Cybersecurity · Wednesday, 30 September 2026
Apple has fixed a hole in how iPhones and Macs open files. Apple says someone may already have used it against a few chosen people.
Apple released updates on Monday for a flaw in CoreGraphics, the part of its software that draws pictures and documents. Meta's security team found it, and Apple says it may have been used against specific people on iPhones older than iOS 27.
8.8 of 10
the hole's severity score on the standard scale for security flaws
a rating added by CISA; NIST, which runs the US National Vulnerability Database, has not scored it yet
3 days
for US federal agencies to install Apple's fix
they must also check by 2 October whether attackers got in before the fix
fewer than 200
people aimed at last year, when a WhatsApp flaw was likely used with an Apple flaw
SecurityWeek asked Meta whether this year's hole was also used through WhatsApp, and had no reply
The lead story — what happened
-
Apple released updates on Monday for iPhones, iPads and Macs to close a hole in CoreGraphics, the part of its software that draws pictures, text and documents.
[1] [2] [5] -
A booby-trapped file could let an attacker run their own program on the device, Apple says.
[6] [4] -
Apple says the hole may have been used in an extremely sophisticated attack on specific people, on iPhones running versions older than iOS 27.
[6] [4] -
iOS 27, Apple's newest iPhone system, and the newest Mac system do not appear to have the flaw, SecurityWeek reports.
[2] -
The fix is iOS 26.7.1 for the iPhone 11 and later, with matching updates for iPads and for Macs.
[1] [5] -
Meta's product security team found the hole and reported it to Apple.
[1] [4] -
Apple has not said who was attacked, how many people, who was behind it, or how the file reached them.
[5] [2] -
SecurityWeek says a file like this could arrive in a web page, an email or a messaging app.
[2] It adds that automatic previews might mean nobody has to tap it.[2] -
Last year WhatsApp said a flaw in its own app was likely used together with an Apple flaw against fewer than 200 people.
[2] -
SecurityWeek asked Meta whether this attack also came through WhatsApp, and had no answer when it published.
[2] -
CISA, the US government's cyber-defence agency, added the hole to its list of flaws being used in attacks.
[3] -
CISA gave federal agencies three days to install the fix, and until 2 October to check whether they had already been broken into.
[3]
Who is involved
-
Apple
makes the iPhone, iPad and Mac; released the fix on Monday and has said almost nothing about the attacks
-
Meta Product Security
the security team at Meta, the company behind Facebook, Instagram and WhatsApp; found the hole and reported it to Apple
-
CISA
the US government's cyber-defence agency; ordered federal agencies to install the fix within three days
-
The attackers
not named by anyone; Apple calls the attack extremely sophisticated and aimed at specific people
How it unfolded
-
2025 WhatsApp says a flaw in its app was likely used with an Apple flaw against fewer than 200 people
[2] -
February Apple fixes another flaw attackers had used, in a different part of its software
[1] [4] -
Mon 28 Sep Apple releases iOS 26.7.1 and Mac updates, and credits Meta with finding the hole
[2] [5] -
This week CISA adds the hole to its list and gives US federal agencies three days to fix it
[3] -
2 Oct Deadline for those agencies to check whether they were broken into before the fix
[3]
Where this points
Watch whether Apple or Meta says how the booby-trapped file reached its targets, and whether it came through a messaging app, as last year's WhatsApp case did.
What is pushing on the whole day
The bar and the word are our reading of how hard each one is pushing today. The arrow is where it is heading. The evidence is in the stories below.
Apple fixed an iPhone hole that it says may have been used against chosen people.
Criminals put fake versions of ChatGPT on OpenAI's own website to send people to harmful software.
Russian government hackers now send trick emails to tens or hundreds of people at a time, and one click is enough.
Apple has not said who was attacked or how many.
The rest of the day
14 more stories on this beat.
Each with its own sources. None of these is a link to the story above.
-
02
Hackers take Dodo Pizza customer data
Dodo Pizza, a Russian chain with about 1,500 restaurants in 28 countries, said on Monday that hackers got into its systems.
[7] Customers' names, addresses, email addresses, phone numbers, birth dates and order details may have been taken.[7] The company says it does not store card details, so no payment data was taken.[7] It has told Roskomnadzor, Russia's communications regulator.[7] A group calling itself DataSuckers claims it took records on 68 million customers and offers to sell them for about $100,000.[7] Dodo's own countnone givenThe hackers' claim68 millionDodo Pizza has not said how many customers were affected. The only number so far is the hackers' own, and nobody has checked it. Why it matters — Dodo has not said how many customers were affected, and nobody has checked the hackers' number.
[7] Earlier this month the same group claimed an attack on Tez Tour, one of Russia's major tour companies.[7] -
03
Russian spies switch to mass emails
Microsoft says Star Blizzard, a hacking group tied to Russia's FSB security service, has added large mailings to its carefully aimed emails.
