Skip to main content

Security

See All Stories

Security Bite: How hackers can take over your Mac using Bluetooth

flipper zero - arin - macbook - mac - bluetooth - malware

9to5Mac Security Bite is exclusively brought to you by Mosyle, the only Apple Unified Platform. Making Apple devices work-ready and enterprise-safe is all we do. Our unique integrated approach to management and security combines state-of-the-art Apple-specific security solutions for fully automated Hardening & Compliance, Next Generation EDR, AI-powered Zero Trust, and exclusive Privilege Management with the most powerful and modern Apple MDM on the market. The result is a totally automated Apple Unified Platform currently trusted by over 45,000 organizations to make millions of Apple devices work-ready with no effort and at an affordable cost. Request your EXTENDED TRIAL today and understand why Mosyle is everything you need to work with Apple.


In a Bluetooth Impersonation Attack (or BIAS), hackers can exploit weaknesses in the Bluetooth protocol to impersonate a trusted device. “BOSE QC Headphones” in the Bluetooth menu could be a low-orbiting ion cannon waiting for an end-user to connect to it before unleashing all sorts of damage.

This week, I want to again share how hackers can use Flipper Zero to send sneaky keystrokes to a Mac if a victim connects to a potentially malicious Bluetooth device. This isn’t going to be a complete tutorial since there are tons of guides out there already. Instead, I want to point out how easy it is to pull this off, to make you a bit more paranoid.

Expand Expanding Close

A staggering 16 billion logins exposed in epic data breach, including Apple accounts

A staggering 16 billion logins exposed in epic data breach, including Apple accounts | Low-key photo of MacBook imagined with old-style rainbow logo

Security researchers have discovered what they describe as “one of the largest data breaches in history,” comprising a staggering 16 billion logins, which include Apple accounts (formerly known as Apple IDs).

The researchers said that the stolen data gives cybercriminals “unprecedented access to personal credentials that can be used for account takeover, identity theft, and highly targeted phishing” …

Expand Expanding Close

Security Bite: Infostealer malware spikes 28% among Mac users, says Jamf

9to5Mac security bite cybersecurity Apple

9to5Mac Security Bite is exclusively brought to you by Mosyle, the only Apple Unified Platform. Making Apple devices work-ready and enterprise-safe is all we do. Our unique integrated approach to management and security combines state-of-the-art Apple-specific security solutions for fully automated Hardening & Compliance, Next Generation EDR, AI-powered Zero Trust, and exclusive Privilege Management with the most powerful and modern Apple MDM on the market. The result is a totally automated Apple Unified Platform currently trusted by over 45,000 organizations to make millions of Apple devices work-ready with no effort and at an affordable cost. Request your EXTENDED TRIAL today and understand why Mosyle is everything you need to work with Apple.


Each year, Jamf—the popular Apple device management platform—releases its Security 360: Annual Trends Report, which gives a broad outlook of the macOS threat landscape currently facing businesses and users. The analysis uses anonymized real-world data collected from 1.4 million Macs across 90 countries with Jamf software installed.

Today, Jamf is out with its 2025 edition, which spans the previous 12 months. The report offers many shocking insights, most notably a 28% spike in infostealer malware, making it the leading Mac malware family type.

Expand Expanding Close

Do these nine things to protect yourself against hackers and scammers

How to carry out a security and privacy audit to guard against scammers | IT professional in a datacenter

Scammers are using AI tools to create increasingly convincing ways to trick victims into sending money, and to access the personal information needed to commit identity theft. Deepfakes mean they can impersonate the voice of a friend or family member, and even fake a video call with them!

The result can be criminals taking out thousands of dollars worth of loans or credit card debt in your name. Fortunately there are steps you can take to protect yourself against even the most sophisticated scams. Here are the security and privacy checks to run to ensure you are safe …

Expand Expanding Close

Security Bite: Apple’s new iOS 26 spam tools will make scammers cry

ios 26 spam scam unkown senders messages app filter wwdc 2025

9to5Mac Security Bite is exclusively brought to you by Mosyle, the only Apple Unified Platform. Making Apple devices work-ready and enterprise-safe is all we do. Our unique integrated approach to management and security combines state-of-the-art Apple-specific security solutions for fully automated Hardening & Compliance, Next Generation EDR, AI-powered Zero Trust, and exclusive Privilege Management with the most powerful and modern Apple MDM on the market. The result is a totally automated Apple Unified Platform currently trusted by over 45,000 organizations to make millions of Apple devices work-ready with no effort and at an affordable cost. Request your EXTENDED TRIAL today and understand why Mosyle is everything you need to work with Apple.


