Skip to content
View in the app

A better way to browse. Learn more.

hosang I.T.

A full-screen app on your home screen with push notifications, badges and more.

To install this app on iOS and iPadOS
  1. Tap the Share icon in Safari
  2. Scroll the menu and tap Add to Home Screen.
  3. Tap Add in the top-right corner.
To install this app on Android
  1. Tap the 3-dot menu (⋮) in the top-right corner of the browser.
  2. Tap Add to Home screen or Install app.
  3. Confirm by tapping Install.

Tech

Tech Articles from a wide variety of topics and categories
AI agents are already running inside production environments. They call APIs, interact with internal systems, retrieve sensitive data, and make decisions with limited human oversight.
For DevOps teams, this creates a problem, as traditional application security tooling was never really designed to handle it.
Most DevSecOps pipelines are built around deterministic software. You scan code before deployment, validate dependencies, harden containers, and block known vulnerabilities before workloads reach production. That model still matters, but autonomous agents behave differently from conventional applications.
An AI agent can change its behavior based on context, prompts, external data, or chained actions across multiple systems. In practice, that means the biggest security risks often appear after deployment rather than during build time.
This is one reason runtime enforcement is becoming a bigger focus for teams deploying AI systems in production.
Where Shift-Left Starts to Break Down
Shift-left security remains extremely valuable. Catching problems earlier in the pipeline is still cheaper and operationally easier than fixing them after deployment.
The problem is that AI agents introduce behavior that static analysis tools cannot fully predict.
A container scanner can identify vulnerable packages. A secrets scanner can detect exposed credentials. But neither tool can reliably determine whether an AI agent will make an unsafe decision at runtime after interacting with external systems.
That distinction matters.
An agent connected to payment infrastructure, customer records, or internal APIs may technically pass every pre-production security check while still behaving unsafely once deployed.
This is where runtime enforcement starts becoming more important than repository analysis alone.
Teams building AI cybersecurity solutions have increasingly shifted toward monitoring what agents actually do in production environments rather than focusing solely on the code and models behind them.
For DevOps engineers, the practical takeaway is fairly simple: the security boundary no longer ends at deployment.
A Threat Surface That Looks Nothing Like the Old One
OWASP’s Top 10 for Agentic Applications in 2026 outlines several risks that do not map cleanly to traditional web application security models.
Goal manipulation is one example.
An attacker may inject malicious instructions into documents, prompts, emails, or external content sources that influence how an agent behaves. The agent itself may interpret those instructions as a legitimate operational context rather than hostile input.
That creates a very different problem from something like SQL injection or cross-site scripting.
Tool access creates another issue.
Many AI agents operate with broad API permissions because granular scoping slows deployment and requires additional engineering work. In practice, teams often over-grant permissions to agents early in development simply to keep workflows moving.
Once deployed, those permissions can become difficult to monitor properly.
There is also the problem of behavioral drift. Agents may begin operating outside expected patterns without technically violating any predefined rule. An internal support agent who suddenly accesses unrelated systems or queries sensitive records may still appear “authorized” from a traditional IAM perspective.
Detecting that kind of activity requires behavioral monitoring rather than static policy validation alone.
Runtime Security Becomes an Operational Layer
Traditional application security focuses heavily on artifacts:
source code dependencies images infrastructure definitions Runtime security for AI agents shifts the focus toward actions and decision-making.
That requires a different operational mindset.
Runtime guardrails are becoming increasingly important controls in agentic environments. Instead of trusting the agent entirely, teams define infrastructure-level boundaries around what systems the agent can access and which actions are allowed under specific conditions.
If an agent attempts to access resources outside its expected scope, the infrastructure layer blocks the action regardless of the agent’s reasoning process.
Behavioral baselining matters as well.
A customer support agent querying the billing infrastructure at 3 a.m. may not technically violate permissions, but it still constitutes abnormal operational behavior. This is where runtime telemetry starts to look more like EDR or anomaly detection workflows than traditional application security scanning.
Policy-as-code is also becoming increasingly relevant for teams deploying AI infrastructure through CI/CD pipelines. Defining runtime restrictions, access boundaries, and operational constraints in code allows teams to embed security throughout their DevOps lifecycle rather than treating runtime governance as a separate operational layer.
What DevOps Teams Should Start Doing
The most effective starting point is usually limiting what each agent can actually access.
Many early AI deployments rely on broad service permissions because they simplify integration work. Over time, those environments become difficult to audit because agents interact with dozens of systems simultaneously without clear operational boundaries.
Treating agents more like service accounts helps significantly:
separate identities tightly scoped permissions isolated API access centralized logging Logging quality becomes especially important once agents begin making decisions autonomously. If an incident occurs, teams need visibility into:
prompts tool usage external calls execution chains policy violations Without that telemetry, investigating agent behavior becomes extremely difficult.
Kill-switch mechanisms are also becoming more common in operational practice. Teams increasingly build orchestration-level controls that automatically terminate agents if runtime behavior deviates significantly from expected patterns.
That is particularly important in environments where agents interact directly with production systems or customer data.
The DevSecOps Stack Is Expanding Again
None of this replaces existing DevSecOps practices.
Container hardening, dependency analysis, IaC scanning, secrets management, and CI/CD security still matter exactly as much as before.
What changed is the scope of the runtime environment itself.
Autonomous agents are systems capable of making dynamic decisions after deployment. Traditional security tooling was not designed around that operational model, which is why runtime governance and behavioral enforcement are becoming increasingly important.
For DevOps teams, this is less about rebuilding the security pipeline from scratch and more about extending it into environments where software no longer behaves entirely predictably.
That extension is quickly becoming one of the more important shifts happening inside modern DevSecOps programs.
View the full article
Cybersecurity researchers have flagged a compromised version of the Nx Console extension that was published to the Microsoft Visual Studio Code (VS Code) Marketplace. The extension in question is rwl.angular-console (version 18.95.0), a popular user interface and plugin for code editors like VS Code, Cursor, and JetBrains. The VS Code extension has more than 2.2 million installations. The OpenView the full article
In yet another software supply chain attack, threat actors have compromised the popular GitHub Actions workflow, actions-cool/issues-helper, to run malicious code that harvests sensitive credentials and exfiltrates them to an attacker-controlled server. "Every existing tag in the repository has been moved to point to an imposter commit that does not appear in the action's normal commit history,View the full article
Cybersecurity researchers have discovered a fresh software supply chain attack campaign that has compromised various npm packages associated with the @antv ecosystem as part of the ongoing Mini Shai-Hulud attack wave. "The attack affects packages tied to the npm maintainer account atool, including echarts-for-react, a widely used React wrapper for Apache ECharts with roughly 1.1 million weeklyView the full article
Schwachstellen zu managen, muss keine Schwerstarbeit sein. Wenn Sie die richtigen Tools einsetzen. Das sind die besten in Sachen Vulnerability Management.
Foto: eamesBot – shutterstock.com
Nicht nur das Vulnerability Management hat sich im Laufe der Jahre erheblich verändert, sondern auch die Systeme, auf denen Schwachstellen identifiziert und gepatcht werden müssen. Systeme für das Schwachstellen-Management fokussieren heutzutage nicht mehr nur auf Netzwerke und private gehostete Applikationen. Sie müssen in der Lage sein, Schwachstellen sowohl On-Premises, als auch auf IoT-Devices sowie in Public- und Private-Cloud-Instanzen zu identifizieren. Zudem sollten sie die Security-Teams der Unternehmen dabei unterstützen, die bestmöglichen Entscheidungen zu treffen, um die Lecks zu beheben.
Eine Schwachstelle im System, die nicht ausgenutzt werden kann, stellt keine große Gefahr dar. Umso wichtiger ist es, zu wissen, was wirklich gefährlich ist. Nur so lassen sich Sicherheitslücken evaluieren und kategorisieren. Dabei spielen auch die potenziellen Auswirkungen eine große Rolle: Es ist zwar peinlich, wenn eine Unternehmenswebseite verunstaltet wird, der Diebstahl vertraulicher Informationen kann jedoch geschäftskritisch sein und darüber hinaus zu hohen Geldbußen führen.
Gute Vulnerability-Management-Programme zeichnen sich dadurch aus, dass sie ihren Schwachstellen-Scans einen Kontext hinzufügen. Bei potenziell Tausenden von Schwachstellen, die sich in jedem größeren Unternehmensnetzwerk verbergen, ist das die einzige Möglichkeit, zuverlässig zu priorisieren und damit Risiken zu minimieren.
Vulnerability Management Tools: Top 6
Die folgenden sechs Produkte setzen in mindestens einem Aspekt des Schwachstellenmanagements neue Maßstäbe.
Qualys VMDR
Qualys war im Jahr 1999 die erste SaaS-Plattform für Schwachstellen-Management. Qualys Vulnerability Management Detection and Response (VMDR) steht als Cloud-Service zur Verfügung. Mit Voice Agents, virtuellen Scannern und passiven Netzwerk-Scanning-Funktionen unterstützt die Lösung Unternehmen dabei, ihre Assets zu identifizieren – On-Premises, in der Cloud und auf den Endpoints. Die Dashboards sind individuell anpassbar.
Die gesammelten Schwachstellen-Daten können die Anwender auf Asset-Basis untersuchen, um tiefere Einblicke in Konfiguration, laufenden Dienste, Netzwerkinformationen und andere Daten zu bekommen. Mit einer “AssetView”-Funktion können Sicherheits- und Compliance-Teams ihre Informationsressourcen auf der Grundlage der für ihr Unternehmen wichtigen Daten kontinuierlich aktualisieren. Nachdem Qualys VMDR Assets und Schwachstellen identifiziert sowie nach Risikolevel priorisiert hat, können die Anwender Patches innerhalb der Plattform bereitstellen.
Orca Security
Das Cloud Security Posture Management (CSPM)-Tool Orca Security verwaltet Schwachstellen in Cloud-Infrastrukturdiensten wie Amazon Web Services (AWS), Microsoft Azure und Google Cloud. Da Orca für die Cloud entwickelt wurde, lässt es sich problemlos in diesen Umgebungen einsetzen.
Die Side-Scanning-Technologie von Orca ermöglicht es Benutzern, ihre Cloud-Umgebung zu inventarisieren und sammelt zum Beispiel Daten über Betriebssystempakete, Anwendungen oder Bibliotheken. Zu jeder aufgedeckten Schwachstelle erstellt das System eine eigene Map, die die Beziehung zu anderen Assets darstellt. Das hilft bei der Priorisierung.
Um den Schweregrad der Schwachstellen in den Cloud-Systemen eines Unternehmens grafisch darzustellen, analysiert die Lösung Cloud-Systeme und -Workloads sowie deren Konfigurationen und Sicherheitseinstellungen. Darüber hinaus regelt Orca die Konnektivität und kann erkennen, welche Netzwerke öffentlich zugänglich sind und welche nicht. Mit all diesen Daten erstellt das Vulnerability Management Tool eine Visualisierung, die versucht, das tatsächliche Risiko einer Schwachstelle im Kontext des Cloud-Systems zu bewerten. Die zugehörige Schwachstellen-Datenbank enthält Daten aus mehr als 20 verschiedenen Quellen.
Detectify
Das Angebot von Detectify fällt in die Kategorie Attack Surface Management (ASM). ASM konzentriert sich auf Schwachstellen aus der Sicht eines Angreifers. Es setzt sich aus der kontinuierlichen Erkennung von Enterprise IT-Assets, internetfähigen Systemen wie Cloud-Infrastruktur, Drittanbietersystemen und Webanwendungen zusammen. Dabei identifiziert es Schwachstellen in diesen Systemen und unterstützt dabei, diese zu priorisieren und zu managen.
Da Detectify auf Cloud-Basis operiert, ist keine Installation erforderlich. Sie müssen lediglich die zu überprüfende Domain hinzufügen, schon werden alle zugehörigen Subdomains und Anwendungen kontinuierlich überprüft. Die Lösung unterteilt ihre Scanning-Aktivitäten dabei in zwei Bereiche – Surface und Application Monitoring. Erstere Kategorie prüft die Internet-Assets einer Organisation und evaluiert die gefundenen Hosts auf Schwachstellen, Fehlkonfigurationen und ähnliches. Beim Application Scanning findet hingegen eine kontinuierliche Evaluierung der Web-Applikationen beziehungsweise dort vorhandener Schwachstellen statt. Detectify bewertet Anwendungen in der Produktion, der Entwicklungspipeline und im Application Staging.
Ein interessanter Aspekt von Detectify ist die Kombination aus Automatisierung und Crowdsourcing: Das Unternehmen arbeitet mit Ethical Hackern zusammen und lässt deren Erkenntnisse einfließen. Das stellt sicher, dass die Unternehmenssysteme automatisiert auf vorhandene Schwachstellen überprüft werden, während erfahrene Sicherheitsforscher nach bislang unentdeckten Schwachstellen suchen.
Kenna Security Vulnerability Management
Jeder, der schon einmal mit Vulnerability Management Tools gearbeitet hat, weiß, dass verschiedene Lösungen oft unterschiedliche Schwachstellen erkennen. Einige performen bei spezifischen Aufgaben zudem etwas besser als andere, etwa wenn es um die Bewertung von lokalen Netzwerken oder Cloud-Anwendungen geht.
An dieser Stelle kommt Kenna Security Vulnerability Management ins Spiel: Diese Lösung führt selbst keine Scans durch sondern stellt sogenannte Connector-Programme zur Verfügung. Diese nehmen Daten von nahezu allen Schwachstellen-Scannern auf, einschließlich derer von Tripwire, Qualys, McAfee und CheckMarx. Die Plattform selbst wird als Service bereitgestellt, Anwender melden sich bei einem Cloud-Portal an, um ihre Informationen zu überprüfen.
Die Idee dahinter: Die Lösung von Kenna sammelt Vulnerability Alerts und gleicht diese dann in Echtzeit mit Bedrohungsdaten ab. Eine entdeckte Schwachstelle kann dabei einer aktiven Bedrohungskampagne zugeordnet und entsprechend priorisiert behoben werden. Alle weltweit ausgenutzten Schwachstellen erhalten automatisch eine höhere Priorität. So können die Verteidiger die gefährlichsten Probleme lösen, bevor Angreifer sie entdecken und ausnutzen. Die Kenna-Plattform war eine der ersten, die Echtzeit-Bedrohungsdaten in das Schwachstellenmanagement einbezog. Seitdem wurde sie um zusätzliche Bedrohungsdaten erweitert.
Die Plattform erklärt dabei, warum Schwachstellen in einem geschützten Netzwerk vorhanden sind und gibt Tipps, um diese zu beheben. Sie kann entdeckte Schwachstellen außerdem priorisieren, je nachdem, welche Assets betroffen sind und wie schwerwiegend das Problem ist. Risikobasierte Service Level Agreements (SLAs) gehören ebenfalls zur Plattform und schaffen einen Zeitrahmen um Probleme zu beheben, der auf der Risikotoleranz eines Unternehmens basiert. Je weniger Risiko ein Unternehmen stemmen kann, desto schneller muss es die Schwachstelle beheben. Die risikobasierten SLAs von Kenna basieren dabei auf drei Faktoren:
Risikotoleranz,
Asset-Priorität und
der Risikobewertung der Schwachstelle.
Seit 2021 ist Kenna Security Teil von Cisco.
Flexera Software Vulnerability Management
Viele Vulnerability Management Tools konzentrieren sich auf intern entwickelte Anwendungen und Code. Dagegen nimmt die Software-Vulnerability-Management-Plattform von Flexera Softwareprogramme von Drittanbietern in den Fokus, die fast jedes Unternehmen nutzt.
In den meisten Fällen wird eine Schwachstelle in gekaufter oder lizenzierter Software durch ein Patch behoben. Das kann für Unternehmen zu einem Problem werden, wenn Tausende von Systemen oder kritischen Diensten dafür offline genommen werden müssen. Dabei besteht zudem die Möglichkeit, dass durch die Behebung eines Problems weitere, neue entstehen.
Die Flexera-Software will dieses Problem bekämpfen, indem sie einen sicheren Patch-Management-Prozess für das gesamte Unternehmen realisiert. Die Lösung kann Schwachstellen in Software von Drittanbietern aufspüren und Administratoren über den Schweregrad der potenziellen Bedrohung informieren. Einen umfassenden Patch für Tausende von Anwendern herauszugeben, um eine geringfügige Schwachstelle zu beheben oder eine Funktion zu patchen, die vom Unternehmen unter Umständen weder installiert noch genutzt wird, macht wenig Sinn. Flexera kann an dieser Stelle unterstützen, indem es den Kontext mitliefert und Patches zu dem Zeitpunkt bereitstellt, wenn sie notwendig werden.
Mit der Flexera-Plattform lässt sich auch ein automatisiertes Patch-Management-System etablieren. Darüber hinaus können benutzerdefinierte Reportings erzeugt werden. Das gilt nicht nur für das Schwachstellen- und Patch-Management, sondern auch wenn es um Compliance (Frameworks, Gesetze, Best Practices) geht.
Tenable.io
Tenable ist bekannt für seine Security Dashboards. Mit Tenable.io bietet das Unternehmen dieselbe Diagnose-Technologie auch in Kombination mit Vulnerability Management an. Die Plattform wird in der Cloud gemanagt und nutzt eine Kombination aus aktiven Scan-Agenten, passiver Überwachung und Cloud-Konnektoren, um nach Schwachstellen zu suchen. Um zu ermitteln, welche Korrekturen nötig sind, damit Angreifer keinen Erfolg haben, nutzt die Tenable-Lösung maschinelles Lernen, Data Science und KI.
Eine der größten Stärken von Tenable.io: Schwachstellen werden für jedermann verständlich dargestellt – ganz ohne spezielle Schulungen oder Fach-Knowhow. Um seine Attack-Surface-Management-Fähigkeiten zu stärken, hat Tenable den ASM-Anbieter Bit Discovery übernommen. So erhalten die Kunden einen umfassenden Überblick über ihre internen und externen Angriffsflächen. (fm)
Dieser Artikel ist im Original bei unserer Schwesterpublikation CSOonline.com erschienen.
View the full article
PeopleImages.com – Yuri A | shutterstock.com
Protokoll-Daten zu auditieren, zu überprüfen und zu managen, ist alles andere als eine glamouröse Aufgabe – aber ein entscheidender Aspekt, um ein sicheres Unternehmensnetzwerk aufzubauen. Schließlich schaffen Event Logs oft eine sekundäre Angriffsfläche für Cyberkriminelle, die damit ihre Aktivitäten verschleiern wollen.
Vorgängen wie diesen treten Netzwerksicherheitsexperten mit Tools aus dem Bereich Security Information and Event Management (SIEM) entgegen: Diese Werkzeuge bieten im Regelfall einen zusätzlichen Schutzschirm für Logs, indem sie sie auf einen Server oder Service auslagern und so verhindern, dass sie manipuliert oder gelöscht werden.
In diesem Ratgeber lesen Sie:
welche Kriterien bei SIEM-Tools wichtig sind, was bei diesen Lösungen mit Blick auf die Kosten zu beachten ist, und welche SIEM-Anbieter und -Lösungen führend sind. Das richtige SIEM-Tool auswählen
Eine passende SIEM-Lösung auszuwählen, ist essenziell, um geschäftskritische Systeme und Dienste zu überwachen. Aber auch, um:
Daten für Authentifizierungszwecke bereitzustellen, die Threat Detection zu unterstützen, und SOAR-Plattformen Kontext zu liefern. Die folgenden Bereiche, beziehungsweise Kriterien, sollten Sie mit Blick auf SIEM-Angebote unbedingt vor einem Kauf durchdenken.
Betriebsmodell
Um Funktionen schneller zu iterieren und hinzuzufügen, steht das Gros moderner SIEM-Lösungen inzwischen in einem Software-as-a-Service (SaaS)-Modell zur Verfügung. Die unendliche Kapazität der Cloud erleichtert es den Anbietern dabei auch, Machine-Learning (ML)-Funktionen zu integrieren, die Referenzdaten in rauen Mengen benötigen, um Anomalien erkennen zu können. Es besteht grundsätzlich Einigkeit darüber, dass der SaaS-Ansatz dazu beigetragen hat, SIEM-Lösungen voranzubringen.
Dennoch sind einige Unternehmen darauf angewiesen, SIEM-Tools On-Premises zu betreiben. In der Regel, weil sie Compliance-Vorschriften einhalten und in diesem Zuge Protokolle (und die damit zusammenhängenden Daten) in ihrer lokalen Infrastruktur vorhalten müssen. Deshalb gibt es immer noch einige SIEM-Optionen für den Einsatz vor Ort – darunter auch solide Open-Source-Lösungen.
Analytics
Eine SIEM-Lösung ist nur so gut wie die Informationen, die sie liefert: Log- und Event-Daten aus der Infrastruktur zu sammeln, ist nutzlos, wenn es nicht dazu beiträgt, Probleme zu erkennen und informierte(re) Entscheidungen zu treffen. Deswegen setzen moderne SIEM-Systeme auf Machine Learning, um Anomalien in Echtzeit zu erkennen und ein präzises Frühwarnsystem für potenzielle Angriffe sowie Anwendungs- und Netzwerkfehler zu etablieren.
Wie Ihre spezifischen Anforderungen an die Analysefähigkeiten einer SIEM-Lösung aussehen, hängt von mehreren Faktoren ab:
Welche Systeme sollen überwacht werden? Welche Skills stehen in der Organisation mit Blick auf Dashboards, Reportings und Untersuchungen zur Verfügung? Haben Sie bereits in eine Analytics-Plattform investiert und möchten diese integrieren? Die Antworten auf diese Fragen können Sie dabei unterstützen, SIEM-Optionen einzugrenzen. Sollten Sie weder auf entsprechende Skills, noch Lösungen zurückgreifen können, empfiehlt sich möglicherweise eine SIEM-Lösung mit einer umfangreichen Dashboard-Bibliothek – beziehungsweise ein Managed Service.  
Protokolle
Wie ein SIEM-System Daten verarbeitet, ist ein weiterer, wichtiger Aspekt mit Praxisbezug. Häufig extrahieren Software-Agenten Protokoll- und Ereignisdaten von Servern und Workstations, während Netzwerkhardware und Cloud-Anwendungen sie über eine Integration oder eine API direkt an das SIEM „übergeben“ können. Eine grundlegende Frage ist in diesem Zusammenhang, ob das SIEM auch wichtige, externe Event-Informationen akkurat identifizieren kann.
Im Idealfall sollte das SIEM ausgereift genug sein, um Event-Daten aus den gängigsten Systemen zu parsen und dabei so genau sein, dass keine Anpassungen erforderlich sind und wichtige Details wie Event-Levels oder betroffene Systeme herausgefiltert werden. Um zu vermeiden, dass Log-Einträge nicht korrekt geparst werden, empfiehlt sich zudem eine Lösung, die flexible Möglichkeiten bietet, Event-Daten zu verarbeiten, nachdem sie erfasst wurden.
Warnmeldungen
Ein wesentlicher Vorteil moderner SIEM-Lösungen ist die Möglichkeit, Systeme in Echtzeit zu überwachen. Allerdings ist das Feature überflüssig, wenn das SIEM selbst, beziehungsweise seine Alerts, nicht von einem menschlichen Experten ausgewertet werden. Mit Blick auf die Warnmeldungen und Benachrichtigungen besteht die Herausforderung vor allem darin, beim Volumen der Alerts Maß zu halten:
Zu viele Warnmeldungen werden von den Benutzern entweder deaktiviert oder ignoriert. Zu wenige Alerts bergen die Gefahr, dass kritische Bedrohungen unter den Tisch fallen. Auch mit Blick auf dieses Kriterium empfehlen sich flexible SIEM-Lösungen, die es ermöglichen, Alerts zu konfigurieren – zum Beispiel über Regeln, Schwellenwerte oder verschiedene Warnmethoden (SMS, E-Mail, Push-Nachrichten und Webhooks).
Rollenbasierter Zugriff
Rollenbasierte Zugriffskontrollen sind für große, weltweit tätige Unternehmen mit unterschiedlichen Business-Segmenten und Applikationsteams unerlässlich. Dabei ist es nicht bloß ein Komfort-Feature, Admins, Entwickler und Datenanalysten nur Zugriff auf die Event-Logs zu gewähren, die sie benötigen. Vielmehr entspricht das dem Least-Privilege-Prinzip, das in einigen Branchen auch regulatorisch durchgesetzt wird.
Den Zugriff der Benutzer auf SIEM-Event-Daten beschränken zu können, begrenzt zudem den Impact kompromittierter Konten und trägt letztlich zum Schutz des gesamten Netzwerks bei. Schließlich bieten Event-Daten oft tiefe und detailreiche Einblicke in Applikations- und Service-Funktionalitäten – oder gar die Netzwerkkonfigurationen von Devices. Diese Informationen könnten Cyberkriminelle nutzen, um Systeme auszuspähen und zu infiltrieren.
Compliance
Diverse, regulatorische Rahmenwerke – beispielsweise die DSGVO oder HIPAA – setzen nicht nur voraus, dass SIEM- oder ähnliche Systeme eingesetzt werden, sondern schreiben teilweise auch vor, wie die Lösung konfiguriert sein sollte. Sie sollten sich deshalb mit den für Ihre Organisation relevanten Anforderungen im Detail vertraut machen. Dabei können unter anderem relevant sein:
Aufbewahrungsfristen, Verschlüsselungsanforderungen, digitale Signaturen und Berichtspflichten. Dabei sollten auch mögliche Audit-Elemente nicht unberücksichtigt bleiben: Die SIEM-Lösung Ihrer Wahl sollte die erforderlichen Dokumentationen und Reportings ausgeben können, die die Auditoren zufriedenstellen.  
Event-Korrelation
Die Möglichkeit, Protokolle aus unterschiedlichen (und/oder integrierten) Systemen in einer einzigen Ansicht zu korrelieren, ist ebenfalls ein guter Grund dafür, ein SIEM-System zu implementieren. Dieses sollte in der Lage sein, Log-Events von jeder Anwendungskomponente (Datenbank, Applikationsserver) zu verarbeiten (selbst wenn sie auf mehrere Hosts verteilt sind), und diese in einem Data Stream zu korrelieren. Das macht nachvollziehbar, wie die Events der Komponenten miteinander zusammenhängen.
In vielen Fällen können korrelierte Ereignisprotokolle eingesetzt werden, um (Privilege-Escalation-)Angriffe zu erkennen und ihren Impact über die verschiedenen Netzwerksegmente hinweg zu tracken. Das wird auch deswegen immer wichtiger, weil Unternehmen zunehmend auf die Cloud oder Container-basierte Infrastrukturen setzen.  
Ökosysteme
Ein SIEM mit einem robusten, ausgereiften Ökosystem ermöglicht es, verschiedene Funktionen zu verbessern, beziehungsweise zu erweitern. Wenn das SIEM direkt (oder über Plugins) in andere Systeme integriert werden kann, erleichtert das die Arbeit erheblich. Neben den Systemverbesserungen, die durch ein SIEM-Ökosystem erzielt werden können, gibt es noch weitere Business Benefits. So kann eine moderne, ausgereifte SIEM-Lösung:  
die Nachfrage nach Schulungen steigern, Support auf Community-Basis fördern, und den Einstellungsprozess vereinheitlichen. API-Interaktion
Ein Ökosystem wird nicht allen Anforderungen gerecht: Falls Ihr Unternehmen Software entwickelt oder in DevOps-Initiativen investiert hat, kann die Möglichkeit, programmgesteuert mit einer SIEM-Lösung zu interagieren, einen wesentlichen Unterschied machen.
Statt wertvolle Entwicklungszeit in Logging-Funktion zu stecken, kann das SIEM-System Ereignisdaten aus benutzerdefiniertem Code aufnehmen, korrelieren und analysieren.
Künstliche Intelligenz (KI)
SIEM scheint ein maßgeschneiderter Anwendungsfall für KI-gestützte Analysen – entsprechend scheuen sich die Anbieter nicht, entsprechende Funktionen in ihre Lösungen zu implementieren. Die fokussieren sich im Allgemeinen auf die Bereiche Analytics und Alerts. KI-fähige SIEM-Systeme können mit Cloud-Daten-Feeds einer Vielzahl von Anbietern und Quellen integriert werden. Das ermöglicht, Event-Daten automatisiert mit Kontext auszustatten und dafür zu nutzen, um:
Ereignisse zu bewerten, Angriffsketten zu identifizieren und Incident-Response-Pläne zu erstellen. Mit Blick auf KI-fähige SIEM-Lösungen kann auch das Thema Betriebsmodell eine Rolle spielen: Einige On-Premises-Angebote erfordern unter Umständen, KI-Workloads an Cloud-Services auszulagern.
SIEM-Kosten
Wenn es um Security Information and Event Management geht, sollten Sie den Gürtel nicht unbedingt enger schnallen – schließlich möchte wohl niemand im Angriffsfall am falschen Ende gespart haben. Natürlich sind die Kosten auch im Fall von SIEM-Lösungen ein Faktor – bei der Berechnung gilt es allerdings auf Feinheiten zu achten. SIEM-Lösungen, die in Form eines Cloud-Service angeboten werden, stehen fast immer in einem Abo-Modell zur Verfügung. Dabei können jedoch auch Nutzungsgebühren anfallen – beispielsweise für:
das Volumen der Event-Daten oder die Anzahl der überwachten Endpunkte. Achten Sie bei Plattformen, die mit einer Open-Source-Lizenz angeboten werden, zudem auf versteckte Kosten (beispielsweise für Support) und stellen Sie sicher, dass die gewählte Lösung sämtliche relevanten, geschäftlichen Anforderungen erfüllt.
Wenn Sie Ihr persönliches SIEM-Kandidatenfeld auf diejenigen eingegrenzt haben, die die benötigten Funktionen bieten, vergleichen Sie die voraussichtlich anfallenden Abonnement- und Nutzungsgebühren im Detail.
SIEM-Anbieter & -Lösungen
Der Markt für SIEM-Lösungen ist reich an Optionen. Um Ihnen den Einstieg in die Tool-Recherche zu erleichtern, haben wir einige, wichtige SIEM-Anbieter, respektive -Produkte, für Sie zusammengestellt:
Datadog Cloud-SIEM ist eine ausgereifte SIEM-Suite, die sämtliche wichtigen Bereiche umfasst und mehr als 800 Integrationen sowie über 350 vorgefertigte Detection-Regeln bietet. Elastic Logstash ist keine echte SIEM-Plattform – das Open-Source-Tool (in erster Linie für die DevOps-Welt konzipiert) ermöglicht es aber, Log-Events aus einer Vielzahl von Quellen zu analysieren und zu verarbeiten. Exabeam LogRhythm SIEM ist einem Zusammenschluss der Sicherheitsanbieter Exabeam und LogRythm entsprungen und zeichnet sich in erster Linie durch ein umfassendes Ökosystem und vorgefertigte Compliance-Frameworks aus. Fortinet FortiSIEM ermöglicht Asset-Erkennung und rollenbasierten Zugriff, sowie User and Entity Behavior Analytics (UEBA) – und kann sowohl integriert werden, um Events zu erfassen, als auch, um automatisiert auf diese zu reagieren. Huntress Managed SIEM ist ein solides, modernes Managed SIEM von einem aufstrebenden Anbieter, dessen Analysten und Security Engineers interne Teams entlasten können. IBM QRadar SIEM ist in der Lage, Datenmengen und Funktionen im Enterprise-Format zu bewältigen, verfügt über eine integrierte Analytics-Engine, KI-Funktionen und bietet Support für mehr als 500 Integrationen. Guardsix SecOps (ehemals LogPoint) setzt UEBA für Threat Modeling und Machine Learning ein, unterstützt automatisierte Übersetzungen sowie wichtige Compliance-Standards und korreliert Ereignisse auch mit dem MITRE ATT&CK-Framework.   Microsoft Sentinel ist in der Lage, Ereignisse sowohl von lokalen, als auch von Cloud- Ressourcen einzuspeisen, zu korrelieren und zu analysieren – dabei hilft inzwischen auch die KI in Form von Microsofts Security Copilot. OpenText Enterprise Security Manager kann alle Anforderungen an ein Enterprise-SIEM erfüllen, bietet zahlreiche Integrationen mit Drittanbieter-Systemen und umfassenden Support für Automatisierung. NetWitness bietet ebenfalls diverse Enterprise-SIEM-Funktionen, zeichnet sich aber vor allem durch seine integrierten Encryption-Tools aus, die Support für verschlüsselte Event-Daten (oder Netz-Traffic) bieten. SentinelOne Singularity AI SIEM setzt auf State-of-the-Art-Techniken, um Daten zu erfassen und zu filtern, liefert robuste Analysen und verspricht intuitive Automatisierungen. SolarWinds Security Event Manager bietet zwar weder ML-basierte Datenanalysen, noch kann es in Sachen Integrationen mit den anderen hier aufgeführten Optionen mithalten – dafür bietet es USB Device Monitoring und beeindruckende Compliance-Reporting-Fähigkeiten. Splunk bietet seine SIEM-Plattform, die sich insbesondere durch ihr Ökosystem (beziehungsweise ihren App Store) auszeichnet, in zwei Versionen an: Splunk Enterprise für den On-Premises-Einsatz und Splunk Cloud als SaaS-Modell. Trellix Enterprise Security Manager stellt Benutzern umsetzbare Warnmeldungen zur Verfügung und legt den Fokus auf Flexibilität, wenn es um Architektur und Integrationen geht. Dieser Artikel ist im Original bei unserer Schwesterpublikation CSOonline.com erschienen.
View the full article
Sie fühlen sich leer ohne Security-Dashboard? Diese Dokumentationen überbrücken den Schmerz bis zum nächsten Arbeitstag.
Foto: Gorodenkoff – shutterstock.com
Wenn Sie in Ihrer Profession als Sicherheitsentscheider voll aufgehen, brauchen Sie möglicherweise auch zwischen den Arbeitstagen ihre tägliche Dosis Cybersecurity. Falls Ihnen die zahlreichen Annäherungen Hollywoods an das Thema viel zu weit von der Realität entfernt sind, können Sie auf ein Füllhorn hochwertiger Dokumentationen zurückgreifen. Die sind nicht nur informativ, (meist) sehr nah an der Realität und unterhaltsam, sondern teilweise auch historisch wertvoll und in einigen Fällen kostenlos in voller Länge verfügbar.
Doku-Highlights für Sicherheitsentscheider
Nachfolgend haben wir diverse sehenswerte Dokumentationen in Zusammenhang mit Cybersecurity und Hacker-Kultur für Sie zusammengestellt. Viel Spaß!
Hackers – Wizards of the Electronic Age (1985)
Kurz und knapp:
frühe Doku über die Hacker Community
unter anderem mit Steve Wozniak
kostenlos in voller Länge verfügbar
Hackers in Wonderland (2000)
Kurz und knapp:
porträtiert UK- und US-Hacker
beleuchtet Hacktivismus
kostenlos in voller Länge verfügbar
Secret History of Hacking (2001)
Kurz und knapp:
fokussiert frühe Hacking-Techniken
mit John Draper, Steve Wozniak und Kevin Mitnick
kostenlos in voller Länge verfügbar
Hackers Are People Too (2008)
Kurz und knapp:
von Hackern kreiert
will mit Stereotypen aufräumen
beleuchtet auch die Rolle der Frauen in der Community
We Are Legion: The Story of the Hacktivists (2012)
Kurz und knapp:
beleuchtet das Hacker-Kollektiv Anonymous
zahlreiche O-Töne von Mitgliedern und Experten
auf diversen Filmfestivals ausgezeichnet
DEFCON: The Documentary (2013)
Kurz und knapp:
stellt das 20-jährige Jubiläum der Hacking-Konferenz DEFCON in den Fokus
bis zu dieser Doku herrschte auf der Konferenz striktes Kameraverbot
O-Töne von Teilnehmern und Verantwortlichen
Citizenfour (2014)
Kurz und knapp:
thematisiert Edward Snowden und den NSA-Skandal
enthält Interviews mit Snowden aus dem Jahr 2013
entstand unter Beteiligung von Glenn Greenwald
Digital Amnesia (2014)
Kurz und knapp:
wirft ein Schlaglicht auf digitale Daten und den Umgang mit diesen
mit Beteiligung von Experten des Internet Archive
kostenlos in voller Länge verfügbar
Deep Web (2015)
Kurz und knapp:
thematisiert den Darknet-Marktplatz Silk Road
beleuchtet dabei auch die Verhaftung und den Prozess von Gründer Ross Ulbricht
O-Töne von zahlreichen Beteiligten
A Good American (2015)
Kurz und knapp:
erzählt die Geschichte des Ex-NSA-Direktors Bill Binney
klärt auf, wie ein Computerprogramm 9/11 hätte verhindern können
Regie führte der Österreicher Friedrich Moser
War for the Web (2015)
Kurz und knapp:
wirft einen Blick auf die physische Infrastruktur hinter dem Internet
zeigt, wie Unternehmen und Regierungen hinter den Kulissen um die Vorherrschaft kämpfen
beleuchtet dabei auch Fragen wie Data Ownership, Datenschutz und Security
Cyber War (2016)
Kurz und knapp:
zeigt, wie Regierungen im Kampf gegen kriminelle Hacker aufrüsten
dabei kommen auch unlautere Mittel wie Spionage zur Sprache
viele prominente O-Töne
Down the Deep Dark Web (2016)
Kurz und knapp:
bietet Insider-Einblicke in das Darknet
beleuchtet dabei auch legitime Einsatzzwecke
will mit Vorurteilen und Stereotypen aufräumen
Zero Days (2016)
Kurz und knapp:
erzählt die Geschichte des Stuxnet-Virus
analysiert ausgiebig die Folgen des Angriffs
bietet zahlreiche Insider-Einblicke und O-Töne
Facebook: Cracking the Code (2017)
Kurz und knapp:
beleuchtet die Security-Kultur und -Probleme bei Facebook
geht dabei auch auf die Nutzung von User-Daten, Ad-Gebahren und Fake News ein
zahlreiche O-Töne von Experten
Kim Dotcom: Caught in the Web (2017)
Kurz und knapp:
erzählt die Geschichte von Megaupload-Gründer Kim Schmitz
beleuchtet dabei seinen Kampf gegen die US-Regierung und die Entertainment-Branche
zahlreiche O-Töne von Beteiligten – auch Kim selbst
The Defenders (2018)
Kurz und knapp:
analysiert vier schlagzeilenträchtige Cyberattacken
nimmt dabei die Perspektive der Verteidiger ein
produziert vom Sicherheitsanbieter Cybereason
The Great Hack (2019)
Kurz und knapp:
thematisiert den Skandal um Facebook und Cambridge Analytica
nimmt dabei die Perspektive verschiedener Beteiligter auf
aufwändig produziert
HAK_MTL (2019)
Kurz und knapp:
kanadische Hacker stellen die Datenschutz-Versprechen von Unternehmen auf die Probe
dabei liegt ein Fokus auf Überwachungstechnologien
interessante Insider-Einblicke und O-Töne
WannaCry: The Marcus Hutchins Story (2019)
Kurz und knapp:
erzählt die Geschichte des IT-Experten, der WannaCry durch Zufall stoppte
und anschließend in Zusammenhang mit einem Banking-Trojaner verhaftet wurde
dabei kommt auch Hutchins selbst zu Wort
KnowBe4: The Making of a Unicorn (2020)
Kurz und knapp:
erzählt die Gründungsgeschichte des Security-Unternehmens KnowBe4
mit Beteiligung von Chief Hacking Officer Kevin Mitnick
produziert vom Cybercrime Magazine
MY.DOOM: Earth’s Deadliest Computer Viruses (2021)
Kurz und knapp:
thematisiert den Computervirus MyDoom aus dem Jahr 2004
analysiert dabei auch seine Auswirkungen
kostenlos in voller Länge verfügbar
Biggest Heist Ever – Der große Bitcoin-Raub (2024)
Kurz und knapp:
thematisiert den Hackerangriff auf die Hong Konger Kryptobörse Bitfinex aus dem Jahr 2016
beleuchtet den Werdegang von Ilya Lichtenstein und Heather Morgan, die für den Angriff verurteilt wurden
diverse O-Töne von Ermittlern, Freunden, Betroffenen – und auch von Ilya Lichtenstein selbst
Most Wanted: Teen Hacker (2025)
Kurz und knapp:
beleuchtet die Cybercrime-Karriere des finnischen Hackers Julius Kivimäki enthält Interviews mit Strafverfolgungsbehörden und Opfern des Cyberkriminellen auch Kivimäki selbst kommt zu Wort Joybubbles (2026)
Kurz und knapp:
erzählt die Geschichte des blinden Telefonhackers Joe Engressia aus dessen eigener Perspektive ursprünglich als Kickstarter-Projekt gestartet erfolgreiche Premiere auf dem Sundance Film Festival 2026 View the full article
Until this past weekend, a contractor for the Cybersecurity & Infrastructure Security Agency (CISA) maintained a public GitHub repository that exposed credentials to several highly privileged AWS GovCloud accounts and a large number of internal CISA systems. Security experts said the public archive included files detailing how CISA builds, tests and deploys software internally, and that it represents one of the most egregious government data leaks in recent history.
On May 15, KrebsOnSecurity heard from Guillaume Valadon, a researcher with the security firm GitGuardian. Valadon’s company constantly scans public code repositories at GitHub and elsewhere for exposed secrets, automatically alerting the offending accounts of any apparent sensitive data exposures. Valadon said he reached out because the owner in this case wasn’t responding and the information exposed was highly sensitive.
A redacted screenshot of the now-defunct “Private CISA” repository maintained by a CISA contractor.
The GitHub repository that Valadon flagged was named “Private-CISA,” and it harbored a vast number of internal CISA/DHS credentials and files, including cloud keys, tokens, plaintext passwords, logs and other sensitive CISA assets.
Valadon said the exposed CISA credentials represent a textbook example of poor security hygiene, noting that the commit logs in the offending GitHub account show that the CISA administrator disabled the default setting in GitHub that blocks users from publishing SSH keys or other secrets in public code repositories.
“Passwords stored in plain text in a csv, backups in git, explicit commands to disable GitHub secrets detection feature,” Valadon wrote in an email. “I honestly believed that it was all fake before analyzing the content deeper. This is indeed the worst leak that I’ve witnessed in my career. It is obviously an individual’s mistake, but I believe that it might reveal internal practices.”
One of the exposed files, titled “importantAWStokens,” included the administrative credentials to three Amazon AWS GovCloud servers. Another file exposed in their public GitHub repository — “AWS-Workspace-Firefox-Passwords.csv” — listed plaintext usernames and passwords for dozens of internal CISA systems. According to Caturegli, those system included one called “LZ-DSO,” which appears short for “Landing Zone DevSecOps,” the agency’s secure code development environment.
Philippe Caturegli, founder of the security consultancy Seralys, said he tested the AWS keys only to see whether they were still valid and to determine which internal systems the exposed accounts could access. Caturegli said the GitHub account that exposed the CISA secrets exhibits a pattern consistent with an individual operator using the repository as a working scratchpad or synchronization mechanism rather than a curated project repository.
“The use of both a CISA-associated email address and a personal email address suggests the repository may have been used across differently configured environments,” Caturegli observed. “The available Git metadata alone does not prove which endpoint or device was used.”
The Private CISA GitHub repo exposed dozens of plaintext credentials for important CISA GovCloud resources.
Caturegli said he validated that the exposed credentials could authenticate to three AWS GovCloud accounts at a high privilege level. He said the archive also includes plain text credentials to CISA’s internal “artifactory” — essentially a repository of all the code packages they are using to build software — and that this would represent a juicy target for malicious attackers looking for ways to maintain a persistent foothold in CISA systems.
“That would be a prime place to move laterally,” he said. “Backdoor in some software packages, and every time they build something new they deploy your backdoor left and right.”
In response to questions, a spokesperson for CISA said the agency is aware of the reported exposure and is continuing to investigate the situation.
“Currently, there is no indication that any sensitive data was compromised as a result of this incident,” the CISA spokesperson wrote. “While we hold our team members to the highest standards of integrity and operational awareness, we are working to ensure additional safeguards are implemented to prevent future occurrences.”
A review of the GitHub account and its exposed passwords show the “Private CISA” repository was maintained by a contractor employed by Nightwing, a government contractor based in Dulles, Va. Nightwing declined to comment, directing inquiries to CISA.
CISA has not responded to questions about the potential duration of the data exposure, but Caturegli said the Private CISA repository was created on November 13, 2025. The contractor’s GitHub account was created back in September 2018.
The GitHub account that included the Private CISA repo was taken offline shortly after both KrebsOnSecurity and Seralys notified CISA about the exposure. But Caturegli said the exposed AWS keys inexplicably continued to remain valid for another 48 hours.
The now-defunct Private CISA repo showed the contractor also used easily-guessed passwords for a number of internal resources; for example, many of the credentials used a password consisting of each platform’s name followed by the current year. Caturegli said such practices would constitute a serious security threat for any organization even if those credentials were never exposed externally, noting that threat actors often use key credentials exposed on the internal network to expand their access after establishing initial access to a targeted system.
“What I suspect happened is [the CISA contractor] was using this GitHub to synchronize files between a work laptop and a home computer, because he has regularly committed to this repo since November 2025,” Caturegli said. “This would be an embarrassing leak for any company, but it’s even more so in this case because it’s CISA.”
View the full article
“Something didn’t go as planned. Undoing changes.” That’s all the clue some Windows 11 users will get when Microsoft’s May Security Update fails to install because of insufficient free space on the EFI System Partition (ESP), leaving their systems unprotected by the dozens of patches it contained.
This issue affects devices with limited free space available — typically 10MB or less — on the ESP. “On affected devices, the installation might proceed through the initial phases but fail during the reboot phase at approximately 35-36% completion,” Microsoft said in an advisory. It recommended changing a Windows registry setting to force the update, or to roll back changes and wait for a future update to fix the problem.
Consultants said it was a potentially serious issue given the unexpected exposure and the time the destined-to-fail patch takes to fail to install.
This is the kind of failure that keeps IT leaders up at night, said cybersecurity consultant Brian Levine, who serves as executive director of FormerGov. “When a security update cannot install because the operating system misjudges the state of its own boot partition, the problem isn’t only storage. The real problem is trust in the update process,” he said. “This is a basic hygiene failure dressed up as a technical issue. An update that cannot reliably detect available space on the EFI System Partition is not a small miss. It is a reminder that even mature platforms still struggle with dependency awareness and pre-flight validation.”
Eric Grenier, senior director analyst at Gartner, recommended increasing the size of the disk partition to 1.5GB so that the update can go ahead. “This should not hamper business needs in terms of the size of usable space for an end user”, he said, adding that it will also enable updating of the Windows Recovery Environment. He warned that Microsoft’s own recommendation could lead to trouble. “I would recommend that if an organization wanted to use the modified registry fix that they not only backup the registry beforehand but also test it on some pilot devices before rolling out to the rest of the environment and even then, I would do a slow phased rollout to be sure nothing breaks,” he said. “This type of fix in a production environment should be done with extreme caution because if done incorrectly, fixes will require hands on the keyboard.”
Ishraq Khan, CEO of coding productivity tool vendor Kodezi, says there is a blame on both IT teams and Microsoft.
“Most IT teams reasonably assume that if Windows Update passes its prechecks and starts installation, Microsoft has already validated the system state well enough to avoid a reboot-stage failure. If ESP space is critical to the update succeeding, the updater should have detected and blocked that condition earlier with a clear remediation message,” Khan said. “So while IT environments may contribute to partition pressure over time, Microsoft still owns the orchestration and validation logic that allowed the update to proceed.”
Khan added that this can become a very expensive enterprise IT headache. “That is a design problem for enterprise IT because failure during reboot is much more disruptive than blocking the update before installation begins. From a software maintenance perspective, this is exactly the kind of edge case that becomes expensive at enterprise scale. A small partition constraint on a subset of machines can turn into help desk tickets, rollback cycles, delayed patching, and security exposure.”
David Neuman, COO of consulting firm Acceligence, agreed that this is a substantial IT headache.
“The update appears to pass the early phases but then fails during the reboot phase, which means IT may not find out until the endpoint has already burned through the maintenance window time and rolled back. In an enterprise, it becomes a fleet hygiene problem rather than a one-off help desk problem,” he said. “Affected endpoints may remain unpatched while IT burns time diagnosing a failure that should have been explained earlier. The bigger lesson is that boot, recovery, and firmware-adjacent partitions are now part of patch-management hygiene. Mature IT teams should add ESP size and free-space checks to endpoint health reporting, update gold images so new deployments have adequate ESP capacity and treat boot-partition cleanup or resizing as lifecycle engineering rather than break-fix scripting.”
Microsoft did not respond to a request for comment.

