Technology
Relentless hackers abandon Windows to target your Apple ID
If there’s one thing that has become clear over the past year, it’s that Apple devices are not as secure as the company wants you to believe.
We’re four months into 2025 and there have already been over 10 instances in which attackers specifically targeted Apple users, and these are just the incidents we know of.
I’ll admit no device is foolproof, but there seems to be a growing trend where bad actors prefer targeting Apple users over other platforms. In fact, security researchers have recently identified a new phishing campaign in which hackers, who previously focused on Windows, are now setting their sights on Apple IDs.
STAY PROTECTED & INFORMED! GET SECURITY ALERTS & EXPERT TECH TIPS – SIGN UP FOR KURT’S ‘THE CYBERGUY REPORT’ NOW
A person working on an Apple laptop (Kurt “CyberGuy” Knutsson)
What you need to know
Security researchers at LayerX Labs have uncovered a new phishing campaign that specifically targets Mac users, marking a shift from its previous focus on Windows. The attackers initially lured Windows users with fake Microsoft security alerts designed to steal login credentials. However, after Microsoft, Chrome and Firefox implemented new security features to block these attacks, the hackers started redirecting their efforts toward Mac users instead.
The new attack closely mirrors its predecessor but with key modifications. The phishing pages have been redesigned to resemble Apple’s security warnings, making them appear legitimate to macOS users. The attack code has also been adjusted to specifically detect macOS and Safari users, ensuring that only Apple users see the fraudulent pages.
Plus, despite shifting their focus, the attackers continue to host these phishing pages on Microsoft’s Windows[.]net domain. Since this is a trusted Microsoft platform, it allows the phishing pages to evade detection by security tools that assess risk based on domain reputation.
Compromised websites displaying fake security warning (LayerX)
FBI WARNS OF DANGEROUS NEW ‘SMISHING’ SCAM TARGETING YOUR PHONE
How victims are lured in
The phishing campaign exploits common yet highly effective methods called typosquatting and malicious redirects. Victims often end up on these phishing pages after making a simple mistake, such as mistyping a URL while trying to visit a legitimate website.
Instead of reaching the intended site, they land on a compromised domain parking page. From there, they are redirected through multiple websites before ultimately arriving at the phishing page, which presents a fake Apple security warning. Believing their Apple ID is at risk, victims are tricked into entering their credentials, unknowingly handing them over to the attackers.
One notable case involved a person using Safari who was working at a business secured by a Secure Web Gateway. Despite the organization’s security measures, the phishing attempt managed to bypass the gateway’s protections.
WHAT IS ARTIFICIAL INTELLIGENCE (AI)?
Compromised websites displaying fake security warning (LayerX)
APPLE’S IOS VULNERABILITY EXPOSES IPHONES TO STEALTHY HACKER ATTACKS
7 ways to stay safe from attackers targeting Apple users
Phishing campaigns are increasingly targeting macOS users, but you’re not defenseless. Here are four essential steps to protect yourself.
1. Use strong antivirus software: A reliable antivirus program is your first line of defense against phishing attempts and malicious websites. While Apple’s built-in security features provide some protection, they aren’t foolproof, especially against sophisticated phishing attacks that mimic legitimate Apple warnings. A robust antivirus solution can detect and block malicious sites before you even reach them, preventing you from accidentally entering your credentials on a fraudulent page. Additionally, advanced security software can identify suspicious redirects and alert you before you fall victim to typosquatting traps. Get my picks for the best 2025 antivirus protection winners for your Windows, Mac, Android and iOS devices.
2. Keep your software up to date: Regular updates to macOS and your applications aren’t just about new features. They’re critical patches that fix security vulnerabilities. Attackers are quick to exploit any weakness, so ensuring your operating system and all installed software are current minimizes the risk of a breach. Enable automatic updates where possible so you’re always protected by the latest security enhancements.
3. Regularly monitor your Apple ID activity: Even with strong security measures in place, it’s important to keep an eye on your Apple ID account for any signs of unauthorized access. Apple allows users to review their account activity, including devices logged into the account and recent changes. Regularly check your Apple ID settings to ensure that only trusted devices are connected and that no suspicious activity has occurred. If you notice anything unusual, such as login attempts from unfamiliar locations, immediately change your password and remove unauthorized devices. This proactive approach can help you catch potential breaches early and minimize damage.
