Feed aggregator

Smashing Security podcast #478: This job interview could destroy your company

Graham Cluely Security Blog - Wed, 07/29/2026 - 7:09pm
You've been headhunted for a great job in cryptocurrency. All you have to do is complete a short online assessment - with your webcam on, of course, so they can verify who you really are. Which is ironic, because the person recruiting you doesn't exist. And North Korean hackers using this trick have already made off with $643 million in crypto this year alone. Meanwhile, researchers at UC San Diego have discovered that 2.2 million cars across the United States can be unlocked or immobilised by anyone with a bit of Bluetooth kit - thanks to one aftermarket car alarm that made a truly spectacular cryptographic blunder. The bug has been sitting there since 2017. Nobody noticed. All this and more in episode 478 of the "Smashing Security" podcast with cybersecurity expert and keynote speaker Graham Cluley, and special guest Paul Ducklin.
Categories: Graham Cluely

AI accelerates exploit timelines from months to hours. Organizations must shift from patch-all to risk-based prioritization using exploitability metrics.

Security Wire Daily News - Wed, 07/29/2026 - 7:01pm
AI accelerates exploit timelines from months to hours. Organizations must shift from patch-all to risk-based prioritization using exploitability metrics.

Deepfake phishing simulation software uses AI to probe organizational resistance to state-of-the-art social engineering attacks. Learn why they should be on CISOs' radar.

Security Wire Daily News - Wed, 07/29/2026 - 7:01pm
Deepfake phishing simulation software uses AI to probe organizational resistance to state-of-the-art social engineering attacks. Learn why they should be on CISOs' radar.

CherryTree Note Taker App

Hacker News - Wed, 07/29/2026 - 6:46pm

Article URL: https://www.giuspen.net/cherrytree/

Comments URL: https://news.ycombinator.com/item?id=49104083

Points: 1

# Comments: 1

Categories: Hacker News

Show HN: An AI Color Grader – Pico

Hacker News - Wed, 07/29/2026 - 6:43pm

I'm a filmmaker, and have been pretty frustrated by AI video editors that are focused on automating editing instead of helping artists produce their visions. Recently got curious about whether Claude could color grade my footage, and built Pico. Turns out Claude can (sometimes!)

Please feel free to ask questions, try it on your own footage, or contribute to the project!

Ask: if you are a researcher or hobbyist filmmaker, I'd love to chat with you to figure out how to make the models better at this!

Comments URL: https://news.ycombinator.com/item?id=49104055

Points: 1

# Comments: 0

Categories: Hacker News

Apple accused of letting fake crypto app steal $1.8 million

Malware Bytes Security - Wed, 07/29/2026 - 6:30pm

Apple’s tagline for its App Store says, “The apps you love. From a place you can trust.” You might love the apps, but can you trust the store? A federal lawsuit filed in the Northern District of California last week suggests not.

Three people have accused Apple of promoting a fake version of the Sparrow Wallet cryptocurrency app through its App Store, even though the real app’s developer had spent over a year telling Apple that he hadn’t produced a version for the mobile platform.

The fake app drained a combined $1.8 million from the victims’ wallets between May and August 2025, and now they’re furious with Apple for allowing it to happen.

How the scam worked

According to the legal complaint published courtesy of BleepingComputer, James Ramirez, Christopher Ellis, and Jalen Delgado downloaded a fake version of Sparrow Wallet from Apple’s App Store. It asked users to enter their recovery phrase (the 12 or 24 words that restore access to a crypto wallet), which is something a legitimate wallet app may also ask for during setup.

Instead of keeping that information private, though, the app handed it to the criminals running the scam. Once someone else has your recovery phrase, they have access to your wallet. If they transfer your cryptocurrency to another address, you cannot get it back.

Ramirez, Ellis, and Delgado say they lost approximately $875,000, $840,000, and $120,000 in Bitcoin, respectively.

Apple terminated the legit developer’s account

The real Sparrow Wallet is a desktop application for Windows, macOS, and Linux. It has never had an official iPhone app.

Craig Raw, the developer of the actual Sparrow Wallet, reported fake versions to Apple in the weeks leading up to January 2024 and publicly confirmed that month that the fake app was still live despite repeated reports.

About a year later, he tried a workaround to stop people from downloading the fake app by submitting a placeholder iOS app with screenshots explicitly warning users that Sparrow Wallet was not available on iOS. Apple responded by terminating his developer account. Thankfully it reversed it later, otherwise he would have been unable to maintain the macOS version.

The complaint also alleges that Apple featured the fake app in curated cryptocurrency collections alongside legitimate products, and allowed additional fake Sparrow Wallet apps onto the App Store even after consumers complained.

Apple’s official response, per TechCrunch, is that:

“apps impersonating others are a violation of its guidelines and it takes swift action to remove them.” Not swift enough, apparently.

The three users are now suing Apple, alleging that it misrepresented the App Store as trustworthy despite knowing about the fake apps. The complaint includes claims of fraudulent concealment, among others, and seeks a jury trial. The plaintiffs are seeking compensation for their losses, along with additional damages permitted under California law.

Not a one-off

Fake cryptocurrency apps are a trend. Kaspersky researchers recently identified 26 crypto wallet impersonators inside Apple’s ecosystem, all targeting seed phrases and recovery keys.

Rather than including malicious code directly inside the app, many of these scams direct users to a convincing fake App Store webpage, where they’re prompted to install another version of the app. That malicious version steals cryptocurrency recovery phrases or private keys by abusing enterprise distribution certificates intended for internal company apps.

How to stay safe

Apple points to its enforcement volume: it terminated 193,000 developer accounts and rejected more than 371,000 copycat submissions in 2025. Those figures come from Apple itself, with no mention of an independent audit. The company says that it uses a mixture of human review and machine learning to spot malicious apps.

If you use cryptocurrency on an iPhone, don’t assume that an App Store listing guarantees an app is genuine. Download apps using links from the developer’s official website whenever possible, and check that the developer actually offers an iPhone version before installing it.

The App Store is generally safer than downloading apps from elsewhere, but this case is a reminder that it is not infallible.

Scammers know more about you than you think. 

Malwarebytes Mobile Security protects you from phishing, scam texts, malicious sites, and more. With real-time AI-powered Scam Guard built right in. 

Download for iOS → Download for Android → 

Categories: Malware Bytes

Pages