A Brazillian crowd records a Luan Santana concert on iPhones in August, 2019. Photo by Mauricio Santana/Getty Images

According to a report from Google's security research team Project Zero, hacked websites implanted surveillance software onto iPhone users between 2016 and their discovery in February of this year.

Threat level: Project Zero alerted Apple in February to attacks they found, and Apple patched the security flaws fueling the atttacks that month. If you use the most current version of the operating system, you are protected from these attacks, and the surveillance software only survived until a victim restarted their phone.

Details: According to the report written by Project Zero's Ian Beer, the malicious websites have been stringing together vulnerabilities in Apple's security for models as early as the 5S in different ways since 2016, changing tactics whenever the operating system was updated.

  • Google found a total of five different chains of vulnerabilities, making use of a total of 14 vulnerabilities.
  • The sites would then install surveillance software onto any phone that visited, making no attempt to limit the spread of the malware beyond the whoever visited the sites.
  • The sites still receive thousands of visitors a week, by Google's estimation.

The big picture: Though the report doesn't document which sites delivered the attacks (or who set the sites up), they likely impacted large numbers of victims.

  • Attacks like this are expensive to acquire — on the open market, methods to secretly install software on iPhones can cost millions of dollars — so they are typically used in very narrow attacks.
  • The breadth of this incident was surprising, and could raise public questions about Apple's reputation (and claims) for superior smartphone security and privacy.

Why it matters: What sets this incident apart is that the iPhone vulnerabilities were used to indiscriminately hack phones in bulk.

  • That's rare, and could be a black eye for Apple.
  • But severe vulnerabilities will never be totally preventable. Google and Apple have both seen potent vulnerabilities in the past, and will see them again.

Go deeper

Right-wing media defanged by dissolving anti-Biden storylines

Data: NewsWhip; Chart: Naema Ahmed/Axios

The three biggest anti-Joe Biden storylines in right-wing media over the last year have either fizzled or are getting less online traction than they used to, according to data from NewsWhip provided exclusively to Axios.

Why it matters: This dynamic has rendered a formidable media ecosystem less effective in boosting President Trump as we move into the heart of the 2020 campaign.

A coronavirus alarm bell is going off in the Midwest

Data: The COVID Tracking Project; Note: Positive rate shown is the 7-day average from June 1 to Aug. 6, 2020; Cartogram: Andrew Witherspoon/Axios

A cluster of states in the Midwest are seeing more of their coronavirus tests coming back positive — potentially an early indicator of a growing outbreak.

The state of play: A high positive rate means that a higher share of those getting tested are sick. That could be because there are more sick people, or because a state isn't doing enough testing.

Biden clarifies comments on African American and Latino communities

Joe Biden delivering a speech in Delaware in July. Photo: Mark Makela/Getty Images

Joe Biden explained on Twitter Thursday night what he "meant" by earlier comments suggesting that "the African American community is a monolith."

What they're saying: "Unlike the African-American community, with notable exceptions, the Latino community is an incredibly diverse community with incredibly different attitudes about different things," Biden remarked in an interview hosted by the National Association of Hispanic Journalists and the National Association for Black Journalists, Politico reports.