Skip to content
View in the app

A better way to browse. Learn more.

hosang I.T.

A full-screen app on your home screen with push notifications, badges and more.

To install this app on iOS and iPadOS
  1. Tap the Share icon in Safari
  2. Scroll the menu and tap Add to Home Screen.
  3. Tap Add in the top-right corner.
To install this app on Android
  1. Tap the 3-dot menu (⋮) in the top-right corner of the browser.
  2. Tap Add to Home screen or Install app.
  3. Confirm by tapping Install.

Tech

Tech Articles from a wide variety of topics and categories
Studio-M – shutterstock.com
Die Linke ist nach eigenen Angaben Opfer einer schweren Cyberattacke geworden und vermutet dahinter russischsprachige Hacker. Man habe am Donnerstag sofort reagiert und Teile der IT-Infrastruktur vom Netz genommen, teilte Bundesgeschäftsführer Janis Ehling mit. 
«Nach derzeitigen Erkenntnissen zielen die Täter darauf ab, sensible Daten aus dem inneren Bereich der Parteiorganisation sowie personenbezogene Informationen von Mitarbeitenden der Parteizentrale zu veröffentlichen», erklärte Ehling. Ob dies gelungen sei, lasse sich noch nicht beurteilen. «Ein entsprechendes Risiko besteht jedoch.» Nicht betroffen sei dagegen die Mitgliederdatenbank. Hier hätten die Täter keine Daten erbeutet.
Nach Ehlings Angaben gab es eine Warnung der Sicherheitsbehörden, als die Attacke bereits in der Parteizentrale auffiel. Man stehe nun in engem Austausch mit den Behörden und habe Strafanzeige erstattet. 
Hybride Kriegsführung?
«Uns liegen Hinweise vor, dass es sich um einen Ransomware-Angriff der Hackergruppe “Qilin” handelt», erklärte der Bundesgeschäftsführer weiter. Das sei eine mutmaßlich russischsprachige Cybercrime-Organisation, deren Aktivitäten sowohl finanziell als auch politisch motiviert sein könnten. Derartige digitale Attacken seien häufig Teil hybrider Kriegsführung. 
Das Sammeln und Veröffentlichen privater oder personenbezogener Daten diene dazu, Betroffene einzuschüchtern, zu belästigen oder öffentlich zu diskreditieren und demokratische Strukturen zu schwächen, hieß es weiter. 
In der Vergangenheit waren bereits andere Cyberattacken auf Parteien bekannt geworden. Ein Angriff auf die IT der SPD 2023 wurde russischen Akteuren zugeschrieben. Hinter einer ähnlichen Attacke 2024 auf die CDU wurden damals chinesische Akteure vermutet. (dpa/ad)
View the full article
Studio-M – shutterstock.com
Die Linke ist nach eigenen Angaben Opfer einer schweren Cyberattacke geworden und vermutet dahinter russischsprachige Hacker. Man habe am Donnerstag sofort reagiert und Teile der IT-Infrastruktur vom Netz genommen, teilte Bundesgeschäftsführer Janis Ehling mit. 
«Nach derzeitigen Erkenntnissen zielen die Täter darauf ab, sensible Daten aus dem inneren Bereich der Parteiorganisation sowie personenbezogene Informationen von Mitarbeitenden der Parteizentrale zu veröffentlichen», erklärte Ehling. Ob dies gelungen sei, lasse sich noch nicht beurteilen. «Ein entsprechendes Risiko besteht jedoch.» Nicht betroffen sei dagegen die Mitgliederdatenbank. Hier hätten die Täter keine Daten erbeutet.
Nach Ehlings Angaben gab es eine Warnung der Sicherheitsbehörden, als die Attacke bereits in der Parteizentrale auffiel. Man stehe nun in engem Austausch mit den Behörden und habe Strafanzeige erstattet. 
Hybride Kriegsführung?
«Uns liegen Hinweise vor, dass es sich um einen Ransomware-Angriff der Hackergruppe “Qilin” handelt», erklärte der Bundesgeschäftsführer weiter. Das sei eine mutmaßlich russischsprachige Cybercrime-Organisation, deren Aktivitäten sowohl finanziell als auch politisch motiviert sein könnten. Derartige digitale Attacken seien häufig Teil hybrider Kriegsführung. 
Das Sammeln und Veröffentlichen privater oder personenbezogener Daten diene dazu, Betroffene einzuschüchtern, zu belästigen oder öffentlich zu diskreditieren und demokratische Strukturen zu schwächen, hieß es weiter. 
In der Vergangenheit waren bereits andere Cyberattacken auf Parteien bekannt geworden. Ein Angriff auf die IT der SPD 2023 wurde russischen Akteuren zugeschrieben. Hinter einer ähnlichen Attacke 2024 auf die CDU wurden damals chinesische Akteure vermutet. (dpa/ad)
View the full article
A pro-Ukrainian group called Bearlyfy has been attributed to more than 70 cyber attacks targeting Russian companies since it first surfaced in the threat landscape in January 2025, with recent attacks leveraging a custom Windows ransomware strain codenamed GenieLocker. "Bearlyfy (also known as Labubu) operates as a dual-purpose group aimed at inflicting maximum damage upon Russian businesses;View the full article
Many leaders know empowered teams deliver better results, but not all leaders understand how to get there. It all starts with knowing what empowerment truly means.
Put simply: Empowerment is the absence of micromanagement. Empowerment provides the foundation for people to develop autonomy; to take action, responsibility, and accountability; and to have the room necessary to grow to become better at execution.
More to the point, however, empowerment requires leaders who are mature, capable, self-secure, and willing to elevate the organization to the next level. It involves delegating decision-making power, providing training and tools, and creating a supportive environment where staff can innovate, solve problems, and contribute meaningfully without constant oversight.
Empowerment leads not only to higher engagement, higher productivity, and faster and better outcomes, but also higher job satisfaction, ensuring employees stay longer, adding even more value to the long-term success of a company.
As a leader, you can’t empower your teams without the right preparation. You need to first instill confidence in your team to make decisions and contribute meaningfully.
You’ll want to start with your direct reports, and empower them to break things down similarly in their respective teams and sub-teams. This won’t be achieved in a week or even in months, especially in old-fashioned companies that are run in pyramidal structures.
Here’s a practical list of steps leaders should take to implement empowerment throughout their organizations effectively.
Build a foundation of trust
Start by demonstrating trust in your employees’ abilities by avoiding micromanaging and allowing them to handle tasks independently. This creates a safe environment where they feel valued and responsible.
In weekly meetings, lead by example by asking questions — not to control, but to make employees part of the path to a solution. And then ask them to execute it.
In subsequent meetings, focus on where you can help. When things go well, give positive feedback and more freedom. Let things fail early, but don’t place blame; focus instead on lessons learned.
Once when we were rolling out a well-known EDR tool, I knew the settings weren’t tight enough, nor were the received updates applied fast enough. So I asked two people to own this, come up with suggestions for tightening the screws, and guarantee a successful rollout on multiple OSes in parallel. The phased approach took serious time, but it got us there, and without breakdowns or other hiccups. This instilled tremendous trust into the team as they could see I had empowered and entrusted them, and they responded with improved, mature actions that significantly contributed to the successful rollout and optimization.
Set clear goals and expectations
When empowering, it’s vital to define specific, measurable objectives aligned with company vision and goals. I recommend the SMART goals methodology — specific, measurable, achievable, relevant, and time-bound — to ensure everyone understands their role and how it contributes to the bigger picture, reducing ambiguity.
It’s important to involve your people in this exercise. Make them help formulate the objectives and metrics, ask for their input on timing, and what support may be required. Don’t set non-achievable goals and don’t underestimate the relevancy factor. People want to be part of something that makes a difference.
Provide ongoing training and development
Leaders should also invest in skill-building programs, workshops, or online courses. In addition to equipping them with the knowledge and tools to excel, leaders must also ensure their people can leverage these learned skills on the job, by applying them.
This will not only solidify the training they have completed but also lead to broader, more business-relevant learnings and experiences. For example, a project leader fresh off their PMP certification empowered to execute a huge project with hundreds of dependencies will be better set up for long-term career success, and your company will benefit from it.
Delegate authority meaningfully
Assign decision-making power to employees at appropriate levels. If your latest technology solution can be implemented without your involvement, assign a direct report complete responsibility and accountability to roll out the solution with a phased approach, and monitor their progress via status reports, while also measuring outcomes.
Ultimate accountability rests with you of course, but by delegating authority you can better scale your team’s efforts, contributing additional overall results for your organization. If things don’t work out, keep delegated leaders accountable to solve the problems that arise. If the project involves other functions, ensure via your functional leader counterpart that delegated authorities will work cross-functionally.
Foster open communication
Encourage two-way dialogue through regular meetings, feedback sessions, and anonymous channels. Keep in mind that different cultures require different styles, and you need to adapt the channel and facilitation to that, especially in international businesses. Employees must understand, however, that these are opportunities for open dialogue not finger-pointing.
Encourage innovation and risk taking
Create a culture where calculated risks are rewarded, even if they lead to failures sometimes. One way to do that is to implement “innovation time” by setting aside time (say, 5-10% of work hours) for experimentation or improving daily work. Once you continuously require your people to think about and act on improvements, you can see the results quite literally.
For risk taking, ensure people understand this doesn’t mean taking just any security risk, but instead encourage them to calculate security risk versus benefits (impact) and likelihoods, and to present — or when fully empowered, to act on — their findings. For example, At risk: $100,000; potential win of $500,000. Likelihood to win 0.5? Then take the risk. Contrary example: At risk: $500,000. Potential win: $100,000. Likelihood to win > 0.5? Choose not to take this security risk without additional controls and preparations.
Supply necessary resources
Ensure team members have access to the right tools, technology, and support systems. This could mean providing better software, more budget, or cross-departmental collaboration to remove barriers to success. I have teamed in the past with IT, OT, engineering, T&D, legal, HR, compliance, and even sales and marketing to get things over the “budget hump” — shared wins and shared successes will enable strong corporate culture and strong trust relationships.
Solicit and act on feedback
Regularly gather input via surveys or one-on-ones, then implement changes based on it. This shows employees their opinions matter, closing the loop on empowerment and driving continuous improvement. This last one is not to be underestimated in both value, guidance, honesty, integrity, visibility, and, last but not least, empowerment. You can proudly share meaningful work, growth, autonomy, and engagement scores on your resume. That is a true accomplishment.
Implementing these steps requires consistent leadership commitment. Start small, measure progress through employee satisfaction surveys, and adjust as needed for your organization’s context.
View the full article
Cybersecurity researchers have disclosed three security vulnerabilities impacting LangChain and LangGraph that, if successfully exploited, could expose filesystem data, environment secrets, and conversation history. Both LangChain and LangGraph are open-source frameworks that are used to build applications powered by Large Language Models (LLMs). LangGraph is built on the foundations ofView the full article
sp3n | shutterstock.com
Selbst wenn Sie bei der Absicherung Ihres Rechenzentrums, Ihrer Cloud-Implementierungen und der physischen Sicherheit Ihres Firmengebäudes alle Register ziehen – mit Hilfe von Social Engineering finden gewiefte Cyberkriminelle meistens einen Weg, diese Maßnahmen zu umgehen.
Social Engineering – Definition
Social Engineering bezeichnet die “Kunst”, menschliche Schwächen auszunutzen, um sich Zugang zu Gebäuden, Systemen oder Daten zu verschaffen. Anstatt zu versuchen, eine Software-Schwachstelle zu finden und auszunutzen, wird ein Social Engineer beispielsweise einen Mitarbeiter anrufen und sich als IT-Support-Angestellter ausgeben, um ihn zur Herausgabe seines Passworts zu bewegen.
Der bekannte Hacker Kevin Mitnick hat den Begriff Social Engineering in den 1990er Jahren entscheidend mitgeprägt. Die Grundidee, sich menschliches Verhalten zunutze zu machen und die Techniken dahinter, gibt es allerdings schon so lange, wie es Betrüger gibt.
Social Engineering – Techniken
Social Engineering hat sich für Cyberkriminelle als besonders erfolgreich erwiesen, wenn es darum geht in Unternehmen einzudringen. Sobald ein Angreifer das Passwort eines vertrauenswürdigen Mitarbeiters erbeutet hat, kann er sich damit einloggen und sensible Daten auslesen. Mit einer Zugangskarte oder einem Code, der physischen Zugang gewährt, können Cyberkriminelle sogar noch größeren Schaden anrichten.
Im Artikel “Social Engineering: Anatomy of a Hack” beschreibt ein Penetrationtester, wie er aktuelle Ereignisse, öffentlich verfügbare Informationen aus sozialen Netzwerken und ein Hemd mit Cisco-Logo aus einem Second-Hand-Laden dazu nutzte, illegal in ein Unternehmen einzudringen. Das vier Dollar teure Gebrauchthemd half ihm, die Rezeptionisten und andere Mitarbeiter davon zu überzeugen, dass er im Auftrag von Cisco technischen Support leisten müsste. Einmal eingedrungen, war es für ihn ein Leichtes, auch anderen Teammitgliedern Zutritt zu verschaffen. Darüber hinaus gelang es dem Ethical Hacker, mehrere mit Malware verseuchte USB-Sticks in den Räumen zu platzieren und sich in das Unternehmensnetzwerk zu hacken. All das lief vor den Augen der Mitarbeiter ab.
Um einen erfolgreichen Social-Engineering-Angriff zu fahren, müssen Sie nicht unbedingt zuerst in einen Second-Hand-Laden gehen, diese Angriffe funktionieren ebenso gut per E-Mail, Telefon oder über soziale Netzwerke. Allen Angriffsarten ist dabei gemein, dass sie menschliche Eigenschaften zu ihrem Vorteil nutzen – beispielsweise Gier, Angst, Neugier oder auch das Bedürfnis, anderen zu helfen.
Cyberkriminelle nehmen sich dabei oft Wochen oder Monate Zeit, um ein Ziel auszukundschaften, bevor Sie einen persönlichen Besuch wagen, eine Nachricht senden oder einen Anruf tätigen. Zu den Vorbereitungen kann beispielsweise gehören, eine Telefonliste oder ein Organigramm des Zielunternehmens zu finden oder die Mitarbeiter über soziale Netzwerke zu recherchieren. Anschließend können Sie beispielsweise über folgende Wege aktiv werden.
Am Telefon: Ein Social Engineer könnte anrufen und vorgeben, ein Mitarbeiter oder eine vertrauenswürdige externe Autorität zu sein (zum Beispiel ein Strafverfolgungsbeamter oder ein Wirtschaftsprüfer).
Im Büro:“Können Sie mir die Tür aufhalten? Ich habe meinen Schlüssel/ meine Zugangskarte vergessen.” Diesen Satz haben Sie sicher auch schon einmal so vernommen. Auch wenn die fragende Person nicht verdächtig erscheinen mag – das ist eine beliebte Taktik beim Social Engineering.
Online: Soziale Netzwerke erleichtern es, Social-Engineering-Angriffe zu fahren. Über Plattformen wie LinkedIn lassen sich schnell und einfach die meisten Mitarbeiter eines Unternehmens finden. Oft kommen noch viele andere Informationen dazu, die unter Umständen für weitere Angriffe nützlich sein können.
Beim Social Engineering werden regelmäßig auch aktuelle Ereignisse, Feiertage oder auch Popkultur-Phänomene dazu eingesetzt, Opfer in die Falle zu locken. Dabei passen die Cyberkriminellen ihre Phishing-Angriffe so an, dass sie auf bestimmte Interessen (Musik, Sport, Politik, etc.) abzielen. Das erhöht die Chance, dass die mit Malware verseuchten Anhänge angeklickt werden.
Social Engineering – Angriffsformen
Phishing-Angriffe (zu denen auch SMS-basierte Smishing– und Voice-basierte Vishing-Attacken zählen) sind oft mit geringem Aufwand verbunden. Das Motto: “Die Masse macht’s”. Im Rahmen von Phishing-Kampagnen werden oft Tausende identischer E-Mails verschickt. Anschließend müssen die Angreifer nur noch darauf warten, dass jemand leichtgläubig genug ist, um auf den enthaltenen Anhang zu klicken.
Spear Phishing oder auch Whaling bezeichnet Phishing-Angriffe, die ganz bewusst hochrangige Ziele ins Visier nehmen. Spear-Phishing-Angreifer verbringen im Regelfall viel Zeit damit, solche Ziele zunächst auszukundschaften. Das Ziel besteht dabei darin, einen möglichst überzeugenden, personalisierten Scam auf die Beine zu stellen.
Baiting ist ein essenzieller Bestandteil aller Phishing-Formen – und anderen Betrügereien. Es bezeichnet die Verlockung, mit der die Ziele in Versuchung geführt werden – sei es eine SMS, die kostenlose Geschenkkarten verspricht oder eine E-Mail, die Kryptowährungen zu besonders attraktiven Preisen oder gar kostenlos in Aussicht stellt.
Beim Pretexting handelt es sich um eine betrügerische Form von “Storytelling”. Die dabei erfundene Geschichte soll das Opfer zum Beispiel dazu bewegen, persönliche Informationen oder Zugangsdaten preiszugeben. Weiß ein Angreifer beispielsweise, bei welcher Bank sein Opfer Kunde ist, könnte er sich als Mitarbeiter des Kundendiensts ausgeben und unter einem Vorwand wie “Zahlungsverzug” versuchen, Finanzinformationen zu erhalten.
Business Email Compromise (BEC), auch bekannt als CEO-Fraud, kombiniert mehrere der bislang genannten Techniken. Ein Angreifer erlangt entweder die Kontrolle über die E-Mail-Adresse eines Opfers oder schafft es, E-Mails zu versenden, die so aussehen, als kämen sie von dieser legitimen Adresse. Damit kontaktieren die Angreifer die Untergebenen des Angegriffenen in seinem Namen und ordnen beispielsweise dringliche Überweisungen an.
Tailgating ist eine physische Social-Engineering-Form, bei der Angreifer den Mitarbeitern eines Unternehmens ins Firmengebäude folgen. Dazu könnten diese sich beispielsweise als Lieferant oder neuer Mitarbeiter, der den Ausweis vergessen hat, ausgeben.
Social Engineering – Beispiele
Um ein Gefühl dafür zu bekommen, auf welche Social-Engineering-Taktiken Sie besonders achten sollten, empfiehlt sich ein Blick auf erfolgreiche Angriffe der Vergangenheit. Hierbei konzentrieren wir uns auf drei spezifische Social-Engineering-Angriffe, die für Cyberkriminelle besonders einträglich ausgefallen sind:
1. Etwas Verlockendes anbieten
Jeder Trickbetrüger weiß: Am einfachsten ist es, aus der menschlichen Gier Profit zu schlagen. Das bildet die Grundlage des klassischen nigerianischen 419-Scams: Hierbei gaukeln Betrüger ihren Opfern vor, sie müssten hohe, unrechtmäßig erworbene Geldsummen aus dem eigenen Land zu einer sicheren Bank im Ausland transferieren. Dazu bräuchten sie Unterstützung: Gegen die Zahlung vermeintlicher Provisions-, Verwaltungs- oder Versicherungsgebühren könnten die Opfer einen Gutteil des oft millionenschweren Geldbetrags abbekommen, so dass betrügerische Versprechen.
Angriffe dieser Art sind seit Jahrzehnten bekannt und eigentlich eine Lachnummer, aber nichtsdestotrotz immer noch eine effektive Social-Engineering-Technik, auf die Menschen hereinfallen: Im Jahr 2007 überwies der Schatzmeister eines dünn besiedelten Bezirks im US-Bundesstaat Michigan einem solchen Betrüger 1,2 Millionen Dollar an öffentlichen Geldern – in der Hoffnung abkassieren zu können.
Ein weiterer gängiger Köder ist die Aussicht auf einen neuen, besseren Job: Im Rahmen einer äußerst peinlichen Kompromittierung traf es im Jahr 2011 das Sicherheitsunternehmen RSA auf diese Weise. Mindestens zwei Mitarbeiter öffneten eine Malware-verseuchte Datei, die an eine Phishing-E-Mail angehängt war. Der Dateiname: “2011 recruitment plan.xls”.
2. Fake it till you make it
Eine der simpelsten – und überraschenderweise auch erfolgreichsten – Social-Engineering-Techniken besteht darin, sich als ratlosen Mitarbeiter auszugeben. Bei einem seiner legendären frühen Betrugsversuche verschaffte sich Kevin Mitnick Zugang zu den Betriebssystem-Entwicklungsservern der Digital Equipment Corporation. Sein Vorgehen: Er rief bei DEC an, gab sich als leitender Entwickler aus und behauptete, er habe Probleme mit dem Login. Er wurde postwendend mit neuen Logindaten versorgt. Das spielte sich schon 1979 ab – man sollte also meinen, die Dinge hätten sich seitdem verbessert. Das ist allerdings nicht der Fall: Im Jahr 2016 erlangte ein Hacker die Kontrolle über ein E-Mail-Konto des US-Justizministeriums und nutzte es, um sich wie seinerzeit Mitnick Zugangsdaten zu verschaffen.
Zwar haben viele Organisationen Barrieren aufgebaut, die diese Art des dreisten Betrugs verhindern sollen, aber oft ist es nicht besonders schwer, sie zu umgehen. Als Hewlett-Packard (HP) im Jahr 2005 Privatdetektive damit beauftragte herauszufinden, welche Vorstandsmitglieder Informationen an die Presse durchstachen, versorgte das Unternehmen die Schnüffler mit den letzten vier Ziffern der Sozialversicherungsnummer ihrer Zielpersonen. Diese Daten akzeptierte der technische Support von HPs TK-Provider AT&T als Identitätsnachweis und händigte den Detektiven detaillierte Anrufprotokolle aus.
3. Autorität spielen
Viele Menschen sind daran gewöhnt, Autoritäten zu respektieren. Das wissen auch Cyberkriminelle. Sie spielen sich als Vorgesetzte oder Führungskräfte aus, um an ihr Ziel zu gelangen. So überwiesen im Jahr 2015 Finanzmitarbeiter von Ubiquiti Networks Firmengelder in Millionenhöhe an Social-Engineering-Betrüger, die sich als Führungskräfte des Unternehmens ausgegeben und ihre Glaubwürdigkeit mit gefälschten E-Mail-Absendern unterstrichen hatten.
Ein anderes Beispiel: Zur Jahrtausendwende gehörte es für (manche) britische Boulevard-Journalisten zum guten Ton, sich Zugang zu den Voicemail-Konten von für sie interessanten Personen zu verschaffen. So überzeugte ein Journalist den TK-Anbieter Vodafone davon, die Voicemail-PIN der Schauspielerin Sienna Miller zurückzusetzen, indem er dort anrief und sich als “Kollege John aus der Credit-Control-Abteilung” ausgab.
Ein weiteres prominentes Beispiel ist John Podesta, Hillary Clintons ehemaliger Wahlkampfleiter, der 2016 von russischen Spionen gehackt wurde. Die Cyberkriminellen hatten ihm im Vorfeld eine Phishing-E-Mail zugestellt, die als Nachricht von Google getarnt war und eine Aufforderung enthielt, sein Passwort zurückzusetzen. Statt sein Konto zu schützen, gab er damit seine Anmeldedaten preis.
Social Engineering – Zahlen & Statistiken
Allein im Jahr 2024 konnten kriminelle Hacker durch BEC-Angriffe rund 6,3 Milliarden Dollar einstreichen. (Quelle: Verizon DBIR 2025)
Smishing macht 39 Prozent aller mobilen Bedrohungen aus. (Quelle: SlashNext)
Mit der Einführung von ChatGPT stieg die Zahl der Social-Engineering-Angriffe um 45 Prozent. (Quelle: SlashNext)
Mit 17 Prozent aller Kompromittierungen ist Phishing der zweithäufigste, initiale Malware-Infektionsvektor. (Quelle: Mandiant M-Trends-Report 2024)
Social-Engineering-Angriffe abwehren
Wir haben fünf Tipps zur Abwehr von Social-Engineering-Attacken für Sie zusammengestellt:
1. Security Awareness
Security-Awareness-Schulungen sind der beste Weg, um Social Engineering zu verhindern. Nur wenn die Mitarbeiter wissen, welche Gefahr ihnen droht, können sie sich gegen solche Angriffe wappnen. Erarbeiten Sie ein umfassendes Schulungsprogramm, dass zu mehr Sicherheitsbewusstsein führt! Es sollte regelmäßig aktualisiert werden, um sowohl allgemeinen Phishing-Bedrohungen als auch neuen, gezielten Bedrohungen angemessen begegnen zu können.
Dabei sollten Sie von einer tiefgehenden Erklärung technischer Schwachstellen und Details absehen und stattdessen Beispiele nennen, die die Methoden der Angreifer in den Fokus stellen. Auch interaktive Elemente wie ein Quiz können dazu beitragen, Mitarbeiter vorzubereiten.
2. Security-Briefing für Mitarbeiter in Schlüsselpositionen
Unternehmen sollten Führungskräfte und leitende Angestellte in ihre Bemühungen einbeziehen, da sie für Cyberkriminelle die attraktivsten Social-Engineering-Ziele darstellen. Wichtig ist es auch Mitarbeiter, die die Berechtigung zu Finanztransaktionen haben, regelmäßig über die Gefahren aufzuklären.
3. Bestehende Prozesse prüfen
Für finanzielle und andere wichtige Transaktionen bietet es sich an, zusätzliche Kontrollmaßnahmen einzuziehen. Dabei gilt es im Auge zu behalten, dass einige Schutzmaßnahmen, beispielsweise eine Aufgabentrennung, sinnlos werden könnten, wenn es sich um eine Insider-Bedrohung handelt. Eine regelmäßige Risikoanalyse ist zu empfehlen.
4. Neue Richtlinien für dringende Anfragen
Sendet der Vorstandsvorsitzende eine E-Mail von seinem Gmail-Konto, sollte das bei den Mitarbeitern Alarmsignale auslösen. Um vorschnelle Reaktionen zu vermeiden, die ins Unglück führen können, sollten Mitarbeiter ein klar definiertes Notfallverfahren an die Hand bekommen und im Zweifel direkt mit dem Absender kommunizieren können.
5. Incident Management
Überprüfen, verfeinern und testen Sie regelmäßig Ihre Incident-Management-Systeme. Dazu bieten sich Übungen mit der Geschäftsleitung und den wichtigsten Mitarbeitern an, in denen Kontrollmechanismen und potenzielle Schwachstellen auf den Prüfstand kommen.
Social Engineering – Toolkits
Es gibt am Markt einige Tools und Services, die Unternehmen bei Awareness-Kampagnen und Phishing-Simulationen unterstützen:
Das Social Engineering Toolkit von TrustedSec steht als kostenloser Download zur Verfügung und hilft bei der Automatisierung von Penetrationstests. Zu den Features gehören neben Social Engineering auch Spear Phishing, Fake Websites und USB-basierte Angriffe.
Das Social Engineering Framework ist eine weitere gute Ressource. Laut Aussage der Macher enthält es “aktuelle wissenschaftliche, technische und psychologische Informationen” zum Thema. Das Ziel sei es, “eine Informationssammlung für Sicherheitsexperten, Penetrationstester und Enthusiasten zu schaffen”. Das Framework wird regelmäßig aktualisiert.
(fm)
View the full article
Google isn’t just responsible for the encryption of a big chunk of the communications on the internet. It is also building its own quantum computers, so it’s well placed to evaluate how close the technology is to fruition.
Until now, the company has been aligned with the NIST timeline, which specifies 2030 for deprecating quantum-unsafe algorithms and their full disallowance by 2035.
But on Wednesday, Google said that 2029 is now the deadline for the migration to post-quantum cryptography (PQC). It also said that it has adjusted its threat model to prioritize PQC migration for authentication services, and urged other engineering teams to follow suit.
Quantum computers increasingly powerful
Quantum computers are expected to break traditional asymmetric encryption, which is used to secure communications, financial transactions, and websites, once they get powerful enough.
That time is coming, says Jordan Kenyon, chief scientist in the quantum practice at Booz Allen Hamilton. “The first version of Shor’s [algorithm] was projected to require 20 million qubits [to break] and recent results have shrunk those requirements down to as a little as around 100,000 qubits.”
It’s not just that the hardware is getting better, she tells CSO. There have also been advances in error correction and algorithms.
“The magnitude of change is tough to deny,” she says.
In 2019, Google estimated that it would take 20 million qubits to break RSA encryption. By May of 2025, Google revised those estimates down to 1 million. And last month, researchers at Australia’s Iceberg Quantum said in a pre-print report that only 100,000 physical qubits were needed.
Fortunately, NIST has already finalized four algorithms that should withstand quantum computing, and has selected a fifth. But unfortunately, according to the Post Quantum Cryptography Coalition, most PQC standards have not achieved broad adoption yet.
Worse yet, says the Trusted Computing Group, its research shows that 91% of businesses do not have a roadmap in place. In addition, 80% say their current crypto libraries and hardware security modules are not ready for PQC integration, and only 39% have begun their PQC compliance readiness assessments.
CSOs can’t afford to watch and wait
Google has upped the ante on PQC migration, Michela Menting, an analyst at ABI Research, tells CSO.
That means that enterprises will also need to step up their transition plans, she says, “to align earlier than what they might have originally thought was acceptable based on the NIST deprecation timelines — especially if they want to keep pace with hyperscalers.”
She expects Microsoft and AWS to set similar migration schedules, and CSOs will need to move their PQC transition plans up the priority list.
“It’s not a side project anymore, with an extended time frame that they can just get to whenever they have extra time to work on it,” she says. “They really can’t afford to watch and wait anymore.”
According to Google, some data is already being collected by attackers. In a post last month, Kent Walker, president of global affairs at Google and Alphabet, wrote, “Malicious actors are not waiting until a cryptographically relevant quantum computer is ready. They are likely already carrying out ‘store now, decrypt later’ attacks and collecting encrypted data, just waiting for the day when a quantum computer can unlock it.”
This means that enterprises need to up their game. According to Gartner, 61% of organizations lack full visibility into their cryptographic systems. The research firm recommends that companies conduct a comprehensive cryptographic inventory, invest in cryptographic agility and visibility, establish a cryptographic center of excellence, and prioritize PQC migration for assets with long-term sensitivity.
View the full article
Google is improving its translation features with Gemini integration, adding AI in search and the Google Translate app. Users can expect smarter and more natural text translations, with improvements to phrases with nuanced meanings.


