Intego Mac Podcast

Intego Mac Podcast

Download on the App Store

Intego Mac Podcast episodes

  • Episode 294: WWDC Preview, RomCom, PyPI, Hot Pixels, and More

    Apple's Worldwide Developer Conferences launches on Monday, and we discuss what to expect. We also talk about RomCom malware, PyPI 2FA, Hot Pixels (which may not be so hot) and other malware and vulnerabilities.

    Show Notes:

    • Apple WWDC
    • macOS Names that Apple has Registered but Not Used Yet
    • US govt banned NSO’s Pegasus, but said to buy rival spyware Paragon Graphite
    • RomCom malware spread via Google Ads for ChatGPT, GIMP, more
    • Legit app in Google Play turns malicious and sends mic recordings every 15 minutes
    • PyPI announces mandatory use of 2FA for all software publishers
    • Hot Pixels attack checks CPU temp, power changes to steal data
    • Microsoft finds macOS bug that lets hackers bypass SIP root restrictions
    • Clever ‘File Archiver In The Browser’ phishing trick uses ZIP domains
    • Maryland License Plates Now Inadvertently Advertising Filipino Online Casino
    • Episode transcript
    • Intego Mac Premium Bundle X9 is the ultimate protection and utility suite for your Mac. Download a free trial now at intego.com, and use this link for a special discount when you're ready to buy.

      28 min
    • Episode 293: When Does Your iPhone Become Unsafe to Use?

      A new hacking tool, BrutePrint, can unlock lots of smartphones, including some iPhones with Touch ID. Router infections can be hard to remove, and we discuss why Apple might have gotten out of the Wi-Fi business. And we take a close look at whether it's safe to use an iPhone, if it can no longer run the latest version of iOS.

      Show Notes:

      • Typing “rash” in Safari may cause a crash
      • Urgent Patches: macOS Ventura 13.4, iOS 16.5 fix 3 actively exploited vulns
      • Here’s how long it takes new BrutePrint attack to unlock 10 different smartphones
      • Hackers infect TP-Link router firmware to attack EU entities
      • Malware turns home routers into proxies for Chinese state-sponsored hackers
      • There’s finally an official OpenAI ChatGPT app for iPhone
      • Almost 9 million Android phones sold pre-infected with malware
      • Kindle E-Reader Device Software Security Updates
      • When does an old iPhone become unsafe to use?
      • Episode transcript
      • Intego Mac Premium Bundle X9 is the ultimate protection and utility suite for your Mac. Download a free trial now at intego.com, and use this link for a special discount when you're ready to buy.

        28 min
      • Episode 292: New Top-Level Domains, .Zip and .Mov; Geacon Malware; and Google to Delete Dormant Accounts

        New top-level domains use common file extensions, and this could lead to confusion, and dangerous downloads. Apple announces a new personal voice modeling feature. And Google warns dormant users: log in, or get shut out.

        Show Notes:

        • New ZIP [and MOV] domains spark debate among cybersecurity experts
        • CVE-2023-26818 - Bypass TCC with Telegram in macOS
        • Apple introduces new features for cognitive accessibility, along with Live Speech, Personal Voice, and Point and Speak in Magnifier
        • ChatGPT & AI Risks – Intego Mac Podcast Episode 278
        • ElevenLabs
        • AI cannot be stopped, says Steve Wozniak; we must prepare for more convincing scams
        • Open-source Cobalt Strike port 'Geacon' used in macOS attacks
        • google: Updating our inactive account policies
        • Google Chrome Dropping Lock Icon from URL Box
        • Google's Dark Web Monitoring Feature Now Available for All US Gmail Users
        • App Store stopped more than $2 billion in fraudulent transactions in 2022
        • Transcript of this episode
        • Intego Mac Premium Bundle X9 is the ultimate protection and utility suite for your Mac. Download a free trial now at intego.com, and use this link for a special discount when you're ready to buy.

          30 min
        • Episode 291: Snake Malware, Lockdown Mode, and Apple App Subscriptions

          The FBI has shut down servers for Snake malware, which we wrote about back in 2017. Apple's lockdown mode has been found to prevent some serious malware attacks. And Apple is testing the water with app subscriptions for two of its pro apps on the iPad.

