- 0 comments
- 34 views
-
Tech
Tech Articles from a wide variety of topics and categories
- 0 comments
- 32 views
-
Anthropic rolled out its agentic platform Claude Cowork in January for macOs and February for Windows, and use of agentic tool OpenClaw skyrocketed early this year after developer Peter Steinberger, now with OpenAI, launched the open-source project in late 2025.
While most organizations are focused on deploying AI that augments human work, there’s been a huge spike in interest in autonomous agentic AI since late last year, says Neal Riley, innovation lead and former CIO at IT consultancy and digital transformation parent company The Adaptavist Group.
Many organizations, even traditionally risk-adverse firms in the financial services and healthcare industries, have begun to experiment with autonomous AI as they look to reshape their workflows, he says.
Even with concerns about unanticipated results and autonomous agents operating as shadow AI, early adopters of agentic AI see huge potential for the technology to be a force multiplier that, for example, empowers non-technical people to solve minor IT problems without involving the tech team.
“Coming to 2026, we are starting to see people investing quite heavily in a lot of these processes that are more agentic and allowing this kind of control to happen in a very tight and regulated way, but allowing for these systems to take that level of autonomy,” Riley says. “We are seeing a huge uptick in this.”
Autonomous bots for everyone
OpenClaw and Claude Cowork are at the forefront of this coming revolution, enabling users to enlist AI to automate workflows on their computers. OpenClaw bots integrate with external large language model (LLM) AIs, such as Claude and OpenAI’s GPT models, and users access it through a chatbot running on a messaging service such as WhatsApp, Telegram, or Discord.
Users give Claude Cowork access to their applications and files, then prompt the AI to complete tasks. Cowork can organize files, build spreadsheets, prepare reports, and analyze notes, by accessing files on the user’s computer, pulling in context from apps such as Slack, and browsing the Web for more information. Before Claude takes action, it shows the user the plan and waits for approval, according to Anthropic.
Still, some users have given these autonomous agents a high level of control, and there are risks when they turn over their computers without hard limits.
Meta AI security researcher Summer Yue in late February tweeted that OpenClaw tried to delete her email inbox after she asked the AI to clean it up. “Nothing humbles you like telling your OpenClaw ‘confirm before acting’ and watching it speedrun deleting your inbox,” she wrote.
She acknowledged a rookie mistake. “Turns out alignment researchers aren’t immune to misalignment,” she wrote. “Got overconfident because this workflow had been working on my toy inbox for weeks. Real inboxes hit different.”
One of the top replies to Yue’s tweet was a picture of someone handing a chimpanzee an assault rifle.
Researchers have also found several security flaws in OpenClaw, including a vulnerability to prompt injection attacks.
Big risk, big reward
Herein lies the rub: AI experts see huge potential advantages with autonomous AI — with the possibility of creating huge workplace efficiencies — but the risks are substantial.
Riley acknowledges both security concerns and the potential for agentic AI to take actions that users didn’t anticipate. While users haven’t yet seen autonomous AI able to complete work faster or cheaper than humans — tokens are expensive — the technology has the potential to remake the nature of work for the better, he says.
“When you talk about the advantages, it’s definitely replacing the work that happens today, but almost that’s a byproduct,” he says. “What it actually enables you to do is coordinate in a different way than you did before with the passing of information back and forth across the team to get those things out faster, with better quality.”
Autonomous AIs will allow organizations to redeploy their human workforces to new tasks, removing much of the drudgery work, advocates say.
“Once you can start trusting a lot of these agentic systems to take the responsibility for things, often it’s not doing it faster or even better than what the human does,” Riley says. “What it does is it doesn’t require the human to be involved, which means they can work on other things.”
Many companies are still early in the autonomous AI journey, says Upal Saha, CTO at AI data integration provider bem. One of the big challenges is getting the AIs to understand how the business operates, he says.
“Inside most companies, the relationships between processes, data, and decisions aren’t documented cleanly,” he adds. “That knowledge lives across teams and individuals. Agents can be incredibly capable, but without that operational context they’re often guessing rather than executing.”
Speed is a huge potential advantage of autonomous agents, but it’s also one of the downsides, Saha notes.
“If they have the right context, they can compress hours of manual operational work into seconds,” he adds. “The downside is that the same speed can amplify mistakes. If an agent misunderstands a workflow or data structure, it can repeat that mistake at scale.”
Despite the risks, the market is shifting quickly toward agentic AI, with large-scale adoptions coming in the next two years, says Russell Twilligear, head of AI R&D at AI-generated content provider BlogBuster.
“We are witnessing a shift from systems that only generate text towards systems that can actually execute multi-step work,” he says. “The biggest advantage is that autonomous agents don’t just answer a simple prompt. They can move from intent to execution by gathering information, updating systems, etc.”
However, there’s a danger if autonomous agents are implemented incorrectly, Twilligear adds.
“The biggest disadvantage is that this is going to scale faster than we can control it,” he says. “That means security risks and misfires on every new integration.”
Security and oversight are the major problems to overcome, he adds. “When an agent can access email, files, browsers, etc., you are opening a world of hurt,” Twilligear says. “The problem is how fast all of this is happening. Recent security reporting shows that a lot of companies don’t even have monitoring over their AI agents. To me, that is just wild.”
Allow experimentation
IT leaders deploying autonomous agents need to put robust controls in place, ensure that their data is clean and accessible, and their app permissions are correctly configured, The Adaptavist Group’s Riley says.
Despite security and output concerns, Riley encourages IT leaders to allow employees to experiment with the emerging technology because of the impending adoption. Organizations that invest in AI training and allow employees to play with the technology tend to get better results from deployments, he notes.
“With all of these tools that are available, people should be trying right now to just understand how they work,” he says. “These things are coming out so fast that the onboarding and the sort of enablement you would have gotten in IT software 10 years ago just simply isn’t there. Everyone’s approach to this is, just go play with it, and you’ll figure out how it works.”
See also:
What CISOs need to know about the OpenClaw security nightmare Your personal OpenClaw agent may also be taking orders from malicious websites Agentic AI: A CISO’s security nightmare in the making? Think agentic AI is hard to secure today? Just wait a few months Agentic AI in IT security: Where expectations meet reality View the full article
- 0 comments
- 37 views
-
- 0 comments
- 34 views
-
Only a flexible, scalable security strategy, one supported by optimized, end-to-end best practices, can position an AI-ready data center business for long-term success.
The future of data centers is already here
The next evolution of data centers isn’t coming — it has arrived. If cloud computing was the blockbuster of the past decade, AI is the global film festival running around the clock. Hyperscale construction continues to accelerate, and the market is projected to more than double in size over the coming years, driven largely by AI demand.
Competing in this environment requires operating at an entirely new level. If you’ve successfully delivered cloud capacity, you have a foundation, but AI scale reduces tolerance for error to nearly zero. Only the most precise, disciplined operators will maintain an edge.
Scaling isn’t simply a matter of increasing output. It requires a rigorous framework that elevates traditional data center expertise to address new physical security risks, emerging threat vectors and design implications unique to AI workloads. These range from hyperscale considerations to more sophisticated protections against nation-state actors and other high-consequence threats. AI compute power has global implications, and its physical protection must reflect that reality.
Organic evolution is too slow for this moment. Businesses must not only accelerate — they must mature.
Think beyond delivery
Every company operates as an economy of projects. But at AI scale, projects must evolve into programs. Designing and delivering AI-capable data centers requires an integrated, fast-moving production model built on repeatable processes and structured knowledge transfer.
Intelligent reuse of project elements, including toolsets, intellectual property, templates, design standards and best practices, becomes essential. Each project should establish precedent for the next. Rapid growth depends on compounding institutional knowledge and applying it with clarity and discipline.
Customizable work packages, accessible knowledge repositories and proactive identification of repeatable workflows all contribute to smoother operations. Even bespoke solutions must be structured in a way that allows future replication.
This extends into how teams use BIM and digital modeling technologies. Three-dimensional visualization and digital twin capabilities are now baseline expectations. What differentiates high performers is their ability to streamline BIM processes with reusable templates, data-driven design libraries, standardized modeling components and automation tools that reduce manual effort while improving precision.
The goal is simple: build a delivery engine that runs like a well-oiled machine, one that is durable, scalable and aligned with both current and future standards of excellence.
Evolve your notion of requirements
AI-scale development affects every point of the project control compass: requirements, budget, resources and time. Of these, requirements demand the most attention. They often involve emerging technologies, novel design approaches and evolving regulatory conditions. Unlike traditional boilerplate standards, many new requirements emerge dynamically throughout the lifecycle of a project.
Successful security programs treat requirements holistically. It’s not enough to understand what a requirement says; you must understand why it exists and how it affects the broader ecosystem of standards, operations and risk posture.
There is also a critical distinction between foundational mandates, which include policies, regulatory frameworks and established standards, and evolving exceptions that gradually become new norms. At AI scale, exceptions are frequent. With multiple projects underway, agility means quickly assessing impact, updating documentation and deploying changes without disrupting timelines.
AI introduces additional challenges. Larger facilities strain the capacity of existing systems. Clients demand higher levels of identity and access assurance. Threat vectors now include airborne risks such as drones and vulnerabilities associated with data-bearing devices. Meanwhile, innovation in cooling technologies, sustainability practices and energy-efficient architecture introduces new physical security implications that must be addressed in parallel.
Where past programs may have relied on an 80/20 ratio of repeatable versus novel work, AI scale pushes that closer to 95/5. Success depends on executing the repeatable 95 percent with seamless accuracy while maintaining the flexibility and ingenuity to manage the 5 percent that is truly new.
Mature agility means shrinking the denominator — maximizing scenarios where standards can be universally applied and minimizing workarounds. High-risk, bespoke elements should be structured in ways that eventually become repeatable.
Supercharge your success factors
In a rapidly evolving market, change is constant. Each new requirement is an opportunity to elevate performance, not just for a single organization but for the industry as a whole.
When designing for AI capacity, the margin for compromise is razor-thin. Excellence requires both breadth and depth of expertise. Teams must combine comprehensive technical knowledge with fluency in a client’s specific operational model. The strongest partnerships balance general subject-matter mastery with the ability to adapt seamlessly to unique organizational needs.
Two capabilities consistently distinguish market leaders: the automation of design, modeling and quality assurance processes, and an almost intuitive attention to the fine details that determine project success. Automation drives efficiency and scalability; disciplined detail orientation preserves quality.
Consistency, paired with continuous optimization, becomes the engine of momentum.
Engage partners
AI-scale development demands more than transactional relationships. A supplier delivers a scope of work; a partner invests in long-term success.
The right security partner engages early at the strategic level, integrating into roadmap discussions rather than reacting to late-stage requirements. They operate with structured methodology and disciplined communication, capable of integrating with in-house teams when necessary, while functioning autonomously when appropriate.
Strong partners extend the reach of internal subject matter experts, collaborating closely to test solutions, validate concepts and refine designs. They assume ownership of the program as if it were their own, representing the organization’s interests consistently across projects and stakeholders.
In complex builds involving multiple consultants and integrators, effective partners also understand how to collaborate without friction. They bring clarity, coordination and stability to environments where misalignment can otherwise derail progress.
Ultimately, the value of a physical security consultant correlates directly with their ability to operate as a sophisticated business in their own right—offering thought leadership, strategic vision and a proven, repeatable method for delivering against unique requirements.
The right partnership doesn’t just support growth. It enables it.
Build the future
The race for AI-driven capacity is accelerating rapidly. Physical security must scale with equal precision and foresight.
By adopting a programmatic mindset, investing in repeatable systems and cultivating strategic partnerships, organizations can build data centers that are effective, efficient, resilient and future-ready.
AI represents an inflection point. Those who mature quickly — while maintaining discipline and consistency — will define the next era of data center excellence.
This article is published as part of the Foundry Expert Contributor Network.
Want to join?
View the full article
- 0 comments
- 38 views
-
It’s a nightmare that plays out every couple of minutes in companies around the world: a cybercriminal pings what they think is a company’s exposed server, only to discover that the seemingly sensitive information it’s sending back is anything but. That’s because what they’ve actually encountered is a honeypot server, a digital cage used by organizations to lure threat actors and capture their movements as they try to break into the company.
In theory, this is much safer than letting them break in while learning something from the damage they leave behind. In practice, however, the effectiveness of honeypots has historically depended on how much effort its programmers put into making the environment seem realistic to the attacker – which, considering such servers can cost tens of thousands of dollars per month to maintain, isn’t usually much. But the recent pairing of large language models (LLMs) with honeypots allows these servers to generate convincing environments at a fraction of the cost, supercharging the acquisition of threat intelligence for both individual organizations and the cybersecurity community at large.
How honeypots have been used
Honeypots themselves have been around since 1986, when the astronomer-turned-computer systems manager Dr Cliff Stoll ensnared a KGB spy attempting to steal US military secrets via an ARPANET connection. Stoll’s innovation would eventually inspire classic honeypot servers.
“Researchers love them [as] they’re one of the best ways to collect real-world attacker TTPs and discover new malware campaigns,” says cybersecurity researcher and founder of Beelzebub Mario Candela. SOC teams, meanwhile, tended to see them as “nice to have,” given how difficult and expensive honeypots were to deploy and maintain – premium versions absorbed thousands of dollars and engineering hours per month – and how quickly the more sophisticated, dangerous threat would identify them.
The emergence of LLMs in the late 2010s, however, would lead to the first experiments by academic researchers in combining AI in honeypots. Dr M. Abdullah Canbaz remembers this period well. An assistant professor in information sciences and technology at the University at Albany, SUNY, the idea of bolting an LLM onto a honeypot came from one of his students. The pair built their own LLM, training it to parse traffic data and handle a huge variety of Linux commands. This, explains Canbaz, allowed it to grapple with even the most sophisticated hacker. The resulting paper was published in 2024, at the peak of an efflorescence of academic interest in AI-powered honeypots. “I’ve got so many calls since then,” says Canbaz, often from people who “want to take our paper and… turn it into a startup business.”
Many have. Far from being an academic exercise, AI-powered honeypots are now being built by organizations large and small. On the smaller end is Beelzebub a low-code, open-source AI-powered honeypot that has acquired a reputation for devilish effectiveness. “The key architectural leap was integrating LLMs directly into the deception layer,” says Candela. “Instead of static, rules-based honeypots, we built high-interaction, LLM-driven deception environments that can dynamically respond to attackers, keeping them engaged for longer and capturing richer intelligence.”
Sophisticated attackers will probably cotton on eventually, but the benefit for cybersecurity teams make it worth trying. They “may eventually notice subtle inconsistencies: perhaps a response latency pattern that differs from a real system, or a file system that’s too ‘clean,’ or a system that fails to exhibit certain expected side effects of a real compromise,” says Candela. But “by the time an attacker starts to suspect they’re in a deception environment, we’ve already captured their tooling, TTPs, and intent.”
Why CISOs should consider honeypots
Another player in the AI honeypot space is Deutsche Telekom (DT). The firm is both a user and purveyor of AI-powered honeypots through its free, open-source platform ‘T-Pot.’ The most obvious advantage to their use, explains Marco Ochse, DT’s lead for threat analytics and mitigation, lies in how little these traps cost to set up and run compared to their antecedents. “In practical terms, AI changes the economics of deception,” says Ochse. “It allows [the organization] to scale believable interaction without [the usual] cost and complexity.”
That doesn’t come at the expense of complexity, adds DT’s chief security officer, Thomas Tschersich. As far as the engineer behind the honeypot is concerned, the difference between the classical and the AI-powered variety is similar to filming a movie scene using complex wooden sets constructed on a back lot or CGI: both are facades, but the latter is much less expensive while remaining nigh-on indistinguishable from a fake city street painstakingly constructed out of plywood. Even better, the AI-powered honeypot can adapt to the requests of the hacker in real time, making it more likely they’ll stay in the trap for longer periods without realizing they’re in one in the first place. In the end, says Tschersich, you can raise the authenticity of interactions with threat actors without this being associated with high investments.
That’s become more important amid a spike in attacks on organizations that begin with threat actors having already obtained valid credentials to access systems. In these scenarios, says Candela, defenders “are blind once an attacker is inside” the network. By keeping threat actors occupied at traditional attack points for longer and deploying AI-powered honeypots in less traditional locations, such as APIs and within AI agents, says Candela, organizations can steal a march on their opponents.
What, then, are we all learning from the deployment of this larger, AI-powered net? The big development, explains Candela, is the use of AI by the cybercriminals themselves. It is “democratizing attacks” with threat actors now using coding assistants to not only rapidly generate and deploy exploit code at scale but also use AI to probe vulnerabilities in target systems automatically. “Open-source AI red-team tools mean autonomous agents can now scan, exploit and adapt without human input,” says Candela.
There are risks to this paradigm. LLM outputs are, after all, essentially the product of very high-level pattern recognition. Cede cybersecurity to this kind of AI, says Canbaz, and you risk leaving the attack surface wide open to exploitation by cybercriminals mounting unorthodox and, therefore, unexpected campaigns. In this future, he continues, “there’s no clear definition of an attacker.”
How attackers may counter the honeypot trap
Candela shares these concerns, envisioning the emergence of ‘deception detection-as-a-service’ providers meeting demand from cybercriminal organizations to root out AI-powered honeypots in companies ahead of breach attempts. Additionally, “sophisticated actors might try to poison honeypot data or manipulate the deception layer,” says Candela, a key reason why Beelzebub’s own deception environment is isolated.
The speed of cyberattacks may also increase as hackers, unaware if they’re interacting with a honeypot or not, aim to conduct their nefarious business as quickly and efficiently as possible just in case they’re being watched. “This actually makes deception more valuable, not less,” says Candela, “because speed-focused attackers are more likely to interact with well-placed honeypots during rapid lateral movement.”
Time, then, to say goodbye to the classic honeypot? Not necessarily, argues Tschersich. “Static honeypot deployments such as low-, medium- or high-interaction sensors will not be replaced but complemented by AI-powered honeypots in response to a highly automated and AI-driven threat landscape,” he says. Even so the cybersecurity landscape is changing rapidly, with responsibility for attack and defense increasingly shouldered by machines. The AI-powered honeypot, perhaps, is a bridge to that future – for good and ill.
View the full article
- 0 comments
- 40 views
-
- 0 comments
- 37 views
-
- 0 comments
- 48 views
-
Foto: mentalmind – shutterstock.com
ISO-Zertifizierungen, aber auch die Einführung eines Informationssicherheits-Managementsystems (ISMS) nach IT-Grundschutz, werden von vielen Unternehmen als Beweis für ihre Qualität und ihren professionellen Ansatz bei der Durchführung ihrer Geschäftstätigkeit angesehen. Obwohl das ein wichtiger Grundstein für jedes Unternehmen ist, läuft in einigen Fällen nicht immer alles wie geplant. Im Folgenden werden die häufigsten Fallstricke bei der ISO-/ISMS-Einführung und deren Zertifizierung sowie Lösungsansätze aufgeführt.
1. Fehlende Verbindlichkeit der Geschäftsleitung
Allen voran geht die Geschäftsleitung. Egal, ob als Einzelperson oder zu mehreren. Einer der maßgeblichen Faktoren, der dazu führt, dass ISO-/ISMS-Einführungen in Unternehmen nicht funktionieren, ist das fehlende Commitment der Geschäftsführer. Diese muss die Bedeutung der ISO-/ISMS-Einführungen verstehen und sich aktiv für ihre Umsetzung und Aufrechterhaltung einsetzen. Ohne das Engagement der Geschäftsleitung ist es oft schwierig, alle Mitarbeiter für den Prozess zu gewinnen und sicherzustellen, dass die ISO-Standards oder auch die Standards nach IT-Grundschutz in den täglichen Geschäftsablauf integriert werden.
Deshalb sollten Unternehmen auf jeden Fall klarstellen, wie wichtig das Thema ist – auch, wenn die Umsetzung mit hohem Aufwand und Unannehmlichkeiten verbunden sein kann. “Aufräumen” ist nicht immer schön. Das Ergebnis dafür aber umso lohnender. Wenn die Geschäftsleitung die ISO-/ISMS-Einführungen unterstützt und fördert, kann dies zu einem erfolgreichen Abschluss und einem besseren Unternehmensimage führen.
2. Dran vorbei statt mittendrin
Einer der häufigsten Gründe, warum ISO-/ISMS-Einführungen in Unternehmen nicht funktionieren, ist, dass sie nicht tatsächlich in den täglichen Geschäftsablauf integriert werden. Viele betrachten die ISO-/ISMS-Einführungen als eine einmalige Aktivität, die einmal durchgeführt wurde, um das Zertifikat zu erhalten. Dabei achten sie jedoch nicht darauf, die geschaffenen Abläufe in ihre täglichen Geschäftspraktiken zu integrieren. Ohne eine tatsächliche Einbindung in den täglichen Geschäftsablauf wird das Zertifikat nutzlos und die Vorteile, die es bietet, werden nicht realisiert. Im schlimmsten Fall zahlen Organisationen sogar drauf, lassen dabei jedoch in jedem Fall wertvolles Entwicklungspotential liegen.
Bei der Integration gilt es zu beachten, dass man sich nicht zu sehr in Details verliert. Die (arbeits-)lebensnahe Umsetzung des Managementsystems ist maßgeblich für dessen Erfolg. Anstatt komplizierte Prosa zu schreiben, tut es vielleicht auch eine Grafik. Frei nach dem Motto “Ein Bild sagt mehr als tausend Worte!”. Sind Abläufe leicht und intuitiv zu erfassen und klar umzusetzen, werden sie auch gelebt. Hier kann es auch hilfreich sein, Prozesse zu automatisieren. Auch der Blick von außen durch einen erfahrenen Berater kann von Vorteil sein.
Lesetipp: Wie Sie sich auf ein SOC-2-Audit vorbereiten
3. Mitarbeiter nicht umfassend beteiligen
Ein weiteres Problem, das bei ISO-/ISMS-Einführungen häufig vorkommt, ist die fehlende Beteiligung aller Mitarbeiter. Wenn nur ein kleiner Teil des Unternehmens für die Umsetzung der ISO-/ISMS-Einführungen verantwortlich ist, kann es zu einer Desynchronisation zwischen den Abteilungen kommen, die nicht Teil des Prozesses sind. Dies führt dazu, dass bestimmte Abteilungen nicht an den vorgesehenen Verfahren teilnehmen und dass die ISO-/ISMS-Einführungen letztendlich nicht funktioniert.
Die Lösung hierzu? Erfahren Sie im nächsten Punkt.
4. Mitarbeiteridentifikation nicht fördern
Ein weiterer Faktor, der die Funktionalität von ISO-/ISMS-Einführungen in Unternehmen erschwert, ist die fehlende Identifikation der Mitarbeitenden mit der Einführung und dem daraus resultierenden Managementsystem. Die Mitarbeiter müssen verstehen, warum die Einführung wichtig ist, wie sie in ihre täglichen Arbeitsabläufe integriert werden soll und wie das ihnen die Arbeit erleichtert. Ist das nicht der Fall, wird es schwierig , die Einführung umzusetzen und eine daraus etwaig resultierende Zertifizierung aufrechtzuerhalten.
Eine Lösung dafür bilden zum Beispiel Schulungen und Weiterbildungsprogramme. Diese tragen dazu bei, dass die Mitarbeitenden frühzeitig in den Zertifizierungsprozess einbezogen werden. Dadurch wird sichergestellt, dass alle Mitarbeitenden die Bedeutung der Zertifizierung verstehen und wie diese in ihre täglichen Arbeitsabläufe integriert werden kann.
Die Schulung und Einbindung der Mitarbeitenden stellt zudem sicher, dass das Managementsystem effektiv umgesetzt wird. Die Angestellten tragen dadurch aktiv zu dessen Verbesserung bei.
5. Vernachlässigen von Kompetenzbildung
Schulungen für Mitarbeitende im Kontext der ISO-/ISMS-Einführungen sind in vielerlei Hinsicht wichtig. Fehlende Kompetenz bei den Verantwortlichen trägt oftmals dazu bei, dass Zertifizierungsvorhaben spätestens im Audit scheitern. Schulungen und das Bilden von Bewusstsein aller Mitarbeitenden für die Bedeutung der ISO-/ISMS-Einführungen und ihre Rolle bei der Umsetzung sind deshalb essentiell.
Ein gut ausgebildetes Team findet gute und effiziente Lösungen für den Aufbau und die Umsetzung eines Managementsystems. So kann Bürokratisierung vermieden werden. Damit ist Kompetenzbildung von Anfang an ein entscheidender Faktor für den Erfolg einer ISO-/ISMS-Einführungen.
6. Umsetzen ohne Plan
Ein weiteres Hindernis bei der Implementierung von ISO-/ISMS-Einführungen, ist das Fehlen eines klaren Plans zum Vorgehen. Viele Organisationen beginnen den Prozess ohne, dass sie eine genaue Vorstellung davon haben, was für eine erfolgreiche Einführung oder eine Zertifizierung benötigt wird. Dadurch verschwenden sie Zeit und Ressourcen. Ohne einen genauen Plan konzentrieren sich Firmen auf Bereiche, die nicht relevant sind oder die Anforderungen der ISO-/IT-Grundschutz Standards nicht erfüllen. Dauert die Umsetzung für den Aufbau eines Managementsystems zu lange, kann es außerdem dazu kommen, dass die reguläre Unternehmensentwicklung den Prozess selbst überflügelt und Arbeit mehrfach anfällt, um Änderungen zu folgen.
Eine mögliche Lösung besteht darin, einen klaren Plan zu erstellen, der die Schritte zur Implementierung der Standards festlegt. Dieser Plan sollte die spezifischen Anforderungen der gewählten Standards, die benötigte Zeit und die Ressourcen für die Einführung/Zertifizierung, sowie die Verantwortlichkeiten und Aufgaben der beteiligten Mitarbeiter und Abteilungen berücksichtigen. Durch eine klare Definition einer Deadline für den primären Aufbau des Managementsystems können Unternehmen sicherstellen, dass sie sich auf die wichtigsten Bereiche konzentrieren. Somit sind sie in der Lage, Zeit und Ressourcen effektiver zu nutzen. Eine vorgelagerte Soll-Ist-Stand- oder GAP-Analyse ist dabei ein erprobtes Mittel, um Klarheit zu schaffen und die Basis für eine konkrete Planung zu erhalten.
7. Das passt schon so oder währt ehrlich doch länger?
Wenn Unternehmen sich selbst belügen, funktioniert die ISO-/ISMS-Einführungen ebenfalls nicht. Oftmals werden Schwachstellen- und Risikoanalysen nicht objektiv betrachtet oder eigentlich relevante Themen schlicht nicht erfasst. So nach dem Motto: “Was der Auditor nicht weiß, macht ihn nicht heiß.”
Dies führt dazu, dass Unternehmen ihre Risiken nur unzulänglich behandeln oder erst gar nicht wahrnehmen und somit die Wirksamkeit des Managementsystems beeinträchtigen. Der Aufschrei, wenn ein Risiko nach einer zuvor positiven Bewertung eintritt und immense Kosten zu dessen Behebung anfallen, ist im Nachhinein oft groß.
Eine unehrliche Betrachtung sorgt dafür, dass die Implementierung der gewählten Standards oberflächlich und unvollständig erfolgt, was die Einführung und gegebenenfalls auch die Zertifizierung letztendlich sinnlos macht.
Eine Lösung hierfür besteht darin, dass Unternehmen schonungslos ehrlich zu sich selbst sind und sich gegebenenfalls auch Hilfe zur Selbsthilfe holen. Ein unvoreingenommener und erfahrener Berater kann helfen, Risiken richtig einzuschätzen. Außerdem ist er in der Lage, potentielle Szenarien aufzeigen, die aufgrund von Betriebsblindheit sonst nicht gesehen werden. So kann das Unternehmen eine ehrliche Risikoanalyse durchführen und Schwachstellen im Unternehmen identifizieren, um eine effektive Implementierung der gewählten Standards zu gewährleisten.
8. Die Einführung/Zertifizierung als abgeschlossenen Prozess betrachten
Ein weiteres häufiges Problem bei ISO-/ISMS-Einführungen ist das Fehlen eines kontinuierlichen Überwachungs- und Verbesserungsprozesses. Viele Unternehmen sehen die ISO-/ISMS-Einführungen als einen abgeschlossenen Prozess. Werden jedoch keine kontinuierlichen Bemühungen unternommen, um die Umsetzung der gewählten Standards aufrechtzuerhalten und zu verbessern, droht das Unternehmen schnell hinter den neuesten Trends und Anforderungen zurückzufallen. Im schlimmsten Fall kann es sogar passieren, dass das Unternehmen seine Zertifizierung verliert. Im Anschluß ist es entsprechend schwer, diese erneut zu erlangen.
Um diese Probleme zu vermeiden, müssen Unternehmen die ISO-/ISMS-Einführungen als einen kontinuierlichen Prozess ansehen, der ständig überwacht und verbessert wird. Alle Mitarbeiter sollten in den Prozess einbezogen werden, um eine reibungslose Umsetzung und eine tatsächliche Integration in den täglichen Geschäftsablauf zu gewährleisten. Zudem ist es wichtig, dass regelmäßig Überprüfungen und Audits durchgeführt werden. Dadurch sorgen Organisationen dafür, dass sie immer den neuesten Standards entsprechen.
9. Einsatz von Billiglösungen
Eine ISO-/ISMS-Einführung und Zertifizierung ist nichts für Unternehmen, die auf Billiglösungen aus sind. Viele Unternehmen versuchen, Kosten zu sparen, indem sie sich für günstigere Lösungen entscheiden oder versuchen, die Standards auf eigene Faust und ohne angemessene Ressourcen zu implementieren.
Dies führt regelmäßig dazu, dass Unternehmen wichtige Bereiche übersehen oder mangelhafte Lösungen implementieren, die die Standards nicht vollständig erfüllen oder nur Mehrarbeit schaffen, ohne die eigentlich möglichen Vorteile eines Managementsystems zu erschließen. Es ist wichtig zu verstehen, dass die Implementierung von ISO/IT-Grundschutz-Standards ein wichtiger und langfristiger Prozess ist. Dieser erfordert eine angemessene Investition, um sicherzustellen, dass alle Anforderungen erfüllt werden und das Managementsystem effizient umgesetzt wird. Was bringt es, am Anfang zu sparen und dann auf Dauer mehr Kosten zu haben, um die Fehler in der Basis auszugleichen?
Lösen lässt sich dieses Dilemma durch eine klare und ausführliche Bestandsaufnahme in Kombination mit einem Soll-Abgleich. Auf Basis eines klaren Bildes, was zu tun ist, lässt sich ein angemessenes Budget für die Implementierung der gewählten Standards bereitstellen und auf qualitativ hochwertige Lösungen setzen, die den Anforderungen entsprechen.
So kommen auch langfristige Vorteile von Managementsystemen zum Tragen, wie eine verbesserte Effizienz, Qualität und Kundenzufriedenheit, was letztendlich zu höheren Umsätzen und Gewinnen führen kann. Ein angemessener Mehraufwand schon bei Implementierung des Systems rechnet sich also langfristig gesehen. (jm)
Lesetipp: Gut zertifiziert ist halb gewonnen
View the full article
- 0 comments
- 38 views
-
Assuming the completion of Palo Alto Networks’ planned acquisition of Koi Security, it said, Prisma AIRS 3.0 will soon also offer an AI Agent Gateway providing a central control plane to enforce agent runtime and identity security.
According to Gartner, 40% of enterprise applications will be integrated with task-specific AI agents by the end of this year, up from less than 5% today. As organizations accelerate their digital transformation, agentic AI in enterprise applications will move beyond individual productivity, Gartner says, setting new standards for teamwork and workflow through smarter human-agent interactions.
To meet that challenge, Prisma AIRS is adding new ways to use AI to detect AI application security issues. In a prerelease briefing for reporters, Nikesh Arora, CEO of Palo Alto Networks, predicted, “in next five years, our customers are going to go through the most significant overhaul of their enterprise networks they’ve ever seen” because of AI.
“Every CIO wants AI implemented yesterday,” he said. “Every company wants to see how they can leverage AI as quickly as possible,” wants to understand if the shift to AI is real, and if so, how CIOs need to prepare.
“Can we use AI to deliver better cybersecurity outcomes? Yes, we can,” he said. But it won’t happen overnight. In fact, he said, the pace at which large language models (LLMs) are moving is significantly expanding the attack surface.
Recently, he said, there have been news reports that AI agents created by firms caused hacks within their own companies. He didn’t cite specific examples, but last week Meta said there had been a severe internal security breach after an autonomous AI agent exposed sensitive company and user data to unauthorized employees for two hours.
In the future, if agents in the enterprise are more than a fad, Arora said, “there will be millions of agents traversing enterprise architectures, trying to execute on their behalf — both agents delegated by people like you and me, and autonomously. I can’t imagine meeting a CEO in the last three months who does not have some aspiration to start having agents effectively doing tasks within the enterprise. It’s slow going, but the intention is there. And I can see many system integrators and consultants out there advocating and helping customers with that migration.”
But, he added, there are risks. To meet them, Prisma AIRS 3.0 will allow admins to safely deploy AI applications, he said. To increase visibility, the platform will identify agents running in cloud environments, on SaaS platforms and locally on endpoints. A capability called Agent Artifact Security maps out an agent’s architecture and scans for vulnerabilities, and another capability called AI Red Teaming for Agents simulates context-aware agentic attacks, discovers AI-related vulnerabilities, and recommends runtime security policies.
Prisma Browser
To also improve AI security, Palo Alto Networks released a new version of Prisma Browser for enterprise end users, with expanded capabilities allowing employees to use any LLM they choose. The new version of the browser is able to discover user-generated AI activity and enforce content-aware boundaries to keep agents within their intended scope. The browser also prevents sensitive data from leaking to unmanaged or public AI tools during automated tasks, identifies and blocks prompt injection attacks, including malicious instructions designed to hijack AI agents hidden within websites.
Palo Alto Networks said the browser also provides real-time distinction between human actions and automated AI tasks. By assessing the intentions of both human and non-human identities, Prisma Browser enables total accountability and compliance with evolving global AI regulations
Next Generation Trust Security
Separately, Palo Alto Networks also announced a new digital certificate lifecycle management platform, following the closing last month of its acquisition of CyberArk.
By integrating CyberArk’s machine identity intelligence into the network, NGTS closes the gap between the teams managing certificates and the teams responsible for uptime, Palo Alto Networks said in a press release.
The company said that Next Generation Trust Security (NGTS) will help organizations deal with the fact that the maximum lifespan of digital certificates has just been cut to 200 days from 398 days, and by 2029 will fall to just 47 days. Until now, many companies have been keeping track of certificates through spreadsheets, says Palo Alto Networks; NGTS discovers and manages the lifecycle of certificates across the network for them.
The company said that NGTS also eliminates unapproved certificates and blind spots that lead to security gaps, protects the business from certificate-related outages and trust failures by automatically identifying and refreshing credentials before they expire and disrupt customer transactions or internal services, and accelerates the transition to a post-quantum future by handling faster renewal cycles and evolving encryption standards through automation.
Palo Alto Networks has not announced pricing for NGTS.
View the full article
- 0 comments
- 40 views
-
If you downloaded any of these compromised images, you should ensure you are no longer using these images and rotate your affected credentials immediately. This issue was isolated to Aqua Security’s images.
The Docker Hardened Images (DHI) version of the Trivy image, Docker’s infrastructure, and other Docker Hub images were not compromised.
