Everything posted by reporter
-
iOS 27 Tidbits: Share a Phone Number on Two iPhones, Independent Alarm Volume, Faster AirPlay and More
At the WWDC 2026 keynote, Apple detailed iOS 27 changes like a new version of Siri with a dedicated Siri app and Apple Intelligence features across multiple apps, but there are dozens of smaller but still important changes that Apple didn't have time to go through. Apple shared an image summarizing some of the bug fixes and optimizations it made in iOS 27, iPadOS 27, and macOS 27, and there are some interesting changes. Dual Phone Numbers Apple says you'll be able to switch between two iPhone devices with the same phone number, which presumably means you can set up two iPhones with one number and then swap between them as needed. It could work similar to how an iPhone and Apple Watch can share the same phone number. It should be a useful change for anyone who wants to get a foldable iPhone and a standard iPhone 18 Pro this year. Sharing numbers between two iPhones may require carrier support, so it's not clear if it's implemented in the beta. Two FaceTime Cameras Dual camera in FaceTime is a listed feature, and that likely means you'll be able to use the front and back cameras at the same time during FaceTime calls. Faster AirPlay and AirDrop AirPlaying content to the HomePod and Apple TV is faster than before thanks to multiple system improvements. AirDrop transfers from the iPhone to other devices are also faster, and it's quicker for an iPhone to find nearby AirDrop recipients. Messages Drawing App There's a drawing app in Messages where you can handwrite a message or draw a picture. It uses the same drawing tools that are available in the Notes app or when annotating images. Extra Large Widgets There's a new extra large widget size you can select on the iPhone's Home Screen. The extra large size takes up an entire app page and displays more information from an app. Shared Album Expirations You can now set a shared photo album to expire after a set time, so it doesn't exist indefinitely. Independent Alarm Volume Alarm volume can be controlled separately from system volume, as can alerts and system sounds. In Settings > Sounds & Haptics, there are toggles to match Alarms, Timers, Alerts, and System Sounds to Ringtone Volume or to decouple them. Toggling off the match option lets you select a preferred volume level for alarms and system sounds. Markdown in Notes You can now copy and paste Markdown in the Notes app. Save a Video Frame There's a new option to save a video frame as a photo in the Photos app. Weather The Weather app has a "Highlights" view with at-a-glance information, plus it includes updated hourly and 10-day views for precipitation and wind speed. Other iOS 27 Optimizations and Changes Faster message loading in Mail Enhanced Safari power efficiency Improved battery insights Smoother scrolling in App Library Smoother unlocking on iPhone New AutoMix transitions in Apple Music Faster HomeKit accessory pairing Faster start page loading in Safari More accurate Visited Places in Maps Improved Messages syncing across devices More power efficient personal hotspot on devices with N1 chip Failed messages will automatically try resending Improved Bluetooth power management Support for time zone changes in Sleep Improved unread badge accuracy in Mail These are just some of the improvements and changes that Apple has introduced in iOS 27. We'll be sharing more new features in iOS 27 as they're discovered by the community. The iOS 27 beta is available for developers right now, with Apple planning to introduce a public beta in July. iOS 27 will launch this fall.Related Roundup: iOS 27 This article, "iOS 27 Tidbits: Share a Phone Number on Two iPhones, Independent Alarm Volume, Faster AirPlay and More" first appeared on MacRumors.com Discuss this article in our forums View the full article
-
Tim Cook Delivers Farewell Remarks at His Last Apple Keynote as CEO
Tim Cook closed out what is expected to be his last keynote as Apple's chief executive officer today with some emotive final remarks. Wrapping up a pre-recorded video message, Cook reflected on his tenure at the company. "Some of the highlights of my time as CEO have been events like this, sharing powerful new tools with all of you," he said, adding that what developers create with Apple's platforms has been "a constant reminder that imagination has no limits." One of the greatest highlights of my time as CEO have been events like this, sharing powerful new tools with all of you and what you create with them has been a constant reminder that imagination has no limits. Over the years, you have helped people create, learn, and experience the world in explain ways, and with the incredible capabilities we introduced today, I truly believe the best is still ahead. Cook said it had been "an honor" to lead the company, describing Apple's north star as always creating products that serve people's needs. "I truly believe the best is still ahead," he said, before thanking the audience. Cook has served as CEO since 2011, succeeding Steve Jobs. John Ternus, Apple's SVP of Hardware Engineering, will takeover from Cook in September, just in time for the announcement of new iPhone models.Tags: Tim Cook, WWDC 2026 This article, "Tim Cook Delivers Farewell Remarks at His Last Apple Keynote as CEO" first appeared on MacRumors.com Discuss this article in our forums View the full article
-
Apple Overhauls Genmoji in iOS 27
iOS 27 includes an entirely revamped Genmoji creation experience. There's an updated interface that supports describing an emoji that you want to create, with options to start from existing emoji, choose an image from Photos, or select a person. After uploading an image or using a text phrase to create a Genmoji, there's now a "Describe a change" interface for making updates to what you've already created. You can iterate on designs and change specific elements of a Genmoji, tweaking colors and objects. Apple's AI is smarter than before and it is able to successfully make iterative updates for better Genmoji customization. Each change uses the old base rather than regenerating a new Genmoji with every request. With a series of requests, it is possible to make a complicated, multi-element Genmoji. Along with describing changes, you can also add in additional emoji, and the interface makes suggestions on what to do next. Genmoji output is also more consistent, and Genmoji look more like real emoji with a 3D, cartoonish style by default. There is now an option to change style, so if you don't want the cartoonish look, you can ask for something else like a drawing or a sketch. Generating a Genmoji does not take as long, and it appears to be less system intensive with less battery drain. Apple also overhauled Image Playground in iOS 27, and both Image Playground and Genmoji use updated Apple Foundation Models. Image Playground now supports generating photorealistic images and adding AI elements to just parts of photos.Related Roundup: iOS 27Tag: Genmoji This article, "Apple Overhauls Genmoji in iOS 27" first appeared on MacRumors.com Discuss this article in our forums View the full article
