VYPR
trendPublished Aug 10, 2026· 1 source

Weekly Security Roundup: Apple WebKit Flaws, AI Scams, and Deepfake Threats

This week's security news highlights vulnerabilities in Apple's WebKit, the growing use of AI in scams including deepfakes, and the enforcement of the EU's AI Act.

This week's security landscape presented a diverse array of threats, from subtle vulnerabilities in widely used software to sophisticated AI-driven scams. Apple's WebKit, the browser engine powering Safari and other apps, was found to have vulnerabilities that could expose users' IP addresses, even when using Apple's Private Relay feature. This revelation raises concerns about user privacy and the effectiveness of built-in security measures.

Beyond browser vulnerabilities, the increasing sophistication of AI-powered scams continues to be a major concern. Threat actors are leveraging deepfake technology to impersonate users on platforms like OnlyFans, likely to defraud or harass individuals. Additionally, Anthropic's AI model, Mythos, has reportedly been employed in social engineering attacks, demonstrating the dual-use nature of advanced AI technologies. The "Pass-ta-key" attack also emerged as a significant threat, capable of stealing Google passkeys, a modern alternative to traditional passwords.

Travelers also faced specific risks this past week, with warnings issued about the security of hotel Wi-Fi networks. Logging into unsecured public networks can expose sensitive personal and financial information to eavesdroppers. Meanwhile, a common "$149.99 unauthorized charge" scam continues to circulate, impersonating major retailers like Amazon and Apple to trick users into revealing payment details.

On the regulatory front, the European Union's AI Act officially began enforcement, mandating transparency for AI chatbots and imposing new obligations on AI developers and deployers. This marks a significant step towards governing the rapidly evolving field of artificial intelligence and ensuring responsible development and use.

Other notable incidents include a WhatsApp account takeover scam that uses a "vote for my friend" ruse, and the discovery of malicious npm packages designed for quick distribution. The proliferation of "adult TikTok" searches leading to scams also underscores the need for vigilance across various online platforms. Malwarebytes highlighted these and other threats, emphasizing the importance of tools like Scam Guard for analyzing suspicious links and texts.

In a move that underscores the challenges of AI governance, Google rolled back a new AI tool for Google Earth after just one day due to online backlash, indicating the sensitivity surrounding AI applications and user data. The ongoing debate over encrypted data access also resurfaced, with Apple reportedly in discussions with the UK regarding encrypted iCloud access.

These varied incidents—from technical vulnerabilities to AI-driven deception and regulatory developments—collectively paint a picture of a complex and rapidly evolving cybersecurity environment. Users are urged to remain cautious, update their software promptly, and utilize security tools to protect themselves against emerging threats.

Synthesized by Vypr AI