Apple Warns Users in 110 Countries They May Be Targets of Mercenary Spyware
Apple sent mercenary spyware threat notifications to users in 110 countries, including Ukrainian military members, in what researchers call an unprecedented notification wave.
Apple notified an unspecified number of users in 110 countries that they may have been targeted by mercenary spyware attacks, bringing total notifications to over 150 countries since the program began in late 2021. Apple does not attribute the attacks but describes the alerts as high-confidence indicators of individual targeting against journalists, activists, politicians, and diplomats. Citizen Lab's John Scott-Railton called the geographic scale unprecedented, and Access Now reported a record number of help requests, with recipients including members of Ukraine's military. Apple advised users to update devices, enable 2FA and Lockdown Mode, and use Stolen Device Protection.
Apple warned hundreds of users of mercenary spyware attacks
Apple sent threat notifications to users in 110 countries warning of targeted mercenary spyware attacks and recommending Lockdown Mode.
Apple sent a new round of threat notifications warning users in 110 countries they may have been individually targeted by mercenary spyware, adding to alerts issued in more than 150 countries since the program began in 2021. The company says such attacks are vastly more sophisticated than criminal activity, cost millions of dollars, and typically target journalists, activists, politicians, diplomats, and lawyers. Apple recommends verifying notices directly at account.apple.com, enabling Lockdown Mode, keeping devices updated, and seeking expert help such as Access Now's Digital Security Helpline. Citizen Lab researchers note the alerts can reveal that entire communities are under targeted surveillance.
⚡ Weekly Recap: AI-Powered PLC Attacks, GitLab Attacks, Stripe Key Leaks and More
US agencies warn of AI-assisted attacks on exposed Siemens PLCs; the week also saw GitLab CVE-2026-19478 exploited and trojanized npm packages found.
The weekly recap leads with a US government warning that threat actors use AI-generated scripts and Censys/ZoomEye scanning to attack internet-exposed Siemens S7 PLCs in water, energy and manufacturing, calling it an active threat. Other stories include active exploitation of GitLab CVE-2026-19478 (CVSS 9.4, unauthenticated project rewriting), 14 trojanized npm packages delivering the RedC2 4.0 Linux backdoor, and the Zombie Card attack that revives expired Visa cards for contactless payment fraud. It also covers suspected Russian clusters UNC6293, UNC7005 and UNC5976 phishing campaigns, a faster Cloudflare Workers Spectre JWT leak, and a bespoke Cl0p JSP web shell deployed after exploiting PTC Windchill flaws.