Idioms, local expressions, and slang will be translated with Gemini for improved accuracy, and Gemini will parse context instead of giving a literal word-for-word translation. The changes are rolling out on March 26 in the Translate app for iOS and on the web, and Gemini translate works with English and nearly 20 languages like Spanish, Hindi, Chinese, German, and Japanese.

Google is debuting a beta experience for real-time translations in headphones. Google says the live translation preserves the tone, emphasis, and cadence of each speaker for more natural translations.

The feature can be used by putting on any headphones, opening up the Google Translate app, and tapping on "Live Translate." As of now, the beta is limited to Android users, but Google plans to expand it to iOS users later in 2026.Tags: Google, Google Translate
This article, "Google Translate Gets Gemini AI for Smarter Translations and Real-Time Headphone Translation" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Apple gave its iPhone Product Design team bonuses worth "several hundred thousand dollars" in an effort to keep them from being poached by other companies, reports Bloomberg. The bonuses were provided as restricted stock units (RSUs) that will vest over a four-year period.


Hardware designers given bonuses will need to stay with Apple to get the full value of the stock award, which can range from $200,000 to $400,000 or even more depending on how Apple stock does over the next several years.

Apple executives are concerned with the number of engineers the company has been losing to rivals like OpenAI. Several former Apple designers are now working on hardware products at OpenAI, including former Apple design chief Jony Ive. OpenAI has been recruiting Apple engineers that worked on the iPhone, iPad, Apple Watch, and Vision Pro, and it has hired over 40 former Apple employees.

In 2021 and 2022, Apple also handed out stock bonuses to engineers in silicon design, hardware, software, and operations to thwart poaching and increase employee retention.Tag: OpenAI
This article, "Apple Gives iPhone Designers Bonuses Up to $400K to Counter OpenAI Poaching" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Apple today released a new update for Safari Technology Preview, the experimental browser that was first introduced in March 2016. Apple designed ‌Safari Technology Preview‌ to allow users to test features that are planned for future release versions of the Safari browser.


‌Safari Technology Preview‌ 240 includes fixes and updates for CSS, Editing, Forms, HTML, Media, PDF, Rendering, SVG, Scrolling, Web API, Web Extensions, Web Inspector, and WebAssembly.

The current ‌Safari Technology Preview‌ release is compatible with machines running macOS Sequoia and macOS Tahoe, the newest version of macOS.

The ‌Safari Technology Preview‌ update is available through the Software Update mechanism in System Preferences or System Settings to anyone who has downloaded the browser from Apple’s website. Complete release notes for the update are available on the Safari Technology Preview website.

Apple’s aim with ‌Safari Technology Preview‌ is to gather feedback from developers and users on its browser development process. ‌Safari Technology Preview‌ can run side-by-side with the existing Safari browser and while it is designed for developers, it does not require a developer account to download and use.Tag: Safari Technology Preview
This article, "Apple Releases Safari Technology Preview 240 With Bug Fixes and Performance Improvements" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Google is adding a new memory import feature to Gemini, making it easier for customers to switch to Gemini AI from another AI service. Users can import memories, context, and chat history from other AI apps.


Importing memory will provide Gemini with an understanding of a user's preferences, relationships, and personal context. Google says that Gemini will understand the same key facts that have been shared with other apps, so there is no need to start over from scratch when moving to Gemini from another AI service.

The import option can be accessed through the Gemini settings, and it will provide a prompt to copy and paste into an existing AI app. The prompt will ask the AI to generate a preferences summary that can be pasted into Gemini.

Google will also allow users to import their full chat history in a ZIP format, with support for searching past conversation threads and building on those threads with Gemini.Tags: ChatGPT, Gemini, Google
This article, "Google Launches Gemini Import Tool for Switching From ChatGPT, Claude, and Other AI Apps" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
App Store product pages will now display whether an app is a regulated medical device, Apple said today. The designation will be shown in the ‌App Store‌ in the European Economic Area (EEA), United Kingdom, and United States.


According to Apple, regulated medical device apps may function on their own or as part of a system for medical purposes like diagnosis, prevention, monitoring, and treatment of diseases and physiological conditions.

The apps may require registration or authorization from regulatory bodies like the Food and Drug Administration.

App developers who distribute Health and Fitness or Medical apps in the EEA, UK, or U.S. will need to provide a regulated medical device status in ‌App Store‌ Connect, along with associated regulatory information.

Apps that are marked as containing frequent references to medical or treatment information in the Age Rating questionnaire in ‌App Store‌ Connect will also need to provide the regulated medical device status.

Apple says the status is required for new apps that meet either criteria as of today. Existing apps will need to provide a status by early 2027. App developers that do not declare a status by early 2027 will no longer be able to submit app updates.

‌App Store‌ pages for regulated medical devices will list an EU Manufacturer SRN or FDA Operator Number, a URL with use instructions, a use statement, and safety information.

More information is available on Apple's developer website.Tag: United Kingdom
This article, "Apple Requires App Developers to Declare Regulated Medical Device Status in EEA, UK, and U.S." first appeared on MacRumors.com

Discuss this article in our forums

View the full article
In addition to discontinuing the Mac Pro, Apple today discontinued the $700 wheel add-on kit that it sold for the Mac Pro.


The ‌Mac Pro‌ Wheels kit was introduced in 2020, and allowed ‌Mac Pro‌ owners to add wheels to their machine after purchase. The ‌Mac Pro‌ could be bought with a wheel option for an additional $400, but the lower price was because opting for wheels removed the $300 feet.

Apple's kit included a 1/4-inch to 4mm hex bit for installing the wheels, and an installation guide.

Apple also sold a $300 ‌Mac Pro‌ Feet Kit for users who ordered wheels but wanted to swap to standard feet. That kit has also been discontinued. The ‌Mac Pro‌ and its accessories have been removed from Apple's website entirely, and old links now redirect to the online Apple Store.

For ‌Mac Pro‌ owners who want to switch to wheels but are now unable to do so, OWC sells a less expensive Rover Pro wheels kit for $200.Related Roundup: Mac ProBuyer's Guide: Mac Pro (Caution)Related Forum: Mac Pro
This article, "Apple's $700 Mac Pro Wheels Kit Discontinued Along With Mac Pro" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Apple has discontinued the Mac Pro and will soon be removing the machine from its website, reports 9to5Mac. Apple does not plan to design a new version of the ‌Mac Pro‌, and no new model will be coming in the future.



The ‌Mac Pro‌ was last updated in 2023, which was when Apple added an M2 Ultra Apple silicon chip, but the chassis has not been refreshed since 2019. Apple redesigned the ‌Mac Pro‌ to be more modular in 2019 after failing with its "innovative" trash can Mac Pro, but the machine has never been mainstream due to its $6,999 starting price.

Apple has largely replaced the ‌Mac Pro‌ with the Mac Studio, a device that is smaller and uses newer Apple silicon chips. The ‌Mac Studio‌ is now Apple's high-end desktop machine designed for professional use.

The current ‌Mac Studio‌ features an M3 Ultra chip, though it is expected to get an M5 Ultra refresh later this year. Apple's desktop lineup also includes the Mac mini and the iMac.Related Roundup: Mac ProBuyer's Guide: Mac Pro (Caution)Related Forum: Mac Pro
This article, "Apple Discontinues Mac Pro" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Netflix is increasing its prices, with all plans set to get $1 to $2 more expensive. The ad-supported plan is now $8.99 per month, up from $7.99/month, while the Standard plan is $19.99 per month, up from $17.99 per month. Netflix's most expensive Premium plan is $26.99 per month, up from $24.99 per month. Extra member add-on pricing is also increasing by $1.


Prices are increasing for both new and existing Netflix subscribers as of March 26. New members will see the higher prices today, with the pricing rolling out to existing subscribers in the coming weeks. Subscribers will be alerted a month before the new prices are applied to them.

In a statement to Variety, Netflix said that it is updating its pricing because it delivers more value to customers.

At $27 per month, Netflix Premium is the most expensive standalone streaming service subscription option. The standard Netflix plan now costs the same $20/month that Netflix used to charge for the Premium plan back in 2023.

There have been no changes to the plans with the exception of the price increase. The Standard with ads plans continues to have ads and some locked titles, with 1080p content able to be watched on two devices at a time.

The Standard plan is ad-free, and it also supports watching on two devices in 1080p. The Premium plan provides 4K HDR streaming on up to four devices, along with spatial audio.Tag: Netflix
This article, "Netflix Raises Prices Across All Plans, Premium Now Costs $27/Month" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Social network X is now limiting X Pro access to customers who subscribe to the X Premium+ plan, which is priced at $40 per month (or $33/month when paid annually). X Pro is a multi-column web interface for managing multiple feeds and lists.


X Pro was known as TweetDeck before Elon Musk bought Twitter, and it was free to use. Before March 26, X subscribers with the standard $8/month Premium plan were able to use X Pro, and now X is requiring a plan that's 5x more expensive.

No notice was provided to X Pro users about the change and access was suddenly cut off, leading to multiple complaints on the social network. On its website, X says features included in Premium "are subject to change at any time as we continue to improve the service." The X Help center clearly states that access to X Pro is now limited to the Premium+ tier.

X has three subscription tiers: Basic for $3/month or $32/year, Premium for $8/month or $84/year, and Premium+ for $40/month or $395/year. Basic still includes ads, Premium has half the number of ads, and Premium+ has no ads except for sponsored content. Paid plans provide vanity blue checkmarks that used to serve as an actual account verification method prior to Musk's takeover.

Other premium features include expanded post reach, post editing, longer post length, and longer video uploads.
This article, "X Moves X Pro Behind $40/Month Premium+ Paywall With No Notice to Users" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Apple today began notifying students who won the WWDC 2026 Swift Student Challenge, held from February 6 to February 28. Students who entered the challenge can sign into the website to see their status.


Apple did not say how many winners it chose this year, but in prior years, the company selected a total of 350 winners. Those who win the Swift Student Challenge are eligible to enter Apple's lottery for the ‌WWDC 2026‌ special event that will take place at Apple Park on Monday, June 8. Apple is also gifting winners AirPods Max 2 and a free one-year Apple Developer membership.

Apple is inviting students and developers to enter to attend the ‌Apple Park‌ event, but space is limited, so attendees are selected through a lottery process. There is no fee associated with the event, but attendees must pay for their own travel and accommodations.

Some of the Swift Student Challenge entrants will be named Distinguished Winners, and will be invited to Cupertino, California for three-day ‌Apple Park‌ experience. Students will attend the keynote meetup and will have additional opportunities to interface with Apple engineers and employees. Distinguished Winners do not need to enter the lottery to visit ‌Apple Park‌.

Swift Student Challenge winners unable to attend the ‌Apple Park‌ event can follow along with Apple's WWDC announcements through the Apple Developer website and the Apple Developer app.

Apple holds the Swift Student Challenge annually, tasking students with developing an innovative coding project using Xcode or Swift Playground. Apple said it was selecting winners that demonstrate "excellence in innovation, creativity, social impact, or inclusivity."

‌WWDC 2026‌ will take place from Monday, June 8 to Friday, June 12.Related Roundup: WWDC 2026Related Forum: Apple, Inc and Tech Industry
This article, "Apple Notifying WWDC 2026 Swift Student Challenge Winners" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Move over shadow IT; shadow AI is the new risk on the scene. The explosion of available AI tools, leadership’s enthusiasm for the new technology, the push for employees to do more with less, nascent governance and the sheer speed at which AI is evolving has created the perfect environment for shadow AI to flourish.
“Every CISO I talk to has discovered some form of shadow AI,” says Andrew Walls, vice president analyst at Gartner.
Vendors are turning AI capabilities on in their products, often without communicating that to their customers. Employees are using these embedded AI capabilities, whether CISOs are aware or not. And, of course, employees are turning to AI tools that have either not been vetted or have been explicitly banned by their employers.
CISOs might learn about these cases through staff reporting or through tools designed to detect AI use. But discovering shadow AI is just the first step. CISOs need to understand the context in which it is being used, the attendant risks and how to adapt governance going forward.
Assess the risk
Once CISOs become aware of a specific instance of shadow AI, the first step is to understand the associated risk. “The first instinct is to react. And that’s never a good thing in cybersecurity,” says Olivia Rose, IANS faculty member and founder of Rose CISO Group. “You need to think through your answer holistically and look at the level of risk to the organization before you respond and address the issue.”
How sensitive is the data? What is the AI tool provider doing with that data? How is it being stored? Is it being used to train an AI model? “It’s not the AI part of shadow AI that concerns them. It’s the data that’s being provided to an AI by the employee,” says Walls.
And the ultimate question for CISOs: Did this instance of shadow AI lead to a breach?
While discovering a breach is never the ideal outcome, CISOs aren’t entirely in uncharted waters. Their organizations should have defined incident response plans to follow, even if the breach in question stems from the use of shadow AI.
“I’ve managed a number of security incidents and major incidents and data breaches. They’re never the same, even before AI. So, how do you handle an AI breach? Depends on what was breached, how it was breached, what type of data was breached, legal, regulatory impact of that breach,” says Vandy Hamidi CISO of BPM, a tax, advisory and accounting firm.
While data breaches are a prominent concern, they aren’t the only potential outcome of AI. “AI risk is not only digital risk, it can become physical very, very quickly,” says Pablo Ballarin, co-founder and vCISO at Balusian and ISACA member. Does the use of shadow AI open the door to operational disruption, wasted resources or safety issues? Answering these questions is also a part of the necessary risk assessment.
Understand why AI is being used
If CISOs want to manage shadow AI effectively, they need to understand why it keeps popping up. The immediate reaction may be to shut down the use of shadow AI, but there must be more to the response than that.
“Our focus is understanding why they’re using it, educating them on the risks of using an unapproved AI tool, identifying whether or not we already have tools in the organization that can meet those needs and then, obviously, redirecting them with a…serious reminder of if it’s not approved for use,” says Hamidi.
Employees are likely engaging with shadow AI because it is making them more productive. Could the business benefit from dragging that AI out of the shadows and into the light? Are employees using an unapproved tool because they don’t know that something similar, and already vetted by the business, is available?
CISOs at companies that take a more draconian stance on AI may find themselves struggling to manage just how many instances of shadow usage pop up.
“If a company as a whole is slow on the adoption curve, it effectively forces the use of shadow AI,” says Hamidi.
Shut it down or integrate it
Once CISOs have a grasp on the risk introduced by shadow AI and why it is being used, they can work with other enterprise leaders to determine whether to shut it down or pursue its approval for use.
If the tool needs to be shut down – if it caused a breach this will almost certainly be the case – CISOs will need to figure out how to get it done and prevent the same use case from happening again.
“You have to look at mitigation strategies to prevent recurrence, whether that’s education of the employee, more coherent policy and acceptable use guidelines, or whether it’s a technological fix through some sort of blocking or filtering mechanism,” says Walls.
If shadow AI represents a potentially valuable use case for the business, it is time for that tool to undergo a formal review process by more than just the security team.
“Our PMO process includes a formal information security review, a legal review, data privacy review. It includes a return on investment as well to see if this tool makes sense. And then it either gets approved or it doesn’t,” Hamidi shares.
The use of AI, shadow or otherwise, is a delicate balancing act with risk on one side and benefit on the other. Shadow AI may have a legitimate business use case that is boosting productivity, but if the risk outweighs that benefit, CISOs must protect their enterprises. And productivity may take a hit.
“Depending on the risk level of the tool they’re using, sometimes that’s a cost that we have to bear,” says Hamidi.
Review and update AI governance
Every instance of shadow AI uncovered is an opportunity, even if it does cause a breach. CISOs can advocate for more resources to support the ongoing task of shadow AI management. “Never let a good breach go to waste. You can leverage it to get budget, resources, support for the cybersecurity organization,” says Rose.
Regardless of shadow AI’s outcome – blocking or integration – its discovery calls for employee education. Do they know what AI tools are already available to them? Do employees know what is considered shadow AI? Do they know the risks of using shadow AI?
That information should be clearly communicated to employees. “If there are not clear guidelines as to what’s okay and what’s not okay, well then, employees are going to do what they think is best,” says Walls.
While clear communication is important, so is its delivery. CISOs do not want to create a culture in which employees are afraid to use AI. Instead, they can push enterprises to have clear pathways for employees to introduce potential tools for evaluation.
“What I don’t want to do is punish people for using AI for increasing their productivity. If they have legitimate business reasons and they want to use it, we have processes in place for them to get it approved,” says Hamidi.
Punishment is not the frontline response to managing shadow AI, but accountability needs to be a part of how the technology is used in an organization. Employees need to understand the consequences of using AI tools: approved and unapproved. They need the training to use AI tools responsibly and a clear picture of what can happen if they continue to turn to unapproved tools. “Work with your HR team to define repercussions for repeat behavior,” says Rose.
The committee tasked with AI governance needs to build that culture of accountability; it cannot be solely the responsibility of the security team. “If that responsibility is not clearly assigned to every single person who touches an AI, then it’s very possible that when the blame game starts, there’s no obvious home for it. And the CISO might be in that line of fire,” says Walls.
For now, AI governance may require its own set of policies, but Walls anticipates that approach will change with time. “Build the AI policy, build the AI security policy, the generative AI policy, the agentic AI policy and guidelines and so forth. They’re necessary right now but in two to three years they will merge with all other technology governance and become one piece,” he says.
Even as AI governance evolves, CISOs will remain at the center of the conversation. Shadow AI is a security risk, and it isn’t going away anytime soon.
“Shadow AI, like shadow IT to a certain extent, cannot be fully avoided. It has to be managed,” says Hamidi.
View the full article
Apple plans to allow third-party AI chatbots to integrate with Siri in iOS 27, reports Bloomberg. Apple already has a partnership with OpenAI that lets ‌Siri‌ hand questions off to ChatGPT, but Apple will expand that integration to other companies like Google and Anthropic.


An iPhone user with the Claude or Gemini app installed will be able to send questions to those chatbots, like how the current ChatGPT feature works. Right now, if a user has a question that ‌Siri‌ cannot handle, ‌Siri‌ suggests sending it to ChatGPT. Users can also ask ‌Siri‌ to query ChatGPT.

iPhone users will be able to select which services they want to use inside ‌Siri‌ through "Extensions" options coming to ‌iOS 27‌, iPadOS 27, and macOS 27. The options will be available in the Apple Intelligence and ‌Siri‌ section of the Settings app, with Apple providing download links for chatbot apps.

AI apps installed through the App Store will be able to work with ‌Siri‌, including with Apple's planned ‌Siri‌ app and other ‌Apple Intelligence‌ features. Bloomberg suggests that expanding ‌Siri‌ integration to other chatbots will allow Apple to generate more money from third-party AI subscriptions made through the ‌App Store‌. AI companies will need to enable support for the new feature in ‌iOS 27‌.

Apple is still planning for a full ‌Siri‌ overhaul, and it will release its own chatbot version of ‌Siri‌ based on Google's Gemini models. Extensions will simply give users the option to direct requests to their favorite chatbot instead of ‌Siri‌.

OpenAI will no longer have an exclusive partnership with Apple when the change is made in ‌iOS 27‌. While most AI companies have not complained about the ‌Siri‌ ChatGPT integration, Elon Musk's xAI startup sued Apple and OpenAI, accusing the two companies of conspiring to "ensure their continued dominance" in the AI market. Musk has been vocal about wanting Grok to be available on the iPhone alongside ChatGPT.

Apple has been considering allowing other companies to integrate with ‌Siri‌ for some time, and it was previously working on a deal that would allow ‌Siri‌ to hand queries to Gemini.

Apple plans to announce the new ‌Siri‌ and the third-party integration option when it unveils ‌iOS 27‌ at the June 8 WWDC 2026 keynote.Related Roundup: iOS 27Tag: Siri
This article, "Apple Plans to Let Rival AI Chatbots Integrate With Siri in iOS 27" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
In addition to indicating that a new full-sized HomePod is in the works, and that the foldable iPhone will likely ship later than the iPhone 18 Pro models this year, Bloomberg's Mark Gurman today said he does not expect any major design changes for the next-generation Apple Watch models coming later this year.


Gurman revealed all of this information in a live Q&A call today on the Bloomberg website, where listeners were invited to ask him anything about Apple.

Over the years, there were rumors about everything from a radically redesigned "Apple Watch X" to a new style of watch band that attaches magnetically, but nothing like that has ever materialized. And based on Gurman's latest commentary, it sounds like the next Apple Watch will continue to look more or less the same this year.

Of course, the Apple Watch Ultra did usher in an all-new design when it launched in 2022, but that model has only received iterative design changes since.

A redesign is not necessary just for the sake of change, but users who are looking forward to something new might have to be patient, as it was recently rumored that a major Apple Watch redesign will not arrive for at least two more years.Related Roundups: Apple Watch 11, Apple Watch SE 3, Apple Watch Ultra 3Tags: Bloomberg, Mark GurmanBuyer's Guide: Apple Watch (Neutral), Apple Watch SE (Buy Now), Apple Watch Ultra (Neutral)Related Forum: Apple Watch
This article, "No Major Apple Watch Redesign Expected This Year" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
A long-term and ongoing campaign attributed to a China-nexus threat actor has embedded itself in telecom networks to conduct espionage against government networks. The strategic positioning activity, which involves implanting and maintaining stealthy access mechanisms within critical environments, has been attributed to Red Menshen, a threat cluster that's also tracked as Earth Bluecrow,View the full article
The new foldable iPhone won't ship to customers in the same September timeframe as the iPhone 18 Pro and ‌iPhone 18 Pro‌ Max, Bloomberg's Mark Gurman said today in a Q&A session.


Apple will likely ship the iPhone Fold to customers after the ‌iPhone 18 Pro‌ and Pro Max come out in September, but Gurman did not provide a specific availability timeline.

Earlier this month, Barclays analyst Tim Long suggested that the foldable iPhone won't ship until December, suggesting a roughly three-month delay between the ‌iPhone Fold‌ and the ‌iPhone 18 Pro‌ models. Apple has done a split launch before, shipping one model later than another. When the iPhone X launched in 2017, it shipped out in November, while the iPhone 8 and 8 Plus introduced alongside it came out in September as usual.

It is entirely possible Apple will ship the ‌iPhone 18 Pro‌ and ‌iPhone 18 Pro‌ Max in September and then follow it with the ‌iPhone Fold‌ sometime between September and the end of the year. Back in December, Apple analyst Ming-Chi Kuo said that the ‌iPhone Fold‌ would be in short supply, suggesting manufacturing difficulties. Kuo expects supply constraints into 2027, and supply problems or manufacturing issues could explain why Apple would delay the ‌iPhone Fold‌'s shipment date.

Even if Apple does plan to ship the ‌iPhone Fold‌ after September, we can still expect to see it introduced during the annual iPhone event that will feature the ‌iPhone 18 Pro‌ models. Apple will likely announce all three phones at once, and then bring them to customers when they're ready.Related Roundups: iPhone 18 Pro, iPhone FoldTag: Foldable iPhone
This article, "iPhone Fold Likely to Ship Later Than iPhone 18 Pro" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
On a live Q&A call today, Bloomberg's Mark Gurman said Apple is planning to release a new full-sized HomePod alongside new HomePod mini and Apple TV models.


Gurman reiterated that updates to all three products are on hold until Apple releases its more personalized version of Siri later this year. The revamped assistant is expected to debut in iOS 27, which will be available in beta starting in June and should be released to all users with a compatible iPhone in September.

Accordingly, new HomePod, HomePod mini, and Apple TV models should be released this year.

In his Power On newsletter last weekend, Gurman said new versions of the Apple TV and HomePod mini at a minimum have been "ready" since last year, and on the call today he explicitly said "yes" to a new full-sized HomePod coming as well.

Inventory of the Apple TV, HomePod mini, and full-sized HomePod is once again "running low" at Apple's retail stores around the world.


Earlier rumors claimed the next Apple TV would be equipped with the A17 Pro chip, which is the oldest chip that supports Apple Intelligence. The device is also expected to feature Apple's N1 chip for Wi-Fi 7, Bluetooth 6, and Thread.

As for the HomePod mini, it is expected to use an Apple Watch's S9 chip or newer, but it is not entirely clear how that chip would be capable enough to support the revamped Siri powered by Apple Intelligence. Other rumored features include the N1 chip, improved sound quality, a newer Ultra Wideband chip, and a red color option.

The current Apple TV 4K debuted in October 2022, and the HomePod mini was introduced in October 2020, so both devices are due for upgrades.

The full-sized HomePod was last updated in January 2023. There have been no rumored upgrades for it yet beyond support for the revamped Siri.Related Roundups: Apple TV, HomePod, HomePod miniTags: Bloomberg, Mark GurmanBuyer's Guide: Apple TV (Don't Buy), HomePod (Neutral), HomePod Mini (Don't Buy)Related Forums: Apple TV and Home Theater, HomePod, HomeKit, CarPlay, Home & Auto Technology
This article, "New HomePod Expected Alongside Updated HomePod Mini and Apple TV" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Apple has shared a mysterious teaser for Widow's Bay, a new horror-comedy series set to premiere on the Apple TV streaming service on Wednesday, April 29.