-
iOS 27 Hints at Foldable iPhone With App Resizability Push and New Framework Strings
Apple appears to be laying the groundwork for a foldable iPhone in iOS 27, with new references discovered in the operating system's frameworks and a notable emphasis on flexible app layouts at this year's Platforms State of the Union. During the Platforms State of the Union session, Apple told developers to move away from designing apps for specific devices and fixed orientations, and to instead target what it described as "a dynamic range of sizes and aspect ratios." The framing appears to go beyond the stated context of iPhone Mirroring and the iPad. Apple used the session to introduce support for resizable iOS apps in iPhone Mirroring and on the iPad. Developers who rebuild against the latest SDK will have their apps automatically opted in to resizability, Apple said, with SwiftUI apps that already use scene lifecycle and standard framework support for basic resizability considered "well on your way to supporting full resizability." A new resizable iOS simulator and Previews in Xcode were also announced, allowing developers to test layouts across a range of screen sizes and aspect ratios. Apple said it is also providing a skill for coding agents to help identify and fix common resizability issues. The guidance effectively asks developers to treat every iOS app as something that may need to reflow across a wide variety of form factors, which is a requirement that makes considerably more sense if a future iPhone is capable of folding open to a substantially larger inner display. As if that wasn't enough evidence for the upcoming foldable iPhone, X user @samhenrigold spotted two strings within iOS 27's frameworks that point directly toward foldable hardware: "foldState" and "angleDegrees." A third discovery, a new key that returns the total count of built-in displays on a device, is a further indication that Apple is preparing the software stack for a device capable of presenting more than one integrated screen. The foldable iPhone, widely expected to be called the "iPhone Ultra," is anticipated to be announced in September 2026 alongside the iPhone 18 Pro and iPhone 18 Pro Max, with a book-style design featuring a roughly 7.8-inch inner display and a 5.5-inch cover display. Other rumored key features include Touch ID instead of Face ID, a titanium frame and Liquid Metal hinge, dual rear cameras, the A20 chip, and the C2 modem. The device is expected to start at over $2,000, making it the most expensive iPhone ever. Related Roundups: iOS 27, iPhone FoldTag: Foldable iPhone This article, "iOS 27 Hints at Foldable iPhone With App Resizability Push and New Framework Strings" first appeared on MacRumors.com Discuss this article in our forums View the full article
-
tvOS 27 Drops Support for Two Apple TV Models
The upcoming tvOS 27 update that was previewed today drops support for two Apple TV models. The two Apple TV models that are compatible with tvOS 26 but not tvOS 27 are the Apple TV HD from 2015 and the Apple TV 4K (1st generation) from 2017. tvOS 27 is compatible with the Apple TV 4K (2nd generation) and newer, according to Apple's documentation. tvOS 27 features a redesigned Podcasts app, smoother app launches and animations, support for larger text across the interface, and more. Apple did not give tvOS 27 much attention during its WWDC 2026 keynote, so we are still in the process of learning what other new features and enhancements are included in the update. tvOS 26 Compatibility Apple TV HD (2015) Apple TV 4K (1st generation, 2017) Apple TV 4K (2nd generation, 2021) Apple TV 4K (3rd generation, 2022) tvOS 27 Compatibility Apple TV 4K (2nd generation, 2021) Apple TV 4K (3rd generation, 2022) The first tvOS 27 developer beta is available today, and a public beta will follow in July. The update will be released later this year — likely in September. A new Apple TV 4K (4th generation) is expected to launch later this year.Related Roundup: Apple TVBuyer's Guide: Apple TV (Don't Buy)Related Forum: Apple TV and Home Theater This article, "tvOS 27 Drops Support for Two Apple TV Models" first appeared on MacRumors.com Discuss this article in our forums View the full article
-
Apple's Most Powerful On-Device AI Now Requires iPhone 17 Pro or iPhone Air
Apple's most advanced on-device AI model in iOS 27 requires a minimum of 12GB of unified memory, meaning the standard iPhone 17 is excluded. The next generation of Apple Intelligence introduces a new on-device model more powerful than anything Apple has shipped before. While most iOS 27 AI features run on the same hardware supported today, including iPhone 15 Pro, the most capable model carries stricter requirements. To run Apple's most powerful on-device model, users will need one of the following devices: iPhone: iPhone Air, iPhone 17 Pro, or iPhone 17 Pro Max iPad: iPad with M4 or later with at least 12GB of unified memory Mac: Mac with M3 or later with at least 12GB of unified memory Vision Pro: Apple Vision Pro with M5 The base iPhone 17 is excluded because it ships with 8GB of memory, falling short of the 12GB threshold. The standard memory requirement for Apple Intelligence has been 8GB since its introduction, so this marks the first time Apple has raised the bar for its most capable on-device features. According to Apple's press release, the new model specifically enables features including expressive voices and more advanced dictation.Related Roundups: iPhone 17 Pro, iPhone AirTag: Apple IntelligenceBuyer's Guide: iPhone 17 Pro (Caution), iPhone Air (Neutral)Related Forum: iPhone This article, "Apple's Most Powerful On-Device AI Now Requires iPhone 17 Pro or iPhone Air" first appeared on MacRumors.com Discuss this article in our forums View the full article
-
Apple Announces tvOS 27 With These New Features
Apple barely touched on tvOS 27 during its WWDC 2026 keynote today, but the update exists, and it adds some new features to the Apple TV. In a slide that was shown very briefly during the keynote, Apple revealed some of tvOS 27's new features and enhancements: A redesigned Podcasts app Smoother app launches and animations Faster AirPlay connectivity with other Apple devices Smart downloads A new Larger Text accessibility option in the Settings app, which increases the size of text across the tvOS interface AppleCare coverage details in the Settings appApple's website does not offer a tvOS 27 preview page like it does for iOS 27 and the other new software updates, and the "what's new in tvOS" page on Apple's developer website has yet to be updated, so no further details about these features are available right now. Stay tuned for more tvOS 27 information over the coming days. The first tvOS 27 developer beta is available today, and a public beta will follow in July. The update will be released later this year — likely in September.Related Roundups: Apple TV, WWDC 2026Buyer's Guide: Apple TV (Don't Buy)Related Forums: Apple TV and Home Theater, Apple, Inc and Tech Industry This article, "Apple Announces tvOS 27 With These New Features" first appeared on MacRumors.com Discuss this article in our forums View the full article
