Skip to content
View in the app

A better way to browse. Learn more.

hosang I.T.

A full-screen app on your home screen with push notifications, badges and more.

To install this app on iOS and iPadOS
  1. Tap the Share icon in Safari
  2. Scroll the menu and tap Add to Home Screen.
  3. Tap Add in the top-right corner.
To install this app on Android
  1. Tap the 3-dot menu (⋮) in the top-right corner of the browser.
  2. Tap Add to Home screen or Install app.
  3. Confirm by tapping Install.

reporter

Members
  • Joined

  • Last visited

    Never

Everything posted by reporter

  1. Apple's first foldable iPhone will feature an innovative liquid metal hinge and has now shipped prototype units to carriers around the world for testing, the leaker known as "Fixed Focus Digital" today said. In a new post on Weibo, Fixed Focus Digital said development and production related to the foldable are now "progressing rapidly." The claim arrives one day after the leaker reported that the foldable iPhone would feature vapor chamber cooling. The liquid metal hinge detail is significant in light of the ongoing debate over the device's production difficulties. Earlier reports from the leaker known as "Instant Digital" attributed manufacturing problems to the hinge failing Apple's quality control standards under prolonged, high-frequency open-and-close testing. Fixed Focus Digital previously pushed back on that characterization, arguing the hinge was not the primary source of difficulty, and today's post appears to position the hinge as a resolved and confirmed element of the design. Liquid metal is an amorphous metal alloy with a notably higher strength-to-weight ratio than conventional metals, along with superior resistance to corrosion and wear. Apple has used liquid metal in limited contexts before, most notably for the SIM ejector tool included with iPhones and for certain internal components, but its application in a structural hinge mechanism would be a far more demanding use of the material. The foldable iPhone is expected to fold and unfold hundreds of thousands of times over its lifespan, placing exceptional stress on the hinge, and liquid metal's durability properties make it a more capable material than conventional alloys. Apple's history with liquid metal stretches back over 15 years. In 2010, Apple signed an exclusive deal with Liquidmetal Technologies, receiving a perpetual worldwide license to commercialize the material in consumer electronics. In the years that followed, the company used liquid metal only for minor components such as the SIM ejector tool, with the material proving difficult to scale for larger structural parts. Apple repeatedly renewed its arrangement with Liquidmetal Technologies, and the material has continued to surface in patent filings covering hinges and other moving parts. Supply chain analyst Ming-Chi Kuo first reported in March 2025 that the foldable iPhone's hinge would use liquid metal, with Dongguan EonTec named as the exclusive supplier of the alloy. A subsequent January supply chain report corroborated the liquid metal hinge plans, but in April Fixed Focus Digital cast doubt on the material choice, claiming Apple was still weighing liquid metal against 3D-printed titanium alloy. The claim that prototypes have reached global carriers for testing represents a meaningful milestone, suggesting the device is now sufficiently complete to undergo the network compatibility and carrier certification process that precedes commercial launch. DigiTimes reported in April that mass production was planned to begin in July, and Bloomberg's Mark Gurman reported the device remains on track for a September debut alongside the iPhone 18 Pro and ‌iPhone 18 Pro‌ Max, though he noted the timing was not yet final at the time of writing. The foldable iPhone is expected to feature a 7.8-inch inner display, a 5.5-inch cover display, the A20 chip, the C2 modem, Touch ID in place of Face ID, and two rear cameras, with pricing rumored to start at around $2,000.Related Roundup: iPhone FoldTags: Fixed Focus Digital, Foldable iPhone, iPhone Ultra This article, "Leaker: Foldable 'iPhone Ultra' Will Feature Liquid Metal Hinge" first appeared on MacRumors.com Discuss this article in our forums View the full article
  2. Apple is evaluating a new OLED display backplane technology that could make future Apple Watch models more power efficient, according to a new report from Korean publication The Elec. LG Display is said to be developing high-mobility oxide, or HMO, thin-film transistor technology for its sixth-generation small and medium-sized OLED production lines. The technology is reportedly being considered by Apple as a next-generation successor to low-temperature polycrystalline oxide, or LTPO – the TFT backplane technology currently used to enable iPhone and Apple Watch features like always-on displays and variable refresh rates. HMO is designed to improve on conventional oxide TFT displays by increasing electron mobility (i.e., how easily electrons move through the transistor material when an electric field is applied). Mobility is important for driving OLED panels while keeping power consumption low, and The Elec says current mass-produced oxide TFTs typically offer mobility below 10 cm²/Vs (square centimeters per volt-second), whereas the industry is targeting around 30 to 50 cm²/Vs for its next-generation OLED products. LG Display is also reportedly using a "sputtering" process that could make the technology easier to integrate into existing production lines. Meanwhile, OLED supplier Samsung Display is said to be pursuing a different approach that uses atomic layer deposition (ALD), which involves laying down extremely thin films one atomic layer at a time. ALD is a slower process, but it suggests Samsung may be trying to create a more carefully controlled oxide transistor layer than HMO allows for. The report goes on to suggest that the first Apple product to use LG Display's HMO technology could be next year's Apple Watch. Apple has historically tested new display backplane technologies in the Apple Watch before expanding them to larger-volume products such as the iPhone, so this could also represent an initial step towards wider adoption. The report notes that LG Display still needs to validate the HMO technology for mass production, and that involves verifying mobility, uniformity, reliability, process temperature, and yield. As such, commercial adoption is not yet guaranteed. So far, rumors suggest this year's Apple Watch lineup won't include any major design changes, with a redesign said to be unlikely before 2028. However, those reports don't necessarily rule out the possibility of Apple adopting the new, more power-efficient OLED technology in 2027.Related Roundups: Apple Watch 11, Apple Watch Ultra 3Tags: OLED, The ElecBuyer's Guide: Apple Watch (Caution), Apple Watch Ultra (Neutral)Related Forum: Apple Watch This article, "2027 Apple Watch Could Adopt Next-Generation OLED Display Tech" first appeared on MacRumors.com Discuss this article in our forums View the full article
  3. Battery capacities for Apple's upcoming iPhone 18 Pro have allegedly surfaced, and the numbers suggest only a modest increase over the iPhone 17 Pro. According to prolific Weibo-based leaker Digital Chat Station, Apple is testing the iPhone 18 Pro with different battery capacities for the China and U.S. versions of the device, similar to last year's iPhone 17 Pro models. The Chinese model is said to have a roughly 4,056 mAh battery, while the U.S. model is said to have a roughly 4,288 mAh battery. Apple removed the tray from U.S. iPhones starting with the iPhone 14 lineup, whereas iPhones sold in China have continued to include one (the iPhone Air is an exception – it is eSIM-only worldwide, including in China). Without the tray, Apple can pack a slightly larger battery into the available internal space, hence the difference in capacity. Model iPhone 17 Pro iPhone 18 Pro Leak Difference China / Physical SIM 3,988 mAh 4,056 mAh +68 mAh, +1.7% US / eSIM-only 4,252 mAh 4,288 mAh +36 mAh, +0.8% If the figures are accurate, the iPhone 18 Pro's battery capacity increase would be fairly small year-over-year. The China model would gain around 68 mAh compared to the iPhone 17 Pro with a SIM card tray, while the U.S. eSIM-only model would gain around 36 mAh compared to the equivalent iPhone 17 Pro. Digital Chat Station claimed in February that the iPhone 18 Pro Max battery capacity will move into the "5,000 mAh" range. The leaker suggested around 5,000 mAh for the China version of the iPhone 18 Pro Max, and around 5,100 mAh to 5,200 mAh for international versions. It's not clear whether these iPhone 18 Pro figures come from a regulatory database or are based on supply chain information regarding device samples, so the numbers should be considered unconfirmed for now. It's also worth noting that modest gains aren't necessarily indicative of a modest battery life improvement – the iPhone 18 Pro models are also expected to benefit from the new A20 Pro chip, which will use TSMC's cutting-edge 2nm process and should subsequently be more power-efficient. The devices are also likely to get Apple's C2 modem, which could also bring a battery boost. 11 Reasons to Wait for the iPhone 18 Pro The ‌iPhone 18‌ Pro and ‌‌iPhone 18‌‌ Pro Max are expected to launch in September, featuring a smaller Dynamic Island, a simplified Camera Control, and an upgraded main camera with a variable aperture.Related Roundup: iPhone 18 ProTag: Digital Chat Station This article, "iPhone 18 Pro Battery Capacities Allegedly Leaked" first appeared on MacRumors.com Discuss this article in our forums View the full article
  4. Introduction In the current landscape of information technology, there is perhaps no career path as dynamic, rewarding, and challenging as DevOps. You see the job postings everywhere, with high salaries and the promise of working with cutting-edge technology. However, for many students and professionals looking to transition, the path is clouded by confusing jargon, an endless list of tools, and a feeling that they are already behind before they even begin. When you decide you want to start learning DevOps step by step, you are not just learning a specific software tool; you are learning a methodology of how to build and deliver software efficiently. The reason beginners feel overwhelmed is that they often start by trying to learn Kubernetes before they understand Linux, or they jump into AWS without grasping basic networking. This is like trying to build a roof before laying the foundation. Structured learning is the only way to navigate this field successfully. You need a path that respects your current skill level and builds your confidence incrementally. This is where the guidance at DevOpsSchool proves invaluable, offering the necessary structured environment to turn confusion into professional competence. In this guide, we will break down the entire process, ensuring you have the patience and the roadmap required to build a sustainable career. What Is DevOps? DevOps is not a single tool, a plugin, or a certificate. At its core, DevOps is a cultural and professional movement that encourages better collaboration between software developers (Dev) and IT operations teams (Ops). In a traditional setup, developers would write code and then throw it over the fence to the operations team, who would then struggle to deploy and maintain it. DevOps breaks down this wall. It promotes a culture where teams are responsible for the entire lifecycle of an application, from design and development to production support. When you learn DevOps, you are learning to automate the “hand-offs” between these teams. You are learning to ensure that code is tested automatically, deployed consistently, and monitored effectively. It is about creating a factory-like pipeline that delivers value to customers faster and more reliably. Why DevOps Feels Difficult for Beginners If you feel overwhelmed, you are not alone. There are several reasons why this field feels like a steep mountain to climb. Too Many Tools: The DevOps landscape is crowded with hundreds of tools, from Jenkins and Terraform to Docker and Kubernetes. Beginners often try to learn them all at once. The Cloud Complexity: Transitioning from local machines to cloud environments like AWS or Azure adds layers of