Skip to content
View in the app

A better way to browse. Learn more.

hosang I.T.

A full-screen app on your home screen with push notifications, badges and more.

To install this app on iOS and iPadOS
  1. Tap the Share icon in Safari
  2. Scroll the menu and tap Add to Home Screen.
  3. Tap Add in the top-right corner.
To install this app on Android
  1. Tap the 3-dot menu (⋮) in the top-right corner of the browser.
  2. Tap Add to Home screen or Install app.
  3. Confirm by tapping Install.

Tech

Tech Articles from a wide variety of topics and categories
Apple today announced a major overhaul of its Apple Intelligence platform, revealing a new architecture built on foundation models developed in collaboration with Google using the technologies behind the Gemini family.


The new architecture centers on Apple Foundation Models co-developed with Google, which Apple says are adapted to run both on-device and on servers through its existing Private Cloud Compute infrastructure. Apple described the collaboration as a "deep" one that it says unlocks what it called a "huge upgrade" for ‌Apple Intelligence‌, bringing state-of-the-art understanding and reasoning capabilities as well as multimodal support including image understanding and generation.

The upgraded models support new capabilities use cases, including realistic image creation, advanced photo editing, and visual question answering. Certain devices will receive a higher-power version of the model with additional capabilities including speech generation, improved dictation accuracy, and stronger natural language understanding, though Apple did not specify which devices qualify.

A new system orchestrator sits at the center of the revised architecture, coordinating ‌Apple Intelligence‌ features securely across Apple's platforms. Apple says the orchestrator allows the system to tailor its responses based on the active app and the user's current task, enabling what the company described as truly system-wide intelligence.

Apple used the announcement to frame its approach as a contrast to competitors it characterized as "racing forward" without regard for users. The company reiterated that ‌Apple Intelligence‌ relies on on-device processing and Private Cloud Compute, with a promise that user data is only used to execute the immediate request and is not accessible to Apple or third parties. Apple added that outside experts can verify those privacy guarantees "at any time."Tags: Apple Intelligence, Google
This article, "Apple Reveals New AI Architecture Built Around Google Gemini Models" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Apple at WWDC 2026 today said it has made several responsiveness improvements across its software ecosystem, speeding up system animations, app launching, and much more.


Apple says that launching iPhone and iPad apps is up to 30 percent faster across devices, while new photos taken on iPhone appear in iCloud Photos up to 70 percent faster.

Elsewhere, sharing files between devices over AirDrop is now up to 80 percent faster and transfers in the Files app are up to 50 percent faster. There's also a new CPU scheduler manager that prioritizes jobs and ensures that the right work is executed on time.

Apple also says that network transitions on its mobile devices have been improved, so that switching between cellular data and Wi-Fi when you're out and about feels a lot more seamless.

More details to follow...Tag: WWDC 2026
This article, "Apple Touts Faster Core Software Features Across Devices" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Apple today announced that AirPods will gain a custom EQ (equalizer) feature, allowing users to further personalize how their AirPods sound.


The new capability is part of Apple's next-generation software platform updates, which the company unveiled today. Custom EQ lets listeners adjust audio output to match their personal preferences, going beyond the fixed audio profiles AirPods have offered previously.

Custom EQ lets you adjust the balance of different sound frequencies, including bass, mids, and treble, to tailor audio output to your personal taste. Boosting the bass makes music feel punchier, for example, while lifting the treble adds more clarity to vocals and instruments.

AirPods already support features such as Adaptive Audio, Personalized Spatial Audio, and Conversation Awareness. Custom EQ adds a further layer of tuning on top of those.Related Roundups: AirPods 4, AirPods Max 2, AirPods Pro 3Tag: WWDC 2026Buyer's Guide: AirPods (Caution), AirPods Max (Buy Now), AirPods Pro (Neutral)Related Forum: AirPods
This article, "Apple to Bring Custom EQ to AirPods" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Apple today announced that it has rebuilt the search infrastructure that powers key features like Spotlight, Photos, and Mail across all of its major next-generation software platforms.


The company says the index has been rearchitected to be more stable, efficient, and comprehensive, covering both old and new content. After updating, the new infrastructure will begin reindexing device content automatically.

New content will be indexed "almost immediately," Apple says, meaning users' files will become searchable much faster than before. After you update, the new search infrastructure goes to work indexing the content of your device.Tag: WWDC 2026
This article, "Apple Rebuilds Search Infrastructure Across Platforms" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
iOS 27 is supported on iPhone 11 and all of the same iPhone models as iOS 26, Apple confirmed today during its WWDC 2026 keynote.


The announcement means that iOS 27 will be compatible with the following iPhone models when it arrives in September:
iPhone 17e
iPhone 17
iPhone 17 Pro & Pro Max
iPhone Air
iPhone 16e
iPhone 16
iPhone 16 Plus
iPhone 16 Pro
iPhone 16 Pro Max
iPhone 15
iPhone 15 Plus
iPhone 15 Pro
iPhone 15 Pro Max
iPhone 14
iPhone 14 Plus

iPhone 14 Pro
iPhone 14 Pro Max
iPhone 13
iPhone 13 mini
iPhone 13 Pro
iPhone 13 Pro Max
iPhone 12
iPhone 12 mini
iPhone 12 Pro
iPhone 12 Pro Max
iPhone 11 Pro
iPhone 11 Pro Max
iPhone 11
iPhone SE (3rd generation)
Apple is also expected to introduce broader Apple Intelligence upgrades that could bring smarter capabilities to apps across the iPhone, iPad, and Mac. Stay tuned for all the details. Related Roundup: iOS 27Tag: WWDC 2026
This article, "iOS 27 Supports iPhone 11 and Newer, Says Apple" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Apple today announced that macOS 27 is named macOS Golden Gate.


macOS Golden Gate has some Liquid Glass design changes. For example, apps now have a unified toolbar at the top, and the sidebar now expands to the edge of the window.

Much like Mac OS X Snow Leopard in 2009, Apple said it focused on improving macOS's performance and dozens of underlying technologies.

More details to follow.Related Roundups: macOS 27, WWDC 2026Related Forum: Apple, Inc and Tech Industry
This article, "Apple Announces macOS Golden Gate" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Apple today announced a series of improvements to Liquid Glass, the translucent design language the company introduced last year.



Apple said it has heard user feedback, which it "deeply appreciates," and is now making adjustments to the underlying foundations of how Liquid Glass is constructed. Chief among those changes is a new slider that lets users control transparency, ranging from fully opaque to completely clear.

