Skip to main content
COSMICBYTEZLABS
NewsSecurityHOWTOsToolsTraining
StudyProjectsNewsletterHire MeAbout
Subscribe

Press Enter to search or Esc to close

News
Security
HOWTOs
Tools
Training
Study
Projects
Newsletter
Hire Me
About
RSS Feed
Reading List
Subscribe

Stay in the Loop

Get the latest security alerts, tutorials, and tech insights delivered to your inbox.

Subscribe NowFree forever. No spam.
COSMICBYTEZLABS

Your trusted source for IT intelligence, cybersecurity insights, and hands-on technical guides.

2368+ Articles
158+ Guides

CONTENT

  • Latest News
  • Security Alerts
  • HOWTOs
  • Checklists
  • Projects
  • Exam Prep

RESOURCES

  • Search
  • Browse Tags
  • Newsletter Archive
  • Reading List
  • RSS Feed

COMPANY

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CosmicBytez Labs. All rights reserved.

System Status: Operational
  1. Home
  2. News
  3. Apple Sends New Threat Notification Alerts Over Mercenary Spyware Attacks
Apple Sends New Threat Notification Alerts Over Mercenary Spyware Attacks
NEWS

Apple Sends New Threat Notification Alerts Over Mercenary Spyware Attacks

Apple warned iPhone users in 110 countries of mercenary spyware attacks. Enable Lockdown Mode and update iOS immediately if you receive an alert.

Dylan H.

News Desk

August 13, 2026
4 min read

Apple dispatched a new wave of Threat Notification alerts on August 13, 2026, warning iPhone users in 110 countries that they may have been targeted by mercenary spyware attacks. The notifications — which appear on the Lock Screen, in device Settings, and via email from threat-notifications@email.apple.com — mark the latest escalation in a notification program Apple launched in 2021 that has now reached users in more than 150 countries cumulatively.

What the Notifications Say

If your iPhone received one of these alerts, the message reads:

"Apple detected a mercenary spyware attack targeted at your iPhone. There are actions you can take now to protect your data and device."

Apple has clarified that legitimate notifications will never ask you to click a link, open a file, install an app, or provide your Apple Account credentials. If you're unsure whether a notification is real, sign in directly to account.apple.com — legitimate warnings will also appear there as a banner.

Who Is Being Targeted

Mercenary spyware campaigns are highly targeted operations. Apple's notifications are typically sent to journalists, activists, politicians, and diplomats — people targeted because of their identity or work, not because of something they downloaded. The attacks are typically commissioned by or associated with nation-state actors, or private companies developing spyware on their behalf.

Apple does not disclose the number of individuals notified or the specific countries targeted in each wave.

Active Spyware Threats Tracked in 2026

While Apple does not name specific spyware in individual alerts, several mercenary spyware families are actively tracked as of August 2026:

SpywareOperatorNotable Technique
PegasusNSO GroupZero-click iMessage exploits
GraphiteParagon SolutionsReads messages before encryption / after decryption on-device
PredatorIntellexa ConsortiumMulti-stage delivery via redirect chains
DarkSwordUnknownPoC published to GitHub; broadening threat actor pool

Google's Threat Analysis Group (TAG) is currently tracking more than 40 companies in the commercial surveillance market.

Recent CVEs Linked to Mercenary Spyware

CVEImpactStatus
CVE-2025-43200Graphite/Paragon — linked to iPhone compromisesPatched in iOS 18.3.1
CVE-2025-31277JavaScriptCore memory corruptionPatched
CVE-2025-43529JavaScriptCore memory corruptionPatched
CVE-2026-20700PAC bypass in dyld — zero-day at time of exploitationPatched

Devices running iOS 18.7.1 or earlier, or iOS 26.0–26.2, may remain vulnerable to DarkSword variants.

Zero-Click Exploits: No Interaction Required

The most dangerous aspect of these attacks is that many mercenary spyware tools use zero-click exploits — no tap, no link, no user action required. An attacker simply sends a malicious message; the device processes it in the background and is silently compromised. Standard antivirus software cannot detect these attacks. Forensic analysis requires specialized tools.

What to Do If You Receive a Threat Notification

Apple recommends the following immediate steps:

  1. Update iOS immediately — Install the latest version to close known exploit chains
  2. Enable Lockdown Mode — Dramatically reduces the attack surface for sophisticated spyware (Settings → Privacy & Security → Lockdown Mode)
  3. Contact a forensics expert — Reach the Digital Security Helpline at Access Now for 24/7 emergency support for civil society targets
  4. Verify the notification — Sign in to account.apple.com directly; do not click links in the notification
  5. Factory reset if compromised — A clean restore from a backup predating the suspected compromise is the safest remediation

Enabling Lockdown Mode

Lockdown Mode aggressively restricts device functionality to minimize the attack surface:

  • Blocks most message attachment types in iMessage
  • Disables FaceTime calls from unknown contacts
  • Restricts shared albums and web-browsing JavaScript JIT
  • Blocks wired connections from computers when the device is locked
Settings → Privacy & Security → Lockdown Mode → Turn On Lockdown Mode

Apple's Notification Program

Since 2021, Apple has sent Threat Notifications to users in over 150 countries. The program uses internal threat intelligence to identify devices that may have been compromised. Apple explicitly states it cannot achieve certainty in its detections, but errs on the side of notifying potential victims rather than remaining silent.

"Apple threat notifications are designed to inform and assist users who may have been individually targeted by mercenary spyware attacks." — Apple

References

  • BleepingComputer — Apple sends new Threat Notification alerts over mercenary spyware attacks
  • Apple — About Apple Threat Notifications and protecting against mercenary spyware
  • Access Now — Digital Security Helpline

Related Reading

  • ZeroDayRAT: Mobile Spyware Targeting iOS and Android
#Apple#Spyware#iOS#Pegasus#Threat Intelligence#Zero-Click

Related Articles

European Parliament Member Investigating Spyware Was Hacked With Pegasus

A Citizen Lab report reveals that former MEP Stelios Kouloglou — a substitute member of the EU's PEGA committee probing Pegasus spyware abuses — had his...

5 min read

PamStealer Uses Fake Maccy Sites and PAM Checks to Steal Mac Login Passwords

Jamf Threat Labs has discovered PamStealer, a sophisticated two-stage macOS infostealer that impersonates the Maccy clipboard manager, delivers a...

6 min read

Bulgaria Allowed Surveillance Tech Firm to Sell Products to Repressive Regimes, Report Says

Human Rights Watch obtained Bulgarian export licensing records showing the government approved surveillance firm Circles' technology sales to law...

3 min read
Back to all News