complexity regarding security, billing, and architecture. Linux Anxiety: For many developers coming from a Windows background, the Linux command line feels like learning a foreign language. Abstract Concepts: CI/CD and orchestration are abstract concepts. You cannot “see” a container or a pipeline in the same way you can see a web page, which makes visualization difficult. The key to overcoming this is to stop looking at the entire landscape and start looking at the individual building blocks. DevOps Learning Mindset Before You Start Before we dive into the technical steps, you must adopt the right mindset. Learn Step by Step: Do not rush. Master Linux before you touch Docker. Master Git before you try to implement CI/CD. Focus on Fundamentals: Tools change, but the fundamentals of networking, security, and OS management remain constant. If you learn the principles, you can learn any tool. Hands-on Over Theory: Watching videos is not learning. You must build. If you read about a command, type it. If you learn about a pipeline, build a broken one and fix it. Accept Failure: In DevOps, things will break. Your server will crash, your deployment will fail, and your code will have bugs. This is not failure; this is the learning process. Step-by-Step DevOps Learning Roadmap The following roadmap is designed to guide you through the transition from a complete beginner to a junior DevOps professional. StepSkill AreaGoal1Linux SkillsMaster the Command Line Interface (CLI)2NetworkingUnderstand how machines talk to each other3GitLearn version control and collaborative coding4ScriptingAutomate simple tasks using Bash5CI/CDAutomate code integration and deployment6ContainersPackage applications using Docker7KubernetesManage container orchestration8Cloud BasicsProvision infrastructure on AWS/Azure/GCP9IaCProvision infrastructure using Terraform10MonitoringTrack system health and logs11ProjectsBuild end-to-end DevOps workflows12PortfolioDocument and showcase your work Step 1: Learn Basic Linux Skills Linux is the backbone of the internet and the foundation of DevOps. You must be comfortable working in a terminal without a graphical user interface. Key Concepts: File management, user permissions, process management, text editors (Vi/Vim), and package management. Example: Practice creating a user, assigning them to a group, and restricting their access to a specific folder. Step 2: Understand Networking Basics You cannot manage servers if you do not understand how they communicate. Key Concepts: IP addresses, DNS, subnets, ports, firewalls, and the OSI model. Example: Learn how to use ‘ping’, ‘curl’, and ‘netstat’ to diagnose why a website is not loading. Step 3: Learn Git and Version Control Git is how teams collaborate on code. It is mandatory for any developer or operations professional. Key Concepts: Repositories, cloning, branching, merging, pull requests, and resolving merge conflicts. Example: Create a repository on GitHub, create a feature branch, make a change, and merge it back to the main branch. Step 4: Learn Basic Scripting Automation is the heart of DevOps. If you do it manually more than once, you should script it. Key Concepts: Variables, loops, conditional statements (if/else), and functions. Example: Write a script that checks if a server has enough disk space and sends an alert if it is running low. Step 5: Understand CI/CD Concepts CI/CD (Continuous Integration and Continuous Delivery) is about automating the release process. Key Concepts: Pipeline stages, build steps, automated testing, and deployment strategies. Example: Use a tool like Jenkins or GitHub Actions to automatically deploy a simple HTML page whenever you push code to your repository. Step 6: Learn Containers and Docker Containers allow you to package an application with all its dependencies so it runs the same way on any machine. Key Concepts: Dockerfiles, images, containers, and Docker Hub. Example: Dockerize a simple Python web application and run it as a container on your local machine. Step 7: Learn Kubernetes Fundamentals Kubernetes is the standard for managing hundreds or thousands of containers. Key Concepts: Pods, deployments, services, clusters, and namespaces. Example: Deploy a containerized application to a local Kubernetes cluster (like Minikube). Step 8: Learn Cloud Basics The cloud is where your infrastructure lives. Key Concepts: Compute (EC2), Storage (S3), Databases (RDS), and IAM (Identity and Access Management). Example: Launch a virtual machine (EC2 instance) on AWS and host a simple web server on it. Step 9: Learn Infrastructure as Code (IaC) Stop creating infrastructure manually. Use code to define it. Key Concepts: Terraform, providers, resources, and state files. Example: Use Terraform to spin up a virtual machine instead of using the AWS console. Step 10: Learn Monitoring and Observability You cannot fix what you cannot see. Key Concepts: Metrics, logs, alerts, and dashboards. Example: Set up Prometheus to collect metrics from your server and visualize them in Grafana. Step 11: Build Small DevOps Projects Combine the skills. Idea: Create a pipeline that builds a Docker image, pushes it to a registry, and deploys it to a server automatically. Step 12: Build a DevOps Portfolio You need to prove you have done the work. Example: Document your projects in a GitHub README file, explaining what problem you solved and how you did it. Beginner-Friendly DevOps Learning Timeline This timeline is a guide. Some may learn faster, others slower. Do not compare your journey to others. Learning StageFocus AreaExpected ProgressMonths 1-2Linux & NetworkingComfort in CLI, basic server managementMonths 3-4Git & ScriptingAutomating simple system tasksMonths 5-6CI/CD & DockerBuilding basic deployment pipelinesMonths 7-9Cloud & IaCManaging cloud infrastructure via codeMonths 10+Kubernetes & MonitoringHandling complex, scalable environments Real-World Example: Beginner Learning DevOps the Wrong Way “Student A” decides to start DevOps. They hear Kubernetes is popular and immediately start a complex K8s tutorial. They do not know Linux commands, they do not understand how networking works, and they have never used Git. They spend three weeks trying to configure a cluster, fail, get frustrated, and quit because they think “DevOps is too hard.” Lesson Learned: Do not jump into advanced orchestration tools without understanding the underlying OS and networking. Real-World Example: Beginner Learning DevOps Step by Step “Student B” starts by mastering the Linux command line. They spend two weeks getting comfortable with terminal navigation. Next, they learn Git and manage their own code projects. Once they are confident, they move to basic scripting, automating their own file backups. By the time they reach Docker and Kubernetes, they understand the “why” behind the tools. They face issues, but they have the fundamental knowledge to debug them. Lesson Learned: Structured growth leads to competence and confidence. Common Beginner Mistakes Skipping Linux: Thinking you can bypass the command line. You cannot. Tool Hopping: Learning a little bit of Jenkins, then switching to GitLab, then to CircleCI. Pick one, master it, then switch if needed. Passive Learning: Only watching videos. If you don’t type the code, you don’t learn it. Ignoring Fundamentals: Trying to learn advanced cloud architecture without knowing basic networking. Lack of Documentation: Not writing down what you did. You will forget. Best Practices for Learning DevOps Successfully Practice Daily: Consistency is better than intensity. One hour a day is better than ten hours on Saturday. Build Real Projects: Build a website, host it, monitor it, and automate its deployment. Learn to Debug: Don’t just look for the answer. Read the error message. Use Google, use documentation, use community forums. Join Communities: Find study groups or online forums. Use Documentation: Read the “official documentation” of the tool (e.g., Docker docs, Terraform docs) instead of just relying on third-party tutorials. Role of DevOpsSchool in DevOps Learning DevOpsSchool provides a path that cuts through the noise of the industry. Many beginners struggle because they lack a structured environment that prioritizes hands-on experience over theoretical lecturing. By focusing on practical application, they ensure that learners get exposure to the tools they will actually use in the workforce. Their curriculum is designed to help students build the CI/CD pipelines and cloud infrastructure they need to master, moving from beginner concepts to advanced deployment strategies. Career Opportunities After Learning DevOps The job market for DevOps professionals remains strong across the globe. Once you have built your skills, you can target roles such as: Junior DevOps Engineer: Focusing on CI/CD pipelines and automation. Cloud Engineer: Managing cloud infrastructure on platforms like AWS, Azure, or GCP. SRE (Site Reliability Engineer): Focusing on the availability, latency, and performance of systems. Platform Engineer: Building internal tools that help other developers deploy code faster. Automation Engineer: Specializing in writing scripts to reduce manual work. Skills needed for these roles include strong Linux proficiency, experience with cloud services, a deep understanding of CI/CD, and the ability to monitor and manage distributed systems. Industries Hiring DevOps Professionals DevOps is no longer limited to tech startups. Every modern company is a software company. SaaS Platforms: Need 24/7 uptime and rapid release cycles. Banking & Finance: Need strict compliance, security, and automated auditing. Healthcare: Require secure, reliable, and scalable infrastructure to manage patient data. E-Commerce: Need to handle massive spikes in traffic during sales. Telecom: Moving legacy systems to the cloud, requiring migration experts. Future of DevOps Learning The future of DevOps is moving toward Platform Engineering, where teams provide “internal developer platforms” (IDP) that make it easier for developers to deploy. We are also seeing a massive rise in DevSecOps, where security is integrated into every step of the pipeline. Additionally, AI-assisted DevOps is becoming real, with AI tools helping to write scripts, detect anomalies, and even fix broken code. The fundamentals, however, will remain the same. The better you understand how a server works, the better you will be able to leverage AI to manage it. FAQs How do I start learning DevOps?Start with Linux basics, then networking, then Git. Build a solid foundation before moving to tools like Docker or Kubernetes. Is DevOps hard for beginners?It can be challenging because of the breadth of tools. However, by breaking it down into a step-by-step roadmap, it becomes manageable. Should I learn Linux first?Yes, absolutely. It is the most critical prerequisite. Do I need coding skills?You do not need to be a software engineer, but you need to know how to read and write basic scripts in languages like Bash or Python. How long does it take to learn DevOps?A solid foundation can be built in 6 to 12 months with consistent daily practice. Can freshers learn DevOps?Yes, many freshers enter the industry through internships or by building a strong portfolio of projects. Which cloud should I learn first?AWS is the most widely used, so it is a good place to start, but the concepts transfer to Azure and GCP. Is Kubernetes mandatory?For modern DevOps roles, yes, it is increasingly becoming a standard skill. Do I need a degree to get a DevOps job?While a degree helps, practical skills and a solid portfolio of work often matter more to employers. What is the difference between SRE and DevOps?DevOps is the culture/methodology; SRE is a specific engineering approach to implementing that culture with a focus on reliability. How much coding do I actually do?It varies by role, but you will spend a lot of time writing scripts for automation and configuration files (like YAML for Kubernetes). Can I learn DevOps by myself?Yes, but it is often faster and less frustrating to follow a structured roadmap or a course. Is it better to learn one tool or many?Master one tool in a category (e.g., learn Terraform for IaC) rather than learning a little bit of five different tools. What is a “Pipeline”?A pipeline is a series of automated steps that code goes through, from the moment it is written to the moment it is running in production. How do I show my skills to recruiters?Maintain an active GitHub profile with documentation and clear examples of projects you have built. Final Thoughts Starting to learn DevOps is a significant commitment, but it is one of the most rewarding paths you can take in the technology sector. It requires patience, a relentless drive to solve problems, and a commitment to continuous learning. Remember that you do not need to know everything on day one. You only need to know the next step. Start with your Linux fundamentals. Set up a simple project. Build a script that does something useful, even if it is small. Celebrate those small wins. Over time, those small wins will compound into the deep, practical expertise that defines a senior DevOps professional. Stay focused, stay consistent, and keep building. View the full article
