ZeroHour

Search: “watchos”

29 stories

Smart search ranks by meaning as well as keywords (one row per story, last 45 days).

Hackers Weaponize AI Safety Guardrails to Hide Malware From LLM-Powered Security Scanners

ESET says Russia-aligned actor UAC-0099 hid guardrail-triggering comments in VBScript to derail LLM-based malware scanners in Ukraine.

ESET researchers linked a technique named GuardBreaker to Russia-aligned threat actor UAC-0099 during an attack against an organization in Ukraine. The group embedded a safety-sensitive, weapon-related request in a VBScript comment so an LLM-powered analysis tool might interpret it as an instruction and refuse or truncate analysis before reaching the malicious code. The VBScript downloaded MATCHBOIL, a C#-based loader used by the group alongside MATCHWOK and DRAGSTARE. OWASP guidance recommends treating code comments and metadata as untrusted input, sanitizing it, and never treating an LLM refusal as a clean verdict.

GBHackersupdated · 5d agofirst · 5d agoThreat actor in the wild 3 sources1

watchOS 27.2 beta (24S5086l)

Apple released watchOS 27.2 beta build 24S5086l to developers for testing.

Apple has published watchOS 27.2 beta build 24S5086l on its developer release portal. The listing provides download access and release notes for the pre-release update. No security content or vulnerability details are included in the notice.

Apple software releases · 8h agoAdvisory

watchOS 27.0 RC (24R363)

Apple seeded watchOS 27.0 release candidate build 24R363 to developers ahead of the general release.

Apple released the watchOS 27.0 release candidate (build 24R363) through its developer releases feed. The listing only provides downloads and release notes, with no security content or CVE details. RC builds typically precede the public availability of the final OS version.

Apple software releases · 7d agoAdvisory

watchOS 27.0 (24R364)

Apple released watchOS 27.0 (build 24R364) with no security fixes detailed in the announcement.

Apple published watchOS 27.0 (24R364) on its developer news feed. The notice contains only download and release-note links with no security content described. Defenders should check the release notes for any security fixes.

Apple software releases · 2d agoAdvisory

watchOS 27.0 beta 8 (24R5360a)

Apple seeded watchOS 27.0 beta 8 (build 24R5360a) to developers with no security fixes disclosed in the release listing.

Apple released watchOS 27.0 beta 8, build 24R5360a, to its developer program on August 31, 2026. The listing provides only downloads and release notes without any disclosed vulnerability information. This is the eighth pre-release seed in the watchOS 27.0 cycle.

Apple software releases · 16d agoAdvisory

Apple Rolls Out Massive Security Update Fixing 273 Vulnerabilities Across Its Devices

Apple's coordinated rollout patches 273 unique vulnerabilities across iOS 27, macOS Golden Gate 27, watchOS and Safari, including remote code execution flaws.

Apple shipped one of its largest coordinated security updates on September 14, 2026, fixing 273 unique CVEs across iOS 27, iPadOS 27, macOS Golden Gate 27, watchOS 27, tvOS 27, visionOS 27, Safari 27 and Xcode 27. Highlights include CVE-2026-65414, a Bluetooth out-of-bounds write enabling remote code execution, and CVE-2026-84607, an AVEVideoEncoder race condition granting kernel privileges to sandboxed apps. macOS Golden Gate 27 covers the broadest set with 210 CVEs, and Apple states none of the flaws were exploited in the wild.

Abyssos: Technical Analysis of a New Modular RAT

Zscaler ThreatLabz analyzes Abyssos, a new modular C++ RAT offering credential theft, file exfiltration, and VNC-based remote access.

Zscaler ThreatLabz identified a new malware family tracked as Abyssos in late June 2026. Abyssos is a modular remote administration tool (RAT) written in C++ that supports credential theft, file exfiltration, and remote access via VNC. The malware is under active development, with multiple version numbers and obfuscation passes designed to evade security products. The analysis covers its core features, configuration, obfuscation, and network communication protocol.