What happened
Starting on March 19, 2026 at 18:24 UTC, threat actors compromised Aqua Security’s CI/CD pipeline to push malware into the aquasec/trivy vulnerability scanner images with the 0.69.4 and latest tags on Docker Hub. The infostealer embedded into those images has the potential to exfiltrate CI/CD secrets, cloud credentials, SSH keys, and Docker configurations. Attackers used compromised credentials to push images to Aqua Security’s own repository on Docker Hub through their build system. Since these pushes used Aqua Security’s credentials, they were authenticated by Docker Hub and were indistinguishable from normal Aqua Security activity.
On March 20, 2026 at 03:26 UTC, the attackers re-pointed the latest tag to compromised content after Aqua Security’s initial cleanup.
Another wave of compromised images were uploaded to Docker Hub with 0.69.5, 0.69.6 and latest tags on March 22. Starting around 08:00 UTC on March 23, Docker became aware of the compromised images and immediately began to investigate.
The images were deleted by the customer in the following order, preventing any further downloads from Docker Hub:
sha256:27f446230c60bbf0b70e008db798bd4f33b7826f9f76f756606f5417100beef3 (tagged with 0.69.4) on Mar 19, 2026 at 22:20 UTC sha256:5aaa1d7cfa9ca4649d6ffad165435c519dc836fa6e21b729a2174ad10b057d2b (tagged with 0.69.5) on Mar 23rd, 2026 at 01:26 UTC sha256:425cd3e1a2846ac73944e891250377d2b03653e6f028833e30fc00c1abbc6d33 (tagged with 0.69.6) on Mar 23rd, 2026 at 1:26 UTC On Mar 23rd at 15:43 UTC the content of the compromised images was quarantined by Docker, to make them available for internal investigation. Docker reached out to Aqua Security to address the images, confirm credential revocation, and share our findings. Aqua Security was already aware and worked to remove these tags and images from Docker Hub.
The last known clean release is 0.69.3.
Am I affected?
You may be affected if your systems pulled aquasec/trivy between March 19, 18:24 UTC and March 23, 01:36 UTC if you specifically pulled the tags 0.69.4, 0.69.5, or 0.69.6 or you pulled the latest tag during the affected period.
How to check your environment
Look for the compromised digests in your local image store, registry mirrors, or Artifactory/Nexus caches: sha256:27f446230c60bbf0b70e008db798bd4f33b7826f9f76f756606f5417100beef3 sha256:5aaa1d7cfa9ca4649d6ffad165435c519dc836fa6e21b729a2174ad10b057d2b sha256:425cd3e1a2846ac73944e891250377d2b03653e6f028833e30fc00c1abbc6d33 If any of these digests are present, you should remove that image and ensure they are running version 0.69.3, which is the last known good version. If any of these digests are present, assume credentials on those systems are compromised. As per our current understanding the malware targets: Docker registry tokens (~/.docker/config.json) Cloud provider credentials (AWS, GCP, Azure) SSH keys, Kubernetes tokens, CI/CD secrets Environment variables and .env files Rotate all credentials accessible from any system that ran the compromised image. Note that a few common Trivy container setup patterns mount the Docker socket (-v /var/run/docker.sock:/var/run/docker.sock), which grants the container full access to the host’s Docker daemon and effectively root-level access to the node. If you ran a compromised Trivy image with the Docker socket mounted, treat the entire host as compromised. Pin to the clean release aquasec/trivy:0.69.3 or wait for a verified new release from Aqua Security. If you believe you are affected and need assistance, contact Docker Support.
Other ways you may be affected
Trivy was compromised across multiple distribution channels, including Docker Hub images and GitHub. If you consumed through other channels (such as GitHub Actions – see advisory GHSA-cxm3-wv7p-598c), you should determine if you may have been affected.
Lessons for the ecosystem
This incident highlights learnings for how you may be able to improve your consumption of container images and CI/CD actions:
Mutable tags are not a security boundary. OCI image tags including latest are mutable pointers that can be overwritten by anyone with push access. This attack succeeded because the latest tag was silently re-pointed to malicious content multiple times. Organizations should pin images by digest (image@sha256:...) in production and CI/CD pipelines rather than relying on tags alone. Digest pinning is not sufficient on its own. A pinned digest ensures you pull the same bytes every time; it does not tell you whether those bytes were built by a trusted party from a known source. Where signed provenance attestations are available, organizations should verify them, not just match digests.
Supply chain integrity requires more than scanning. Trivy is a vulnerability scanner, a tool organizations deploy to improve supply chain security. The compromise had nothing to do with a vulnerability in the CVE sense. No software bug was exploited in the Trivy codebase. The attacker stole publishing credentials and used them to push malicious content through a trusted distribution channel. A scanner examining the compromised image would have had no reason to flag it, because the attack was in the publishing process, not the dependency graph. Scanning tells you about known vulnerabilities in image content. It does not tell you whether the image was built by the party you trust, from the source you expect.
Secret rotation must be atomic. When responding to a compromise, revoke all credentials simultaneously before issuing replacements. Partial rotation can leave windows for re-exploitation.
What Docker is doing beyond incident response
The properties that made this attack possible, such as mutable references, unverifiable provenance, trust rooted in credentials rather than build systems, are all problems we have been working on. Here is where that work applies to this incident:
Docker Hardened Images (DHI): The Trivy compromise was possible because a single stolen push token gave the attacker the ability to overwrite trusted image tags on a public registry. For images in the Docker Hardened Images catalog, this class of attack does not apply. Docker rebuilds those images from source in a hermetic build environment rather than pulling and republishing upstream binaries. Each image carries signed provenance attestations that allow consumers to verify who built it, when, and from what source. When the compromise was identified, our team locked DHI builds of Trivy to prevent any auto-update to the compromised upstream release. The exposure was limited to users pulling aquasec/trivy directly from Docker Hub.
Docker Scout: Scout can surface whether any of the three compromised digests listed above are present across your repositories, including in registry mirrors or artifact caches that may have retained copies pulled during the exposure window.
Other resources
Aqua has also published their own incident report at aquasec.com/blog.
View the full article
- 0 comments
- 48 views
-
The feature works with Kwikset locks that are controlled with the Kwikset app, and it allows locks to be accessed without the need to open the app on an iPhone. When arriving home or leaving, vehicle owners can use CarPlay to unlock or lock their home's doors.
When an iPhone is connected to CarPlay, the Kwikset app is shown alongside other third-party apps, so users can choose their home and lock or unlock their home door with a tap.
Kwikset new CarPlay functionality is designed for Kwikset locks that include the Halo Touch, Halo Keypad, Halo Touchscreen, Halo Select, and Halo Select Plus. The feature does not work with Kwikset Halo locks that are set to Matter mode. Kwikset is also adding the same integration for Android Auto.Related Roundup: CarPlayTag: KwiksetRelated Forum: HomePod, HomeKit, CarPlay, Home & Auto Technology
This article, "Kwikset Smart Locks Can Now Be Controlled Through Apple CarPlay" first appeared on MacRumors.com
Discuss this article in our forums
View the full article
- 0 comments
- 36 views
-
Ads in Apple Maps will be similar to ads in Google Maps. Retailers and brands will be able to bid for ads associated with search categories. Starbucks, for example, might display an ad when someone searches for coffee. Restaurants will be able to bid for search terms, and the highest bidder's ads will appear at the top of the results for a given term.
Apple plans to display ads in the iPhone app, Mac app, iPad app, and on the web. We first started hearing about ads in the Maps app last year, but now the feature is nearing completion.
Revenue from ads could make up for current and future changes to the App Store that could limit the money that Apple earns, or from the loss of any search deals with Google due to ongoing regulatory issues.
In January, Apple said that it would show additional ads in App Store search results starting on March 3, expanding the number of ad slots in search. App Store searches previously showed just one ad, but Apple is rolling out multiple ad slots. Apple expanded App Store ads in the UK and Japan first, and will bring them to other markets like the U.S. by the end of March.
Apple also rebranded its ad business from "Search Ads" to "Apple Ads" last year as part of its plan to show ads in more places.Tag: Apple Maps
This article, "Apple to Introduce Ads in Apple Maps as Part of Services Revenue Push" first appeared on MacRumors.com
Discuss this article in our forums
View the full article
- 0 comments
- 37 views
-
Apple Vía Santa Fe in Mexico City
The page listed Apple as a future tenant in the mall, which is set to expand into an adjacent area previously occupied by the older Centro Coyoacán shopping mall. It is unclear when Apple's store would open, and the plans could change.
It is unclear why the page was deleted, but Apple has a culture of secrecy.
Apple has two other stores in Mexico City — one is inside the Vía Santa Fe shopping mall, and the other is at the Antara open-air shopping center.
Apple Vía Santa Fe opened in 2016, and Apple Antara followed in 2019.
(Thanks, José!)Tags: Apple Store, Mexico
This article, "Mexico is Seemingly Getting a Third Apple Store" first appeared on MacRumors.com
Discuss this article in our forums
View the full article
- 0 comments
- 31 views
-
Priced starting at $170, the Chromatic String Lights come in a 32.8-foot strand with 10 bulbs or a 65.6-foot strand with 20 bulbs. I was able to test out the lights ahead of launch, and I haven't seen string lights quite like them before.
Govee put 55 RGB LEDs inside each bulb, and the LEDs can be controlled semi-individually, with combinations of colors, shadows, and patterns able to make visually attractive scenes. The lights support millions of colors, and three layered cycling effects can be added per bulb. Patterns control how the lights change, and there are a lot of different options to choose from. Govee has tons of pre-installed scenes to select from, but there are also options to create your own with custom colors and patterns, or use AI to come up with something based on a text-based suggestion.
The lights have rich colors and the multi-color effect works well, but some colored LED lights struggle with certain shades. Govee's orange colors are more yellow than orange, and purple is more pink. I can get a truer orange by choosing a shade of red or setting a gradient that shifts between different colors, but most of the "orange" shades in Govee's app aren't true orange. The same goes for purple. It's not easy to photograph colored lights, so I don't have an example, but purple in particular is a color some RGB lights often struggle with.
The bulbs are large for string lights, and I'd say they're similar to a large egg. The top is black, the cord is black, and the bottom is a dual-layer shell with a diffusing layer covered by clear plastic. The shape and the multi-layer shell produce some aesthetic lighting combinations, though I didn't like how much cord there is to deal with.
10 bulbs spread across 33 feet is around one bulb per three feet (or 20 for 65 feet). I would have liked a shorter strand with more closely situated bulbs, or more bulbs on the longer strand. That said, these are large bulbs, and just 10 can put off enough light for a small patio. At full brightness in a shade of white, they put off a surprising amount of light. Govee says they're 240 lumens, which sounds about right. With the diffusion layer, they aren't hard to look at even at max brightness. I did test these at night and during the day. They look great at night, but the colors are visible during the day, and indoors with other lights on.
Outdoors at night, it'd be the perfect amount of light for eating dinner or just chilling on a deck. I don't have these permanently outside because I'm not sure how to arrange 10 lights over my deck without it looking unusual. The 20 bulb strand is probably the better fit for most outdoor spaces, unless the area is small. You can connect multiple strands together, but that would get expensive quickly.
Govee added T-shaped clips for each light, so you can decide how far you want them to hang down. You can clip the strands between two of the lights together to establish the length, and if you make them long, it can eat up some of the cord so there's less to deal with. I tested them at about three inches, but they can be longer or shorter. It was a hassle getting the clips on, but worth it for the length customization.
I wish I had a more sophisticated way to say this, but with the 55 LEDs in each bulb, Govee's lights have effects that are just plain cool. There's a "bubbles" effect that combines bubbles of one color with another base color, "ghost" that uses shadow to make it look like something is moving in the bulbs, and a whole range of gradients in different colors. Each bulb can have a gradient of colors, or colors can be set to shift between bulbs. Govee goes above and beyond with pre-set scenes. There are around 120 scene options, and most of those have a dozen color palettes to choose from. There are scenes for every holiday, plus some that are nature or planet-themed or aimed at waking up or going to sleep.
The Govee app has so much going on that I find it confusing. There's too much to choose from, and too many different tools to experiment with. You can choose a Scene from the Scene tab, but there's also a color tab where you can pick one color or paint colors on each bulb, and the DIY section is separate from the color section, even though it has a somewhat similar purpose. I'm still not entirely sure what Finger Sketch does, and AI is also its own tab. Govee also has a random color feature, an Effects lab, and a Color Slider that's distinct from the Color section. Some of these options could be combined into something that's more user-friendly to use and less chaotic.
Since there are so many scenes, it's easiest to use those, but I did like choosing colors for each bulb. I think most people will get used to the app interface after using the lights for a short period of time, but it takes experimentation. Kids will love playing with these lights, since there are so many colors and patterns to play with. I don't think these are the lights that are appropriate for a sophisticated outdoor dinner party, but they'd be ideal for a night time pool party. You can do soft, elegant scenes with fewer colors, or choose nice white light effects, but if you're not planning to go all out taking advantage of the multi-color ability, there are better lights to get.
I haven't had these lights long enough to test how they hold up over time, but they do have IP67 waterproofing and Govee says they can be used outdoors year-round. They're supposed to last for "more than 10 years" under typical outdoor conditions.
You can use the Chromatic String Lights with HomeKit, because they're Matter-enabled. You can turn the lights on, turn them off, or set them to a single color with the Home app or with Siri, but for most color options, you're going to need the Govee app. HomeKit is useful for automations with other HomeKit devices, so you can have the Govee lights come on with other HomeKit-enabled lights or when motion is detected, but I otherwise haven't used HomeKit for much. You can also connect them to other Matter platforms, including Amazon Alexa and Google Home.
The lights are priced at $169.99 for the 33-foot strand or $299.99 for the 66-foot strand, and they can be purchased from Amazon or the Govee website as of today.
Note: Govee provided MacRumors with the 33-foot Chromatic String Lights for the purpose of this review. No other compensation was received.Tag: HomeKit
This article, "Review: Govee's New Chromatic String Lights Work With HomeKit and Display Multiple Colors Per Bulb" first appeared on MacRumors.com
Discuss this article in our forums
View the full article
- 0 comments
- 35 views
-
- 0 comments
- 35 views
-
Apple's Swift Student Challenge tasks students with creating an original coding project using Swift Playgrounds or Xcode. This year's event began on February 6, and Apple accepted submissions through Saturday, February 28 before judging began.
Apple plans to choose winners based on submissions that demonstrate "excellence in innovation, creativity, social impact, or inclusivity."
All Swift Student Challenge Winners in 2026 will be eligible to enter the lottery process to attend Apple's June 8 WWDC Special Event at the Apple Park campus in Cupertino, California.
Apple will also recognize Distinguished Winners whose submissions are "truly exceptional." Distinguished Winners will be invited to Cupertino for a three-day experience that will include the Special Event keynote viewing along with other activities, and these winners will not need to enter the lottery to visit Apple Park.
Students who entered the challenge can expect to receive an email notifying them about their status later this week.Related Roundup: WWDC 2026Related Forum: Apple, Inc and Tech Industry
This article, "Apple to Announce 2026 Swift Student Challenge Winners on March 26" first appeared on MacRumors.com
Discuss this article in our forums
View the full article
- 0 comments
- 39 views
-
Since iOS 18, we've been waiting for Apple to introduce a more intelligent version of Siri, and that might finally happen with iOS 27. We are expecting the Apple Intelligence version of Siri that includes personal context with support for new, deeper search capabilities, onscreen awareness so Siri can answer questions about what you're looking at, and the ability to do more in and between apps.
Apple is also working on a chatbot version of Siri that will rival ChatGPT, Gemini, and Claude, and we could potentially get a chatbot Siri preview at WWDC.
Apple's AI advancements wording hints at the inclusion of new Siri features, plus it suggests we could get other new AI capabilities as well. We have a full iOS 27 roundup on all of the iOS 27 rumors we've heard so far, which is worth checking out if you want a refresh on what could be coming.Related Roundup: WWDC 2026Related Forum: Apple, Inc and Tech Industry
This article, "WWDC 2026 to Showcase Apple's 'AI Advancements'" first appeared on MacRumors.com
Discuss this article in our forums
View the full article
- 0 comments
- 42 views
-
WWDC always begins with a keynote that happens on the first day of the event, and this year's keynote will take place on June 8 at 10:00 a.m. Pacific Time. Apple will unveil iOS 27, iPadOS 27, macOS 27, tvOS 27, watchOS 27 and visionOS 27.
Apple does plan to hold an in-person component for select developers and students, with the event set to take place on June 8 at the Apple Park Campus in Cupertino, California. Attendees will be invited to watch the keynote and State of the Union at Apple Park, as well as meet with Apple employees and tour the campus.
Current Apple Developer Program members, Apple Entrepreneur Camp alumni, prior Swift Student Challenge winners, and current Apple Developer Enterprise Program members can enter to attend the June 8 Apple Park event, and Apple will choose participants through a random lottery. Submissions will be accepted will be accepted until 11:59 p.m. PT on Monday, March 30.
Apple accepted submissions for its Swift Student Challenge in February, and winners will be announced soon. Those who are named Distinguished Winners will be invited to Cupertino for a multi-day experience.
WWDC 2026 will include online sessions and labs so that developers can learn about all of the new software features and how to incorporate new capabilities into their apps. The keynote and online sessions will be available on the Apple Developer app, Apple website, and YouTube.
Apple will provide more information about WWDC 2026 through the Apple Developer app and the Apple Developer website as June approaches.Related Roundup: WWDC 2026Related Forum: Apple, Inc and Tech Industry
This article, "Apple Announces WWDC 2026 Will Take Place June 8 to 12" first appeared on MacRumors.com
Discuss this article in our forums
View the full article
- 0 comments
- 41 views
-
For example, he said the latest AirPods Max being named "AirPods Max 2" is a "massive stretch" given the headphones received the H2 chip and little else.
AirPods Max 2 did gain many new features overall, including increased active noise cancellation, improved sound quality, Adaptive Audio, Personalized Volume, Conversation Awareness, Voice Isolation, and Live Translation, but many of these capabilities were enabled as a result of the headphones finally getting the H2 chip from 2022.
"The real issue is putting a '2' in the name," he argued. "It means that Apple is treating a maintenance update as if it were a new generation. Historically, this branding would signal meaningful hardware changes." With the AirPods Max 2 name, however, he said it "implies a leap forward that isn't present."
"Like the earlier USB-C refresh, this update feels designed to sustain sales rather than push the product forward," he added.
While the MacBook Neo is impressive in the sense that it is easily Apple's most affordable new MacBook ever, and the Studio Display XDR checks a lot of boxes, many other products unveiled this month received faster chips and little else, including the MacBook Air, MacBook Pro, iPad Air, and the regular Studio Display.
Nevertheless, Gurman acknowledged that customers continue to purchase Apple products, with the company reporting an all-time revenue record last quarter.
"Imagine if the recent product updates themselves were as impressive as the advertising," he concluded.Tag: Mark Gurman
This article, "Gurman: Many of Apple's Latest Products Are 'as Incremental as Ever'" first appeared on MacRumors.com
Discuss this article in our forums
View the full article
- 0 comments
- 34 views
-
The article said Ternus is leading development of a trio of new home products, including a tabletop robot with a swiveling screen, a smart home hub with Apple Intelligence and facial recognition, and "a small sensor for managing home security."
The sensor has an internal codename of J450, according to Gurman. In his previous reporting, he has referred to this J450 product as a security camera, but in his Ternus profile he opted to describe the accessory as a "small sensor."
Ultimately, it sounds like it will be both a HomeKit camera and a sensor.
Last August, Gurman reported that the camera was "designed for home security" and "has facial recognition and infrared sensors to determine who is in a room." It will be powered by a battery, he added, so it will probably be wireless.
In addition to security, Gurman said the accessory will be designed for "automating tasks."
"Apple believes users will place cameras throughout their home to help with automation," wrote Gurman. "That could mean turning lights off when someone leaves a room or automatically playing music liked by a particular family member."
Indeed, many third-party HomeKit sensors offer all-in-one functionality for motion and people detection, indoor temperature and humidity measurement, the level of light in a room, and more. These sensors are typically part of a home's broader HomeKit ecosystem, working in unison with smart lightbulbs, door locks, thermostats, and more.
Apple is planning to develop an entire lineup of smart home cameras and security products, according to that August report, and that might even include a video doorbell with Face ID. These accessories will likely be sold as optional add-ons to the company's long-rumored smart home hub, which is currently expected to launch in September.Tags: Apple Smart Home Camera, Bloomberg, Mark Gurman
This article, "Apple Reportedly Working on 'Small Sensor for Managing Home Security'" first appeared on MacRumors.com
Discuss this article in our forums
View the full article
- 0 comments
- 34 views
-
Crowdsourced Speedtest data published by Ookla suggests the iPhone Air captured 6.8 percent of iPhone 17 generation samples in the U.S. during the fourth quarter of 2025, up from the 2.9 percent share the iPhone 16 Plus managed in the same launch window a year earlier.
However, the gains seem to have come at the iPhone 17 Pro's expense. The latter model's share fell from 34.9 percent to 30.6 percent year over year, while the iPhone 17 Pro Max remained essentially flat at 55.5 percent. The figures suggest that roughly 4 percent of buyers were willing to trade the better camera and processing power of the smaller iPhone 17 Pro model for the Air's thinner chassis.
Apple has had several attempts at making a differentiated fourth iPhone model work. The iPhone mini under-performed over two iterations, while the iPhone 14/15/16 Plus – with its larger screen but without the Pro Max's premium features – fared worse, and neither carved out anything more than a niche fan base. In contrast, the iPhone Air has done what those models couldn't, at least in its opening months of availability.
Based on Ookla's data, adoption of Apple's ultra-thin device was even stronger abroad, with the Air taking 11.2 percent share in South Korea, 8.9 percent in Japan, and 8.4 percent in Singapore.
Separately, Ookla's testing found that Apple's in-house C1X modem in the iPhone Air has reached effective download parity with the Qualcomm X80 in the iPhone 17 Pro Max, and beat it on latency in 19 of 22 analyzed markets. Upload speeds are still Qualcomm's advantage, however, with the X80 holding up to a 32 percent lead in some regions – a gap Ookla attributes to more mature Uplink Carrier Aggregation (UL-CA).
For all the details, check out Ookla's full report.Related Roundups: iPhone 16, iPhone AirTag: OoklaBuyer's Guide: iPhone Air (Buy Now)Related Forum: iPhone
This article, "iPhone Air Said to Be Roughly Twice as Popular as iPhone 16 Plus" first appeared on MacRumors.com
Discuss this article in our forums
View the full article
- 0 comments
- 36 views
-
Experts say the wiper campaign against Iran materialized this past weekend and came from a relatively new cybercrime group known as TeamPCP. In December 2025, the group began compromising corporate cloud environments using a self-propagating worm that went after exposed Docker APIs, Kubernetes clusters, Redis servers, and the React2Shell vulnerability. TeamPCP then attempted to move laterally through victim networks, siphoning authentication credentials and extorting victims over Telegram.
A snippet of the malicious CanisterWorm that seeks out and destroys data on systems that match Iran’s timezone or have Farsi as the default language. Image: Aikido.dev.
In a profile of TeamPCP published in January, the security firm Flare said the group weaponizes exposed control planes rather than exploiting endpoints, predominantly targeting cloud infrastructure over end-user devices, with Azure (61%) and AWS (36%) accounting for 97% of compromised servers.
“TeamPCP’s strength does not come from novel exploits or original malware, but from the large-scale automation and integration of well-known attack techniques,” Flare’s Assaf Morag wrote. “The group industrializes existing vulnerabilities, misconfigurations, and recycled tooling into a cloud-native exploitation platform that turns exposed infrastructure into a self-propagating criminal ecosystem.”
On March 19, TeamPCP executed a supply chain attack against the vulnerability scanner Trivy from Aqua Security, injecting credential-stealing malware into official releases on GitHub actions. Aqua Security said it has since removed the harmful files, but the security firm Wiz notes the attackers were able to publish malicious versions that snarfed SSH keys, cloud credentials, Kubernetes tokens and cryptocurrency wallets from users.
Over the weekend, the same technical infrastructure TeamPCP used in the Trivy attack was leveraged to deploy a new malicious payload which executes a wiper attack if the user’s timezone and locale are determined to correspond to Iran, said Charlie Eriksen, a security researcher at Aikido. In a blog post published on Sunday, Eriksen said if the wiper component detects that the victim is in Iran and has access to a Kubernetes cluster, it will destroy data on every node in that cluster.
“If it doesn’t it will just wipe the local machine,” Eriksen told KrebsOnSecurity.
Image: Aikido.dev.
Aikido refers to TeamPCP’s infrastructure as “CanisterWorm” because the group orchestrates their campaigns using an Internet Computer Protocol (ICP) canister — a system of tamperproof, blockchain-based “smart contracts” that combine both code and data. ICP canisters can serve Web content directly to visitors, and their distributed architecture makes them resistant to takedown attempts. These canisters will remain reachable so long as their operators continue to pay virtual currency fees to keep them online.
Eriksen said the people behind TeamPCP are bragging about their exploits in a group on Telegram and claim to have used the worm to steal vast amounts of sensitive data from major companies, including a large multinational pharmaceutical firm.
“When they compromised Aqua a second time, they took a lot of GitHub accounts and started spamming these with junk messages,” Eriksen said. “It was almost like they were just showing off how much access they had. Clearly, they have an entire stash of these credentials, and what we’ve seen so far is probably a small sample of what they have.”
Security experts say the spammed GitHub messages could be a way for TeamPCP to ensure that any code packages tainted with their malware will remain prominent in GitHub searches. In a newsletter published today titled GitHub is Starting to Have a Real Malware Problem, Risky Business reporter Catalin Cimpanu writes that attackers often are seen pushing meaningless commits to their repos or using online services that sell GitHub stars and “likes” to keep malicious packages at the top of the GitHub search page.
This weekend’s outbreak is the second major supply chain attack involving Trivy in as many months. At the end of February, Trivy was hit as part of an automated threat called HackerBot-Claw, which mass exploited misconfigured workflows in GitHub Actions to steal authentication tokens.
Eriksen said it appears TeamPCP used access gained in the first attack on Aqua Security to perpetrate this weekend’s mischief. But he said there is no reliable way to tell whether TeamPCP’s wiper actually succeeded in trashing any data from victim systems, and that the malicious payload was only active for a short time over the weekend.
“They’ve been taking [the malicious code] up and down, rapidly changing it adding new features,” Eriksen said, noting that when the malicious canister wasn’t serving up malware downloads it was pointing visitors to a Rick Roll video on YouTube.
“It’s a little all over the place, and there’s a chance this whole Iran thing is just their way of getting attention,” Eriksen said. “I feel like these people are really playing this Chaotic Evil role here.”
Cimpanu observed that supply chain attacks have increased in frequency of late as threat actors begin to grasp just how efficient they can be, and his post documents an alarming number of these incidents since 2024.
“While security firms appear to be doing a good job spotting this, we’re also gonna need GitHub’s security team to step up,” Cimpanu wrote. “Unfortunately, on a platform designed to copy (fork) a project and create new versions of it (clones), spotting malicious additions to clones of legitimate repos might be quite the engineering problem to fix.”
View the full article
- 0 comments
- 37 views
-
The report, based on more than 500,000 hours of incident response engagements in 2025, finds that attackers are compressing key phases of the attack lifecycle, even as median dwell time increased to 14 days, up from 11 days the previous year.
In addition, it reveals a change in tactics. Voice phishing accounted for 11% of initial infection vectors, making it the second most common entry point after exploits, which led at 32%. Email phishing declined to 6%, down from 14% the year before, reflecting a move toward more interactive social engineering. Together, the trends point to a shift in both how quickly attacks unfold and what attackers are trying to achieve once inside.
It also highlights a growing imbalance between speed and persistence. While some attack phases now unfold in seconds, others are becoming more prolonged. Incidents identified through external notification had a median dwell time of 25 days, compared with nine days for those detected internally, pointing to improved internal detection but continued gaps in visibility, particularly in complex environments.
At the same time, attackers are refining their objectives. Ransomware-related intrusions accounted for 13% of investigations, while extortion activity appeared in 23% of cases. Data theft was observed in 40% of incidents, up slightly from 37% the previous year.
As Jurgen Kutscher, vice president at Mandiant Consulting, Google Cloud, writes in a blog post accompanying the report, financially motivated groups are “optimized for immediate impact and deliberate recovery denial,” while other threat actors such as nation-states focus on long-term persistence.
Attack timelines compress as threat actors specialize
One of the most consequential developments is the rise of hand-off operations, in which one threat actor gains initial access and rapidly transfers it to another, often a ransomware group. A major driver of this shift is what Mandiant describes as “increased specialization and collaboration within the cybercrime ecosystem.”
The speed of that transition has changed dramatically. “In 2022, the median time between an initial access event and the hand-off to a secondary threat group was more than 8 hours. In 2025, that window collapsed to just 22 seconds,” Kutscher writes.
Prior compromise, in which access is inherited from another threat actor, accounted for roughly 10%–13% of initial infection vectors globally and as much as 30% in ransomware operations. For defenders, alerts that once seemed low priority can now escalate into full-scale incidents almost immediately.
Social engineering becomes more interactive
While exploits remain the leading initial infection vector at 32%, the report underscores a shift toward more adaptive social engineering. Voice phishing has risen sharply, while email phishing continues to decline, signaling a move away from high-volume campaigns toward real-time interaction.
Mandiant’s data shows that email phishing dropped to just 6% of intrusions in 2025. In its place, adversaries have pivoted to highly interactive, voice-based social engineering.
Attackers are also using messaging platforms and social media to engage targets directly, often bypassing technical controls by manipulating help desk processes or identity verification workflows. The report highlights how attackers are exploiting SaaS environments, harvesting tokens and credentials to move laterally across organizations and their partners.
AI accelerates early-stage attacks, not outcomes
Artificial intelligence is contributing to these changes, but not as a primary driver of successful breaches. The report indicates that attackers are using large language models to improve phishing, reconnaissance, and evasion, increasing the efficiency of early-stage operations.
At the same time, the underlying causes of successful intrusions remain unchanged. “The vast majority of successful intrusions still stem from fundamental human and systemic failures,” Kutscher writes.
AI is accelerating existing attack methods rather than replacing them, reinforcing the need for CISOs to address persistent gaps in patching, identity security, and visibility.
Ransomware shifts toward recovery denial
Ransomware tactics are evolving. While encryption and data theft remain central, attackers are increasingly focused on undermining an organization’s ability to recover. In 2025, Mandiant observed a systemic shift in which ransomware operators actively targeted backup infrastructure, identity services, and virtualization management planes.
This shift toward recovery denial changes the dynamics of extortion. By compromising or destroying recovery capabilities, attackers increase the likelihood that victims will pay, even when backups exist. “Modern ransomware is now a fundamental resilience problem, forcing organizations into a choice: pay or rebuild,” Kutscher writes.
Dwell time increases as persistence improves
The increase in median dwell time reflects a broader trend toward persistence, particularly in espionage operations and activity linked to North Korean IT worker schemes. In those cases, median dwell time reached 122 days, illustrating how some attackers are optimizing for long-term access rather than immediate impact.
Attackers are also exploiting gaps in monitoring infrastructure. The report notes that some threats achieve dwell times of nearly 400 days, highlighting persistent visibility challenges tied to limited log retention and monitoring of edge devices.
Detection improves, but gaps remain
Mandiant’s research indicates that 52% of organizations detected intrusions internally in 2025, up from 43% the previous year. External notifications accounted for 34% of detections, while the attacker first disclosed 14% of incidents.
Although internal detection is improving, reliance on external parties and adversary disclosure highlights ongoing visibility gaps, particularly in hybrid and cloud environments.
What CISOs should prioritize
Mandiant’s recommendations reflect a shift away from static defenses toward faster, more adaptive response models.
One key recommendation is that security teams need to rethink alert triage. With hand-off times now measured in seconds, low-level detections can no longer be treated as routine noise. What appears to be an isolated alert may signal the start of a secondary intrusion, requiring immediate action before attackers move to hands-on-keyboard activity.
Organizations also need to treat core infrastructure—identity systems, backup environments, and virtualization platforms—as critical control planes. These are now primary targets for attackers seeking to undermine recovery and must be isolated, tightly controlled, and protected as Tier-0 assets.
Identity is becoming a central battleground. As interactive social engineering bypasses traditional MFA, organizations need continuous identity verification, stricter privilege controls, and tighter governance over SaaS integrations.
Detection strategies must also evolve as attackers rely more on legitimate tools and in-memory malware. Static indicators are less effective, requiring a shift to behavioral detection that flags anomalies such as unusual access patterns, suspicious API activity, or misuse of authentication tokens.
Finally, visibility gaps remain a persistent problem. Extending log retention and centralizing telemetry across network, cloud, and virtualization environments are critical to detecting long-running intrusions and understanding their full scope.
View the full article
- 0 comments
- 42 views
-
These enhancements were added in version 3.9 of the app, available now in the App Store. Turning off betting odds previously required using the Settings app.
Launched in 2024, the Apple Sports app is available on the iPhone in the U.S., Canada, Mexico, and many countries in Europe, the Caribbean, and Latin America. The app shows scores, stats, standings, and more for a variety of leagues and events, including the NFL, MLB, NBA, NHL, NASCAR, F1, Premier League, PGA TOUR, and more.Tag: Apple Sports
This article, "Apple Sports App on iPhone Receives Three Improvements" first appeared on MacRumors.com
Discuss this article in our forums
View the full article
- 0 comments
- 38 views
-
Note: MacRumors is an affiliate partner with Amazon. When you click a link and make a purchase, we may receive a small payment, which helps us keep the site running.
Overall, this is a new all-time low price on the AirTag 4-pack. Amazon's stock on the first generation AirTag 1-Pack has begun dwindling now that the new second generation models are here, so anyone interested in this low price on the first gen 4-Pack should pick it up while it's still around.
$39 OFFAirTag 4-Pack for $59.99
Apple recently debuted the all-new AirTag, featuring longer range for tracking items and a louder speaker. We haven't tracked any notable discounts on the new second generation models as of yet, so anyone who wants to save money should keep looking into the original models.
If you're on the hunt for more discounts, be sure to visit our Apple Deals roundup where we recap the best Apple-related bargains of the past week.
Deals Newsletter
Interested in hearing more about the best deals you can find in 2026? Sign up for our Deals Newsletter and we'll keep you updated so you don't miss the biggest deals of the season!
Related Roundup: Apple Deals
This article, "AirTag 1 Gets Major Amazon Discount With 4-Pack at $59.99" first appeared on MacRumors.com
Discuss this article in our forums
View the full article
- 0 comments
- 39 views
-
The video is a recording of a July 27, 1999 employee gathering at Apple's Cupertino campus, uploaded by former Apple software engineer Akira Nonaka, who worked at Apple from 1991 to 2000. The 15-minute talk appears to have been recorded informally, likely by an employee present at the event, and has apparently not previously been shared online.
The remarks come just two years after Jobs returned to Apple in 1997, when the company was struggling financially and had a fragmented product lineup. The speech directly followed Apple's Macworld New York 1999 appearance, where it unveiled the iBook G3, its first consumer laptop in years. Jobs said the event drew nearly 50,000 attendees and received extensive media coverage, and he credited teams across the company for delivering the product.
The talk outlines Apple's product strategy at the time, centered on its four-quadrant lineup of consumer and professional desktops and portables. With the iBook, Jobs said the matrix was complete alongside the iMac, Power Mac G3, and PowerBook G3, and noted that several of these products were already on their second or third iterations.
A significant part of the talk focuses on AirPort, Apple's then-new wireless networking system developed with Lucent. Jobs described it as a long-awaited breakthrough, especially for education, and emphasized Apple's role in making it affordable and easy to use through integration with its other products.
