Skip to content
View in the app

A better way to browse. Learn more.

hosang I.T.

A full-screen app on your home screen with push notifications, badges and more.

To install this app on iOS and iPadOS
  1. Tap the Share icon in Safari
  2. Scroll the menu and tap Add to Home Screen.
  3. Tap Add in the top-right corner.
To install this app on Android
  1. Tap the 3-dot menu (⋮) in the top-right corner of the browser.
  2. Tap Add to Home screen or Install app.
  3. Confirm by tapping Install.

Tech

Tech Articles from a wide variety of topics and categories
Cybersecurity researchers have discovered a previously undocumented data wiper that has been used in attacks targeting Venezuela at the end of last year and the start of 2026. Dubbed Lotus Wiper, the novel file wiper has been used in a destructive campaign targeting the energy and utilities sector in Venezuela, per findings from Kaspersky. "Two batch scripts are responsible for initiating theView the full article
On January 31, 2026, researchers disclosed that Moltbook, a social network built for AI agents, had left its database wide open, exposing 35,000 email addresses and 1.5 million agent API tokens across 770,000 active agents. The more worrying part sat inside the private messages. Some of those conversations held plaintext third-party credentials, including OpenAI API keys shared between agents,View the full article
X, formerly Twitter, has announced it is launching a custom timelines feature that allows users to pin specific topics to their home tab in the X app for iOS.


The company says custom timelines are powered by Grok AI, which understands the social media platform's algorithm personalization so that timelines are tuned for individual users.

Paying users will see an Add+ button appear next to the Following tab, with support for over 75 topics, ranging from design to robotics to real estate. X says Grok's filters work even better for topics a user already engages with.

Early access to custom timelines is currently limited to Premium subscribers on iOS, with Android set to follow "soon."


Today, X is also rolling out a tool to snooze topics on the For You tab, allowing users to tune out politics- or sports-related posts, for example.
This article, "X Rolls Out AI-Powered Custom Timelines for Premium Users" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Anthropic’s Mythos has intensified a problem that vulnerability management programs were already struggling to contain: too many vulnerabilities and not enough clarity about which ones matter.
What changes with Mythos — and the AI-based class of vulnerability discovery systems it represents — is the speed at which software flaws can be found and exploited.
That speed raises a more immediate question for defenders: Which vulnerabilities require action?
Anthropic has pointed to one method. In guidance tied to its work on AI-accelerated offense, the company recommended using the Exploit Prediction Scoring System (EPSS), a probabilistic model developed by the data scientists behind Empirical Security, and published through FIRST, as a way to triage vulnerabilities as discovery increases.
According to Anthropic, “Patching the KEV [CISA’s Known Exploited Vulnerabilities catalog] list first, and then everything above a chosen EPSS threshold will help you turn thousands of open CVEs into a manageable queue.”
“EPSS uses the same probabilistic models that weather forecasters do,” Michael Roytman, co-founder and CTO of Empirical Security and one of the original EPSS authors, told CSO. “The forecast is which vulnerabilities are likely to be exploited somewhere on the internet in the next 30 days.”
Roytman added, “We don’t deal with rain by constantly having an umbrella over our heads. We have predictive models that tell us whether we should or should not bring an umbrella.”
Ed Bellis, CEO of Empirical Security, told CSO that Anthropic’s recommendation stood out because of who made it, not because EPSS is new. According to Bellis, it was the first time, to his knowledge, that a large language model provider had explicitly endorsed a probabilistic, purpose-built model for vulnerability prioritization.
A system already under strain
Mythos arrives as the vulnerability ecosystem is already under strain.
Most recently, the volume of new vulnerabilities forced NIST to scale back enrichment of its National Vulnerability Database (NVD) to only certain CVEs. The NVD enriches vulnerability reports with CVSS scores, which are developed by FIRST, while EPSS provides a separate estimate of exploitation likelihood.
“The fact that they’re [NIST] narrowing down the vulnerabilities that they are going to focus on [for CVSS] is because it’s all human-driven,” Bellis said. EPSS, by contrast, is machine-driven and can be applied across all CVEs, with scores published daily.
“It’s machine-driven, and it’s a machine learning model that ultimately scores that vulnerability,” Bellis added. “The average vulnerability management practice today is not thinking about it from a machine-learning, data-driven perspective, but they could be.”
According to the Zero Day Clock, the mean time to exploit a vulnerability after it’s been discovered is going to reach one hour this year, and only one minute by 2028, down from 2.3 years in 2018.
Security leaders weigh promise versus reality
Security vendors are increasingly incorporating EPSS scores into their systems.
According to Roytman, EPSS has been incorporated into more than 120 security vendors’ products, including CrowdStrike, Cisco, Palo Alto Networks, Qualys, and Tenable platforms.
“I do not think other CISOs realize how broadly EPSS has been adopted, but that adoption is great news for the industry,” James Robinson, CISO at Netskope, told CSO.
“EPSS, when applied to [software flaws], is an essential step in being able to know if this exploitable vulnerability applies to your implementation or operation,” he said, adding that “the role that EPSS can play in identifying non-CVE vulnerabilities identified from Mythos and other upcoming models is extremely useful.”
Aaron Weismann, CISO at Main Line Health, welcomed the faster discovery of vulnerabilities but questioned whether the guidance translates to sectors such as healthcare, telling CSO, “It’ll be interesting to see how actionable those recommendations are for critical infrastructure — like healthcare, utilities, government, and others — where immediate and automated patching can be challenging due to the prevalence of legacy hardware and software.”
Not all defenders embrace the concept of EPSS or even CVSS to address the rapid discovery of vulnerabilities.
“To be direct: Both CVSS and EPSS are fundamentally outdated in the ‘Mythos’ era and require a complete rethink,” Ramy Houssaini, chief cyber solutions officer of Cloudflare, told CSO. “EPSS relies on lagging, 30-day historical data, but AI has collapsed the time-to-exploit into mere minutes. Instead of waiting for a predictive score to prioritize human-speed patching, organizations must shift to real-time defense.”
Exposure management will extend beyond CVEs
While most of the analysis of the power of Mythos to discover vulnerabilities has centered on common applications to which CVEs can be applied, its discoveries will most likely reveal millions of other vulnerabilities that don’t meet this definition. “A similar process is happening across clouds and applications, where there is no common enumerator across those applications,” Empirical Security’s Roytman said.
“My application looks very different than yours, even if it’s written in the same language,” he added. “So, when we think about that probabilistic modeling expanding to all of exposure management, which might be a bigger problem than just CVEs themselves, we have to think about building local predictive models for applications, clouds, configurations, misconfigurations, and that is another exercise in taking advantage of the existing security tooling and building small, purpose-built models rather than having humans do the manual triage work.”
In short, Mythos and competing AI models will soon be able to find millions and millions of vulnerabilities that will not fit into the CVE model. “We see enterprises all the time that might have tens of millions of open instances of vulnerabilities, let alone the sheer volume of those classes of flaws that they’re going to discover on the AI front,” Bellis said.
“This is a problem, but the sky is not falling,” Roytman said. “There are methods for managing it.”
View the full article
Apple has announced the availability of Tap to Pay on iPhone in Malaysia, allowing independent sellers, small merchants, and large retailers in the region to use ‌iPhones‌ as a payment terminal.


Tap to Pay allows iPhones to accept payments via Apple Pay, contactless credit and debit cards, and other digital wallets‌‌‌. All transactions are encrypted, and Apple has no information about what is purchased or the person who made the purchase.

No additional hardware or credit card machine is required‌ to use Tap to Pay on iPhone. The feature uses NFC technology to securely authenticate the contactless payments, plus the feature also supports PIN entry, which includes accessibility options.

Starting today, ADAPTIS, Fiuu, HitPay, Stripe, and Zoho are the first payment platforms in Malaysia to bring Tap to Pay on iPhone to its merchants. Tap to Pay on iPhone will also be coming soon for checkout at Apple The Exchange TRX. Supported contactless debit and credit cards include American Express, JCB, Mastercard, MyDebit, UnionPay, and Visa.

Tap to Pay on ‌iPhone‌ launched in February 2022 in the United States, and since then, Apple has expanded it to more than 50 countries and regions around the world.Tags: Malaysia, Tap to Pay on iPhone
This article, "Apple Launches Tap to Pay on iPhone in Malaysia" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Cybersecurity researchers have discovered a new variant of a known malware called LOTUSLITE that's distributed via a theme related to India's banking sector. "The backdoor communicates with a dynamic DNS-based command-and-control server over HTTPS and supports remote shell access, file operations, and session management, indicating a continued espionage-focused capability set rather thanView the full article
A critical security vulnerability has been disclosed in a Python-based sandbox called Terrarium that could result in arbitrary code execution. The vulnerability, tracked as CVE-2026-5752, is rated 9.3 on the CVSS scoring system. "Sandbox escape vulnerability in Terrarium allows arbitrary code execution with root privileges on a host process via JavaScript prototype chain traversal," according toView the full article
Softwareentwicklung und Autoproduktion haben mehr gemein, als man denkt. Lesen Sie, was Sie zum Thema Software Bill of Materials (SBOM) wissen sollten.
Foto: Ju1978 – shutterstock.com
Eine Software Bill of Materials ist ein detaillierter Leitfaden, der unter anderem Aufschluss über die Komponenten Ihrer Software gibt. Als eine Art Stückliste hilft eine SBOM Anbietern und Käufern gleichermaßen, den Überblick über die Komponenten zu behalten und die Sicherheit der Softwarelieferkette zu verbessern.
SBOM – Definition
Eine Software Bill of Materials ist eine formale, strukturierte Aufzeichnung, die die
Komponenten eines Softwareprodukts und
ihre Beziehungen innerhalb der Softwarelieferkette
beschreibt. Eine SBOM gibt also einerseits an, welche Pakete und Bibliotheken in Ihre Anwendung eingeflossen sind, andererseits auch die Beziehung zwischen diesen Paketen und Bibliotheken und anderen vorgelagerten Projekten. Das ist besonders wichtig ist, wenn es um wiederverwendeten Code und Open-Source-Komponenten geht.
Sie kennen Stücklisten vielleicht im Zusammenhang mit Neuwagen. In diesem Fall handelt es sich um ein Dokument, das jede Komponente, die sich in Ihrem neuen Fahrzeug befindet, detailliert beschreibt. Auch wenn Ihr Auto von Toyota oder General Motors zusammengebaut wurde: Viele seiner Komponenten stammen von Subunternehmern auf der ganzen Welt. Die Stückliste gibt Aufschluss darüber, woher jedes einzelne dieser Teile stammt. Das dient nicht nur der Transparenz, sondern auch der Sicherheit: Wird eine bestimmte Serie von Airbags zurückgerufen, müssen die Fahrzeughersteller schnell herausfinden können, wo diese verbaut sind.
Da Open-Source-Bibliotheken von Drittanbietern sich jedoch zunehmender Beliebtheit erfreuen, um containerisierte, verteilte Applikationen zu erstellen, weisen Softwareentwicklung und Fahrzeugfertigung inzwischen mehr Gemeinsamkeiten auf, als man denkt. Sowohl Entwickler als auch Benutzer können eine Software Bill of Materials verwenden, um nachzuvollziehen, welche Bestandteile in die Software eingeflossen sind, wie sie verteilt und verwendet wurden. Das erlaubt – insbesondere aus Sicherheitsperspektive – eine Reihe wichtiger Rückschlüsse.
Software Bill of Materials – Vorteile
Die Zeiten monolithischer, proprietärer Codebasen sind längst vorbei. Moderne Anwendungen basieren oft auf in großen Teilen wiederverwendetem Code – häufig mit Beteiligung von Open-Source-Bibliotheken. Diese Anwendungen werden auch zunehmend in kleinere, in sich geschlossene Funktionskomponenten, so genannte Container, aufgeteilt, die über Orchestrierungsplattformen wie Kubernetes gemanagt und lokal oder in der Cloud ausgeführt werden.
Im Großen und Ganzen waren diese Veränderungen ein Segen für die Softwareentwicklung und haben dazu beigetragen, die Entwicklerproduktivität zu erhöhen und Kosten zu senken. Aus Security-Perspektive sieht das Bild nicht ganz so rosig aus: Indem sie sich in hohem Maße auf den Code von Drittanbietern verlassen, (deren interne Prozesse sie möglicherweise nicht oder nur teilweise kennen), haben Entwickler eine Lieferkette von Softwarekomponenten geschaffen, die genauso komplex ist, wie die von Herstellern physischer Produkte. Da eine Anwendung jedoch nur so sicher ist wie ihre schwächste Komponente, kann dieses Gebahren gravierende Schwachstellen zur Folge haben. Die 2020er Jahre waren von einer Reihe von Angriffen auf die Softwarelieferkette geprägt, die für Schlagzeilen sorgten:
Ende 2020 gelang es Hackern, die mit dem russischen Geheimdienst in Verbindung stehen sollen, eine Backdoor in die Netzwerk-Monitoring-Plattform von SolarWinds einzuschleusen. Diese wird wiederum von anderen Sicherheitsprodukten genutzt, was zu ihrer Kompromittierung führte.
Ende 2021 wurde eine schwerwiegende Sicherheitslücke in Apache Log4j entdeckt, einer Java-Bibliothek, die für die Protokollierung von Systemereignissen verwendet wird. Das hört sich nur so lange langweilig an, bis man feststellt, dass fast jede Java-Anwendung Log4j in irgendeiner Form verwendet und damit angreifbar wird.
Diese Sicherheitskrisen verdeutlichen die potenzielle Rolle der Software Bill of Materials innerhalb der Sicherheitslandschaft. Viele Anwender haben vielleicht nur beiläufig von diesen Schwachstellen gehört, waren sich aber nicht bewusst, dass sie Log4j oder eine andere SolarWinds-Komponente verwenden. Mit einer SBOM wissen Sie genau, welche Pakete Sie installiert haben – und vor allem, welche Versionen dieser Pakete. So können Sie bei Bedarf aktualisieren, um auf der sicheren Seite zu sein.
Eine Software Bill of Material kann auch über die Sicherheit hinausgehen: SBOMs können Entwicklern beispielsweise dabei helfen, den Überblick über die Open-Source-Lizenzen ihrer verschiedenen Softwarekomponenten zu behalten, was wichtig ist, wenn es darum geht, Applikationen zu distribuieren.
SBOMs – Pflicht in den USA und bald auch in Europa
Der SolarWinds-Hack hat insbesondere bei der US-Regierung die Alarmglocken schrillen lassen – auch weil viele US-Bundesbehörden die kompromittierte Komponente eingesetzt hatten. Deshalb enthielt die im Mai 2022 von der Biden-Regierung erlassene Cybersecurity-Verordnung auch Richtlinien im Zusammenhang mit Software Bill of Materials. Das US-Handelsministerium veröffentlichte einen Leitfaden, welche grundlegenden Elemente in SBOMs enthalten sein müssen.
Obwohl sich die Anordnung speziell auf diejenigen bezieht, die in direkter Beziehung zu den US-Bundesbehörden stehen, werden die Regelungen weitergehende Auswirkungen haben. Schließlich werden die an die US-Regierung verkauften Produkte, die nun mit einer SBOM ausgeliefert werden müssen, größtenteils auch an andere Unternehmen und Organisationen verkauft. Viele Softwarehersteller hoffen, dass die Kunden aus der Privatwirtschaft SBOMs ebenfalls als Mehrwert betrachten.
Außerdem ist das staatliche Auftragswesen selbst eine Lieferkette, wie Sounil Yu, ehemaliger Chief Security Scientist bei der Bank of America sowie CISO bei JupiterOn, unterstreicht: “Es gibt nur eine bestimmte Anzahl von Unternehmen, die direkt mit der US-Regierung zusammenarbeiten und von der Verordnung betroffen sind. Die Auswirkungen auf der zweiten Zuliefererebene sind noch wesentlich größer.”
In Europa wird die SBOM ebenfalls verpflichtend – und zwar im Rahmen der Umsetzung des Cyber Resilience Act bis Ende 2027.
Software Bill of Materials – Aufbau
Als Reaktion auf die Executive Order veröffentlichte die National Telecommunications and Information Administration (NTIA) im Juli 2021 den Leitfaden “The Minimum Elements For a Software Bill of Materials” (PDF). Das Dokument könnte zu einem De-facto-Standard für SBOMs in der gesamten Branche werden und legt sieben Datenfelder fest, die jede SBOM enthalten sollte:
Name des Anbieters: Der Name einer Einheit, die eine Komponente erstellt, definiert und identifiziert.
Komponentenname: Die Bezeichnung, die einer vom ursprünglichen Lieferanten definierten Softwareeinheit zugewiesen wird.
Version der Komponente: Eine Kennung, die vom Lieferanten verwendet wird, um eine Änderung der Software gegenüber einer zuvor identifizierten Version anzugeben.
Andere eindeutige Identifikatoren: Andere Informationen, die verwendet werden, um eine Komponente zu identifizieren oder als Nachschlageschlüssel für relevante Datenbanken dienen. Das könnte etwa ein Identifikator aus dem NIST CPE Dictionary sein.
Abhängigkeitsbeziehung: Kennzeichnet die Beziehung, in der eine Upstream-Komponente X in Software Y enthalten ist. Das ist besonders wichtig für Open-Source-Projekte.
Autor der SBOM-Daten: Der Name der Entität, die die SBOM-Daten erstellt.
Zeitstempel: Aufzeichnung des Datums und der Uhrzeit der Zusammenstellung der SBOM-Daten.
SBOMs müssen darüber hinaus auch folgende Anforderungen erfüllen:
Die SBOM muss in einem von drei standardisierten Formaten vorliegen, damit sie maschinenlesbar ist – SPDX, CycloneDX oder SWID-Tags.
Mit jeder neuen Softwareversion muss eine neue SBOM generiert werden, um sicherzustellen, dass sie auf dem neuesten Stand ist.
Die SBOM muss nicht nur Abhängigkeitsbeziehungen enthalten, sondern auch Aufschluss darüber geben, wo solche Beziehungen wahrscheinlich bestehen, aber der Organisation, die die SBOM erstellt, unbekannt sind.
SBOM erstellen – so geht’s
Wenn Sie diesen Artikel lesen, empfinden Sie es möglicherweise als entmutigende Aufgabe, eine Software Bill of Materials zu erstellen. Schließlich muss es ein Alptraum sein, all diese Informationen manuell zusammenzutragen. Glücklicherweise werden SBOMs in den meisten Fällen mit Hilfe von SCA-Tools (Software Composition Analysis ) automatisch erstellt. Diese Tools werden häufig in DevSecOps-Pipelines eingesetzt und spielen nicht nur für die Erstellung von SBOMs eine Rolle.
SCA-Tools durchsuchen Ihre Codeverzeichnisse nach Paketen und vergleichen sie mit Online-Datenbanken, um sie mit bekannten Bibliotheken abzugleichen. Es gibt aber auch Werkzeuge, die eine Software Bill of Materials im Rahmen des Software-Build-Prozesses erstellen. Die OWASP Foundation hat eine umfassende Liste von SCA-Tools zusammengestellt, die von einfachen, quelloffenen Kommandozeilen-Tools bis hin zu spezialisierten, kommerziellen Produkten reicht. Wenn Sie tiefer in diesen Bereich eintauchen möchten, sollten Sie außerdem einen Blick auf unseren Artikel “7 Tools, die Ihre Softwarelieferkette absichern” werfen.
Wenn Sie verteilte Software entwickeln, wird es immer wichtiger, SBOMs in Ihre Entwicklungspraxis zu integrieren. Auch wenn Sie keine Verträge mit der US-Regierung abschließen – Sie sollten sich angesichts der Bedrohungslage in jedem Fall Gedanken über die Sicherheit ihrer Softwarelieferkette machen.
View the full article
Apple yesterday announced that longtime Apple CEO Tim Cook is planning to step down from his role later this year, with current hardware engineering chief John Ternus set to take over as CEO. We've seen media reports suggesting Ternus will bring Jobs-like decisiveness back to Apple, as well as reactions from top world leaders, but we thought we'd also highlight what MacRumors readers think of the transition.


Reactions on the MacRumors forums run the gamut from positive to negative, with some people praising Cook for everything he's done for Apple, and others celebrating his departure from the role.

From Cook fans:

nfl46 - Thank you, Tim! He left John in a reallyyyyyyy good financial position!
RMMediccc - Thanks for being the right guy at the right time Tim. You will be missed, but it was time and you are making the correct call just as Steve did.
DocMultimedia - Congrats to Mr. Cook for amazing growth for Apple over so many years. Hopefully Apple will continue to grow under Mr. Ternus. So much respect for both (unlike many on this forum).
Adelphos33 - A lot of... let's say disappointing responses. Cook became COO on October 14, 2005. One of the best and most important executives of all time. He made a lot of people very wealthy, and not just Apple employees. A personally pioneering one as well.
KPOM - Tim Cook will go down as one of the best CEOs to lead a Fortune 500. I expect he'll stay on as executive chairman at least until January 2029 as he is Apple's ambassador to the world of politics.
transpo1 - Cook was the right guy for the job at the right time. He could never do what Jobs did, and Jobs could never do what Cook did. Jobs told him "Don't do what I would do, do what you would do," and like it or not, he made wildly profitable decisions that enabled the company to keep moving forward from a position of enormous success.

From Cook critics:

Kylo83 - good, hopefully we actually see real change now
firstcitazen - Ding Dong the ....
iPedro - But Tim Cook was anything but a visionary and he completely missed what Steve Jobs intended for Siri, which debuted in the iPhone the day before his death. New blood is needed and an engineer who's a stickler for detail is a great place to start.
turbineseaplane - Party time!!! 🥳 Fantastic news. It's time for some fresh ideology, I hope.
Anonymous123 - Good riddance. Glad to see the penny pincher finally gone. Hope this marks a new, better direction for Apple. Less focus on services and ads, more focus on higher quality software and hardware, please.
gleepskip - Tim Cook is so dull, his memoirs would be an autobiography titled "Supply Chain Optimization: A Love Story."
delsoul - Does this mean we'll finally get some ballsy, new daring products instead of trying to appease the shareholders nonstop with boring stale products
superarijit - He got fired, pure and simple, PR free. Why? Imagine the utter billions he lost on failed Apple Intelligence, Apple Car, Apple Vision Pro and more. Crap software, same hardware every year. He's lucky that iphone saved him each and every time.
tgurske - Thank god. I don't know why Jobs picked a Toyota Camry to be CEO but I can't wait for someone interesting to get in there.
iMac The Knife - Hip hip hooray! Cook ended up being the worst possible choice to succeed Steve Jobs as Apple's CEO - at least in terms of product design, user experience, and genuine innovation.
HiVolt - It's finally happening. I really hope Ternus can make things better, and at least he will have a more interesting personality than a potted plant.

From Ternus fans:

Nismo73 - John's the guy for the job. Congrats!
venom600 - Awesome... glad to have a hardware guy in charge.
aj8690 - MAKE CEOs HOT AGAIN
spritle - THE TERNUSATOR!
jonnyb098 - Best Apple News in a while. Apple needs a product visionary after 5 years of stagnation (Vision Pro is not a consumer hit at all nor do most know it exists). Tim made the company a behemoth but that comes with risks. John is a product guy and that's what Apple needs now.
fant0mas - I like that John doesn't wear white shoes though... his taste in this regard seems better than Tim's. Hope this means that the OS designs will improve again as well.

General comments:

terminator-jq - Tim Cook had very big shoes to fill, but ultimately he did great work in making Apple one of the most valuable companies worldwide. That being said the change and CEO could not have come at a better time. Smart phones have stagnated and we are quickly approaching the new augmented reality era. If Apple is going to maintain this leadership position through this transition, having a hardware guy at the helm might be their best bet.
Brother Cavil - People expecting meaningful change from Ternus are in for a world of disappointment. If you pop your head outside the delusional MacRumors bubble, people LOVE their Apple products. He has no incentive to fix what isn't broken. Quite the opposite.
erikkfi - You can't look at Apple's revenue and sales graph since 2011 and argue that Tim was an unsuccessful CEO on a metric that, like it or not, is really important. Since 2011 Apple has lost its flair, imagination, and verve, though, while still making very good, buttoned-down products that sell like crazy. I don't think they make many viscerally desirable products anymore. I hope a change at the top can help with that, but I don't know much about Ternus' taste and where he falls on a hypothetical Steve-Tim spectrum.
jon9091 - Can he take Liquid Glass with him?
turbineseaplane - Feel free to take the Vision Pro with you on the way out the door. That was quite the dud Tim.
GermanSuplex - Negativity aside, Cook had a good run but it's time for a change. I expect the foldable iPhone will deliver a hardware "wow" factor that's been missing, and it's got a big hole to dig itself out of, but if they can overdeliver on their revamped Siri, that would be a good way to kickstart this guy's stint.
macduke - Finally, and someone "younger." Between this and the liquid ass guy leaving and Apple hiring the excellent designer Sebastiaan de With, I'm hopeful for the future of Apple. They just need to get their AI ducks in a row. But nothing wrong with paying for a model they can keep in-house and customize.
AnInanimateCarbonRod - I'm grateful for his time as CEO. Apple's ecosystem is still by far and away the only one I want to be in. iPhones, iPads and the Mac are still the best products in their class. MacBook Neo has totally upended the low-end market and put everyone else to shame. Apple Silicon is incredible engineering and an industry wide game changer. They haven't wavered from their commitment to privacy - and remain the only tech company I actually trust with my data. I could go on and on - AirPods, Apple TV, etc. - all fantastic successes in their own right.
mk313 - Man, what are the macrumors commenters going to complain about now!
mjschabow - Future Hot Take: "Tim Cook never would have allowed this."

Tim Cook is set to step down as CEO on September 1, 2026, which is when Ternus will take over. Cook will remain at Apple as executive chairman, a role he intends to hold "for a long time."Tags: John Ternus, Tim Cook
This article, "MacRumors Readers React to Tim Cook Stepping Down as CEO" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Apple today announced that its hit sci-fi series "Silo" is returning for a third season starting Friday, July 3, and it shared a teaser trailer.


"Silo" follows the lives of 10,000 people living in an underground bunker to escape the seemingly toxic wasteland outside. The people are unaware of why the silo was built, and those who seek the truth face deadly consequences. Rebecca Ferguson stars as Juliette Nichols, an engineer who attempts to unravel the mysteries surrounding the silo following a loved one's murder. The show is based on Hugh Howey's best-selling book series, and it is one of the most popular original series on the Apple TV streaming service.

The third season will have 10 episodes, with one released every Friday through September 4.

Apple already renewed "Silo" for a fourth and final season as well.

"With the final two chapters of 'Silo,' we can't wait to give fans of the show an incredibly satisfying conclusion to the many mysteries and unanswered questions contained within the walls of these silos," said showrunner and executive producer Graham Yost, regarding the third and fourth seasons of the show.

About Season Three (Spoilers Ahead)

Apple says the third season "continues the saga of a dystopian society."

"In the present, Juliette Nichols (Rebecca Ferguson) survives her forced 'cleaning' but returns with memory loss as the silo recovers from rebellion and faces a dangerous new threat," says Apple. "Meanwhile, in the 'Before Times,' journalist Helen Drew (Jessica Henwick) and Congressman Daniel Keene (Ashley Zukerman) uncover a conspiracy that pulls them into a chain of events with catastrophic, irreversible consequences."

Trailer


Apple TV

In the U.S., Apple TV is priced at $12.99 per month or $129 per year, with a free one-week trial available for new subscribers. Apple TV is also included in Apple One and Peacock bundles, with all of the options outlined on Apple's website.