Sidebar behavior is also being updated. Sidebars will now expand to the full edge of the window, with refraction effects continuing beneath them rather than cutting off at the sidebar boundary. Sidebar icons will also retain their color, a change that addresses a common complaint about the original Liquid Glass implementation.



Apple also announced updates to its app icon design language. Having redesigned all of its first-party icons last year to create a more consistent look across apps and platforms, the company said it is now taking that work further by incorporating additional layers of Liquid Glass directly into the icon artwork itself.Tags: Liquid Glass, WWDC 2026
This article, "Apple Announces Liquid Glass Improvements and Transparency Slider" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Apple's Beta Software Program website has gone down ahead of the company's WWDC 2026 keynote next hour.

The first developer betas of iOS 27, iPadOS 27, macOS 27, watchOS 27, tvOS 27, and visionOS 27 should be available today, and the first public betas typically follow in July.Related Roundup: WWDC 2026Related Forum: Apple, Inc and Tech Industry
This article, "Apple's Beta Website Says 'We'll Be Back Soon' Just Ahead of WWDC" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Apple's Worldwide Developers Conference (WWDC) starts today with the traditional keynote kicking things off at 10:00 a.m. Pacific Time. MacRumors is on hand for the event and we'll be sharing details and our thoughts throughout the day.


We're expecting to see a number of software-related announcements today, headlined by a reset on Apple's push into AI that should see a significant overhaul for Siri plus quite a few new AI-driven features.

Apple is providing a live video stream on its website, on YouTube, and in the company's TV and Developer apps across its platforms. We will also be updating this article with live blog coverage and issuing Twitter updates through our @MacRumorsLive account as the keynote unfolds. Highlights from the event and separate news stories regarding today's announcements will go out through our @MacRumors account.

Sign up for our newsletter to keep up with Apple news and rumors.

Live Updates - No need to refresh
Loading live updates...



Related Roundups: iOS 27, WWDC 2026Tags: Apple Event, SiriRelated Forum: Apple, Inc and Tech Industry
This article, "WWDC 2026 Apple Event Live Keynote Coverage: iOS 27, Revamped Siri, and More" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Apple's WWDC 2026 begins today, with the event kicking off at 10:00 am Pacific Time via the traditional opening keynote. We know that some MacRumors readers who can't follow the event as it's being broadcast are interested in avoiding all of the announcements and waiting until the event video is available for on-demand viewing so as to experience it without already knowing the outcome.

For those individuals, we've posted this news story, which will be updated with a direct link to the presentation once it becomes available from Apple. No other news stories or announcements will be displayed alongside this story.

Replays of Apple's recent events have been made available to view almost immediately following the conclusion of the broadcasts, and we expect similar timing for today's event. Users waiting for the video to be posted are welcome to gather in the thread associated with this news story, and we ask that those who follow the events as they occur refrain from making any posts about Apple's announcements in this thread.Related Roundup: WWDC 2026Tag: Spoiler-FreeRelated Forum: Apple, Inc and Tech Industry
This article, "WWDC 2026 Spoiler-Free Video Stream" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Ahead of the WWDC 2026 keynote at 10 a.m. Pacific Time today, Apple CEO Tim Cook has shared a short video in which country singer Lainey Wilson, actress Rhea Seehorn, DJ and producer Zedd, and other celebrities say "good morning" in various ways.


"I think I'll say it the way I always say it," concludes Cook.

Apple's hardware engineering chief John Ternus becomes CEO on September 1, so this WWDC will likely be Cook's final event running the company.

Related Roundup: WWDC 2026Tags: Apple Event, Tim CookRelated Forum: Apple, Inc and Tech Industry
This article, "Tim Cook Shares 'Good Morning' Video Ahead of Today's Apple Event" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Apple analyst Ming-Chi Kuo says the real test of today's WWDC keynote is whether Apple can deliver better AI experiences than Google using the same Gemini models.


Apple is using Google's Gemini to underpin the revamped version of Siri and new Apple Intelligence features. The key takeaway from WWDC, Kuo argues in a new post on X, will not be the short-term market reaction after the event. It will be whether Apple, using the same Gemini models, can deliver better AI applications, agentic workflows, and on-device and cloud hybrid experiences than Google.

If the answer is yes, it would help extend Apple's "bull" case. If the answer is no, the implication is that Apple's ceiling is set by a model it does not control. Kuo raised the point arguing against the market sentiment that "Even if Apple is temporarily behind on AI, it will ultimately catch up and come out ahead."

Nevertheless, Kuo believes Apple's business momentum will stay strong through year-end based on his latest supply-chain checks, which he expects observers to spin as "If Apple is doing this well without AI, just imagine once it has AI." Other reports suggest Apple's longer-term advantage could lie in on-device AI, with the company expected to show how its custom silicon lets it process more AI queries directly on the device rather than in the cloud.

Kuo expects today's announcements to have little bearing on the direction of Apple's stock price in the second half of the year. Regardless of what Apple says at WWDC, he argues, the positive second half of 2026 share-price trend is unlikely to change as long as the core narrative stays intact.