Earlier this week, during its annual WWDC keynote, Apple unveiled a slew of headline features like Liquid Glass, a new Games app, and Visual Intelligence, as well as two major spam protection tools coming to iOS 26 this fall. While I was a little disappointed in the lack of new security or even privacy features, these new tools will change the game for users who receive annoying spam calls and messages on the daily. Here’s how they work.

Expand Expanding Close

Security Bite: Is this a scam? Malwarebytes’ new feature can tell you in seconds

malwarebytes scam guard security bite

9to5Mac Security Bite is exclusively brought to you by Mosyle, the only Apple Unified Platform. Making Apple devices work-ready and enterprise-safe is all we do. Our unique integrated approach to management and security combines state-of-the-art Apple-specific security solutions for fully automated Hardening & Compliance, Next Generation EDR, AI-powered Zero Trust, and exclusive Privilege Management with the most powerful and modern Apple MDM on the market. The result is a totally automated Apple Unified Platform currently trusted by over 45,000 organizations to make millions of Apple devices work-ready with no effort and at an affordable cost. Request your EXTENDED TRIAL today and understand why Mosyle is everything you need to work with Apple.


It’s no secret that AI is improving the way scammers operate. Phishing texts are more convincing than ever, and malicious emails can look legitimate for longer than just a glance. Attackers are getting smarter about how they trick people into handing over money or personal info. But the good guys are getting better, too.

Earlier this week, Malwarebytes, best known for its real-time anti-malware protection software, launched a new AI-powered feature aimed specifically at mobile scams. I’ve been testing it out for the past few days. Here’s how it works and my quick thoughts on it.

Expand Expanding Close

Security Bite: Apple could announce cross-platform E2EE for RCS messaging at WWDC

test

9to5Mac Security Bite is exclusively brought to you by Mosyle, the only Apple Unified Platform. Making Apple devices work-ready and enterprise-safe is all we do. Our unique integrated approach to management and security combines state-of-the-art Apple-specific security solutions for fully automated Hardening & Compliance, Next Generation EDR, AI-powered Zero Trust, and exclusive Privilege Management with the most powerful and modern Apple MDM on the market. The result is a totally automated Apple Unified Platform currently trusted by over 45,000 organizations to make millions of Apple devices work-ready with no effort and at an affordable cost. Request your EXTENDED TRIAL today and understand why Mosyle is everything you need to work with Apple.


We’re officially just over a week away from WWDC 2025. While we expect big design enhancements and much-needed Apple Intelligence improvements to iOS, Apple has the opportunity to do something it’s quite good at: flexing its privacy prowess.

Expand Expanding Close

Apple logins with plain text passwords found in massive database of 184M records

Apple logins with plain text passwords found in massive database of 184M records | Close-up photo of the inside of a hard drive

Apple login credentials were among a massive database of 184 million records found sitting unprotected on a web server. Other logins included Facebook, Google, Instagram, Microsoft, and PayPal.

The owner of the database is unclear, but the security researcher who discovered it says that it amounts to “a cybercriminal’s dream working list” …

Expand Expanding Close

Coinbase hack sees some customers tricked into sending funds; will be reimbursed

Coinbase hack sees some customers tricked into sending funds; will be reimbursed | Photo of physical representations of cryptocurrency

A Coinbase hack has seen some customers tricked into sending funds to the attackers, with the company estimating that they suffered losses of somewhere between $180M and $400M.

The attackers also stole personal data, after Coinbase refused to pay a ransom demand – instead reporting the hack to law enforcement, and offering a $20M reward for information on the perpetrators …

Expand Expanding Close

Security Bite: Down the rabbit hole of neat, lesser-known Terminal commands (Pt. 2)

terminal app security bite

9to5Mac Security Bite is exclusively brought to you by Mosyle, the only Apple Unified Platform. Making Apple devices work-ready and enterprise-safe is all we do. Our unique integrated approach to management and security combines state-of-the-art Apple-specific security solutions for fully automated Hardening & Compliance, Next Generation EDR, AI-powered Zero Trust, and exclusive Privilege Management with the most powerful and modern Apple MDM on the market. The result is a totally automated Apple Unified Platform currently trusted by over 45,000 organizations to make millions of Apple devices work-ready with no effort and at an affordable cost. Request your EXTENDED TRIAL today and understand why Mosyle is everything you need to work with Apple.


I’ve recently fallen into the rabbit hole of lesser-known Terminal features. These past months, I covered everything from enabling Touch ID for sudo authentication to cleaning up public Wi-Fi connections stored on your Mac. But this week, I want to share even more neat features you probably didn’t know Terminal could do. These can be helpful if you’re an everyday Mac user or managing an enterprise fleet. In this edition of Security Bite, allow me to elevate your command line prowess further.