You can stream Apple TV in the Apple TV app, which is available on the iPhone, iPad, Mac, Apple TV 4K, Apple Vision Pro, Android, PlayStation, Xbox, Roku, Amazon Fire TV, select smart TVs, on the web at tv.apple.com, and more.Related Roundup: Apple TVTags: Apple TV Service, Apple TV ShowsBuyer's Guide: Apple TV (Don't Buy)Related Forum: Apple TV and Home Theater
This article, "Apple TV's Hit Show 'Silo' is Returning Soon: Release Date and Trailer" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Two weeks after researchers using an AI tool discovered a major hole in Apache’s ActiveMQ messaging middleware, there are still thousands of unpatched instances open to the internet, more evidence that many application developers and IT leaders aren’t paying close attention to warnings about vulnerabilities.
While the remote code injection vulnerability [CVE-2026-34197] was revealed on April 7, according to statistics from the ShadowServer Foundation, there are still almost 6,500 unpatched instances of ActiveMQ open to being abused.
“The fact that ShadowServer is still seeing 6,000+ unpatched boxes nearly two weeks later is just mind-blowing,” IT analyst Rob Enderle of the Enderle Group told CSO. “In a world where an LLM can help an attacker weaponize a bug the second it’s announced, taking 12 days to patch is essentially a suicide note for your network”.
Vulnerable are versions of ActiveMQ and ActiveMQ Broker before 5.19.4, and 6.0 to before 6.2.3; this means the flaw could have been exploited for over a decade. ActiveMQ Artemis isn’t affected.
The issue is so serious that the US Cybersecurity and Infrastructure Security Agency (CISA) added the bug to its known and exploited vulnerability list (KEV) this week, urging federal agencies to promptly update their applications.
The move should also be seen by private sector developers who use ActiveMQ in their applications, and IT and security leaders who have apps using ActiveMQ in their environments, as a cue to act fast and upgrade to patched versions 5.19.4 or 6.2.3.
Bug found by AI in 10 minutes
The hole was discovered by researchers at Horizon3.ai using Anthropic’s Claude AI assistant. It took them about 10 minutes, an illustration of how quickly modern AI tools can be used by experts to find vulnerabilities. Anthropic says its limited release Claude Mythos tool is even better than Claude at finding flaws.
Apache says an authenticated attacker can exploit the hole with a crafted discovery URI that triggers a parameter to load a remote Spring XML application context using ResourceXmlApplicationContext.  Because Spring’s ResourceXmlApplicationContext instantiates all singleton beans before the BrokerService validates the configuration, arbitrary code execution occurs on the broker’s Java VM through bean factory methods such as Runtime.exec.
“This vulnerability sat there for 13 years,” noted Enderle. “Humans missed it, scanners missed it, but Claude finds it in what, 10 minutes? That’s a massive capability leap. AI is basically acting like an archeologist for exploits, digging up every skeleton we’ve left in our legacy closets for the last decade.”
The problem for CSOs is “we’re basically bringing a knife to an AI gunfight,” he added. “Most IT shops are still stuck in ‘Human-Speed,’ waiting for a weekend maintenance window or a committee meeting, while the bad guys are running at ‘Machine-Speed.’ If you aren’t automating your defense and using AI to patch as fast as AI is finding the holes, you aren’t just behind; you’re already breached and just don’t know it yet.”
Automation is key
“If a company hasn’t patched this by now, it’s moved past a ‘resource issue’ and straight into professional negligence,” Enderle said. “We’ve got to stop treating patching like a chore and start treating it like a survival requirement.”
The fix is simple, but hard for most old-school IT shops to swallow, he noted: Get the humans out of the way. “If AI is finding holes in minutes,” he said, “a 12-day manual patch cycle is basically an invitation to get robbed.”
Start by putting together a software bill of materials for every app in your environment, Enderle advised. “Without it, you’re just guessing what’s under the hood. You need a live, automated inventory, using standards like CycloneDX, so the second a bug like this [ActiveMQ] hits, you aren’t scanning. You already know exactly which apps are carrying the poisoned ingredient.”
Second, he said, auto-patch the small stuff and use automated testing for the big systems. Again, he maintained that if IT is still waiting for a weekend maintenance window or a committee approval to fix a critical flaw, “you’re playing a 2010 game in a 2026 world.” 
“Bottom line,” he said: “If you don’t know what’s in your software, and you can’t fix it faster than an LLM can find it, you’re just a target.”
View the full article
Apple recently cracked down on Cal AI, an app owned by MyFitnessPal that tried to skirt Apple's in-app purchase rules. Apple told TechCrunch that it briefly pulled the calorie-counting app last week for violating purchasing guidelines and using a deceptive billing design.


When the app was pulled last week, there was speculation that it was removed for implementing web-based payments, something that is now allowed in the U.S. Apple said that's not the whole story, though, and the app was violating other guidelines.

Apple's ongoing legal battle with Epic Games led a judge to force Apple to allow U.S. developers to include links to external payment systems in their apps, but apps that are not classified as reader apps also have to include an in-app purchase option. Apps like Netflix and Spotify that offer streaming content are considered reader apps, but Cal AI is not.

As a non-reader app, Cal AI was allowed to direct users to a non-Apple purchase option for a subscription, which it did with a purchase flow using Stripe, but the purchase option should have been displayed alongside an in-app purchase option. Apple said Cal AI bypassed its required in-app purchase flow, misled customers by displaying the weekly calculated pricing more prominently than the amount the user would be billed, and had a free trial toggle that did not make the subscription's automatic renewal clear.

The app also prompted users who declined the initial subscription to agree to a second, different subscription purchase flow, leading to multiple negative reviews for its confusing third-party payment options.

Cal AI fixed the issues that Apple brought up, and the app returned to the App Store. TechCrunch suggests that Cal AI was experimenting to see whether Apple was still enforcing its rules following the court ruling requiring it to allow external payments in apps. With the Cal AI crackdown, Apple made it clear that it is indeed policing external payments.

MyFitnessPal and Cal AI have not commented on the situation. After returning to the ‌App Store‌, Cal AI is once again the number four app on the ‌App Store‌'s Health and Fitness charts.Tag: App Store
This article, "Apple Pulled Cal AI for Deceptive Billing Design, Not External Payments" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
In an all-hands meeting with employees today, Apple's future CEO John Ternus teased an "incredible road map ahead."


"I'm not exaggerating when I say this is the most exciting time to be building products and services at Apple in my entire career," said Ternus. While the meeting was private, Ternus' comments were reported by Bloomberg's Mark Gurman.

Appearing alongside Apple's current CEO Tim Cook at the Steve Jobs Theater, Ternus expressed optimism about artificial intelligence in particular.

"AI is going to create almost unlimited potential," said Ternus. "We're going to be able to keep unlocking possibilities that are going to create entirely new opportunities for our products and services, and I'm so excited about what that's going to mean for our users." Unsurprisingly, he did not provide any specific details at this time.

"We are about to change the world once again," he said.

Ternus ensured that design remains "core" to Apple, and he promised that the company is still committed to user privacy and environmental responsibility.

As for Cook, he told employees he is "healthy" and plans to serve as Apple's executive chairman for "a long time." Apple said Cook will "assist with certain aspects of the company, including engaging with policymakers around the world."

Ternus will become Apple's CEO on September 1.Tags: Bloomberg, John Ternus, Mark Gurman, Tim Cook
This article, "Apple Teases 'Incredible Road Map Ahead'" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Threat actors associated with The Gentlemen ransomware‑as‑a‑service (RaaS) operation have been observed attempting to deploy a known proxy malware called SystemBC. According to new research published by Check Point, the command-and-control (C2 or C&C) server linked to SystemBC has led to the discovery of a botnet of more than 1,570 victims. "SystemBC establishes SOCKS5 network tunnels withinView the full article
Tim Cook today told employees he plans to be at Apple "for a long time" in his new role as executive chairman. Cook shared the information in an all-hands meeting detailed by Bloomberg.


"I am healthy. My energy is high, and I plan to be in this role for a long time," said Cook. He said he will support current hardware engineering chief John Ternus in any way necessary when Ternus takes over as CEO, and he plans to continue to offer knowledge and experience whenever it's needed. "Apple will be my top priority," he said. "It's who I am at my core, and I can't imagine it any other way."

Cook is stepping down from his role as Apple CEO, handing the company over to Ternus. Apple announced the upcoming change yesterday, and said that Cook will remain on as executive chairman, where he will "assist with certain aspects of the company, including engaging with policymakers around the world."

During the meeting, Cook told employees that he thinks he can help with strengthening Apple's global relationships. When asked why he is stepping down now, Cook said that it was a good time because Apple is "doing great," the product lineup is "incredible," and Ternus is ready for the role. "These three things all intersected, and they intersect now. And so now was the time," said Cook.

Cook is set to remain CEO through September 1, 2026, at which point he will move into his new role and Ternus will take over as CEO. Cook will see Apple through WWDC, but Ternus will be leading the company by the time the iPhone 18 Pro and iPhone Fold launch.Tag: Tim Cook
This article, "Tim Cook Says He's 'Healthy,' Plans to Remain at Apple 'for a Long Time'" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Apple today provided public beta testers with new releases of upcoming iOS 26.5, iPadOS 26.5, macOS Tahoe 26.5, watchOS 26.5, and tvOS 26.5 updates for testing purposes. The public betas come a day after Apple provided the betas to developers. These are the third iOS 26.5 and iPadOS 26.5 betas, but the second ‌macOS Tahoe‌ 26.5 public beta.


After signing up for beta testing on Apple's beta site, public beta testers can download the updates using the Software Update section of the Settings app on each device.

iOS 26.5, iPadOS 26.5, and ‌macOS Tahoe‌ 26.5 include a new Suggested Places feature for recommending nearby locations to visit, and Apple is also gearing up to start showing ads in Maps.

Apple is testing end-to-end encryption for RCS messages between iPhone and Android users again, and there are proximity pairing, notification forwarding, and Live Activities for third-party wearables in the EU.Related Roundups: iOS 26, iPadOS 26, macOS TahoeRelated Forums: iOS 26, macOS Tahoe
This article, "Apple Releases New iOS 26.5, iPadOS 26.5 and macOS Tahoe 26.5 Public Betas" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Sony refreshed its earbuds earlier this year, introducing the $330 WF-1000XM6 earbuds to compete with the $249 AirPods Pro 3 that came out last September. We compared Sony's new earbuds with Apple's latest model to see which is better.

Subscribe to the MacRumors YouTube channel for more videos.
Sony's XM6 earbuds are smaller than the ‌AirPods Pro 3‌ because there's no stem, but the in-ear fit is different. The ‌AirPods Pro 3‌ have foam-infused silicone tips that are comfortable to wear for multiple hours at a time. Sony is using a polyurethane and silicone foam hybrid that feels secure in the ears, but you'll feel them more when using them for longer periods. The XM6 aren't as likely to fall out of your ears when moving around, so they're better for workouts. Earbud fit is going to vary from person to person, so some people might find the XM6 more comfortable. Both the ‌AirPods Pro 3‌ and the XM6 come with tips in multiple sizes to fit ears in different shapes.

Though Sony's earbuds have a tighter fit that's ideal for fitness-related use, the ‌AirPods Pro 3‌ have heart rate tracking and better waterproofing for sweat resistance. The XM6 have an IPX4 water resistance rating, compared to the IP57 dust and water resistance rating of the ‌AirPods Pro 3‌.

The ‌AirPods Pro 3‌ and the XM6 are both high-end flagship earbud options, and they produce excellent sound. Like fit, your opinion on sound quality will come down to individual preference.

Sony offers LDAC high-resolution codec support for improved sound quality on an Android device, along with an app that supports EQ adjustments with custom presets, adjustable bass, treble sliders, and more. Apple does not offer built-in EQ, but AirPods come with well-balanced tuning that sounds great to many people. If you want to tinker with sound adjustments, Sony's earbuds are the way to go, but if you want good sound with no tuning requirements, the ‌AirPods Pro 3‌ are the better pick.

As with sound, both models have some of the best Active Noise Cancellation you can get from earbuds. The XM6 seem to do just a bit better at canceling out low-frequency sound like engines on an airplane and higher-frequency sound like office chatter, but it's close. How the ANC works for each person will come down to the ear seal with the tip and personal preference.

Apple's ‌AirPods Pro 3‌ have the edge when it comes to Transparency because the sound passing through the microphones is more natural. Sony's version of transparency is fine, but it sounds more robotic. The difference is especially noticeable with voices. The XM6 seem to have better noise isolation on calls when outdoors, but indoors, the AirPods sound clearer.

The ‌AirPods Pro 3‌ can be used as an over-the-counter hearing aid alternative, but the XM6 can't, plus there's spatial audio support, real-time Live Translation, and heart rate tracking for workouts. Sony's earbuds have better gesture control, 360 Reality Audio, and more software customization.

The XM6 offer eight hours of playback with ANC on, which is the same battery life as the ‌AirPods Pro 3‌. For the AirPods, spatial audio with head tracking and heart rate sensing drop that total down slightly, but battery life is almost identical overall. The ‌AirPods Pro 3‌ case has enough battery for 24 hours of listening time, as does the XM6 case.

If you're in the Apple ecosystem, you're going to have a better experience with the ‌AirPods Pro 3‌ with iCloud-based features like one-tap pairing, automatic device switching anywhere you're signed in with your Apple ID, and support for Apple features like Live Translation. Sony can't implement the same close integration with Apple devices, which makes it harder to recommend Sony earbuds for Apple users.

The XM6 earbuds pair through the iPhone's Bluetooth menu or the Sony Sound Connect app. It's not a one-tap process, and while Sony can now support connecting to two devices at once, it's still not as good as Apple's process.

If you have Apple devices, the ‌AirPods Pro 3‌ are probably the better choice, and they're $81 cheaper too. The XM6 are the best pick for Android users or those who really want to tinker with sound.Related Roundup: AirPods Pro 3Tags: AirPods Pro 3, SonyBuyer's Guide: AirPods Pro (Buy Now)Related Forum: AirPods
This article, "AirPods Pro 3 vs. Sony WF-1000XM6: Which Flagship Earbuds Should You Buy?" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Satechi is adding to its lineup of charging solutions for Apple devices with the new ChargeView 140W Desktop Charger that’s available starting today. The ChargeView is a gallium-nitride charger that has adaptive charging intelligence and a digital display that shows real-time power usage.


The ChargeView is meant to be used on top of a desk, so it has space black aluminum build to match Apple’s Macs and a clean, modern design. It is meant to be used upright to minimize the amount of space that it takes up on a desk. The ChargeView includes four USB-C ports, with 140W total output. 140W is enough to charge a 16-inch MacBook Pro at full speed, but power is split when using more than one port. The included display shows how power is distributed.

Fast charging for the iPhone, iPad, and Macs is supported, and Satechi says the ChargeView supports USB PD 3.2 with AVS for advanced power optimization. Satechi’s power optimization makes sure devices get optimal output with protection against overheating, overcurrent, and overvoltage.

The ChargeView 140W Desktop Charger is priced at $100 and it can be purchased from the Satechi website or from Amazon.com.Tag: Satechi
This article, "Satechi Launches ChargeView 140W Desktop Charger" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Amazon this week is taking up to $52 off Wi-Fi models of Apple's 11th generation iPad. Prices start at $299.00 for the 128GB Wi-Fi iPad, down from $349.00, which is a solid second-best price on this model.

Note: MacRumors is an affiliate partner with Amazon. When you click a link and make a purchase, we may receive a small payment, which helps us keep the site running.

Additionally, Amazon has the 256GB Wi-Fi iPad for $399.99 ($49 off) and the 512GB Wi-Fi iPad for $597.00 ($52 off). Free delivery estimates are placed around the end of April for most of these iPad models, but Prime members should be able to get same-day delivery in many locations.

$50 OFF128GB Wi-Fi iPad for $299.00
$49 OFF256GB Wi-Fi iPad for $399.99
$52 OFF512GB Wi-Fi iPad for $597.00

If you're on the hunt for more discounts, be sure to visit our Apple Deals roundup where we recap the best Apple-related bargains of the past week.



Deals Newsletter

Interested in hearing more about the best deals you can find in 2026? Sign up for our Deals Newsletter and we'll keep you updated so you don't miss the biggest deals of the season!




Related Roundup: Apple Deals
This article, "Get Up to $52 Off the 11th Gen iPad, Available From $299" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
A 24-year-old British national and senior member of the cybercrime group “Scattered Spider” has pleaded guilty to wire fraud conspiracy and aggravated identity theft. Tyler Robert Buchanan admitted his role in a series of text-message phishing attacks in the summer of 2022 that allowed the group to hack into at least a dozen major technology companies and steal tens of millions of dollars worth of cryptocurrency from investors.
Buchanan’s hacker handle “Tylerb” once graced a leaderboard in the English-language criminal hacking scene that tracked the most accomplished cyber thieves. Now in U.S. custody and awaiting sentencing, the Dundee, Scotland native is facing the possibility of more than 20 years in prison.
Two photos published in a Daily Mail story dated May 3, 2025 show Buchanan as a child (left) and as an adult being detained by airport authorities in Spain. “M&S” in this screenshot refers to Marks & Spencer, a major U.K. retail chain that suffered a ransomware attack last year at the hands of Scattered Spider.
Scattered Spider is the name given to a prolific English-speaking cybercrime group known for using social engineering tactics to break into companies and steal data for ransom, often impersonating employees or contractors to deceive IT help desks into granting access.
As part of his guilty plea, Buchanan admitted conspiring with other Scattered Spider members to launch tens of thousands of SMS-based phishing attacks in 2022 that led to intrusions at a number of technology companies, including Twilio, LastPass, DoorDash, and Mailchimp.
The group then used data stolen in those breaches to carry out SIM-swapping attacks that siphoned funds from individual cryptocurrency investors. In an unauthorized SIM-swap, crooks transfer the target’s phone number to a device they control and intercept any text messages or phone calls to the victim’s device — such as one-time passcodes for authentication and password reset links sent via SMS. The U.S. Justice Department said Buchanan admitted to stealing at least $8 million in virtual currency from individual victims throughout the United States.
FBI investigators tied Buchanan to the 2022 SMS phishing attacks after discovering the same username and email address was used to register numerous phishing domains seen in the campaign. The domain registrar NameCheap found that less than a month before the phishing spree, the account that registered those domains logged in from an Internet address in the U.K. FBI investigators said the Scottish police told them the address was leased to Buchanan throughout 2022.
As first reported by KrebsOnSecurity, Buchanan fled the United Kingdom in February 2023, after a rival cybercrime gang hired thugs to invade his home, assault his mother, and threaten to burn him with a blowtorch unless he gave up the keys to his cryptocurrency wallet. That same year, U.K. investigators found a device at Buchanan’s Scotland residence that included data stolen from SMS phishing victims and seed phrases from cryptocurrency theft victims.
Buchanan was arrested by Spanish authorities in June 2024 while trying to board a flight to Italy. He was extradited to the United States and has remained in U.S. federal custody since April 2025.
Buchanan is the second known Scattered Spider member to plead guilty. Noah Michael Urban, 21, of Palm Coast, Fla., was sentenced to 10 years in federal prison last year and ordered to pay $13 million in restitution. Three other alleged co-conspirators — Ahmed Hossam Eldin Elbadawy, 24, a.k.a. “AD,” of College Station, Texas; Evans Onyeaka Osiebo, 21, of Dallas, Texas; and Joel Martin Evans, 26, a.k.a. “joeleoli,” of Jacksonville, North Carolina – still face criminal charges.
Two other alleged Scattered Spider members will soon be tried in the United Kingdom. Owen Flowers, 18, and Thalha Jubair, 20, are facing charges related to the hacking and extortion of several large U.K. retailers, the London transit system, and healthcare providers in the United States. Both have pleaded not guilty, and their trial is slated to begin in June.
Investigators say the Scattered Spider suspects are part of a sprawling cybercriminal community online known as “The Com,” wherein hackers from different cliques boast publicly on Telegram and Discord about high-profile cyber thefts that almost invariably begin with social engineering — tricking people over the phone, email or SMS into giving away credentials that allow remote access to corporate internal networks.
One of the more popular SIM-swapping channels on Telegram has long maintained a leaderboard of the most rapacious SIM-swappers, indexed by their supposed conquests in stealing cryptocurrency. That leaderboard previously listed Buchanan’s hacker alias Tylerb at #65 (out of 100 hackers), with Urban’s moniker “Sosa” coming in at #24.
Buchanan’s sentencing hearing is scheduled for August 21, 2026. According to the Justice Department, he faces a statutory maximum sentence of 22 years in federal prison. However, any sentence the judge hands down in this case may be significantly tempered by a number of mitigating factors in the U.S. Sentencing Guidelines, including the defendant’s age, criminal history, time already served in U.S. custody, and the degree to which they cooperated with federal authorities.
View the full article
Yelp is introducing an expanded version of its Yelp Assistant, an agentic chatbot that is able to answer questions, suggest places to visit, and complete tasks like booking a restaurant reservation.


Answers rely on hundreds of millions of Yelp reviews sourced from real people, which Yelp says allows the assistant to address "complex and highly specific requests." Yelp Assistant was previously available for hiring service professionals and getting answers to questions about businesses, but now it is available across all Yelp categories.

Users are able to ask specific questions when looking for a location, such as "birthday dinner spots with vegan options and heated outdoor seating," or "top-rated gyms with group classes and childcare."

With the AI Assistant, users can start out by asking questions to find a suitable location, and then make reservations, book appointments, place delivery orders, or get quotes in the same conversation. Yelp is adding new integrated services including Vagaro, Zocdoc, and Calendly.


There is a new AI-powered personalization model for the Yelp home feed on the iPhone and iPad, and it is able to surface more relevant content and improved recommendations.

Yelp is also updating its AI Menu Vision feature with support for photo overlays so users can see what popular dishes, drinks, and desserts look like.

The Yelp Assistant is rolling out today and it is accessible through a new Assistant tab in the Yelp app.Tag: Yelp
This article, "Yelp's AI Assistant Can Now Book Restaurants, Doctors, and More" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Anker is hosting a new suite of deals for Earth Day on both Amazon and Anker.com, highlighted by the new Prime 3-in-1 Wireless Charging Station for $119.99, down from $149.99. This accessory just launched last month, and Amazon's sale today is a solid second-best price.

Note: MacRumors is an affiliate partner with some of these vendors. When you click a link and make a purchase, we may receive a small payment, which helps us keep the site running.

The Prime 3-in-1 Wireless Charging Station features Qi2.2 support, which lets a compatible MagSafe ‌iPhone‌ charge at up to 25W. It's the same speed as Apple's ‌MagSafe‌ charger, and it is 10W faster than the standard Qi2 ‌MagSafe‌ chargers. You can also simultaneously charge an Apple Watch and AirPods with the device.

$29 OFFAnker Prime 3-in-1 Wireless Charging Station for $119.99

There are plenty of other Anker discounts happening on Amazon this week, including Anker's popular 3-in-1 MagSafe-Compatible Charging Cube for $89.98, down from $129.99. Below you'll find a list of the best Anker discounts on Amazon this week, also including wall chargers, portable chargers, and more.

Anker's website has most of the same deals, with discounts that increase with the more you buy. You'll get 5 percent off when you spend $89 or more, 10 percent off when you spend $139 or more, and 20 percent off when you spend $199 or more.

UP TO 40% OFFAnker Earth Day Sale

Although it's not on sale, Anker recently launched a new desktop charging accessory with the Anker Nano Desk Clamp Power Strip for $69.99. The new device attaches to your desk and has 10 total ports including six AC outlets, two USB-C ports, and two USB-A ports. It supports 70W USB-C fast charging and comes in white and black color options.

Wall Chargers

Nano USB-C Wall Charger - $27.99, down from $39.99
140W 4-Port GaN USB-C Charger - $64.99, down from $99.99
Wireless Chargers

3-in-1 MagSafe-Compatible UFO Charger - $75.99, down from $89.99
3-in-1 MagSafe-Compatible Foldable Charging Station - $79.99, down from $109.99
3-in-1 MagSafe-Compatible Charging Cube - $89.98, down from $129.99
3-in-1 Prime Wireless Charging Station - $119.99, down from $149.99
Prime MagSafe-Compatible 3-in-1 Charging Station - $149.99, down from $229.99
Portable Chargers

SOLIX C300 Power Station with Lantern - $169.99, down from $249.00
Prime Power Bank 26,250 mAh - $199.99, down from $229.99
SOLIX C1000 Gen 2 Portable Power Station - $428.99, down from $799.00
SOLIX C2000 Gen 2 Portable Power Station - $799.99, down from $1,499.00
If you're on the hunt for more discounts, be sure to visit our Apple Deals roundup where we recap the best Apple-related bargains of the past week.



Deals Newsletter

Interested in hearing more about the best deals you can find in 2026? Sign up for our Deals Newsletter and we'll keep you updated so you don't miss the biggest deals of the season!




Related Roundup: Apple Deals
This article, "Anker Earth Day Sale Features Up to 40% Off Popular Chargers and More" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Apple on Monday announced that Tim Cook will be stepping down as CEO, and some top leaders around the world have publicly commented on the news.


Effective September 1, Apple's hardware engineering chief John Ternus will become the company's next CEO, while Cook will become executive chairman of Apple's board of directors. In his new role, Apple said Cook will assist with "certain aspects" of the company, including "engaging with policymakers around the world."

OpenAI CEO Sam Altman:U.S. President Donald Trump:More from Trump:Alabama Governor Kay Ivey:Berkshire Hathaway chairman Warren Buffett:More from Buffett:Oculus VR founder Palmer Luckey:We will update this story with any additional quotes throughout the day.Tag: Tim Cook
This article, "Top Leaders React to Apple Announcing Tim Cook Will Step Down as CEO" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
WhatsApp has started testing a paid subscription tier called WhatsApp Plus, which adds a set of personalization options on top of the standard messaging experience, according to WABetaInfo.


The paid plan Meta is testing appears to be geared towards hardcore users who spend a lot of time in the app: subscribers get access to premium sticker packs with fullscreen overlay animations (visible to recipients without the plan), optional accent colors that replace the app's default green across the UI, and alternate app icons ranging from minimal designs to textured effects like glitter, nebula, and fuzzy purple.

The plan also raises the pinned-chat limit from 3 to 20, adds 10 exclusive ringtones, and allows bulk application of custom themes and notification settings across chat lists.

While we don't know how much the plan will cost when it goes live, the test interface currently shows €2.49 per month in Europe and $29 in Mexico. Based on the beta, users may eventually see a free one-month trial.

Otherwise, WhatsApp's main functionality remains unchanged. Messaging, voice and video calls, status updates, and end-to-end encryption are still free, suggesting the paid tier sits alongside existing features rather than restricting anything that was previously unpaid.

Overall, it's a test that was anticipated – Meta has been laying the groundwork for subscription revenue across its apps for some time. The company is already testing "Instagram Plus," a new paid subscription service in select markets for roughly $1–$2/month. That plan offers premium features focused on Stories, such as anonymous viewing, 48-hour story duration, and analytics on re-watches.