View the full article
“Something didn’t go as planned. Undoing changes.” That’s all the clue some Windows 11 users will get when Microsoft’s May Security Update fails to install because of insufficient free space on the EFI System Partition (ESP), leaving their systems unprotected by the dozens of patches it contained.
This issue affects devices with limited free space available — typically 10MB or less — on the ESP. “On affected devices, the installation might proceed through the initial phases but fail during the reboot phase at approximately 35-36% completion,” Microsoft said in an advisory. It recommended changing a Windows registry setting to force the update, or to roll back changes and wait for a future update to fix the problem.
Consultants said it was a potentially serious issue given the unexpected exposure and the time the destined-to-fail patch takes to fail to install.
This is the kind of failure that keeps IT leaders up at night, said cybersecurity consultant Brian Levine, who serves as executive director of FormerGov. “When a security update cannot install because the operating system misjudges the state of its own boot partition, the problem isn’t only storage. The real problem is trust in the update process,” he said. “This is a basic hygiene failure dressed up as a technical issue. An update that cannot reliably detect available space on the EFI System Partition is not a small miss. It is a reminder that even mature platforms still struggle with dependency awareness and pre-flight validation.”
Eric Grenier, senior director analyst at Gartner, recommended increasing the size of the disk partition to 1.5GB so that the update can go ahead. “This should not hamper business needs in terms of the size of usable space for an end user”, he said, adding that it will also enable updating of the Windows Recovery Environment. He warned that Microsoft’s own recommendation could lead to trouble. “I would recommend that if an organization wanted to use the modified registry fix that they not only backup the registry beforehand but also test it on some pilot devices before rolling out to the rest of the environment and even then, I would do a slow phased rollout to be sure nothing breaks,” he said. “This type of fix in a production environment should be done with extreme caution because if done incorrectly, fixes will require hands on the keyboard.”
Ishraq Khan, CEO of coding productivity tool vendor Kodezi, says there is a blame on both IT teams and Microsoft.
“Most IT teams reasonably assume that if Windows Update passes its prechecks and starts installation, Microsoft has already validated the system state well enough to avoid a reboot-stage failure. If ESP space is critical to the update succeeding, the updater should have detected and blocked that condition earlier with a clear remediation message,” Khan said. “So while IT environments may contribute to partition pressure over time, Microsoft still owns the orchestration and validation logic that allowed the update to proceed.”
Khan added that this can become a very expensive enterprise IT headache. “That is a design problem for enterprise IT because failure during reboot is much more disruptive than blocking the update before installation begins. From a software maintenance perspective, this is exactly the kind of edge case that becomes expensive at enterprise scale. A small partition constraint on a subset of machines can turn into help desk tickets, rollback cycles, delayed patching, and security exposure.”
David Neuman, COO of consulting firm Acceligence, agreed that this is a substantial IT headache.
“The update appears to pass the early phases but then fails during the reboot phase, which means IT may not find out until the endpoint has already burned through the maintenance window time and rolled back. In an enterprise, it becomes a fleet hygiene problem rather than a one-off help desk problem,” he said. “Affected endpoints may remain unpatched while IT burns time diagnosing a failure that should have been explained earlier. The bigger lesson is that boot, recovery, and firmware-adjacent partitions are now part of patch-management hygiene. Mature IT teams should add ESP size and free-space checks to endpoint health reporting, update gold images so new deployments have adequate ESP capacity and treat boot-partition cleanup or resizing as lifecycle engineering rather than break-fix scripting.”
Microsoft said that it had resolved the issue automatically for consumer devices and non-managed business devices, but that leaves enterprises managing their own devices to sort things out for themselves. “We recommend IT administrators follow guidance within the known issues documentation, to mitigate this issue and re-deploy the latest May Security Updates to be protected,” a Microsoft representative said via email. The company plans to update documentation when it has resolved the problem.

View the full article
iOS 27 will include a custom wallpaper generator and an option to automatically create shortcuts using AI, reports Bloomberg.


When choosing a new wallpaper, users will have the option to generate something custom using the Image Playground app. ‌Image Playground‌ is used for generating custom emoji and images that can be used throughout iOS, and it is set to get an upgrade in ‌iOS 27‌.

Apple is testing models that produce more lifelike images, so the version of ‌Image Playground‌ that's used for generating custom wallpapers could be different from the current version.

Shortcuts is also getting a major update, with users able to use natural language to ask Siri to make a shortcut. There is an option for users to tell ‌Siri‌ what they want to accomplish with a shortcut to have the workflow created using AI.

Bloomberg says the Shortcuts app has a prompt that says "What do you want your shortcut to do?" with a text field to enter a description. Shortcuts that are created using AI are then automatically installed and immediately available for use.

Shortcut creation is largely done manually now, and it is a tool that has remained out of reach of many casual iPhone users. A Shortcuts app that's able to work with natural language capabilities will see the app getting more widespread use.

The new Shortcuts app and the wallpaper generation tool will be previewed at the WWDC keynote that's set to take place on June 8.Related Roundup: iOS 27
This article, "iOS 27 to Let Users Generate Wallpapers and Build Shortcuts With AI" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
iOS 27 and iPadOS 27 will include a revamped AI chatbot version of Siri with new capabilities, but Apple is also planning to introduce new Apple Intelligence features across the operating system, reports Bloomberg.


Apple is testing an expanded version of Writing Tools that will do more rewriting and text generation than the current version. There is a "Write With ‌Siri‌" toggle at the top of the keyboard, along with a "Help Me Write" option that comes up when ‌Siri‌ is activated while a text field is open.

Apple is planning to introduce a dedicated AI grammar checker for Writing Tools that will work like Grammarly. When writing in Messages, Mail, and other apps there will be a translucent menu that slides up from the bottom of the iPhone's screen, and it will show suggested revisions next to the original written text.

Users can go through the suggestions and accept or reject them one by one, approve all of the changes at once, or ignore all of the changes. Apple has an option for pausing grammar checking and for moving between different flagged sections of text. Apple already has a spellchecking feature, but the new feature will add grammar suggestions.

The updates to Writing Tools will be unveiled at Apple's June 8 WWDC keynote. Apple is also planning AI updates for the Photos app, Camera app, and more, with details available in our iOS 27 roundup.Related Roundup: iOS 27
This article, "Apple Expanding AI Writing Tools With Grammar Checker in iOS 27" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
In preparation for the 2026 Worldwide Developers Conference that is set to begin on June 8, Apple today announced its finalists for the 2026 Apple Design Awards. Apple picks top apps and games annually, and announces winners at WWDC.


The Apple Design Awards recognize apps with innovation, ingenuity, and technical achievement in app and game design.
Delight and Fun - Apps


Blippo+
Metaballs
Grug

Delight and Fun - Games


PowerWash Simulator
Is This Seat Taken?
Ball x Pit

Inclusivity - Apps


Guitar Wiz
Hearing Buddy
Structured

Inclusivity - Games


Sago Mini Jinja's Garden
Pine Hearts
Civilization VII

Innovation - Apps


Detail: AI Video Editor
NBA: Live Games & Scores
D-Day: The Camera Soldier

Innovation - Games


TR–49
Blue Prince
Pickle Pro

Interaction - Apps


The Outsiders: Athlete Tracker
Moonlitt: Moon Phase Tracker
Tide Guide: Charts & Tables

Interaction - Games


TR–49
Sago Mini Jinja's Garden
Grand Mountain Adventure 2

Social Impact - Apps


Primary: News in Depth
Katha Room
Harvee

Social Impact - Games


Consume Me
Despelote
Spilled!

Visuals and Graphics - Apps


Tide Guide: Charts & Tables
Caradise
(Not Boring) Camera

Visuals and Graphics - Games


Cyberpunk 2077 Ultimate Edition
Arknights: Endfield
SILT

One app and one game will be chosen in each category, with Apple to announce winners during the 2026 Worldwide Developers Conference. Winners will receive a physical award and hardware to help them continue to create apps and games.

Links to all of the apps that are nominated can be found on Apple's website.Related Roundup: WWDC 2026Related Forum: Apple, Inc and Tech Industry
This article, "Apple Design Award Finalists Announced Ahead of WWDC 2026" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Apple today provided a schedule for its 2026 Worldwide Developers Conference, which starts on June 8 and ends on June 12. Apple also sent out invites to members of the media who have been invited to attend an in-person keynote viewing at Apple Park.


Both the invites and schedule confirm that the keynote will begin at the standard time, 10:00 a.m. Pacific Time or 1:00 p.m Eastern Time.

Apple says the keynote event will be available to stream on Apple.com, the Apple TV app, and the Apple YouTube channel. We'll also be providing live coverage at MacRumors.com for those who are unable to watch.

Apple also plans to host the Platforms State of the Union for developers at 1:00 p.m. Pacific Time, and video sessions and guides will start coming out after the keynote event. Group Labs and Q&A sessions will be hosted by Apple engineers and designers throughout the week, providing more insight into the new software coming at WWDC 2026.

‌WWDC 2026‌ will see Apple unveil iOS 27, iPadOS 27, macOS 27, and more. An updated version of Siri that's smarter and more like a ChatGPT-style chatbot will be unveiled, along with multiple design changes to accommodate ‌Siri‌'s new abilities. We have an in-depth look at what's coming in iOS 27 in our dedicated roundup.Related Roundup: WWDC 2026Related Forum: Apple, Inc and Tech Industry
This article, "Apple Announces WWDC 2026 Schedule, Sends Media Invites" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
INTERPOL has coordinated a first-of-its-kind cybercrime crackdown across the Middle East and North Africa (MENA) that led to 201 arrests and the identification of an additional 382 suspects. The initiative involved the efforts of 13 countries from the region between October 2025 and February 2026, aiming to investigate and neutralize malicious infrastructure, arrest perpetrators behind theseView the full article
The ability of AI models to perform end-to-end, multi-stage penetration tests that match the capabilities of humans undertaking the same tasks has improved dramatically in recent months, according to new benchmarks published by the UK government’s AI Security Institute (AISI).
In November 2025, the difficulty of cyber tasks the best models could complete was doubling every eight months, according to AISI, a research organization within the Department for Science, Innovation and Technology (DSIT).
By February this year, the performance improvements had accelerated, with the difficulty of the tasks AI models could complete doubling every 4.7 months, and since then the latest Claude Mythos Preview and GPT-5.5 models are showing even greater capability, AISI said.
The time horizon benchmarks used by AISI first measure or estimate the time it would take a human expert to solve a variety of challenges as a proxy for their difficulty and then estimate the longest task (in human work hours) that AI models can complete with a success rate of 80%. This makes it a measure of autonomous capability rather than speed: If a human can successfully complete a set of pen testing tasks in 4 hours, time horizon testing measures how successfully an AI model can match this capability at a given reliability.
To achieve this, the AI must sustain performance over multiple steps while maintaining context and recovering from failures. The more steps, the more difficult pen testing becomes, and the more meaningful the results.
As with all benchmarks, there are caveats. The first is that to compare performance between models over time, the testing capped the AI systems at a low 2.5 million tokens. This has a number of effects including, in these benchmarks, limiting the ability of the AI models to keep track of what they were working on at an earlier stage.
As AISI said in its analysis, “They are inexact predictors of performance; AI struggles with some tasks humans do quickly, and easily completes others that humans find hard. However, we use this type of benchmark because it offers a measure of AI autonomy from which we can draw trends.”
Growing risk
The research is cause for concern for the UK government.
“Our independent testing shows that cyber capabilities in leading AI systems are advancing much faster than we expected. That matters because this isn’t theoretical — those advances are already starting to translate into real risks for organisations, especially those with weak cyber defences,” UK AI Minister Kanishka Narayan said via email.
“These tools can also help cyber security teams spot and fix weaknesses faster. The UK is leading the way in testing and understanding frontier AI, and that capability is only going to become more important as the technology continues to move at pace,” he added.
In April, DSIT Secretary of State Liz Kendall and Security Minister Dan Jarvis posted an open letter warning businesses of the growing cyber security risks posed by AI models.
What’s clear is that the capabilities of AI models under real-world scenarios are rapidly improving and, on the evidence of the recent AISI evaluation of Claude Mythos Preview, are probably accelerating.
Not all recent benchmarking of AI’s abilities to solve difficult problems has delivered such impressive results. In a recent test of 19 AI models against a range of tasks including coding, crystallography, genealogy and music sheet notation, researchers at Microsoft found the models could be error-prone and unreliable, especially for longer tasks.
Kat Traxler, principal security researcher at Vectra AI, sees the benchmarks as a useful signal that enterprises should pay attention to. “The AISI benchmarks don’t measure if models can spot a flaw. Rather, they measure whether various models can chain together a series of exploits into working attacks to achieve an end goal, like a real-world attackers do. As a signal of offensive capability, AISI’s results carry real weight,” she said.
However, she pointed to a recent Xbow evaluation of Claude Mythos that found mixed performance at some tasks. “How these known model limitations will actually limit real-world autonomous offensive campaigns is still being determined, but it does point to the need for a sophisticated validation harness to truly see the ceiling of model capabilities.”
According to Chris Lentricchia, director cloud and AI security strategy at Sweet Security, enterprises should also look at the upside — AI models aid attackers, but also defenders.
“This is not purely an offensive story. The same acceleration improving attacker capability can also improve defensive capability in areas like proactive threat detection and response automation. Benchmarks are best viewed as indicators for understanding whether enterprise defenses are evolving fast enough to keep pace with accelerating AI capability,” said Lentricchia.
View the full article
The ability of AI models to perform end-to-end, multi-stage penetration tests that match the capabilities of humans undertaking the same tasks has improved dramatically in recent months, according to new benchmarks published by the UK government’s AI Security Institute (AISI).
In November 2025, the difficulty of cyber tasks the best models could complete was doubling every eight months, according to AISI, a research organization within the Department for Science, Innovation and Technology (DSIT).
By February this year, the performance improvements had accelerated, with the difficulty of the tasks AI models could complete doubling every 4.7 months, and since then the latest Claude Mythos Preview and GPT-5.5 models are showing even greater capability, AISI said.
The time horizon benchmarks used by AISI first measure or estimate the time it would take a human expert to solve a variety of challenges as a proxy for their difficulty and then estimate the longest task (in human work hours) that AI models can complete with a success rate of 80%. This makes it a measure of autonomous capability rather than speed: If a human can successfully complete a set of pen testing tasks in 4 hours, time horizon testing measures how successfully an AI model can match this capability at a given reliability.
To achieve this, the AI must sustain performance over multiple steps while maintaining context and recovering from failures. The more steps, the more difficult pen testing becomes, and the more meaningful the results.
As with all benchmarks, there are caveats. The first is that to compare performance between models over time, the testing capped the AI systems at a low 2.5 million tokens. This has a number of effects including, in these benchmarks, limiting the ability of the AI models to keep track of what they were working on at an earlier stage.
As AISI said in its analysis, “They are inexact predictors of performance; AI struggles with some tasks humans do quickly, and easily completes others that humans find hard. However, we use this type of benchmark because it offers a measure of AI autonomy from which we can draw trends.”
Growing risk
The research is cause for concern for the UK government.
“Our independent testing shows that cyber capabilities in leading AI systems are advancing much faster than we expected. That matters because this isn’t theoretical — those advances are already starting to translate into real risks for organisations, especially those with weak cyber defences,” UK AI Minister Kanishka Narayan said via email.
“These tools can also help cyber security teams spot and fix weaknesses faster. The UK is leading the way in testing and understanding frontier AI, and that capability is only going to become more important as the technology continues to move at pace,” he added.
In April, DSIT Secretary of State Liz Kendall and Security Minister Dan Jarvis posted an open letter warning businesses of the growing cyber security risks posed by AI models.
What’s clear is that the capabilities of AI models under real-world scenarios are rapidly improving and, on the evidence of the recent AISI evaluation of Claude Mythos Preview, are probably accelerating.
Not all recent benchmarking of AI’s abilities to solve difficult problems has delivered such impressive results. In a recent test of 19 AI models against a range of tasks including coding, crystallography, genealogy and music sheet notation, researchers at Microsoft found the models could be error-prone and unreliable, especially for longer tasks.
Kat Traxler, principal security researcher at Vectra AI, sees the benchmarks as a useful signal that enterprises should pay attention to. “The AISI benchmarks don’t measure if models can spot a flaw. Rather, they measure whether various models can chain together a series of exploits into working attacks to achieve an end goal, like a real-world attackers do. As a signal of offensive capability, AISI’s results carry real weight,” she said.
However, she pointed to a recent Xbow evaluation of Claude Mythos that found mixed performance at some tasks. “How these known model limitations will actually limit real-world autonomous offensive campaigns is still being determined, but it does point to the need for a sophisticated validation harness to truly see the ceiling of model capabilities.”
According to Chris Lentricchia, director cloud and AI security strategy at Sweet Security, enterprises should also look at the upside — AI models aid attackers, but also defenders.
“This is not purely an offensive story. The same acceleration improving attacker capability can also improve defensive capability in areas like proactive threat detection and response automation. Benchmarks are best viewed as indicators for understanding whether enterprise defenses are evolving fast enough to keep pace with accelerating AI capability,” said Lentricchia.
View the full article
The Apple Watch Ultra 4 could feature a complete redesign and blood pressure monitoring, according to DigiTimes.


Apple will apparently add a new high blood pressure notification feature to the Apple Watch that uses the optical heart-rate sensor on the back of the device to analyze how blood vessels respond to each heartbeat, sending alerts when an abnormal pattern is detected. The feature is said to be under FDA review.

It is not entirely clear how it differs from the Hypertension Notifications feature Apple introduced with watchOS 26 last fall, which itself uses the optical heart sensor to analyze blood vessel responses over 30-day periods. DigiTimes says that earlier Apple Watch models already had some blood-pressure sensing capabilities, and the new feature appears to represent a more refined or clinically validated implementation of that underlying hardware.

After this, Apple's next health monitoring capabilities are expected to focus on noninvasive blood-glucose monitoring, a capability Apple has been pursuing for a number of years, pending government approval.

The report is largely consistent with a DigiTimes report from last year, which said at least one new Apple Watch model would feature a "significant redesign," with supply chain sources pointing to exterior design changes including eight sensors arranged in a ring pattern on the back of the device. Today's update describes the changes more forcefully, calling it a "full redesign" alongside a "significant upgrade to sensing functions."

According to market observers cited by the report, the redesign could boost Apple Watch shipments by 20% to 30% compared to 2025. The sensor upgrades are expected to be a major boost for Taiwan-Asia Semiconductor (TASC), Apple's exclusive supplier of sensor components, with large-volume orders anticipated as early as July.

Apple Watch Ultra 4 is expected to be announced alongside the Apple Watch Series 12, iPhone 18 Pro, ‌iPhone 18 Pro‌ Max, and foldable "iPhone Ultra" in fall 2026.Related Roundup: Apple Watch Ultra 3Tags: DigiTimes, Health and Fitness, Health TechnologiesBuyer's Guide: Apple Watch Ultra (Neutral)Related Forum: Apple Watch
This article, "Apple Watch Ultra 4 Could Get Redesign and Blood Pressure Monitoring" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Apple today launched a new promotion offering new Apple Card holders the chance to earn back the cost of AirPods Pro 3 through monthly cash rebates, but there is a recurring spend requirement attached.


Customers who open a new Apple Card account and purchase ‌AirPods Pro 3‌ directly from Apple by June 15 will qualify. Starting July 1 and running through April 30, 2027, cardholders can earn $25 in Bonus Daily Cash each month, up to $250 total, but only in months where they make at least ten purchases on the card. Each qualifying purchase must be at least $0.01, and the ‌AirPods Pro 3‌ purchase itself does not count toward the monthly ten-purchase threshold.

The offer is open to new ‌Apple Card‌ applicants only, and is not available to existing cardholders or anyone with a pending application. The ‌AirPods Pro 3‌ purchase must be made directly from Apple, either online or in an Apple Store. Refurbished products, purchases through third-party retailers, international transactions, and business bulk orders are all excluded. The ‌AirPods Pro 3‌ purchase cannot be made entirely with an Apple Gift Card or Apple Account balance.

All ‌Apple Card‌ payment options are eligible, including paying in full or financing via ‌Apple Card‌ Monthly Installments, and any trade-in applied to the purchase does not affect eligibility. Returning the ‌AirPods Pro 3‌ purchase may result in forfeiture of the offer.

The ‌AirPods Pro 3‌ are priced at $249 and were introduced alongside the iPhone 17 lineup in September 2025.Related Roundup: AirPods Pro 3Tags: AirPods Pro 3, Apple CardBuyer's Guide: AirPods Pro (Neutral)Related Forum: AirPods
This article, "Apple Card Holders Can Now Get Free AirPods Pro 3, But There's a Catch" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Anker's new Prime 3-in-1 Wireless Charging Station has been marked down to $104.99 on Amazon, down from $149.99. This is one of Anker's newest accessories, and Amazon's sale today is a match of the all-time low price.

Note: MacRumors is an affiliate partner with some of these vendors. When you click a link and make a purchase, we may receive a small payment, which helps us keep the site running.

The Prime 3-in-1 Wireless Charging Station features Qi2.2 support, which lets a compatible MagSafe ‌iPhone‌ charge at up to 25W. It's the same speed as Apple's ‌MagSafe‌ charger, and it is 10W faster than the standard Qi2 ‌MagSafe‌ chargers. You can also simultaneously charge an Apple Watch and AirPods with the device.

$45 OFFAnker Prime 3-in-1 Wireless Charging Station for $104.99

There are plenty of other Anker discounts happening on Amazon this week, including Anker's Prime 14-in-1 Docking Station for $339.99, down from $399.99. Below you'll find a list of the best Anker discounts on Amazon this week, also including wall chargers, portable chargers, and more.

$60 OFFAnker Prime 14-in-1 Docking Station for $339.99
Wall Chargers

Nano USB-C Wall Charger - $29.99, down from $39.99
140W 4-Port GaN USB-C Charger - $79.99, down from $99.99
160W 3-Port Compact Charger - $105.99, down from $149.99
Wireless Chargers

3-in-1 MagSafe-Compatible UFO Charger - $69.99, down from $89.99
3-in-1 MagSafe-Compatible Foldable Charging Station - $85.99, down from $109.99
3-in-1 MagSafe-Compatible Charging Cube - $86.99, down from $129.99
3-in-1 Prime Wireless Charging Station - $104.99, down from $149.99
Prime MagSafe-Compatible 3-in-1 Charging Station - $159.99, down from $229.99
Portable Chargers

MagGo Power Bank 10,000 mAh - $63.99, down from $79.99
Prime Power Bank 20,100 mAh - $149.99, down from $179.99
SOLIX C300 Power Station with Lantern - $169.99, down from $249.00
Prime Power Bank 26,250 mAh - $171.48, down from $229.99
SOLIX C1000 Gen 2 Portable Power Station - $449.99, down from $799.00
SOLIX C2000 Gen 2 Portable Power Station - $799.99, down from $1,499.00
If you're on the hunt for more discounts, be sure to visit our Apple Deals roundup where we recap the best Apple-related bargains of the past week.



Deals Newsletter

Interested in hearing more about the best deals you can find in 2026? Sign up for our Deals Newsletter and we'll keep you updated so you don't miss the biggest deals of the season!




Related Roundup: Apple Deals
This article, "Anker's Newest Prime Chargers Hit Their Lowest-Ever Prices on Amazon" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Trial production of Apple's long-anticipated foldable iPhone, likely called the "iPhone Ultra," has run into a significant engineering hurdle centered on hinge reliability, according to a known leaker.


The leaker known as "Instant Digital" posted on Weibo that the foldable device's hinge is consistently failing to meet Apple's quality control standards under conditions of prolonged, high-frequency opening and closing. The leaker described the mechanical wear issue as one that "must be resolved with absolute perfection; otherwise, progress will simply have to be stalled for the time being."

The hinge has been a key focus of Apple's foldable development for years. Supply chain analyst Ming-Chi Kuo first reported that the device would use Liquid Metal components in the hinge mechanism, with Dongguan EonTec serving as the exclusive supplier of the amorphous alloy. Instant Digital subsequently elaborated that the material, also known as metallic glass, features a disordered atomic structure that is more resistant to bending and deformation than traditional metals, and more durable than titanium alloy. This makes it suitable for a foldable's hinge.

Apple has previously used the material only in small components such as SIM ejector pins, so the ‌iPhone Ultra‌ would mark its first major use in a critical mechanical part. A subsequent report in January corroborated the liquid metal hinge plans, noting that Apple has been exploring the material for over 15 years, tracing back to a 2010 licensing deal with Liquidmetal Technologies.

Screen creasing is a concern that has followed the foldable smartphone category since its inception. Instant Digital says Apple has essentially accepted some degree of crease as inevitable, but that test results have demonstrated the device can maintain a visually crease-free state over the long term. That aligns with previous reporting: leaker "Fixed Focus Digital" reported in February that production orders had been placed with a crease depth under 0.15mm and a crease angle under 2.5 degrees. Apple has reportedly pursued eliminating the crease "regardless of cost," with engineering solutions including a dual-layer ultra-thin glass structure designed to spread mechanical stress across multiple layers, and advances in optically clear adhesive to keep display layers in precise alignment.

A follow-up post from the leaker suggested the hinge difficulties are unlikely to push back the device's expected release window somewhat, noting that there is still ample time remaining. That is broadly consistent with earlier reporting: DigiTimes reported in April that production was running roughly one to two months behind schedule, but that a fall 2026 launch remained on track, with mass production planned to begin in July. Apple is expected to announce the foldable iPhone alongside the iPhone 18 Pro models at its September event, though some reports suggest customer availability could slip as late as December.

In a third post, Instant Digital offered a note on the device's experience, suggesting that despite its larger form factor the foldable feels like an iPhone rather than an iPad when in use. The leaker added that the screen size offers limited practical utility for a stylus, casting doubt on whether Apple Pencil support would be a meaningful feature for the device.

The foldable iPhone is expected to feature a 7.8-inch inner display and a 5.5-inch cover display, with an A20 chip, C2 modem, Touch ID power button, and two rear cameras. Pricing is rumored to sit at around $2,000.Related Roundup: iPhone FoldTags: Foldable iPhone, Instant Digital
This article, "Foldable iPhone Production Stalls Amid Hinge Issues" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
AMC+ has kicked off a major new discount this week, offering 74 percent off your entire first year of the service via Amazon channels. This knocks the price of AMC+ Premium down to $29.99 per year, down from $109.99 per year.

Note: MacRumors is an affiliate partner with Amazon. When you click a link and make a purchase, we may receive a small payment, which helps us keep the site running.

This is the Premium tier of the subscription service, allowing you to stream without ads (with limited exceptions), access to six live TV channels, and the ability to download and watch programs on the go. It also features full access to Shudder, BBC America, and Sundance Now.

74% OFFAMC+ Premium via Amazon for $29.99/Year

To get the deal, you can follow this link on Amazon and click "select plan" under the AMC+ Premium tier option. From there, you can select the Annual option to add the AMC+ Premium subscription to your channels list for just $29.99 for one year.

Shoppers should note that the price will increase to $109.99 per year at the end of your first year unless canceled. This discount is expected to expire on May 25, so be sure to lock in the sale soon if you're interested.

If you're on the hunt for more discounts, be sure to visit our Apple Deals roundup where we recap the best Apple-related bargains of the past week.



Deals Newsletter

Interested in hearing more about the best deals you can find in 2026? Sign up for our Deals Newsletter and we'll keep you updated so you don't miss the biggest deals of the season!




Related Roundup: Apple Deals
This article, "AMC+ Premium for $29.99: Stream Shudder, BBC America, and More for a Year" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Sony's latest noise-canceling headphones have been leaked. Images of the 10th anniversary models, called 1000X "The Collexion" Edition, were shared online today by OnLeaks. They're expected to launch tomorrow, coming just a year after the company's WH-1000XM6 series.


From what we can tell based on the leaked materials, the changes are largely design-based. The new cans have a thicker leatherette padding than their predecessors, as well as larger ear cups, while the buttons are more separated and the microphone grilles get more breathing room. But it's the headband stems that stand out. Depending on the color choice, they're glossy black or chrome-on-white. The touch control surface has also been moved to the side and rear of each cup.

The biggest difference though is said to be a more robust design. Durability was reportedly a recurring complaint with the XM6's, so Sony has reinforced the stems by making them a single piece of polished metal rather than a fork. A purse-style carry case comes along for the ride, as does a headphone cable, but a USB-C charging cable may not be included (the leaked materials are contradictory on this point).

Battery life on a single charge sounds roughly comparable to the XM6's, with up to 24 hours of playback with acoustic noise-canceling enabled and 32 hours with ANC off. There's also a five-minute quick-charge feature that gets you 1.5 hours of battery life.

Sony says it has partnered with three world-class mastering studios for the driver tuning, including Battery Studios, Sterling Sound and Coast Mastering.

The new headphones will be available on Tuesday for $649 in the United States – $200 more than the cost of the XM6 headphones at launch, suggesting they are being marketed as a luxury product. It's only a short step up from the category occupied by Apple's $549 AirPods Max, which received a refresh earlier this year with a H2 chip.

(Via HotEUDeals.)Tag: Sony
This article, "Sony's 10th Anniversary 'Collexion' Over-Ear Headphones Leaked" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
This is issue 1 of a new series called Coding Agent Horror Stories where we examine critical security failures in the AI coding agent ecosystem and how Docker Sandboxes provide enterprise-grade protection against these threats.
AI coding agents are everywhere. According to Anthropic’s 2026 Agentic Coding Trends Report, developers are now using AI in roughly 60% of their work. The report describes a shift from single agents to coordinated teams of agents, with tasks that took hours or days getting compressed into minutes. Walk into almost any engineering team in 2026 and you’ll find AI coding agents sitting somewhere in the workflow, usually in more than one place.
The productivity story is real, and if you’ve watched an agent ship a feature in an afternoon that would have taken your team a sprint, you already know why. But the same agents that ship features in an afternoon can also delete your home directory in a few seconds. The same loop that lets an agent autonomously refactor a 12-million-line codebase will, given the wrong context, autonomously drop your production database. 
Over the past sixteen months, these aren’t hypothetical failure modes, they’re documented incidents with named victims, screenshotted agent outputs, and in several cases, public apologies from the vendors. This issue is the first in a new series mapping how those failures happen and how Docker Sandboxes can contain them.
What Are AI Coding Agents?
Unlike a traditional AI assistant that answers your question and waits for the next one, a coding agent reads your files, runs shell commands, writes and deploys code, queries databases, sends emails, and makes a chain of decisions to get a task done, none of which require you to approve each step along the way.
If you’ve worked with any of the current coding agents such as Claude Code, Cursor, Replit Agent, GitHub Copilot Workspace, Amazon Kiro, Google Antigravity, you’ve seen the pattern. They plug straight into your local machine, your cloud accounts, and increasingly your production systems. Adoption has been faster than almost any developer tool in recent memory: by late 2025, the vast majority of working developers were using AI coding tools as part of their daily workflow, and the question on most engineering teams shifted from “should we use this?” to “how do we use this without something going wrong?”
The simplest mental model I’ve found: an AI coding agent is a junior developer with root access, the ability to type at 10,000 words per minute, and no instinct for when to stop and ask. That combination is a lot of capability with no built-in sense of where the boundary is an entire reason this series exists.