  5. iOS 27, iPadOS 27, and macOS 27 will include a standalone Siri app for the first time, providing a dedicated space for interfacing with ‌Siri‌. Siri Chatbot Apple needs a ‌Siri‌ app because ‌Siri‌ is turning into a chatbot. ‌Siri‌ will work like ChatGPT or Claude, able to pull information from the web to provide answers to questions. ‌Siri‌ will be integrated into iOS, iPadOS, and macOS at the system level, and can draw on device information. It will know more personal context than before, and will be able to access emails, texts, photos, calendar information, contacts, notes, and other personal data. Some of what ‌Siri‌ will be able to do: Search the web for information Generate images Generate content Summarize information Analyze uploaded files Use personal data to complete tasks Write emails, notes, and texts Control device features and settings Search for on-device content, pulling information from emails, messages, files, and more ‌Siri‌ will be integrated into Apple apps like Mail, Messages, Photos, and Apple TV. Siri App Design The standalone ‌Siri‌ app will look similar to the ChatGPT, Claude, or Gemini apps. Bloomberg's Mark Gurman shared a mockup of what the ‌Siri‌ app will look like. Image via Bloomberg ‌Siri‌ will support text or voice-based conversations. The app will open with an "Ask ‌Siri‌" bar where users can type in a question. A paperclip icon will be available for attaching images, PDFs, and other documents. Apple will provide prompts with suggestions on what users can ask. Questions will resemble iMessage chat bubbles, with Apple adopting a design that is familiar to users. Responses will include links, images, and other information. Image via Bloomberg. A section of the app will be dedicated to past conversations that can be shown in a card-style interface with conversation summaries, or a list view. Users will be able to tap into a conversation to continue it. Dark Interface Apple's ‌Siri‌ interface both inside and outside of the dedicated ‌Siri‌ app will adopt dark colors. Apple's WWDC website hints at the colors it plans to use for ‌Siri‌. The website features the Swift bird logo in white on a black background, with subtle highlights in pink, dark blue, purple, and orange. The colors are reminiscent of the current ‌Siri‌ animation that surrounds the iPhone's display when ‌Siri‌ is activated, but the shades are softer and not as saturated. WWDC 2026 The updated version of ‌Siri‌ will be unveiled at WWDC 2026, which is set to begin on Monday, June 8 at 10:00 a.m. Pacific Time.Related Roundup: iOS 27Tag: Siri This article, "iOS 27: What We Know About the New Siri App" first appeared on MacRumors.com Discuss this article in our forums View the full article
  6. Meta's AI support assistant has been helping hackers get access to high-profile Instagram accounts, according to reports on social media. With no verification check, Meta AI would change the email address associated with an Instagram account, allowing the password to be updated. Meta introduced its AI support assistant back in December with the aim of making it easier for customers to access 24/7 account support. It can be used for reporting scams, getting information on content removal, and resetting passwords. The latter option is what bad actors were able to exploit. The Instagram vulnerability showed up on social media over the weekend, with demonstrations of the simple steps taken to get access to an account. In one demo, a hacker asks Meta's support bot to change the email address linked to a target Instagram account, and the AI does it without question. Meta's support did not do robust identity verification, and in some cases, it appears it bypassed two-factor authentication. All that was required was a VPN connection set to a location near the target account, which is trivial. Meta appeared to be verifying account ownership based on location. "Our systems recognize the device you usually use and familiar locations better than ever," reads Meta's blog post on its AI support agent. In some cases, users were asked to verify their identity with a selfie, which was bypassed using AI. For a short period of time, the exploit was available to the public, and account takeovers ramped up. One security researcher said Telegram channels that offer black market Instagram services "made lots of $$$" with Meta's AI. 404 Media said hackers have been aware of the exploit since March. Meta patched the issue over the weekend, and today, Meta's VP of communications Andy Stone said the issue has been fixed. Meta is now "securing impacted accounts." Information about the Instagram attack vector comes after hackers were able to take over accounts for Sephora, the Chief Master Sergeant of the Space Force, researcher Jane Manchun Wong, developer Albert Renshaw who owned @albert, and the archived Barack Obama White House account. Multiple other users with desirable Instagram handles reported having their accounts taken. Some users who have had their accounts stolen over the weekend were not able to use the AI to get their accounts back, and there was no option to speak with a human for help.Tags: Instagram, Meta This article, "Meta AI Support Bot Helped Hackers Hijack Instagram Accounts" first appeared on MacRumors.com Discuss this article in our forums View the full article
  7. Developers that have been invited to watch the WWDC 2026 keynote at Apple Park are also able to attend a special screening of The Mandalorian and Grogu. The screening will take place at 8:00 p.m. Pacific Time on Tuesday, June 9 at the Steve Jobs Theater. Apple says that a "special guest" will be in attendance, with the doors set to open at 7:00 p.m. There is no word on the special guest, but the movie stars Pedro Pascal as the Mandalorian and Jon Favreau directed. Favreau reportedly used the Apple Vision Pro headset to preview the IMAX version of the film while working on it, which explains why Apple is planning to screen the movie. Apple says that theater capacity is limited, and developers can RSVP to attend on Thursday, June 4 on a first-come, first-served basis on the event site. Developers were able to enter a lottery to attend an in-person WWDC event in Cupertino, California. Apple picked lottery winners earlier this year. Attendees will also be able to watch the keynote and Platforms State of the Union, plus meet with Apple experts one-on-one and in group labs. The Mandalorian and Grogu came out in the U.S. on May 22, and it is the latest film in Disney's Star Wars franchise.Related Roundup: WWDC 2026Related Forum: Apple, Inc and Tech Industry This article, "Apple Invites WWDC 2026 Attendees to 'The Mandalorian and Grogu' Screening at Apple Park" first appeared on MacRumors.com Discuss this article in our forums View the full article
  8. Apple Card and Uber One users can earn up to $30 Uber Cash through August 31 by using their ‌Apple Card‌ on Uber Eats. Users can earn $10 Uber Cash each month in June, July, and August by making one eligible order per month on Uber Eats using their ‌Apple Card‌. Uber One members can earn $10 Uber Cash on one eligible grocery or retail order per month, now through August 31, when you check out with your Apple Card on Uber Eats. Shop food, health and beauty, pet supplies, and more. You could earn up to a total of $30 in Uber Cash, awarded by Uber, to use on Uber Eats orders. ‌Apple Card‌ users are also eligible to receive a six-month free trial of Uber One when signing up with your ‌Apple Card‌ and Apple Pay. After the six-month trial, your Uber One subscription will automatically renew at $9.99 per month. In addition to these promos, Apple partners with multiple vendors to offer three percent Daily Cash back on ‌‌‌‌Apple Pay‌‌‌‌ purchases made with ‌‌‌‌Apple Card‌‌‌‌, including Uber Eats. Three percent cash back can also be earned from Nike, Ace Hardware, Uber, Hertz, Walgreens, Exxon Mobil, and Apple's own retail stores.Tags: Apple Card, Uber This article, "Apple Card Promo Offers $30 Uber Cash Back With Uber Eats" first appeared on MacRumors.com Discuss this article in our forums View the full article
  9. iOS 27 will include a nice quality-of-life improvement for those who frequently split bills with friends and family, allowing them to easily take a photo of a receipt and generate payment requests for different people, according to Bloomberg's Mark Gurman. The feature will be tied to the peer-to-peer Apple Cash feature in the Wallet app, which lets users easily send money to other people and even make purchases.Gurman says that Apple is intending to announce the new feature "as early as next week" at WWDC, and it should be included in the upcoming ‌iOS 27‌ release. Notably, Apple Cash is currently only available in the United States. The bill-splitting feature will be available through the Wallet and Messages apps, and users will be able to approve payments from an Apple Watch. This functionality isn't the only Apple Wallet improvement coming ‌iOS 27‌, as the update will also bring the ability to let users create their own digital passes by scanning items like movie tickets, concert passes, and gym membership cards.Related Roundup: iOS 27Tags: Apple Cash, Bloomberg, Mark Gurman This article, "Apple Cash in iOS 27 Will Help You Split Bills With Just a Photo" first appeared on MacRumors.com Discuss this article in our forums View the full article
  10. Apple today released macOS Tahoe 26.5.1, a small update to the ‌macOS Tahoe‌ operating system that came out last year. ‌macOS Tahoe‌ 26.5.1 comes three weeks after Apple released ‌macOS Tahoe‌ 26.5. Mac owners can download the software by opening the System Settings app and then navigating to the Software Updates section. According to Apple's release notes for the update, ‌macOS Tahoe‌ 26.5.1 addresses an unexpected shutdown issue affecting certain enterprise users on M5 Macs.This update addresses an issue for enterprise users where Macs with an M5 chip could expectedly shut down when using certain content filtering network extensions.macOS 27 is right around the corner, with Apple set to unveil the next major macOS update at the WWDC 2026 keynote on Monday, June 8.Related Roundup: macOS TahoeRelated Forum: macOS Tahoe This article, "Apple Releases macOS Tahoe 26.5.1 to Fix Shutdown Issue Affecting Enterprise Users on M5 Macs" first appeared on MacRumors.com Discuss this article in our forums View the full article
  11. Apple today released iOS 26.5.1, a minor update to iOS 26. The software is available three weeks after iOS 26.5 came out, and appears to only be available for the iPhone Air and all models in the iPhone 17 lineup. The new software can be downloaded on eligible iPhones over-the-air by going to Settings > General > Software Update. According to Apple's release notes, the update fixes a previously documented charging issue with ‌iPhone Air‌ and ‌iPhone 17‌ models.This update addresses an issue for a small number of users that may prevent wired charging on iPhone Air and iPhone 17 models when the battery is nearly drained.Apple's work on ‌iOS 26‌ is winding down as it prepares to introduce iOS 27 at the June 8 WWDC keynote event.Related Roundups: iOS 26, iPadOS 26, iPhone 17, iPhone AirBuyer's Guide: iPhone 17 (Neutral), iPhone Air (Neutral)Related Forums: iOS 26, iPhone This article, "Apple Releases iOS 26.5.1 to Fix Charging Issue on iPhone Air and iPhone 17 Models" first appeared on MacRumors.com Discuss this article in our forums View the full article