The optional WhatsApp plan is currently available to a limited number of Android beta users, with a wider rollout planned over the coming weeks. iOS support is expected at a later stage, and the subscription is not expected to apply to WhatsApp Business.Tag: WhatsApp
This article, "WhatsApp Testing Paid 'Plus' Subscription Tier – Here's What's Included" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
A high-severity authentication flaw in Microsoft’s Azure SRE Agent exposed sensitive agent data to unauthorized network access, according to a confirmed vulnerability disclosure.
The issue was identified by Enclave AI researcher Yanir Tsarimi, who detailed the findings in a blog post describing how agent interactions could be accessed without proper authentication controls. The vulnerability has been tracked as CVE-2026-32173 and rated critical with a CVSS score of 8.6.
In the blog, Tsarimi described scenarios where agent activity could be observed during execution, including interactions between users and the system. The exposure stemmed from an authentication gap in the service, allowing access to data streams without valid credentials.
Microsoft classified it as an improper authentication issue that allows an unauthorized attacker to disclose information over a network, the NVD entry said.
“Imagine you hired an assistant who has access to everything: your servers, your logs, your passwords, your source code. Now imagine a total stranger, from a completely unrelated company, could silently listen to every conversation that assistant has,” Enclave researcher Yanir Tsarimi wrote. “That’s what we found in Azure SRE Agent.”
Microsoft has since fixed the issue, the blog added. The fix was applied server-side, and Microsoft’s advisory states that no customer action is required. Azure SRE Agent reached general availability on March 10.
Multi-tenant by default
The agent streams all activity through a WebSocket endpoint called /agentHub, the blog said.
The endpoint required a token to connect, but the underlying Entra ID app registration was configured as multi-tenant, meaning any account from any Entra ID tenant could obtain a valid token that the hub would accept.
“The hub then checked: Is the token valid? Yes. Is the audience correct? Yes. It never asked: Does this caller belong to the target’s tenant? Are they authorized to use this agent? Do they have any role on this resource?” Tsarimi wrote.
Once connected, the hub broadcasts all events to all clients with no identity filtering, the blog said.
The exposed channel included user prompts, agent responses, internal reasoning traces, every command executed with full arguments, and the command output.
“In our own test environment, we watched the agent run a routine task and return deployment credentials for live web applications,” Tsarimi wrote. “An eavesdropper on a real target would have received the same. Silently. With nothing to indicate anyone else was on the line.”
Exploitation required only the target agent’s subdomain, which Enclave described as predictable and enumerable, and roughly 15 lines of Python. Third-party trackers identified the affected component as the Azure SRE Agent Gateway SignalR Hub.
Watching a privileged operator think out loud
The category of flaw should not be compared too closely to a conventional API bug, said Alexander Hagenah, cybersecurity researcher and executive director at Zurich-based financial infrastructure operator SIX Group.
“A normal API issue is usually bound by a specific endpoint, dataset, or permission check. With an AI operations agent, the agent itself becomes the aggregation point for infrastructure state, logs, source code, incident context, commands, outputs, and sometimes credentials that appear during troubleshooting,” Hagenah said.
“In practical terms, it can look like watching a privileged operator think out loud,” he added.
The exposure does not amount to automatic infrastructure compromise, Hagenah said, but it can be more valuable than many read-only bugs. Attackers typically have to work hard after initial access to understand an environment. An SRE agent may already have that context assembled for them.
The connection also left no trace on the victim’s side, the researcher wrote. “Victim organizations had no way to detect it, no way to investigate after the fact, and no way to scope what had been exposed.”
Considerations for enterprises
Enclave, as per the blog post, noted that organizations that ran Azure SRE Agent during the preview window must treat the period as potentially exposed and review any credentials, configuration data, or sensitive information that may have passed through agent conversations or CLI outputs.
Hagenah said agentic operations services need to be governed more like privileged automation platforms than ordinary SaaS tools.
“Before granting that level of access, I would want very clear answers on tenant isolation and resource-level authorization. It should not be enough that a token is valid. The service has to verify that the caller belongs to the right tenant, is authorized for that specific agent, and is allowed to access that specific stream, thread, tool output, or action,” he said.
The agent should run under a dedicated managed identity with minimal permissions, and integrations with command execution, log query, source repositories, and incident platforms should be reviewed like any other privileged system, Hagenah said. Enterprises also need to know who connected, what threads they accessed, what commands ran, and what output was returned, with logs exportable to the SIEM. Microsoft did not immediately respond to a request for comment.
View the full article
Security researchers have revealed a prompt injection flaw in Google’s Antigravity IDE that could be weaponized to bypass its sandbox protections and achieve remote code execution (RCE).
The issue came from Antigravity’s ability to allow AI agents to invoke native functions, like searching files, on behalf of the user. Designed to kill complexity, the feature could allow attackers to inject malicious input into a tool parameter.
According to Pillar Security researchers, the vulnerability could bypass Antigravity’s “most restrictive security configuration,” Secure Mode.
The flaw was reported to Google in January, which acknowledged and fixed the issue internally, awarding Pillar Security a bounty through its Vulnerability Reward Program (VRP) for AI-specific categories. Google did not immediately respond to CSO’s request for comments.
File search could be turned into code execution
Pillar’s prompt injection vector relied on Antigravity’s “find_my_name” tool and an “fd” utility within. find_my_name is one of Antigravity’s built-in agent tools that allows the AI to search for files and directories in the project workspace using the fd command line.
What was happening is that any string beginning with “-” was being interpreted by fd as a flag rather than a search pattern, allowing execution of binaries within files matching a “-Xsh” pattern. “The technique exploits insufficient input sanitization of the find_by_name tool’s Pattern parameter, allowing attackers to inject command-line flags into the underlying fd utility, converting a file search operation into arbitrary code execution,” the researchers said in a blog post.
Essentially, instead of just locating files, “fd” could be tricked into executing attacker-supplied binaries across those files using a crafted prompt that manipulates the “Pattern” parameter. The researchers demonstrated this by creating a file in the local directory with the malicious prompt to exploit the “pattern” injected. Antigravity picked up the file, ran its intended tasks (like launching Calculator), and also launched the search tool, now primed to execute “-Xsh” patterns.
This could also be turned into remote code execution via indirect prompt injection. “A user pulls a benign-looking source file from an untrusted origin, such as a public repository, containing attacker-controlled comments that instruct the agent to stage and trigger the exploit,” the researchers explained.
The worst part was that it was unstoppable with the existing protection.
Google’s sandbox never got a chance
Antigravity’s Secure Mode, which is designed to restrict network access, prevent out-of-workspace writes, and ensure all command operations run strictly under a sandbox context, could not flag or quarantine this technique. This is because the find_my_name tool is called much before Secure Mode restrictions are evaluated.
“The agent treats it as a native tool invocation, not a shell command, so it never reaches the security boundary that Secure Mode enforces,“ the researchers noted.
The issue was trimmed down to a twofold root cause. A “No input validation” at the Pattern parameter, which accepts arbitrary strings without checking for legitimate search pattern characters. The second was “no argument termination,” which refers to fd’s inability to distinguish between flags and search terms. Google has already fixed the flaw internally, and Antigravity users need not do anything else to remain protected. However, the flaw’s ability to bypass Secure Mode, Pillar researchers point out, underlines that security controls focused on shell commands are insufficient. “The industry must move beyond sanitization-based controls toward execution isolation,” they said. “Every native tool parameter that reaches a shell command is a potential injection point.”
View the full article
The following is the list of F5 Distributed Cloud Services technical knowledge updates:
Data Residency and Processing
Updated the Data Residency and Processing Reference guide. Modified section "F5 Distributed Cloud L7 DDoS, WAF, API Protection, CDN and App Connect" and added new section "F5 Distributed Cloud L3/L4 DDoS".
IP Addresses and Domains
Updated the F5 Distributed Cloud Services IP Address and Domain Reference for Firewall or Proxy Settings guide. Added India IP addresses for the Global Log Receiver service.
View the full article
Security teams have invested in automation for years, but automation alone has not solved the operational bottlenecks inside the SOC. The next shift is not simply more playbooks. In this blog, we look at how the SOC is moving from automation to autonomy, what that change actually means, and why agentic SOC models are emerging as the next operating model for modern security operations.
View the full article
The cybersecurity industry has spent the last several years chasing sophisticated threats like zero-days, supply chain compromises, and AI-generated exploits. However, the most reliable entry point for attackers still hasn't changed: stolen credentials. Identity-based attacks remain a dominant initial access vector in breaches today. Attackers obtain valid credentials through credential stuffingView the full article
Apple on Monday announced that CEO Tim Cook is stepping down as the company's chief executive officer, with hardware engineering chief John Ternus set to take the helm. In a new Bloomberg report, reporter Mark Gurman suggests one of the reasons Ternus has been chosen as successor is for his decision-making style, which is said to be closer to co-founder Steve Jobs than Cook, who has a more deliberative approach.


From the report:
Earlier this month, Ternus reportedly reorganized the hardware engineering division around a new AI platform designed to speed up product development and improve device quality. Ternus is said to be keen to deploy AI quickly throughout Apple to improve its operations, suggesting he is willing to make clear calls and shake things up where necessary. Ternus has also told employees he will remain closely involved in hardware engineering development, indicating a sharper focus on products.

He is also reportedly ready to push back when it matters – Ternus apparently opposed development of the Vision Pro, which has flopped, as well as the company's autonomous car project that cost around $10 billion, but was ultimately scrapped.

Cook will hand over the reins to Ternus on September 1, in time for him to oversee the launch of the iPhone 18 Pro models as well as the company's first foldable iPhone later the same month. Cook will continue to advise Apple in a new role as executive chairman.Tag: Bloomberg
This article, "Report: Ternus to Bring Jobs-Era Decisiveness Back to Apple" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Cybersecurity researchers have discovered a new iteration of an Android malware family calledNGate that has been found to abuse a legitimate application called HandyPay instead of NFCGate. "The threat actors took the app, which is used to relay NFC data, and patched it with malicious code that appears to have been AI-generated," ESET security researcher Lukáš Štefanko said in a reportView the full article
Cybersecurity researchers have discovered a vulnerability in Google's agentic integrated development environment (IDE), Antigravity, that could be exploited to achieve code execution. The flaw, since patched, combines Antigravity's permitted file-creation capabilities with an insufficient input sanitization in Antigravity's native file-searching tool, find_by_name, to bypass the program's StrictView the full article
Identity centric technologies have undergone a significant transformation in recent times. Gone are the days when it was all about logging in and out of any given system. Today, identity has become the backbone of all digital enterprises. It’s the ‘invisible engine’ that powers everything. From security to how modern-day products are sold.
Today’s Identity based frameworks not only controls who can access what, how and when, they also help businesses work efficiently, improves customer satisfaction and reduces fraud and risk, especially associated with back-office jobs.
In this article, we’ll look at why identity is key and how it supports several key aspects of digital transformation.
Identity is the new security boundary
Traditionally, enterprises used firewalls and internal network policies to protect themselves against any external attacks. If you were inside the company network, then trust was automatically granted. If you were not, you were perceived as a threat.
That world no longer exists. Because, unlike in the past, companies have employees working from different geographic locations or work from home. Most systems are hosted in the cloud. Customers can access services from mobile devices. And even programs and bots require access to the system.
This means that identity is the new perimeter. And traditional methods of securing systems won’t work anymore, as there’s no clear definition of who is ‘inside’ or ‘outside’ the perimeter anymore.
Instead of relying on location to grant access, verification is performed on the person or system making the request, and subsequently authorization checks are performed to allow the requested action.
Managing user access is not easy at an enterprise scale. And it doesn’t get any easier for those using complicated network rules and manual setups. In fact, it often results in errors and delays. This is where identity-based solutions come into play.
When someone from any team logs in, the identity system will accurately pinpoint:
Who they are and what they are up to. The project they are working on. Which environment should they use? Using this information, the system can determine which resource someone needs, when they need it and how to use it. The principle behind it is ‘never trust, always verify’. With it, errors that normally occur are reduced, less manual configuration is required and overall efficiency and accountability increase.
When something goes haywire, it becomes easy for the enterprise to track which resource was accessed by whom and when. This helps teams move faster without losing control.
How identity helps software teams work faster
Software is usually managed in various stages during its creation. To do this effectively, companies have different test environments, such as:
Development Testing Staging Performance testing For all these environments, we’ve got different teams working simultaneously on the same software. For example, when development teams are working on building new features for the software, business users would be validating the beta version in the parallel testing environment. Modern Identity structure easily carries this context in the message and helps route transactions to the appropriate environment.
Identity helps to control exactly what people can see and do
Every organization has its own hierarchical structure. Within it, everyone has limitation to what they can access or see. For instance, a junior officer cannot have the same privileges as a manager. Similarly, a manager cannot have the same authorization as the CEO. If everyone had the same access, it would create a serious security risk.
This is where modern identity systems shine. It stores information about users based on department, job description, location, level of responsibility and whether the user has special permissions. When logging in, this information travels with them. The application uses this to determine which information to disclose and which to restrict.
Put simply, some users see certain menu options while others using the same system can’t see them at all. Similarly, others might have the ability to read and write data, while others can only view it. This is what is known as fine-grained access control, where access is given to users when they truly need it.
Some of its benefits are:
Enhanced security against internal misuse of data. Reduced data leaks. Makes it easy to comply with data protection laws. Auditing and filing of reports are simplified. Beyond security: Identity powers customer personalization
Identity goes beyond just managing employee access. It helps the business grow as it manages crucial customer profile information such as preferences, purchase history, product interest and consent for data use.
The data collected is used to market personalized products, send relevant offers, show content based on previous browsing history and even communicate in their customer’s preferred language.
Before customer identity management systems, all this information was scattered across different systems. One database could handle emails, another purchase history and another might track website visits.
With unified identity management, all this information is summarized under one customer. This translates to better customer experience, higher conversion rates, increased customer loyalty and better marketing.
Plus, when customers see how their data is being handled, they are more likely to trust the brand and give permissions for their data to be used.
Identity reduces risk and prevents fraud in finance
This is where identity is needed the most because financial institutions, such as banks, deal with sensitive information and large amounts of money. Any slight error in processing data could easily incur huge losses and serious repercussions to the institution.
In many cases, most customers usually have multiple accounts:
Savings account Credit card Mortgage Investment account Business account All these accounts usually exist in different systems. With centralized identity systems, they can all be linked using a single identifier and traced back to one verified customer.
This creates a complete financial picture of the customer.
Better risk assessment
With a clear picture, banks can make informed decisions, which in the long run helps reduce losses. We’re talking about smarter lending decisions, better assessment of risks, income and debt, repayment history, just to mention a few.
Stronger fraud detection
For any business to stand a chance against sophisticated modern cyberattacks like fraud, early detection is key. With AI-based identity security, detection takes place in real time. So, when someone makes a transaction, the system cross-checks with information such as login location, device type, behavioral patterns and transaction history.
If an issue arises during this time, the system can either request extra verification or block the transaction entirely.
Detecting fake identities
Criminals today are evolving almost at the same pace as technology. To avoid detection, some of them create fake identities by mixing real and false information. Without strong security measures in place, most of them usually get away with it.
To prevent this, identity systems based on vast information collected can be able to tell what ‘normal’ looks like for each customer and what doesn’t make sense. For example, when one personal number is linked to multiple unrelated accounts.
Building identity as core infrastructure
To support the areas this article talked about, it’s crystal clear that organizations can’t just treat identity as an old-fashioned list of names. It must be woven within the very foundation of the business.
Here are three golden rules to make that happen:
1. It must be ‘real time’
The system should always share updates whenever they occur. For example, when a user logs in or changes their privacy settings, the information should be propagated throughout the entire system so that other parts of the company can react.
2. It must be easy to integrate with other systems
They should be like plug-and-play tools that allow developers to easily connect with others without necessarily needing any assistance from a specialist.
3. It must be built for governance
Not everyone needs to have unlimited access to the system. Each organization needs to have a clear set of rules on who gets access to what and when. On top of that, these permissions need to be reviewed from time to time, and all the activities tracked.
This not only ensures the company stays safe but also complies with the law.
Identity is the foundation of modern business
Time and time again, most people often associate digital transformation with advanced new technology. But it’s not just about that. It involves connecting systems, data and the people using these resources smartly and securely.
Identity makes this possible. It ensures that only the right users access the right resources at the right time. With identity, software developers are creating and deploying applications much faster, organizations get to control access to sensitive information, businesses can create personalized customer experiences and banks can detect and manage fraud right before it occurs.
Therefore, as more businesses continue their migration towards digital transformation, identity needs to be established as the foundation. Those who do this are better positioned to grow, innovate and compete in this digital age.
This article is published as part of the Foundry Expert Contributor Network.
Want to join?
View the full article
Apple is unlikely to add a 200-megapixel telephoto camera to the iPhone before 2028, despite having already tested such a sensor in prototypes, according to leaker Digital Chat Station.


In a post today shared on China's Weibo social platform, the leaker said Apple has evaluated a 200-megapixel sensor for a periscope-type camera, but adoption remains at least a couple of years away.

The leaker did not give a reason for the time frame, but they have previously referred to Apple's continuing focus on improving optical flexibility and low-light performance, rather than a jump in raw resolution. This year's iPhone 18 Pro is expected to feature a 48-megapixel main camera with a variable aperture, alongside a 48-megapixel telephoto camera featuring a longer focal length and a larger aperture.

Digital Chat Station's latest post reflects a shift in position. In March, they said a 200-megapixel sensor could potentially ship in an iPhone as soon as next year, but the supply chain evidence no longer appears to support this claim.

Back in January, Morgan Stanley reported that Apple is working to bring a 200-megapixel camera to the iPhone as soon as 2028, so the two independent sources are now more closely aligned on the matter.

Samsung introduced a 200-megapixel rear camera on its Galaxy S23 Ultra in 2023, and the follow-up models also have one. With a 200-megapixel camera, an iPhone would be able to shoot photos with greater detail. The increased megapixel count would also result in higher-resolution photos, which can be cropped further and printed at larger sizes without a loss of image quality.

