Breaking
August 21, 2026

This Week in Security: Apple Warns Users, Stripe Merchants Leak Keys, Copilot Helps Hack Itself, and Comcast Senses Movement Mike Kershaw | usagoldmines.com

Apple has started sending some users push notifications warning that they have been targeted with specific malware. No specific information about the threat Apple detected is available. While multiple iOS attacks were released in spring of 2026, they all target much older versions of iOS and older hardware versions.

Users in 110 countries have received notifications recently, warning them they may have been targeted or already impacted by malware such. Apple typically uses the crash reporting mechanism for system apps to track new attack trends. The majority of users will likely never see an alert from Apple because malware with state-level capabilities like the Pegasus family is extremely expensive to develop. However, commercial availability means that some governments have deployed them against political opponents, protesters, human rights lawyers, and journalists.

If Apple pushes a security alert, it will show up as an email and a standard system notification, but also as a notification inside the Settings application. While email and notifications can be spoofed as part of phishing attempts, to date there is nothing which can generate false alerts inside Settings.

Almost universally in these cases, Apple recommends enabling “Lockdown Mode“, which adds extra protection to devices at the cost of decreased battery life and slower performance. Lockdown mode disables custom fonts on web pages, accelerated JavaScript, restricts message attachments over SMS and iMessage, and disables other common paths used by malware to steal data. Android devices offer a similar feature since Android 15 that is less comprehensive but can still provide additional safeguards for users directly at risk.

Attacking Airplane Networks

With research that will surely result in some breathless reports, researchers presented at Usenix 2026 an attack against the communications bus of a Boeing 737.

The ARINC 429 bus is a communications architecture for planes, similar to the CAN bus used in cars. Once you are connected to that bus, it can be vulnerable in the same ways cars can be vulnerable to data manipulation. In the Usenix paper, researchers discovered that one access port to the airplane communications system is easily reached from the outside of the plane, though “easily” in this context means “by airplane maintenance technicians”. The paper represents over a decade of work by the team in obtaining and building a test lab of avionics equipment to represent an actual airplane, culminating in an embedded device described as “the size of a quarter” that plugs into the communications port and provides remote access over WiFi.

It needs to be emphasized, given other recent news, that this is a piece of hardware being added to the plane which communicates over WiFi, and not a way to attack an unmodified plane via passenger WiFi!

Once part of the ARINC bus, it seems access is basically unfettered: the team describes being able to reprogram the autopilot, feed the pilot displays false data, and being able to modify the temperature and weight data shown, which could lead to miscalculations in take-off speeds with obviously catastrophic results. Fortunately, the researchers have also been working with Boeing since 2020 to address the issues being found, and the practicality of the attack in the wild remains largely theoretical. The research team has recommended removing the external ports in future aircraft, and blocking access to them physically, like with epoxy, in the current designs.

If reading security research papers is your kind of fun, be sure to check out the rest of the papers that were part of Usenix 2026.

Copilot Reveals Secrets

Microsoft Copilot was tricked into executing hostile prompts without user intervention, and the team that accomplished it used Copilot itself to expose the vulnerability.

Copilot has a set of guardrails in place intended to safeguard against disclosing private information. Given the initial question — asking how to submit a prompt without the user confirming — the model said this was impossible. Over the course of many questions, researchers at Varonis were able to get Copilot to disclose the exact errors and restrictions that prevented running unauthorized queries, culminating in it admitting that there was an undocumented URL parameter (“autorun=1”, naturally) that would automatically execute a query.

Why such a parameter would exist in the first place is a little unclear. The Ars Technica article says that when Microsoft removed the parameter as part of the initial fix, it caused several AI browser extensions to fail, hinting that it may have been in place to enable automation on behalf of the user without showing the user the actual prompts being run. Regardless, prompts set to autorun were allowed to execute with no intervention, including prompts to disclose the contents of the users inbox, stored information in the users Copilot session, and any connected apps and services.

Comcast Senses Motion With WiFi

Comcast is enabling “WiFi Motion Detection” on its fleet of home router/access point devices. Conceptually, it’s a fairly simple trick. When a WiFi device changes position, or if something partially blocks the signal, the signal level of the device will change. People and pets are basically various sized bags of radio-blocking water, and as we move around we cause fluctuations in the signal levels of surrounding devices.

The risks lie in the second-order aspects: how much data is collected, how is it stored, and what does it expose about your home? Comcast says the feature is optional, and is opt-in: it won’t be turned on unless a customer enables it. This is refreshing, but once enabled, how is the data protected? Currently, Comcast states that the fidelity of the information may not be able to distinguish between a large pet and a small child, and can not identify individual people, but other public projects have refined a similar process to identify the number of people and characteristics about specific people, all based on the signal level. (Be careful when looking for other projects, though. There are several that appear to be completely AI generated, with both false claims and false data!)