  12. Dell this week introduced a new version of the XPS 13, a laptop that it said is "contending with the MacBook Neo on price, and exceeding it on features." In the U.S., the XPS 13 starts at $699 for the general public and at $599 for eligible students, which is $100 more than the MacBook Neo on both fronts. However, Dell said the XPS 13 offers the following six features "you won't find on a MacBook Neo." A touch screen A backlit keyboard A faster second USB-C port (10 GB/s vs. 480 MB/s) Wi-Fi 7 (vs. Wi-Fi 6E) Windows Hello to unlock laptop via facial recognition (MacBook Neo does offer Touch ID at the same $699 price point) Four speakers (vs. two) "Apple's MacBook Neo is a capable machine, and its arrival confirms that there's real appetite for premium quality at accessible prices," said Dell. "Where Dell differs is what we think premium means at this price point and what we were willing to build to deliver it." While not mentioned in Dell's list above, the XPS 13's display offers up to a 120Hz refresh rate and 100% coverage of the DCI-P3 color gamut, whereas the MacBook Neo has a 60Hz refresh rate and sRGB coverage only. And with a 13-inch display and a resolution of 2,560×1,600 pixels, the XPS 13 offers Retina-like quality. Like the MacBook Neo, the XPS 13 base model is equipped with 8GB of RAM and 256GB of SSD storage inside a thin aluminum enclosure. The base model is powered by Intel's new Core Series 3 processor, with higher-priced configurations offering Intel's Core Ultra Series 3 processors, up to 32GB of RAM, and up to 1TB of storage. Apple silicon offers industry-leading performance per watt, allowing for the MacBook Neo with an A18 Pro chip to have a fanless design. In the XPS 13, there are two fans. Dell said the XPS 13 is the thinnest and lightest XPS laptop it has ever made. It measures 12.7mm thin, matching the MacBook Neo, but its advertised weight of 2.2 pounds comes in half a pound below the MacBook Neo. The XPS 13 base model with a Core Series 3 processor is arriving "soon" in the U.S., according to Dell. The laptop will come in two finishes, Sky and Storm, with the latter color not available until "later this summer." Windows vs. macOS remains an important factor, but increased competition is good for all customers, as it helps to lower prices across the board. "A few months ago at CES, we made a commitment: compete at every price point in the consumer market and build products worthy of the XPS name," said Dell. "Even though memory shortages have pushed component costs higher across virtually every industry, we are delivering on that commitment." Without the MacBook Neo, which was rumored since June 2025, we might not be in this situation.Related Roundup: MacBook NeoTags: Dell, WindowsBuyer's Guide: MacBook Neo (Buy Now)Related Forum: MacBook Neo This article, "Dell Says Its New $699 Laptop Has Features 'You Won't Find on a MacBook Neo'" first appeared on MacRumors.com Discuss this article in our forums View the full article
  13. We're just a week out from the 2026 Worldwide Developers Conference, and Apple's keynote will take place on Monday, June 8 at 10:00 a.m. Pacific Time or 1:00 p.m. Eastern Time. Ahead of the event, Apple has launched its WWDC 2026 YouTube event placeholder. Apple's YouTube page has a "Notify me" button that lets you set a reminder for the keynote in your local time. It's a useful way to make sure you're ready to watch when the event happens because you'll get a notification ahead of when the livestream begins. The ‌WWDC 2026‌ keynote will be streamed on YouTube, on the Apple Events page, and in the Apple TV app. We'll also have coverage on MacRumors.com for those who are unable to watch. At this year's event, Apple will introduce the latest versions of its software, including iOS 27, iPadOS 27, macOS 27, watchOS 27, tvOS 27, and visionOS 27. The main focus will be on Siri and the major AI updates coming to Apple's personal assistant. ‌Siri‌ is going to be much smarter, with chatbot-like capabilities and a dedicated ‌Siri‌ app. We have details on what to expect in our iOS 27 roundup.Related Roundup: WWDC 2026Related Forum: Apple, Inc and Tech Industry This article, "One Week to Go: Apple Gets Ready for WWDC 2026 With YouTube Placeholder" first appeared on MacRumors.com Discuss this article in our forums View the full article
  14. In addition to teasing WWDC 2026 with a new tagline today, Apple has shared a wallpaper, playlist, and a "Get Ready" video ahead of the event. iPhone, iPad, and Mac versions of the wallpaper are available to download on Apple's website. The wallpaper features a dark color scheme with a glowing Apple logo, which likely hints at Siri's rumored new design coming with iOS 27. The wallpaper page has a "Glow all out" tagline, which adds to the "All systems glow" and "Coming bright up" taglines that Apple previously shared. A new "WWDC26 Hello" playlist is available on Apple Music, with more playlists to follow throughout the weeklong developers conference. WWDC 2026 kicks off with Apple's keynote on Monday, June 8 at 10 a.m. Pacific Time. The company is set to unveil iOS 27, iPadOS 27, macOS 27, watchOS 27, tvOS 27, and visionOS 27 on that day, and the conference will run through Friday, June 12, with hundreds of developer sessions to be shared online. The keynote will be streamed live on the Apple Events website — the page is now live. There will also be streams in the Apple TV app and on YouTube. For developers, Apple has shared a new "Get Ready" video that offers tips on how to take advantage of WWDC, with all content and resources to be released for free as always. While there will be an in-person component at Apple Park for some lucky attendees, WWDC has largely been an online event since 2020. MacRumors will be attending WWDC 2026 in person, and we will have in-depth coverage of the event as always, so stay tuned.Related Roundup: WWDC 2026Related Forum: Apple, Inc and Tech Industry This article, "Apple Shares WWDC26 Wallpaper, Playlist, 'Get Ready' Video, and More" first appeared on MacRumors.com Discuss this article in our forums View the full article
  15. reporter posted a techarticle in DevOps
    If you’re already familiar with sandboxing as an isolation technique, sandbox security is the next layer: the policies, controls, and enforcement mechanisms that make sure those isolation boundaries actually hold under real-world pressure. According to our State of Agentic AI report, 40% of respondents cite security as the top challenge in scaling agentic AI, and 43% point to increased security exposure from orchestration sprawl. As agents execute code, call APIs, and interact with live infrastructure, a sandbox without strong enforcement is a locked room with an open window. This piece goes deeper into what sandbox security looks like day to day. We’ll cover how to choose the right implementation model and why this layer of security matters now more than ever as AI agents start executing code in your infrastructure. Key takeaways Sandbox security is the practice of enforcing isolation boundaries and access controls around sandboxed environments to prevent threats from escaping containment. Effective sandbox security combines multiple layers: process isolation, network segmentation, resource limits, and runtime monitoring. As AI agents increasingly execute arbitrary code in production, sandbox security has become critical infrastructure for safe deployment. What sandbox security means in practice Sandbox security is the set of controls and enforcement mechanisms that prevent untrusted or risky processes from breaching their isolation boundaries. Where sandboxing creates the boundary, sandbox security ensures it holds. As we mentioned before, a sandbox without strong security controls is like a locked room with an open window. The isolation exists in theory, but the enforcement gaps leave room for escape. For developers and platform engineers, this translates into concrete, daily decisions: which system calls an agent is allowed to make, whether a process can reach the network, how much memory or CPU it can consume, and what happens when it tries to exceed those limits. These are not abstract policy questions. They’re flags you set, profiles you configure, and defaults you either audit or accept on faith. 5 Core components of sandbox security Sandbox security is not a single control. It’s a combination of mechanisms that work together to keep isolation boundaries intact. The most effective implementations layer several of these components so that a failure in one area does not compromise the entire sandbox. 1. Process isolation Process isolation ensures that code running inside a sandbox has no visibility into processes on the host or in other sandboxes. On Linux, kernel namespaces handle this by partitioning process IDs, network interfaces, file systems, and user IDs into separate scopes. A process inside a namespace sees only what you’ve explicitly made available to it. When things go wrong. Run a container with –pid=host and you’ve just given that workload a window into every process on the machine. It can enumerate services, identify targets, and attempt to interfere with them. That single flag turns your sandbox into a shared apartment. Proper sandbox security eliminates this by enforcing strict namespace boundaries by default and flagging configurations that weaken them. 2. System call filtering Even within a namespace, processes interact with the host kernel through system calls. System call filtering (commonly implemented through seccomp profiles on Linux) restricts which kernel functions a sandboxed process can invoke. Docker’s default seccomp profile blocks around 44 of the 300+ available Linux system calls. That’s a meaningful reduction in attack surface, but it’s a general-purpose default, not a tailored fit. What to look for. High-security workloads benefit from custom seccomp profiles scoped to the specific application. A sandboxed process that needs to read files and make HTTP requests has no reason to call mount, init_module, or reboot. The tighter the profile, the fewer options an attacker has if they gain code execution inside the sandbox. It’s the same least-privilege thinking that underpins container security more broadly. 3. Network segmentation A sandbox that can communicate freely with external systems or internal services is harder to defend. Network segmentation restricts what a sandboxed process can reach, limiting both inbound and outbound connections. That’s especially important for workloads that process untrusted input or execute arbitrary code. How this applies to agents. AI agents that invoke external tools or APIs during execution present a unique challenge. Without network controls, a compromised agent could exfiltrate data to an external endpoint or pivot to internal services it was never intended to reach. Enforcing egress policies at the sandbox environment level ensures agents can only communicate with pre-approved destinations. 