惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

人人都是产品经理
人人都是产品经理
Threat Intelligence Blog | Flashpoint
Threat Intelligence Blog | Flashpoint
P
Privacy International News Feed
Simon Willison's Weblog
Simon Willison's Weblog
I
Intezer
Spread Privacy
Spread Privacy
The Hacker News
The Hacker News
P
Palo Alto Networks Blog
TaoSecurity Blog
TaoSecurity Blog
S
Secure Thoughts
Google Online Security Blog
Google Online Security Blog
H
Heimdal Security Blog
N
News | PayPal Newsroom
Attack and Defense Labs
Attack and Defense Labs
Recent Commits to openclaw:main
Recent Commits to openclaw:main
博客园 - 【当耐特】
Webroot Blog
Webroot Blog
小众软件
小众软件
Help Net Security
Help Net Security
D
Darknet – Hacking Tools, Hacker News & Cyber Security
N
News and Events Feed by Topic
Hacker News - Newest:
Hacker News - Newest: "LLM"
PCI Perspectives
PCI Perspectives
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
The Cloudflare Blog
Cloudbric
Cloudbric
AI
AI
WordPress大学
WordPress大学
博客园 - 聂微东
Jina AI
Jina AI
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
博客园 - 三生石上(FineUI控件)
Hacker News: Ask HN
Hacker News: Ask HN
H
Hacker News: Front Page
博客园 - Franky
V
V2EX
Schneier on Security
Schneier on Security
G
GRAHAM CLULEY
S
SegmentFault 最新的问题
有赞技术团队
有赞技术团队
H
Help Net Security
量子位
S
Security @ Cisco Blogs
大猫的无限游戏
大猫的无限游戏
cs.AI updates on arXiv.org
cs.AI updates on arXiv.org
Recorded Future
Recorded Future
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
J
Java Code Geeks
C
Cisco Blogs
S
Security Affairs

