Apple has issued a new series of threat notifications to customers suspected of being targeted by mercenary spyware. These alerts were sent to users in 110 countries, indicating that their iPhones, iPads, or Macs might have been compromised. This latest round of warnings contributes to Apple's ongoing effort, which has seen customers in over 150 countries notified to date.
The company has updated its user experience for these warnings. Notifications will now appear directly on the iPhone lock screen as a push notification, urging recipients to take action. The message reads: “Apple detected a mercenary spyware attack targeted at your iPhone. There are actions you can take now to protect your data and device.” Apple also sends notifications via email and when users log in to their accounts.
A new support article titled “About Apple threat notifications and protecting against mercenary spyware” has been published, detailing what these notifications are, how they are delivered, and recommended protective measures.
Mercenary spyware attacks are typically highly sophisticated and expensive, aimed at a small number of individuals rather than the general public. These targets often include journalists, activists, politicians, and diplomats. The spyware can bypass encryption to access private files, monitor conversations, capture audio and video, track locations, and control devices.
Apple advises anyone who receives a threat notification to enable Lockdown Mode on their iPhone, iPad, or Mac. This mode provides extreme, optional protection for devices against highly targeted cyberattacks.
Apple has been sending these threat notifications multiple times a year since 2021, when it began detecting highly targeted mercenary spyware attacks. While Apple does not identify the specific spyware behind individual alerts, it has cited NSO Group's Pegasus as an example of mercenary spyware historically associated with this type of attack. Forensic investigations into previous Apple threat notifications have confirmed Pegasus infections in some cases.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
At least 14 individuals in Serbian civil society were targeted with advanced spyware, including NSO Group's Pegasus, in what the Share Foundation describes as the largest documented surveillance wave in Serbia. This incident highlights the use of sophisticated tools against pro-democracy movements, raising concerns about digital rights and potential government involvement ahead of upcoming elections.
At least 14 Serbian opposition figures and activists were targeted with advanced spyware, including Pegasus and a new Android variant called NoviSpy, coinciding with local elections. Digital forensic researchers confirmed infections, with one victim's messages appearing on a pro-government TV network, indicating a pattern of digital surveillance against critical voices.
Citizen Lab and SHARE Foundation reported that NSO Group's Pegasus spyware infected a Serbian student activist's iPhone via an iMessage zero-click exploit. This incident is part of a broader pattern of advanced spyware targeting activists and opposition figures in Serbia, with at least 14 individuals affected since early 2026.
Apple has updated its threat notification system to display alerts directly on device Lock Screens and in Settings, making them more prominent for users targeted by mercenary spyware. These notifications indicate detected activity suggesting a spyware attack, prompting users to seek digital forensic investigation from experts like Access Now's Digital Security Helpline.
Apple recently sent out a large wave of threat notifications to users in 110 countries, warning them of suspected "mercenary spyware" attacks. Digital rights groups and cybersecurity firms report a significant increase in users seeking help after receiving these alerts, indicating this batch is the largest yet.
Apple issued threat notifications to users in 110 countries regarding targeted mercenary spyware attacks on iPhones, iPads, and Macs. These attacks are aimed at high-profile individuals like journalists and politicians, and Apple advises enabling Lockdown Mode to protect devices.
Apple issued threat notifications to users in 110 countries suspected of being targeted by mercenary spyware. These alerts are high-confidence warnings for individuals like journalists and activists, indicating sophisticated, resource-intensive attacks.
Apple has sent out a new round of notifications to users it believes have been targeted by mercenary spyware attacks, such as Pegasus. The company also updated its user experience for these warnings and published a new support page detailing mercenary spyware and protective measures, including enabling Lockdown Mode.
Apple has sent out a new batch of "Threat Notification" alerts to users whose iPhones are suspected of being targeted by mercenary spyware. These notifications, which Apple has issued since 2021, indicate highly sophisticated and expensive attacks typically aimed at a small number of individuals like journalists, activists, and diplomats.
Apple has notified users in 110 countries about potential mercenary spyware attacks, bringing the total number of countries alerted over the past few years to more than 150. The company also released a new support article detailing threat notifications and security recommendations.
Apple has sent out a new round of push notifications to users in 110 countries, alerting them to potential mercenary spyware attacks on their devices. These notifications, which now appear directly on the iPhone lock screen, advise users on steps to protect their data and devices, including enabling Lockdown Mode.