Widow's Bay is described as a "quaint island town 40 miles off the coast of New England," but apparently "something lurks beneath the surface."

The series stars Matthew Rhys as a mayor who is desperate to revive the struggling community.


"There's no Wi-Fi, spotty cellular reception and he must contend with superstitious locals who believe their island is cursed," Apple explains.

"Loftis is determined to build a better future for his teenage son and turn the island into a tourist destination," adds Apple. "Miraculously, he succeeds: tourists are finally coming. Unfortunately, the locals were right. After decades of calm, the old stories that seemed too ludicrous to be true, start happening again."

Apple says Widow's Bay blends genuine horror with character-driven comedy.


The first three episodes in the 10-episode season are set to premiere on Apple TV on Wednesday, April 29, and one additional episode will come out every Wednesday through June 17. The series is created and executive produced by Katie Dippold, and Hiro Murai directs five episodes this season, according to Apple.

In the U.S., Apple TV is priced at $12.99 per month or $129 per year, with a free one-week trial available for new subscribers. Apple TV is also included in Apple One and Peacock bundles, with all of the options outlined on Apple's website.

You can stream Apple TV in the Apple TV app, which is available on the iPhone, iPad, Mac, Apple TV 4K, Apple Vision Pro, Android, PlayStation, Xbox, Roku, Amazon Fire TV, select smart TVs, on the web at tv.apple.com, and more.Related Roundup: Apple TVTags: Apple TV Service, Apple TV ShowsBuyer's Guide: Apple TV (Don't Buy)Related Forum: Apple TV and Home Theater
This article, "Apple TV Teases Mysterious New Horror Series With 'No Wi-Fi'" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
We're in the middle of Amazon's "Big Spring Sale," which includes deals and offers on everything from Apple devices to clothes, kitchen electronics, furniture, and much more. The new event is set to run through March 31, so you'll have a few days of discounts to shop, with new markdowns appearing every day.

Note: MacRumors is an affiliate partner with some of these vendors. When you click a link and make a purchase, we may receive a small payment, which helps us keep the site running.

We've already begun tracking great deals on Apple products like AirPods, iPads, and MacBooks, but today we're focusing on accessory discounts you can get during the event. This includes products from Anker, Jackery, Samsung, and more.

Anker



Anker's new Prime 3-in-1 Wireless Charging Station has been marked down to $104.99 during the Big Spring Sale, down from $149.99, with no need for a coupon. This accessory just launched last month, and Amazon's sale today represents a new all-time low price.

$45 OFFAnker Prime 3-in-1 Wireless Charging Station for $104.99

The Prime 3-in-1 Wireless Charging Station features Qi2.2 support, which lets a compatible MagSafe ‌iPhone‌ charge at up to 25W. It's the same speed as Apple's ‌MagSafe‌ charger, and it is 10W faster than the standard Qi2 ‌MagSafe‌ chargers. You can also simultaneously charge an Apple Watch and AirPods with the device.

There are plenty of other Anker discounts happening on Amazon this week, including the Prime 14-in-1 Thunderbolt 5 Dock back at its all-time low price of $339.99, down from $399.99. Anker's popular 3-in-1 MagSafe-Compatible Charging Cube is also down to a new all-time low price of $79.03, down from $129.99.

$60 OFFAnker Prime 14-in-1 Thunderbolt 5 Dock for $339.99
Wall Chargers

Nano USB-C Wall Charger - $27.99, down from $39.99
6-in-1 USB-C Power Strip - $59.99, down from $109.99
140W 4-Port GaN USB-C Charger - $89.99, down from $99.99
14-in-1 Prime Thunderbolt 5 Dock - $339.99, down from $399.99
Wireless Chargers

3-in-1 MagSafe-Compatible UFO Charger - $69.99, down from $89.99
3-in-1 MagSafe-Compatible Foldable Charging Station - $79.99, down from $109.99
3-in-1 MagSafe-Compatible Charging Cube - $79.03, down from $129.99
3-in-1 Prime Wireless Charging Station - $104.99, down from $149.99
Prime MagSafe-Compatible 3-in-1 Charging Station - $149.99, down from $229.99
Portable Chargers

SOLIX C300 Power Station with Lantern - $169.99, down from $249.00
Prime Power Bank 26,250 mAh - $199.99, down from $229.99
SOLIX C1000 Gen 2 Portable Power Station - $428.99, down from $799.00
SOLIX C2000 Gen 2 Portable Power Station - $749.00, down from $1,499.00

Apple: The First 50 Years



This month, tech columnist David Pogue launched a new book called "Apple: The First 50 Years." On Amazon, you can get the new book for $34.38 in hardcover, down from $50.00, the best price we've seen so far on the book.

30% OFFApple: The First 50 Years for $34.38

The book explores the first five decades of Apple's history, including interviews with 150 key people who shaped Apple into what it is today, like Steve Wozniak, John Sculley, Jony Ive, and more. The book is launching to coincide with Apple's upcoming 50th anniversary on April 1, 2026.

UGREEN



UGREEN is discounting its entire range of NASync personal storage accessories, with up to 20 percent off on Amazon during the Big Spring Sale.

UGREEN NAS 2-Bay DH2300 Desktop Personal Storage - $175.99, down from $219.99
UGREEN NAS 2-Bay DXP2800 Desktop Personal Storage - $346.99, down from $439.99
UGREEN NAS 4-Bay Desktop Personal Storage - $351.99, down from $439.99
UGREEN NAS 4-Bay DXP4800 Personal Storage - $583.99, down from $729.99
UGREEN NAS 6-Bay DXP6800 Personal Storage - $967.99, down from $1,209.99

Portable Power Stations


Anker SOLIX

The majority of Anker's portable power station deals are from the SOLIX brand on Amazon, and all of these deals have been automatically applied on each page. There are plenty of notable discounts, including the popular Anker SOLIX C300 Portable Power Station with Lantern for $169.99, down from $249.99.

UP TO 56% OFFAnker SOLIX Sale
Anker 521 PowerHouse - $169.99, down from $219.99
SOLIX C300 with Lantern - $169.99, down from $249.99
SOLIX C1000 Gen 2 - $428.99, down from $799.00
SOLIX C1000 Gen 2 with Solar Panel - $699.99, down from $1,598.00
SOLIX F2000 - $799.99, down from $1,999.00
SOLIX C2000 Gen 2 - $749.00, down from $1,499.00
SOLIX C2000 Gen 2 with Solar Panel - $969.98, down from $1,998.00
SOLIX E10 Whole-Home Backup System - $4,299.00, down from $5,799.00

Jackery

Explorer 300 Portable Power Station + Solar Panel - $369.00, down from $499.00
Explorer 1000 V2 Portable Power Station - $429.00, down from $799.00
HomePower 3000 Portable Power Station - $1,198.99, down from $2,499.00
HomePower 3000 Portable Power Station + Solar Panels - $1,698.99, down from $2,999.00
HomePower 3600 Plus Portable Power Station - $2,149.00, down from $3,699.00

Samsung


Samsung has a few monitors on sale during the Amazon Big Spring Sale, with over $700 in savings on select models. One of the best all-around deals is on the 49-inch Odyssey G95C Curved Gaming Monitor at $699.99, down from $999.99, but you can find even more on sale below.

$300 OFFSamsung 49-Inch Odyssey Gaming Monitor for $849.99
27-inch Odyssey G61SD Gaming Monitor - $649.99, down from $799.99
49-inch Odyssey G95C Curved Gaming Monitor - $699.99, down from $999.99
49-inch Odyssey G91SD Curved Gaming Monitor - $799.99, down from $1,299.99
27-inch Odyssey 3D G90XF Monitor - $849.99, down from $1,999.99
49-inch Odyssey G95SD Curved Gaming Monitor - $1,197.99, down from $1,899.99
57-inch Odyssey Neo G95NC Curved Gaming Monitor - $1,580.21, down from $2,299.99

If you're on the hunt for more discounts, be sure to visit our Apple Deals roundup where we recap the best Apple-related bargains of the past week.



Deals Newsletter

Interested in hearing more about the best deals you can find in 2026? Sign up for our Deals Newsletter and we'll keep you updated so you don't miss the biggest deals of the season!




Related Roundup: Apple Deals
This article, "Amazon Prime Day 'Big Spring Sale' Accessory Deals on Qi2 Chargers, Monitors, and More" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Vivaldi has released version 7.9 of its iOS browser, introducing two-level tab stacks, Safari import tools, and a new Daily Image feature.


Two-level tab stacks is said to be the browser's most-requested iOS feature, having been available on Android since 2021. Tabs are now grouped into stacks displayed in the top row of the Tab Bar, with the tabs inside each stack appearing in a second row below, but only when that stack is active, in order to keep the interface clean.

There are two stacking styles included: Two-Level and Accordion. Users can select their preference in the app via Settings ➝ Tabs ➝ Tab Stacking Style. Creating a stack involves long-pressing the New Tab button and selecting New Tab Stack.

As mentioned, version 7.9 also comes with a new option to import bookmarks, passwords, browsing history, and stored payment information directly from Safari. The feature can be found in Settings ➝ Safari Import, and requires just a single step and confirmation.

Elsewhere, the new Daily Image feature shows a new curated photograph on the Start Page each day. Users can now also optionally sync that image as their iPhone wallpaper, keeping their Start Page and Home screen in step and refreshed automatically every day.

Vivaldi 7.9 is available now for iPhone and iPad via the App Store. [Direct Link]Tag: Vivaldi
This article, "Vivaldi Browser Brings Two-Level Tab Stacks to iPhone and iPad" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Apple continues to test under-screen camera technology as it works toward a 20th-anniversary iPhone with an uninterrupted display, according to Chinese leaker Digital Chat Station.


Apple has long been rumored to be planning a major redesign for 2027. Bloomberg's Mark Gurman reported last May that the company is aiming for an all-glass device "without any cutouts in the display."

More recently, however, there have been signs that Apple's under-display ambitions could take longer to materialize. In January, display analyst Ross Young said the smaller Dynamic Island expected on this year's iPhone 18 Pro models is likely to persist through 2027. Just this week, leaker Fixed Focus Digital similarly claimed Apple is still facing challenges with under-display Face ID, and may instead focus on gradually shrinking the cutout.

Digital Chat Station's latest comments suggest a similar incremental approach. According to the leaker, Apple's roadmap moves from a smaller Dynamic Island with some Face ID components under the display – potentially for the iPhone 18 Pro – to a further reduced cutout with a hole-punch camera and fully under-display Face ID by 2027.

However, the timeline suggests the fully uninterrupted display could be reserved for a higher-end 20th-anniversary model. Indeed, Digital Chat Station says Apple is continuing to test an all-screen device with a quad-curved display that wraps around all four edges, creating a more borderless look.

For Apple to realize a true all-glass design, though, it will need to eliminate the remaining front-facing cutout entirely. Whether current under-display technologies can meet Apple's standards in time remains to be seen.Tags: 20th-Anniversary iPhone, Digital Chat Station
This article, "Apple Still Aiming for 20th Anniversary iPhone With All-Screen Display" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Apple is selling the iPhone Air with up to a 30% discount on its official Amazon storefront in the United Kingdom, marking a steep and highly unusual direct price reduction.


The sale price brings the 256GB ‌iPhone Air‌ down to as low as £699 across two colorways (Sky Blue and Space Black), both reduced from their original £999 price. The Light Gold 256GB model is currently listed at £749, while the White 256GB configuration sits at £799. All four colors are available with free next-day delivery.

512GB models are also discounted: The Cloud White configuration is listed at £1,049, down from £1,199, while other colors are available from £899. The 1TB model is similarly reduced, with pricing starting from £1,099 for the Space Black option, down from £1,399.

The reduction of up to 30% represents the lowest price at which the ‌iPhone Air‌ has ever been available directly from Apple in any market. It is also unprecedented for Apple to heavily discount a current-generation iPhone. Apple never normally discounts its current lineup and the company typically holds firm on pricing until a model is superseded. This appears to support the narrative that the ‌iPhone Air‌ has not been the commercial success Apple had hoped for.

The device is widely believed to have struggled since its launch in September last year. A KeyBanc Capital Markets survey revealed "virtually no demand" for the ‌iPhone Air‌, and Apple analyst Ming-Chi Kuo reported that suppliers had been asked to reduce capacity by more than 80% between launch and the first quarter of 2026, with some components discontinued by the end of 2025.

Apple reportedly cut production orders to nearly "end of production" levels, and supplier Foxconn reportedly dismantled all of its production lines for the device, while Luxshare stopped production at the end of October. The device is now believed to be out of production and Apple may simply be selling through its existing stockpile of the device.

Mizuho Securities found the ‌iPhone Air‌ was the only outlier in an otherwise strong iPhone 17 cycle, with Apple cutting Air production by one million units while increasing orders for all other models by two million. The ‌iPhone Air‌ is believed to have captured just 6.8% of ‌iPhone 17‌ generation sales in the U.S. in its launch quarter, compared to 30.6% for the iPhone 17 Pro and 55.5% for the Pro Max.

Analysts have pointed to price as the central issue: The ‌iPhone Air‌ launched at $999, just $100 less than the $1,099 ‌iPhone 17 Pro‌, which offers a triple-lens rear camera and substantially better speakers and battery life. Rival smartphone manufacturers including Xiaomi, Oppo, and Vivo have either cancelled or adjusted development plans for their own ultra-thin models in response to the ‌iPhone Air‌'s poor reception, with Samsung similarly reportedly cancelling the Galaxy S26 Edge after the Galaxy S25 Edge sold poorly.

The Information reported in November that Apple has delayed the second-generation ‌iPhone Air‌, which had been scheduled to launch alongside the iPhone 18 Pro in fall 2026. The next version of the device could feature a second rear camera in response to customer feedback and launch in spring 2027.Related Roundup: iPhone AirTags: Amazon, United KingdomBuyer's Guide: iPhone Air (Buy Now)
This article, "Apple Massively Discounts iPhone Air on Amazon in UK" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Apple today announced four new members of its American Manufacturing Program: TDK, Bosch, Cirrus Logic, and Qnity Electronics.


Apple said TDK will manufacture tunnel magnetoresistance (TMR) sensors in the U.S. for the first time ever, for use in iPhones shipped around the world. Apple says these sensors help to support iPhone features such as camera stabilization.

Apple, Bosch, and TSMC will work together to produce integrated circuits (ICs) for Bosch's new sensing hardware at a TSMC facility in Washington, according to Apple. These chips help to support features like Crash Detection, tracking in the Activity app, and elevation measurements across products like the iPhone and Apple Watch.

Apple said it is also working with Cirrus Logic and GlobalFoundries to establish new semiconductor process technologies at a GlobalFoundries facility in New York. This collaboration enables Cirrus Logic to develop solutions for a number of components in Apple products, including advanced chips that power Face ID systems.

Finally, Qnity Electronics and HD MicroSystems will provide "cutting-edge materials and technologies essential for semiconductor manufacturing." This collaboration will "pioneer innovations for high-performance computing and AI."

Apple's American Manufacturing Program aims to bring more "advanced manufacturing and critical component production" to the U.S., as part of the company's four-year $600 billion commitment to U.S. manufacturing and innovation. Apple is dedicating $400 million of the $600 billion to these four new members of the program through 2030.

"At Apple, we believe in the power of American innovation and manufacturing, and we're proud to partner with even more companies to produce critical components and cutting-edge materials for our products right here in the U.S.," said Apple's CEO Tim Cook.

The program's initial members included Amkor, Broadcom, Coherent, Corning, GlobalFoundries, GlobalWafers America, Samsung, Texas Instruments, and others.Tag: American Manufacturing Program
This article, "Apple Announces Plans to Make More iPhone Parts in USA" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Cybersecurity researchers have disclosed a vulnerability in Anthropic's Claude Google Chrome Extension that could have been exploited to trigger malicious prompts simply by visiting a web page. The flaw "allowed any website to silently inject prompts into that assistant as if the user wrote them," Koi Security researcher Oren Yomtov said in a report shared with The Hacker News. "No clicks, noView the full article
Databricks has previewed a new open agentic Security Information and Event Management software (SIEM) named Lakewatch that signals its first deliberate step beyond data warehousing into security analytics.
The data warehouse-provider is pitching Lakewatch as a lower-cost alternative to traditional security tools, arguing that consolidating security analytics into its data platform can reduce overall spend.
“Right now, existing solutions’ (rival SIEMs) ingestion costs force teams to discard up to 75% of their data, so while attackers can use AI to attack anywhere, defenders only see a fraction of their own data. Our goal with Lakewatch is to close this gap… because our lakehouse architecture is uniquely built to handle massive amounts of data cheaply,” Andrew Krioukov, general manager of Lakewatch at Databricks, told InfoWorld.
“Unlike other SIEM platforms, we do not charge based on the amount of data ingested or stored, but rather on the compute that security teams use. This allows organizations to achieve up to an 80% reduction in total cost of ownership (TCO) while maintaining years of hot, queryable data for compliance and hunting,” Krioukov added.
Analysts, too, agree with Krioukov, but only in part.
“The cost problem in SIEM is real. Many organizations often are forced to discard data because ingestion pricing makes full retention prohibitively expensive,” said Stephanie Walter, leader of the AI stack at HyperFRAME Research.
In contrast, Lakewatch can reduce costs in some cases, especially if enterprises want to retain large amounts of data, echoed Akshat Tyagi, associate practice leader at HFS Research.
However, analysts warned that savings may be less straightforward, with costs potentially shifting to compute and data processing rather than disappearing altogether.
“Costs don’t disappear; they shift. If usage isn’t controlled, compute can add up quickly. It can be more efficient, but not automatically cheaper,” said Robert Kramer, principal analyst at Moor Strategy and Insights.
Beyond costs, though, analysts say Lakewatch is offering a progressive structural shift in how enterprises conduct security operations, especially analytics.
The platform stitches together components such as Unity Catalog for governance and access control, Lakeflow Connect for ingesting and streaming security data, and the Open Cybersecurity Schema Framework (OCSF) to standardize disparate log formats, effectively turning the lakehouse into a centralized system of record for security operations, Walter said.
The added context from all the combined data in the lakehouse is also likely to act as an accelerant for helping enterprises automate security operations at scale with agents, Walter added.
That said, translating these benefits into near-term buy-in from CIOs and CISOs could prove challenging for Databricks.
“This is more likely to complement existing SIEMs than replace them. Early adoption will come from large enterprises already committed to Databricks, especially those seeking flexibility or cost control. It aligns with existing investments but remains new territory for operational security teams. Building trust through proven use cases will be key,” Kramer said.
Even so, Databricks is signaling serious intent, with the acquisitions of two cybersecurity startups — Antimatter and SiftD.ai, which analysts say point to its broader security roadmap ahead. “This looks like the foundation of a long-term security portfolio, not a one-off SIEM feature. Acquiring security-focused companies is less about adding features and more about importing credibility. Security buyers trust vendors with domain depth, not just infrastructure scale,” HyperFRAME Research’s Walter said.
The article originally appeared in InfoWorld.
View the full article
Apple just announced the AirPods Max 2 earlier this month, and today Amazon introduced the first cash discount on the headphones. You can get the Midnight and Starlight color options for $529.99 on Amazon, down from $549.00.

Note: MacRumors is an affiliate partner with some of these vendors. When you click a link and make a purchase, we may receive a small payment, which helps us keep the site running.

Shoppers should remember that this is a pre-order discount on the AirPods Max 2, which are set to officially launch on April 1. Although this is only a $19 discount on the AirPods Max 2, it's the best markdown you'll find online if you're looking to pre-order the headphones.

$19 OFFAirPods Max 2 for $529.99

This deal is part of Amazon's Big Spring Sale, which also includes big savings on the AirPods Pro 3 and AirPods 4. If you're on the hunt for more discounts, be sure to visit our Apple Deals roundup where we recap the best Apple-related bargains of the past week.



Deals Newsletter

Interested in hearing more about the best deals you can find in 2026? Sign up for our Deals Newsletter and we'll keep you updated so you don't miss the biggest deals of the season!




Related Roundup: Apple Deals
This article, "AirPods Max 2 Get First Discount on Amazon" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Unmasking impostors is something the art world has faced for decades, and there are valuable lessons from the works of Elmyr de Hory that can apply to the world of defensive cybersecurity. During the 1960s, de Hory gained infamy as a premier forger, passing off counterfeit masterworks of Picasso, Matisse, and Renoir to unsuspecting collectors and renowned museums. Over the next several decades,View the full article
Some weeks in security feel loud. This one feels sneaky. Less big dramatic fireworks, more of that slow creeping sense that too many people are getting way too comfortable abusing things they probably shouldn’t even be touching. There’s a little bit of everything in this one, too. Weird delivery tricks, old problems coming back in slightly worse forms, shady infrastructure doingView the full article
Threat actors are actively exploiting OpenClaw’s viral popularity to run a phishing campaign that targets developers on GitHub with lures of free crypto tokens.
According to a disclosure by OX Security, the campaign involves fake “CLAW” token airdrops that promise thousands of dollars in rewards. Developers are being tricked into malicious GitHub repositories and discussions, and eventually redirected to convincingly cloned websites that prompt them to connect their crypto wallets.
“The threat actor opens issues in attacker-controlled repositories and tags GitHub users to maximize visibility and reach,” OX researchers said in a blog post. “The linked site is an almost identical clone of openclaw.ai, with one key difference: it adds a “connect your wallet” button designed to initiate wallet theft.”
The researchers said that the threat actor created multiple accounts for the campaign and deleted all of them a few hours after the campaign began. Analysis suggested no users have yet been affected by the campaign.
GitHub is used for delivery
The campaign moves phishing inside GitHub workflows, something not very commonly seen. Attackers created or hijacked repositories, seeded them with attractive content, and amplified reach by tagging developers or engaging in discussions to boost visibility.
The campaign uses a social engineering layer, which includes legitimate-looking issues, pull requests, and repo mentions, to bypass suspicion. GitHub was presumably chosen to exploit developer trust, as they are more likely to click through a lure spread within a familiar environment.
Victims are first pulled in via GitHub issues that read, “Appreciate for your contributions on GitHub. We analyzed profiles and chose developers to get OpenClaw allocation.” The message is framed as a limited-time token giveaway of $5000 worth of CLAW tokens, directing them to collect the tokens by visiting the malicious site. “We assess that the attackers may be using GitHub’s star feature to identify users who starred OpenClaw-related repositories and target them specifically, making the phishing campaign appear more credible and relevant to recipients,” the researchers added.

CLAW isn’t a legitimate token and is being promoted as a new launch in the scam narrative. In fact, OpenClaw developer Peter Steinberger has explicitly said in the past that the project will never issue tokens and any claim otherwise is a scam.
Smart, obfuscated malware code
According to OX, the malicious phishing and wallet-stealing code is “highly obfuscated” and resides within the “eleven.js” JavaScript file in the repository.
The threat actor used “watery-compost[.]today” to host a C2 server to collect information (including wallet address, transaction value, and name) and drain wallets once they were connected. Commands used by the C2 include PromtTx, Approved, and Declined. Additionally, the malware code includes a ”nuke“ function that deletes wallet-stealing information from the browser’s local storage to avoid detection and forensics, the researchers added.
The address “0x6981E9EA7023a8407E4B08ad97f186A5CBDaFCf5” was extracted from the code and identified as the threat actor’s wallet used to receive stolen cryptocurrency. The phishing page (“token-claw[.]xyz“) was said to support multiple crypto wallets, including WalletConnect, MetaMask, Trust Wallet, OKX Wallet, and Bybit Wallet.
OX researchers recommended blocking the phishing domain from all environments, refraining from connecting crypto wallets to untrusted websites, and treating token giveaway issues from unknown sources as suspicious. Users should also review any recent wallet connections associated with the campaign and revoke all approvals immediately to stay protected.
View the full article
Most teams have security tools in place. Alerts are firing, dashboards look clean, threat intel is flowing in. On the surface, everything feels under control. But one question usually stays unanswered: Would your defenses actually stop a real attack? That’s where things get shaky. A control exists, so it’s assumed to work. A detection rule is active, so it’s expected to catch something. But veryView the full article
The kernel exploit for two security vulnerabilities used in the recently uncovered Apple iOS exploit kit known as Coruna is an updated version of the same exploit that was used in the Operation Triangulation campaign back in 2023, according to new findings from Kaspersky. "When Coruna was first reported, the public evidence wasn't sufficient to link its code to Triangulation — sharedView the full article
Apple is evaluating a 200-megapixel telephoto camera sensor that could potentially ship in an iPhone as soon as next year, according to Digital Chat Station, a leaker on Chinese social media platform Weibo with a decent track record.


In a post shared today, the leaker said Apple is actively testing a 200-megapixel 1/1.2" sensor similar to the one rumored for Oppo's upcoming Find X9 Ultra.

On the already-released Find X9 Pro, Oppo debuted a 200-megapixel periscopic telephoto lens with a large 1/1.56" sensor that's far bigger than typical zoom cameras. An earlier leak by Digital Chat Station suggests Oppo's upcoming Ultra model will push this further by introducing a 1/1.28" sensor.

The leaker's latest claim is a notable development. In January, they said 200-megapixel camera sensors were being discussed in Apple's supply chain, but that they had not appeared in engineering prototypes. At the time, Apple's development work was said to remain focused on refining its existing 48-megapixel systems.

January was also the month that Morgan Stanley reported Apple is working to bring a 200-megapixel camera to the iPhone as soon as 2028.

Samsung introduced a 200-megapixel rear camera on its Galaxy S23 Ultra in 2023, and the follow-up models also have one. With a 200-megapixel camera, an iPhone would be able to shoot photos with greater detail. The increased megapixel count would also result in higher-resolution photos, which can be cropped further and printed at larger sizes without a loss of image quality.

In 2027, Apple is expected to release the regular iPhone 18 as part of a new split-launch cycle, with next-generation Pro models following during the usual September time frame. Next year could also usher in a 20th anniversary iPhone, which could either be a Pro equivalent or perhaps a higher-tier premium model, similar to Apple's iPhone X.Related Roundup: iPhone 18 ProTag: Digital Chat Station
This article, "Apple Testing 200MP iPhone Camera That Could Ship Next Year" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Cybersecurity researchers have discovered a new payment skimmer that uses WebRTC data channels as a means to receive payloads and exfiltrate data, effectively bypassing security controls. "Instead of the usual HTTP requests or image beacons, this malware uses WebRTC data channels to load its payload and exfiltrate stolen payment data," Sansec said in a report published this week. The attack,View the full article
If you prepare and file taxes electronically, federal law has specific things to say about how your technology is set up.
Not general cybersecurity advice. Specific, documented, enforceable requirements under IRS Publication 4557 and the Federal Trade Commission’s Safeguards Rule. And if your IT infrastructure does not meet them, the consequences go well beyond a cautionary letter.
Tax and accounting firms are legally classified as financial institutions under the Gramm-Leach-Bliley Act. That classification means the FTC holds your firm to the same data protection standards as banks and credit unions.
It also means the IRS expects documented, auditable evidence of your security controls, not just good intentions. For enrolled agents and professional tax preparers, non-compliance is a PTIN issue. Lose your Preparer Tax Identification Number, and you cannot legally file taxes for clients.
If you are an enrolled agent, independent tax preparer, or small CPA firm owner, these are the five IT systems the IRS and FTC now expect you to have in 2026.
Key Takeaways
A Written Information Security Plan (WISP) is a federal legal requirement for all tax preparers who file electronically. It is not a best practice or a recommendation. It is a legal mandate.
IRS Publication 4557 requires multi-factor authentication (MFA), AES-256 encrypted data storage, and a documented incident response plan for every firm that handles electronic returns.
The FTC Safeguards Rule classifies accounting and tax firms as financial institutions and requires a formal, written data protection program that is reviewed and updated annually.
Automated encrypted backups, managed endpoint protection, and accounting-specialist IT support are each individually required to meet the combined obligations of IRS and FTC mandates in 2026. What are the 5 IT Essentials Accounting Firms Must Have to Stay IRS-Compliant?
The five requirements below are drawn directly from IRS Publication 4557, IRS Publication 5708, and the FTC Safeguards Rule.