Digital Chat Station has a large following on Chinese social media platform Weibo, and the account has previously shared accurate information about Apple's future products.Tag: Digital Chat Station
This article, "200MP Telephoto iPhone Lens Unlikely to Arrive Before 2028" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Much of the talk around cybersecurity these days revolves around AI and the threat it poses to corporate systems when used by nefarious actors.
But the reality on the ground remains a little more mundane than polymorphic AI malware and criminal masterminds putting machine learning and generative AI to work at scale.
Still, keeping on top of even minor nuances and emerging trends in the techniques cyberattackers are deploying of late can greatly help cyber defenders in their task.
Of note is the fact that attackers are increasingly exploiting identity as a preferred method for infiltrating systems.
While exploiting vulnerabilities also remains an important vector with its own emerging subtleties in practice, phishing, stolen credentials, and social engineering are among the more common root causes of initial attack today, according to threat response experts.
“Identity-related attack techniques such as phishing (41%), stolen credentials (18%), and social engineering (12%) dominating our incident response engagements,” Alexandra Rose, director at the Counter Threat Unit at Sophos, tells CSO.
Rose adds: “Attackers are increasingly looking to leverage weaknesses that can’t be targeted by patching — instead going after the human link in the chain: people.”
Entry points created by expanding hybrid and cloud environments, integrations with AI tooling, and new SaaS apps are also particularly attractive to threat actors, allowing them to infiltrate systems without needing to deploy traditional malware.
“Attackers [are exploiting] trusted tools, identities, and user behaviour rather than relying on technical sophistication” to mount attacks, according to threat intel vendor ReliaQuest’s latest Annual Cyber-Threat Report.
Here, cyber experts quizzed by CSO identify the most prevalent cyberattack techniques being deployed against enterprises today.
Drive-by RMM misuse
Attackers have increasingly been abusing legitimate remote monitoring and management (RMM) tools to camouflage attacks on corporate networks. Designed to help IT teams manage systems remotely, popular RMM tools, such as ConnectWise ScreenConnect, Tactical RMM, and MeshAgent, are often abused by attackers for command-and-control, lateral movement, and ransomware deployment.
Now, trojanized versions of RMM tools are being dropped directly onto hosts, often through drive-by compromise, according to ReliaQuest. ConnectWise ScreenConnect led RMM-related incidents between December 2025 up until the end of February 2026, according to the threat intel vendor.
A separate study by managed detection and response firm Blackpoint found that abuse of legitimate RMM tools represented 30% of incidents handled by the firm.
Network security device hacking
Network edge devices have increasingly drawn attackers’ attention over the past two years, establishing a new battleground where the very devices meant to protect the network have become attractive targets for exploitation.
As a result, flaws in security device, such as SSL VPN systems and other gateways, are among the top initial access vectors for attackers.
SSL VPN compromises, for example, accounted for 33% of identifiable activity, according to Blackpoint.
ClickFix
ClickFix is a social engineering tactic that aims to trick prospective marks into pasting and executing malicious PowerShell commands from fake “fix” prompts.
Because these bogus prompts come from either compromised websites or manipulated search results, the approach bypasses traditional security controls such as email filters or denylists.
ClickFix scams often uses fake CAPTCHA pages as the lure.
The methodology is most frequently used to distribute remote access trojans or infostealers, but attackers have also begun to feature ClickFix in ransomware attacks.
“ClickFix adoption continues to expand across the attacker spectrum, with ransomware operators like LeakNet now using ClickFix lures to run campaigns directly rather than purchasing access from initial access brokers,” according to ReliaQuest.
Identity-based attacks
Attackers are increasingly impersonating legitimate users, machines, or services to gain access to systems, data, or infrastructure. The technique is on the upswing in part due to improved security defenses, according to some experts, and also demonstrates attackers’ interest in targeting authentication mechanisms rather than exploiting software vulnerabilities directly.
“Endpoint detection and response technologies have pushed criminals into stealing credentials — or buying them from thieves — and then using them for authentication as account users,” says Tom Exelby, head of cybersecurity at UK-based cybersecurity services firm Red Helix. “Once they have access, they can augment their privileges through systems such as Microsoft Active Directory and Entra ID.”
Instead of stealing passwords, attackers steal active authentication tokens to bypass multi-factor authentication (MFA) protections.
Attackers are increasingly using OAuth consent phishing and reverse proxy kits to steal session tokens and bypass MFA, adds cloud-native security firm Netskope.
“Attackers targeting Microsoft 365 environments are also adopting adversary-in-the-middle attacks,” Red Helix’s Exelby adds. “They capture credentials, MFA responses, and session cookies by using phishing kits as a proxy between the target and the legitimate authentication service.”
Cybercriminals are using platforms such as the Tycoon 2FA phishing-as-a-service to run adversary-in-the-middle (AiTM) attacks. Many of the victims of this attack vector are “likely to be SMBs with limited cybersecurity resources,” according to Red Helix.
Phishing
Despite a year-over-year decline in the number of people clicking on phishing links, in part due to improved user education, this traditional form of social engineer remains a problem.
According to a recent study by Netskope, 87 out of every 10,000 users click on a phishing link each month. Microsoft remains the brand attackers impersonate most.
Remote and hybrid workforces have given attackers more opportunities for phishing and credential theft, and now the power of AI in facilitating such attacks is becoming a major concern. Cybercriminals have been putting AI to use to develop highly personalized phishing lures, automated reconnaissance, and synthetic voice and deepfake attacks.
Hacking machine identities
The rapid profileration of machine identities is proving to be a wellspring for attackers seeking inroads into corporate systems. Much of this is due to increased use of service accounts, containers, APIs, and the automation of DevOps, but agentic AI, with its promise of autonomous AI activity, is another rising source of concern for security organizations.
“With non-human identities central to infrastructure, attackers are inevitably focusing on compromise of service accounts and API identities, which give them long-lived credentials and a broad range of permissions,” says Red Helix’s Exelby.
Exelby adds: “Machine identities often have weak protection, are notoriously invisible, and poorly managed.”
Managed service providers that hold privileged access to many client’s systems have a magnetic attraction for attackers as a potential route to carry out supply chain attacks. Even a midsize business is likely to have hundreds of SaaS apps and thousands of identities criminals can exploit.
Shai-Hulud: The supply-chain attack evolves
In September 2025, credential-stealing code wormed its way through scores of npm libraries, adding a modern twist to the supply chain attack. What would become known as Shai-Hulud included self-propagation logic that would eventually spread to hundreds of packages by automatically replicating and injecting itself into projects owned by compromised maintainers.
Later versions of the npm supply-chain worm (“Shai-Hulud 2.0”) have expanded into cloud credential theft, making it the most significant new entry in ReliaQuest’s attack technique list since the previous edition last year.
“The self-replicating nature [of the malware] makes containment particularly difficult once it enters a development pipeline,” ReliaQuest warns.
Countermeasures
Defenders should prioritize ClickFix-specific user training, enforce remote monitoring and management (RMM) tool allowlists, and centralize SaaS audit logging, ReliaQuest advises.
Protection against the tide of identity-based attacks requires a shift to layered defenses.
“Layered defences should include phishing-resistant authentication with hardware security keys, FIDO2 password-free approaches or certificate-based methods to reduce credential theft and adversary-in-the-middle attacks,” says Red Helix’s Exelby.
Exelby adds: “Zero trust and least privilege access principles are essential, validating continuously using device posture, user behaviour and network context, along with risk-scoring. Time-bound access for accounts should be part of this.”
View the full article
On April 7, six US government agencies issued a critical advisory warning domestic private sector organizations of potential infrastructural cyberattacks conducted by Iranian-affiliated Advanced Persistent Threat (APT) actors. The advisory stops short of attributing these threats to a single group but makes reference to 2023 attacks on US water and wastewater facilities linked to the known Iranian APT “CyberAv3ngers”, suggesting a possible correlation between historical and current incidents.
Reports on “CyberAv3ngers” and analogous group “Handala Hack Team” — who have recently been in headlines for their numerous clashes with the FBI — emphasize that while these operations present themselves as radical pro-Palestinian hacktivist collectives, both are believed to be heavily-resourced and directly tied to the Iranian Ministry of Intelligence (MOIS).
Sometimes referred to as “fronts”, “proxy insurgents” or “ghost groups”, these presumed false flag operations represent a longstanding obfuscation tactic amongst the so-called “Big Four” of cybercrime — Russia, China, North Korea and Iran. Notably, Russia’s largest military intelligence agency, the GRU, is widely known to recruit talented threat actors to execute complex cyber campaigns against political enemies.
The Big Four are known for their pervasive assertions of soft power, otherwise known as ‘Influence Cyber Operations’ (ICOs). Each has a flagship operation in this field: Russia with disinformation campaigns, China with long-term operational technology espionage, North Korea with remote worker scams and laptop farms, and Iran with critical infrastructure disruptions.
The “gray area” of plausible deniability
Iran’s use of proxy insurgent groups follows a clear line of logic.
A radical activist organization would be expected to execute politically motivated attacks, but not on a large scale or with exceptional technical skill. In the case of a group like Handala, openly proclaiming to be pro-Iranian nationalists aligns their interests with the Iranian government, making them a perfect cover for state-backed operations. It’s a strategy that allows for symbolic retributive actions by Iran without having to reveal the extent of its tactical power, and — crucially — one that allows for attacks to continue in times of supposed peace.
This “death by a thousand cuts” approach — sometimes referred to as “soft warfare” or “gray warfare” — follows a military doctrine centered around a consistent, slow erosion of the enemy via covert operations. Obscuring the state’s involvement beneath a grandiose, pro-Iranian rhetoric allows it to affect change in the US with less chance of immediate retaliation, especially compared to an act of direct physical aggression, such as an overseas bombing on US soil.
A state of perpetual interference
To understand how proxy insurgent groups such as Handala fit within Iran’s modern-day intelligence ecosystem, we first need to look at the historical development of the country’s intelligence operations.
In 1953, the United States and Britain (via conduit operations of the CIA and MI6, respectively) instigated a coup in Iran that displaced then-Prime Minister Mohammad Mosaddegh in favor of strengthening the imperialist power of its Shah, Mohammad Reza Pahlavi. The US hoped that by bolstering Iran’s monarchical leader in exchange for underlying influence in a newly pro-Western regime, it would be able to gain access to Iran’s rich petroleum resources.
Part of this influence included the establishment and shaping of SAVAK in 1957, the first intelligence agency and secret police of the Imperial State of Iran. Despite being classed as a civilian organization, SAVAK was primarily composed of military figures whose objectives involved suppressing opposition, surveillance of threats to the monarchy and media control within Iran, often operating outside existing laws.
When the group was violently dismantled following the 1979 Iranian Revolution, its replacement MOIS — still the country’s dominant intelligence organization — borrowed significantly from its personnel, core philosophy and tactics. All current Iranian entities involved in intelligence are technically required to report to and collaborate with MOIS, including the Islamic Revolutionary Guards Corps (IRGC), which was notably created directly in response to the first Supreme Leader’s suspicions of Iran’s existing military forces.
Iran’s modern-day intelligence capabilities have ultimately formed from a mishmash of competing outfits. This includes MOIS, the Islamic Revolutionary Kumitehs, SAVAMA, the IGRC and its paramilitary force the IRGC-QF, all of which were established to support various pro-revolutionary and counterintelligence directives at the end of the 1970s and throughout the 1980s.
In short, Iran’s cyber ecosystem has been shaped by decades of political upheaval, revolutionary factioning and calculated external influence. The protective front of a “pro-revolutionary” ideology, therefore, has long been used by the Iranian state to justify acts of political violence, espionage, surveillance and subterfuge.
What do these groups actually represent?
Western perceptions of groups such as Handala Hack Team and CyberAv3ngers are likely distorted by culturally based assumptions. In the US, for example, we tend to associate terms like “insurgent” with anti-authoritarians, not government loyalists. However, historically in Iran, civilian and military intelligence enterprises have been simultaneously enmeshed and compartmentalized by design.
While there hasn’t been much discussion of the semantics in this scenario to-date, there’s no real qualifier preventing Handala from technically being considered a “radical hacktivist group” while also being a highly intentional product of the state. Whether they actually carry the values that they espouse publicly is anyone’s guess.
Think of it this way: a radical activist organization is created to fight whatever it deems as an “oppressive system”, using symbolic direct action to compensate for its lack of size. And while Iranian APT groups are well-resourced domestically, in a global arena, they are still undeniably small. When held next to cyber superpowers like the US and Israel, even Iran’s most elite task forces are microscopic by comparison.
A captive audience
Experts have noted that Handala’s social media posts often contain exaggerated, near-theatrical claims. One blog post reads: “The slightest aggression against Iran’s vital facilities will mean the beginning of a devastating reaction that will turn all these vital infrastructures to ashes.” The group makes constant, unsubstantiated threats with claims of successful breach operations that quickly fade into the ether, never to be backed with evidence.
However, to dismiss Handala’s evangelizing as laughable is missing the point — intentionally or not, Handala’s outsized assertions of its own power to retaliate against its aggressors highlight just how asymmetric the whole conflict really is. If nothing else, readers of Handala Hack’s messaging — conveniently written in English — are forced to grapple with the reality of a massive power imbalance between “us” and “them” just to figure out how safe they are allowed to feel.
Americans engaging with Handala’s threats will likely feel alarmed, with that fear quickly turning to frustration that random American businesses are being symbolically attacked on behalf of entire industries due to Iran’s limited targeting capabilities. Suddenly, the imminent specter of Iran as presented by the US begins to fall apart.
This is the true advantage of a state entity adopting a radical persona, particularly one with an air of “righteous fury” or a “bleeding heart”. Many have accused Handala of falsely claiming to be a pro-Palestinian group, but from a strategic standpoint, they are, because they are explicitly and violently anti-Israel — for a group with such radical political goals, sometimes ideology just means having a shared enemy.
Beneath their seemingly unshakeable veneer, however, it’s only becoming clearer that Handala’s words are those of a state in crisis, one which has been hampered by sanctions into near technological autarky and that is literally struggling to keep the lights on thanks to repeated sieges of its own critical infrastructures.
Lest we forget, the “world’s first cyberweapon”, Stuxnet, was created as a joint US-Israeli venture for the express purpose of destroying Iran’s nuclear program by targeting its SCADA and PLC systems. When the US warns that Iran is capable of targeting those same systems, it is merely positioning Iran as an enemy that is capable of doing to us exactly what we are to them.
Although its motivations are ultimately multilayered and complex, Handala/the Iranian state’s “goal” is likely not simple fear-mongering. It’s to cause embarrassment, eroding the public’s good faith assumptions of its leaders’ motivations in the Global East as their actions are brought to light. Given the group’s level of media coverage for its minor hacking feats, who’s to say that things aren’t going as planned?
This article is published as part of the Foundry Expert Contributor Network.
Want to join?
View the full article
Introduction
The transition from experimental machine learning to production-grade artificial intelligence is one of the most significant challenges facing modern enterprises. While data scientists excel at building models, the operationalization of those models requires a rigorous engineering approach known as MLOps. This guide explores the Certified MLOps Professional designation, a curriculum designed to bridge the gap between data science and IT operations. This roadmap is intended for engineers, architects, and technical leaders who aim to master the lifecycle of machine learning systems within cloud-native environments.
Navigating the landscape of DevOps, SRE, and platform engineering now requires a deep understanding of how data and models integrate into standard software delivery pipelines. The AIOps School provides a structured framework for professionals to validate their expertise in automating model deployment, monitoring, and governance. By following this guide, professionals can make informed decisions about their career trajectory and understand how to apply MLOps principles to solve real-world scalability and reliability issues in the enterprise.
What is the Certified MLOps Professional?
The Certified MLOps Professional program represents a standardized benchmark for engineers who need to manage the complexities of machine learning in production. Unlike theoretical courses that focus solely on model architecture, this certification emphasizes the “Ops” in MLOps, focusing on the infrastructure, automation, and monitoring necessary for sustainable AI. It exists to provide a clear, competency-based framework for professionals to prove they can handle the unique challenges of data versioning, model drift, and automated retraining.
This certification aligns with modern engineering workflows by treating machine learning assets as first-class citizens in the DevOps pipeline. It emphasizes enterprise practices such as CI/CD for ML, infrastructure as code for GPU clusters, and rigorous testing for both code and data. By focusing on production-grade outcomes, the program ensures that practitioners are prepared to move models from a researcher’s notebook into a scalable, resilient, and observable production environment that meets business requirements.
Who Should Pursue Certified MLOps Professional?
This certification is designed for a broad spectrum of technical professionals who sit at the intersection of development and operations. Software engineers looking to specialize in the high-growth field of AI infrastructure will find the curriculum particularly beneficial. Site Reliability Engineers (SREs) and Cloud Architects who are tasked with maintaining the uptime and performance of ML-driven applications will gain the specific specialized knowledge required to manage non-deterministic systems and heavy compute workloads.
The program also caters to data engineers who need to build robust pipelines and security professionals who must audit ML systems for compliance and vulnerability. For engineering managers and technical leaders in India and across the global market, this certification provides the conceptual foundation needed to lead cross-functional teams effectively. Whether you are a beginner looking to enter the field or an experienced professional aiming to formalize your skills, this certification offers a path toward mastering the operational side of artificial intelligence.
Why Certified MLOps Professional is Valuable Today and Beyond
In the current technological landscape, the demand for MLOps expertise is outpacing the supply of qualified engineers. As enterprises move beyond basic AI experimentation, they require professionals who can ensure that models remain accurate, secure, and cost-effective over time. The Certified MLOps Professional program provides the longevity needed for a career in this space by teaching fundamental principles that remain relevant even as specific tools and frameworks evolve.
The value of this certification lies in its focus on the return on time and career investment. By mastering the ability to automate the ML lifecycle, professionals can significantly reduce the “technical debt” often associated with manual model deployments. This expertise ensures that an individual remains a critical asset to any organization seeking to implement AI at scale. As enterprise adoption of AI continues to grow, having a validated skill set in MLOps will be a key differentiator in the competitive global job market.
Certified MLOps Professional Certification Overview
The program is delivered via the official portal at Certified MLOps Professional and is hosted on the AIOps School platform. This certification is structured to provide a comprehensive evaluation of a candidate’s ability to design, implement, and manage MLOps workflows. The assessment approach is practical, often involving hands-on scenarios that reflect the actual challenges faced by MLOps teams in industry settings.
Ownership of the certification rests with a body of experts who ensure the content is updated to reflect the latest industry trends and best practices. The structure is broken down into modular components, covering everything from data engineering and model training automation to deployment strategies and post-deployment monitoring. This practical orientation ensures that the certification is not just a theoretical credential but a reflection of an engineer’s ability to deliver tangible results in a production environment.
Certified MLOps Professional Certification Tracks & Levels
The certification is organized into three distinct levels to accommodate various stages of professional growth. The Foundation level focuses on the core concepts of MLOps, introducing candidates to the vocabulary, basic tools, and the overarching philosophy of combining data science with DevOps. This level is ideal for those new to the field or managers who need a high-level understanding of the ML lifecycle without getting bogged down in implementation details.
The Professional level is where the technical deep dive occurs, focusing on implementation, pipeline construction, and automation. This level is targeted at active practitioners who are responsible for building and maintaining MLOps systems. Finally, the Advanced level focuses on architecture, strategy, and complex problem-solving at the enterprise scale. These levels are designed to align with a natural career progression, allowing a professional to grow from a foundational contributor to a senior architect or technical lead.
Complete Certified MLOps Professional Certification Table
TrackLevelWho it’s forPrerequisitesSkills CoveredRecommended OrderMLOps CoreFoundationBeginners, ManagersBasic IT knowledgeMLOps Lifecycle, ToolsFirstMLOps EngineeringProfessionalDevOps, Data EngineersLinux, Python, CI/CDPipeline Automation, MonitoringSecondMLOps ArchitectureAdvancedSenior Engineers, LeadsProfessional CertScaling, Governance, StrategyThirdSpecialized DataOpsProfessionalData EngineersData SQL, ETLData Versioning, Feature StoresOptionalSpecialized AIOpsProfessionalSREs, IT OpsMonitoring knowledgeAI for IT Operations, AnalyticsOptional Detailed Guide for Each Certified MLOps Professional Certification
Certified MLOps Professional – Foundation
What it is
This certification validates a candidate’s understanding of the fundamental principles of MLOps. It confirms that the individual understands the differences between traditional DevOps and MLOps and can identify the core components of a machine learning pipeline.
Who should take it
This is suitable for junior engineers, product managers, and data scientists who want to understand how their models are deployed. It is also an excellent entry point for IT professionals transitioning from traditional software backgrounds.
Skills you’ll gain
Understanding the MLOps maturity model. Identifying key roles and responsibilities in an MLOps team. Familiarity with common MLOps tools and cloud services. Knowledge of the end-to-end ML lifecycle from data ingestion to monitoring. Real-world projects you should be able to do
Create a conceptual design for a basic ML pipeline. Document the requirements for an MLOps environment. Conduct a gap analysis of an existing ML workflow. Preparation plan
7–14 days: Review the official glossary and watch introductory videos on MLOps concepts. 30 days: Complete the foundational modules on the platform and take practice quizzes. 60 days: Deeply study the integration points between data science and operations through case studies. Common mistakes
Focusing too much on specific machine learning algorithms instead of the operational workflow. Underestimating the importance of data management in the MLOps process. Best next certification after this
Same-track option: Certified MLOps Professional – Professional Level Cross-track option: Cloud Practitioner or DevOps Foundation Leadership option: Project Management Professional (PMP) Certified MLOps Professional – Professional
What it is
This certification validates the technical ability to implement and manage MLOps pipelines. It covers the hands-on aspects of automation, containerization, and orchestration specifically tailored for machine learning workloads.
Who should take it
This is intended for DevOps engineers, data engineers, and SREs who are actively working on or moving into MLOps roles. A working knowledge of Python and container technologies like Docker is highly recommended.
Skills you’ll gain
Building CI/CD pipelines for machine learning models. Implementing model versioning and data lineage. Deploying models using Kubernetes and serverless architectures. Setting up automated monitoring for model performance and data drift. Real-world projects you should be able to do
Automate the retraining of a model based on performance triggers. Build a scalable feature store for high-throughput model inference. Implement an A/B testing framework for model deployment in production. Preparation plan
7–14 days: Set up a lab environment with Docker and a CI/CD tool like Jenkins or GitLab. 30 days: Complete hands-on labs focusing on model deployment and monitoring tools. 60 days: Build a full end-to-end pipeline using a cloud provider (AWS, Azure, or GCP). Common mistakes
Ignoring security practices during the model deployment phase. Failing to implement robust logging and observability for ML components. Best next certification after this
Same-track option: Certified MLOps Professional – Advanced Level Cross-track option: Certified Kubernetes Administrator (CKA) Leadership option: Technical Lead or Architect training Choose Your Learning Path
DevOps Path
The DevOps path focuses on integrating machine learning into existing software delivery frameworks. Engineers on this path will learn how to extend traditional CI/CD pipelines to handle model artifacts and data dependencies. The goal is to treat ML as just another part of the software ecosystem while respecting its unique requirements for compute and data. This path is ideal for those who want to bridge the gap between application development and data science production.
DevSecOps Path
The DevSecOps path emphasizes the security and compliance aspects of machine learning operations. It involves learning how to secure data pipelines, protect model endpoints from adversarial attacks, and ensure data privacy throughout the lifecycle. Professionals will focus on automating security scans for ML code and auditing the provenance of training data. This path is critical for highly regulated industries such as finance and healthcare where model integrity is paramount.
SRE Path
The SRE path for MLOps centers on the reliability and scalability of machine learning systems. It applies Site Reliability Engineering principles—such as Error Budgets and Service Level Objectives—to the specific world of AI. Engineers learn how to manage the infrastructure that supports large-scale model inference and how to automate the recovery of failed ML services. This path is suited for those who enjoy troubleshooting complex distributed systems and optimizing performance.
AIOps Path
The AIOps path focuses on using artificial intelligence and machine learning to improve IT operations themselves. Professionals on this track learn how to implement algorithms that detect anomalies in system logs, predict outages before they occur, and automate the resolution of common IT tickets. This is a distinct field from MLOps, as it uses AI as a tool for the operations team rather than focusing on the deployment of business models. It is highly valuable for large-scale enterprise infrastructure management.
MLOps Path
The MLOps path is the primary technical route for those dedicated to the machine learning lifecycle. It covers the technical depths of model orchestration, experiment tracking, and automated model governance. Engineers focus on tools like Kubeflow, MLflow, and specialized feature stores to create a seamless flow from the data scientist’s workspace to the production environment. This path provides the most comprehensive coverage of the Certified MLOps Professional curriculum.
DataOps Path
The DataOps path concentrates on the health and flow of data that feeds machine learning models. Without high-quality, reliable data, MLOps cannot succeed. This path teaches engineers how to apply DevOps principles to data pipelines, focusing on data quality testing, versioning, and automated ETL processes. It is the perfect path for data engineers who want to ensure that the foundation of their ML systems is robust and scalable.
FinOps Path
The FinOps path focuses on the financial management and optimization of machine learning workloads. Because ML can consume vast amounts of expensive GPU and TPU resources, managing costs is a vital skill. Professionals learn how to attribute costs to specific models, optimize resource utilization, and implement automated scaling to keep cloud bills under control. This path is essential for organizations looking to scale their AI initiatives sustainably and profitably.
Role → Recommended Certified MLOps Professional Certifications
RoleRecommended CertificationsDevOps EngineerCertified MLOps Professional (Professional), CKASRECertified MLOps Professional (Professional), SRE FoundationPlatform EngineerCertified MLOps Professional (Advanced), Terraform AssociateCloud EngineerCertified MLOps Professional (Professional), Cloud ArchitectSecurity EngineerCertified MLOps Professional (Foundation), DevSecOps ProfessionalData EngineerCertified MLOps Professional (Professional), DataOps ProfessionalFinOps PractitionerCertified MLOps Professional (Foundation), FinOps CertifiedEngineering ManagerCertified MLOps Professional (Foundation), Leadership Training Next Certifications to Take After Certified MLOps Professional
Same Track Progression
Once you have achieved the professional level of the Certified MLOps Professional, the natural progression is toward the Advanced or Expert levels. This involves deep specialization in niche areas such as distributed training at scale or specialized hardware acceleration. Staying within the track allows you to become a recognized subject matter expert in the field, making you a prime candidate for principal engineering or architectural roles within large-scale AI organizations.
Cross-Track Expansion
For those looking to broaden their skill set, expanding into adjacent tracks like DataOps or DevSecOps is highly recommended. Understanding the security implications of ML or the intricacies of data pipeline management makes you a more versatile and valuable engineer. This cross-pollination of skills allows you to handle a wider variety of project challenges and effectively communicate across different technical teams, which is essential for senior-level career growth.
Leadership & Management Track
If you are interested in moving into leadership, transitioning toward management certifications or strategic architecture programs is the logical step. A leader with a Certified MLOps Professional background is uniquely positioned to guide organizations through the complexities of AI transformation. This path focuses on team building, budget management, and aligning technical AI capabilities with business goals, ensuring that the technology delivers actual value to the enterprise.
Training & Certification Support Providers for Certified MLOps Professional
DevOpsSchool is a leading platform that provides comprehensive training programs for a wide range of engineering certifications. They offer hands-on labs and instructor-led sessions that help professionals master the technical requirements of the Certified MLOps Professional program. Their curriculum is designed by industry experts who bring real-world scenarios into the classroom, ensuring that students gain practical knowledge that can be applied immediately in their jobs. They have a strong presence in the Indian market and offer flexible learning schedules.
Cotocus specializes in high-end technical training and consulting, focusing on cloud-native technologies and MLOps. They provide personalized mentoring and intensive bootcamps designed to help engineers clear professional certifications. Their approach emphasizes deep technical understanding and the ability to solve complex architectural problems. For those pursuing the Certified MLOps Professional, Cotocus offers specialized modules that cover advanced automation and infrastructure management, making them a preferred choice for senior professionals seeking to upgrade their skills.
Scmgalaxy is a community-driven platform that offers an extensive library of resources, tutorials, and training for DevOps and MLOps. They focus on the practical implementation of tools like Git, Jenkins, and Kubernetes within the machine learning lifecycle. For candidates of the Certified MLOps Professional, Scmgalaxy provides a wealth of community support and practice materials that are invaluable for exam preparation. Their content is known for being straightforward and highly relevant to the daily tasks of an automation engineer.
BestDevOps provides targeted training for professionals looking to excel in the operations space. They offer structured courses that guide students through the complexities of modern software delivery and machine learning operations. Their training methodology for the Certified MLOps Professional focuses on the integration of various tools into a cohesive pipeline. They provide a supportive learning environment with access to experienced mentors who help clarify difficult concepts and provide career guidance for those entering the MLOps field.
devsecopsschool.com is the go-to resource for engineers who want to integrate security into their MLOps workflows. They offer specialized training that aligns with the Certified MLOps Professional program, with a heavy emphasis on the DevSecOps path. Their courses cover essential topics like model security, data privacy compliance, and automated security testing. For professionals who want to ensure their machine learning systems are not only efficient but also secure, this platform provides the specialized knowledge required to achieve that goal.
sreschool.com focuses on the principles of reliability and performance, which are critical for successful MLOps implementation. They provide training that helps engineers apply SRE practices to machine learning systems, ensuring high availability and optimal resource usage. Their curriculum supports the Certified MLOps Professional by teaching candidates how to manage large-scale ML infrastructure and automate incident response. This is an excellent resource for SREs looking to pivot into the world of AI operations.
aiopsschool.com is the primary hosting and delivery partner for the Certified MLOps Professional program. They offer the most direct and comprehensive path to achieving the certification, with a curriculum that is specifically designed to meet the program’s requirements. Their platform provides a seamless learning experience, from foundational courses to advanced architectural modules. By training directly with the hosting site, professionals can ensure they are getting the most up-to-date and relevant information for their certification journey.
dataopsschool.com provides specialized training for data engineers and professionals focused on the data lifecycle within MLOps. Their courses emphasize the importance of data quality, versioning, and pipeline automation. For those pursuing the Certified MLOps Professional, dataopsschool.com offers the deep dive into data management that is often missing from more general courses. Their training ensures that the data feeding the machine learning models is reliable, clean, and well-governed, which is the foundation of any successful ML project.
finopsschool.com addresses the critical need for cost management in cloud-based machine learning operations. They provide training on how to optimize GPU spend and manage the financial impact of large-scale AI initiatives. Their curriculum is highly relevant for professionals taking the Certified MLOps Professional who need to demonstrate fiscal responsibility and resource efficiency. By learning FinOps principles, engineers can ensure that their MLOps strategies are not only technically sound but also financially sustainable for their organizations.
Frequently Asked Questions (General)
What is the typical difficulty level of the Certified MLOps Professional exam?
The exam is considered moderate to challenging because it requires both a conceptual understanding of MLOps and practical knowledge of engineering tools like Docker, Kubernetes, and CI/CD platforms. How much time does it usually take to prepare for this certification?
For an experienced DevOps engineer, 30 to 45 days of focused study is usually sufficient. Beginners or those transitioning from other fields may require 60 to 90 days to master the prerequisites and core concepts. Are there any mandatory prerequisites before taking the Professional level exam?
While there are no strict official prerequisites, it is highly recommended to have a basic understanding of Python, Linux command line, and general DevOps principles before attempting the Professional level. What is the return on investment for the Certified MLOps Professional?
The ROI is significant, as MLOps professionals often command higher salaries than general DevOps engineers. It also opens doors to specialized roles in high-growth companies building AI products. In what order should I take the certifications if I want to be an architect?
The recommended order is Foundation, followed by Professional, then a specialization like DataOps, and finally the Advanced MLOps Architecture level. Does this certification focus on a specific cloud provider like AWS or Azure?
The certification is designed to be cloud-agnostic, focusing on principles and tools that can be applied across any major cloud provider or on-premises environment. How long is the certification valid for?
The certification is typically valid for two to three years, after which professionals are encouraged to recertify to stay updated with the latest industry changes and tool versions. Is there a hands-on component to the assessment?
Yes, the Professional and Advanced levels often include practical scenarios or lab-based assessments to ensure candidates can apply their knowledge in real-world situations. Can a data scientist benefit from this certification?
Absolutely. It helps data scientists understand the operational constraints of their models, leading to better collaboration with engineering teams and more successful deployments. Are there group discounts available for corporate teams?
Many training providers associated with the program offer corporate packages and group discounts for teams looking to upskill their entire engineering department. Does the certification cover the ethical aspects of AI and machine learning?
Yes, the curriculum includes modules on model governance, bias detection, and ethical considerations, which are increasingly important for enterprise compliance. How does this certification compare to general DevOps certifications?
While general DevOps certs focus on application lifecycles, this certification specifically addresses the unique challenges of data versioning, model retraining, and non-deterministic software behavior. FAQs on Certified MLOps Professional
Why is the Certified MLOps Professional important for engineers in India?
India is a global hub for IT services and product development. As more global companies move their AI operations to India, having a recognized MLOps credential becomes a vital competitive advantage for local engineers. Does this program cover specific MLOps tools like Kubeflow or MLflow?
Yes, the curriculum introduces these industry-standard tools and explains how they fit into the broader MLOps ecosystem for experiment tracking and model orchestration. How much coding is required to pass the Professional level?
A proficient understanding of Python is necessary, particularly for writing automation scripts, managing data pipelines, and interacting with various MLOps tool APIs. Can I take the exam online, or do I need to go to a testing center?
The certification is designed to be accessible globally, with online proctored exam options available through the official hosting platform. Does the certification teach you how to build machine learning models?
The focus is on the operationalization of models rather than model development. While you will learn the basics of the ML process, the emphasis is on deployment, monitoring, and scaling. Is there a focus on large language models (LLMs) in this certification?
The newer modules of the program address the specific operational challenges of LLMs, such as fine-tuning pipelines and managing vector databases. What kind of career support is provided after certification?
Many of the associated training providers offer job assistance, resume building, and access to a network of hiring partners looking for MLOps talent. How often is the Certified MLOps Professional curriculum updated?
The curriculum is reviewed annually by a panel of industry experts to ensure it reflects the most current practices and tools used in production environments. Final Thoughts: Is Certified MLOps Professional Worth It?
As a mentor who has seen the evolution of the industry from physical servers to cloud-native AI, my advice is straightforward: MLOps is not a trend; it is the inevitable maturity of the software engineering discipline. The Certified MLOps Professional program provides a structured and credible way to gain the skills that the market is currently desperate for. It moves you beyond the hype of AI and gives you the tools to build systems that actually work, scale, and provide value over the long term.
If you are an engineer looking to future-proof your career, this is a solid investment. It requires effort and a willingness to learn both the data and the operations side of the house, but the career impact is undeniable. There is no sales pitch here—just the reality that as AI becomes integrated into every piece of software, the people who know how to keep those systems running reliably will be the most valuable people in the room. This certification is a practical step toward becoming one of those professionals.
View the full article
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added eight new vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, including three flaws impacting Cisco Catalyst SD-WAN Manager, citing evidence of active exploitation. The list of vulnerabilities is as follows - CVE-2023-27351 (CVSS score: 8.2) - An improper authentication vulnerability in PaperCutView the full article
Current Apple CEO Tim Cook is set to leave his role on September 1, 2026, and as he prepares to step down as CEO, he has written a letter addressed to the Apple community.


Cook said that he starts his day reading notes from Apple users all over the world, which fills him with an indescribable gratitude. According to Cook, Ternus is the perfect person to take over as Apple's CEO.

Cook will remain on as Apple CEO until September 1, 2026, which is when John Ternus will take over. After Ternus assumes the role of CEO, Cook will continue to advise Apple in his role as board chairman.Tags: John Ternus, Tim Cook
This article, "Apple's Tim Cook Shares Community Letter After Announcing Plans to Step Down as CEO" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Apple's Senior Vice President of Hardware Technologies Johny Srouji is set to take on an expanded role as Apple's Chief Hardware Officer as John Ternus transitions to his role as Apple's next CEO.


Srouji is going to lead Hardware Engineering, reporting to Ternus. Current Apple CEO Tim Cook said that Srouji has been pivotal in Apple's transition to Apple silicon.

Srouji is well-known as Apple's chip lead, and he has overseen the development of Apple silicon chips for the Mac. Apple's hardware engineering team is responsible for all of Apple's hardware products, and Srouji will lead everything from product design to system engineering to reliability and durability testing.
This article, "Johny Srouji Taking Over as Apple's Chief Hardware Officer as John Ternus Transitions to CEO" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Apple CEO Tim Cook is stepping down as Apple's chief executive officer, and hardware engineering chief John Ternus is set to take over, Apple announced today.


Cook will continue on as Apple CEO through the summer, with Ternus set to join Apple's Board of Directors and take over as CEO on September 1, 2026. Cook is going to keep his role as chairman of the board at Apple, and he will "assist with certain aspects of the company, including engaging with policymakers around the world."

In a statement, Cook said that his time as Apple's CEO has been the "greatest privilege" of his life.

Ternus said that he is optimistic about what Apple can achieve in the years to come.

Apple says that the transition was approved by the Board of Directors and is the result of a "thoughtful, long-term succession planning process."Tag: Tim Cook
This article, "Apple CEO Tim Cook Stepping Down, John Ternus Taking Over" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Apple is finally planning to release The Savant, an Apple TV series that it delayed following the assassination of Charlie Kirk.


The Savant is set to air in July 2026, according to Variety. The ‌Apple TV‌ show was supposed to come out on Friday, September 26, 2025, but Apple decided not to release it due to the topic and the political climate.

When the series was pulled, star Jessica Chastain said that she was "not aligned" with Apple's decision.

Chastain told Variety this weekend that she originally wasn't sure if the show would come out at all, but now she has received confirmation that it will be released. "We're going to see it," she said.

The Savant is a political thriller featuring Chastain as a woman who works undercover on the dark web to infiltrate online hate groups to prevent large-scale public attacks.

The July timing for The Savant has not yet been confirmed by Apple.Related Roundup: Apple TVTag: Apple TV ServiceBuyer's Guide: Apple TV (Don't Buy)Related Forum: Apple TV and Home Theater
This article, "Apple TV Series 'The Savant' Set for July Premiere After Delay" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Apple's iPhone became qualified for extended use in space back in February, and during the Artemis II mission to the Moon in April, NASA astronauts shared several photos taken with the iPhone 17 Pro Max.


Artemis II Commander Reid Wiseman recently followed up with a shot on iPhone video of an "Earthset," or the moment that the Earth disappears behind the Moon. The video was captured from the docking hatch window on the Orion capsule, and it is the first Earthset shot on a mobile device.


It takes a second for the iPhone to focus as Wiseman switches to 8x zoom mode on his ‌iPhone 17 Pro‌ Max, but the rest of the 53-second video features a clear look at the craters on the Moon as the Earth slips out of sight.

Wiseman said that at 8x zoom, the view was "quite comparable to the view of the human eye."Related Roundup: iPhone 17 ProTag: Shot on iPhoneBuyer's Guide: iPhone 17 Pro (Neutral)Related Forum: iPhone
This article, "NASA Astronaut Shares Incredible 'Earthset' Video Captured With iPhone 17 Pro Max" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
If Apple Music isn't working for you, you're not alone. According to Apple's System Status page, there's currently an ‌Apple Music‌ outage.


Apple says that users may be experiencing intermittent issues with the service. The outage started at 2:38 p.m. Eastern Time, and it is ongoing. We'll update this article when the outage has been resolved.Tag: Apple Music
This article, "Apple Music Is Down for Some Users" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
To celebrate Apple’s 50th anniversary earlier this month, Paul McCartney held a special performance for Apple employees at the company’s Apple Park campus.


McCartney recently shared a behind-the-scenes tour video of his visit to ‌Apple Park‌, providing an inside look at the campus and a special meeting with Apple CEO Tim Cook.

Cook said that Apple could not think of anyone better to celebrate its 50th anniversary with.

The video is just about three minutes long, and it includes snippets of McCartney’s private performance.
This article, "Paul McCartney Gives Inside Look at Apple Park 50th Anniversary Performance" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
A critical security vulnerability has been disclosed in SGLang that, if successfully exploited, could result in remote code execution on susceptible systems. The vulnerability, tracked as CVE-2026-5760, carries a CVSS score of 9.8 out of 10.0. It has been described as a case of command injection leading to the execution of arbitrary code. SGLang is a high-performance, open-source servingView the full article
Apple today provided the third beta of an upcoming macOS Tahoe 26.5 update to developers for testing purposes, with the update coming a week after the second beta.