Expand Expanding Close

iPhone spyware company NSO must pay Meta $167M for WhatsApp attack [U]

iPhone spyware company NSO must reveal code | Code on monitor viewed through glasses

The Android and iPhone spyware company NSO has suffered a major defeat in a US court, after a judge ruled that the company must hand over its Pegasus code to Meta.

Update: NSO was yesterday ordered to pay Meta more than $167M in damages for the attack. It’s the latest setback for the company, which has been blacklisted in the US, sued by Apple, seen victims alerted by the iPhone maker, and faced severe financial problems

Expand Expanding Close

Security Bite: Your browser uses a psychological trick to stop phishing — and you probably never noticed

Mac malware fake Safari Chrome updates

9to5Mac Security Bite is exclusively brought to you by Mosyle, the only Apple Unified Platform. Making Apple devices work-ready and enterprise-safe is all we do. Our unique integrated approach to management and security combines state-of-the-art Apple-specific security solutions for fully automated Hardening & Compliance, Next Generation EDR, AI-powered Zero Trust, and exclusive Privilege Management with the most powerful and modern Apple MDM on the market. The result is a totally automated Apple Unified Platform currently trusted by over 45,000 organizations to make millions of Apple devices work-ready with no effort and at an affordable cost. Request your EXTENDED TRIAL today and understand why Mosyle is everything you need to work with Apple.


If you’re reading this week’s Security Bite on your desktop, look closely at your browser’s address bar. Notice how the main (root) domain is darker or black, while the rest of the URL is a lighter grey? This is not an accident — it’s actually a subtle psychological trick called salience bias. This little design choice has protected users from phishing attacks for over a decade.

Expand Expanding Close

Apple warns iPhone users in 100 countries that they are victims of spyware

Apple warns iPhone users in 100 countries that they are victims of spyware | Creepy-looking low-key b&w photo of hands typing on a keyboard

Apple has notified iPhone users in 100 countries that their devices have been infected with spyware, implying that it may be NSO’s Pegasus.

The company has warned victims to take it seriously, and to immediately take a number of security actions in response. One of the recipients has shared almost the entire message, the first time I can recall seeing more than a brief excerpt …

Expand Expanding Close

Millions of AirPlay devices can be hacked over Wi-Fi; CarPlay too

Millions of AirPlay devices can be hacked over Wi-Fi | Screenshot of demo on Bose speaker

Security vulnerabilities discovered in Apple’s AirPlay SDK mean that millions of devices could be hacked by attackers. The flaw has been dubbed AirBorne.

Related vulnerabilities would also have allowed hackers to attack Apple devices too, but the iPhone maker says it has issued fixes for these in the past few months. CarPlay devices are also vulnerable, though the real-life risks there are very low …

Expand Expanding Close

Security Bite: FBI releases 2024 Internet Crime Report, ‘new record for losses’

9to5Mac security bite cybersecurity Apple

9to5Mac Security Bite is exclusively brought to you by Mosyle, the only Apple Unified Platform. Making Apple devices work-ready and enterprise-safe is all we do. Our unique integrated approach to management and security combines state-of-the-art Apple-specific security solutions for fully automated Hardening & Compliance, Next Generation EDR, AI-powered Zero Trust, and exclusive Privilege Management with the most powerful and modern Apple MDM on the market. The result is a totally automated Apple Unified Platform currently trusted by over 45,000 organizations to make millions of Apple devices work-ready with no effort and at an affordable cost. Request your EXTENDED TRIAL today and understand why Mosyle is everything you need to work with Apple.


This year marks the 25th anniversary of the FBI’s Internet Crime Complaint Center, or IC3 for short. Since its inception in 2000, the organization has released an annual report detailing trends based on the thousands of cybercrime complaints it receives daily from victims. This week, the FBI released its 2024 Internet Crime Report, revealing a record $16.6 billion in reported losses—a 33% increase and “a new record for losses reported to IC3.”

If there’s one thing this report highlights best, it’s that humans are more vulnerable than machines.

Expand Expanding Close

PSA: Watch out for ultra-convincing phishing emails from Google & PayPal

Watch out for ultra-convincing phishing emails from Google & PayPal | Fake security alert shown

Detecting scam emails is getting increasingly difficult as attackers use more and more sophisticated methods. A new report highlights a method which makes fake security alerts from Google and PayPal look extremely convincing.

It reinforces the need to apply a simple but effective safeguard anytime you receive what seems to be an important email requiring your immediate attention …

Expand Expanding Close