Original briefings. Zero spin.
Every story is an original briefing written from 60+ sources across the spectrum — sources linked so you can verify it yourself.
Apple Warns iPhone Users in 110 Countries They May Be Targeted by Government Spyware

Apple pushed out a new wave of spyware threat notifications on Thursday, August 13, warning users in 110 countries their iPhones, iPads, or Macs may have been targeted by government-grade surveillance tools, according to TechCrunch. Apple confirmed to the outlet that its cumulative total now covers more than 150 countries since it started sending these alerts in 2021.
Apple has been doing this for five years. What changed is how the warning reaches you.
According to cyberkendra, this is the first round where the alert lands as a push notification directly on the iPhone Lock Screen, not just buried in an email or account webpage that people routinely ignore, filter as spam, or dismiss as phishing. An email sitting unread for a week provides no protection if a foreign government is already on your phone.
The notification itself is blunt: "Apple detected a mercenary spyware attack targeted at your iPhone. There are actions you can take now to protect your data and device." Apple also emails users and flags the alert when they log into their Apple account, per 9to5Mac.
Cyberkendra flagged a wrinkle worth knowing: Apple's revised support page no longer lists iMessage as a delivery channel, even though earlier rounds went out that way. Notification types may vary by device model and software version, meaning users on older hardware might only get the email version, not the Lock Screen banner.
What "mercenary spyware" actually means
Apple defines mercenary spyware as tools built by private companies and sold to governments to spy on specific people: journalists, activists, politicians, diplomats. These attacks cost millions of dollars per target, according to Apple's support documentation, which is why they're rare but nasty when deployed.
BleepingComputer noted that Apple doesn't name the spyware behind any individual alert. There's no confirmation these specific August notifications trace back to NSO Group's Pegasus. But Apple does cite Pegasus as a historical example, and past forensic investigations tied to earlier Apple alerts have confirmed Pegasus infections in some cases.
Apple won't say what triggers a notification. The company's reasoning: publishing detection criteria would let spyware makers tune their tools to dodge future alerts. Apple also refuses to attribute any attack to a specific government or company, a position it has held consistently, including through politically charged episodes.
Apple's refusal to name names creates frustration for those wanting accountability. If a government is bankrolling spyware against journalists or opposition figures, the public arguably deserves to know which one. Apple's counterargument, that attribution would tip off attackers and undercut the detection system that makes these warnings possible at all, reflects a longstanding tradeoff security researchers have navigated. Both positions involve real constraints: transparency versus operational security.
Why this isn't just noise
John Scott-Railton, a senior researcher at Citizen Lab (University of Toronto), told TechCrunch these notifications matter because they create "a critical signal that a community is being targeted." A handful of recipients seek help, and that often triggers investigations revealing far more victims than the original alert count.
Scott-Railton pointed to Poland as the clearest proof: the country's scandal over the former government's use of spyware against political rivals came to light in large part because of Apple's notification system, he told TechCrunch. Without it, he said, "that entire massive scandal about spyware abuse in the Polish election wouldn't have been uncovered."
What to actually do if you get one
Apple's guidance, echoed across TechCrunch, 9to5Mac, and Livemint, boils down to this: update your device software immediately, enable two-factor authentication, use Face ID or Touch ID, turn on Stolen Device Protection, and only install apps from the App Store. Most critically, enable Lockdown Mode, Apple's extreme security setting that blocks most message attachments, FaceTime calls, and shared album invitations. Apple says it has yet to see a confirmed case of a device being hacked while Lockdown Mode was active.
Apple also points recipients to Access Now's Digital Security Helpline, a nonprofit offering free 24/7 emergency security assistance. Outside groups like Access Now don't get insight into why Apple flagged a specific user, but they can still help with tailored security advice once someone reaches out.
One genuine unresolved question: bleepingcomputer noted fake versions of these alerts are already a known problem, meaning scammers may try to exploit the Lock Screen format to phish real users. Apple says it will never ask for your password, verification code, or ask you to click a link or install a profile in a genuine notification. Verify any alert directly at account.apple.com before doing anything else.
Sources used for this briefing
This briefing was written by UBH's AI agent — these are the reporting inputs it draws on, linked so you can verify.