Jobs said Apple could bring technologies like wireless networking and FireWire to market more effectively because it controlled the whole product, unlike competitors such as Dell and Compaq that had to coordinate across multiple companies.
The talk also includes commentary on Apple's financial performance and internal transformation, but he rejected the idea that the company's primary goal had been financial recovery.
This reflects a broader shift at Apple during the period, as the company moved beyond crisis management and began focusing on long-term product development and growth.
Jobs said the previous two years had been spent rebuilding key capabilities across the business, from operations to engineering and design, adding that Apple had achieved "the best operational excellence in the business now, even better than Dell." Jobs' successor, Tim Cook, joined Apple just a year earlier as Senior Vice President of Worldwide Operations.
The video also shows Jobs deliberately avoiding direct competition in enterprise markets, which were dominated by Windows systems and large corporate IT deployments, with Jobs instead reaffirming the company's focus on creative professionals, education, and consumers.
He also expressed confidence in Apple's future product pipeline, stating that the company had multiple upcoming releases that he described as "the best stuff I've ever seen in my life." This likely alluded to the introduction of Mac OS X and the iPod just two years later.Tag: Steve Jobs
This article, "Steve Jobs Talks iBook, AirPort, and More in Newly Surfaced 1999 Video" first appeared on MacRumors.com
Discuss this article in our forums
View the full article
- 0 comments
- 38 views
-
Specifically, he is referring to the long-rumored foldable iPhone, as well as an ambitious 20th-anniversary iPhone with a truly "edge-to-edge" design.
In an in-depth profile of Apple's hardware engineering chief John Ternus, who is widely considered to be the leading candidate to become Apple's next CEO whenever Tim Cook steps down, Gurman said Ternus is "overseeing the biggest set of iPhone revamps in the product's history, including a foldable model this year and a version with an edge-to-edge screen that could arrive as early as 2027, for the device's 20th anniversary."
Apple is expected to unveil the foldable iPhone in September this year, while the 20th-anniversary iPhone would debut next year, if such a device materializes. Apple unveiled the original iPhone in January 2007, so the iconic device turns 20 next year.
Given the article was focused on Ternus, it did not provide any further details about these iPhone models, but there are already plenty of rumors.
Like Samsung's Galaxy Z Fold 7, the foldable iPhone will open up like a book, providing users with a large screen for watching videos, playing games, and multitasking. iOS 27 is expected to be optimized for the foldable iPhone, allowing for side-by-side apps.
A few months ago, a report said the foldable iPhone will be equipped with a 7.7-inch inner display, and a 5.3-inch outer display. It was initially rumored that the device would have a virtually "crease-free" inner display, but it was later reported that Apple is using technology that "reduces the crease without eliminating it entirely."
Apple supply chain analyst Ming-Chi Kuo expects the foldable iPhone to have two rear cameras, one front camera, and a Touch ID power button instead of Face ID.
As for the 20th-anniversary iPhone, previous reports have indicated that the device will have a seamless design, with a curved glass enclosure and no cutouts in the display. To achieve this, the front camera would be located under the screen.
It is unclear if Apple will be able to pull off such a device by next year, but if it does, then it truly would be a big two years ahead for the iPhone.Related Roundup: iPhone FoldTags: 20th-Anniversary iPhone, Bloomberg, Foldable iPhone, Mark Gurman
This article, "Apple Reportedly Preparing 'Biggest Set of iPhone Revamps' Ever" first appeared on MacRumors.com
Discuss this article in our forums
View the full article
- 0 comments
- 46 views
-
In a detailed profile of Apple's hardware engineering chief John Ternus, Gurman revealed that Apple considered adding a camera and a more advanced array of sensors to the original HomePod, which was announced in 2017. Ternus apparently believed that the additional capabilities would push up development costs and decided to cancel the features as a result.
Ternus was said to be reluctant to invest deeply in smart home devices when the first leading products from Amazon and Google arrived on the market around a decade ago. He subsequently took "some responsibility" for Apple falling behind in the smart home category.
Now, Ternus is leading Apple's efforts to re-establish itself in the smart home market with three new products, including an AI-powered smart home hub with facial recognition (J490), a small sensor for managing home security (J450), and a robotic device (J595). The smart home hub, dubbed "HomePad" in some reports, is expected to launch in the fall of 2026. Related Roundup: HomePodTags: Bloomberg, John Ternus, Mark GurmanBuyer's Guide: HomePod (Neutral)
This article, "Apple Considered Adding a Camera to the HomePod Years Ago" first appeared on MacRumors.com
Discuss this article in our forums
View the full article
- 0 comments
- 44 views
-
- 0 comments
- 52 views
-
Writing in his latest Power On newsletter, Gurman said that Apple updated the pricing on several external drive offerings recently, and the increases are steep. For example, a SanDisk 4TB solid-state external drive that previously sold for around $500 now costs $1,200, while a 1TB model has jumped from $120 to $360.
The price hikes are said to be indirectly caused by the AI-fueled demand for memory and storage chips, which is continuing to squeeze the consumer market. Gurman noted that it is vendors who set the pricing on third-party accessories, rather than Apple. However, the impact on buyers is the same regardless.
It's not just a pricing issue either. External drives on Apple's online store are largely sold out, with most models showing no availability for delivery or in-store pickup. Shoppers at physical Apple Store locations may still find stock, but at the same inflated prices. Similar shortages and hikes can be found at Best Buy, Amazon, and other retailers.
The shortage stems from the same supply crunch that forced Apple to raise MacBook Air and MacBook Pro prices by $100 earlier this month. Its removal of the Mac Studio's top 512GB RAM memory upgrade was also likely related. As things stand, AI data center build-outs are consuming enormous quantities of NAND flash and memory chips, and manufacturers are prioritizing those lucrative enterprise contracts over consumer products. As Gurman notes, the situation is likely to get worse throughout 2026 – and possible beyond.Tags: Apple Store, Mark Gurman
This article, "Apple Store External Storage Prices Spike Amid AI-Driven Shortage" first appeared on MacRumors.com
Discuss this article in our forums
View the full article
- 0 comments
- 46 views
-
- 0 comments
- 41 views
-
Called “VoidStealer,” the stealer seems to have found a way around ABE, introduced in Chrome 127 in 2024, a security control aimed at locking sensitive browser data like passwords and cookies behind tighter encryptions, tying decryption to a privileged system service.
While ABE bypasses have existed before, through techniques that involved code injection into Chrome, abusing COM/elevation service, and remote debugging, almost all of them required admin privileges.
Vojtěch Krejsa, the threat researcher at Gen who first flagged the stealer, calls VoidStealer’s bypass non-noisy. “The bypass requires neither privilege escalation nor code injection, making it a stealthier approach compared to alternative ABE bypass methods,” he said in a blog post.
Chasing the master key
An ABE bypass revolves around a critical piece of material, the “v20_master-key.” This key is what ultimately unlocks stored browser secrets, including cookies, passwords, and tokens, once the browser has verified the request. In theory, ABE keeps this key tightly guarded, ensuring it’s never exposed in a way that malware can easily access it.
However, in practice, that key still has to exist in plaintext at runtime, if only briefly, for Chrome to do its job.
Earlier bypass techniques found ways to go after decryption, some relying on process injection that involved slipping malicious code into Chrome to invoke a legitimate decryption routine. Others used memory dumping or remote debugging, scanning large chunks of process memory to locate decrypted data. More advanced approaches abused Chrome’s elevation service or COM interfaces to trick the browser into handing over decrypted material.
VoidStealer takes a more surgical route, Krejsa explained. Instead of forcing Chrome to decrypt data or scraping memory broadly, it attaches as a debugger and waits. By placing hardware breakpoints on a precise instruction tied to Chrome’s decryption flow, it intercepts the exact moment the v20_master_key appears in plaintext in memory. It then reads the key using standard debugging APIs.
VoidStealer uses hardware breakpoints because they don’t modify code, Krejsa explained. Unlike software breakpoints, which can be detected, hardware ones rely on CPU registers, leaving memory untouched and without altering Chrome’s natural execution.
Malware with many tricks
VoidStealer is part of a broader shift in how infostealers are evolving post-ABE. The malware already supports multiple bypass techniques, falling back to older injection-based methods if needed, but clearly prioritizing stealth where possible.
Krejsa also warned of its development pace. Since first appearing in December 2025, the malware has evolved quickly through versions, suggesting active maintenance and likely customer demand in underground markets. The malware, which runs a MaaS model, has undergone a total of 12 iterations so far, with the latest version “v2.1” rolled out on Mar 18, 2026.
Because VoidStealer avoids injection and privilege escalation, traditional indicators could fall short, Krejsa noted. He said defenders must focus on behavioral signals, including unexpected debugger attachments to browser processes, unusual use of memory-reading APIs, and anomalous Chrome process spawning patterns.
As a primary indicator of compromise (IoC), the researcher shared a sample linked to VoidStealer v2.0.
View the full article
- 0 comments
- 55 views
-
According to Weibo-based leaker Digital Chat Station, Apple's first book-style foldable will feature two layers of ultra-thin glass (UTG) or ultra-thin flexible glass (UFG), with the display sandwiched between them, isolating it from direct contact with the hinge. The arrangement is designed to spread mechanical stress across multiple layers rather than concentrating it on a single sheet, which could improve durability and reduce visible creasing over time.
The approach would be a departure from most current foldables, which typically use a single UTG layer that must simultaneously handle bending forces and protect the display underneath. Decoupling the display from the hinge mechanism could also help Apple meet its reported goal of making the crease almost imperceptible – though more recent reports have pushed back on past "crease-free" claims.
As we reported in December, Apple has been testing next-generation UFG with variable thickness, with a thinner layer at the fold for flexibility, and a thicker layer elsewhere for rigidity. The latest rumor suggests Apple has developed a composite glass stack rather than relying on a single panel alone.
The foldable iPhone is expected to launch later in September alongside the iPhone 18 Pro lineup, although recently one analyst claimed the device could be released closer to December.
The device is expected to feature an approximately 5.3- to 5.5-inch outer display and a 7.8-inch inner screen. It will reportedly use liquid metal hinges to achieve a virtually crease-free display and is expected to be priced between $2,000 and $2,500, making it Apple's most expensive iPhone ever.Tags: Digital Chat Station, Foldable iPhone
This article, "Foldable iPhone Uses Layered Glass to Reduce Display Crease" first appeared on MacRumors.com
Discuss this article in our forums
View the full article
- 0 comments
- 33 views
-
- 0 comments
- 37 views
-
In a Sunday newsroom announcement, Samsung said the rollout is starting today in Korea, with devices in the U.S. to follow later this week. The feature will expand to more regions and on more Galaxy devices at a later date, including Canada, Latin America, Europe, Southeast Asia, Hong Kong, Japan, and Taiwan.
Owners of Galaxy S26, S26 Plus, and S26 Ultra devices will need to enable the feature in their phone's Quick Share settings menu, using a new Share with Apple devices toggle.
Last November, Google announced Quick Share compatibility with AirDrop on Pixel phones. The feature was initially limited to the newest Pixel 10 devices, but has since been expanded to the Pixel 9, Pixel 9 Pro, Pixel 9 Pro XL, and Pixel 9 Pro Fold.Tags: AirDrop, Samsung
This article, "AirDrop Support Rolling Out to Samsung Galaxy S26 Devices This Week" first appeared on MacRumors.com
Discuss this article in our forums
View the full article
- 0 comments
- 34 views
-
According to a recent report from LevelBlue SpiderLabs, a suspected North Korea-linked operative was hired, passed security checks, and was assigned to work on Salesforce data before being identified and terminated 10 days later. It took a combination of geolocation anomalies, unmanaged device access, and threat intelligence correlation to identify the threat.
In August 2025, routine onboarding quickly unraveled when Cybereason XDR behavioral analytics flagged suspicious login patterns and LevelBlue SpiderLabs threat intelligence confirmed the organization had unknowingly hired the bad actor.
When an admin from the organization activated the new hire’s EntraID account, the team observed that the new hire used an EntraID login from a Dallas, Texas, IP address that deviated from his usual login regions (China). The EntraID login originated from an unmanaged device and used an IP address from the Astrill VPN, which is typically used by North Korea-linked IT workers.
Tue Luu, threat detection engineer at LevelBlue SpiderLabs, told CSO that it was the threat intelligence correlation that set alarm bells ringing. “These things are seldom determined by a single piece of information or telemetry or behavior; rather, they result from a confluence of suspicions and statistical anomalies.”
The North Korean fake IT worker scheme can allow operatives to steal sensitive data, proprietary source code, trade secrets, and intellectual property. It can expose organizations to ransom demands and the harvesting of credentials to maintain persistent unauthorized access.
“It’s the ultimate trojan horse: difficult to mitigate, especially if they pass your employee vetting process,” Luu said.
It’s estimated that North Korea-linked remote worker schemes have infiltrated hundreds of organizations globally, generating between $250 million and $500 million annually for the regime.
How the scheme played out in detail
Friday: Threat actor hired as remote employee assigned to work on Salesforce data and passed standard verification procedures.
Friday to Wednesday: Cybereason XDR established behavioral baseline showing consistent logins from China.
Thursday: A login anomaly is detected that triggered a high-severity alert.
Friday: Threat intel matched OTX pulse for Astrill VPN infrastructure used by North Korean actors.
Monday: User’s account revoked and an extended investigation initiated.
During the SpiderLabs team’s deep dive, they scoured employee interactions, group chat additions, and other material to look for evidence of persistence mechanisms and remote access tools. They found no evidence of residual access, backdoors, or malicious artifacts, attributed to the speed of detection.
In most cases, these rogue insiders attempt to operate in the shadows.
“As long as they aren’t lighting up too many of the company’s controls, perhaps using communication channels that pass proxy muster, you may see methods like QQ chat clients, pastebin-like sites, or even shared cloud-based email drafts as ways to pass information,” Luu said.
Key signs of NK-linked insider infiltration
SpiderLabs has found that these threat actors commonly operate from China rather than North Korea because the internet is more stable and they can employ VPN services to conceal their true geographic origin.
Astrill VPN has the ability to bypass China’s Great Firewall and allows threat actors to tunnel traffic through US exit nodes and masquerade as legitimate domestic employees. As a result, authentication events from known Astrill VPN IP ranges represent a high-fidelity indicator of compromise.
In this case, however, the VPN itself wasn’t the only sign things were not as they seemed.
“I believe what happened here is that Astrill VPN was not a standard solution used in the specific environment we were monitoring for the client in this case. If it had been, then this particular indicator might not have had as much weight,” Luu said.
“The true anomaly here is that the use of that particular VPN software was unusual for this particular environment. There are personal VPNs and business VPNs, and the XDR solution can distinguish between the personal and business VPN solutions and only alert on the personal VPN usage,” Luu added.
No silver IAM bullet for CISOs
Identity and access management offers no magical method for spotting fake IT workers. As this example demonstrates, discovering a North Korean insider requires patching together a number of signals. This investigative and alert work can take different forms.
“Some approaches start with well-segregated privileges and begin ramping up privileges over time as trust and tenure are established to ‘slow roll’ risky hires,” Luu told CSO.
In some cases, it’s looking for logon or work activity outside of typical working hours for a particular geography.
“Certainly, the confluence of suspicions helps. For example, are employees accessing data or attempting to authenticate data, hosts, or applications outside their established roles?” Luu noted.
The reminder for CISO is to ensure onboarding processes are robust and regularly reviewed. “Learn what software is ‘normal’ in your environment and set software standards, and ensure employees have company-managed devices, preferably Windows for more control,” Luu advised. “Make sure IT admins apply EntraID Conditional Access policy to lock down logins from allowed regions or areas where employees are employed. The client didn’t have the conditional access policy activated before the incident, and they applied it after as a recommendation from Cybereason.”
View the full article
- 0 comments
- 48 views
-
The rise of complex, distributed systems has made manual intervention nearly impossible for modern operations teams. As organizations scale, the need for intelligent automation becomes a necessity rather than a luxury. This guide explores the Certified AIOps Engineer program, a comprehensive curriculum designed to bridge the gap between traditional operations and artificial intelligence. Whether you are in DevOps, SRE, or platform engineering, understanding how to apply machine learning to operational data is the next logical step in your professional evolution.
This roadmap is provided by AIOps School to help engineers and managers navigate the complexities of algorithmic IT operations. By the end of this guide, you will understand the specific value of this certification, the difficulty level of the exams, and how it maps to high-growth roles in the global tech landscape. Our goal is to provide an unbiased perspective that helps you decide if this learning path aligns with your long-term career objectives in the cloud-native ecosystem.
What is the Certified AIOps Engineer?
The Certified AIOps Engineer designation represents a specialized standard for professionals who manage IT infrastructure using artificial intelligence and machine learning. Unlike theoretical data science courses, this program is rooted in production environments, focusing on how algorithms can solve real-world uptime and performance issues. It exists to validate an engineer’s ability to move beyond reactive troubleshooting into the realm of predictive and proactive system management.
This certification focuses heavily on the practical application of big data, streaming analytics, and automated response patterns within modern engineering workflows. It aligns with enterprise practices by emphasizing the reduction of “noise” in monitoring systems and the acceleration of Mean Time to Repair (MTTR). By completing this program, engineers demonstrate they can handle the scale of modern microservices architecture where traditional monitoring tools often fall short.
Who Should Pursue Certified AIOps Engineer?
This certification is built for professionals who sit at the intersection of development and operations, specifically DevOps engineers, Site Reliability Engineers (SREs), and Cloud Architects. Security professionals and data engineers also find significant value here, as the principles of anomaly detection and automated remediation apply directly to threat hunting and data pipeline stability. It is an ideal path for those who want to move away from repetitive manual tasks and toward high-level system orchestration.
In terms of experience levels, the program offers entry points for motivated beginners who have a baseline understanding of Linux and networking, as well as advanced tracks for senior leaders. In regions like India and across global tech hubs, there is a massive demand for engineers who can manage the operational costs of the cloud. Engineering managers and technical leaders should also consider this track to better understand how to structure their teams for an AI-driven future.
Why Certified AIOps Engineer is Valuable in the Current Market and Beyond
As enterprise adoption of cloud-native technologies continues to accelerate, the volume of telemetry data being generated has surpassed human capacity for analysis. AIOps ensures that engineers remain relevant by teaching them to build systems that think, rather than just systems that alert. The longevity of this certification lies in its focus on logic and architectural patterns rather than specific, fleeting tools, making it a stable career investment for the next decade.
The return on time invested in this certification is reflected in the increased efficiency of the teams that employ these certified professionals. Organizations are actively seeking ways to reduce operational overhead while maintaining high availability, and AIOps is the primary methodology for achieving this. By mastering these skills, you position yourself as a key contributor to business continuity and financial optimization within the enterprise.
Certified AIOps Engineer Certification Overview
The certification program is delivered via the official Certified AIOps Engineer curriculum and hosted on the AIOps School platform. The approach is deeply rooted in practical assessment, requiring candidates to demonstrate competency through labs and scenario-based testing rather than simple multiple-choice questions. This ensures that the credential carries weight in the industry as a true measure of technical capability.
The structure of the program is divided into logical modules that cover data ingestion, event correlation, and automated incident response. It is designed to be flexible, allowing professionals to balance their learning with full-time work commitments while still moving through a rigorous technical syllabus. Ownership of the certification resides with a community of practitioners who ensure the content is updated frequently to reflect current industry challenges.
Certified AIOps Engineer Certification Tracks & Levels
The program is structured into Foundation, Professional, and Advanced levels to cater to different stages of an engineer’s career. The Foundation level introduces the core concepts of data science for operations, while the Professional level dives into complex event processing and model deployment. The Advanced level is reserved for architects designing global-scale automated remediation frameworks that operate across multi-cloud environments.
These levels align directly with career progression, taking a practitioner from an individual contributor role to a strategic lead position. Specialization tracks are also available, allowing you to pivot toward SRE-focused AIOps, FinOps-driven cost automation, or DevSecOps security intelligence. This modularity allows you to build a personalized learning journey that supports your specific professional goals.
Complete Certified AIOps Engineer Certification Table
TrackLevelWho it’s forPrerequisitesSkills CoveredRecommended OrderOperations FoundationAssociateJunior Admins/GradsBasic Linux/CloudData ingestion, Monitoring1stAIOps ImplementationProfessionalDevOps/SREs2+ Years IT ExpPattern Discovery, ML Ops2ndIntelligent AutomationSpecialistAutomation EngineersScripting/PythonWorkflow Orchestration3rdAIOps ArchitectureExpertLead Engineers/ArchsProfessional CertStrategy, Governance4th Detailed Guide for Each Certified AIOps Engineer Certification
Certified AIOps Engineer – Foundation Level
What it is
This certification validates a foundational understanding of how AI integrates with traditional IT operations. It ensures the candidate understands the core terminology and the data lifecycle involved in intelligent monitoring.
Who should take it
It is designed for junior engineers, recent graduates, or experienced managers who need a conceptual understanding of AIOps without getting bogged down in deep coding.
Skills you’ll gain
Understanding the difference between traditional monitoring and AIOps. Basics of telemetry data collection (Logs, Metrics, Traces). Identification of common AI use cases in production environments. Familiarity with the AIOps maturity model. Real-world projects you should be able to do
Setting up a basic centralized logging and metrics pipeline. Configuring simple threshold-based alerting with noise reduction. Preparation plan
7–14 days: Review official course materials and terminology. 30 days: Complete all fundamental labs and practice quizzes. 60 days: Not typically required for this level if the candidate has a background in IT. Common mistakes
Overcomplicating basic machine learning concepts. Ignoring the importance of data quality at the ingestion phase. Best next certification after this
Same-track option: Professional AIOps Engineer. Cross-track option: Certified SRE Professional. Leadership option: IT Operations Management (ITOM) Lead. Certified AIOps Engineer – Professional Level
What it is
The Professional level validates the ability to implement and manage machine learning models specifically for operational tasks. It focuses on event correlation and anomaly detection in real-time.
Who should take it
DevOps engineers and SREs with at least two years of experience who are responsible for maintaining high-availability systems.
Skills you’ll gain
Building and deploying anomaly detection algorithms. Implementing automated root cause analysis (RCA). Managing high-volume event streams using Kafka or similar tools. Integrating AI models with existing ITSM platforms. Real-world projects you should be able to do
Building a predictive alerting system that identifies failures before they occur. Developing an automated incident response workflow for common service disruptions. Preparation plan
7–14 days: Intensive lab work focusing on data modeling. 30 days: Deep dive into Python for operations and ML frameworks. 60 days: End-to-end project implementation and exam review. Common mistakes
Failing to account for model drift in dynamic infrastructure. Creating too many automated actions without proper guardrails. Best next certification after this
Same-track option: Expert AIOps Architect. Cross-track option: Certified MLOps Specialist. Leadership option: Principal Platform Engineer. Choose Your Learning Path
DevOps Path
The DevOps path focuses on integrating AIOps into the CI/CD pipeline and deployment strategies. Engineers learn how to use AI to predict deployment failures and automate rollbacks based on performance metrics. This path is ideal for those who want to enhance the “Operations” side of DevOps with intelligent feedback loops. It emphasizes the speed of delivery without sacrificing system stability.
DevSecOps Path
In this track, the focus shifts to security intelligence and automated threat response. Candidates learn how to apply anomaly detection to identify unauthorized access patterns or unusual data egress. The goal is to move security from a periodic audit to a real-time, AI-driven defense mechanism. This path is critical for engineers working in highly regulated industries or finance.
SRE Path
The SRE path is deeply rooted in reliability and the management of Error Budgets. AIOps tools are used here to manage toil and provide deep insights into service-level indicators (SLIs). Professionals learn to build self-healing systems that can resolve incidents without human intervention. This is the most technically demanding path, requiring a strong grasp of both systems engineering and data science.
AIOps Path
This dedicated path focuses on the overarching strategy of transforming a traditional NOC into an AI-driven command center. It covers the full spectrum of the AIOps lifecycle, from data strategy to organizational change management. It is designed for those who want to become specialists in the AIOps field specifically. You will master the art of noise reduction and intelligent event orchestration.
MLOps Path
The MLOps path bridges the gap between data science and production engineering. It focuses on the lifecycle of machine learning models—training, testing, deployment, and monitoring. This ensures that the AI models used in operations are themselves reliable and scalable. It is a perfect fit for data-heavy organizations that rely on sophisticated algorithms for their core business.
DataOps Path
DataOps focuses on the reliability and quality of the data pipelines that feed into AIOps engines. This path teaches engineers how to automate data testing, orchestration, and deployment. Without high-quality data, AIOps cannot function, making this a foundational career path. It is ideal for data engineers who want to apply DevOps principles to data management.
FinOps Path
The FinOps track uses AI to manage and optimize cloud spending in real-time. Engineers learn to build models that predict cost spikes and automatically identify underutilized resources. This path is increasingly valuable as cloud bills become a significant portion of corporate overhead. It combines financial accountability with technical automation to drive business value.
Role → Recommended Certified AIOps Engineer Certifications
RoleRecommended CertificationsDevOps EngineerCertified AIOps Professional, MLOps SpecialistSRECertified AIOps Expert, SRE ProfessionalPlatform EngineerAIOps Architect, Cloud Infrastructure SpecialistCloud EngineerCertified AIOps Foundation, FinOps PractitionerSecurity EngineerAI-Driven DevSecOps, Anomaly Detection SpecialistData EngineerDataOps Professional, Certified AIOps FoundationFinOps PractitionerCloud Cost Optimizer, AIOps SpecialistEngineering ManagerAIOps for Leaders, ITOM Strategy Next Certifications to Take After Certified AIOps Engineer
Same Track Progression
Deepening your specialization within AIOps involves moving toward the Architect or Expert levels. These certifications focus on the strategic design of autonomous systems and the governance of AI in the enterprise. You will learn how to lead large-scale digital transformation projects and manage the cultural shifts required for AI adoption. This is the natural path for those aiming for Principal or Distinguished Engineer roles.
Cross-Track Expansion
Broadening your skills often means looking toward MLOps or DevSecOps to complement your AIOps knowledge. Understanding how to secure the AI pipeline or how to manage the models themselves makes you a much more versatile professional. This cross-pollination of skills is highly valued in the industry, as it allows you to sit at the center of multiple critical departments. It ensures you can speak the language of developers, security teams, and data scientists.
Leadership & Management Track
If you are looking to move into management, certifications in ITIL, COBIT, or specialized Engineering Leadership programs are recommended. These help you translate technical AI successes into business outcomes and ROI. Leading an AIOps team requires a different set of skills than building the models, including budget management and talent development. This track prepares you for roles like VP of Infrastructure or CTO.
Training & Certification Support Providers for Certified AIOps Engineer
DevOpsSchool
DevOpsSchool has established itself as a premier destination for technical upskilling in India and beyond. They offer a robust curriculum that focuses on the entire DevOps ecosystem, including specialized training for AIOps. Their approach combines theoretical knowledge with deep practical labs, ensuring that students can apply what they learn immediately in a professional setting. With a focus on industry-standard tools and methodologies, they provide a strong foundation for any engineer looking to modernize their skill set. Their instructors are typically working professionals who bring real-world scenarios into the virtual classroom.
Cotocus
Cotocus is known for its high-touch, hands-on training programs that cater specifically to the needs of enterprise teams. They specialize in cloud-native technologies and provide comprehensive support for certifications in the AIOps and SRE domains. Their training modules are designed to be modular and flexible, allowing companies to tailor the learning experience to their specific stack. Cotocus places a heavy emphasis on lab environments that mirror production systems, which is essential for mastering the complexities of algorithmic operations. Their mentorship programs help bridge the gap between passing an exam and performing on the job.
Scmgalaxy
Scmgalaxy is a community-driven platform that has been a staple in the software configuration management and DevOps world for years. They provide an extensive repository of resources, tutorials, and certification guides that are invaluable for self-paced learners. Their focus on the community means that their content is often updated based on the latest industry trends and candidate feedback. For those looking for a mix of formal training and community support, Scmgalaxy offers a unique ecosystem. They are particularly strong in providing deep dives into specific tools and automation frameworks that support AIOps implementations.
BestDevOps
BestDevOps focuses on delivering high-quality, curated training experiences for individual professionals seeking to advance their careers. They offer a range of certification prep courses that are specifically designed to be concise and impactful. Their curriculum for AIOps focuses on the most critical skills needed to succeed in the modern market, avoiding unnecessary filler. By prioritizing mentor-led sessions, they ensure that students get their questions answered by experts. This provider is an excellent choice for those who value time efficiency and a direct path to certification and career growth.
devsecopsschool.com
DevSecOpsSchool is the leading authority for engineers who want to integrate security into every phase of the development lifecycle. Their training programs are essential for AIOps professionals who need to understand how AI can be used to detect threats and automate security compliance. They offer specialized tracks that combine machine learning with security orchestration, automation, and response (SOAR). Their curriculum is designed to help professionals stay ahead of evolving cyber threats by using intelligent systems. If your career goal is to work in high-security environments, this is a critical support provider for your journey.
sreschool.com
SRESchool focuses exclusively on the principles of Site Reliability Engineering, which is the natural home for AIOps. Their training covers essential topics like Error Budgets, SLIs/SLOs, and incident management, all through the lens of automated operations. They provide the technical depth required to build and maintain high-scale, reliable systems using algorithmic approaches. By focusing on the “SRE way” of doing things, they help students develop the mindset needed to manage complex production environments. Their courses are a perfect complement to the Certified AIOps Engineer program, providing the operational context needed for AI.
aiopsschool.com
AIOpsSchool is the primary authority and hosting site for the Certified AIOps Engineer program itself. They provide the most direct and comprehensive training for this specific certification, including the official syllabus and practice exams. Their focus is entirely on the intersection of AI and operations, making them the most specialized provider in this list. By training through the official source, candidates ensure they are learning exactly what is required for the certification. They offer a range of levels from foundation to expert, providing a complete career path for aspiring AIOps engineers.
dataopsschool.com
DataOpsSchool addresses the critical need for data reliability in the AIOps lifecycle. They teach the principles of managing data as a product, ensuring that the information feeding your AI models is accurate, timely, and secure. Their curriculum covers data pipeline automation, quality control, and orchestration, which are all vital skills for an AIOps professional. As data becomes more complex, the role of DataOps becomes more central to the success of any AI initiative. This provider helps engineers master the underlying data architecture that makes intelligent operations possible.
finopsschool.com
FinOpsSchool is dedicated to the growing field of cloud financial management and cost optimization. They provide training on how to use AI and machine learning to predict cloud spend and automate cost-saving measures. This is a vital skill set for AIOps engineers who are tasked with maintaining not just system reliability, but also financial efficiency. Their courses help bridge the gap between engineering, finance, and business leadership. By mastering FinOps through this school, professionals can demonstrate their value in terms of direct bottom-line impact for their organizations.
Frequently Asked Questions (General)
How difficult is it to get certified?
The difficulty depends on the level, but professional certifications are designed to be challenging and require significant hands-on experience with operations and data analysis. Is there a prerequisite for the foundation level?
No formal prerequisites are required, but a basic understanding of IT infrastructure and monitoring concepts is highly recommended for success. How long does the certification remain valid?
Most certifications in this field are valid for two to three years, after which you may need to recertify or move to a higher level. Do I need to be a programmer to succeed in AIOps?
While you don’t need to be a software developer, a working knowledge of scripting languages like Python is essential for the professional and expert levels. Is the exam proctored or open-book?
Most professional-grade exams are proctored and conducted in a controlled environment to maintain the integrity of the credential. What is the typical timeframe for preparation?
A dedicated professional can usually prepare for the professional-level exam in 30 to 60 days of consistent study and lab work. Does this certification help with salary increases?
Certified professionals in niche fields like AIOps often command higher salaries due to the scarcity of these specialized skills in the market. Can I take the exam online?
Yes, most providers offer remote proctoring options that allow you to take the exam from your home or office. Are there lab-based questions in the exam?
Yes, the higher-level certifications often include lab environments where you must solve real-world operational problems. Is there a community for certified individuals?
Yes, most schools maintain a community or alumni network where professionals can share insights and job opportunities. Do companies recognize this certification?
Major enterprises and cloud service providers increasingly recognize these credentials as they seek to build more automated operations teams. How much do the exams cost?
Costs vary by provider and level, but they typically range from $200 to $500 per attempt. FAQs on Certified AIOps Engineer
What exactly does a Certified AIOps Engineer do daily?
They build and maintain the systems that monitor IT health, using AI to filter out false alerts and automatically resolve common infrastructure issues. How does this certification differ from a standard Data Science degree?
This program focuses specifically on the “Operations” use cases, such as log analysis and incident response, rather than general-purpose machine learning. Which tools will I learn during the certification?
You will be exposed to a variety of tools for data streaming, log management, and ML modeling, but the focus is on the underlying architectural principles. Is AIOps only for large enterprises?
While large companies benefit most from the scale, any organization with complex cloud infrastructure can use AIOps to reduce the burden on their engineers. Can an SRE benefit from becoming a Certified AIOps Engineer?
Absolutely. It is the natural evolution of SRE work, allowing for the management of thousands of services without a linear increase in headcount. What is the focus of the AIOps School curriculum?
The curriculum is designed to be vendor-neutral, focusing on the core logic of data ingestion, correlation, and automated remediation. Is there a focus on India’s tech market in this training?
The program is global, but the providers mentioned have a strong presence in India, catering to the massive demand for DevOps and SRE talent there. How do I start my journey if I’m currently a System Administrator?
Start with the Foundation level to understand the landscape, then gradually build your Python and cloud skills to move toward the Professional track. Final Thoughts: Is Certified AIOps Engineer Worth It?
The decision to pursue a certification should always be based on your long-term career goals and the needs of the industry. From my perspective, the shift toward algorithmic operations is not a trend; it is a fundamental change in how technology is managed. As systems grow more complex, the humans responsible for them must leverage better tools and smarter logic. The Certified AIOps Engineer program provides a structured, high-quality path to mastering these necessary skills.
If you are looking for a way to differentiate yourself in a crowded market of DevOps and Cloud engineers, this is a strategic move. It shows that you are prepared for the next wave of IT management and that you have the practical skills to implement it. While it requires a significant investment of time and effort, the potential for career growth and the ability to work on cutting-edge systems makes it a highly worthwhile endeavor for any serious IT professional.
View the full article
- 0 comments
- 52 views
-
The first answers were the usual suspects: TLS on the edge, our VPN and the certificates on laptops. Then we pulled up a dependency map and the mood changed. Crypto wasn’t just in a few obvious places. It was buried in API gateways, service meshes, database drivers, firmware update pipelines and third-party SaaS. Some of it was configurable. A lot of it wasn’t.
That exercise is why I think the post-quantum conversation has to move from “interesting someday” to “start now.” Even if large, fault-tolerant quantum computers are not here yet, adversaries can harvest encrypted traffic and data today and attempt to decrypt it later. If you have information that must remain confidential for a decade or more — customer PII, health data, proprietary models, merger plans — waiting for a clean deadline is the riskiest option.
The good news is that we do not have to bet the enterprise on a single new algorithm overnight. A hybrid approach lets us add post-quantum protection while keeping classical algorithms that are widely deployed and interoperable. The trick is to start early enough that the migration is deliberate, measurable and boring by the time 2030 arrives.
The 2030 deadline is closer than it looks
In security programs, 2030 can feel like an eternity. In cryptography programs, it is frighteningly close. The reason is the long tail of enterprise change: inventories, procurement, platform upgrades, certificate lifecycles, embedded devices and the slowest vendor in your stack.
The standards foundation is already landing. NIST published its first three finalized post-quantum cryptography standards in August 2024, including FIPS 203 for ML-KEM and companion signature standards. That shifted the question I hear from “what should we wait for?” to “how do we operationalize this without breaking everything?”