The longer-term risk is more pointed. Should Apple fail to outdo Google with Gemini, Kuo says the stock would not necessarily turn bearish, but the assumption that Apple "will ultimately come out ahead" would begin to face growing scrutiny. How much longer the bull narrative can last beyond 2026, in his view, is what makes the keynote worth watching closely.Tags: Apple Intelligence, Gemini, Google, Ming-Chi Kuo, WWDC 2026
This article, "Google Gemini Could Be the Ceiling on Apple's AI Ambitions" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
A widely used JavaScript implementation of Google’s Protocol Buffers format is placing too much trust in untrusted data, exposing affected applications to remote code execution and other attacks.
Researchers at Cyera have disclosed six vulnerabilities affecting “protobuf.js,” all stemming from the library’s handling of schema and metadata. Attackers could exploit an input validation oversight to insert malicious data and influence an application’s behavior.
Protocol Buffers is a technology for packaging data in a compact, structured format to streamline the exchange of information between different applications. The protobuf.js library reportedly receives more than 50 million weekly downloads. It is commonly pulled into applications indirectly through dependencies such as gRPC tooling, Google Cloud libraries, and other frameworks, making it difficult for organizations to track.
Researchers disclosed six CVEs covering remote code execution, denial-of-service (DoS) conditions, prototype pollution, prototype injection, and code-generation issues.
“While exploitation of these vulnerabilities generally requires specific conditions, those conditions are increasingly common in data and AI ecosystems that routinely exchange data, schemas, and configuration files across services, repositories, cloud platforms, and third-party integrations,” Cyera researchers Assaf Morag and Vladimir Tokarev said in a blog post.
Patches are available for both protobuf.js and protonufjs-cli, the project’s command-line code generation tools.
Metadata capable of writing code
The most significant of the bugs is a code-generation flaw tracked as CVE-2026-44291.
According to Cyera, protobuf.js dynamically generates encoder and decoder functions and compiles them using JavaScript’s Function () constructor. Under specific conditions, an attacker can manipulate schema-derived information so that data intended to describe a message instead becomes executable code.
The researchers demonstrated an attack chain in which prototype pollution is used to trick protobuf.js into accepting attacker-controlled values as legitimate protobuf types. Those values are then incorporated into the generated code and executed within the Node.js process.
The impact extends beyond runtime applications. A separate code-injection issue, tracked as CVE-2026-44295, affects the pbjs command-line tool, where crafted schema names can be embedded into generated JavaScript files and executed when those files are later imported.
While successful exploitation requires specific preconditions, such as the ability to influence protobuf schemas or descriptors, researchers noted that modern software increasingly exchanges schemas, descriptors, and configuration files across repositories, cloud environments, APIs, and third-party integrations, making those assumptions less restrictive than they once were.
The remaining vulnerabilities are less severe. Researchers identified a prototype injection (CVE-2026-44292) flaw that can alter application behavior by tampering with inherited object properties, as well as denial-of-services (DoS) bugs (CVE-2026-44289, CVE-2026-44290, and CVE-2026-44294) that can crash or exhaust application resources using maliciously crafted inputs.
Patching advised as supply chain risk looms
The researchers noted that protobuf.js is often consumed as a transitive dependency, meaning organizations may be exposed without realizing the library is present in their software stack. As schemas move through automated development pipelines and software supply chains, components traditionally viewed as passive data can become a pathway for attacks.
“Development teams routinely accept code contributions, integrate third-party components, and automatically process files through CI/CD pipelines,” they explained. “We found that under certain conditions, a malicious protobuf schema could be introduced into this workflow and ultimately executed within trusted build environments.”
A compromise at this stage could have downstream impacts on products, customers, and business operations, they added.
The vulnerabilities affect protobuf.js versions 7.5.5 and earlier, along with versions 8.0.0 and 8.0.1, as well as vulnerable releases of protobuf.js-cli. Patches are available in protobuf.js 7.5.6 and 8.0.2, while protobuf.js-cli users are advised to upgrade to versions 1.2.1 or 2.0.2.
View the full article
A widely used JavaScript implementation of Google’s Protocol Buffers format is placing too much trust in untrusted data, exposing affected applications to remote code execution and other attacks.
Researchers at Cyera have disclosed six vulnerabilities affecting “protobuf.js,” all stemming from the library’s handling of schema and metadata. Attackers could exploit an input validation oversight to insert malicious data and influence an application’s behavior.
Protocol Buffers is a technology for packaging data in a compact, structured format to streamline the exchange of information between different applications. The protobuf.js library reportedly receives more than 50 million weekly downloads. It is commonly pulled into applications indirectly through dependencies such as gRPC tooling, Google Cloud libraries, and other frameworks, making it difficult for organizations to track.
Researchers disclosed six CVEs covering remote code execution, denial-of-service (DoS) conditions, prototype pollution, prototype injection, and code-generation issues.
“While exploitation of these vulnerabilities generally requires specific conditions, those conditions are increasingly common in data and AI ecosystems that routinely exchange data, schemas, and configuration files across services, repositories, cloud platforms, and third-party integrations,” Cyera researchers Assaf Morag and Vladimir Tokarev said in a blog post.
Patches are available for both protobuf.js and protonufjs-cli, the project’s command-line code generation tools.
Metadata capable of writing code
The most significant of the bugs is a code-generation flaw tracked as CVE-2026-44291.
According to Cyera, protobuf.js dynamically generates encoder and decoder functions and compiles them using JavaScript’s Function () constructor. Under specific conditions, an attacker can manipulate schema-derived information so that data intended to describe a message instead becomes executable code.
The researchers demonstrated an attack chain in which prototype pollution is used to trick protobuf.js into accepting attacker-controlled values as legitimate protobuf types. Those values are then incorporated into the generated code and executed within the Node.js process.
The impact extends beyond runtime applications. A separate code-injection issue, tracked as CVE-2026-44295, affects the pbjs command-line tool, where crafted schema names can be embedded into generated JavaScript files and executed when those files are later imported.
While successful exploitation requires specific preconditions, such as the ability to influence protobuf schemas or descriptors, researchers noted that modern software increasingly exchanges schemas, descriptors, and configuration files across repositories, cloud environments, APIs, and third-party integrations, making those assumptions less restrictive than they once were.
The remaining vulnerabilities are less severe. Researchers identified a prototype injection (CVE-2026-44292) flaw that can alter application behavior by tampering with inherited object properties, as well as denial-of-services (DoS) bugs (CVE-2026-44289, CVE-2026-44290, and CVE-2026-44294) that can crash or exhaust application resources using maliciously crafted inputs.
Patching advised as supply chain risk looms
The researchers noted that protobuf.js is often consumed as a transitive dependency, meaning organizations may be exposed without realizing the library is present in their software stack. As schemas move through automated development pipelines and software supply chains, components traditionally viewed as passive data can become a pathway for attacks.
“Development teams routinely accept code contributions, integrate third-party components, and automatically process files through CI/CD pipelines,” they explained. “We found that under certain conditions, a malicious protobuf schema could be introduced into this workflow and ultimately executed within trusted build environments.”
A compromise at this stage could have downstream impacts on products, customers, and business operations, they added.
The vulnerabilities affect protobuf.js versions 7.5.5 and earlier, along with versions 8.0.0 and 8.0.1, as well as vulnerable releases of protobuf.js-cli. Patches are available in protobuf.js 7.5.6 and 8.0.2, while protobuf.js-cli users are advised to upgrade to versions 1.2.1 or 2.0.2.
View the full article
WWDC 2026 has officially arrived, with Apple set to kick off its annual developer conference with its opening keynote at 10 a.m. Pacific Time today.


Apple will announce its latest software updates, including iPadOS 27, macOS 27, watchOS 27, tvOS 27, and visionOS 27. Could there also be a surprise or two in store?