-
Siri AI Gains Customizable Voice Expressiveness and Pace
Apple today announced that Siri AI will offer a "brand new voice experience," giving users the ability to customize how the voice assistant sounds. On devices that support Apple's most advanced on-device model, Siri AI will deliver more expressive voices alongside a significant improvement to systemwide dictation accuracy. Users will be able to adjust both the expressiveness and pace of Siri's voice to their preference via a new UI with sliders. As of developer beta 1, American is the sole voice option. The updated dictation engine will capture speech as polished text, automatically handling capitalization, punctuation, and formatting in real time. Apple says improved speech understanding means users can speak naturally and trust that their words will appear accurately and as intended.Tags: Siri, Siri AI This article, "Siri AI Gains Customizable Voice Expressiveness and Pace" first appeared on MacRumors.com Discuss this article in our forums View the full article
-
iOS 27 Wallet App Gets 'Create a Pass' Feature
The Wallet app in iOS 27 has a new "Create a Pass" option that's designed to let you add passes for tickets, memberships, and more using Visual Intelligence. If you have a ticket for an event and there's not a digital version available in the Wallet app already, you can create one using the physical pass. By default, the Wallet app uses Visual Intelligence to scan a pass and add it, but there's also a "Create Pass Manually" option. Pass templates include Standard, Membership, and Event. Each type includes relevant information like name, location, or admission type, along with a scannable code drawn from an included barcode or QR code that you take a photo of. There are 12 background colors to choose from, or seven custom backgrounds for categories like theater, music, sports, and movies. Fields can be added or removed as needed when creating a custom pass, with options like label, date, membership, contact, coupon code, VIN, insurance, and more, so most physical cards should be able to be stored digitally. Related Roundup: iOS 27 This article, "iOS 27 Wallet App Gets 'Create a Pass' Feature" first appeared on MacRumors.com Discuss this article in our forums View the full article
-
Apple Intelligence Gains Smarter Writing Tools in iOS 27
Apple today announced a series of Apple Intelligence improvements coming to Mail, Messages, Files, and system-wide text input as part of iOS 27 and its other major platform updates. The updates include automatic proofreading, which surfaces spelling and grammar suggestions as users type across the system. Apple is also introducing intelligent file and folder naming suggestions based on content. Two enhancements come specifically to Mail and Messages. Apple's composition assistant will now adapt to how a user typically communicates with different contacts, tailoring its suggestions to match individual conversational styles. Smart Reply, which proposes quick responses to incoming messages, has also been updated to draw on a user's personalized writing style rather than offering generic reply options.Related Roundup: iOS 27Tag: Apple Intelligence This article, "Apple Intelligence Gains Smarter Writing Tools in iOS 27" first appeared on MacRumors.com Discuss this article in our forums View the full article
-
iOS 27 Camera App Gets Siri Mode, Updated UI
The iOS 27 Camera app has a new "Siri" mode that is available in addition to the video, photo, and other camera modes. You can get to Siri mode by swiping over to it at the bottom of the Camera app in the iOS 27 developer beta. Siri mode integrates Visual Intelligence, so you can take a photo of something and ask Siri about it. Siri can answer questions about whatever you're taking a photo of, identifying plants, animals, landmarks, and more. Visual Intelligence is expanding to new categories in iOS 27, and it can help you determine the calories in a plate of food or split a bill with friends by calculating what each person owes. In Siri mode, the main Camera button captures an image and Siri will give information about what's in the shot. A button on the right lets you search Google Images, and a button on the left lets you ask a specific question. In other Camera modes, there are minor interface updates. Quick access tools for turning on Night Mode, turning off Live Photo, and activating Flash are at the top center of the interface, and the full set of tools can be accessed from the bottom right instead of the top right. While there were rumors of a Camera app widget section for customizing the available camera controls, that's not a feature that's available yet. Using Siri mode in the Camera app requires access to the Siri waitlist. The iOS 27 beta is only available to developers right now, but Apple plans to make a public beta available in July. iOS 27 will launch this fall.Related Roundup: iOS 27Tag: Siri This article, "iOS 27 Camera App Gets Siri Mode, Updated UI" first appeared on MacRumors.com Discuss this article in our forums View the full article
-
Apple Brings AI Tab Organization and AI-Generated Extensions to Safari
Apple today unveiled a raft of Safari upgrades powered by Apple Intelligence, including automatic tab organization, AI-generated custom extensions, and new privacy-first browsing tools. The centerpiece feature is automatic tab organization, which uses Apple Intelligence to group a user's open tabs into relevant topics without any manual intervention. If someone is planning a weekend trip, for example, Safari can pull all of their travel-related tabs into a single topic. As browsing continues, Safari will slot new tabs into existing topics or create fresh ones as needed. Apple is also introducing a way for users to create custom Safari extensions using natural language. The company described the feature as "describe an extension," letting users specify what they want in plain English and having Safari generate an extension that adapts web pages accordingly. Apple's example was adding a toolbar button that saves and rates recipes from cooking sites. A new "Notify Me" feature lets users ask Safari to watch a specific web page for changes and alert them when something relevant happens, such as a product restocking or a price drop. Users tell Safari in natural language what they are looking for, and Safari sends a notification when it detects a matching change on that page. Apple is bringing a background agentic password-updating tool to the browser. Working alongside the Passwords app, Apple Intelligence can automatically navigate to eligible websites, sign in, and update weak or compromised passwords to strong ones with a single tap. Apple says all of these capabilities are built with privacy in mind, and that no personal browsing data is exposed to Apple or anyone else in the process.Tags: Apple Intelligence, Safari This article, "Apple Brings AI Tab Organization and AI-Generated Extensions to Safari" first appeared on MacRumors.com Discuss this article in our forums View the full article