They are not a prioritized wish list or a vendor’s interpretation of best practices. They are the controls the IRS and FTC have documented as mandatory for firms that handle electronic returns and hold sensitive taxpayer data. Each one addresses a specific regulatory obligation, and together they form the complete IT compliance baseline every enrolled agent and CPA firm operating in 2026 is expected to meet.

The IRS refers to its core technical requirements as the “Security Six”: antivirus, firewalls, MFA, drive encryption, tested backups, and secure remote access. The five essentials below are the operational systems a firm must have to actually implement and sustain those controls in a production environment.
1. A Written Information Security Plan (WISP)
A Written Information Security Plan is a formal, documented policy that describes how your firm identifies, manages, and protects the sensitive taxpayer data it holds. It is the foundational compliance document that every other IT control feeds into.
Without it, even a firm with solid technical defenses has no documented evidence that those defenses exist, which is what regulators actually audit.
The IRS Security Summit, a coalition of the IRS, state tax agencies, and the broader tax industry, has made the WISP a centerpiece of its annual data security guidance for years. IRS Publication 4557 names it as a required safeguard for all professional preparers who file electronically. IRS Publication 5708 goes further and provides a step-by-step WISP template that firms can use as a baseline.
These are not ambiguous recommendations. They are the IRS’s direct guidance to tax professionals on what their security documentation must contain.
The document itself must cover, at minimum: a formal risk assessment, administrative safeguards governing staff access and training, technical controls including MFA and encryption, physical access restrictions, a written incident response procedure, and a schedule for annual review.
What Happens If You Don’t Have a WISP?
When you renew your PTIN each year, the renewal attestation asks you to confirm a WISP is in place.
A missing or inadequate WISP is not a gray area in that process. The IRS can revoke PTIN status for demonstrated non-compliance with its data security requirements, ending your ability to file professionally. The FTC can impose civil penalties of up to $46,517 per violation under the Gramm-Leach-Bliley Act for failure to maintain a written information security program, and each affected client record can constitute a separate violation.
And in the event of a breach, the absence of a documented WISP creates direct exposure with cyber insurance carriers who increasingly require proof of written security controls before honoring claims.
According to IBM’s Cost of a Data Breach Report 2024, the average cost of a data breach reached $4.88 million globally.
Firms that need a fully customized, audit-ready WISP aligned to their specific software stack and staff size can now take the help of specialized WISP service for tax and accounting firms that delivers a compliant, IRS-aligned plan in as little as five business days.
2. Secure, IRS-Compliant Cloud Hosting for Tax Software
IRS Publication 4557 requires that all client data be stored with AES-256 encryption, accessible only to authorized personnel, and protected both at rest and in transit at all times.
Your tax software is the primary container for that data. Drake Tax, Lacerte, ProSeries, UltraTax CS, and QuickBooks Desktop collectively hold Social Security numbers, Employer Identification Numbers, prior-year return data, and complete financial records for every client you serve. Where and how that software runs is a compliance question before it is an operational one.
Compliance-grade hosting for tax and accounting software means several specific things:
AES-256 encryption at rest and in transit. Multi-factor authentication enforced on every login without exception. SOC 2 Type II certified infrastructure that has been independently audited. A dedicated server environment where your firm’s data is fully isolated from other tenants. That last requirement deserves more attention than it typically receives. In a shared cloud hosting environment, one tenant’s misconfiguration or vulnerability can create risk for neighboring accounts. During tax season, when servers handle the highest volume of sensitive returns in the tightest timeframe, shared infrastructure is a compliance and security liability that Publication 4557 requires you to address.
There is a meaningful operational benefit alongside the regulatory one. When tax software runs on certified, dedicated cloud infrastructure, your team can access Drake, ProSeries, Lacerte, or QuickBooks from any device and any operating system without configuring a VPN or maintaining aging local hardware.
A dedicated server environment where your firm’s data is fully isolated from other tenants also delivers the most tangible operational benefit: reliability during the period it matters most. Shared cloud hosting environments experience performance degradation under peak tax-season load precisely because server resources are spread across hundreds of firms simultaneously.
Dedicated infrastructure removes that variable entirely. Providers like Verito, which has maintained a 100% uptime record since 2016 serving tax and accounting firms exclusively, demonstrate what that commitment looks like in practice.
For enrolled agents and preparers relying on Drake, ProSeries, or Lacerte to meet filing deadlines, access continuity is not a convenience feature. In compliance terms, downtime is a risk. In operational terms, it is lost revenue. A dedicated hosting environment addresses both.
3. Managed Endpoint Protection
Endpoint protection covers every device that connects to your firm’s data or network: workstations, laptops, tablets, and mobile phones used for work.
The FTC Safeguards Rule, whose updated provisions took full effect in June 2023, explicitly requires covered firms to encrypt data in transit, enforce MFA, maintain a documented patch management program, and monitor system activity for unauthorized access. These four requirements cannot be reliably met by traditional antivirus software, regardless of how recently it was updated.
The practical distinction between legacy antivirus and next-generation Endpoint Detection and Response (EDR) matters here. Traditional antivirus identifies threats by comparing files against a database of known malware signatures. EDR uses behavioral analysis to detect threats that have never been cataloged before, including the lateral movement patterns that consistently precede ransomware deployment.
According to Verizon’s 2024 Data Breach Investigations Report, 68% of breaches involved a human element such as phishing or credential theft. EDR is specifically designed to catch those entry points before they become incidents that trigger your notification obligations under state data breach laws.
Accounting and tax firms are high-value targets because of what they hold: Social Security numbers, bank account data, EINs, and years of financial history for individuals and businesses, all in a single system, typically behind lighter defenses than dedicated financial institutions.
The IRS Security Summit has documented a sustained pattern of credential phishing campaigns targeting tax professionals specifically. The technical safeguards that address those threats are not optional enrichments. In 2026, they are the regulatory floor.
Providers of managed IT services built for accounting firms typically bundle EDR, MFA enforcement, patch management, and FTC Safeguards Rule compliance documentation into a single monthly service, removing the burden of sourcing and managing each control independently.
4. Automated, Encrypted Backups
IRS Publication 4557 explicitly requires that firms maintain the ability to restore critical client data following a system failure, ransomware attack, or natural disaster.
A backup process that depends on a staff member manually exporting files to a USB drive or external hard disk does not satisfy that requirement. The IRS expects an automated, encrypted, and periodically tested backup solution.
A compliant backup strategy has four components:
Automated nightly execution so no backup depends on human action AES-256 encryption at rest so the backup itself cannot be read if intercepted Geographically separate or cloud-based off-site storage so a single physical event cannot destroy both primary and backup data simultaneously A documented test restore process that confirms the backup actually works before it is needed.  That last component is the one most small firms skip entirely, and it is the one that determines whether a backup is a recovery plan or an assumption.
The tax season timing dimension is not abstract. A ransomware attack in February or early March, at the peak of filing volume, leaves a sole practitioner with no technical recovery path if backups are untested or unencrypted. The firm faces data loss, mandatory client notification under applicable state breach reporting statutes, and potential IRS reporting obligations.
Firms that run automated nightly backups and test their restore process quarterly can recover from most incidents within hours. Firms that discover their backup has not been running at the moment they need it cannot.
5. 24/7 IT Support from Specialists Who Know Tax Software
A support technician who has never opened Drake Tax cannot resolve a Drake Tax failure at 9 PM on April 14.
This is not a criticism of general IT support providers. It is a structural limitation. Tax and accounting software has specific, recurring failure modes around multi-user licensing configurations, update timing conflicts, remote desktop session behavior, and integration issues with practice management platforms like TaxDome and OfficeTools.
Resolving those problems requires hands-on familiarity with how the software actually behaves in production, not just general Windows Server knowledge.
The compliance dimension of IT support quality is often overlooked. When firms cannot get fast, first-call resolution, staff create workarounds. Shared login credentials. MFA turned-off on one workstation “just temporarily.” A client return processed on an unpatched personal laptop because the office server was down and a deadline was approaching.
These are not policy failures. They are predictable responses to inadequate support. IRS Publication 4557 requires firms to prevent exactly these kinds of control degradations, which means the quality and responsiveness of your IT support provider directly affects your compliance posture, not just your productivity.
Firms assessing specialist IT providers should ask explicitly for documented response time SLAs and first-call resolution rates, and should confirm that the provider’s technicians can name and demonstrate familiarity with the specific software the firm runs.
When evaluating services such as managed IT for accounting firms, look for response times under 60 seconds and first-call resolution rates above 90%. Those benchmarks exist, they are achievable, and they are the specific service levels that prevent tax-season workarounds before they become compliance gaps.
The Baseline is Higher Than Most Firms Realize
These five requirements represent the regulatory floor for 2026, not an advanced security posture reserved for large CPA firms.
The FTC Safeguards Rule update that took effect in June 2023 brought independent tax preparers and small accounting firms into a compliance regime that previously applied primarily to larger financial institutions. That shift has not been fully absorbed across the profession, and enforcement activity is increasing.
The practical benefit of addressing all five requirements under a single framework is that compliance documentation becomes unified. When the same provider manages your cloud environment, endpoints, backups, and support, there is no gap where one vendor assumes another has covered a requirement.
Your WISP documents controls that are actually in place, tested, and generating evidence logs. That is what IRS auditors and FTC reviewers verify when they assess whether a firm’s data security program is real or theoretical.
For enrolled agents and small CPA firms operating in 2026, the compliance floor is clear: a documented WISP, compliant cloud hosting, managed endpoint protection, tested automated backups, and specialist IT support are each individually required under IRS Publication 4557 and the FTC Safeguards Rule, not collectively optional.
The FTC Safeguards Rule update that took full effect in June 2023 extended these obligations to independent preparers with no revenue or headcount threshold. Firms that can demonstrate all five controls through documented, auditable evidence are compliant. Firms that cannot, are exposed.
Frequently Asked Questions
1. Is a WISP required for all accounting firms and enrolled agents?
Yes. Under IRS Publication 4557 and the FTC Safeguards Rule, every professional tax preparer who files electronically is legally required to have a Written Information Security Plan. PTIN renewal attestation asks preparers to confirm a WISP is in place. Firms without a current WISP face PTIN revocation risk and potential civil penalties under the Gramm-Leach-Bliley Act.
2. What does IRS Publication 4557 require from a technology standpoint?
IRS Publication 4557 requires multi-factor authentication on all accounts that access taxpayer data, AES-256 encryption for data stored and transmitted, a documented incident response plan, and a written WISP that captures these controls. It also requires ongoing monitoring for unauthorized system access and a formal annual review of all security practices. These are not suggestions. They are the IRS’s baseline data security requirements for professional tax preparers.
3. Does the FTC Safeguards Rule apply to independent tax preparers and small CPA firms?
Yes. The FTC classifies tax preparers and CPA firms as financial institutions under the Gramm-Leach-Bliley Act. This means they are subject to the Safeguards Rule, which requires a written information security program, a designated security coordinator, a formal risk assessment, and annual program reviews. The 2023 rule update introduced stricter documentation, encryption, and monitoring requirements that apply to firms of all sizes.
4. What should I look for when choosing IT support for my accounting firm?
Prioritize providers with verifiable, hands-on experience supporting Drake Tax, Lacerte, ProSeries, UltraTax CS, and QuickBooks Desktop. Ask specifically for their documented response time SLA and first-call resolution rate. Confirm they generate compliance documentation that satisfies IRS Publication 4557 and FTC Safeguards Rule requirements. Avoid general-purpose managed service providers that cannot demonstrate specific accounting and tax software expertise. Those gaps in knowledge become your compliance gaps during filing season.
View the full article
A new critical vulnerability that is similar to the widely-exploited CitrixBleed and CitrixBleed2 holes should be patched in NetScaler devices immediately, say experts.
The hole, CVE-2026-3055, is an out-of-bounds read vulnerability in customer-managed NetScaler ADC and NetScaler Gateway devices configured as SAML IDP for approving identity and authentication. It’s rated at 9.3 in severity on the CVSS scale,
“The implications of leaving it unpatched are serious,” Ryan Emmons, staff security researcher at Rapid7, told CSO in an email, because the hole allows an unauthenticated remote attacker to leak potentially sensitive information from the appliance’s memory.
“This vulnerability is one that threat actors and researchers alike are paying attention to,” he said.
The vulnerability carries similar ramifications to 2023’s CitrixBleed and 2025’s CitrixBleed2 memory leak vulnerabilities, Emmons added. Then, unauthenticated attackers with no existing level of access were able to steal credentials from business-critical Citrix NetScaler systems exposed to the public internet.
CitrixBleed2 enabled attackers to leak sensitive memory content by sending specially crafted HTTP requests to a vulnerable Citrix endpoint. When it was discovered last year, researchers at Imperva quickly saw threat actors trying to exploit the hole, detecting over 11.5 million attacks.
One that was successful involved the China-based group known to researchers as Salt Typhoon, which, according to Darktrace, got past defenses at an unnamed European telecom provider by exploiting CitrixBleed2 and installed a backdoor.
“We expect that’s also what exploitation of this vulnerability facilitates,” he said “Initial access. With so much to potentially gain, it’s overwhelmingly likely that threat actors are actively working on developing an exploit for CVE-2026-3055, and we believe that exploitation in the wild is imminent.”
Affected are NetScaler ADC and NetScaler Gateway version 14.1 before 14.1-66.59; NetScaler ADC and NetScaler Gateway version 13.1 before 13.1-62.23; and NetScaler ADC FIPS and NDcPP before 13.1-37.262
In its notice to customers, Citrix “strongly urges affected customers” to install the relevant updated versions as soon as possible.
In the same notice, Citrix alerted admins to CVE-2026-4368, a race condition leading to user session mixup, rated at 7.7 on the CVSS scale, that applies to NetScaler ADC and NetScaler Gateway 14.1-66.54 devices.
Prime targets
NetScaler ADCs are application delivery controllers that optimize the delivery of web and traditional applications through load balancing and traffic management, while NetScaler Gateways are VPN solutions.
As categories, ADCs and VPNs are prime targets for threat actors because they are internet-facing. “Anything that organizations tend to heavily rely on and expose at the network edge makes for a juicy target in the eyes of attackers,” said Emmons. “That doesn’t mean these products are of poor quality, it just means that threat actors are spending a significant amount of time and energy finding and exploiting subtle flaws in them.”
Citrix says in its advisory that CVE-2026-3055 was found through product security testing, he pointed out, “which means they’re taking a proactive approach to find these bugs before threat actors do. That’s a great thing to see. Citrix products are incredibly popular and widely used, and they are routinely exposed to the public internet, so it’s of the utmost importance that the vendor is prioritizing security in this manner.”
Emmons said the best things defenders can do to protect ADCs and VPNs are to reduce their exposed attack surface, ensure vulnerability intelligence is available and effectively distributed, and prioritize patching the systems that matter most.
“Systems that don’t need to be exposed to the internet shouldn’t be,” he said. “Reducing public-facing attack surface is key, where possible. When that’s already in place, it’s vital to have early and accurate intelligence on vulnerabilities affecting products the organization relies on. A focus should be placed on ensuring important security advisories are highly visible to defending teams on the day of publication for triage.”
View the full article
Apple is working on an AI wearable device that's been described as a pin or a pendant. Apple is experimenting with the device right now, but if development moves forward, it could launch as soon as 2027.


We've rounded up everything we know about the AI pin so far.

Design

The pin is said to be similar in size to an AirTag, with a thin, flat, circular disc shape. It features an aluminum and glass shell, and there's a physical control button on one edge. Apple apparently wants the final version of the device to be about the same size as an ‌AirTag‌, but with the hardware inside, it will be slightly thicker.

Apple will let users attach it to clothing or a bag with a clip, or wear it as a necklace using a hole at the top of the accessory.

The AI pin wirelessly charges like an Apple Watch.
Camera

Apple plans to add a camera to the AI pin, but rumors are mixed on what the camera will do.

Bloomberg says the pin will have a low-resolution camera that gives it info about its surroundings rather than a camera for capturing photos and videos. The camera will be always-on and always recording, but users will not be able to use it for images.

The Information believes there will be two front cameras, one with a standard lens and one with a wide-angle lens for capturing photos and videos.

Apple's AI device will rely heavily on Visual Intelligence, which is currently an iPhone feature that uses the camera to provide users with more information about places and objects around them.

Speaker and Microphone

The AI pin has at least one microphone for speaking to Siri and picking up sounds around the wearer, but Apple has not decided whether to add a speaker for back-and-forth ‌Siri‌ conversations and audio playback.

Siri

The AI pin will run the updated version of ‌Siri‌ that Apple plans to unveil in iOS 27. Apple is working on a chatbot upgrade for ‌Siri‌, putting it on par with Claude, Gemini, and OpenAI.

‌Siri‌ will be powered by a version of Gemini thanks to Apple's partnership with Google. All of the intelligence features promised in iOS 18 are expected in iOS 27, plus more.

iPhone Reliance

The AI pin will have a dedicated chip inside, but it will be similar to the H2 chip in the AirPods. It's not going to be a high-powered chip, and most processing will be done on the iPhone.

Apple is not designing the AI pin to be a standalone device, and it will instead be marketed as an iPhone accessory. Bloomberg said some Apple employees see it as the "eyes and ears" of the iPhone.

Competition

OpenAI is also rumored to be working on an AI device through its collaboration with former Apple designer Jony Ive. OpenAI's device will be powered by ChatGPT, and it could launch in 2027. Rumors suggest that it's a small, pocket-sized non-wearable, but it would still compete with a similar AI wearable from Apple.

Other wearable AI devices like the $700 Humane AI Pin have failed, but the Humane pin was developed as a standalone device rather than an accessory to an existing product like the iPhone.

Apple's Other AI Wearable Work

Apple is working on AirPods that have a built-in infrared camera that's meant to gather information about the wearer's surroundings, similar to the pin. Development on the AirPods is further along, and rumors suggest we could see a camera-equipped version of the AirPods Pro as soon as this year.

Apple is also developing smart glasses that will compete with the Meta Ray-Bans. The glasses will have a high-resolution camera system able to capture photos and videos, plus a second camera that feeds visual data to ‌Siri‌ for environmental context. The glasses won't have an embedded display in the lens, and are reliant on the upcoming smarter version of ‌Siri‌.

Launch Date

Development on the AI pin is in the early stages, and it could still be canceled. If Apple moves forward with plans for the pin, it's possible that it could launch as soon as 2027.Related Roundup: AirTagBuyer's Guide: AirTag (Buy Now)
This article, "Apple's AirTag-Sized AI Pin: Everything We Know" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Apple continues to celebrate its upcoming 50th anniversary by hosting events around the world, with the latest two held in the UK and Australia today.

Mumford & Sons at Apple Battersea
Outside of its UK headquarters at the former Battersea Power Station in London, Apple hosted British folk-rock band Mumford & Sons for an under-the-radar performance that was open to the public. Apple invited MacRumors reporter Hartley Charlton to the event, which included a private reception for media personnel.


Over in Australia, Apple showcased digital artwork on the Sydney Opera House's eastern sails. The artwork was created in the Procreate app on the iPad by a group of 10 emerging Australian artists. Through free Today at Apple sessions, the public also had the opportunity to create and submit artwork for potential illumination.

Apple showcased digital artwork at the Sydney Opera House
If you missed tonight's exhibition, Apple said additional artwork from both commissioned artists and public submissions will be curated and projected onto the Opera House's eastern sails on March 26 and March 27 at 8 p.m. local time.

Apple has hosted celebrations in many other countries, including the United States, France, China, South Korea, and Thailand, with more to follow this week in Canada, Japan, India, and Mexico. Apple turns 50 on April 1.Tags: Apple 50th Anniversary, Apple Battersea
This article, "Apple's 50th: Mumford & Sons in London, Illuminated Artwork in Sydney" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
macOS Tahoe 26.4 introduces a new security feature that warns Mac users if they paste certain commands in the Terminal app that may be harmful.


For those unaware, the Terminal app allows you to enter text commands to perform tasks on your Mac. Terminal is primarily intended for advanced users and developers, but unfortunately casual users can be tricked into entering harmful commands that can permanently delete files, change user permissions, and cause other problems.

Here is what the warning says when it appears:The warning was spotted by users across Reddit and X over the past week.

Screenshot via "Mr. Macintosh"
We have yet to determine exactly which commands trigger the warning, which does not always appear. For this reason, always be careful. If you are unfamiliar with how Terminal works, it is probably best to avoid using it entirely.

macOS 26.4 was released earlier this week.Related Roundup: macOS TahoeTags: Apple Security, TerminalRelated Forum: macOS Tahoe
This article, "macOS 26.4 Introduces New Security Feature for Terminal Commands" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Cisco’s widely deployed Catalyst 9300 Series enterprise switches have four security vulnerabilities, two of which could be chained to cause a denial-of-service outage, infrastructure security company Opswat has revealed.
The two most operationally significant are CVE-2026-20114 and CVE-2026-20110, which the researchers found could be chained to make possible a dangerous privilege escalation. Opswat’s Unit 515 Critical Infrastructure Protection (CIP) Lab discovered them and reported them to Cisco last July.
The first weakness was in the Catalyst WebUI Lobby Ambassador account, which exists to allow non-technical staff with no admin privileges to administer guest Wi-Fi access.
This turned out to have a command injection vulnerability (CVE-2026-20114) which allowed the researchers to create a MAC-based account with a slightly higher privilege level.
With this access, they then discovered a second and more serious vulnerability caused by insufficient sanitization (CVE-2026-20110) which allowed them to reach a high enough privilege level to put Catalyst 9300 switches into ‘maintenance mode,’ at which point they would stop passing traffic.
“This vulnerability chain allows a low privileged user to escalate their capabilities and ultimately trigger a full denial of service condition on the Cisco device,” Opswat said in a proof-of-concept video.
Opswat also discovered two other Catalyst 9300 vulnerabilities: CVE-2026-20112 (cross-site scripting) and CVE-2026-20113 (CRLF injection). These relate to the IOS XE IOx integration environment which enables cloud edge computing features on Catalyst switches.
The first of these, CVE-2026-20112, could be exploited by an “authenticated user [who] could store malicious JavaScript payloads that would later execute in the context of another user’s session,” said Opswat in its full vulnerability analysis.
The second, CVE-2026-20113, would allow an attacker to cover their tracks for any exploit on IOS XE IOx: “By injecting crafted control characters, an attacker can forge or manipulate log entries, potentially obscuring malicious activity and compromising the integrity of audit records,” said Opswat, adding that this weakens the reliability of logging mechanisms critical for monitoring, incident response, and forensic analysis.
Patching priority
To make headway, an attacker would need to chain the first two vulnerabilities, CVE-2026-20114 and CVE-2026-20110, the first of which would require authentication using stolen credentials.
This slightly raises the bar to any compromise, although stealing credentials for low-privilege user accounts is not a major barrier for an attacker.
However, the fact that an attacker can elevate privileges from a basic Lobby Ambassador account to put a switch into a denial-of-service state underlines the risk this vulnerability poses. A short-term mitigation for this would be to make sure MFA security is turned on for all user accounts accessing the Lobby Ambassador feature.
According to Opswat, it took from last July until this month to patch the flaws because of Cisco’s twice-yearly patching cycle.
“Since we reported these issues in August 2025, there was not enough time for Cisco to complete the investigation, remediation, and advisory process in time for the September cycle. As a result, publication moved to the next advisory window in March 2026,” pen testing team leader Loc Nguyen said. “To the best of our knowledge, there is no evidence that these vulnerabilities were exploited by third parties,” he added.
Vulnerable products and fixes
Cisco has addressed all four CVEs in its March 25 semiannual Cisco IOS and IOS XE Software Security Advisory. Although none of the individual CVSS scores are high (ranging from 4.8 for CVE-2026-20112 to 6.5 for CVE-2026-20110) the danger is amplified by the way the first two can be chained.
Cisco’s Software Checker tool can be used to determine whether a switch is vulnerable by entering the software/firmware version currently in use.
No workarounds are possible for CVE-2026-20114, CVE-2026-20112, or CVE-2026-20113. The highest-rated flaw, CVE-2026-20110, can be mitigated by setting the privilege level of the ‘start maintenance’ command manually from the command line interface, Cisco said.
In February, Cisco made public a different series of vulnerabilities affecting the Catalyst SD-WAN Manager, CVE-2026-20122, CVE-2026-20126, and CVE-2026-20128. These allowed an attacker to elevate themselves to root and were assigned a CVSS score of 9.8 (‘critical’) with no workarounds possible.
That same month Cisco also patched a vulnerability in its Catalyst SD-WAN Controller, CVE-2026-20127.
This article first appeared on Network World.

View the full article
The alleged administrator of the LeakBase cybercrime forum has been arrested by Russian law enforcement authorities, state media reported Thursday. According to TASS and MVD Media, a news website linked to the Russian Interior Ministry, the suspect is a resident of the city of Taganrog. The suspect is said to have been detained for creating and managing a criminal site that allowed stolenView the full article
Google today said that Android has set a new record for mobile web performance, making it the fastest mobile platform for web browsing.


The newest Android devices have set new records on web performance benchmarks like Speedometer and LoadLine, which Google attributes to "deep vertical integration across hardware, the Android OS, and the Chrome engine."

Speedometer simulates real-world user actions to measure interaction latency when using a web browser, and it's a metric that major browser engine developers use to determine responsiveness. According to Google, a high Speedometer score correlates to a "more fluid, snappy feeling when you tap, scroll, or type on a website."

In charts published by Google, three unnamed Android devices earned higher Speedometer 3.1 scores than an unnamed "competing mobile phone platform," which is likely iOS.


LoadLine is an emerging benchmark test developed by the Chrome and Android teams that simulates the complete process of loading a website to determine how fast a webpage appears after a link is clicked. Android phones score up to 47 percent higher on the LoadLine test than non-Android competitors, according to Google.

Google says that it collaborated with select SoC and OEM partners to optimize Chrome and kernel scheduler policies to get the faster web browsing speeds. With the improvements, some Android flagship phones have improved their Speedometer and LoadLine scores by 20 to 60 percent year-over-year. For users, the change translates to four to six percent faster page loads and six to nine percent faster high-percentile interactions.Tags: Android, Chrome, Google
This article, "Google Claims Android Is Now Faster Than iPhone for Web Browsing" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Apple has full access to Gemini to customize the model for Siri and other AI features, reports The Information. Google gave Apple "complete access" to the Gemini model in its own data centers, and Apple can use the access for distillation, or creating smaller models for specific tasks. Apple is able to design models that are built to run on Apple devices without the need to connect to the internet.


The Information explains that Apple can ask the main Gemini model to perform a series of tasks that provide high-quality results, with a rundown of the reasoning process. Apple can feed the answers and reasoning information that it gets from Gemini to train smaller, cheaper models. With this process, the smaller models are able to learn the internal computations used by Gemini, producing efficient models that have Gemini-like performance but require less computing power.

Apple is also able to edit Gemini as needed to make sure that it responds to queries in a way that Apple wants, but Apple has been running into some issues because Gemini has been tuned for chatbot and coding applications, which doesn't always meet Apple's needs.

Apple is relying on Google's Gemini models for the smarter, chatbot version of Siri that's planned for iOS 27, but the Apple Foundation Models team is still working on Apple AI models that are distinct from the Gemini models.