[12] Since January it has run at least 13 big campaigns, each of tens to hundreds of emails, mostly against governments, research groups and non-profits.[12] The emails invite people to exclusive events, or warn of tax audits, payment notices and fines.[12] Microsoft counts more than 100 organisations affected, mostly in the US and UK.[12] Why it matters — The group aimed first at Ukraine, then at banks and governments that support Ukraine.
[12] Its new method needs only one click from the victim before it installs a hidden program that lets it listen in.[12] -
04
Hackers copy Arizona court records
The Arizona Supreme Court said on Friday that hackers broke into the state's court system and copied personal details of many people in Arizona.
[13] Chief Justice Ann Scott Timmer said the courts are trying to warn as many of those people as possible.[13] A court spokesperson said it was not a ransomware attack, and no ransom had been demanded as of Monday.[13] No group has claimed the break-in.[13] Why it matters — The court will not say what was taken or how, because it says details could affect the FBI's investigation.
[13] Courts hold large amounts of personal and police data, and court systems in at least ten other US states have been hit in recent years.[13] -
05
Fake ChatGPT helpers spread spy software
Criminals built custom versions of ChatGPT, which anyone can publish on OpenAI's own website, to lead people to harmful software, the security firm Huntress says.
[8] [9] Victims searched Google for ChatGPT and clicked a paid advert at the top of the results.[9] The fake assistant, called Plus 5.6, sent them to a page with a fake security check that told them to run a command.[8] [9] That installed a program that lets the attacker control the computer and use its camera and microphone.[8] Why it matters — OpenAI removed the first fake by 25 September, and a second one turned up two days later.
[8] Because the fake sits on ChatGPT.com, the address looks trustworthy.[8] OpenAI already plans to retire custom versions of ChatGPT on 11 December.[8] -
06
OnePlus phones left open for months
A researcher, Rasmus Moorats, showed that a harmful app can take full control of a OnePlus 15 phone without asking for any permissions.
[17] He joined two flaws in software OnePlus adds to its phones, and says an older OnePlus 12 Pro is affected too.[17] OnePlus confirmed the flaws in May and told him it alone decides when a flaw is made public.[17] He published on 24 September anyway, when there was still no fix.[17] Why it matters — OnePlus warned that publishing without its permission could bring legal action, and says phones from OPPO, which use the same software, share the problem.
[17] There is no sign of a real attack yet, and the harmful app has to be installed on the phone first.[17] -
07
Two former airmen jailed for email fraud
Two former US Air Force members were sentenced on Friday for stealing from businesses by email while stationed at Dover Air Force Base in Delaware.
[10] [11] Chijioke Timothy Odimegwu, 25, got 111 months in prison and Harafat Mogaji, 26, got 78 months.[11] They stole email logins with fake messages, then watched for talk of payments.[10] At the right moment they sent new bank details that looked like they came from a business partner.[10] [11] Why it matters — One payment they diverted was more than $1.68 million from a victim in Iowa City, and another was $720,000 from a victim in Ohio.
[11] They were ordered to repay $366,617 and $995,680, and ran the scheme for more than two years before the FBI and local police caught them.[10] [11] -
08
An AI program breaks into a Dutch security group
DIVD, a Dutch non-profit whose volunteers scan the internet for known flaws and warn the owners, says it has been hacked for the first time in seven years.
[14] An attacker used a flaw in one of its systems, then let an AI program work inside the network on its own.[14] DIVD says the program chose each next step by itself and was loud and very messy.[14] It even got in the way of one of its own attacks.[14] Why it matters — The mess left enough evidence for DIVD to piece together what happened, and it has told the Dutch police and data-protection regulator.
[14] It says the flaw was not in Citrix, and it will give more details on 1 October and warn others with the same flaw.[14] -
09
Police read chats by linking a computer
Germany's customs office has been linking police computers to suspects' WhatsApp and Signal accounts, the security writer Bruce Schneier noted on Tuesday.
[16] Both apps let people add a laptop to their account, and new messages then arrive on the laptop too.[16] So officers can read the messages without breaking the scrambling that protects them on the way.[16] German reports say they get in by holding the phone, or by catching the one-time approval code through a fake message or a phone tap.[16] Why it matters — Schneier says the apps should clearly show every linked device, so a person could notice one they never added.
[16] -
10
Man charged over a $16m crypto scam
US prosecutors have charged Trung Nguyen Van, a 37-year-old from Vietnam, with laundering money from a so-called pig butchering scam.