4. Resource limits and quotas Resource exhaustion attacks do not require a sandbox escape, and that’s what makes them easy to overlook. A runaway process that consumes all available CPU or memory can take down every other workload on the same host without ever breaching an isolation boundary. Cgroups on Linux cap what each sandbox can consume, turning a potential host-wide outage into a single contained failure. The tricky part is calibration. Set memory limits too low and legitimate workloads get OOM-killed. Set them too high and you’re back to sharing the blast radius. The most reliable approach is to monitor actual resource consumption over time, set limits based on observed peaks plus a margin, and treat the initial configuration as something you’ll tune rather than something you’ll get right on the first pass. 5. Runtime monitoring and audit trails Prevention is only part of the equation. You also need to know what’s happening inside the sandbox. Runtime monitoring tools observe system calls, file access patterns, network connections, and process behavior as they occur. When something deviates from the expected baseline, the system can alert operators or kill the process automatically. If you’re evaluating AI governance tools, you’ll find that many of these runtime observability capabilities overlap directly with agent monitoring requirements. Audit trails serve a different but equally important purpose. When an incident does happen, you need a forensic record of exactly what the sandboxed process did: which files it touched, which endpoints it called, which syscalls it made. That’s valuable for incident response and essential for compliance frameworks that require demonstrable evidence of isolation and access control. Choosing an implementation model Understanding the different sandboxing models is a good starting point, but the more useful question for sandbox security is: what does each model actually protect against, and what do you need to configure to make it hold? Here’s how they compare on the dimensions that matter for security decisions. Model Isolation boundary Key security controls Best for Watch out for OS-level namespaces, seccomp, MAC Shared kernel, separate namespaces seccomp profiles, AppArmor/ SELinux policies, read-only rootfs, capability dropping Container runtimes, CI/CD jobs, most production workloads Kernel vulnerabilities bypass all controls; defaults are permissive VM-based microVMs, hardware virtualization Separate kernel per sandbox Hypervisor-enforced memory isolation, independent kernel patching, vTPM Multi-tenant platforms, malware analysis, running fully untrusted code Higher resource cost; networking and image management add ops complexity Application-level Wasm, browser tabs, language VMs Within-process memory and API restrictions Memory-safe execution model, restricted host API surface, capability-based permissions Plugin systems, edge functions, embedded scripting App compromise bypasses internal sandbox; should never be the only layer The right choice depends on your threat model. For most containerized workloads, OS-level controls with a hardened seccomp profile and mandatory access control policy provide strong security at minimal overhead. VM-based isolation makes sense when you genuinely do not trust the code being executed, such as in multi-tenant environments or agent-driven code generation. Application-level sandboxing is a valuable addition in either case, but it should layer on top of kernel-level or hypervisor-level controls, never replace them. Whichever model you choose, treat the default configuration as a starting point. The security of any sandbox does depend on the isolation technology, but whether someone actually audited the settings is the sticking point. It’s the same software supply chain security discipline that applies at every layer of the stack: trust, but verify the configuration. Sandbox security for AI agents Traditional applications follow predictable execution paths. You can read the code, trace the logic, and anticipate the behavior. AI agents are a different story. They make decisions at runtime, generate and execute code on the fly, call external tools, and produce outputs that their own developers may not have anticipated. That autonomy is the whole point of agents, but it’s also what makes sandbox security non-negotiable. In these situations, perimeter-based security is not sufficient. You need controls that constrain agent behavior at the execution level, regardless of what the agent decides to do. It’s a fundamentally different security challenge. Teams building AI agent sandboxes are converging on a few patterns that address the unique risks agents introduce. Isolating tool use When an AI agent invokes a tool (a code interpreter, a file manager, an API client), each tool execution should run inside its own sandbox with the minimum permissions required. If the agent’s tool-use layer is compromised, sandbox security prevents that compromise from reaching the host or other services. Controlling data access Agents often process sensitive data as part of their reasoning. Sandbox security controls which files, databases, and environment variables are visible inside the agent’s execution environment. A well-configured secure sandbox exposes only the data the agent needs for its current task, nothing more. Enforcing network boundaries Left unchecked, an agent with network access could make arbitrary HTTP requests, potentially exfiltrating data or interacting with unintended services. Network-level sandbox security restricts egress to an allowlist of approved endpoints. Getting started with sandbox security Start with your threat model. Which workloads process untrusted input? Which ones execute arbitrary code or handle sensitive data? Those are your highest-priority candidates for hardened sandbox security. From there, layer controls rather than relying on any single mechanism. Combine process isolation with system call filtering, add network segmentation, set resource limits, and enable runtime monitoring. Each layer addresses a different category of risk. Together, they create a posture where any single failure stays contained. If you’re already running containers, much of the foundation is in place. Container runtimes provide namespace isolation, seccomp profiles, and cgroup limits out of the box. The next step is to actually audit those defaults against your requirements and tighten what needs tightening. Docker Sandboxes extend this with purpose-built microVM isolation for agent workloads. Start with Docker Sandboxes to put sandbox security into practice. Frequently asked questions What is the difference between sandboxing and sandbox security? Sandboxing is the technique of running code in an isolated environment. Sandbox security is the broader discipline of ensuring that isolation actually holds. It’s the policies, configurations, monitoring, and enforcement mechanisms that make a sandbox resistant to escape, resource abuse, and unauthorized access. You can have a sandbox without strong security, but the isolation it provides will be unreliable. Can sandbox security prevent all container escapes? No single security measure can guarantee complete protection. Sandbox security significantly raises the bar by layering multiple controls (namespaces, seccomp, network policies, resource limits, runtime monitoring) so that an attacker would need to bypass several independent defenses. This defense-in-depth approach reduces risk to a level most organizations consider acceptable, especially when combined with regular patching and configuration audits. How does sandbox security affect application performance? The performance impact varies by implementation. OS-level controls like namespaces and seccomp add negligible overhead. Network policies and resource limits introduce minimal latency. VM-based sandbox security has higher overhead due to hardware virtualization, but technologies like microVMs have narrowed that gap significantly. For most workloads, it’s a trade-off that strongly favors security. Is sandbox security relevant for AI and machine learning workloads? Absolutely. AI workloads, particularly agents that execute code dynamically, are among the highest-priority use cases for sandbox security. These workloads are inherently unpredictable, and that’s exactly why strong isolation boundaries are essential. Sandbox security ensures that even if an agent produces unexpected behavior, the impact stays contained within its execution environment. What compliance frameworks require sandbox security? Several frameworks reference isolation and access controls that map directly to sandbox security practices. SOC 2 requires logical access controls and monitoring. PCI DSS mandates network segmentation for systems handling payment data. FedRAMP and NIST 800-53 include specific controls around process isolation and boundary protection. Organizations pursuing these certifications often find that container-based sandbox security, guided by a structured AI governance framework, provides a strong implementation foundation. View the full article
  16. Apple's annual developers conference WWDC returns for 2026 next week, and the company has teased the event with a new "All systems glow" tagline. "All systems glow" is a play on the phrase "all systems go," and it likely hints at Siri's rumored new design on iOS 27. Both a dedicated Siri app and a new "Search or Ask" feature in the iPhone's Dynamic Island will reportedly have a dark color scheme with glowing elements, as shown in leaked images last week. Apple's previous tagline for WWDC 2026 was "Coming bright up." That tagline and the graphics for the event all hint at the new Siri design as well. WWDC 2026 kicks off with Apple's keynote on Monday, June 8 at 10 a.m. Pacific Time. The company is set to unveil iOS 27, iPadOS 27, macOS 27, watchOS 27, tvOS 27, and visionOS 27 on that day, and the conference will run through Friday, June 12, with hundreds of developer sessions to be shared online. All systems glow for a great #WWDC26 next week! Tune in June 8 at 10 am PT. pic.twitter.com/g6A5v5vWI4 — Greg Joswiak (@gregjoz) June 1, 2026 Related Roundup: WWDC 2026Tag: SiriRelated Forum: Apple, Inc and Tech Industry This article, "Apple Teases Next Week's WWDC 2026 Event: 'All Systems Glow'" first appeared on MacRumors.com Discuss this article in our forums View the full article
  17. Apple's first foldable iPhone, known as the "iPhone Ultra," will feature impressive vapor chamber cooling and launch in September despite production difficulties, a known leaker today reported. The iPhone 17 Pro's vapor chamber thermal plate. In a new post today on Weibo, the leaker known as "Fixed Focus Digital" said the foldable iPhone's pre-assembly manufacturing processes are facing pressure and that the initial production ramp-up is proving difficult. The leaker added that prevailing speculation points to the original September launch schedule holding, and teased that further positive news is expected tomorrow. The leaker added that the device will feature vapor chamber (VC) cooling and that its thermal performance is "quite impressive," with Apple "really going all out" with its thermal engineering. The claim marks the first time a source has attributed vapor chamber cooling to the ‌iPhone Ultra‌, and the detail is notable given the extent of the design compromises the device is expected to make. Rumors suggest the ‌iPhone Ultra‌ could be missing at least five features present on the ‌iPhone 17 Pro‌, including Face ID, a telephoto camera, MagSafe, the Action Button, and a physical SIM card slot, largely as a result of its 4.5mm folded thickness. The iPhone Air, which shares a similar ultra-thin philosophy, does not feature vapor chamber cooling, making its presence on the ‌iPhone Ultra‌ far from a given before today's report. Apple overhauled the thermal design of the ‌iPhone 17 Pro‌ last year, adopting a vapor chamber cooling system for the first time in an iPhone. The system circulates a small amount of deionized water to move heat away from the A19 Pro chip and distribute it throughout the device's aluminum unibody frame, with Apple claiming the design delivers 40% better sustained performance for demanding tasks compared to the graphite thermal systems used in previous Pro models. The post arrives amid a series of production difficulty reports surrounding the foldable iPhone. Earlier this month, Fixed Focus Digital pointed to yield problems at the pre-assembly stage related to surface-mount technology (SMT), distinct from a separate report by the leaker known as "Instant Digital" that attributed production difficulties to the hinge failing Apple's quality control standards under conditions of prolonged, high-frequency opening and closing. Fixed Focus Digital's account pushed back on that framing, suggesting the hinge was not the primary source of difficulty. DigiTimes reported in April that production was already running roughly one to two months behind schedule while still maintaining that a fall 2026 launch remained on track, with mass production planned to begin in July. Fixed Focus Digital also reported in April that price negotiations with Apple's assembly partner were a potentially disruptive factor. Despite the difficulties, the launch timeline does not appear to be at risk. Bloomberg's Mark Gurman reported in April that the ‌iPhone Ultra‌ is on track for a September debut alongside the iPhone 18 Pro and ‌iPhone 18 Pro‌ Max, though he noted the timing was not final and production had yet to ramp up. The device is expected to feature a 7.8-inch inner display, a 5.5-inch cover display, the A20 chip, the C2 modem, Touch ID in place of ‌Face ID‌, and two rear cameras, with pricing rumored to start at around $2,000.Related Roundup: iPhone FoldTags: Fixed Focus Digital, Foldable iPhone, iPhone Ultra This article, "Foldable 'iPhone Ultra' Rumored to Feature Vapor Chamber Cooling Despite Thin Design" first appeared on MacRumors.com Discuss this article in our forums View the full article