-
Apple Passwords Can Now Automatically Fix Weak and Compromised Passwords With Agentic AI
Apple today announced that the Passwords app can now automatically update weak and compromised passwords using Apple Intelligence and Safari to take action on a user's behalf. The feature builds on Passwords' existing ability to flag weak or compromised credentials. While the app has long been able to alert users to security issues, acting on those alerts required manually visiting each site and changing passwords individually. The new capability removes that friction by automating the process end-to-end in the background. Apple describes the system as agentic, with Apple Intelligence and Safari securely navigating through websites, signing in, and upgrading accounts to strong passwords without the user needing to intervene beyond an initial tap. The feature displays as a Live Activity when active.Tag: Apple Intelligence This article, "Apple Passwords Can Now Automatically Fix Weak and Compromised Passwords With Agentic AI" first appeared on MacRumors.com Discuss this article in our forums View the full article
-
iOS 27 Calendar and Reminders Apps Get New AI Features and Natural Language Support
The Calendar and Reminders apps in iOS 27 let you create events and reminders using natural language commands, making it easier to manage your schedule and task list. You can tap the "+" button in the Calendar app and then type in something like "Movies with Sarah at 8pm on Thursday" to schedule an event. You don't need to go to the specific day to create an event, and you can instead just tap when the date and time suggestions appear as you type. You can also use timing like "every week" to set up a recurring event. Reminders work in a similar way, and you can type in something like "Remind me to go grocery shopping at 2pm on Thursday" to set up a reminder for that date and time. Apple says editing an event in Calendar is also simpler. If you have a meeting that's every week and update it to every other week, the Calendar app will intelligently adjust frequency for all future events. Visual Intelligence integrates with Calendar and Reminders, so if you're looking at an event online and take a screenshot, or if you snap a photo of a flyer with your phone, you can have relevant information added to the Calendar app automatically. Siri is also able to intelligently add events to the Calendar app with natural language requests. iOS 27 is limited to developers right now, but Apple plans to make a public beta available in July.Related Roundup: iOS 27 This article, "iOS 27 Calendar and Reminders Apps Get New AI Features and Natural Language Support" first appeared on MacRumors.com Discuss this article in our forums View the full article
-
5 Software Supply Chain Security Best Practices for Development Teams
Understanding software supply chain security is one thing. Putting it into practice across a real pipeline, with real deadlines and real constraints, is another. Most organizations recognize that their software supply chain is a growing attack surface, but translating that awareness into concrete, repeatable practices is where the work gets difficult. But why should your team tackle this now? According to Sonatype, over 99% of open source malware identified in 2025 occurred on npm. And the first self-replicating npm worm emerged, spreading autonomously across developer environments and compromising hundreds of packages within days. Meanwhile, Verizon’s 2025 Data Breach Investigations Report found that the share of breaches involving third parties doubled year-over-year to 30%. This guide focuses on those practices that matter most for teams building and shipping container-based workloads. It’s organized around five categories that follow the natural flow of software delivery: trusted content, build security, pre-deployment verification, access and policy controls, and continuous monitoring. This way, your team can be better equipped to protect your software supply chain in the wake of increasingly automated and sophisticated attacks. Key takeaways Start from trusted, minimal base images and pin all dependencies by digest to eliminate upstream drift. Verify build provenance with cryptographic attestations and generate SBOMs at every build. Integrate vulnerability analysis into developer workflows and enforce policy-driven access controls across registries and pipelines. The most effective programs treat supply chain security as an engineering discipline, not a compliance checkbox. 1. Start with trusted content Choose verified, minimal base images Every container image inherits the security posture of its base image. If that foundation contains unpatched vulnerabilities, outdated libraries, or components you do not need, those risks propagate into every image built on top of it. The first and highest-leverage supply chain practice is selecting base images that are minimal, continuously maintained, and verifiably built. Look for base images that ship with complete SBOMs, provenance attestations at SLSA Build Level 3, and cryptographic signatures you can verify before deployment. Minimal images reduce attack surface by removing shells, package managers, and utilities that production workloads rarely need but attackers frequently exploit.This is where hardened, provenance-verified base images become a foundational practice. Rather than maintaining custom hardening scripts for each base image, teams can start from images that are rebuilt from source with full transparency into how they were produced. Pin dependencies and verify integrity Dependency pinning is a deceptively simple practice that prevents a category of supply chain attacks. When a Dockerfile references a tag like python:3.12, that tag can point to a different image digest tomorrow than it does today. A compromised or accidental change upstream flows silently into your builds. Pin container images by SHA256 digest, not by tag. Pin language-level dependencies (npm, pip, Maven) to exact versions with lock files, and verify the integrity of those lock files in CI. If your build system pulls a dependency and the hash does not match what was committed, the build should fail. Scenario spotlight: Consider a team that builds nightly from a :latest-tagged base image. One morning, a routine build deploys to staging and integration tests start failing. The root cause: an upstream package update in the base image introduced a breaking change. With digest pinning and explicit upgrade workflows, this class of problem disappears entirely, and so does the more dangerous variant where a malicious change slips in unnoticed. 