Consumer Insights

The ransomware negotiator who was working for the other side After years on the run, alleged Ryuk ransomware operator pleads guilty INTERPOL crackdown shows scammers shifting to social media Meta lets strangers remix your public Instagram photos with AI—here’s how to opt out Invited to a "job interview" with Netflix or OpenAI? Beware! Your Google password could be at risk Two arrested over credit card phishing - as the Netherlands is named Europe's worst for payment fraud India pauses WhatsApp username feature over security concerns Alleged teen ransomware hustler faces US charges after arrest in Finland WhatsApp usernames explained: how to reserve yours and stay safe Scammers race to cash in on Venezuelan earthquake disaster USB drives carrying China-linked malware infected Japanese military networks for nearly a year WhatsApp tests new safety prompt before you chat with strangers Social media is worth celebrating. It's also worth protecting. Polish police dismantle SIM-swap gang accused of crypto theft Operation Endgame deals fresh blow to StealC and Amadey malware networks Hacker hijacks Brazil's national alert system, sending "misanthropy" to millions of phones Cybercrime now rivals traditional crime across parts of Asia Apple's Hide My Email tweak leaves privacy fans fuming Americans lost $3.5 billion to imposter scams last year — and the scams are getting harder to spot Scammers have killed the physical Steam Gift cards Crypto investment scam sends couriers to collect victims' cash, FBI warns Maine forced to take down data breach portal after fake notices filed with authorities Privacy own-goal: World Cup blunder leaks Lionel Messi's passport details Why schools remain one of cybercriminals' favourite targets WhatsApp detects new spyware activity from Israel’s NSO Group despite court order Got a LinkedIn message from a recruiter? It might be Chinese intelligence, warn FBI and MI5 Europol cracks down on illegal streaming globally Hackers didn't hack Instagram; they just asked Meta AI FBI Warns Fans About FIFA Scams Ahead of 2026 World Cup Virtual knife, real lawsuit: Counter-Strike skin dispute ends in court As Deepfakes Spread, YouTube Makes AI Labels Harder to Miss Carnival breach exposes data of nearly 6 million people Police arrest man following hack of Ajax football club MyPillow listed on ransomware gang's leak site, but denies it has been breached FBI warns criminals impersonating IT support to breach law firms FBI warns of Kali365 phishing kit that breaks into Microsoft 365 accounts — no password required Telecom Executives Plead Guilty to Tech Support Fraud 7-Eleven data breach exposes data of 185,000 people ASIC Warns Australians About Crypto Trading Scams Google Search AI Mode brings a major overhaul Deleted Google API keys may remain active for 23 minutes Ukrainian police identify perp in $721k infostealer scheme Steam removes horror game after malware steals player data FBI: Crypto ATM Scams Keep Growing as Americans Lose Millions FBI warns students and staff that ShinyHunters may come knocking after Canvas breach Scam Centers Under Pressure as INTERPOL Makes More Arrests FBI Warns Older Adults Lost Billions to Scammers Burst Statistics WordPress flaw under attack Android 17 Will Let Users Verify Whether Their OS Is Legit Suspected Dream Market kingpin arrested after gold bars sent to his home address BitLocker zero-day exposes Windows drives as PoC goes public Apple Fixes ‘Persistent Notifications’ Flaw on Older iPhones Football Ticket Scams Are Rising Fast, Lloyds Bank Warns When ransomware gets physical: cybercriminals turn to threats of violence iPhone-to-Android Texts Are Now Encrypted (RCS Messaging) UK Water Supplier Fined Nearly £1 Million After Hackers Roamed Networks for Almost 2 Years Instagram Drops Encrypted DMs — What This Means for You New fear: Man films woman with smart glasses, seeks money to take video down ClickFix Campaign Uses Compromised WordPress Sites to Spread Vidar Stealer in Australia Inside Department 4: Russia's secret school for hackers Ubuntu’s new AI dreams attracted a very old-fashioned crypto scam on X Chrome 4GB AI model: What weights.bin does Sri Lanka makes 37 arrests as it raids another scam centre DAEMON Tools Lite breach prompts urgent update after malware-laced installer Brits Lost £102 Million to Romance Scams Last Year The Online Safety Act Is Changing the Internet for Kids World Password Day 2026 How Hackers Stole and Sold Roblox Accounts for $250,000 Before Getting Caught Four Years in Prison for Cybersecurity Pros Turned Ransomware Attackers Teenager alleged to be Scattered Spider hacker arrested in Finland, faces US extradition 276 Arrested in Crypto Scam Crackdown Popular WordPress redirect plugin found with years-old backdoor Iran-linked Handala hackers leak US Marines data, send chilling WhatsApp threats Alleged Silk Typhoon hacker extradited to the United States to face charges FTC: Social Media Scams Cost Americans $2.1 Billion in 2025 French police arrest 21-year-old "HexDex" hacker over 100 alleged data breaches iOS Flaw Exposed ‘Deleted’ Signal Messages Sony Starts Enforcing PlayStation Age Verification; UK and Ireland Are First Ransomware ‘Negotiator’ Faces 20 Years in Prison for Allegedly Betraying His Employers You’ve Got Mail and It’s Tracking Your Warship Crypto Investment Scam Costs Woman in Hong Kong Nearly $1 Million Operation PowerOFF warns 75,000 DDoS users Singer loses life savings to fake wallet downloaded from the Apple App Store AgingFly malware targets Ukraine government, hospitals 108 malicious Chrome extensions caught stealing Google and Telegram data from 20,000 users Rockstar Games confirms breach after ShinyHunters leaks stolen analytics data FBI: Cybercrime Losses Hit $21 Billion in 2025, Fueled by AI Life imprisonment for Cambodian scam compound operators - but will it make a difference? Fake Claude Code leak on GitHub spreads Vidar malware Apple Expands ‘DarkSword’ Patch to More iPhones and iPads Nigerian romance scammer jailed after being caught out by fellow fraudster Fake WhatsApp Clone Used in Spyware Campaign, Meta Warns Fake CERT-UA emails spread AGEWHEEZE in ukraine Alleged RedLine malware developer extradited to United States The Scam That Tricks You Into Infecting Your Own Mac Iranian hackers breach FBI director's personal email, and post his CV and photos online Meta and YouTube Designed Addictive Platforms, Jury Finds TikTok Business phishing campaign targets advertisers Lapsus$ claims AstraZeneca breach exposes code and credentials How one man used 10,000 bots to steal $8,000,000 from music artists
Don't Ignore This Security Alert Apple Sent to iPhone Lock Screens
Filip TRUȚĂ · 2026-03-30 · via Consumer Insights

If your iPhone isn’t up to date, you’re at greater risk of cyber-attacks — that’s Apple’s warning to users wielding older-generation hardware capped on outdated software versions.

Key takeaways:

  • Apple is escalating security warnings by pushing alerts directly to iPhone lock screens.
  • Outdated iPhones are actively targeted through real-world attacks exploiting known vulnerabilities.
  • Attacks can require minimal interaction —  sometimes just a visit to a malicious website or tapping a link.
  • Apple has already released patches, but devices remain vulnerable until users actually install updates.
  • Older devices are especially at risk, particularly those stuck on unsupported or delayed update cycles.
  • This isn’t only a high-profile target problem — everyday users can also be exposed if they fall behind on updates.
  • Apple’s unusual alert strategy highlights urgency, not routine maintenance.