As a company subject to the laws of any countries they operate in, Comcast may also be legally compelled to turn over motion and presence data in criminal or civil cases, or may opt to re-sell the data for other training or advertising purposes. Leveraging equipment you already have to collect more data is cool, but personally I’m not sure I want even more tracking data of when I’m home or where I spend time in my home to be that easily collected by a third party.

Stripe Merchant Keys Leaked

The payment processor Stripe has not been hacked, but it looks like 650 companies using it may have been.

Someone has collected hundreds of Stripe API keys, probably from GitHub, mis-configured servers, and infostealer malware, and made them available on trading forums. Despite guardrails by GitHub, a common mistake is committing configuration files, environment files, or code with API keys into public repositories. Once data goes into git, it’s fairly hard to remove it without resetting the entire repository: the whole point of code management is to be able to go back in time and identify the changes! The prevalence of information stealing malware on developer devices, VSCode plugin repositories, and inside packaging systems is another excellent source of stolen authentication tokens for many services.

A Stripe API token acts as the login credentials for the company using Stripe to process payments: it allows creating charging, listing past customers, extracting stored payment data, and essentially anything else a logged in administrator can do.

Stripe themselves say that they actively scan GitHub and other source management platforms looking for leaked keys and notifying customers, and hopefully impacted companies will be notified and can rotate their API tokens before they are used against actual customers.

More Windows Defender Issues

Last week was another Microsoft Patch Tuesday, which somehow didn’t set a third record for the highest number of security fixes in a month. Nonetheless, it would hardly be a proper Patch Tuesday in 2026 without another bypass of Windows Defender.

Previous exploits released by the researcher known as NightmareEclipse have demonstrated bypasses for BitLocker and Windows Defender and have stirred legal threats from Microsoft. Previous attacks against Windows Defender were fixed in the July set of patches, however now the “ShieldBreak” exploit, identified as CVE-2026-69414, uses Windows Defender itself to escalate to admin privileges.

The current fix? Disable Windows Defender. Which probably isn’t a great plan. Hopefully Microsoft is able to release an official fix rapidly.

Kicking Out Hackers by Cutting the Cable

A new article discusses how, during the Salt Typhoon attacks, T-Mobile operators drove to the datacenter physically cut the cable from a compromised system to prevent the attackers from accessing the rest of the network.

Salt Typhoon is believed to be a group based in China, often credited as part of the Ministry of State Security, which perpetrated widespread hacks of the United States telecom industry in 2024. The attackers utilized the hooks in the infrastructure devices required for US wiretap law, which gave them access to call records, contents of text messages, and voice recording of calls, targeting industry, government, and election officials.

Stopping a hack with a pair of wire cutters is definitely a story worth remembering.

Supply Chain Attacks Hit Rust

Supply chain attacks appear to be spreading to Rust packages now. The Rust Security Response Team was notified that a set of packages were downloading malicious payloads during build and confirmed the behavior.

To facilitate building required components, Rust packages can include a build script that is automatically compiled and executed. This is extremely similar to the build hooks enabling the spread of malware in the NPM and PyPI repositories, and could be used to perform the same authentication token theft and manipulation of packages.

Time will show if the Rust Cargo repository is able to prevent a similar scourge of infected packages now that the alarm is raised.

DEF CON Speakers and Attendees Targeted

Huntress reports some DEF CON speakers and attendees are being targeted with a phishing campaign on X/Twitter.

Starting with a claim to be the vice president of Coindesk, the phishing lure asks to collaborate on a future conference and provides a link to a Google document. The Google doc then tries to trick the user into running a click-fix style attack where the user is asked to copy and paste malware into a command shell, or into downloading a malware binary outright.

The malware payload targets the usual selection of cryptocurrency, authentication tokens, SSH keys, and the like. The Huntress article dives deep into the makeup of the malware, which has custom deployments if the victim is on Windows or macOS and can download several dynamic stages as the infection is triggered.

 

This articles is written by : Nermeen Nabil Khear Abdelmalak

All rights reserved to : USAGOLDMIES . www.usagoldmines.com

You can Enjoy surfing our website categories and read more content in many fields you may like .

Why USAGoldMines ?

USAGoldMines is a comprehensive website offering the latest in financial, crypto, and technical news. With specialized sections for each category, it provides readers with up-to-date market insights, investment trends, and technological advancements, making it a valuable resource for investors and enthusiasts in the fast-paced financial world.