Topic: spyware attacks
-
Phone and App Features That Help Block Spyware
In early 2025, WhatsApp and Apple confirmed that journalists and civil society members were targeted by Paragon Solutions' Graphite spyware using zero-click attacks, highlighting that such espionage is now common. Spyware gives government operators full access to devices,recording calls, stealing...
Read More » -
Apple Issues Spyware Attack Warning to Targeted Users
Apple has issued urgent warnings about sophisticated mercenary spyware attacks targeting high-profile individuals via zero-interaction exploits. These attacks exploit zero-day vulnerabilities, often without victim interaction, and primarily target journalists, activists, politicians, and official...
Read More » -
Apple Offers Up to $5 Million for Bug Bounty Rewards
Apple has increased its bug bounty rewards to up to $5 million, doubling the base reward to $2 million for sophisticated exploit chains, to counter advanced threats like mercenary spyware. The program now includes bonuses for bypassing Lockdown Mode and finding pre-release software vulnerabilitie...
Read More » -
iPhone Exploit Kit Leaked, Millions of Devices at Risk
A sophisticated exploit toolkit called "DarkSword" has been publicly leaked, enabling cybercriminals to more easily deploy spyware on iPhones running outdated iOS software. The primary risk is to users who have not installed the latest iOS security updates, as the kit can bypass protections on ol...
Read More » -
Apple's Bold Move to End iPhone's Biggest Security Flaws
Apple's new iPhone lineup introduces Memory Integrity Enforcement, a hardware and software feature designed to protect against memory-safety vulnerabilities often exploited by attackers. Memory-safety issues, frequently caused by programming errors in languages like C and C++, have long been a pr...
Read More » -
Urgent Chrome Update Fixes Actively Exploited 0-Day Bug
Google has released a critical update for Chrome to patch a zero-day vulnerability (CVE-2025-13223) that is already being actively exploited in attacks. The flaw is a type confusion issue in the V8 JavaScript engine that could allow attackers to execute unauthorized code and potentially take cont...
Read More »