Developers can download the ‌macOS Tahoe‌ 26.5 update by opening up the System Settings app, selecting the General category, and then choosing Software Update. Beta Updates will need to be enabled, and a free developer account is required.

No new features were found in the first two ‌macOS Tahoe‌ 26.5 betas, and it's likely the update primarily focuses on bug fixes and performance improvements.Related Roundup: macOS TahoeRelated Forum: macOS Tahoe
This article, "Third macOS Tahoe 26.5 Beta Now Available for Developers" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Apple today seeded the third betas of upcoming iOS 26.5 and iPadOS 26.5 updates to developers for testing purposes, with the software coming a week after Apple released the second betas.


Registered developers can download the betas from the Settings app on the iPhone or iPad by going to the General section and selecting Software Update.

iOS 26.5 and iPadOS 26.5 do not include new Siri capabilities, suggesting any ‌Siri‌ updates are being held until iOS 27. The Maps app has a Suggested Places feature for recommending locations to visit nearby based on trends and recent searches, plus Apple is laying the groundwork for ads in the Apple Maps app.

Apple is continuing to test end-to-end encryption (E2EE) for RCS messages between iPhone and Android users. Apple included the feature in the iOS 26.4 beta, but removed it before the update launched to the public.

In the European Union, Apple is testing proximity pairing, notification forwarding, and Live Activities for third-party wearables like earbuds and smartwatches. The functionality will allow third-party wearables to have many of the same features as the Apple Watch and AirPods.

More detail on what's new in iOS 26.5 can be found in our iOS 26.5 beta features guide.Related Roundups: iOS 26, iPadOS 26Related Forum: iOS 26
This article, "Apple Seeds Third iOS 26.5 and iPadOS 26.5 Betas to Developers" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Apple today provided developers with the third betas of upcoming watchOS 26.5, tvOS 26.5, and visionOS 26.5 betas for testing purposes. The software comes a week after Apple released the second betas for each platform.


The software updates are available through the Settings app on each device, and because these are developer betas, a free developer account is required.

There's no word on what's in the software as of yet. watchOS, tvOS, and visionOS often get few features in each new beta, with updates primarily focusing on bug fixes and performance improvements. Nothing new was found in the first two betas. Related Roundups: Apple TV, Apple Vision Pro, watchOS 26Buyer's Guide: Apple TV (Don't Buy), Vision Pro (Buy Now)Related Forums: Apple TV and Home Theater, Apple Vision Pro, Apple Watch
This article, "Apple Releases Third watchOS 26.5, tvOS 26.5 and visionOS 26.5 Betas" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Apple today updated its Sports app with weather conditions for F1 Grand Prix races and smaller widget options for both the iPhone's Home Screen and CarPlay.


The widget lets you view scores for your favorite leagues and teams at a glance.

CarPlay gained support for widgets on iOS 26. To view them, swipe right on CarPlay's interface until you reach the Dashboard screen, shown below.


In addition, Apple encourages people to get ready for the 2026 FIFA World Cup by following their favorite teams and exploring the groups of countries in the Apple Sports app before the tournament kicks off on Thursday, June 11.

Here are Apple's release notes for version 3.10 of the app:Launched in 2024, the Apple Sports app is available on the iPhone in the U.S., Canada, Mexico, and many countries in Europe, the Caribbean, and Latin America. The app shows scores, stats, standings, and more for a variety of leagues and events, including the NFL, MLB, NBA, NHL, NASCAR, F1, Premier League, PGA TOUR, and more.Related Roundup: CarPlayTag: Apple SportsRelated Forum: HomePod, HomeKit, CarPlay, Home & Auto Technology
This article, "Apple Sports App Receives Two New Features Across iPhone and CarPlay" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Apple is downgrading the planned specifications of the standard iPhone 18 to cut costs, a leaker claims.


In a new post on Weibo, the user known as "Fixed Focus Digital" said that the ‌iPhone 18‌ features "certain manufacturing downgrades" that bring it more into line with the low-cost iPhone 18e model. The decision is said to be "a cost-cutting measure."

Apple has apparently chosen to implement new cost-control strategies for the device, including specific downgrades to manufacturing processes, chips, memory, and more. The move will "effectively bring it in line with the '18e' model."

With the iPhone 17e and iPhone 17, the biggest differences are the Dynamic Island, display size, ProMotion, brightness, the front facing camera, the Ultra Wide camera, and battery life. It is not clear which key differentiators will remain between the two devices in their next iterations.


iPhone 17e vs. iPhone 17 Buyer's Guide: 35+ Differences Compared

The leaker apparently "confirmed" and verified the information using multiple sources. They noted that the information originates from the same source who correctly confirmed that the ‌iPhone 17e‌ would continue to feature a "notch," contrary to false reports that the device would have a ‌Dynamic Island‌.

The standard ‌iPhone 18‌ is expected to launch months after the iPhone 18 Pro models as part of an all-new split launch strategy. Apple's usual fall iPhone announcement is expected to include the ‌iPhone 18 Pro‌, ‌iPhone 18 Pro‌ Max, and the so-called foldable "iPhone Ultra." The iPhone 18e, ‌iPhone 18‌, and iPhone Air 2 will likely follow in the spring of 2027.


Related Roundup: iPhone 18Tag: Fixed Focus DigitalRelated Forum: iPhone
This article, "Leaker: Apple Downgrading iPhone 18 to Cut Costs" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Apple's software engineers are testing iOS 26.4.2, according to the MacRumors visitor logs, which have been a reliable indicator of upcoming iOS versions.


iOS 26.4.2 should be a minor update that fixes bugs and/or security vulnerabilities, and it will likely be released either this week or next week.

iOS 26.4.2 will come after iOS 26.4.1 and before iOS 26.5.

iOS 26.4.1 was released earlier this month. The update fixes a few bugs, including one that affected iCloud data syncing in select apps.

iOS 26.5 is in beta. The update lays the groundwork for Apple Maps ads and end-to-end encryption for RCS messages in the Messages app, but it is a minor update overall as Apple starts to shift its attention towards iOS 27.Related Roundups: iOS 26, iPadOS 26Related Forum: iOS 26
This article, "iOS 26.4.2 Update for iPhones is Coming Soon" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
iOS 27 will be compatible with the iPhone 12 series and newer, according to Instant Digital, a known Apple leaker on the Chinese social media platform Weibo.


If this rumor is accurate, iOS 27 will drop support for the following iPhone models:iPhone 11
iPhone 11 Pro
iPhone 11 Pro Max
iPhone SE (2nd generation)However, these devices will continue to receive iOS 26 security updates for at least a few years.

iOS 27 will be compatible with the following iPhone models, according to the leaker:iPhone 17e
iPhone 17
iPhone 17 Pro
iPhone 17 Pro Max
iPhone Air
iPhone 16e
iPhone 16
iPhone 16 Plus
iPhone 16 Pro
iPhone 16 Pro Max
iPhone 15
iPhone 15 Plus
iPhone 15 Pro
iPhone 15 Pro Max
iPhone 14
iPhone 14 Plus
iPhone 14 Pro
iPhone 14 Pro Max
iPhone 13
iPhone 13 mini
iPhone 13 Pro
iPhone 13 Pro Max
iPhone 12
iPhone 12 mini
iPhone 12 Pro
iPhone 12 Pro Max
iPhone SE (3rd generation)Any new Apple Intelligence features introduced in iOS 27 will require an iPhone 15 Pro or newer.

Apple will unveil iOS 27 during its WWDC 2026 keynote on Monday, June 8, and the first developer beta should be released later that day. A public beta typically follows in July, ahead of a final release to all users in September.

iOS 27 been likened to Mac OS X Snow Leopard, in the sense that Apple is reportedly focused on bug fixes and stability improvements. A handful of new features are still expected, including a dedicated Siri app, a system-wide slider for finely adjusting the opacity of Liquid Glass, improved keyboard autocorrection, and more.

Instant Digital has accurately leaked Apple information before, such as the yellow color for the iPhone 14 and iPhone 14 Plus, and the Apple Watch Ultra 2's Titanium Milanese Loop. However, the account does not have a perfect track record.Related Roundup: iOS 27Tags: Instant Digital, Weibo
This article, "iOS 27 Rumored to Drop Support for These iPhone Models" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Apple's first foldable iPhone will be eSIM only and feature a Camera Control despite its ultra-thin design, according to a known leaker.


In a series of new posts, the leaker known as "Instant Digital" said that Apple has made deliberate engineering compromises to ensure that the first foldable iPhone features a Camera Control button, despite it being at least 1.1mm thinner than the iPhone Air when unfolded.

According to the leaker, Apple's rationale is largely ergonomic: With competing foldable phones, Apple believes that making adjustments and taking photos can be "cumbersome" owing to their large size. The Camera Control is said to be the company's preferred solution, enabling users to maintain a steady grip on the device while making any required adjustments, or do so one-handed if they wish.



In addition, Apple's U.S. imaging team apparently recently took a trip to Shenzhen, China, to test the cameras of foldable smartphones from rival brands such as Huawei, with particular attention to telephoto zoom capabilities. The first foldable iPhone is not expected to offer a telephoto camera, with only wide and ultra wide cameras on the rear like the iPhone 17. Most high-end rival foldable smartphones, such as the Samsung Galaxy Z Fold 7, feature three rear cameras, including a telephoto.

Instant Digital added that they have seen no signs in the supply chain of tooling or stocking for SIM card tray modules for the foldable iPhone, concluding the device will be eSIM-only across all regions, just like the ‌iPhone Air‌. The leaker also puts first-year production at a conservative 10 million units, with pricing expected to fall between 15,000 and 20,000 RMB (roughly $2,060–$2,750).

The leaker added that the mainland China variants of the iPhone 18 Pro models are set to adopt a "Single SIM + eSIM" configuration, dropping the dual-physical-SIM setup currently used in the region. The Hong Kong version is said to follow the same approach while retaining a physical SIM card slot.

The foldable iPhone is widely expected to launch alongside the ‌iPhone 18 Pro‌ and ‌iPhone 18 Pro‌ Max in fall 2026. It is expected to feature a 7.8-inch inner display, a 5.5-inch outer display, Touch ID, the A20 chip, the C2 modem, and more.Related Roundups: iPhone 18 Pro, iPhone FoldTags: Camera Control, China, eSIM, Foldable iPhone, Instant Digital
This article, "Apple Apparently Sees Camera Control as Key Foldable iPhone Feature" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Amazon is offering a few all-time low prices on Apple's M5 Pro/M5 Max MacBook Pro, with up to $200 off select models. These deals join Amazon's discounts on the M5 MacBook Air from last week, which are seeing $150 in savings on some models.

Note: MacRumors is an affiliate partner with Amazon. When you click a link and make a purchase, we may receive a small payment, which helps us keep the site running.

Starting with the 14-inch models, you can get the 24GB/1TB M5 Pro MacBook Pro for $2,048.00, down from $2,199.00. This deal, along with all of the others we're tracking in this article, represent best-ever prices on the brand new M5 Pro and M5 Max MacBook Pro.

$151 OFF14-inch M5 Pro MacBook Pro (24GB/1TB) for $2,048.00
$150 OFF14-inch M5 Max MacBook Pro (36GB/2TB) for $3,449.00

This time around, some of the best deals are on the larger 16-inch MacBook Pro. You can get $200 off every model right now on Amazon, with the 24GB RAM/1TB M5 Pro model hitting a new all-time low price of $2,499.00, down from $2,699.00.

$200 OFF16-inch M5 Pro MacBook Pro (24GB/1TB) for $2,499.00
$200 OFF16-inch M5 Pro MacBook Pro (48GB/1TB) for $2,899.00
$200 OFF16-inch M5 Max MacBook Pro (36GB/2TB) for $3,699.00

If you're on the hunt for more discounts, be sure to visit our Apple Deals roundup where we recap the best Apple-related bargains of the past week.



Deals Newsletter

Interested in hearing more about the best deals you can find in 2026? Sign up for our Deals Newsletter and we'll keep you updated so you don't miss the biggest deals of the season!




Related Roundup: Apple Deals
This article, "Apple's 2026 MacBook Pro Hits New Record Low Prices on Amazon at $200 Off" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
While the iPhone 18 Pro and iPhone 18 Pro Max are not launching until September, there are already plenty of rumors about the devices.


It was initially reported that the iPhone 18 Pro models would have fully under-screen Face ID, with only a front camera visible in the top-left corner of the screen. However, the latest rumors indicate that only one Face ID component will be moved under the screen on the devices, which will result in merely a smaller Dynamic Island.

Below, we have recapped 10 features rumored for the iPhone 18 Pro models, as of April 20:Dark Cherry: The special color for the iPhone 18 Pro models will reportedly be Dark Cherry, alongside Light Blue, Dark Gray, and Silver. The existing Cosmic Orange and Deep Blue colors are expected to be discontinued.
Smaller Dynamic Island: It has been rumored that Face ID's flood illuminator will be moved under the screen on the iPhone 18 Pro models, paving the way for a smaller Dynamic Island on the devices.
LTPO+ Displays: The next Pro models are expected to have the same overall design as the iPhone 17 Pro models, including 6.3-inch and 6.9-inch display sizes and a "plateau" housing three rear cameras. However, the displays will reportedly use so-called LTPO+ display technology, which should contribute to longer battery life.
Variable Aperture: The main 48-megapixel Fusion camera on both iPhone 18 Pro models is rumored to have a variable aperture, which would allow users to control the amount of light that passes through the camera's lens and reaches the sensor. This would provide greater control over depth of field. However, given that iPhones have smaller image sensors due to smartphone size constraints, it is unclear exactly how meaningful this improvement would be.
A20 Pro Chip: Apple's next-generation A20 Pro chip is expected to use TSMC's first-generation 2nm process, whereas the A19 Pro chip is 3nm. With a 2nm architecture and a new packaging design, the A20 Pro chip should deliver solid year-over-year performance and power efficiency gains.
C2 Modem: Apple's custom C1 cellular modem for 5G and LTE debuted in the iPhone 16e last year, and that was followed by a C1X chip in the iPhone Air. Apple says the C1X modem is up to twice as fast as the C1 modem, and the most power-efficient modem in an iPhone ever. The improvements should continue with Apple's third-generation C2 modem in the iPhone 18 Pro models.
5G via Satellite: With the C2 modem, the iPhone 18 Pro models will reportedly support 5G via satellite for web browsing without Wi-Fi or cellular connectivity.
N2 Chip: Most of the iPhone 17 models and the iPhone Air are equipped with an Apple-designed N1 chip that enables Wi-Fi 7, Bluetooth 6, and Thread. Apple says the N1 chip also improves the overall performance and reliability of features like Personal Hotspot and AirDrop. iPhone 18 Pro models are expected to have Apple's next-generation N2 chip, but it is not yet known what improvements would come with this upgrade.
Simplified Camera Control: Apple is expected to simplify the Camera Control button on the iPhone 18 Pro models, by removing touch sensitivity and haptic feedback. The redesigned button will only have pressure sensitivity.
Redesigned Rear Ceramic Shield: The rear Ceramic Shield area for MagSafe is rumored to feature a more frosted and seamless appearance on the iPhone 18 Pro models compared to the current two-tone design.Apple is expected to release the iPhone 18 Pro, iPhone 18 Pro Max, and a foldable iPhone in September, followed by a standard iPhone 18 model, a lower-end iPhone 18e, and a second-generation iPhone Air early next year.Related Roundup: iPhone 18 Pro
This article, "iPhone 18 Pro Launching in September With These 10 New Features" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Monday’s recap shows the same pattern in different places. A third-party tool becomes a way in, then leads to internal access. A trusted download path is briefly swapped to deliver malware. Browser extensions act normally while pulling data and running code. Even update channels are used to push payloads. It’s not breaking systems—it’s bending trust. There’s also a shift in how attacks run.View the full article
Woot today has Apple's first generation AirTag 4-Pack for $56.99, down from $99.00, which is a match of the all-time low price on this model. The AirTag 4-Pack is in new condition and comes with a 90-day Woot limited warranty.

Note: MacRumors is an affiliate partner with Woot. When you click a link and make a purchase, we may receive a small payment, which helps us keep the site running.

Woot provides an estimated delivery date between April 29 and May 1 for the AirTag 4-Pack, and the sale is set to last for four more days. Deals on the first generation AirTag models have been rare since the launch of the AirTag 2, so this is a great time to snag an older model if you've been waiting for a sale.

$42 OFFAirTag 4-Pack (1st Gen) for $56.99

If you're on the hunt for more discounts, be sure to visit our Apple Deals roundup where we recap the best Apple-related bargains of the past week.



Deals Newsletter

Interested in hearing more about the best deals you can find in 2026? Sign up for our Deals Newsletter and we'll keep you updated so you don't miss the biggest deals of the season!




Related Roundup: Apple Deals
This article, "Get the First Gen AirTag 4-Pack for Lowest-Ever Price of $56.99" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Attackers are increasingly exploiting enterprise collaboration platforms such as Microsoft Teams to gain initial access, impersonating IT helpdesk staff and persuading employees to grant remote control, according to new research from Microsoft.
In a blog post, Microsoft described a “cross-tenant helpdesk impersonation” technique in which threat actors initiate conversations with employees via Teams’ external access feature.
“Attackers use social engineering to convince users to grant access,” Microsoft said, noting that the approach allows adversaries to operate within trusted communication channels and bypass traditional phishing defenses.
Unlike conventional phishing or exploit-driven attacks, the technique relies on what Microsoft characterizes as user-approved access. Victims are persuaded to initiate remote sessions, often using legitimate tools, effectively handing control to attackers without triggering typical malware-based detections, the blog post said.
Shift to collaboration apps
While the technique may appear new, analysts say it reflects an evolution rather than a reinvention of attack methods.
“From my perspective, this is more an evolution of existing social engineering tactics than a fundamental shift,” said Prabhjyot Kaur, senior analyst at Everest Group. “The underlying objective hasn’t changed. Attackers are still exploiting user trust and urgency to gain initial access. What is changing is the channel.”
As platforms such as Teams become central to workplace communication, attackers are following users into those environments. Unlike email, these platforms enable real-time engagement, making impersonation of IT or helpdesk staff more convincing.
Kaur said collaboration platforms enable real-time interaction, making impersonation of IT or helpdesk staff more convincing than email-based phishing. “So rather than replacing phishing, this expands the attack surface and makes social engineering more operationally effective,” Kaur said.
Offering a sharper view of the shift, Sanchit Vir Gogia, chief analyst at Greyhound Research, said the change is less about channel and more about how attacks unfold. “Phishing asked for attention. This model demands participation,” he said.
“Attackers are inserting themselves into legitimate workflows and guiding users step by step through actions that grant access,” Gogia added, describing it as a move toward “guided execution” rather than simple deception.
Microsoft’s findings follow earlier incidents in which attackers used Teams chats and calls to impersonate IT support and initiate remote access.
Cross-tenant risk grows
The attack chain uses Teams’ cross-tenant communication capability, which allows external users to initiate chats with employees, Microsoft wrote in the blog.
“The cross-tenant risk is significant, and many organizations probably do underestimate it,” said Sunil Varkey, advisor at Beagle Security.
“Collaboration tools were designed to reduce friction, but many organizations enabled that convenience before fully applying Zero Trust controls,” Varkey said. “The sustainable approach is to keep the business value of these platforms while treating every external interaction, support request, and access approval as something that must be verified, limited, and monitored.”
He compared the risk to a physical security gap. Allowing anyone into a lobby should not mean they can walk employees to restricted areas and request access.
Kaur added that many enterprises still treat collaboration platforms primarily as productivity tools rather than part of their attack surface. “Cross-tenant access is necessary for business, but it introduces a trust boundary that is often not well understood or tightly controlled,” she said.
Gogia said the issue is rooted in how trust is applied in modern environments. “External actors can now initiate interactions inside environments that employees associate with internal coordination,” he said, adding that this creates a “false sense of safety.”
Detection becomes harder
Microsoft said attackers use legitimate administrative tools and remote access utilities after gaining entry, making activity harder to distinguish from normal operations.
Because attackers use legitimate tools and approved workflows, “there’s very little that looks overtly malicious in isolation,” Kaur said. “These attacks blend into normal IT operations.”
Microsoft also noted that attackers rely on native administrative tools and legitimate data transfer utilities to move laterally and exfiltrate data while appearing as routine activity.
This shifts the focus toward behavioral detection. “Security teams should prioritize detecting sequences of activity,” Kaur said, pointing to patterns such as an unsolicited external Teams interaction followed by remote support activity and lateral movement.
Gogia said this requires a shift in detection approach. “These attacks do not rely on exploits. They rely on sequence,” he said. “Each individual action appears legitimate. The compromise emerges only when those actions are connected.”
Varkey added that defenders need to move beyond traditional indicators. “Because these attacks rely on legitimate tools and user-approved actions, security teams need to focus on context and behavior, not just malware,” he said.
Tighter controls needed
To reduce risk, experts say organizations need stronger governance over collaboration environments.
“Collaboration platforms are often configured for convenience first, with easy external chat, calls, screen sharing, and remote assistance, without fully considering how those features can be abused together,” Varkey said.
Kaur emphasized the need for integrated visibility. “The most effective defenses will come from integrating collaboration, identity, endpoint, and SOC visibility rather than treating them as separate layers,” she said.
Recommended measures include tightening external access controls, restricting remote-support tools to approved workflows, enforcing conditional access and multi-factor authentication, and improving user awareness around how legitimate IT support interactions occur, Microsoft wrote.
View the full article
Apple is preparing to bring support for its digital car key feature to Tata EV vehicles, based on evidence uncovered by MacRumors on Apple's backend.


Tata is an Indian multinational commercial vehicle manufacturer, headquartered in Mumbai. The company produces trucks, vans, and buses, and is now on an internal Apple list of vehicles that offer car key integration, but it is not known which EV models the support pertains to.

Introduced in 2022, Car Keys allows an iPhone or Apple Watch to unlock a vehicle through the Wallet app. A digital version of a car key is stored in Wallet, and unlocking can be done by holding an Apple Watch or ‌iPhone‌ near a compatible vehicle's NFC reader.

A tap on the door handle is enough to initiate an unlock, and while Face ID authentication is a security option, Apple offers an Express Mode that eliminates the need to authenticate for a faster unlocking process.

At WWDC 2025, Apple confirmed that 13 vehicle brands would "soon" add support for digital car keys, and Tata was on the list. Vehicles from BMW, Genesis, Kia, Hyundai, Lotus, Mercedes, Volvo, and more offer car keys support, with a list available on MacRumors.com.Tags: iPhone Car Keys, India
This article, "Apple Set to Add Car Key Support for India's Tata Vehicles" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Frontend cloud platform Vercel, the creator of Next.js and Turbo.js, has warned about a data breach after a compromised third-party AI application abused OAuth to access its internal systems.
A Vercel employee used the third party app, identified as Context.ai , which allowed the attackers to take over their Google Workspace account and access some environment variables that the company said were not marked as “sensitive.”
“Environment variables marked as “sensitive” in Vercel are stored in a manner that prevents them from being read, and we currently do not have evidence that those values were accessed,” Vercel said in a security post.
The incident compromised what the company described as a “limited subset” of customers whose Vercel credentials were exposed. These customers have now been reached out with requests to rotate their credentials, Vercel said.
According to reports surfacing on the internet, a threat actor claiming to be the Shinyhunters began attempting to sell the stolen data, which allegedly include access key, source code, and private database, even before Vercel confirmed the breach publicly.
Hacking the access
Vercel’s disclosure confirmed that the initial access vector was Google Workspace OAuth tied to Context.ai. Once the application was compromised, attackers inherited the permissions granted to it, including access to Vercel employee’s account.
It remains unclear whether Context.ai’s infrastructure was compromised, OAuth tokens were stolen, or a session/token leak within the AI workspace enabled attackers to abuse authenticated access into Vercel’s environments. Context.ai did not immediately respond to CSO’s request for comments.
“We have engaged Context.ai directly to understand the full scope of the underlying compromise,” Vercel said in the post. “We assess the attacker as highly sophisticated based on their operational velocity and detailed understanding of Vercel’s systems. We are working with Mandiant, additional cybersecurity firms, industry peers, and law enforcement.”
Vercel has urged its customers to review activity logs for suspicious behavior and to rotate environment variables, especially any unprotected secrets that may have been exposed. It also recommended enabling sensitive variable protections, checking recent deployments for anomalies, and strengthening safeguards by updating deployment protection settings and rotating related tokens where needed.
Sensitive secrets, including API keys, tokens, database credentials, and signing keys, that were not marked as “sensitive” should be treated as potentially exposed and rotated as a priority, Vercel emphasized.
For users in panic, Vercel has offered an shortcut. “If you have not been contacted, we do not have reason to believe that your Vercel credentials or personal data have been compromised at this time,” the post reassured.
Allegedly breached by ShinyHunters
According to screenshots circulating on the internet, a threat actor has already claimed the breach on the dark web and is attempting to sell the spoils. “Greetings All, Today I am selling Access Key/ Source Code/ Database from Vercel company,” the actor said in one of such posts. “Give me a quote if you’re interested. This could be the largest supply chain attack ever if done right.”
The data was put up for $2 million on April, 19.
The threat actor can be seen using a “BreachForums” domain in the screenshot, claiming (not explicitly) to be Shinyhunters themselves, one of the operators of the notorious hacksite. Other giveaways include a Telegram channel “@Shinyc0rpsss” and an email id “[email protected]” mentioned in the post.
While recent incidents have hinted at ShinyHunters resurfacing after  takedowns and alleged arrests, it remains likely that this is an imposter leveraging the name to lend credibility, something that has precedent.
View the full article
Apple is facing a fast-track decision on regulatory penalties in India because it has not submitted data sought by the country's antitrust body as part of an investigation into its market practices.


The Competition Commission of India (CCI) ⁠published a report in 2024 that Apple exploited its dominant position in the apps market by forcing developers to use its proprietary in-app purchase system. The report was the result of a case that began in 2021​ after a non-profit group opposed Apple's practices.

Apple in 2024 denied any wrongdoing by arguing that it is a minor presence in India. However, nowadays iPhones have an 9% market share in the country compared to just 4% two years ago, according to data from Counterpoint Research, potentially weakening its case.

According to Reuters, the CCI this month said that Apple has not submitted details of its financials ​and its views on the investigation since October 2024. Instead, Apple has cited a separate case pending in the ​Delhi High Court where the company has challenged India's entire antitrust penalty law.

The CCI typically requires financial ⁠information from companies to calculate penalties when they are found to have contravened the law, but Apple has said it fears it could be fined up to $38 billion. Apple last year said that using global turnover would result in a fine that's "manifestly arbitrary, unconstitutional, grossly disproportionate, and unjust."

Apple in March requested that the CCI put its proceedings "in abeyance" while the High Court case plays out, but the CCI has rejected that demand and suggested Apple is trying to stall the antitrust case, which is just one of many that the company is facing around the globe.