‌Siri‌ will be able to do many of the same things that Gemini and other chatbots are able to do, such as answering questions, summarizing information, scanning and understanding uploaded documents, telling stories, providing emotional support, and completing tasks like booking travel.Tags: Gemini, Google
This article, "Apple Can Create Smaller On-Device AI Models From Google's Gemini" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Poland's government has announced plans to begin drafting legislation to impose a tax of up to 3% on revenues from certain digital services, a move that could affect Apple and other major U.S. tech companies operating in the country.


Reuters reports that Deputy Prime Minister and Digitalization Minister Krzysztof Gawkowski announced the decision on Tuesday, describing it as an effort to ensure fair competition between domestic businesses and large foreign digital platforms.



The bill would tax companies that earn money from targeted online ads, platforms where users connect or buy and sell, and selling user data. It would only affect companies making over €1 billion globally and more than $6.79 million in Poland per year.

Based on that language, Apple services including the App Store, Apple Music, Apple TV+, Apple Books, Apple Podcasts, and its growing advertising business could fall within scope. At the same time, the draft includes broad exemptions, such as digital interfaces whose "sole or main purpose" is delivering content owned by the provider or for which it holds distribution rights, as well as online stores where the seller is not acting as an intermediary. Apple could potentially argue that some of its services qualify for those carve-outs, though the draft's language leaves considerable room for interpretation.

Alphabet, Meta, and Amazon would also likely be subject to the tax if the bill passes as written. Poland's digital tax push comes just months after the European Commission reversed its own plans for a similar digital levy.Tag: Poland
This article, "Poland Announces Digital Services Tax That Could Hit Apple" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Cybersecurity researchers have flagged a new evolution of the GlassWorm campaign that delivers a multi-stage framework capable of comprehensive data theft and installing a remote access trojan (RAT), which deploys an information-stealing Google Chrome extension masquerading as an offline version of Google Docs. "It logs keystrokes, dumps cookies and session tokens, captures screenshots, andView the full article
Apple this week released tvOS 26.4, and the software update includes a handful of new features and changes for the Apple TV.


tvOS 26.4 is compatible with all Apple TV 4K and Apple TV HD models released since 2015. To update your Apple TV, open the Settings app on the device, navigate to System → Software Updates, and select Update Software.

Below, we have recapped what is new in tvOS 26.4.

tvOS 26.4: New Features

Genius Browse


Apple added a new "Genius Browse" section to the ‌Apple TV‌ app on tvOS 26.4. Genius Browse is a content discovery feature that provides recommendations for TV shows and movies across multiple suggested categories. Suggestions vary based on content preferences, and the options are updated regularly.

Examples of categories include "Bittersweet Family Dramas" and "Good for a Pick-Me-Up."

Continuous Audio Connection

Apple says tvOS 26.4 fixes an issue with audio playback on Apple TV 4K that can occur when sound transitions between programs with different formats.

Specifically, there is a new "Continuous Audio Connection" setting in the Settings app, under Video and Audio → Audio Format → HDMI Output.

"Apple TV uses a Dolby MAT connection for glitch-free playback across formats," reads Apple's description of the setting. "Older receivers may indicate an Atmos connection, but original mixes will not be modified."

Subtitle Styling

You can now change the style of subtitles/captions while you are watching content in the Apple TV app and other apps that use the Apple TV's default video player, without needing to open the Settings app. You can adjust the size and appearance of the subtitles, opt for subtitles to have a transparent background, and so forth.

To turn on subtitles from the video player, look for the speech bubble button.

No More iTunes TV Shows and Movies Apps


tvOS 26.4 finally removes the preinstalled iTunes TV Shows and iTunes Movies apps from the Apple TV, with all content now found in the Apple TV app.

Performance Improvements

Apple says tvOS 26.4 includes performance and stability improvements.

tvOS 26.4: Release Notes

Here are Apple's release notes for tvOS 26.4:Some tvOS features are limited to newer Apple TV models.Related Roundup: Apple TVBuyer's Guide: Apple TV (Don't Buy)Related Forum: Apple TV and Home Theater
This article, "tvOS 26.4 Adds These New Features to Your Apple TV" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Amazon today has the AirPods Pro 3 available for $199.00 during its Big Spring Sale, down from $249.00. This is a match of the all-time low price on the AirPods Pro 3, and one of the best all-around deals you can get during the Amazon's springtime Prime Day.

Note: MacRumors is an affiliate partner with some of these vendors. When you click a link and make a purchase, we may receive a small payment, which helps us keep the site running.

This model of the AirPods Pro launched in September 2025 and has 2x better Active Noise Cancellation than the previous generation, better audio quality, a revised fit that's meant to improve comfort and stability, Live Translation for in-person conversations, and heart rate sensing for workouts.

$50 OFFAirPods Pro 3 for $199.00

You can also get the AirPods 4 for $99.99 in the Big Spring Sale, down from $129.00, which is a solid second-best price. You can find all of the best discounts going on during this event in our dedicated post, which highlights discounts on AirTag, iPads, MacBooks, and more.

Keep up with all of this week's best discounts on Apple products and related accessories in our dedicated Apple Deals roundup.



Deals Newsletter

Interested in hearing more about the best deals you can find in 2026? Sign up for our Deals Newsletter and we'll keep you updated so you don't miss the biggest deals of the season!




Related Roundup: Apple Deals
This article, "AirPods Pro 3 Hit $199 Record Low Price in Amazon's Big Spring Sale" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
App Store Connect is a tool that allows app developers to view App Store metrics such as total downloads, and today it is receiving a major update.


"Analytics in App Store Connect receives its biggest update since its launch," said Apple, in a post on its developer news portal.

Apple says App Store Connect has a refreshed user experience that makes it easier to measure the performance of apps and games. There are more than 100 new metrics available, including new in-app purchase and subscription data.

Here is what is new, according to Apple:Apple has an App Store Connect app for the iPhone and iPad. App Store Connect is also available on the web at appstoreconnect.apple.com.Tags: App Store, App Store Connect
This article, "Apple Updates App Store Connect With More Than 100 New Metrics" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Apple is accepting pre-orders for the AirPods Max 2 headphones that were introduced on March 16, with a purchase option now available on the Apple.com website.


In the U.S., Apple's online store lists a delivery timeframe of April 1 to April 3.

Priced at $549, the ‌AirPods Max 2‌ feature the same design as the original AirPods Max, but Apple updated the over-ear headphones with an H2 chip that adds new capabilities already offered by other AirPods models.

The H2 chip delivers up to 1.5x better Active Noise Cancellation with computational audio algorithms that are better able to detect and mitigate outside sound. Real-time Live Translation is supported, and features like Adaptive Audio, Voice Isolation, Conversation Awareness, Loud Sound Reduction, and Personalized Volume are available.

Audio quality has improved with a new high dynamic range amplifier that offers more consistent bass, more natural-sounding mids and highs, and improved localization of instruments. Transparency Mode sounds more natural than before, and the Digital Crown on the AirPods Max can now be used as a camera shutter for the iPhone or iPad. Bluetooth has been upgraded to Bluetooth 5.3.

The ‌AirPods Max 2‌ charge using USB-C and last for up to 20 hours in ANC mode before needing to be recharged. Like the prior-generation USB-C model, the ‌AirPods Max 2‌ support 24-bit 48kHz lossless audio over USB-C, and ship with a Smart Case. Color options continue to include midnight, starlight, orange, purple, and blue.Related Roundup: AirPods Max 2Buyer's Guide: AirPods Max (Buy Now)Related Forum: AirPods
This article, "AirPods Max 2 Now Available for Pre-Order With Delivery as Soon as April 1" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Amazon this week is hosting a "Big Spring Sale," which includes deals and offers on everything from Apple devices to clothes, kitchen electronics, furniture, and much more. The new event is set to run through March 31, so you'll have a few days of discounts to shop, with new markdowns appearing every day.

Note: MacRumors is an affiliate partner with some of these vendors. When you click a link and make a purchase, we may receive a small payment, which helps us keep the site running.

This Prime Day-like event has record low prices and great deals on a huge variety of Apple products and related accessories, and in this article we're focusing mainly on Apple devices. Below you'll find big discounts on AirPods, iPads, MacBooks, and more. Similar to Prime Day, some deals will require a Prime membership.

AirPods



Amazon today has the AirPods Pro 3 available for $199.00, down from $249.00. This is a match of the all-time low price on the AirPods Pro 3, which has been rare on Amazon in recent weeks.

$30 OFFAirPods 4 for $99.00
$50 OFFAirPods Pro 3 for $199.00

This model of the AirPods Pro launched in September 2025 and has 2x better Active Noise Cancellation than the previous generation, better audio quality, a revised fit that's meant to improve comfort and stability, Live Translation for in-person conversations, and heart rate sensing for workouts.

AirTag



Amazon has the first generation AirTag 4-Pack on sale for $59.99 during the Big Spring Sale, down from $99.00. This is a new record low price on the first generation accessory.

$39 OFFAirTag 4-Pack for $59.99
Apple Watch Series 11



Amazon this week has all-time low prices on the Apple Watch Series 11, with $100 discounts across numerous models of the smartwatch. We first started tracking the return of these deals last month, but this sale has now expanded with many more options on both 42mm and 46mm GPS models.

$100 OFFApple Watch Series 11 (42mm GPS) for $299.00
$100 OFFApple Watch Series 11 (46mm GPS) for $329.00

You can get the 42mm GPS Apple Watch Series 11 for $299.00, down from $399.00, and the 46mm GPS model for $329.00, down from $429.00. On Amazon, you'll find four of the 42mm GPS models on sale at this all-time low price, and four of the 46mm GPS models on sale as well.

$100 OFFApple Watch Series 11 (42mm Cell) for $399.00
$100 OFFApple Watch Series 11 (46mm Cell) for $429.00

If you're shopping for cellular models, you can find record low prices on multiple models this week on Amazon. The 42mm cellular Apple Watch Series 11 has hit $399.00, down from $499.00, and the 46mm cellular model has hit $429.00, down from $529.00.

M4 iPad Air



Amazon is taking up to $100 off the brand new M4 iPad Air during its Big Spring Sale this week. Specifically, Amazon has up to $80 off the 11-inch M4 iPad Air and up to $100 off the 13-inch M4 iPad Air. All of these discounts have been automatically applied and do not require a coupon code or a Prime membership.

$40 OFF11-inch M4 iPad Air for $559.00
$50 OFF13-inch M4 iPad Air for $749.00

The new iPad Air features the M4 chip, C1X modem, and N1 networking chip, which brings support for Wi-Fi 7 and Bluetooth 6. In terms of design, the 2026 models are identical to the 2025 iPad Air tablets, with an edge-to-edge display, slim bezels, and aluminum chassis.

11-inch M4 iPad Air

128GB Wi-Fi - $559.00 ($40 off)
256GB Wi-Fi - $649.00 ($50 off)
512GB Wi-Fi - $839.00 ($60 off)
1TB Wi-Fi - $1,017.34 ($82 off)

13-inch M4 iPad Air

128GB Wi-Fi - $749.00 ($50 off)
256GB Wi-Fi - $836.50 ($63 off)
512GB Wi-Fi - $1,044.00 ($55 off)
iPad



Amazon this week is taking $50 off Wi-Fi models of Apple's 11th generation iPad, as well as $100 off the iPad mini 7. Prices start at $299.00 for the 128GB Wi-Fi iPad, down from $349.00, which is a solid second-best price on this model.

$50 OFF128GB Wi-Fi iPad for $299.00
$50 OFF256GB Wi-Fi iPad for $399.00
$50 OFF512GB Wi-Fi iPad for $599.00

We saw a few of these iPad models around $20 cheaper over the holiday season last year, but those all-time low prices never reappeared. As of now, Amazon's discounts are the best prices we've tracked so far in 2026.

iPad mini 7



There are also quite a few $100 discounts on the iPad mini 7 this week on Amazon, starting at $399.00 for the 128GB Wi-Fi tablet, down from $499.00. It's been a few weeks since we last tracked prices this low on the iPad mini 7.

$99 OFF128GB Wi-Fi iPad mini 7 for $399.99
$99 OFF512GB Wi-Fi iPad mini 7 for $699.99
M5 MacBook Air



Apple's new M5 MacBook Air just launched, and now Amazon has the first cash discounts on these models. You'll find $50 off nearly every new MacBook model on Amazon, without the need of a membership or clipping a coupon.

$50 OFF13-inch M5 MacBook Air (512GB) for $1,049.00
$50 OFF15-inch M5 MacBook Air (512GB) for $1,249.00

Although only $50 markdowns, these are the first and most notable discounts on the new M5 MacBook Air.

M5 Pro/M5 Max MacBook Pro



Similar to the MacBook Air, Amazon is also taking $49 off the M5 Pro and M5 Max MacBook Pro for its Big Spring Sale.

$49 OFF16-inch M5 Pro MacBook Pro (24GB/1TB) for $2,649.99
$49 OFF16-inch M5 Max MacBook Pro (36GB/2TB) for $3,849.99
Apple Studio Display



Apple just launched the new line of Studio Displays this month, and now Amazon has introduced the first discount on the Standard Glass model with Tilt-Adjustable Stand. You can get this Studio Display for $1,499.00, down from $1,599.00, a new all-time low price.

$100 OFFApple Studio Display (Standard/Tilt) for $1,499.00
$100 OFFApple Studio Display (Standard/VESA) for $1,499.00
$100 OFFApple Studio Display (Nano-Texture/VESA) for $1,799.00
$100 OFFApple Studio Display (Standard/Tilt & Height) for $1,899.00

If you're on the hunt for more discounts, be sure to visit our Apple Deals roundup where we recap the best Apple-related bargains of the past week.



Deals Newsletter

Interested in hearing more about the best deals you can find in 2026? Sign up for our Deals Newsletter and we'll keep you updated so you don't miss the biggest deals of the season!




Related Roundup: Apple Deals
This article, "Amazon Prime Day 'Big Spring Sale' Introduces Major Discounts on AirPods, iPads, AirTag, and Much More" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
OpenAI is overhauling the shopping experience in its ChatGPT app by shifting the focus from in-app purchases to product discovery, after the company's Instant Checkout feature apparently failed to gain traction.


Launched in September, Instant Checkout let users buy items from retailers like Etsy, Walmart, and Shopify directly within ChatGPT. In a new product post, OpenAI now says it is deprioritizing the feature as a standalone offering, because it "did not offer the level of flexibility that we aspire to provide."

In place of it, ChatGPT is getting richer visual shopping tools, including side-by-side product comparisons, image-based search for finding similar items, and conversational result filtering.

OpenAI says the updates are powered by an expansion of its Agentic Commerce Protocol, which lets merchants feed product catalogs and promotions directly into ChatGPT. Retailers including Target, Sephora, Nordstrom, Best Buy, and The Home Depot are already on board.

Meanwhile, Walmart is launching a dedicated in-app ChatGPT experience that supports account linking, loyalty programs, and its own payment system. The updates are rolling out this week to all ChatGPT Free, Go, Plus, and Pro users.

In related news, OpenAI yesterday said that it is ending support for its Sora AI video app just six months after it initially launched.Tags: ChatGPT, OpenAI
This article, "ChatGPT Revamps Shopping Features, Drops In-App Checkout" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
What started as a supply chain attack on Trivy, a widely used security scanner, has become a Lapsus$-linked extortion campaign, with more than 1,000 enterprise SaaS environments already compromised.
Charles Carmakal, CTO of Mandiant Consulting, made the assessment at a Google-hosted threat briefing held alongside the RSA Conference 2026 in San Francisco on Tuesday.
“We know of over 1,000 impacted SaaS environments right now that are actively dealing with this particular threat campaign,” he said at the event, reported CyberScoop. “That thousand-plus downstream victims will probably expand into another 500, another 1,000, maybe another 10,000.”
He, according to the report, warned that widespread breach disclosures and follow-on attacks would play out over the coming months.
The criminal collaboration behind the attack has also widened. Where the initial breach was attributed to a cloud-native threat group called TeamPCP, Mandiant’s response work has revealed that those actors are now channeling stolen access to broader criminal networks with Lapsus$, a group known for high-profile and aggressive extortion, among confirmed collaborators, the report added.
Katie Paxton-Fear, staff security advocate at cybersecurity firm Semgrep, warned the group may already be positioned for further strikes. “The attackers may be sitting on many more compromises across the open-source ecosystem, waiting for guards to go down before launching the next,” she said.
Cloud security company Wiz and supply chain security firm Socket have also documented that expansion across multiple fronts.
Widening blast radius
Wiz, in its technical analysis of the attack, found that attackers extended their reach to LiteLLM, a widely used AI middleware library embedded across a significant portion of cloud environments, using credentials stolen during the initial Trivy breach.
Socket, meanwhile, identified a self-replicating worm dubbed CanisterWorm that leveraged stolen npm publish tokens from the same breach to backdoor more than 29 packages across the npm ecosystem.
The attackers have also publicly stated their intent to target additional open-source projects, with Socket reporting messages posted by the group on Telegram taunting the security industry and signaling plans to expand the campaign.
Paxton-Fear noted that the timing of the escalation appeared calculated. “The attackers first gained access to LiteLLM during their attack last week on Trivy, but they didn’t rush to attack while defenders were already on high alert,” she said. “Instead, they sat on their access, waiting until defenders were busy with a major security conference.”
Socket’s threat research team also identified further compromised Trivy artifacts on Docker Hub over the weekend — versions 0.69.5 and 0.69.6 — published without corresponding GitHub releases and carrying the same infostealer payload. Even after removal, Socket found cached copies continued to circulate through the mirror infrastructure, including mirror.gcr.io.
The firm also found that the attackers had defaced Aqua Security’s GitHub organization, renaming all 44 repositories with descriptions reading “TeamPCP Owns Aqua Security,” based on archived snapshots it analyzed.
“The presence of these repositories indicates a deeper level of control over the GitHub organization during the compromise,” Socket wrote in the analysis.
A pattern of persistent access
This is the second compromise affecting the Trivy ecosystem within roughly a month. Socket identified compromised Aqua Trivy VS Code extension releases on OpenVSX in late February, and now trivy-action, Trivy’s official GitHub Action for running scans in CI/CD workflows, has been abused through manipulated version tags to distribute malicious code across pipelines.
“Repeated compromises of the same vendor in a short period suggest a persistent weakness,” said Cory Michal, CSO of SaaS security management company AppOmni. He said the method reflects a broader pattern. Rather than targeting victims individually, attackers compromised the organization behind a trusted supply-chain component and used its GitHub repository and mutable version tags to reach downstream users at scale.
“Many organizations still allow build systems and developers to automatically pull in third-party code from the internet with limited review and too much implicit trust,” Michal said. “Convenience and speed in modern software delivery have outpaced governance.”
Isaac Evans, founder and CEO of Semgrep, said the incident shows how easily broken pipeline trust can be re-exploited. “Defenders need to adopt the same mindset as attackers — continuously probing their own surface and verifying the integrity of their pipelines, rather than relying on static controls or assumed trust,” he said.
As the fallout continues to unfold, Aqua Security and Mandiant are still working to fully contain the damage.
Where things stand
In a Tuesday update, Aqua Security said it has engaged incident response firm Sygnia. Credential revocation and rotation across all environments remains ongoing. The company maintained that its commercial products are architecturally isolated from the compromised open-source environment and remain unaffected.
According to CyberScoop, Mandiant said it has not yet determined how the original credentials were first stolen, and believes the initial theft likely occurred outside the direct victim’s environment, possibly through a business process outsourcer or partner organization.
For AppOmni’s Michal, the incident is a warning that the industry’s approach to third-party code needs to fundamentally change. “Organizations need stronger controls around what external code they allow, how it is approved, how it is pinned, and how changes are monitored before that code is trusted inside production or SaaS-connected environments,” he said.
View the full article
In September 2025, Anthropic disclosed that a state-sponsored threat actor used an AI coding agent to execute an autonomous cyber espionage campaign against 30 global targets. The AI handled 80-90% of tactical operations on its own, performing reconnaissance, writing exploit code, and attempting lateral movement at machine speed. This incident is worrying, but there's a scenario that shouldView the full article
The U.S. Department of Justice (DoJ) said a Russian national has been sentenced to two years in prison for managing a botnet that was used to launch ransomware attacks against U.S. companies. Ilya Angelov, 40, of Tolyatti, Russia, was also fined $100,000. Angelov, who went by the online aliases "milan" and "okart," is said to have co-managed a Russia-based cybercriminal group known as TA551 (akaView the full article
Cybersecurity researchers are calling attention to an active device code phishing campaign that's targeting Microsoft 365 identities across more than 340 organizations in the U.S., Canada, Australia, New Zealand, and Germany. The activity, per Huntress, was first spotted on February 19, 2026, with subsequent cases appearing at an accelerated pace since then. Notably, the campaign leveragesView the full article
macOS Tahoe 26.4 includes a new slow charger indicator that tells MacBook users when their charging setup isn't delivering full power.


As described in an updated Apple support document, a "Slow Charger" label now appears in orange text in the battery status menu and above the Battery Level graph in Battery settings. The indicator is accompanied by an info button for more details.

Apple says that to charge more quickly, users should use a power adapter and cable that deliver at least the minimum wattage recommended for their MacBook model.

The feature is similar to one Apple added to iPhone with iOS 18, where periods of slow charging appear as an orange bar in the Battery section of the Settings app.

The slow charger indicator is one of two battery-related changes in macOS 26.4. The update also adds a Charge Limit feature that lets MacBook users set a maximum charge level anywhere from 80 to 100 percent, with the aim of preserving long-term battery health.