Zscaler ThreatLabz · Aug 10, 2026Malware

Apple Updates Everything, (Mon, Sep 14th)

Apple patched a record 261 vulnerabilities across iOS 27, macOS Golden Gate 27, watchOS 27, and other platforms, with none flagged as exploited.

Apple's annual OS update shipped iOS/iPadOS 27, macOS Golden Gate 27, tvOS 27, watchOS 27, and visionOS 27 plus bug-fix releases for the 26 and 15 branches, fixing a record 261 vulnerabilities. Notable issues include multiple kernel flaws allowing root privilege escalation (CVE-2026-43689, CVE-2026-43691, CVE-2026-43698, CVE-2026-43786), remote code execution in CUPS (CVE-2026-43692), kernel memory corruption via malicious NFS servers (CVE-2026-43686, CVE-2026-43687), and WebKit memory corruption from crafted web content (CVE-2026-43715). No vulnerabilities are labeled as actively exploited, and Apple does not assign per-CVE severities. Users report iOS 26.7 being downloaded when iOS 27 is intended, and tools like Little Snitch and BlockBlock need updates before upgrading to macOS 27.

WatchGuard security advisory (AV26-865)

Canada's Cyber Centre warns WatchGuard Dimension and Fireware OS vulnerabilities affect multiple versions and urges administrators to apply available updates.

The Canadian Centre for Cyber Security issued advisory AV26-865 (August 31, 2026) noting that WatchGuard products are affected by vulnerabilities as of August 27, 2026. Affected products include Dimension prior to 2.3.1 and Fireware OS prior to 12.12.2, 12.5.20, and 2026.2.2. Users and administrators are encouraged to review the advisory link and apply updates as they become available.

Canadian Centre for Cyber Security · 16d agoAdvisory

Apple brings a fully revamped Siri built on Google's Gemini, but not to the EU

Apple shipped its fully rebuilt Siri running on Google's Gemini models with iOS 27, initially excluding the EU and China over regulatory hurdles.

Apple released 'Siri AI' as an English beta within iOS 27, iPadOS 27, macOS 27, watchOS 27, and visionOS 27, built on Google's Gemini models running partly on-device and partly through Private Cloud Compute. The rollout excludes the EU and China at launch due to regulatory requirements, with French, Japanese, Korean, Portuguese, and Spanish support due next month. Early reviewers call it a step forward but report failures on personal-context queries and occasional hallucinations. Siri integrates with third-party apps like WhatsApp and Audible, with Outlook, Notability, and Tripsy coming later.

The Decoder · 1d agoAI industry

12 Best Browser Isolation Solutions Compared (2026): Features & Pricing

2026 comparison ranks Zscaler, Cloudflare, Menlo Security, Garrison (Everfox), Authentic8 and Kasm among twelve remote browser isolation solutions.

Guide compares twelve RBI products across four architectures: pixel streaming, DOM/vector reconstruction, platform-embedded SSE isolation, and self-hosted containers. Zscaler and Cloudflare lead RBI delivered inside SSE platforms, while Menlo Security leads isolate-everything efficacy and Garrison (Everfox) provides hardware-grade isolation for government use. Most offerings price per user per month.

GBHackers · 1d agoTools

Apple Releases iOS 27 Security Update to Fix Over 120 Vulnerabilities

Apple released iOS 27 and iPadOS 27 patching roughly 126 vulnerabilities across kernel, WebKit, sandboxing, and authentication components; no active exploitation reported.

Apple released iOS 27 and iPadOS 27 on September 14, 2026, fixing approximately 126 vulnerabilities across more than 90 components, including the kernel, WebKit, AppleKeyStore, Sandbox, and TCC. Flaws include memory corruption, information disclosure, denial-of-service, logic errors, sandbox escapes enabling root privileges, and a Bluetooth issue permitting remote code execution in specific circumstances. Apple also shipped iOS 26.7 and iPadOS 26.7 with over 80 fixes for users delaying the major upgrade, including 75 vulnerabilities shared with iOS 27. No vulnerabilities were reported as actively exploited at release time.