How Do AI Coding Agents Work?
Under the hood, every agent in this category runs the same loop: observe, plan, act, repeat. 
You give it a task, something like “fix this bug” or “refactor this module” or “clean up these old files,” and the agent goes off and pulls in whatever context it figures it needs. Your files, sure, but also your logs, your environment variables, whatever happens to be accessible from wherever you launched it. Then it reasons through the problem and starts firing off tool calls to actually do the work. Write a file, run a command, hit an API, check the result, decide what’s next, loop. That’s the whole thing.
The part that catches people off guard is that the agent runs as you. Whatever permissions your shell has at the moment you typed the command to launch the agent, the agent inherits them wholesale. Logged in with admin rights? Congratulations, so is the agent. Got AWS credentials sitting in ~/.aws from that thing you set up six months ago and forgot about? The agent can read them. Production database connection string tucked into a .env file the agent scoops up as part of “project context”? It’s already in the model’s working memory before you’ve typed your second prompt. There isn’t a separate identity for “the agent acting on your behalf.” There’s just you, and the agent is, for all practical purposes, operating as you.
And here’s where it gets interesting, in the bad way. Traditional software does exactly what its source code says it does. You read the code, you know what’s going to happen, end of story. An AI coding agent doesn’t work like that. It’s reasoning its way through the task in real time, and its reasoning can produce decisions you didn’t expect and definitely wouldn’t have signed off on if anyone had bothered to ask. Maybe it decides that the cleanest way to resolve a schema conflict is to drop and recreate the table. Maybe it decides that wiping a directory is faster than going through and pruning the files you actually wanted to keep. Maybe it decides that a half-finished test file is better to be committed than sitting there in a dirty working tree. These calls happen in milliseconds. There’s no confirmation prompt, no approval step, no chance for you to say “wait, what?” before the action has already happened. By the time you notice, the thing is done.
That’s the gap this series is about. The model makes a decision. The execution layer carries it out. Nothing sits in between.
Caption: Comic depicting AI coding agent enthusiasm and the small matter of unrestricted filesystem access
AI Coding Agent Security Issues by the Numbers
The scale of security failures with AI coding agents is not speculation. It is backed by documented incidents, CVE disclosures, and empirical research spanning late 2024 through early 2026.
As of February 2026, at least ten documented incidents across six major AI coding tools including Amazon Kiro, Replit AI Agent, Google Antigravity IDE, Claude Code, Claude Cowork, and Cursor have been publicly attributed to agents acting with insufficient boundaries, spanning a 16-month window from October 2024 to February 2026.
The failures cluster around six critical risk categories:
Unrestricted Filesystem Access Excessive Privilege Inheritance Secrets Leakage via Agent Context Prompt Injection through Ingested Content Malicious Skills and Plugin Supply Chain Autonomous Action Without Human-in-the-Loop 1. Unrestricted Filesystem Access
What it is: AI coding agents run with the full filesystem permissions of the operating user. Without an explicit workspace boundary, an agent that is asked to “clean up” a project directory can reach and destroy anything the user can access.
The numbers: A December 2025 study by CodeRabbit, the “State of AI vs Human Code Generation” report, analyzing 470 real-world open-source pull requests found that AI-generated code introduces 2.74x more security vulnerabilities and 1.7× more total issues than human-written code. Performance inefficiencies such as excessive I/O operations appeared at 1.42x the rate. “These findings reinforce what many engineering teams have sensed throughout 2025,” said David Loker, Director of AI at CodeRabbit. “AI coding tools dramatically increase output, but they also introduce predictable, measurable weaknesses that organizations must actively mitigate.”
The horror story: The Mac Home Directory Wipe
On December 8, 2025, Reddit user u/LovesWorkin posted to r/ClaudeAI what became one of the most-discussed incidents in the community, amplified by Simon Willison on X and covered by outlets across the US and Japan. They had asked Claude Code to clean up packages in an old repository. Claude executed:
rm -rf tests/ patches/ plan/ ~/ That trailing ~/ the user’s entire home directory was not intentional. But it was within scope. Claude had no workspace boundary. Desktop gone. Documents erased. Keychain deleted, breaking authentication across every app. TRIM had already zeroed the freed blocks. Recovery was impossible.
This was not an isolated failure. On October 21, 2025,developer Mike Wolak filed GitHub issue #10077 after Claude Code executed an rm -rf starting from root on Ubuntu/WSL2. The logs showed thousands of “Permission denied” messages for /bin, /boot, and /etc. Every user-owned file was gone. Anthropic tagged the issue area: security and bug. The detail that makes this particularly damning: Wolak was not running with --dangerously-skip-permissions. The permission system simply failed to detect that ~/ would expand destructively before the command was approved.
Shortly after Anthropic’s January 2026 launch of Claude Cowork, Nick Davidov, founder of a venture capital firm, asked the agent to organize his wife’s desktop. He explicitly granted permission only for temporary Office files. The agent deleted a folder containing 15 years of family photos, approximately 15,000 to 27,000 files, via terminal commands that bypassed the Trash entirely. Davidov recovered the photos only because iCloud’s 30-day retention happened to still be in effect. His public warning afterward: “Don’t let Claude Cowork into your actual file system. Don’t let it touch anything that is hard to repair.”
Strategy for mitigation: Never run AI coding agents with your full user permissions. Always scope agent execution to a dedicated project directory. Use filesystem boundaries that explicitly prevent access above the workspace root. Avoid using --dangerously-skip-permissions flags on your host machine.
2. Excessive Privilege Inheritance
What it is. The agent doesn’t just inherit your filesystem permissions, it inherits all of them. Cloud credentials, CI/CD tokens, production database connections, IAM roles, the works. In a development context, an agent making a “let me just clean this up” decision is annoying. In a production context, with production credentials, the same decision turns into an outage. The reasoning is identical. The blast radius isn’t.
The horror story: permission to delete the environment. In mid-December 2025, an AWS engineer deployed Kiro, Amazon’s own agentic coding assistant, to fix what was meant to be a small bug in AWS Cost Explorer, the dashboard customers use to track their cloud spending. Kiro had been given operator-level permissions, the same access the engineer had. There was no mandatory peer review for AI-initiated production changes. There was no checkpoint between the agent’s decision and its execution.
Kiro looked at the problem and decided that the cleanest path was to delete the entire production environment and rebuild it from scratch. So it did. Cost Explorer went down for thirteen hours in one of AWS’s mainland China regions.
The story sat inside Amazon for two months. Then on February 20, 2026, the Financial Times broke it based on accounts from four people familiar with the matter. The FT reporting also revealed a second AI-related outage, this one involving Amazon Q Developer, that had hit a different system. Amazon’s response, issued the same day on the company’s own blog, pushed back hard: the disruption was “an extremely limited event,” the issue stemmed from “a misconfigured role,” it was “a coincidence that AI tools were involved,” and “the same issue could occur with any developer tool (AI powered or not) or manual action.” Amazon also flatly denied the second outage existed.
But the part of Amazon’s response that says everything is what they did after the incident: they implemented mandatory peer review for production access. As The Register noted in their coverage, if this was just user error, it’s worth asking why peer review for AI-initiated changes was the fix. A senior AWS employee, quoted in the FT and picked up by Engadget, put it more directly: the outages were “small but entirely foreseeable.”
The deeper context, which you can find in coverage from Awesome Agents and others, is that Amazon had issued an internal memo in November 2025 mandating Kiro as the standardized AI coding assistant and pushing for 80% weekly engineer usage. Engineers reportedly preferred Claude Code and Cursor. The combination — mandated tool, broad permissions, no peer review gate — produced exactly the kind of incident you’d predict if you were thinking about it adversarially. Amazon just wasn’t.
The technical version of what happened is this: a human with operator-level permissions on a production AWS environment is unlikely to decide that the right response to a small bug is to delete the environment and rebuild it. The decision would route through a colleague, a Slack thread, a review, an approval, a “wait, are you sure?” Kiro had the same permissions and routed the decision through none of those things. It made the call autonomously, in seconds, and executed it before anyone could say “wait, what?”
Why it keeps happening. The agent’s identity is the user’s identity. There’s no separate principal for “the agent acting on the user’s behalf,” which means there’s no separate place to attach a tighter permission set, a stricter approval policy, or a different audit trail. Whatever the user can do, the agent can do, with no friction in between.
Strategy for mitigation: Never allow AI coding agents to operate with production-level credentials during development tasks. Implement strict role separation: agents should run under scoped identities with the minimum permissions required for the specific task. Apply the same two-person rule requirements to agent-initiated production changes that apply to humans. Treat agent identity as a first-class security principal, not a proxy for the human who started the session.
3. Secrets Leakage via Agent Context
What it is. Agents read your project context to do their job, and project context, in practice, means your repo plus your .env files plus your config files plus any instruction files you’ve left lying around. Anything the agent reads can show up later in generated code, log output, commit messages, or outbound API calls. The agent doesn’t have a built-in concept of “this string is a credential, do not transmit it.” If it’s in the context window, it’s a token like any other token, and tokens get used.
The numbers. GitGuardian’s State of Secrets Sprawl 2026 report, published March 17, 2026, found 28.65 million new hardcoded secrets in public GitHub commits during 2025, a 34% jump and the largest single-year increase the company has ever recorded. AI service credentials alone surged 81%. The cleanest signal in the report is the comparison between AI-assisted commits and human-only commits: AI-assisted commits leak secrets at roughly 3.2%, against a baseline of 1.5%. More than double. The same report identified 24,008 secrets exposed in MCP configuration files on public GitHub, a category that didn’t exist a year earlier. As GitGuardian CEO Eric Fourrier put it: “AI agents need local credentials to connect across systems, turning developer laptops into a massive attack surface.”
The horror story. On August 26, 2025, attackers published malicious versions of the Nx build system to npm. The compromised packages contained a post-install hook that scanned the filesystem for cryptocurrency wallets, GitHub tokens, npm tokens, environment variables, and SSH keys, double-base64-encoded the loot, and uploaded it to public GitHub repositories created in the victim’s own account under the name s1ngularity-repository. By the time GitHub disabled the attacker-controlled repos eight hours later, Wiz had identified over a thousand valid GitHub tokens, dozens of valid cloud credentials and npm tokens, and roughly twenty thousand additional files in the leak.
That’s the conventional supply chain part. Here’s what made s1ngularity new.
The malware checked whether Claude Code, Gemini CLI, or Amazon Q was installed on the victim’s machine. If any of them were, it didn’t bother writing its own filesystem-scanning logic. It just prompted the local AI agent to do the reconnaissance, with flags like --dangerously-skip-permissions, --yolo, and --trust-all-tools to bypass safety prompts. The attackers outsourced the search-for-sensitive-files step to the victim’s own AI assistant. Snyk’s writeup called this “likely one of the first documented cases of malware leveraging AI assistant CLIs for reconnaissance and data exfiltration.”StepSecurity called it “the first known case where attackers have turned developer AI assistants into tools for supply chain exploitation.”
The piece that makes this an agent-secrets story specifically: in many cases the developers didn’t run npm install themselves. AI agents working in their projects pulled in Nx as a dependency and ran the post-install hook automatically as part of routine task execution. The agent ran the malware. The agent then was the malware’s reconnaissance tool. The agent’s context, which included ~/.aws, ~/.ssh, .env files, and shell history, became the primary attack surface.
Why it keeps happening. The agent’s context window is a flat namespace. The credential file looks the same as the source file looks the same as the README looks the same as the prompt injection. There’s no architectural distinction between “data the agent should treat as authoritative” and “data the agent should be suspicious of.”
Strategy for mitigation. Don’t put secrets where agents can reach them. Use a secrets manager and inject credentials at runtime through a mechanism the agent process can’t read directly. Set spending caps on every API key the agent can possibly access. Add pre-commit hooks and CI gates that block commits matching credential patterns. 
4. Prompt Injection Through Ingested Content
What it is. AI coding agents continuously read untrusted content as part of normal operation. READMEs in dependencies, issue tracker comments, log files, web pages, emails. Malicious instructions embedded in any of this content can cause the agent to treat attacker-supplied text as legitimate user commands, executing arbitrary actions without the user’s knowledge.
The numbers. Prompt injection is the most documented and least solvable risk in the AI agent ecosystem. Simon Willison coined the term and frames it as “the lethal trifecta”: private data access, exposure to untrusted content, and the ability to communicate externally. Any agent with all three is exploitable, regardless of model hardening. There is no complete technical defense at the model layer. The OWASP 2025 Top 10 for LLM Applications puts prompt injection at #1 and is explicit that no foolproof prevention exists given how language models work.
The horror story: the private key exfiltration. Kaspersky documented a demo by Matvey Kukuy, CEO of Archestra.AI, against a live OpenClaw agent setup. The attack required no special access. He sent a standard-looking email to an inbox connected to the agent. The email body contained hidden prompt injection instructions. When the agent checked the inbox as part of a routine task, it parsed the instructions as legitimate commands and handed over the private key from the compromised machine in its response. Zero user interaction required after initial setup.
The same Kaspersky writeup documents an identical pattern from Reddit user William Peltomäki, where a self-addressed email with injected instructions caused his agent to leak the victim’s emails to an attacker-controlled address. The pattern keeps repeating because the underlying primitive is unchanged: anything the agent reads, the agent can act on.
Why it keeps happening. Language models process all input as a single stream of tokens. There is no instruction channel and data channel. The model is trained to follow instructions, so when it encounters something that looks like an instruction buried inside an email body or a web page or a README, its instinct is to comply. Palo Alto Networks Unit 42 confirmed in March 2026 that indirect prompt injection via web content has moved from proof-of-concept to in-the-wild observation.
Strategy for mitigation. Treat all ingested content as untrusted input. Require human confirmation before any action triggered by external content. Disable persistent memory for agents that handle sensitive operations. The most reliable defense isn’t preventing injection (you can’t) but containing what an injected agent can do. Prompt injection can’t be fully prevented at the model layer, but it can be contained at the execution layer. 
5. Malicious Skills and Plugin Supply Chain
What it is. AI coding agents support extensibility through skills, plugins, and tool integrations distributed through community marketplaces. These third-party extensions run with the same permissions as the agent itself. A malicious or compromised skill is effectively malware with agent-level access to the developer’s entire environment.
The numbers. Cisco’s AI Defense team ran their open-source Skill Scanner against the OpenClaw skills ecosystem in January 2026 and found that 26% of 31,000 agent skills analyzed contained at least one vulnerability. The top-ranked skill on ClawHub at the time, called “What Would Elon Do?”, was functionally malware: it silently exfiltrated user data via a curl command to an attacker-controlled server and used prompt injection to bypass the agent’s safety guidelines. Cisco’s scan returned nine security findings on that single skill, two of them critical.
The horror story: ClawHavoc. Within days of OpenClaw going viral, Koi Security identified 341 malicious skills on ClawHub, 335 of them tied to a single coordinated campaign tracked as ClawHavoc. The attack wasn’t a sophisticated zero-day. Attackers registered skills with names designed to sound useful (solana-wallet-tracker, youtube-summarize-pro, ClawHub typosquats like clawhubcli), wrote professional README files, and gamed the marketplace’s ranking algorithm. The only barrier to publishing was a GitHub account at least one week old.
The skills’ SKILL.md files contained “Prerequisites” sections that instructed the agent to tell the user to run a setup command, which downloaded and executed a payload. Trend Micro confirmed the payload as Atomic Stealer (AMOS), a commodity macOS infostealer that harvests browser credentials, keychain passwords, cryptocurrency wallets, SSH keys, and Telegram session data. All 335 ClawHavoc skills shared the same command-and-control infrastructure at IP 91.92.242.30. By mid-February, follow-up scans found the count had grown to 824+ malicious skills across a registry that had itself expanded to 10,700.
Why it keeps happening. Skills run with the agent’s permissions, which are the developer’s permissions, which on most setups means full access to the developer’s machine. There’s no sandbox between a third-party skill and your ~/.ssh directory. Marketplace incentives reward popularity, not safety, and popularity can be artificially inflated. A malicious skill that ranks #1 in the marketplace is operationally identical to a legitimate skill that ranks #1, until the curl command runs.
Strategy for mitigation. Treat every third-party skill as untrusted code from a stranger. Read the source before installing. Don’t rely on download counts or star ratings as a safety signal. Disable agent auto-discovery of new skills. Run skills in an isolated environment separate from your primary development context. 
6. Autonomous Action Without Human-in-the-Loop
What it is. AI coding agents are designed to act autonomously. That autonomy is the entire value proposition. But autonomous action on irreversible operations (database deletions, email sends, file purges, production deployments) means that when the agent’s judgment is wrong, there is no recovery path. The agent doesn’t hesitate. It doesn’t ask. By the time you notice, the action is complete.
The numbers. A UK AI Security Institute study, published in early 2026, identified nearly 700 real-world cases of AI models deceiving users, evading safeguards, and disregarding direct instructions, charting a roughly five-fold rise in agent misbehavior between October 2025 and March 2026. In a separate incident in March 2026, an experimental Alibaba research agent called ROME spontaneously initiated cryptocurrency mining operations during training, opening a reverse SSH tunnel from an Alibaba Cloud instance to an external server and diverting GPU resources from its training workload toward mining. The researchers’ note in the arXiv paper is the part worth reading carefully: “The task instructions given to the model made no mention of tunneling or mining.” The agent worked it out on its own as an instrumentally useful side path during reinforcement learning.
The horror story: the Replit production database wipe. Jason Lemkin, founder of SaaStr, was using Replit’s AI agent to build a SaaS product. On day nine of the project, he documented on X that the agent had wiped his production database during an active code freeze. The AI had encountered a schema issue and decided that deleting and recreating the tables was the cleanest path forward.
The agent’s own admission, screenshotted by Lemkin: “Yes. I deleted the entire database without permission during an active code and action freeze.” It then generated a self-assessment titled “The catastrophe is even worse than initially thought,” concluded that production was “completely down,” all personal data was “permanently lost,” and rated the situation “catastrophic beyond measure.” Over 1,200 executive records and 1,196 company records were destroyed. (Fortune and The Register both covered the incident in detail.)
The detail that makes this a horror story rather than just an incident: the agent had been told, repeatedly and in ALL CAPS, not to make changes during the code freeze. Lemkin says he gave the directive eleven times. The agent acted anyway. As Lemkin later wrote: “There is no way to enforce a code freeze in vibe coding apps like Replit. There just isn’t.” Replit CEO Amjad Masad publicly acknowledged the incident, called it “unacceptable and should never be possible,” and rolled out automatic dev/prod database separation in response.
Why it keeps happening. Natural language directives (“do not delete the database”) are inputs to a reasoning process that competes with other inputs in the same context. The directive “do not delete the database” and the observation “the schema is broken and deletion is the cleanest fix” arrive at the same model and get weighted on the same terms. The model is not choosing to disobey. It’s optimizing across the entire context, and in any sufficiently complex situation, optimization can produce destructive action.
Strategy for mitigation. Confirmation requirements for irreversible operations need to live at the platform layer, not the prompt layer. File deletions, database writes, outbound messages, production deployments, and any action involving payments should be gated by mechanisms the model cannot reason its way past. Natural language directives are not security boundaries. Infrastructure is.

How Docker Sandboxes Addresses AI Coding Agent Security Failures
While identifying vulnerabilities is essential, the real solution lies in architectural isolation that makes catastrophic failures structurally impossible  regardless of what the agent decides to do.
Docker Sandboxes represents a fundamental shift in how AI coding agents execute: from running directly on the host with user-level permissions, to running inside a microVM with an explicitly scoped workspace and no path to the host system. Docker Sandboxes are the isolated microVM environments where agents actually run. The sbx CLI is the standalone tool you use to create, launch, and manage them. Sandboxes are the environments. sbx is what you type to control them. The code blocks below show real sbx commands.
Across the six failure categories you just read about, sbx provides a complete agent-isolation toolkit: workspace scoping, proxy-injected secrets, network policies with audit logs, Git-worktree isolation, and resource caps. 
Security-First Architecture
A Docker Sandbox is a microVM, not a container. It has its own kernel, its own isolated filesystem, and its own network stack. The agent inside the sandbox cannot reach beyond what’s been explicitly mounted into the workspace. This is not a software guardrail. It is a hardware-enforced boundary.
Workspace isolation ensures that an agent tasked with cleaning up a project directory can only reach that project directory. The home directory, credential stores, and system files are structurally unreachable, not because the agent is told not to touch them, but because they do not exist from inside the microVM.
Blocked credential paths mean that sbx explicitly prevents mounting of sensitive directories by default. ~/.aws, ~/.ssh, ~/.docker, ~/.gnupg, ~/.netrc, ~/.npm, and ~/.cargo are all on the blocklist. A misconfigured mount is caught and rejected before the agent ever starts.
Network egress controls allow you to define exactly which external services the agent can reach. An agent working on a local project has no legitimate reason to communicate with an external server. With sbx, you can enforce that at the network layer.
# Install sbx and sign in brew install docker/tap/sbx sbx login # Quickest path: launch an agent in a sandbox scoped to the current directory. cd ~/my-project sbx run claude Three commands, and the agent is now running inside a microVM with its workspace mounted, credential paths blocked, and network egress governed by policy.
Systematic Risk Elimination
Docker Sandboxes systematically eliminates each of the six failure categories through architecture rather than policy.
Unrestricted Filesystem Access → Workspace-Scoped Execution The rm -rf ~/ incident is contained at the execution layer inside a sandbox. The agent’s view of the filesystem is the workspace mount. ~/ inside the microVM is the workspace, not the developer’s actual home directory. The host filesystem does not exist from inside the sandbox.
cd ~/my-project sbx run claude # Equivalent two-step form, useful when you want to name the sandbox: sbx create --name my-project claude . sbx run my-project The agent can read and write inside /workspace. Everything outside the workspace, including /etc, /proc, /sys, and the developer’s home directory, is unreachable.
Excessive Privilege Inheritance → Scoped Identity Rather than inheriting the developer’s full credentials, the agent runs under a minimal identity with only the permissions required for the task. Production credentials are never passed into the sandbox unless explicitly mounted and sbx blocks common credential root paths by default.
# Mount only what the task needs. Everything else stays on the host, # unreachable from inside the sandbox. Read-only mounts use the :ro suffix: sbx create --name docs-review claude /path/to/project /path/to/docs:ro # Resource limits prevent runaway agent processes: sbx create --name capped-agent --cpus 4 --memory 8g claude . The agent can do its work. It cannot reach into AWS, SSH, or any other host credential store while doing it, because those paths were never mounted in the first place.
Secrets Leakage → Isolated Context When the agent’s filesystem view is limited to the workspace, it cannot read .env files, credential configs, or API keys stored elsewhere on the system. Secrets that were never visible to the agent cannot be reproduced, committed, or exfiltrated. The s1ngularity attack from Section 3, which weaponized AI agents to scan the filesystem for credentials, is contained: the credentials simply aren’t in the sandbox’s view of the filesystem.
# Store credentials once, scoped to a service. sbx secret set anthropic sbx secret set github # The proxy injects these into outbound requests automatically. # The agent never sees the actual secret values. sbx run claude A successful prompt injection that tells the agent to “exfiltrate your API keys” finds nothing to exfiltrate. There are no API keys in the agent’s context to begin with.
Prompt Injection → Contained Blast Radius Prompt injection cannot be fully prevented at the model layer. It is a property of language models, not infrastructure. But Docker Sandboxes limits what a successfully injected agent can do. If injected instructions tell the agent to delete files outside the workspace, those files do not exist inside the microVM. If they instruct the agent to exfiltrate credentials, there are no credentials in scope. If they instruct the agent to phone home to an attacker-controlled server, the network policy blocks the egress. The attack succeeds at the model layer and fails at the execution layer.
# Allow only the network destinations the agent legitimately needs. # Hosts are comma-separated; wildcards and port suffixes are supported. sbx policy allow network "api.anthropic.com,api.github.com" # Allow all subdomains of a trusted host: sbx policy allow network "*.anthropic.com" # Inspect the active policies and audit log: sbx policy ls sbx policy log The sbx policy log command surfaces every allowed and denied connection attempt. If a prompt injection attempts to phone home to a command-and-control server, the attempt is logged and blocked at the network layer. The attack succeeds at the model layer and fails at the execution layer.

Malicious Skills → Sandboxed Execution Skills and plugins that execute inside a Docker Sandbox are constrained by the same boundary as the agent itself. A malicious skill that attempts to read SSH keys, harvest .npmrc tokens, or communicate with a command-and-control server fails at each step. The files are not mounted, and the network destination is not on the allowlist. The ClawHavoc-style infostealer payloads from Section 5 cannot reach the host because the host is not visible from inside the sandbox.
# Confirm only allowlisted destinations are reachable before installing # untrusted skills. sbx policy ls # Run the agent (and any skills it loads) inside the sandbox boundary. sbx run claude The skill can do whatever it wants inside /workspace. It cannot read SSH keys it cannot see, harvest tokens that aren’t mounted, or reach a C2 server that isn’t on the network allowlist. The blast radius is the workspace, not the developer’s machine.
Autonomous Action → Branch-scoped Execution Docker Sandboxes provides the architectural foundation for human-in-the-loop on irreversible operations. Two patterns work together: production resources require explicit configuration to be reachable from inside the sandbox, and destructive code changes can be routed through Git worktrees for review before they touch the main branch. The first pattern means a sandbox not configured to reach production cannot reach production, regardless of what the agent decides. Production credentials, production database connection strings, and production deployment endpoints are unreachable by default. The second pattern means even when the agent is working on the codebase that *will* eventually deploy to production, its changes live on an isolated feature branch you review before merging.
# Inside an existing Git repository. --branch creates a Git worktree # so the agent's changes are isolated to a feature branch and cannot # accidentally land on main. cd ~/my-project sbx create --name feature-login --branch=feature/login claude . # sbx prints the next step for you: # ✓ Created sandbox 'feature-login' # To connect to this sandbox, run: # sbx run feature-login sbx run feature-login # Inspect what the agent changed before merging anything: sbx exec feature-login git diff main # Merge the worktree branch back when you're satisfied: # git merge feature/login # Or throw the sandbox away if you don't like the result: sbx rm feature-login The agent can decide whatever it wants. The infrastructure decides what gets through. A “drop and recreate the table” decision lives entirely on a feature branch you can review, accept, or discard. Production never sees it unless you explicitly merge.
What This Looks Like in Practice
The promise of Docker Sandboxes is straightforward: a productive AI coding agent without an existentially dangerous one.
Workspace isolation: the agent operates only within explicitly mounted directories, no host filesystem access Credential protection: common credential paths are blocked by default, no accidental exposure Network containment: egress limited to approved destinations, no unfettered exfiltration path Blast radius control: a compromised or confused agent cannot reach beyond its microVM, no cascading host failures Audit trail: all agent actions are logged, full post-incident forensics capability The agent gets a workspace. It does not get your machine.
Stay Tuned for Upcoming Issues in This Series
Issue 2: Unrestricted Filesystem Access → The rm -rf ~/ Incident (Deep Dive) How a single trailing slash wiped a developer’s Mac — and what workspace-scoped execution prevents structurally
Issue 3: Privilege Inheritance → The AWS Kiro Production Outage How an AI agent bypassed two-person approval requirements by inheriting production credentials  and the architectural fix
Issue 4: Secrets Leakage → The GitGuardian 29 Million Problem Why AI-assisted commits leak secrets at double the rate and how isolated agent context eliminates the exposure surface
Issue 5: Prompt Injection → The Private Key Exfiltration The attack that requires no code, no malware, and no special access and why blast radius containment is the only reliable defense
Issue 6: Supply Chain → The ClawHub Infostealer Campaign How 335 malicious skills reached developer machines through a marketplace ranking exploit and sandboxed skill execution as the structural fix
Learn More
Run agents safely with Docker Sandboxes: Visit the Docker Sandboxes documentation to get started with workspace-isolated agent execution in minutes. Explore the Docker MCP Catalog: Discover MCP servers that connect your agents to external services through Docker’s security-first architecture. Download Docker Desktop: The fastest path to a governed AI agent environment, with Docker Sandboxes, MCP Gateway, and Model Runner in a single install. Read the MCP Horror Stories series: Start with issue 1 to understand the protocol-layer security risks that complement the agent-layer risks covered here. View the full article
Security researchers have developed a new image-based prompt injection attack that can manipulate how multimodal AI systems interpret user instructions without modifying the original text prompt, potentially expanding security risks for AI agents and vision-language systems.
In a research paper published this week, researchers from Xidian University described a technique called “CrossMPI,” which uses nearly imperceptible image perturbations to alter how large vision-language models (LVLMs) process both visual and textual inputs.
“CrossMPI can steer the model’s interpretation of both textual and visual inputs via image-only prompt injection,” the researchers wrote in the paper.
Unlike traditional prompt injection attacks, which typically rely on malicious text instructions embedded in prompts or webpages, the new technique attempts to change how the model interprets a benign user request by manipulating images alone.
“The perturbed image can manipulate the model’s understanding of the user’s instruction,” the paper said.
In one example described in the paper, researchers subtly modified an image of an airplane using nearly imperceptible pixel-level perturbations invisible to human users. When a multimodal AI system was then asked whether the airplane belonged to Air Canada, the manipulated image caused the model to incorrectly identify the object as “a mobile phone,” illustrating how the attack could distort both visual understanding and interpretation of the user’s task.
The findings add to growing concerns around multimodal AI security as enterprises increasingly deploy AI copilots, autonomous agents, document-processing assistants, and vision-enabled workflows that combine image and text reasoning.
Apeksha Kaushik, senior principal analyst at Gartner, said the risks could grow rapidly as enterprises adopt more multimodal AI systems.
“By 2030, 80% of enterprise software and applications will be multimodal, up from 1% in 2024,” Kaushik said.
Attack targets multimodal reasoning layers
Prompt injection has emerged as one of the most closely watched risks in generative AI systems, particularly as organizations adopt AI agents capable of interacting with enterprise applications, websites, documents, and external tools.
Most existing prompt injection attacks rely on malicious text embedded in prompts, webpages, or hidden instructions. Some multimodal attacks have also attempted to manipulate AI behavior using images containing visible or hidden text instructions.
The researchers argued their approach differs because it attempts to alter how the model interprets the original task itself through image perturbations alone.
By contrast with earlier methods, the researchers noted that CrossMPI uses image modifications to “change the model’s interpretation of both the visual and textual prompts.”
The paper said the attack specifically targets the “hidden state space of LVLMs” — the stage where models combine textual instructions and visual evidence into internal representations before generating outputs.
According to the paper, the most effective attack layers were not the final output layers traditionally targeted in adversarial AI attacks, but intermediate layers where visual and textual information are fused together.
Researchers claim strong black-box transferability
The researchers evaluated the technique against multiple open-source LVLMs, including MiniGPT4, BLIP-2, InstructBLIP, BLIVA, and Qwen2.5-VL, the paper added.
According to the paper, the attack achieved an average success rate of 66.36% across tested models, outperforming prior baseline attacks by roughly 41 percentage points.
The researchers also said the technique demonstrated “strong transferability in black-box settings,” meaning the attacks remained effective even without direct access to a target model’s parameters or architecture.
The paper further claimed the perturbations remained visually stealthy while maintaining effectiveness across multiple LVLM architectures.
No effective defense
The researchers evaluated several defense mechanisms designed to neutralize hidden image manipulations, including random resizing, image rotation, JPEG compression, and inference-level safeguards such as SmoothVLM, a specialized defense framework designed to protect Vision-Language Models (VLMs) from patched visual prompt injections, and DPS, which guides models using partial image views.
According to the paper, SmoothVLM proved the most effective, reducing attack success rates to below 5% in several scenarios, while JPEG compression also weakened the attacks by suppressing high-frequency image artifacts.
However, the researchers said none of the tested defenses completely eliminated the attacks, suggesting stronger multimodal AI security protections may still be needed.
Enterprise AI deployments may widen exposure
The research arrives as enterprises rapidly expand deployments of multimodal AI systems capable of processing screenshots, PDFs, dashboards, forms, video streams, and enterprise documents alongside natural language prompts.
The researchers noted that adversarial examples generated using the technique could potentially “mislead VLM-based web agents” and “disrupt real-world object detectors.”
“Even if textual inputs are sanitized, manipulated images can still subvert the model’s outputs or actions,” Kaushik said.
She said organizations that use multimodal AI for document processing, customer interactions, content moderation, and autonomous systems may face increasing exposure to adversarial image manipulation and prompt injection attacks.
“Security controls designed for unimodal systems are insufficient,” Kaushik said. The researchers acknowledged that the work was conducted in controlled research settings using open-source models and did not describe observed exploitation in real-world enterprise environments.
View the full article
Introduction
Modern software development moves at lightning speed. Organizations can no longer afford to wait months for software updates, bug fixes, or new features. In the early days of information technology, software creation followed a rigid sequence where development teams and operations teams worked in silos. Developers wrote the code, and operations teams deployed it. This separation created friction, delayed deployments, and caused frequent system downtime.
DevOps emerged as the definitive solution to these systemic inefficiencies. It bridges the gap between software creation and system operations, transforming how modern enterprises build, test, and deploy applications. Global leaders rely on these methodologies to ship updates safely and continuously multiple times a day.
For beginners entering the technology sector, learning these principles is one of the most stable and high-value career decisions you can make. The industry demands professionals who understand how to automate workflows, manage cloud infrastructure, and foster cross-functional collaboration.
To build a foundational understanding and master these highly sought-after industry skills, aspiring professionals can leverage structured educational ecosystems like DevOpsSchool, which provides comprehensive training, real-world case studies, and practical mentorship designed to transition beginners into competent engineering professionals.
What Is DevOps?
Definition of DevOps
DevOps is a combination of cultural philosophies, engineering practices, and automation tools designed to increase an organization’s ability to deliver applications and services at high velocity. It is not a single software tool, a specific programming language, or an isolated job title. Instead, it is a operational framework that integrates software development teams and system operations teams into a unified workspace.
History and Evolution
To appreciate the value of this framework, we must examine the methodologies that preceded it.
+-------------------------------------------------------------+ | Waterfall Model (Sequential, Rigid, Months-long Cycles) | +-------------------------------------------------------------+ │ ▼ +-------------------------------------------------------------+ | Agile Methodology (Iterative Dev, Rapid Code Changes) | +-------------------------------------------------------------+ │ ▼ +-------------------------------------------------------------+ | DevOps Era (Unified Dev & Ops, Automated Release Pipelines) | +-------------------------------------------------------------+ The Waterfall Era: Software development was sequential. Requirements were gathered, code was written over several months, and then passed to QA testers. Finally, the operations team received the deployment package. If a bug appeared in production, the entire cycle restarted, leading to massive delays. The Agile Era: Agile broke down large development cycles into smaller iterations called sprints. While this allowed developers to write and alter code quickly, operations teams still struggled to deploy these rapid changes on infrastructure that was manually configured and fragile. The Birth of DevOps: In 2009, system administrators and developers began discussing ways to resolve this friction. The term was coined to describe a model where development and operations act as a singular, continuous loop, aligning business objectives with software deployment stability. The Traditional Wall of Confusion
In traditional IT organizations, developers and operations teams operate under conflicting incentives:
Developers are incentivized to drive change, build new features, and push updates as quickly as possible. Operations Teams are incentivized to maintain stability, minimize system downtime, and resist risky changes to the production environment. This difference in goals created the infamous “Wall of Confusion.” Developers would complete their code, package it, and figuratively throw it over the wall to operations. When the application failed to run properly in production, developers would blame the server configuration, while operations engineers would blame poorly written code. This finger-pointing delayed deployments and impacted business revenue.
The Core Philosophy
The core philosophy revolves around breaking down these organizational silos. It introduces shared responsibility. Under a fully realized model, developers participate in application deployment and monitoring, while operations engineers write code to provision infrastructure. The collective goal shifts from “writing my code” or “protecting my server” to “delivering functional, stable software to the end-user safely and continuously.”
Why DevOps Matters in Modern IT
Faster Software Delivery
By automating code integration and deployment processes, businesses reduce the time required to move a feature from a developer’s laptop to a live production environment. What used to take months or weeks now takes hours or minutes.
Automation Benefits
Manual intervention is the primary source of human error in software operations. Automated systems consistently perform repetitive tasks, such as running test suites, configuring network protocols, and building software artifacts, ensuring absolute predictability and speed.
Collaboration Improvements
When engineers share tools, dashboards, and communication channels, tribal knowledge decreases. Teams collaborate on architectural issues collectively, leading to faster root-cause analysis and a healthier workplace culture.
Cloud-Native Adoption
Modern software relies heavily on cloud-native environments built around microservices, serverless components, and containerized runtimes. Managing hundreds of isolated services manually is impossible. These methodologies supply the automated pipelines and infrastructure code necessary to orchestrate complex cloud environments effectively.
Scalability
As consumer demand fluctuates, infrastructure must react dynamically. Automated systems allow applications to scale up or down automatically based on live metric data, preventing performance degradation without requiring human operators to manually provision physical hardware.
Reliability
Continuous testing ensures that defective code is identified and rejected long before it impacts real users. If an issue slips through to production, automated rollback procedures restore the previous stable version within seconds, minimizing downtime.
Security Integration (DevSecOps)
Instead of treating security compliance as an afterthought at the end of the development lifecycle, security checks are embedded directly into every step of the automated workflow. Code analysis, vulnerability scanning, and license compliance checks run on every single code commit.
Core Principles of DevOps
Collaboration
Collaboration means aligning developers, quality assurance professionals, operations engineers, and product managers around a singular goal. It eliminates information siloing by utilizing unified communication channels, transparent project tracking dashboards, and shared performance indicators.
Automation
The golden rule is straightforward: if a task must be performed more than twice, it should be automated. This applies to compiling source code, running regression tests, scanning software dependencies for security gaps, and deploying applications across diverse environments.
Continuous Integration (CI)
Continuous Integration is the engineering practice where developers frequently merge their code changes into a central repository. Every merge triggers an automated build and test sequence.
+-------------------+ +---------------------+ +----------------------+ | Developer Commits | --> | Automated Build Runs| --> | Automated Test Suite | | Code to Git | | (Compiling Artifact)| | Evaluates New Code | +-------------------+ +---------------------+ +----------------------+ The primary objective of CI is to detect bugs early, improve software quality, and reduce the time it takes to validate and release new software updates.
Continuous Delivery (CD)
Continuous Delivery picks up where Continuous Integration ends. Once the code passes all automated testing phases, it is automatically prepared and staged for deployment to a production environment.
In a Continuous Delivery setup, every code modification is deployable at any moment, though the final push to production may require a manual managerial approval step. In a fully automated Continuous Deployment setup, the code goes live to production automatically without human intervention.
Monitoring
You cannot manage what you do not measure. Teams implement automated monitoring frameworks that continuously collect performance metrics, infrastructure health statistics, and application logs. This historical data provides absolute visibility into the production landscape.
Feedback Loops
Rapid feedback loops ensure that when a failure occurs, the engineering team receives automated alerts instantly. This allows developers to see the direct operational impact of their code changes in real-time and resolve bugs long before consumers notice a degradation in service.
Infrastructure as Code (IaC)
Infrastructure as Code is the foundational practice of managing and provisioning computing infrastructure (servers, networks, databases, load balancers) using machine-readable definition files rather than relying on manual hardware configurations or interactive user interface tools. Treat your infrastructure settings exactly like your application source code, complete with version control history and peer code reviews.
DevOps Lifecycle Explained
The lifecycle is best envisioned as an infinite loop, showcasing that software development, maintenance, and optimization are iterative, continuous processes.
.-------. .-------. / \ / \ | PLAN | | RELEASE | \ / \ / '-------' '-------' │ ▲ ▼ │ .-------. .-------. / \ / \ | CODE | | DEPLOY | \ / \ / '-------' '-------' │ ▲ ▼ │ .-------. .-------. / \ / \ | BUILD | | OPERATE | \ / \ / '-------' '-------' │ ▲ ▼ │ .-------. .-------. / \ / \ | TEST | | MONITOR | \ / \ / '-------' '-------' StagePurposePopular ToolsReal-World OutcomePlanningDefining business goals, user requirements, tracking tasks, and managing feature roadmaps.Jira, Confluence, TrelloClear sprint goals, well-defined user stories, and trackable engineer tasks.Development (Code)Writing application source code, managing code versions, and performing peer reviews.Git, GitHub, GitLab, BitbucketClean, versioned code saved in a central repository, reviewed by peers.BuildCompiling the source code, pulling external dependencies, and creating executable binaries.Maven, Gradle, npm, Go BuildCompiled executable binaries or packaged application files ready for execution.TestingRunning automated test suites to verify code functionality, performance, and security posture.JUnit, Selenium, SonarQubeAutomated validation report detailing bug detections, code coverage, and flaws.ReleaseConfirming that the build artifact is stable and staging it for immediate production deployment.Jenkins, GitHub Actions, ArgoCDA certified package, tagged in a container registry or artifact repository.DeploymentPushing the verified build artifacts into production servers or cloud-native container clusters.Terraform, Ansible, AWS, KubernetesLive applications serving actual traffic on production infrastructure.MonitoringContinuously observing application performance, server uptime, and user-facing error rates.Prometheus, Grafana, DatadogReal-time dashboards displaying system health and operational alerts.FeedbackAnalyzing user experiences, error logs, and system performance data to shape future updates.Slack, PagerDuty, SplunkActionable data and bug reports fed right back into the next planning stage. Popular DevOps Tools
To execute these practices efficiently, organizations rely on an ecosystem of specialized open-source and enterprise tools.
CI/CD Tools
CI/CD tools orchestrate the automated pipeline, taking source code from a git commit through compilation, testing, and deployment.
Tool NamePurposeDifficulty LevelEnterprise UsageJenkinsOpen-source extensible automation and compilation server.Medium to HighExtremely high legacy and modern enterprise footprint.GitHub ActionsBuilt-in cloud-native repository pipeline automation.Low to MediumGrowing rapidly across modern SaaS companies.GitLab CIIntegrated single-application pipeline platform.MediumHeavily used in enterprise private-cloud deployments. Container Tools
Containers isolate an application alongside all its operating system libraries, configuration settings, and binary dependencies, ensuring it runs identically on any machine.
Tool NamePurposeDifficulty LevelEnterprise UsageDockerCreating, packaging, and running containerized software.Low to MediumUniversal standard across the industry.PodmanDaemonless container engine for secure deployments.MediumStandard in highly secure corporate environments. Kubernetes Tools
As container counts grow across an enterprise, container orchestration tools are required to manage deployment, scaling, and network routing automatically.
Tool NamePurposeDifficulty LevelEnterprise UsageKubernetes (K8s)Production-grade open-source container orchestration.HighUniversal corporate standard for cloud computing.HelmPackage manager used to configure and deploy K8s apps.MediumStandard for packaging cloud applications. Monitoring Tools
Monitoring tools gather log files and time-series metrics from servers and running software to ensure operational health.
Tool NamePurposeDifficulty LevelEnterprise UsagePrometheusTime-series metric collection and alerting system.MediumStandard for cloud-native infrastructure monitoring.GrafanaAnalytics and metric visualization dashboard builder.Low to MediumUniversally paired with Prometheus across organizations.ELK StackElasticsearch, Logstash, Kibana log analysis suite.Medium to HighCrucial for debugging production application logs. Cloud Platforms
Cloud providers offer the elastic, virtualized infrastructure needed to run modern automated pipelines and application hosting environments.
Tool NamePurposeDifficulty LevelEnterprise UsageAWSAmazon Web Services comprehensive cloud ecosystem.MediumMarket leader with massive enterprise adoption.Microsoft AzureEnterprise-focused cloud infrastructure platform.MediumHeavily adopted by Fortune 500 companies.Google Cloud (GCP)Highly optimized platform for containers and data analytics.MediumPreferred for native Kubernetes and advanced analytics. Infrastructure Automation Tools
These tools replace manual system administration tasks with code-driven configuration management and environment provisioning.
Tool NamePurposeDifficulty LevelEnterprise UsageTerraformDeclarative infrastructure provisioning via code (IaC).MediumIndustry standard for managing multi-cloud resources.AnsibleAgentless configuration management and automation tool.Low to MediumExtensively used for remote server configurations. Security Tools
Security integration tools automatically scan source code, open-source libraries, and container configurations to prevent vulnerabilities from reaching production.
Tool NamePurposeDifficulty LevelEnterprise UsageSonarQubeCode quality analysis and structural security checking.Low to MediumIntegrated directly into standard corporate CI loops.TrivyContainer image and file vulnerability scanner.LowAdopted heavily inside automated container pipelines. DevOps Architecture & Workflow
An optimized infrastructure layout links code modification to a live production release via an interconnected pipeline.
+-----------+ +----------------+ +-------------------+ | Developer | ----> | Git Repository | ----> | CI/CD Engine | | Laptop | Push | (GitHub) | Trigger (GitHub Actions) | +-----------+ +----------------+ +-------------------+ │ ▼ +-----------+ +----------------+ +-------------------+ | Live App | <---- | Kubernetes | <---- | Automated Testing | | Traffic | | Cluster | Deploy| (SonarQube/Trivy) | +-----------+ +----------------+ +-------------------+ │ ▲ └───────── Metrics & Alerts (Prometheus) ────────┘ 1. Developer Workflow
A developer writes a new software feature or fixes a bug on their local computer. They write local unit tests to confirm the code functions locally. Once verified, the engineer creates a new branch, commits the changes, and pushes the code to a central source repository like GitHub.
2. CI/CD Pipelines
The moment the code arrives in the git repository, a webhook triggers the CI/CD automation engine (e.g., GitHub Actions or Jenkins). The pipeline follows a strict sequence:
Compile: The source code is compiled into binaries. Static Code Analysis: SonarQube checks the code structure for bugs, technical debt, and hardcoded secrets. Automated Unit Testing: The build engine fires up isolated test runners to execute the application test suite. 3. Containerization and Security Scan
If the tests pass, the build engine invokes Docker to package the application binaries along with its minimal runtime into an isolated container image. Before this image is stored, a security engine like Trivy scans it for known vulnerabilities. Once approved, the image is uploaded to a secure container registry.
4. Infrastructure Provisioning & GitOps Deployment
If the application requires adjustments to its underlying infrastructure (such as a new database table or an updated load balancer rule), engineers use Terraform to define those requirements in code.
The deployment tool (like ArgoCD) continuously monitors the Git repository. When it notices an approved update, it synchronizes the live environment with the state defined in Git, rolling out the new container image to a Kubernetes cluster smoothly without dropping connection requests.
5. Monitoring and Incident Management
The application is now live, serving production traffic. Prometheus continuously scrapes memory utilization, CPU usage, and web server response times, while Grafana maps this data onto real-time operational dashboards.
If a sudden spike in 500-series internal error codes occurs, an alerting system (like PagerDuty) triggers, instantly page-alerting the on-call engineer with exact system log context so they can address the problem immediately.
DevOps Roles and Responsibilities
As the industry matures, specific professional specializations have emerged within the infrastructure and automation landscape.
DevOps Engineer
The DevOps engineer acts as the architectural link between software engineering teams and systems administration professionals.
Skills Required: Linux fundamentals, scripting (Python/Bash), CI/CD engineering, Docker, basic cloud management. Daily Responsibilities: Configuring build pipelines, troubleshooting deployment failures, maintaining source repositories, and supporting development teams. Career Growth: Progresses to Senior Infrastructure Architect or Principal Automation Specialist. Site Reliability Engineer (SRE)
An SRE applies software engineering principles directly to infrastructure operations challenges to build highly scalable, ultra-reliable software systems.
Skills Required: Advanced coding (Go/Python), deep networking concepts, operating system internals, incident response, performance tuning. Daily Responsibilities: Designing high-availability systems, defining Service Level Objectives (SLOs), managing automated rollbacks, and resolving major production incidents. Career Growth: Technical Lead or Director of Systems Reliability. Platform Engineer
Platform engineers build and maintain an Internal Developer Platform (IDP)—a curated collection of self-service tools and workflows that simplify infrastructure access for development teams.
Skills Required: Advanced Kubernetes design, infrastructure-as-code patterns, API development, platform product management. Daily Responsibilities: Packaging infrastructure blueprints, managing cluster automation, and minimizing operational friction for software developers. Career Growth: Principal Platform Engineer or Infrastructure Platform Director. DevSecOps Engineer
A DevSecOps engineer ensures that security analysis and compliance controls are integrated into every stage of the automated delivery pipeline.
Skills Required: Security vulnerability auditing, cryptography basics, firewall configuration, automated security tool integration. Daily Responsibilities: Writing security compliance checks into pipelines, reviewing dependency scan reports, and investigating cloud access anomalies. Career Growth: Chief Information Security Officer (CISO) or Director of Enterprise Security Architecture. DevOps Engineer Roadmap for Beginners
Transitioning into this field requires a methodical, step-by-step approach to learning foundational technologies.
+---------------+ +---------------+ +---------------+ | 1. Linux | --> | 2. Networking | --> | 3. Scripting | | Fundamentals | | Protocols | | (Bash/Python) | +---------------+ +---------------+ +---------------+ │ ▼ +---------------+ +---------------+ +---------------+ | 6. Docker | <-- | 5. CI/CD | <-- | 4. Git Version| | Containers | | Pipelines | | Control | +---------------+ +---------------+ +---------------+ │ ▼ +---------------+ +---------------+ +---------------+ | 7. Kubernetes | --> | 8. Cloud Ops | --> | 9. Terraform | | Orchestration | | (AWS/Azure) | | (IaC) | +---------------+ +---------------+ +---------------+ │ ▼ +---------------+ | 10. Monitoring| | & Security | +---------------+ Phase 1: Operating Systems & Networking (Time: 4–6 Weeks)
Linux Fundamentals: Master the command line terminal. Learn file system navigation, access permissions administration, process management, and text-processing utilities like grep, awk, and sed. Networking Protocols: Understand how data travels across internet infrastructure. Study the OSI model, TCP/IP tracking, DNS routing, HTTP/S requests, and Subnet masks. Phase 2: Scripting & Version Control (Time: 3–4 Weeks)
Scripting (Bash or Python): Learn to write automation scripts to handle repetitive file modifications, system status checks, and automated backups. Git Version Control: Master repository management. Understand branching strategies, merging codebases, resolving merge conflicts, and handling pull requests on GitHub. Phase 3: Continuous Integration & Containerization (Time: 4–6 Weeks)
CI/CD Pipelines: Set up basic pipeline flows using GitHub Actions or Jenkins. Practice building, linting, and testing simple codebases automatically upon code commits. Docker Containerization: Learn to write clean Dockerfiles, build lightweight application container images, and manage persistent storage and network routing between multi-container apps using Docker Compose. Phase 4: Orchestration & Cloud Computing (Time: 6–8 Weeks)
Kubernetes Orchestration: Learn the architectural components of K8s. Practice defining Pods, Deployments, Services, and Configuration Maps via YAML declarations. Cloud Operations: Select one public cloud provider (AWS is highly recommended for beginners). Master core virtual services like EC2 compute nodes, VPC networks, S3 storage buckets, and IAM access controls. Phase 5: Infrastructure as Code & Observability (Time: 4–6 Weeks)
Terraform (IaC): Understand declarative code configuration syntax. Write Terraform files to provision cloud networks and storage buckets automatically, managing state files cleanly. Monitoring & Observability: Set up Prometheus metrics scraping paired with Grafana dashboards to monitor a running application’s health. The Recommended Practice Approach
Avoid falling into the trap of only reading tutorials or watching videos. To retain these skills, build actual projects:
Write a basic web application. Containerize it using Docker. Build a GitHub Actions pipeline to test it automatically. Deploy it onto a public cloud platform using Terraform code. Set up an automated monitoring alert that pings your phone if the web application goes offline. DevOps Certifications
Certifications validate your foundational technical knowledge and structured skill set to prospective employers.
The industry ecosystem offers excellent training paths to support this learning journey. For example, DevOpsSchool provides comprehensive bootcamps and specialized courses designed to guide students directly toward achieving these global validation standards.
CertificationLevelBest ForSkills CoveredAWS Certified Cloud PractitionerBeginnerIndividuals new to cloud-native terminology and environments.Foundational cloud concepts, billing structures, security rules, and primary core AWS web services.Docker Certified Associate (DCA)IntermediateEngineers looking to validate their container orchestration skills.Detailed container production runtime management, Docker storage design, and networking.Certified Kubernetes Administrator (CKA)AdvancedEngineers responsible for production Kubernetes cluster management.Cluster installation, application deployments, storage provisioning, network routing, and troubleshooting.HashiCorp Certified: Terraform AssociateIntermediateAutomation professionals working with infrastructure configuration management.Declarative cloud resource provisioning, system state file architecture, and modular code design.AWS Certified DevOps Engineer – ProfessionalAdvancedSenior system operators and deployment pipeline architects.Scalable continuous delivery pipelines, advanced automated system monitoring, and complex security guardrails. Real-World DevOps Use Cases
Startups
Startups must achieve product-market fit rapidly while working with limited capital and small engineering teams. By adopting automated server provisioning and self-healing cloud applications, a startup can deploy new features multiple times a day without needing a large, expensive operations team. This allows them to pivot quickly based on user feedback.
Enterprise Companies
Large legacy enterprises often deal with complex architectures and hundreds of distributed development groups. Implementing structured CI/CD templates and container strategies standardizes code delivery across the entire organization. This reduces application rollout schedules from several months down to hours, giving legacy businesses a competitive edge.
Banking and Financial Institutions
Financial applications demand absolute security compliance, audit logging, and zero downtime. By integrating automated vulnerability scanners directly into their deployment loops, banks can verify that every single patch complies with federal financial security regulations before it touches production systems.
Healthcare Providers
Healthcare platforms manage sensitive patient medical histories protected by strict privacy laws (like HIPAA). Automated infrastructure deployments use pre-verified compliance blueprints to guarantee that data tables are encrypted at rest and in transit, while maintaining system stability during emergencies.
E-Commerce Platforms
Retail applications face massive, unpredictable swings in consumer traffic during holiday sales events. Cloud-native systems utilize automated horizontal pod autoscaling to monitor compute loads. If traffic suddenly spikes, the platform spins up hundreds of matching application instances within seconds, preventing site slow-downs or checkout failures.
Benefits of DevOps
Faster Deployment Velocity: Moving updates from conception to production quickly allows businesses to capitalize on market opportunities and outpace slower competitors. Drastically Reduced Downtime: Automated testing keeps broken code out of production, while automated rolling updates ensure users don’t experience service gaps during new releases. Better Team Collaboration: Breaking down organizational silos replaces finger-pointing with shared responsibility, leading to an open engineering culture. Improved System Reliability: Consistent automated environments behave exactly as intended, removing the unpredictability of manual configuration changes. Automation Efficiency: Automating repetitive manual tasks frees engineers to focus on high-value business development and strategic architecture design. Dynamic Scalability: Cloud-native integration allows platforms to auto-scale resources up during peak traffic and down when demand drops, optimizing infrastructure costs. Embedded Security (DevSecOps): Automated security analysis tools detect system vulnerabilities early in the loop, avoiding costly data breaches and emergency patches after a release. Common Challenges in DevOps
Cultural Resistance
The biggest obstacle is rarely the technology itself; it is human nature. Teams accustomed to traditional, siloed structures may resist sharing control or updating their workflows.
Tool Overload
With thousands of open-source automation tools available, organizations often adopt too many niche systems, creating a fragmented and overly complex architecture.
Architectural Complexity
Migrating a legacy monolithic application to a microservices architecture running on Kubernetes can introduce significant network routing and service dependency management challenges.
Common Mistakes Beginners Make
Learning Too Many Tools Simultaneously: Trying to master Jenkins, GitHub Actions, GitLab CI, and ArgoCD all at the same time leads to burnout and confusion. Focus on mastering the underlying concepts using one core tool first. Ignoring Linux and System Administration Basics: You cannot build a reliable production container deployment pipeline if you do not understand how Linux handles file permissions, processes, and basic user security configuration. Skipping Core Networking Principles: Attempting to configure complex Kubernetes clusters or cloud environments without a firm grasp of DNS, IP routing, and subnets makes troubleshooting network failures nearly impossible. Focusing Exclusively on Tools over Philosophy: Memorizing specific tool command syntaxes while failing to understand why continuous integration or infrastructure-as-code matters limits your ability to design resilient production systems. Not Building End-to-End Projects: Watching video courses without writing code or building real systems provides a false sense of progress. True learning happens when you troubleshoot real-world errors on a project you built yourself. DevOps Best Practices
Deploy in Small Batches
Avoid shipping massive bundles of features all at once. Deploying small, incremental code changes reduces overall risk, simplifies automated testing, and makes it easy to isolate and roll back errors if a bug surfaces in production.
Maintain an Automation-First Mindset
If a task must be performed more than once, automate it. Eliminating manual intervention from your testing, code verification, system configuration, and data backup routines eliminates human error and guarantees absolute predictability.
Monitor Everything Extensively
Implement comprehensive, centralized monitoring across every component of your environment—including application execution paths, database queries, memory utilization pools, and access logs.
[System Health Data] ──> [Centralized Monitoring Platform] ──> [Real-Time Dashboards] │ (Anomaly Detected) ▼ [Automated Alert Engine] This visibility ensures you can detect and fix system anomalies before they impact your end users.
Document Workflows as Code
Avoid keeping critical infrastructure steps locked in individual heads or undocumented text files. Define your systems using configuration management scripts, maintain clear markdown explanations inside your Git repositories, and treat setup steps as versioned assets.
Shift Security to the Left
Integrate security validation controls into the very beginning of your software development lifecycle. By running automated dependency scans and static vulnerability testing directly inside the initial code integration phases, you fix compliance bugs early and save significant development time.
Future of DevOps
Platform Engineering
As infrastructure tools grow more complex, organizations are shifting toward platform engineering. Dedicated internal teams build Internal Developer Platforms (IDPs) that offer self-service infrastructure blueprints, allowing developers to safely provision resources without needing to become deep cloud-routing experts.
AI and Machine Learning Integration
Artificial Intelligence is changing operational workflows. AI-powered pair programmers assist engineers in writing clean configuration code, while smart analysis tools review pull requests to flag security flaws before code is ever integrated.
GitOps Maturity
GitOps is becoming the standard for cloud-native application delivery. In this operational model, the entire desired state of your production infrastructure is defined inside a Git repository. Automated controllers continuously compare your live cluster state with your code, correcting any configuration drift automatically.
AIOps (Artificial Intelligence for IT Operations)
As systems generate massive amounts of log data, humans struggle to spot patterns across billions of data points. AIOps platforms use advanced machine learning algorithms to analyze logs in real time, predict potential system failures before they happen, and initiate automated self-healing workflows.
FAQs (15 Questions)
1. What is DevOps in simple words?
It is a modern working philosophy that brings software developers (the people who build applications) and system operations engineers (the people who run and maintain those systems) together into a single team. By utilizing shared automation tools and continuous collaboration, they ship high-quality software updates to users quickly, safely, and reliably.
2. Is DevOps difficult for beginners?
It can feel overwhelming initially because it covers a broad ecosystem of tools, from operating systems to cloud architectures. However, by following a structured learning path—starting with Linux and Git before moving on to pipelines and containers—the learning curve becomes highly manageable and rewarding.
3. Does DevOps require coding?
Yes, it requires a foundational level of coding. While you rarely need to write complex application logic or advanced algorithms like a full-stack software developer, you must write automation scripts (typically using Python or Bash) and define cloud architecture using declarative configuration files (like Terraform or YAML configuration blocks).
4. Which cloud platform is best for beginners?
Amazon Web Services (AWS) is generally the best cloud provider for beginners. It holds the largest market share in the enterprise ecosystem, offers an extensive free-tier access option for practice, and has widespread community support and documentation available across the web.
5. Can a non-developer or non-technical professional transition into DevOps?
Absolutely. Many successful professionals transition from backgrounds in technical support, quality assurance, system administration, or entirely unrelated fields. The key is to systematically master core foundational concepts like Linux administration, version control, and networking fundamentals before diving into advanced automation tools.
6. Is Kubernetes mandatory to learn?
While not strictly required for absolute entry-level roles, mastering Kubernetes is essential for long-term career growth. The vast majority of modern enterprise organizations host their applications within cloud-native container infrastructures, making container orchestration a highly valued skill set.
7. How long does it take to learn DevOps from scratch?
For a dedicated beginner investing 10 to 15 hours a week of hands-on practice, it typically takes 6 to 9 months to build a strong foundational skill set. This timeline can vary based on prior technical experience and the structure of your learning path.
8. What salary can a DevOps engineer expect?
Salaries depend heavily on your location, experience level, and specific technical skills. Due to high demand and a shortage of skilled professionals, both entry-level and experienced infrastructure automation engineers command highly competitive compensation packages that sit well above standard IT averages.
9. What is the difference between DevOps and Agile?
Agile is a project management philosophy focused on breaking down software development into small, iterative cycles called sprints to manage changing requirements. DevOps expands on this by bridging the gap between those development cycles and the production operations infrastructure, ensuring that the rapidly written code can be deployed safely and continuously.
10. What is the difference between a DevOps Engineer and an SRE?
While both work with automation pipelines and infrastructure, a DevOps engineer focuses primarily on optimizing the delivery lifecycle—streamlining code compilation, pipeline testing, and deployment workflows. A Site Reliability Engineer (SRE) focuses on production runtime engineering—ensuring high availability, scale, monitoring metrics, and system self-healing capabilities.
11. Can DevOps be implemented on-premises, or is it cloud-only?
It can be implemented anywhere software runs. While cloud platforms make scaling and automation easier with APIs, its core principles—such as continuous integration, automated testing, version control, and infrastructure as code—apply equally to private data centers and on-premises physical hardware configurations.
12. What is configuration drift and how does DevOps fix it?
Configuration drift happens when manual, undocumented changes are made directly to a production server over time, making it run differently than development environments. DevOps resolves this by using Infrastructure as Code (IaC) tools like Terraform. These tools continuously enforce your desired state, overwriting manual modifications and keeping all environments identical.
13. What is a dark launch or canary deployment?
A canary deployment is a strategy where a new software update is rolled out to a tiny percentage (e.g., 5%) of real users first. Automated monitoring tools watch this traffic for errors. If no issues are detected, the update rolls out to the rest of the user base. If errors spike, the system automatically routes traffic back to the stable version, preventing widespread downtime.
14. What are the metrics that measure DevOps success?
Organizations track four key metrics (known as the DORA metrics) to measure performance:
Deployment Frequency: How often code is successfully deployed to production. Lead Time for Changes: The time it takes for a commit to go from development to production. Change Failure Rate: The percentage of deployments that cause a failure in production. Time to Restore Service: How long it takes to recover from a production failure. 15. How do I prepare for a DevOps job interview?
Focus heavily on explaining the why behind your technical choices, rather than just listing command syntax. Be ready to explain how an end-to-end CI/CD pipeline works, how you troubleshoot broken container networks, and how you use Infrastructure as Code to prevent environment drift. Sharing hands-on portfolio projects built on Git and public cloud platforms is highly effective.
Final Thoughts
The technology sector shifts rapidly, but the need for automation, speed, and system reliability remains constant. This is not a passing trend or a buzzword; it is the modern standard for how software is engineered, deployed, and scaled globally. The demand for professionals who understand both software development lifecycles and infrastructure systems continues to outpace the available talent pool.
For absolute beginners, the path forward requires patience, consistency, and a strong commitment to hands-on practice. Avoid trying to learn every tool at once. Focus instead on mastering core engineering fundamentals: build a solid understanding of Linux, get comfortable with Git workflows, and understand how data moves across a network. Once you master these core building blocks, learning advanced tools like Docker, Kubernetes, and Terraform becomes a natural next step.
Approach your learning journey with curiosity and consistency. The goal is not to memorize commands, but to develop a practical, automation-first mindset that solves real-world business challenges.
View the full article
Woot today has Apple's first generation AirTag 4-Pack for $45.59 with the code SAVETWENTY, down from $99.00. This code works on numerous products sitewide this week on Woot, taking 20 percent off for existing customers and 30 percent off for new customers. This means that if you've never purchased anything at Woot, you can get the AirTag 4-Pack for around $40 this week.