macOS Tahoe 26.4 is available now via System Settings ➝ General ➝ Software Update.Related Roundup: macOS TahoeRelated Forum: macOS Tahoe
This article, "macOS Tahoe 26.4 Adds Slow Charger Indicator for MacBooks" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
PyPI is warning of possible credential theft from AI applications and developer pipelines after two malicious versions of the widely used Python middleware for large language models, LiteLLM, were briefly published.
“Anyone who has installed and run the project should assume any credentials available to the LiteLLM environment may have been exposed, and revoke/rotate them accordingly,” PyPI said in an advisory that linked the incident to an exploited Trivy dependency from the ongoing TeamPCP supply-chain attack.
According to a Sonatype analysis, the packages embedded a multi-stage payload designed to harvest sensitive data from developer environments, CI/CD pipelines, and cloud configurations, and were live on PyPI for roughly two hours before being taken down.
“Given the package’s three million daily downloads, the compromised LiteLLM could have seen significant exposure during that short time span,” Sonatype researchers said in a blog post. On top of serving as a stealer, the packages were also acting as droppers, enabling follow-on payloads and deeper system compromise.
Three-stage payload built for maximum reach
The compromise affected versions 1.82.7 and 1.82.8. Sonatype’s analysis noted the payload operating in three distinct stages. These included initial execution and data exfiltration, deeper reconnaissance and credential harvesting, and finally persistence with remote control capabilities.
The attack chain relied heavily on obfuscation, with base64-encoded Python code covering up the payload’s tracks. Once executed, the malware collected sensitive data, encrypted it using AES-256-CBC, and then secured the encryption key with an embedded RSA public key before sending everything to attacker-controlled servers.
The disclosure highlighted a common approach that attackers follow these days. Instead of going off immediately after installation, the malware quietly lingers to map the environment and establish a foothold, before pulling credentials from local machines, cloud configs, and automation pipelines.
“It (payload) targets environment variables (including API keys and tokens), SSH Keys, cloud credentials (AWS, GCP, Azure), Kubernetes configs, CI/CD secrets, Docker configs, database credentials, and even cryptocurrency wallets,” said Wiz researchers, who are separately tracking the campaign, in a blog post. “Our data shows that LiteLLM is present in 36% of cloud environments, signifying the potential for widespread impact.”
Wiz also provided a way for its customers to check their environment for exposure via the Wiz Threat Center.
An expanding supply-chain campaign
The LiteLLM incident has been confirmed to be a part of the rapidly unfolding TeamPCP supply chain campaign that first compromised Trivy.
Trivy, developed by Aqua Security, is a widely used open-source vulnerability scanner designed to identify security issues in container images, file systems, and infrastructure-as-code (IaC) configurations. The ongoing attack, attributed to TeamPCP with reported links to LAPSUS$, involved attackers compromising publishing credentials and injecting credential-stealing code into official releases and GitHub Actions used in CI/CD pipelines.
The Trivy compromise was quickly followed by similar supply chain incidents, with attackers leveraging the same access and tactics to target other developer security tools like KICS and Checkmarx, extending the campaign’s reach across multiple CI/CD ecosystems.
PyPI advisory tied the LiteLLM incident directly to the Trivy compromise. The malicious packages were uploaded “after an API Token exposure from an exploited Trivy dependency,” it said.
Ben Read, a lead researcher at Wiz, calls it a systematic campaign that needs to be monitored for further expansion. “We are seeing a dangerous convergence between supply chain attackers and high-profile extortion groups like LAPSUS$,” he said. “By moving horizontally across the ecosystem – hitting tools like liteLLM that are present in over a third of cloud environments – they are creating a snowball effect.”
PyPI has advised users to rotate any secrets accessible to the affected LiteLLM environment, as researchers confirm active data exfiltration and potential exposure across cloud environments tied to the ongoing campaign.
View the full article
The identity and access management (IAM) market has shifted its focus from traditional “login and MFA” mechanisms toward treating identity as a security control plane.
Buyers are prioritizing phishing-resistant authentication, including passkeys, and the management of non-human identities, according to an array of experts quizzed on developments in the market by CSO.
“Workforce access is still the anchor, but more programs now pull in governance, privileged access, and controls for non-human identities because those gaps are where attackers and auditors keep finding leverage,” says Dave Lewis, global advisory CISO at password management tools vendor 1Password.
While the overall European cybersecurity market grew by 7.5% in 2025, IAM surged by 10.8%, according to industry analysts Context.
As of January 2026, the market has accelerated even further, showing a 24% year-over-year (YoY) increase in the first month alone.
Joe Turner, global director of research and business development at Context, says the market growth reflects how “securing the user” has become a spending priority in many enterprise security programs.
Agentic AI shakes up IAM’s future
The increased need to manage non-human identities — machine identities, AI agents, secrets — is one vector shaping the evolution of IAM, as both a technology and a market.
“Non-human identities — service accounts, API keys, AI agents, and IoT devices — are rising significantly, and in most enterprises they already outnumber human users by around three to one,” says Paul Hanagan, CTO of Conscia UK, a provider of secure and complex digital infrastructures.
The IT industry is moving past the introduction of AI technologies toward agentic AI, where autonomous agents act on behalf of users with increasing autonomy. This transformation requires a rethink in how security controls manage identities and access to resources.
“The volume and independence of these [AI] entities demands careful monitoring, with least-privilege enforcement and secret keys rotated regularly to ensure non-human identities are secure,” Hanagan says. “Hackers are increasingly targeting non-human identities to gain access, so these services must be secured with the same rigor as human accounts.”
AI should play a big role in behavior analytics, entitlement management, and configuration management by helping to build an identity fabric that bridges security and governance.
“To work effectively, AI agents will need continuous access to all sorts of data, which will lead to rapid behavioral changes,” says Jon Oltsik, analyst in residence at SiliconAngle and theCUBE. “We’ll need policies and guardrails here.”
Passwordless authentication on the rise
Passwords have long been the weakest link in most security architectures.
Many mobile phones and laptops already use biometrics for authentication, and the user experience is typically far better than typing a long and complex password into an interface.
The growing uptake of passwordless authentication (FIDO2/passkeys, biometrics) is redefining the scope of many IAM projects.
“Many enterprises are still in the early stages of deploying passkeys and FIDO2, and biometrics are often deployed as part of a broader MFA strategy, where hardware costs and management overhead remain barriers to widespread adoption,” says Conscia’s Hanagan.
Regulations shake up IAM architectures
The regulatory environment has evolved from a tick-box exercise in compliance toward governance and continuous testing to demonstrate corporate adherence to regulations. That shift, according to Conscia’s Hanagan, is actively reshaping how organizations architect their IAM programs.
“There is a significant amount of regulatory work under way,” he says. “GDPR, NIS2, DORA, PCI DSS 4.0, and sector-specific frameworks all focus on who accesses what, when, and why.”
Hanagan adds: “The EU often takes a different approach to the UK — eIDAS 2.0, for example, is driving digital identity wallet adoption across Europe — which makes compliance particularly difficult for multinational enterprises spanning multiple regions.”
Sovereign IAM and eIDAS 2.0 decentralize identity
With the introduction of the European Digital Identity (EUDI) Wallet, companies are looking at decentralized identity architectures.
“Instead of storing user data, European firms are becoming ‘relying parties,’ verifying identities through cryptographic proof via government-backed digital wallets to reduce PII [personally identifiable information] liability and comply with the EU Data Act, particularly regarding data minimization,” Context’s Turner says.
Managed IAM services make their pitch
Issues such as the cybersecurity workforce gap and the technical complexity of IAM in the modern enterprise are impacting both CISOs’ identity and access strategies and the direction of the IAM market.
“Most organizations are running hybrid estates alongside SaaS sprawl, and the identity surface is fragmented across multiple directories, legacy apps, and inconsistent entitlement models,” 1Password’s Lewis says.
To bridge the challenges posed by this complexity in the face of talent shortages, many organizations are turning to managed IAM services, according to Conscia’s Hanagan.
“Modern IAM solutions are complex to set up and require deep knowledge and expertise,” he says. “When this is coupled with the fear that AI may displace roles — which discourages new entrants into the profession — and tightening regulation, it takes its toll on why modern IAM projects struggle to progress at pace.”
The IAM industry consolidates
The IAM market is going through a period of consolidation as vendors vie to build the most comprehensive platforms while tackling the problem of managing machine identities and AI agents.
Notable IAM M&A activity over recent months include:
Last July, Palo Alto Networks acquired privileged access management firm CyberArk for $25 billion. Delinea announced plans to acquire universal access management firm StrongDM in March. StrongDM provides “just-in-time” access for DevOps and AI agents, moving Delinea from offering static password management to offering a platform for dynamic, runtime authorization. Financial terms of the deal were not disclosed. CrowdStrike has announced deals to acquire identity security startup SGNL for $740 million and browser security startup Seraphic Security for $420 million in January 2026. SGNL provides the ability to grant access based on real-time context (e.g., “Allow this dev to see the database only while they have an active Jira ticket.”) Zscaler snapped up SquareX in February 2026, allowing it to acquire browser security technology that can detect identity-based attacks on unmanaged devices. Sophos is buying Arco Cyber in a deal focused on bringing AI-powered governance to the midmarket. “It [the deal] targets those 50- to 500-seat companies that lack a full-time CISO but need to meet the new UK Cyber Security Bill requirements,” Context’s Turner says. See also:
How cybersecurity leaders can defend against the spur of AI-driven NHI Agentic AI already hinting at cybersecurity’s pending identity crisis Your passwordless future may never fully arrive What are non-human identities and why do they matter? Always-on privileged access is pervasive — and fraught with risks Redefining multifactor authentication: Why we need passkeys View the full article
Traditionally, enterprise security operating models operated a fixed and regular cycle: Findings surfaced through periodic scans, security teams triaged results and remediation followed through ticket-based workflows. It was almost an SOP of sorts; the accountability existed, but it was often implicit and fragmented. The remediation would travel across tools, teams and handoffs rather than designed into the system itself. The result? Your product was already live, your security teams had raised the alarms and moved on to identifying risk with the next big thing, but the remediation kept falling behind and your incident response teams kept getting busy with MSIs. 
That model held together largely because the speed of decision-making for remediation was traded off at times in favor of fail-fast, disrupt-fast innovation. A structure of coverage using just manual reviews scoped to the code being promised as being shipped, periodic scanner report triages and delayed prioritization were sufficient when software delivery moved at a measured pace. 
AI-native product development has fundamentally altered that equilibrium. 
Adopting LLM-based AI-assisted security triage helps accelerate how teams detect, triage and prioritize those vulnerability findings and thus eliminates the delay between identifying issues and making decisions. Findings no longer arrive as a bunch of scan outputs waiting in a queue for someone to be picked up and triaged without any metadata. They arrive with context: Exploitability indicators (both external and specific to your app/platform), ownership metadata and business-impact signals. 
This shift does more than just increase the speed of triage. It forces teams to rethink who owns vulnerabilities, who decides what gets fixed and how quickly those decisions happen. Existing operating models can’t keep up—they weren’t built to handle findings that arrive fully contextualized and demand immediate action. 
Accountability was implicit until AI made it visible 
Traditional vulnerability management relied heavily on abstraction. Scanners fed findings into dashboards, which produced tickets that accumulated in backlogs. Teams treated the workflow itself as assigning ownership, but nobody explicitly named the responsible team or role upfront. 
In practice, this created confusion. When a vulnerable dependency showed up across multiple services, or when severity changed based on new intelligence, figuring out “who owns this?” became a procedural exercise rather than something the system just knew. 
AI-driven platforms change that dynamic. By correlating findings across the full lifecycle, from discovery through remediation, they surface ownership at detection time. When a vulnerability gets mapped directly to a repository, pipeline and responsible team, accountability stops being a matter of ticket routing. It becomes baked into the system architecture. 
What was once a coordination problem becomes a governance question: If ownership is now clear the moment something is detected, who is accountable for acting on it? 
AI triage redefines the security team’s role 
As AI systems increasingly triage vulnerabilities with high confidence, security teams face a subtle but consequential shift in responsibility. 
People no longer debate whether AI can reduce noise. It demonstrably can. The harder question is which responsibilities remain with security teams once triage is automated. Are they accountable for handling individual findings, ensuring model accuracy or governing the decision system itself? 
In practice, effective programs are settling into a hybrid model. Let AI triage routine alerts and flag high-risk items. Have analysts investigate unusual signals, tune the decision rules and approve exceptions. Metrics shift accordingly. Instead of counting defects, teams now track false positive rates, confidence in coverage and how model performance changes over time. 
This transition alters how security expertise gets used. Teams spend less time on manual triage and more time ensuring the quality of decisions the system makes. 
Why “human-in-the-loop” still matters at scale 
Fully autonomous security testing is often framed as an end goal, but in practice, it introduces new accountability gaps. When systems make decisions without defined human checkpoints, responsibility becomes diffuse, especially when those decisions affect production environments. 
Some of the most effective AI-driven security programs intentionally maintain human decision points. Not as bottlenecks, but as accountability checkpoints. Automation accelerates detection and enrichment. Humans retain authority over high-stakes outcomes. 
A useful parallel exists in broader AI safety research. Google’s “Big Sleep” project, for example, proved AI can identify exploitable vulnerabilities before attackers do. But it still needed human supervision to validate findings and take appropriate actions. 
In enterprise security, the same principle applies. Automation scales insight. Humans’ own consequence. 
AI features introduce a new ownership boundary 
As organizations add generative AI into products, a new class of security questions emerges. Prompt injection, training data leakage and model manipulation don’t fit existing security categories. 
This creates a new ownership boundary. Product security teams must now partner closely with AI and ML engineering teams. Decide who will own code security, model behavior and misuse prevention. 
Treating AI features as first-class risk surfaces, rather than extensions of existing ones, forces clarity. Assign clear owners now, so these risks are identified before they become incidents or audit findings. 
AI does not just accelerate security workflows. It exposes where accountability, ownership and decision-making were never clearly defined in the first place. Organizations that treat AI as a force multiplier without redesigning their operating models may move faster, but not necessarily safer. The teams that succeed will be the ones that redesign for explicit ownership, governed decisions and human accountability at the points where consequences matter most. 
This article is published as part of the Foundry Expert Contributor Network.
Want to join?
View the full article
The U.S. Federal Communications Commission (FCC) said on Monday that it was banning the import of new, foreign-made consumer routers, citing "unacceptable" risks to cyber and national security. The action was designed to safeguard Americans and the underlying communications networks the country relies on, FCC Chairman Brendan Carr said in a post on X. The development means that new models ofView the full article
earthphotostock – shutterstock.com
In vielen Unternehmen stoßen IT-Sicherheitsrichtlinien auf Widerstand, da Mitarbeitende sie als hinderlich oder praxisfern empfinden. Dies erschwert die Umsetzung, untergräbt die Wirksamkeit und belastet die Zusammenarbeit zwischen der Sicherheitsabteilung und den Fachbereichen. Statt als Partner wird Cybersecurity oft als Bremser wahrgenommen – ein fatales Sicherheitsrisiko. Für CISOs (Chief Security Information Officer) bedeutet das, dass neben technisch korrekten Richtlinien vor allem die Akzeptanz im Alltag entscheidend ist. Ein neuer Ansatz mit empathischem Policy-Engineering und strategischer Sicherheitskommunikation fördert eine nachhaltige Sicherheitskultur.
IT-Sicherheit: Arbeitsdruck und soziale Einflussfaktoren
In vielen IT-Abteilungen herrscht die Ansicht, dass Anwender wenig motiviert sind, Sicherheitsvorgaben einzuhalten. Unternehmen setzen auf Sanktionen und Schulungen, um regelkonformes Verhalten zu erzwingen. Ein zwei-tägiges Experiment, das untersucht, wie sich Sicherheitsdesigns auf richtlinienkonformes Nutzerverhalten auswirken, zeigte jedoch: Hatten Teilnehmende anfänglich noch eine positive Einstellung gegenüber Sicherheitsrichtlinien, wurden diese unter steigendem Arbeitsdruck zunehmend als hinderlich empfunden, was vermehrt zu Regelverstößen führte. Stress und situative Faktoren hatten einen spürbaren Einfluss auf das sicherheitsrelevante Verhalten der Teilnehmenden.
Sicheres Verhalten entsteht also nicht allein durch Wissensvermittlung, sondern hängt stark von der individuelle Risikoeinschätzung und den konkreten Alltagssituationen ab. Nutzer handeln nicht immer so, wie es die Richtlinien vorsehen. Oft nicht aus Unwillen, sondern weil andere Faktoren überwiegen oder als wichtiger eingeschätzt werden. Ambitionierte Ziele, Zeitdruck und das Bedürfnis nach reibungsloser Zusammenarbeit stehen häufig im Widerspruch zu abstrakten Sicherheitsvorgaben. Diese Interessenkonflikte führen schnell zu Spannungen zwischen Security, IT und den anderen Fachbereichen. Das gefährdet letztlich die Sicherheitskultur.
Sicherheitsverantwortliche können an drei Punkten ansetzen, um dem entgegenzuwirken.
1. Die Anwender verstehen
CISOs sollten sich zunächst die Frage stellen, warum sich Nutzer nicht sicher verhalten. Eine Vielzahl von Faktoren spielen hier eine Rolle: Beispielsweise sind sich Anwender der Bedrohung nicht bewusst, sehen den Nutzen von sicherem Verhalten nicht oder empfinden Sicherheitsmaßnahmen als hinderlich für ihre Arbeit. Eventuell besteht auch ein Interessenkonflikt mit den Zielen der Nutzer oder sie stehen unter Zeitdruck. Oft fehlen schlicht die Mittel – beispielsweise, wenn Vorschriften einen sicheren Datenaustausch mit Zulieferern und Kunden fordern, aber den Mitarbeitenden keine Plattform für einen solchen Datenaustausch zur Verfügung gestellt wird – oder auch Vorbilder im Umfeld.
Vor der Implementierung von Sicherheitsmaßnahmen ist es wichtig, widersprüchliche Ziele und Prioritäten der verschiedenen Interessensgruppen (IT-Abteilung, technische Abteilungen, Management, Verwaltung, Mitarbeitende in der Produktion) zu identifizieren und auszugleichen. Dies ist beispielsweise im Rahmen einer Stakeholder-Analyse möglich – einer Methode aus der Wirtschaftsinformatik, um die Präferenzen aller beteiligten Stakeholder zu erheben. Je mehr Sicherheitsverantwortliche über die Arbeitswirklichkeit und die Ziele der verschiedenen Bereiche wissen, desto besser gelingt es ihnen, Sicherheitsmaßnahmen dazu passend zu gestalten – was zu mehr Akzeptanz und am Ende einer erfolgreichen Umsetzung führt.
2. Sicherheitsrichtlinien mit Blick auf den Anwender gestalten
Unsicheres Verhalten wird häufig den Nutzern angelastet, dabei liegt das Problem oft in der Maßnahme selbst. In der IT-Sicherheitsforschung liegt der Fokus häufig auf dem individuellen Verhalten der Nutzer – beispielsweise auf der Frage, ob sicheres Verhalten von Persönlichkeitsmerkmalen abhängt. Vernachlässigt wird dabei die Frage, wie gut Sicherheitsmaßnahmen überhaupt zur Arbeitsrealität passen – sprich, wie wahrscheinlich es ist, dass sie im Alltag akzeptiert werden.
Für jede Bedrohung gibt es meist mehrere verfügbare Sicherheitsmaßnahmen. Doch Unterschiede in Aufwand, Akzeptanz, Kompatibilität oder Komplexität werden in der Praxis oft nicht berücksichtigt. Stattdessen treffen Sicherheits- oder IT-Abteilungen Entscheidungen häufig ausschließlich auf Grundlage technischer Aspekte.
Um wirksame IT-Sicherheitsrichtlinien zu etablieren, müssen diese nicht nur technisch korrekt sein – sie müssen auch aus Mitarbeitersicht sinnvoll und praktikabel sein. Der Schlüssel dazu liegt im empathischen Policy Engineering: Sicherheitsvorgaben sollten so gestaltet sein, dass sie verständlich sind, akzeptiert werden und mit den alltäglichen Arbeitszielen vereinbar sind. Das gelingt am besten, wenn Mitarbeitende frühzeitig in die Entwicklung eingebunden werden – inklusive ihrer Zielkonflikte und praktischen Herausforderungen.
Ein anschließender Pilotversuch hilft dabei, potenzielle Stolpersteine und Hindernisse frühzeitig zu erkennen und die Maßnahmen entsprechend nach zu justieren. Es hat sich bewährt, dabei mit den “Early Adopters” zu starten – also der Gruppe an Anwendern, die Neuerungen gegenüber aufgeschlossen ist und im Anschluss konstruktives Feedback geben kann. Dieses sollte vor dem großen Roll-out berücksichtig werden. So kann eine Sicherheitskultur entstehen, die wirkt – und im Alltag tatsächlich gelebt wird.
3. Sinnvoll kommunizieren: Der RESPECT-Ansatz
Aktuell werden Sicherheitsmaßnahmen und -richtlinien häufig in einer Art und Weise kommuniziert, die Anwender nicht in ihrer Arbeitsrealität abholen, weil sie gar nicht darauf abzielen, dass Mitarbeitende sich damit beschäftigen und motiviert werden: Etwa über Anweisungen, Standard-Online-Trainings oder zu verspielte Formate wie Comics, die Mitarbeitende nicht ernst nehmen. Besser funktioniert das mit dem RESPECT-Ansatz: Er setzt auf Kommunikation auf Augenhöhe, statt auf Verbote und Strafen.
Der entscheidende Unterschied: Mitarbeitende werden als kompetente, verantwortungsvolle Erwachsene behandelt. Im Zentrum steht ein empathischer Blick auf ihre Bedürfnisse und Arbeitsrealitäten – ohne die Sicherheitsziele aus den Augen zu verlieren.
Es gibt mehrere Techniken, um die Kommunikation von Sicherheitsrichtlinien erfolgreich zu gestalten und Konflikte zu vermeiden:
Taktische Empathie: Diese schafft Anerkennung, stärkt Vertrauen und sorgt so dafür, dass sich Mitarbeitende gehört fühlen und bereit sind, sicherheitsrelevante Informationen anzunehmen.
„Help me to help you“ anstelle von „Nein“: Statt Sicherheitsvorgeben durchzusetzen, können CISOs mit gezielten „Wie“-Fragen Anwender dazu anregen, über die vorgeschlagenen Lösungen nachzudenken. Wenn Anwender Änderungswünsche zu den Sicherheitsvorgaben haben, sollte die Security nicht einfach nur ‘Nein’ sagen. Eine Rückfrage dazu, was die Mitarbeitenden selbst vorschlagen, um sowohl die Sicherheitsvorgaben einzuhalten als auch effizientes Arbeiten zu ermöglichen, ist sinnvoll. So entsteht ein Dialog und es ist leichter, einen für alle Beteiligten tragbaren Kompromiss zu finden.
Praxiserfahrung statt grauer Theorie: Ein Trainingskonzept, das auf direkte Erfahrung setzt, konfrontiert Teilnehmende mit realistischen Szenarien – etwa Cyberangriffe wie Phishing, Ransomware oder USB-Angriffe. Sie erleben hautnah in einer realitätsnahen Umgebung, die typische Arbeitsplätze in kleinen und mittleren Unternehmen abbildet, wie Cyberangriffe ablaufen. So entsteht ein tiefes, nachhaltiges Verständnis für IT-Sicherheit. Statt Belehrungen stehen der Mensch und das Erleben im Mittelpunkt.
Fazit: CISOs als Gestalter wirksamer Sicherheitskultur
Der geringe Erfolg vieler Sicherheitsmaßnahmen liegt nicht allein an den Nutzenden – oft sind es unrealistische Vorgaben, fehlende Einbindung und unzureichende Kommunikation. Für Sicherheitschefs bedeutet das: Statt auf Erziehung und Sanktionen zu setzen, braucht es einen strategischen Paradigmenwechsel. Sie sollten zu einer Art Emphatic Policy Architekt werden, dessen Sicherheitsstrategie nicht nur technisch funktioniert, sondern auch menschlich überzeugt. Er gestaltet Rahmenbedingungen, in denen sich sichere Entscheidungen selbstverständlich in den Arbeitsalltag einfügen. Dafür braucht es ein gutes Gespür für Zielkonflikte, Kommunikation auf Augenhöhe – und die Fähigkeit, Sicherheit als gemeinsamen Wert im Unternehmen zu verankern. (jm)
Lesetipp: So erfüllen Sie Ihre Compliance-Anforderungen
 
View the full article
Apple today released watchOS 5.3.10 and watchOS 8.8.2 for older Apple Watch models that are not able to run the current watchOS 26 update. watchOS 5.3.10 is available for the Apple Watch Series 1, Series 2, Series 3, and Series 4, while watchOS 8.8.2 is available for the Apple Watch Series 3, Series 4, Series 5, Series 6, Series 7, and original Apple Watch SE.


According to Apple's release notes, the updates extend the certificate that features like device activation, iMessage, and FaceTime need to function. The certificate update ensures that these apps and features will continue to work after January 2027, which is when the existing certificate was set to expire.

watchOS 8 is the final version of watchOS that's supported on the Apple Watch Series 3.

watchOS 5 is the final version of watchOS able to be installed on an Apple Watch Series 1 or Series 2 using an iPhone 5s, iPhone 6, or iPhone 6 Plus. The Series 1 and Series 2 do support watchOS 6, but installing watchOS 6 requires an iPhone 6s or later.Related Roundup: watchOS 26Tag: FaceTimeRelated Forum: Apple Watch
This article, "Apple Releases watchOS 5 and watchOS 8 Updates to Keep FaceTime and iMessage Running on Older Apple Watches" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
The latest version of iOS 26, iOS 26.4, is now available for download. The update doesn't have the Siri feature set we were hoping for, but there are quite a few new additions like new emoji and an AI music feature.


Playlist Playground

Apple Music has a new Playlist Playground feature that lets users create a playlist with a text-based prompt.


In the ‌Apple Music‌ app, there's an option to type in an idea and get automatic song suggestions for a playlist. Apple has some pre-set suggestions that include "morning coffee music," "hip-hop party songs," and "disco songs that defined the 1970s," but you can type in any idea, mood, or feeling.

From there, the Playlist Playground feature will automatically generate a list of 25 songs, along with a custom title. Playlists that you create can be customized further with additional text prompts, and you can select a cover and a description.

Playlist Playground is limited to the United States.

New Emoji

iOS 26.4 adds eight new emoji characters, including trombone, treasure chest, distorted face, hairy creature (Sasquatch), fight cloud, orca, landslide, and ballet dancer.


There are also new skin tone modifiers for people wrestling and dancers with bunny ears.

Apple Music

‌Apple Music‌ features a "Concerts Near You" feature that helps you find shows in your area and tour dates for artists that you're a fan of. Apple is partnering with companies like Ticketmaster to provide local concert info.


Apple has redesigned albums and playlists, adding full-page artwork.

A song can be added to multiple playlists at the same time in the ‌Apple Music‌ app. In the add to playlist interface, there is a list button, and tapping it allows you to select multiple playlists at the same time.



Offline Music Recognition

In Control Center, the song recognition feature is now able to identify songs without an internet connection, providing results when you're back online.

Purchase Sharing Changes

Adult members in a Family Sharing group can now use separate payment methods for purchases, rather than having to share a single payment method.



Apple Podcasts

With iOS 26.4, Apple added video podcast capabilities to the Apple Podcasts app. The feature uses HTTP Live Streaming (HLS) to provide podcast creators with "unprecedented control and monetization opportunities" while also providing a high-quality viewing experience.


The iOS 26.4 Podcasts app will let users switch between watching and listening to shows, with videos able to be downloaded for offline viewing. HLS ensures smooth playback regardless of network connection, so videos will work on Wi-Fi or cellular. Apple says that the new video episodes will integrate with existing ‌Apple Podcasts‌ features, including personalized recommendations and editorial suggestions in the New and Category sections.

Stolen Device Protection

Stolen Device Protection is now enabled by default for all iPhone users, rather than being an opt-in feature.


Apple implemented Stolen Device Protection in iOS 17.3 after reports about a new iPhone theft method. Thieves would spy on an intended victim to learn their passcode, then steal the target's iPhone. With the passcode, criminals were able to empty bank accounts, access passwords, and turn off Find My.

Stolen Device Protection requires additional authentication through Face ID or Touch ID to access certain iPhone features like the Passwords app, Lost mode in ‌Find My‌, Safari purchases, and more. Some features are disabled entirely without authentication, while others have a one-hour security delay.

Messages App

There are new animations in the Messages app for actions like launching a new conversation.

Apple Account Unified Design

In the App Store, ‌Apple Music‌, and other apps that have user settings, there is a new unified Apple Account hub that replaces the existing profile feature.


It offers largely the same functionality as the prior profile settings for each app, but there is a new unified design.

The ‌App Store‌ merges apps and purchase history, and has a dedicated section for app updates. It now takes two taps to get to app updates rather than having them available at the bottom of the profile page.

The ‌App Store‌'s navigation bar also no longer features Search as a separate button, and the search bar itself is at the top when tapped rather than the bottom.

Ambient Music Widget

There is a new Ambient Music widget for the Home and Lock Screen. It supports playing different built-in ambient music options for sleep, productivity, wellbeing, and more.


Wallpaper and Watch Face Gallery

The Wallpaper Gallery has an updated design that allows Wallpapers from each category like Weather, Astronomy, Emoji, Colors and More to be downloaded to the iPhone.


The Watch Face Gallery in the Apple Watch app also features the same design change.

Captions

Subtitle and caption customization settings are available from the captions icon when viewing media, which makes them easier to access and change.

Freeform Creator Studio

Freeform Creator Studio is live in iOS 26.4, allowing Creator Studio subscribers to access new Freeform features. Creator Studio for Freeform adds a dedicated Content Hub that houses the Freeform shape options.


Creator Studio users will be able to access free, high-quality content like graphics, photos, and illustrations that are not available to non-subscribers, plus there are AI capabilities for creating and editing images.

When Creator Studio launched, Apple said the premium content and features in Freeform would be coming to the Apple Creator Studio subscription later this year.

Freeform also has a new icon.
Reminders

The Reminders app has a new "Urgent" section. Reminders that have Urgent toggled on during creation will show up here. Urgent ensures that reminders have an accompanying alarm so you get a clear warning when a reminder is due.


Reminders can also be marked as urgent from the Quick Toolbar or by touching and holding.

iCloud Web Settings

In the iCloud section of the Settings app, there's now an "iCloud.com" option if you scroll all the way to the bottom of the interface. It replaces the simple "Access ‌iCloud‌ Data on the Web" toggle that was previously available.


The setting includes a new "Allow Search" toggle that lets trusted Apple devices provide search results to iCloud.com.

Health App

iOS 26.4 includes a new Average Bedtime metric for the sleep section of the Health app, providing a better idea of how bedtime can impact sleep quality.



Apple also updated the Vitals section of the Health app in the U.S., and now includes blood oxygen level on the line graph overview that's available each day. In iOS 26.3 and earlier versions of ‌iOS 26‌, there was a section for the blood oxygen level, but the graph did not include a blood oxygen measurement.


Reduce Motion and Bright Effects

There's a new Reduce Bright Effects option that minimizes bright flashes when tapping on interface elements like buttons. The Reduce Motion setting also more reliably reduces the animations of Liquid Glass for those who prefer less movement.

Camera

In the Settings section of the Camera app, there is a new "Audio Zoom" option. The feature causes recorded audio to focus on the subject when the camera is zoomed while recording a video. It can be turned on or off, depending on the audio settings you prefer.


CarPlay

With iOS 26.4, AI services like Claude, Gemini, and ChatGPT are accessible through the CarPlay system for the first time.

The new integration lets ‌CarPlay‌ users access voice-based apps like ChatGPT to ask questions hands-free, but the apps will not be able to control vehicle or iPhone functions. There also won't be a wake word option to activate a third-party app, so users will still need to open the app to use the chatbot. After an app is launched, the customizable voice control screen will give users vehicle-optimized chatbot experiences.

Third-party apps need to implement support for the feature, so it may take some time for the functionality to be available.

We also found mentions of Apple TV support for CarPlay during the beta period, indicating that Apple will eventually allow users to watch Apple TV content through their car's dashboard when the vehicle is not in motion.



At WWDC 2025, Apple said that it would add support for AirPlaying video content to a ‌CarPlay‌ display.

Hotspot Data

Apple moved the location of hotspot data usage. Rather than having data usage metrics tucked away under Cellular, you'll see how much data you've used right in the Personal Hotspot section.



Live Captions

Chinese (Taiwan) is a new language option for Live Captions in the Accessibility section.



Passcode Settings

In the ‌Face ID‌ and Passcode section of the Settings app, when you enter a passcode to access your options, the text is now center aligned instead of left aligned.


Shortcuts

Apple added a Set Charge Limit action to the Shortcuts app. It sets a battery charge limit for the iPhone.



Keyboard Bug Fix

iOS 26.4 offers improved keyboard accuracy when typing quickly, addressing a bug in iOS that caused some characters to be missed when a user was typing rapidly. The missed characters could impact how autocorrect worked, causing the feature to be unable to predict what the user meant to type.



Carrier Updates

The iOS 26.4 beta has a Voice Over New Radio (VoNR) feature for Telus iPhone users. The feature lets compatible devices remain on the 5G Standalone network during voice calls instead of 4G LTE.

Security Updates

iOS 26.4 fixes more than 35 security vulnerabilities impacting everything from Safari to Messages, and multiple underlying services.

There were no actively exploited vulnerabilities that Apple encountered, but it is still a good idea to update to iOS 26.4 to get the latest patches.

Now that Apple has publicized the vulnerabilities, they might be taken advantage of by bad actors.

How to Get iOS 26.4

You can install iOS 26.4 by opening up the Settings app, tapping into the General section, and navigating to Software Update.