From there, three forces compress the timeline:
“Harvest now, decrypt later” is not theoretical. If an attacker steals encrypted session captures or archived backups, the confidentiality loss happens the day quantum-capable decryption becomes practical. Your risk horizon is set by the shelf life of your data, not the arrival date of a quantum computer. Government and critical infrastructure guidance are converging. The National Security Agency’s CNSA 2.0 suite sets expectations for quantum-resistant algorithms in national security systems with milestones that pull software and firmware signing toward a 2030 horizon. Even if you are not building for government, those supply chain requirements tend to flow downhill into commercial products. Crypto migration is never a single project. Your public TLS endpoints might be modernized quickly. Your internal PKI, code signing pipeline and long-lived devices can take years. The last crypto refresh many enterprises remember — deprecating SHA-1 and older TLS — was manageable largely because teams started before the hard cutoff dates. That is why I recommend a hybrid strategy before 2030. It buys down long-term confidentiality risk now, creates time for interoperability bugs to surface and avoids a last-minute scramble when customers, regulators or your own board ask, “Are we quantum ready?”
What hybrid post-quantum looks like in the real world
When I say “hybrid,” I mean using a classical algorithm and a post-quantum algorithm together so the connection stays secure even if one component is later broken. The most relevant enterprise example is hybrid key establishment for TLS and internal mTLS.
The IETF is standardizing approaches that combine classical ECDHE with ML-KEM so a TLS 1.3 session key depends on both mechanisms.
Hybrid signatures touch certificate chains, code signing systems and validation logic, so they usually come later. In most roadmaps I run, we begin by keeping classical certificates for compatibility while preparing PKI components, HSMs and signing services to support post-quantum signature algorithms as platforms mature.
In practice, hybrid almost always starts inside the enterprise first. External customer traffic has the most interoperability constraints and the highest blast radius. Internal service-to-service traffic, VPN tunnels between managed endpoints and software signing are better early candidates because we control both ends and can roll back quickly.
You also have to plan for real constraints:
Size and performance: post-quantum keys, ciphertexts and signatures can be larger than today’s elliptic curve equivalents, which can break assumptions in certificate stores, load balancers and MTU sizing. Crypto agility: hybrid only works if you can change algorithms without rewriting half your environment, which means pushing cryptographic choices into configuration and deprecating bespoke crypto. Operational observability: you need telemetry for handshake success rates, latency impact, error patterns and downgrade behavior so the rollout looks like any other reliability program. The point is not to be “post-quantum only” tomorrow. The point is to make post-quantum a normal part of your cryptographic control plane so the eventual full transition becomes a series of routine upgrades, not a crisis.
A practical roadmap you can start this quarter
If you are looking for a pragmatic way to begin, here is the roadmap I have used with large US enterprises.
Build a cryptography inventory tied to data value
Start with an inventory of where cryptography is used: TLS termination, internal mTLS, VPN, SSH, S/MIME, code signing, disk and database encryption, backups, identity tokens, key management systems and embedded device firmware. Map those uses to data classes and retention horizons. The systems protecting 10+ year secrets are your “harvest now, decrypt later” priorities.
CISA’s post-quantum cryptography initiative is a useful checklist for the categories and dependencies you should capture and for how to think about critical functions.
Pick 3 early migration surfaces you control end-to-end
In most enterprises, the first three areas I target are:
Internal mTLS between services VPN and remote access Code signing for internal software distribution and update pipelines These reduce long-term exposure without forcing you to negotiate compatibility with every customer browser, partner system or unmanaged device.
Stand up a “hybrid-ready” lab and instrument it
Before you touch production, stand up a lab that mirrors core traffic patterns: edge TLS, internal service mesh, API gateway and identity provider. Measure handshake sizes, latency and failure modes. Make sure you can roll back cleanly and explain what changed.
Upgrade for crypto agility
Standardize on modern TLS stacks, keep them patched and make algorithm selection a managed configuration. Consolidate certificate issuance flows. Push teams away from static crypto choices baked into application code. The more you centralize, the faster you can migrate.
Run a limited hybrid pilot with explicit success metrics
Pick one internal domain or one non-critical endpoint and pilot hybrid TLS. Define success as measurable outcomes: no increase in error rate, acceptable latency delta, stable CPU utilization and clean telemetry. When something breaks, document the dependency that caused it and feed that back into your inventory.
Put post-quantum requirements into procurement now
The fastest way to make 2030 painless is to make 2026 contracts future-friendly. Add language that requires crypto agility, support for NIST standardized post-quantum algorithms as they are adopted and a documented roadmap for hybrid support in TLS, VPN and signing.
If you start now, you buy time for standards, platforms and operational tooling to converge. Hybrid post-quantum migration rewards early, quiet work. The enterprises that begin before 2030 will not just be safer against future decryption. They will have a more agile, measurable cryptographic program that is easier to govern, audit and modernize for whatever comes next.
This article is published as part of the Foundry Expert Contributor Network.
Want to join?
View the full article
- 0 comments
- 45 views
-
- 0 comments
- 39 views
-
According to the State of Human Risk Report from Mimecast, 42% of organizations have experienced an increase in malicious insider incidents over the past year, with 42% also reporting a rise in negligent incidents for the first time.
The report further found that organizations experienced an average of six insider-driven incidents per month at an estimated cost of $13.1 million per incident. Additionally, 66% of the 2,500 surveyed IT security and IT decision-makers expect insider-related data loss to increase over the next 12 months.
“Insider risk has become one of the most consequential and underestimated threats facing organizations today, not just because of the data loss it causes, but because attackers are increasingly exploiting insiders as a deliberate entry point to bypass perimeter defenses entirely,” Mimecast CISO Leslie Nielsen said in announcing his company’s research results.
“The data shows both careless mistakes and deliberate actions driving incidents in equal measure,” he added. “Rather than trying to manage human behavior, organizations need adaptive controls that identify high-risk actions and adjust protections in real-time, creating friction when someone accesses data they shouldn’t, regardless of whether they have valid credentials. As AI makes it easier for insiders to exfiltrate data at scale, security must meet users at the point of risk.”
The state of insider threats today as technologies, tactics, and motivations evolve
Insider threats continue to fall into two broad camps. On one side is the malicious insider who knowingly acts with the intent to harm. On the other side is a member of the organization whose impacting actions may be accidental or negligent, or in some cases manipulated by a malicious outsider.
According to Forrester Research’s 2025 Security Survey, 22% of data breaches in the prior 12 months were the result of internal incidents. Some 47% were due to abuse or malicious intent, 32% were due to inadvertent misuse or an accident, and 21% involved both.
These categories cover a wide swath of activities, says Joseph Blankenship, vice president and research director at Forrester. For example, a nonmalicious insider may accidentally email protected data to someone not authorized to have it or mistakenly allow public access to a database. A disgruntled employee may actively circumvent security controls to steal sensitive information to post to embarrass the organization.
Although those scenarios have been around for years, new technologies, tactics, and motivations are evolving to drive, manipulate, and enable insiders, security leaders say.
“My background is in the intelligence community, where we studied insider threat through a well-established lens: ego, ideology, and economics. Those motivations haven’t changed. What’s changed is the operating environment and who/what qualifies as an insider,” says Chris Cochran, field CISO and vice president of AI security at the SANS Institute.
“It’s no longer just employees. It’s contractors, fraudulent hires who gained access through identity fraud, and now AI agents operating with persistent, privileged access,” he says. “A misconfigured agent is a superuser that never sleeps. A compromised agent is an adversary with legitimate credentials moving at machine speed. If it has trusted access and can act on data, it’s an insider, witting or unwitting.”
The shift to remote work, Cochran adds, also removed physical and psychological barriers to insider risks. “Downloading data to a personal device doesn’t feel like espionage, and that trivialization is the risk,” he says. “Layer on economic pressure: While companies freeze hiring and suppress raises, and you have a recipe for witting insider threat at scale.”
Niel Harper, executive coach and strategic advisor at Octave Digital and a board member with governance association ISACA, points to the growth of social media as another factor spurring insider threats today.
Social media platforms, he says, give external threat actors information they can use to bribe, trick, or entice insiders to do their bidding. “They provide a treasure trove of information for threat actors, and a threat collective can easily conduct open-source intelligence to help them understand who is susceptible to blackmail or becoming a mercenary,” he explains.
In such incidents, Blankenship says malicious actors often coach insiders on how to get around security controls and evade detection.
Employees today are also more tech savvy and have greater access to powerful digital tools, including AI, and thus are more capable of finding ways around security controls, experts say.
“The average staffer can now become a really high-risk threat actor,” says Harper, who is also chief trust officer at Hugo and a former CISO, including at the international police organization Interpol.
Moreover, AI itself can become an insider threat, Harper adds, explaining that agents can go rogue or be programmed to do so. “So AI has changed the paradigm when it comes to insider threats,” he adds.
Meanwhile, the modern work environment has created new scenarios that increase the insider threat risk, Harper says.
For example, he says the rise in the use of contractors and outsourced providers as well as people working multiple jobs can up the opportunities for both malicious and nonmalicious incidents, as does remote work, due in part to the distributed nature of digital access for such workers.
Hacktivism against companies, polarization, ideological divisions, economic pressures, and fears of job loss are also driving up insider risk today, Harper adds.
Some of these dynamics have enabled malicious actors to land work within companies to then become insider threats, says Errol Weiss, CSO at Health-ISAC. These malicious actors, who are often from North Korea, obfuscate their identities and locations so they can be hired for legitimate roles, typically in IT. The common MO is to work for as long as possible to earn money to send back to North Korea while also laying the groundwork to launch some type of attack when their employers uncover their true identities. “They’re monetizing their exits by stealing data or extorting their employers on their way out,” Weiss explains.
Additionally, threat actors are becoming more aggressive in their attempts to get insiders to do their dirty work, says Lina Dabit, executive director of the CISO office at Optiv Canada. They’re paying rewards to people willing to harass targeted individuals or provide personal information, such as a personal email or family members’ names. And they’re setting up honeypots, such as romance scams, to gain leverage over insiders.
“We’ve always had malicious insiders, but now we have coerced insiders,” Dabit says. “I think it’s just a matter of time before a threat actor shows up at someone’s home or someone’s children’s school.”
At the same time, technology has made it easier to facilitate such illicit activities, she and others say. In addition to threat actors using social media and other online sources to cull data they can use to entice or coerce insiders, they’re also using the dark web to connect with insiders willing to help. A 2026 Accenture Cyber Intelligence executive summary, titled “Rising dark-web enabled insider risk,” highlighted a 69% increase in insiders offering their access to hackers in 2025 compared to 2024 and a 127% surge in hackers recruiting insiders compared with 2022.
“The world is different and more dangerous than it has ever been,” warns Dabit, a former unit commander with the Cybercrime Investigative Team of the Royal Canadian Mounted Police. “Do not make assumptions that threat actor groups will fit into neat little boxes like nation-state, organized crime, hacktivism, etc. Collaboration between nation state and organized threat groups, whether intentional or simply opportunistic, [is happening and there is a] blurring between organized crime, nation-state, and hacktivism. Newer groups are not adhering to reputational norms, [and the threat environment] has become a no-holds barred approach and nothing is off the table.”
Shifting to proactive defense
Organizations must be on the lookout for insider threats, Dabit and others advise.
“And you need mechanisms in place to look for it,” Blankenship says, highlighting the various security technologies that can detect behaviors such as unusual or unauthorized attempts to access data and systems that could indicate an insider threat. Those, of course, are in addition to all the security and data protection controls considered standard today, he adds.
Dabit also advises security leaders to have a plan for how to respond if they suspect or catch an insider either inadvertently or maliciously causing harm.
And he advises CISOs to work with the chief legal officer and the head of HR to identify employees who could be insider threats — such as those who are about to be laid off or are disgruntled.
Harper recommends regular employee background checks, with more rigorous ones for executives and workers with access to sensitive information or systems.
Cochran says most security teams have work to do to meet the insider threats that exist today.
“Many of the CISOs I speak with don’t feel very confident they can detect an insider threat before serious damage occurs,” he says. “What needs to change is a shift from reactive, technically focused programs to integrated ones that fuse behavioral signals with technical telemetry, and critically, organizations need to extend insider risk frameworks to non-human/ agentic identities with the same rigor they’d apply to a human employee.”
View the full article
- 0 comments
- 48 views
-
- 0 comments
- 40 views
-
The article is very long, so we recommend reading it in full, but a few of the key takeaways are that Ternus is apparently "well-liked among Apple's leadership" and helped with "reversing a trend of declining product quality" at the company.
"Since getting the top hardware engineering role in 2021, he's overseen an expansion in Apple's product lineup, improving quality and focusing on functional improvements around battery life, performance and connectivity," wrote Gurman.
Cook reportedly gave oversight of Apple's design teams to Ternus at the end of last year, and Ternus has been making a lot more public appearances in interviews and in product introduction videos over the past few years. The profile provides a closer look at how Ternus has risen to become the frontrunner to succeed Cook eventually.
Cook has not shared his retirement plans with even some of his closest lieutenants, according to the report, so it is unclear when he plans to step down. Cook has served as Apple's CEO since 2011, and he reached the common retirement age of 65 last year. In a recent interview, he vaguely said he "I can't imagine life without Apple."
The full Bloomberg Businessweek article is titled "Apple's 'Nice Guy' Heir Apparent."Tags: Bloomberg, John Ternus, Mark Gurman, Tim Cook
This article, "Apple CEO Candidate John Ternus is 'Well-Liked' and Helped Reverse 'Declining Product Quality'" first appeared on MacRumors.com
Discuss this article in our forums
View the full article
- 0 comments
- 49 views
-
In an in-depth profile of Apple's hardware engineering chief John Ternus, who is widely viewed as the leading candidate to become Apple's next CEO, Bloomberg's Mark Gurman said the company is planning "an elaborate 50th birthday party" at its Apple Park headquarters in Cupertino, California, and he expects Ternus to be "center stage."
The report did not offer any further details about the celebration, but our best guess is that it will take place under the rainbow arches in the middle of Apple Park. Apple turns 50 on April 1, so the party will likely take place soon. It is unclear if the celebration will be limited to Apple's employees, or if there will be a public component involving the Apple Park Visitor Center. In any case, selected members of the press may be invited.
Apple kicked off its 50th anniversary celebrations with a surprise Alicia Keys performance at its Grand Central store in New York earlier this month, and it has since hosted similar events in China and South Korea. Apple is planning to host additional celebrations in Australia, Canada, France, Thailand, and the UK over the coming days.
MacRumors has been invited to attend one of Apple's 50th-anniversary celebrations in London this week, but we are keeping specific details under wraps in order to avoid spoiling Apple's surprise. Stay tuned for our coverage of the event.Tags: Apple 50th Anniversary, Bloomberg, Mark Gurman
This article, "Apple to Celebrate 50th Anniversary With 'Elaborate' Party at Apple Park" first appeared on MacRumors.com
Discuss this article in our forums
View the full article
- 0 comments
- 49 views
-
Note: MacRumors is an affiliate partner with Amazon. When you click a link and make a purchase, we may receive a small payment, which helps us keep the site running.
The book explores the first five decades of Apple's history, including interviews with 150 key people who shaped Apple into what it is today, like Steve Wozniak, John Sculley, Jony Ive, and more. The book is launching to coincide with Apple's upcoming 50th anniversary on April 1, 2026.
30% OFFApple: The First 50 Years for $34.78
Amazon's sale is on the hardcover version of the book, and provides an estimated March 27 delivery date for free delivery. If you're on the hunt for more discounts, be sure to visit our Apple Deals roundup where we recap the best Apple-related bargains of the past week.
Deals Newsletter
Interested in hearing more about the best deals you can find in 2026? Sign up for our Deals Newsletter and we'll keep you updated so you don't miss the biggest deals of the season!
Related Roundup: Apple Deals
This article, "Get the New Book 'Apple: The First 50 Years' for 30% Off on Amazon" first appeared on MacRumors.com
Discuss this article in our forums
View the full article
- 0 comments
- 37 views
-
5% Daily Cash is limited to $500 in combined Walgreens and Duane Reade purchases, meaning that the maximum cash back that you can receive from this offer is $25.
Ordinarily, the Apple Card offers 3% Daily Cash for Walgreens and Duane Reade purchases.
Apple's credit card is available in the U.S. only.Tags: Apple Card, Walgreens
This article, "Apple Card Offering New Walgreens Bonus" first appeared on MacRumors.com
Discuss this article in our forums
View the full article
- 0 comments
- 46 views
-
The new products include an iPhone 17e, iPad Air models with the M4 chip, MacBook Air models with the M5 chip, MacBook Pro models with M5 Pro and M5 Max chips, the all-new MacBook Neo, an updated Studio Display, a higher-end Studio Display XDR, AirPods Max 2, and the Nike Powerbeats Pro 2. The new accessories include iPhone cases, Apple Watch bands, and the iPhone's Crossbody Strap in a range of fresh color options like Bright Guava, Vanilla, Soft Pink, Clementine, and/or Electric Lavender.
iPhone 17e features the same overall design as the iPhone 16e, but it gains Apple's A19 chip, MagSafe for magnetic wireless charging and magnetic accessories, Apple's second-generation C1X modem for faster 5G, and a doubled 256GB of base storage. In the U.S., the iPhone 17e starts at $599, just like the iPhone 16e did.
The new iPad Air's key upgrades include Apple's M4 chip, an increased 12GB of RAM, Apple's N1 chip with Wi-Fi 7 support, and the C1X modem in cellular models.
The MacBook Air received a faster M5 chip, and a doubled 512GB of base storage, but the starting price increased from $999 to $1,099 as a result of a 256GB configuration being dropped. With the N1 chip, the MacBook Air now has Wi-Fi 7 and Bluetooth 6, and it now comes with Apple's 40W Dynamic Power Adapter with 60W Max.
The higher-end 14-inch and 16-inch MacBook Pro models finally received M5 Pro and M5 Max chips, plus up to twice as fast SSD speeds and a doubled 1TB of base storage. Battery life has increased slightly across all of the models, and the N1 chip extends to the MacBook Pro line now for Wi-Fi 7 and Bluetooth 6 support.
The regular Studio Display gained Thunderbolt 5 support and improved speakers, and the camera now supports Desk View. There is also an all-new, higher-end Studio Display XDR that gained all of those benefits, plus bigger improvements such as a 120Hz refresh rate, mini-LED backlighting, increased brightness, and more.
The colorful new MacBook Neo starts at just $599 in the United States, and at an even lower $499 for college students. Available in Blush, Citrus, Indigo, and Silver, the MacBook Neo is powered by the A18 Pro chip from the iPhone, and it is equipped with a 13-inch display, up to 512GB of storage, and a non-configurable 8GB of RAM.
AirPods Max 2 have a handful of upgrades over the previous AirPods Max, including Apple's H2 chip, increased active noise cancellation, improved sound quality, and features such as Adaptive Audio, Conversation Awareness, Voice Isolation, and Live Translation. Plus, the Digital Crown has a new Camera Remote function.
The special-edition Nike Powerbeats Pro 2 are the same as the regular Powerbeats Pro 2, except they have a two-tone design consisting of black and Nike's signature Volt neon green-yellow color. The earbuds have both Nike and Beats logos.
To learn more, read our coverage:Apple Announces iPhone 17e With A19 Chip, MagSafe, and More
Apple Unveils iPad Air With M4 Chip, Increased RAM, Wi-Fi 7, and More
Apple Announces MacBook Air With M5 Chip and 512GB Base Storage
Apple Unveils MacBook Pro Featuring M5 Pro and M5 Max Chips
Apple Updates Studio Display With Thunderbolt 5 and More
Apple Introduces All-New Studio Display XDR: 120Hz, Mini-LED, and More
Apple Announces $599 'MacBook Neo' With A18 Pro Chip
Apple Announces AirPods Max 2 With H2 Chip and More
Apple's Special-Edition Nike Powerbeats Pro 2 Now Available
Apple Releases iPhone Cases, Apple Watch Bands, and Crossbody Strap in New ColorsAll of the products and accessories listed above have been released, except for the AirPods Max 2, which are available to pre-order starting Wednesday, March 25.
This article, "Apple Has Released More Than 10 Products and Accessories This Month" first appeared on MacRumors.com
Discuss this article in our forums
View the full article
- 0 comments
- 45 views
-
Fortunately, Bloomberg's Mark Gurman today said an iPad with an A18 chip for Apple Intelligence is "ready to go" and "still coming this year."
An earlier report from Macworld claimed that the iPad 12 will actually have an A19 chip.
No other major changes have been rumored so far for the iPad 12, so we expect the device to have the same overall design as the current model.
Apple Intelligence is already available on all other current-generation iPad models, including the iPad mini, iPad Air, and iPad Pro.
Apple released the iPad 11 with an A16 chip in March 2025, with U.S. pricing starting at $349.
Related Roundup: iPadTags: Apple Intelligence, Bloomberg, Mark GurmanBuyer's Guide: iPad (Don't Buy)Related Forum: iPad
This article, "iPad 12 With A18 Chip for Apple Intelligence is 'Still Coming This Year'" first appeared on MacRumors.com
Discuss this article in our forums
View the full article
- 0 comments
- 49 views
-
In his Power On newsletter today, Bloomberg's Mark Gurman said new versions of the Apple TV and HomePod mini have been "ready" since last year, but he reiterated that Apple has held off on releasing them until the more personalized version of Siri and other Apple Intelligence upgrades are released later this year.
Inventory of the Apple TV, HomePod mini, and full-sized HomePod is once again "running low" at Apple's retail stores around the world, according to Gurman, but it is unclear if this means anything since the revamped Siri has yet to debut.
Gurman previously reported that Apple was aiming to release the personalized Siri features in either iOS 26.5 or iOS 27. The first developer beta of iOS 26.5 could be available in late March or early April, so at least some of the Siri upgrades might be just a week or two away, unless they are entirely held back until iOS 27 debuts in June.
Accordingly, if the new Apple TV and HomePod mini models remain tied to the Siri upgrades arriving in iOS 26.5 or iOS 27, then Apple should announce the devices at any point between late March and the end of September this year.
Earlier rumors claimed the next Apple TV would be equipped with the A17 Pro chip, which is the oldest chip that supports Apple Intelligence. The device is also expected to feature Apple's N1 chip for Wi-Fi 7, Bluetooth 6, and Thread.
As for the HomePod mini, it is expected to use an Apple Watch's S9 chip or newer, but it is not entirely clear how that chip would be capable enough to support the revamped Siri powered by Apple Intelligence. Other rumored features include the N1 chip, improved sound quality, a newer Ultra Wideband chip, and a red color option.
The current Apple TV 4K debuted in October 2022, and the HomePod mini was introduced in October 2020, so both devices are due for upgrades.
Related Roundups: Apple TV, HomePod miniTags: Bloomberg, Mark GurmanBuyer's Guide: Apple TV (Don't Buy), HomePod Mini (Don't Buy)Related Forums: Apple TV and Home Theater, HomePod, HomeKit, CarPlay, Home & Auto Technology
This article, "New Apple TV and HomePod Mini Remain 'Ready' to Launch" first appeared on MacRumors.com
Discuss this article in our forums
View the full article
- 0 comments
- 44 views
-
In the summer of 2025, Apple reportedly held discussions to acquire Lux Optics, the developer behind the popular iPhone camera apps Halide, Kino, and Spectre. The company concluded that it could get a better offer from Apple in the future following updates to the app. Two months after the talks concluded without a deal, Apple set about recruiting Lux's co-founder and designer Sebastian de With.
Lux CEO and co-founder Ben Sandofsky is said to have fired de With in December over financial misconduct. de With announced that he had joined Apple's design team in January.
Sandofsky has now filed a lawsuit in the California Superior Court of Santa Cruz against de With, accusing him of improperly using more than $150,000 in Lux company funds to pay for personal expenses since 2022, as well as providing confidential material and source code from Lux to Apple.
During the discussions to acquire Lux, Apple employees purportedly told the startup that its intellectual property was a major consideration in evaluating the company. Apple apparently wanted to acquire Lux to bolster the built-in Camera app, which is said to be "top priority for the company right now." The iPhone 18 Pro will "match professional-grade cameras in terms of certain advanced features," necessitating an upgrade of the built-in Camera app. Apple is not named as a defendant in the case and it is not accused of any wrongdoing.
de With's legal representatives say that the lawsuit is meritless and deny that he "used, transferred, or disclosed any Lux intellectual property" as part of his new job at Apple. They added that the lawsuit was only filed after de With raised concerns with Sandofsky about financial irregularities at Lux and had requested access to its financial records and payments, suggesting that it was a "retaliatory response to those efforts and an attempt to avoid scrutiny of that conduct."Related Roundups: iPhone 18, iPhone 18 ProTags: Halide, Apple LawsuitsRelated Forum: iPhone
This article, "Apple Wanted to Buy Halide to Boost iPhone 18 Pro's Camera App—Now There's a Lawsuit" first appeared on MacRumors.com
Discuss this article in our forums
View the full article
- 0 comments
- 50 views
-
- 0 comments
- 50 views
-
Today marks 19 years Apple launched the original Apple TV. Apple CEO Steve Jobs unveiled the Apple TV at Macworld Expo in January 2007 alongside the original iPhone, but it didn't launch until March.
The Apple TV was initially previewed as the "iTV." The device allowed users to wirelessly stream movies, TV shows, music, and photos from their Mac or PC directly to their TV. Unlike today, there was no App Store or third-party app support, and the experience was centered almost entirely around iTunes-purchased or synced media.
The Apple TV was controlled with a simple Apple Remote and ran a Front Row-style interface designed for navigating iTunes libraries on a TV. It featured a 40GB hard drive for local content storage and supported 720p HD resolution, offering both HDMI and component video output, and was priced at $299.
Apple famously described the Apple TV as a "hobby," reflecting its niche and experimental status within the company at the time. Over subsequent years, Apple slowly repositioned the device over time from a Mac accessory to a standalone streaming device.
In 2010, it dropped the internal hard drive and shifted to a smaller, streaming-focused design. The introduction of tvOS and the App Store in 2015 marked a major turning point, enabling third-party apps and games. Apple later added 4K support in 2017 and continued to iterate with faster chips, culminating in the current model powered by the A15 Bionic chip.
Unlike the original Apple TV, which was primarily designed to stream iTunes content from a Mac or PC, the device now serves as a hub for Apple's services, with integrations for Apple TV+, Apple Arcade, Apple Fitness+, AirPlay, and HomeKit. While competitors such as Roku, Amazon Fire TV, and Google TV devices still dominate the lower end of the market, Apple has continued to position the Apple TV as a premium option with tighter ecosystem integration and more powerful hardware.
Today's Apple TV is the third-generation 4K model from November 2022. A new Apple TV is expected to be announced soon, featuring a faster chip and Apple's custom N1 wireless chip for Wi-Fi and Bluetooth. Related Roundup: Apple TVBuyer's Guide: Apple TV (Don't Buy)Related Forum: Apple TV and Home Theater
This article, "Apple TV Is Now Almost 20 Years Old" first appeared on MacRumors.com
Discuss this article in our forums
View the full article
- 0 comments
- 46 views
-
China smartphone sales apparently fell by 4% year-over-year in the first nine weeks of 2026. Within this environment, Apple emerged as the fastest-growing major vendor, with iPhone sales rising 23% compared to the same period in 2025. Counterpoint attributed Apple's impressive performance partly to a combination of e-commerce discounts and the inclusion of the standard iPhone 17 in government subsidy programs aimed at stimulating consumer electronics purchases.
Counterpoint noted that the rising cost of memory components has been passed on to vendors, forcing several Android brands to adjust pricing strategies. Chinese smartphone makers OPPO and vivo have announced notable price increases for some existing models, with those changes set to take effect this month.
In contrast, Apple has not announced any comparable price increases and is unlikely to follow competitors in raising prices, instead absorbing some of the margin pressure from higher component costs to maintain pricing stability. The firm added that Apple's control over its supply chain leaves it better positioned than rivals to withstand rising memory costs.
Rising memory prices are expected to persist throughout 2026. The research firm expects China's smartphone market to remain under pressure in the coming months, with potential improvement in June driven by the country's mid-year "618" shopping festival. Counterpoint's findings are based on its China Weekly Smartphone Sell-Out Tracker, which monitors retail sales across the market. Tags: China, Counterpoint
This article, "Apple Bucks China's Smartphone Slump With 23% Sales Jump" first appeared on MacRumors.com
Discuss this article in our forums
View the full article
- 0 comments
- 55 views
-
- 0 comments
- 49 views
-
In the current landscape of platform engineering and site reliability, the sheer volume of data generated by modern applications has surpassed human capacity for manual analysis. This is where the AIOps Foundation Certification becomes a critical asset for any professional looking to bridge the gap between traditional operations and automated intelligence. This guide is designed for software engineers, SREs, and IT managers who recognize that the future of infrastructure lies in algorithmic decision-making. By choosing a structured learning path through AIOps School, professionals can move beyond the noise of standard monitoring tools and start building resilient, self-healing systems. This comprehensive breakdown will help you understand how this certification fits into your career and whether it is the right move for your professional growth.
What is the AIOps Foundation Certification?
The AIOps Foundation Certification is a formal recognition of an engineer’s ability to apply artificial intelligence and machine learning principles to IT operations. It represents a shift from reactive troubleshooting to proactive, data-driven system management. Rather than focusing purely on theoretical models, this certification emphasizes real-world applications in production environments. It addresses how to handle high-cardinality data, logs, and metrics using automated patterns. The goal is to align modern engineering workflows with enterprise-grade practices, ensuring that teams can maintain uptime even as their infrastructure scales to thousands of microservices.
Who Should Pursue AIOps Foundation Certification?
This certification is ideal for a wide range of technical professionals who are responsible for maintaining system health and performance. Site Reliability Engineers (SREs) and DevOps professionals will find it particularly useful as it provides the tools to automate repetitive tasks and reduce “alert fatigue.” Cloud architects and platform engineers can use these skills to build more intelligent infrastructure as code. Even for those in security and data engineering roles, understanding the operational side of AI is becoming a necessity. In markets like India and globally, there is a massive push for engineers who can manage complex distributed systems without needing to hire a massive army of manual operators.
Why AIOps Foundation Certification is Valuable in the Current Era
The demand for AIOps skills is driven by the fact that enterprise adoption of cloud-native technologies is accelerating. As companies move to multi-cloud and hybrid environments, the complexity grows exponentially. This certification ensures that a professional stays relevant regardless of which specific monitoring tool a company uses, because it teaches the underlying logic of data correlation and anomaly detection. It is a high-return investment in your career because it moves you away from “firefighting” and into a strategic role where you are designing intelligent systems. This longevity is what distinguishes a senior engineer from a junior one in the current job market.
AIOps Foundation Certification Overview
The program is delivered via the official AIOps Foundation Certification portal and is hosted on AIOps School. The certification approach is grounded in practical assessment, ensuring that candidates don’t just memorize definitions but understand how to apply concepts to live systems. It is owned and structured by industry leaders who have seen the evolution of operations from physical servers to serverless functions. The assessment typically involves demonstrating competency in data ingestion, pattern recognition, and automated remediation. This structure ensures that when an employer sees this certification on a resume, they know the candidate is ready to contribute to a production environment immediately.
AIOps Foundation Certification Tracks & Levels
The certification is structured to support long-term career progression, starting from the foundation and moving toward mastery. The foundation level focuses on core concepts, terminology, and the fundamental architecture of AIOps platforms. Once an engineer masters the basics, they can move into professional levels that involve deeper integration with DevOps and SRE practices. Advanced levels are available for those who want to specialize in the algorithmic side of operations or lead large-scale digital transformation projects. This tiered approach allows professionals to pace their learning and gain recognition at every stage of their technical journey.
Complete AIOps Foundation Certification Table
TrackLevelWho it’s forPrerequisitesSkills CoveredRecommended OrderOperations IntelligenceFoundationJunior Engineers & AdminsBasic Linux/Cloud knowledgeLog Analysis, Monitoring, Metrics1stAlgorithmic SREProfessionalSREs & DevOps Engineers2-3 years of Ops experienceAnomaly Detection, Event Correlation2ndAutomation LeadershipAdvancedArchitects & Managers5+ years of experienceStrategic AI implementation, ROI3rd Detailed Guide for Each AIOps Foundation Certification
AIOps Foundation Certification – Foundation Level
What it is
This certification validates a professional’s understanding of the basic pillars of AIOps and how machine learning can be applied to standard IT operations. It serves as the entry point for anyone looking to modernize their operational skill set.
Who should take it
It is suitable for junior DevOps engineers, system administrators, and technical managers who need to understand the language and logic of automated operations. No deep data science background is required to start.
Skills you’ll gain
Understanding the difference between traditional monitoring and AIOps. Mastery of data ingestion and telemetry gathering. Basic knowledge of event noise reduction and correlation techniques. Familiarity with the AIOps lifecycle in a production environment. Real-world projects you should be able to do
Setting up a basic centralized logging system that uses pattern recognition. Configuring automated alerts based on dynamic thresholds instead of static limits. Building a dashboard that correlates application performance with infrastructure health. Preparation plan
7-14 days: Review core terminology and the basic architecture of AIOps platforms provided in the study materials. 30 days: Engage with hands-on labs focused on log aggregation and basic metric visualization. 60 days: Complete a full practice project that involves reducing alert noise in a simulated environment. Common mistakes
Focusing too much on the math of machine learning rather than the operational outcomes. Neglecting the importance of high-quality data ingestion before applying AI models. Over-complicating the initial automation steps before understanding the manual process. Best next certification after this
Same-track option: AIOps Professional Certification. Cross-track option: SRE Professional Certification. Leadership option: Engineering Management for Automated Systems. Choose Your Learning Path
DevOps Path
The DevOps path focuses on integrating AI into the CI/CD pipeline to improve software delivery velocity and reliability. Engineers on this path learn how to use automated testing and deployment data to predict potential failures before they reach production. The goal is to create a seamless loop where operational insights inform development teams in real-time. This path is perfect for those who want to be at the intersection of code and infrastructure.
DevSecOps Path
In this track, the focus is on applying AIOps to security operations, often referred to as AI-driven security. Professionals learn how to detect anomalous behavior that might indicate a security breach before traditional signature-based tools catch it. It involves automating the response to common threats and ensuring that security checks are built into the automated delivery process. This is a critical path for engineers in highly regulated industries.
SRE Path
The Site Reliability Engineering path is arguably the most natural fit for AIOps. Here, the focus is on maintaining Service Level Objectives (SLOs) through automated error budget tracking and incident response. Engineers learn how to build “self-healing” systems that can automatically scale or restart services based on predictive analytics. This path prioritizes system availability and the reduction of manual toil through intelligent automation.
AIOps Path
This is the specialized track for those who want to become domain experts in algorithmic operations. It focuses deeply on the selection of models, the tuning of anomaly detection algorithms, and the integration of diverse data sources. Professionals on this path often act as internal consultants for other engineering teams, helping them implement AI-driven strategies. It is a deep dive into the technical mechanics of the AIOps platform itself.
MLOps Path
The MLOps path is for those who are responsible for the lifecycle of machine learning models themselves. It involves taking AIOps principles and applying them to the deployment, monitoring, and retraining of ML models in production. This path bridges the gap between data scientists and operations engineers, ensuring that AI models remain accurate and performant over time. It is essential for organizations that rely on AI as a core product feature.
DataOps Path
DataOps focuses on the automated, policy-based management of data flows within an organization. Engineers learn how to use AIOps to monitor data pipelines, detect data drift, and ensure high data quality for downstream analytics. This path is vital for maintaining the “fuel” that powers AIOps and MLOps initiatives. It ensures that the data being used for operational decisions is reliable, timely, and secure.