Below, we recap five key talking points heading into WWDC 2026:
Apple could announce new hardware at this year's conference – reportedly, it even has a couple of new devices "ready to go" – but we are keeping our expectations in check. Apple is believed to be holding back new additions to the company's hardware lineup until the new version of Siri and other Apple Intelligence upgrades are released to the general public later this year. The global memory shortage is also making Mac upgrades less likely for now.
Apple may gate access to new Siri features via a waitlist when iOS 27 arrives in September, similar to the initial launch of the Apple Intelligence platform two years ago. Apple is still internally labeling the long-delayed revamped Siri as a "beta," suggesting it won't be marketed as finished when it arrives later this year. Today's preview of the software should clarify what still needs work.
macOS 26 Tahoe will be the final major macOS version for Intel-based Macs, Apple revealed at last year's WWDC. That means macOS 27 will be compatible with Apple silicon Macs only, so you will need a Mac with an M-series chip or a MacBook Neo with an A18 Pro chip in order to install the software update. Dropping support for the legacy chips also means Apple can focus on honing new features exclusively for Apple silicon.
WWDC 2026 will be Apple CEO Tim Cook's last as keynote speaker. The opening keynote of WWDC has been presented by Apple CEO Tim Cook every year since 2012, but Cook is stepping down as Apple's chief executive officer, and hardware engineering chief John Ternus is set to take over on September 1. Bloomberg's Mark Gurman anticipates that Cook will kick off the keynote, but software chief Craig Federighi will be the most prominent figure for the majority of the presentation as he introduces the new AI-centric features.
This year, macOS Emerald and macOS Big Bear have emerged as two speculative possibilities for the name of macOS 27, which Apple has yet to announce. Meanwhile, Little Finder Guy has re-appeared, this time in WWDC swag bags! The tiny anthropomorphized version of the Mac Finder icon went viral earlier this year after appearing in Apple's MacBook Neo marketing campaign. Could we see the character return during the macOS 27 preview? Fingers crossed!

Stay tuned for in-depth coverage of all of Apple's announcements today. We also have a guide explaining all the ways you can watch Apple's WWDC 2026 Keynote live as it happens.Related Roundup: WWDC 2026Related Forum: Apple, Inc and Tech Industry
This article, "5 Things to Watch for During Apple's WWDC 2026 Keynote Today" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
A China-nexus cyber espionage group has been observed deploying a BSD variant of a known backdoor called BRICKSTORM, as well as two other malware families codenamed PLENET (aka GRIMBOLT) and AGENTPSD to target Linux systems. The activity has been attributed by Volexity to a threat cluster it tracks as VerdantBamboo, which it said overlaps with hacking groups known as Clay Typhoon (Microsoft),View the full article
Just hours away from WWDC's opening keynote, some developers have been sharing the contents of their conference swag bags on social media. The bags are given to attendees when they register for the event, and typically contain limited-edition Apple gifts.


This year, developers have been registering early at Apple's Infinite Loop campus, where they have been gifted a black tote bag emblazoned with the WWDC 2026 logo, along with a water bottle, a selection of stickers, and collectible enamel pins.

There are four pins in the bag, including the Apple skull and crossbones, an Apple 50 pin, Clarius the Dogcow, and Little Finder Guy – the tiny anthropomorphized version of the Mac Finder icon that went viral after appearing in Apple's recent online marketing campaign for the MacBook Neo.