4. Enable two-factor authentication (2FA): Strong, unique passwords for every account are essential, but they’re even more effective when combined with two-factor authentication. Even if attackers manage to steal your credentials through a phishing attack, 2FA adds an extra barrier that makes unauthorized access significantly harder. Consider using a password manager to generate and store complex passwords. Get more details about my best expert-reviewed password managers of 2025 here.
5. Use a recovery key for enhanced security: Apple offers an optional feature called a recovery key, which is a 28-character code that provides an extra layer of security for your Apple ID. When you enable a recovery key, Apple disables its standard account recovery process, meaning you’ll need this key, along with access to a trusted device or phone number, to reset your password or regain access to your account. This makes it significantly harder for attackers to take control of your account.
To set up a recovery key, go to Settings > [Your Name] > Sign-in & Security > Recovery Key on your iPhone, iPad or Mac. Follow the prompts to generate and confirm your recovery key. Be sure to write it down and store it in a secure location, such as a safe or with a trusted family member. Keep in mind that losing both your recovery key and access to trusted devices can permanently lock you out of your account. However, if used responsibly, this feature gives you greater control over your account’s security.
6. Enable biometric authentication: Apple devices offer advanced biometric authentication options like Face ID and Touch ID, which provide an extra layer of security. These features make it significantly harder for attackers to gain access to your device or sensitive accounts, even if they manage to steal your credentials. Enable biometric authentication wherever possible, especially for apps and services that store personal or financial information. Since biometric data is unique to you, it adds a level of protection that passwords alone cannot provide.
7. Practice safe browsing: Many attacks rely on simple user mistakes, such as mistyping a URL or clicking on suspicious links. Always verify that you’re visiting legitimate websites before entering any personal information. Be skeptical of unexpected security alerts, even if they mimic Apple’s design. Learning to identify the subtle signs of phishing, like unusual URL structures or generic greetings, can help you avoid falling for these scams.
HOW TO PROTECT YOUR IPHONE & IPAD FROM MALWARE
Kurt’s key takeaways
Apple has long sold the idea that its ecosystem is inherently safer than the alternatives, but that claim is starting to wear thin. The reality is that attackers are no longer ignoring Mac users, they’re actively targeting them, and Apple’s response has been anything but proactive. While Microsoft, Google and others roll out new security measures to counter evolving threats, Apple remains slow to adapt, relying on outdated assumptions about its platform’s safety.
Do you believe Apple should be more transparent about security vulnerabilities affecting its users? Let us know by writing us at Cyberguy.com/Contact.
For more of my tech tips and security alerts, subscribe to my free CyberGuy Report Newsletter by heading to Cyberguy.com/Newsletter.
Ask Kurt a question or let us know what stories you’d like us to cover.
Follow Kurt on his social channels:
Answers to the most-asked CyberGuy questions:
New from Kurt:
Copyright 2025 CyberGuy.com. All rights reserved.
Technology
TikTok ban: all the news on the app’s shutdown and return in the US
After briefly going dark in the US to comply with the divest-or-ban law targeting ByteDance that went into effect on January 19th, TikTok quickly came back online. It eventually reappeared in the App Store and Google Play as negotiations between the US and China continued, and Donald Trump continued to sign extensions directing officials not to apply the law’s penalties.
Finally, in mid-December, TikTok CEO Shou Zi Chew told employees that the agreements to create TikTok USDS Joint Venture LLC, which includes Oracle, Silver Lake, and MGX as part owners, have been signed, and the deal is expected to close on January 22nd, 2026. His letter said that for users in the US, the new joint venture will oversee data protection, the security of a newly-retrained algorithm, content moderation, and the deployment of the US app and platform.
Read on for all the latest news on the TikTok ban law in the US.
Technology
Secret phrases to get you past AI bot customer service
NEWYou can now listen to Fox News articles!
You’re gonna love me for this.
Say you’re calling customer service because you need help. Maybe your bill is wrong, your service is down or you want a refund. Instead of a person, a cheerful AI voice answers and drops you into an endless loop of menus and misunderstood prompts. Now what?
That’s not an accident. Many companies use what insiders call “frustration AI.” The system is specifically designed to exhaust you until you hang up and walk away.