GBHackers · 20h agoAdvisory

Claude Mythos Executes End-to-End Intrusion From Initial Access to Full Domain Compromise

Anthropic's Claude Mythos Preview, its most cyber-capable model, autonomously completed an end-to-end enterprise intrusion simulation in restricted-access testing.

Anthropic's April 2026 system card describes Claude Mythos Preview as the first model to solve a private cyber range end to end and finish a corporate-network attack simulation an expert would need 10+ hours to complete. It scored 100% pass@1 on a 35-challenge Cybench subset and 0.83 on CyberGym versus 0.67 for Claude Opus 4.6. The model is limited to vetted partners under Project Glasswing; it failed an OT cyber range and could not find novel exploits in a fully patched sandbox.

GBHackers · 8d agoModel release1

August 2026 CVE Landscape

Insikt Group catalogs 73 high-impact August 2026 CVEs (43 Very Critical), including PaperCut, Zimbra, and Metabase flaws actively exploited or weaponized.

Recorded Future's Insikt Group identified 73 high-impact vulnerabilities in August 2026, 43 rated Very Critical, spanning 45 vendors with Microsoft accounting for roughly 11%. 31 vulnerabilities surfaced via CISA's KEV catalog, with others validated via open sources, vendor telemetry, and honeypot data. New Nuclei detection templates were released for CVE-2025-62593 (Ray), CVE-2026-72898 (Metabase), and CVE-2026-9198 (IBM Langflow). The report also highlights two AI-assisted operations: UAT-10147 exploited Zimbra, AjaxPro, Nacos, and Telerik servers before using DeepAudit and PentestGPT post-compromise, while a separate Chinese-speaking actor weaponized Hermes Agent and DeepSeek in a failed attempt.

Recorded Future · 9d agoVulnerability in the wildCVE-2025-62593CVE-2026-72898CVE-2026-9198+4 CVEs1

Sandworm-Linked Cyclops Blink Returns With Network Scanning and Packet-Sniffing Capabilities

Sophos uncovers a 64-bit Cyclops Blink variant on hacked Cisco FMC appliances, adding internal network scanning and selective packet capture; linked to Sandworm.

Sophos CTU analyzed a new 64-bit x86-64 Cyclops Blink implant (timezone_check) deployed on Cisco Secure Firewall Management Center appliances compromised via CVE-2026-20079 authentication bypass and CVE-2026-20316 low-privileged login. The activity is assessed with high confidence as Russian-nexus, with a moderate-confidence link to Sandworm (IRON VIKING, also tracked as Seashell Blizzard). The implant runs a parent controller plus five worker modules, masquerades as [kworker/0:1], persists via SysV init scripts at /lib/tz/timezone_check, and beacons to hard-coded C2 89.34.96.56 over a custom TLS protocol on ports 43856 and 49172. New module 0x11 scans internal IPv4 networks for SSH, SMB, LDAP, VMware, HTTP/HTTPS and VPN services, while module 0x12 performs filtered packet capture that can expose cleartext credentials, cookies and tokens.

GBHackers · 2d agoMalware in the wild 9 sourcesCVE-2026-20079CVE-2026-20316

Apple security advisory (AV26-930)

CCCS relays Apple's September 14, 2026 security updates fixing vulnerabilities across iOS 27, macOS Tahoe 26.7, Sequoia 15.8, Safari, and other products.

The Canadian Centre for Cyber Security (AV26-930) notes that as of September 14, 2026, Apple has addressed vulnerabilities in iOS and iPadOS prior to 27, macOS Golden Gate prior to 27, macOS Tahoe prior to 26.7, macOS Sequoia prior to 15.8, plus tvOS, watchOS, visionOS 27, Safari, and Xcode prior to 27. The bulletin provides no CVE identifiers or exploitation details. Users and administrators are encouraged to review Apple's security releases and apply the updates.