MacRumors will be in attendance at the keynote, with live coverage of the event beginning shortly after 10:00 a.m. Pacific Time. Stay tuned to MacRumors.com and our @MacRumorsLive account on X (Twitter). We've also put together a guide explaining all the ways you can watch Apple's WWDC 2026 Keynote live as it happens.Related Roundup: WWDC 2026Related Forum: Apple, Inc and Tech Industry
This article, "WWDC 2026 Swag Bag Includes Little Finder Guy" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Have you ever watched a military cyber ops team go to work responding to a cyberattack simulation? It’s like that scene from Die Hard 4.0 when all the screens start flashing red and systems start shutting down; however, unlike the movies, where bumbling government IT workers are caught out and panicking, our military actually moves with practiced precision to understand, contain, and mitigate the threat. Everybody understands their roles and any gaps are quickly highlighted and handled. This is because the military treats cyber as a kinetic threat requiring constant mission rehearsal, while the corporate sector is still treating cyber defense as a compliance checkbox, rather than an operational capability. This is untenable in a world where attackers constantly innovate their tactics and techniques to probe and access systems.
Over the past 12 months, we’ve seen just how unprepared different industry sectors have been in the face of major cyber incidents. Early in 2025, retailers and insurance brokers were brought down by the Scattered Spider group, and major manufacturers, including Jaguar Land Rover and Asahi Beer, saw months of downtime following ransomware attacks resulting from supply chain compromises.
More recently, researchers at Cisco revealed that frontier models from OpenAI, Anthropic, Google, xAI, and Amazon have significantly worse risk profiles when pressured in multi-turn attacks, a discovery that revealed attack success rates are considerably higher than those benchmarked in simulated single-prompt attacks. This, combined with recent news that the Google Threat Intelligence Group identified what researchers believe to be the first zero-day exploit created using AI, represents an entirely new stage in the technological arms race.
Those old-fashioned tabletop exercises where, once a year, you’d get everyone from IT to PR in a room for a couple of days and play out various scenarios and then tick that audit box for another 12 months aren’t going to cut it when attackers are probing on a daily basis. The military is using dynamic cyber ranges to test their real tools, people, and processes, in an exact simulation of their unique environment, against real-world threats like the tactics of Scattered Spider. Without real-world testing of your team’s capabilities, you’re not going to be able to go into an incident scenario confident that everyone’s prepared.
So, what can we learn from how the military prepares for cyberattacks in terms of mindset, readiness, and execution?
Military cyber doctrine starts with the assumption that you will be attacked and so prepare as though an attack is inevitable and not hypothetical. Businesses need to shift their mindset from “preventing breaches” to “detail, contain, and recover” and treat incidents as operational events rather than reputational crises. This reduces panic and leads to better decisions under pressure. It’s also critical for business leaders to understand their true vulnerabilities. Reputational and financial harm is typical collateral damage following a cyberattack, but was this the intended outcome? If sensitive data is compromised, are there persistent threats beyond the initial attack? Just as the military examines the secondary and tertiary impacts of risk scenarios in threat modeling, business leaders have to consider what else beyond their reputation and stock price may be compromised when they are attacked.
The military runs constant exercises; simulations, red team and blue team drills, and scenario planning that reflects real adversary behavior. Businesses can exercise that muscle by running regular live cyber simulations and updating based on real-world attacks. Conventional training still has its place, and companies should continue to invest in professional development programs that provide a strong foundational understanding of the most urgent threats facing their business. But, as the military says, “train like you fight.” There is simply no substitute for practical, hands-on training, especially when it comes to high-pressure, time-sensitive scenarios such as large-scale cyberattacks.
This readiness and preparedness training can, and should, extend to AI Agents too. Think about it like an “AI Proving Grounds”. Effectively, a realistic, intelligent environment where organizations can safely train human operators alongside AI agents, test autonomous workflows, and validate how both perform under real adversarial pressure before deployment. Continue to involve all the stakeholders, including executives and comms teams, who are going to be on the front line of customer, investor, and media inquiries should an attack occur. Without realism, readiness is an assumption, not a fact.
In a military cyber incident, everyone knows who decides, who communicates, and who executes, reducing any mid-crisis debate and empowering teams to act without permission to faster contain the incident. This principle is just as relevant in a corporate environment. Individual training is crucial, and operators should be confident acting in isolation, but it’s just as important that everyone in a rapid response team can work effectively with others, under often-intense pressure. This simulated teamwork is another advantage offered by AI Proving Grounds. In the same way that everyone in a military chain of command understands their role and that of their unit, businesses can pre-assign decision makers and define escalation paths before an incident to ensure clarity and calm rather than blind panic.
Finally, attackers are sharing knowledge all the time. Defenders must adopt the same approach. We know that militaries collaborate extensively across allies, agencies, and domains, recognizing that no unit has the full threat picture. Businesses can benefit from this information sharing by participating in ISACs, CERTs, and industry groups, treating threat intel as a collective defense rather than a competitive weakness.
AI Proving Grounds themselves are only part of the solution. Security is cultural, not just procedural. Even the most realistic simulated attack scenario is only useful if structures are in place for stakeholders to learn from it. What didn’t work well? What didn’t go as expected? What are the weakest links in the response chain? These are all questions executives and technical leadership should be comfortable asking themselves, and businesses must adopt cultures of responsibility to identify potential weaknesses beyond technical limitations. Such retrospectives can and should inform rapid-response playbooks to ensure that training is relevant and that weaknesses cannot be exploited in a production environment.
Many of the clients we work with are corporations and enterprises, but AI Proving Grounds have other applications. Recent years have seen coordinated attacks on critical infrastructure such as the nation’s power grid, including the prolonged intrusion by the Volt Typhoon persistent threat actor, which maintained unauthorized access to the operational technology networks of Littleton Electric Light and Water Departments in Massachusetts from February 2024 to November 2024. Such threats can also be simulated in AI Proving Grounds and provide crucial hands-on training opportunities for critical infrastructure providers that, until now, have been challenging to realistically model. With geopolitical tensions rising across the globe, operational readiness has never been more critical.
“Cyber resilience” has become something of a buzzword in itself and I can almost hear the eye rolls just using the phrase, but it is something the military does actively practice. Cyber resilience isn’t about prevention; it means being able to recover from as well as protect against attacks. With AI-powered adversaries scaling their approach to infiltration, extortion, and espionage, attacks are only going to increase and businesses need to be prepared to deal with them as well as prevent them. Continuous training within highly realistic and dynamic environments against real threat examples is the best way to ensure your teams are prepared at a military grade to secure your organization.
This article is published as part of the Foundry Expert Contributor Network.
Want to join?
View the full article
As CISOs know, an effective security program cannot be static. Rather, it must adapt to the evolving threat landscape and an ever-changing business environment.
To adapt and improve, CISOs must continuously evaluate their existing program. That starts with asking tough questions about their performance, investments, and strategies.
Here, security leaders share 15 questions every CISO should ask to ensure their programs can meet current demands and future needs.
1. What issue or incident has my security program addressed that would otherwise have hindered the business?
Roland Palmer, CISO and vice president of security at tech company JumpCloud, says he regularly asks himself this question because it forces him to identify and communicate what security efforts avert a negative impact to the business.