The CCI has given Apple two more weeks to file its responses and has for the first time fixed a final hearing date of May 21.Tags: Apple Antitrust, India
This article, "Apple Withholds Data as India Antitrust Case Advances to Final Hearing" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
The fastest way to fall in love with an AI tool is to watch the demo. Everything moves quickly. Prompts land cleanly. The system produces impressive outputs in seconds. It feels like the beginning of a new era for your team. But most AI initiatives don't fail because of bad technology. They stall because what worked in the demo doesn't survive contact with real operations. The gap between aView the full article
Nitin Raina’s career history resembles that of many CISOs: He worked in IT infrastructure, operations, and services before moving into security and advancing through the ranks. He’s now global chief information security officer at technology consultancy Thoughtworks.
But in a less common professional move Raina also picked up the role of global head of enterprise risk, a position he has held at Thoughtworks since 2020. He earned the job, he says, because of his ability and propensity to talk “about risk in totality.”
After taking the position, Raina established the enterprise risk management function, which he now oversees. The function identifies and mitigates strategic, operational, and cybersecurity risks throughout the organization, and performs in-depth risk assessments and gap analyses to uncover vulnerabilities and inefficiencies within critical business processes, systems, and controls.
Raina says heading enterprise risk is a natural fit for him as CISO, which is why he believes the two roles should be paired more frequently.
“The risk conversation, as CISOs, we can lead that,” Raina says. “We have the ability and the forum in which we can raise it.”
Most CISOs don’t hold a risk title, as Raina does, yet researchers, executive advisers, and other security leaders say CISOs are increasingly taking on more enterprise risk management tasks.
It’s a logical expansion, these experts say. CISOs have been coached for years to identify how cyber risks pose business risks and to understand which risks represent the biggest risks to the enterprise, whether the impact of any of those exceed the organization’s tolerance for risks, and if so by how much.
That CISO work is more critical than ever, they further assert. Nearly all business operations have become digital. That fact makes any cyber risk a material risk to the business, and it makes resiliency an operational imperative today. As such, the CISO should be a key player in assessing and managing business risk.
“CISOs had once been focused on IT and cybersecurity risk. They’d ask, ‘What are the risks I have for platforms, applications, systems, the tech stack?’ It was a very flat plane,” says Paul Caron, global managed services lead and head of cybersecurity for the Americas at S-RM, a global corporate intelligence and cybersecurity consultancy. “But it has evolved in the past few years, and now CISOs are being pulled into new areas. They’re being asked, ‘What are the risks to the business?’”
CISOs lead the way on risk
In the 2026 CISO Report from data platform maker Splunk, 78% of CISOs reported joint accountability with other technical C-suite leaders (CIO, CTO, etc.) for security operational business risk, 56% have that joint accountability with CEOs, and 29% have joint accountability with other C-suite roles (CFO, chief legal officer, etc.).
The report also found that 96% of CISOs are now responsible for AI governance and risk management.
Meanwhile, the CyberRisk Alliance’s Q1 2026 CISO Top 10 report found that governance, risk, and compliance is the top priority for CISOs today. The report says this reflects GRC’s “role as the primary mechanism through which cybersecurity earns executive and board trust.”
The report also notes that “organizations are under pressure to prove that risk oversight is continuous, defensible, and integrated into enterprise decision-making. CISOs are increasingly expected to unify regulatory obligations, enterprise risk tolerance, and security controls into a coherent operating model that supports real-time governance.”
Evolving risks require a new CISO leadership profile
The shift to CISO as a risk position, and not one limited to technical and cybersecurity alone, has been years in the making. But it has accelerated since the arrival of ChatGPT in late 2022, as organizations embraced first generative AI and more recently agentic AI. That’s because AI melds with the business process, whereas prior technologies only enabled business processes. That melding raises the stakes and makes cyber, digital, and business risk nearly synonymous.
That evolution has pushed the CISO deeper into risk assessment and management, and it requires a different type of CISO than those of the past.
“CISOs cannot walk around and make decisions based on fear or compliance. They must now be able to talk about risk in business terms. They need to understand that risk is a business conversation,” says Leon DuPree, lecturer at Eastern Michigan University’s School of Information Security and Applied Computing.
Leading CISOs do this by quantifying both risk and the ROI of their options to address those risks, DuPree says, noting that many use the Factor Analysis of Information Risk (FAIR) model to understand and position cyber and operational risk in financial terms.
“That’s the direction that CISOs are trying to go, so they can facilitate change and innovation working from ROIs for all the dollars being spent on security assets and risk mitigation,” he adds.
S-RM’s Caron sees more CISOs taking this approach.
For example, he says more security chiefs are being tasked with assessing and modeling risks associated with the AI uses within their organizations and reporting how those risks impact business processes — not just data integrity and IT systems.
To perform such duties, CISOs must use more of their executive skills than their cyber acumen, Caron says. They must identify risks that come with the deployment of AI and other technologies, quantify those risks in business terms, offer mitigation strategies, quantify how each mitigation option reduces business risks, and help prioritize risk-related tasks based on expected returns and business objectives.
“It takes more of a business leader’s lens than a very technical lens. So CISOs now have to be the ones responsible for steering the conversation into directions that show they’re a partner with the business to accelerate growth,” he explains. “The businesses of today are demanding more and more a business CISO.”
Caron acknowledges that it’s a significant demand, one that requires CISOs to expand their knowledge base beyond technical and even compliance to business operations, enterprise strategy, and market conditions.
“I think that’s where CISOs needs to start going, not necessarily where they are today,” he adds. “Many do still struggle with the mental shift it takes.”
A question of appetite
Steve Martano, an IANS Research faculty member and a partner in Artico Search’s cybersecurity practice, says the majority of CISOs rise through the technical and engineering ranks, so many still find enterprise risk assessment and management novel tasks.
But, like Caron, he says it’s now part of the gig.
“I think understanding how emerging tech impacts the organization’s risk profile is something they must do, and I think the conversation around enterprise risk is always something security practitioners should be striving for when they communicate,” he says.
But Martano, like others, also says CISOs do not have — nor should they assume — ownership over establishing the organization’s risk appetite.
“It’s not the CISOs job to revisit the risk posture itself. It’s not the CISO’s job to say, ‘We’re operating too loose,’” Martano says.
Instead, CISOs must possess “a good understanding of what the organization thinks is inbounds and out-of-bounds” so they can “flag how technologies, processes, and tools could have an effect on the risk posture,” he says. “The CISO is the adviser.”
Boards expect CISOs to be capable of identifying and assessing current and future risks as well as advising on whether to mitigate, transfer, insure against or accept those risks, he adds.
That may be more challenging now than ever, with technology, AI, and enterprise use of them swiftly evolving.
“The best CISOs think about risks that are around the corner. They have to have a pulse on where things are going,” Martano adds. “They don’t have to be visionary; but they do need to be proactive by engaging more outside their four walls, engaging with vendors, information-sharing with their peers, having a pulse on the macro level. The more they diversify what they’re hearing, the better, so they can bring nuggets of information to their boards and executive teams to discuss and how those affect their own organization’s risk culture.”
View the full article
DC Studio / Shutterstock
KI-Agenten fürs Enterprise können bekanntlich Arbeitsabläufe optimieren. Aber auch die Datenexfiltration – wie Sicherheitsforscher von Capsule Security herausgefunden haben. Sie haben sowohl in Microsoft Copilot Studio als auch Salesforce Agentforce Prompt-Injection-Schwachstellen entdeckt.
Diese ermöglichen Angreifern in beiden Fällen schadhafte Befehle über scheinbar harmlose Prompts einzuschleusen – mit potenziell verheerenden Folgen.
Copilot leakt Sharepoint-Daten
Beim „ShareLeak“ getauften Problem auf Microsoft-Seite liegt der Knackpunkt darin, wie Copilot-Studio-Agenten SharePoint-Formulare verarbeiten. Der Angriff beginnt mit einem manipulierten Payload, der in ein Standard-Formularfeld (etwa „Kommentare“) eingefügt wird. Diese fließt später im Rahmen seines operationellen Kontexts in den KI-Agenten ein. Weil das KI-System Benutzer-Inputs mit System-Prompts verknüpft, überschreibt der „injizierte“ Payload die ursprünglichen Anweisungen des Agenten. Das KI-Modell behandelt damit die Anweisungen eines Angreifers als legitime System-Direktiven – der schadhafte Input wird ohne jegliche Widerstände vom Agenten ausgeführt.
Sobald ein Agent auf diese Art und Weise kompromittiert wurde, ist es demnach auch möglich,
auf verbundene Sharepoint-Listen zuzugreifen, sensible Kundendaten zu extrahieren und diese per E-Mail zu versenden. Wie die Forscher feststellten, wurden Daten selbst dann exfiltriert, wenn die Sicherheitsmechanismen von Microsoft verdächtiges Verhalten meldeten. „Die Hauptursache dafür ist, dass es keine zuverlässige Trennung zwischen vertrauenswürdigen Systemanweisungen und nicht vertrauenswürdigen Benutzerdaten gibt. In der bestehenden Konfiguration kann die KI das nicht voneinander unterscheiden“, so die Sicherheitsexperten.
Microsoft hat inzwischen einen Patch veröffentlicht, der das Problem behoben hat. Und die Sicherheitslücke mit einem Schweregrad von 7,5 von 10 auf der CVSS-Skala bewertet. Seitens der Benutzer sind keine weiteren Maßnahmen erforderlich.
Lead-Formulare kapern Agentforce
Im Fall von Salesforce Agentforce konnten die Forscher von Capsule maliziöse Instruktionen in ein öffentlich zugängliches Lead-Formular einbetten, die im Anschluss über einen „Agent Flow“ mit E-Mail-Funktionen ausgeführt wurden. Weist ein interner Benutzer einen Agentforce-Agenten später an, diesen Lead zu überprüfen oder zu verarbeiten, führt dieser die Anweisungen aus und exfiltriert sensible Daten. „Das resultiert in einer nicht-autorisierten Datenoffenlegung und potenziell massenhafter Exfiltration von CRM-Daten“, schreiben die Forscher.
Massenhaft deswegen, weil sich die Kompromittierung nicht auf einen einzelnen Datensatz beschränkt: Laut den Capsule-Experten kann ein gekaperter Agent mehrere Lead-Datensätze gleichzeitig abfragen und exfiltrieren, wodurch eine einzelne Formularübermittlung effektiv zur Datenbank-Extraktions-Pipeline werde. Den Forschern zufolge habe Salesforce das Prompt-Injection-Problem zwar anerkannt, den Exfiltrations-Vektor jedoch als „konfigurationsspezifisch“ eingestuft und auf optionale Human-in-the-Loop-Kontrollen verwiesen. Die Sicherheitsforscher von Capsule widersprechen dieser Darstellung und argumentieren, dass manuelle Genehmigungen den eigentlichen Zweck autonomer Agenten untergraben.
Das eigentliche Problem, so die Forscher, seien unsichere Standardeinstellungen. Für die Automatisierung konzipierte Systeme sollten es demnach nicht zulassen, dass nicht-vertrauenswürdige Inputs die Ziele der Agenten neu definieren können.
Was Unternehmen tun sollten
Beide Sicherheitslücken laufen auf eine Grundvoraussetzung hinaus: Sämtliche externe Inputs sollten als nicht vertrauenswürdig behandelt werden. Und: Filter einzurichten, die Daten von Anweisungen trennen, ist zu empfehlen. Dies würde auch bedeuten, folgende Maßnahmen durchzusetzen:
Input-Validierung, Least-Privilege-Zugriff, sowie strikte Kontrollmaßnahmen für Dinge wie ausgehende E-Mails. (fm)
View the full article
Anthropic | Screenshot Der Hype um Anthropics Security-Modell Mythos bekommt erste Risse: Während KI-Konkurrent OpenAI plant, mit einem eigenen Cybersecurity-fokussierten KI-Modell „entgegenzuwirken“, stellen die Sicherheitsexperten von VulnCheck in einer aktuellen Untersuchung die praktischen Auswirkungen von Claude Mythos, respektive „Project Glasswing“ in Frage.
„Anthropics Project Glasswing hat große Aufmerksamkeit erregt – liefert aber nur sehr wenig konkrete Daten“, schreibt VulnCheck-Forscher Patrick Garrity in einem Blogbeitrag. Zwar würden die Forschungsaktivitäten von Anthropic aktiv dazu beitragen, Schwachstellen aufzudecken und seien insgesamt vielversprechend – der nachweisbare Impact des Projekts bislang jedoch eher überschaubar.
Die CVE-Analyse von VulnCheck
Für ihre Analyse haben sich die Experten von VulnCheck die Zahlen hinter „Project Glasswing“ genauer angesehen – beziehungsweise die CVEs, die der Initiative direkt zuzuordnen sind.
„Weder der Report zu Glasswing noch die von Anthropic veröffentlichten Sicherheitshinweise liefern eine umfassende Liste der entdeckten Schwachstellen. Also beschloss ich, die gesamte CVE-Datenbank nach Einträgen zu durchsuchen, die den Begriff ‚anthropic‘ enthielten und überprüfte jeden einzelnen“, beschreibt Garrity sein Vorgehen. Insgesamt identifizierte der Researcher 75 solche CVE-Einträge. Allerdings wurden davon lediglich 40 den Forschern von Anthropic zugeschrieben. Nach einer weiteren Eingrenzung zeigte sich, dass lediglich eine einzige CVE ausdrücklich „Project Glasswing“ selbst zugeordnet wird. Dabei handelt es sich um eine Sicherheitslücke in FreeBSD, die es ermöglicht, remote Code auszuführen. Diese wird als „autonom identifiziert“ und „ausgenutzt“ beschrieben.
Bei seiner Analyse hat Garrity drei Schwachstellen außen vor gelassen, die auf der Website des Projekts erwähnt werden – allerdings unter Embargo stehen, beziehungsweise nicht im Detail einsehbar sind, bis Patches verfügbar sind. Darunter:
eine 27 Jahre alte Sicherheitslücke in OpenBSD, ein 16 Jahre alter Bug in FFmpeg, sowie Privilege-Escalation-Ketten im Linux-Kernel. „Ein abschließendes Bild von der tatsächlichen Leistungsfähigkeit von Claude Mythos zu gewinnen, wird erst möglich sein, wenn Anthropic umfassend öffentlich Rechenschaft darüber ablegt, welche Schwachstellen im Rahmen von Project Glasswing gefunden und behoben wurden“, so Garrity. Damit rechnet der Sicherheitsexperte für den Juli 2026.
Das sagen Experten
Die Erkenntnisse von VulnCheck werfen ein neues Licht auf die Fähigkeiten von Claude Mythos – beziehungsweise darauf, wie diese gemessen werden. Schließlich ist die Anzahl direkt zurechenbarer CVEs nur ein Weg, den Impact des KI-Modells von Anthropic zu erfassen.
So nimmt etwa Melissa Bischoping, Vorstandsmitglied des SANS Technology Institute und Senior Director beim Sicherheitsanbieter Tanium, eine andere Perspektive ein, wenn es um das Potenzial von Claude Mythos geht: „Wir haben bei Tanium die System Card der Claude Mythos Preview analysiert – und das Modell erzielt eine bisher unerreichte Erfolgsquote bei Exploits. Der Sprung von einer Erfolgsquote nahe Null auf ungefähr 72 Prozent bei derselben Klasse von Angriffszielen deutet darauf hin, dass es kein Bottleneck mehr darstellt, raffinierte, aufwendige Exploits zu entwickeln.“
Auch wenn Claude Mythos derzeit im eng abgesteckten Rahmen von Project Glasswing getestet werde, habe es bereits gezeigt was künftig möglich ist, meint die Managerin: „Die Kluft zwischen Frontier- und Open-Weight-Modellen hat sich von mehr als einem Jahr auf wenige Wochen verringert. Dieses Leistungsniveau wird sich rasch ausbreiten – sehr wahrscheinlich, können die Sicherheitsvorkehrungen dabei nicht Schritt halten“, warnt Bischoping.
Die Expertin zeigt sich insbesondere besorgt darüber, ob Unternehmen noch fähig sein werden, auf die durch Claude Mythos zu Tage geförderten Erkenntnisse zu reagieren – bevor das Modell in die freie Wildbahn gelangt: „Agentic-Patch-Workflows sind realisierbar und können in vielen Fällen mit Adversarial AI Schritt halten. Allerdings laufen Unternehmenspolitik und Change-Kontrolle aktuell nicht mit KI-Geschwindigkeit.“ (fm)
View the full article
Chinese leaker Ice Universe has shared an image showing four camera plateau protection plates with finishes that appear to match the latest color rumors for Apple's iPhone 18 Pro models.


Last week, a Macworld report claimed Apple is working on four color options for the iPhone 18 Pro and iPhone 18 Pro Max: Light blue, dark cherry, dark gray, and silver.

The four anodized aluminum camera lens protector plates shown here are labeled as black, silver, wine red, and blue. Note that the accessories in the picture are not actual phone bodies but third-party camera covers designed to complement the rumored finishes, and we believe the "black" description refers to dark gray. According to Weibo-based leaker Instant Digital, Apple won't be offering its next-generation premium models in a black color option this year.

All four colors are said to be still in development, and Apple still has time to make changes.

The iPhone 18 Pro models are expected to be unveiled this September alongside Apple's first foldable iPhone, which will have its own set of color finishes that are likely to be more muted, with silver, white, and indigo rumored so far.Related Roundup: iPhone 18 ProTag: Ice Universe
This article, "iPhone 18 Pro May Come in These Four Colors" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Cybersecurity researchers have flagged a new malware called ZionSiphon that appears to be specifically designed to target Israeli water treatment and desalination systems. The malware has been codenamed ZionSiphon by Darktrace, highlighting its ability to set up persistence, tamper with local configuration files, and scan for operational technology (OT)-relevant services on the local subnet.View the full article
The global memory chip shortage may result in the next MacBook Pro and Mac Studio models launching later than expected, according to the latest rumor.


Bloomberg's Mark Gurman has repeatedly stated that 14-inch and 16-inch MacBook Pro models with a touch screen are slated to launch in late 2026 to early 2027. In his Power On newsletter today, though, he said to be prepared for the laptops to potentially arrive towards the end of that timeframe due to the chip shortage.

In other words, early 2027 is now more likely than late 2026.

Gurman previously expected a new Mac Studio to launch around the middle of 2026, which pointed towards an announcement around WWDC 2026 in June. However, in his newsletter today, he wrote that sources within Apple believe that the next Mac Studio models will not ship until around October this year as a result of the shortage.

Touch-screen support will be part of a major refresh planned for the high-end MacBook Pro models, with other rumored features including M6 Pro and M6 Max chips, an OLED display, a Dynamic Island, and a thinner design. The laptops might have MacBook Ultra branding, and macOS 27 will offer a touch-friendly interface.

For the Mac Studio, the key change will be M5 Max and M5 Ultra chips. The current model has mismatched M4 Max and M3 Ultra chips, as Apple never introduced an M4 Ultra chip. No major design changes are expected for the desktop computer.

All in all, expect a Mac Studio refresh around October this year, followed by MacBook Pro models with a touch screen by the end of January 2027.Related Roundups: Mac Studio, MacBook ProTags: Bloomberg, Mark GurmanBuyer's Guide: Mac Studio (Caution), MacBook Pro (Buy Now)Related Forums: Mac Studio, MacBook Pro
This article, "MacBook Pro With Touch Screen and New Mac Studio Likely 'Postponed'" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Apple is planning to add "Undo" and "Redo" options to the iPhone's Home Screen customization menu on iOS 27, according to Bloomberg's Mark Gurman.


These two options will make it easier to reverse or redo your Home Screen changes.

"Right now, when you long-press on the home screen, you get a bubble in the top left corner with four options: Add Widget, Customize, Edit Wallpaper and Edit Pages," he explained, in his latest Power On newsletter. "Apple is looking at adding 'undo' and 'redo' buttons in that same menu to make reversing or redoing changes easier."

Other rumored iOS 27 features include a dedicated Siri app and Apple Intelligence advancements. The update has been likened to Mac OS X Snow Leopard, in the sense that Apple is apparently very focused on bug fixes and stability improvements.

iOS 27 beta testing will begin in June, and the update will be released in September.Related Roundup: iOS 27Tags: Bloomberg, Mark Gurman
This article, "Apple Testing Two Small Yet Useful iOS 27 Options" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Apple's WWDC 2026 graphic provides "a glimpse of the revamped Siri interface coming in iOS 27," according to Bloomberg's Mark Gurman.


In his Power On newsletter today, Gurman said iOS 27 will include a new Siri interface in the Dynamic Island. When you trigger Siri, he said the Dynamic Island will show a "Search or Ask" prompt, and this will apparently be accompanied by a "glowing cursor" that looks similar to how the "26" is highlighted in the WWDC 2026 graphic.

There will also be a "thin glow" around the edges of the Dynamic Island when Siri is invoked, and in the search bar of a dedicated Siri app that will be preinstalled on iOS 27, according to Gurman. He previously reported that the Siri app will allow you to have back-and-forth conversations with Siri and view your conversation history.

While the Dynamic Island is available on the iPhone 14 Pro and newer, at least some aspects of the upcoming Siri design will likely be limited to the iPhone 15 Pro and newer due to Apple Intelligence compatibility reasons.

Apple announced that WWDC 2026 will run from Monday, June 8 through Friday, June 12. At the annual developers conference, Apple is expected to unveil iOS 27, iPadOS 27, macOS 27, watchOS 27, tvOS 27, visionOS 27, and more.Related Roundups: iOS 27, WWDC 2026Tags: Bloomberg, Mark Gurman, SiriRelated Forum: Apple, Inc and Tech Industry
This article, "WWDC 2026 Graphic Teases Major iOS 27 Feature" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Amazon today has the AirPods Pro 3 available for $199.99, down from $249.00. This is a match of the all-time low price on the AirPods Pro 3, and it's accompanied by a solid deal on the AirPods 4.

Note: MacRumors is an affiliate partner with some of these vendors. When you click a link and make a purchase, we may receive a small payment, which helps us keep the site running.

This model of the AirPods Pro launched in September 2025 and has 2x better Active Noise Cancellation than the previous generation, better audio quality, a revised fit that's meant to improve comfort and stability, Live Translation for in-person conversations, and heart rate sensing for workouts.

$49 OFFAirPods Pro 3 for $199.99

You can also get the AirPods 4 for $99.00, down from $129.00. This is a second-best price on the AirPods 4, which is the base model without Active Noise Cancellation. Amazon provides an April 23 estimated delivery date for free shipping, with faster delivery options for Prime members.

$30 OFFAirPods 4 for $99.00

Head to our full Deals Roundup to get caught up with all of the latest deals and discounts that we've been tracking over the past week.



Deals Newsletter

Interested in hearing more about the best deals you can find in 2026? Sign up for our Deals Newsletter and we'll keep you updated so you don't miss the biggest deals of the season!




Related Roundup: Apple Deals
This article, "AirPods Weekend Deals Include AirPods Pro 3 for $199.99 and AirPods 4 for $99" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Apple has released more than 12 new products and accessories this year. The company kicked things off by unveiling a second-generation AirTag in January, and it unveiled a wide range of devices in March, including the MacBook Neo, iPhone 17e, two new Studio Display models, updated iPad Air models with the M4 chip, and more.


Here is everything that Apple has released in 2026 so far:Apple Unveils New AirTag With Longer Range, Louder Speaker, and More
Apple Introduces New Black Unity Apple Watch Band
Apple Announces iPhone 17e With A19 Chip, MagSafe, and More
Apple Unveils iPad Air With M4 Chip, Increased RAM, Wi-Fi 7, and More
Apple Announces MacBook Air With M5 Chip and 512GB Base Storage
Apple Unveils MacBook Pro Featuring M5 Pro and M5 Max Chips
Apple Updates Studio Display With Thunderbolt 5 and More
Apple Introduces All-New Studio Display XDR: 120Hz, Mini-LED, and More
Apple Announces $599 'MacBook Neo' With A18 Pro Chip
Apple Announces AirPods Max 2 With H2 Chip and More
Apple's Special-Edition Nike Powerbeats Pro 2 Now Available
Apple Releases iPhone Cases, Apple Watch Bands, and Crossbody Strap in New ColorsThe new AirTag is equipped with a second-generation Ultra Wideband chip, enabling the Precision Finding feature to work up to 50% farther away from an item compared to the previous-generation model, according to Apple. The new AirTag also has an upgraded Bluetooth chip for improved overall range outside of Precision Finding mode.

With an updated internal design, the new AirTag features a 50% louder speaker compared to the previous-generation model, according to Apple.

Apple said the Black Unity Connection Braided Solo Loop for the Apple Watch features the colors of the Pan-African flag in honor of Black History Month.

iPhone 17e features the same overall design as the iPhone 16e, but it gains Apple's A19 chip, MagSafe for magnetic wireless charging and magnetic accessories, Apple's second-generation C1X modem for faster 5G, and a doubled 256GB of base storage. In the U.S., the iPhone 17e starts at $599, just like the iPhone 16e did.

The new iPad Air's key upgrades include Apple's M4 chip, an increased 12GB of RAM, Apple's N1 chip with Wi-Fi 7 support, and the C1X modem in cellular models.

The MacBook Air received a faster M5 chip, and a doubled 512GB of base storage, but the starting price increased from $999 to $1,099 as a result of a 256GB configuration being dropped. With the N1 chip, the MacBook Air now has Wi-Fi 7 and Bluetooth 6, and it now comes with Apple's 40W Dynamic Power Adapter with 60W Max.

The higher-end 14-inch and 16-inch MacBook Pro models finally received M5 Pro and M5 Max chips, plus up to twice as fast SSD speeds and a doubled 1TB of base storage. Battery life has increased slightly across all of the models, and the N1 chip extends to the MacBook Pro line now for Wi-Fi 7 and Bluetooth 6 support.

The regular Studio Display gained Thunderbolt 5 support and improved speakers, and the camera now supports Desk View. There is also an all-new, higher-end Studio Display XDR that gained all of those benefits, plus bigger improvements such as a 120Hz refresh rate, mini-LED backlighting, increased brightness, and more.

The colorful MacBook Neo starts at just $599 in the United States, and at an even lower $499 for college students. Available in Blush, Citrus, Indigo, and Silver, the MacBook Neo is powered by the A18 Pro chip from the iPhone, and it is equipped with a 13-inch display, up to 512GB of storage, and a non-configurable 8GB of RAM.

AirPods Max 2 have a handful of upgrades over the previous AirPods Max, including Apple's H2 chip, increased active noise cancellation, improved sound quality, and features such as Adaptive Audio, Conversation Awareness, Voice Isolation, and Live Translation. Plus, the Digital Crown has a new Camera Remote function.

The special-edition Nike Powerbeats Pro 2 are the same as the regular Powerbeats Pro 2, except they have a two-tone design consisting of black and Nike's signature Volt neon green-yellow color. The earbuds have both Nike and Beats logos.

What's Next?

Beyond the usual annual updates to iPhones and Apple Watches, Apple's all-new smart home hub is finally expected to launch later this year, once the more personalized version of Siri arrives. We are also expecting a foldable iPhone, a MacBook Pro with an OLED display, and long-awaited updates to the Apple TV and HomePods this year.

Related Reading: Apple to Launch These 15+ New Products Later This Year
This article, "Apple Has Released These 12 New Products This Year" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Grinex, a Kyrgyzstan-incorporated cryptocurrency exchange sanctioned by the U.K. and the U.S. last year, said it's suspending operations after it blamed Western intelligence agencies for a $13.74 million hack. The exchange said it fell victim to what it described as a large-scale cyber attack that bore hallmarks of foreign intelligence agency involvement. This attack led to the theft of over 1View the full article
Threat actors are exploiting security flaws in TBK DVR and end‑of‑life (EoL) TP-Link Wi-Fi routers to deploy Mirai-botnet variants on compromised devices, according to findings from Fortinet FortiGuard Labs and Palo Alto Networks Unit 42. The attack targeting TBK DVR devices has been found to exploit CVE-2024-3721 (CVSS score: 6.3), a medium-severity command injection vulnerability affectingView the full article
Apple is working on an updated version of the Mac Studio that's expected at some point in 2026, and with supplies of existing machines running low, we thought we'd highlight what's next for Apple's most powerful desktop machine.



Design

We're not expecting Apple to redesign the ‌Mac Studio‌, and there haven't been rumors of a design update. The ‌Mac Studio‌ will continue to have an Apple TV or Mac mini-like squircle design with rounded corners.

The ‌Mac Studio‌ is a much more compact desktop than the now-discontinued Mac Pro, measuring in at 3.7 inches tall and 7.7 inches wide. The current ‌Mac Studio‌ supports Thunderbolt 5, and the next version will too. There haven't been rumors of any changes to the port configuration.

M5 Max and M5 Ultra Chips

We're expecting the ‌Mac Studio‌ to adopt M5 Max and M5 Ultra chips. Apple already debuted the M5 Max with the MacBook Pro models that came out in March, but the M5 Ultra is still a mystery.

The M5 Max has up to an 18-core CPU and 40-core GPU, with up to 614GB/s memory bandwidth. Apple says the M5 Max offers up to 30 percent faster CPU performance for pro workloads than the M4 Max. The M5 Ultra will bring even better performance, and historically, Apple's Ultra chips have been two Max chips linked together.

