← Latest briefing

Technology

Apple updates spyware threat notifications with direct device alerts

The company now displays warnings directly on Lock Screens and Settings to ensure high-risk users do not miss mercenary spyware alerts.

The short version

  • Apple has updated its delivery of threat notifications, placing them directly on users' device Lock Screens and Settings to make them harder to miss.
  • The alerts warn users that activity signaling targeted mercenary spyware, such as Pegasus, has been detected on their device.
  • Security experts recommend that notified users immediately preserve device evidence and seek expert digital forensic support.

Key facts

  • Apple updated its threat notification delivery in September, moving alerts directly to users' device Lock Screens and Settings rather than relying solely on emails, iMessages, and account banners.[Hacker News]
  • The threat notifications signal that a user has been targeted by sophisticated commercial surveillance technology from mercenary spyware vendors such as NSO Group, Paragon, or Cytrox.[Hacker News]
  • Apple's alerts do not confirm whether a spyware attack succeeded, nor do they identify the perpetrator or motive.[Hacker News]
  • Civil society members, including journalists and human rights defenders, are advised by Apple and Access Now to seek expert forensic assistance, such as Access Now's Digital Security Helpline, upon receiving a verified alert.[Hacker News]
  • Security experts state that no single consumer application or security service can diagnose, prevent, or mitigate all forms of mercenary spyware.[Hacker News]

What remains uncertain

  • A lack of forensic traces or obvious device misbehavior does not guarantee a device is safe, as sophisticated spyware is designed to hide its presence and erase traces of infection.[Hacker News]

Sources