“This is about us trying to demonstrate ROI and articulating it,” he says. “It frames how I think about my role and where I should be targeting the media blitz [to inform] the business about what we do that demonstrates the value of security.”
2. How are we protecting our organization’s most important business processes?
This question pushes CISOs to put business resilience front and center, a focus that helps ensure security programs are aligned with business needs.
“Many organizations still take a broad, defensive approach rather than focusing their cyber strategy around critical processes. In an AI-enabled threat environment, the challenge is less about identifying every vulnerability and more about protecting critical processes and ensuring resilience when incidents occur. This is also increasingly reinforced by regulation,” says Richard Watson, global cybersecurity leader with professional services firm EY, noting the EU’s DORA, for example.
3. Do we know the actual business impact of critical service availability?
In addition to knowing which processes are critical to the organization, CISOs need to understand the true impact of a successful attack on those processes. Such knowledge helps align their security strategy and articulate the value of their security investments to the C-suite colleagues.
“Understanding which systems generate revenue, support customers, fulfill regulatory obligations, or enable critical operations helps organizations prioritize security investments where they matter most,” says Dale Hoak, CISO at software firm RegScale. “Business impact analyses should be reviewed regularly and updated whenever significant organizational changes occur.”
Similarly, Sean Murphy, senior vice president and CISO at BECU, the nation’s fifth-largest credit union, asks, “What are the security things that will shut down the business?” He says this question helps security align and prioritize its work to business risk, which ensures business reliance not just IT resilience.
4. If we were breached tomorrow, how quickly would we know?
Mean time to detect, as well as mean time to respond and mean time to contain, remain critical metrics for measuring the effectiveness of security programs, as a low MTTD generally correlates to a smaller blast radius and less impact to the business.
That’s what makes asking this question critical, Hoak says.
“The reality is that every organization should assume an attacker will eventually gain access somewhere within the environment. The more important question becomes how quickly security teams can detect malicious activity, understand the scope, and respond effectively,” he says. “This question should be evaluated continuously through monitoring, tabletop exercises, purple team exercises, and incident response testing.”
5. Are we operating at machine speed or human speed?
According to Watson, CISOs should be wondering about their department’s overall speed and whether it’s as fast as needed.
“Today’s cyber and IT operating models, governance processes, and controls were built for a slower threat landscape. As AI accelerates both attack and defense capabilities, organizations need to assess whether they are keeping pace or whether gaps are emerging as threat actors increasingly use advanced automation and AI,” he says.
6. What don’t we know?
This is a question that Murphy regularly puts to his security team to help them prepare for whatever is out there.
“We have to think about where we don’t have visibility, where are our blind spots, what we don’t know but need to know, whether it’s around people, process, or technology,” he says. “It’s an uncomfortable conversation, but we have to think about where the gaps might be. We have to think about where we may have new exposure.”
Murphy and his team use threat intelligence and information from colleagues, peer groups, industry associations, and its own security systems “to understand what we’re seeing. It’s a lot of ingestion of information that’s available. And it’s about being curious and critical, and questioning and not assuming. I’m trying to see around corners.”
7. Which third parties could significantly impact our operations if compromised?
“Recent attacks have demonstrated that compromising one trusted supplier can create downstream risk across thousands of organizations,” Hoak says. “Many companies have stronger visibility into their own environments than they do into the organizations they depend upon.”
So CISOs must be continuously asking this, he adds, “because vendor relationships, software dependencies, and threat landscapes constantly evolve.”
8. How buttoned up is our IAM program for both human and nonhuman identities?
Identity and access management (IAM) has become a central component of modern security programs. So it’s essential, Palmer says, for CISOs to know exactly how many human and nonhuman identities operate within their organizations and whether their access is restricted to just the appropriate use cases.
“This has become an everyday question. I’d go farther and say it’s now an every-hour question,” Palmer says, noting that the proliferation of AI use, shadow AI, and AI agents means the number of identities and their access rights are constantly changing.
9. How are we securing our nonhuman identities?
On another AI-related note, Watson says CISOs everywhere need to ask whether they have adequate security for their nonhuman assets.
“Nonhuman identities are an emerging frontier of cyber risk, and many traditional identity governance tools have not yet evolved to address them. As organizations adopt more automated and agent-driven processes, managing access and privileges across these identities becomes increasingly important,” he says.
10. Do we know where AI is being used, what data is being shared, and who is accountable for those decisions?
As Doug Kersten, CISO at software maker Appfire, observes, “Many employees are adopting AI tools on their own to solve real business problems before leadership even knows those tools exist, creating unidentified security risks. That creates the same kind of visibility and accountability issues we saw for years with shadow IT; [it’s] just happening much faster.”
To ensure they can answer “yes” to those questions, CISOs need governance processes that keep pace with quickly evolving technology and that involve legal, procurement, HR, engineering, and business teams as well as security, he says.
11. Is my application security program built for a world where everyone is a coder?
AI has made application development accessibility to everyone in the organization, so CISOs need to consider whether their security programs have the right controls for this new reality.
“CISOs have to figure out the guardrails [for the organization] to do vibe coding in a secure way, and those guardrails have to match the speed of vibe coding,” says Nico Waisman, CISO at security tech company XBOW.
12. Are we ready for the expanding attack surface that vibe coding is creating?
Similarly, Waisman says he and other CISOs have to ponder whether their security programs are capable of safeguarding the expanding attack surface and technical debt that vide coding is creating.
“If anyone can generate their own product, we’re going to have applications popping up all over the network and the environment. That means [the organization likely] is generating technical debt, because people love to build software but no one loves to maintain software. And if no one is maintaining it, then it could have vulnerabilities that no one is monitoring or fixing. It may end up with only security caring for it,” Waisman says.
To avoid such a scenario, CISOs must be diligent about inventorying assets and assigning ownership to every application, he says.
13. What are we doing to prepare for a world where hackers have Mythos?
Claude Mythos is a frontier AI model from Anthropic that can autonomously find and exploit software vulnerabilities. In hackers’ hands, this would drastically shrink even further the speed at which attacks can be built and launched.
“The speed and scale are different now,” Waisman says. “Anthropic and OpenAI models have opened the doors for a scale of attacks that we have never seen before. So CISOs have to think about how that will affect their security posture and how they’ll be defending against attacks as the scale and speed change even more.”
14. Am I confident enough to share our real-time security posture if a customer asked for it?
JumpCloud’s Palmer puts himself and his security team to the test by regularly asking whether he’d be comfortable sharing a real-time snapshot of his security program.
“Am I comfortable with our patch management, our vulnerability management, and with our customers seeing those stats? Am I comfortable with customers looking behind the curtain?” he asks.
Palmer says such questions help him assess whether his security program is where it should be. He says he can answer “yes” to those questions most of the time, but he admits that sometimes he answers “no.” And while a “no” from time to time is expected, Palmer says if there are two or more a quarter, he knows he must focus on righting the security team’s efforts to get him back to more affirmative responses.
15. Are we securing the business we have today and the business we’ll have a year from now?