[18] In these scams a stranger met online builds trust, then talks the victim into a fake investment.[18] One victim sent about $16 million in cryptocurrency between June and August 2024, believing it went to a platform called Triangle.[18] Van was arrested on 24 September at Los Angeles airport, before a flight to Taiwan.[18] One victim$16mVan's wallets, 2018-24$53mThe wider scheme$125mOne victim's transfers, the money Van's wallets took in, and the wider fraud prosecutors say the charges come from, in millions of US dollars. Why it matters — Prosecutors say his wallets took in more than $53 million from fraud aimed at Americans between 2018 and 2024.
[18] The FBI says investment scams cost Americans $8.6 billion in 2025.[18] -
11
Signal backups now on every device
Signal, the private messaging app, has released version 8.30, which brings scrambled backups to iPhones and computers as well as Android phones.
[15] A backup lets people get their chats back on a new device if they lose their phone.[15] Backups can be kept by Signal, free for up to 45 days of photos and videos, or kept on the user's own device with no size limit.[15] Both kinds are scrambled and need a recovery key to open.[15] Kept by Signal, free45 days of mediaKept on your deviceno size limitThe free backup that Signal stores keeps 45 days of photos and videos. A backup kept on the phone or computer itself has no size limit. Why it matters — One recovery key opens every past backup it made, and BleepingComputer says attackers have already made that key a target.
[15] Messages set to vanish within 24 hours are left out of backups.[15] -
12
New chip trick leaks a Linux password
Researchers at VU Amsterdam and Scuola Superiore Sant'Anna have found a new version of Spectre, a known kind of attack on computer processors.
[19] Processors predict which instructions come next and briefly run them early.[19] The new attack makes a processor predict from leftovers of old code, so it briefly runs the wrong instructions and exposes data.[19] On Intel processors running Linux, it recovered the scrambled form of the main administrator password in three to five minutes on average.[19] Why it matters — The researchers told the affected companies, and fixes are already in the Linux kernel, the core of the system.
[19] A scrambled password still has to be cracked, which depends on how strong the password is.[19] -
13
An example web address turns into a trap
Coding guides often use third-party.com as a made-up example address, the way others use example.com, BleepingComputer reported on 23 September.
[20] Unlike example.com, which is reserved for guides, third-party.com is an ordinary domain whose owner controls what it shows.[20] It began showing a fake Cloudflare security check that tells Windows users to paste in and run a command.[20] Why it matters — The security firm Manifold found it while reading public guides for AI tools that name the address.
[20] The server that delivered the next stage no longer worked when BleepingComputer tested it.[20] -
14
Cloudflare plans its own web certificates
Cloudflare, which gave millions of websites free encryption in 2014, said on Tuesday it plans to become a certificate authority.
[21] A certificate authority issues the digital certificates that let a website scramble its traffic and prove who it is.[21] Cloudflare says it has agreed to buy trusted root keys from GlobalSign, an existing authority, so older devices will accept its certificates.[21] It will also issue a new kind of certificate meant to hold up against future quantum computers.[21] Why it matters — Cloudflare says trust on the web rests on a few big issuers, which is a risk if one of them fails.
[21] It has applied to be accepted by Google's Chrome, Apple, Microsoft and Mozilla, which each decide what their software trusts.[21] -
15
Finnair trains pilots for daily GPS jamming
The airline Finnair has changed how it trains pilots because GPS signals are disrupted every day over the Baltic Sea, its chief executive told Reuters last Thursday.
[22] Finnair stopped flying over Russia and Belarus, so more of its routes now cross the Baltic, a hotspot for this kind of electronic interference.[22] Poland said in August that satellite signals on its Baltic coast were disrupted on most summer days.[22] In 2024 Finnair paused flights to Tartu in Estonia for about a month.[22] Why it matters — Modern planes have several backup ways to find their position, so they keep flying safely.
[22] The chief executive, Turkka Kuusisto, says airlines from outside Europe are surprised that it is a daily problem.[22]
A message is only scrambled while it travels
Apps like WhatsApp and Signal scramble messages on the way, so anyone who wants to read them goes after the phone at either end.
The twist
Scrambling protects a message only while it travels. On the phone that shows it to you, the message has to be readable, so that is where the attacks go.
The picture
How it works
- Apps like WhatsApp and Signal scramble each message before it leaves the phone
- Anyone in between sees only scrambled text, even the company that runs the app
- The message is unscrambled on the phone at each end, so people can read it
- So anyone who wants it goes to an end: a hole in the phone, an extra linked computer, or a backup
- There the message is already readable, and nothing had to be broken
The same force, elsewhere today
Where this chain is also running, in today's other stories.
-
Police read chats by linking a computer
German customs officers added their own computer as a linked device, so new messages arrived there already readable and nothing had to be cracked.
-
Signal backups now on every device
A backup keeps the whole chat history at one end of the line, and one recovery key opens all of it, which is why attackers want that key.
