The company on Monday pushed out emergency security updates for iOS, macOS, and its other operating systems to plug a hole that threatened security on a range of devices. Credit: Bitdefender Apple on Monday issued emergency security updates for iOS, macOS and its other operating systems to plug a hole that Canadian researchers claimed had been planted on a Saudi political activist’s device by NSO Group, an Israeli seller of spyware and surveillance software to governments and their security agencies. Updates to patch the under-active-exploit vulnerability were released for iOS 14; macOS 11 and 10, aka Big Sur and Catalina, respectively; iPad OS 14; and watchOS 7. According to Apple, the vulnerability can be exploited by “processing a maliciously crafted PDF,” which “may lead to arbitrary code execution.” The phrase “arbitrary code execution” is Apple’s way of saying that the bug was of the most serious nature; Apple does not rank threat level of vulnerabilities, unlike operating system rivals such as Microsoft and Google. Apple credited The Citizen Lab for reporting the flaw. Also on Monday, Citizen Lab, a cybersecurity watchdog organization that operates from the Munk School of Global Affairs & Public Policy at the University of Toronto, released a report outlining what it found. “While analyzing the phone of a Saudi activist infected with NSO Group’s Pegasus spyware, we discovered a zero-day zero-click exploit against iMessage,” Citizen Lab researchers wrote. The exploit, which Citizen Lab dubbed “FORCEDENTRY,” had been used to infect the phone of the activist — and possibly others as far back as February 2021 — with the NGO Group’s “Pegasus” surveillance suite. It, in turn, consists largely of spyware that can document texts and emails sent to and from the device as well as switch on its camera and microphone for secret recording. Citizen Lab was confident that FORCEDENTRY was associated with Pegasus and thus, NGO Group. According to researchers, the spyware loaded by the zero-click exploit contained coding characteristics, including ones never made public, that Citizen Lab had come across in previous analysis of NGO Group and Pegasus. “Despite promising their customers the utmost secrecy and confidentiality, NSO Group’s business model contains the seeds of their ongoing unmasking,” Citizen Labs’ researcher wrote in their Monday report. “Selling technology to governments that will use the technology recklessly in violation of international human rights law ultimately facilitates discovery of the spyware by investigatory watchdog organizations.” Apple device owners can download and install the security-only updates issued Monday by triggering a software update through the device’s OS. Related content how-to A new Windows 11 backup and recovery paradigm? If used properly, new features built into Windows 11 offer safe, nearly complete backup, restore, repair, and recovery operations without third-party tools — but there are some caveats worth knowing. By Ed Tittel Apr 29, 2024 17 mins Windows 11 Backup and Recovery Windows feature Q&A: Georgia Tech dean details why the school needed a new AI supercomputer Georgia Tech partnered with Nvidia to roll out its first supercomputer so students can experiment with AI and machine learning to better prepare for a job market where those skills are now critical to success. By Lucas Mearian Apr 29, 2024 12 mins CPUs and Processors Education Industry Generative AI feature Windows 11 Insider Previews: What’s in the latest build? Get the latest info on new preview builds of Windows 11 as they roll out to Windows Insiders. Now updated for Build 22635.3566 for the Beta Channel, released on April 26, 2024. By Preston Gralla Apr 26, 2024 251 mins Small and Medium Business Microsoft Windows 11 news Dropbox adds end-to-end encryption for team folders Dropbox this week unveiled a range of features, including security updates and key management, and the ability to co-edit Microsoft 365 documents from within the file-sharing app. By Matthew Finnegan Apr 26, 2024 3 mins Cloud Storage Collaboration Software Productivity Software Podcasts Videos Resources Events SUBSCRIBE TO OUR NEWSLETTER From our editors straight to your inbox Get started by entering your email address below. Please enter a valid email address Subscribe