FinOps Path
The FinOps path uses AIOps to manage and optimize cloud spending in real-time. Instead of waiting for a monthly bill, engineers use automated tools to detect cost anomalies and predict future spending patterns. It involves automating the rightsizing of resources and identifying wasted cloud spend across complex environments. This path is highly valued by management teams looking to maintain fiscal discipline in the cloud.
Role → Recommended AIOps Foundation Certification Certifications
RoleRecommended CertificationsDevOps EngineerAIOps Foundation, DevOps ProfessionalSREAIOps Foundation, SRE PractitionerPlatform EngineerAIOps Foundation, Cloud ArchitectureCloud EngineerAIOps Foundation, Multi-Cloud OpsSecurity EngineerAIOps Foundation, DevSecOps SpecialistData EngineerAIOps Foundation, DataOps SpecialistFinOps PractitionerAIOps Foundation, Cloud Cost ManagementEngineering ManagerAIOps Foundation, Digital Transformation Next Certifications to Take After AIOps Foundation Certification
Same Track Progression
Once the foundation is established, the next logical step is to dive into professional-level certifications that focus on implementation and architecture. This involves moving from understanding concepts to designing the actual systems that ingest and process operational data. Deep specialization in specific AIOps platforms or algorithmic tuning is the hallmark of this stage. It ensures you are seen as a subject matter expert who can own the entire operational strategy of an organization.
Cross-Track Expansion
Broadening your skills into related areas like SRE or DevSecOps can make you a more versatile engineer. For example, combining AIOps with SRE allows you to apply intelligent automation specifically to reliability goals. Alternatively, moving into the security space with AIOps knowledge makes you a formidable asset in modern threat detection. Skill broadening is about understanding how AI-driven operations interact with other parts of the technical ecosystem to create a more resilient whole.
Leadership & Management Track
For those looking to move into management, the focus shifts from “how to build” to “how to lead.” This involves understanding the ROI of AIOps, managing the cultural shift required for automation, and leading teams through digital transformations. Leadership tracks help you communicate the value of these technical investments to stakeholders and executives. It is the path for those who want to shape the technical direction of a company rather than working on individual configurations.
Training & Certification Support Providers for AIOps Foundation Certification
DevOpsSchool
DevOpsSchool is a leading provider of technical training that focuses on the end-to-end software delivery lifecycle. They offer extensive resources for those looking to master DevOps and AIOps through hands-on labs and expert-led sessions. Their curriculum is designed to be practical, ensuring that students can apply what they learn to real-world production environments immediately. With a focus on industry standards and current toolsets, DevOpsSchool helps engineers stay ahead in a rapidly changing market. They have a strong reputation for producing high-quality content that caters to both beginners and seasoned professionals. Their approach is centered on career growth and technical excellence in the field of modern operations.
Cotocus
Cotocus provides specialized consulting and training services aimed at helping organizations and individuals adopt modern engineering practices. They focus heavily on cloud-native technologies and the automation of infrastructure. Their training programs are known for being intensive and deeply technical, providing learners with a thorough understanding of the underlying principles of AIOps and SRE. Cotocus emphasizes the importance of a culture of automation and provides the tools necessary to implement it effectively. By focusing on real-world scenarios and production-grade challenges, they prepare their students for the complexities of modern enterprise environments. Their expertise is highly sought after by companies undergoing digital transformation.
Scmgalaxy
Scmgalaxy is a massive community-driven platform that offers a wealth of information on software configuration management, DevOps, and AIOps. It serves as a hub for engineers to share knowledge, tutorials, and best practices. The platform provides structured learning paths and certifications that are well-respected in the industry. Scmgalaxy is particularly known for its extensive library of technical articles and guides that cover a wide range of tools and methodologies. They focus on the practical side of engineering, providing clear instructions on how to solve common operational problems. For many engineers, Scmgalaxy is the go-to resource for staying updated on the latest trends in the automation space.
BestDevOps
BestDevOps is dedicated to providing high-quality training and certification programs that help professionals master the art of automated operations. They offer a variety of courses that cover everything from basic DevOps principles to advanced AIOps strategies. Their training is delivered by experienced practitioners who bring years of industry knowledge to the classroom. BestDevOps focuses on providing a comprehensive learning experience that includes both theory and practical application. They are committed to helping their students achieve their career goals through rigorous training and industry-recognized certifications. Their programs are designed to be accessible yet challenging, ensuring that graduates are well-prepared for the demands of the job market.
devsecopsschool.com
DevSecOpsSchool is a specialized training provider that focuses on the integration of security into the DevOps and AIOps lifecycle. They recognize that security cannot be an afterthought and must be built into the automation process from the start. Their courses cover a range of topics, including automated security testing, threat modeling, and AI-driven security operations. DevSecOpsSchool provides the skills necessary to build secure and resilient systems in a cloud-native world. Their training is essential for engineers who want to specialize in the intersection of security and operations. By focusing on “security as code,” they help organizations protect their assets without slowing down the delivery process.
sreschool.com
SRESchool is dedicated to the discipline of Site Reliability Engineering, providing deep dives into how to maintain system availability and performance at scale. Their curriculum is heavily influenced by the practices developed at major technology companies and focuses on the reduction of manual toil through automation. They offer specialized training in AIOps as a core component of modern SRE work. SRESchool emphasizes the use of service level objectives and error budgets to drive operational decisions. Their courses are designed for engineers who want to master the art of building and maintaining reliable systems in complex, distributed environments. They provide a clear path from traditional administration to advanced SRE roles.
aiopsschool.com
AIOpsSchool is the primary destination for professionals looking to specialize in artificial intelligence for IT operations. They offer a focused curriculum that covers the entire spectrum of AIOps, from data collection to automated remediation. Their training is designed to be highly practical, with a strong emphasis on real-world use cases and hands-on experience. AIOpsSchool helps engineers understand how to leverage machine learning to solve complex operational challenges. They are a key player in defining the standards and best practices for the AIOps industry. Their certifications are a mark of expertise for anyone looking to lead in the field of automated intelligence and proactive system management.
dataopsschool.com
DataOpsSchool focuses on the critical intersection of data engineering and operations. They provide training on how to build and manage automated data pipelines that are reliable, scalable, and secure. Their curriculum includes the use of AIOps to monitor and optimize data flows, ensuring high data quality for business intelligence and machine learning. DataOpsSchool emphasizes the importance of collaboration between data scientists, engineers, and operations teams. Their courses are essential for anyone responsible for the data infrastructure that powers modern enterprises. By focusing on “data as a product,” they help organizations treat their data with the same rigors as their software code.
finopsschool.com
FinOpsSchool is the leading provider of training for the emerging field of cloud financial management. They teach engineers and finance professionals how to work together to optimize cloud spending using AIOps and automated tools. Their curriculum covers the principles of visibility, optimization, and operation in the cloud. FinOpsSchool provides the skills needed to track cloud costs in real-time and make data-driven decisions about resource allocation. Their training is vital for organizations looking to maximize the value of their cloud investments while maintaining control over their budget. By focusing on cultural change and technical automation, they help companies build sustainable cloud financial practices.
Frequently Asked Questions (General)
How difficult is the AIOps Foundation Certification?
The foundation level is designed to be accessible to anyone with a basic understanding of IT operations. It focuses on concepts rather than complex mathematics, making it manageable for most engineers. How much time does it take to prepare for the exam?
Most professionals find that 30 to 60 days of consistent study is sufficient. This includes reviewing theoretical materials and engaging in hands-on practice. Are there any prerequisites for the foundation level?
There are no formal prerequisites, but a basic understanding of Linux, cloud computing, and monitoring concepts is highly recommended to get the most out of the course. What is the ROI of getting an AIOps certification?
The return on investment is high, as it positions you for senior roles in SRE and DevOps. It can lead to significant salary increases and better job security in a tech-driven market. Is this certification recognized globally?
Yes, AIOps certifications from recognized providers like AIOps School are valued by major enterprises and tech companies across the globe, including in India. Do I need to be a data scientist to learn AIOps?
No, you do not need a data science background. AIOps is about using AI tools to improve operations, not necessarily building the underlying AI models from scratch. How does AIOps differ from standard DevOps?
DevOps is a cultural and procedural shift for faster delivery, while AIOps is a technical shift that uses AI to handle the operational complexity that DevOps can create. Should I take SRE or AIOps certification first?
If you are already in an operations role, starting with AIOps Foundation provides a modern lens through which to view SRE practices, though both are complementary. How often do I need to renew the certification?
Most certifications are valid for two to three years. Given the speed of change in the field, staying updated with newer levels is encouraged. Does this certification help in moving to a management role?
Yes, it demonstrates that you understand the strategic value of automation, which is a key requirement for modern engineering leadership. Can I prepare for this certification while working full-time?
Yes, the learning paths are designed to be self-paced, allowing working professionals to study during their off-hours. Is there a practical component to the exam?
Most modern certifications include scenario-based questions or hands-on labs to ensure you can apply the knowledge in a production-like setting. FAQs on AIOps Foundation Certification
What specific tools are covered in the AIOps Foundation Certification?
While it focuses on principles, you will learn the logic behind tools used for log aggregation, metric collection, and event correlation found in the modern ecosystem. How does this certification address alert fatigue?
It teaches you how to use machine learning algorithms to filter out noise and group related events into single actionable incidents, reducing the burden on engineers. Does the course cover the use of AI in root cause analysis?
Yes, a core part of the foundation is understanding how AI can trace dependencies across a distributed system to identify the primary cause of a failure. Will I learn about predictive scaling in this program?
Predictive scaling is covered as a key outcome of AIOps, teaching you how to anticipate traffic spikes and adjust resources before performance is affected. How is data quality addressed in the AIOps lifecycle?
The certification emphasizes that AIOps is only as good as the data it receives, covering the basics of data normalization and deduplication. What is the role of human-in-the-loop in AIOps?
The foundation level teaches that AI is meant to augment, not replace, human decision-making, particularly in complex or high-risk remediation scenarios. Does the certification cover ethical considerations of AI in ops?
Yes, it touches upon the importance of transparency and explainability in automated decisions to ensure that engineers can trust the AI’s output. Is cloud-native architecture a major focus of the certification?
Absolutely, as AIOps is most valuable in the complex, dynamic environments typical of Kubernetes and microservices architectures. Final Thoughts: Is AIOps Foundation Certification Worth It?
From a mentoring perspective, the answer is a definitive yes. We have reached a point in the industry where manual operations simply cannot scale with the speed of business. If you continue to rely on static thresholds and manual log diving, you will eventually become a bottleneck for your organization. The AIOps Foundation Certification isn’t just a badge on your resume; it is a fundamental shift in how you think about system reliability and your own role as an engineer. It moves you from being a “operator” to being an “architect of intelligence.” If you want to remain relevant and move into high-impact roles, mastering the intersection of AI and operations is no longer optional—it is a requirement. Start with the foundation, get your hands dirty with the data, and build the future of automated engineering.
View the full article
- 0 comments
- 51 views
-
Docker is a platform for building, packaging, shipping, and running applications inside containers. Docker uses a client-server model: the docker CLI is the client, dockerd is the daemon, and the daemon manages images, containers, networks, and volumes. Under the hood, Docker Engine uses containerd for container lifecycle management, and containerd typically uses runc to actually create and run containers. (Docker Documentation)
A clean mental model is this:
User → Docker Client (docker) → Docker Daemon (dockerd) → containerd → runc → Linux Kernel
That model is much closer to how Docker works today than “Docker Server” as a generic term. Docker Desktop on macOS and Windows still gives you Docker commands, but Linux containers run inside a Linux VM behind the scenes. (Docker Documentation)
2) Docker on Linux vs Mac
On a Linux server, Docker Engine normally stores its data under /var/lib/docker. That includes images, containers, volumes, networks, and related metadata. (Docker Documentation)
On macOS, Docker Desktop runs Linux containers inside a Linux VM, and the images/containers are stored in Docker Desktop’s disk image rather than directly in /var/lib/docker on the Mac host. That is why users often cannot find the same storage paths on Mac that they see on Linux. (Docker Documentation)
There is another important update for Linux users: on fresh Docker Engine 29+ installations, the containerd image store is the default backend. If a host was upgraded from an older version, it may still use the legacy storage path behavior until the containerd image store is enabled. This explains why image files and overlay directories do not always appear exactly where older tutorials expect them. (Docker Documentation)
3) Filesystem concepts: what belongs in an image and what does not
Your notes mention boot filesystem and kernel, which is a useful teaching angle, but one detail must be corrected:
A Docker image does not contain the Linux kernel. Containers share the host kernel. The image provides the userspace filesystem and application content. (Docker Documentation)
A simpler way to explain filesystem layers is this:
Kernel = provided by the host OS Image = read-only layers containing userspace packages, libraries, configs, and app files Container = image + one writable layer on top So instead of saying “OS inside container = kernel + root fs + user fs + app fs,” the modern and accurate explanation is:
Container runtime view = host kernel + image layers + writable container layer. (Docker Documentation)
4) What is a Docker image?
A Docker image is a packaged, read-only template used to create containers. Images are made of layers, and each layer represents filesystem changes such as adding packages, copying files, or changing configuration. This layered design improves reuse, caching, and storage efficiency. (Docker Documentation)
Examples of base images include:
ubuntu debian alpine fedora Examples of application images built on top of base images include:
httpd mysql nginx jenkins/jenkins In practice, an image is best understood as “a filesystem snapshot plus metadata and startup instructions.” (Docker Documentation)
5) What is a container?
A container is a running instance of an image. When Docker starts a container, it takes the read-only image layers and adds a writable container layer on top. All runtime changes made inside that container are written into that writable layer unless you use volumes or bind mounts. (Docker Documentation)
That writable layer is ephemeral. If the container is deleted, the data in that writable layer is lost unless it was stored in a volume or external mount. This is why databases and Jenkins data should use volumes instead of depending on the container filesystem. (Docker Documentation)
6) Installing Docker on Ubuntu
Your command history is very close to the right process. The current official recommendation is to install Docker Engine from Docker’s APT repository, not from random distro packages, and the standard package set now includes docker-buildx-plugin and docker-compose-plugin. (Docker Documentation)
Use this updated install flow on Ubuntu:
sudo apt-get update sudo apt-get install -y ca-certificates curl sudo install -m 0755 -d /etc/apt/keyrings sudo curl -fsSL https://download.docker.com/linux/ubuntu/gpg -o /etc/apt/keyrings/docker.asc sudo chmod a+r /etc/apt/keyrings/docker.asc echo \ "deb [arch=$(dpkg --print-architecture) signed-by=/etc/apt/keyrings/docker.asc] \ https://download.docker.com/linux/ubuntu \ $(. /etc/os-release && echo "${UBUNTU_CODENAME:-$VERSION_CODENAME}") stable" | \ sudo tee /etc/apt/sources.list.d/docker.list > /dev/null sudo apt-get update sudo apt-get install -y docker-ce docker-ce-cli containerd.io docker-buildx-plugin docker-compose-plugin sudo systemctl enable --now docker docker version docker info If you want to run Docker without sudo, Docker’s post-installation guidance recommends adding your user to the docker group. (Docker Documentation)
7) First image and first container
To pull an image:
docker pull ubuntu docker pull httpd docker images To run a container from an image:
docker run -d --name web1 httpd docker ps docker inspect web1 This is the key concept:
Image exists first Container is created from the image One image can create many containers So the answer to “From image, how do we get containers?” is: Docker starts a container by using the image as the read-only template and adding a writable layer for that container instance. (Docker Documentation)
8) How to create an image
There are two common ways to create an image.
Method 1: Create from an existing container using docker commit
This is good for demos and quick experiments.
Example flow:
docker run -itd --name motox ubuntu docker exec -it motox /bin/bash # inside container: apt update && apt install -y git apache2 exit docker commit -a "Rajesh" -m "Ubuntu with git and apache" motox motoxv2 docker images docker history motoxv2 docker commit captures the container’s filesystem changes into a new image. However, it is not the preferred long-term way to build production images, because it is less reproducible and harder to version-control. Also, commits do not include mounted volume data. (Docker Documentation)
Method 2: Create from a Dockerfile
This is the recommended and professional approach because it is repeatable, reviewable, and version-controlled. Docker’s docs define a Dockerfile as a text file containing instructions used to build an image automatically. (Docker Documentation)
9) Updated Dockerfile tutorial
Your original Dockerfile idea is good, but it should be modernized.
Older teaching example
FROM ubuntu MAINTAINER Rajesh kumar RUN apt update RUN apt install git -y RUN apt install apache2 -y COPY index.html /tmp ENV JAVA_HOME /tmp/java What should be updated
The MAINTAINER instruction is deprecated. Docker recommends labels instead. Also, combining package installation steps reduces layers and makes builds cleaner. (Docker Documentation)
Better updated example
FROM ubuntu:24.04 LABEL org.opencontainers.image.authors="Rajesh Kumar" RUN apt-get update && \ apt-get install -y --no-install-recommends apache2 git && \ rm -rf /var/lib/apt/lists/* COPY index.html /var/www/html/index.html ENV JAVA_HOME=/opt/java EXPOSE 80 CMD ["apache2ctl", "-D", "FOREGROUND"] Build it like this:
docker build -t motoshare:1.0 . docker images docker history motoshare:1.0 This example is better because it is reproducible, uses a non-deprecated metadata pattern, and defines how the container should start. (Docker Documentation)
10) What is CMD and what is ENTRYPOINT?
This is one of the most important interview and training topics.
CMD
CMD provides the default command or default arguments for the container. If the user supplies a command in docker run, that can replace CMD. (Docker Documentation)
ENTRYPOINT
ENTRYPOINT defines the main executable of the image. Docker’s best-practices guidance says ENTRYPOINT is best used to set the image’s main command, and CMD can then provide default flags or arguments. (Docker Documentation)
Best teaching rule
Use:
ENTRYPOINT for the fixed main executable CMD for default parameters Example
FROM alpine:3.21 ENTRYPOINT ["ping"] CMD ["localhost"] Behavior:
docker run myping # runs: ping localhost docker run myping google.com # runs: ping google.com Also remember: if you define multiple CMD or ENTRYPOINT instructions in one stage, only the last one is used. (Docker Documentation)
11) How to share an image
There are two main ways to share Docker images.
Option 1: Push to a registry
This is the normal team or production method.
docker login docker tag motoshare:1.0 yourdockerhubuser/motoshare:1.0 docker push yourdockerhubuser/motoshare:1.0 Docker’s build-and-publish documentation recommends building, tagging, and publishing images to Docker Hub or another registry. Tags help identify versions. (Docker Documentation)
Option 2: Save to a tar file
This is useful for offline transfer.
docker save -o motoshare.tar motoshare:1.0 docker load -i motoshare.tar docker image save exports image data into a tar archive, and docker image load restores images and tags from that archive. (Docker Documentation)
12) Where image files are stored
This part connects directly to your command history.
On Linux, Docker daemon data is usually under /var/lib/docker. But depending on your Docker version and storage backend, you may not see the exact old-style overlay paths you expect. With newer setups, containerd’s image store may be in use, and snapshot data may be managed differently. (Docker Documentation)
So if someone asks:
“Where is the image path?”
The modern answer is:
On Linux, start with /var/lib/docker Check docker info to see the storage driver and data root On newer systems, image and snapshot handling may involve containerd storage backends On Mac, images are usually inside Docker Desktop’s Linux VM disk image, not plain host directories (Docker Documentation) 13) Jenkins example in Docker
Since your notes mention Jenkins, the best practical teaching advice is: for Jenkins, prefer the official Jenkins Docker image instead of manually assembling Jenkins from raw Ubuntu unless your goal is specifically to teach image construction. Jenkins’ official docs include Docker-based installation guidance using the jenkins/jenkins image. (Jenkins)
A simple example is:
docker run -d \ --name jenkins \ -p 8080:8080 \ -p 50000:50000 \ -v jenkins_home:/var/jenkins_home \ jenkins/jenkins:lts-jdk17 This is a good example of why volumes matter: Jenkins data should live in a persistent volume, not only inside the container writable layer. (Jenkins)
14) Best-practice summary
Use this as the “final takeaway” section in your tutorial:
Docker images are layered, read-only templates. (Docker Documentation) Containers are running instances of images with a writable layer. (Docker Documentation) Containers do not bring their own kernel; they use the host kernel. (Docker Documentation) On Mac and Windows, Linux containers usually run inside a VM provided by Docker Desktop. (Docker Documentation) docker commit is okay for learning and debugging, but Dockerfiles are the preferred way to create production images. (Docker Documentation) Use ENTRYPOINT for the main executable and CMD for default arguments. (Docker Documentation) Share images through Docker Hub/private registries or with docker save and docker load. (Docker Documentation) Use volumes for persistent data such as Jenkins home, MySQL data, and application uploads. (Docker Documentation) 15) Suggested assignments for students
Assignment 1
Pull the ubuntu image, inspect it, and explain why it is an image and not a running container.
Assignment 2
Run two containers from the same httpd image and prove that one image can create multiple containers.
Assignment 3
Create a custom image by:
starting an Ubuntu container installing git and apache2 committing it as motoxv2 Then compare docker history ubuntu and docker history motoxv2.
Assignment 4
Write a Dockerfile that:
starts from Ubuntu installs apache2 copies index.html starts Apache in the foreground Assignment 5
Create one image using CMD only, and another using ENTRYPOINT + CMD, then observe how docker run arguments behave.
Assignment 6
Share your image in two ways:
push to Docker Hub export with docker save and restore with docker load 16) One-line short definition set for training slides
You can use these directly in slides:
Docker: A container platform for building, shipping, and running applications.
Image: A read-only layered template used to create containers.
Container: A running instance of an image with a writable layer.
Dockerfile: A text file containing instructions to build an image.
dockerd: The Docker daemon that manages Docker objects.
containerd: Runtime component used by Docker for container lifecycle management.
CMD: Default command or arguments for a container.
ENTRYPOINT: Main executable of the container image.
Volume: Persistent storage used by containers.
View the full article
- 0 comments
- 51 views
-
- 0 comments
- 41 views
-
- 0 comments
- 37 views
-
The attack, disclosed by Trivy maintainers today, results from an earlier compromise announced late last month that also leveraged insecure GitHub Actions and impacted multiple projects. Security firms Socket and Wiz traced the root cause to an incomplete credential rotation after the first breach, allowing the attackers to return to Trivy’s environment and introduce malicious commits.
“If you suspect you were running a compromised version, treat all pipeline secrets as compromised and rotate immediately,” Trivy maintainer Itay Shakury wrote on GitHub.
Multiple components backdoored
Trivy, developed by Aqua Security, is one of the most widely used open-source vulnerability scanners, with over 32,000 GitHub stars and more than 100 million Docker Hub downloads. Developers use it to detect vulnerabilities and exposed secrets in their CI/CD pipelines and container images.
The attackers compromised three components of the Trivy project: trivy-action, the official GitHub Action for running Trivy scans in CI/CD workflows; setup-trivy, a helper action for installing the scanner; and the Trivy binary itself. Backdoored artifacts were published to GitHub releases, Docker Hub, the GitHub Container Registry, and the Amazon Elastic Container Registry.
According to Socket, 75 of 76 version tags in trivy-action were overwritten with malicious code, along with seven tags in setup-trivy. The only unaffected trivy-action tag was version 0.35.0. The compromised tags include widely used versions such as 0.34.2, 0.33.0, and 0.18.0.
“When the malicious binary is executed it starts both the legitimate trivy service and the malicious code in parallel,” Wiz researchers wrote in their analysis of the attack.
Attackers look for development secrets
On GitHub Actions runners, the credential stealer reads the process memory to extract secrets and searches the filesystem for SSH keys, cloud provider credentials, Kubernetes tokens, Docker registry configurations, and cryptocurrency wallets.
The stolen data is encrypted and sent to a typosquatted domain that mimics Aqua Security’s legitimate site. If this fails, the malware falls back to creating a public repository called “tpcp-docs” on the victim’s own GitHub account and uploading the encrypted data there.
According to Wiz, the attack also installs a persistent Python dropper on developer machines that connects to an attacker-controlled server every five minutes in search for additional payloads to execute.
Stealthy tag manipulation technique bypasses detection
Instead of creating new releases, which would trigger notifications, the attackers force-pushed existing version tags to point to new malicious commits. Git tags are pointers that reference a specific commit by its fingerprint. By overwriting where those pointers lead, any workflow referencing the tag begins pulling the attacker’s code.
To further avoid detection, the attackers cloned the original commit metadata such as author names, email addresses, timestamps, and messages, making the malicious commits appear identical to the legitimate ones they replaced. The forgery left subtle traces such as missing cryptographic signatures and inconsistent timestamp relationships.
The same tag manipulation technique was used in the compromise of the tj-actions/changed-files GitHub Action a year ago which affected 23,000 repositories.
A lesson for victims
The initial Trivy compromise happened in late February when attackers exploited a misconfigured GitHub Actions workflow that had been present in the repository since October 2025. The workflow, triggered by external pull requests, ran with access to repository secrets, a dangerous pattern in GitHub Actions that has been documented before.
The attackers stole a personal access token (PAT) with write permissions and used it to delete releases, rename the repository, and publish a malicious Visual Studio Code extension. The Trivy maintainers rotated their credentials, but it seems the process missed some of them.
This failure, especially by a company that is specialized in CI/CD security, should serve as a warning to organizations affected by this new attack, especially because the malware is designed to steal the same type of credentials that could enable supply chain compromises in their own pipelines.
A recurring pattern
The Trivy compromise is the latest in a growing pattern of attacks targeting GitHub Actions and developers in general. The tj-actions/changed-files compromise last year used the same tag manipulation approach and was later traced to an upstream compromise of the reviewdog/action-setup action. Other incidents in 2025 included the GhostAction campaign, which stole over 3,000 secrets from 327 GitHub users, and an attack on the nx npm package that exploited a vulnerable pull_request_target workflow.
GitHub changed the default behavior of pull_request_target workflows in December 2025 to reduce the risk of exploitation, but the vulnerable workflow in the Trivy repository predated that change.
Organizations using Trivy should pin GitHub Actions to the full commit SHA hashes rather than version tags to prevent tag manipulation attacks. The safe versions are Trivy v0.69.3, trivy-action tag 0.35.0, and setup-trivy 0.2.6. Security teams should also search their GitHub accounts for repositories named tpcp-docs, which would indicate successful fallback exfiltration, and block the command-and-control domain and its IP address at the network perimeter.
View the full article
- 0 comments
- 49 views
-
Speaking at an event hosted by the Royal United Services Institute (RUSI) that reviewed the CMC’s activities in its first year of operation, Ciaran Martin, chair of the CMC’s cyber monitoring technical committee, discussed the loan guarantee announced last year following an attack that has been described as one of the UK’s worst cyber incidents.
“I must stress that I’m speaking personally now. I think the loan guarantee is an unfortunate precedent because the government intervened in a case-specific way, in response to a set of events, without the clear criteria of what form such intervention could take,” said Martin during a panel discussion with CMC executives and Tracey Paul, chief strategy and communications officer at Pool Re, a UK terrorism reinsurer.
Martin, who is also a RUSI Distinguished Fellow, said, “there clearly are a set of plausible, realistic, bad scenarios where most reasonable citizens would expect some form of government activity. But it would be better to have a framework, whether that’s compulsory insurance, incentivizing insurance with tax breaks, whether it’s a set of principles as to what would trigger state intervention. And in what form? Loan guarantees? Something else?”
To complicate things, Paul noted that today there is a cyber insurance protection gap. “I don’t know how we are going to bridge this gap between the potential economics loss and the insured loss without some partnership between government and the insurance industry and other parts of the cyber ecosystem,” she said. The industry has a prefunded model, and a contract with the government under which, if the insurer runs out of money, the government will step in and loan the money to pay the losses.
“But that is one way of doing it and I think they would like the flexibility to do it in another way,” she observed. “But what I do think is you cannot have a transfer of risk between the public sector and the private sector unless you have some kind of structure around it, and at some point the government are going to have to come to the table on what that looks like in order to make that happen.”
Event impact can ‘ripple across an entire economy’
Analysts share Martin’s concerns.
Erik Avakian, technical counselor at Info-Tech Research Group, said on Friday that he “has been predicting for years now that attackers would start to move on from pure small disruption types of attacks (think DDoS) to catastrophic disruption and destruction of a company’s operations.”
The incident at JLR, he said, “really speaks to impacting the overall resilience of a company’s business operations. And once that happens, the impacts can go well beyond just a quarterly earnings miss.”
Avakian added, “what we’ve seen with the Jaguar Land Rover attack is certainly exemplary of that, and has shown that a cyber incident can shut down real-world operations in a way where the impacts can ripple across an entire economy, not just IT systems; where a cyberattack can directly impact a nation’s GDP, employment, and wreak havoc on national exports.”
He agreed with Martin’s sentiments, explaining, “in my opinion, the government stepping in like this with a loan guarantee is creating and sending a signal that some companies could now be considered too important to fail due to cyber risk. That can create a dangerous precedent because large, critical organizations could become primary targets for cyber criminals if they know that a successful attack could cause such massive consequences.”
It could also lead to new risks, said Avakian, “where companies may potentially underinvest in their security if they believe there’s an implicit safety net that will be there for them. Cyber resilience is more important than ever and should be central to how organizations think about security and risk management; not just how to prevent a breach, but how to keep business operations running in the face of cyberattacks.”
David Shipley, CEO of Beauceron Security, added, “a monster has been created by using insurance to cheat our way out of hanging the risk in near-term more expensive, but long-term more effective ways.”
Why, he asked, should organizations “invest all the work in multifactor authentication when you can just buy insurance? The problem now is the cybercrime monster that insurance fed is now Godzilla sized, and we can’t insure all of the damage. Great job.”
Government bailouts of industry, said Shipley, “is just the next, bad leap in the same flawed decision. If insurance was the crack cocaine of cyber risk mismanagement, government bailouts are the corporate fentanyl. Maybe the smart answer is, we have to account for the real cost of proper security in our goods and services, and invest in ways that don’t put money in the hands of criminals.”
This article originally appeared on CIO.com.
View the full article
- 0 comments
- 50 views
-
Speaking at an event hosted by the Royal United Services Institute (RUSI) that reviewed the CMC’s activities in its first year of operation, Ciaran Martin, chair of the CMC’s cyber monitoring technical committee, discussed the loan guarantee announced last year following an attack that has been described as one of the UK’s worst cyber incidents.
“I must stress that I’m speaking personally now. I think the loan guarantee is an unfortunate precedent because the government intervened in a case-specific way, in response to a set of events, without the clear criteria of what form such intervention could take,” said Martin during a panel discussion with CMC executives and Tracey Paul, chief strategy and communications officer at Pool Re, a UK terrorism reinsurer.
Martin, who is also a RUSI Distinguished Fellow, said, “there clearly are a set of plausible, realistic, bad scenarios where most reasonable citizens would expect some form of government activity. But it would be better to have a framework, whether that’s compulsory insurance, incentivizing insurance with tax breaks, whether it’s a set of principles as to what would trigger state intervention. And in what form? Loan guarantees? Something else?”
To complicate things, Paul noted that today there is a cyber insurance protection gap. “I don’t know how we are going to bridge this gap between the potential economics loss and the insured loss without some partnership between government and the insurance industry and other parts of the cyber ecosystem,” she said. The industry has a prefunded model, and a contract with the government under which, if the insurer runs out of money, the government will step in and loan the money to pay the losses.
“But that is one way of doing it and I think they would like the flexibility to do it in another way,” she observed. “But what I do think is you cannot have a transfer of risk between the public sector and the private sector unless you have some kind of structure around it, and at some point the government are going to have to come to the table on what that looks like in order to make that happen.”
Event impact can ‘ripple across an entire economy’
Analysts share Martin’s concerns.
Erik Avakian, technical counselor at Info-Tech Research Group, said on Friday that he “has been predicting for years now that attackers would start to move on from pure small disruption types of attacks (think DDoS) to catastrophic disruption and destruction of a company’s operations.”
The incident at JLR, he said, “really speaks to impacting the overall resilience of a company’s business operations. And once that happens, the impacts can go well beyond just a quarterly earnings miss.”
Avakian added, “what we’ve seen with the Jaguar Land Rover attack is certainly exemplary of that, and has shown that a cyber incident can shut down real-world operations in a way where the impacts can ripple across an entire economy, not just IT systems; where a cyberattack can directly impact a nation’s GDP, employment, and wreak havoc on national exports.”
He agreed with Martin’s sentiments, explaining, “in my opinion, the government stepping in like this with a loan guarantee is creating and sending a signal that some companies could now be considered too important to fail due to cyber risk. That can create a dangerous precedent because large, critical organizations could become primary targets for cyber criminals if they know that a successful attack could cause such massive consequences.”
It could also lead to new risks, said Avakian, “where companies may potentially underinvest in their security if they believe there’s an implicit safety net that will be there for them. Cyber resilience is more important than ever and should be central to how organizations think about security and risk management; not just how to prevent a breach, but how to keep business operations running in the face of cyberattacks.”
David Shipley, CEO of Beauceron Security, added, “a monster has been created by using insurance to cheat our way out of handling the risk in near-term more expensive, but long-term more effective ways.”
Why, he asked, should organizations “invest all the work in multifactor authentication when you can just buy insurance? The problem now is the cybercrime monster that insurance fed is now Godzilla sized, and we can’t insure all of the damage. Great job.”
Government bailouts of industry, said Shipley, “is just the next, bad leap in the same flawed decision. If insurance was the crack cocaine of cyber risk mismanagement, government bailouts are the corporate fentanyl. Maybe the smart answer is, we have to account for the real cost of proper security in our goods and services, and invest in ways that don’t put money in the hands of criminals.”
This article originally appeared on CIO.com.
View the full article
- 0 comments
- 40 views
-
Playlist Playground - Apple Music has a Playlist Playground option that lets you generate playlists from text-based descriptions. You can include moods, feelings, activities, or make up something entirely nonsensical and let the AI figure out what you mean.
Ambient Music widget - Apple added a widget for the built-in Ambient Music feature in iOS, so it's quicker to play background sounds. You can choose Sleep, Chill, Productivity, and Wellbeing playlists curated by Apple.
Emoji - There are eight new emoji characters including trombone, treasure chest, distorted face, hairy creature, fight cloud, orca, landslide, and ballet dancer.
Reduce Bright Effects - If you dislike Liquid Glass, there's a Reduce Bright Effects setting that cuts down on bright flashes when tapping buttons. Reduce Motion also limits Liquid Glass animations more than it did previously.
Keyboard Fix - iOS 26.4 fixes an iOS 26 keyboard bug that caused typos when typing quickly.
Purchase Sharing - Adults in Family Sharing groups no longer have to use the same payment method, and Apple now lets everyone add their own credit or debit card.
CarPlay AI apps - CarPlay users can use third-party chatbots with CarPlay starting in iOS 26.4. Companies like OpenAI, Anthropic, and Google will need to update their apps with CarPlay support, but the framework is in iOS 26.4.
Video Podcasts - The Podcasts app has native video episode support with HLS streaming, along with options to swap between audio and video and offline video downloads.
Average Bedtime - The Sleep feature in the Health app now records average bedtime for the past two weeks to give you a better idea of how your bedtime impacts sleep.
Stolen Device Protection - Stolen Device Protection is now on by default. It thwarts physical theft and access of your iPhone by requiring biometric authentication for things like viewing passwords and turning off Lost Mode on the iPhone. Some features like changing an Apple ID password have a one-hour security delay.
There are other new additions in iOS 26.4, like offline song recognition in Control Center, nearby concert suggestions and full-page album artwork in Apple Music, easier access to subtitle customization options in media apps, and Apple Creator Studio support for Freeform, with details available in our full iOS 26.4 notes article.