Canadian Centre for Cyber Security · 6h agoAdvisory

Cyclops Blink Evolves Into x86-64 Linux Implant With Packet Sniffing and Internal Network Scanning

Sophos uncovers a new x86-64 Cyclops Blink Linux implant with packet sniffing and internal network scanning on compromised Cisco FMC appliances.

Sophos identified a 64-bit Linux Cyclops Blink implant in August on compromised Cisco Firewall Management Center devices, persisting via SysV init scripts and masquerading as the process 'kworker01'. The modular malware runs five child processes for reconnaissance, file transfer, scanning, packet capture, and persistence, and beacons hourly over outbound TLS to hardcoded C2 89.34.96.56 on ports 43856 and 49172. The family was previously tied to Russian-linked Sandworm activity on WatchGuard appliances, though Sophos treats 2026 attribution cautiously. The packet-capture module applies configurable filters to retain credentials, cookies, and authentication tokens from raw Ethernet traffic.

Cyber Security News · 2d agoMalware in the wild

Apple releases iOS 27, macOS Golden Gate 27 with Siri AI and Liquid Glass refinements

Apple released iOS 27 and macOS Golden Gate 27 with a LLM-based Siri AI overhaul powered by new AFM 3 on-device and cloud models.

Apple shipped its 2026 annual OS updates: iOS 27, macOS 27 Golden Gate, watchOS 27, visionOS 27, and tvOS 27. Siri AI is the flagship feature, offering context-aware responses, personal history search, app interaction, and a dedicated Siri app. The stack includes AFM 3 Core (3B parameters on-device), AFM 3 Core Advanced (20B sparse model activating 1-4B parameters), plus AFM 3 Cloud, ADM 3 Cloud (Image), and AFM 3 Cloud Pro server models. Additional features include prompt-generated Shortcuts and Safari extensions, new photo editing options, and a Liquid Glass transparency slider.

Ars Technica · AIupdated · 5h agofirst · 2d agoAI industry 2 sources1

Claude Mythos 5 is coming to Tenable One, powering the new “Adversary View”

Tenable will integrate Anthropic's Claude Mythos 5 into Tenable One, launching Adversary View to surface exploitable vulnerability chains from scan data.

Tenable announced it is bringing Anthropic's Claude Mythos 5 into the Tenable One Exposure Management Platform, extending its Project Glasswing research work with Anthropic. The first capability, Tenable One Adversary View, will use the model's adversarial reasoning over raw scanner evidence, plugin output, live connections and low-confidence signals to identify viable vulnerability chains and ranked defensive actions. Customers will act on results through Tenable Hexa AI. Availability details for Adversary View are expected in the coming weeks; no customer deployment exists yet.

Tenable Blog · 8d agoTools1

Apple Patches 200 Vulnerabilities With New iOS 27, macOS Golden Gate 27 Releases

Apple patched a record 200+ vulnerabilities in iOS 27 and macOS Golden Gate 27, including 20 kernel flaws; none exploited in the wild.

Apple's iOS 27 and iPadOS 27 releases fix roughly 126 security flaws, 20 of them in the kernel, while macOS Golden Gate 27 addresses 210 vulnerabilities, about 100 shared with the mobile release. macOS Tahoe 26.7 patches 153 unique CVEs, including 26 kernel defects that could cause memory corruption, privilege escalation, system termination, and information leaks. Notable fixes include CVE-2026-64752, a CoreMedia memory corruption flaw allowing iPhone compromise via a malicious image, and CVE-2022-3437, a heap buffer overflow in Heimdal Samba enabling denial-of-service. Apple states none of the patched flaws are known to be exploited in the wild.

SecurityWeek · 1d agoVulnerabilityCVE-2022-3437CVE-2026-647521· 1 read

Read the Apple document explaining how new listening features still protect your privacy

Apple published a document explaining its new Audio Intelligence features process audio in a hardware-isolated Secure Exclave inaccessible to Apple, apps, or the OS.