2. Secure the build pipeline Enforce build provenance and attestation Build provenance answers a question that SBOMs alone cannot: where was this artifact built, by what system, and from what source? Without provenance, you can verify what’s in an image but not whether the build environment itself was trustworthy. The SLSA framework defines progressive levels of build integrity, from basic provenance documentation at Level 1 through hardened, tamper-resistant build platforms producing non-falsifiable provenance at Level 3. At minimum, builds should generate signed provenance attestations that link every artifact back to its source commit, build configuration, and builder identity. In practice, this means configuring your CI/CD system to produce SLSA provenance attestations (typically expressed using the in-toto attestation format) alongside every image build. These attestations become the cryptographic evidence that your deployment policies can verify before allowing an image into production. Harden CI/CD infrastructure The build pipeline itself is a high-value target. If an attacker compromises your CI/CD system, they can inject malicious code into every artifact you produce, and your existing checks may not catch it because the malicious modification happens after the source code review. Key hardening practices include: Isolate build environments so each job runs in a fresh, ephemeral context with no residual state from previous builds. Limit the secrets available to build jobs to the minimum required. Pin GitHub Actions and other CI plugins to full commit SHAs rather than mutable tags. Enforce branch protection rules that require code review and passing status checks before any merge to a release branch. CISA emphasizes build system integrity as a foundational element of supply chain assurance. If you cannot trust the system that produced an artifact, no amount of post-build scanning will compensate. 3. Verify before you deploy Generate and consume SBOMs continuously A software bill of materials is only useful if it’s accurate, current, and integrated into your decision-making. Generating an SBOM once at release time and filing it away satisfies a compliance requirement but provides minimal security value. The more effective practice is generating SBOMs at every build, attaching them to the image as attestations, and consuming them downstream in admission controllers, vulnerability scanners, and license compliance checks. When a new CVE drops, teams with current SBOMs can determine in minutes which running workloads are affected. Teams without them start a multi-day forensic exercise. Pairing SBOMs with exploitability data (VEX) adds another layer of actionability. VEX documents indicate whether a vulnerability in your SBOM is actually exploitable in the context of your specific image, reducing the noise that causes alert fatigue and helps teams focus remediation on the vulnerabilities that actually matter. Integrate vulnerability analysis into developer workflows Vulnerability scanning is most effective when it surfaces results where developers are already working, not in a security dashboard that gets checked once a sprint. Shifting analysis into the inner development loop means flagging issues at build time, in pull requests, and during local development, well before an image reaches a registry. This is where continuous vulnerability analysis integrated into the developer workflow becomes essential. Rather than batching scan results into weekly reports, effective programs surface findings alongside the code change that introduced them, with actionable remediation guidance. The NIST Secure Software Development Framework (SSDF) reinforces this pattern. Practice PW.7 recommends that organizations review and analyze human-readable code to identify vulnerabilities and verify compliance with security requirements. Automated analysis integrated into CI/CD is the scalable implementation of that guidance. 4. Control access and enforce policy Manage registry access and image policies Your container registry is the distribution point for every image your organization runs. If developers can pull any image from any public registry without restriction, the supply chain extends to every maintainer of every image they choose to use. Implement registry access controls that restrict which images are approved for use, enforce that all images come from verified publishers or internal builds, and require signature verification before any image enters production. Image access management policies ensure that teams can experiment freely in development while production environments consume only vetted, policy-compliant images. Scenario spotlight: Medplum, a healthcare developer platform helping customers meet HIPAA and HITRUST requirements, migrated their container foundation to Docker Hardened Images with just 54 lines added and 52 removed across their codebase. The result was a dramatically reduced CVE count, non-root execution by default, and no shell access in production. They also got a cleaner story to tell their auditors. Instead of explaining custom hardening scripts and per-CVE exception documentation, the team can point to documented hardening methodology and SLSA Build Level 3 provenance. Apply least privilege across the pipeline Supply chain attacks frequently exploit over-permissioned service accounts, CI tokens with broad scope, or shared credentials that provide more access than any single job requires. Applying least privilege to your delivery pipeline means scoping every credential, token, and API key to the minimum permissions needed for its specific task. CISA specifically recommends phishing-resistant multi-factor authentication on all developer and CI/CD accounts. Beyond authentication, ensure that build service accounts cannot push to production registries, that deployment tokens cannot modify build configurations, and that no single credential grants access to both source code and production infrastructure. 5. Monitor, respond, and improve Implement runtime monitoring Static analysis and build-time scanning catch the threats you anticipate. Runtime monitoring catches the ones you did not. When a supply chain compromise makes it past your pre-deployment controls, runtime anomaly detection is the layer that identifies unexpected behavior: new network connections from a container that should not make outbound calls, file system modifications in an immutable image, or process execution patterns that diverge from the image’s normal profile. Effective runtime monitoring for supply chain security goes beyond traditional application performance monitoring. It requires baseline behavioral profiles for your container workloads and alerting that triggers on deviation, not just on known-bad signatures. This is particularly important for detecting compromised dependencies that behave normally during testing but activate malicious behavior under specific runtime conditions. Build incident response into your supply chain program When a supply chain incident occurs, response speed depends on preparation. Teams that have practiced their response to a compromised dependency, a malicious base image update, or a build system breach respond in hours. Teams that have not practiced these scenarios scramble for days. Your incident response plan should include procedures for: Identifying which artifacts were produced