  18. Amazon today has the AirPods Pro 3 available for $199.99, down from $249.00. This is a match of the all-time low price on the AirPods Pro 3, and it's a deal that hasn't been as frequent as discounts on the AirPods 4 and AirPods Max 2. Note: MacRumors is an affiliate partner with some of these vendors. When you click a link and make a purchase, we may receive a small payment, which helps us keep the site running. This model of the AirPods Pro launched in September 2025 and has 2x better Active Noise Cancellation than the previous generation, better audio quality, a revised fit that's meant to improve comfort and stability, Live Translation for in-person conversations, and heart rate sensing for workouts. $49 OFFAirPods Pro 3 for $199.99 Head to our full Deals Roundup to get caught up with all of the latest deals and discounts that we've been tracking over the past week. Deals Newsletter Interested in hearing more about the best deals you can find in 2026? Sign up for our Deals Newsletter and we'll keep you updated so you don't miss the biggest deals of the season! Related Roundup: Apple Deals This article, "AirPods Pro 3 Available for $199.99 Low Price on Amazon" first appeared on MacRumors.com Discuss this article in our forums View the full article
  19. This is Part 2 of our AI Coding Agent Horror Stories series, an in-depth look at real-world security incidents exposing the vulnerabilities in AI coding agents, and how Docker Sandboxes deliver workspace-scoped isolation that contains the worst failures at the execution layer. In part 1 of this series, we mapped six categories of AI coding agent failures and the architectural reason they keep happening: the agent runs as you, on your filesystem, with your credentials, and nothing sits between the model’s decision and the shell’s execution. For Part 2, we’re going deep on the most destructive failure mode in the entire ecosystem: an AI coding agent deleting a developer’s entire home directory in a single command. Today’s Horror Story: The Tilde That Wiped a Mac In December 2025, a Reddit user posting under the handle u/LovesWorkin shared what became one of the most-discussed AI coding agent incidents of the year. They had asked Claude Code to clean up an old repository. Claude executed rm -rf tests/ patches/ plan/ ~/, and the trailing ~/ wiped their entire Mac. This wasn’t a CVE. It wasn’t a sophisticated attack. It was the AI coding agent doing exactly what it was told, in a way the user did not anticipate, with no architectural boundary to catch the mistake. In this issue, you’ll learn: How a single trailing slash in a rm -rf command erased a developer’s entire Mac Why the --dangerously-skip-permissions flag exists, and why developers keep using it anyway The pattern this incident shares with the GitHub-issue-#10077 Ubuntu wipe and the Claude Cowork family-photos incident How Docker Sandboxes contains this entire class of failure at the execution layer Why This Series Matters Each “Horror Story” in this series examines a real-world incident that turns laboratory findings into production disasters. These aren’t hypothetical attacks. They’re documented cases with named victims, screenshotted command logs, and in several cases, public apologies from the vendors. Our goal is to show the human impact behind the security statistics, demonstrate how these failures unfold in practice, and provide concrete guidance on protecting your AI development infrastructure through Docker’s workspace-scoped execution model. The story begins with something every developer has done: asking the agent to clean up an old repository. The Problem On December 8, 2025,a developer posting under the handle u/LovesWorkin shared a Reddit thread on r/ClaudeAI with the title that says everything: “Claude CLI deleted my entire home directory! Wiped my whole mac.” The post climbed past 1,500 upvotes within hours, was amplified by Simon Willison on X, covered by Gigazine in Japan on December 16, and became one of the most-discussed AI coding agent incidents of 2025. The setup was unremarkable. The user asked Claude Code to clean up packages in an old repository. Routine maintenance, the kind any developer would hand off without thinking. Claude generated and executed: rm -rf tests/ patches/ plan/ ~/ On the surface, this is a command to delete three project directories. The fatal error is the trailing ~/. In Unix, ~ expands to the user’s home directory. ~/ with the trailing slash means “everything inside the home directory.” Combined with rm -rf, which removes recursively and without confirmation, the command deletes the user’s entire home directory in a single shot. Within seconds, the developer had lost: The Desktop, Documents, and Downloads folders The Library folder containing application state for every app on the system The Keychain, which broke authentication across every app, including Claude Code itself, which could no longer talk to its own backend Years of project files, family photos, and work product All of it on an SSD where TRIM had already zeroed the freed blocks by the time recovery was attempted There was no recovery. As the developer put it in the original thread: “It nuked my whole Mac! What the hell?” Caption: Once an AI agent gains direct filesystem access, “organize my desktop” can become catastrophic. The Scale of the Problem This wasn’t a one-off. It was an instance of a pattern. On October 21, 2025, weeks before the LovesWorkin incident, developer Mike Wolak filed GitHub issue #10077 against the Claude Code repository. Wolak’s report described a similar failure on Ubuntu/WSL2: Claude Code had executed rm -rf starting from root, and the logs showed thousands of “Permission denied” messages for /bin, /boot, and /etc as the agent worked its way through the system trying to delete files it didn’t own. Every user-owned file on the system was gone. Anthropic tagged the issue area:security and bug. The damning detail in Wolak’s report: he was not running with --dangerously-skip-permissions. Claude Code’s permission system simply failed to detect that the agent’s command would expand destructively before the user approved it. Two weeks later, on November 28, 2025, GitHub issue #12637 documented yet another variant. Claude Code had earlier created a directory literally named ~ by mistake. Later, when the agent tried to clean up that directory by running an unquoted rm -rf ~, the shell expanded ~ to the user’s actual home directory before rm saw the argument. Same destructive outcome, completely different mechanism. The agent had found a new way to destroy a developer’s work. Shortly after the January 2026 launch of Anthropic’s Claude Cowork, Nick Davidov, founder of a venture capital firm, used Anthropic’s Claude Cowork, a general-purpose AI agent product to organize his wife’s desktop. He explicitly granted permission for temporary Office files only. The agent deleted a folder containing 15 years of family photos, somewhere between 15,000 and 27,000 files, via terminal commands that bypassed the macOS Trash entirely. Davidov recovered the photos only because iCloud’s 30-day retention happened to still be in effect. The Trash had been bypassed entirely. These aren’t isolated stories. They’re the same story with different file paths. How the Failure Works To understand why these incidents keep happening, we need to look at the architecture of how a modern AI coding agent executes commands on a developer’s machine. The agent is doing exactly what its design says it should do. The architecture is the failure. The Coding Agent (Claude Code, Cursor, Replit, Kiro) is an AI-driven shell. It reads your prompt, reasons about how to satisfy it, generates a command, and runs that command directly on your operating system. There is no separate “execution proposal” step that a human approves. The reasoning step and the execution step are the same step. The User’s Shell is whatever shell the agent inherited when you launched it. On macOS, that’s typically zsh. The agent’s commands run through this shell with the developer’s full user permissions. ~ expands to the developer’s home directory because that’s what ~ means in zsh. Permission Inheritance is implicit and total. Whatever the developer’s shell can do, the agent can do. There is no separate identity for “the agent acting on the developer’s behalf.” The agent is the developer for as long as the session lasts. The --dangerously-skip-permissions Flag, which Lanzani’s technical blog post analyzes in detail, is what removes the one safety net that exists by default. Without the flag, Claude Code asks for confirmation before each shell command. With it, the agent runs commands in the background while the developer goes back to other work. That last point is the one that matters. The flag exists because the default behavior, asking for confirmation on every shell command, makes multi-step tasks tedious. Developers add the flag to make the agent useful. The agent then becomes capable of executing destructive commands without intervention. The flag is named honestly. It is a dangerous flag. But it is also a popular one, because the alternative is approving every ls and cat the agent runs. The vulnerability happens between steps 2 and 3. The agent reasons about what command to run. The shell executes that command on the host. Nothing sits in between. There is no architectural boundary that says “this command would delete the user’s home directory, refuse to run it.” The shell sees a syntactically valid rm -rf and does what rm -rf does. Technical Breakdown: How a Trailing Slash Wipes a Mac Here’s how the incident unfolds, step by step: Caption: Diagram illustrating how unrestricted AI agent execution can escalate a simple cleanup task into full home-directory destruction 1. The User’s Request The developer asks Claude Code to clean up packages in an old repository. The prompt is the kind of thing every developer types daily: Please clean up unused test files, patches, and plan documents from this old repo. 2. The Agent’s Reasoning The agent identifies three directories that match the request: tests/, patches/, and plan/. It then generates a rm -rf command, because removing directories recursively is the standard way to delete them. So far, this is correct behavior. 3. The Hallucinated Argument The agent appends ~/ to the command. We don’t know exactly why. Possibly the agent inferred that “clean up” included tidying the home directory. Possibly it generated ~/ as a no-op separator and didn’t realize it was a destructive argument. Possibly its training data included shell snippets where ~/ appears in this position and it pattern-matched. The result either way is the same: rm -rf tests/ patches/ plan/ ~/ This is a syntactically valid shell command. There is nothing in the syntax that says “this is dangerous.” 4. Shell Expansion When this command runs in zsh on macOS, the shell expands ~/ to /Users/loveswarkin/. The command becomes, effectively: rm -rf tests/ patches/ plan/ /Users/loveswarkin/ The shell does not warn. It does not confirm. It does not flag the home directory as protected. There is no system-level check that says “this command would delete a user’s entire home directory.” The shell does what shells do: expand the path and execute. 