Accessibility links
  • Skip to main content
News Icon NEWS FILTER
All News Scams & Phishing Security Education Videos Mobile Security Your Security Education Identity Theft Corporate Security
Search Icon SEARCH
 

Email Icon SUBSCRIBE TO WEEKLY NEWSLETTER
Apple Patches Dangerous Zero-Day—Update Now!
Facebook   X   LinkedIn   Email

Apple Patches Dangerous Zero-Day—Update Now!

October 6, 2025

Heads up, Apple users—this one’s a seriously bad apple that can truly ruin the whole bunch. The company just rushed out a patch for a dangerous zero-day flaw, CVE-2025-43300, that’s already being wielded in the wild against targeted individuals. If your devices are running on any Apple operating system, be it a smartphone, tablet, or computer, take heed of this advice that could prevent you from getting a lot of worms in your fruit.

The flaw sits in Apple’s Image I/O framework—basically, the software that handles your images. If someone sends you a malicious image, your device could write data wrong—called "out-of-bounds write"—leading to memory corruption. In everyday terms? It opens the door for hackers to take over your device or install malware, which really won’t keep the doctor away for anyone.

Which devices and software versions are impacted?

If your devices are running versions older than the following, you're vulnerable:

  • iOS: versions up to 18.6.1 (patch is in 18.6.2)
  • iPadOS: versions up to 17.7.9 (patch in 17.7.10), and up to 18.6.1 (patched in 18.6.2)
  • macOS: Sequoia before 15.6.1, Sonoma before 14.7.8, Ventura before 13.7.8

CISA has already added this to its "Known Exploited Vulnerabilities" list and set a September 11, 2025 deadline for federal agencies to patch it.

What you should do right now:

  • Update your iPhones, iPads, and Macs immediately using Software Update. Make sure you hit iOS/iPadOS 18.6.2, iPadOS 17.7.10, macOS Sequoia 15.6.1, Sonoma 14.7.8, or Ventura 13.7.8.
  • Don’t delay—attackers are already using this. Yep. That’s what zero-day means. They were exploiting it even before a patch was ready.
  • Bonus tip: keep your device set to auto-update to stay protected against future threats.

Scary New Mac Attack Locks Browsers

Your Security

Scary New Mac Attack Locks Browsers

A new scareware attack is targeting Mac users, tricking them into believing their computer has been locked by Apple. Cybercriminals use a browser-based pop-up scam that mimics Apple’s official "Find My Mac" lock screen. Researchers at LayerX Labs have been tracking this for a while now. For this ruse, a fake lock screen appears after users visit compromised or malicious websites, creating panic and pressuring them into taking immediate action. READ FULL STORY

Spyware Pop-Up Danger – 4 Words NOT To Click

Scams & Phishing

Spyware Pop-Up Danger – 4 Words NOT To Click

When it comes to our personal online safety, sometimes knowing what NOT to do is as important as doing the smart thing. Avoiding trouble like spyware is crazy important, including knowing how not to download it. There are security basics we can all benefit from, and one of the following tips involves four little words NOT to click on with those annoying but potentially dangerous pop-ups. A security employee from McAfee shares the four words to avoid those bad pop-ups or risk downloading spyware. READ FULL STORY

Phone Scammers Use Big Tech As Lures

Mobile Security

Phone Scammers Use Big Tech As Lures

Ask a robocall recipient and they’ll tell you that robocalls are annoying and a waste of time. But the victim of a phone scam (vishing) will tell you it could mean losing a lot more than just time. Like email phishing, falling for a vishing scam can put you in danger of losing your identity, your money, and any other private information a criminal can get. So, what to do when the caller claims to be from a trusted business and has a legitimate reason to call? READ FULL STORY

Calling Your FI? You Could Be Calling a Hacker Instead

Mobile Security

Calling Your FI? You Could Be Calling a Hacker Instead

When did calling your financial institution (FI) turn into calling a hacker instead? Well, there’s now an improved Android banking trojan named FakeCall that’s intercepting calls to FIs. FakeCall reportedly has 13 new variations, with all making detection more difficult. It sounds hard to believe, but victims of FakeCall malware along with their financial accounts tell the story—and there’s more to know. One of them is that all versions have one thing in common. READ FULL STORY

New Malware Sparkles Up Your Android and iOS

Mobile Security

New Malware Sparkles Up Your Android and iOS

Who can you trust these days? Sadly, it’s getting more and more difficult to be sure. However, there are plenty of trustworthy cybersecurity researchers out there, such as those at Kaspersky. They found a mobile trojan just hanging out in the official app stores for the most popular smartphones just waiting to steal all of your photos. And it’s been out there hunting since February of 2024. It’s a follow-up to Kaspersky’s earlier warning about SparkCat spyware.  READ FULL STORY








Close
Fraud News & Alerts!

Keep up with the latest cyber security news through our weekly Fraud News & Alerts updates. Each week you will receive an email containing the latest cyber security news, tips and breach notifications.



You're all set!

You will receive your first official security update email within the next week.

A welcome email has also just been sent to you. If you do not receive this email within the next few minutes, please check your Junk box or spam filter to confirm our emails are not being blocked.


 
Help  
Enter any word or words you like.        

The email newsletter will arrive from news@stickleyonsecurity.com


Loading
Please wait...