The M5 Ultra could have up to a 36-core CPU and up to an 80-core GPU.

The current ‌Mac Studio‌ has a mix of M4 Max and M3 Ultra chips because Apple didn't design an M4 Ultra chip, but the M5 cycle is expected to unify the ‌Mac Studio‌ chip options to a single generation.

Faster SSD

The M5 ‌MacBook Pro‌ models were updated with a faster SSD, so the ‌Mac Studio‌ could get the same SSD improvements. Apple says the updated SSD in the M5 ‌MacBook Pro‌ models is up to 2x faster than the SSD in the M4 MacBook Pro models.

RAM

Because of global RAM shortages, Apple discontinued the 512GB Mac Studio earlier this year. The current machine maxes out at 256GB RAM, and that's a limitation we could see with the next ‌Mac Studio‌ too.

The M5 Max ‌MacBook Pro‌ supports up to 128GB RAM, so that will be the ceiling for the M5 Max ‌Mac Studio‌. The M5 Ultra model could support up to 256GB.

RAM shortages are expected to continue throughout the year, because companies that manufacture memory are prioritizing orders from companies building AI servers that require huge amounts of RAM. There is little supply left for consumer products, which has caused prices to increase. Many PC and smartphone makers have raised their prices on existing machines, but Apple hasn't changed ‌Mac Studio‌ pricing.

Mac Studio Shortages

Apple stopped accepting orders for some ‌Mac Studio‌ configurations in early April, and they are out of stock. ‌Mac Studio‌ configurations with 128GB or 256GB of RAM can no longer be ordered, but that's not necessarily a sign that a new machine is launching imminently.

Apple has been dealing with soaring DRAM and NAND flash prices, and the fact that only models with higher RAM are unavailable suggests it's a supply issue and not an indication of a refresh.

Pricing

There haven't been rumors of pricing increases for the ‌Mac Studio‌, so it could continue to start at $1,999, but Apple has raised the prices of other Macs this year.

Starting prices for the M5 MacBook Air and the M5 Pro and M5 Max ‌MacBook Pro‌ models increased, though Apple did soften the blow with higher starting storage. It's possible the ‌Mac Studio‌ price will go up, and the entry-level machine will start with a 1TB SSD instead of a 512GB SSD.

No More Mac Pro

Apple discontinued the Mac Pro in late March, so the ‌Mac Studio‌ is now Apple's only pro desktop option. There was a lot of overlap between the Mac Pro and the ‌Mac Studio‌, with the Mac Pro only offering PCIe expansion slots as a differentiating feature.

The ‌Mac Studio‌, Mac mini, and iMac are Apple's desktop Mac options.

Release Timing

It's not clear when we might see a refreshed ‌Mac Studio‌ because of the shortages that Apple is facing. It's possible Apple is holding RAM supply for new models and that's why some current versions are out of stock, but it's also possible things are so dire that Apple will need to hold the ‌Mac Studio‌ launch.

The next logical time for a new ‌Mac Studio‌ to be introduced is WWDC. Apple has introduced new Macs at WWDC in the past, but there isn't always new hardware. The WWDC keynote is being held on June 8, and if a new ‌Mac Studio‌ is coming around the first half of 2026, that's likely when it will be announced.

If an updated ‌Mac Studio‌ doesn't come at WWDC, we're looking at a refresh later in the year. Macs aren't often updated in September, so October or November are stronger possibilities.Related Roundup: Mac StudioBuyer's Guide: Mac Studio (Caution)Related Forum: Mac Studio
This article, "5+ Things to Know About the Next Mac Studio" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Maintainers of Thymeleaf, a widely used template engine for Java web applications, fixed a rare critical vulnerability that allows unauthenticated attackers to execute malicious code on servers.
The vulnerability, tracked as CVE-2026-40478, is rated 9.1 on the CVSS severity scale and is described as a Server-Side Template Injection (SSTI) issue. Thymeleaf has a sandbox-like protection that prevents user input from executing dangerous expressions, but this flaw allows attackers to bypass those protections.
“Although the library provides mechanisms to prevent expression injection, it fails to properly neutralize specific syntax patterns that allow for the execution of unauthorized expressions,” the developers said in their advisory. “If an application developer passes unvalidated user input directly to the template engine, an unauthenticated remote attacker can bypass the library’s protections to achieve Server-Side Template Injection (SSTI).”
Thymeleaf is the de facto template engine in the Java Spring ecosystem and Spring is the most popular framework for developing web applications in Java. Since Java is still widely used for development in enterprise environments, this vulnerability has the potential to impact numerous business applications.
All Thymeleaf versions before 3.1.4.RELEASE are affected and no work-around exists. Companies are advised to identify which of their applications use Thymeleaf and upgrade to 3.1.4.RELEASE as soon as possible.


Straightforward exploitation
According to researchers from application security testing firm Endor Labs, exploitation is straightforward with no special privileges or conditions required. Attackers just need to control input that reaches Thymeleaf’s expression engine, which is a common pattern in web applications.
Endor Labs notes in their report that Thymeleaf has defense-in-depth layers to block dangerous expressions and in this case two of them failed. For example, a string check scanned the expression text for dangerous patterns, such as the new keyword followed by an ASCII space, T (Spring Expression Language type references) and @ (SpEL bean references in some code paths). However, the check only looked for ASCII space 0x20 characters, but the SpEL’s parser also accepts tab (0x09), newline (0x0A), and other control characters between new and the class name.
Another policy blocked classes that start with java.* from being used inside T() type references, but did not block types from org.springframework.*, ognl.*, or javax.*.
“Since typical Spring applications have spring-core on the classpath, classes like org.springframework.core.io.FileSystemResource were freely constructable, and that class can create arbitrary files on disk,” the researchers said.
As such, Endor Labs was able to easily build a proof-of-concept exploit by combining the two: use a tab character after new and calling the org.springframework.core.io.FileSystemResource class to create a file on disk.
“With the right class, an attacker can escalate from file creation to full remote code execution, for example, instantiating a ProcessBuilder wrapper from a third-party library, or leveraging Spring’s own GenericApplicationContext to register and invoke arbitrary beans,” the researchers explained.
Vulnerabilities in the Java Spring Framework itself have been exploited in the past to compromise web servers, so it’s likely that an easy-to-exploit flaw such as this one will be quickly adopted by attackers.
View the full article
India will not require smartphone makers like Apple and Samsung to preload devices with a state-owned biometric identification app, reports Reuters.


The Unique Identification Authority of India asked the IT ministry to start talks with Apple and other tech companies about the possibility of mandatory preinstallation of the Aadhaar identity app, but the IT ministry told Reuters today that it reviewed the proposal and is "not in favor" of mandating the app's preinstallation.

Aadhaar is a 12-digit identity number that residents of India can apply for, and it has been issued to more than 1.34 billion residents. The number is linked to an individual's image, fingerprints, and iris scans, and it serves as proof of residence. It is used for government benefits, banking, taxes, mobile connections, and more.

The Identification Authority said that the IT ministry consulted with "stakeholders from the electronics industry" before deciding not to proceed with the proposal to preload Aadhaar. India's government has asked smartphone makers to preinstall state-owned apps on devices six times over the last two years, according to Reuters. Smartphone makers like Apple have thwarted all requests.

Late last year, India's Department of Communications gave smartphone companies 90 days to start preinstalling the Sanchar Saathi government app on all new devices sold in the country. Sanchar Saathi is a government app that lets users block stolen devices, report fraudulent calls, and verify second-hand phones. Apple told government officials that it would not comply with the requirement because of privacy and security concerns, and the government dropped the issue.

Apple told India the same thing about the Aadhaar app, informing the IT ministry that it had safety and security concerns about preloading apps.Tag: India
This article, "India Won't Require Apple to Preinstall Government ID App on iPhones" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Cisco admins are scrambling to patch a critical flash memory overflow vulnerability in over 200 Cisco Systems IOS XE-based models of wireless access points (APs), caused by a recent flawed software update.
If the issue is not corrected quickly, the AP’s memory will become so flooded that new software updates will be blocked and the AP rendered insecure, or possibly even bricked.
The problematic library update causes a specific log file in the flash memory of affected access points to grow by about 5MB a day. Over time, Cisco said in an advisory this week, this could consume “a big portion” of the available memory space.
“The longer an AP runs the affected software, the higher the probability that a software download will fail due to insufficient space,” the advisory says.
Analyst Rob Enderle of the Enderle Group said that ‘buggy logs’ are a common trope in networking. But, he added, “this particular case is dangerous because it targets the physical limitations of flash memory on hardware that is notoriously difficult to access once it becomes bricked or enters a boot loop. In the world of networking, this is a high-impact, medium-rarity event.”
He explained, “what makes this unique is the Catch-22 it creates. To fix the bug, you must upgrade the software. However, the bug itself prevents the device from having enough space to download the fix. If an admin waits too long, the device may require manual, physical intervention or become permanently stuck in a boot loop.”
Johannes Ullrich, dean of research at the SANS Institute, called this particular problem uncommon, although he acknowledged flash memory space in IoT devices like access points is limited and may fill up from time to time.
“But,” he added, “there is a bigger issue: A competent [vendor] vulnerability management program must always include verification that the patch was indeed applied as expected. There are many reasons why a patch may not be applied correctly, and this is just one way a patch may fail to apply.”
Kellman Meghu, CTO of incident response firm DeepCove Cybersecurity, said overflowing a fixed device’s memory due to a bug “would have me rather annoyed with this vendor. This is very rare in my experience, and something that was an issue way back when storage costs were a factor. I would expect my vendor to be able to clean and manage storage for fixed devices. If this device is supported, this would be an RMA [return merchandise authorization] or fix issue, and expectation [for vendor action] would be right away/proactive.”
[Related content: Cisco Webex SSO flaw]
Affected are access points running IOS XE versions 17.12.4, 17.12.5, 17.12.6, and 17.12.6a. These include Cisco Catalyst 9130AX series APs, as well as 9130AX models with a Stadium Antenna, Catalyst 91361, 91621, 9163E, 91641, 9166D1, and IW9167 series APs, and Wi-Fi 6 Outdoor APs,
There are two ways for admins to solve the problem: Download a Cisco tool called WLANPoller, which automates execution of a fix across multiple APs, or manually use the show boot command on each device to look into the boot partition and see if it has enough space for an upgrade. Greater detail on the necessary action is in the Cisco advisory.
Cisco says a mandatory precheck of an AP’s status should be run as close to the scheduled maintenance window as possible. But because the affected log file grows daily, Enderle said, “you sure don’t want to wait until [AP] failure.” 
Manual fixing will probably take 5-10 minutes of active work per AP, he cautioned, plus another 15-20 minutes soak time to make sure the fix takes if the AP does have room for the upgrade. But if the AP has space problems, the time per device could jump to around 20-45 minutes.
And if the AP has failed, then it would take one to two hours to fix, he added, and would need physical access to the device.
Using WLANPoller will make the process faster, he added.
Enderle said that if an admin finds an AP whose flash memory is already too full to upgrade, a reboot sometimes clears temporary buffers or allows a small window for a manual transfer. However, with this specific log bug, a reboot may not be enough if the file is persistent. Admins should contact Cisco for the emergency cleanup script before attempting a mass push, he said.
Ultimately, Enderle said, the pushing of a flawed update is a supply chain integrity issue. CSOs should ask their teams, ‘Do we have monitoring in place for hardware health metrics (CPU, RAM, Flash), or only for ‘Up/Down’ status?’ An AP that is Up but has 0MB of free flash memory is a liability, he said.
CSOs should look at this vulnerability as a Critical Availability Risk, he added. “While it isn’t a data breach, the potential for a site-wide Wi-Fi outage (due to failed automated updates or boot loops) can halt business operations,” he noted, adding that CSOs should also enforce a policy where even “minor library updates” are still tested in a lab environment for seven to 14 days. “This 5MB/day log growth would likely have been caught in a lab before hitting a production fleet of 5,000 APs,” Enderle said.
This article originally appeared on NetworkWorld.
View the full article
Anthropic today launched Claude Design, a new AI product for creating designs, prototypes, slides, and more. Claude Design uses Opus 4.7, a new AI model that was introduced earlier this week.


Opus 4.7 is Anthropic's most capable vision model, and it can see images in greater resolution. Anthropic says that it is "more tasteful and creative" when doing professional tasks. It is able to create higher-quality interfaces, slides, and docs, making it ideal for Claude Design. Claude Design was developed to allow founders, product managers, and marketers without a design background to create visuals for sharing an idea.

Claude Design is able to mock up an initial design after being provided with a prompt, and from there, designers can make revisions through conversation, comments, direct edits, and custom sliders made by Claude. Anthropic says that teams have been using Claude Design for realistic prototypes, wireframes and mockups, design explorations, pitch decks, presentations, social media assets, and more.

Working with Claude Design starts with brand assets, which Claude can get from the user's design files and codebase. Projects will use brand colors, typography, and other components, plus users can use a web capture tool to pull elements directly from their brand's website. Claude Design is not an image generator like Gemini's Nano Banana or ChatGPT, but it is similar to AI assistants that Adobe and Canva have rolled out.

There are included collaboration tools so multiple members of an organization can access and edit a design, and content created by Claude can be exported anywhere with support for Canva, PDF, PPTX, and standalone HTML files. Designs that are ready to build can be handed off to Claude Code, and Anthropic plans to make it easier to build integrations with Claude Design in the coming weeks.

Claude Design is available as a research preview for Claude Pro, Max, Team, and Enterprise subscribers. It is rolling out to users gradually throughout the day.Tag: Anthropic
This article, "Anthropic Debuts Claude Design for Creating Prototypes, Pitch Decks, and Mockups" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Amazon this week announced plans to acquire Globalstar, the satellite company that powers Apple's satellite features on the iPhone 14 and newer and the Apple Watch Ultra 3. In turn, Amazon announced that it has signed an agreement with Apple to provide satellite connectivity for current and future iPhone and Apple Watch features.


The transaction, subject to regulatory approval, is expected to close in 2027. At that point, Apple's features will be powered by Amazon Leo satellites.

Apple's current satellite features:Emergency SOS via satellite
Find My via satellite
Roadside Assistance via satellite
Messages via satellite All of the features are currently free to use in supported areas without Wi-Fi or cellular connectivity. Availability varies by country.

There were already five more iPhone satellite features or enhancements rumored to be in the works, even before Amazon announced this deal with Apple. At least some of the improvements may be part of iOS 27, which is expected to be available in beta starting in June and widely released in September this year.

Those enhancements are as follows:5G via satellite (may be exclusive to iPhone 18 Pro and iPhone 18 Pro Max)
Apple Maps via satellite
Photos support for Messages via satellite
Third-party apps in the App Store will be able to integrate Apple's satellite features
The ability to connect an iPhone to a satellite without pointing the device toward the skyAmazon's announcement mentioned future features, too, so Apple's suite of satellite functions should expand even more over the coming years.Related Roundup: iOS 27Tag: iPhone Satellite Features
This article, "iPhones to Get These New Satellite Features" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
It was another busy week of Apple news and rumors, with upcoming Apple product categories like the foldable iPhone and smart glasses featuring prominently in the news.


This week also saw continued tightening of supplies of the Mac mini and Mac Studio, while Amazon announced it will be acquiring Apple's satellite partner that supports a variety of Apple services for users off the terrestrial grid, so read on below for all the details on these stories and more!

Top Stories

'iPhone Ultra' Will Solve Two Key Problems

Apple reportedly plans to unveil a foldable iPhone in September, with one leaker on Chinese social media claiming the device will be called the "iPhone Ultra."


Now, according to Bloomberg's Mark Gurman, the device will have improved screen quality and overall durability compared to competing foldables. "Apple engineers believe they've solved problems with screen quality and overall durability, two long-running flaws with phones in this category," he said.

Rumors on launch timing have been all over the place, with some claiming the foldable iPhone will be available in September alongside the iPhone 18 Pro models while others suggest there could be a delay in availability that might extend even into early 2027. The latest rumor suggests, however, that while production is behind schedule, Apple is still aiming for a fall 2026 launch.

For more on the iPhone Ultra, check out last week's episode of The MacRumors Show.

Apple Stops Accepting Orders for Some Mac Mini and Mac Studio Models

Amid severe global RAM chip shortages and rumors of updated models, some Mac mini and Mac Studio configurations are now completely out of stock on Apple's online store in the U.S.


Mac mini configurations with an upgraded 32GB or 64GB of RAM and Mac Studio configurations with an upgraded 128GB or 256GB of RAM are listed as "currently unavailable" on the storefront, meaning they can no longer be ordered at all.

Other configurations that remain available continue to face lengthy shipping delays, with estimated delivery time frames ranging from one to three months. Last month, Apple entirely removed the Mac Studio's 512GB of RAM option, but supplies are clearly now tightening even further.

Apple Testing Four Smart Glasses Styles Made of High-End Materials

Apple is developing at least four different styles of smart glasses, and the company is betting that their superior design will set them apart from rival products, according to Bloomberg's Mark Gurman.


Writing in his latest Power On newsletter, Gurman says that Apple's latest designs are made from a high-end acetate material, which is "more durable and luxurious" than the standard plastic used by most existing brands. In Gurman's words, the designs in testing include:
A large rectangular frame, reminiscent of Ray-Ban Wayfarers
A slimmer rectangular design, similar to the glasses worn by Apple CEO Tim Cook
Larger oval or circular frames
A smaller, more refined oval or circular option

Apple and Amazon Ink Satellite Deal Amid Amazon's Takeover of Globalstar

Amazon has announced that it will acquire Globalstar, which currently serves as Apple's exclusive satellite connectivity partner, but it appears Apple satellite services will be preserved and will perhaps expand under the deal.


Alongside the acquisition, Amazon and Apple have signed a separate agreement for Amazon's Leo satellite network to power existing iPhone and Apple Watch satellite features, including Emergency SOS, Messages via satellite, Find My, and Roadside Assistance via satellite.

Amazon said it will continue supporting iPhone and Apple Watch models that use Globalstar's existing and upcoming low Earth orbit constellation. Amazon also said it will work with Apple on future satellite services running on the expanded Leo network.

Check Who's Using Your iPhone Hotspot Data

If you regularly share your iPhone's data connection with your laptop or iPad, or let family members piggyback on your device's data, you'll be glad to learn that Apple recently made it a lot easier to keep tabs on who's burning through your monthly allowance.


In a welcome change with the release of iOS 26.4, Apple has moved Personal Hotspot data usage info out of its previous hiding spot and put it in a much more convenient location right in the Personal Hotspot menu.

Apple Highlights Photos Shot on iPhone During NASA's Mission to Moon

Astronauts aboard NASA's Orion spacecraft used the iPhone 17 Pro Max to take selfies of themselves with the Earth in the background during the Artemis II mission around the far side of the Moon earlier this month.


Now that the crew members have safely returned to Earth, Apple's CEO Tim Cook and marketing chief Greg Joswiak have both turned to social media to congratulate them on their successful mission and highlight the iPhone's involvement.

"You captured the wonders of space and our planet beautifully, taking iPhone photography to new heights, and we're grateful you shared it with the world," wrote Cook. "Your work continues to inspire us all to think different. Welcome home!"

MacRumors Newsletter

Each week, we publish an email newsletter like this highlighting the top Apple stories, making it a great way to get a bite-sized recap of the week hitting all of the major topics we've covered and tying together related stories for a big-picture view.

So if you want to have top stories like the above recap delivered to your email inbox each week, subscribe to our newsletter!Tag: Top Stories
This article, "Top Stories: 'iPhone Ultra' Rumors, Mac Mini and Mac Studio Shortages, and More" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
On this week's episode of The MacRumors Show, we talk through Apple's upcoming overhaul of the iPad mini and iPad Air, looking at the future of the product lineup as a whole.

Subscribe to The MacRumors Show YouTube channel for more videos
The headline upgrade for the ‌iPad mini‌ 8 is a switch from LCD to OLED display technology. The device is expected to use a single-stack LTPS panel, which is dimmer than the tandem OLED in the iPad Pro, but a substantial step up from the current display. The screen will also likely grow from 8.3 to 8.7 inches, and ProMotion is a possibility.

On the chip, sources disagree. Code Apple accidentally published in August pointed to the A19 Pro, but other evidence suggests the device will use the unreleased A20 Pro chip instead. The N1 and C1X chips are also highly likely to be present.

Bloomberg's Mark Gurman reported that Apple is also working on a more water-resistant design, which would make new the ‌iPad mini‌ the first to carry an official IP rating. Apple is said to have developed a vibration-based speaker system that eliminates traditional speaker holes, removing a primary path for water ingress.

The scale of the upgrades strongly suggests a redesigned, thinner chassis to accommodate them. Gurman says the upgrades could push the price up by as much as $100 to around $599. The leaker known as "Instant Digital" has said the device will launch in the second half of 2026 at the earliest.

Apple is also expected to update the ‌iPad Air‌ in early 2027, with the headline change similarly being a switch to OLED. Like the ‌iPad mini‌ 8, the next-generation ‌iPad Air‌ is expected to use a single-stack LTPS panel supplied by Samsung, keeiping costs down relative to the tandem OLED in the ‌iPad Pro‌. Arriving over six years after the device's last redesign, it is also likely to feature a new design similar to the ‌iPad mini‌, along with the M5 chip.

The next ‌iPad Pro‌ is expected in spring 2027, with an M6 chip and a vapor chamber cooling system similar to the one Apple introduced in the iPhone 17 Pro, but no design changes are rumored. With the ‌iPad Air‌ set to close the gap significantly by adopting OLED and a thinner design, the Pro's key differentiators will narrow considerably. A more transformative reason to choose the Pro may not arrive until Apple launches its long-rumored foldable iPad, which Gurman says will feature an 18-inch display. The device has faced development hurdles around weight and display technology and is now expected no earlier than 2029, with a price potentially reaching $3,900, up to three times the cost of the current 13-inch ‌iPad Pro‌.

The MacRumors Show has its own YouTube channel, so make sure you're subscribed to keep up with new episodes and clips.

Subscribe to The MacRumors Show YouTube channel!

You can also listen to ‌The MacRumors Show‌ on Apple Podcasts, Spotify, Overcast, or other podcast apps. You can also copy our RSS feed directly into your player.



If you haven't already listened to the previous episode of The MacRumors Show, catch up to hear our discussion about all of the rumors surrounding Apple's upcoming foldable iPhone, now said to be called the "iPhone Ultra," which is shaping up to be a comprehensive redesign unlike anything the company has shipped before.

Subscribe to ‌The MacRumors Show‌ for new episodes every week, where we discuss some of the topical news breaking here on MacRumors, often joined by interesting guests such as Kayci Lacob, Kevin Nether, John Gruber, Mark Gurman, Jon Prosser, Luke Miani, Matthew Cassinelli, Brian Tong, Quinn Nelson, Jared Nelson, Eli Hodapp, Mike Bell, Sara Dietschy, iJustine, Jon Rettinger, Andru Edwards, Arnold Kim, Ben Sullins, Marcus Kane, Christopher Lawley, Frank McShan, David Lewis, Tyler Stalman, Sam Kohl, Federico Viticci, Thomas Frank, Jonathan Morrison, Ross Young, Ian Zelbo, and Rene Ritchie.

‌The MacRumors Show‌ is on X @MacRumorsShow, so be sure to give us a follow to keep up with the podcast. You can also email us at [email protected] or head over to The MacRumors Show forum thread. Remember to rate and review the podcast, and let us know what subjects and guests you would like to see in the future.Tag: The MacRumors Show
This article, "The MacRumors Show: What's Next for the iPad" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Photos have been making the rounds on Chinese social media today showing an Honor-branded advertising truck parked directly in front of Apple Canton Road store in Hong Kong, promoting the company's new Honor 600 series smartphone.


The truck's ad features the slogan "It's our HONOR" alongside the phrase "orange to orange," which appears to be a play on the English idiom "apples to apples" – referring to a like-for-like comparison. The slogan is paired with an image of the Honor phone, in a finish that bears more than a passing resemblance to the iPhone 17 Pro's Cosmic Orange.

It's a brazen stunt for a brand that spun off from Huawei in 2020 before being sold off to another entity to bypass U.S. sanctions. Using Apple's retail store as a backdrop to pitch your rival device with a similar color is one thing, but when the design is arguably a shameless copy, you're definitely out of ideas.

Apple is unlikely to make a big stink about such guerrilla marketing, as it would only amplify it. And as they say, imitation is the sincerest form of flattery.Tag: Apple Store
This article, "Apple Store Becomes Backdrop for Honor's Brazen Hong Kong Ad Stunt" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
China's smartphone shipments fell 4% year over year in the first quarter of 2026, according to data from Counterpoint Research, with Apple delivering the strongest growth among the top six brands.



Counterpoint's Market Monitor Tracker attributed the decline primarily to a high base effect from last year's government subsidy program and rising component costs. Counterpoint noted that February's Lunar New Year promotions provided a slight boost, but said the "magnitude of these discounts was hampered by a sharp increase in memory costs." Rising costs are already driving up retail prices on both new and used devices, and the pressure is expected to continue through the second quarter.

Apple rose to second place in the market with shipments up 20% year over year, driven by strong iPhone 17 series demand, promotional price cuts, and government subsidies. Counterpoint says Apple is best positioned among manufacturers to navigate the ongoing global memory crunch, supported by its premium product portfolio and supply chain management. The firm expects Apple to absorb rising costs internally in the near-to-medium term and expand its market share as a result. The first quarter result extends a strong run for Apple in China; the company reclaimed the top spot in the country in the fourth quarter of 2025 with shipments up 28% year over year, and recorded a 23% sales increase in the first nine weeks of 2026.

Huawei led with a 20% market share, its highest since the fourth quarter of 2020, with shipments up 2% year over year, aided by domestic supplier relationships that cushion the impact of rising memory costs. OPPO ranked third following the reintegration of realme, with OnePlus rising 53% year over year on the Ace 6 and Turbo 6 series, though OPPO's decision to raise prices on older models in March has weighed on demand. vivo grew 2% year over year on mid-to-low-end strength, while Xiaomi was the sharpest decliner, falling 35% year over year as its core models underperformed the previous generation.

Counterpoint warned that manufacturers broadly face a "double hit" of shrinking shipments and thinning margins, and forecast that China smartphone shipments will decline 9% for the full year. Apple, by contrast, is expected to use the cost pressure to its advantage, absorbing memory price increases internally while rivals are forced to raise prices and cede ground.Tags: China, Counterpoint
This article, "Apple Leads Top Brands for China Smartphone Growth as Market Declines" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Apple plans to release iPad mini and MacBook Pro models with OLED displays this year, according to industry sources who spoke to South Korea's ETNews.


The current iPad mini and MacBook Pro models have LCD displays with either LED or mini-LED backlighting. The move to OLED technology would result in improved image quality, thanks to richer colors and higher contrast ratio with true blacks.

Samsung will supply the OLED displays for both devices, the report said.

All of the iPhone, Apple Watch, and iPad Pro models that Apple sells today are already equipped with OLED displays, excluding refurbished models.

Other new features rumored for the next iPad mini include an A19 Pro or an A20 Pro chip, a vibration-based speaker system, and a water-resistant design. Apple will likely announce the device in September or October this year.

For the 14-inch and 16-inch MacBook Pro, other new features rumored include M6 Pro and M6 Max chips, a touch screen, a Dynamic Island, and a thinner design. Apple reportedly plans to release the laptops towards the end of 2026, although there is a chance that the launch will not happen until early 2027.

The report said the iPad Air will also receive an OLED display next year.Related Roundups: iPad mini, MacBook ProTags: ETNews, OLEDBuyer's Guide: iPad Mini (Caution), MacBook Pro (Buy Now)Related Forums: iPad, MacBook Pro
This article, "Apple to Upgrade These Two Devices With OLED Displays Later This Year" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
This week we saw some heavy-hitter Apple deals arrive for the M5 MacBook Air and AirPods Pro 3, with record low prices still available for both of these devices on Amazon. Below, you'll also find great deals on Apple Watch Series 11 and the new AirPods Max 2.

Note: MacRumors is an affiliate partner with some of these vendors. When you click a link and make a purchase, we may receive a small payment, which helps us keep the site running.