5. Recursive Force Deletion rm -rf walks the filesystem under each argument and deletes everything. The Desktop, Documents, Library, Keychain, Application Support folders, Claude Code’s own config and credentials, the user’s SSH keys, the user’s git config, the user’s photos. All of it. In order. Without pausing. The deletion runs to completion in seconds because most of these files are small, and the SSD’s controller acknowledges deletes nearly instantly. By the time the user notices their terminal is unresponsive and tabs out to check, it’s done. 6. The Aftermath The keychain is gone, which means every app that authenticates against the keychain is now logged out. Mail, browsers, Slack, GitHub Desktop, every service that stored a token, every saved password. The user’s identity infrastructure on that machine is gone. Claude Code itself can no longer authenticate, because its own credentials lived in the home directory. The agent that did the destruction can’t even apologize properly, because it can’t connect to its own backend. The Impact Within a single command execution, the developer has: Lost years of personal and professional files Lost cryptographic keys (SSH, GPG) needed to access remote systems Lost authentication state for every app on the system Lost git history for any uncommitted work Inherited a system in a partially-broken state where logging back in and reinstalling apps will take days There is no recovery path. SSDs with TRIM enabled (which is the default on every modern Mac) zero freed blocks at the controller level, so even forensic recovery tools come up empty. The data is not “deleted” in the sense of “marked unavailable but recoverable.” It is gone. This is what one trailing slash in one AI-generated command produces. How Docker Sandboxes Eliminates This Attack Vector The current AI coding agent ecosystem forces developers into the same dangerous tradeoff that the MCP ecosystem forced on users in Part 1 of our companion series. Every time you run claude --dangerously-skip-permissions or any equivalent flag in another agent, you’re executing arbitrary AI-generated commands directly on your host system with full access to: Your entire file system Your home directory and everything in it Your credentials, keychain, SSH keys, and cloud config Every running process and every network connection your shell can make This is exactly how the rm -rf ~/ incident achieves total system destruction. The agent runs as the developer, on the developer’s filesystem, with no architectural boundary to stop it. Docker’s Security-First Architecture Docker Sandboxes represents a fundamental shift in how AI coding agents execute. Rather than running directly on the host with user-level permissions, the agent runs inside a microVM with its own kernel, its own filesystem, and its own network. The agent’s view of ~/ is the workspace mount, not the developer’s actual home directory. The developer’s actual home directory simply does not exist from inside the sandbox. Docker Sandboxes are managed through the sbx CLI. A quick distinction worth making: Docker Sandboxes are the isolated microVM environments where agents actually run. sbx is the standalone CLI tool used to create, launch, and manage them. Sandboxes are the environments. sbx is what you type to control them. Docker Sandboxes solves the rm -rf ~/ class of failure by making the destructive command architecturally impossible. The agent can absolutely generate rm -rf tests/ patches/ plan/ ~/. It can absolutely run that command. The command will absolutely succeed. But what gets deleted is the workspace inside the sandbox, not the developer’s actual home directory. The host filesystem isn’t visible from inside the microVM, so there is nothing to delete. Workspace-Scoped Execution The most important architectural shift is that the agent’s filesystem view is the workspace mount, and only the workspace mount. # Install sbx and sign in brew install docker/tap/sbx sbx login # Launch the agent inside a sandbox scoped to the project directory cd ~/my-project sbx run claude Three commands and the agent is now running inside a microVM. From inside the sandbox, the agent’s ~/ IS the workspace, not the developer’s actual home directory. The Library folder, the keychain, the SSH keys, the AWS config – none of that exists inside the sandbox. The agent cannot reach what it cannot see. A rm -rf ~/ from inside the sandbox deletes the workspace files. The developer can throw the sandbox away with sbx rm and start fresh. The host system is untouched. Blocked Credential Paths Even if a developer explicitly mounts additional paths into the sandbox, common credential directories are blocked from being mounted by default: # Credential roots blocked by default: # ~/.aws ~/.ssh ~/.docker ~/.gnupg # ~/.netrc ~/.npm ~/.cargo ~/.config # A misconfigured mount that tries to include these is rejected # before the sandbox even starts. sbx run claude This blocklist directly addresses the keychain-deletion fallout from the LovesWorkin incident. Even an agent that decides to recursively delete its workspace cannot reach the credentials that keep the developer’s authentication state intact. Read-Only Mounts for Sensitive Workspaces For workflows where the agent should read but not write to a directory, the :ro suffix declares a mount as read-only: # Mount the project workspace as writable, the docs as read-only sbx run --name docs-review claude /path/to/project /path/to/docs:ro A rm -rf against a read-only mount fails at the kernel level. The microVM enforces the mount mode, which means the agent cannot decide to override it through reasoning, prompt manipulation, or flag misuse. The infrastructure decides what’s writable. The model doesn’t get a vote. Git-Worktree Isolation for Risky Operations For destructive operations like cleanup tasks, refactors, and “let me just clean this up” requests, sbx run --branch lets the agent operate on an isolated Git worktree: # Create a sandbox on a fresh feature branch sbx run --name cleanup-agent --branch=cleanup/old-files claude . # Review what got cleaned up before merging sbx exec cleanup-agent git diff main # If the agent did something destructive, throw it away sbx rm cleanup-agent This is the architectural answer to “the agent decided to drop and recreate the schema.” The agent’s changes never touch the main branch until the developer reviews them. If the agent runs rm -rf ~/, the worktree gets wiped and the main branch is untouched. The developer reviews git diff main, sees what happened, and decides whether to merge or discard. Throwaway Sandboxes by Design The final piece is that sandboxes are designed to be discarded: # When the work is done, list active sandboxes and remove the one you're done with: sbx ls sbx rm <sandbox-name> This is what makes the Docker Sandboxes model fundamentally different from running an agent on the host. On the host, a destructive command leaves permanent damage. Inside a sandbox, every session is throwaway. The worst the agent can do is destroy the workspace, which is reproducible from the source repo. The keychain, the credentials, the years of personal data, none of those can be touched, because none of those exist from inside the sandbox. What This Looks Like in Practice Here’s the LovesWorkin incident replayed under Docker Sandboxes. The user asks the same question. The agent generates the same command. The shell executes the same expansion. # After Docker Sandboxes: $ cd ~/my-project $ sbx run claude > Please clean up unused test files, patches, and plan documents [Agent runs: rm -rf tests/ patches/ plan/ ~/] [Workspace inside the sandbox wiped. Host home directory intact.] # The sandbox is throwaway. List it and remove it to start fresh: $ sbx ls $ sbx rm <sandbox-name> The agent’s behavior is identical. The architectural outcome is completely different. The Practical Improvements Security Aspect Traditional AI Coding Agent Docker Sandboxes Execution Environment Direct host execution as the user Isolated microVM with its own kernel Filesystem View Full host filesystem, including ~/ Workspace mount only Credential Access All credentials in user’s home dir Credential paths blocked by default Destructive Command Impact Permanent host damage Throwaway sandbox Review Before Merge None Git worktree isolation with sbx exec <sandbox-name> git diff main Recovery Often impossible (TRIM zeroes blocks) sbx rm and start fresh Best Practices for Secure AI Coding Agent Deployment Stop running coding agents directly on your host. Containerization or microVM isolation should be the default, not an advanced option. Use sbx run for every coding task that involves filesystem operations. Especially “clean up,” “organize,” “refactor,” and “delete unused” prompts. These are the prompt categories most likely to produce a destructive rm -rf. Use Git worktrees for destructive operations. sbx run --name <name> --branch=<branch> claude ensures the agent’s changes are reviewable before they touch your main branch. Never use --dangerously-skip-permissions on the host machine. If you need the agent to run commands without per-command approval, run it inside a sandbox. The sandbox boundary is what makes “skip permissions” safe. Treat the sandbox as throwaway. Don’t store anything important inside it. The whole point is that you can sbx rm and start fresh. Audit the policy log. sbx policy log shows every allowed and denied connection attempt, which becomes your forensics trail if something does go wrong. Take Action: Secure Your AI Coding Agent Today The path to safe AI coding agent execution starts with one command. Here’s how to move away from running agents on the host: Install Docker Sandboxes. Visit the Docker Sandboxes documentation to install sbx and run your first sandboxed agent in under five minutes. Try it with your existing workflow. sbx run claude (or sbx run cursor, sbx run codex, etc.) drops your existing agent into a microVM with no configuration changes required. Read the architecture deep-dive. The Docker Sandboxes architecture documentation explains the microVM model, the workspace mounting, and the network policy layer. Browse the MCP Catalog. If your agent uses MCP servers, the Docker MCP Catalog provides containerized, verified servers that complement sandboxed agent execution. Conclusion The LovesWorkin incident, the Mike Wolak Ubuntu wipe, the Claude Cowork family-photos deletion, and the GitHub issue #12637 shell-glob expansion bug are all the same story. An AI coding agent reasoned its way through a task, generated a command that contained a destructive argument, and the shell executed it because there was nothing in the architecture to say “this command would destroy the developer’s work.” These aren’t bugs in Claude Code, or Cursor, or Kiro, or any individual agent. They’re properties of the execution model. As long as agents run on the host with the user’s permissions, this category of failure will keep happening, with new variations each time. Docker Sandboxes doesn’t try to make the agent smarter. It changes where the agent runs. The agent gets a workspace. It does not get your machine. Coming up in our series: Issue 3 will explore the AWS Cost Explorer outage, where Amazon’s own Kiro agent decided to delete and rebuild a production environment in seconds, and what scoped-identity sandbox configuration prevents that class of failure. Learn More Run agents safely with Docker Sandboxes: Visit the Docker Sandboxes documentation to get started with workspace-isolated agent execution in minutes. Explore the Docker MCP Catalog: Discover MCP servers that connect your agents to external services through Docker’s security-first architecture. Download Docker Desktop: The fastest path to a governed AI agent environment, with Docker Sandboxes, MCP Gateway, and Model Runner in a single install. Read the MCP Horror Stories series: Start with issue 1 to understand the protocol-layer security risks that complement the agent-layer risks covered here. View the full article
  20. Apple's Car Keys feature appears to be coming to future vehicles made by Indian maker Mahindra, based on code changes discovered by MacRumors in Apple's Wallet app backend. Car Keys allows an iPhone or Apple Watch with NFC capabilities to unlock a vehicle through the Wallet app. A digital version of a car key is stored in Wallet, and unlocking can be done simply by holding an Apple Watch or ‌iPhone‌ near a compatible vehicle's NFC reader. Mahindra already supports Samsung Wallet's Digital Car Key feature for Galaxy devices, but it does not yet offer native Apple Car Key support, so this would need to be implemented by the automobile manufacturer first on future models. What can be done with Car Keys may vary by car manufacturer, but at a minimum, Car Keys can be used to unlock your car, lock your car, and start your car, which are the features available with a physical key. Apple introduced Car Keys in 2022, and car manufacturers like BMW, Rivian, Kia, and Hyundai have all implemented support for Car Keys. Apple maintains a full list of vehicles that support Car Keys on its CarPlay model availability webpage.Tag: iPhone Car Keys This article, "Apple Car Key Support Coming to Future Mahindra Vehicles" first appeared on MacRumors.com Discuss this article in our forums View the full article