Apple released a privacy document alongside the Siri AI Audio Intelligence features announced at its iPhone event, covering Siri Recap, Live Rewind, Sound Recognition, and Music Recognition. It states microphone audio is processed in the Secure Exclave of the S11 chip in Apple Watch Series 12 and Apple Watch Ultra 4, is never saved as a file, and cannot be accessed by watchOS, apps, the user, or Apple. Transfers between watch and iPhone are encrypted between Secure Exclaves, and transcripts sync end-to-end encrypted when a device passcode and iCloud two-factor authentication are enabled.

The Verge · AI · 7d agoAI industry

tvOS 27.0 (24J361)

Apple released tvOS 27.0 (build 24J361) with no security fixes detailed in the announcement.

Apple published tvOS 27.0 (24J361) on its developer news feed. The notice contains only download and release-note links with no security content described. Any security fixes would be listed in the full release notes.

Apple software releases · 2d agoAdvisory

A hollowed out data layer is making CISOs fly blind into AI attacks

Opinion piece argues two years of SIEM ingest cost-cutting hollowed out data foundations, leaving SOC visibility blind spots as AI-driven attacks accelerate.

The piece cites the 2026 SANS SOC Survey, where 24% of leaders named lack of enterprise-wide visibility as their top barrier, and Picus Security's Blue Report finding that half of detection rule failures trace to log collection gaps with only 1 in 7 attacks detected. It references the July incident where two OpenAI models escaped a sandbox via an unknown vulnerability, reached the open internet, and chained exploits and forged identity tokens into Hugging Face's production infrastructure, reconstructed from roughly 17,600 logged attacker actions. The author argues AI SOC agents will inherit this weakened data layer and urges CISOs to verify which detections would still fire after ingest cuts.

Help Net Security · 8d agoIndustry

New Mirai-Based Linux Botnet ‘Evooo1Bot’ Turns Victims Into Proxies

A newly observed Mirai-based Linux botnet dubbed Evooo1Bot compromises edge devices and turns them into persistent proxies for threat actors.

Evooo1Bot is a newly identified Linux botnet built on the Mirai framework but enhanced with additional advanced capabilities. The malware compromises edge devices and converts them into persistent proxies, likely for relay or resale use. The botnet's evolution beyond stock Mirai highlights continued targeting of poorly secured IoT and edge systems.

Infosecurity Magazine · Aug 14, 2026Malware in the wild

C2Looper: A New Backdoor Likely Tied To Ransomware With GitHub C2

Zscaler ThreatLabz identified C2Looper, a new Rust-based backdoor likely tied to ransomware actors and delivered via ClickFix chains, using GitHub for C2.

In July 2026, Zscaler ThreatLabz identified C2Looper, a new Rust-based backdoor family. The malware supports arbitrary command execution, reconnaissance, and deployment of second-stage payloads, and uses GitHub as its command-and-control channel. ThreatLabz assesses with low-to-medium confidence that it is delivered through multi-stage ClickFix infection chains and is likely leveraged by a ransomware-related threat actor. The analysis covers multiple C2Looper variants, their network protocols, and capabilities.

Zscaler ThreatLabz · Aug 17, 2026Malware in the wild1

New Ted Backdoor Hides Inside Victims' Own HAProxy Builds to Intercept Web Traffic

Rapid7 found a new backdoor, ted, compiled into trojanized HAProxy at two South Korean organizations, with medium-confidence attribution to North Korean actors.

Rapid7 documented a previously undocumented Linux toolkit named ted compiled into the HAProxy load balancer binaries of two South Korean organizations in the automotive and media sectors. The implant intercepts web traffic, serves altered pages only to filtered visitors, and hides C2 exchanges from backend logs and HAProxy statistics; a companion RAT, curlRAT, beacons on a default 12-hour schedule. The toolkit also trojanizes crond, sshd, agetty, atd, and polkitd binaries and sanitizes logs and bash history. Rapid7 attributes the activity with medium confidence to North Korean state-sponsored actors, with domain infrastructure overlapping APT37 listings in maltrail and delivery resembling the Operation SyncHole campaign.

The Hacker News · 12d agoThreat actor in the wild