from compromised components (this is where provenance and SBOMs pay for themselves) Revoking and rotating credentials that may have been exposed Rebuilding affected images from verified sources Communicating with downstream consumers of your software Best practices at a glance Software supply chain practice What it looks like in production Trusted base images All production images built from minimal, signed, provenance-verified base images with near-zero CVEs Dependency pinning Container images pinned by digest; language dependencies locked to exact versions with hash verification Build provenance Every artifact ships with signed SLSA attestations linking it to its source, builder, and build configuration CI/CD hardening Ephemeral build environments, pinned CI plugins, scoped secrets, branch protection enforced Continuous SBOMs SBOMs generated at every build, attached as attestations, consumed by admission and scanning tools Developer-integrated scanning Vulnerability analysis in PRs, local builds, and CI with actionable remediation guidance Registry access management Image pull policies restrict production to approved, signature-verified images from vetted sources Least privilege Pipeline credentials scoped per job; phishing-resistant MFA on all developer and CI/CD accounts Runtime monitoring Behavioral baselines for containers with alerts on anomalous network, filesystem, and process activity Incident response Documented, practiced playbooks for supply chain scenarios with provenance-backed blast radius analysis Getting started Building a software supply chain security program is iterative work. The practices in this guide represent the larger picture, but the path there is incremental. Start with the foundation: trusted base images and dependency integrity. Layer in build provenance and SBOMs. Then expand into policy enforcement, developer-integrated scanning, and runtime monitoring as your program matures. Docker Hardened Images provide a ready-made foundation for teams implementing these practices. Thousands of minimal, continuously rebuilt images ship with SLSA Build Level 3 provenance, signed SBOMs, and OpenVEX exploitability data, giving you a trusted starting point without the overhead of maintaining custom hardening pipelines. An independent assessment by SRLabs validated DHI’s provenance chain, signing model, and vulnerability management workflow, and continuous hardening practices. Pair that with Docker Scout for continuous vulnerability analysis integrated directly into your development workflow, and you have the core tooling to support a supply chain security program that scales with your engineering organization. Explore our full catalog of hardened images and start replacing your base images today. Frequently asked questions What’s the most important software supply chain security best practice? Starting from trusted, minimal base images has the highest leverage because it reduces the attack surface for everything built on top. A single vulnerable component in a base image can propagate across hundreds of downstream images and workloads. How do SBOMs and build provenance work together? An SBOM tells you what’s inside an artifact. Build provenance tells you where and how it was built. Together, they provide the transparency needed to assess whether an artifact is trustworthy and to quickly identify affected workloads when a vulnerability or compromise is discovered. How does the SLSA framework relate to supply chain best practices? SLSA (Supply Chain Levels for Software Artifacts) provides a progressive maturity model for build integrity. It gives teams a clear path from basic provenance documentation toward hardened, isolated build platforms with non-falsifiable provenance. Future iterations of the spec are expected to extend coverage into areas like hermeticity, reproducibility, and source integrity. What is the difference between vulnerability scanning and runtime monitoring Vulnerability scanning identifies known weaknesses in code and dependencies before deployment. Runtime monitoring detects unexpected behavior in running workloads, catching compromises that scanning missed or that activate only under specific conditions. Where should teams start if they have no supply chain security program today? Start with base image selection and dependency pinning. These two practices are relatively low-effort to implement and immediately reduce your exposure to the most common supply chain attack vectors. From there, add SBOM generation and build provenance to build the visibility needed for everything else. View the full article
-
Apple Says New Siri is Compatible With These iPhones, iPads, and Macs
The more intelligent and personalized version of Siri that Apple introduced today — "Siri AI" — is limited to devices with Apple Intelligence support. "Siri AI" is available on the devices listed below. iPhone iPhone 15 Pro iPhone 15 Pro Max iPhone 16e iPhone 16 iPhone 16 Plus iPhone 16 Pro iPhone 16 Pro Max iPhone 17e iPhone 17 iPhone Air iPhone 17 Pro iPhone 17 Pro Max iPad iPad mini (A17 Pro) iPad Air (M1 chip and newer) iPad Pro (M1 chip and newer) Mac "Siri AI" is compatible with any Mac with the M1 chip and newer. Apple Watch "Siri AI" is compatible with the following Apple Watch models when they are paired with an Apple Intelligence-enabled iPhone model that is nearby: Apple Watch Series 10 Apple Watch Series 11 Apple Watch Ultra 2 Apple Watch Ultra 3 Apple Watch SE (3rd generation) Vision ProVision Pro (M2 chip) Vision Pro (M5 chip) Some of the "Siri AI" features are also available on CarPlay when an Apple Intelligence-enabled iPhone model is connected to the vehicle. "Siri AI" is available to test in English in the iOS 27, iPadOS 27, macOS 27, and visionOS 27 developer betas starting today, but there is a wait, and it will be coming to the Apple Watch in a future watchOS 27 beta. "Siri AI" will also be included in the public betas of each update, which will be available in July. The revamped Siri is launching later this year. Even then, it will still have a "beta" label. Note that "Siri AI" will not be available in the EU on iOS 27 and iPadOS 27 at launch, with Apple citing regulatory issues related to the Digital Markets Act.Related Roundup: WWDC 2026Tags: Siri, Siri AIRelated Forum: Apple, Inc and Tech Industry This article, "Apple Says New Siri is Compatible With These iPhones, iPads, and Macs" first appeared on MacRumors.com Discuss this article in our forums View the full article
-
Apple Intelligence Introduces Contextual Call and Messages Features