M5 MacBook Air


What's the deal? Take $150 off M5 MacBook Air
Where can I get it? Amazon
Where can I find the original deal? Right here
$150 OFF13-inch M5 MacBook Air (16GB/1TB) for $1,149.00
$150 OFF15-inch M5 MacBook Air (512GB) for $1,149.00

Amazon has a few record low prices on the new M5 MacBook Air this week, with $150 off select models of the brand new notebook. Stock has begun dwindling on these notebooks and we're no longer tracking an all-time low price on the 512GB 13-inch M5 MacBook Air, but most other configurations have availability.

AirPods Pro 3


What's the deal? Take $49 off AirPods Pro 3
Where can I get it? Amazon
Where can I find the original deal? Right here
$49 OFFAirPods Pro 3 for $199.99

Amazon this week brought back an all-time low price on the AirPods Pro 3, available for $199.99, down from $249.00.

AirPods Max 2


What's the deal? Take $19 off AirPods Max 2
Where can I get it? Amazon
Where can I find the original deal? Right here
$19 OFFAirPods Max 2 for $529.99

Apple's new AirPods Max 2 launched earlier this month, and Amazon is one of the only retailers offering a discount on the headphones. You can get the Midnight and Starlight color options for $529.99 on Amazon, down from $549.00.

Apple Watch Series 11


What's the deal? Take $100 off Apple Watch Series 11
Where can I get it? Amazon
Where can I find the original deal? Right here
$100 OFFApple Watch Series 11 (42mm GPS) for $299.00
$100 OFFApple Watch Series 11 (46mm GPS) for $329.00

Amazon this week has all-time low prices on the Apple Watch Series 11, with $100 discounts across numerous models of the smartwatch. This sale includes nearly every aluminum model of the Series 11 on sale at a record low price.

If you're on the hunt for more discounts, be sure to visit our Apple Deals roundup where we recap the best Apple-related bargains of the past week.



Deals Newsletter

Interested in hearing more about the best deals you can find in 2026? Sign up for our Deals Newsletter and we'll keep you updated so you don't miss the biggest deals of the season!




Related Roundup: Apple Deals
This article, "Best Apple Deals of the Week: M5 MacBook Air $150 Off Deals, Plus Sales on AirPods Pro 3 and AirPods Max 2" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
The US government is preparing to authorize a version of Anthropic’s Claude Mythos model for use by major US federal agencies, amid concerns that the AI model could rapidly spot cybersecurity vulnerabilities and offer the ability to exploit them.
Federal Chief Information Officer Gregory Barbaccia at the White House Office of Management and Budget (OMB) told officials at Cabinet departments on Tuesday that the OMB was setting up protections to allow federal agencies to begin using the model, reported Bloomberg, citing an internal memo.
The memo did not commit specific agencies to deployment or provide a timeline, the report said.
“We’re working closely with model providers, other industry partners, and the intelligence community to ensure the appropriate guardrails and safeguards are in place before potentially releasing a modified version of the model to agencies,” Barbaccia wrote in the email, according to the report.
The OMB move comes while the Department of Defense’s supply-chain risk designation against Anthropic, issued on March 3, remains in force. The D.C. Circuit refused to stay the designation on April 8, keeping Anthropic barred from defense contracts while civilian agencies are now being positioned for access.
The White House and Anthropic did not immediately respond to requests for comment.
Defining the guardrails
The memo’s reference to a modified version of the model points to open questions about what agency deployment would actually look like. Anthropic announced Claude Mythos Preview on April 7 under Project Glasswing, a controlled-access program for select technology and financial organizations.
The company then said the model identified thousands of zero-day vulnerabilities across every major operating system and browser in internal testing and stated it did not plan to make the model generally available.
“For a federal deployment to be defensible, the modifications must cover specific assurance dimensions,” said Neil Shah, VP for research and partner at Counterpoint Research. “The software code base being scanned should remain sovereign within an isolated and air-gapped environment, and the data should not be used to retrain the base model.” Additional steps could include transparency requirements and human-in-the-loop review before any bug fix is applied, he said, to make the deployment more controlled.
Enterprise implications
Those same assurance questions translate directly to enterprise procurement. The OMB move signals that federal cyber defense is pivoting toward frontier models that can find vulnerabilities faster than human teams can patch them, and the rift between the Pentagon and the White House carries a lesson for private-sector buyers, Shah said.
“The rift between the two government entities is a lesson on how important it is to control the deployment of potent AI capabilities which could be misused,” he said, calling for a multi-layered control framework spanning discovery, classification, security, assurance, and action.
The asymmetry extends beyond US borders. European agencies have largely been blocked out of early access, with only the UK AI Security Institute granted the ability to test the model. If the OMB authorization proceeds on the terms Barbaccia described, defensive AI capability inside the US federal government would advance ahead of European counterparts, while the Pentagon designation against the same vendor continues to move through the courts.
A civilian workaround to the Pentagon ban
The modified version approach is how Anthropic is navigating around the Pentagon position without losing control of the model, Shah said.
“The Anthropic modified version thereby circumvents the Pentagon’s black and white approach and helps other entities adopt the model as a security enclave for civilian and enterprise sovereignty with agreed-upon guardrails,” Shah said. He added that the arrangement sets a precedent for Anthropic’s future adoption across other government entities and enterprises.
Federal access to Anthropic has been in flux for weeks. A US District Court in California granted Anthropic a preliminary injunction on March 26 against a parallel civilian designation, a ruling that gave contractors breathing room to reassess AI supply chains.
Anthropic is now simultaneously blacklisted from military procurement, enjoined from removal across civilian systems, and under discussion for expanded access through OMB. Contractors face operational difficulty identifying where specific AI models sit inside their stacks, a challenge that has reshaped supply-chain risk across federal AI deployments.
View the full article
Stan Ng, Apple's vice president of product marketing for Apple Watch, AirPods, Health, and Home, has retired after 31 years at the company (via Bloomberg).


Ng publicly announced his departure on LinkedIn on Thursday, sharing an image of the sunrise at Apple Park. "After 31 years at Apple, today was my last day," he wrote. "It was a joy to work at Apple and I truly loved what I did." Apple's latest stock vesting date took place on Wednesday, and many employees who retire or leave tend to do so around that time.

Ng joined Apple in 1995 as a senior systems engineer, before Steve Jobs had returned to the company. He later moved into product roles for the Mac before becoming one of the key marketing executives behind the original iPod. He also appeared in product launch videos, including the iPod touch reveal in 2007, and went on to oversee marketing for the iPhone and Apple Watch before Home initiatives were added to his remit in 2021.

Within Apple's marketing organization, Ng reported to Bob Borchers, who oversees product marketing under senior vice president Greg Joswiak. Marketing leaders at Apple go beyond traditional marketing, with Apple's product marketing leaders playing an active role in shaping the products themselves. Erik Treski, Apple's worldwide product marketing executive for AirPods and Home, who was referenced in last month's AirPods Max update announcement, will assume part of Ng's responsibilities. It is not yet known how the rest of his responsibilities will be divided up.

Ng's exit is the latest in a wave of senior departures that has accelerated in recent months. John Giannandrea, Apple's longtime artificial intelligence chief, was also reported to be leaving this week. Former COO Jeff Williams retired last year, design chief Alan Dye departed for Meta Platforms at the end of 2025, environment and government affairs head Lisa Jackson retired earlier this year, and general counsel Katherine Adams is set to leave later in 2026.

Ng is also the third executive closely tied to Apple's health and fitness push to exit in quick succession. Williams had overseen those groups until his retirement, while Jay Blahnik, head of Fitness+, is departing following an investigation and lawsuit related to allegations about his behavior. Apple's health initiatives were recently brought under Eddy Cue as part of a broader organizational reshuffle following Williams' retirement.
This article, "iPod Marketing Veteran Stan Ng Retires After 31 Years at Apple" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Days after Microsoft patched a high-severity issue affecting its Windows Defender antivirus tool through April’s Patch Tuesday, researchers warn of another vulnerability that could enable SYSTEM privileges through local escalation.
In a newly disclosed proof-of-concept (PoC) exploit, dubbed “RedSun,” GitHub user going by the name “Nightmare Eclipse” demonstrated how Microsoft Defender’s handling of certain cloud-tagged files can be abused to overwrite protected system files and escalate privileges.
“When Windows Defender realizes that a malicious file has a cloud tag, for whatever stupid and hilarious reason, the antivirus that’s supposed to protect decides that it is a good idea to just rewrite the file it found again to its original location,” Eclipse wrote in the PoC repository description.
The PoC exploit impacts Windows 10 and Windows 11 systems running Microsoft Defender, specifically builds with cloud files features enabled.
Antivirus rewrites the threat
The RedSun PoC highlights a counterintuitive behavior. Defender’s remediation process may restore a flagged file under certain conditions. Specifically, files tagged with cloud metadata (such as those used by OneDrive and similar services) trigger a different handling path inside the antivirus engine.
Rather than permanently removing the malicious file, Defender attempts to restore it to its original source, rewriting the file back to disk. The PoC exploits this mechanism to, during the rewrite process, manipulate the file contents or destination.
If an attacker can control the timing and location of the rewrite, they can replace legitimate system binaries or configuration files with malicious payloads. RedSun demonstrated this exploit to gain SYSTEM-level privileges.
Will Dormann from Infosec Exchange verified the PoC using the Cloud Files API. “This works ~100% reliably to go from unprivileged user to SYSTEM against Windows 11 and Windows Server 2019+ with April 2026 updates, as well as Windows 10, as long as you have Windows Defender enabled,” he said. “Any system that has cldapi.dll should be affected.”
Dormann used the Cloud Files API to introduce a specially crafted file, followed by “oplock“ to control file access timing. From there, the exploit leverages Volume Shadow Copy race conditions and directory junctions/reparse points to redirect where Defender writes the file.
Second Defender-based LPE in days
The Defender flaw addressed earlier this week as part of Patch Tuesday was one of the two zero-day bugs Microsoft fixed, and it also allowed local privilege escalation stemming from “insufficient granularity of access control.”
While Microsoft attributed the discovery of the flaw, tracked as CVE-2026-33825, to security researcher Zen Dodd, the flaw already had a PoC exploit, “BlueHammer,” available before it was even fixed. It came from “Chaotic Eclipse,” an alias used by Nightmare Eclipse on other publishing platforms. The flaw received a high-severity rating of 7.8 out of 10.
Eclipse has some disagreements with how Microsoft handled the disclosure of CVE-2026-33825. While it is unknown if “RedSun” was reported to Microsoft before disclosure, the PoC still sits unaddressed.

Microsoft did not immediately respond to CSO’s requests for comments. Dormann confirmed that the exploit is being detected on VirusTotal, but relies heavily on a test file signature (EICAR), which can be handled to some extent with string encryption. “Defender (Microsoft)  currently doesn’t detect the exploit in either case,” he noted.
View the full article
Days after Microsoft patched a high-severity issue affecting its Windows Defender antivirus tool through April’s Patch Tuesday, researchers warn of another vulnerability that could enable SYSTEM privileges through local escalation.
In a newly disclosed proof-of-concept (PoC) exploit, dubbed “RedSun,” GitHub user going by the name “Nightmare Eclipse” demonstrated how Microsoft Defender’s handling of certain cloud-tagged files can be abused to overwrite protected system files and escalate privileges.
“When Windows Defender realizes that a malicious file has a cloud tag, for whatever stupid and hilarious reason, the antivirus that’s supposed to protect decides that it is a good idea to just rewrite the file it found again to its original location,” Eclipse wrote in the PoC repository description.
The PoC exploit impacts Windows 10 and Windows 11 systems running Microsoft Defender, specifically builds with cloud files features enabled.
Antivirus rewrites the threat
The RedSun PoC highlights a counterintuitive behavior. Defender’s remediation process may restore a flagged file under certain conditions. Specifically, files tagged with cloud metadata (such as those used by OneDrive and similar services) trigger a different handling path inside the antivirus engine.
Rather than permanently removing the malicious file, Defender attempts to restore it to its original source, rewriting the file back to disk. The PoC exploits this mechanism to, during the rewrite process, manipulate the file contents or destination.
If an attacker can control the timing and location of the rewrite, they can replace legitimate system binaries or configuration files with malicious payloads. RedSun demonstrated this exploit to gain SYSTEM-level privileges.
Will Dormann from Infosec Exchange verified the PoC using the Cloud Files API. “This works ~100% reliably to go from unprivileged user to SYSTEM against Windows 11 and Windows Server 2019+ with April 2026 updates, as well as Windows 10, as long as you have Windows Defender enabled,” he said. “Any system that has cldapi.dll should be affected.”
Dormann used the Cloud Files API to introduce a specially crafted file, followed by “oplock“ to control file access timing. From there, the exploit leverages Volume Shadow Copy race conditions and directory junctions/reparse points to redirect where Defender writes the file.
Second Defender-based LPE in days
The Defender flaw addressed earlier this week as part of Patch Tuesday was one of the two zero-day bugs Microsoft fixed, and it also allowed local privilege escalation stemming from “insufficient granularity of access control.”
While Microsoft attributed the discovery of the flaw, tracked as CVE-2026-33825, to security researcher Zen Dodd, the flaw already had a PoC exploit, “BlueHammer,” available before it was even fixed. It came from “Chaotic Eclipse,” an alias used by Nightmare Eclipse on other publishing platforms. The flaw received a high-severity rating of 7.8 out of 10.
Eclipse has some disagreements with how Microsoft handled the disclosure of CVE-2026-33825. While it is unknown if “RedSun” was reported to Microsoft before disclosure, the PoC still sits unaddressed.

Microsoft did not immediately respond to CSO’s requests for comments. Dormann confirmed that the exploit is being detected on VirusTotal, but relies heavily on a test file signature (EICAR), which can be handled to some extent with string encryption. “Defender (Microsoft)  currently doesn’t detect the exploit in either case,” he noted.
View the full article
Name : 6th Annual 100 CISO Summit & Awards 2026
The 6th Annual 100 CISO Summit & Awards 2026 unites Malaysia’s foremost cybersecurity leaders, regulators, and technology experts to address the next wave of challenges. Through real-world case studies, forward-looking strategies, and practical discussions, this summit equips security leaders with the insights to anticipate AI-driven threats, prepare for post-quantum disruption, and embed resilience across the enterprise. Join us to explore the future of cybersecurity leadership, gain actionable intelligence from regional experts, and connect with peers shaping the next frontier of Malaysia’s cyber defense.
The post 6th Annual 100 CISO Summit & Awards 2026 appeared first on CISO MAG | Cyber Security Magazine.
View the full article
Security operations has not become less important. It has become harder to operate at the level the business now requires. In this blog, we examine why the modern SOC is straining under alert volume, attack speed, and operational complexity, and why autonomous SOC and agentic SOC models are gaining attention as a practical response.
View the full article
A source said to be familiar with Apple's supply chain today revealed the color options Apple is planning for the iPhone 18 Pro, ‌iPhone 18 Pro‌ Max, and the upcoming foldable iPhone.

Image via Macworld.
The information comes from Macworld, which says the signature new color for this year's Pro models will be Dark Cherry, a deep wine-like red. While other sources had previously reported on a "Dark Red" option, the hue is said to be considerably closer to wine than a brighter red. Bloomberg's Mark Gurman and other leakers had previously suggested Apple was experimenting with a shade of red for the ‌iPhone 18 Pro‌, but the color will apparently be much more muted than last year's Cosmic Orange on the iPhone 17 Pro.

According to Macworld's source, Apple has been working on four color options for the ‌iPhone 18 Pro‌ and Pro Max, with the following Pantone codes said to be in use internally:


Light Blue (Pantone 2121), resembling the current iPhone 17's Mist Blue
Dark Cherry (Pantone 6076), the headline new color
Dark Gray (Pantone 426C)
Silver (Pantone 427C), similar to the current generation


The source cautions that all four colors are still in development, and since the ‌iPhone 18 Pro‌ has not yet gone into mass production, Apple still has time to make changes. Apple also does not always offer four color options for the Pro lineup, so one of these shades could be dropped before launch. Last year, both Macworld and leaker Sonny Dickson reported that Apple had considered launching the ‌iPhone 17 Pro‌ in black or steel gray, but neither color was released.

For the first foldable iPhone, which has been rumored to be called the "iPhone Ultra," the device will reportedly come in fewer options than the Pro models, with no bold or vibrant colors. Macworld's source says Apple has been working on a classic silver and white model, as well as an Indigo option similar to the ‌iPhone 17 Pro‌'s Deep Blue.

The same source corroborates earlier leaks on the foldable's design, saying the device will feature two rear cameras, a selfie camera on the outer display, a second selfie camera in the upper-left corner of the inner display, and an iPad mini-style shape when unfolded. The foldable is reportedly just 4.7 millimeters thick when unfolded, which would make it considerably thinner than the 5.6mm iPhone Air.

On the design of the ‌iPhone 18 Pro‌, the CAD drawings seen by Macworld's source support existing rumors of a smaller Dynamic Island, which would free up a small amount of additional screen space when Live Activities are not in use. The schematics also show a slightly reduced gap between the glass cutout on the back and the camera bump in at least one render, though the source was unable to confirm whether this reflects a finalized design change. A Weibo leaker known as "Instant Digital" previously reported that Apple would adopt a new manufacturing process to minimize the color difference between the glass and the aluminum frame, which may be connected.

The ‌iPhone 18 Pro‌ models and foldable iPhone are expected to be announced in September 2026, though some analysts suggest the foldable will launch at a later date. The iPhone 18, iPhone 18e, and ‌iPhone Air‌ 2 are rumored to follow in the first half of 2027.Related Roundup: iPhone 18 ProTag: Macworld
This article, "iPhone 18 Pro's Four Rumored Colors Revealed, Including 'Dark Cherry'" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Google this week announced a new set of Play policy updates to strengthen user privacy and protect businesses against fraud, even as it revealed it blocked or removed over 8.3 billion ads globally and suspended 24.9 million accounts in 2025. The new policy updates relate to contact and location permissions in Android, allowing third-party apps to access the contact lists and a user's location inView the full article
In two decades, Palo Alto Networks has evolved from a next-generation niche player to one of the largest global cybersecurity giants today. Under its mantra of “platformization,” the company has catapulted its revenues over its closest competitors and boosted its stock valuation to over $130 billion.
No stranger to AI use in cybersecurity, Palo Alto recently announced its participation in Project Glasswing, an AI-based vulnerability-discovery initiative led by Anthropic that many are viewing as a structural shift for the cyber industry. The initiative, which includes 10 other major technology companies as coalition partners, including AWS, Apple, Broadcom, Cisco, CrowdStrike, Google, and Microsoft, aims to leverage Anthropic’s Claude Mythos to improve the security of the software that underpins much of the world’s technical infrastructure.
It is in this context that Computerworld Spain spoke with Helmut Reisinger, CEO of Palo Alto Networks for EMEA, in Madrid at the company’s Ignite event on April 14. The interview was conducted in Spanish, a language that the multilingual Austrian executive and PhD holder speaks fluently.
Following are excerpts from that interview, edited for length and clarity.
Computerworld Spain: Let’s start with the recent announcement of Palo Alto’s participation in the exclusive Mythos project, which few companies have access to due to the power of this technology and the risk of it falling into the wrong hands. Or is this just a marketing strategy?
Helmut Reisinger: Indeed, this is a restricted release that only a few companies can access for vulnerability testing. We’ve witnessed firsthand how this pioneering model represents a radical shift. With it, we’ve detected zero-day vulnerabilities in an unprecedented number of operating systems and browsers. And it’s capable of turning most of these vulnerabilities into working exploits, with all the risks that entails. For now, we can’t say much more. We’re currently working on providing more information through a blog. In any case, the important thing is the context in which this is happening.
On the democratization of AI.
Yes. At Palo Alto, we’ve been using AI to improve cybersecurity for a long time. Back in 2014, we integrated machine learning technology into our systems, initially just firewalls. But we also develop cybersecurity solutions specifically for AI. The major challenge today is that, according to a Stanford University report, only 6% of AI deployments are implemented with appropriate cybersecurity. And this is happening in the age of agents, where for every human identity there are approximately 80 machine identities, and even more if we include agents. That’s why, thanks to our acquisition of Protect AI, a company founded by Ian Swanson, formerly head of AI at Amazon, we’ve launched a security solution for AI deployments, language models, and agents.
This is just one of several purchases Palo Alto has made recently, correct?
Yes, we just closed the deal [in February] with CyberArk, a leader in identity security. At Palo Alto, we’re convinced that AI and identity are two worlds that must go hand in hand, especially now in the era of generative systems and agents.
Another acquisition we recently completed, in January, and which falls within this context of addressing the current AI landscape, is that of Chronosphere, a leader in observability. Chronosphere is capable of managing and protecting massive volumes of AI-generated data at a lower cost — half the price — of other market players. This is an important acquisition because observability is essential in cybersecurity.
And finally, we’ve acquired Koi, a deal I expect will close in a few days. Koi’s technology focuses on agentic endpoint security — protecting businesses from the risks of using AI agents and autonomous development tools operating on users’ devices. Koi’s technology will be integrated into our Cortex XDR platform to monitor what AI agents are doing on users’ computers and detect if they are being manipulated to execute malicious commands.
I imagine effectively integrate all these companies presents significant challenges.
That’s right, because many IT companies, when they make acquisitions, focus more on contractual than technological integrations, but that’s not our approach. Our strategy involves complete technological integrations, like Protect AI, which is now part of our network platform. This aligns with our commitment to platformization using a modular system.
It’s clear that ‘platformization’ is the company’s mantra and a way to simplify life for customers, but doesn’t it also create greater dependencies, including vendor lock-in?
Yes, we sometimes hear clients say they don’t want to put all their eggs in one basket. But that’s precisely why our strategy is modular, so the client can decide. It’s also true that all the clients who have experienced a massive data breach have opted for complete platformization. In fact, our founder [Nir Zuk] has always said that “everyone will switch to platforms as soon as they suffer a mega-breach.”
The speed of platform adoption, therefore, will be determined by the client themselves, their business, their use cases, their existing contracts, and so on. We are also making efforts to reduce costs to encourage clients to migrate and simplify their platformization process. Furthermore, we mustn’t lose sight of the fact that the approach to cybersecurity must be comprehensive; it’s a global chain.
Regarding cost, Palo Alto has a reputation for having powerful but expensive technology. What’s your opinion?
Compared to the level of protection we provide our customers, our technology isn’t that expensive. On the other hand, the cost also reflects all the innovation included in our solutions.
How do you see Palo Alto Networks’ major competitors, primarily Fortinet and CrowdStrike?
The cybersecurity market is fragmented, but we lead it. That said, we have to win every single day.
The current, highly turbulent geopolitical climate is having a significant impact on the cybersecurity field, as well as on customers’ IT purchasing decisions. Does being a US player in Europe affect Palo Alto? Are you seeing a shift among public sector clients toward more local options?
CISOs with high levels of responsibility know very well that a wealth of telemetry data is essential for effective protection, and that’s why we aren’t seeing a decrease in demand. That’s the primary reason. Furthermore, each region and country has its own legal frameworks and regulations, which we fully respect. In fact, we were among the first companies in the world to sign the European AI Act and ensured we also obtained the corresponding national certifications.
Our view on sovereignty is that we must find a balance between perfect sovereignty and zero sovereignty. When we talk about sovereignty, we can refer, for example, to hardware. Regarding this issue, we must accept the interdependence we have between different global markets; this happens, for example, in the field of chips. But if we talk about data sovereignty, this is something that can be easily achieved.
We implement the Bring Your Own Key (BYOK) policy for many clients to ensure that the telemetry data sent by their devices is encrypted and protected. We are not interested in accessing the personal data our clients handle; we only use telemetry, application identity, user, and device data. It was precisely thanks to this type of analysis that we were able to discover the attempted intrusion using SolarWinds, although, as it occurred years ago [2020], it was carried out using machine learning tools.
How is the current war in Iran affecting the threat landscape?
This has many implications. Our Unit42 team recently published a report outlining how the joint military offensive launched by the United States and Israel activated the Iranian-aligned cyber ecosystem, creating a scenario of digital confrontation that transcends the region and combines hacktivism, political messaging campaigns, and pressure on critical infrastructure.
In this regard, I want to bring up the issue of sovereignty again because what can a company do if its infrastructure is, for example, bombed? In other words, what does the concept of sovereignty mean in an emergency situation? We already have clients in the Middle East who are rethinking their sovereignty strategy because of this situation. Furthermore, as we saw earlier, we are talking about telemetry data, not other types of data. Ultimately, all of this shows that the concept of sovereignty is fluid.
Returning to Europe, in less than two months Palo Alto will be opening new offices in Spain and, in addition, a ‘hub’, correct?
Yes, we want to establish a center of excellence here. In Europe, in addition to Madrid, Palo Alto has large offices in London, Amsterdam, Paris, and Munich. From Madrid, Jordi Botifoll has been leading the business for 87 countries — not only in Southern Europe, but also in the Middle East, Africa, etc. — for the past three years.
And what are your expectations for the new center of excellence? Why have you chosen Spain?
Cybersecurity requires a lot of technological expertise, and Spain has very good engineers who can help our clients in case of emergency, both through our incident response unit, Unit 42, and through our partners, such as Telefónica Tech, Kyndryl, and Orange, because ours is a technology company, not a service company.
How many employees do they have in Spain, and what will the number of employees be at the new center?
I can’t break down local numbers, but overall, across the entire company, once the 4,000 CyberArk professionals are integrated, we’re already around 20,000 people worldwide. Our main development centers are in California and Israel, although we also have others in Poland and Lithuania.
Looking ahead, significant challenges in information security are coming with the arrival of the post-quantum era.
Yes, and we’re already preparing. We’ve launched Quantum Safe Security to help organizations get ready for the post-quantum era. Because the big question scientists and experts are asking now is when ‘Q Day’ will be, which might arrive sometime between 2029 and 2035. Furthermore, integrating CyberArk technology will help ensure that credentials used by machines cannot be compromised through quantum decryption.
The cybersecurity of the future must be real-time, highly automated, and simple for customers, or what we call modular ‘platformization.’
Finally, what would you say is the biggest challenge for CISOs today?
Shadow AI. We must prevent AI from suffering the same fate as other technologies in the past, creating what’s known as shadow IT. AI deployments must be accompanied by robust cybersecurity. And AI and identity management must go hand in hand. Another concern is the fragmentation of solutions. I was recently speaking with an executive at a large European bank who told me they have 60 different solutions; the gaps between these systems are a clear invitation to attack.
View the full article
No, you aren't going crazy – Apple has quietly made a backend change to the App Store app in iOS that switches the location of the Updates tab and renames it to make it more prominent.


In the App Store app, you can see the change by tapping your profile picture in the top-right corner. The "Apps & Purchase History" tab used to be at the top the list, but it has switched places with "Updates," which is now called "App Updates."

The change was made by Apple without issuing a software update and is evident on both iOS 26.4.1 and the iOS 26.5 beta.


There's actually a faster way to access the App Updates page in iOS 26.4 that was recently highlighted by Daring Fireball's John Gruber: Simply long-press on the App Store app on your Home Screen and you can jump straight to it from the contextual menu.Tag: App Store
This article, "Apple Quietly Tweaked the iOS App Store App – Here's What's Changed" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
The National Institute of Standards and Technology (NIST) has announced changes to the way it handles cybersecurity vulnerabilities and exposures (CVEs) listed in its National Vulnerability Database (NVD), stating it will only enrich those that fulfil certain conditions owing to an explosion in CVE submissions. "CVEs that do not meet those criteria will still be listed in the NVD but will notView the full article
An international law enforcement operation has taken down 53 domains and arrested four people in connection with commercial distributed denial-of-service (DDoS) operations that were used by more than 75,000 cybercriminals. The ongoing effort, dubbed Operation PowerOFF, disrupted access to the DDoS-for-hire services, took down the technical infrastructure supporting them, and obtained access toView the full article
OHC_logo_transparent_01.jpeg flags-medium.png OHC_logo_blue_square_small.jpeg

 

Account

Navigation

Search

Search

Configure browser push notifications

Chrome (Android)
  1. Tap the lock icon next to the address bar.
  2. Tap Permissions → Notifications.
  3. Adjust your preference.
Chrome (Desktop)
  1. Click the padlock icon in the address bar.
  2. Select Site settings.
  3. Find Notifications and adjust your preference.