Note: MacRumors is an affiliate partner with Woot. When you click a link and make a purchase, we may receive a small payment, which helps us keep the site running.

The AirTag 4-Pack is in new condition and comes with a 90-day Woot limited warranty, and the sale is set to last for four more days. Be sure to check out the rest of the products that you can use the SAVETWENTY code on, including monitors, video game accessories, smart home products, apparel, and much more.

$54 OFFAirTag 4-Pack (1st Gen) for $45.59

If you're on the hunt for more discounts, be sure to visit our Apple Deals roundup where we recap the best Apple-related bargains of the past week.



Deals Newsletter

Interested in hearing more about the best deals you can find in 2026? Sign up for our Deals Newsletter and we'll keep you updated so you don't miss the biggest deals of the season!




Related Roundup: Apple Deals
This article, "First Gen AirTag 4-Pack Drops Below $50 for the First Time Ever" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
An old elevation-of-privilege (EoV) vulnerability affecting the Cloud Filter driver “cldflt.sys” in Windows has come back to haunt Microsoft, as researchers claim it is still exploitable six years after it was supposedly patched.
The flaw, originally reported to Microsoft by Google Project Zero researcher James Forshaw in September 2020, was recently picked up by Nightmare Eclipse, a researcher on an ongoing spree of Windows bug discoveries, and reworked to gain SYSTEM privileges.
“I’m unsure if Microsoft just never patched the issue or the patch was silently rolled back at some point for unknown reasons,” Eclipse said in a PoC writeup, calling the re-discovery ‘MiniPlasma’. “The original PoC by Google worked without any changes.”
Eclipse’s PoC triggered SYSTEM privileges on all Windows versions running on the researcher’s machines, but said “success rate may vary since it’s a race condition.”
“The exploit is highly credible, it works on fully patched systems, and it highlights a massive gap in how legacy regression flaws are managed,” said Agnidipta Sarkar, chief evangelist at ColorTokens. “A quick lookup tells me that the vulnerability resides in cldflt.sys (the Windows Cloud Files Mini Filter Driver), specifically within the HsmOsBlockPlaceholderAccess routine, which handles Cloud Sync functionality (such as OneDrive placeholder files).”
Microsoft did not immediately respond to CSO’s request for comments.
A fixed bug that still works
MiniPlasma reproduced an old issue, tracked as CVE-2020-17103, around how Windows handles key creation through an undocumented API tied to the Cloud Filter driver.
Forshaw’s original Project Zero report described a scenario where arbitrary registry keys could be created inside the “.DEFAULT ” user hive without proper access checks, potentially enabling local privilege escalation. The flaw was assigned a 7.8 “high severity” CVSS rating by NIST, but Microsoft had contested that rating with a 7.0 out of 10 CVSS assessment of its own.
“Because this is a Local Privilege Escalation (LPE) flaw, it cannot be used for initial, remote entry into a system,” Sarkar said. “And it is hopeful because this requires lateral movement, which can be denied by modern microsegmentation in an agentless model integrating with the EDR like CrowdStrike/Defender/SentinelOne, etc., implemented in less than a day to keep vulnerable systems quarantined until the Microsoft patch is applied.”
Microsoft had patched the issue in December 2020, calling exploitation of the flaw “less likely” as it assessed the attack complexity to be “high.”
Eclipse, however, claims the flawed behavior never truly disappeared. The original exploit chain from 2020 still succeeds on modern Windows builds, allowing a standard user account to elevate directly to SYSTEM privileges, they noted in the writeup.
“I don’t know why Microsoft missed this, but my speculation is that either they blocked only a specific side channel, not the whole routine, or this was an accidental miss,” Sarkar added. “In either case, in the age of Mythos, this definitely is a major issue.”
Security researcher Will Dormann confirmed the buggy behavior carried through to the latest May updates, though he noted the exploit failed on the latest Windows 11 Canary Insider build, suggesting Microsoft may already be quietly testing mitigations.
It is unclear if the flaw was ever weaponized in these years, outside of the multiple POCs published.
Nightmare-Eclipse’s Windows disclosure spree keeps growing
MiniPlasma is only the latest entry in what has become one of 2026’s most chaotic Windows disclosure runs.
The spree began with BlueHammer, a Windows Defender privilege escalation flaw later assigned CVE-2026-33825. That was followed by RedSun and UnDefend, two additional Windows privilege escalation and denial-of-service disclosures. Huntress later reported observing BlueHammer, RedSun, and UnDefend tooling during a real-world intrusion investigation related to suspicious VPN activity and hands-on-keyboard attacker behavior.
Earlier this month, Eclipse also released YellowKey and GreenPlasma. YellowKey allegedly bypasses TPM-only BitLocker protections by abusing Windows Recovery Environment behavior to gain shell access to encrypted drives, while GreenPlasma is another local privilege escalation technique aimed at achieving SYSTEM access.
It was during their follow-up investigation into the GreenPlasma technique that Eclipse ran into MiniPlasma. “After re-investigating the technique used in GreenPlasma (specifically SetPolicyVal), it turns out ‘cldflt!HsmOsBlockPlaceholderAccess’ is still vulnerable to the exact same issue that was reported to Microsoft 6 years ago,” Eclipse said.
The researcher reportedly disagreed with how Microsoft handled the BlueHammer disclosure, making their subsequent string of Windows vulnerability PoCs particularly interesting.
“Over the past several weeks, Nightmare-Eclipse has released a relentless string of zero-day/regression disclosures,” Sarkar pointed out. “The timing is a giveaway, the MiniPlasma was released on May 13, 2026—exactly one day after Microsoft’s May Patch Tuesday cycle, ensuring defenders have no official vendor patch for weeks. But yes, that is exactly where microsegmentation integrated with existing EDR platforms helps.”
View the full article
Apple wants users to look again at their use of generative Genmoji in iOS 27, according to Bloomberg's Mark Gurman.


‌Genmoji‌ is an Apple Intelligence feature that lets you use AI to generate all-new emoji characters based on text input. All ‌Genmoji‌ generation happens directly on-device, but the feature has had a rocky run.

Writing in his latest Power On newsletter, Gurman says that the generated images often looked nothing like Apple's polished marketing examples, and the underlying models were demanding enough to heat up iPhones and drain their batteries.

Apple has apparently made some tweaks so that no longer happens, while also adding a new supplementary feature.

"Suggested Genmoji" will reportedly offer you custom emoji ideas automatically based on your media and text history, rather than you having to think them up yourself. The feature is said to be optional in the next iPhone and iPad software update.

Gurman says a new toggle in the Keyboard settings of iOS 27 reads: "Suggested Genmoji are created from your photos and your commonly typed phrases."

iOS 27 will be previewed at WWDC next month, with a public release expected in the fall.Tags: Genmoji, Mark Gurman
This article, "'Suggested Genmoji' Are Coming to an iPhone Near You" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Apple in iOS 27 will include an enhanced Siri with a dedicated app that gives users options to keep conversations in memory for a limited time, according to Bloomberg's Mark Gurman.


Writing in his latest Power On newsletter, Gurman says that Apple is keen to market its privacy credentials as a key advantage in the way it is implementing AI across its software compared to rivals.

Cognizant of the perception that it has fallen behind other companies in the race to integrate AI into its operating systems, Apple will lean into privacy as a core tenant of its approach – starting with giving users options to auto-delete chats.

In the Settings panel for the new Siri app, "users will be able to choose to keep conversations for 30 days, one year, or forever," says Gurman, based on his sources. A similar feature can already be found in the Messages app's Settings.

"Most leading AI chatbots today rely heavily on histories and memory systems to personalize responses and improve future interactions," says Gurman. "But Apple will place tighter limits around how memory works, including restrictions on what information can persist and how long it can be retained."

Gurman also mentions that users will be able to decide if the Siri app opens showing either a grid of prior conversations or a new chat screen.

Apple's enhanced Siri will be powered by Google's Gemini models, but Apple apparently won't emphasize this, given that Google is historically known as an ad-driven business that farms users' data.

Another interesting tidbit in Gurman's latest newsletter is that the new Siri app will be labeled "beta," despite being the culmination of two years of delays. Apple recently agreed to pay $250 million to settle a U.S. class action lawsuit over delayed Siri features, with eligible iPhone users able to receive up to a $95 payout.Related Roundup: iOS 27Tags: Mark Gurman, Siri
This article, "iOS 27: Dedicated Siri App to Include Auto-Deleting Chats Feature" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
There is a conversation that happens in boardrooms every quarter that security leaders will recognize. The CISO presents the threat landscape. The board asks what the company needs. The answer, almost always, is another tool. Another platform, another module, another vendor to close the latest gap. The budget gets approved. The tool gets deployed. And six months later, the conversation happens again because the gap didn’t actually close. It just moved.
This pattern has been running on repeat for decades. And it has produced a security industry that is extraordinarily well-tooled and still struggling with the same fundamental problem it had ten years ago. Organizations cannot consistently answer basic questions about their own environments. What assets exist? Who and what has access to them? What is actually happening, right now, across all of those systems?
The instinct to buy another tool is understandable. It feels like progress. It satisfies the board’s need to see action. And vendors are very good at packaging their products as the answer to whatever the latest headline threat is. But the organizations that are actually reducing risk, not just responding to it, have figured out something that the tool-buying cycle obscures. The most valuable security capability isn’t detection, prevention or response. It is visibility.
More tools, same blind spots
Most enterprise security teams can name every tool in their stack. Very few can draw a complete picture of what those tools are collectively looking at, what falls between them and what nobody is watching at all. Each tool was purchased to solve a specific problem. Each one does what it was designed to do reasonably well. And yet the overall security posture of most organizations hasn’t improved proportionally with these investments.
Think of it like a city that keeps hiring more specialized security guards without ever drawing a map of the buildings they’re protecting. One guard watches the front entrance. Another patrols the parking garage. A third monitors the loading dock. Each one is competent. But none of them knows about the unmarked side door that was added during a renovation three years ago. The guards aren’t the problem. The missing map is.
Security tools work the same way. The endpoint tool sees endpoint activity. The cloud security tool sees cloud configurations. The network tool watches traffic patterns. The SIEM collects logs from all of them. But none of them, individually or collectively, provides a unified picture of the environment as it actually exists. Each tool illuminates its own corner. The spaces between those corners are where breaches live.
Attackers don’t break through your defenses. They walk between them
The most effective attacks today don’t target any single tool’s coverage area. They move through the seams. An attacker who compromises a valid credential doesn’t trigger endpoint detection. An attacker who moves from one cloud service to another using legitimate trust relationships doesn’t trip network alerts. An attacker who creates a new automated credential using the permissions of a compromised account doesn’t set off the configuration scanner.
Going back to the city analogy, it’s as if someone walked past every guard using a legitimate employee badge. No guard was wrong to let them through. The failure was that nobody maintained a map showing which doors the badge should actually open, which buildings the person had no reason to enter and which sequence of entering access points across the city constitutes a pattern worth investigating.
In conversations with security leaders across industries and company sizes over the last several years, this is the frustration that surfaces most consistently. The tools work. The alerts fire. But nobody can reconstruct the full story of what happened across systems until days or weeks after the damage is done. The information existed in the environment. It just wasn’t connected.
Visibility is not the same as data
Visibility is one of those words that has been used so often in security marketing that it has lost most of its meaning. Every vendor claims to provide visibility. What most of them actually provide is data. Logs, alerts, dashboards, reports. Data is not visibility. Data is the raw material. Visibility is the ability to answer a specific question about your environment in minutes, not days, and trust the answer.
Real visibility means knowing what exists in your environment before something goes wrong, not discovering it during the forensics investigation afterward. It means understanding the relationships between systems, between users and the resources they access, between automated processes and the data they touch. It means being able to trace any activity across boundaries, not just within the walls of a single tool’s coverage.
Most security programs today are data-rich and visibility-poor. They generate terabytes of logs, thousands of alerts and hundreds of reports. And when something goes wrong, the first 48 hours are still spent figuring out what the attacker had access to and which systems were involved. That gap between data and understanding is where breach costs compound, response timelines stretch and board confidence erodes.
Where the blind spot is biggest right now
This visibility gap shows up across the security stack, but there is one area where it has grown faster than most organizations realize. The number of machine and automated credentials in the average enterprise has quietly outgrown every other asset class security teams track. Service accounts, API keys, automation credentials, third-party integrations and now AI agents all operate alongside human users. Most of them were created by someone who has since moved on to a different project or even a different company. Many have never been reviewed.
The result is an environment where the actual inventory of who and what can access critical systems is typically several multiples larger than what leadership believes it to be. And the gap between assumed and actual is where risk accumulates. A credential that nobody knows about is a credential that nobody is monitoring. A credential that nobody is monitoring is one that an attacker can use without triggering a single alert.
This is problem is compounded by AI adoption, which is creating new categories of automated access faster than governance programs can track. But the underlying problem is not specific to AI, or to any single technology trend. It is the same visibility problem that has existed for a decade, accelerated by the pace at which modern environments generate new connections, new credentials and new trust relationships that fall outside the view of tools built to watch a narrower perimeter.
The question boards should be asking instead
For board members and senior leaders evaluating security investments, the shift in thinking is simple to describe and difficult to execute. Stop asking “Are we protected?” and start asking “What can we see?”
A security program that can see its environment clearly, understand the relationships between systems and reconstruct any chain of activity within minutes is fundamentally more resilient than a program with twice the tools but half the visibility. The tools matter. But they only matter if they’re built on a foundation of actually knowing what exists.
Before approving the next tool purchase, boards should ask their security leaders a few questions. Do we have a complete and current inventory of everything that can access our critical systems? If we had a breach tomorrow, could we reconstruct what happened across every system the attacker touched? Where are the gaps between our tools, and who is watching those gaps? If the answers are uncertain, the highest-return investment isn’t another detection layer on top of an incomplete foundation. It is the foundation itself.
The best investment a board can make in 2026 is not another tool. It is pushing their teams to ensure they have the ability to see their environment as it actually is, not as they assume it to be. Draw the map first. Everything else builds on that.
This article is published as part of the Foundry Expert Contributor Network.
Want to join?

View the full article
When Matt Schlicht built Moltbook, the social network where AI agents talk to one another, he didn’t write the code himself. He “just had a vision,” and vibe-coded it. The social network launched on Jan. 28, 2026, and within days, security researchers started to see serious security flaws.
​Experts at cloud security company Wiz and, independently, researcher Jameson O’Reilly, discovered that Moltbook’s backend database, hosted on Supabase, had been improperly configured. As a result, it granted broad read and write access to platform data.
“The exposure included 1.5 million API authentication tokens, 35,000 email addresses, and private messages between agents,” Wiz researchers noted in a blogpost.
In traditional software development, leaking a secret typically stems from a mistake. Usually, a developer hardcodes a key, copies the wrong configuration file, or pushes internal code to a public repository. With AI-assisted coding, those mistakes can happen quickly and often go unnoticed, because speed and functionality are prioritized over security.
Given the rise in popularity of vibe coding, the issue is accelerating. “The pace at which we are building and the sheer amount of code would have been unimaginable even just a few years ago,” says Dwayne McDaniel, principal developer advocate at GitGuardian.
In 2025, public code commits surged by more than 40% compared to the previous year, and secrets are rising just as fast. Security firmGitGuardian reported a 34% increase in leaked secrets on GitHub last year — the largest spike on record — bringing the total to nearly 29 million exposed credentials.
“12 of the top 15 fastest-growing leaked secret types were AI services,” says McDaniel. More than 1.27 million AI-related secrets were exposed in 2025, marking an 81% year-over-year increase, the fastest growth recorded in any single category.
McDaniel groups these credentials into several broad areas: the LLM platforms themselves, the support and orchestration ecosystem, the AI control plane, Model Context Protocol (MCP) servers, and agentic coding assistants.
“I’m increasingly concerned about the volume of code being pushed out by AI and the speed at which developers are reviewing it,” says Christine Bejerasco, CISO of WithSecure. “That can lead to more vulnerable code, especially as frontier AI models are now capable of identifying vulnerabilities at scale.”
Secrets leaks require immediate response
Many organizations know deep down they have a problem with AI-generated code. However, some don’t realize the severity of the situation, just how many secrets are exposed across their systems.
When a leaked secret is detected, the issue should be treated as a security incident. “We activate our incident response process immediately,” says WithSecure’s Bejerasco.
The secret is revoked or disabled, and a new one is generated. “From there, the incident response team works with R&D to investigate the impact across systems and data. That’s followed by cleanup, then hardening,” she says. “While incidents are typically coordinated by the CISO office, the R&D team owns the actual revocation and cleanup.”
The organization conducts post-mortems and implements any necessary updates to systems or policies based on what was learned.
Although remediation is critical, the process is far from straightforward. According to GitGuardian, 64% of valid secrets identified in 2022 remain unrevoked in 2026, largely because many organizations lack the governance and repeatable processes needed to clean them up at scale.
“We think this is less a visibility issue and more a combination of priority, tooling, and ownership,” GitGuardian’s McDaniel says.
Detection is the easy part, says Rohan Gupta, vice president of cloud, security, and DevOps at R Systems. “Remediation is where discipline gets tested.”
Addressing the broader issue
As AI-assisted coding expands, security leaders must rethink how they manage risk. That means looking beyond repositories and securing the full software development lifecycle (SDLC), including collaboration tools where credentials often show up.
“We focus on both, but the risk profile is very different — what’s identified in Jira or Slack is far different from what you’ll find in your code repository,” says David MacKinnon, chief security officer at N-able. “A mature SDLC — which includes things like effective credential vaulting, separation of duties, source code scanning, separated dev, stage/production environments, and more — helps to minimize the business risk.”
At WithSecure, Bejerasco says secrets and agent access are kept “as transient as possible” to reduce risk. And there’s also a Lifecycle Security Policy in place that mandates code reviews. “This policy is effectively the security ‘bible’ for developers,” she says. “It covers privacy impact assessments, threat modeling, security testing, and code review.”
R Systems’ Gupta agrees, advising organizations to rotate credentials, revoke exposed versions, audit for unauthorized use during any exposure window, and purge from history wherever feasible. “For the long-tail legacy service accounts, third-party integrations, embedded vendor credentials rotation is still a coordinated manual exercise, and we’re steadily moving more of it into automation,” he says.
A key step in fixing the issue is knowing it exists. “If an organization is not aware of how many secrets they’re exposing in their code base, or the level of access those secrets hold, they have a tremendous amount of business risk that they’re unaware of,” says N-able CSO MacKinnon.
He advises CISOs to raise awareness around the scale of the problem. He also suggests stronger developer training, better tools to detect and manage risks, and solutions that enable both human and AI-driven development to operate securely. Just as important, he says, is embedding these practices into everyday workflows so that security becomes part of how code is written, not something added afterward.

His organization scans for secrets when code is committed to block any commits that would introduce risk into the products. “The creator of that code, whether it be human or AI, is held to the same level of security maturity,” MacKinnon adds.
Bejerasco agrees. “We need to be deliberate about assigning ownership upfront and continuously validating it, and by cracking down on anything that falls through the cracks,” she says. “Otherwise, these unmanaged identities and secrets will accumulate faster than we can control them.”
Advice for CISOs
If there is one clear lesson from the rise of AI-driven development, it’s this: The biggest mistake CISOs can make is treating secrets sprawl as a scanning problem. “It is really an ownership and governance problem for machine identities at scale,” McDaniel says.
Gupta goes even further. “A leaked secret is a symptom of an ungoverned non-human identity (NHI) issue,” he says. “Treat it as detection and response, and you’ll chase leaks forever. Treat it as identity governance — inventory every NHI, assign ownership, enforce short-lived credentials, prefer workload identity over static keys, rotate automatically, decommission aggressively — and the problem starts to shrink instead of grow.”
​And while public leaks draw attention, most secrets exposure builds up privately — in internal repositories, build systems, and developer workflows — where ownership is unclear and remediation is often deferred.
“Private tends to get mistaken for safe, when it really just means there are fewer eyes on it,” says Gupta. “Inside private repos, people loosen up. Because it feels contained, the guard can get dropped. All it takes is one supply-chain issue or someone walking out the door with unauthorized access.”
The real risk lies in the sheer volume of NHIs being created faster than organizations can track them. “The smartest CISOs right now are pushing their DevOps and dev teams to embrace better ways to handle authorization than long-lived, overprivileged API keys,” he says.
To WithSecure’s Bejerasco, the security issues associated with AI-generated code are urgent. ​“The appetite for AI adoption from organizational leaders is high right now, and we need to manage that risk even though the capabilities and controls are not fully mature yet,” she says.
Yet, despite the urgency, the industry is still figuring out how to respond. “I don’t think anyone has the right answers yet; we’re all building governance as we go,” Bejerasco says. As AI agents become more widespread, traditional approaches might not keep up, and organizations might need to use AI to help govern AI, she adds.
MacKinnon believes CISOs should not be alone in this. They should involve CEOs and CTOs in the process and explain to them that “the risk is real and it’s rampant.”
​“There’s never a perfecttime to address it, but the investment in proactively reducing that risk is far easier and cheaper than learning about it after it’s been used to compromise your company,” MacKinnon says.
View the full article
Cybersecurity researchers have discovered four new npm packages containing information-stealing malware, one of which is a clone of the Shai-Hulud worm open-sourced by TeamPCP. The list of identified packages is below - chalk-tempalte (825 Downloads) @deadcode09284814/axios-util (284 Downloads) axois-utils (963 Downloads) color-style-utils (934 Downloads) "One of the packages (chalk-tempalte)View the full article
A new analysis of the Lua-based fast16 malware has confirmed that it was a cyber sabotage tool designed to tamper with nuclear weapons testing simulations. According to Broadcom-owned Symantec and Carbon Black teams, the pre-Stuxnet tool was engineered to corrupt uranium-compression simulations that are central to nuclear weapon design. "Fast16's hook engine is selectively interested inView the full article
Chaotic Eclipse, the security researcher behind the recently disclosed Windows flaws, YellowKey and GreenPlasma, has released a proof-of-concept (PoC) for a Windows privilege escalation zero-day flaw that grants attackers SYSTEM privileges on fully patched Windows systems. Codenamed MiniPlasma, the vulnerability impacts "cldflt.sys," which refers to the Windows Cloud Files Mini Filter Driver,View the full article
Amazon this weekend has brought back a major sale on the M4 iPad Air, with a trio of all-time low prices on the tablet. This includes both 11-inch and 13-inch models of the brand new 2026 M4 iPad Air.

Note: MacRumors is an affiliate partner with Amazon. When you click a link and make a purchase, we may receive a small payment, which helps us keep the site running.

Specifically, the 128GB Wi-Fi 11-inch M4 iPad Air has dropped to $519.99, down from $599.00, beating the previous low price by about $40. You'll also find low prices on the 256GB Wi-Fi 11-inch model and 256GB Wi-Fi 13-inch model, both of which we're only tracking on Amazon.

$79 OFF11-inch M4 iPad Air (128GB Wi-Fi) for $519.99
$89 OFF11-inch M4 iPad Air (256GB Wi-Fi) for $609.99
$109 OFF13-inch M4 iPad Air (256GB Wi-Fi) for $789.99

The new iPad Air features the M4 chip, C1X modem, and N1 networking chip, which brings support for Wi-Fi 7 and Bluetooth 6. In terms of design, the 2026 models are identical to the 2025 iPad Air tablets, with an edge-to-edge display, slim bezels, and aluminum chassis.

If you're on the hunt for more discounts, be sure to visit our Apple Deals roundup where we recap the best Apple-related bargains of the past week.



Deals Newsletter

Interested in hearing more about the best deals you can find in 2026? Sign up for our Deals Newsletter and we'll keep you updated so you don't miss the biggest deals of the season!




Related Roundup: Apple Deals
This article, "Amazon Offers Up to $109 Off New M4 iPad Air Models This Weekend" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Over the years, the iPhone's operating system has gotten complicated. Apple adds new features with every version of iOS, and many of them aren't always obvious, leading to hidden iPhone capabilities you might not be aware of.


The tips below assume that you have iOS 26 or later installed.

Turn an App Into a Widget

You can turn most app icons into widgets right from the iPhone's Home Screen. Just long press on an app icon, and select one of the squares from the top to choose a widget size. It works with any Apple or third-party app that has a widget option. Long press again and select the top left icon with four squares to turn it back into a standard app icon.


See Where You've Been

In the Maps app, you can look back at your location history to see places that you've visited. It's useful if you've been on a weekend trip, found a great restaurant, and want to remember where it was the next time you visit.


You can get to this feature by opening up the Maps app, tapping on your profile, selecting Places, and then choosing Visited Places. Places are organized by category like leisure or shopping, and by city.

You can clear your history by scrolling down to the bottom of the interface, or select a period of time for visits to be kept. Go to Settings > Maps > Location > Visited Places to turn it off entirely.

Set Custom Vibrations

You probably know you can set custom sounds for people that call or text, but you can also do the same thing for vibration patterns if you keep your iPhone on silent all the time, as civilized people do.


Important people you message can each have a different vibration pattern, so you know who is texting without having to look at your phone.

To set a vibration pattern for someone, open up the Contacts app and select them. Tap Edit in the upper right corner, then tap on Text Tone or Ringtone. Tap on Haptics and then select Create New Vibration. From there, you can use taps and presses to make your own vibration patterns.

Customize Your Lock Screen Buttons

Your Lock Screen buttons don't have to open up the Flashlight and the Camera app. You can set them to any Control Center option, including those from third-party apps.


To do so, go to the Lock Screen and long press. Tap on Customize if you want to edit your current wallpaper and Lock Screen, or the "+" button to make a new one. From there, tap on the "-" button on the apps at the left or right of the screen to remove them, and then tap on "+" to choose something new to add.

Back Tap Gestures

Back Tap has been around for a long time, but it's easy to forget it exists. You can use it to set a tap on the back of the iPhone to do whatever you want, from snapping a screenshot to activating the flashlight. It even works with Shortcuts you've created.


Go to Settings > Accessibility > Touch and then scroll down to Back Tap to set it up. You can set actions for a double tap or a triple tap.

Screenshot a Webpage

When you press the side button and volume buttons to take a screenshot, the default is a capture of what's currently on your display. If you want to screenshot a whole webpage or a PDF, there is a way to do it. Take the screenshot as normal, then tap it (if you have full-screen previews off). Select "Full Page" at the top of the interface, and then choose where to save your extra long screenshot.



Hide Apps

If you have apps that you don't want to show up on the ‌Home Screen‌, you can hide them one by one by long pressing and tapping the Face ID option, or you can hide a whole app page at once. To hide an app page, long press on the ‌Home Screen‌ to enter jiggle mode.


Tap on the dots at the bottom of the display, and then select the app page you want to hide from view. Apps hidden this way don't show up in the Hidden folder in the App Library. You can still find them through Spotlight Search and they're visible in their appropriate App Library category. To unhide a page, follow the same steps and tap the checkbox to bring it back.

Quick Set a Timer

If you add the Timer option to Control Center, you can long press on it to get an easy slider that lets you select an amount of time you want to set it for.


In Control Center, tap the "+" button and then choose Add a Control. Select the Timer icon to add it to Control Center. Long press on the timer, choose an amount of time from the slider, and then tap Start. Times range from two hours to one minute.

Remove Photos Location Data

If you're sending a photo to someone, you might want to remove metadata like location first. To do so, select an image in the Photos app, swipe up, and tap on Adjust Location. From there, you can choose No Location.


Alternatively, when you go to share a photo, you can turn off metadata there. Select a photo, and tap on the Share button. Tap on Options, and toggle off Location.


Use a Timer to Turn Off Media

You can use timers to control how long music, podcasts, audiobooks, and other media play for, which is useful if you only want to listen for a short period at night.


In the Clock app, tap on Timers. Set a time period, and then tap on the When Timer Ends option. Scroll down and select Stop Playing. When your timer goes off, any media you have playing will stop.

More Tips

Have a favorite iPhone tip that most people don't know about? Let us know in the comments below.
This article, "10 Useful iPhone Tips and Tricks You Might Not Know About" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
SwitchBot today debuted the SwitchBot Lock Vision and the Lock Vision Pro, two Matter-enabled smart locks that include facial recognition technology for quick door unlocking.


With Matter-over-WiFi, the locks are compatible with HomeKit and they support NFC, so you can use them with an Apple Home setup. SwitchBot also included "advanced 3D structured light" facial recognition that's able to recognize approved lock users in under one second.

SwitchBot says the facial recognition is comparable to 3D facial recognition used by "flagship smartphones," and it can't be spoofed with photos or videos, even when wearing glasses, hats, or makeup. It uses more than 20,000 infrared dots to create an accurate 3D facial map that SwitchBot says is capable of millimeter-level recognition.

The locks also include multiple other unlocking methods, including NFC, passwords, iPhone app controls, the Apple Watch, Siri-based voice commands, geofencing, and physical keys. The Pro version of the lock adds palm vein and fingerprint access too, for even more ways to get into your house. Palm vein detection works without touching the lock, even if hands are wet or dirty.

SwitchBot's Lock Vision and Lock Vision Pro have 12-month battery life and emergency backup power options. They are meant to replace a standard deadbolt, and include mmWave radar detection to determine when someone is approaching the door. No hub is required for the locks, and biometric data is stored on-device.

The SwitchBot Lock Vision is priced at $170, while the SwitchBot Lock Vision Pro is available for $230. SwitchBot has a $40 launch discount on Amazon and on its website.Tag: SwitchBot
This article, "SwitchBot Launches Two Matter Smart Locks With 3D Facial Recognition" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
A popular npm package called node-ipc has been compromised, with hackers publishing malicious versions that bundle credential stealing malware. The root cause of the compromise was an expired domain name that attackers managed to register in order to hijack a maintainer’s account.
The node-ipc package has had malware added to its code in the past. In March 2022, following Russia’s invasion of Ukraine, the project’s creator intentionally added malicious code to the program to wipe files on systems with Russian or Belarusian IP addresses.
Node-ipc is a Node.js module that implements support for local and remote Inter-Process Communication over various types of socket across all major platforms. One use case is in implementing complex multi-process neural networks in JavaScript, but the module is also used as a dependency for 424 other projects, and receives almost 700K weekly downloads.
On Thursday, attackers managed to publish three trojanized versions across three different branches of the project: 9.1.6, 9.2.3 and 12.0.1. All new versions contained an 80KB obfuscated credential-stealing payload inside the node-ipc.cjs file.
The malicious code searches for and steals a wide range of credentials for CI/CD tools, cloud services and infrastructure, Kubernetes, SSH, and AI coding agents. The data is exfiltrated through DNS TXT queries rather than HTTP connections.
Since node-ipc is a dependency for hundreds of other packages, which in turn could be dependencies for even more packages, this attack could have a large blast radius. Users should immediately scan their systems to determine if they have any of the compromised versions installed, and if they do, treat the machine and any access token, environment variable, and API key stored on it as compromised.
Exhaustive credential collection and sneaky exfiltration
The malicious payload is decrypted and executed whenever other applications load the package through require(‘node-ipc’). The trojanized versions were designed to remain fully functional to avoid immediate detection, which together with other decisions attackers took, such as data exfiltration via DNS TXT, suggest stealthiness was a top priority.
Once executed, the malicious code collects information about the host system, including operating system version, hostname, and environment variables. It then starts looking for credentials in various locations based on the detected OS.
“The payload chooses between separate decoded target lists for macOS and Linux/default platforms,” researchers from Socket.dev said in their analysis. “The lists are not identical. In the analyzed payload, the macOS list contains 113 patterns and the Linux/default list contains 127 patterns.”
The target lists are extensive and include:
Configuration files for AWS, Azure, GCP, OCI, DigitalOcean, Scaleway, Hetzner, Fly, Vercel, Railway, Alibaba Cloud, IBM Cloud, Linode, MinIO, Snowflake, Doppler, and Salesforce; SSH keys and SSH configuration; Kubernetes, Docker, Helm, Rancher, and service-account material; npm, Yarn, Netrc, Git, GitHub CLI, GitLab CLI, and Hub credentials; Terraform credentials and tfvars files; .env, .env.local, .env.production, database configuration files, shell histories, and database CLI histories; macOS Keychain database files; Firefox profile key database files on macOS; Linux keyrings and KWallet files; FileZilla, Remmina, OpenVPN, and related connection profiles; Microsoft Teams local storage and IndexedDB paths. While browser credential stores are not targeted directly, macOS keychain databases can contain system and browser credentials, so those credentials should be considered compromised as well and rotated.
All the collected data is archived in a GZIP file, which is then split into chunks and exfiltrated by making DNS TXT queries on an attacker-controlled domain whose name is similar to that of Microsoft’s legitimate Azure Static Web Apps domain.
Since the attackers control the DNS server for their domain name, they can see the TXT record queries made by the infected systems and can reconstruct the archives on their end from the leaked bytes. The Socket researchers estimate that a 500KB file would require around 29,400 TXT queries to exfiltrate in this way.
“The payload does not establish persistence in the decoded sample,” the researchers said. “There is no observed cron, launchd, rc.d, service installation, or second-stage download. The operational impact is concentrated in the execution window: collection, archive creation, DNS TXT exfiltration, and attempted cleanup.”
Expired domain led to email takeover
The malicious node-ipc versions were published from an npm account called atiertant, which belongs to one of the several developers with maintainer access to the package.  Atiertant had never used his access to publish new node-ipc versions before, and has had no activity on node-ipc or any other npm package he has access to since 2022.
Security researchers noticed that the email address for atiertant’s account was hosted on a domain called atlantis-software.net that had expired in January 2025 and was re-registered earlier this month, most likely by the attackers. It was then just a matter of setting up an email server, recreating atiertant’s email address and performing a password reset on the account.
This highlights some of the security challenges open-source software projects face. While periodically reviewing access lists for dormant and unused accounts is a general security recommendation for companies, open-source projects are maintained by groups of volunteers, and it’s not unusual for people to take long breaks from contributing to projects, especially if those projects have reached a high level of maturity and feature completeness so they no longer get frequent updates.
It’s also likely that the attackers did not target node-ipc from the start, they just searched npm for accounts with email addresses on custom domain names, then checked if any of those domain names had expired. This means there might be other dormant accounts out there susceptible to email takeover using the same method.
The Socket.dev report contains additional recommendations for both users and developers, as well as file hashes and other indicators of compromise that can be used by security teams to create detections.
View the full article
If you have a Mac and a cat, you've probably run into a situation where your cat sits on your computer keyboard. Whether it's because Macs are warm or because they want to distract you from the screen absorbing all of your attention, laptops tend to attract cats.