Given the speed of technology advancements, changes in the threat landscape, and business strategy, RegScale’s Hoak knows he must have his eyes on the horizon and a plan to meet it head-on.
“Security programs often lag behind business growth and transformation initiatives. Organizations are rapidly adopting AI, modernizing applications, expanding cloud environments, and integrating new third-party services. If security strategies are only focused on current-state risks, they quickly become outdated,” he explains.
So he actively asks himself whether he’s prepared for the future, noting that “this question should be revisited whenever strategic business plans, acquisitions, major technology initiatives, or new market opportunities emerge.”
View the full article
Security researchers are warning of an issue with the default HTTP/2 configuration used by major web servers which reportedly survived more than a decade of human review before showing up in Codex-assisted analysis.
A flaw in the handling of the HTTP/2 protocol made a denial-of-service (DoS) attack possible on web servers including nginx, Apache HTTP server, Microsoft IIS, Envoy, and Cloudflare’s Pingora, according to security consultancy Calif.
HTTP/2 was introduced in 2015 to increase the speed of HTTP by allowing multiple simultaneous connections, and is gradually being superceded by HTTP/3, which is built on the new QUIC encrypted transport protocol. The problem uncovered by Calif lies in how affected servers handle HTTP/2 header compression and request processing, allowing an attacker to trigger disproportionate memory consumption.
“The attack chained two techniques known to humans for a decade: a compression bomb and a Slowloris-style hold,” Calif CEO Thai Duong said in a blog post, calling the technique HTTP/2 Bomb. A search of Shodan revealed 880,000+ websites supporting HTTP/2 and running one of these servers, although many of these websites use a Content Delivery Network (CDN), which may add some complexity to the attack, he said.
Weaponizing a compression feature for DoS
The issue, tracked as CVE-2026-49975, involves HPACK, the header compression mechanism built into HTTP/2. Calif found that attackers can abuse the protocol’s dynamic header table in a way that forces servers to repeatedly allocate memory far beyond what would normally be expected from the size of incoming requests.
A relatively small amount of attacker-controlled traffic can trigger excessive memory allocations on the target server, Duong said.
“The bomb targets HPACK, HTTP/2’s header compression scheme: One byte on the wire becomes one full header allocation on the server, repeated thousands of times per request,” he said. “The hold is a zero-byte flow-control window that keeps the server from ever freeing any of it.”
This isn’t the first time HTTP/2 was flagged for allowing DoS attacks. In 2019, multiple HTTP/2 denial-of-service vulnerabilities disclosed by Netflix affected numerous server implementations and prompted emergency patches across the ecosystem.
In October 2023, the protocol was disclosed to be prone to massive DDoS attacks owing to its stream multiplexing capability.
Duong recalled in the post how in 2012 he contributed to the discovery and patching of a flaw in HPACK, that back then was exploited by a different attack, CRIME. “I was too fixated on fighting CRIME and missed the Bomb,” he reflected.
Calif reported the flaw to all affected projects. nginx and Apache HTTP Server moved quickly to block the attack path, while Envoy patched on June 3. Microsoft IIS and Cloudflare’s Pingora had yet to release patches at the time of publication.
Cloudflare updated Pingora to version 0.8.1 later on June 4, mitigating the memory exhaustion problem.
Admins will need to obtain the fixed versions of nginx (v1.29.8+) or Apache (mod_http2 v2.0.41), through the normal update channels used for these products. Envoy issued patches for versions 1.35.11, 1.36.7, 1.37.3, and 1.38.1.
For organizations without a patch available to them, Calif recommended disabling HTTP/2 if possible, or “front the server with something that enforces a hard cap on header count per request.”
Updated to note that Cloudflare has since patched Pingora.
View the full article
Cybersecurity researchers have disclosed details of a financially motivated data theft extortion campaign that has targeted dozens of organizations across professional, legal, and financial services in the U.S. between January and May 2026. The activity has been attributed by Google Mandiant and Google Threat Intelligence Group (GTIG) to a threat actor dubbed UNC3753, which is also known asView the full article
Cybersecurity professionals were offered lessons of resilience in the most extreme circumstances from Ukraine’s former minister of foreign affairs.
Dmytro Kuleba, who served as Ukraine’s Minister of Foreign Affairs between 2020 and 2024, told Infosecurity Europe delegates that the key to Ukraine’s survival after the full-scale Russian invasion of 2022 was pre-planning, a lesson learned in the early weeks of the war.
Ukraine’s largest mobile operator KyivStar was subjected to an outage in December 2023 because of a Russian cyberattack.
“They got to the very core of their system of their network,” Kuleba said. “They put it down, or they knocked it out, and the way they did it, they penetrated through an account of one single employee of KyivStar.”
Kuleba added: “Miraculously, KyivStar did [the] unimaginable, and within days they restored the system and fenced it off.”
Few successful cyberattacks have happened since this incident, according to Kuleba, who credited this success on a pre-planning for resilience methodology that has been adopted by the Ukrainian government and businesses.
“We don’t know what and how it is going to happen,” Kuleba said. “But you can presume, you can brainstorm, you can calculate, and you can prepare. You can prepare so that it becomes your muscle memory.”
Even if the unexpected happens you will be more prepared if you’ve gone through preparations, Kuleba argued.
“Make no mistake when the crisis situation occurs, everything will be different,” said Kuleba. “You will be punched in the face. You plan not to follow the plan but to know your environment perfectly and to develop instincts of survival in this environment.”
Exodus
Kuleba began preparing Ukraine’s foreign ministry for the war in November 2021, starting with learning precisely how its systems worked and planning for contingencies such as how diplomats and staff could communicate if online messaging apps became unavailable.
When war broke out foreign ministry services was evacuated abroad.
“We did not waste a single second on figuring out what is possible and what is impossible, because we knew all of that in advance,” Kuleba said.
Preparation for potential disasters might seem like a distraction from more immediate projects or even boring but making contingency plans is vital not just for Ukraine but for technologists around the world.
“There are more important projects than preparing for something that might not even happen,” Kuleba advised. “But if you care for your company, if you care for your country, you have to prepare for the worst.”
Kuleba concluded: “Resilience is not being prepared to repair a destruction. Resilience is your ability to keep repairing the wrecks as destruction becomes new normal.”
The war has affected the operations of even smaller Ukrainian businesses as Russian cyberattacks have become stealthier.
For example, Russian operatives have recently sought to gain “pattern of life” intelligence that might be used to assassinate Ukrainian officials or target members of their family for kidnap after hacking into the customer relationship management (CRM) systems used by businesses such as barbers, gyms, and nail bars.
“What Russian security services are doing is they break into CRM systems of barbers, fitness clubs … the loyalty programmes of supermarkets, to track your movements, to understand whether you usually show up, [and] how much time do you usually spend, to build a picture, and then do what they believe is necessary,” Kuleba said.
In one case Kuleba linked to this tactic, the son of an unspecified Ukrainian official was kidnapped before his father was blackmailed by the Russians into leaking intel.
CRM systems in the Ukraine were particularly vulnerable because for years before the invasion, “Russian companies had been offering very lucrative offers to Ukrainian businesses so that they would install [their] CRM platforms,” Kuleba said.
Kuleba added: “Did these Russian companies do that on their own initiative? Perhaps. Did the Russian security service ask them to do that and help them to do it? Perhaps. But the thing is, even such innocent programme as a check-in system at a restaurant, or a barber shop, or a gym, can help your enemy to kill someone … to kidnap.”
“Do not trust the products made by your potential enemy,” Kuleba concluded, adding that the incident shows the importance of technological sovereignty and data security even for the smallest companies.
View the full article
Microsoft has announced that Visual Studio Code (VS Code) will apply a two-hour delay before extensions for the integrated development environment (IDE) are updated automatically to a newer version in an attempt to tackle software supply chain threats. "When automatic updates are enabled, new versions are auto-updated two hours after they are published, adding an extra layer of protectionView the full article