Not today. (Get more tips like this at GetKim.com)
FOX NEWS POLL: VOTERS SAY GO SLOW ON AI DEVELOPMENT — BUT DON’T KNOW WHO SHOULD STEER
Here are a few ways to bypass “frustration” AI bots. (Sebastian Kahnert/picture alliance via Getty Images)
Use the magic words
You want a human. For starters, don’t explain your issue. That’s the trap. You need words the AI has been programmed to treat differently.
Nuclear phrases: When the AI bot asks why you’re calling, say, “I need to cancel my service” or “I am returning a call.” The word cancel sets off alarms and often sends you straight to the customer retention team. Saying you’re returning a call signals an existing issue the bot cannot track. I used that last weekend when my internet went down, and, bam, I had a human.
Power words: When the system starts listing options, clearly say one word: “Supervisor.” If that doesn’t work, say, “I need to file a formal complaint.” Most systems are not programmed to deal with complaints or supervisors. They escalate fast.
Technical bypass: Asked to enter your account number? Press the pound key (#) instead of numbers. Many older systems treat unexpected input as an error and default to a human.
OPENAI ANNOUNCES UPGRADES FOR CHATGPT IMAGES WITH ‘4X FASTER GENERATION SPEED’
“Supervisor” is one magic word that can get you a human on the other end of the line. (Neil Godwin/Future via Getty Images)
Go above the bots
If direct commands fail with AI, be a confused human.
The Frustration Act: When the AI bot asks a question, pause. Wait 10 seconds before answering. These systems are built for fast, clean responses. Long pauses often break the flow and send your call to a human.
The Unintelligible Bypass: Stuck in a loop? Act like your phone connection is terrible. Say garbled words or nonsense. After the system says, “I’m having trouble understanding you” three times, many bots automatically transfer you to a live agent.
The Language Barrier Trick: If the company offers multiple languages, choose one that’s not your primary language or does not match your accent. The AI often gives up quickly and routes you to a human trained to handle language issues.
Use these tricks when you need help. You are calling for service, not an AI bot.
CLICK HERE TO DOWNLOAD THE FOX NEWS APP
Long pauses and garbled language can also get you referred to a human. (iStock)
Get tech-smarter on your schedule
- National radio: Airing on 500-plus stations across the U.S. Find yours or get the free podcast.
- Daily newsletter: Join 650,000 people who read the Current (free!)
- Watch: On Kim’s YouTube channel
Award-winning host Kim Komando is your secret weapon for navigating tech.
Copyright 2026, WestStar Multimedia Entertainment. All rights reserved.
Technology
The latest iPad Air is $400 for the first time and arrives by Christmas
If you have $400 and want an iPad, your options are usually kind of limited to either just the base iPad, or better yet, the latest iPad Mini — if it happens to be on sale when you’re shopping (it is now, but that’s not always the case). But right now, you should consider getting the 128GB version of Apple’s 11-inch iPad Air with the capable M3 processor. At Target, multiple colors of this model are $399.99, beating the previous low of $449.99 we’ve seen during large-scale deal events. Currently, no other retailer is matching this price. This sale ends Saturday night.
$400 is a sweet price for this model, as it debuted in early 2025 for $600. In terms of how it stacks up to other iPad models, Verge editor-at-large David Pierce said in his impressions that the M3 Air is “exactly what you think it is. Which is fine.” I know, that sounds like a back-handed compliment, but it’s been a while since iPads peaked in terms of utility, design, and fast performance. This one carries the torch in Apple’s tablet dominance, and its M3 processor means it’ll be a fantastic tablet for longer than any other iPad at the $400 price point. Read our in-depth impressions.
Other Verge-approved deals
-
Iowa4 days agoAddy Brown motivated to step up in Audi Crooks’ absence vs. UNI
-
Washington1 week agoLIVE UPDATES: Mudslide, road closures across Western Washington
-
Iowa6 days agoHow much snow did Iowa get? See Iowa’s latest snowfall totals
-
Maine3 days agoElementary-aged student killed in school bus crash in southern Maine
-
Maryland4 days agoFrigid temperatures to start the week in Maryland
-
Technology1 week agoThe Game Awards are losing their luster
-
South Dakota5 days agoNature: Snow in South Dakota
-
Nebraska1 week agoNebraska lands commitment from DL Jayden Travers adding to early Top 5 recruiting class