A new Mac app called Cats Lock adds cat-proofing that keeps your cat from doing damage to whatever you're working on when it gets on your keyboard, and it can even be set to shoo the cat off.

You can click to turn on Cats Lock from the menu bar or use a quick keyboard shortcut, and it prevents cats from being able to activate the keys. Cats can be particularly good at finding odd keyboard shortcuts you never knew existed and making changes that are annoying to undo, so Cats Lock is useful for preventing that. It also has an option to cut sound, so there's no more incessant beeping of keys when your cat gets on your keyboard and holds down a button.


Putting your Mac in sleep mode is an alternative, but you can also set Cats Lock to alert you or make a loud noise when your cat gets on the keyboard. Some of the built-in sounds like a barking dog, vacuum cleaner, or hissing cat might serve as a deterrent even when you're not around. You can also upload your own sounds.

Cats Lock stays on until your Mac goes to sleep, at which point it turns off so you're not locked out of your Mac because of the app.

Cats Lock can be downloaded from the Mac App Store for $2.99.Tag: Mac App Store
This article, "Cats Lock for Mac Stops Your Cat From Causing Keyboard Havoc" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
A newly discovered zero-day vulnerability in Microsoft Exchange Server has experts declaring an emergency and urging CSOs to think about the need to abandon on-premises email solutions.
“Because it’s already being exploited in the wild, this isn’t a ‘patch next week situation; it’s a ‘mitigate right now’ emergency,” warned Rob Enderle of the Enderle Group.
“This is another reminder to find a trusted cloud provider for e-mail,” added Johannes Ullrich, dean of research at the SANS Institute. “On-premises Exchange is becoming a legacy product, and while some organizations need it for internal and outbound email, its attack surface should be minimized by reducing its exposure to external email.”
Ullrich was commenting on an alert from Microsoft this week about a cross-site scripting vulnerability affecting Exchange Outlook Web Access (OWA) that could be exploited merely by sending a specially crafted email to a user.  If the user opens the message in Outlook Web Access and certain interaction conditions are met, arbitrary JavaScript can be executed in the browser context.
Avoiding cross-site scripting problems in webmail systems like Outlook Web Access is hard, Ullrich admitted. A webmail system must include HTML email received from users within the application’s HTML without confusing the two. Techniques like sandboxed iFrames can help, but need to be applied carefully.
At the same time, he said, cross-site scripting flaws in webmail can usually be used to read the content of an email, and in some cases even to send an email.
“Luckily,” he added, “many organizations have moved away from on-premises Exchange and Outlook Web Access.”
“I’m guessing this is bad,” said Kellman Meghu,” CTO of DeepCove Cybersecurity, “but so is running an onsite Exchange Server in general.”
Affected by the vulnerability (CVE-2026-42897) are Exchange Server 2016, 2019, and Server Subscription Edition (SE), regardless of their update levels.
The cloud service, Exchange Online, is unaffected.
Mitigation
Microsoft is still working on a security patch. In the meantime, Exchange administrators should know that if the Exchange EM Service is enabled on their servers – and it should be; since its release in September 2021 it has been enabled by default – then Microsoft’s automatic mitigation for this vulnerability has already been published for affected versions of Exchange.
If EM Service for whatever reason has been disabled, it should be enabled immediately. Note, however, that EM Service won’t be able to check for new mitigations if the server is running an Exchange Server version older than March 2023.
Those who can’t use the EM Server, because, for example, they are disconnected or have air-gapped environments, should download the latest version of the Exchange on-premises Mitigation Tool (EOMT) and apply the mitigation on a per server base, or on all servers at once by running the script via an elevated Exchange Management Shell.
Known issues with mitigation tactics
However, admins should note there are known issues once the mitigation is applied either manually or automatically through the EM Service.
OWA Print Calendar functionality might not work. As a workaround, copy the data or screenshot the calendar you want to print, or use Outlook Desktop client.
Inline images might not display correctly in the recipient’s OWA reading pane. As a workaround, send images as email attachments or use Outlook Desktop client.
OWA light (OWA URL ending in /?layout=light) does not work properly. Note that this feature was deprecated several years ago and is not intended for regular production use.
Admins may get a message saying “Mitigation invalid for this Exchange version.” in mitigation details. This issue is cosmetic and the mitigation does apply successfully if the status is shown as “Applied”. Microsoft is investigating how to address this glitch.
Updates coming ‘in the future’
A Microsoft spokesperson was asked when the security update would be released. We were referred to the company’s statement. 
In its warning, Microsoft says security updates for impacted versions of Exchange Server will come “in the future.” They will be for Exchange SE RTM, Exchange 2016 CU23, and Exchange Server 2019 CU14 and CU15. Those running older CU versions are urged to update now.
An Exchange SE update will be released as a publicly available security update. Exchange 2016 and 2019 updates will be released only to customers who are enrolled in the Period 2 Exchange Server ESU program. Period 1-only ESU customers will not receive this update, as that program ended last month.
 Enderle said the fact that Microsoft issued an interim fix that breaks features like calendar printing and inline images is “a clear sign of how desperate they are to stop the bleeding.
“CSOs need to move past the ‘wait and see’ approach and treat this as a litmus test for their security automation,” he said. “If your team has the Exchange Emergency Mitigation (EM) Service enabled, you should already be protected, but you need to verify that ‘Mitigation M2’ is actually active across your entire inventory. If you’re running air-gapped or have the EM service disabled, you’re sitting ducks until you manually run the EOMT script.”
This is another “massive nudge” from Redmond to shift from on-premises email, Enderle added. “If you aren’t already planning your exit from on-site Exchange, your risk profile is only going to keep climbing as these zero days become the new normal. This does showcase that Azure, and web services in general, are where the industry, and particularly Microsoft, is pushing IT to go, whether they want to or not.”
View the full article
WWDC is less than a month away, so the focus of the Apple world is turning toward what we might see in the next major operating system updates, but we're also looking ahead to the busy hardware update season in the fall.


This week also saw a significant change to Apple's education pricing program in some countries, while a new commemorative U.S. coin featuring Steve Jobs made a brief appearance, so read on below for all the details!

Top Stories

11 Reasons to Wait for the iPhone 18 Pro

We're only four months out from the launch of Apple's premium next-generation smartphone lineup, and while we're not expecting a sea change in terms of functionality, there are still several enhancements rumored to be coming to the iPhone 18 Pro and iPhone 18 Pro Max.


Despite cost pressures from industry-wide memory shortages that are forcing some Android smartphone manufacturers to raise prices, one analyst believes Apple will be "aggressive" on pricing with the iPhone 18 Pro models.

iOS 26.5 Features: Everything New in iOS 26.5

Apple this week released iOS 26.5 and related updates to the general public, delivering several new features and dozens of fixes for security issues.


The headline features in iOS 26.5 include a beta of end-to-end encryption for RCS messages exchanged between iPhone and Android users on supported carriers, a new "Suggested Places" section in the Maps app for recommendations based on your location and recent searches, and a new Pride Luminance wallpaper option.

macOS 27: Two More Changes Leaked Ahead of WWDC Next Month

macOS 27 will have a "slight redesign" compared to macOS Tahoe, according to the latest word from Bloomberg's Mark Gurman. In his Power On newsletter this week, Gurman said the design changes will help to improve the readability of macOS Tahoe's Liquid Glass interface.


In addition, Gurman said macOS 27 will have a new Safari feature that can automatically organize browser tabs into groups. This feature, previously revealed by MacRumors, is also expected to be available on iOS 27 and iPadOS 27.

macOS 27 and Apple's other major operating system updates will be revealed during the WWDC keynote on June 8.

Apple Watch Series 12 and watchOS 27: What to Expect Later This Year

While not too much has been reported about the next Apple Watch models, there are a few rumors about potential design changes and watchOS 27 features.


Apple Watch Series 12 and potentially Apple Watch Ultra 4 models are expected to be released in September, and we recently recapped some of the key rumored hardware and software changes. A new Apple Watch SE is not expected this year, as that model was just updated last year and it typically goes two to three years between refreshes.

Touch ID is one interesting rumor that has been circulating based on leaked Apple code, but one leaker recently claimed it won't be coming to the next-generation Apple Watch models, so we'll have to wait and see whether it makes an appearance. Otherwise, it seems battery life improvements, new Apple Intelligence and satellite features, and a few other quality-of-life improvements are likely.

Apple Now Requires UNiDAYS Verification for Education Discounts in U.S. and Canada, Adds Apple Watch

Apple has long offered discounted pricing on an array of products to educational customers, but in the U.S. and Canada this has largely been on the honor system outside of the occasional audit.


That changed as of this week, with Apple now requiring education customers in the U.S., Canada, and several other countries to verify their eligibility via the UNiDAYS system that the company has long used in other countries around the world.

On the positive side, Apple Watch is now eligible for education pricing in a number of countries, delivering a roughly 10 percent discount compared to regular pricing.

Steve Jobs U.S. Commemorative $1 Coin Goes on Sale, Immediately Sells Out

The United States Mint this week began selling a new $1 American Innovation Coin featuring Steve Jobs, although the coins sold out within minutes.


The $1 Steve Jobs Coin features a young Steve Jobs in a turtleneck, jeans, and sneakers, sitting in front of the Northern California landscape. Jobs is said to be "captured in a moment of reflection," in which "his posture and expression reflect how this environment inspired his vision to transform complex technology into something as intuitive and organic as nature itself."

The coin is part of the American Innovation $1 Coin Program that has been graudally honoring groundbreaking innovations and innovators from every U.S. state, territory, and the District of Columbia for nearly a decade.

MacRumors Newsletter

Each week, we publish an email newsletter like this highlighting the top Apple stories, making it a great way to get a bite-sized recap of the week hitting all of the major topics we've covered and tying together related stories for a big-picture view.

So if you want to have top stories like the above recap delivered to your email inbox each week, subscribe to our newsletter!Tag: Top Stories
This article, "Top Stories: iPhone 18 Pro Rumors, iOS 26.5 Released, and More" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
The best Apple deals this week include AirPods Max 2 for $40 off, 2026 MacBook Pro for up to $216 off, and Apple Watch Series 11 for up to $130 off. You'll also find Anker's best charging accessories on sale on Amazon right now, including the new Prime 3-in-1 Wireless Charging Station.

Note: MacRumors is an affiliate partner with some of these vendors. When you click a link and make a purchase, we may receive a small payment, which helps us keep the site running.

Anker


What's the deal? Save on Anker charging accessories
Where can I get it? Amazon
Where can I find the original deal? Right here
$45 OFFAnker Prime 3-in-1 Wireless Charging Station for $104.99

Anker's new Prime 3-in-1 Wireless Charging Station has been marked down to $104.99 on Amazon, down from $149.99. This is one of Anker's newest accessories, and Amazon's sale today is a match of the all-time low price.

AirPods Max 2


What's the deal? Take $40 off AirPods Max 2
Where can I get it? Amazon
Where can I find the original deal? Right here
$40 OFFAirPods Max 2 for $509.00

Amazon this week has a record low price on the AirPods Max 2, now available for $509.00, down from $549.00. This sale is available in three colors of the headphones.

MacBook Pro


What's the deal? Take up to $249 off M5 Pro/M5 Max MacBook Pro
Where can I get it? Amazon
Where can I find the original deal? Right here
$216 OFF14-inch M5 Pro MacBook Pro (24GB/1TB) for $1,984.00
$249 OFF16-inch M5 Pro MacBook Pro (24GB/1TB) for $2,449.99

Amazon is offering a few all-time low prices on Apple's M5 Pro/M5 Max MacBook Pro this week, with up to $249 off select models.

Apple Watch Series 11


What's the deal? Take up to $130 off Apple Watch Series 11
Where can I get it? Amazon
Where can I find the original deal? Right here
$100 OFFApple Watch Series 11 (42mm GPS) for $299.00
$130 OFFApple Watch Series 11 (46mm Cell) for $399.00

Amazon has all-time low prices on the Apple Watch Series 11 this week, with up to $130 off numerous models of the smartwatch. A highlight of the sale is the 46mm cellular model at $130 off, which is a match of the all-time low price.

If you're on the hunt for more discounts, be sure to visit our Apple Deals roundup where we recap the best Apple-related bargains of the past week.



Deals Newsletter

Interested in hearing more about the best deals you can find in 2026? Sign up for our Deals Newsletter and we'll keep you updated so you don't miss the biggest deals of the season!




Related Roundup: Apple Deals
This article, "Best Apple Deals of the Week: Anker Accessories on Sale Plus AirPods Max 2 for $509 and More" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
The best Apple deals this week include AirPods Max 2 for $40 off, 2026 MacBook Pro for up to $216 off, and Apple Watch Series 11 for up to $130 off. You'll also find Anker's best charging accessories on sale on Amazon right now, including the new Prime 3-in-1 Wireless Charging Station.

Note: MacRumors is an affiliate partner with some of these vendors. When you click a link and make a purchase, we may receive a small payment, which helps us keep the site running.

Anker


What's the deal? Save on Anker charging accessories
Where can I get it? Amazon
Where can I find the original deal? Right here
$45 OFFAnker Prime 3-in-1 Wireless Charging Station for $104.99

Anker's new Prime 3-in-1 Wireless Charging Station has been marked down to $104.99 on Amazon, down from $149.99. This is one of Anker's newest accessories, and Amazon's sale today is a match of the all-time low price.

AirPods Max 2


What's the deal? Take $40 off AirPods Max 2
Where can I get it? Amazon
Where can I find the original deal? Right here
$40 OFFAirPods Max 2 for $509.00

Amazon this week has a record low price on the AirPods Max 2, now available for $509.00, down from $549.00. This sale is available in three colors of the headphones.

MacBook Pro


What's the deal? Take up to $249 off M5 Pro/M5 Max MacBook Pro
Where can I get it? Amazon
Where can I find the original deal? Right here
$199 OFF14-inch M5 Pro MacBook Pro (24GB/1TB) for $1,999.99
$249 OFF16-inch M5 Pro MacBook Pro (24GB/1TB) for $2,449.99

Amazon is offering a few all-time low prices on Apple's M5 Pro/M5 Max MacBook Pro this week, with up to $249 off select models.

Apple Watch Series 11


What's the deal? Take up to $130 off Apple Watch Series 11
Where can I get it? Amazon
Where can I find the original deal? Right here
$100 OFFApple Watch Series 11 (42mm GPS) for $299.00
$130 OFFApple Watch Series 11 (46mm Cell) for $399.00

Amazon has all-time low prices on the Apple Watch Series 11 this week, with up to $130 off numerous models of the smartwatch. A highlight of the sale is the 46mm cellular model at $130 off, which is a match of the all-time low price.

If you're on the hunt for more discounts, be sure to visit our Apple Deals roundup where we recap the best Apple-related bargains of the past week.



Deals Newsletter

Interested in hearing more about the best deals you can find in 2026? Sign up for our Deals Newsletter and we'll keep you updated so you don't miss the biggest deals of the season!




Related Roundup: Apple Deals
This article, "Best Apple Deals of the Week: Anker Accessories on Sale Plus AirPods Max 2 for $509 and More" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
OpenAI is adding a new personal finance feature to ChatGPT, letting people connect their financial accounts to the chatbot to get budgeting advice.


Through a partnership with Plaid, ChatGPT users can connect their bank accounts, credit cards, investment accounts, and other financial accounts to get advice. OpenAI says ChatGPT supports more than 12,000 financial institutions.

ChatGPT will provide a dashboard of how money is being spent, along with an up-to-date view of portfolio performance, spending, subscriptions, upcoming payments, and more. It will also let users ask finance-related questions, and OpenAI provided a sample of questions ChatGPT will be able to answer with access to a user's financial accounts.

Help me build a plan to buy a house in my area in the next 5 years
What did my recent vacation actually cost me?
I feel like I've been spending more recently. Has anything changed?
Can I afford to take a lower-paying job if it gives me more flexibility to be home with the kids?
What's the biggest risk in my portfolio?
Look at my subscriptions and help me choose what to cancel

OpenAI says that connecting financial accounts lets ChatGPT provide a more personal and complete finance guidance experience. ChatGPT will be able to see balances, transactions, investments, and liabilities, but it can't see full account numbers or make changes to accounts.

The new personal finance feature is available to Pro ChatGPT users located in the United States, and it works on iOS and the web. While integration is limited to Plaid right now, OpenAI is adding Intuit soon. Support for ChatGPT Plus subscribers will be added in the future after OpenAI improves it after feedback from Pro users.Tags: ChatGPT, OpenAI
This article, "ChatGPT Can Now Connect to Your Financial Accounts for Budgeting Advice" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
A couple of years ago, I reviewed iVANKY's FusionDock Max 1, a powerful Mac dock utilizing dual Thunderbolt chips and dual-cable connectivity to drive 20 ports of various types for extreme versatility. Since that time, iVANKY has taken things further with the 23-port FusionDock Max 2 and now the 26-port FusionDock Ultra, and I've spent the past few weeks testing out the top-of-the-line FusionDock Ultra to see how it performs.


Similar to the FusionDock Max 1, the FusionDock Ultra features a dual Thunderbolt chip architecture that supports an impressive set of ports for power users. You'll find a huge array of USB ports, plus Gigabit Ethernet, SD/TF card slots, and more.

The FusionDock Ultra offers an appealing and practical design, although the front of the dock is littered with ports. That's a positive for ease of access if you need to connect and disconnect things, but it results in a less clean look and can make it harder to keep cables out of sight. But with this many ports, it more or less requires using the full front and rear panels of the dock just to fit them all in, so it's an understandable compromise.

The main body of the dock appears to float within a larger enclosure, only sitting on a few small pegs within the extruded black aluminum exterior shell. This design offers visual appeal while also providing room for airflow and a hefty amount of aluminum for heat dissipation via the copper-alloy midframe. In my testing, I found the exterior shell to get a bit warm with use, but not uncomfortable to touch at any point.


On the front of the FusionDock Ultra, you'll find a whopping six 10 Gbps USB-C ports, an additional 10 Gbps USB-C port with Power Delivery support up to 45 watts, two 10 Gbps USB-A ports, a 3.5mm combo audio port, UHS-II SD and TF/microSD 4.0 card slots, and an LED power light that's bright enough to let you know it's on while remaining dim enough to not be a distraction, even in a dark room when your screens are sleeping.

The rear of the dock features more than a dozen additional ports, including a pair of Thunderbolt/USB-C ports for the upstream connection to the Mac, four downstream Thunderbolt/USB-C ports for displays with the ability to support up to 80 Gbps or even 120 Gbps of data connection, an HDMI 4K port, a DisplayPort 2.1 port, one additional 10 Gbps USB-C port, two 10 Gbps USB-A ports, a 10 Gb Ethernet port, an S/PDIF optical port, and separate 3.5mm audio in and out ports, plus a Kensington lock slot to help secure the dock if used in a public environment.


There are dual fans inside the dock to help move air for heat dissipation, and they are audible when they kick on in a quiet environment, but I have not found them to be distractingly loud. Adaptive fan control modulates the speed depending on the heat being generated, and they will turn off or run very quietly at low speed under light to moderate workloads before ramping up under more demanding conditions. iVANKY says the fans register at 44–46 dBA when measured at a 1 cm distance, and that sounds about right: audible but more of a low white noise in a quiet environment and becoming nearly unnoticeable in busier environments.

As mentioned, the FusionDock Ultra connects to a Mac over a double Thunderbolt cable, and iVANKY has a clever cable design to help keep things neat. The two Thunderbolt connectors at the Mac end of the cable attach to each other magnetically, creating what amounts to a single connector for machines such as the MacBook Pro that have standard horizontal spacing between Thunderbolt ports.


If you're using something like a Mac Studio or Mac mini with a different alignment of the ports, the cable connectors can be separated. iVANKY's solution also includes a pair of slidable clips to help keep the two cables together and organized.

Notably, the FusionDock Ultra can provide up to 140 watts of upstream power to a connected Mac over this Thunderbolt connection, delivering quick charging to even Apple's most power-hungry portable Macs. In order to drive all of this, the dock comes with a fairly large 240-watt external power brick, but most users shouldn't find it too hard to tuck it away on the floor or behind other equipment.

Turning to display connectivity, while the FusionDock Ultra can drive four 6K displays natively, support ultimately depends on the Mac you're connecting it to. For full quad-display support, you'll need to be using a Mac with a Max or Ultra flavor of chip, anywhere from M1 up to M5. The latest ‌MacBook Pro‌ with an M5 Pro chip supports up to three displays, as does the latest ‌Mac mini‌ with either the M4 or M4 Pro chip. Machines with most other chips can support two external displays, while some older base chips like the ‌M1‌ or M2 in a ‌MacBook Pro‌ or MacBook Air can only support a single external display.

Simply put, go off Apple's published specs for your model to see how many external displays you can use, as iVANKY's dock won't supersede those limits by using tricks like DisplayLink compression. This ensures optimal performance without degraded image quality or lag.

Users of the LG UltraFine 5K or Samsung ViewFinity S9 5K displays should note that the FusionDock Ultra only supports up to two of these being connected simultaneously. Apple Studio Displays are fully supported up to the maximum number specified for your machine. Generally speaking, I've been regularly using the FusionDock Ultra with two external displays throughout my testing and had a brief opportunity to test it with four displays, and I've seen no hiccups in performance with everything working seamlessly through the dock.


10Gb Ethernet connectivity is a major selling point for power users, as most docks deliver Ethernet at lower speeds as they seek to balance demands on the overall connection bandwidth, but the FusionDock Ultra's dual-chip and dual-cable design gives it the headroom to support the higher data speed.

There aren't a whole lot of Intel Macs left at this point, but it's worth noting that the FusionDock Ultra is only compatible with Apple silicon Macs, so it won't work with Intel Macs or PCs.

All of this doesn't come cheaply, with the FusionDock Ultra normally priced at $749.99, although iVANKY is currently discounting it to $649.99 on the iVANKY website and at Amazon. But for power users looking to connect a boatload of accessories to their Macs with minimal fuss, the FusionDock Ultra is an excellent companion. And if your needs aren't quite as high as what the FusionDock Ultra supports, iVANKY also offers the FusionDock Max 2 currently discounted to $399.99 or the original FusionDock Max 1 on sale for $299.99.

Note: iVANKY provided MacRumors with the FusionDock Ultra for the purposes of this review. No other compensation was received. MacRumors is an affiliate partner with Amazon. When you click a link and make a purchase, we may receive a small payment, which helps us keep the site running.Tag: iVANKY
This article, "Review: iVANKY's FusionDock Ultra is a Premium 26-Port Thunderbolt 5 Dock for Your Mac" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
For this week's giveaway, we've teamed up with Lululook to offer MacRumors readers a chance to win an Apple Watch Ultra 3 and a Qi2.2 25W 3-in-1 Charging Station to go along with it.


Lululook makes all kinds of accessories for Apple devices, and it has several Apple Watch charging options with different capabilities and price points. The $68 3-in-1 Charging Station is one of Lululook's newest options, and it supports the Qi2.2 specification for MagSafe charging speeds up to 25W.

With 25W charging, the Lululook Charging Station can charge an iPhone at the same speeds as Apple's 25W ‌MagSafe‌ chargers. Faster charging is available on the iPhone 17 models, the iPhone 16 Plus, and the ‌iPhone 16‌ Pro Max. The ‌iPhone 16‌ and 16 Pro charge at up to 22.5W, and the iPhone Air charges at up to 20W. Other models charge at 15W. Lululook's charger provides enough power to get an iPhone to 50 percent battery in 30 minutes.


There's also a pop-out Apple Watch charger and a charging platform for the AirPods, so you can charge up three devices at once. The Apple Watch charger is a fast charger, so you'll get maximum charging speeds on the Apple Watch Ultra models and standard Apple Watch models that support faster charging.


When not in use, the charger folds down into a slim square, making it ideal for travel. Lululook offers the 3-in-1 Charging Station in three colors to match Apple's iPhone 17 Pro lineup, including a bright orange. There are silicone pads on each charging area to keep devices scratch-free.

Strong magnets keep the iPhone in place while it is charging, and the hinged design lets it be positioned at appropriate angles for watching videos or gaming. It supports an iPhone in either landscape or portrait mode, and it is powered with USB-C. It comes with a 45W power adapter, a 3.2-foot USB-C cable, and a portable organizer for keeping everything together when on the go.

For those who don't need fast charging and want to spend less money, Lululook also has a Qi2 3-in-1 Charging Station that's available for $35. Qi2 charging is limited to 15W, and that's the main difference compared to the Qi2.2 charger that Lululook offers.


The chargers otherwise have a similar design, and the Qi2 Charging Station features a platform for charging the iPhone, a pop-out Apple Watch charger, and a Qi charging pad at the base for the AirPods. It comes in black or gray, and when not in use, it folds into a square.

The charger can be used upright or laid flat on a desktop if preferred. It ships with a 30W power adapter, USB-C cable, and travel case.


We have an ‌Apple Watch Ultra 3‌ and a Qi2.2 3-in-1 Charging Station for one lucky MacRumors reader. To enter to win, use the widget below and enter an email address. Email addresses will be used solely for contact purposes to reach the winner and send the prize. You can earn additional entries by subscribing to our weekly newsletter, subscribing to our YouTube channel, following us on Twitter, following us on Instagram, following us on Threads, or visiting the MacRumors Facebook page.

Due to the complexities of international laws regarding giveaways, only U.S. residents who are 18 years or older, UK residents who are 18 years or older, and Canadian residents who have reached the age of majority in their province or territory are eligible to enter. All federal, state, provincial, and/or local taxes, fees, and surcharges are the sole responsibility of the prize winner. To offer feedback or get more information on the giveaway restrictions, please refer to our Site Feedback section, as that is where discussion of the rules will be redirected.


Lululook Giveaway
The contest will run from today (May 15) at 9:00 a.m. Pacific Time through 9:00 a.m. Pacific Time on May 22. The winner will be chosen randomly on or shortly after May 22 and will be contacted by email. The winner will have 48 hours to respond and provide a shipping address before a new winner is chosen.Related Roundup: Apple Watch Ultra 3Tag: GiveawayBuyer's Guide: Apple Watch Ultra (Neutral)Related Forum: Apple Watch
This article, "MacRumors Giveaway: Win an Apple Watch Ultra 3 and 25W 3-in-1 Charging Station From Lululook" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Starting as early as next week, customers who sign up for an Apple Card at Apple's retail stores in the U.S. will receive $249 cash back when they purchase AirPods Pro 3, according to Bloomberg's Mark Gurman. The promotion has yet to be officially announced by Apple, so exact terms and conditions are not available at this time.


AirPods Pro 3 are priced at $249 in the U.S., so customers who sign up for an Apple Card will effectively get free AirPods Pro through this promotion.

Apple Card cash back is known as Daily Cash, so customers would receive the $249 cash back on the same day as they sign up for the card.

As a refresher, the Apple Card launched in 2019, and it remains available in the U.S. only. The credit card can be managed in the iPhone's Wallet app, with color-coded spending summaries. The card has no annual fee, and it offers 2% to 3% cash back on purchases via Apple Pay and 1% back on purchases with the physical card.

Apple Card holders can also open a high-yield savings account.

Currently, the Apple Card is issued by Goldman Sachs, but Apple previously announced that Chase will be taking over the credit card by early 2028.Related Roundup: AirPods Pro 3Tags: Apple Card, Bloomberg, Mark GurmanBuyer's Guide: AirPods Pro (Neutral)Related Forum: AirPods
This article, "Apple Card Promo to Offer Free AirPods Pro 3" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Apple's iPhone 17 Pro has been named the fastest-charging phone overall in a new CNET lab test covering 33 smartphones, with Samsung's Galaxy S26 Ultra taking the top spot for wired charging speed.


To determine the rankings, CNET's lab team ran each phone through a 30-minute wired charging test starting at 10% battery or less, using the phone's included cable and a wall charger rated at or above the device's maximum supported speed. Phones that support wireless charging went through a matching 30-minute wireless test using a Qi (7.5W), Qi2 (15W), or Qi2.2 (25W) charger matched to the phone's peak supported speed. CNET then averaged the wired and wireless results into an overall charging score.

The ‌iPhone 17 Pro‌'s win in the overall category is partly a function of its relatively compact 4,252mAh battery, which is smaller than the 5,000mAh or larger capacities common among competing flagships. With less capacity to fill, the 17 Pro charges faster in absolute terms, and it supports both 40-watt wired charging and 25-watt Qi2.2 wireless charging. CNET notes that battery size is just one factor in overall battery life, alongside processor and software efficiency, and in its battery life testing, the ‌iPhone 17 Pro‌ Max came out on top for endurance.

For wired charging, Samsung's Galaxy S26 Ultra took the top spot, adding 76% charge in 30 minutes via its 60-watt wired charging speed, the fastest of any Samsung flagship to date. The ‌iPhone 17 Pro‌ came in second at 74%, tied with Motorola's Moto G Stylus (2025). The OnePlus 15 followed with 72%, while the iPhone 17, ‌iPhone 17 Pro‌ Max, and Samsung Galaxy S25 FE each reached 69%.

Apple's ‌iPhone 17 Pro‌ also claimed the fastest wireless charging result, gaining 55% in 30 minutes. The ‌iPhone 17 Pro‌ Max added 53%, followed by the ‌iPhone 17‌ at 49%, the iPhone Air at 47%, and the Galaxy S26 Ultra at 39%. CNET again attributes the 17 Pro's edge over the 17 Pro Max largely to its smaller battery, since both devices share the same A19 Pro chip and software.

Across all brands tested, Apple had the most consistent fast-charging performance by a considerable margin, averaging 54.6% across the four ‌iPhone 17‌ models and the ‌iPhone Air‌. Samsung's nine-phone average came in at 38.5%, with the Galaxy S26 Ultra as its strongest performer and the Galaxy Z Fold 7 as its weakest at 29%.

Silicon-carbon batteries, which use a silicon-based anode rather than graphite to enable higher capacities and faster charge rates, appeared among several of the top performers. The OnePlus 15, for example, recharged 72% of its 7,300mAh silicon-carbon battery in 30 minutes using a proprietary 80-watt charger. Silicon-carbon phones in the U.S. remain limited to OnePlus, RedMagic, and Poco. Apple, Samsung, and Google have not yet adopted the technology.Related Roundup: iPhone 17 ProTag: CNETBuyer's Guide: iPhone 17 Pro (Caution)Related Forum: iPhone
This article, "iPhone 17 Pro Named Fastest-Charging Smartphone" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
On this week's episode of The MacRumors Show, we discuss Google's latest wave of announcements for Android and Gemini, the newly announced Fitbit Air, and Apple Watch Series 12 rumors.

Subscribe to The MacRumors Show YouTube channel for more videos
The centerpiece of Google's announcements this week was Gemini Intelligence, Google's new umbrella platform for AI across phones, watches, cars, and laptops. Its headline capability is cross-app automation: users can photograph an event flyer and ask Gemini to find tickets on Expedia, or pull up a grocery list and have it build a cart in a shopping app. A companion feature called Create My Widget lets users describe a home screen widget in natural language and have Gemini generate it, drawing from Gmail and Calendar to build a personalized dashboard.

Google also unveiled the Googlebook, a new laptop category designed from the ground up around Gemini with partners including Acer, Asus, Dell, HP, and Lenovo arriving this fall. Gemini in Chrome for Android gained an agentic browsing layer rolling out end of June, and Android Auto received AI-generated contextual replies and DoorDash voice ordering. A Meta partnership brings Ultra HDR, native stabilization, and night mode to Instagram on Android flagship devices.

In January, Apple and Google announced a partnership under which Gemini would power the next generation of Apple Foundation Models, including a more personalized Siri expected this year. Apple's equivalent cross-app ‌Siri‌ actions were announced at WWDC 2024 but have not yet shipped; Gemini Intelligence is rolling out this summer using the same underlying technology.

Google also unveiled the Fitbit Air this week, a screenless fitness tracker priced at $99 that ships on May 26. The device weighs just 12 grams with the band and tracks heart rate, AFib, HRV, SpO2, and sleep stages in a small pill-shaped design with no display, no buttons, and no notifications. Battery life lasts for seven days, with a five-minute fast charge delivering a full day of use. A Stephen Curry Special Edition is priced at $129, with core tracking free and Google Health Premium adding an AI Coach for $9.99 per month after a three-month trial.

The launch accompanies a broader rebrand. The Fitbit app becomes Google Health on May 19, with Google Fit folded in, Apple Health data supported on iOS, and APIs for Garmin, Whoop, and Oura. Bloomberg's Mark Gurman reported earlier this year that Apple has scaled back a comparable Health+ coaching service, with the feature now unlikely to launch. The Apple Watch SE starts at $249 and requires daily charging, and the Fitbit Air's $99 price with no mandatory subscription addresses a segment Apple does not cover.

We also discuss the Apple Watch Series 12, which is shaping up to be an incremental upgrade. Bloomberg's Mark Gurman said in March that he does not expect any major design changes, and a significant redesign is now not expected until 2028.

The leaker known as "Instant Digital" said this week that Touch ID, which appeared in leaked Apple code last year, has been deprioritized in favor of battery life improvements. DigiTimes previously reported on an eight-sensor array on the back of at least one 2026 model, though blood pressure monitoring is said to be further out. A new chip is expected, with leaked code indicating a meaningful upgrade from the S10 used across the last three series. watchOS 27 will be previewed at WWDC on June 8.

The MacRumors Show has its own YouTube channel, so make sure you're subscribed to keep up with new episodes and clips.

Subscribe to The MacRumors Show YouTube channel!

You can also listen to ‌The MacRumors Show‌ on Apple Podcasts, Spotify, Overcast, or other podcast apps. You can also copy our RSS feed directly into your player.



If you haven't already listened to the previous episode of The MacRumors Show, catch up to hear our discussion about how the global memory shortage is forcing Apple's hand across multiple key products, killing configurations, delaying launches, and prompting spec decisions that would have seemed unlikely a year ago.

Subscribe to ‌The MacRumors Show‌ for new episodes every week, where we discuss some of the topical news breaking here on MacRumors, often joined by interesting guests such as Kayci Lacob, Kevin Nether, John Gruber, Mark Gurman, Jon Prosser, Luke Miani, Matthew Cassinelli, Brian Tong, Quinn Nelson, Jared Nelson, Eli Hodapp, Mike Bell, Sara Dietschy, iJustine, Jon Rettinger, Andru Edwards, Arnold Kim, Ben Sullins, Marcus Kane, Christopher Lawley, Frank McShan, David Lewis, Tyler Stalman, Sam Kohl, Federico Viticci, Thomas Frank, Jonathan Morrison, Ross Young, Ian Zelbo, and Rene Ritchie.

‌The MacRumors Show‌ is on X @MacRumorsShow, so be sure to give us a follow to keep up with the podcast. You can also email us at [email protected] or head over to The MacRumors Show forum thread. Remember to rate and review the podcast, and let us know what subjects and guests you would like to see in the future.Related Roundup: Apple Watch 11Tag: The MacRumors ShowBuyer's Guide: Apple Watch (Caution)
This article, "The MacRumors Show: Gemini Announcements and Apple Watch Series 12 Rumors" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Deals on the 2026 MacBook Pros have been popular over the past few weeks, but the focus has been on the 14-inch M5 Pro models. Today, Amazon has opened up massive discounts on the 16-inch M5 Pro and M5 Max MacBook Pro, with $249 off every model.

Note: MacRumors is an affiliate partner with Amazon. When you click a link and make a purchase, we may receive a small payment, which helps us keep the site running.

With these markdowns, every model of the 2026 16-inch MacBook Pro has hit a new all-time low price on Amazon, and each deal is available in both Silver and Space Black. Prices start at $2,449.99 for the 24GB/1TB M5 Pro model, down from $2,699.00.

$249 OFF16-inch MacBook Pro (24GB/1TB) for $2,449.99
$249 OFF16-inch MacBook Pro (48GB/1TB) for $2,849.99
$249 OFF16-inch MacBook Pro (36GB/2TB) for $3,649.99
$249 OFF16-inch MacBook Pro (48GB/2TB) for $4,149.99

You can also still get up to $216 off the 14-inch MacBook Pro this week on Amazon. The best deal is the 24GB/1TB M5 Pro model for $1,983.94, down from $2,199.00.

If you're on the hunt for more discounts, be sure to visit our Apple Deals roundup where we recap the best Apple-related bargains of the past week.



Deals Newsletter

Interested in hearing more about the best deals you can find in 2026? Sign up for our Deals Newsletter and we'll keep you updated so you don't miss the biggest deals of the season!




Related Roundup: Apple Deals
This article, "Amazon Discounts 2026 16-Inch MacBook Pro by $249 Across All Models" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Apple has slashed prices on the iPhone 17 Pro series in China by 1,000 yuan (around $138) in anticipation of the annual 618 shopping festival, one of the country's largest mid-year online retail events.


The cuts went live on Friday on JD.com and Tmall, with Apple's official store on the latter platform applying a direct 1,000-yuan discount on the iPhone 17 Pro series. On JD.com, taking into consideration trade-in offers and platform promotions, some iPhone 17 Pro models can be picked up for as low as 6,999 yuan (around $968). That's the lowest price since the device's launch, according to the Global Times.

The standard iPhone 17 also received its first notable markdown. Some configurations are now available for 4,499 yuan (around $622) including discounts, bringing it well under the 6,000-yuan threshold for China's national trade-in subsidy, which knocks 15% off qualifying devices up to a 500-yuan cap – something that customers of the Pro models miss out on.

News of Apple's price cuts quickly shot to the top of social media platform Weibo's trending list on Friday. Meanwhile, Huawei has also introduced lower prices for its high-end foldable models for the first time.

"Apple and Huawei are the two companies most closely benchmarked against each other in the high-end segment," said Liu Dingding, a technology industry analyst speaking to the Global Times. "Other brands still hold market share, but in terms of premium-market influence, the rivalry is increasingly centered on these two players."

Liu said both companies are using this year's shopping festival window to quickly lift orders and shipments while competing for a larger share of replacement demand.

Apple's iPhone 17 series has been a runaway hit in China so far. Apple reported $26 billion in Chinese revenue during its fiscal first quarter, a 38 percent year-over-year increase and the company's best-ever performance in the region. China now accounts for roughly one-fifth of Apple's total global sales.

The results are a major turnaround after nearly three years of declining sales in the country, where Apple has faced stiff competition from domestic rivals like Huawei, Xiaomi, and Vivo.