Compatibility

iOS 26.4 runs on all iPhones that support ‌iOS 26‌, which includes the iPhone 11 and later.

What's Coming Next

We could get the first beta of iOS 26.5 as soon as this week now that iOS 26.4 is publicly available.Related Roundups: iOS 26, iPadOS 26Related Forum: iOS 26
This article, "iOS 26.4 Features: Everything New in iOS 26.4" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
OpenAI today said that it is ending support for its Sora AI video app just six months after it initially launched.



OpenAI did not provide more detail into why Sora is being discontinued, but the company said that it plans to share more soon, including specific information on when the app and API will be shut down. OpenAI CEO Sam Altman told employees that ending Sora will free up resources for OpenAI's next-generation AI models, according to The Information.

Sora generates AI videos of real people, with each user uploading a "cameo" or short video of themselves that's used as the basis for AI prompts. Users are able to share their cameos with others, allowing anyone on the app to generate AI video with their likeness.

When it launched at the end of September 2025, Sora gained viral popularity. It was downloaded more than a million times just a week and a half after launch, reaching the milestone faster than ChatGPT, and for a period of time, it was the top free app on the App Store.

OpenAI received criticism for deepfake videos featuring celebrities both dead and alive, and the company stopped allowing users to create videos featuring celebrity likenesses or voices without express consent. The guardrails that OpenAI put in place killed some of the interest in the app, and its popularity died down.Tag: OpenAI
This article, "OpenAI Discontinuing Sora AI Video App" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
iOS 26.4 was released today, and it includes a couple of new features for CarPlay: an Ambient Music widget and support for voice-based chatbot apps.


To update your iPhone 11 or newer to iOS 26.4, open the Settings app and tap on General → Software Update. CarPlay will automatically offer the new features so long as the iPhone connected to your vehicle is running iOS 26.4 or later.

Below, we have outlined the two new CarPlay features.

Ambient Music Widget

CarPlay gained support for widgets on iOS 26. To view them, swipe right on CarPlay's interface until you reach the Dashboard screen, shown below.


Starting with iOS 26.4, both the iPhone and CarPlay now have an Ambient Music widget option.

Apple introduced the Ambient Music feature on iOS 18.4 last year. It offers curated playlists based on themes such as Sleep, Chill, Productivity, and Wellbeing, with no Apple Music subscription required to listen to the songs.

To add the Ambient Music widget to a CarPlay widget stack, open the Settings app on your iPhone and tap on General → CarPlay → [Your Vehicle] → Widgets → Add Widget, select the Ambient Music option, and tap on the Add Widget button.

Chatbot Apps

Starting with iOS 26.4, CarPlay supports voice-based conversational apps, according to Apple's CarPlay Developer Guide. This means that chatbot like OpenAI's ChatGPT, Google's Gemini, and Anthropic's Claude will be able to extend their iPhone apps to CarPlay for voice-based conversations, should any of them choose to do so.


Of course, Apple's own assistant Siri remains available on CarPlay, without needing to open an app. It was recently reported that Apple is testing a new Siri app for iOS 27 with chatbot-like functionality and conversation history, so it will be interesting to see if that Siri app is available on CarPlay in a voice-only state later this year.Related Roundups: CarPlay, iOS 26, iPadOS 26Related Forums: HomePod, HomeKit, CarPlay, Home & Auto Technology, iOS 26
This article, "iOS 26.4 Adds Two New Features to CarPlay" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Smart lock company Nuki today launched the Keypad 2 NFC, which is the first keypad that includes support for Aliro. Aliro is a smart lock standard that supports interoperability between mobile devices and platforms, allowing smart locks to work with any smartphone or wearable device without the need for a dedicated app.


Aliro was designed by the Connectivity Standards Alliance, which includes Apple, and the Aliro 1.0 specification was released at the end of February. Nuki has one of the first Aliro-supported devices, and the Keypad 2 NFC allows a paired Nuki smart lock to be unlocked with Apple Home Key.

To use the Home Key functionality, you need the Nuki Smart Lock and the new Keypad 2 NFC, and I was able to test the setup prior to launch. The Nuki Smart Lock has Matter integration so it works with HomeKit and can be added to Apple Home without the keypad, but the Keypad 2 NFC adds Home Key for automatic unlocking with a digital key stored in the Apple Wallet app.

The Nuki Smart Lock has a clever design. It's meant to work with a standard deadbolt, and it uses the framework of the existing lock. I had a smart lock already, so I needed to install a regular deadbolt to test the Nuki. It's not a smart lock to smart lock upgrade, but it's a good hassle-free lock for adding digital unlocking to a lock you already have.


Nuki's Smart Lock reminds me of a doorknob, because it's a similar size and shape, plus you turn it like a doorknob to unlock the door. You keep your standard deadbolt outside, and the Nuki lock mechanism is on the inside. It's smaller than locks from some competing companies, and there's no big box on the door. I like the design because it looks like a normal lock on the exterior, and it's minimally distracting on the inside. I recently swapped all of my bulkier smart locks with the minimal Level Locks because I got tired of looking at boxes, and while Nuki's lock adds a little more bulk to a door than a Level Lock, it's not bad at all.

The only Nuki lock downside is the charging method. It uses a proprietary cable that attaches magnetically to the lock, and it seems easy to misplace. I even prefer Nuki's unlocking method to other smart locks, because I just turn the handle.

The Smart Lock has been around for a while, but the Keypad 2 NFC that adds Home Key is new. On its own, the Nuki Lock supports ‌HomeKit‌, but not Home Key. The Keypad is a candy bar-shaped device that attaches to the outside of your door with adhesive. It has a touchpad that you can use to enter a code, plus a fingerprint sensor. It can be opened with NFC using Home Key, the code, or the fingerprint sensor, so it adds multiple access methods to the Nuki Smart Lock.

I didn't find the process of setting up the Keypad 2 NFC with Home Key to be the most intuitive process. I added it to the Nuki app first, then tapped on the option to associate it with a smart home platform. The app instructed me to open up Apple Home, but there were no further instructions because an associated support document was unavailable (it could be up post launch).

It turned out I was able to set up Home Key by tapping my iPhone to the keypad, which added it to my existing Home Key setup. I have Level Locks that support Home Key, so the Home Key card in my Wallet app can now control multiple locks in my home.

With Home Key, I'm able to tap my iPhone or Apple Watch on the keypad without having to unlock the iPhone or open up the Nuki app.

There are already smart locks that support Home Key, but Aliro is a standard like Matter that makes it easier for lock companies to implement one unlocking feature that works across a variety of platforms. Locks that have Aliro support going forward will be compatible with Home Key and other smart home platforms. Aliro does have Ultra Wideband support for unlocking the door as you approach, but Nuki's product doesn't include UWB.


The lock can be used with geofencing and automations in the Home app or the Nuki app for automatic unlocking, and there are settings to automatically lock the door after it's opened as well.

Using Home Key with the Keypad does require a Matter-enabled Apple hub, which includes the Apple TV, HomePod, and HomePod mini. There are also hardware requirements, and it works with the iPhone XS or later with iOS 18.6 or later or an Apple Watch Series 4 or later running watchOS 11.6 or later.

Nuki's Keypad 2 NFC supports up to 20 fingerprints so multiple people in the family can unlock the door via biometric authentication, plus users can have 200 access codes and 35 tap-to-unlock keys.

The Keypad 2 has IP54 water and dust resistance, so it can hold up to poor weather outside, but it's best to keep it in a covered location. It uses AAA batteries that are supposed to last for up to a year, and the Nuki app will provide a notification when the battery is low. There isn't a backlight, but if you're using NFC, you don't need that for the tap unlock functionality.

Nuki's Keypad 2 NFC is available from the Nuki website for $179, while the Smart Lock is priced at $199. Nuki products are also available from Amazon.

Note: Nuki provided MacRumors a Nuki Lock and Keypad 2 NFC for the purpose of this review. No other compensation was received.
This article, "Nuki Keypad 2 NFC Brings Aliro-Powered Tap-to-Unlock Home Key Support to Nuki Smart Locks" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Apple today released new firmware for the AirPods Pro 2, AirPods Pro 3, and the AirPods 4. The firmware has a version number of 8B39, up from 8B34 on the ‌AirPods Pro 3‌, 8B28 on the AirPods Pro 2, and 8B21 on the ‌AirPods 4‌.



There is no word on what's included in the firmware, but Apple has a support document with limited notes. Most updates are limited to bug fixes and performance improvements.

To get the new firmware, make sure your AirPods are in range of your iPhone, iPad, or Mac and are connected via Bluetooth. From there, connect your Apple device to Wi-Fi, put your AirPods in the Charging Case, and connect the Charging Case to power. Keep the case closed and wait at least 30 minutes for the firmware update to install.Related Roundups: AirPods 4, AirPods Pro 3Tag: AirPods Pro 3Buyer's Guide: AirPods (Neutral), AirPods Pro (Buy Now)Related Forum: AirPods
This article, "Apple Releases New Firmware for AirPods Pro 3, AirPods Pro 2 and AirPods 4" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Apple is testing a standalone Siri chatbot app for iOS 27, reports Bloomberg's Mark Gurman. Apple plans to debut a chatbot version of ‌Siri‌ that will compete with Claude and ChatGPT, and the new ‌Siri‌ could be accessible through a dedicated app.


Gurman previously said that Apple was not going to develop a standalone ‌Siri‌ app, but it appears plans have changed. It was not clear how the rumored chatbot version of ‌Siri‌ was going to work without an app, because people often have multiple back-and-forth text-based conversations with chatbots, and not having a dedicated space would have been confusing.

Like ChatGPT and Claude, ‌Siri‌ will support both text and voice-based conversations. The app will display either a list or grid of past conversations, with options to favorite chats, search through chats, initiate new chats, and save chats. Conversations with ‌Siri‌ will resemble iMessage conversations, with Apple using chat bubbles. New conversations will start with suggested prompts on what to ask.

‌Siri‌ will be able to do much of what current chatbots can do, such as searching the web with visually rich results, providing summaries, and evaluating uploaded documents, and the personal assistant will still be integrated into Apple devices. Pressing the side button on an iPhone or using the ‌Siri‌ wake word will activate ‌Siri‌. ‌Siri‌ integration will replace the current Spotlight search functionality, but Apple plans to keep and expand on ‌Siri‌ Suggestions. ‌Siri‌ Suggestions will have more access to user data to provide more relevant prompts.

Chatbot ‌Siri‌ will have an updated look to go along with the dedicated app. Activating ‌Siri‌ will have a new animation that prompts the user to search or ask a question, and Gurman says Apple is testing a version of ‌Siri‌ integrated into the Dynamic Island. Apple's test interface includes a glowing ‌Siri‌ icon and a "searching" label in the ‌Dynamic Island‌ while ‌Siri‌ is processing a request, and once done, ‌Siri‌ expands into a larger translucent panel with the results. Pulling down on the menu initiates an interface for a conversation.

It's also possible Apple will integrate an "Ask ‌Siri‌" button into the menus of other apps, giving users a way to send content directly to ‌Siri‌ alongside a request. The iOS keyboard could get a Write with ‌Siri‌ option that surfaces Writing Tools.

Apple Intelligence ‌Siri‌ features that were originally planned for iOS 18 will be introduced in ‌iOS 27‌, with ‌Siri‌ able to use personal data and context to answer queries. ‌Siri‌ will also be able to do more in and between apps, and will be able to see what's on the user's screen. Apple promised that those features would appear before the end of 2026.

Apple is planning to introduce the new version of ‌Siri‌ at the June WWDC keynote. Dates for WWDC were announced yesterday, and the keynote event is set to take place on Monday, June 8.Related Roundup: iOS 27Tags: Bloomberg, Dynamic Island, Mark Gurman, Siri
This article, "iOS 27 Siri Overhaul: Standalone App, New Design, Dynamic Island Integration and Ask Siri Button" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Apple today released a new firmware update for the Studio Display and ‌Studio Display‌ XDR, its two new monitors that came out earlier in March.


The ‌Studio Display‌ Firmware 26.4 update is only for the new ‌Studio Display‌ options, and it is not available on the older model.

‌Studio Display‌ firmware can be updated by connecting the display to a Mac and going to System Settings > Software Update.

Apple did not provide release notes for the firmware update. Related Roundup: Studio DisplayBuyer's Guide: Displays (Buy Now)Related Forum: Mac Accessories
This article, "Studio Display and Studio Display XDR Get Firmware Update" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
TeamPCP, the threat actor behind the recent compromises of Trivy and KICS, has now compromised a popular Python package named litellm, pushing two malicious versions containing a credential harvester, a Kubernetes lateral movement toolkit, and a persistent backdoor. Multiple security vendors, including Endor Labs and JFrog, revealed that litellm versions 1.82.7 and 1.82.8 were published onView the full article
Apple today released macOS Tahoe 26.4, the fourth major update to the ‌macOS Tahoe‌ operating system. ‌macOS Tahoe‌ comes six weeks after Apple released ‌macOS Tahoe‌ 26.3.


Mac users can download the new software by opening up the System Settings app and navigating to the Software Update section.

‌macOS Tahoe‌ 26.4 returns the compact tab bar option to Safari for those who prefer the slimmed down look, along with a new Charge Limit feature for the Mac so you can set a maximum charge level from 80 to 100 percent. It also adds new eight emoji characters, and it displays warnings for apps that will stop working in the future. Apple is ending support for Rosetta 2 after macOS 27, so app that are still using Rosetta will display a popup letting users know that the app won't work starting with macOS 28.

macOS 26.4 also includes Apple Creator Studio for the Freeform app and it has the same Family Sharing change as iOS 26.4. Adult members of a family group can now opt to use their own payment methods for purchases instead of having to share one.Related Roundup: macOS TahoeRelated Forum: macOS Tahoe
This article, "macOS Tahoe 26.4 Now Available With Safari Compact Tab Bar, Battery Charge Limits and More" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
A large-scale malvertising campaign active since January 2026 has been observed targeting U.S.-based individuals searching for tax-related documents to serve rogue installers for ConnectWise ScreenConnect that drop a tool named HwAudKiller to blind security programs using the bring your own vulnerable driver (BYOVD) technique. "The campaign abuses Google Ads to serve rogue ScreenConnect (View the full article
Apple today released iOS 26.4 and iPadOS 26.4, the latest updates to the iOS 26 and iPadOS 26 operating systems. The new software comes six weeks after Apple released iOS 26.3 and iOS 26.4.



The new software can be downloaded on eligible iPhones and iPads over-the-air by going to Settings > General > Software Update.

iOS 26.4 adds a new Apple Music feature called Playlist Playground, which uses AI to generate playlists for you based on text-based prompts. You can ask for moods, feelings, occasions, and more when making a request.

The update also has new emoji characters, a useful change to payment methods for Purchase Sharing in family groups, and much more. Apple's notes for the update are below.

We should be getting iOS 26.5 and iPadOS 26.5 betas in the near future, perhaps as soon as this week.Related Roundups: iOS 26, iPadOS 26Related Forum: iOS 26
This article, "Apple Releases iOS 26.4 and iPadOS 26.4 With New Emoji, Playlist Playground, Purchase Sharing Changes and More" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Apple today released watchOS 26.4, the fourth major update to the watchOS 26 operating system that came out in September. watchOS 26.4 comes a month and a half after Apple released watchOS 26.3.


watchOS 26.4 can be downloaded for free on an iPhone running iOS 26.4 by opening up the Apple Watch app and going to General > Software Update, or initiating an update in the Settings app on the watch. To install the new software, the Apple Watch needs to have at least 50 percent battery and it needs to be placed on a charger.

The update makes it quicker to start a workout in the Workout app by tapping on a Workout type icon, plus it has eight new emoji characters that include orca, trombone, treasure chest, fight cloud, hairy creature, landslide, ballet dancer, and distorted face. Apple's release notes are below.

More on what's new in ‌watchOS 26‌ can be found in our watchOS 26 roundup.Related Roundups: Apple Watch 11, watchOS 26Buyer's Guide: Apple Watch (Neutral)Related Forum: Apple Watch
This article, "watchOS 26.4 Now Available With Workout Update and New Emoji" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Apple today released tvOS 26.4, the fourth update to the tvOS operating system that came out last fall. tvOS 26.4 is available for the Apple TV 4K and the ‌Apple TV‌ HD, and it comes over a month after Apple released tvOS 26.3.


tvOS 26.4 can be downloaded using the Settings app on the ‌‌‌Apple TV‌‌‌. Open up Settings and go to System > Software Update to get the new software. ‌‌‌Apple TV‌‌‌ owners who have automatic software updates activated will be upgraded to tvOS 26.4 automatically.

Apple added a new Genius Browse section to the ‌Apple TV‌ app in tvOS 26.4. Genius Browse is a content discovery feature that provides recommendations for TV shows and movies across multiple suggested categories. Suggestions vary based on content preferences, and the options are updated regularly.



The update removes the dedicated iTunes Movies and iTunes TV Shows apps that Apple started phasing out in 2023, which means wishlists will no longer be available. Apple sent emails to affected customers with instructions on how to transfer wishlist content to the ‌Apple TV‌ app watchlist.

tvOS 26.4 also adds more easily accessible customization options for subtitles, and it improves ‌Apple TV‌ Audio Format settings with an option for Continuous Audio Connection for HDMI output.

Full release notes for tvOS 26.4 are available through Apple's tvOS support document.Related Roundup: Apple TVBuyer's Guide: Apple TV (Don't Buy)Related Forum: Apple TV and Home Theater
This article, "Apple Releases tvOS 26.4 With Genius Browse" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Apple today released visionOS 26.4, the fourth update to the visionOS 26 operating system that launched in September. visionOS 26.4 comes 1.5 months after Apple released visionOS 26.3.


‌visionOS 26‌.4 can be downloaded on all Vision Pro headsets by navigating to the Settings app, selecting the General section, and choosing the Software Update option. To install an update, the Vision Pro headset needs to be removed, and there is a software progress bar available on the exterior EyeSight display.

Apple's release notes say that visionOS 26.4 includes bug fixes and security improvements, along with eight new emoji characters. New additions include distorted face, fight cloud, landslide, ballet dancer, treasure chest, trombone, orca, and hairy creature.

visionOS 26.4 is recommended for all Vision Pro users.Related Roundup: Apple Vision ProBuyer's Guide: Vision Pro (Buy Now)Related Forum: Apple Vision Pro
This article, "Apple Releases visionOS 26.4" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Alongside iOS 26.4, iPadOS 26.4, and macOS Tahoe 26.4, Apple has released new HomePod 26.4 software for the ‌HomePod‌ and the HomePod mini. The update comes a little over a month after Apple released ‌HomePod‌ Software 26.3.


According to Apple's release notes, ‌HomePod‌ Software 26.4 includes performance and stability improvements.

‌‌HomePod‌‌‌‌‌‌‌‌ software is installed automatically on the ‌‌‌‌‌‌‌‌HomePod‌‌‌‌ unless the feature is disabled‌‌‌‌, but the ‌‌‌‌‌‌‌‌HomePod‌‌‌‌‌‌‌‌ can also be manually updated in the Home app on iPhone, iPad, or Mac by tapping on the More button, choosing Home Settings, and then selecting the Software Update option.Related Roundups: HomePod, HomePod miniBuyer's Guide: HomePod (Neutral), HomePod Mini (Don't Buy)Related Forum: HomePod, HomeKit, CarPlay, Home & Auto Technology
This article, "Apple Releases HomePod Software 26.4" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Apple has been celebrating its upcoming 50th anniversary by hosting special events around the world, making stops in the United States, China, South Korea, and Thailand so far. Over the coming days, the celebrations will continue in the UK, France, Canada, Mexico, India, Japan, and Australia, while China will get an encore performance.


MacRumors has been invited to attend one of Apple's 50th-anniversary celebrations in London this week, but we are keeping specific details under wraps in order to avoid spoiling Apple's surprise. Stay tuned for our coverage of the event.

Apple Stores in Paris, France and Vancouver, Canada will be hosting special Today at Apple sessions tied to the company's 50th anniversary this week, with more details about those events outlined in our previous reporting.

Apple is also planning to host celebrations in Mexico, India, and Japan over the coming days, according to a source familiar with the matter.

Apple and the Sydney Opera House in Australia recently announced a collaboration, and we reported that this will tie into Apple's 50th-anniversary celebrations.

On his Instagram page last week, Australian composer Bailey Pickles said Apple asked him to compose and perform music for its upcoming 50th-anniversary celebration at the Opera House, where Apple will soon be illuminating artwork.

From March 25 to March 27, the Opera House's eastern sails will be illuminated with artwork created in the Procreate app on the iPad by a group of 10 emerging Australian artists. Through free Today at Apple sessions earlier this month, the public also had the opportunity to create and submit artwork for potential illumination.

Apple said selected artworks from both commissioned artists and public submissions will be curated and projected onto the Opera House's eastern sails on March 25 at 8:30 p.m. local time, and on March 26 and March 27 at 8 p.m. local time. Pickles did not say exactly when he will be performing at the world-famous venue, but it is clear that the 50th-anniversary celebration will involve a mix of artwork and music.

China is getting an encore 50th-anniversary celebration, as Apple will be hosting a special Today at Apple session at its Jing'an store in Shanghai, China on March 28, and there may be a surprise performance outside of the store as well.

Finally, there may be a grand finale at Apple Park in Cupertino, California, although this event might be limited to Apple's employees.

Apple kicked off its celebrations with a surprise performance by singer Alicia Keys at the iconic Grand Central Terminal in New York earlier this month. ↓


Chinese singer Li Yuchun also performed at Apple's Taikoo Li store in Chengdu, China last week, as part of the celebrations. ↓


South Korean boy band CORTIS performed at Apple's Myeongdong store in Seoul last week. ↓


Molly Yllom, the artist behind the Crybaby universe, led a special Today at Apple session at Apple's Iconsiam store in Bangkok last week. ↓


Apple turns 50 on April 1.

"At Apple, we're more focused on building tomorrow than remembering yesterday," said Apple's CEO Tim Cook, in a public letter. "But we couldn't let this milestone pass without thanking the millions of people who make Apple what it is today."Tags: Apple 50th Anniversary, Apple Store, Today at Apple, United Kingdom
This article, "Apple's 50th Anniversary Events Continue in UK, Canada, Mexico, Japan, Thailand, and Beyond" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
An ongoing phishing campaign is targeting French-speaking corporate environments with fake resumes that lead to the deployment of cryptocurrency miners and information stealers. "The campaign uses highly obfuscated VBScript files disguised as resume/CV documents, delivered through phishing emails," Securonix researchers Shikha Sangwan, Akshay Gaikwad, and Aaron Beardslee said in a report sharedView the full article
Your iPhone's Lock Screen has built-in media playback controls that appear whenever music, a podcast, or other audio is playing. What you might not realize is that those controls can also include a volume slider that lets you adjust the volume without you having to unlock your iPhone or fumble for the physical buttons.


Originally, Apple included a volume slider in the Lock Screen media player by default, but it quietly removed the function in iOS 16. It eventually returned as an option in iOS 18.2, but Apple decided to bury it in Accessibility settings, where it's easy to overlook. The setting is still available in iOS 26, and it's super-simple to enable.

Here's how to turn it on:

Open Settings on your iPhone.
Tap Accessibility.
Under "Hearing," tap Audio & Visual.
Toggle on the switch next to Always Show Volume Control.


The next time you play audio, a volume slider will appear in the Lock Screen's media player underneath the existing playback controls. It's especially useful when your iPhone is propped up on a desk or sitting on a nightstand, since you don't need to pick it up just to change the volume.

To turn it off again, just head back to Settings ➝ Accessibility ➝ Audio & Visual and toggle off Always Show Volume Control.
This article, "Add a Volume Slider to Your iPhone Lock Screen" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
As expected, Apple has officially announced that ads are coming to the Apple Maps app on the iPhone and iPad in the U.S. and Canada starting "this summer."


Apple says businesses in the U.S. and Canada only will be able to place ads in search results and at the top of a new "Suggested Places" section in the app.

"Ads on Maps will appear when users search in Maps, and can appear at the top of a user's search results based on relevance, as well as at the top of a new Suggested Places experience in Maps, which will display recommendations based on what's trending nearby, the user's recent searches, and more," says Apple.

Similar to the ads that are already shown in App Store search results on the iPhone and iPad, ads in Apple Maps will have an "Ad" label, and Apple promises strong privacy protections. For example, Apple says a user's location and the ads they see and interact with in Apple Maps are not associated with a user's Apple Account.

"Maps with ads is just as private as Maps without ads," says Apple. "Where you go and the ads you see and interact with are not associated with your Apple Account. Personal data stays on your device, is not collected or stored by Apple Ads, and is not shared with third parties."

The introduction of ads in Apple Maps will obviously help to further increase Apple's services revenue, but the move will disappoint some customers.

Businesses will be able to set up ads in Apple Maps via the new Apple Business platform. More details are available on Apple's website.Tags: Apple Ads, Apple Maps
This article, "Apple Announces Ads Are Coming to Apple Maps" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Apple today announced Apple Business, a new all-in-one platform that unifies device management, productivity tools, and customer outreach features.


The service is designed to be a consolidated replacement for several of Apple's existing business-focused offerings, including Apple Business Essentials, Apple Business Manager, and Apple Business Connect. It provides organizations with a single interface to manage devices, employees, communications, and customer engagement across Apple's ecosystem.

Apple Business incorporates built-in mobile device management (MDM), which allows companies to configure device settings, security policies, apps, and user groups from one place. Apple Business app will allow employees to install work-related apps, access colleague contact information, and request support.

New "Blueprints" enable administrators to preconfigure devices with specific settings and apps, facilitating zero-touch deployment so that employees can begin using devices immediately after unboxing. Zero-touch deployment is available when devices are purchased through Apple or authorized resellers.

The platform introduces Managed Apple Accounts with what Apple describes as "cryptographic separation" between personal and work data, allowing employees to use the same device for both purposes without commingling information. Account provisioning can be automated through integrations with identity providers such as Google Workspace and Microsoft Entra ID.

Additional features include the ability to create user groups, assign roles, distribute apps through the App Store, and access an Admin API for large-scale deployments, covering device, user, audit, and MDM service data.

Apple Business also adds integrated email, calendar, and directory services tied to custom domains. Businesses can either bring an existing domain or purchase one through the platform. These tools include features such as calendar delegation and a company directory with personalized contact cards.

In addition to internal management tools, Apple Business introduces new tools for customer engagement. The platform will allow businesses to manage how their brand and locations appear across Apple services, consolidating features previously available in Apple Business Connect.

These include brand profiles with logos and details, customizable place cards in Apple Maps with photos, hours, and actions such as ordering or reservations, and analytics showing how users discover and interact with locations. Branded communications will extend to the Mail app and iCloud Mail, as well as order tracking in Wallet, and that businesses using Tap to Pay on iPhone can display their branding during transactions.

Apple also announced a new advertising feature tied to ‌Apple Maps‌, scheduled to launch in the United States and Canada later this summer. Businesses will be able to create ads that appear at the top of search results in Maps, as well as within a new Suggested Places experience.

Apple Business will be available starting April 14 in more than 200 countries and regions as a free service for new and existing users of its prior business platforms, with certain features limited to specific regions. Optional paid services for additional ‌iCloud‌ storage and AppleCare+ will remain available within the platform.

Apple Business Essentials, Apple Business Manager, and Apple Business Connect will be discontinued once Apple Business launches, with existing data such as claimed locations and account information automatically migrated to the new system. Business Essentials customers will no longer be charged monthly fees for device management after the transition.Tag: Apple Business
This article, "Apple Unveils 'Apple Business' All-in-One Platform" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Anker's new Prime 3-in-1 Wireless Charging Station has been marked down to $119.99 today on Amazon, down from $149.99, with no need for a coupon. This accessory just launched last month, and Amazon's price is within $4 of the all-time low we tracked a few weeks back.

