Apple sent a new round of threat notifications to users it believes were targeted by mercenary spyware capable of compromising iPhone, iPad, and Mac devices. The company said the latest alerts reached customers in 110 countries, and that it has now notified users in more than 150 countries since launching the program. The updated warning process includes a lock-screen push notification, an email, and a notice on the user’s Apple account page, reflecting a broader effort to ensure suspected victims recognize the seriousness of the targeting.
Apple’s guidance tells recipients to seek expert help and enable Lockdown Mode, a hardened security setting designed for people at elevated risk of targeted attacks. According to Apple, it has not observed a case in which a device was successfully compromised while Lockdown Mode was enabled. Researchers said the stronger notification flow can help victims identify spyware targeting earlier and may support wider investigations into abuse by governments and commercial surveillance vendors.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
Apple sent a new batch of threat notifications on Thursday to customers in 110 countries whom it believes were targeted by mercenary spyware capable of compromising iPhones, iPads, or Macs. The updated notification flow includes a lock-screen push alert, email, and an Apple account notification.
Apple published a support article explaining its threat notifications for users it believes were targeted by mercenary spyware and outlining protective steps such as enabling Lockdown Mode.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
19 references tracked. Mallory keeps watching after this page renders.
xakep.ru
Open sourcetechrepublic.com
Open sourcetechcrunch.com
Open sourcezdnet.fr
Open sourcetechcrunch.com
Open sourcesupport.apple.com
Open sourcesupport.apple.com
Open sourcesupport.apple.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.