-
OnePlus phones left open for months
An app that takes full control of the phone sits at the end of the line, where messages are shown to the owner in plain text.
Where you've seen this
Cash vans
the armoured van is hard to rob, so robbers wait for the guard carrying the bag across the pavement
Sealed letters
the envelope keeps the post office out, but not someone reading over your shoulder once it is open
Exam papers
they travel in sealed boxes, so leaks usually happen at the printer or in the school office
The catch
Getting to the ends is costly: it takes an unknown hole in the phone, the phone in hand, or a stolen approval code. So it is used on chosen people, not on everyone.
And the whole of it
Every message you send is readable on at least two phones, and on any laptop or backup linked to them. You can keep your own phone updated. You cannot see how the person you are writing to looks after theirs.
What is really going on
Apple and Meta closed a hole that Apple says may have been used against a few chosen iPhone owners, and neither company has said who was attacked or who did it.
Why it works on us — Hearing that only a few chosen people were attacked makes most iPhone owners feel it has nothing to do with them. The fix is for every iPhone 11 or later that has not moved to iOS 27.
Who gains
-
DataSuckers, the group that hit Dodo
— With no count from Dodo, its claim of 68 million customers is the only number, and it is offering the data for about $100,000.
[7] -
OnePlus
— By keeping the flaws private from May until a researcher published, it went about five months without a public warning to owners.
[17] -
The criminals behind the fake ChatGPTs
— Their trap sat on ChatGPT.com and was reached through a paid Google advert, which made it look genuine.
[8] [9] -
Star Blizzard
— A mass-mailing tool lets it send trick emails to hundreds of people at a time, and one click from anyone is enough.
[12] -
German customs investigators
— Linking a computer to a suspect's account gives them the messages without having to break any scrambling.
[16]
Who pays
-
Chosen iPhone owners on versions older than iOS 27
— Apple says the hole may have been used against them, and it has not said publicly who they are.
[4] [5] -
Dodo Pizza customers
— Their names, addresses, phone numbers, birth dates and order details may have been taken.
[7] -
Businesses in Iowa and Ohio
— One lost a payment of more than $1.68 million and another $720,000 to new bank details sent by the two airmen.
[11] -
People who searched Google for ChatGPT
— A paid advert led them to a fake assistant, and then to software that lets criminals use their camera and microphone.
[9] [8] -
OnePlus and OPPO owners
— Their phones carry flaws that a harmful app can use to take full control, and there is no fix yet.
[17] -
The pig butchering victim
— About $16 million in cryptocurrency went to a fake platform called Triangle.
[18]
What nobody knows yet
Open questions from across today’s stories — ours included.
-
01
Who used the iPhone hole, against whom, and how many people.
Apple has not said who was targeted, how many, or who was behind it, and Meta has given no details.
[5] [4] -
02
How the booby-trapped file reached its targets.
SecurityWeek asked Meta whether it came through WhatsApp, as a similar attack likely did last year, and had no answer.
[2] -
03
How many holes Apple has fixed this year after attackers found them first.
The Register counts it as the seventh flaw this year that Apple fixed after attackers found it first. BleepingComputer counts two used in real attacks since January.
[5] [1] -
04
How many Dodo Pizza customers are affected.
Dodo has given no number. The only figure is the hackers' claim of 68 million customers, which nobody has checked.
[7] -
05
What was copied from Arizona's courts, and about how many people.
The court says only that it was many Arizonans, and will not give details while the investigation goes on.
[13] -
06
How many people the fake ChatGPT assistants infected.
SecurityWeek reports at least 40 infected. BleepingComputer says Huntress investigated at least 40 incidents and confirmed that only two came through a fake assistant.
[9] [8] -
07
When OnePlus will fix its phones, and which OPPO phones are affected.
OnePlus confirmed the flaws in May, has released no fix and has not named the OPPO models.
[17] -
08
How DIVD's attacker got in.
DIVD says only that the flaw was not in Citrix, and promises more details on 1 October.
[14]
Apple has fixed the hole that may have been used against chosen iPhone owners, in iOS 26.7.1 and matching updates for iPads and Macs. Meta's security team found it and reported it to Apple.
Also true today
- Two former US Air Force members who diverted business payments by email were sentenced to 111 and 78 months in prison. They were ordered to repay more than $1.3 million between them.
- Signal has finished bringing scrambled backups to Android, iPhone, Windows, Mac and Linux, so people who lose a phone can get their chats back.
- Fixes for a new attack on Intel processors, which leaked the scrambled form of a Linux password in minutes, were already in the Linux kernel when the researchers described it.
- A man charged over a $16 million crypto investment scam was arrested at Los Angeles airport before he could board a flight to Taiwan.
More from Cybersecurity
Across the beats