GoKawiil Original QR Code Scams Explained: How to Check a Code Before You Scan It
Quishing works because a QR code gives you nothing to judge before you commit. Here is what the scams look like in practice and the habits that defuse them.
Quishing works because a QR code gives you nothing to judge before you commit. Here is what the scams look like in practice and the habits that defuse them.
Security researcher Patrick Wardle discovered that any app or Terminal command running on a Mac could silently alter undocumented settings in Meta's new Muse AI agent without requiring special macOS permissions. One affected setting, endo_voyager_dictation_endpoint, determines where a user's dictated voice prompts are transmitted, meaning an attacker could reroute that data elsewhere. The flaw surfaced just weeks after Meta heavily promoted Muse's security architecture, including a dedicated Secure VM, a monitoring system called Sentinel, and bug bounties up to $300,000.
Passkeys replace a secret you know with a key your device holds. That single change removes most of what makes phishing work, and it changes how account recovery should be set up.
Check Point Software has issued emergency hotfixes for CVE-2026-93616, a critical path traversal vulnerability in its Security Management Server that lets unauthenticated attackers upload and run arbitrary scripts. The company confirmed the flaw is being actively exploited, with a handful of customers already compromised, and released a fix in R82.20 Security Hotfix covering Security Management Server, Multi-Domain Security Management Server, Log Server, Multi-Domain Log Server, and SmartEvent.
According to The Elec, Samsung plans to embed a security chip inside batteries for upcoming mid-range devices, including the Galaxy A series. The chip would let the phone verify whether an installed battery is genuine, mirroring a system Apple has used for years with iPhones.
A tech guide outlines how homeowners can assemble their own smart security systems using motion sensors, door sensors, cameras and video doorbells that store footage locally instead of in the cloud. The approach avoids recurring subscription costs charged by brands like Abode and SimpliSafe, while still letting users customize and expand their setup over time.
In the latest Apple @ Work episode, host discusses tailored phishing simulations with Samantha Schwartz and Jack Hirsch of Sublime Security. The conversation focuses on how simulated phishing tests are evolving to reflect increasingly sophisticated, AI-generated attack techniques. The episode is sponsored by Mosyle, which markets itself as a unified Apple device management platform used by over 45,000 organizations.
The default configuration on a consumer router is tuned for setup convenience, not for the years it then spends untouched. A few changes cover most of the gap.
BleepingComputer is partnering with Material Security for a live webinar on September 23 examining documented Google Workspace breaches. Speakers Rajan Kapoor of Material Security and Rick Fitzgerald of Fireside Consulting will dissect two incidents where attackers used social engineering and rogue OAuth apps to gain access, then walk through the response decisions that followed.
An extension can read and change everything you do in the browser, including pages you are signed into. That is worth about ninety seconds of checking first.
Security researcher Patrick Wardle found an unpatched setting in Meta's Muse macOS app that let local attackers reroute the app's cloud-based dictation to their own server, effectively seizing control of the AI agent. Wardle demonstrated the flaw by using Muse's own privileges to snap photos and write files to disk, often without alerting the user. Meta issued a hotfix within hours of the report, though it maintains the exploit required existing local access and posed low real-world risk.
New code found in iOS 27.2 beta 2 shows Apple continuing development of an internal feature called AutoLock, which detects signals like sudden acceleration, loss of connection to a paired Apple Watch, or extended network dropout to guess that an iPhone has been snatched and lock it automatically. The code also reveals safeguards, including biometric checks, familiar-location detection, and a voting system where certain signals can veto a false lock trigger. The feature remains inactive and unavailable to users in this beta.