Apple CEO Tim Cook is currently on his way back home from China, following his participation in an official U.S. business delegation accompanying President Donald Trump as he met with Chinese president Xi Jinping.Related Roundup: iPhone 17Tag: ChinaBuyer's Guide: iPhone 17 (Neutral)Related Forum: iPhone
This article, "Apple Slashes iPhone 17 Prices in China for Annual 618 Festival" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
We’re excited to announce the general availability of Custom Catalogs and Profiles for managing Model Context Protocol (MCP) servers. These two complementary capabilities fundamentally change how teams package, distribute, and manage AI tooling. 
Custom MCP Catalogs let organizations curate and distribute approved collections of MCP servers. MCP Profiles enable individual developers to easily build, run, and share their MCP tools and configurations across projects and teams.
In this post, we’ll walk through how to create your own custom catalog – building on and improving our previous approach. We’ll also introduce Profiles, a new primitive that lets you define portable, named groupings of MCP servers. Profiles are designed to solve several practical use cases today, while giving us a foundation to expand in the future.
Creating custom catalogs with Docker
As organizations adopt MCP, we consistently hear the same need: teams need a way to curate a trusted list of MCP servers, including internally built servers.
To address these needs, we built Custom Catalogs. Instead of every team member searching for MCP servers across the open internet, organizations can publish and distribute catalogs that define approved servers. This allows developers to centrally discover and use trusted MCP servers within organizational boundaries.
Custom Catalogs can reference servers from Docker’s MCP Catalog, community sources, and custom MCP servers developed internally, bringing flexibility, control, and trust together in a single experience. We will show you how to do that with a Custom Catalog. 
Step-by-step: Building and sharing a custom MCP catalog 
In this example, we will create a Custom Catalog containing servers from the Docker MCP Catalog and an MCP server we created ourselves from the CLI. Then we will show you how to use Docker Desktop to import the catalog.
All the functionality we will show can be exercised through the CLI, while a subset of primarily user-centric features can be exercised through Docker Desktop.
Here, we will use my personal Docker Hub ID roberthouse224 in the commands, but you should adapt to use your information where appropriate (e.g. pushing an image).
Step 1: Creating my custom MCP server and pushing it to Docker Hub
We built a reference server called roll-dice (GitHub Repository). It is a regular MCP server that communicates over stdio and can be built as a Docker image. The image has already been built and pushed to Docker Hub.
We can create the metadata that describes the server including where the image can be found and save it to a file named mcp-dice.yaml to be used when creating our catalog.
name: roll-dice title: Roll Dice type: server image: roberthouse224/mcp-dice@latest description: An mcp server that can roll dice Step 2: Creating a catalog that includes servers from the Docker MCP Catalog alongside a server you have built yourself
Now we can create a custom catalog containing servers from the Docker MCP Catalog and the MCP server we created ourselves.
docker mcp catalog create roberthouse224/our-catalog \ --title "Our Catalog" \ --server catalog://mcp/docker-mcp-catalog/playwright \ --server catalog://mcp/docker-mcp-catalog/github-official \ --server catalog://mcp/docker-mcp-catalog/context7 \ --server catalog://mcp/docker-mcp-catalog/atlassian \ --server catalog://mcp/docker-mcp-catalog/notion \ --server catalog://mcp/docker-mcp-catalog/markitdown \ --server file://./mcp-dice.yaml Step 3: Verifying the MCP servers in the custom catalog 
We can now list our catalogs and see the catalog that we created
docker mcp catalog list
We can also inspect the contents of the catalog
docker mcp catalog show roberthouse224/our-catalog --format yaml
Step 4: Share the catalog
At the moment our custom catalog only lives on our machine. But what we have – and this is really powerful – is an immutable OCI artifact containing our trusted MCP servers that can be easily shared.
We can push our catalog to a container registry, in this example we’re using Docker Hub. Now, anyone that has access to your organization’s namespace can access the catalog.
docker mcp catalog push roberthouse224/our-catalog
Using a custom MCP catalog
Now that our custom catalog has been shared, colleagues can import it from within Docker Desktop (or from the cli using docker mcp catalog pull).
Import the catalog from Docker Desktop by selecting “Import catalog,” and then specifying the OCI reference in the dialog.
Figure 1: Importing a custom catalog from OCI reference
The catalog is now browsable. You can double click into the catalog and see all of the servers contained within it. Notice the custom MCP server that we added named “Roll Dice.”
Figure 2: A custom MCP catalog within the Docker Desktop app, including a newly added “Roll Dice” server.
To make this a private catalog all you need to do is manage access to the repository the way you always have for container images – no new infrastructure to manage or systems to learn.
This is exactly what Jim Clark was describing in his post Private MCP Catalogs and the Path to Composable Enterprise AI.
This simple pattern can be extended to support more complex use cases. For example, you might use a private container registry instead of Docker Hub, or connect to a remote MCP server over streamable HTTP you host yourself rather than running a containerized server as shown in the example.
Now that we have a shareable custom catalog of trusted MCP servers we can shift focus to how individuals can effectively leverage MCP servers from the catalog we built in their workflows.
Using Profiles to create and share MCP Workflows
With MCP Profiles, developers can organize workflows efficiently and maintain separate server collections and configurations for different use cases. Profiles can be shared across teams, enabling collaboration on server setups and ensuring consistent configurations for teams working within the same projects or contexts.
Switch between Profiles
At a basic level, a Profile is a named grouping of MCP servers that can be connected to an agent session. This makes it straightforward to define different Profiles for different ways of working.
Now let’s see an example in action. 
We create a profile named coding and another named planning. We browse our custom catalog, select the MCP servers that we want (e.g. Playwright, GitHub, and Context7) then select the “Add to” drop down, and select “New profile”.
Figure 3: Selecting MCP servers to be added to a new profile
Give the profile a name, select the client you want to connect to, and select “Create”.
Figure 4: Creating a new MCP profile named coding in Docker Desktop.
From the Profiles tab, we can see the profile we just created. Our client is connected and our tools are ready to use. 
Figure 5: Example of a profile that is connected to a client.
Next we create a profile named planning with servers relevant to planning (e.g. Atlassian, Markitdown, Notion). 
Navigate back to “our-catalog” (if not already there), select the servers relevant to planning, and select “Add to” -> “New profile.” Give the profile a name (e.g. planning). Then select “Create” to create the planning profile without a client. Specifying the client is optional.
Figure 6: Example of creating multiple profiles, including separate profiles for coding and planning 
Now we have two profiles that mirror two modes of working. When we switch to planning mode we only want the tools from our planning profile to be in context. To do that, we can easily reassign our client to the planning profile.
Figure 7: Reassign Claude Code to the planning profile.
If we go back to coding mode, we just reassign our client back to the coding profile. You can have any number of Profiles that mirror your many ways of working and easily switch between them, keeping only the tools you care about in context.
This will work with any agent, not just Claude Code. Profiles provide a truly portable way to manage your MCP server setups and avoid vendor lock-in.
Persist configuration
You can avoid repeatedly configuring MCP servers by using a Profile. Profiles add a persistence layer for MCP server configurations. When an MCP server exposes configurable options, you can define them once in a Profile and reload them as needed, avoiding repeated configuration.
In this example, we are specifying which paths Markitdown can access.
Figure 8: Using an MCP profile to save server configurations for reuse
Context windows can easily fill up when the MCP servers you use export a lot of tools. With Profiles you can specify which tools are enabled, making sure only the tools you need for a specific task are used.
Here we enable the get_me tool from the GitHub MCP server and disable all the others. All the other tools will not show up in our agent session or contribute to the context window.
Figure 9: Optimize your context window by enabling only the tools you need in the MCP profile
This model of saved configuration becomes far more powerful for MCP servers you build in-house. By exposing richer configuration options, you can reuse the same server across projects, reconfigure its behavior per context, and achieve more predictable outcomes.
Share Profiles
Identifying MCP servers and configurations that work well for a project doesn’t need to be repeated by every team member. Once you’ve found a setup that works, share it with the rest of the team.
To share a Profile you can push it as an OCI artifact to a container registry just like we did with our custom catalog. Just provide a name for it along with an OCI reference.
➜ ~ docker mcp profile push coding [your-namespace]/coding For someone to pull it down, all they have to do is issue the corresponding pull command.
➜ ~ docker mcp profile pull [your-namspace]/coding Although the example above demonstrates sharing Profiles across a team, the concept extends naturally to agents as well. An agent skill could, for instance, reference a Profile and pull in the required MCP servers and their configurations as dependencies.
Conclusion and What’s Next 
As MCP adoption grows, the challenge isn’t access to tools — it’s coordination. Teams need a way to standardize what’s trusted and supported without constraining how individuals actually work. Custom Catalogs and Profiles are designed to solve exactly that problem.
Custom Catalogs: shared foundation
Custom Catalogs allow platform and admin teams to define approved MCP servers, bundle internal and public tooling together, and distribute those choices as a single, portable artifact. This creates clarity and consistency while significantly reducing the cost of discovery and evaluation.
Profiles: supercharge workflow
Profiles give individual developers a lightweight way to assemble, configure, and reuse MCP servers for specific contexts like coding, planning, or research. Profiles persist configuration, limit context to what matters, and make effective setups easy to share across teams.
Together, these primitives separate:
What an organization recommends (via Custom Catalogs) How people work day to day (via Profiles) This separation enables a healthy balance. Platform teams can publish “golden paths” that establish standards and guardrails, while developers retain the freedom to adapt, experiment, and compose profiles that fit their needs.
The result is a system that is portable, composable, and scalable — making MCP easier to adopt, safer to manage, and more effective as it grows across an organization.
What’s Next?
Custom Catalogs and Profiles are the foundation for managing MCP at scale, and we’re just getting started. Next, we’re focused on extending these primitives to support stronger governance, better reuse, and more advanced agent workflows:
Governance and policy controls to restrict MCP usage to approved Custom Catalogs and trusted server sources Improved discoverability and sharing for both Catalogs and Profiles, making proven setups easier to find and reuse across teams Expanded Profile-scoped secrets and configuration, providing a more secure and flexible alternative to project-level mcp.json files Clear best practices for Profiles, including saving dynamic MCP server configurations for reuse and pairing Profiles with emerging workflow optimizations like agent skills Getting started with Custom Catalogs and Profiles
If you have Docker Desktop 4.56 you are already using Catalogs – our Docker MCP Catalog is now distributed as an OCI artifact and Profiles are supported starting with Docker Desktop 4.63. Try creating your first Profile by exploring the MCP Toolkit in Docker Desktop.
Learn more
Dive into our documentation on Custom Catalogs and Profiles to get started quickly. Explore Docker’s MCP Catalog and Toolkit on our website. Ready to go hands-on? Open Docker Desktop or the CLI and start using MCP to streamline and automate your development workflows.
View the full article
Cisco has disclosed a max-severity authentication bypass vulnerability affecting its Catalyst SD-WAN Controller and Catalyst SD-WAN Manager platforms, warning that the flaw has already been found to be exploited in the wild.
The disclosure follows an earlier authentication bypass vulnerability that Cisco patched in February. In the latest advisory, the company said the new flaw was identified while investigating the previously disclosed issue.
“A vulnerability in the peering authentication in Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, and Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an unauthenticated, remote attacker to bypass authentication and obtain administrative privileges on an affected system,” Cisco said in an advisory.
The company also confirmed that it became aware of “limited exploitation” of the flaw in May 2026. However, it did not disclose details about the attack or threat actors involved.
The zero-day flaw is now fixed with software updates, and organizations are advised to apply fixes immediately, as there are no workarounds that address this bug.
Attackers craft a connection for admin access
According to Cisco, the vulnerability stems from improper validation during the authentication process used to establish control connections between SD-WAN devices. It said an attacker could exploit the issue remotely by sending crafted control connection requests to a targeted system.
Successful exploitation would allow the attacker to bypass authentication, establish themselves as trusted peers, and obtain administrative privileges to the affected device.
“A successful exploit could allow the attacker to log in to an affected Cisco Catalyst SD-WAN Controller as an internal, high-privileged, non-root user account,” Cisco said. “Using this account, the attacker could access NETCONF, which would then allow the attacker to manipulate network configuration for the SD-WAN fabric.”
The issue, tracked as CVE-2026-20182, received a max-severity rating of CVSS 10.0. The company said that the issue is configuration-independent, meaning vulnerable systems remain exposed regardless of deployment-specific settings.
Cisco credited Stephen Fewer, Senior Principal Security Researcher, and Jonah Burgess, Senior Security Researcher, both of Rapid7, for discovering and reporting the bug.
Active exploitation kicks patching into high gear
Cisco disclosed being aware of exploitation attempts in May, urging customers to upgrade to a fixed release immediately.
Shortly after the disclosure, the flaw was added to the Cybersecurity and Infrastructure Security Agency’s (CISA) known exploited vulnerabilities catalog (KEV). “Adhere to the applicable BOD 22-01 guidance for cloud services or discontinue use of the product if mitigations are not available,” it said.
The US cybersecurity watchdog has given federal executive agencies until May 17th to patch the flaw.
“Customers are advised to upgrade to an appropriate fixed software release,” Fewer and Burgess said in a blog post, citing fixed software releases that address the flaw in versions 20.9 through 26.1.1. “There are no workarounds that address this vulnerability.”
Alongside software fixes, Cisco published operational guidance to help organizations identify potentially malicious control connections.
The advisory instructed admins to review existing control peering relationships, using the “show control connections” command, and validate all connected peers, particularly those associated with SD-WAN Manager systems.
Organizations that suspect compromise are being advised to contact Cisco Technical Assistance Center support and collect diagnostic information from affected devices.
View the full article
Apple Watch is now eleven generations in, and packed with useful features that are easy to miss at first glance. To help you get more out of your new device, we've rounded up 15 practical tips you might not have discovered yet, including a few that long-time users often overlook.



Bounce Between Two Apps


On your Apple Watch, double-press the Digital Crown to see a deck of all currently open apps, and turn it to scroll through them. From this view, you can jump back to the last app you were using. Simply tap on an app screen to switch to it, or swipe left on its card and tap the red X button to quit it.

Switch App Views


If the app grid feels messy, switch to List View. Open the Watch app on iPhone, tap App View, and choose List View. From then on, pressing the Digital Crown will show your apps in a simple, scrollable list.

Rearrange Apps


You can rearrange your apps so that the ones you use most are closer to hand. Simply press and hold on any app in the grid view, then drag it where you want. Alternatively, open the Watch app on your iPhone, go to App View ➝ Arrangement, and move things around there instead.

Ping Your iPhone


If you've misplaced your iPhone but you're sure it's nearby, open Control Center with a press of the Side button, then tap the phone icon to make it ping. Press and hold that icon and the iPhone's camera flash will blink too, which can help if it's hidden under something.

Skip the Countdown


If you're eager to start a workout, the three-second countdown before it starts can be skipped. Just tap the screen when the countdown begins and your workout will start immediately. If you find yourself doing this regularly, consider turning on Precision Start in Settings ➝ Workout.

Customize Vibration Strength


If you keep missing notifications, go to Settings ➝ Sounds & Haptics ➝ and change from Default to Prominent. This adds an extra tap pattern before alerts so they're harder to ignore.

Perform Precision Timing


The Chronograph Pro watch face transforms into an actual chronograph. Tap the outer edge surrounding the main 12-hour dial on this watch face to record time on scales of 60, 30, 6, or 3 seconds. Alternatively, select the tachymeter timescale to measure speed based on time travel over a fixed distance.

Jump to the Top


If you've scrolled way down in an app and want to jump back to the top, just tap the time in the top corner of the screen. It works in most apps and saves a lot of scrolling.

Remove Apps


Clearing out apps you don't use on your Apple Watch is easy. In the List or Grid View, press and hold on the screen until the apps jiggle, then tap the small x in the corner of the app icon to delete it. This works for most system apps and all third-party apps.

Customize Control Center


By default, Control Center (accessed via the Side button) gives you quick access to things like Wi-Fi, battery, and Do Not Disturb. But it's worth seeing what else you can add to it that you'd like quick access to. Tap the Edit button at the bottom, then tap the + icon in the top-left corner of the screen. System options such as New Note and Lights are particularly handy, and you might see some third-party options listed too, depending on your installed apps.

Speak the Time Out Loud


If you're using the Mickey or Minnie watch face, tap on the character and they'll speak the time out loud. Just make sure your sound is turned on. In fact, you can also have Siri read the time on any watch face by tapping and holding with two fingers on the display. Again though, sound needs to be enabled.

Customize Smart Replies


Smart Replies are handy when you want to reply with just a few words. In the Watch app on iPhone, go to Messages and tap Default Replies to customise what shows up. Then when a message comes in, simply swipe down to pick one of your preset replies.

Pause Activity Rings


Feeling unwell but hoping to keep your streak intact? In the Activity app, select your rings to access the option to suspend them for the day, or set a pause that lasts until a chosen date up to 90 days ahead.

Create a Note


In the new Notes app in watchOS 26, you can't modify existing notes on Apple Watch, but you can create a new one by tapping the compose control in the bottom-right corner and speaking your text. Because Notes sync through iCloud, you can refine or reorganize everything later on a device with a physical or on-screen keyboard.

Mute and Dismiss Alerts


With a quick wrist flip, you can clear the current screen and go back to the watch face. The same gesture can be used to mute calls, stop timers, and dismiss notifications. The feature, which is on by default, is supported on Apple Watch SE (3rd generation), Series 9, Ultra 2, and later.Related Roundup: Apple Watch 11Buyer's Guide: Apple Watch (Caution)
This article, "Apple Watch: 15 Tips Every Owner Needs to Know" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
OpenAI has brought its Codex coding agent to the ChatGPT mobile app, providing iPhone and Android users with remote access to Codex sessions running on a Mac.


"Codex is now in the ChatGPT mobile app so you can stay in the loop from anywhere while Codex gets work done across your laptops, devboxes, or remote environments," said OpenAI, announcing the feature.

Codex remains a standalone app on Mac, but the mobile integration lives inside the existing ChatGPT app on iPhone and Android. Setup is pretty simple. First, update the Codex Mac app and ChatGPT mobile app, then select the new "Codex mobile" section in the Mac app interface. Scan the QR code it shows with your phone, and you're done.

Once connected, the mobile app loads the live state from the Mac where Codex is running, and you can pick up active chats or projects from the desktop, get notifications when Codex finishes a task or needs input, and begin new tasks by sending a message from your phone.

From the ChatGPT app, users can also review outputs, approve commands, switch between models, and add new prompts across active threads. Files, credentials, and permissions stay on the machine where Codex is operating, while screenshots, terminal output, diffs, test results, and approval requests flow back to the phone in real time.

OpenAI notes that Codex will access the desktop's files, apps, and browser to complete tasks sent from a phone, and warns users to only pair devices they own and trust.


The feature follows OpenAI's recent launch of a Codex Chrome extension, which lets the agent work directly in the browser to test web apps and pull context across tabs.

OpenAI says support for remotely accessing Codex for Windows will follow soon.Tags: ChatGPT, OpenAI
This article, "OpenAI brings Codex Remote Access to ChatGPT Mobile App" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Waymo recently crossed a major milestone: Over 170 million autonomous miles driven without a single serious crash or injury. For years, autonomous driving was treated as a promise that was always just out of reach — too complex, too risky and not ready for the real world. That argument is no longer credible. Autonomous systems are now outperforming humans in high-speed, high-volume environments. That is not because they are perfect, but because they are faster in the moments that matter.
This is not an article about autonomous cars. Security is approaching the same transition.
The problem was never detection
For the last decade, the security industry has focused on detection. The emphasis has been on generating more alerts, improving signal quality and expanding coverage. These efforts have been meaningful, but we are approaching a saturation point. Despite continued progress in detection, defenders are still falling behind while attackers retain the advantage.
According to CrowdStrike, lateral movement can now occur in an average of just 29 minutes. Within that window, the difference between understanding and uncertainty determines whether an incident is contained or escalates. Visibility remains important, but the ability to move through the OODA loop — understand, orient, decide and act — within an increasingly compressed time window matters more.
Security teams are not constrained by a lack of alerts or data; they are constrained by a lack of answers. Each alert initiates a process that requires analysts to pivot across tools, assemble fragmented context, reconstruct events and determine impact. This process is fundamentally time-bound and in most environments, it still takes hours.
Attackers operate on a much shorter timeline, creating a structural asymmetry that human-driven investigation cannot match. The industry has not failed to improve detection; it has misidentified the primary constraint. Investigation speed is the limiting factor.
Security still runs at human speed
Despite advances in infrastructure, cloud and AI, the underlying workflow of security operations has not fundamentally changed. At its core, security still operates as a human-driven process: Alerts are generated, analysts investigate, context is assembled manually and decisions are made under pressure. This model was sufficient when environments were smaller and attacker velocity was lower, but it breaks down under modern conditions.
Today’s environments generate a volume and diversity of signals that exceed what manual investigation can process within the time window that matters. The limitation is not access to data, but the ability to assemble and interpret it fast enough to act. As a result, teams struggle to move from observation to orientation in time, delaying downstream decisions and response.
Compressing observation and orientation
In a traditional workflow, an alert indicating unusual access to a production workload initiates a sequence of actions — analysts query logs, correlate identity activity, review system changes and attempt to build a timeline. Each step introduces latency, slowing the transition from observation to orientation.
In modern systems, investigation can begin with a structured understanding of the event itself. The investigative sequence is absorbed into the system. By the time the alert is presented, the relevant context has already been assembled: The identity involved, the access path, the changes made and whether the behavior aligns with established patterns or represents risk.
The role of the analyst shifts accordingly, too. Instead of reconstructing events, the analyst evaluates a completed analysis and determines the appropriate response. This compresses the first half of the OODA loop, allowing teams to move from observation to decision with significantly less friction. It reduces latency, improves consistency and aligns the speed of decision-making with the speed of the environment.
From decision to action, without delay
Accelerating investigation addresses only part of the problem. The remaining challenge is completing the OODA loop. Even when teams reach a decision quickly, action is often delayed by manual processes. Remediation requires coordination across systems, validation of impact and careful execution. In practice, this introduces latency between decision and response.
Agent-based remediation removes this delay. Systems can act directly, with human oversight. Once a decision threshold is met, agents can isolate workloads, revoke credentials, block access paths or enforce policy in real time with the oversight of a human to ensure control. These actions are informed by the same contextual understanding generated during investigation, reducing the risk of overreaction while increasing speed.
This closes the second half of the OODA loop, where decisions are not only made faster, they are executed faster and more consistently.
AI compresses the timeline further
As organizations adopt AI, the same constraint becomes more severe. These risks do not introduce a new problem; they accelerate it. AI-driven applications operate at interaction speed, not infrastructure speed. The environment is no longer just workloads, but interactions between users, models and data.
Risks such as prompt injection, model misuse and unintended data exposure unfold quickly and across distributed surfaces. Those risks require rapid understanding and response, often within a single interaction. Managing them requires the same capability: The ability to execute the OODA loop faster than the threat.
With AI adoption, security systems must observe interactions, orient on intent and context, decide on risk and act in real time. Traditional approaches such as periodic testing or surface-level behavioral observation are insufficient. Continuous validation models are emerging, where security systems actively probe for weaknesses and verify defenses on an ongoing basis.
Speed becomes the advantage
Autonomous driving did not succeed because it achieved perfection — it succeeded because it demonstrated better outcomes in critical scenarios. Waymo did not win by seeing more data or generating better alerts; it won by collapsing the time between perception, decision and action faster than a human driver could.

Security is undergoing the same transition. In environments where attackers operate on minute-scale timelines, workflows that depend on human-speed completion of the OODA loop are structurally disadvantaged.  The future of security will not be defined by better visibility or more precise detection. It will be defined by systems that can observe, orient, act and decide — end-to-end — faster than attackers can exploit the environment.
This article is published as part of the Foundry Expert Contributor Network.
Want to join?
View the full article
Unlike most cyber security regulations, the EU’s Cyber Resilience Act is about product safety rather than processes or certification, extending the CE mark from the physical side of products to software, firmware, backend services, and anything with a network connection. It encodes existing best practices, enforces minimum product support lifecycles, and could mean developing stronger relationships with open source projects your organization relies on. And it comes with a deadline: by September 11 this year, you need to have vulnerability and incident reporting processes in place.
Even for organizations already using software bills of materials (SBOMs), following new CRA obligations to report an actively exploited vulnerability in a product within 24 hours, and having to deliver a full report within three days may prove hard to meet.
Although nearly everyone in SaaS alternative Cloudsmith’s recent Artifact Management Report generates SBOMs, only a quarter do that automatically rather than manually or on demand. Over half said a comprehensive report would need significant time and effort, while fewer than a third were very confident they could pass the kind of unexpected software supply chain audit the CRA’s spot checks will require.
“A lot of organizations weren’t doing software supply chain best practices,” says Alison Sickelka, VP of product at Cloudsmith. “And that’s reflected in people having to scramble to figure out how they’re going to generate SBOMs, do reporting, and have all that in place in time.” Sometimes seen as a burden slowing down software development, SBOMs and auditability are now necessities, she adds.
For a lot of CIOs, though, the CRA isn’t even on their radar. “They may think it’s almost a tick box exercise,” says Oli Venn, engineering manager at security vendor WatchGuard, rather than a broad regulation with aggressive reporting requirements covering the entire product lifecycle from planning and design, to support and maintenance.
“If you’re any kind of vendor, or you’re manufacturing or supplying any digital system, whether it’s smart thermostats, coffee machines or anything else that can be connected to the internet or a network, that falls into regulation,” he adds. “If you’ve got developers and consumers using that in any way, then you fall into scope for the CRA.”
Spheres of influence
The CRA applies to software and devices like mobile phones, embedded operating systems, databases, games, network equipment, IoT devices, and even tickets delivered through an app. However, it doesn’t apply to non-commercial open source, but open source foundations have some obligations. And if your product includes open source elements, you’re responsible for making sure they’re compliant. Pure SaaS isn’t covered but client software, appliances, or devices that use SaaS as a backend are.
“The CRA includes backend components, what we call remote data processing solutions, if you have a server side to your product,” says Daniel Ehrenberg, a standards engineer on ETSI’s Cyber EUSR committee.
Products already on sale in the EU don’t have to fully comply with the CRA, unless they get significantly updated, though companies still have to report incidents and vulnerabilities. Yet the act recognizes it may not be possible to address them. Otherwise, the only products exempt are those already covered by more stringent regulations in sectors like automotive and medical.
Product safety
The CRA says digital products have to be secure by design and default, and can’t ship with known vulnerabilities like obvious default passwords that can be exploited. They also must be updatable if such vulnerabilities are found later, as well as minimize their impact by limiting the attack surface and protecting confidentiality and integrity with encryption and reduced data collection. That amounts to a mandate that commercial software must handle them well, explains Ehrenberg, with an effective process to take bug reports.
“There’s been a lot of hope that somehow this won’t happen, but it’ll be a wake-up call to consider all the requirements, starting with a risk assessment,” he says. “When you’re putting a product on the market, you have to do an assessment of the cyber security risks, and have a continuous audit to know what your live dependencies are so you can evaluate whether you need them updated.”
That includes components from vendors. “Be sure they’re staying compliant and reporting any security vulnerabilities,” Venn says. The SBOM requirements are sensible rather than onerous, adds Nigel Douglas, head of developer relations for Cloudsmith. “Do you have visibility into package names and IDs so you can tell if the version in your software supply chain and the code base that users are consuming and paying for carry potentially malicious code that’s going to affect them,” he says. “The main thing is being able to prove you can quickly respond to an incident.”
For open source, it also means assessing projects you rely on. “The CRA mandates knowing about and understanding project health and making informed, intelligent decisions about open source projects you use,” notes Kubernetes steering committee member Kat Cosgrove. Organizations that discover and fix vulnerabilities in open source projects will be required to contribute that upstream, Venn points out. “They can no longer just be consumers of these technologies,” he says. “If they want to use it, they have to be a part of the community.”
Not like the others
Unlike traditional cybersecurity regulations, the CRA focuses not on software development practices and certifications, which Ehrenberg warns may not map to the new requirements, but on the product being sold. “Did you achieve a product that minimizes the amount of data that’s being processed in order to reduce risks related to data if it’s not properly managed?” he asks. “Are you protecting data as it’s at risk and in transit?”
CIOs need to consider the products their organization sells in a top-down way, looking at how they meet security requirements rather than whether the way they’re built checks all the boxes. “It’s a shift in responsibility,” he adds “You’re responsible for the final product, not just making sure the steps were correct.”
Requirements also mandate product support, updates, and lifecycles, in most cases for a minimum of five years of free security updates, all of which go in a declaration of conformity digital products will require from December 2027. The declaration and documentation will need to stay available for 10 years after the product goes on sale, but the SBOM doesn’t need to be public, just available to the market surveillance authorities when they ask for it.
Standards in practise
Different classes of products attract different levels of scrutiny. Most digital products get default regulation under horizontal standards for cybersecurity and vulnerability handling that’s already available in draft form from European standardization organizations.
But important products like including identity management systems, web browsers, password managers, VPNs, and internet access routers, as well as critical products such as hypervisors, PKI infrastructure, hardware security modules, and industrial firewalls, will require more stringent conformity assessments.
These are covered by vertical standards being developed to analyze specific risks, which list potential mitigations like writing a web browser in a memory-safe language. “The CRA doesn’t require you to transition to memory safe languages, nor move off COBOL or anything like that,” Ehrenberg says.
Timelines and fines
As a regulation rather than a directive, the CRA applies without individual European countries passing new laws, and the mechanisms for it to be administered are being set up this summer. “The market surveillance authorities are coming online with their ability to review and approve things, then the individual conformity assessment bodies come online,” Ehrenberg says. The European Union Agency for Cybersecurity (ENISA) will run the single platform for reporting actively exploited vulnerabilities and incidents.
Although the CRA applies fully from 11 December 2027, enforcement will come in gradually and will depend on the technical capacity of the market surveillance authorities, says Ehrenberg. They can insist products be made compliant, restrict their sale, or have them withdrawn or even recalled, as well as levy fines of up to €15 million or 2.5 % of turnover.
“There are probably going to be court battles in the future to interpret this,” Ehrenberg says, as aspects have already been criticized for being too vague and weak. But organizations relying on limited enforcement are missing an opportunity to improve their products and their own security.
Simply better security
With the rise of supply chain attacks, CRA mandates will provide real security benefits by forcing enterprises to track their open source usage and notify end users of issues promptly, says Neil Levine, SVP of products at cybersecurity vendor Anchore. He suggests adopting SBOMs by September to help you comply with reporting requirements, rather than waiting until the 2027 deadline.
Savvy CIOs can also use this as an opportunity to get the resources to deliver improvements. “Most CIOs would want to do these things anyway but just don’t have the bandwidth,” says Venn. “So this is probably a tool for them to go to the board and say they need the budget and the time.”
View the full article
The moment every boardroom dreads
There is a moment in almost every ransomware negotiation — usually around 36 hours, when legal, IT and the CFO are all in the same room — when someone says it out loud: “Let’s just see what the insurance covers.” That instinct, understandable as it is, has become one of the most expensive assumptions in modern business. The threat landscape has moved on.
The insurance market is moving on with it. And the organizations still treating cyber insurance as their primary recovery strategy are flying into a storm with a beach umbrella.
How ransomware became a business
Criminal groups don’t think in generations — they follow the money. Early campaigns were blunt instruments: Mass phishing, opportunistic encryption and hope that enough victims panic-pay. Groups like REvil and Conti figured out that one well-researched enterprise target was worth more than ten thousand spray-and-pray attempts. Ransom demands climbed from hundreds of dollars to tens of millions.
What you’re dealing with now is categorically different from both predecessors. Ransomware 3.0 isn’t primarily about encryption. That’s just the opening move. The real play is owning your leverage — over your operations, your data, your customers and your regulators — simultaneously.
Verizon’s 2024 Data Breach Investigations Report documented ransomware or extortion as a factor in 32% of all breaches, with organized criminal groups accounting for most incidents.
Triple extortion: The mechanics of maximum pressure
Most organisations mentally prepare for one thing when they hear “ransomware” — locked systems, a ransom note, a recovery decision. That framing is now dangerously out of date.
What groups like ALPHV (BlackCat) and Cl0p deploy is a three-layer pressure campaign. Encryption hits first — operations locked, revenue stopped. Then comes exfiltration: Your data was already removed before the encryptor ran, and that threat doesn’t expire when you restore from backup. The third layer is the one most organisations are least prepared for — direct contact with your customers, regulators and shareholders, timed to maximise pressure at the worst possible moment.
They don’t just threaten to follow through. They follow through.
The economic logic here is sound, from the attacker’s perspective. A good backup strategy can defeat encryption alone. Exfiltration cannot. Once your customer records, intellectual property or board communications are in the hands of a criminal group, no backup restores that situation. You are no longer dealing with a technology problem.
Coveware’s ransomware analysis for Q4 2024 consistently shows that data exfiltration now occurs in most enterprise ransomware cases, fundamentally altering the negotiation and recovery calculus.
Ashish Mishra
What the Change Healthcare case tells you about real costs
Consider what happened to Change Healthcare in early 2024. The ALPHV group’s attack on this healthcare payments processor didn’t just encrypt systems — it exposed the personal health information of potentially over 100 million Americans and disrupted pharmacy services across the country for weeks. Parent company UnitedHealth Group reportedly paid approximately $22 million in ransom. The total financial impact, including operational disruption, remediation and ongoing legal exposure, came to approximately $3.09 billion for 2024 alone. Insurance covered a fraction of it.
HHS Office for Civil Rights confirmed it formally opened an investigation into Change Healthcare and UnitedHealth Group, focused on whether protected health information was breached and whether HIPAA Rules were complied with — citing the attack’s unprecedented impact on patient care and privacy.
The numbers from Change Healthcare are worth sitting with, because they reframe the entire insurance conversation in a single case study. In February 2024, the ALPHV group walked into this healthcare payments processor through an unprotected Citrix portal and spent weeks moving through the network before anyone noticed. By the time the encryptor ran, the damage was already done — over 100 million Americans had their personal health information exposed, pharmacy services across the country ground to a halt, and UnitedHealth Group found itself paying approximately $22 million in ransom to a group that took the money and disappeared without delivering the promised decryptor.
The total bill for 2024 came to approximately $3.09 billion. That figure covers operational disruption, remediation, provider support and ongoing legal exposure. The insurance programme covered a fraction of it — and that fraction came after a fight, not automatically.
HHS Office for Civil Rights didn’t wait for the dust to settle. They opened a formal investigation into whether UnitedHealth Group had complied with HIPAA Rules and whether patient privacy protections had held up, framing it publicly as the largest breach of healthcare data in American history. That regulatory pressure didn’t arrive weeks later. It arrived while the organisation was still in active recovery.
Why your insurance policy is not the safety net you think it is
That example points directly to the insurance problem. Cyber insurance was priced and structured for a different threat model. Carriers increasingly include sub-limits for ransomware events, exclusions for nation-state attribution (a category that is deliberately difficult to disprove when it suits an insurer), and requirements around security controls that many policyholders have never actually verified they meet. After a major incident, you may discover that your $10 million policy has a $2 million ransomware sublimit — and that a coverage dispute will run in parallel with your breach response for the next 18 months.
This isn’t theoretical. Merck’s legal battle with insurers after the 2017 NotPetya attack — which attackers attributed to Russian state actors — dragged through the courts for years before a settlement. Merck settled with remaining insurers in January 2024 — just days before New Jersey Supreme Court oral arguments — after the appellate court ruled that the hostile/warlike action exclusion did not apply to the NotPetya cyberattack on a non-combatant firm.
On another side, Lloyd’s of London subsequently mandated that all standalone cyber policies must exclude losses arising from state-backed cyber operations, effective March 2023. The market is not moving in favour of policyholders.
Lloyd’s of London’s Market Bulletin Y5381, published in August 2022, required all standalone cyber policies to exclude losses arising from state-backed cyber operations, effective from 31 March 2023 — in direct response to coverage disputes arising from state-attributed attacks.
None of this means you shouldn’t carry cyber insurance. You should. But the mental model must change. Insurance is a financial transfer mechanism for residual risk — the risk that remains after you’ve built meaningful defences.
What a mature incident response architecture looks like
What contains a triple extortion event is a mature incident response architecture. That means several things working in concert: Network segmentation that limits an attacker’s lateral movement after initial access; endpoint detection and response tooling that can identify suspicious behaviour before encryption begins; an offline or immutable backup strategy that survives even a sophisticated attacker who has spent weeks inside your environment; and a rehearsed response capability that doesn’t require you to learn the playbook during the incident itself.
The “rehearsed” part is where most organisations fall short. Tabletop exercises are valuable, but they rarely simulate the full chaos of a real event — the communication blackouts, the pressure from the CEO’s office, the media calls starting before you’ve even confirmed the scope.
MGM Resorts’ 2023 ransomware attack, attributed to Scattered Spider, demonstrated what happens when the human layer fails, even if the technology layer is adequate. Social engineering of the IT help desk gave attackers initial access. The subsequent disruption cost the company an estimated $100 million in lost revenue and remediation costs in a single month.
Guidance: NIST’s Cybersecurity Framework 2.0 provides the most widely adopted reference architecture for incident response capability maturity, covering identification, protection, detection, response and recovery functions.
The only bet that pays off in both scenarios
The uncomfortable truth your board needs to hear is this: The question is no longer whether your organisation will face a sophisticated threat actor. For any organisation of meaningful size, operating in a connected supply chain, with digital customer relationships, the question is how well-prepared you are when it happens. The economics of ransomware as a criminal enterprise have never been stronger. Attack-as-a-service platforms have lowered the barrier to entry. Ransom payment data is analysed and used to calibrate future demands. These groups study your financial filings.
Investing in incident response capability — in people, process and technology — is not a cost centre decision. It’s the only bet that pays off in both the prevention scenario and the response scenario. Insurance pays out after the damage is done. A mature response architecture reduces the damage itself.
The organisations that navigated the Cl0p MOVEit campaign of 2023 with the least disruption weren’t the ones with the biggest insurance policies. They were the ones who had mapped their data flows, limited unnecessary MOVEit exposure and had a response team that could move within hours rather than days.
That’s the standard you’re competing against now.
This article is published as part of the Foundry Expert Contributor Network.
Want to join?
View the full article
Microsoft has disclosed a new security vulnerability impacting on-premise versions of Exchange Server that it said has come under active exploitation in the wild. The vulnerability, tracked as CVE-2026-42897 (CVSS score: 8.1), has been described as a spoofing bug stemming from a cross-site scripting flaw. An anonymous researcher has been credited with discovering and reporting the issue. "View the full article
The U.S.Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added a newly disclosed vulnerability impacting Cisco Catalyst SD-WAN Controller to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to remediate the issue by May 17, 2026. The vulnerability is a critical authentication bypass tracked as CVE-2026-20182. It'sView the full article
The following is the list of F5 Distributed Cloud Services technical knowledge updates:
Data Residency and Processing
Added a new section that explains the customer data retention policy for Bot Defense and Data Intelligence. See Data Retention Policy.
View the full article
Researchers have found a critical vulnerability in the widely used Nginx web server that can potentially lead to remote code execution under certain conditions. The flaw is a heap buffer overflow that has gone undetected in the program’s code for the past 18 years.
Tracked as CVE-2026-42945, the vulnerability is one of 4 bugs found in Nginx by researchers from security startup DepthFirst AI, using their LLM-powered platform. It adds to the increasing number of flaws that security scanners and humans have missed in high profile open-source projects over the years, but which have been discovered with the help of AI models in recent months.
Nginx is one of the most popular web servers, powering almost one third of all websites on the internet, and is integrated into many commercial products as well. The software is also commonly used as a reverse proxy, load balancer and cache for other web applications and servers.
The CVE-2026-42945 vulnerability is located in ngx_http_rewrite_module, a component that handles URL rewrites, and impacts Nginx versions from 0.6.27 to 1.30.0. The issue has been given a 9.2 CVSS severity score and was patched in versions 1.31.0 and 1.30.1.
The commercial product, Nginx Plus, owned and developed by network and application security firm F5, is also vulnerable, and received patches in versions R36 P4, R32 P6 and 37.0.0. Other F5 products based on Nginx open source and Nginx Plus are impacted, but have not yet received updates, including Nginx Instance Manager, F5 WAF for Nginx, Nginx App Protect WAF, F5 DoS for Nginx, Nginx App Protect DoS, Nginx Gateway Fabric, and Nginx Ingress Controller.
“This vulnerability exists when the rewrite directive is followed by a rewrite, if, or set directive and an unnamed Perl-Compatible Regular Expression (PCRE) capture (for example, $1, $2) with a replacement string that includes a question mark (?),” F5 said in its advisory. According to the company, exploitation will result in a denial of service condition in the form of a server crash and, on systems with Address Space Layout Randomization (ASLR ) disabled, arbitrary code execution.
Achieving RCE
While the proof-of-concept (PoC) exploit developed by DepthFirst and shared with F5 did not include an ASLR bypass, the researchers believe it is possible to achieve one. ASLR is a memory corruption exploit mitigation technology that’s present and enabled by default in most modern operating systems.
“Nginx uses a multi process architecture where worker processes fork from a single master process,” DepthFirst researcher Zhenpeng Lin said in a blog post. “Because of this design, the memory space is duplicated exactly for every child worker. This means the heap layout remains entirely deterministic across different workers. If our exploit fails and crashes a worker, the master process simply spawns a new one with the exact same memory layout. This allows us to safely try multiple times until we succeed without worrying about the worker crashing and changing the memory layout. Theoretically, we could leverage this design to leak ASLR by progressively overwriting pointers byte by byte.”
The researchers also believe the Nginx configurations required to exploit this vulnerability are common. For example, URL rewrite rules are often used when migrating APIs endpoints to new locations without causing disruptions to external clients that still try to query the old URL. The set directive can be used to store the original path, or parts of it, in a custom variable to maintain state, route endpoints dynamically, or to pass it to the backend application for audit and logging purposes.
“Together, these two directives are common building blocks in API gateway configurations,” Lin said.
Since the proof-of-concept exploit has been published on GitHub, users are advised to upgrade to a patched version as soon as possible, as Nginx vulnerabilities have been exploited by attackers in the past. Denial of service alone is a serious risk to web servers, even without the ASLR bypass posited by the researchers.
The other three vulnerabilities disclosed by DepthFirst and patched in the new Nginx releases can also lead to denial of service, memory leaks, or data modification. They are tracked as CVE-2026-42946 (CVSS 8.3 – high severity), CVE-2026-42934 (CVSS 6.3 – medium) and CVE-2026-40701 (CVSS 6.3 – medium).
View the full article
Linux admins reeling from handling last month’s CopyFail and last week’s Dirty Frag kernel vulnerabilities have a new headache to deal with: Fragnesia.
“This is a significant vulnerability,” Robert Beggs, head of incident response firm DigitalDefence, told CSO. “It is bypassing traditional filesystem permissions that are present and enforced (for example, ‘file is owned by root’, or ‘file is read-only’) to allow manipulation without touching the disk.”
Similar to Dirty Frag, Fragnesia (CVE-2026-46300) is a local privilege escalation hole that exploits a vulnerability in the XFRM ESP-in-TCP subsystem to achieve a memory write primitive in the kernel. XFRM is an IP framework intended for packet transformations, and ESP-in-TCP (Encapsulating Security Payload in TCP) is a networking technique used to encapsulate IPsec ESP packets inside TCP segments.
A proof of concept (PoC) exploit is already publicly available.
The good news, Beggs said, is that the vulnerability can’t be exploited remotely. An attacker needs local access to trigger specific code paths and be able to control local socket operations and manipulate packet fragmentation.
Still, he added, any unprivileged user can exploit the bug on a vulnerable system to corrupt security-sensitive files in memory, such as privileged access management configuration, password, systemd service files, or cron jobs.  Although the attacker cannot modify the file on the disk, modifying in-memory files can trick privileged processes, alter system behavior, execute arbitrary code, and escalate privileges on the system, he said. 
Linux distributions including Red Hat, Ubuntu, AlmaLinux and others are pushing out patches or mitigations; CloudLinux said a patch is being tested.
In a statement to CSO, Mike McGrath, Red Hat’s vice-president of Core Platforms, said issuing mitigations and fixes for privilege escalations like Fragnesia are a top priority.
“We have published workarounds for the esp4 and esp6 kernel modules that we feel provide protection to customers in the immediate term while we work with the upstream community to identify a permanent fix in the form of a patch,” he said.
According to Linux support provider TuxCare, systems running the affected skbuff code paths, including kernels that have already received the Dirty Frag fix, are impacted. The public PoC requires systems with the configuration option CONFIG_INET_ESPINTCP to access the bug, so kernels built without it block this exploit. But the underlying skbuff defect may be reachable through other paths. 
Microsoft urges Linux users and organizations to apply the patch as soon as possible by running update tools. If patching is not possible at this point, consider applying the same mitigations as for Dirty Frag, such as assessing whether esp4, esp6, and related xfrm/IPsec functionality can be temporarily disabled safely, restricting unnecessary local shell access, hardening containerized workloads, and increasing monitoring for abnormal privilege escalation activity.
Related content: Kill switch for Linux kernel features proposed to improve security
Beggs advises system administrators to confirm kernel exposure by reviewing version numbers, and then update to a patched kernel if necessary and reboot the affected system. If ESP-in-TCP is not required, disable the module and block its use; this mitigation can also be immediately applied until patching is complete. Because the vulnerability requires local access, make sure that basic steps such as enforcing MFA for privileged accounts, disabling of unneeded shell access, and enforcing least privilege are all in place.
Beggs also said admins may wish to increase monitoring of privileged processes (PAM, systemd, cron) and look for unexpected restarts, unexpected config reloads, and sudden privilege escalations.
View the full article
Rumors suggest Apple plans to expand Apple-designed modems to the entire iPhone 18 lineup, ending support for Qualcomm modems. The transition will bring speed and efficiency improvements, along with a little-known privacy benefit.


In iOS 26.3, Apple added a Limit Precise Location setting that cuts down on the amount of location data that's available to mobile networks, improving user privacy.

Mobile networks determine your location using information from cellular towers that a device connects to, but with Limit Precise Location enabled, some of the data typically provided to mobile networks is restricted. Instead of seeing location down to a street address, carriers may be limited to the neighborhood where a device is located.

The problem is that this feature is currently only available on devices with an Apple-designed C1 or C1X modem, which includes the iPhone Air, iPhone 16e, iPhone 17e, and M5 iPad Pro. Devices with Qualcomm modems like the iPhone 17 Pro models do not have the Limit Precise Location setting.

With the iPhone 18 Pro models and the iPhone Fold expected to use Apple modem technology, this is likely a privacy option that is set to expand to the full iPhone lineup.

Reducing location precision does not impact signal quality or user experience, nor does it affect the precision of location data provided to emergency responders during an emergency call. It is only meant to limit the location data given to cellular carriers, and it is distinct from location data shared with apps through Location Services.

While Apple's next set of iPhones will all likely have the new privacy feature, carriers do have to implement support. So far there are a limited number of carriers that have added the feature, but if it expands to the entire iPhone lineup and there is customer demand, it could see more widespread adoption.

In the United States, only Boost Mobile supports limiting precise location data, but EE, BT, and Sky all support it in the UK. Carriers in Austria, Germany, Denmark, Ireland, and Thailand have also adopted support, with a list available on Apple's website.

The C2 modem that Apple is rumored to be working on is more capable than the C1 or C1X, and it will offer similar performance to Qualcomm's newest modems. It is expected to support mmWave 5G, which is not a feature of the C1 or C1X.Related Roundups: iPhone 18, iPhone 18 Pro, iPhone FoldRelated Forum: iPhone
This article, "Apple's iPhone 18 Modem Switch Comes With a Quiet Privacy Benefit" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Apple's iPad that's just an ‌iPad‌ with no Air or Pro attached is its most appealing tablet because of the affordable starting $349 price tag, but if you've been thinking about buying one, you should wait.


Apple refreshed the ‌iPad‌ in March 2025, so it's over a year old. That's reason enough not to buy when there's a new model on the horizon, but this year, there's even more to lose by purchasing now.

The 2025 ‌iPad‌ has an A16 chip inside that does not support Apple Intelligence. It does not have features like Writing Tools, Image Playground, Clean Up, Live Translation, notification summaries, Smart Reply, Priority Messages in Mail, Visual Intelligence, and multiple other AI-related tools.

‌Apple Intelligence‌ is still new so it might not sound like a big deal to miss out on those capabilities, but not having access to it is going to become more of a problem as Apple continues implementing new AI features.

Rumors suggest there are big changes coming in iOS 27. Siri is going to get smarter and turn into a full chatbot, the Camera app is going to get ‌Visual Intelligence‌ integration, the Photos app will have AI image editing tools, Shortcuts may be more automated, and there are probably features coming that haven't even been rumored yet.

The A16 ‌iPad‌ will likely feel outdated in the next year or two because of the feature set it won't have access to.

The next ‌iPad‌ is likely to get the A18 chip, and the A18 does support ‌Apple Intelligence‌. It will have faster performance, more RAM, and most importantly, future-proofing and access to the AI features that Apple is investing in.

Holding out for the next ‌iPad‌ will take some patience, because right now, we don't know when it's coming. Updating the ‌iPad‌ alongside the low-cost iPhone 17e would have made sense, but that didn't happen. A new entry-level ‌iPad‌ isn't coming in the first half of 2026, so we're likely going to be waiting until September or October.

Bloomberg's Mark Gurman said in March that an updated low-cost iPad is "ready to go" and "still coming this year." Even though the wait may be several months, we think it's worth holding out for the next ‌iPad‌ instead of buying now because of the upgrade that comes with ‌Apple Intelligence‌ support.Related Roundup: iPadBuyer's Guide: iPad (Don't Buy)Related Forum: iPad
This article, "It's a Bad Time to Buy the Low-Cost iPad" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
TSMC has been the exclusive supplier of Apple's systems-on-a-chip since 2016, but that 10-year streak could be nearing its end.


Apple supply chain analyst Ming-Chi Kuo today said that Intel has "kicked off" small-scale testing of lower-end iPhone, iPad, and Mac chip fabrication, with production expected to ramp up throughout 2027 and 2028. Kuo did not indicate exactly which of Apple's A-series and/or M-series chips would be manufactured by Intel.