          Show Notes:

          • Snake Malware Ported from Windows to Mac (Intego 2017 article)
          • U.S. and Allies Identify and Expose Russian Intelligence-Gathering “Snake” Malware
          • Hunting Russian Intelligence “Snake” Malware
          • Apple’s high security mode blocked NSO spyware, researchers say
          • QuaDream spyware hacked iPhone victims with rogue calendar invites
          • Apple's Safari Again Overtakes Microsoft Edge as Second Most Popular Desktop Browser
          • Selling an older iPhone SE for $199 in emerging markets would be a smart move
          • Apple brings Final Cut Pro and Logic Pro to iPad
          • Intego Mac Premium Bundle X9 is the ultimate protection and utility suite for your Mac. Download a free trial now at intego.com, and use this link for a special discount when you're ready to buy.

            28 min
          • Episode 290: Apple's First Rapid Security Response, New Mac Malware, and Insecure Google Authenticator Sync

            Apple has issued the first of a new type of updates to its operating systems: Rapid Security Response. We discuss several new types of Mac malware, and we look at how Google's cloud sync for its Authenticator app is insecure.

            Show Notes:

            • RSA Conference
            • Apple issues first Rapid Security Response for macOS, iOS, iPadOS
            • Google adds account sync for Authenticator, without E2EE
            • What are Passkeys, and how do they work?
            • AI Malware, Copilot, & Passkeys – Intego Mac Podcast Episode 284
            • New Atomic macOS info-stealing malware targets 50 crypto wallets
            • RustBucket: Hackers are using a fake PDF viewer to infect Macs with malware — how to stay safe
            • “The Dark Side of the Mac App Store” Part 1
            • “The Dark Side of the Mac App Store” Part 2
            • So long passwords, thanks for all the phish
            • IBM plans to replace 7,800 jobs with AI over time, pauses hiring certain positions
            • Intego Mac Premium Bundle X9 is the ultimate protection and utility suite for your Mac. Download a free trial now at intego.com, and use this link for a special discount when you're ready to buy.

              31 min
            • Episode 289: AI Is Everywhere, and How to Set Up an Old Mac as a Server

              AI is coming to an app near you. We discuss how these features will affect work, and the potential security implications of AI tools snarfing up files in businesses. We also discuss how to set up an old - or new - Mac as a home server. It's a useful tool if you have multiple Macs.

              Show Notes:

              • The Three Laws of Robotics
              • ChatGPT banned in Italy over privacy concerns
              • Malicious Keylogger Malware “BlackMamba” Made Using ChatGPT
              • AI cracks passwords this fast, how to protect yourself
              • Meet PassGAN, the supposedly “terrifying” AI password cracker that’s mostly hype
              • AI-Based Chat is Coming for Your Privacy: Should We Pause Development of Large Language Models?
              • Google is adding AI to its work apps; Here’s what that means
              • MacWhisper
              • How to set up your own Mac server (with an old or new Mac)
              • Intego Mac Premium Bundle X9 is the ultimate protection and utility suite for your Mac. Download a free trial now at intego.com, and use this link for a special discount when you're ready to buy.

                30 min
              • Episode 288: Sideloading on iOS, Lockbit Ransomware on Mac, and Zero-Day Chrome Vulnerabilities

                Lockbit ransomware is starting to target Macs, two zero-day Chrome vulnerabilities require urgent updates, and sideloading - installing apps not from Apple's App Store - is coming to iOS soon; at least in the EU.

                Show Notes:

                • Urgent Update: Chrome, Edge, Brave, Vivaldi browsers patch zero-day vulnerability
                • Urgent: 2nd Chrome zero-day vulnerability patched in 5 days
                • The LockBit ransomware (kinda) comes for macOS
                • Fake “Geek Squad” emails: Call center scam leverages Intuit QuickBooks servers
                • Sideloading may be coming to iOS 17 for the EU in early 2024
                • The Digital Markets Act: ensuring fair and open digital markets
                • Intego Mac Premium Bundle X9 is the ultimate protection and utility suite for your Mac. Download a free trial now at intego.com, and use this link for a special discount when you're ready to buy.