Apple today announced a set of new communication-focused Apple Intelligence features, including contextual suggestions in Messages and a Call Context tool that surfaces relevant information from Mail when a user phones a business. The new Messages features offer one-tap suggestions based on the content of a conversation. If a contact asks for photos, Messages can surface a suggestion to search the library, recognizing keywords, locations, and people to find the best matches. Messages can also prompt users to create a reminder or a note directly from the conversation thread. Smart Reply in both Messages and Mail can now draw on a user's personalized writing style, and suggestions in Mail gain the ability to take action with third-party apps. The other headline feature is Call Context, which proactively surfaces relevant information when a user places a call to a business. If someone calls an airline to change a flight, for example, the Phone app can automatically find the relevant confirmation code or reservation number from Mail and display it during the call. Apple says Call Context looks only at who the user is calling and not at the call audio itself. The feature runs entirely on device, meaning no data is shared with Apple or any third party.Tags: Apple Intelligence, Messages This article, "Apple Intelligence Introduces Contextual Call and Messages Features" first appeared on MacRumors.com Discuss this article in our forums View the full article
-
Apple to Add AI Video Descriptions and Smarter Notifications to Home App
Apple today announced new Apple Intelligence features for the Home app, including AI-generated descriptions of HomeKit Secure Video camera clips and smarter grouping of accessory notifications. The Home app will use Apple Intelligence to analyze recorded clips from compatible cameras and generate text descriptions summarizing what happened in them. Users can search through footage to find specific events, such as a package delivery, without needing to watch each clip individually. The app will also surface noteworthy clips at the top of the Search page, so users can quickly identify important moments. When playing a clip, the Home app can pull together footage from multiple cameras to provide a more complete picture of an event. Apple Intelligence will also make accessory notifications smarter. Rather than receiving a separate alert for every triggered accessory, the Home app will understand related notifications as a single ongoing activity and deliver one notification that continues to update as the activity unfolds.Tags: Apple Home, Apple Intelligence This article, "Apple to Add AI Video Descriptions and Smarter Notifications to Home App" first appeared on MacRumors.com Discuss this article in our forums View the full article
-
iOS 27 Adds New Parental Controls: Ask to Browse, Time Allowances, and a Redesigned Screen Time
This fall, Apple will bring new child safety features to iOS 27, iPadOS 27, and macOS Golden Gate. Apple says parents will have access to a simpler setup experience with recommended apps, a new Ask to Browse feature for Safari, and an overhauled Screen Time interface with Time Allowances. Parents will be able to select the apps a child can access, opting for a few essential apps, a curated set, or the apps that are appropriate for the individual child. Apps can be added over time, and kids can get parental approval for app downloads with Ask to Buy. If the new Ask to Browse option is enabled, parents can also approve each new website that a child visits. There are tools for managing who children can connect to on Messages, FaceTime, and Phone, and parents can enable a setting that will require children to get permission before connecting with a new contact. Communication Safety is being updated to blur gore and violence in Messages and FaceTime calls by default for users under 18. As with nudity, it will automatically blur content when gore or violence is detected in images and videos. With Time Allowances, parents can manage the time that children spend in apps in the Entertainment, Games, and Social Media categories. Parents can set a limit based on the child's age, with suggestions from the latest expert guidance. Daily Schedules let parents limit which apps children can access and when based on time of day and day of the week. Screen Time gives parents an at-a-glance view of their kids' device usage and most used apps, with options to make adjustments to access in the moment. Apple says parents will be able to quickly limit access during meals, outdoor play, and other times that "deserve full attention." Apple now has a dedicated Child Safety website where parents can learn more about the tools coming in iOS 27, iPadOS 27, and macOS Golden Gate.Related Roundup: iOS 27 This article, "iOS 27 Adds New Parental Controls: Ask to Browse, Time Allowances, and a Redesigned Screen Time" first appeared on MacRumors.com Discuss this article in our forums View the full article
-
Apple Revamps Image Playground With Photorealistic Generation and New Editing Tools
Apple has announced a major overhaul of Image Playground, introducing a new generative model capable of photorealistic image creation alongside expanded editing and sharing capabilities. The updated app is powered by a new generative model that runs on Private Cloud Compute, enabling it to produce high-quality images in virtually any style, including photorealistic output for the first time. All generated images will automatically carry a hidden SynthID watermark to identify them as AI-generated. Image Playground now supports photo-based editing in addition to creation. Users can describe changes they want to make to an existing image, or use touch gestures such as tapping, circling, or brushing to highlight specific objects and move or resize them. Photos can also be transformed into different styles using a text description, and people from a user's photo library can be included in generated images. The experience extends further into iOS with new output destinations. In addition to Messages, generated images can now be used as Lock Screen wallpapers and Contact Posters. Users can also choose an aspect ratio when creating images, such as landscape for a website header or portrait for a flyer. Developers will have access to the new capabilities through the Image Playground API, allowing third-party apps to integrate photorealistic generation and editing features directly.Tag: Image Playground This article, "Apple Revamps Image Playground With Photorealistic Generation and New Editing Tools" first appeared on MacRumors.com Discuss this article in our forums View the full article
-
Apple Unveils Xcode and Foundation Models Framework Improvements
Apple today announced a new Foundation Models framework for developers alongside a set of Xcode enhancements aimed at agentic coding workflows. The Foundation Models framework gains image input support, allowing developers to pass images alongside text into on-device models. Apple also introduced custom skills and server-side model execution as part of the framework, giving developers more flexibility in how they integrate AI capabilities into their apps. Apple also announced a new Core AI framework alongside the Foundation Models changes. Xcode's coding assistant has been expanded to handle app localization and can now interact with simulated devices, with the ability to extend its capabilities further via custom skills. Apple also said developers will be able to more easily resize and interact with app previews, with additional details to follow in upcoming sessions and the State of the Union presentation. Apple SVP of Software Engineering Craig Federighi said Xcode is now the "best place" to build apps using agentic coding. Apple also highlighted expanded App Intents support, with Apple citing third-party apps such as Line as examples of how developers can allow users to ask Siri to perform actions within their apps on their behalf.Tag: Xcode This article, "Apple Unveils Xcode and Foundation Models Framework Improvements" first appeared on MacRumors.com Discuss this article in our forums View the full article
