Also this week: an Apple alert, a Comcast deadline, and a teen account nobody asked for
Apple warned the people it thinks are spyware targets and shipped an update the rest of us should install, the Comcast breach claim deadline moved to September 14, ChatGPT started sorting its own users by age, and four states put Meta on trial in Oakland.
I can't write a full piece on everything that happens in tech every week, and you don't have time to read one anyway. So on Fridays I point you at the handful of stories that actually matter to everyday people, tell you in a sentence or two why you should care, and send you to someone who reported it well. Four this week.
Apple warned the people it thinks are spyware targets, then patched an image bug the rest of us should install
On August 13 Apple sent another round of what it calls threat notifications. They go to people Apple believes were "individually targeted by mercenary spyware attacks, likely because of who they are or what they do." Apple told TechCrunch this wave went to users in 110 countries. Apple does not publish per-wave counts on its own support page, where it says only that it has sent these since 2021 and has "notified users in over 150 countries in total."
If one of these showed up on your phone, it is not spam and it is not a mistake. Apple tells you to turn on Lockdown Mode, and it points you at the Digital Security Helpline at Access Now, which does rapid-response emergency work for people in that position.
Most people will never get one. Everybody else has a smaller job. On August 17 Apple shipped iOS 26.6.1 and iPadOS 26.6.1, along with iOS 18.7.10 and iPadOS 18.7.10 for older hardware, and a Safari update for Macs the day after. The iOS 26.6.1 notes include an image-processing bug where, in Apple's own wording, "processing an image may lead to arbitrary code execution." The notes for the older release carry a comparable one. Apple did not say anybody had used either, and neither page carries the language Apple uses when a flaw has been exploited. Install it anyway. Settings, then General, then Software Update. That 18.7.10 release covers the iPhone XS, XS Max, XR and the 7th-generation iPad, so a phone from 2018 got patched too.
Scammers will imitate these, and fake "your Apple device is infected" texts and pop-ups are already permanent furniture, so here is how to tell a genuine one. It shows on your Lock Screen and in Settings, in an email from threat-notifications@email.apple.com to the address on your Apple Account, and as a banner on your account page. Apple says the alert on the phone itself is new this year and that what you get can vary by device. A real notification does ask you to do things, like turning on Lockdown Mode, so "it told me to take action" is not how you spot a fake. The tell is what it never asks for. It will not ask you to click a link, open a file, install an app or a profile, or hand over your Apple Account password or a verification code by email or over the phone. Apple's own instruction for checking is to sign in at account.apple.com, where a real one sits at the top of the page. If something gets you anyway, there is an order to work through in the first hour.
Sources: Apple threat notifications and Apple security releases
Comcast is paying $117.5 million over the Xfinity breach, and the claim deadline moved
This is narrower than the coverage makes it sound. You are in it if you live in the United States and Comcast sent you a notice, on or around December 18, 2023, about the breach that ran from October 16 to 19 that year. Having Xfinity service at the time is not the test. A few groups are carved out, including Comcast employees, anyone who opted out by July 1, and anyone who already took the breach to arbitration.
If you got that notice, look at the date again, because the court moved it. Plenty of stories still print August 14. In May the judge pushed the claims deadline to September 14, 2026. If you saw the old date and figured you had missed your shot, you have not.
You can claim documented out-of-pocket losses you can tie to the breach, counting from October 16, 2023, plus lost time at $30 an hour for up to five hours, capped at $10,000 for the two together. If you have nothing to document, there is an alternative cash payment estimated at $50. Filing with receipts does not cost you that $50 either, because the settlement pays whichever is greater. All of it gets adjusted up or down depending on how many people file.
Identity defense and restoration services need no claim form, but they are not automatic. Your notice carried an enrollment code and you have to use it, and none of it starts until the settlement is final.
On timing, settle in. The court held its final approval hearing on August 5, and this week Judge John Younge approved the deal, cutting the lawyers' fee request from $39 million to $31.7 million. The settlement site has not caught up, so do not go by what it says. Money still does not move until the appeal window runs out.
One website is the real one, comcastbreachsettlement.com, run by Kroll Settlement Administration at 1-833-319-2401. Filing is free, so treat anyone who asks you for a fee to release your money as a thief. And if the notice you are thinking of came from a debt collector called FBCS in 2024, that is a different breach and it is not this settlement.
Source: Comcast Data Breach Settlement
ChatGPT started deciding which of its users are teenagers
On August 18 OpenAI began rolling out ChatGPT for Teens. Accounts it believes belong to somebody under 18 get moved into it, and nobody has to ask for it. OpenAI assigns it from "account-provided age information, verified age, or age prediction." That last one is the company guessing, from the way an account behaves, that the person typing is a teen. The guess runs on things like the topics that come up, the time of day the account gets used, and how long it has existed.
A teen account gets:
- age-appropriate content safeguards
- Study mode, with hints and step-by-step guidance, plus quizzes and homework reminders
- reminders to take a break, and reminders that it is an AI tool
- a nudge, before some image uploads, telling the teen to check for sensitive information first
A parent can send their teen an invite to link accounts, and the teen has to accept it. Once linked you can set Study hours, which make new chats start in study mode, and Quiet hours, which limit access at set times. Keep those straight, because the names invite the wrong guess. Quiet hours is the one that shuts it off. Study hours only changes the mode.
Linking does not let you read anything. OpenAI's line is that "parental controls do not let a parent or guardian read or monitor the teen's conversations." What it does do is tell you if the company's reviewers see signs of acute distress, by email, text and push notification unless you opt out, and that alert carries no transcript. Either of you can unlink whenever you want, and if your teen does it, you get told.
So the thing to actually do is send the invite. If your kid set their account up years ago with whatever birth year got them past the door, the age guess may or may not catch that, and the guess is the one part of this you have no say in. Linking is the part you do. One warning if you go poking around in the settings yourself: leave the "Verify age" button alone. That flow exists to take teen protections off, not to check them. And if you are not sure what your kid is actually talking to, we wrote that up.
Source: OpenAI Help Center
Four states are in court arguing Facebook and Instagram were built to hook kids
Opening statements were Tuesday in Oakland and testimony is underway. California, Colorado, Kentucky and New Jersey are trying the case in federal court in front of US District Judge Yvonne Gonzalez Rogers, as the test run for a coalition of 29 state attorneys general whose case goes back to 2023. The states say the products were built to keep young people using them, and they name the like button, infinite scroll and the recommendation algorithms they say "encourage compulsive use." They also say Meta knowingly took data from children under 13 without a parent's consent, which federal privacy law forbids.
The trillion-dollar number in the headlines is Meta's arithmetic, not the states'. Meta says the theory could expose it to as much as $1.4 trillion if every alleged violation drew the maximum penalty. California's own lawyer put it at $193 billion in her opening. Neither is a ruling. In a statement, Meta said the attorneys general "offer no proof anyone in their states was misled."
File one thing away for October. A jury is hearing this, but only in an advisory role. Gonzalez Rogers decides liability and any penalty herself.
Source: NPR
That's the week.
If you are new here, Start Here collects the pieces worth reading first, and the Tuesday email carries the whole week in one place.