Release Date
The iOS 26.4 release candidate is available to developers and public beta testers, and it's likely the update will see an official launch on March 23 or March 24.Related Roundups: iOS 26, iPadOS 26Related Forum: iOS 26
This article, "iOS 26.4: Top 10 New Features Coming to Your iPhone" first appeared on MacRumors.com
Discuss this article in our forums
View the full article
- 0 comments
- 41 views
-
Aside from the Nike-focused design, these are the same Powerbeats Pro 2 that were introduced last year, with the signature Powerbeats wraparound earhooks for stability, Active Noise Cancelling with Transparency mode, built-in heart rate monitoring, and up to 45 hours of battery life when tapping into the charging case to recharge.
Powerbeats Pro 2 are essentially a fitness-focused alternative to the AirPods Pro 3.
Nike showed off the headphones in an ad starring NBA superstar LeBron James.
In the U.S., pricing is set at $249.99, in line with the regular Powerbeats Pro 2. Apple is currently showing a March 24 delivery date.Tags: Beats, Nike, Powerbeats Pro
This article, "Apple's Special-Edition Nike Powerbeats Pro 2 Now Available" first appeared on MacRumors.com
Discuss this article in our forums
View the full article
- 0 comments
- 48 views
-
This week also saw fresh rumors about iOS 27 coming later this year while an iOS 26.4 release looks to be right around the corner, and Apple kicked off a series of events around the world in celebration of the company's upcoming 50th anniversary, so read on below for all the details on these stories and more!
Top Stories
Apple Announces AirPods Max 2 With H2 Chip and More
In a surprise move, Apple this week unveiled AirPods Max 2, with key upgrades including the H2 chip, increased active noise cancellation, improved sound quality, and features such as Adaptive Audio, Conversation Awareness, Voice Isolation, and Live Translation.
The new AirPods Max have the same overall design as the previous generation, with most of the new features coming from the upgrade to the H2 chip, but they do bring a nice set of audio improvements and a new Camera Remote function for the Digital Crown. If you're a current AirPods Max owner and are considering an upgrade, be sure to check out our buyer's guide comparing the two generations.
AirPods Max 2 will be available to order starting Wednesday, March 25, with a launch to follow sometime in early April.
iOS 27 Will Reportedly Be Like Mac OS X Snow Leopard
In his Power On newsletter this week, Bloomberg's Mark Gurman reiterated that iOS 27 will be similar to 2009's Mac OS X Snow Leopard, in the sense that one of Apple's biggest priorities is bug fixes for improved performance and stability.
That isn't to say, however, that the update will be completely devoid of new features, as we have already heard about a number of them that are in the works beyond the significant revamp to Siri that has been repeatedly pushed back. Perhaps most notable for those who dislike the Liquid Glass redesign that arrived in iOS 26, Apple is said to be aiming to include a system-wide slider to allow users to adjust the Liquid Glass effect.
Here Are Apple's Release Notes for iOS 26.4
Apple this week seeded the release candidate versions of upcoming iOS 26.4 and related updates to developers and public beta testers, representing the final versions that will be provided to the public if no additional bugs are found.
Apple shared full release notes for iOS 26.4 as part of the seeding, revealing a few previously unknown changes including a fix for a keyboard accuracy bug and a change to App Store Family Sharing that will allow adults in a group to use different payment methods.
iOS 26.4 also includes support for AirPods Max 2, so the update will definitely be released by the time those arrive in early April, but the iOS 26.4 public release could come as soon as next week.
iPhone Fold: 5 Things We've Learned About Apple's Foldable
It's been a big couple of weeks for foldable iPhone rumors. In case you missed any of them, we've recapped five recent rumors that we previously covered. It sounds like display production for the device may be about to get underway as Apple looks toward a launch later this year, potentially as late as December.
In other foldable smartphone news, Samsung is discontinuing its Galaxy Z TriFold after just three months on the market. The innovative device unfolds twice to reveal a massive 10-inch inner display.
Apple Kicks Off 50th Anniversary With Surprise Alicia Keys Concert in New York
As part of its upcoming 50th anniversary celebration, Apple is hosting gatherings "around the world" throughout the month of March to celebrate human creativity and ingenuity.
The series kicked off with a surprise concert by Alicia Keysat Apple's retail store overlooking the main concourse at New York City's iconic Grand Central Terminal, with MacRumors in attendance for the event.
Tim Cook then traveled to China for a performance by Li Yuchun at the company's Taikoo Li store in Chengdu, with events in additional countries planned for the next few weeks.
Apple CEO Tim Cook Responds to Retirement Rumors
After a flurry rumors late last year going back and forth about whether his retirement as Apple CEO might be imminent, Tim Cook addressed the rumors in an interview with Good Morning America's Michael Strahan earlier this week.
While Cook referred to the idea as "a rumor," he did not explicitly confirm or deny that he will be stepping down as CEO any time soon, though he did say "I can't imagine life without Apple."
In a separate brief interview with Nikias Molina at the Alicia Keys concert, Cook reiterated that Apple still sees a long life ahead for the iPhone, even as rumors have suggested the company is looking to integrate its technology into other personal devices like augmented-reality glasses and an AI-powered pendant that will be able to gather information from the world around you. "There's so much left that we can do with the iPhone," said Cook. "I think it's going to continue to be the center of people's digital lives."
MacRumors Newsletter
Each week, we publish an email newsletter like this highlighting the top Apple stories, making it a great way to get a bite-sized recap of the week hitting all of the major topics we've covered and tying together related stories for a big-picture view.
So if you want to have top stories like the above recap delivered to your email inbox each week, subscribe to our newsletter!Tag: Top Stories
This article, "Top Stories: AirPods Max 2, iOS 27 and iPhone Fold Rumors, and More" first appeared on MacRumors.com
Discuss this article in our forums
View the full article
- 0 comments
- 40 views
-
The water industry has a security issue: Many utilities operate with ageing systems and minimal IT or cybersecurity personnel. But by coordinating responses to cyber-attacks, participants in a pilot program run by the Cyber Readiness Institute (CRI) and the Center on Cyber and Technology Innovation (CCTI) improved security.
One of the key findings of the two-year pilot involving 200 small and medium-sized utilities was that companies need to combine cybersecurity training with adequate support structures.
There have already been some reported attacks. In October 2024, American Water was hit by a cyber-attack that meant that the company could no longer bill customers and in 2024 a Texan water company suffered a cyber-attack, The US is not the only country to be so hit: Norway and Poland have reported similar attacks.
The pilot program, sponsored by Microsoft, identified four factors that would improve security. First, companies should be wary of free tools, which are often inadequate. Second, utilities should expand hands-on technical assistance to support implementation. The next issue that companies should address is the need to include cybersecurity training in operator licensing. Finally, companies should develop their links water sector associations to help improve cybersecurity operations.
The report of the program concludes that to avoid future cybersecurity incidents, utilities should shift from information distribution to capacity building, ensuring that a resilient infrastructure is in place.
View the full article
- 0 comments
- 52 views
-
- 0 comments
- 50 views
-
Subscribe to The MacRumors Show YouTube channel for more videos
The AirPods Max 2 introduce a range of improvements primarily driven by the addition of Apple's H2 chip, which replaces the H1 chip used in previous models. This new chip underpins most of the upgrades, enabling more advanced computational audio and significantly enhancing the overall listening experience.
One of the most notable improvements is Active Noise Cancellation, which Apple says is up to 1.5x more effective than before, making the headphones better suited to noisy environments such as travel. Transparency mode is also refined, with more natural-sounding ambient audio and improved clarity when hearing voices and surroundings.
The H2 chip also facilitates a suite of new adaptive listening features. Adaptive Audio dynamically adjusts the balance between noise cancellation and environmental sound depending on your surroundings, while Conversation Awareness automatically lowers playback and enhances nearby voices when you begin speaking. Personalized Volume builds on this by learning your listening preferences over time and adjusting volume levels accordingly. In addition, Voice Isolation has been improved, helping to prioritize your voice during calls and reduce background noise more effectively.
Audio quality is enhanced with a new high dynamic range amplifier and updated signal processing. These changes should result in more consistent bass, clearer midrange, more natural vocals, and improved separation of instruments. Spatial Audio has also been refined, offering more accurate sound placement and a more coherent soundstage.
Wireless performance sees an upgrade with support for Bluetooth 5.3, which reduces latency compared to the previous generation. Alongside audio improvements, several new features have been added, including Live Translation powered by Apple Intelligence, the ability to use the Digital Crown as a camera remote for taking photos or controlling video recording, and expanded Siri interactions, including hands-free activation without "Hey Siri" and gesture-based responses.
Despite these updates, several core aspects remain unchanged. The design, materials, and overall form factor are identical to earlier versions, battery life remains at up to 20 hours with noise cancellation enabled, and the headphones continue to use the same Smart Case. Pricing is also unchanged at $549.
AirPods Max 2 will be available to order on Apple.com and in the Apple Store app starting Wednesday, March 25 in the U.S. and more than 30 other countries, and they launch on an unspecified day in early April. The MacRumors Show has its own YouTube channel, so make sure you're subscribed to keep up with new episodes and clips.
Subscribe to The MacRumors Show YouTube channel!
You can also listen to The MacRumors Show on Apple Podcasts, Spotify, Overcast, or other podcast apps. You can also copy our RSS feed directly into your player.
If you haven't already listened to the previous episode of The MacRumors Show, catch up to hear our discussion about Apple's concentrated week of announcements that saw the introduction of 10 new products.
Subscribe to The MacRumors Show for new episodes every week, where we discuss some of the topical news breaking here on MacRumors, often joined by interesting guests such as Kayci Lacob, Kevin Nether, John Gruber, Mark Gurman, Jon Prosser, Luke Miani, Matthew Cassinelli, Brian Tong, Quinn Nelson, Jared Nelson, Eli Hodapp, Mike Bell, Sara Dietschy, iJustine, Jon Rettinger, Andru Edwards, Arnold Kim, Ben Sullins, Marcus Kane, Christopher Lawley, Frank McShan, David Lewis, Tyler Stalman, Sam Kohl, Federico Viticci, Thomas Frank, Jonathan Morrison, Ross Young, Ian Zelbo, and Rene Ritchie.
The MacRumors Show is on X @MacRumorsShow, so be sure to give us a follow to keep up with the podcast. You can also email us at [email protected] or head over to The MacRumors Show forum thread. Remember to rate and review the podcast, and let us know what subjects and guests you would like to see in the future.Related Roundup: AirPods Max 2Tag: The MacRumors ShowBuyer's Guide: AirPods Max (Buy Now)Related Forum: AirPods
This article, "The MacRumors Show: Surprise AirPods Max 2 Announcement" first appeared on MacRumors.com
Discuss this article in our forums
View the full article
- 0 comments
- 35 views
-
The Google Open Source Software Vulnerability Reward Program team is increasingly concerned about the low quality of some AI-generated bug submissions, with many including hallucinations about how a vulnerability can be triggered or reporting bugs with little security impact.
“To ensure our triage teams can focus on the most critical threats, we will now require higher-quality proof (like OSS-Fuzz reproduction or a merged patch) for certain tiers to filter out low-quality reports and allow us to focus on real-world impact,” Google wrote in a blog post.
The Linux Foundation too is finding the volume of AI-generated bug submissions overwhelming and has sought financial help from AI companies including Google, Anthropic, AWS, Microsoft, and OpenAI to deal with the problem. Together, they are contributing $12.5 million to the foundation to improve the security of open-source software.
“Grant funding alone is not going to help solve the problem that AI tools are causing today on open-source security teams,” said Greg Kroah-Hartman of the Linux kernel project in a blog post. “OpenSSF has the active resources needed to support numerous projects that will help these overworked maintainers with the triage and processing of the increased AI-generated security reports they are currently receiving.”
The funding will be managed by open source security project Alpha-Omega and the Open Source Security Foundation (OSSF) and will be used to provide AI tools to help maintainers deal with the volume of AI-generated submissions.
“We are excited to bring maintainer-centric AI security assistance to the hundreds of thousands of projects that power our world,” said Alpha-Omega co-founder Michael Winser.
This article first appeared on InfoWorld.
View the full article
- 0 comments
- 46 views
-
While the 13-inch MacBook Air starts at $1,099 and the 15-inch model at $1,299, moving to the 14-inch MacBook Pro requires spending at least $300 more. For some buyers, the extra cost is unnecessary; for others, the Pro's ability to sustain performance, along with its more advanced display and expanded I/O, meaningfully change the experience in ways the Air cannot match even with higher configurations.
With the introduction of the MacBook Neo as a new entry-level option, the Mac lineup now spans three distinct tiers. As a result, the MacBook Air no longer represents the default choice for most buyers, but instead occupies a middle position between affordability and performance. If you've already ruled out the MacBook Neo, this guide helps to answer the question of how to decide which of Apple's other two popular laptops is best for you. The key differences are as follows:
MacBook Air
MacBook Pro
13.6- or 15.3-inch display
14.2-inch display
Slimmer borders around the display
LCD Liquid Retina display
Mini-LED Liquid Retina XDR display
60Hz refresh rate
ProMotion for refresh rates up to 120Hz
Up to 500 nits brightness
Up to 1,000 nits brightness and 1,600 nits peak HDR brightness
Nano-texture display option
Passive cooling
Active cooling
Two Thunderbolt 4 (USB-C) ports
Three Thunderbolt 4 (USB-C) ports
HDMI 2.1 port with support for multichannel audio output
SDXC card slot
13-Inch: Four-speaker sound system
15-Inch: Six-speaker sound system with force-canceling woofers
High-fidelity six-speaker sound system with force-cancelling woofers
Three-mic array with directional beamforming
Studio-quality three-mic array with high signal-to-noise ratio and directional beamforming
512GB, 1TB, or 2TB of storage
512GB, 1TB, 2TB, or 4TB storage
13-Inch: 53.8-watt-hour lithium-polymer battery
15-Inch: 66.5-watt-hour lithium-polymer battery
14-Inch: 72.4-watt-hour lithium-polymer battery
18-hour battery life
24-hour battery life
30W, 35W, or 70W USB-C Power Adapter
70W or 96W USB-C Power Adapter
Silver, Sky Blue, Starlight, or Midnight color options
Silver or Space Black color options
13-Inch: Starts at $1,099
15-Inch: Starts at $1,299
Starts at $1,599
Dimensions are also a key area of difference between the MacBook Air and MacBook Pro. The MacBook Pro is noticeably thicker and heavier than both MacBook Air models:
MacBook Air (13-Inch)
MacBook Air (15-Inch)
MacBook Pro (14-Inch)
Height
0.44 inches (1.13 cm)
0.45 inch (1.15 cm)
0.61 inches (1.55 cm)
Width
11.97 inches (30.41 cm)
13.40 inches (34.04 cm)
12.31 inches (31.26 cm)
Depth
8.46 inches (21.5 cm)
9.35 inches (23.76 cm)
8.71 inches (22.12 cm)
Weight
2.7 pounds (1.24 kg)
3.3 pounds (1.51 kg)
3.4 pounds (1.55 kg)
Taken as a whole, the MacBook Air now occupies a more clearly defined middle position in Apple's laptop lineup. With the introduction of the MacBook Neo as a lower-cost entry point, the Air no longer represents the default choice for most buyers, but instead serves those who want a meaningful step up in performance, features, and long-term usability without moving into the MacBook Pro tier.
The MacBook Air offers excellent performance with the M5 chip, capable memory and storage options, a good all-round display, and key features like a backlit keyboard, 18 hours of battery life, and a 12MP Center Stage camera. For everyday tasks, performance remains effectively indistinguishable from more expensive models, but the Air is far less likely to feel constrained after several years of use compared to the MacBook Neo. Its thinner chassis, lower weight, silent fanless design, and broader range of color options also remain important advantages.
By contrast, the 14-inch MacBook Pro is differentiated less by baseline performance and more by its ability to sustain it, as well as by a collection of hardware features that materially change the experience. Active cooling allows the M5 chip to operate at higher levels for prolonged periods, avoiding the thermal limitations inherent to the Air's passive design. This becomes noticeable in extended workloads such as video editing, 3D rendering, compiling large codebases, or running intensive AI-driven tasks. If your workload regularly involves sustained performance, such as long video exports, large code builds, or intensive multitasking, the MacBook Air's fanless design may become a limiting factor.
Alongside this, MacBook Pro's mini-LED Liquid Retina XDR display with ProMotion offers substantially higher brightness, contrast, and motion fluidity, while the inclusion of HDMI, SDXC, and an additional Thunderbolt port expands its versatility in professional environments. It also delivers consistently better speakers, higher-quality microphones, and longer battery life. For users planning to keep their machine for several years, this sustained performance headroom and broader feature set can make the MacBook Pro a more resilient long-term investment.
The most consequential trade-off emerges at the upper end of the MacBook Air's pricing. At $1,299, the 15-inch MacBook Air sits close enough to the 14-inch MacBook Pro's $1,599 starting price that the decision becomes less about affordability and more about priorities. For an additional $300, the Pro offers a significantly more advanced display, active cooling for sustained performance, longer battery life, additional I/O, and overall greater versatility. Once you are already considering spending over $1,000 on a laptop, these advantages become disproportionately impactful, particularly for users intending to keep their machine for several years.
As a result, the MacBook Air is best understood as the balanced option within the lineup: Meaningfully more capable and longer-lasting than the MacBook Neo, but somewhat constrained compared to the MacBook Pro. The right choice depends less on basic specifications and more on where your needs sit across three distinct tiers, with basic computing at the low end, sustained performance and advanced features at the high end, and the MacBook Air positioned squarely between them.Related Roundups: MacBook Pro, MacBook AirBuyer's Guide: MacBook Pro (Buy Now), MacBook Air (Buy Now)Related Forums: MacBook Pro, MacBook Air
This article, "M5 MacBook Air vs. M5 MacBook Pro Buyer's Guide" first appeared on MacRumors.com
Discuss this article in our forums
View the full article
- 0 comments
- 43 views
-
Apple includes its 20W USB-C Power Adapter with the MacBook Neo (except in the UK and the EU, where the laptop does not ship with a charger at all), but a new charging test has revealed that Apple's 35W Dual USB-C Port Compact Power Adapter is a better choice if you want the fastest charging speeds at the lowest additional cost from Apple.
In the video below, ChargerLAB shows that the MacBook Neo reaches a peak charging speed of 18W with the included 20W charger, but this rises to 30W with Apple's 35W adapter, which is available in two sizes for $59 on Apple's online store.
ChargerLAB did not show exactly how much time you can save by using the 35W charger over the 20W charger, but it is probably up to 20-30 minutes for a full charge.
Of course, a variety of 30W-and-higher chargers sold by Apple and other companies can charge the MacBook Neo at peak speeds of 28W to 30W, so look beyond Apple if you want to save money. If you stick with Apple, just know this: its 35W adapter is faster than the included 20W adapter, but its expensive 96W and 140W chargers do not charge the MacBook Neo any faster than the 35W adapter despite costing more.
MacBook Neo launched last Wednesday, and Apple's CEO Tim Cook today revealed that the Mac just had its best launch week ever with first-time buyers.Related Roundup: MacBook NeoTag: ChargerLabBuyer's Guide: MacBook Neo (Buy Now)Related Forum: MacBook Neo
This article, "MacBook Neo Charging Test: Here's Which Apple Charger is the Fastest" first appeared on MacRumors.com
Discuss this article in our forums
View the full article
- 0 comments
- 40 views
-
The idea behind the all-in-one app is to simplify the user experience, following the launch of several standalone products, some of which haven't resonated with OpenAI's customers. The company is also trying to bounce back after the recent successes of its main rival, Anthropic.
OpenAI executives are said to be looking at areas it can deprioritize while it focuses on creating agentic AI capabilities within the new superapp that can work autonomously on a user's computer to carry out various tasks like writing code and analyzing data.
In an all-hands meeting last week, OpenAI's chief of applications Fidji Simo reportedly told employees they couldn't afford to be distracted by "side quests" given Anthropic's rapid success winning over enterprise and coding customers. From the report:
OpenAI unveiled a series of major initiatives last year, like its Sora video app and the acquisition of Jony Ive's AI hardware venture. Since then, however, Anthropic has gained strong momentum with the success of its Code Claude and Cowork offerings.
The WSJ report gave no timeline for the launch of OpenAI's so-called superapp, but it said the company's mobile ChatGPT app will remain unchanged.Tags: ChatGPT, OpenAI
This article, "OpenAI 'Superapp' to Merge ChatGPT, Codex, and Atlas Browser" first appeared on MacRumors.com
Discuss this article in our forums
View the full article
- 0 comments
- 45 views
-
On his Instagram page earlier this week, Australian composer Bailey Pickles said Apple asked him to compose and perform music for its upcoming 50th-anniversary celebration at the Opera House, where Apple will soon be illuminating artwork.
From March 25 to March 27, the Opera House's eastern sails will be illuminated with artwork created in the Procreate app on the iPad by a group of 10 emerging Australian artists. Through free Today at Apple sessions earlier this month, the public also had the opportunity to create and submit artwork for potential illumination.
Apple said selected artworks from both commissioned artists and public submissions will be curated and projected on to the Opera House's eastern sails on March 25 at 8:30 p.m. local time, and on March 26 and March 27 at 8 p.m. local time. Pickles did not say exactly when he will be performing at the world-famous venue, but it is clear that the 50th-anniversary celebration will involve a mix of artwork and music.
It is unclear if Apple's CEO Tim Cook or any other company executives will attend this celebration, but it is worth noting that Cook is currently in China, so he is a lot closer to Australia right now than he would ordinarily be. Perhaps he will make a surprise appearance at the Opera House at some point, but only time will tell.
Apple has hosted 50th-anniversary celebrations in the United States, China, and South Korea so far, with more to follow in Canada, France, and Thailand, plus Australia. Our guess is that Apple will eventually hold a final celebration in California — the rainbow arches inside Apple Park would be the perfect spot for one last gathering.
Apple turns 50 on April 1.Tags: Apple 50th Anniversary, Australia
This article, "Apple's 50th Anniversary Celebrations Headed to Australia" first appeared on MacRumors.com
Discuss this article in our forums
View the full article
- 0 comments
- 47 views
-
- 0 comments
- 43 views
-
The overwhelming majority of Apple's AI app commission revenue came courtesy of ChatGPT downloads leading to subsequent subscriptions, which alone accounted for around 75 percent of the above total. Elon Musk's Grok app came a distant second, making up just 5 percent of the revenue.
Apple is now said to be on course to earn $1 billion in generative app revenue this year. Given how behind the company is in the AI race, highlighted by the sluggish progress of its enhanced Siri rollout, it's a tidy sum indeed.
Of course, the reason Apple benefits from the popularity of AI apps built by other companies is that the iPhone remains the smartphone market leader. Most AI apps still have to go through its App Store, where Apple takes a commission of up to 30 percent on subscriptions. As the report notes:
The revenue stands in contrast to Apple's relatively modest AI spending compared to rivals like Microsoft, Amazon, and Meta, all of whom have poured tens of billions into AI infrastructure, with little to no profit yet to show for it. Meanwhile, Apple's capital expenditures have remained comparatively flat, thanks to its prioritization of investment in on-device AI over large data centers filled with GPU processors.
The strategy won't enable a more capable Siri, but Apple appears to be happy to lean on Google to provide the necessary AI infrastructure for that. The two companies announced in January that Gemini will power a revamped version of Apple's virtual assistant, coming later this year. The financial terms of the partnership haven't been disclosed, but Bloomberg reported last year that the deal would be around $1 billion annually. That will give Apple access to a 1.2 trillion parameter model that dwarfs its in-house capabilities.
Perhaps the deeper irony is that Google already pays Apple around $20 billion per year to remain the default search engine on iPhones, so now money is flowing in the other direction too, albeit at a drastically lower rate.
Still, some investors see the App Store approach as a more viable long-term strategy. Charles Rinehart, chief investment officer of Johnson Asset Management, told WSJ that if Apple "can act as a toll road for providers of AI, then they'll probably end up looking good long-term."Tag: App Store
This article, "Apple Made Nearly $900 Million From Generative AI Apps Last Year" first appeared on MacRumors.com
Discuss this article in our forums
View the full article
- 0 comments
- 42 views
-
This comes after the MacBook Neo launched on Wednesday, March 11. In the U.S., the laptop starts at just $599, or an even lower $499 for college students.
Related Roundup: MacBook NeoTag: Tim CookBuyer's Guide: MacBook Neo (Buy Now)Related Forum: MacBook Neo
This article, "Apple Reveals New Sales Achievement Following MacBook Neo Launch" first appeared on MacRumors.com
Discuss this article in our forums
View the full article
- 0 comments
- 45 views
-
Data Residency and Processing
Updated the Data Residency and Processing Reference guide for persistent storage locations.
IP Addresses and Domains
Updated the F5 Distributed Cloud Services IP Address and Domain Reference for Firewall or Proxy Settings guide for new IP addresses.
View the full article
- 0 comments
- 40 views
-
In einem großangelegten Schlag gegen ein internationales Hacker-Netzwerk haben Sicherheitsbehörden in Nordamerika und Deutschland die beiden weltgrößten Botnetze zerschlagen. Die Infrastruktur der Kriminellen war vor allem für sogenannte Denial-of-Services-Attacken (DDoS), verwendet worden, teilte das Bundeskriminalamt mit. Dabei versuchen die Cyberkriminellen, die Webseiten und Apps ihrer Opfer lahmzulegen, indem Sie sie mit unzähligen Datenanfragen überschütten. Zuletzt waren die Informationsangebote der Deutschen Bahn und die DB-Navigator-App Opfer einer DDoS-Attacke geworden.
Werkzeuge für Überlastungsangriffe
Konkret richtete sich die Aktion gegen die beiden berüchtigten Botnetze «Aisuru» und «Kimwolf». Das ältere System «Aisuru» hat vor allem Geräte infiziert, die sich im «Internet der Dinge» befinden und schlecht gesichert sind. Dazu gehören etwa Router und Überwachungskameras. «Aisuru» wird auch der bislang größte bekannte DDoS-Angriff zugeschrieben, bei dem die gewaltige Datenmenge von 31,4 Terabit pro Sekunde bewegt wurde. Dieser Angriff wurde damals vom IT-Dienstleister Cloudflare abgewehrt. Das eigentliche Ziel blieb unbekannt.
«Kimwolf» ist nach Einschätzung von Experten eng mit «Aisuru» verwandt. Das zweite Botnetz legte den Fokus stärker auf Android und Consumer Geräte, darunter TV-Boxen.
Internationale Zusammenarbeit der Fahnder
An dem Schlag gegen die kriminellen Hacker waren auf deutscher Seite die Zentral- und Ansprechstelle Cybercrime Nordrhein-Westfalen (ZAC NRW) und das Bundeskriminalamt (BKA) beteiligt. Zusammen mit Strafverfolgungsbehörden aus Kanada und den USA wurde die global verteilte technische Infrastruktur der beiden Botnetze abgeschaltet.
Das kriminelle Netzwerk ist allerdings nicht vollständig zerschlagen, weil es den Fahndern nicht gelang, Tatverdächtige festzunehmen. Immerhin wurden von den Strafverfolgungsbehörden zwei mutmaßliche Administratoren identifiziert. «Auf die Beschuldigten kommen nun rechtliche Konsequenzen zu», erklärte das Bundeskriminalamt. An ihren Wohnorten in Deutschland und in Kanada seien bei Durchsuchungen umfassende Beweismittel sichergestellt worden. Neben zahlreichen Datenträgern wurden auch Kryptowährungen im fünfstelligen Bereich gesichert. (dpa/ad)
View the full article
- 0 comments
- 40 views
-
In einem großangelegten Schlag gegen ein internationales Hacker-Netzwerk haben Sicherheitsbehörden in Nordamerika und Deutschland die beiden weltgrößten Botnetze zerschlagen. Die Infrastruktur der Kriminellen war vor allem für sogenannte Denial-of-Services-Attacken (DDoS), verwendet worden, teilte das Bundeskriminalamt mit. Dabei versuchen die Cyberkriminellen, die Webseiten und Apps ihrer Opfer lahmzulegen, indem Sie sie mit unzähligen Datenanfragen überschütten. Zuletzt waren die Informationsangebote der Deutschen Bahn und die DB-Navigator-App Opfer einer DDoS-Attacke geworden.
Werkzeuge für Überlastungsangriffe
Konkret richtete sich die Aktion gegen die beiden berüchtigten Botnetze «Aisuru» und «Kimwolf». Das ältere System «Aisuru» hat vor allem Geräte infiziert, die sich im «Internet der Dinge» befinden und schlecht gesichert sind. Dazu gehören etwa Router und Überwachungskameras. «Aisuru» wird auch der bislang größte bekannte DDoS-Angriff zugeschrieben, bei dem die gewaltige Datenmenge von 31,4 Terabit pro Sekunde bewegt wurde. Dieser Angriff wurde damals vom IT-Dienstleister Cloudflare abgewehrt. Das eigentliche Ziel blieb unbekannt.
«Kimwolf» ist nach Einschätzung von Experten eng mit «Aisuru» verwandt. Das zweite Botnetz legte den Fokus stärker auf Android und Consumer Geräte, darunter TV-Boxen.
Internationale Zusammenarbeit der Fahnder
An dem Schlag gegen die kriminellen Hacker waren auf deutscher Seite die Zentral- und Ansprechstelle Cybercrime Nordrhein-Westfalen (ZAC NRW) und das Bundeskriminalamt (BKA) beteiligt. Zusammen mit Strafverfolgungsbehörden aus Kanada und den USA wurde die global verteilte technische Infrastruktur der beiden Botnetze abgeschaltet.
Das kriminelle Netzwerk ist allerdings nicht vollständig zerschlagen, weil es den Fahndern nicht gelang, Tatverdächtige festzunehmen. Immerhin wurden von den Strafverfolgungsbehörden zwei mutmaßliche Administratoren identifiziert. «Auf die Beschuldigten kommen nun rechtliche Konsequenzen zu», erklärte das Bundeskriminalamt. An ihren Wohnorten in Deutschland und in Kanada seien bei Durchsuchungen umfassende Beweismittel sichergestellt worden. Neben zahlreichen Datenträgern wurden auch Kryptowährungen im fünfstelligen Bereich gesichert. (dpa/ad)
View the full article
- 0 comments
- 32 views
-
- 0 comments
- 39 views
-
The Certified Site Reliability Professional program is a comprehensive validation framework designed for engineers who want to master the art of balancing system reliability with the speed of software delivery. This guide is written for software engineers, systems administrators, and technical leads who are navigating the complex transition from traditional operations to modern reliability engineering. In an era where downtime costs millions, understanding the principles of error budgets, toil reduction, and automated incident response is no longer optional.
Navigating the landscape of technical certifications can be overwhelming, especially with the overlap between DevOps and SRE roles. This guide provides a clear roadmap to help you understand where the Certified Site Reliability Professional fits into your career trajectory. Whether you are based in India or working in a global distributed team, this program bridges the gap between theoretical cloud-native concepts and the gritty reality of managing production systems at scale.
By reading this guide, professionals will gain clarity on which learning paths align with their current skills and future aspirations. We move beyond the buzzwords to examine the practical utility of this certification. Our goal is to empower you with the information needed to make a strategic decision about your professional development, ensuring that your investment in learning translates into tangible career growth and improved system stability for your organization through SREschool.
What is the Certified Site Reliability Professional?
The Certified Site Reliability Professional represents a standardized benchmark for excellence in the field of reliability engineering. It is not merely a test of theoretical knowledge but a validation of an engineer’s ability to apply SRE principles to real-world production environments. The program exists to formalize the diverse skill set required to keep modern, distributed systems running smoothly, moving away from “firefighting” toward proactive system design.
The curriculum is built around the core pillars of SRE as defined by industry leaders, emphasizing measurable reliability. It focuses on how to define Service Level Objectives (SLOs) that actually matter to the business and how to implement Service Level Indicators (SLIs) that provide true visibility into system health. This certification ensures that practitioners understand how to manage the lifecycle of an application from code commit through to long-term production maintenance.
In the modern enterprise, this certification acts as a signal that an engineer can handle the pressure of high-availability requirements. It aligns with cloud-native workflows, Kubernetes-driven orchestration, and the shift toward infrastructure as code. By completing this program, professionals demonstrate that they are capable of reducing operational load through automation and building resilient systems that can self-heal during failures.
Who Should Pursue Certified Site Reliability Professional?
Software engineers who find themselves spending more time managing infrastructure than writing features will find immense value in this program. It is particularly beneficial for DevOps practitioners who want to specialize specifically in the reliability and observability aspects of the delivery pipeline. As organizations move toward platform engineering models, having a certified SRE on the team becomes a critical requirement for maintaining service integrity.
Cloud professionals and systems administrators who are transitioning from manual server management to automated cloud operations should consider this path. For these individuals, the certification provides the structured methodology needed to scale their impact across hundreds or thousands of microservices. It moves the needle from “running a server” to “architecting a resilient ecosystem,” which is a vital shift for career longevity.
Engineering managers and technical leaders also benefit from this certification, even if they are not coding daily. Understanding the SRE framework allows managers to set realistic expectations for their teams and communicate effectively with stakeholders about system risks. In the Indian market and globally, there is a massive talent gap for professionals who understand the financial and operational implications of system reliability, making this an ideal choice for ambitious technical leads.
Why Certified Site Reliability Professional is Valuable and Beyond
The demand for reliability expertise is skyrocketing as every company becomes a software company. As systems grow in complexity due to microservices and multi-cloud strategies, the risk of catastrophic failure increases. The Certified Site Reliability Professional helps engineers stay relevant by focusing on evergreen principles like observability, automation, and risk management rather than just chasing the latest ephemeral tool or framework.
Enterprise adoption of SRE practices is no longer limited to “Big Tech” firms; it is now a standard requirement in banking, healthcare, and retail. This certification provides a return on investment by making you a high-value asset in any organization that prioritizes uptime and customer experience. It provides the language and frameworks needed to advocate for reliability-focused projects, which are often the most technically challenging and rewarding tasks in an organization.
Furthermore, the focus on toil reduction ensures that your career remains sustainable. By learning how to automate away repetitive tasks, you free yourself to work on high-impact engineering problems. This shift not only increases your professional satisfaction but also makes you indispensable to your employer. The certification proves that you are committed to the long-term health of both the systems you manage and the engineering culture you work within.
Certified Site Reliability Professional Certification Overview
The Certified Site Reliability Professional program is a multi-tiered educational journey delivered through Certified Site Reliability Professional and hosted on the SREschool.com platform. The program is designed to cater to different stages of professional maturity, from those just entering the field to seasoned veterans looking to lead SRE departments. Each level is built to challenge the candidate’s practical understanding of reliability concepts.
Assessment in this program is rigorous and performance-based. Unlike traditional certifications that rely heavily on multiple-choice questions, this program emphasizes practical scenarios and case studies that reflect actual production incidents. This approach ensures that a certified professional can hit the ground running when faced with a real-world outage or a scaling bottleneck. The ownership of the program lies with industry practitioners who update the curriculum to reflect current enterprise practices.
The structure is modular, allowing engineers to pick tracks that align with their specific day-to-day responsibilities. This flexibility is essential in a field as broad as SRE, where one engineer might focus on infrastructure automation while another focuses on deep-dive observability and distributed tracing. The program provides a clear path of progression, ensuring that as you grow in your career, there is a corresponding certification level to validate your advanced expertise.