                  31 min
                • Episode 287: Juice Jacking, Best Buy Phishing, and Garage Doors Redux

                  The FBI warns people not to use public charging stations; we warned about this five years ago. An interesting phishing attack leverages QuickBooks accounting software to send fake invoices to people. And what does a company do if its smart garage doors are hacked? Disable them.

                  Show Notes:

                  • Urgent Patches: macOS Ventura 13.3.1, iOS 16.4.1 fix 2 actively exploited vulns (UPDATED)
                  • Smart Garage Company Fixes Vulnerability by Breaking Customers' Devices
                  • FBI warns against using public charging stations
                  • iOS trustjacking: How attackers can hijack your iPhone (2018)
                  • Beware of Juice-Jacking - Krebs on Security (2011)
                  • Plenty of juice-jacking scare stories, but precious little juice-jacking
                  • What are Passkeys, and how do they work?
                  • Fake “Geek Squad” emails: Call center scam leverages Intuit QuickBooks servers
                  • IRS-Authorized Tax Service eFile Contains Malicious Link
                  • There’s a new form of keyless car theft that works in under 2 minutes
                  • Intego Mac Premium Bundle X9 is the ultimate protection and utility suite for your Mac. Download a free trial now at intego.com, and use this link for a special discount when you're ready to buy.

                    28 min
                  • Episode 286: Supply Chain Attacks, Garage Doors, and Exploding USB Drives

                    We look at new malware that uses a supply chain attack; we explain what this is, and why it is not uncommon. We discuss how hackers can open a certain company's garage doors from anywhere, and how a journalist got injured by a malicious USB drive that exploded.

                    Show Notes:

                    • Apple’s Worldwide Developers Conference returns June 5, 2023
                    • Gordon E. Moore, Intel co-founder (and of “Moore’s Law” fame) dies at age 94
                    • How to securely dispose of old hard drives and SSDs
                    • SmoothOperator: 3CX VoIP app spreads Mac malware by Lazarus Group APT
                    • 3CX knew its app was flagged as malicious but took no action for 7 days
                    • North Korean hackers target security researchers with a new backdoor
                    • Journalist plugs in unknown USB drive mailed to him—it exploded in his face
                    • Open garage doors anywhere in the world by exploiting this “smart” device
                    • If your Netgear Orbi router isn’t patched, you’ll want to change that pronto
                    • You will not be jailed for 20 years if you use TikTok after its banned—despite internet fear-mongering
                    • Why is TikTok banned from government phones — and should the rest of us be worried?
                    • UK Joins U.S., Canada, Others in Banning TikTok From Government Devices
                    • Complete transcript of this episode
                    • Intego Mac Premium Bundle X9 is the ultimate protection and utility suite for your Mac. Download a free trial now at intego.com, and use this link for a special discount when you're ready to buy.

                      27 min
                    • Episode 285: New Mac Malware, and Stolen Session Cookies

                      New Mac malware can exfiltrate various types of data from your Mac, and a Chrome extension can steal Facebook session cookies. We discuss how stolen session cookies can give attackers easy access to your accounts, and potential ways to thwart this.

                      Show Notes:

                      • Apple releases macOS Ventura 13.3, iOS 16.4, and more, with security updates
                      • Apple Reveals How Many iPhones and iPads Are Running iOS 16 and iPadOS 16
                      • MacStealer: Mac Trojan malware steals passwords, wallets, and files
                      • FakeGPT: Trojanized ChatGPT Chrome extensions hijack Facebook accounts
                      • AmIUnique - My browser fingerprint
                      • What3Words
                      • Complete transcript of this episode
                      • Intego Mac Premium Bundle X9 is the ultimate protection and utility suite for your Mac. Download a free trial now at intego.com, and use this link for a special discount when you're ready to buy.

                        30 min

                      About Intego Mac Podcast

                      From the publisher's feed

                      Join the Intego Mac security experts for the latest Apple news, industry opinions, and a splash of security advice in our easy-to-digest, entertaining, and informative podcast series. Hosted by Kirk…