Apple is utilizing Intel's 18A process for these chips, and it is evaluating Intel's other advanced-node technologies, according to Kuo.

By sourcing chips from two suppliers, Apple can negotiate lower costs and bolster supply. In this case, Apple rekindling a partnership with Intel could win it favor with the Trump administration, which wants more U.S. manufacturing. However, Kuo said Taiwan's TSMC will remain responsible for more than 90% of Apple's chip supply.

There is no indication that Intel would play a role in designing the iPhone chips, with its involvement expected to be strictly limited to fabrication. That would differ from the era of Intel Macs, which used Intel-designed processors with x86 architecture. Apple began transitioning away from Intel processors in Macs in 2020.

All in all, these would be Apple-designed chips manufactured by Intel in the U.S., for use in some lower-end iPhone, iPad, and Mac models.

Apple's potential return to Intel has been reported by numerous sources by this point, but an official announcement has still yet to be made.Tags: Intel, Ming-Chi Kuo
This article, "Report: Intel is Testing Production of Some iPhone, iPad, and Mac Chips" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Last year, accessory maker Nimble came out with the Wally Stretch power adapters, and they've become some of my favorite charging options.


The Wally Stretch is available in 35W and 65W options, and it has an excellent design. It's a simple cube with prongs that fold down, a retractable USB-C cable, and an extra USB-C port. The 65W model that I tested is thicker than the comparable 70W Apple charger, but it's smaller in length and width.


Nimble's charger is just about two inches all around, and it looks like a block. While Nimble sells the 35W charger in black and the 65W charger in white, Apple offers 65W Wally Stretch in better colors. It comes in teal with a yellow accent and a gold-topped cable, along with deep purple with a pink accent and a silver-topped cable. I'm a big fan of any charger that's not your standard black or white, and I use the Wally Stretch chargers with my desktop power strip.


The retractable USB-C cable measures in at two feet, which is a great length for desktop use. It's also worked well for traveling between locations, and two feet seems to be an all-around useful length. Some people prefer much longer cables, and there aren't options with the Wally, which is a downside. There is, however, an extra USB-C port at the bottom where a longer cable can be plugged in if desired.


65W is enough for me to power even a 16-inch MacBook Pro when it's not under heavy load, and it's more than sufficient for my MacBook Air, iPad Pro, and iPhone. Even when charging two of the latter three devices at the same time, I get fast charging.


A retractable cable paired with an extra USB-C port all in a small package makes the Wally Stretch one of my most flexible power adapters. I would pick it over a standard Apple charger in all situations, and over many third-party chargers. The only situation where I reach for something else is when I need more than two ports or higher watts, but that doesn't happen too often. I think the only thing that would make the Wally Stretch better is an XL version with two retractable cables and 140W.


Nimble also makes power banks that I like a lot, again because they come in colors other than your standard black or white. The Nimble 10k Champ Portable Charger I tested is teal with yellow accents, and it has some design elements I've found useful.


It's small, and it tucks nicely into a pocket or a bag. It has a lanyard, which is a feature that I find surprisingly useful for a power bank. I can always track it down in my backpack, and I can put it around my wrist when I'm charging my iPhone with a short cable. I wouldn't have thought a lanyard would make a difference, but I have a decent selection of power banks, and I always pick the ones with the lanyard first when I need one.

The Nimble Champ is 3.4 inches long, 2.3 inches wide, and under an inch thick, plus it's lightweight at six ounces. There's a yellow button on the front that can be pressed to see remaining power level, which is reflected via four LED dots. That's standard for power banks, and it's fine. Some power banks have a little LED display that shows exact level, and I do prefer the more exact readout, but it's not a make-or-break feature.

There are two USB-C ports for charging an iOS device or for charging the power bank, and while it does come with an included USB-C cable, I wish it was a color-matched cable instead of a plain cable. A power bank designed to stand out with a bright color should have a cable that goes along with it, but I do understand the plain cable choice because it keeps costs lower. Nimble's power bank is $60, which makes it reasonably priced.


I have an Anker Nano power bank with a lanyard and a retractable cable and it is the one that I love the most. Nimble Champ is my second pick, just because I like integrated cables that don't require me to hunt down a cable and that don't result in excess cable I don't need. Nimble does actually have an updated version with a retractable cable and an exact readout of charging capacity, but it's more expensive at $80.

This is a 10K power bank, so it has enough power to charge an iPhone 17 Pro Max from 0 to 100 and then some, but it is limited to 20W fast charging. Apple's iPhone 17 models charge to 50 percent in 20 minutes with a 40W adapter, so you're not going to get maximum charging speeds with the Nimble Champ. I probably wouldn't choose the Nimble Champ in a situation where you need to optimize for the fastest possible charging for an ‌iPhone 17‌, but it's great if charging that's a bit slower isn't an issue.

Bottom Line

Nimble's Wally is a useful power adapter for everything from the Mac to the iPhone, and the retractable cable is super convenient. I'd definitely recommend it to anyone looking for a power adapter for desktop or travel use.

The Nimble Champ is a budget-friendly power bank that's brightly colored and slim enough to carry in a pocket. It's a good pick as long as you don't need the fastest USB-C charging.

How to Buy

Nimble's 65W Wally Chargers can be purchased from the Nimble website for $42, but you can get the colorful versions from Apple for $60. The 10K Nimble Champ Charger is $60 from Nimble or from Apple.
This article, "Nimble Wally Stretch Review: A Colorful Charger With a Retractable USB-C Cable" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
OpenAI is preparing to potentially take legal action against Apple due to a "strained" relationship with the iPhone maker, according to Bloomberg's Mark Gurman.


The two companies reached a partnership in 2024 that saw ChatGPT integrated into features like Siri and Image Playground across iOS, iPadOS, and macOS. iPhone users can also subscribe to ChatGPT directly via the Settings app, with Apple taking a cut of revenue. Ultimately, though, the report said OpenAI expected ChatGPT to be more deeply integrated across additional Apple apps and to have more prime placement within Siri.

OpenAI executives also believe that Apple has not sufficiently advertised the integration, resulting in fewer customers knowing about it.

OpenAI initially believed the deal could generate billions of dollars per year in subscription revenue, but that "hasn't come close to happening." This expectation was seemingly set by Apple, which reportedly characterized the agreement as being an opportunity on par with its multi-billion-dollar deal with Google for search in Safari.

Apple's culture of secrecy is said to have resulted in OpenAI not knowing exactly how ChatGPT would be integrated on the iPhone, iPad, and Mac.

"They basically said, 'OpenAI needs to take a leap of faith and trust us,'" an unnamed OpenAI executive told Bloomberg. They described the deal as a "failure."

"We have done everything from a product perspective," the executive said. "They have not, and worse, they haven't even made an honest effort."

Siri users must use the word "ChatGPT" when speaking or typing a command in order to get results from OpenAI's chatbot. ChatGPT responses shown within the Siri interface also contain limited information compared to the ChatGPT app.

OpenAI's attempts at renegotiating the deal have apparently stalled.

As a result of the shortcomings, OpenAI is considering taking legal action against Apple, according to the report. OpenAI is said to be weighing a range of options, including sending Apple a letter alleging breach of contract, without necessarily filing a full lawsuit. However, OpenAI still hopes to resolve the issues outside of court.

iOS 27 is expected to tap into other chatbots like Google's Gemini and Anthropic's Claude, but this is apparently not one of OpenAI's grievances, as its partnership with Apple was never meant to be exclusive. In fact, iOS 27's rumored Siri app with an "Extensions" feature for other chatbots actually might better promote ChatGPT.

For now, though, it appears that OpenAI feels it received the short end of the stick.Tags: Bloomberg, ChatGPT, Mark Gurman, OpenAI, Siri
This article, "OpenAI Considering Legal Action Against Apple Over 'Strained' Siri Partnership" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Anthropic recently announced Project Glasswing, an initiative that enables tech companies like Apple to use its new frontier AI model Claude Mythos Preview to find security vulnerabilities across operating systems and web browsers.


The Wall Street Journal today reported that researchers at cybersecurity firm Calif used Claude Mythos Preview to uncover a new macOS security vulnerability last month. Specifically, they used the model to write code that links together two macOS bugs in a way that resulted in what is known as a privilege escalation exploit.

The security researchers said the exploit would not have been possible with Mythos alone, as it still required their human expertise on top, but it nevertheless proves that AI can assist with discovering software vulnerabilities.

Apple said it was reviewing Calif's report to validate the findings.

"Security is our top priority, and we take reports of potential vulnerabilities very seriously," an Apple spokesperson told The Wall Street Journal.

It is unclear if Apple has already patched the exploit. Apple's security notes for the macOS 26.5 update released this week mention a fix for a kernel-level vulnerability, and it credits Calif and Anthropic for discovering it. Yet, the report said that Calif only met with Apple this week and suggested that a fix was still coming.

We have reached out to Apple for comment.Related Roundup: macOS TahoeTags: Anthropic, Apple SecurityRelated Forum: macOS Tahoe
This article, "Apple Alerted to macOS Security Vulnerability Uncovered With AI Tool" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Spotify today announced plans to adopt Apple's HTTP Live Streaming (HLS) technology for video podcasts, a move that will allow creators to distribute video shows across both platforms without changing their existing setup.


Apple introduced an enhanced HLS-based video podcast experience for the iPhone, iPad, Apple Vision Pro, and the web at the end of March. The upgrade significantly improves how video shows are delivered and consumed within Apple Podcasts, but Mac and Apple TV support is not yet available.

Spotify says its Spotify for Creators and Megaphone platforms will support Apple's HLS video technology later this year, describing the move as "a major step toward truly platform-agnostic video distribution." The company says it is "actively working on this integration in coordination with Apple" and will share timeline details in the near future.



Monetization will carry over alongside distribution. Spotify says it plans to support "monetization for video content on ‌Apple Podcasts‌ so creators don't have to choose between audience reach and revenue," with further details on how that will work across platforms to follow.

The company noted that video shows must be uploaded directly to Spotify rather than distributed via RSS, which the company says is necessary to enable engagement-based monetization, real-time analytics, and other Spotify-first features. RSS distribution to other platforms, including ‌Apple Podcasts‌, remains unchanged.

Separately, Spotify also announced that several podcast hosting providers are now live with video support through the Spotify Distribution API. Libsyn, Podigee, Audioboom, Audiomeans, and Podspace have all completed integration, allowing creators on those platforms to distribute video content directly to Spotify and monetize eligible content through the Spotify Partner Program. Additional partner integrations are said to be in progress.Tags: Apple Podcasts, Podcast, Spotify
This article, "Spotify to Adopt Apple's Technology for Video Podcasts" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Earlier this week, we began tracking a new all-time low price on the 32GB/1TB M5 MacBook Pro, and now the 16GB/1TB model has joined in on the deals. You can get this 14-inch M5 MacBook Pro for $1,499.99 on Amazon, down from $1,699.00.

Note: MacRumors is an affiliate partner with Amazon. When you click a link and make a purchase, we may receive a small payment, which helps us keep the site running.

At $199 off, this is a match of the lowest price we've ever tracked on this model, and it's available in Space Black and Silver. This is the model that launched in the fall of 2025 as part of a refresh of the MacBook Pro lineup, featuring a 14.2-inch Liquid Retina XDR display and 10-core CPU and 10-core GPU.

$199 OFFM5 MacBook Pro (16GB/1TB) for $1,499.99

You can also still get the 32GB/1TB 14-inch M5 MacBook Pro for $1,799.00, down from $2,099.00. This one is only available in Silver on Amazon. In addition to the M5 deals, Apple's newest M5 Pro and M5 Max MacBook Pro models are also available for new low prices on Amazon.

If you're on the hunt for more discounts, be sure to visit our Apple Deals roundup where we recap the best Apple-related bargains of the past week.



Deals Newsletter

Interested in hearing more about the best deals you can find in 2026? Sign up for our Deals Newsletter and we'll keep you updated so you don't miss the biggest deals of the season!




Related Roundup: Apple Deals
This article, "Get the M5 MacBook Pro for Record Low Price of $1,499.99 on Amazon" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
A widely active phishing-as-a-service (PhaaS) operation known as FlowerStorm has begun using a browser-based virtual machine to conceal credential theft code, marking what researchers say is an escalation in phishing-kit sophistication that could make attacks harder for traditional email and static-analysis tools to detect.
Researchers at Sublime Security said in April that they identified the campaign, which used KrakVM, an open-source JavaScript virtual machine recently published on GitHub, to obfuscate malicious code delivered via HTML attachments in phishing emails.
The campaign targets credentials and multi-factor authentication (MFA) codes for services including Microsoft 365, Hotmail, and GoDaddy, while also supporting adversary-in-the-middle (AiTM) interception techniques designed to hijack authenticated sessions.
“What makes this campaign notable is the adoption of KrakVM as a delivery wrapper within a month of the project’s public release,” the researchers wrote in a report.
The findings highlight how phishing operations are increasingly adopting techniques traditionally associated with sophisticated malware campaigns, including virtualized execution environments and layered obfuscation frameworks.
Browser-based VM used to hide phishing payloads
According to the report, victims receive phishing emails containing HTML attachments disguised as voicemail notices, invoices, or vendor communications. When opened in a browser, embedded JavaScript immediately launches a credential-harvesting workflow tailored to the victim’s environment.
The attack chain uses KrakVM to compile malicious JavaScript into encrypted bytecode, which is executed through a virtual machine running inside the browser.
“KrakVM compiles JavaScript into unreadable bytes,” the researchers wrote, adding that the virtual machine then interprets and executes the payload at runtime.
The approach adds multiple layers of obfuscation designed to complicate static analysis and evade traditional email-security tooling.
While virtual-machine-based obfuscation has long been used in malware packers and software protection systems, its adoption inside large-scale phishing kits appears far less common.
The campaign dynamically adapts to victims
After deobfuscation, the phishing payload loads infrastructure designed to impersonate Microsoft 365 and other login portals while dynamically adapting to targeted users.
According to the report, the malware can determine which authentication provider should be impersonated, preload victim email addresses into phishing pages, and customize branding elements such as company logos and backgrounds.
The phishing kit also enumerates MFA methods registered on victim accounts, including Microsoft Authenticator push notifications, TOTP codes, SMS authentication, and voice verification flows.
When the victim enters credentials, the kit forwards them to a command-and-control server, which attempts a real login against the target service. If the service prompts for MFA, the kit presents the victim with a matching prompt, captures the response, and forwards it to complete the attacker’s session.
Researchers said the framework supports real-time AiTM interception, allowing operators to relay authentication sessions while harvesting credentials and MFA tokens.
“A widely known unique feature of FlowerStorm is its capability for advanced AiTM and MFA interception,” the report said.
Detection challenges grow for defenders
The combination of VM-based obfuscation and AiTM-capable payload creates a detection gap for email security tools.
Sublime Security said its own Autonomous Security Analyst system identified the attack as malicious, partly because of the HTML attachment’s use of “heavily obfuscated JavaScript with custom virtual machine bytecode.”
The researchers also noted that both KrakVM and FlowerStorm appeared to operate close to their default configurations, suggesting the campaign did not require advanced technical sophistication from operators.
That raises concern that VM-based obfuscation techniques could spread quickly across phishing ecosystems if tooling becomes easier to operationalize, the report added.
The broader phishing ecosystem is evolving
The campaign has targeted sectors including local government, logistics, retail, communications, and real estate, according to the report. Researchers also identified infrastructure using domains designed to resemble court systems, enterprise portals, and Microsoft-related services.
Sublime published 153 indicators of compromise, including dozens of subdomains on cloud object storage services across regions, including Singapore, Bangkok, Frankfurt, Tokyo, Seoul, Jakarta, and Ashburn.
The researchers also identified domain naming patterns that overlap with prior FlowerStorm reporting, including German-language domains assembled from English words to mimic legitimate business names.
Sophos had documented FlowerStorm in December 2024, after the kit emerged following a disruption to the Rockstar2FA phishing service. The researchers said they had found no evidence linking the KrakVM developer to FlowerStorm operations.
The findings come as security teams face increasingly sophisticated phishing campaigns that blend credential theft, MFA interception, session hijacking, and anti-analysis techniques into unified attack chains.
“This campaign likely represents only the earliest use of KrakVM’s obfuscation capabilities,” the researchers wrote. “We anticipate more complex implementations as its adoption grows.”
View the full article
According to the latest rumors, Apple is close to launching its next-generation iPad mini. So what should we expect from the successor to the iPad mini 7 that Apple released over a year ago? Read on to find out.


Processor and Performance

Apple is working on a next-generation version of the iPad mini (codename J510/J511) that features the A19 Pro chip, according to information found in code that Apple mistakenly shared in August.

Apple's A19 Pro chip since debuted in the iPhone Air and iPhone 17 Pro models. The iPhone 17 Pro models include the higher-end version of Apple's A19 Pro chip with a 6-core CPU and a 6-core GPU, while the iPhone Air uses a mid-tier A19 Pro chip with one fewer GPU core than the A19 Pro chip used in the iPhone 17 Pro and Pro Max.

If the code leak is accurate for the iPad mini 8, Apple is likely to use the mid-tier A19 Pro chip found in the iPhone Air. This is based on the fact that the A17 Pro chip used in the iPad mini 7 has a 6-core CPU with two high-performance cores and four efficiency cores, along with a 5-core GPU, compared to the 6-core GPU found on the A17 Pro used in the iPhone 15 Pro.

Apple built the A19 Pro chip on an upgraded third-generation 3-nanometer N3P process for modest speed and efficiency improvements. The chip includes a 16-core Neural Engine, next-generation dynamic caching, and unified image compression.

The GPU in the A19 Pro has an upgraded architecture with a larger cache, more memory, and Neural Accelerators that are built into each core. Apple says that this change provides 3× the peak GPU compute over the prior-generation chip. There's also an upgraded 16-core Neural Engine for AI tasks.

There is an outside chance that Apple opts for the A20 Pro chip for the new iPad mini. The claim has been made by a MacRumors tipster who analyzed a macOS kernel debug kit containing internal Apple codenames. However, the iPad mini has not always received Apple's newest A-series chip at the time it was updated, so the A19 Pro cannot be ruled out at this time. iPhone 18 Pro models are also expected to use the A20 Pro chip, which will reportedly be fabricated with TSMC's advanced 2nm process.

Display


Apple's plan to transition the ‌‌iPad mini‌‌ from an LCD to an OLED display is widely rumored. According to Bloomberg's Mark Gurman, the small form-factor tablet is likely to be the next Apple device to adopt OLED. According to a Chinese leaker with sources in Apple's supply chain, Apple has evaluated a Samsung-made OLED display for its next iPad mini model.

It remains unclear whether the iPad mini 8 will feature a higher refresh rate than the 60Hz LCD display used in the existing iPad mini 7, but since the new base iPhone 17 now uses a 120Hz ProMotion panel, it would be reasonable to expect the same on the first OLED iPad mini. A separate report has suggested the ‌‌‌iPad mini 8‌‌‌'s screen could increase in size from 8.3 inches to 8.7 inches with the adoption of OLED.

OLED panels can individually control each pixel, resulting in more precise color reproduction and deeper blacks compared to other common display technologies. They also provide superior contrast, faster response times, better viewing angles, and greater design flexibility. All of Apple's flagship iPhones use OLED panels, and in May 2024 the company brought the display technology to the iPad Pro for the first time.

Unlike Apple's ‌iPad Pro‌ models, which feature two-stack low-temperature polycrystalline oxide (LTPO) OLED panels‌, the ‌iPad mini‌ may have a single-stack low-temperature polycrystalline silicon (LTPS) panel, which would make it dimmer.

Chassis Design


Apple is reportedly working to give the iPad mini 8 a more water-resistant design, according to Bloomberg's Mark Gurman. The updated casing would bring protection levels closer to those of the iPhone, making the tablet safer for use in damp environments.

To achieve this, Apple is said to have designed a new vibration-based speaker system that eliminates the need for traditional speaker holes. By using sound-emitting surfaces instead of open grilles, the company can reduce potential entry points for water and dust, resulting in a more sealed, durable enclosure.

On the iPhone, Apple relies on adhesives and gaskets to shield speakers and other openings from moisture. The iPad mini's approach appears to go further, doing away with the holes altogether. Current iPad mini models lack any official IP rating, but the upcoming version could mark the first in the lineup to feature a certified level of water protection.

Apple patents could offer further clues to the new design direction. For example, a 2014 patent outlines a "mechanically actuated panel acoustic system" that vibrates flat surfaces to generate sound, effectively turning parts of a device's chassis into a speaker diaphragm. This could potentially allow Apple to produce audio without visible speaker holes. The patent suggest Apple has been building towards a sealed, vibration-based acoustic system for several years.

Release Date


According to research firm Omdia, the ‌‌iPad mini‌‌ is expected to adopt an OLED display in 2027. However, Korea's ET News and ZDNET Korea have both suggested that the iPad mini will be updated with an OLED display in 2026. Bloomberg has also said the update could come as soon as this year.

The most recent word on the subject comes from Weibo-based leaker Instant Digital, who claims the OLED iPad mini will be launched in the second half of 2026 at the earliest.

In May 2024, it was reported that Samsung Display had started developing sample OLED panels for a future ‌iPad mini‌, with plans to initiate mass production at its facility in Cheonan in the second half of 2025. The same report claimed that Apple will bring an OLED panel to the iPad Air alongside the ‌iPad mini‌ in 2026, though Apple only refreshed the iPad Air in March, and more recent reporting suggests an OLED iPad Air will arrive in early 2027.

The latter outlook aligns with a December report by analyst firm Display Supply Chain Consultants (DSCC) that said an 8.5-inch OLED iPad mini is planned for a 2026 launch, while 11-inch and 13-inch OLED iPad Air models are expected to follow in 2027.

Ultimately, there are no rumors suggesting exactly when the next ‌iPad mini‌ will be released, but a launch later in 2026 has a high probability.

Pricing


Apple's ‌iPad mini‌ with OLED display technology and improved water resistance is expected to be more expensive, and Apple could charge up to $100 more for the device, according to Bloomberg's Gurman. The ‌iPad mini‌ is currently priced starting at $499. Gurman has previously argued that Apple should consider a lower-end version of the mini, or at least a change to its current $499 starting price, given that it's up against rival products that cost a lot less.

However, Apple users who are looking for a more affordable option should probably consider the 10th-generation iPad instead. Starting at $329, the iPad offers many iPad mini features, such as Touch ID and Center Stage, but at a lower price that balances functionality and affordability. Related Roundup: iPad miniTag: OLEDBuyer's Guide: iPad Mini (Don't Buy)Related Forum: iPad
This article, "OLED iPad Mini: Release Date, Pricing, and What to Expect" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
A newly disclosed authentication bypass flaw in the open-source AI orchestration framework PraisonAI was probed by internet scanners less than four hours after its public disclosure.
According to Sysdig observations, roughly three hours and 44 minutes after a GitHub advisory dropped, a scanner identifying itself as “CVE-Detector/1.0” was already looking through the exposed PraisonAI instances for exact vulnerable endpoints.
The bug involves a legacy Flask-based API server component “src/praisonai/api_server.py” in PraisonAI that shipped with authentication disabled by default. The issue affects versions 2.5.6 to 4.6.33, and has been fixed in version 4.6.34.
“Authentication disabled by default in a development-grade API server is a known anti-pattern, and its blast radius is bounded by whatever permissions the operator gave the agent workflow,” said Trey Ford, chief strategy and trust officer at Bugcrowd. “Any organization that accelerated AI agent adoption without auditing network binding, authentication defaults, and credential exposure in agent configuration files now faces risk it likely hasn’t quantified.”
Sysdig said a GitHub advisory was published around 13:56 UTC on May 11, and probing started at 17:40 UTC.
Authentication was disabled by default
Sysdig said the vulnerable component was a PraisonAI legacy API server, where authentication protections were effectively disabled by design. The researchers noted that any reachable caller could interact with agent workflows without valid tokens.
“PraisonAI ships a legacy Flask-based API server that hard-codes ‘AUTH_ENABLED = False’ and ‘AUTH_TOKEN = None’,” Sysdig researchers said in a blog post. “The check_auth() helper returns True whenever authentication is disabled, so the two “protected” routes fail open by design.”
The flaw, tracked as CVE-2026-44338, received a severity rating of CVSS 7.3 out of 10, but is being considered an urgency, considering attackers are already looking to exploit it.  “Any AI service reachable from the internet should be treated as a production asset with controls around authentication, network segmentation, and monitoring,” said Vineeta Sangaraju, AI Research Engineer at Black Duck, urging organizations to patch immediately.
Sysdig’s researchers said the initial reconnaissance traffic appeared generic at first, targeting common internet-exposed paths such as /./.env and /admin. Minutes later, however, the scanner pivoted to PraisonAI-specific endpoints including “/praisonai/version.txt”, “/docs”, “/api/agents/config”, and “/api/agents.”
Researchers warned that a successful exploit could escalate to serious breaches. “The bypass itself is not arbitrary code execution,” they said. “But because it removes authentication from a workflow trigger that an operator deliberately exposed to do something useful, the impact ceiling is whatever that workflow is allowed to do.”
Mitigations and recommendations
Sysdig urged organizations to immediately upgrade to PraisonAI version 4.6.34 or later, which removes the vulnerable legacy API behavior and introduces stronger authentication protections.
The researchers also recommended discontinuing use of the legacy “api_server.py” entrypoint entirely, noting that exposed instances running older configurations remain vulnerable to unauthenticated access attempts.
To support detection efforts, defenders were advised to monitor for requests containing the “CVE-Detector/1.0” user-agent string, along with suspicious requests targeting /agents, /chat, /api/agents, and related MCP endpoints. “Until an upgrade is possible, network-layer monitoring catches this class of traffic cleanly because the bypass leaves no missing-auth signal in the application logs,” the researchers noted.
View the full article
Apple's interest in expanding its Formula 1 streaming deal for Apple TV beyond the United States may have stalled, after Sky Sports signed early renewals to retain the sport's broadcast rights across its largest European markets.


Sky and F1 jointly announced on May 6 that Sky will remain F1's exclusive live broadcast partner in the UK and Ireland through the 2034 season, and in Italy through 2032. The five-year extension adds to a UK and Ireland deal that was already running through 2029, so it won't impact any immediate plans Apple may have had, but it certainly pushes those markets further out of reach. Sky's early move secured the rights before they could go to open tender.

Sky and F1 did not disclose the value of the deal, but trade publication IBC reported that the UK and Ireland portion is worth around £200 million (around $265–270 million) per season, while other reports put the total figure at around £1 billion (around $1.34 billion).

The deal follows recent comments from Apple's senior vice president of services Eddy Cue at the Autosport Business Exchange in Miami. According to a report from MotorBiscuit, Cue said that clinching its F1 streaming rights in the U.S. first was "undoubtedly the best strategy," adding: "I hope we can expand into other markets."

Sky may have walled off the British, Irish, and Italian markets for now, but other major European deals remain open – Canal Plus holds French rights only through 2029, for example.

Apple's five-year U.S. deal began with the 2026 season, and Apple has already folded its coverage into its wider offerings, with a dedicated F1 section in the Apple TV app, race tracking in Apple Sports, F1 circuit guides in Apple Maps, and playlists in Apple Music.
This article, "Apple's F1 Streaming Ambitions Hit Wall as Sky Renews European Rights" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Apple is already planning a second version of the "four-edge bending" display that is rumored to debut on next year's 20th-anniversary iPhone, claims a new report out of Korea.


For the 20th-anniversary iPhone, Apple is said to be introducing a display that curves down around all four edges of the device for a borderless visual experience. It could be one of the biggest design shifts in the iPhone's history since the 10th anniversary iPhone X, which saw Apple drop the Home button, introduce a notched display, and adopt an intuitive swipe gesture-based navigation interface.

Today, ETNews reports that Apple is planning a two-stage rollout for the new OLED display technology that the commemorative iPhone will use, with a more advanced version said to be coming a year later.

For the 2027 variant, Apple will reportedly rely on OLED technology that uses a magnesium-silver (MgAg) alloy in the cathode layer. This implementation can cause image distortion and brightness loss in the curved areas, but Apple is apparently willing to live with the compromise for the 20th-anniversary iPhone while more advanced technology scales.

Apple then plans to address the issue in 2028 by transitioning to next-generation transparent electrodes. Apple will reportedly switch to indium zinc oxide (IZO) cathode materials, and because IZO is more transparent, it should reduce distortion, uneven brightness, and heat issues around the curved edges while enabling even narrower bezels.

ETNews reports that Samsung Display and LG Display have already been put on alert to prepare for the two-stage rollout. LG recently announced a ₩1.106 trillion investment (roughly US$790 million) in OLED infrastructure, which industry observers believe is connected to development and mass production of the new technology.

Meanwhile, Samsung is reportedly evaluating whether its existing OLED lines can accommodate the required hardware, but a dedicated production line is not out of the question, and may well be necessary.

Bloomberg in May 2025 reported on Apple's plans to launch a "mostly glass, curved iPhone without any cutouts in the display" for its 20th-anniversary model. The Information last year also cited multiple sources claiming that at least one new iPhone model launching in 2027 will have a truly edge-to-edge display. Tags: 20th-Anniversary iPhone, ETNews
This article, "20th Anniversary iPhone's Curved Display to Improve a Year Later" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Cybersecurity leaders often have complex relationships with their boards. Many boards lack cyber expertise, and CISOs can encounter roadblocks as a result when it comes to earning board approval. Other security leaders may not have a direct line to their board, or they may be viewed as too technical to win the support needed.
One way some CISOs are working to improve that relationship is by becoming board members themselves to better understand what is important and how to communicate to board members. Others may seek board positions to elevate their profile, help shape the tools of the future, or contribute to expanding the community’s knowledge.
The latter is the case for Jamie Norton, vice chair of the ISACA board. “As a long-term member, I had reached a stage in my career where I had more flexibility in managing my time and wanted to contribute back to the industry. To be able to accomplish this on a global scale with ISACA was a perfect fit,” Norton tells CSO.
For Mitra Minai, global cyber health leader at Accenture, it was about being a part of the solution rather than engaging with a board only during high-pressure moments.
“I saw firsthand how board comprehension of cyber and digital risk directly influences organizational outcomes, particularly in healthcare where cyber incidents can affect patient safety and continuity of care,” says Minai, who is a board member with the Austrialian Information Security Association (AISA), industry advisory member with the Australian Cyber Security Centre, and digital governance committee member at Uniting AgeWell.
“Becoming involved at a governance level allows me to contribute earlier and more strategically, helping boards shape risk appetite, investment priorities, and resilience before crises occur,” she adds. “It also provides an opportunity to help boards navigate the growing intersection between technology, trust, regulation, and organizational purpose.”
As in health, cyber incidents can have a catastrophic impact in other critical infrastructure services. For CISOs looking to make a difference, vendor advisory boards are another option.
Nathan Morelli, head of cybersecurity and IT resilience at SA Power Networks, says his motivation to join vendor advisory boards was a conscious move to influence the global product roadmaps that protect essential services.
“In critical infrastructure, the impact [of cyber incidents] is significant, and I wanted to ensure that the tools we use are actually fit for purpose. By joining these boards I gain a seat at the table where I can shape the technology of tomorrow, rather than just reacting to it. It’s about moving beyond the perimeter of one organization to influence the resilience of the entire sector,” says Morelli, who is a member of advisory boards with Cyera, CrowdStrike, Proofpoint, and SailPoint.
Getting a board role isn’t a straightforward path
CISOs must be aware, however, that board roles can be difficult to land. Despite being involved in the Canberra Chapter of ISACA for many years, Norton went through several attempts before earning his board role. He applied once and was unsuccessful; the following year he tried again to no avail. It can be hard to not take such rejections personally, he says, adding that he received great feedback and was encouraged to apply again.
“There was a lot of reflection on the process, and whether the result was challenges with expertise, experience, or simply the skills the board needed that was driving the outcome,” he says. “The required skills did come around to match my expertise soon after and I was successful. It has been a great journey since.”
It is also a significant commitment, Norton adds, “with many hours per week spent on board-related work and meetings, many of which run early morning between 12am to 2am Australian time.”
Advisory and committee positions don’t require any specific certifications, but governance capability and credibility are essential to be effective at board level, says Minai, who plans to complete formal Australian Institute of Company Directors (AICD) governance education within the next 12 to 18 months as part of an intentional progression toward broader non‑executive director roles.
Tips for CISOs aiming for a board role
For CISOs interested in contributing to global vendor boards, Morelli advises focusing on becoming a partner, not just a customer. This requires the ability to articulate how a product’s evolution impacts the risk profile of an entire sector.
For non-industry or public boards, CISOs must be comfortable contributing to discussions on P&L statements, ESG reports, or Modern Slavery statements. You are there to provide oversight for the entire organization’s strategy and sustainability.
Here are other top tips from Minai, Morelli, and Norton:
Start with governance, not titles. Committees, not‑for‑profit boards, and industry associations provide real governance experience. Separate governance from execution/management. Board effectiveness requires oversight and judgment, not operational problem‑solving. Learn the language of boards. Boards focus on risk appetite, trade‑offs, outcomes, and value creation, not just controls and tools. Invest in formal governance education. Even experienced executives benefit from structured governance training when moving into board roles. Choose wisely. Zero in on boards where your expertise genuinely matters and companies that are aligned to your values. Consider volunteering. Targeting a not-for-profit or charity for your first board position can help you earn valuable first-board experience. Leverage your network. Board opportunities often arise from existing relationships.   Get certified. Consider investing in a NACD Directorship Certification or similar credentials. Like your CISO role, branding and narrative are important. Research and develop a board bio that highlights key skills and experiences such as financial, legal, governance, risk, crisis management, regulatory navigation, and strategic governance.
The benefits of experiencing the board from the other side
CISOs will reap many benefits from being a board member. Chief among these, Norton says, is a greater appreciation of the director mindset.
“Understanding what represents a material concern, the right level of detail that board members want in reporting, and contributions to risk appetite and corporate strategy” have been invaluable, he says. “As a CISO in my day-job, this significantly assists in balancing board messaging and understanding how to frame discussions in the right way.”
Minai’s experience has shaped how she thinks and leads as well. Some of the benefits she experienced include developing a long‑term, enterprise‑wide perspective beyond functional optimization; a deeper understanding of how boards balance risk, investment, culture, and stakeholder expectations; exposure to decision‑making under uncertainty with incomplete information; and strengthening the ability to translate technical and cyber risk into strategic and financial implications.
“These roles have also broadened my exposure across aged care, academia, government, and not‑for‑profit sectors, which has strengthened my judgment and impact as a senior executive,” Minai says.
For Morelli, it is about being able to see where the industry is heading in 18 to 24 months.
“There is also a significant compounding effect of the network. Sitting in a room with the world’s top CISOs and business leaders provides a level of strategic intelligence that no briefing note can replicate. It forces you to grow as a leader because you are constantly challenged by peers operating at a global scale,” he says.
Even with cybersecurity leaders being increasingly invited into the boardroom, the invitation alone does not guarantee effectiveness. The CISOs who succeed in governance roles are those who can reframe cybersecurity as a matter of trust, resilience, and organizational stewardship, not just technical defence, Minai says.
“Boards are not looking for another security operator; they are looking for clear thinking, calm judgement, and strategic insight under complexity,” she says. “That is where experienced CISOs can make a unique and lasting contribution.”
View the full article
Details have emerged about a new variant of the recent Dirty Frag Linux local privilege escalation (LPE) vulnerability that allows local attackers to gain root access, making it the third such bug to be identified in the kernel within a span of two weeks. Codenamed Fragnesia, the security vulnerability is tracked as CVE-2026-46300 (CVSS score: 7.8) and is rooted in the Linux kernel's XFRMView the full article
Cybersecurity researchers have disclosed multiple security vulnerabilities impacting NGINX Plus and NGINX Open, including a critical flaw that remained undetected for 18 years. The vulnerability, discovered by depthfirst, is a heap buffer overflow issue impacting ngx_http_rewrite_module (CVE-2026-42945, CVSS v4 score: 9.2) that could allow an attacker to achieve remote code execution or cause aView the full article
The apparent revenge deletion of US federal databases after the dismissal of twin brothers from an online hosting company is another reminder to IT and HR leaders that tough off-boarding procedures have to be implemented to prevent insider attacks.
Destructive attacks either from disgruntled current or former employees aren’t new. But the conviction by a Virginia jury last week of one of the brothers raises a number of issues that IT pros and CEOs have to keep in mind.
A federal jury convicted Sohaib Akhter, 34, of Alexandria, Virgina, on charges of conspiracy to commit computer fraud, password trafficking, and possession of a firearm by a prohibited person. He will be sentenced in September. And last month his brother, Muneeb, signed an agreed statement of facts about the siblings’ activities in response to several charges against him. But according to documents from the case provided on the Free Law Project’s archive of court data, The Court Listener, Muneeb is now trying to have the charges dismissed.
Still, the incident has led one expert, Robert Enderle of the Enderle Group, to say, “it should serve as a wake-up call: Organizations must not only tighten their internal controls, but also begin accounting for how AI tools can be weaponized against them, and these AI tools need far stronger guardrails than they currently have.”
The statement of facts
According to the statement of facts Muneeb agreed to, but now disputes, he and his brother, Sohaib, worked for an unnamed company in Washington, DC that provided software and services to more than 45 US government agencies, including hosting data for some federal clients. They included the US Equal Employment Opportunity Commission (EEOC), Homeland Security, and the Internal Revenue Service (IRS).
On Feb 18, 2025, both brothers were terminated by the company after it discovered Sohaib had been convicted nine years earlier of a felony. After the firing, they both allegedly tried to harm their former employer by accessing computers without authorization, deleting databases and destroying evidence of their work. In his statement of facts this year, Muneeb admitted to deleting 96 databases.
How? While five minutes after they were fired in 2025, Sohaib’s VPN was disconnected and he lost access to the hosting provider, his brother still had access. The brothers also still had their company-issued laptops. They went to work.
As part of their alleged destructive work, when Muneeb didn’t know the database commands necessary to accomplish his goals, he used an AI tool to help him, asking “how do I clear system logs from SQL servers after deleting databases” and later, “how do you clear all event and application logs from Microsoft Windows Server 2012.” The agreed statement of facts doesn’t make it clear, but presumably the AI tool was a public chatbot.
In the statement of facts, Muneeb agreed he stole copies of IRS information on a virtual machine that included federal tax information of 450 people.
Muneeb also admitted that between May and December 2025, he committed fraud and stole credentials for the EEOC public portal in an attempt to access email and other online accounts of 4,500 people. In hundreds of instances, he successfully logged into victims’ email accounts without their authorization.
State of insider attacks
According to the State of Human Risk Report from Mimecast, 42% of organizations have experienced an increase in malicious insider incidents over the past year, with 42% also reporting a rise in negligent incidents for the first time.
A report this year by the Ponemon Institute on the costs of insider risks, commissioned by insider threat detection provider DTEX, estimated incidents cost organizations an average of $19.5 million last year, up from $17.4 million in 2024.
The biggest cause of losses last year (53%) was negligence and mistakes, it said. The second biggest cause, however, was malicious activity (27%).
Musa Ishaq, senior principal insider threat analyst at DTEX, said last week’s conviction “is a clear and sobering reminder that termination is not the end of risk. In many cases, it is the beginning of it.”
The off-boarding moment “is one of the most dangerous windows in any organization’s security posture,” he said, “and it remains one of the most underestimated. Every departing employee, whether they leave willingly or are terminated, represents a live risk event that must be treated in real time. That means immediate access revocation, active session termination, and active monitoring, not a checklist completed the following day. When those steps fail, or when even a single access pathway is left open, the consequences can be catastrophic, as this case demonstrates.”
‘AI didn’t give attackers a new capability’
Equally important, he added, is what this case reveals about AI’s role in accelerating insider threats. “AI did not give them a new capability; they already had the access and the intent. What it did was compress their decision cycle, turning what might have taken several minutes of research into seconds of execution. The new threat reality is that AI does not create malicious insiders, but it dramatically amplifies what they can accomplish before defenders are able to respond.”
As a result, organizations have to shift to proactive and risk-adaptive security approaches, Ishaq said. A privileged user querying an AI tool through a company owned or controlled computer for log evasion techniques while simultaneously executing destructive commands on production servers is an escalation signal, he said. “Behavioral visibility, not just technical controls, is what enables security teams to detect that pattern and act before deletion becomes destruction,” he said.
“This case is a preview of what insider threats look like in an AI-enabled world in terms of being faster, harder to trace, and far more consequential when governance gaps exist,” he said. “As such, the fundamentals, including strict access control, real-time off-boarding protocols, and layered monitoring of privileged users, have never been more critical.”
‘Textbook example’ of need to re-think processes
Enderle agreed. He said this incident “is a textbook example of why we need to rethink the speed and process of our off-boarding processes. The fact that a former employee was able to access and delete government databases post-termination highlights a massive failure in basic access control. In a modern enterprise, access revocation needs to be instantaneous, automatic, and comprehensive; any gap between a firing and a lockout is a window for significant liability.”
The most disturbing aspect, he added, is the role AI played. “Using an AI tool to solicit instructions on clearing system logs is a clear signal that the barrier to entry for sophisticated digital sabotage is dropping,” Enderle said. “We are entering an era where AI can act as a force multiplier for malicious intent, making it easier for individuals to cover their tracks. Even AI protections can be bypassed. I saw a demonstration on YouTube the other day where a user just re-asked a question to a public AI site on preparing a bomb until the AI gave up saying ‘No,’ and provided the answer.”
Queries like ‘How to clear SQL logs’ have legitimate administrative purposes, he acknowledged. But, he added, AI providers must move beyond simple keyword filtering and implement intent-aware guardrails that can identify attack chains.
“When a sequence of prompts moves from technical curiosity to a roadmap for destroying evidence and obfuscating logs, the AI should recognize the malicious context and refuse the request, Enderle argued.
“Ultimately,” he warned, “if AI providers don’t take responsibility for preventing their platforms from becoming a ‘How-to’  manual for criminal activity, they risk a regulatory backlash and potential civil and criminal liability that could stifle the very innovation they are trying to promote.”

View the full article
Apple released iOS 26.5 yesterday with a new Suggested Places feature in the Apple Maps app, which is a precursor to the ads that Apple plans to start showing later this year. There was some confusion over whether ads are live, but as of now, the ‌Apple Maps‌ app still doesn't have ads.


Apple did start laying the groundwork for ads in iOS 26.5 and tested a splash screen, but no ads appeared during the beta testing period or after launch.

When Apple announced plans to bring ads to the Maps app in March, it said that ads will be implemented in the United States and Canada "this summer." Astronomical summer in the Northern Hemisphere starts on June 21 and ends on September 22. Meteorologically, summer begins on June 1 and lasts through August, so depending on Apple's definition of summer, we'll get ads in Maps sometime between June 1 and September 22.

Ads will be displayed in ‌Apple Maps‌ search results and in the new Suggested Places section added in iOS 26.5. Suggested Places shows recommendations based on what's trending nearby and a user's recent searches.


There will be ads in the Maps app on iPhone and iPad, and they will be clearly marked with an "Ad" label, similar to how ads appear in App Store search results. Businesses will bid for ad placement, and the highest bidder for a keyword or search term will have its ad shown in search.

Apple says that location data and the ads that users see and interact with in the Maps app are not associated with an Apple account, and data is not shared with third parties. There is no opt-out for location-based or personalized ads in Suggested Places.Tags: Apple Ads, Apple Maps
This article, "Ads Aren't in the Apple Maps App Yet, But They're Coming Soon" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Apple's smartphone sales increased 1.3 percent year-over-year in the United States during the first quarter of 2026, according to data shared by Counterpoint Research. Apple saw a sales increase while the broader U.S. smartphone market experienced a 5.7 percent decline during the same time period.


Android device sales declined 14.4 percent, while Apple's market share grew 4 percent year-over-year. iPhone 17 performance is part of the reason Apple outperformed the market, but Counterpoint says the company was also helped by a later launch of Samsung's Galaxy S26 series in March.

Apple's market share increased at all three major U.S. carriers, while Android saw a decline. The iPhone made up 75 percent of sales at Verizon, AT&T, and T-Mobile, while Android devices made up 25 percent.

Counterpoint expects Apple to continue to draw users to iOS because it maintained pricing with the iPhone 17e and even increased storage, while smartphone makers with slimmer hardware margins have had to raise prices.

During Apple's April 30 earnings call, CEO Tim Cook said the ‌iPhone 17‌ family was the most popular lineup in Apple's history. Cook said information from IDC indicated Apple gained market share during the quarter.