  21. Apple is expected to launch its first foldable iPhone later this year. Rumors suggest the "iPhone Ultra" will come in two color options, and a leaker shared an image today that allegedly shows one of them. Posted on Weibo by the Chinese leaker known as Ice Universe, the image purportedly offers a first glimpse of Apple's foldable in white. The device is believed to have entered early mass production, but the model shown is likely a dummy. Regardless, fellow leaker Instant Digital has said white is so far the only "confirmed" finish that the device will be available in. It is not yet clear what the alternative color will be, but Macworld recently cited a supply chain source claiming that it will be an indigo option similar to the iPhone 17 Pro's Deep Blue finish. The same source said the device will offer fewer choices than the iPhone 18 Pro models, with no bold or vibrant colors. According to Bloomberg's Mark Gurman, Apple plans to "stay away from fun colors" and stick to more traditional space gray/black and silver/white finishes. Such an approach would be similar to the iPhone X, which launched in just two colors – Silver and Space Gray – when it debuted in November 2017. A limited color selection may simply reflect the foldable iPhone's expected low production volumes. Industry analyst Ming-Chi Kuo has warned that manufacturing challenges could constrain supply through at least the end of 2026, and adding more colors would increase complexity and costs for an already difficult-to-produce device. With launch supply expected to be tight and a price above $2,000, as reported by Gurman, Apple likely has little incentive to expand the initial color lineup, while buyers at this price point are also less likely to base their purchasing decision on color options. The iPhone Ultra is expected to launch alongside the iPhone 18 Pro and iPhone 18 Pro Max this coming September.Tags: Foldable iPhone, Ice Universe, iPhone Ultra This article, "First 'Confirmed' iPhone Ultra Color Allegedly Revealed in Leaked Image" first appeared on MacRumors.com Discuss this article in our forums View the full article
  22. Nvidia is entering the consumer PC chip business for the first time and has thrown down the gauntlet to Apple, describing its new RTX Spark processor as "the most efficient PC chip ever built." Nvidia says its RTX Spark Superchip is purpose-built to run AI agents that can work proactively across apps and run in the background as a personal "teammate." With the chip, Nvidia says users can "render ultra-large 90GB 3D scenes with OptiX and DLSS, edit 12K 4:2:2 video with the NVIDIA Blackwell decoder, run 120-billion-parameter large language models with 1 million tokens context, and play AAA games at 1440p resolution and over 100 frames per second with ray tracing, DLSS and Reflex." The chip was announced by Nvidia chief executive Jensen Huang at the Computex conference in Taipei on Monday. It's a big play for a company traditionally focused on graphics cards to move into the kind of integrated silicon that runs an entire laptop. It also puts the RTX Spark on a collision course with Apple's M5, widely regarded as the laptop chip to beat for running AI tasks on-device. Like Apple's chips, the RTX Spark is Arm-based, pairing an Nvidia Blackwell RTX graphics processor with a Grace CPU. It's effectively the same GB10 chip that's found in the DGX Spark, the tiny "personal AI supercomputer" that Nvidia released last year. Microsoft's new 15-inch Surface Laptop Ultra will be among the first machines to ship with the integrated silicon. The machine features a mini-LED touchscreen, the largest haptic touchpad Microsoft has fitted to a Surface, and a selection of ports covering HDMI, USB-C, USB-A, SD cards, and headphones. Configured with up to 128GB of unified memory, the Ultra can run AI models with up to 120 billion parameters locally, a figure Microsoft attributes to Nvidia, based on a theoretical performance measure. Microsoft claims it's the most powerful Surface it has ever built. Nvidia says its chip will eventually appear in around 30 laptops and more than 10 desktops. Microsoft says the Surface Laptop Ultra will arrive later this year. Pricing has not been announced, but Nvidia has suggested the first wave of RTX Spark machines will target the premium end of the market.Tags: Apple Silicon, Microsoft, Nvidia This article, "Nvidia Challenges Apple Silicon With New RTX Spark PC Chip" first appeared on MacRumors.com Discuss this article in our forums View the full article
  23. Apple is still working on a cheaper, lighter successor to its Vision Pro headset, but it is unlikely to launch before late 2028 or 2029, according to Bloomberg's Mark Gurman. Writing in his latest Power On newsletter, Gurman says that Apple needs to come up with a slimmer design for the $3,499 headset and bring down the cost before it can return to the category, which is essentially "on ice" until then. Gurman made a point of distinguishing the Vision Pro successor from the long-rumored "Vision Air," which was cancelled last year. In the meantime, Apple's smart glasses project is now the focus, and former Vision Products Group members have been reassigned to that team. Apple is now aiming to release its first smart glasses in "late 2027," according to Gurman. Apple refreshed the Vision Pro in October 2025 with an updated model featuring an M5 chip.Related Roundup: Apple Vision ProTag: Mark GurmanBuyer's Guide: Vision Pro (Neutral)Related Forum: Apple Vision Pro This article, "Cheaper, Lighter Apple Vision Pro Successor Could Arrive in Late 2028" first appeared on MacRumors.com Discuss this article in our forums View the full article
  24. Most people get hit by a car and take a few days off. Knocked Loose apparently get hit by a car, post a selfie, rate the recovery beverage and continue opening for Metallica. “felt bad but got this boba after and it was really good.” In what is objectively one of the more hardcore updates to come out of the heavy music world this week, Knocked Loose guitarist Isaac Hale revealed over the weekend that he’d been hit by a car while touring Europe. Thankfully, the update appears to be more chaotic than catastrophic. Posting a photo with his arm wrapped in a support bandage, Hale kept things characteristically understated, writing: “tour update got hit by a car yesterday felt bad but got this boba after and it was really good.” Honestly? Elite caption. The incident came shortly after Knocked Loose played back-to-back shows in Zurich, Switzerland – and remarkably, doesn’t appear to have derailed the band’s absolutely stacked touring schedule. Because yes, they are still out there doing support dates with Metallica. The Louisville wrecking crew are currently deep into a monster run of summer shows that includes massive festival appearances at Primavera Sound, Rock for People and Graspop Metal Meeting, alongside stadium dates supporting literal metal institution Metallica. As if that wasn’t enough, Knocked Loose also recently announced a North American co-headline run with Denzel Curry – a crossover lineup that feels aggressively 2026 in the best possible way. The band have also started pulling back the curtain on life behind the scenes via a new YouTube documentary series, Wherever We May Roam, with the first episode capturing everything from European touring chaos to the moment they found out they’d landed the Metallica support slot. So while getting hit by a moving vehicle probably wasn’t part of the itinerary… somehow this whole update still feels extremely Knocked Loose-coded. Anyway, wishing Isaac a speedy recovery and continued access to quality boba. Further Reading AI Metalcore ‘Band’ Broken Avenue Busted Ripping Off Knocked Loose, Counterparts & More Knocked Loose Respond After TV Viewers Hate On Their Performance On Kimmel Knocked Loose Announce New Album ‘You Won’t Go Before You’re Supposed To’ The post Knocked Loose Are Continuing Their Metallica Tour After Isaac Hale Got Hit By A Car appeared first on Music Feeds. View the full article
  25. After selling out her 2024 return run, GRAMMY-winning soul icon Macy Gray is officially heading back Down Under this September and October… and this time she’s going bigger than ever. Dubbed The Encore Tour, the mammoth run will see Gray return to major cities while also venturing deep into regional Australia for the first time in years, bringing her unmistakable raspy vocals and catalogue of era-defining hits to theatres, clubs and concert halls right across the country. Macy Gray – I’m Too Sexy ft. BBC Concert Orchestra | Radio 2 Piano Room And honestly? Respect to Macy for looking at Australia and saying “yeah nah let’s do Port Macquarie”. This isn’t just a quick capital-city victory lap either. Across more than two decades, over 25 million records sold and a trophy cabinet featuring a GRAMMY, multiple BRIT Awards and ten studio albums, Macy Gray has become one of modern soul and R&B’s most instantly recognisable voices. But Australia has always had a particularly strong history with Macy. Long before the US fully caught on, Australian audiences embraced her breakout album On How Life Is, while I Try became an absolute monster locally – helping cement Gray as one of those artists whose songs somehow became woven into the cultural wallpaper of the early 2000s. And based on her own comments, she definitely remembers. “Australia! The band and I have always had a ball down under and we can’t wait to see you all again!” Gray shared in a statement. “This time, I’m heading to places I’ve never been before and will get to see so much more of your beautiful country.” “We’re going to be performing all the songs you want to hear, plus a few from my new album – The Trouble with the Truth. Australia will be the first audiences to hear tracks from the new album live so get your dancing shoes ready and come along and party with us at a show near you!” Expect the setlist to pull heavily from across her catalogue, including I Try, Still, Do Something, Sexual Revolution, Sweet Baby and selections from the forthcoming album – including her latest single, a rework of I’m Too Sexy. Which means yes: there’s a very real chance someone will hear I Try live and immediately be transported back to 2001. Peep all the dates and details down below, Macy Gray – The Encore Tour (Australia) 2026 Fri 11 Sept — Hamer Hall, Melbourne VIC Sat 12 Sept — Hindley Street Music Hall, Adelaide SA Sun 13 Sept — Shepparton Entertainment Centre, Shepparton VIC Mon 14 Sept — Albury Entertainment Centre, Albury NSW Wed 16 Sept — Anita’s Theatre, Thirroul NSW Fri 18 Sept — Wrest Point, Hobart TAS Sat 19 Sept — The Station, Newcastle NSW Sun 20 Sept — Tacking Point Tavern, Port Macquarie NSW Thu 24 Sept — Coliseum Theatre, Rooty Hill NSW Fri 25 Sept — Enmore Theatre, Sydney NSW Sat 26 Sept — Woodport Hotel, Erina NSW Sun 27 Sept — Tamworth Town Hall, Tamworth NSW Wed 30 Sept — Southern Cross Club, Canberra ACT Fri 2 Oct — Townsville Civic Theatre, Townsville QLD Sat 3 Oct — CPAC, Cairns QLD Wed 7 Oct — Pilbeam Theatre, Rockhampton QLD Thu 8 Oct — Beach Road Hotel, Byron Bay NSW Fri 9 Oct — Concert Hall QPAC, Brisbane QLD Sat 10 Oct — C.ex Club, Coffs Harbour NSW Sun 11 Oct — Shoal Bay Country Club, Shoal Bay NSW Also appearing in Margaret River WA – click here to join the waitlist for this show Venue and ticket outlet database members can secure tickets first during the exclusive pre-sales from 9.00am local times on Monday 1 June. General Public tickets for Macy Gray – The Encore Tour go on sale at 9.00am local times on Wednesday, 3 June 2026 from macygraylive.com.au. Further Reading Hockey Dad Cover A Macy Gray Classic To Kick Off ‘Like A Version’ For 2019 Promoter Apologises After Macy Gray Arrives Late And Says “Hello Sydney” At Perth Gig Macy Gray’s Love Song To Her Vibrator Gets Cute Animated Video The post Macy Gray Is Returning To Australia For Her Biggest Tour Here Yet (And She’s Going Regional) appeared first on Music Feeds. View the full article

Account

Navigation

Search

Search

Configure browser push notifications

Chrome (Android)
  1. Tap the lock icon next to the address bar.
  2. Tap Permissions → Notifications.
  3. Adjust your preference.
Chrome (Desktop)
  1. Click the padlock icon in the address bar.
  2. Select Site settings.
  3. Find Notifications and adjust your preference.