Certified Site Reliability Professional Certification Tracks & Levels
The certification is divided into three primary levels: Foundation, Professional, and Advanced. The Foundation level introduces the core vocabulary and concepts, ensuring a baseline of understanding across the organization. The Professional level dives into implementation, focusing on the tools and techniques required to manage production systems. The Advanced level is for architects and leaders who design reliability strategies for entire organizations.
Specialization tracks are a key feature of the program. While the core focuses on SRE, there are pathways that branch into DevOps, FinOps, and DevSecOps. These tracks allow professionals to cross-pollinate their reliability skills with other critical domains. For instance, a FinOps-focused SRE learns how to optimize for both reliability and cost, a skill set that is highly sought after in current economic climates.
These levels align perfectly with career progression from Junior SRE to Senior SRE and eventually to Principal Engineer or SRE Manager. By following the structured tracks, an engineer can build a holistic portfolio of skills that covers every aspect of the modern technology stack. This tiered approach prevents “knowledge gaps” and ensures that the professional has a solid foundation before moving into complex, high-stakes reliability engineering tasks.
Complete Certified Site Reliability Professional Certification Table
TrackLevelWho it’s forPrerequisitesSkills CoveredRecommended OrderCore SREFoundationBeginners & ManagersBasic IT KnowledgeSLIs/SLOs, Toil, Incident Mgmt1Core SREProfessionalSREs & DevOps EngineersFoundation LevelAutomation, Observability, CI/CD2Core SREAdvancedLead Engineers & ArchitectsProfessional LevelError Budgets, Capacity Planning3FinOpsSpecialistCloud Financial AnalystsProfessional LevelCost Modeling, Unit Economics4 (Optional)DevSecOpsSpecialistSecurity EngineersProfessional LevelChaos Security, Policy as Code4 (Optional)PlatformExpertPlatform EngineersAdvanced LevelIDPs, Self-Service Infrastructure5 Detailed Guide for Each Certified Site Reliability Professional Certification
Certified Site Reliability Professional – Foundation
What it is
This certification validates a candidate’s understanding of the fundamental principles of Site Reliability Engineering. It ensures the individual can communicate using SRE terminology and understands the cultural shift required for reliability.
Who should take it
This is suitable for junior engineers, product managers, and traditional IT operations staff who are new to the SRE philosophy. It is also ideal for stakeholders who need to understand why reliability is a shared responsibility.
Skills you’ll gain
Defining Service Level Indicators (SLIs) and Service Level Objectives (SLOs). Understanding the concept of Error Budgets and how they govern releases. Identifying “Toil” and understanding its impact on engineering productivity. Basic incident response workflows and post-mortem culture. Real-world projects you should be able to do
Drafting an initial SLO document for a simple web service. Conducting a blameless post-mortem for a minor system disruption. Mapping manual tasks to identify candidates for automation. Preparation plan
7-14 days: Focus on reading core SRE books and understanding the vocabulary. 30 days: Engage with online modules and attend foundational webinars. 60 days: Apply concepts to a small internal project and review case studies. Common mistakes
Treating SLOs as rigid targets rather than negotiation tools. Confusing SRE with traditional “Ops” with a new title. Best next certification after this
Same-track option: Professional Level SRE Cross-track option: DevOps Foundation Leadership option: Technical Lead Essentials Certified Site Reliability Professional – Professional
What it is
This level validates the ability to implement SRE practices using modern tooling and automation. It proves that the engineer can actively improve the reliability of a production system through technical intervention.
Who should take it
This is designed for practicing SREs and DevOps engineers with 2-4 years of experience who are responsible for the uptime and performance of live environments.
Skills you’ll gain
Implementing advanced observability with Prometheus and Grafana. Building automated CI/CD pipelines with integrated reliability checks. Configuring automated incident alerting and escalation paths. Managing infrastructure as code using Terraform or Ansible. Real-world projects you should be able to do
Designing a dashboard that visualizes error budget consumption in real-time. Automating the recovery of a failed microservice using Kubernetes probes. Building a canary deployment pipeline that rolls back based on SLI degradation. Preparation plan
7-14 days: Review documentation for monitoring and automation tools. 30 days: Complete hands-on labs focusing on incident response and IaC. 60 days: Conduct an end-to-end reliability audit of a staging environment. Common mistakes
Over-automating before understanding the manual process. Creating too many alerts, leading to alert fatigue. Best next certification after this
Same-track option: Advanced Level SRE Cross-track option: DevSecOps Specialist Leadership option: SRE Management Certified Site Reliability Professional – Advanced
What it is
The Advanced certification validates an engineer’s ability to design complex, multi-region reliability strategies. It focuses on high-level architecture, capacity planning, and organizational SRE culture.
Who should take it
This is intended for Principal Engineers, Architects, and SRE Leads who are responsible for the reliability of entire platforms or business units.
Skills you’ll gain
Designing multi-cloud and multi-region failover strategies. Advanced capacity planning and performance tuning at scale. Implementing Chaos Engineering to proactively find system weaknesses. Developing SRE team structures and hiring frameworks. Real-world projects you should be able to do
Creating a global traffic management strategy for 99.99% availability. Running a “Game Day” to simulate a total region outage and recovery. Developing a custom observability platform for high-cardinality data. Preparation plan
7-14 days: Deep dive into distributed systems papers and architecture. 30 days: Design and document a complex failure scenario recovery plan. 60 days: Implement a Chaos Engineering experiment on a non-critical system. Common mistakes
Ignoring the cost implications of high-availability designs. Focusing only on technical solutions while ignoring team culture. Best next certification after this
Same-track option: Platform Engineering Expert Cross-track option: FinOps Specialist Leadership option: Director of Engineering / VP of Reliability Choose Your Learning Path
DevOps Path
The DevOps path focuses on the seamless integration of development and operations. For the Certified Site Reliability Professional, this means emphasizing the automation of the delivery pipeline and ensuring that reliability is baked into the code from the start. Practitioners on this path will learn how to bridge the gap between “building it” and “running it” using shared metrics.
DevSecOps Path
In this path, security is treated as a core component of reliability. A system cannot be reliable if it is not secure. Candidates will learn how to integrate automated security scanning into their CI/CD pipelines and how to apply SRE principles to security incident response. This path is essential for those working in highly regulated industries.
SRE Path
This is the “pure” reliability path, focusing deeply on the mechanics of production systems. It prioritizes observability, incident management, and the mathematical rigor of SLOs. This path is for the specialist who wants to be the ultimate authority on system uptime and performance, moving toward high-level reliability architecture.
AIOps Path
The AIOps path explores the intersection of artificial intelligence and operations. Candidates learn how to use machine learning models to predict system failures before they occur and how to automate the analysis of vast amounts of log data. This is a forward-looking path for engineers who want to manage systems at a scale that exceeds human manual capacity.
MLOps Path
Focusing on the reliability of machine learning pipelines, this path addresses the unique challenges of model drift and data integrity. An SRE in this path ensures that ML models are served reliably and that the underlying infrastructure can handle the intensive compute requirements of modern AI applications. It is a critical role for data-driven organizations.
DataOps Path
The DataOps path applies SRE principles to data engineering and data pipelines. It focuses on the reliability of data delivery, ensuring that data warehouses and real-time streams are consistent and performant. This path is vital for companies where data is the primary product or where business decisions depend on real-time analytics.
FinOps Path
Reliability at any cost is not a sustainable business strategy. The FinOps path teaches SREs how to balance performance with cloud spending. Candidates learn about unit economics, cost allocation, and how to optimize infrastructure to provide the highest reliability for the lowest possible price.
Role → Recommended Certified Site Reliability Professional Certifications
RoleRecommended CertificationsDevOps EngineerFoundation, Professional, DevSecOps SpecialistSREFoundation, Professional, AdvancedPlatform EngineerProfessional, Advanced, Platform ExpertCloud EngineerFoundation, Professional, FinOps SpecialistSecurity EngineerFoundation, DevSecOps SpecialistData EngineerFoundation, DataOps SpecialistFinOps PractitionerFoundation, FinOps SpecialistEngineering ManagerFoundation, SRE Management Track Next Certifications to Take After Certified Site Reliability Professional
Same Track Progression
Once you have mastered the Advanced level of SRE, the natural progression is to look toward Platform Engineering. This involves building the internal developer platforms (IDP) that allow other teams to be self-sufficient while maintaining reliability standards. Deepening your expertise in specific tools like Kubernetes or cloud-native networking also complements this track perfectly.
Cross-Track Expansion
An SRE professional can significantly increase their value by expanding into FinOps or DevSecOps. Understanding the financial implications of reliability or the security vulnerabilities of a distributed system makes you a much more versatile engineer. This cross-training allows you to participate in high-level business discussions that go beyond technical implementation.
Leadership & Management Track
For those looking to move away from the keyboard, the management track focuses on building and scaling SRE organizations. This involves learning how to hire the right talent, how to advocate for SRE budgets at the executive level, and how to foster a culture of blamelessness and continuous improvement across the entire engineering department.
Training & Certification Support Providers for Certified Site Reliability Professional
DevOpsSchool
DevOpsSchool provides comprehensive training programs tailored for professionals looking to transition into SRE and DevOps roles. Their curriculum is highly practical, focusing on the tools and methodologies used in modern tech environments. With a strong presence in India, they offer both online and classroom-based sessions led by experienced industry practitioners. They emphasize hands-on labs, ensuring that students do not just learn the theory but can actually implement the solutions. Their support extends to career guidance and placement assistance, making them a popular choice for engineers at various stages of their careers.
Cotocus
Cotocus is known for its high-end technical consulting and specialized training programs in the cloud-native space. They focus on delivering in-depth knowledge of SRE, Kubernetes, and automated infrastructure. Their trainers are often active consultants who bring real-world problems and solutions into the classroom. Cotocus is particularly effective for corporate training, helping entire teams align on reliability standards. Their approach is focused on architectural depth, ensuring that candidates understand the “why” behind every technical decision. They provide a robust environment for learning the complexities of distributed systems at scale.
Scmgalaxy
Scmgalaxy serves as a massive knowledge hub and community for software configuration management and DevOps professionals. They offer a wide array of resources, including tutorials, certifications, and technical blogs that cover every aspect of the delivery lifecycle. Their training programs for SRE are designed to be accessible yet thorough, making them a great starting point for those new to the field. Scmgalaxy’s strength lies in its community-driven approach, providing a platform where engineers can share experiences and solve problems together. They are a reliable source for staying updated on the latest trends in reliability engineering.
BestDevOps
BestDevOps focuses on quality-driven education for the modern engineering professional. Their courses are structured to provide a clear path from beginner to expert level, with a strong emphasis on SRE and platform engineering. They pride themselves on keeping their content updated with the latest industry shifts, ensuring that students are learning current practices. BestDevOps provides a supportive learning environment with dedicated mentors who help candidates navigate the certification process. Their training modules are designed to be concise and impactful, catering to busy working professionals who need to maximize their learning time.
devsecopsschool.com
devsecopsschool.com is the go-to destination for engineers who want to master the integration of security into the reliability framework. Their courses focus on the DevSecOps track, teaching how to automate security checks and build resilient systems that can withstand cyber threats. They provide specialized training that is essential for SREs working in security-sensitive environments. The curriculum includes practical exercises on chaos security and policy as code. By focusing on this niche, they help professionals develop a rare and highly valuable skill set that bridges the gap between operations, security, and reliability.
sreschool.com
sreschool.com is the primary platform for the Certified Site Reliability Professional program, offering dedicated tracks for every level of SRE expertise. The platform is built by SREs for SREs, ensuring that the content is technically accurate and practically relevant. They provide a comprehensive suite of learning tools, including sandboxed environments where engineers can practice incident response in real-time. Their focus is entirely on reliability, making them the most specialized provider for this specific certification. The platform’s modular approach allows for a personalized learning journey that fits the specific needs of the individual.
aiopsschool.com
aiopsschool.com focuses on the future of operations, where artificial intelligence and machine learning are used to manage system reliability. Their training programs cover the AIOps track, teaching engineers how to implement predictive maintenance and automated root cause analysis. This is an essential resource for those looking to work with large-scale, complex systems that require automated oversight. They provide insight into the latest AI tools and how they can be integrated into traditional SRE workflows. Their courses are designed for forward-thinking engineers who want to be at the forefront of the next operational revolution.
dataopsschool.com
dataopsschool.com addresses the growing need for reliability in data engineering through its DataOps-focused curriculum. They teach how to apply SRE principles to data pipelines, ensuring that data is delivered accurately and on time. Their courses are vital for data engineers and SREs who are responsible for the health of data platforms. They cover topics such as data observability, pipeline automation, and managing the reliability of distributed data stores. By focusing on the intersection of data and operations, they help professionals ensure that the business can always rely on its data-driven insights.
finopsschool.com
finopsschool.com provides specialized training in cloud financial management, a critical skill for the modern SRE. Their courses teach how to align technical reliability with financial efficiency, ensuring that cloud infrastructure is optimized for both performance and cost. They provide a structured approach to FinOps, covering everything from cost allocation to unit economics. This training is essential for SREs who need to justify their infrastructure spending to stakeholders. Their curriculum helps professionals become “cloud-economists,” capable of driving significant cost savings for their organizations while maintaining high service levels.
Frequently Asked Questions (General)
How difficult is the Certified Site Reliability Professional exam?
The difficulty depends on the level, but the Professional and Advanced levels are considered challenging due to their focus on practical application and real-world scenarios rather than rote memorization. How long does it take to prepare for the certification?
Most professionals spend between 30 to 60 days preparing, depending on their existing experience with SRE concepts and the specific level of certification they are pursuing. Are there any prerequisites for the Foundation level?
There are no formal prerequisites, though a basic understanding of software development and IT operations is highly recommended to grasp the concepts effectively. Does this certification help in getting a job in India?
Yes, the demand for SREs in India’s tech hubs is massive, and this certification serves as a strong validator for recruiters looking for specialized reliability talent. Can I skip the Foundation level and go straight to Professional?
While possible for very experienced engineers, it is generally recommended to follow the sequence to ensure no gaps exist in your understanding of the core SRE philosophy. What is the ROI of getting certified as an SRE?
Certified SREs often command higher salaries and have access to more senior roles, as they are capable of managing the high-stakes production environments of major enterprises. How often is the certification content updated?
The curriculum is reviewed annually to ensure it reflects current industry trends, tool updates, and evolving best practices in reliability engineering. Is the exam conducted online or at a center?
The certification is primarily delivered online through a proctored environment, allowing professionals from around the globe to take the exam at their convenience. What tools should I be familiar with before taking the Professional exam?
Familiarity with Kubernetes, Prometheus, Grafana, and at least one major cloud provider (AWS, Azure, or GCP) is highly beneficial for the practical sections. Is there a community or alumni network I can join?
Yes, successful candidates gain access to a global community of certified professionals where they can network, share knowledge, and find career opportunities. Do I need to know how to code to become a Certified Site Reliability Professional?
Yes, a basic to intermediate level of coding (usually Python or Go) and shell scripting is necessary, as SRE is essentially an engineering approach to operations. How does this certification compare to a DevOps certification?
While DevOps is broad, this certification is specialized, focusing specifically on the “Run” phase and the technical reliability of systems in production. FAQs on Certified Site Reliability Professional
What makes the Certified Site Reliability Professional unique compared to other SRE programs?
It focuses heavily on the practical “day-two” operations and the alignment of technical metrics with business goals like customer satisfaction and cost. Can this certification be used to transition from a manual QA role?
Yes, but it requires a significant upskilling in automation and infrastructure, making the Foundation level an excellent starting point for that transition. How does the program handle multi-cloud reliability?
The Advanced level specifically covers strategies for maintaining availability across different cloud providers, reflecting the reality of modern enterprise environments. Is incident management a major part of the exam?
Yes, understanding the lifecycle of an incident, from detection to resolution and post – mortem analysis, is a core component of the certification. Are the labs included in the training program?
Most training providers for this certification include hands-on labs that simulate real production environments to help you practice your skills. Does the certification cover Chaos Engineering?
Yes, specifically at the Professional and Advanced levels, where proactive failure testing is introduced as a key reliability practice. How does this program address the “human” side of SRE?
It emphasizes blameless culture and psychological safety, recognizing that human factors are just as important as technical ones in incident response. Can I renew my certification?
Certifications are typically valid for two to three years, after which you can renew by passing an updated exam or progressing to the next level. Final Thoughts: Is Certified Site Reliability Professional Worth It?
From the perspective of a mentor who has seen the industry evolve over decades, the Certified Site Reliability Professional is a high-value investment for any engineer committed to the production side of software. We are moving past the era where “knowing how to code” is enough. Today’s market demands engineers who understand how that code behaves under pressure, how it fails, and how to make it resilient.
This certification provides the structured path needed to move from a reactive role to a proactive engineering role. It isn’t just about adding a badge to your profile; it’s about internalizing a mindset that prioritizes long-term system health over short-term fixes. If you are looking to future-proof your career and take on the most challenging and rewarding roles in modern technology, this certification is an excellent step forward.
View the full article
- 0 comments
- 58 views
-
- 0 comments
- 44 views
-
- 0 comments
- 40 views
-
In today’s digital landscape, the need for converting documents from one format to another is greater than ever. Whether it’s converting PDF files to Word, PowerPoint to PDF, or even image files into text through Optical Character Recognition (OCR), document conversion tools have become essential for individuals, businesses, and professionals alike. As technology continues to evolve, the demand for versatile, accurate, and user-friendly document conversion tools is on the rise.
In 2026, the document conversion tool industry is expected to be even more robust, offering faster, more secure, and highly efficient solutions. These tools provide businesses and individuals with a means to streamline their workflows, improve productivity, and save time by converting documents without the need for manual intervention. However, with so many options available, choosing the right document conversion tool can be daunting. This guide highlights the top 10 document conversion tools for 2026, along with their features, pros, cons, and a comparison to help you make an informed decision.
Top 10 Document Conversion Tools for 2026
1. Adobe Acrobat Pro DC
Short Description
Adobe Acrobat Pro DC is one of the most well-known tools in the document conversion space. It allows users to convert a variety of document formats, including PDFs, Word, Excel, PowerPoint, and more.
Key Features
Converts PDFs to various formats (Word, Excel, PowerPoint, etc.). OCR for converting scanned documents into editable text. Integrates seamlessly with Adobe Cloud for easy storage and sharing. Provides secure and password-protected conversions. Converts web pages into PDFs and vice versa. Pros
Highly accurate PDF conversions. Trusted brand with strong security features. Excellent OCR support for scanned documents. Cons
Expensive subscription plan. The user interface can be overwhelming for beginners. Limited free trial period. 2. Smallpdf
Short Description
Smallpdf is an online document conversion tool that is known for its simplicity and user-friendly interface. It allows users to convert, merge, split, and compress PDFs, making it an excellent option for quick, on-the-go conversions.
Key Features
Converts PDFs to Word, Excel, PowerPoint, and image formats. Online tool, no software installation required. Compresses PDFs to reduce file sizes. Secure file transfer with SSL encryption. Supports batch processing for multiple documents. Pros
Easy-to-use interface. Free version with essential tools. No installation required (online tool). Cons
Limited features in the free version. Upload and download speed can be slow with larger files. Limited to the web-based platform. 3. Nitro Pro
Short Description
Nitro Pro is another powerful desktop PDF tool that allows users to convert, create, and edit PDF documents. It is known for its wide range of conversion options, including converting scanned documents into editable text.
Key Features
Convert PDFs to Word, Excel, PowerPoint, and more. Edit and annotate PDF files. Includes advanced OCR features for scanned documents. Integration with cloud storage platforms like Google Drive and Dropbox. Batch processing support. Pros
Affordable compared to Adobe Acrobat Pro. Fast document conversion speeds. Advanced editing and OCR features. Cons
Limited online support and updates. Not as feature-rich as Adobe Acrobat. No mobile application for on-the-go conversion. 4. Smallpdf
Short Description:
Smallpdf is an online document conversion tool known for its simplicity and user-friendly interface. It enables users to convert, merge, split, and compress PDFs, making it a great option for quick, on-the-go document handling.
Key Features:
Converts PDFs to Word, Excel, PowerPoint, and image formats Fully online tool with no software installation required Compresses PDFs to reduce file sizes Secure file transfer with SSL encryption Supports batch processing for multiple documents Pros:
Easy-to-use interface Free version with essential tools No installation required (web-based) Cons:
Limited features in the free version Upload and download speed may be slow for large files Restricted to a web-based platform only 5. Wondershare PDFelement
Short Description
Wondershare PDFelement is a versatile PDF editor that also offers document conversion features. It is suitable for users looking for a comprehensive solution to manage and convert their documents.
Key Features
Convert PDFs to Word, Excel, PowerPoint, and more. OCR technology for converting scanned PDFs to editable formats. Batch processing for multiple file conversions. Supports file encryption and password protection. User-friendly interface with drag-and-drop functionality. Pros
Affordable subscription compared to other tools. Rich editing and conversion features. OCR capabilities for scanned documents. Cons
Limited advanced features in comparison to Adobe Acrobat. Occasional lag with large files. Learning curve for advanced features. 6. PDF Converter Ultimate
Short Description
PDF Converter Ultimate is a document conversion tool that focuses on converting PDF files to and from multiple formats. It also offers batch processing and high-quality conversions.
Key Features
Converts PDF to Word, Excel, PPT, HTML, and image formats. Batch processing for high-volume conversion tasks. OCR for converting scanned PDFs. Supports a wide range of document formats. Offers file editing and merging tools. Pros
High-quality conversion with minimal errors. Supports a large variety of file formats. Affordable pricing. Cons
Doesn’t offer cloud integration. No mobile version available. Slow processing for large files. 7. CloudConvert
Short Description
CloudConvert is an online file conversion tool that supports various file types. It allows users to convert documents, images, audio, and video files, making it a versatile solution for all-in-one conversions.
Key Features
Supports over 200 file formats. Converts documents, images, audio, and video files. API integration for developers. No software installation required (web-based tool). Free version with limitations on file size. Pros
Supports a wide variety of file types. API support for automation and integration. No installation needed. Cons
Slower conversion times for larger files. Limited features in the free version. Requires an internet connection. 8. UniPDF
Short Description
UniPDF is a free desktop tool for Windows users that specializes in converting PDFs into text-based formats such as Word, HTML, and image files.
Key Features
Convert PDFs to Word, HTML, JPG, and other formats. Batch conversion support. Retains formatting and images during conversion. Simple interface suitable for beginners. Free version available. Pros
Completely free to use. Simple and lightweight tool. Batch processing support. Cons
Limited to a small number of file formats. Only available for Windows. No cloud storage integration. 9. Online2PDF
Short Description
Online2PDF is a free web-based tool that allows users to convert and edit PDFs quickly. It supports a variety of document formats and provides powerful tools for editing PDF documents before conversion.
Key Features
Convert PDFs to Word, Excel, PowerPoint, and more. Edit PDFs by adding text, annotations, and images. Support for batch processing. Online and free to use. Allows file merging and splitting. Pros
Completely free to use. Simple to use for basic conversions. Allows document merging and splitting. Cons
Limited features compared to paid tools. Requires an internet connection. File size restrictions for free users. 10. DocuSign
Short Description
DocuSign is primarily known for its eSignature functionality, but it also offers document conversion features, especially for PDF files. It is best suited for businesses that require document signing and conversion in a secure environment.
Key Features
Convert documents to and from PDF. Electronic signatures for legal agreements. Cloud-based service for storing and sharing documents. Document tracking and audit trail. High-level security with encryption. Pros
Excellent for legal and business document signing. Highly secure with encryption. Easy integration with other tools. Cons
More focused on eSigning than conversions. Limited free trial period. Pricing can be high for small businesses. Comparison Table:
Tool NameBest ForPlatform(s) SupportedStandout FeaturePricingG2/Capterra RatingAdobe AcrobatProfessionals & EnterprisesWindows, macOSPowerful OCRStarts at $14.99/month4.5/5SmallpdfIndividuals & SMBsWebEasy-to-use interfaceFree / Premium Plan4.4/5Nitro ProEnterprises & BusinessesWindows, macOSAdvanced editing toolsStarts at $159.99/year4.4/5ZamzarOccasional UsersWebLarge file format supportFree / Paid Plans4.0/5Wondershare PDFelementSMBs & ProfessionalsWindows, macOSComprehensive PDF editingStarts at $79.99/year4.3/5PDF Converter UltimateBusinesses with high-volume needsWindowsBatch processingStarts at $29.99/year4.2/5CloudConvertDevelopers & Tech UsersWebAPI integrationFree / Paid Plans4.5/5UniPDFWindows UsersWindowsSimple, free PDF conversionFree4.1/5Online2PDFCasual UsersWebFree and easy to useFree4.0/5DocuSignLegal & EnterpriseWeb, iOS, AndroidE-signature and conversionStarts at $10/month4.6/5 Which Document Conversion Tool is Right for You?
Choosing the right document conversion tool largely depends on your specific needs. Here’s a guide to help you decide:
For businesses or enterprises: Tools like Adobe Acrobat Pro DC, Nitro Pro, or DocuSign are ideal, offering comprehensive features and high-level security. For casual users: Smallpdf, Zamzar, and UniPDF are perfect for quick conversions with an easy-to-use interface. For developers and tech users: CloudConvert is a great choice, offering API integration and support for a wide range of file formats. Conclusion
As digital transformation accelerates, document conversion tools are an essential asset for anyone who deals with various document formats. The tools listed above offer a range of features, from basic conversions to advanced editing, OCR, and e-signatures. By evaluating your needs—whether you’re an individual, small business, or large enterprise—you can select the best tool that fits your document conversion requirements. In 2026, these tools will continue to evolve, offering more seamless integrations, better accuracy, and enhanced security features to keep up with the growing demand for efficient document handling.
FAQs
1. What is the best document conversion tool for OCR?
Adobe Acrobat Pro DC and Wondershare PDFelement are excellent tools for OCR, offering high accuracy in converting scanned documents.
2. Can I use these tools for free?
Many tools, like Smallpdf and Zamzar, offer free versions with basic features. For advanced capabilities, paid plans are available.
3. Are these tools secure?
Yes, most of these tools use SSL encryption and offer password protection for secure document conversions.
View the full article
- 0 comments
- 59 views
-
Enterprises now sit directly in the adversary’s collection path. They don’t have to be the target; they are on the board and in play because they ride on the same infrastructure the adversary is already exploiting. The CISO’s challenge is to ensure their organization doesn’t become an intelligence channel for someone else simply by virtue of how it connects to the world.
Convergence
Two unrelated campaigns are now intersecting across the same operational dependencies.
The overlap is not coordination; it’s the predictable byproduct of how modern infrastructure centralizes access. When everything routes through a handful of shared services, shared identity layers, and shared connectivity providers, the adversary doesn’t need to coordinate. They simply arrive through the same door.
The targeted collection surfaces are well understood: telecom routing, cloud adjacency, managed service channels, and identity federation. These are the connective tissues enterprises rely on to function. They are also the connective tissues adversaries exploit to monitor authentication, siphon data, and maintain long‑term access without ever touching the enterprise directly.
When actors with different missions arrive through the same dependencies, it signals a structural exposure problem. Because these dependencies are shared and unavoidable, the issue is not the individual campaign. It’s the architecture that allows both campaigns to operate upstream of the enterprise with minimal friction and maximum persistence.
Commercial spyware as an intelligence channel
Criminal operators deploying Predator, a spyware suite sold by the sanctioned Intellexa consortium, have been documented across more than a dozen countries. US sanctions haven’t slowed them down an iota. Their targets are not random: journalists, activists, politicians, human‑rights defenders, government employees and contractors, and other high‑value individuals. Why? These targets have access to information of value that extends well beyond the device. I’ve long posited that criminal entities operate with two goals in mind: enhance capability or monetize information.
The maturation of tradecraft we are seeing today follows the logical arc of the past decade. These include one‑click links, zero‑click exploit chains, network injection in some cases, and persistent device access. Predator is not a commodity tool. Predator is one of several device‑level compromises that become enterprise‑level exposures. It is a commercial espionage platform sold to governments or their proxies, and once deployed, it creates upstream surveillance capabilities that intersect directly with enterprise data flows, authentication systems, and service‑provider networks.
This is why it matters. These tools don’t just compromise individuals. They compromise the systems those individuals authenticate into, the networks they traverse, and the service providers that carry their traffic. They operate in the same shared dependencies enterprises rely on. The enterprise becomes part of the collection surface whether it wants to or not.
State‑aligned exploitation
In February 2026, Singapore disclosed that UNC3886, a sophisticated cyber‑espionage group, had penetrated the networks of all four major telcos servicing Singapore: Singtel, StarHub, M1, and Simba. The threat actors used zero‑days, rootkits, and advanced persistence techniques to gain long‑term access to backbone infrastructure and technical/network data.
Think about that for a moment: all four telcos with their infrastructure compromised. These companies serve as part of the country’s national infrastructure, supporting government, enterprise, and individuals alike. When a telco becomes a real‑time signals‑intelligence collection point, the adversary doesn’t need to break into your environment directly. They can collect from the pathways your environment depends on.
Singapore named the group but not the sponsor. Most external analysis immediately called UNC3886 China‑nexus. Palo Alto Networks Unit 42’s parallel “Shadow Campaigns” report on TGR‑STA‑1030 (UNC6619) used similar cautious language: a “state‑aligned group that operates out of Asia.”
The point is not attribution. The point is that the access was upstream, persistent, and structurally embedded. Regardless of point of origin, the CISO’s focus remains the same: Keep these actors from taking up residence in the infrastructure your organization and your clients depend on. The data‑protection problem is now structural. The collection is permanent. The access is embedded.
What does this mean for CISOs
The operational implications are not theoretical. They are immediate and measurable.
Reevaluate exposure through the lens of shared dependencies, not just internal assets. Your environment is only one part of the attack surface. The dependencies you ride on are also collection points. Strengthen visibility across telecom, cloud, MSP/MSSP, and identity pathways. If you cannot see upstream, you cannot defend downstream. Treat upstream and downstream partners as active components of your threat surface. The adversary already does. Your governance model should reflect the same reality. Demand attestation from telecom and cloud providers. If your upstream providers cannot demonstrate integrity, you inherit their exposure. Reduce implicit trust in upstream pathways. Assume compromise in the infrastructure you do not control. Harden the session layer. Device‑level compromise and upstream compromise both lead to the same outcome: the adversary can impersonate your users and collapse your identity layer. Assume token theft, assume impersonation, and design authentication flows that degrade safely under compromise. In other words, design so that if the adversary gets in, they can’t go far. Shift detection toward low‑noise, long‑term access patterns typical of intelligence‑driven operations. These actors are not loud. They are patient, persistent, and structurally embedded. Recognize the insurance implications. The Singapore telco breaches are the tipping point. Cyber insurers are now explicitly factoring in the risk of permanent APT residency in backbone infrastructure. Expect materially higher premiums, broader exclusions, and the genuine possibility that organizations riding unvetted telco or cloud providers could become uninsurable at renewal. Integrate intelligence‑driven risk assessments into routine governance and architectural decisions. This is no longer a “nice to have.” It is a requirement for operating in an environment where upstream compromise is the norm, not the exception. Strategic reality
Commercial (criminal) and state‑linked actors are moving through the same dependencies modern organizations rely on, and that overlap is now a defining feature of the operating environment.
These campaigns are not anomalies. CISOs should see these as a fortuitous heads-ups. The question for CISOs is no longer whether adversaries will target their environment directly. The question is whether the infrastructure they depend on has already been turned into an intelligence platform for someone else and whether they would even know if it had.
View the full article
- 0 comments
- 38 views
-
- 0 comments
- 37 views
-
- 0 comments
- 43 views
-
Foto: ne2pi – shutterstock.com
Identität wird zum neuen Perimeter: Unternehmen verlassen sich immer seltener auf die traditionelle Perimeter-Verteidigung und forcieren den Umstieg auf Zero-Trust-Umgebungen. Sicherer Zugriff und Identity Management bilden die Grundlage jeder Cybersicherheitsstrategie. Gleichzeitig sorgt die Art und Weise, wie sich Menschen, Anwendungen und Systeme anmelden und miteinander vernetzt sind, auch dafür, dass sich neue, sichtbare Touchpoints für Business-Stakeholder herausbilden.
Die Sicherheitsexperten bewegen sich dabei auf einem schmalen Grat zwischen Benutzerfreundlichkeit und Security: Laxe Kontrollen und Authentifizierungsmechanismen machen Unternehmen angreifbar – zu strenge Kontrollmaßnahmen stören den Geschäftsfluss.
IAM-Tools im Wandel
Die gute – und gleichzeitig schlechte – Nachricht für Unternehmen, die im Bereich Identity & Access Management (IAM) tätig werden wollen: In Sachen Tools zeigt sich dieser Sektor inzwischen differenzierter und leistungsfähiger als je zuvor. IAM-Tools können die Komplexität verschiedener Aufgaben inzwischen deutlich reduzieren. Zum Beispiel wenn es darum geht:
Identitäten in hybriden und Multi-Cloud-Umgebungen zu managen,
privilegierte Konten zu kontrollieren,
Login-Muster zu analysieren,
auf Grundlage von Risikofaktoren zu authentifizieren oder
Provisioning und andere Elemente des Benutzerlebenszyklus zu automatisieren.
“Egal, ob es um fortschrittliche Analysen der Prozesse, die Integration mit Cloud-Service-Providern für ein verbessertes Workload-Management geht oder darum, die Benutzererfahrung per KI zu vereinheitlichen – den Unternehmen bieten sich heute so viele Funktionalitäten wie nie zuvor, um robuste IAM-Initiativen aufzubauen”, meint Naresh Persaud, Managing Director bei Deloitte.
Diese Entwicklung habe dazu geführt, dass sich viele kleine Teilmärkte gebildet haben – auf denen sich teils eigenständige Produkte und teils Features, die Teil einer breiteren Plattform sind, tummelten. Da sich die Anbieter in diesem Bereich rasch annäherten, sei zu erwarten, dass diese sich in hohem Maß gegenseitig befruchten und übergreifende Funktionalitäten entstehen. Kurz gesagt: Es gibt eine Vielzahl von Optionen, die in eine IAM-Analyse-Paralyse führen können.
“Einige Anbieter konzentrieren sich ausschließlich auf Identity Governance und Administration (IGA), andere auf Privileged Access Management (PAM) – beides sind kritische Elemente eines effektiven Identity-Programms. Der Bereich Authentifizierung ist wahrscheinlich derjenige mit der größten Produktvielfalt, wobei viele Anbieter in der Branche Lösungen im Bereich Multi-Faktor-Authentifizierung (MFA) anbieten”, erklärt JR Cunningham, CSO beim Managed Service Provider Nuspire. “Deshalb ist es für Unternehmen essenziell, seine aktuellen Fähigkeiten und Anforderungen zu definieren, um sicherzustellen, dass die gewählten Produkte, diese auch erfüllen.”
Empfehlenswerte Identity & Access Management Tools
Im folgenden Absatz haben wir einige der besten Anbieter im Bereich IAM für Sie zusammengestellt – dabei haben wir Einschätzungen der Analystenhäuser Gartner und Forrester einfließen lassen. Diese Identity-und-Access-Management-Anbieter und -Tools sollten CISOs auf dem Zettel haben.
Avatier
Das Unternehmen Avatier blickt auf eine lange Geschichte im Bereich ITSM und Helpdesk zurück. Seine Identity-Governance-and-Administration (IGA)-Plattform basiert auf automatisierter Benutzerbereitstellung und Passwort-Management. Zuletzt hat der Anbieter massiv in die Modernisierung seines Portfolios investiert: Die Identity-Anwhere-Plattform ist eine containerisierte Lösung, die wahlweise auch in der Cloud gehostet werden kann. Inzwischen unterstützt sie auch passwortlose Authentifizierung per SSO und bietet einen universelle User Experience – auch über Collaboration-Plattformen wie Slack, Microsoft Teams oder ServiceNow.