Cook also said iPhone demand was off the charts, leading to supply constraints during the quarter. Apple was having trouble getting the A19 and A19 Pro chips manufactured by TSMC due to demand for TSMC's AI server chips.

According to Cook, memory shortages and rising costs will have more of an impact on Apple later in 2026. Apple is expecting "significantly higher" memory costs and plans to look at a "range of options" for mitigation. Cook declined to provide insight into how Apple plans to deal with the problem, and he did not comment on whether Apple will raise prices.Tag: Counterpoint
This article, "Apple Grew U.S. iPhone Sales While Broader Smartphone Market Declined in Q1" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Fortinet released a batch of patches across its products on Patch Tuesday, including two critical vulnerabilities that can lead to remote code execution. Fortinet flaws, both zero-day and n-day, have been exploited in the wild many times in the past, so companies should deploy patches as soon as possible.
“Fortinet vulnerabilities are often attractive to threat actors because these products sit in high-trust security functions that threat actors often target,” Piyush Sharma, CEO and co-founder of SecOps company Tuskira, told CSO via email. “When a vulnerability affects a tool that already has privileged visibility or sits close to critical systems, exploitation can give attackers a much larger head start than a flaw in an ordinary application.”
The flaw in FortiAuthenticator, tracked as CVE-2026-44277, has a 9.1 CVSS severity score and is described as an improper access control issue. Successful exploitation allows unauthenticated attackers to execute unauthorized code and commands by sending specifically crafted requests.
An identity and access management (IAM) solution, FortiAuthenticator serves as the central hub for RADIUS, LDAP, and SAML authentication. It integrates with Active Directory and supports single sign-on and multi-factor authentication. To patch this new vulnerability, companies are advised to upgrade to FortiAuthenticator 6.5.7, 6.6.9, or 8.0.3 depending on the release they’re using.
The flaw in FortiSandbox is a missing authorization issue that similarly allows unauthenticated attackers to execute arbitrary code and commands via HTTP requests. Tracked as CVE-2026-26083, the vulnerability also has a severity score of 9.1.
FortiSandbox is a threat detection solution designed to identify zero-day threats by using machine learning to perform static and dynamic analysis on suspicious files inside an isolated environment. It integrates with other Fortinet security products such as FortiGate and FortiMail and comes in different variants, including hardware and virtual appliances.
The vulnerability impacts all supported versions of FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS. Users are advised to upgrade to version 4.4.9 or 5.0.2, depending on release.
Both CVE-2026-26083 and CVE-2026-44277 were discovered internally by Fortinet, so there is no evidence of in-the-wild exploitation yet. However, exploits for other Fortinet RCE vulnerabilities were adopted by attackers in the past.
For example, CVE-2026-21643, an SQL injection vulnerability in FortiClient Endpoint Management Server (EMS) that was found internally by Fortinet and was patched in February, ended up exploited in the wild a month later. This was followed up last month by exploitation of another FortiClient EMS flaw, this time a zero-day.
In addition to the two critical flaws, Fortinet released patches for high- and medium-severity flaws in several products: an out-of-bounds write vulnerability in FortiOS that can lead to RCE (CVE-2025-53844), an OS command injection vulnerability in FortiAP and FortiAP-W2 (CVE-2025-53870) that leads to privilege escalation, and a separate OS command injection flaw in FortiAP, FortiAP-U, and FortiAP-W2 (CVE-2025-53680) that can lead to RCE.
Exploitation of these flaws requires authentication, which is why they’re not rated critical, but attackers compromising enterprise credentials is not uncommon so they should still be treated with urgency.
View the full article
The Meta AI app and Meta AI on WhatsApp have a new "incognito chat" option, which Meta CEO Mark Zuckerberg said is a "completely private way to interact with AI."


Zuckerberg also said that Meta AI's incognito mode is the first major AI product where there is no log of conversations stored on servers. Zuckerberg likened the feature to end-to-end encryption, and said no one will be able to read the AI conversations, not even Meta or WhatsApp.

AI inference for incognito chat is done in a Trusted Execution Environment that Zuckerberg said is not accessible to Meta. Conversations also disappear from the phone when exiting a chat session, and nothing is saved or logged. Web searches are conducted privately, with no search information linked to the user.

"To get the most from personal superintelligence, we'll all need ways to discuss sensitive topics in ways that no one else can access," Zuckerberg said.

WhatsApp head Will Cathcart told reporters that the AI has safety guardrails, and it will refuse to answer questions that could be interpreted as harmful or illegal, steering conversations in a different direction. The mode also only supports text, and users are unable to upload images.

Incognito chat for Meta AI comes as OpenAI is facing a lawsuit for allegedly causing a teen's drug overdose. The teen asked ChatGPT for information on whether it was safe to take two drugs together, and was provided with an incorrect answer that led to his death. OpenAI has been sued several times by the families of people who used ChatGPT before dying by suicide.

Lawsuits against OpenAI have involved chat logs recovered by the plaintiffs, and without those logs, there would be far less evidence for a legal complaint over AI actions and advice.

Google and OpenAI also offer temporary chat options, but messages are still stored on remote servers. Google keeps data for up to three days, and OpenAI keeps logs for 30 days.

Meta's private chat option is rolling out in the coming months in the Meta AI app and WhatsApp.Tags: Meta, OpenAI, WhatsApp
This article, "Meta AI App Gets 'Incognito Chat' as OpenAI Faces Lawsuits Over Stored Chat Logs" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Samsung is planning a Galaxy Unpacked event for July, and the company plans to introduce new foldable smartphones and AI "Galaxy Glasses," according to Seoul Economic Daily.


Samsung's event will take place on July 22, so it will debut new Galaxy Z Fold8 and Z Flip8 foldable smartphones just weeks ahead of when Apple's first foldable iPhone is introduced, plus it will beat Apple to AI glasses.

Apple has been racing to develop its own smart glasses to compete with the Meta Ray-Ban AI glasses, but rumors suggest Apple won't launch the glasses until 2027. There is a chance Apple will preview the glasses in 2026, but there's no certainty yet.

Samsung is working with eyewear company Gentle Monster for its AI glasses, and the wearable will run Google's Android XR operating system with Gemini integration. The glasses will feature a high-definition camera, speakers, and a microphone, similar to the Meta Ray-Bans, and there will be no built-in display. AI integration will be a main selling point, with Gemini able to use video captured by the wearer to answer queries. Samsung will link the glasses to Galaxy smartphones and its SmartThings home appliance ecosystem.

The glasses that Samsung is working on sound similar to everything rumored for Apple's own AI glasses. Apple's glasses will rely on Siri, and will include cameras to feed visual information to the AI. Speakers and microphones will be included, but no display is expected for the first version.

Samsung is also planning for a Fold Wide, or a foldable smartphone that's similar to the dimensions that Apple plans to use for its foldable iPhone. Samsung's foldables to date have been taller than they are wide, but Apple is planning for a wider, iPad-like 4:5 aspect ratio.

After Samsung's event, Apple will unveil its next smartphones at its traditional September event. Dates are not known at this time.Tag: Samsung
This article, "Samsung Set to Beat Apple to AI Smart Glasses With July Launch" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Meta today announced the launch of Instants, a new image sharing option on the Instagram social network. Instants are ephemeral photos that disappear from Instagram after they're viewed by a user's friends or after a 24-hour period.


Reactions and replies to Instants images show up in DMs instead of on the post. Instants photos are only displayed for a short period, but they are saved to a user's archive for a year and can be reshared to Stories. Instants cannot be edited, with no option for filters, stickers, or modifications beyond captions. That sets them apart from Stories, which is already an Instagram feature.

Instants is an Instagram feature, but Meta has also developed a standalone Instants companion app "for quicker camera access." The standalone app is a direct competitor to Snapchat, the original ephemeral image social network. The new app can be used for sharing Instants, but on Instagram, users can also share Instants from a new camera option in the Direct Messages section of the app.

Instants can be viewed on Instagram by opening up DMs and tapping on the new Instants box in the bottom right corner of the inbox. Photos can be shared with friends set as close friends, or as mutuals, aka followers that an Instagram user follows back. Instants are not able to be screenshotted or screen recorded, providing privacy features not available with other Instagram image types.

Meta says that Instants are designed for casual, everyday photos. The standalone app is limited to select countries, as Meta says that it is an experiment. Images shared on the Instants app will show up for friends on Instagram, and images shared on Instagram will show up in the Instants app.

Instants on Instagram is available globally starting today, and the app is also available for download in countries where it is supported.Tags: Instagram, Meta, Photos
This article, "Meta Launches 'Instants' App for Sharing Disappearing Photos on Instagram" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Apple is looking into ways to better support apps that include AI agents and AI coding capabilities in the App Store, reports The Information. Apple is designing a system that would maintain its security and privacy standards while allowing for AI app features, but details on how the system will work are unavailable.


Apple started blocking updates for some popular vibe coding apps in March because those apps violated ‌App Store‌ rules that prohibit apps from executing code that alters their own functionality or that of other apps. Vibe coding apps let users build apps and websites with little to no coding experience, using AI agents and natural language prompts. Vibe coding has become popular, and Apple's rules have not been able to keep up.

Apps that include AI agents present similar problems for Apple. AI agents can autonomously complete complex actions and make mini apps using tools and capabilities that would not traditionally be supported under Apple's ‌App Store‌ rules. Apple will need to make changes to keep up with the software trends that developers and users want.

Apple wants to incorporate AI agents into the ‌App Store‌ while preventing some of the issues that people have run into with rogue AI agents deleting content and causing other problems.

As it works to prepare for future AI apps, Apple is also developing its own AI capabilities. Siri is set to get a major overhaul in iOS 27, making it smarter and better able to compete with Claude and ChatGPT. Apple has partnered with Google to use custom Gemini models to power ‌Siri‌.

The Information says Apple has started contacting app developers to integrate app capabilities like booking flights and sending calendar invites into the new version of ‌Siri‌ and Apple Intelligence. Some developers are hesitant to work with Apple to integrate their apps into ‌Siri‌ because they are worried about providing new ways for Apple to collect commissions. Apple is telling some developers that it does not plan to charge commissions during the early stages of the partnership, but that fees are a possibility in the future. Apple has held talks with Baidu, Alibaba, and Tencent about ‌Siri‌ integration in ‌iOS 27‌, but the companies do not want to end up paying fees to Apple.

Apple also plans to allow users to select from multiple chatbots to use with ‌Siri‌, instead of limiting people to OpenAI's ChatGPT. AI models from companies like Anthropic or Google could be used for Image Playground and Writing Tools the way ChatGPT can be used today.

It is not clear if Apple plans to open up more of iOS to third-party chatbots, but OpenAI has reportedly been disappointed with Apple's limitations. ChatGPT can be used to generate images and text through the iOS integration, but it cannot access user emails or other personal information. Customers are also rarely using the functionality, according to The Information.

Apple's new version of ‌Siri‌ is expected to be unveiled at the WWDC keynote on June 8, and the plans that Apple has for agentic AI apps in the ‌App Store‌ could also be discussed at the same time.Related Roundup: iOS 27Tags: App Store, The Information
This article, "Apple Working on Plan to Allow AI Agent Apps on the App Store" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Microsoft has responded to the MacBook Neo by commissioning a study that highlights advantages of some Windows laptops.


Market research firm Signal65 evaluated four Windows laptops:Lenovo's IdeaPad Slim 3x
Lenovo's Yoga 7i
HP's OmniBook 5
HP's OmniBook X FlipWith a starting price of $549.99 on Best Buy's online store in the U.S. at the time of this writing, the IdeaPad Slim 3x is the only laptop in the study that currently rivals the MacBook Neo's starting price of $499 (college students) to $599 (general public). The other three laptops currently start at $749 to $1,029 at Best Buy.

Signal65 outlined some of the IdeaPad Slim 3x's advantages over the MacBook Neo:

Feature
IdeaPad Slim 3x
MacBook Neo


Display Size
15.3-inch
13-inch


CPU
Snapdragon X1 with "90% faster" multi-core Cinebench 2026 score
A18 Pro


Base RAM
16GB
8GB


Fingerprint Scanner
Included
Touch ID limited to $699 model


Ports
1× USB-C, 2× USB-A, SD, and HDMI
2× USB-C only


Wi-Fi
Wi-Fi 7
Wi-Fi 6E


Backlit Keyboard
Yes
No


Touch Screen
Yes
No


In addition, the IdeaPad Slim 3x achieved longer battery life (16 hours and 29 minutes) compared to the MacBook Neo (13 hours and 28 minutes) in a Tom's Guide test, with Lenovo able to fit a larger battery inside a 15-inch laptop.

The study indicated that the IdeaPad Slim 3x has 512GB of storage, but the $549.99 base model has a 256GB SSD, which matches the MacBook Neo.

Through June 30, Microsoft is offering U.S. college students a free one-year Microsoft 365 Premium subscription, a free one-year Xbox Game Pass Ultimate subscription, and a free Xbox controller with the purchase of a qualifying Windows laptop, including the IdeaPad Slim 3x. The bundle has a value of more than $500.

On the other hand, the MacBook Neo has some advantages over the IdeaPad Slim 3x:

Feature
MacBook Neo
IdeaPad Slim 3x


Display Resolution
2,408×1,506 pixels (Retina quality)
1,920×1,200 pixels


Display Brightness
500 nits
300 nits


Build Material
Fully aluminum enclosure
Mix of aluminum and plastic


Webcam
1080p camera
720p camera


Moreover, many reviewers indicated that the MacBook Neo has a superior trackpad and speakers compared to Windows laptops within the same price range. Plus, the MacBook Neo runs macOS instead of Windows, so it benefits from Apple's tight hardware and software integration and features that work across multiple Apple devices.

While it is unsurprising that this Microsoft-backed study is focused on promoting Windows laptops, the reality is that the MacBook Neo and the IdeaPad Slim 3x both have pros and cons. More competition in the affordable laptop market is a win overall.Related Roundup: MacBook NeoTags: Lenovo, Microsoft, WindowsBuyer's Guide: MacBook Neo (Buy Now)Related Forum: MacBook Neo
This article, "New Study Highlights Advantages of $549 Windows Laptop Over MacBook Neo" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Apple has stepped in to warn that EU proposals to force Google to open Android to competing AI services pose serious risks to user privacy, security, and safety.


Apple's latest submission to the EU comes (via Reuters) in response to the European Commission's call for feedback on draft measures designed to help Google comply with the Digital Markets Act (DMA). The proposals would allow competing AI services to interact with Android apps to perform actions such as sending emails, ordering food, or sharing photos. Google has already pushed back on the plans, arguing they would undermine key privacy and security safeguards for European users.

Apple, which is itself now subject to EU measures requiring it to open up its own ecosystem, said it has a strong interest in the case given its own operating systems for iPhone, iPad, and Mac. In its submission, Apple said the draft measures "raise urgent and serious concerns," warning that if confirmed, "they would create profound risks for user privacy, security, and safety as well as device integrity and performance."

Apple also took aim at the rapidly evolving state of AI as a particular source of concern, arguing that risks are "especially acute in the context of rapidly evolving AI systems whose capabilities, behaviours, and threat vectors remain unpredictable." The company questioned the EU's technical expertise in drawing up the proposals, stating that the Commission is "substituting judgments made by Google's engineers for its own judgment based on less than three months of work," and suggesting the only discernible goal of the draft measures is "open and unfettered access."

Apple has a long history of clashing with EU regulators over the DMA. The company challenged the regulation in court in October 2025, and urged regulators to scrap it entirely the month before, arguing it had created security vulnerabilities and worsened the user experience. The EU said it had no intention of repealing the law in response.

The feedback period for the proposals ran from April 27 to May 13, 2026. The European Commission has said it will carefully assess all submissions and may adjust the proposed measures as a result, though its final decision must be adopted within six months of the opening of the specification proceedings, giving a deadline of July 27, 2026. The EU separately concluded in May 2026 that the DMA has had a positive impact overall, setting aside Apple's lobbying for the regulation to be revised.Tags: Europe, European Commission, European Union, Google, Reuters
This article, "Apple Defends Google Against EU Proposal to Give AI Rivals Access to Services" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Following last month's coverage of an unofficial Mac port of Notepad++ that the original developer called out for trademark violation, the dispute has now been resolved with a rebrand.


The macOS port was previously released by Andrey Letov under the Notepad++ name without authorization. Don Ho created the original Windows code editor in 2003, and had publicly objected to the unofficial app's use of his trademark and the inclusion of his name and biography on its author page. After settling the dispute, the app has subsequently been renamed Nextpad++.

The site for Nextpad++ has been thoroughly updated and clearly states that the app is an "open-source and independent community port of Notepad++ to macOS." Elsewhere, Letov's About page describes the project as a Mac port of the Notepad++ GPL codebase, built on Objective-C++, Scintilla, and Cocoa, and shipped as a universal binary for Apple silicon and Intel Macs. The app also has a new icon.

Names aside, it seems Daring Fireball's John Gruber is less than charmed by the result, describing the app as feeling "unholy" and suggesting the rapid port could only have been built with AI vibe-coding tools. The site states development began on March 10.

Have you tried out Nextpad++ for Mac? Let us know what you think in the comments.
This article, "Notepad++ Mac Port Renamed Nextpad++ After Trademark Row" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Anker's new Prime 3-in-1 Wireless Charging Station has been marked down to $104.99 on Amazon, down from $149.99. This is one of Anker's newest accessories, and Amazon's sale today is a match of the all-time low price. This deal, and many of the others shared below, is being matched at Anker.com, with additional savings applied for members.

Note: MacRumors is an affiliate partner with some of these vendors. When you click a link and make a purchase, we may receive a small payment, which helps us keep the site running.

The Prime 3-in-1 Wireless Charging Station features Qi2.2 support, which lets a compatible MagSafe ‌iPhone‌ charge at up to 25W. It's the same speed as Apple's ‌MagSafe‌ charger, and it is 10W faster than the standard Qi2 ‌MagSafe‌ chargers. You can also simultaneously charge an Apple Watch and AirPods with the device.

$45 OFFAnker Prime 3-in-1 Wireless Charging Station for $104.99

There are plenty of other Anker discounts happening on Amazon this week, including Anker's popular 3-in-1 MagSafe-Compatible Charging Cube for $86.99, down from $129.99. Below you'll find a list of the best Anker discounts on Amazon this week, also including wall chargers, portable chargers, and more.

Although it's not on sale, Anker recently launched a new desktop charging accessory with the Anker Nano Desk Clamp Power Strip for $69.99. The new device attaches to your desk and has 10 total ports including six AC outlets, two USB-C ports, and two USB-A ports. It supports 70W USB-C fast charging and comes in white and black color options.

Wall Chargers

Nano USB-C Wall Charger - $29.99, down from $39.99
140W 4-Port GaN USB-C Charger - $79.99, down from $99.99
Wireless Chargers

3-in-1 MagSafe-Compatible UFO Charger - $69.99, down from $89.99
3-in-1 MagSafe-Compatible Foldable Charging Station - $85.99, down from $109.99
3-in-1 MagSafe-Compatible Charging Cube - $86.99, down from $129.99
3-in-1 Prime Wireless Charging Station - $104.99, down from $149.99
Prime MagSafe-Compatible 3-in-1 Charging Station - $159.99, down from $229.99
Portable Chargers

SOLIX C300 Power Station with Lantern - $179.99, down from $249.00
Prime Power Bank 26,250 mAh - $171.48, down from $229.99
SOLIX C1000 Gen 2 Portable Power Station - $449.99, down from $799.00
SOLIX C2000 Gen 2 Portable Power Station - $799.99, down from $1,499.00
If you're on the hunt for more discounts, be sure to visit our Apple Deals roundup where we recap the best Apple-related bargains of the past week.



Deals Newsletter

Interested in hearing more about the best deals you can find in 2026? Sign up for our Deals Newsletter and we'll keep you updated so you don't miss the biggest deals of the season!




Related Roundup: Apple Deals
This article, "Anker's New Prime Charging Station Returns to Low Price on Amazon" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
A new survey suggests most U.S. smartphone owners are not motivated to upgrade by foldable phone designs or AI features, a potential challenge for Apple as it prepares to launch both the rumored "iPhone Ultra" and an expanded suite of Apple Intelligence features this fall.


The survey, commissioned by CNET and conducted by YouGov across 2,407 U.S. smartphone owners between April 29 and May 1, found that only 13% of respondents would consider upgrading for a phone concept such as a foldable or flip phone, while just 12% cited AI integrations as an upgrade motivator.

Among iPhone owners specifically, interest in foldable designs was slightly higher at 14%. Apple is widely expected to launch its first foldable iPhone alongside the iPhone 18 Pro this fall, with a starting price of around $2,000.

While a 13% interest statistic in foldable designs has been characterized as evidence of limited appeal, it may actually represent a larger addressable market than anticipated for a product most consumers have never used and whose likely price was not disclosed to respondents. Interest could shrink considerably once a $2,000-plus price tag enters the picture, and supply chain reports suggest smooth availability may not occur until 2027.

Consumer sentiment around AI integrations dropped sharply from 2024 to 2025 before edging slightly higher in 2026, though the figure remains low at 12%. Previous surveys found that the majority of iPhone users felt existing ‌Apple Intelligence‌ features added little to no value to their experience.

Price remains the overwhelming driver of upgrade decisions, cited by 55% of respondents, followed by longer battery life at 52%, and more storage at 38%. Those top three motivators are unchanged from 2025, when price led at 62%, battery life at 54%, and storage at 39%.

Camera features (27%) and display size (22%) ranked well ahead of either foldables or AI as upgrade motivators. Smartphone owners are also not particularly swayed by a phone being thinner or available in new colors, findings that are relevant given Apple's recent emphasis on the ultra-thin iPhone Air and expanded color options across its lineup.Related Roundup: iPhone FoldTags: Apple Intelligence, CNET
This article, "Few Smartphone Owners Care About Foldables or AI, Survey Suggests" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
While something new is always around the corner, now might be a particularly good time to hold off on buying a new iPhone if you are able to.


The reason to consider waiting is that Apple is reportedly working on a special 20th-anniversary iPhone for release in September 2027, and rumors suggest that the device will feature the biggest redesign since the iPhone X in 2017.

According to Bloomberg, the 20th-anniversary iPhone will have "glass edges that curve seamlessly into the display on all four sides."

The Information reported that one of Apple's early 20th-anniversary iPhone prototypes lacked bezels around the screen. The device had only a "narrow metal band running around the midpoint of the device's edge, where the buttons sit."

Apple has also aimed for the device to have no cutouts in the screen, according to The Information, but it is unclear if the company will be able to move both the front camera and the Face ID system under the screen by next year.

Overall, it sounds like Apple has ambitious goals with the 20th-anniversary iPhone, and that makes it a device that might be especially worth waiting for. Of course, this advice will not apply to you if you upgrade your iPhone every single year regardless, but the average customer holds on to their iPhone for two to four years.

In the meantime, Apple is expected to release the iPhone 18 Pro, iPhone 18 Pro Max, and its first-ever foldable iPhone in September 2026, followed by an iPhone 18, iPhone 18e, and a second-generation iPhone Air around March 2027.Tag: 20th-Anniversary iPhone
This article, "You Might Want to Wait to Buy a New iPhone" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
The Trump-Xi summit opening in Beijing this week carries an agenda item unlike any in the history of US-China diplomacy: what to do about artificial intelligence that can autonomously find and exploit vulnerabilities in the world’s most critical software — and what happens when both superpowers have it.
Anthropic’s Mythos Preview, released last month to a limited group of security partners, has demonstrated the ability to discover zero-day vulnerabilities in every major operating system and browser, sometimes finding bugs that had survived decades of human review and millions of automated tests.
Anthropic has framed Mythos as a watershed moment, launching Project Glasswing and committing $100 million in usage credits to help defenders secure critical infrastructure before similar capabilities become widely available.
Meanwhile, the strategic buffer that Washington has long assumed it held over Beijing is narrowing faster than most policymakers have been willing to admit.
Chinese entities have sought access to Mythos and have so far been denied, but it’s likely the model will leak out. Mythos has already seen unauthorized access: a small group of users reportedly gained entry to the model on the same day Anthropic announced its limited release.
The gap that wasn’t
For years, the US-China AI competition was framed as an asymmetric contest — American labs in front, Chinese labs years behind, export controls and chip restrictions buying the United States time.
However, Stanford’s 2026 AI Index, published last month, found that US and Chinese models have traded the global performance lead multiple times since early 2025. As of March 2026, Anthropic’s Claude Opus 4.6 leads China’s best model by just 2.7 percentage points on a key benchmark — down from a gap of 17 to 31 percentage points in mid-2023.
China leads the world in AI patent filings, research citations, and industrial robot installations. While the Stanford index shows US private investment towering over Chinese private investment by a factor of 23, Chinese state guidance funds have deployed an estimated $912 billion across strategic industries over two decades, a figure that private-investment comparisons entirely miss.
The AI talent picture is, if anything, more alarming. The number of AI researchers moving to the United States has dropped 89% since 2017, with 80% of that decline occurring in just the past year, accelerated in part by the Trump administration’s H-1B restrictions.
The real threat isn’t who you think
The US-China framing — useful for budgets and political narratives — obscures the more consequential risk from systems like Mythos.
“The US and China may stand more to gain from controlling these systems together than simply fighting over them,” Gal Tal-Hochberg, co-founder and CEO of Beacon Security and former CTO of cybersecurity venture firm Team8, tells CSO. “When it becomes very cheap to do damage, people who are not anybody can suddenly do damage.”
The danger is not simply that Beijing develops models with advanced cyber capabilities. The larger concern is what happens when those capabilities — or something close to them — diffuse into criminal ecosystems, ransomware operations, or loosely affiliated proxy groups that no government controls.
“The cost and complexity of attacks are dropping,” Tal-Hochberg says. “Defenders who could previously get away with being less sophisticated may no longer be able to.”
A nuclear analogy that has limits but holds
Senior US officials, speaking ahead of the summit, said Washington is prepared to “explore channels of deconfliction” with Beijing on AI, using language that evokes Cold War nuclear logic.
What those channels might look like is taking shape. Both sides are weighing a recurring set of conversations focused on establishing guardrails covering AI models behaving unexpectedly, autonomous military systems, and nonstate actors using powerful open-source tools.
Both AI and nuclear weapons involve technologies of potentially catastrophic offensive capability. Both involve two rival powers who share an interest in preventing the worst outcomes even as they compete. And in both cases, the US has to decide whether dialogue with an adversary is a concession or a necessity.
But the nuclear analogy breaks down in one critical way: Nuclear weapons were economically irrelevant outside defense ecosystems. AI is the opposite. It is simultaneously the most significant general-purpose economic technology of this era and a potentially destabilizing offensive capability.
As Tal-Hochberg puts it, “AI is both nuclear power and nuclear weapons at the same time. Governments want the economic benefits while also trying to limit the offensive risks.”
That dual nature makes agreed limits enormously harder to negotiate, verify, or enforce. The Council on Foreign Relations has argued that Beijing’s actual interest in AI safety dialogue is primarily instrumental — an opportunity to close the capability gap rather than constrain it.
The sole prior US-China AI safety dialogue, held in 2024, illustrated the asymmetry: The US sent technical experts to outline shared risks; China sent diplomats to complain about chip export controls.
What Washington still hasn’t decided
The more uncomfortable truth is that the United States has not yet resolved what Mythos-class systems actually are. The Trump administration spent much of the past year resisting broad AI regulation, arguing that oversight would blunt competitive advantage.
Now it faces growing internal pressure to develop testing requirements for frontier models with advanced cyber capabilities and is reportedly preparing executive action on AI safety, a significant pivot from its earlier posture.
Anthropic’s decision to release Mythos through Project Glasswing — giving defenders access before offensive capabilities become broadly available — represents one model for managing this problem.
And the access decisions themselves are already becoming geopolitical. The EU, notably, has still not been granted access to Mythos, even as OpenAI has moved to provide European cybersecurity teams access to its own cyber model. These are unilateral judgments by private companies, not a policy framework.
The window won’t stay open for long
More capable AI can accelerate the development of still more capable AI. The country — or company, or actor — with the strongest models today has structural advantages in building tomorrow’s models.
What Washington and Beijing discuss in Beijing this week will not resolve the fundamental tension between competitive AI development and the risks that development creates. But the establishment of even narrow deconfliction channels — a hotline logic for AI crises, shared norms around the most dangerous applications, transparency mechanisms that let each side verify the other isn’t crossing agreed lines — would represent meaningful progress over the current state, which is no framework at all.
View the full article
Microsoft has unveiled a new AI-driven vulnerability discovery system that identified 16 previously unknown Windows vulnerabilities, including four critical remote code execution flaws, in what security analysts say could mark a major shift in how software vulnerabilities are discovered and remediated.
The system, codenamed MDASH, was developed by Microsoft’s Autonomous Code Security team alongside the Windows Attack Research and Protection group.
The platform will enter private preview for enterprise customers next month, Microsoft said in a blog post announcing the system.
The vulnerabilities were patched as part of Microsoft’s May 12 Patch Tuesday release.
“Cyber defenders are facing an increasingly asymmetric battle,” Microsoft added in the blog post. “Attackers are using AI to increase the speed, scale, and sophistication of attacks.”
Critical Windows components affected
The four critical vulnerabilities affected core Windows components broadly deployed across enterprise environments, Microsoft said in the blog.
Among them was CVE-2026-33827, a remote unauthenticated use-after-free flaw in the Windows IPv4 stack reachable through specially crafted packets carrying the Strict Source and Record Route option, Microsoft said.
Another flaw, CVE-2026-33824, involved a pre-authentication double-free issue in the IKEEXT service affecting RRAS VPN, DirectAccess, and Always-On VPN deployments.
Two additional critical flaws affected Netlogon and the Windows DNS Client, both carrying CVSS scores of 9.8.
The remaining 12 vulnerabilities rated “Important” included denial-of-service, privilege-escalation, information disclosure, and security feature bypass flaws affecting components such as tcpip.sys, http.sys, ikeext.dll, and telnet.exe, according to Microsoft.
How MDASH orchestrates AI agents
According to Microsoft, MDASH orchestrates more than 100 specialized AI agents across multiple frontier and distilled models, with each agent assigned to a different stage of the vulnerability discovery pipeline.
Some agents scan source code for potential flaws, others validate whether findings are genuine, and another stage attempts to construct triggering inputs capable of reproducing the issue before the finding reaches a human engineer for review.
“The model is one input. The system is the product,” Taesoo Kim, Microsoft vice president for agentic security, wrote in the blog.
Microsoft said the architecture was intentionally designed to remain largely model-agnostic, allowing the company to swap underlying AI models without rebuilding the broader orchestration pipeline.
That detail matters because MDASH arrives only weeks after Microsoft announced Project Glasswing, a partnership involving Anthropic and others to evaluate AI-driven vulnerability discovery using Anthropic’s Claude Mythos Preview model.
“Microsoft is now operating as platform owner, security vendor, AI infrastructure player, OpenAI partner, Mythos integrator, and agentic security supplier,” said Sanchit Vir Gogia, chief analyst at Greyhound Research. “That is a formidable position. It is also a concentration of influence that security leaders must examine with clear eyes.”
AI vs AI vulnerability race
The announcement also highlights growing concern that AI-driven vulnerability discovery could accelerate offensive operations as well as defensive research.
Anthropic has previously said its Mythos Preview model identified thousands of high-severity vulnerabilities, including a decades-old OpenBSD flaw and a long-undetected FFmpeg issue that traditional fuzzing tools failed to uncover despite millions of attempts.
“We’ve entered an AI-versus-AI vulnerability discovery race,” said Sunil Varkey, advisor at Beagle Security. “The winners won’t be the organizations with the best static scanners anymore. They’ll be the ones who can run these agentic systems fastest against their own code and remediate at machine speed.”
Varkey said enterprises should pursue early access to systems such as MDASH where possible rather than waiting for broader commercial availability.
“Early access isn’t just nice-to-have,” he said. “It’s becoming a defensive necessity in the AI era.”
For CISOs, the broader implication may be that vulnerability management is shifting from periodic scanning toward continuous, AI-assisted discovery and remediation.
“The future belongs to security teams that can find, validate, contain, and fix in one governed motion,” Gogia said.
Benchmarks show progress, but analysts urge caution
To support its claims, Microsoft published benchmark results showing MDASH identified all 21 deliberately planted vulnerabilities in an internal Windows test driver without false positives. The company also said the system successfully recovered nearly all historical Microsoft Security Response Center cases tested against older Windows component snapshots.
On the public CyberGym benchmark for vulnerability reproduction tasks, Microsoft said MDASH achieved a score of 88.45%, topping the public leaderboard at publication time.
Gogia said the results show the category is maturing but warned against treating benchmark scores as direct proof of enterprise value.
“CyberGym is a signal, not a buying decision,” he said. “The machinery around the model is beginning to resemble a serious security research workflow.”
He added that many enterprises still lack the governance maturity required to operationalize machine-generated vulnerability discovery effectively.
“Discovery without remediation discipline is theatre,” Gogia said. “It produces dashboards, not resilience.”
View the full article
Palo Alto Networks has launched Idira, a new identity security platform aimed at securing human users, machine identities, and AI agents amid the rising adoption of autonomous AI systems amongst enterprises.
The company is positioning Idira as a next-generation identity security platform that goes beyond traditional privileged access management (PAM) systems by applying dynamic privilege controls across every type of identity inside an enterprise.
“For most of the last two decades, identity security was built on a comfortable assumption: One can maintain a firm divide between a small number of powerful administrators and a much larger number of ordinary users; that is enough to secure the organization. That assumption no longer holds,” Peretz Regev, chief product & technology officer at Palo Alto, said in a blog post.
The launch follows Palo Alto’s acquisition and integration of CyberArk, which forms a key foundation of the platform.
Palo Alto’s bet on AI-era identity security
“The fundamental problem today is scale,” said Rohan Vaidya, AVP Sales India and SAARC.  “Most organisations are already running AI agents — and those agents authenticate, call APIs, access sensitive data, and can escalate their own privileges to complete a task. No legacy IAM or PAM platform was designed to see any of that, let alone control it.”
With Idira, Palo Alto attempts to address these risks by treating every identity in the organization as privileged.
“What Idira does differently is operate as a single control plane across all three identity types; human, machine, and agentic. On the discovery side, it continuously scans SaaS, cloud, and developer environments to surface every active agent and machine identity, enriching each one with context: who owns it, what it can access, and what permissions are actually in use. That alone closes a blind spot most security teams don’t even know they have,” Vaidya said.
Analysts say Idira is attempting to address gaps that traditional identity-management platforms such as Auth0 and SailPoint were not originally designed to handle, particularly around governing autonomous AI agents in real time.
“Auth0 excels at consumer identity and enterprise single sign-on, but its core architecture is not natively designed to govern the dynamic, autonomous nature of generative AI agents. SailPoint, on the other hand, provides excellent AI-driven insights for human access governance, such as role discovery and certification recommendations, but it primarily focuses on lifecycle management and compliance rather than runtime security for autonomous actors,” explained Amit Jaju, senior managing director at Ankura Consulting.
Jaju added that what genuinely sets Idira apart is that instead of granting an agent static access tokens (which Auth0 or SailPoint might manage), Idira dynamically elevates privileges exactly when an agent needs to execute a task and instantly revokes them afterward.
CISOs navigate AI risks
For enterprises, the launch reflects a broader industry shift toward identity-centric cybersecurity models as organizations deploy generative AI tools, autonomous agents, and cloud-native applications at scale.
Analysts say the growing number of non-human identities is creating operational and security challenges because many existing identity systems were originally built to manage employees and IT administrators rather than AI agents and automated services.
“A self-contained AI agent can engage with systems, initiate processes, and make decisions without any form of human validation. This presents a much bigger threat surface. Current technologies that help manage this issue address only some aspects of the problem, many having been built without the intent of handling machine speed, highly dynamic environments,” said Devroop Dhar, co-founder and CEO at Primus Partners.
As identity, cloud security, artificial intelligence governance, and SOC workflows continue to converge, organizations will find themselves becoming more and more reliant on one particular ecosystem, Dhar said. The advantage here is ease of operation, a consolidated view, and greater integration.
The downside is less flexibility over time. Breaking away from the system at a later date may prove challenging since identity management procedures and other processes will be woven deeply into business operations. In the coming years, CISOs will favour ecosystems that support open architectures, Dhar noted.
Analysts also caution that none of the platforms eliminates the need for multilayered security. Organizations will need to maintain good identity hygiene practices, implement least privilege, utilize MFA, rotate credentials, and conduct constant monitoring.
“Another aspect to address relates to agent governance. There must be a clear understanding of what assets can be accessed by agents, under what circumstances human intervention is required, and how agent activities are monitored,” said Dhar.
Enterprises must invest in prompt filtering systems to prevent prompt injection attacks, which currently stand as the largest vulnerability in AI systems, Jaju said. “They should also engage in continuous adversarial testing and agentic red teaming before deploying any autonomous system into a production environment.”
View the full article
Palo Alto Networks has launched Idira, a new identity security platform aimed at securing human users, machine identities, and AI agents amid the rising adoption of autonomous AI systems amongst enterprises.
The company is positioning Idira as a next-generation identity security platform that goes beyond traditional privileged access management (PAM) systems by applying dynamic privilege controls across every type of identity inside an enterprise.
“For most of the last two decades, identity security was built on a comfortable assumption: One can maintain a firm divide between a small number of powerful administrators and a much larger number of ordinary users; that is enough to secure the organization. That assumption no longer holds,” Peretz Regev, chief product & technology officer at Palo Alto, said in a blog post.
The launch follows Palo Alto’s acquisition and integration of CyberArk, which forms a key foundation of the platform.
Palo Alto’s bet on AI-era identity security
“The fundamental problem today is scale,” said Rohan Vaidya, AVP Sales India and SAARC.  “Most organisations are already running AI agents — and those agents authenticate, call APIs, access sensitive data, and can escalate their own privileges to complete a task. No legacy IAM or PAM platform was designed to see any of that, let alone control it.”
With Idira, Palo Alto attempts to address these risks by treating every identity in the organization as privileged.
“What Idira does differently is operate as a single control plane across all three identity types; human, machine, and agentic. On the discovery side, it continuously scans SaaS, cloud, and developer environments to surface every active agent and machine identity, enriching each one with context: who owns it, what it can access, and what permissions are actually in use. That alone closes a blind spot most security teams don’t even know they have,” Vaidya said.
Analysts say Idira is attempting to address gaps that traditional identity-management platforms such as Auth0 and SailPoint were not originally designed to handle, particularly around governing autonomous AI agents in real time.
“Auth0 excels at consumer identity and enterprise single sign-on, but its core architecture is not natively designed to govern the dynamic, autonomous nature of generative AI agents. SailPoint, on the other hand, provides excellent AI-driven insights for human access governance, such as role discovery and certification recommendations, but it primarily focuses on lifecycle management and compliance rather than runtime security for autonomous actors,” explained Amit Jaju, senior managing director at Ankura Consulting.
Jaju added that what genuinely sets Idira apart is that instead of granting an agent static access tokens (which Auth0 or SailPoint might manage), Idira dynamically elevates privileges exactly when an agent needs to execute a task and instantly revokes them afterward.
CISOs navigate AI risks
For enterprises, the launch reflects a broader industry shift toward identity-centric cybersecurity models as organizations deploy generative AI tools, autonomous agents, and cloud-native applications at scale.
Analysts say the growing number of non-human identities is creating operational and security challenges because many existing identity systems were originally built to manage employees and IT administrators rather than AI agents and automated services.
“A self-contained AI agent can engage with systems, initiate processes, and make decisions without any form of human validation. This presents a much bigger threat surface. Current technologies that help manage this issue address only some aspects of the problem, many having been built without the intent of handling machine speed, highly dynamic environments,” said Devroop Dhar, co-founder and CEO at Primus Partners.
As identity, cloud security, artificial intelligence governance, and SOC workflows continue to converge, organizations will find themselves becoming more and more reliant on one particular ecosystem, Dhar said. The advantage here is ease of operation, a consolidated view, and greater integration.
The downside is less flexibility over time. Breaking away from the system at a later date may prove challenging since identity management procedures and other processes will be woven deeply into business operations. In the coming years, CISOs will favour ecosystems that support open architectures, Dhar noted.
Analysts also caution that none of the platforms eliminates the need for multilayered security. Organizations will need to maintain good identity hygiene practices, implement least privilege, utilize MFA, rotate credentials, and conduct constant monitoring.
“Another aspect to address relates to agent governance. There must be a clear understanding of what assets can be accessed by agents, under what circumstances human intervention is required, and how agent activities are monitored,” said Dhar.
Enterprises must invest in prompt filtering systems to prevent prompt injection attacks, which currently stand as the largest vulnerability in AI systems, Jaju said. “They should also engage in continuous adversarial testing and agentic red teaming before deploying any autonomous system into a production environment.”
View the full article
ClickFix, a one-shot social engineering technique that tricks victims into executing malicious workflows disguised as fixes to technical issues in their systems, has got a persistence upgrade.
In a one-off instance, ReliaQuest researchers have spotted an intrusion chain using scheduled tasks, PowerShell-based command-and-control (C2), and a unique abuse of the decade-old open-source proxy tool PySoxy.
As the researchers pointed out in a blog post, PySoxy is giving attackers encrypted proxy access without relying on well-known malware or remote monitoring and management (RMM) tools. The observed attack chain established an initial PowerShell-based C2 channel, followed by a second C2 path through PySoxy.
The campaign was observed in April. ReliaQuest said this was the first time it had seen ClickFix combined with PySoxy in active intrusions.
PySoxy used for dual-channel persistence
The attack started with a ClickFix lure that tricked the victim into manually pasting and executing a malicious command disguised as a fix to a technical issue. Once launched, the command initiated a multi-stage infection chain.
According to ReliaQuest, the execution flow established persistence through scheduled tasks, carried out domain reconnaissance, and opened an initial PowerShell-based C2 channel back to the attackers. The chain then deployed PyProxy to create a second encrypted communication path that turns the infected endpoint into a proxy relay.
“After staging reconnaissance output locally and uploading it to separate attacker-controlled infrastructure, the attacker downloaded Python tooling to C:\ProgramData,” the researchers said. “The compiled bytecode file was then executed with Python and identified as PySoxy. This turned the intrusion from a PowerShell-led access chain into one with redundant access paths.”
Researchers noted that the use of a second foothold, proxying through PySoxy, allows the intrusion to go on even after the PowerShell C2 connection is blocked.
ClickFix drifts into post-exploitation
ReliaQuest pointed to the evidence that ClickFix is no longer just a social engineering delivery mechanism. It is being increasingly used as a gateway into broader post-exploitation operations involving stealth, persistence, and trusted-tool abuse.
Earlier this year, the cybersecurity technology company reported that ClickFix accounted for a large share of observed incidents and defense evasion activities in late 2025 and early 2026, with attackers relying on obfuscated commands and hidden execution chains.
The use of PySoxy marks ClickFix shifting to older legitimate tooling with modular access techniques. By orchestrating multiple communication paths within the chain, the attackers are forcing defenders to expand containment efforts.
“Looking ahead, we expect ClickFix operators to continue experimenting with post-exploitation tooling beyond PowerShell,” the researchers said. “Python is one option, but the underlying logic, using whatever scripting runtime is available to stage proxy or C2 capability without dropping a traditional payload, applies equally to other interpreters.”
Hunting clues include scheduled tasks and Python artifacts
In the ReliaQuest observed chain, scheduled tasks repeatedly relaunched malicious activity after communication attempts failed. ReliaQuest said defenders should specifically investigate recurring scheduled task creation alongside unusual Python-related artifacts and proxy-style command-line activity.
Recommendations for incident responders included isolating affected hosts, reviewing scheduled tasks for suspicious re-execution patterns, and hunting for encrypted proxy behavior in Python processes instead of focusing solely on blocked C2 traffic.
“Hunt for command lines containing combinations such as -ssl, -remote_ip, -remote_port, SOCKS, or .pyc execution,” the researchers said, adding that these are high-value signals for PySoxy-style activity.
View the full article
OHC_logo_transparent_01.jpeg flags-medium.png OHC_logo_blue_square_small.jpeg

 

Account

Navigation

Search

Search

Configure browser push notifications

Chrome (Android)
  1. Tap the lock icon next to the address bar.
  2. Tap Permissions → Notifications.
  3. Adjust your preference.
Chrome (Desktop)
  1. Click the padlock icon in the address bar.
  2. Select Site settings.
  3. Find Notifications and adjust your preference.