-
How to Get iOS 27's New Siri AI: Join the Waitlist First
Apple released the first betas of iOS 27, iPadOS 27, and macOS 27 today, introducing a more capable version of Siri called Siri AI. Developers are able to download the betas and try Siri out, but there is a waitlist. After updating to iOS 27, developers will need to open the Settings app, go to the Apple Intelligence section, and opt in to the waitlist to get access to Siri. There is no word yet on how long the wait will be, but Apple used a similar waitlist when rolling out Apple Intelligence in iOS 18. It could be a matter of hours for some of the first developers to update to iOS 27. The new Siri and Apple Intelligence features that Apple introduced today are available on all devices that support Apple Intelligence, but some on-device capabilities will be limited to newer iPhones, iPads, and Macs. Siri AI is free, but Apple does have daily limits on some capabilities like image generation. Opting into an iCloud+ subscription plan increases AI limits. Siri AI is limited to English, and it is not available in the European Union on the iPhone or the iPad, but EU users can try it on Mac. Siri AI is not available in China. Related Roundup: iOS 27Tag: Siri This article, "How to Get iOS 27's New Siri AI: Join the Waitlist First" first appeared on MacRumors.com Discuss this article in our forums View the full article
-
iPadOS 27 Drops Support for a Wave of iPads
iPadOS 27 cuts support for more iPad models than last year's iPadOS 26 did, with older iPad Pro, iPad Air, iPad, and iPad mini models all losing compatibility. iPadOS 26 supported iPad Air models from the 3rd generation onward. iPadOS 27 raises the floor to A14, M1, or later, cutting the 3rd generation iPad Air model from the compatibility list entirely. The iPad Pro also sees cuts. iPadOS 26 retained support for iPad Pro 12.9-inch from the 3rd generation onward and iPad Pro 11-inch from the 1st generation onward. iPadOS 27 raises those floors to the 4th generation 12.9-inch and the 2nd generation 11-inch, dropping two older Pro models that were still supported just a year ago. For the standard iPad lineup, iPadOS 26 drew the line at the 8th generation, having already dropped the 7th generation last year. iPadOS 27 cuts the 8th generation as well, leaving only the 9th generation, 10th generation, and the current A16 model as compatible. The iPad mini sees its oldest supported model bumped from the 5th generation to the 6th generation, with the A17 Pro-equipped mini 7 also included. The 5th generation mini, which ran iPadOS 26, will not receive the update. By contrast, iPadOS 26 was a relatively conservative cull; it dropped only the 7th generation iPad from the iPadOS 18 compatibility list. iPadOS 27 represents a considerably more aggressive pruning across the entire iPad lineup.Related Roundup: iOS 27 This article, "iPadOS 27 Drops Support for a Wave of iPads" first appeared on MacRumors.com Discuss this article in our forums View the full article
-
Apple Releases First iOS 27, iPadOS 27, and macOS 27 Betas to Developers
Following the WWDC 2026 keynote event, Apple has seeded the first betas of iOS 27, iPadOS 27, macOS 27, watchOS 27, tvOS 27, and visionOS 27 to developers for testing purposes. Registered developers can opt in to betas and download the software through the Settings app on each device. The software includes many of the new features that were shown off earlier today, though some of what Apple demoed won't be available right away. Highlights include an updated version of Siri with a Siri app and new AI features for apps like Photos, Camera, and Wallet. There are dozens of new features to go through, including hundreds of smaller tweaks and changes that we'll be writing about over the next several weeks. Make sure to stay tuned to MacRumors for hands-on coverage, guides, how-tos, and an in-depth look at everything you'll want to know about the new software. Today's betas are limited to developers who will incorporate the new features into their apps. Apple will release a public beta so anyone can test out the software in July. iOS 27, iPadOS 27, macOS 27, watchOS 27, tvOS 27, and visionOS 27 will all launch to the public in the fall.Related Roundups: Apple TV, Apple Vision Pro, iOS 27, macOS 27, watchOS 26Buyer's Guide: Apple TV (Don't Buy), Vision Pro (Neutral)Related Forums: Apple TV and Home Theater, Apple Vision Pro, Apple Watch This article, "Apple Releases First iOS 27, iPadOS 27, and macOS 27 Betas to Developers" first appeared on MacRumors.com Discuss this article in our forums View the full article
-
Apple Announces When iOS 27 and Revamped 'Siri AI' Will Be Released
Apple today announced that iOS 27, iPadOS 27, macOS 27, watchOS 27, tvOS 27, and visionOS 27 will be available in developer beta starting today, with public betas to follow in July. The software updates will all be released in the "fall" as usual — likely September — but Apple did not provide any specific date at this time. The revamped version of Siri that is officially named "Siri AI" will be available to test in the iOS 27, iPadOS 27, macOS 27, and visionOS 27 developer betas starting today, and it is coming to the Apple Watch in a future watchOS 27 beta. "Siri AI" will also be included in the public betas of each platform that are launching in July. "Siri AI" requires a device that is compatible with Apple Intelligence. The revamped version of Siri will roll out to all customers with a compatible device later this year, but even the launch version will be considered a "beta." "Siri AI" is the more personalized version of Siri that Apple first previewed all the way back at WWDC 2024. Two years later, it is finally arriving, with the core upgrades being understanding of personal context and on-screen awareness. "Siri AI is an entirely new version of Siri deeply integrated into iPhone, iPad, Mac, Apple Watch, and Apple Vision Pro," said Apple. "It can draw on personal context understanding to search across messages, emails, photos, and more, and get things done across apps with even more systemwide app actions." With broad world knowledge, the new Siri is able to answer many more questions. An all-new Siri app across iOS 27, iPadOS 27, and macOS 27 provides users with a dedicated spot to fully interact with the revamped assistant.Related Roundups: iOS 27, macOS 27Tag: Siri This article, "Apple Announces When iOS 27 and Revamped 'Siri AI' Will Be Released" first appeared on MacRumors.com Discuss this article in our forums View the full article