bug Bounty, w którym nagroda za łańcuchy exploitów porównywalne do ataków szpiegowskich wzrosła do 2 mln USD.

    Łączne wypłaty z bonusami za obejście Lockdown Mode i luki w wersjach beta mogą przekroczyć 5 mln USD, co Apple nazywa największą nagrodą oferowaną przez jakikolwiek program bug bounty.

    Nowy program skupia się na kompletnych łańcuchach exploitów, a nie pojedynczych lukach, co odzwierciedla realne ataki. Nagrody za zdalne wektory ataku znacząco wzrosły, podczas gdy mniej powszechne kategorie otrzymają mniejsze wypłaty.

    Apple wprowadza też „Target Flags”, inspirowane grami typu capture-the-flag. Pozwalają one badaczom udowodnić poziom uzyskanego dostępu (np. wykonanie kodu lub arbitralny odczyt/zapis). Po weryfikacji przez Apple nagroda jest wypłacana w najbliższym cyklu płatności, bez oczekiwania na poprawkę systemu.

    Nowe kategorie obejmują m.in.:

    • One-click WebKit sandbox escapes – do 300 000 USD
    • Exploity bezprzewodowe – do 1 mln USD
    • Pełne obejście Gatekeeper w macOS – 100 000 USD

    Program wchodzi w życie od listopada 2025, a od startu w 2020 Apple wypłaciło ponad 35 mln USD ponad 800 badaczom.

    Podobne programy mają inne filmy technologiczne z całego świata, w tym Synology, o czym szerzej posłuchasz w jednym z odcinków mojego podcastu „Bo czemu nie?”.

    #Apple #AppleSecurity #Bezpieczeństwo #bezpieczeństwosystemów #BugBounty #cybersecurity #exploit #exploitchains #hackowanie #iOS #LockdownMode #macOS #nagroda #programiści #technews #vulnerability

  14. 🚀🐑 Apple's security gibberish—SPTM, #TXM, and Exclaves—because who needs clear communication when you can have an alphabet soup? 🤪 Dive deep into buzzwords and acronyms, and emerge none the wiser! 📚🔍
    arxiv.org/abs/2510.09272 #AppleSecurity #SPTM #Exclaves #BuzzwordSoup #HackerNews #ngated

  15. Apple just upped its bug bounty game to a whopping $2M for critical exploits, with potential payouts over $5M for bypassing Lockdown Mode. Suddenly, 'it works on my machine' isn't cutting it. My compiler just started whispering about early retirement. What's the wildest bug you've ever found (or dreamt of finding) that *isn't* worth millions?
    engadget.com/big-tech/apple-do
    #AppleSecurity #BugBounty #DevLife #InfoSec #CyberSecurity

  16. Apple 'Account'? Remember when it was just an 'ID'? If you've ever found yourself locked out or just want to refresh your digital security, here's how to change your Apple password across all your devices and the web. Because who *hasn't* needed this at 3 AM?

    Read more: engadget.com/computing/how-to-

    #AppleSecurity #PasswordTips #TechTips #Cybersecurity #DevLife
    What's your go-to strategy for crafting and remembering truly strong passwords?

  17. Apple is introducing "Background Security Improvements" (BSI) in iOS 26 for silent, automatic security patches! 🔒 No more manual updates or interruptions, with potential reboot-free fixes and rollback options. A big step in seamless security! 🚀 #iOS26 #AppleSecurity #SilentUpdates heise.de/en/news/Security-upda
    #newz

  18. Rumors su iOS 26.1: Apple starebbe testando Background Security Improvements, un sistema per patch di sicurezza silenziose, senza intervento dell'utente.

    💡 Sostituirebbe Rapid Security Responses.
    📱 Mantenere l'iPhone sicuro sarebbe più semplice.

    #iOS26 #AppleSecurity #iPhoneNews