Die IAM-Plattform von Avatier verfügt über Konnektoren zu mehr als 90 Unternehmens- und 5.000 Cloud-Anwendungen und -Plattformen sowie über einen generischen Low-Code/No-Code-Konnektor für individuelle Integrationen. Diese Plattform fliegt oft unter dem Radar der Analysten, da sie im Vergleich zu den Marktführern (in Forrester Wave und Gartners Magic Quadrant) als erschwinglichere Lösung positioniert ist.
BeyondTrust
Eine feste Größe in der Privileged-Access-Management (PAM) -Nische, hat BeyondTrust die Fähigkeiten und Funktionen seiner Plattform kontinuierlich ausgebaut. Neben PAM bietet die Plattform zentrales Management für Remote-Zugriffe sowie Endpoint Privilege Management für Windows und Mac – und über die “Active Directory Bridge”-Technologie auch für Unix und Linux.
Darüber hinaus hat der Anbieter mit seiner “Cloud Privilege Broker”-Technologie (Berechtigungsmanagement in Multi-Cloud-Umgebungen) nun auch im Bereich Cloud Infrastructure Entitlement Management (CIEM) Fuß gefasst – einem PAM-Ableger. Laut den Analysten von Gartner weist BeyondTrust einen starken Bezug zur Compliance- und Audit-Welt auf – ein Unterscheidungsmerkmal liegt dabei in den Reporting- und Visualisierungsfunktionen. Erweiterte Analysefähigkeiten können die Anwender über das Paket “BeyondInsight” zubuchen. Allerdings warnen die Auguren potenzielle Kunden hinsichtlich der Integrationsmöglichkeiten – sowohl bezogen auf externe Lösungen als auch auf sich überschneidende Funktionalitäten sei das der Schwachpunkt von BeyondTrust.
CyberArk
Laut Forrester Research ist CyberArk (nach Umsatz) der größte PAM-Anbieter und verbindet Privileged Access Management mit Identity-as-a-Service (IDaaS). Mit der Übernahme von Idaptive konnte CyberArk im Jahr 2020 seine SaaS-Kompetenz entscheidend ausbauen: Seitdem gehören SSO, MFA und Customer-Identity-Management-Funktionen genauso zum Programm wie Passwordless- und Self-Service-Optionen für das Account Management. Darüber hinaus bietet die Cyberark-Lösung auch leistungsstarke Analysefunktionen, die ausgereiftere Programme mit Security-Metriken füttern können. CyberArk bietet auch Risk-Based Authentication (RBA), die Administratoren entsprechend ihrer Bedürfnisse granular abstimmen können. Das Ganze kostet allerdings: Laut Gartner können die Preise für einige Anwendungsfälle im Bereich Workforce weit über dem Durchschnitt liegen.
CyberArk bietet – etwa für Multi-Cloud-Umgebungen – über seinen “Cloud Entitlements Manager” auch ausgereifte CIEM-Funktionen, einschließlich der Risikobewertung von Berechtigungen. An der IDaaS-Front ist CyberArk laut Forrester eine ernstzunehmende Alternative für alle, “einen risikobasierten Ansatz auf IDaaS” anwenden wollen und diesen mit Privilege-Management-Funktionen anreichen möchten. Auf der anderen Seite warnen die Analysten vor Performance-Problemen und verweisen dabei auf Service-Degradation-Vorfälle. Zudem fehle bislang der Nachweis über die Skalierbarkeit des Produkts.
Microsoft Entra ID
Geht es nach Forrester, spielt Microsoft mit Entra ID (ehemals Azure Active Directory), das mit über 300.000 zahlenden Kunden die größte IDaaS-Installationsbasis aufweist, im Identity-and-Access-Management-Bereich ganze vorne mit. Gartner führt das rasante Wachstum von Entra ID vor allem darauf zurück, dass das Produkt im Jahr 2020 mit Microsoft 365 und Microsoft Enterprise Mobility and Security (EMS) gekoppelt wurde, wodurch sich die Installationsbasis verdoppelt hat. Das Hauptaugenmerk von Entra ID liegt auf Workforce IAM, insbesondere in Microsoft-lastigen IT-Umgebungen. Die Übernahme von CloudKnox Security im Jahr 2021 hat für zusätzliche PAM- und IGA-Features gesorgt.
Okta
Trotz einer im März 2022 bekannt gewordenen Datenpanne bleibt Okta eine der renommiertesten Optionen in Sachen Identity & Access Management. Schon seit seiner Gründung im Jahr 2009 ist das Unternehmen Cloud-zentriert – zu einer Zeit, als Cloud-Implementierungen in vielen Unternehmen noch eine Randerscheinung waren. Oktas SaaS-Plattform bietet eine ganze Reihe von gebündelten oder eigenständigen Funktionen, die in hybriden und komplexen Multi-Cloud-Umgebungen funktionieren, darunter SSO, MFA, API-Zugriffsmanagement, Lifecycle- und User Management, sowie Identity Automation und Workflow-Orchestrierung.
Der IAM-Anbieter verfügt über eines der robustesten API- und Konnektor-Ökosysteme auf dem Markt und hat sich durch die Übernahme von Auth0 im vergangenen Jahr einen festen Platz im Bereich Customer IAM erobert. Mit der Veröffentlichung von “Okta Privileged Access” hat das Unternehmen 2021 seine Fühler auch in Richtung PAM ausgestreckt. Die Innovationen müssen die Anwender allerdings auch teuer bezahlen: Laut Gartner sind die hohen Kosten der Okta-Lösung bei seinen Kunden “immer wieder” ein Thema.
One Identity
Vor der Übernahme von OneLogin (Anbieter reiner IDaaS-Lösungen) im Jahr 2021 war One Identity ein PAM- und IGA-Anbieter, der stark in der On-Premises-IAM-Welt verwurzelt war.
Laut Forrester hat der Deal das Unternehmen den Einstieg ins IDaaS-Geschäft ermöglicht. Dabei unterscheide sich One Identity von anderen Anbietern insbesondere durch native PAM- und IGA-Funktionen. Allerdings ist es noch zu früh, um abzuschätzen, wie gut das Unternehmen die OneLogin-Technologie integrieren und die Stärken beider Seiten miteinander kombinieren kann. Auch ist nicht klar, was der Zusammenschluss für die Preisgestaltung von OneLogin und den bisherigen Fokus auf kleinere Unternehmen bedeutet.
Ping Identity
Dieser Anbieter adressiert Unternehmen mit komplexen, hybriden Umgebungen und bildet mit der Kombination von Ping One (IDaaS-Plattform) und PingFederate (föderiertes SSO) eine Brücke zwischen SaaS und lokalem IAM. Zusätzlich zu den Standard-IAM-Funktionen für Mitarbeiter und Kunden (SSO, MFA, Cloud-Identitity-Funktionen) bietet die IDaaS-Plattform dank einiger Übernahmen intwische auch dezentrale Identity-Features. Darüber hinaus bereichert ein Low-Code-Flow-Designer die PingOne-Plattform – und auch Analysen (einschließlich API-Transparenz) und eine optimierteRBA gehören zum Paket.
Dabei handelt es sich allerdings nicht um eine vollständige IAM-Plattform aus einer Hand: Wie Gartner erklärt, bietet die Lösung von Ping Identity nur wenige Funktionen für das Identity Management, was es für kleinere Unternehmen oder solche, die eingebettete IGA- oder PAM-Funktionen suchen, weniger attraktiv macht. Anfang 2023 wurde das Identitäts-Angebot von Forgerock Teil von Ping Identity.
SailPoint
SailPoint gehört auf dem IGA-Markt zu den Marktführern und richtet sich an verteilte Unternehmen mit komplexen IT-Umgebungen, die ausgefeilte Automatisierungs- und Integrationsfunktionen benötigen.
Laut Forrester schneidet die SailPoint-Plattform in den Bereichen User Lifecycle Management, Compliance Management und Integration am besten ab. SailPoint ist bestrebt, sein SaaS-Angebot auszubauen, um den sich ändernden Kundenbedürfnissen gerecht zu werden und genießt einen sehr guten Ruf bei den Kunden: Im Rahmen von Gartners Peer Insights Customers’ Choice 2021 wurde das Unternehmen zu einem der besten IGA-Anbieter gewählt. (fm)
View the full article
- 0 comments
- 46 views
-
Image: Shutterstock, @Elzicon.
The Justice Department said the Department of Defense Office of Inspector General’s (DoDIG) Defense Criminal Investigative Service (DCIS) executed seizure warrants targeting multiple U.S.-registered domains, virtual servers, and other infrastructure involved in DDoS attacks against Internet addresses owned by the DoD.
The government alleges the unnamed people in control of the four botnets used their crime machines to launch hundreds of thousands of DDoS attacks, often demanding extortion payments from victims. Some victims reported tens of thousands of dollars in losses and remediation expenses.
The oldest of the botnets — Aisuru — issued more than 200,000 attacks commands, while JackSkid hurled at least 90,000 attacks. Kimwolf issued more than 25,000 attack commands, the government said, while Mossad was blamed for roughy 1,000 digital sieges.
The DOJ said the law enforcement action was designed to prevent further infection to victim devices and to limit or eliminate the ability of the botnets to launch future attacks. The case is being investigated by the DCIS with help from the FBI’s field office in Anchorage, Alaska, and the DOJ’s statement credits nearly two dozen technology companies with assisting in the operation.
“By working closely with DCIS and our international law enforcement partners, we collectively identified and disrupted criminal infrastructure used to carry out large-scale DDoS attacks,” said Special Agent in Charge Rebecca Day of the FBI Anchorage Field Office.
Aisuru emerged in late 2024, and by mid-2025 it was launching record-breaking DDoS attacks as it rapidly infected new IoT devices. In October 2025, Aisuru was used to seed Kimwolf, an Aisuru variant which introduced a novel spreading mechanism that allowed the botnet to infect devices hidden behind the protection of the user’s internal network.
On January 2, 2026, the security firm Synthient publicly disclosed the vulnerability Kimwolf was using to propagate so quickly. That disclosure helped curtail Kimwolf’s spread somewhat, but since then several other IoT botnets have emerged that effectively copy Kimwolf’s spreading methods while competing for the same pool of vulnerable devices. According to the DOJ, the JackSkid botnet also sought out systems on internal networks just like Kimwolf.
The DOJ said its disruption of the four botnets coincided with “law enforcement actions” conducted in Canada and Germany targeting individuals who allegedly operated those botnets, although no further details were available on the suspected operators.
In late February, KrebsOnSecurity identified a 22-year-old Canadian man as a core operator of the Kimwolf botnet. Multiple sources familiar with the investigation told KrebsOnSecurity the other prime suspect is a 15-year-old living in Germany.
View the full article
- 0 comments
- 44 views
-
The warning from the US Cybersecurity and Infrastructure Security Agency (CISA) is principally for organizations using Microsoft Intune, a cloud-based unified endpoint management (UEM) service that Handala, known for multiple destructive wiping, data theft and data leak attacks, was reportedly able to compromise. But CISA said the defensive principles of its recommendations can be applied to any endpoint management software.
Top issue: phishing resistance
The CISA advice is certainly “timely and appropriate,” said Johannes Ullrich, dean of research at the SANS Institute. “In my opinion, the top issue is implementing phishing-resistant authentication” to protect logins.
“This problem goes beyond the specific issue of mobile device management and is something IT leaders need to prioritize,” he pointed out. “While multi-factor authentication does solve many problems, not all MFA technologies are phishing-resistant. In particular, for cloud-based solutions, which are usually accessible to everybody, solid phishing-resistant authentication is a must-have.”
Organizations must also be careful when enrolling personal devices into corporate-managed endpoint solutions, he added. Only company-owned devices should be enrolled, to avoid disrupting personal devices, and enrolled devices should be dedicated to company business.
Hardening endpoint management systems
CISA advises IT leaders to:
use principles of least privilege access when designing administrative roles for endpoint management systems. For Intune systems, there is role-based access control limiting what actions a role can take, what users the actions are applied to, and which devices are covered; enforce phishing-resistant multi-factor authentication (MFA) and privileged access hygiene. Intune users and others can take advantage of Microsoft Entra ID capabilities including conditional access, MFA, risk signals, and privileged access controls to block unauthorized access to Intune; configure access policies to require multi-admin approval for accessing and making changes to endpoint management systems. CISA also points Intune admins to these Microsoft documents: Best practices for securing Microsoft Intune; Use Access policies to implement Multi Admin Approval, Configure Microsoft Intune for increased security; Role-based access control (RBAC) with Microsoft Intune and Plan a Privileged Identity Management deployment.
Michael Smith, field CTO at DigiCert, noted that while the CISA warning applies specifically to Microsoft Intune, there are many similar products that run as an administrator on endpoints. These need escalated privileges because they make changes on the endpoint, which makes them powerful tools for IT. However, he added, that also makes them a target. Any compromise of these products could lead to compromise of the endpoints they manage.
The power to create ‘irreversible damage’
Stryker said the March 11 attack caused disruption to its order processing, manufacturing and shipping. However, Handala claims it was also able to remotely wipe thousands of employee devices.
In a March 15 update Stryker said all connected, digital and life-saving technologies used by customers remain safe to use. “This event was contained to Stryker’s internal Microsoft environment, and as a result it did not affect any of our products—connected or otherwise,” the statement said. No ransomware or malware was deployed, the company added.
In the Stryker incident, attackers hijacked a tool that companies trust every day, and used it to shut down operations on a global scale, commented Ismael Valenzuela, vice-president of threat intelligence at Arctic Wolf. “By abusing Microsoft Intune, they were able to remotely wipe more than 200,000 devices across 79 countries. The lesson is clear: no single login should ever have the power to cause irreversible damage,” he said.
“Destructive administrative operations like device wipes, mass policy changes, or tenant‑wide updates must require multiple approvals,” he added. “No one session, credential, or role should be able to take destructive action at scale without independent authorization. Organizations should immediately lock down endpoint management tools by tightly limiting admin access, enforcing multi‑party approvals, and continuously monitoring privileged activity so trusted platforms don’t become single points of failure.”
Endpoint management a high-value target
Robert Beggs, head of Canadian incident response firm Digital Defence, said endpoint management systems have always been high-value targets because they are universally trusted and push configurations, scripts, and remote actions across an entire IT network.
“Although the Stryker incident speaks to exploits of the Microsoft Intune application, similar products have been targeted in the past, including SolarWinds Orion (2020), Kaseya VSA (2021), and the Microsoft Exchange management interface (2021),” he pointed out. “All of these attacks demonstrate that malicious actors recognize the value of attacking controls with the keys to the kingdom, rather than going after individual systems.”
He said that the following defenses against this kind of attack are frequently cited by experts: Employ least-privilege access and dual approval for major actions, ensure that strong identity controls are in place, employ micro segmentation and monitor for unusual administrative actions.
Monitoring for administrative activity is especially critical with these types of attacks, Beggs added “Look for activities such as admin actions after hours, or from unusual locations or IP addresses,” he said. “Validate the creation of new admin roles or elevated privileges. And baseline normal admin activities so that you can identify admins performing tasks that they usually don’t do.”
Because endpoint management systems can push changes to thousands of devices at once, an unexpected script deployment could create new configuration profiles or execute unexpected actions to disable defenses or deploy malicious content, he noted. Signs of compromise include disabling of MFA, removal of security controls, removal of monitoring tools, changes to network access controls, and altered logging settings.
“The most important question is, how quickly can you identify these actions,” he said, “and are you prepared to recover?”
Two Handala sites seized
On Thursday, researchers at Flashpoint confirmed that the FBI had seized two Handala websites used for propaganda and releasing stolen data. One site now carries a statement saying the domain had been seized under a US court order. Flashpoint believes Handala is associated with the Iranian regime, and is not an independent actor.
View the full article
- 0 comments
- 48 views
-
Perplexity suggests that the feature is useful for aggregating health data from across different portals, apps, and devices. It is able to track metrics and trends over time across biomarkers, with information shown on a personalized dashboard.
When asked a health-related question, Perplexity Health can answer based on medical records, lab results, and wearable data. With Perplexity Computer (Perplexity's AI agent tool), AI agents can use health information to build personalized fitness plans, nutrition plans, and more. Perplexity Health on Computer is rolling out to Pro and Max users in the U.S. first.
Perplexity says that Perplexity Health draws from "premium medical literature" like clinical guidelines and peer-reviewed journals. Perplexity has established a Perplexity Health Advisory Board with physicians, researchers, and health tech experts who will "pressure-test" product decisions, content quality, and clinical safeguards against evidence-based medicine standards.
Perplexity Health is able to connect to Apple Health, so it can integrate data collected by the Apple Watch and added to the Apple Health app. It also supports Fitbit, Ultrahuman, and Withings, along with electronic health records from more than 1.7 million care providers. Oura and Function integrations are coming soon.
Health data is encrypted, and Perplexity says there are strict access controls and tools to manage or delete information at any time. Health information is not used to train AI models or sold to third parties.
Perplexity is the second AI company to integrate with Apple Health. OpenAI introduced a ChatGPT Health feature with Apple Health support in early 2026.Tags: Apple Health, Perplexity
This article, "Perplexity Can Now Access Your Apple Health Data to Answer Medical Questions" first appeared on MacRumors.com
Discuss this article in our forums
View the full article
- 0 comments
- 42 views
-
KVM-over-IP devices enable users to control computers remotely as if they were physically present, with full keyboard, video, and mouse access, including at the BIOS level when the OS is not running. Enterprises have long relied on rack-mounted multi-port KVM switches that include security features such as multi-factor authentication, encryption, and logging but cost hundreds or thousands of dollars.
In recent times, smaller businesses and IT teams operating on tight budgets have increasingly turned to a new class of compact, Linux-based, single-port KVM devices that offer the same access at a fraction of the cost. However, the quality of their firmware and access controls are not nearly as strong.
Researchers from security firm Eclypsium analyzed several of these cheap models in recent months and found lack of brute-force protections for authentication, insecure firmware update mechanisms, exposed debugging interfaces, and unauthenticated vulnerabilities that can lead to full device takeover.
The number of such devices exposed directly to the internet has grown from a few hundred less than a year ago to over 1,600, according to Eclypsium. That might not sound like a big number, but users of these devices range from small IT shops and MSPs to enterprises that span many industry verticals.
“Enterprise data centers and colocation facilities use IP-KVMs for remote server management,” the Eclypsium researchers said. “Industrial and OT environments deploy them to manage HMI machines in hazardous zones. Healthcare facilities use them for systems in imaging suites and research labs that cannot be easily rebooted. Government and defense installations rely on them for mission-critical servers where physical access requires escorts and approvals.”
Basic oversights
The nine vulnerabilities impact devices from GL-iNet, Angeet/Yeeso, Sipeed, and JetKVM.
The most severe flaw, with a 9.8 CVSS, was found in the Angeet/Yeeso ES3 KVM and allows any attacker with network access to write arbitrary files to the device via an unprotected upload endpoint. Chained with a separate command injection flaw, it creates the premise for pre-authentication remote code execution with root privileges. Angeet has committed to fixing the flaws but has not provided a timeline to Eclypsium.
The GL-iNet Comet RM-1 has four vulnerabilities, including a lack of brute-force protection for authentication and insecure connection during provisioning. The device also uses the easy-to-crack MD5 hash function for its firmware update mechanism and no cryptographic signature. As a result, attackers could potentially create backdoored firmware images that the device would accept.
Separately, the device’s UART serial interface provides unauthenticated root access to anyone with physical access to the device. GL-iNet has issued partial fixes in a beta release but has no planned fix for firmware signing or UART authentication.
JetKVM, one of the most popular devices in the low-cost KVM segment, also used an over-the-air (OTA) update mechanism that relied on SHA-256 hashes without cryptographic signatures and no brute-force protection on its single-password login. Both flaws have been patched.
Sipeed’s NanoKVM had an unauthenticated WiFi configuration endpoint that could be exploited to hijack the device’s network connection. The flaw has now been patched.
“These are not exotic zero-days requiring months of reverse engineering,” the Eclypsium researchers said. “These are fundamental security controls that any networked device should implement: Input validation, authentication, cryptographic verification, rate limiting. We are looking at the same class of failures that plagued early IoT devices a decade ago, but now on a device class that provides the equivalent of physical access to everything it connects to.”
Stealthy backdoors
A compromised KVM device can become a powerful backdoor in any environment. An attacker can inject keystrokes to execute commands or access UEFI settings to disable security features such as disk encryption and Secure Boot.
Because the device operates outside the controlled system’s OS, endpoint detection tools and host firewalls cannot see it. These devices run their own Linux-based firmware, allowing attackers to hide malware and re-infect connected systems even after disk wipes.
“Compromising a KVM device gives an attacker the equivalent of physical access to every machine connected to it,” the Eclypsium researchers warned. “Not ‘kind of like’ physical access. Actual keyboard, video, and mouse control, at the BIOS level, below the operating system, below EDR, below every security control you have deployed.”
North Korean spies posing as remote workers have used PiKVM devices connected to laptops and workstations provided to them by employers to fake their physical presence in different countries and gain access to corporate networks.
Enterprise-grade KVM switches are not immune to vulnerabilities either. ATEN, one of the leading vendors, patched critical buffer overflow vulnerabilities in some of its products last year. Baseband Management Controller (BMC) interfaces, another type of out-of-band management technology that is common in server products, have been plagued by vulnerabilities for years and some were even exploited to deploy rootkits.
Eclypsium advises organizations to isolate KVM devices on dedicated management VLANs, never expose them directly to the internet, deploy two-factor authentication when available, and use VPN solutions to access them. Companies should also audit their networks for KVM devices that they might not be aware of and deploy firmware updates when available.
“Audit your KVM deployments,” the researchers wrote. “Know what you have, where it is, and what firmware it is running. These devices are the keys to your kingdom, and right now, too many of them are hanging on the network with the door wide open.”
View the full article
- 0 comments
- 35 views
-
The $1,250 Paddock Solo Charger is a magnetic charger that works with a single device, while the $1,750 Paddock Duo can charge an Apple Watch and iPhone at the same time. The $1,750 Paddock Yoyo is also a dual charger, but it has a USB-C cable that wraps around the charger for travel purposes.
Hermès also has bundles that pair the chargers with a Grand Paddock or Petit Paddock case, with prices ranging from $3,725 to $5,150.
Each of the charging products has an H logo over the magnetic charging spot for alignment purposes, and they've been "meticulously encased in Swift calfskin" with saddle stitching.
While these chargers cost thousands of dollars, Hermès took a cue from Apple and did not bundle them with a power adapter. Each charger requires a 20W or higher power adapter, but the company does throw in a free 3.3-foot USB-C cable. Apple stopped offering power adapters starting in 2020.
Hermès is a longtime Apple partner, and has designed Apple Watch bands to be sold with the Hermès-branded Apple Watch models since 2015.
Apple sells Hermès Apple Watch models and bands, but it is not offering the new Hermès chargers.Tags: Apple Watch Hermès, MagSafe
This article, "Hermès Now Sells $1,250+ MagSafe Chargers Wrapped in Calfskin Leather" first appeared on MacRumors.com
Discuss this article in our forums
View the full article
- 0 comments
- 38 views
-
After Apple was found to have violated Masimo's patents related to blood oxygen sensing, the Apple Watch faced a U.S. import ban that caused Apple to briefly pause sales of the device in December 2023 before Apple earned a temporary stay. Apple disabled blood oxygen sensing in January 2024, and was able to resume selling the Apple Watch without the functionality.
In August 2025, Apple found a workaround and was able to bring blood oxygen sensing back to U.S. Apple Watch owners. Data is collected by the blood oxygen sensor on the Apple Watch, but it is processed on a paired iPhone rather than the watch itself, and the resulting information can only be viewed on the iPhone. Apple said the updated process did not violate the ITC ban, or infringe on Masimo's patents, and it was cleared by U.S. Customs and Border Protection (CBP).
Masimo did not agree with the decision and it quickly filed a lawsuit against CBP, accusing the agency of acting unlawfully and exceeding its authority. Masimo also pushed the ITC to look into whether Apple's solution violated the original import ban.
The ITC ended up siding with Apple, and said that Apple's workaround does not violate Masimo patents. Since today's decision is preliminary, the full commission will need to affirm the ruling.
Though Apple scored a win with the ITC, Masimo came out ahead in a separate appeals ruling today. The U.S. Court of Appeals for the Federal Circuit affirmed the original 2023 ITC decision that led to the Apple Watch import ban. The appeals court said that the Apple Watch did indeed infringe on Masimo's patents, and it declined to overturn the ban.
Apple said that it would continue to investigate "all avenues for further review" in light of the appeals court decision.
In November 2025, Apple also lost the patent infringement lawsuit that Masimo filed against it. A federal jury awarded Masimo $634 million, which Apple is appealing.Related Roundup: Apple Watch 11Tags: Apple Lawsuits, Masimo, Patent LawsuitsBuyer's Guide: Apple Watch (Neutral)
This article, "ITC Judge Rules Apple Watch Blood Oxygen Workaround Does Not Infringe Masimo Patents" first appeared on MacRumors.com
Discuss this article in our forums
View the full article
- 0 comments
- 37 views
-
Google competitors like Anthropic and OpenAI have dedicated Mac apps for their chatbots, potentially making Claude and ChatGPT more convenient to use than Gemini.
Google shared an early version of the Gemini app with beta testers this week to get feedback, but it's not clear when it might launch. Google has not provided release date information for the Gemini Mac app, and testers were told that the app only has "critical features," suggesting there's more to come before release. The app apparently looks similar to the Gemini apps designed for iPhone and iPad.
The app is able to search the web, analyze uploaded documents, and maintain a conversation history. Google is asking users to test content generation tools for images, tables and charts, video, music, and more, plus provide feedback on mathematical questions and information analysis.
Gemini for Mac will be able to integrate with other Mac apps through a Desktop Intelligence feature, mirroring functionality available with tools like Claude Cowork. Gemini will be able to read the Mac's display, using the content to personalize Gemini and allow the AI to complete tasks.
Bloomberg says the Mac Gemini app includes wording about how Desktop Intelligence works. "When you enable apps for Desktop Intelligence you are enabling Gemini to see what you see (such as screen context) and pull content directly from these apps to improve and personalize your experience only when Gemini is in use," reads app code.
With iOS 27 and macOS 27, Apple plans to introduce its own Siri chatbot that will rival Gemini, Claude, and ChatGPT. Apple has partnered with Google, and the Siri chatbot will use an AI model developed by Google. Tags: ChatGPT, Gemini, Google
This article, "Google Working on Native Gemini AI App for Mac to Rival ChatGPT and Claude" first appeared on MacRumors.com
Discuss this article in our forums
View the full article
- 0 comments
- 39 views
-
More interestingly, Long dropped two unique pieces of information.
First, he said shipments of the rumored foldable iPhone will likely begin in December this year, a few months after the iPhone 18 Pro and iPhone 18 Pro Max launch in the usual September timeframe. A similar situation occurred in 2017, with the iPhone 8 and iPhone 8 Plus launching in September, and the iPhone X launching in November.
Second, Long said that Apple plans to release two other devices alongside the iPhone 18 base model in March next year, including a lower-end iPhone 18e and either an iPhone 18 Plus or an iPhone Air 2. Long mentioning the possibility of an iPhone 18 Plus is notable, as we have not heard any other rumors about such a device.
It is unclear if Long mentioning the possibility of an iPhone 18 Plus is simply spitballing, or if it is information that he received from his supply chain contacts. There have been multiple reports about a revamped iPhone Air being in the works for next year, so an iPhone 18 Plus seems quite unlikely for now, but we shall see what happens.
Apple does not break down its iPhone sales on a model-by-model basis, but various reports and research firms have indicated that both the Plus and Air have been unpopular relative to other iPhone models over the years. The return of a Plus model does not seem entirely out of the realm of possibility, if the Air has sold even worse than the Plus, and there is still a chance that the Air model was a one-off release. But, if an iPhone 18 Plus was truly coming next March, we probably would have heard more rumors about it by now.
This is the first time we have heard these claims, so treat them with some skepticism for now.Related Roundups: iPhone 18, iPhone Air, iPhone FoldTags: Barclays, Foldable iPhone, Tim LongBuyer's Guide: iPhone Air (Buy Now)Related Forum: iPhone
This article, "Analyst: Foldable iPhone Likely to Ship in December, iPhone 18 Plus is Possible Next Year" first appeared on MacRumors.com
Discuss this article in our forums
View the full article
- 0 comments
- 43 views
-
Note: MacRumors is an affiliate partner with some of these vendors. When you click a link and make a purchase, we may receive a small payment, which helps us keep the site running.
AirPods Pro 3
What's the deal? Take $49 off AirPods Pro 3
Where can I get it? Amazon
Where can I find the original deal? Right here
$49 OFFAirPods Pro 3 for $199.99
Amazon has the AirPods Pro 3 available for $199.99 this week, down from $249.00. This is a match of the all-time low price on the AirPods Pro 3, which has been rare on Amazon in recent weeks.
M4 iPad Air
What's the deal? Take up to $80 off M4 iPad Air
Where can I get it? Amazon
Where can I find the original deal? Right here
$40 OFF11-inch M4 iPad Air for $559.00
$50 OFF13-inch M4 iPad Air for $749.00
Last week was the launch week for all of Apple's new products, and Amazon is already offering good discounts on many models of the M4 iPad Air, although a few of the prices have risen a bit since we first covered the deals earlier this week. We're still seeing up to $80 off both the 11-inch and 13-inch models, however, which is solid for a brand-new product.
MacBook Air and MacBook Pro
What's the deal? Take $49 off M5 MacBook Air and M5 Pro/M5 Max MacBook Pro
Where can I get it? Amazon
Where can I find the original deal? Right here
$49 OFF13-inch M5 MacBook Air (512GB) for $1,049.99
$49 OFF15-inch M5 MacBook Air (512GB) for $1,249.99
$49 OFF16-inch M5 Pro MacBook Pro (24GB/1TB) for $2,649.99
$49 OFF16-inch M5 Max MacBook Pro (36GB/2TB) for $3,849.99
Similar to the M4 iPad Air, Amazon is offering multiple discounts across the new M5 MacBook Air and M5 Pro/M5 Max MacBook Pro this week. You'll find $49 off select models right now, without the need of a coupon code.
Samsung Monitors
What's the deal? Save on Samsung monitors
Where can I get it? Amazon
Where can I find the original deal? Right here
$300 OFFSamsung Smart Monitor M9 on Amazon
UP TO $1,000 OFFSamsung Monitor Sale
This week, there were two sales on Samsung monitors, split between Amazon and Samsung's own website. On Amazon, there was a big accessory sale this week, and the highlights of the event included big savings on monitors from Samsung, LG, Dell, and more. Samsung's newest Smart Monitor M9 hit the all-time low price of $1,299.99 during the sale, and it's still available now.
On Samsung, you can get a free copy of Resident Evil Requiem with the purchase of select monitors. You'll also find big discounts on TVs and Galaxy products this week.
Apple Watch Series 11
What's the deal? Take $100 off Apple Watch Series 11
Where can I get it? Amazon
Where can I find the original deal? Right here
$100 OFFApple Watch Series 11 (42mm GPS) for $299.00
$100 OFFApple Watch Series 11 (46mm GPS) for $329.00
Amazon this week has all-time low prices on the Apple Watch Series 11, with $100 discounts across numerous models of the smartwatch. We first started tracking the return of these deals last month, but this sale has now expanded with many more options on both 42mm and 46mm GPS models.
If you're on the hunt for more discounts, be sure to visit our Apple Deals roundup where we recap the best Apple-related bargains of the past week.
Deals Newsletter
Interested in hearing more about the best deals you can find in 2026? Sign up for our Deals Newsletter and we'll keep you updated so you don't miss the biggest deals of the season!
Related Roundup: Apple Deals
This article, "Best Apple Deals of the Week: AirPods Pro 3 Hit $199.99 Lowest Price on Amazon" first appeared on MacRumors.com
Discuss this article in our forums
View the full article
- 0 comments
- 29 views
-
- 0 comments
- 32 views
-
- 0 comments
- 40 views
-
Ransomware group exploited Cisco firewall vulnerability as a zero day, weeks before a patch appeared
The vulnerability in question is CVE-2026-20131, a remotely exploitable deserialization flaw in Cisco Secure Firewall Management Center (FMC) Software which was given a maximum 10 CVSS score.
When Cisco released a patch for it on March 4 as part of its semiannual firewall update, security teams would have known this needed to be applied urgently, alongside a fix for a second FMC vulnerability, CVE-2026-20079, with an identical severity rating.
However, Amazon’s discovery that Interlock started exploiting CVE-2026-20131 on January 26, around 38 days prior to the release of the patch, turns the issue from merely ‘urgent’ into something akin to a full-blown zero-day vulnerability patching emergency.
Attacker mistake
Amazon said it started searching for exploitation of CVE-2026-20131 after Cisco’s advisory, using the company’s MadPot global network, a honeypot system comprising thousands of sensors deployed throughout its AWS platform.
This quickly uncovered attacks dated weeks prior to the vulnerability being made public. “Observed activity involved HTTP requests to a specific path in the affected software,” said CJ Moses, CISO for Amazon Integrated Security, in a blog this week.
He added: “This wasn’t just another vulnerability exploit, Interlock had a zero-day in their hands, giving them a week’s head start to compromise organizations before defenders even knew to look.” He later clarified to CSO that the “week’s head start” he referred to was the gap between the date of the first exploit that Amazon’s later analysis had unearthed and Cisco’s discovery of the bug.
Amazon gained insight into the attacker’s infrastructure by using the honeypot to mimic a vulnerable firewall system. This resulted in an attack on the honeypot, which received a malicious binary from the attackers; it also revealed that the ransomware depended on a single server with a poorly-secured staging area.
From this, researchers were able to analyze the group’s full attack chain, including Trojans, reconnaissance scripts, and evasion techniques.
Unlocking Interlock
According to Amazon, the tools and techniques connect the malware to Interlock, a ransomware actor that appeared in 2024, possibly as a ransomware-as-a-service (RaaS) offshoot of the notorious Rhysida group which was behind the hugely disruptive 2023 ransomware attack on The British Library.
“The ELF [Linux executable] binary and associated artifacts are attributable to the Interlock ransomware family based on convergent technical and operational indicators. The embedded ransom note and TOR negotiation portal are consistent with Interlock’s established branding and infrastructure,” said Amazon’s Moses.
In the past, Interlock had targeted sectors such as education, engineering, architecture, construction, manufacturing, and healthcare, as well as government and public sector entities, Moses said.
However, given that the group has been able to exploit a zero-day vulnerability in equipment as prevalent as Cisco firewalls for more than a month, any vulnerable organization might be at risk.
The ‘fundamental challenge’ of zero-day exploits
“The real story here isn’t just about one vulnerability or one ransomware group — it’s about the fundamental challenge zero-day exploits pose to every security model,” said Moses.
“When attackers exploit vulnerabilities before patches exist, even the most diligent patching programs can’t protect you in that critical window. This is precisely why defense in depth is essential.”
It’s still unclear how many victims Interlock might have compromised during the period it was able to exploit CVE-2026-20131 as a zero-day vulnerability, but they are likely to be numerous. The Amazon blog includes a list of IP addresses, malicious domains, and JA3 client fingerprint hashes that security teams can search for in logs as evidence of possible compromise.
The procedure for patching CVE-2026-20131, and the other 47 CVEs included in Cisco’s March 4 update, varies depending on the FMC software version installed. Cisco recommends using its software checker to determine the appropriate update.
View the full article
- 0 comments
- 35 views
-