The tech titan has taken the unusual step of pushing critical security warnings directly to iPhone lock screens, urging users to update their devices immediately amid active cyberattacks targeting outdated iOS versions.

The move echoes earlier warnings about exploit kits like Coruna and DarkSword, which threaten unpatched devices.

Lock screen alerts

As signaled by the Cupertino company earlier this month, users running older versions of iOS — including iOS 17 — now see a “Critical Software” notification appear directly on their lock screen. The alert warns that Apple is aware of real-world attacks targeting outdated devices and strongly recommends installing the latest update.

Unlike typical update reminders buried in settings, these alerts are deliberately hard to ignore. Apple is escalating its messaging because the threat is no longer theoretical.

Source: MacRumors

According to reports, attackers are actively exploiting vulnerabilities through malicious websites and links, meaning a simple tap could expose sensitive data on an unpatched device.

Coruna and DarkSword exploits

Apple’s warning ties into the continued use of sophisticated exploit kits targeting older iOS versions.

Security researchers have linked ongoing attacks to exploit kits like Coruna and DarkSword that can exploit vulnerabilities across multiple iOS generations — from iOS 13 up to early iOS 17 builds.

These toolkits are especially dangerous because they:

  • Require minimal user interaction (often just visiting a compromised site)
  • Can lead to data theft or device compromise
  • Target users who delay updates or use unsupported devices

This mirrors what we’ve previously covered — attackers don’t need zero-days if users stay on vulnerable versions.

Apple has already released fixes (but you need to install them)

Apple has patched the vulnerabilities in recent updates, including:

  • iOS 15.8.7
  • iOS 16.7.15
  • Newer iOS versions (devices with the latest, updated versions of iOS 15 through iOS 26 are already protected)

However, patches only protect people who actually install these updates.

Devices stuck on very old versions (like iOS 13 or 14) are being pushed to upgrade to iOS 15 just to receive critical protections.

Why Apple is taking this seriously

The Cupertino tech giant rarely uses lock screen alerts for updates, which makes this move notable.

According to reports, attacks are active, exploits are circulating, and outdated devices are prime targets.

What iPhone users should do now

If you receive this alert — or if you’re unsure about your device status — take action immediately:

1. Update your device

  • Go to Settings → General → Software Update
  • Install the latest available version

2. Avoid risky browsing behavior

  • Don’t click unknown links or pop-ups
  • Be careful of unsolicited messages

3. Enable built-in protections

  • Safari’s Safe Browsing is enabled by default and helps block malicious domains. If you’ve disabled it, consider switching it back on.

4. Consider additional security layers

Apple’s decision to push lock screen security alerts is a clear warning: attackers are actively targeting outdated iPhones, and the window to stay protected is shrinking.

As we regularly warn, exploit kits have historically been used in spyware attacks on the devices of activists, dissidents, political rivals, human rights advocates, investigative journalists and high-profile figures in general. Big-Tech players have been fighting spyware for years.

Even if you’re not a high-risk person, it’s a good idea to stay up to date with the latest security patches — you never know when you trip a wire and become a target.

The company has posted a support page dedicated entirely to updating iOS — from iOS 12 to iOS 26.

For those who can’t update their device for any reason, Apple recommends enabling Lockdown Mode.

Frequently asked questions (FAQ)

How do I know if an Apple security alert is real?

A real Apple security alert appears as a system notification on your device or through your Apple ID settings—not as a browser pop-up, random text, or phone call. Legitimate alerts never ask for passwords, payments, or to click suspicious links. If unsure, check directly in Settings or on Apple’s official website.

Why did I just get a security alert on my iPhone?

You may receive a real security alert if your iPhone is running outdated software, your Apple ID was used on a new device, or suspicious activity was detected. Apple sends these alerts to help protect your account and prompt you to take action, such as updating iOS or reviewing account access.

How to get rid of Apple security warning pop-up?

If it’s a fake pop-up, close the browser tab immediately, clear your browsing data, and avoid clicking any links. Then check your device for suspicious apps and update your iOS. If the alert came from a legitimate Apple notification, follow the instructions in Settings to resolve the issue.

Is the “your iPhone has been hacked” warning real?

In most cases, no. Messages claiming “your iPhone has been hacked” are usually scam pop-ups designed to scare you into clicking links or downloading malicious apps. Real Apple warnings do not use alarming language or appear as browser pop-ups.

You may also want to read:

‘Update iOS to Protect Your Data’ – Apple Urges Users to Patch Against Coruna and DarkSword Exploits

Apple Patches Older iPhones Against ‘Coruna’ Hacks Used in Espionage and Crypto Theft

Apple Debuts ‘Background Security Improvements’ with Urgent WebKit Fix for iPhone and Mac – Here’s How to Enable It