Note: MacRumors is an affiliate partner with Amazon. When you click a link and make a purchase, we may receive a small payment, which helps us keep the site running.

This deal, and many of the others we've collected below, are part of early deals for Amazon's Big Spring Sale, which officially kicks off tomorrow. Because of this, you'll need to have an Amazon Prime membership in order to get some of these discounts, including the Prime 3-in-1 Wireless Charging Station.

$30 OFFAnker Prime 3-in-1 Wireless Charging Station for $119.99

The Prime 3-in-1 Wireless Charging Station features Qi2.2 support, which lets a compatible MagSafe ‌iPhone‌ charge at up to 25W. It's the same speed as Apple's ‌MagSafe‌ charger, and it is 10W faster than the standard Qi2 ‌MagSafe‌ chargers. You can also simultaneously charge an Apple Watch and AirPods with the device.

There are plenty of other Anker discounts happening on Amazon this week, including the Prime 14-in-1 Thunderbolt 5 Dock back at its all-time low price of $339.99, down from $399.99. Anker's popular 3-in-1 MagSafe-Compatible Charging Cube is also down to a new all-time low price of $92.98, down from $129.99.

$60 OFFAnker Prime 14-in-1 Thunderbolt 5 Dock for $339.99
Wall Chargers

Nano USB-C Wall Charger - $29.99, down from $39.99
6-in-1 USB-C Power Strip - $79.99, down from $109.99
140W 4-Port GaN USB-C Charger - $89.99, down from $99.99
14-in-1 Prime Thunderbolt 5 Dock - $339.99, down from $399.99
Wireless Chargers

3-in-1 MagSafe-Compatible UFO Charger - $69.99, down from $89.99
3-in-1 MagSafe-Compatible Foldable Charging Station - $85.99, down from $109.99
3-in-1 MagSafe-Compatible Charging Cube - $92.98, down from $129.99
3-in-1 Prime Wireless Charging Station - $119.99, down from $149.99
Prime MagSafe-Compatible 3-in-1 Charging Station - $169.99, down from $229.99

Portable Chargers

SOLIX C300 Power Station with Lantern - $179.99, down from $249.00
Prime Power Bank 26,250 mAh - $199.99, down from $229.99
SOLIX C1000 Gen 2 Portable Power Station - $559.99, down from $799.00
SOLIX C2000 Gen 2 Portable Power Station - $999.99, down from $1,499.00

If you're on the hunt for more discounts, be sure to visit our Apple Deals roundup where we recap the best Apple-related bargains of the past week.



Deals Newsletter

Interested in hearing more about the best deals you can find in 2026? Sign up for our Deals Newsletter and we'll keep you updated so you don't miss the biggest deals of the season!




Related Roundup: Apple Deals
This article, "Anker's New Prime 3-in-1 Foldable Charging Station Hits Low Price on Amazon" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Apple's progress toward under-display Face ID and a fully uninterrupted iPhone display is encountering ongoing challenges, with a new report indicating that the company is likely to focus on incremental reductions to the Dynamic Island rather than major front-facing design changes in the near term.



A new post from Weibo user "Fixed Focus Digital" suggests that Apple's development of under-display technologies is not advancing as smoothly as previously anticipated, casting doubt on expectations for significant front-facing design changes in upcoming iPhone models. According to the leaker, Apple's near-term approach is expected to prioritize refining existing solutions rather than introducing a fully hidden front camera and ‌Face ID‌ system.

The latest information aligns with a growing body of mixed reports surrounding the iPhone 18 Pro models. Earlier claims from multiple sources, including Bloomberg's Mark Gurman and display industry analyst Ross Young, indicated that Apple would reduce the size of the ‌Dynamic Island‌, likely by relocating some ‌Face ID‌ components beneath the display.

Other sources have cast doubt on the extent of these changes. Weibo leaker "Digital Chat Station" recently claimed that the ‌iPhone 18 Pro‌ models may reuse much of their existing front-facing design, with ‌Face ID‌ and the ‌Dynamic Island‌ remaining "largely unchanged" and more ambitious under-display implementations pushed to a later generation.

In the same series of posts, Fixed Focus Digital also commented on Apple's upcoming foldable iPhone, describing the device as "ultra-flat, moderately sized, and affordably priced," and claimed that supply chain expectations for production volumes are relatively high.



The ‌iPhone 18 Pro‌, ‌iPhone 18 Pro‌ Max, and Apple's first foldable iPhone are expected to be announced in the fall. Tags: Dynamic Island, Face ID, Fixed Focus Digital, Foldable iPhone
This article, "Apple Still 'Far From' Full-Screen iPhone as Hidden Face ID Hits Snags" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Gcore Radar
Laut dem halbjährlich erscheinenden Radar-Report des luxemburgischen Softwareanbieters Gcore haben sich die registrierten DDoS-Angriffe von Juli bis Dezember 2025 gegenüber dem ersten Halbjahr verdoppelt. Insgesamt zählte Gcore weltweit rund 2,25 Millionen DDoS-Angriffe im zweiten Halbjahr 2025 gegenüber etwa 1,17 Millionen im ersten Halbjahr.
DDoS im Jahresvergleich
Das summiert sich für 2025 auf insgesamt 3,42 Millionen Angriffe. Im Vorjahr 2024 registrierte der Softwareanbieter lediglich 1,8 Millionen Attacken. Ein Anstieg um 90 Prozent im Jahresvergleich.
Die Volumina der Attacken haben ebenfalls zugelegt. So erreichten die Angriffe laut Gcore 2025 Spitzenwerte von bis zu 12 Tbit/s (Terabit pro Sekunde) während 2024 lediglich 2,2 Tbit/s verzeichnet wurden. Das entspricht einer Zunahme um zirka 550 Prozent.
Gcore Radar
Angriffsstruktur verändert sich
Volumetrische Attacken auf Netzwerkebene fallen laut Gcore zunehmend kürzer und aggressiver aus. Insgesamt entfielen im zweiten Halbjahr 2025 82 Prozent aller Angriffe auf den Network Layer, etwa drei Viertel dieser Attacken dauerten weniger als eine Minute. Die meisten (84 Prozent) der Netzwerk-Attacken nutzen UDP-Floods, also DDoS-Angriffe mithilfe des User Datagram Protocol.
Angriffe auf Anwendungsebene (18 Prozent aller Attacken) sind dagegen gezielter und langwieriger. Etwa die Hälfte dauerte zwischen zehn und 30 Minuten, acht Prozent sogar über eine Stunde. Diese Angriffe zielen laut Gcore verstärkt auf geschäftskritische Funktionen wie Programmierschnittstellen (APIs), Authentifizierungsprozesse oder Backend-Systeme und verwenden automatisierte Bots, um gezielt Geschäftslogiken auszunutzen.
Tech-Unternehmen in Visier
Zu den Opfern der Attacken zählten im zweiten Halbjahr 2025 vor allem Technologieunternehmen (34 Prozent). Darauf folgten Finanzdienstleister (20 Prozent) und Gaming-Unternehmen (19 Prozent).
Auf Netzwerkebene stammten 75 Prozent des von Gcore beobachteten Angriffs-Traffics aus Nord- und Südamerika. Insbesondere Mexiko, Brasilien und die USA stachen heraus. Application-Layer-Angriffe waren dagegen global breiter verteilt und wurden unter anderem auch in Deutschland registriert. 
View the full article
Gcore Radar
Laut dem halbjährlich erscheinenden Radar-Report des luxemburgischen Softwareanbieters Gcore haben sich die registrierten DDoS-Angriffe von Juli bis Dezember 2025 gegenüber dem ersten Halbjahr verdoppelt. Insgesamt zählte Gcore weltweit rund 2,25 Millionen DDoS-Angriffe im zweiten Halbjahr 2025 gegenüber etwa 1,17 Millionen im ersten Halbjahr.
DDoS im Jahresvergleich
Das summiert sich für 2025 auf insgesamt 3,42 Millionen Angriffe. Im Vorjahr 2024 registrierte der Softwareanbieter lediglich 1,8 Millionen Attacken. Ein Anstieg um 90 Prozent im Jahresvergleich.
Die Volumina der Attacken haben ebenfalls zugelegt. So erreichten die Angriffe laut Gcore 2025 Spitzenwerte von bis zu 12 Tbit/s (Terabit pro Sekunde) während 2024 lediglich 2,2 Tbit/s verzeichnet wurden. Das entspricht einer Zunahme um zirka 550 Prozent.
Gcore Radar
Angriffsstruktur verändert sich
Volumetrische Attacken auf Netzwerkebene fallen laut Gcore zunehmend kürzer und aggressiver aus. Insgesamt entfielen im zweiten Halbjahr 2025 82 Prozent aller Angriffe auf den Network Layer, etwa drei Viertel dieser Attacken dauerten weniger als eine Minute. Die meisten (84 Prozent) der Netzwerk-Attacken nutzen UDP-Floods, also DDoS-Angriffe mithilfe des User Datagram Protocol.
Angriffe auf Anwendungsebene (18 Prozent aller Attacken) sind dagegen gezielter und langwieriger. Etwa die Hälfte dauerte zwischen zehn und 30 Minuten, acht Prozent sogar über eine Stunde. Diese Angriffe zielen laut Gcore verstärkt auf geschäftskritische Funktionen wie Programmierschnittstellen (APIs), Authentifizierungsprozesse oder Backend-Systeme und verwenden automatisierte Bots, um gezielt Geschäftslogiken auszunutzen.
Tech-Unternehmen in Visier
Zu den Opfern der Attacken zählten im zweiten Halbjahr 2025 vor allem Technologieunternehmen (34 Prozent). Darauf folgten Finanzdienstleister (20 Prozent) und Gaming-Unternehmen (19 Prozent).
Auf Netzwerkebene stammten 75 Prozent des von Gcore beobachteten Angriffs-Traffics aus Nord- und Südamerika. Insbesondere Mexiko, Brasilien und die USA stachen heraus. Application-Layer-Angriffe waren dagegen global breiter verteilt und wurden unter anderem auch in Deutschland registriert. 
View the full article
The Trusted Platform Module (TPM), developed by the Trusted Computing Group (TCG), is a mandatory security component in any computer running Windows 11. It stores sensitive information such as encryption keys in a separate, secure chip, passing it to the CPU as required.
However, there’s a problem. If an attacker can get physical access to the device, they can use hardware costing less than $20, running readily available software, to grab those encryption keys as they are sent to the CPU, allowing data on the system to be readily decrypted by the attacker and stolen.
At its Imagine event this week, HP announced a product that it says prevents this kind of attack without the need to make changes to device encryption software such as BitLocker. TPM Guard is a combination of hardware and firmware that creates an authenticated and encrypted tunnel between the TPM and the CPU to protect the communication between them, said Ian Pratt, HP’s vice president of security and commercial systems. The TPM is cryptographically bound to the host processor so if the chip is removed from the system, the TPM will cease to function.
“This isn’t just about espionage agents sneaking into hotel rooms of executives while they’re out at dinner,” he said during a media briefing. “Many laptops get stolen every day, and if a laptop is owned by an enterprise, there’s potentially a lot more value to the data it contains than the resale value of the device itself. And hence, opportunity for that device to work its way through the black market to a crime group that is capable of extracting the data and monetizing it, perhaps using the credentials it contains to gain access to enterprise systems or threatening to leak customer data.”
Most companies today rely on BitLocker to encrypt that data, but the TPM issue can negate that protection, putting organizations at risk.
TPM can prevent a whole class of bus interception and interposition attacks, Pratt said.
HP wants the technology behind it to become an industry standard, and has already submitted a proposal to the TCG, he said.
Starting in July, TPM Guard will be available as a firmware update at no additional charge on “selected” HP G2 commercial PCs, and will be built in to supported PCs in the future.
Structurally significant
“HP TPM Guard is arguably the most structurally significant announcement [at HP Imagine] for enterprise, government, and high-compliance customers,” said Anurag Agrawal, chief global analyst at Techaisle. “From an architectural standpoint, it closes a massive physical edge loophole.”
It’s “a brilliant maneuver” against Microsoft’s Pluton architecture, Agrawal said, noting that Pluton eliminates the bus by putting security directly on the CPU die, while TPM Guard gives highly regulated customers the physical security of Pluton without forcing them to abandon their preferred TCG-certified discrete TPMs.
HP’s proposal of TPM Guard to the Trusted Computing Group (TCG) as a new industry standard “creates immediate security debt for HP’s rivals,” he said.
“By positioning TPM Guard as the first and only solution to this physical bus attack, HP is implicitly stating that the existing ‘secure’ fleets from competitors like Dell and Lenovo carry a known, exploitable vulnerability, giving HP and its channel partners a highly aggressive wedge issue to force early device refresh cycles,” he said.
TPM hasn’t been significantly updated for some time, making HP’s TPM Guard all the more important, said Rob Enderle, principal analyst at Enderle Group. “In the face of rising threats, it is always important to reinvest in defense, and that is what they are doing here.”

View the full article
The Trusted Platform Module (TPM), developed by the Trusted Computing Group (TCG), is a mandatory security component in any computer running Windows 11. It stores sensitive information such as encryption keys in a separate, secure chip, passing it to the CPU as required.
However, there’s a problem. If an attacker can get physical access to the device, they can use hardware costing less than $20, running readily available software, to grab those encryption keys as they are sent to the CPU, allowing data on the system to be readily decrypted by the attacker and stolen.
At its Imagine event this week, HP announced a product that it says prevents this kind of attack without the need to make changes to device encryption software such as BitLocker. TPM Guard is a combination of hardware and firmware that creates an authenticated and encrypted tunnel between the TPM and the CPU to protect the communication between them, said Ian Pratt, HP’s vice president of security and commercial systems. The TPM is cryptographically bound to the host processor so if the chip is removed from the system, the TPM will cease to function.
“This isn’t just about espionage agents sneaking into hotel rooms of executives while they’re out at dinner,” he said during a media briefing. “Many laptops get stolen every day, and if a laptop is owned by an enterprise, there’s potentially a lot more value to the data it contains than the resale value of the device itself. And hence, opportunity for that device to work its way through the black market to a crime group that is capable of extracting the data and monetizing it, perhaps using the credentials it contains to gain access to enterprise systems or threatening to leak customer data.”
Most companies today rely on BitLocker to encrypt that data, but the TPM issue can negate that protection, putting organizations at risk.
TPM Guard can prevent a whole class of bus interception and interposition attacks, Pratt said.
HP wants the technology behind it to become an industry standard, and has already submitted a proposal to the TCG, he said.
Starting in July, TPM Guard will be available as a firmware update at no additional charge on “selected” HP G2 commercial PCs, and will be built in to supported PCs in the future.
Structurally significant
“HP TPM Guard is arguably the most structurally significant announcement [at HP Imagine] for enterprise, government, and high-compliance customers,” said Anurag Agrawal, chief global analyst at Techaisle. “From an architectural standpoint, it closes a massive physical edge loophole.”
It’s “a brilliant maneuver” against Microsoft’s Pluton architecture, Agrawal said, noting that Pluton eliminates the bus by putting security directly on the CPU die, while TPM Guard gives highly regulated customers the physical security of Pluton without forcing them to abandon their preferred TCG-certified discrete TPMs.
HP’s proposal of TPM Guard to the Trusted Computing Group (TCG) as a new industry standard “creates immediate security debt for HP’s rivals,” he said.
“By positioning TPM Guard as the first and only solution to this physical bus attack, HP is implicitly stating that the existing ‘secure’ fleets from competitors like Dell and Lenovo carry a known, exploitable vulnerability, giving HP and its channel partners a highly aggressive wedge issue to force early device refresh cycles,” he said.
TPM hasn’t been significantly updated for some time, making HP’s TPM Guard all the more important, said Rob Enderle, principal analyst at Enderle Group. “In the face of rising threats, it is always important to reinvest in defense, and that is what they are doing here.”

View the full article
Today marks the 25th anniversary of Apple launching Mac OS X, the operating system that serves as the foundation of modern-day macOS.


Apple released a public beta of Mac OS X in September 2000, and the operating system officially launched on March 24, 2001.

"Mac OS X is the future of the Mac, and we hope it will delight our customers with its unrivaled power and ease of use," said Steve Jobs, in 2001. "The Public Beta has generated incredible feedback and support from Mac users and developers, which has helped us to make Mac OS X the most advanced operating system ever."

Mac OS X was a next-generation, UNIX-based operating system for the Mac, succeeding the classic Mac OS operating system. It ushered in Apple's iconic "Aqua" interface, the Dock, an improved Finder app with hierarchical navigation, and more.


"Mac OS X is the most important software from Apple since the original Macintosh operating system in 1984 that revolutionized the entire industry," said Jobs.

In the U.S., Mac OS X was priced at $129. Apple stopped charging for macOS releases in 2013, when OS X Mavericks was released free of charge.

Mac OS X was renamed to OS X in 2012 and to macOS in 2016:Mac OS X 10.0 (2001): "Cheetah"
Mac OS X 10.1 (2001): "Puma"
Mac OS X 10.2 (2002): Jaguar
Mac OS X 10.3 (2003): Panther
Mac OS X 10.4 (2005): Tiger
Mac OS X 10.5 (2007): Leopard
Mac OS X 10.6 (2009): Snow Leopard
Mac OS X 10.7 (2011): Lion
OS X 10.8 (2012): Mountain Lion
OS X 10.9 (2013): Mavericks
OS X 10.10 (2014): Yosemite
OS X 10.11 (2015): El Capitan
macOS 10.12 (2016): Sierra
macOS 10.13 (2017): High Sierra
macOS 10.14 (2018): Mojave
macOS 10.15 (2019): Catalina
macOS 11 (2020): Big Sur
macOS 12 (2021): Monterey
macOS 13 (2022): Ventura
macOS 14 (2023): Sonoma
macOS 15 (2024): Sequoia
macOS 26 (2025): TahoeMac OS X was a big part of Apple's renaissance, which began when Jobs returned to the company in the late 1990s. Big hits in those first few years after his return included the iMac in 1998, the iBook in 1999, and Mac OS X and the iPod in 2001. In this sense, it is poetic that this milestone comes just a week ahead of Apple's 50th anniversary.Related Roundup: macOS TahoeRelated Forum: macOS Tahoe
This article, "Mac OS X Launched 25 Years Ago Today: 'The Future of the Mac'" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
A coalition of Europe's biggest broadcasters is pushing the EU to bring smart TV platforms like Apple TV and virtual assistants like Siri under the bloc's toughest tech regulation, reports Reuters.


The Association of Commercial Television and Video on Demand Services in Europe (ACT), whose members include Disney, NBCUniversal, Paramount+, and Sky, sent a letter on Monday to EU antitrust chief Teresa Ribera arguing that smart TV operating systems from Google, Amazon, Apple, and Samsung should be designated as gatekeepers under the Digital Markets Act (DMA).

Under the DMA, any platform with more than 45 million monthly active EU users and a market valuation above €75 billion is presumed to be a gatekeeper, subject to obligations designed to curb self-preferencing and increase interoperability.

To evidence their claim, the broadcasters cited market data showing Android TV's share grew from 16 percent to 23 percent between 2019 and 2024, while Amazon Fire OS climbed from 5 percent to 12 percent. Samsung's Tizen holds 24 percent, but Apple TV's share was not referenced.

The ACT also wants virtual assistants like Alexa and Siri brought under the DMA, arguing that the current lack of regulation has left AI assistants free to act as de facto gatekeepers for media content across phones, smart speakers, and car infotainment systems.

The European Commission confirmed it received the letter and is reviewing it. So far, Apple, Google, Amazon, and Samsung have not commented.

Apple's App Store, iOS, and Safari are already classified as DMA gatekeepers. A separate review into whether Apple Maps and Apple Ads meet the threshold was concluded last month, with regulators ruling that neither qualified due to low usage in Europe.

Notably, the broadcasters' letter asks the Commission to apply the DMA based on "qualitative criteria," even where platforms don't hit the usual quantitative benchmarks outlined in the regulations.

The request may sound like it's on shaky ground, but the DMA does actually have a provision for this circumstance – the EC can designate a company as a gatekeeper even if it doesn't meet the hard numeric thresholds stated above. It can look instead at factors like the platform's size, number of business users, network effects, lock-in, and structural market characteristics. In fact, this is how the Commission designated iPadOS as having gatekeeper status, even though it didn't meet the quantitative threshold.

In practice, though, the Commission is likely to be cautious about using this approach because it's messier than quantitative rules and easier to challenge in court. Apple is very likely to contest it, especially given that Apple TV's market share appears to be relatively small. Whether the same will apply to Siri is another matter, since it's tied to the iPhone and the EU already considers that a gatekeeper platform.Related Roundup: Apple TVTags: Apple Antitrust, European Commission, European Union, SiriBuyer's Guide: Apple TV (Don't Buy)Related Forum: Apple TV and Home Theater
This article, "Apple TV, Siri Targeted in EU Broadcaster Complaint Citing DMA Rules" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Apple is moving more decisively to reduce its reliance on Chinese manufacturers ahead of the launch of a wave of new products with OLED panels, DigiTimes reports.


Apple has apparently accelerated efforts to diversify its OLED sourcing away from Chinese suppliers such as BOE, which have historically played an important role in the company's display supply chain. The impact on BOE has already been substantial. DigiTimes says the company's dedicated Apple OLED production line in Mianyang, Sichuan saw utilization rates fall from approximately 82% in 2024 to 48% by February 2026.

Shipments to Apple have also declined sharply, dropping by more than 40% compared to initial expectations. OLED panel shipments from Sichuan to Apple's assembly partners in Vietnam fell by over 50% year over year in February, underscoring the speed of the transition.

In place of Chinese suppliers, Apple is increasingly depending on reliable South Korean display manufacturers such as Samsung Display and LG Display. ‌DigiTimes‌ says future Apple devices, including the iPhone 18 Pro, the first foldable iPhone, and upcoming MacBook Pro and iPad mini models, are expected to depend predominantly on OLED panels sourced from these companies. All of these products are expected to launch this year, with OLED coming to the ‌MacBook Pro‌ and ‌iPad mini‌ for the first time.

The realignment reflects a broader shift in Apple's component sourcing strategy that has been underway for several years, as the company seeks to mitigate supply chain risk. Apple has already diversified final assembly across countries such as India and Vietnam.
Tags: China, DigiTimes, LG, LG Display, OLED, Samsung, South Korea
This article, "Apple Bracing Display Supply Chain for Wave of New OLED Devices" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Cybersecurity researchers have uncovered a new set of malicious npm packages that are designed to steal cryptocurrency wallets and sensitive data. The activity is being tracked by ReversingLabs as the Ghost campaign. The list of identified packages, all published by a user named mikilanjillo, is below - react-performance-suite react-state-optimizer-core react-fast-utilsa ai-fast-auto-traderView the full article
A newly disclosed malware strain dubbed “StoatWaffle” is giving fresh teeth to the notorious, developer-targeting “Contagious Interview” threat campaign.
According to NTT Security findings, the malware marks an evolution from the long-running campaign’s user-triggered execution to a near-frictionless compromise embedded directly in developer workflows. Attackers are using blockchain-themed project repositories as decoys, embedding a malicious VS Code configuration file that triggers code execution when the folder is opened and trusted by the victim.
“StoatWaffle is a modular malware implemented by Node.js and it has Stealer and RAT modules,” NTT researchers said in a blog post, adding that the campaign operator “WaterPlum” is “continuously developing new malware and updating existing ones.”
This means tracking Contagious Interview activity may now require widening the scope of detection efforts to include weaponized dev environments, not just malicious packages and interview lures.
Opening a folder is all it takes
StoatWaffle abuses developer trust within Visual Studio Code environments. Instead of relying on users to execute suspicious scripts, like in earlier attacks, attackers are embedding malicious configurations inside legitimate-looking project repositories, often themed around blockchain development, a lure theme that has been consistent with Contagious Interview campaigns.
The trick relies on a “.vscode/tasks.json” file configured with a “runOn: folderOpen” setting. Once a developer opens the project and grants trust, the payload executes automatically without any further clicks. The executed StoatWaffle malware operates a modular, Node.js-based framework that typically unfolds in stages. These stages include a loader, credential harvesting components, and then a remote access trojan (RAT) planted for persistence and pivoting access across systems.
The RAT module maintains regular communication with an attacker-controlled C2 server, executing commands to terminate its own process, change the working directory, list files and directories, navigate to the application directory, retrieve directory details, upload a file, execute Node.js code, and run arbitrary shell commands, among others.

StoatWaffle also exhibits custom behavior depending on the victim’s browser. “If the victim browser was Chromium family, it steals browser extension data besides stored credentials,” the researchers said. “If the victim browser was Firefox, it steals browser extension data besides stored credentials. It reads extensions.json and gets the list of browser extension names, then checks whether the designated keyword is included.”
For victims running macOS, the malware also targets Keychain databases, they added.
Contagious Interview, revisited
StoatWaffle isn’t an isolated campaign. It’s the latest chapter in the Contagious Interview attacks, widely attributed to North Korea-linked threat actors tracked as WaterPlum.
Historically, this campaign has targeted developers and job seekers through fake interview processes, luring them into running malicious code under the guise of technical assessments. Previously, the campaign weaponized npm packages and staged loaders like XORIndex and HexEval, often distributing dozens of malicious packages to infiltrate developer ecosystems at scale.
Team 8, one of the group’s sub-clusters, previously relied on malware such as OtterCookie, shifting to StoatWaffle around December 2025, the researchers said.
The disclosure also shared a set of IP-based indicators of compromise (IOCs), likely tied to C2 infrastructure observed during analysis, to support detection efforts.
View the full article
Anthropic are out with yet another update to Claude AI: the company's Claude Code and Cowork tools can now remotely control your Mac on your behalf.


When Claude lacks a direct connector for a given app like Slack or Google Calendar, it falls back to controlling the computer like a human, using the screen to navigate.

From the Claude blog:


The capability pairs with Dispatch (released last week) which lets you assign Claude tasks from your iPhone and return to finished work on your desktop. In the YouTube video embedded below, Anthropic's demo shows a user asking Claude to export a pitch deck as a PDF and attach it to a meeting invite, all while the user is away from their Mac.

"Computer use is still early compared to Claude's ability to code or interact with text," notes Anthropic. "Claude can make mistakes, and while we continue to improve our safeguards, threats are constantly evolving. We recommend starting with the apps you trust and not working with sensitive data."

The new feature is essentially Anthropic's version of OpenClaw, the open-source AI agent that went viral earlier this year. OpenClaw runs locally and connects to messaging apps like WhatsApp and Telegram, using a plugin-based "skills" system to execute tasks ranging from file management to browser automation. It's powerful, but notoriously tricky to configure safely.


In contrast, Claude's version is more locked down. The system uses a permission-first approach, and requests user access before touching a new app. It's currently also Mac-only, whereas OpenClaw supports macOS, Windows, and Linux.

The new feature is now available in research preview for Claude Pro and Max subscribers.

Earlier this month, Claude was updated with support for inline visual content that aims to help provide clearer answers. Anthropic also rolled out a memory import tool that allows users to import conversations and memories from other AI providers into Claude, so new users don't need to start from scratch when they switch.Tag: Anthropic
This article, "Anthropic's Claude AI Can Now Use Your Mac While You're Away" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
OHC_logo_transparent_01.jpeg flags-medium.png OHC_logo_blue_square_small.jpeg

 

Account

Navigation

Search

Search

Configure browser push notifications

Chrome (Android)
  1. Tap the lock icon next to the address bar.
  2. Tap Permissions → Notifications.
  3. Adjust your preference.
Chrome (Desktop)
  1. Click the padlock icon in the address bar.
  2. Select Site settings.
  3. Find Notifications and adjust your preference.