Apple issued a fresh round of threat notifications this week warning iPhone, iPad, and Mac users across 110 countries that their devices may have been individually targeted by mercenary spyware, the commercial surveillance tools typically sold to government clients and used against journalists, activists, dissidents, and executives. This is not a mass warning: Apple designs these as high-confidence, individually targeted alerts, and the company is explicit that anyone who receives one should treat it seriously rather than assume it is a false positive or phishing attempt. What is new in this wave is not just the scale but the delivery mechanism. Apple has started surfacing the alert directly on the Lock Screen and inside Settings, in addition to the existing channels of an email notification and a banner on the user Apple Account page. That change matters operationally: threat notifications sent purely by email are easy to miss, mistake for phishing, or bury in spam, and a growing share of past recipients reportedly never saw or acted on the original notice. A persistent on-device alert is much harder to overlook and gives targeted users a clearer, faster path to protective action. For developers and security teams, the practical relevance is twofold. First, Apple's guidance for anyone who receives a notification centers on enabling Lockdown Mode, the restrictive OS mode that disables many attack surfaces spyware relies on, such as JIT compilation for Safari, most message attachment types, and incoming FaceTime calls from unknown contacts; teams building consumer-facing apps that serve high-risk users (journalists, NGOs, political figures) should understand what breaks under Lockdown Mode and test accordingly. Second, this notification wave is a reminder that zero-click and one-click mobile exploit chains remain commercially viable and are being actively deployed at meaningful scale in 2026, which should inform how mobile security teams prioritize patch velocity, attack surface reduction, and detection tooling for high-value user segments rather than treating spyware as a rare, theoretical threat model.