Introduction
Software development has changed drastically over the last decade. In the past, companies released software once or twice a year. Today, users expect new features, security updates, and bug fixes on a weekly or even daily basis. This pressure to release code faster has forced development teams to rethink how they build, test, and deliver applications.
Teams that rely on manual processes often struggle with integration errors. When developers work in isolation and merge their code manually at the end of a project, the results are often disastrous. Systems break, bugs hide in the shadows, and release schedules crumble under the weight of “integration hell.”
This is where Continuous Integration (CI) changes the game. It is the practice of merging all developer working copies to a shared mainline several times a day, ensuring that every change is tested immediately. For beginners, understanding CI is the first step toward mastering the broader DevOps culture.
To gain hands-on experience and deep industry insights, many professionals turn to DevOpsSchool. Whether you are a student or a developer transitioning into a DevOps role, learning the fundamentals of automation is essential. This guide will walk you through the core concepts, tools, and workflows you need to understand Continuous Integration for beginners.
What Is Continuous Integration?
Continuous Integration is a development practice where developers integrate their code into a shared repository frequently. Each integration is verified by an automated build and automated tests.
Imagine a group of writers working on a single book. If every writer works on their own separate chapter for three months without talking to each other, bringing all those chapters together would be a nightmare. There would be conflicting character names, timeline inconsistencies, and plot holes.
Now, imagine if every time a writer finished a paragraph, they shared it with the team, and a smart editor immediately checked it for grammar, tone, and plot consistency. If there is a problem, the writer finds out within minutes and fixes it. That is exactly what Continuous Integration does for code. It turns a massive, risky “all-at-once” integration into small, frequent, and manageable steps.
Why Continuous Integration Matters
Continuous Integration is not just about tools; it is about building a culture of reliability. In modern software engineering, speed without quality is a recipe for failure. CI bridges that gap.
Faster Development Cycles
When you automate the testing of code, you remove the bottlenecks caused by manual code reviews and QA processes. Developers get immediate feedback on whether their code works, allowing them to iterate quickly.
Improved Software Quality
Because the software is tested every time a change is made, bugs are caught early. It is significantly easier and cheaper to fix a bug immediately after writing the code than it is to find it weeks later in a production environment.
Reduced “Integration Hell”
The term “integration hell” describes the painful process of merging code from multiple developers at the end of a project. By integrating code continuously, you ensure that components always work together.
Problems Developers Faced Before CI
Before the widespread adoption of CI, software teams faced significant hurdles that delayed releases and frustrated engineers.
ProblemImpactCode ConflictsDevelopers spent days resolving overlapping changes in the codebase.Delayed TestingQA teams only tested code at the end of the project, leading to late-stage discovery of critical bugs.Slow ReleasesManual build and deployment processes made releasing new features time-consuming.Late Bug DetectionBugs remained hidden for weeks, making them harder to trace and fix.Team SilosCommunication gaps between developers led to fragmented and incompatible code. How Continuous Integration Works
The CI workflow is a cycle designed to keep the codebase healthy. Here is how a standard process looks in a modern development environment.
Code Commit: A developer writes code on their local machine and pushes it to a shared Version Control System (VCS), such as GitHub or GitLab. Automated Build: The CI server detects the change and triggers an automated build. It compiles the code and ensures there are no syntax errors or dependency issues. Automated Testing: The CI system runs a suite of automated tests (unit tests, integration tests). If the tests fail, the process stops, and the developer is notified immediately. Feedback Loop: The developer receives a notification (via email, Slack, or dashboard) about the build status. If it failed, they fix the code. If it passed, the code is ready for the next stage. This loop ensures that the main branch of your code is always in a “deployable” state.
Core Components of Continuous Integration
To implement CI effectively, you need several foundational components working in harmony.
ComponentPurposeVersion Control System (VCS)Stores the source code and tracks changes (e.g., Git).Build ServerThe automation engine that executes the CI tasks.Automated Build ScriptsInstructions that tell the server how to compile and prepare the application.Automated Test SuiteA collection of scripts that verify the functionality of the code.Notification SystemAlerts the team immediately when a build or test fails.Artifact RepositoryStores the output of the build (e.g., binaries, Docker images) for later use. Popular CI Tools for Beginners
Choosing the right tool is the first step in your learning journey. Many industry-standard tools share similar core features.
ToolBest ForJenkinsThe industry standard, highly customizable, and great for learning the basics of self-hosted automation.GitHub ActionsNative to GitHub, extremely easy to set up for beginners, and requires no external servers.GitLab CI/CDAll-in-one solution that integrates code management and pipeline automation seamlessly.CircleCIKnown for speed and ease of integration with third-party tools.Azure DevOpsAn enterprise-grade platform offering robust boards, repositories, and pipelines in one place. For a beginner, I recommend starting with GitHub Actions. It lives directly inside your code repository, meaning you do not need to set up complex infrastructure to start experimenting.
Real-World Example: Team Without Continuous Integration
Consider a team of five developers building an e-commerce website. Without CI, they share code by manually copying files or using shared drives.
Developer A updates the shopping cart logic. Developer B changes the database schema. They do not merge their code until Friday. When they finally combine the files, the website crashes. They spend the entire weekend manually debugging code, trying to figure out which change broke the site. The deadline is missed, and the client is unhappy. This is a classic example of the risks associated with manual integration.
Real-World Example: Team Using Continuous Integration
Now, consider the same team using a CI pipeline.
Developer A pushes their shopping cart update. The CI server immediately runs tests. It detects that Developer A’s change is incompatible with the current database schema. The CI tool sends a notification to the team’s dashboard.
Developer A sees the failure within five minutes. They coordinate with Developer B, update the schema, and push the fix. The tests pass. By the end of the day, all features are integrated, tested, and ready to go. The team leaves on Friday with no stress and a stable codebase.
Benefits of Continuous Integration
Continuous Integration offers tangible benefits that extend beyond just “writing code.”
Faster Feedback: Developers know immediately if their changes are correct. Early Issue Detection: Bugs are isolated to the specific change, making them easy to identify. Better Collaboration: Teams communicate through code integration rather than just meetings. Reliable Releases: Since the code is always tested, the risk of breaking the production environment is significantly reduced. Historical Tracking: Every build is logged, providing a history of what changed and why. Common Beginner Mistakes While Learning CI
When starting out, it is easy to get overwhelmed. Avoid these common traps to make your learning journey smoother.
Skipping Git Basics: You cannot do CI if you do not understand version control. Master Git first. Overcomplicating Pipelines: Start with a simple “Hello World” build. Do not try to build a complex, multi-stage pipeline on your first day. Ignoring Testing: CI is useless without tests. You must write code that can be tested. Learning Too Many Tools: Pick one tool (like GitHub Actions or Jenkins) and master it before moving on to others. Manual Intervention: Avoid the temptation to “fix it manually” on the server. If the pipeline fails, the code should be fixed in the repository, not on the server. Best Practices for Learning Continuous Integration
To build a strong foundation, follow these practical steps.
Start Simple: Create a repository with a simple script. Set up a CI pipeline that runs that script every time you push code. Learn Git First: Understand how branches, commits, and pull requests work. Practice Small Commits: Don’t wait until the end of the week to merge code. Merge often, even if the feature is incomplete. Understand Automation: Think about every step you do manually (like compiling or running tests) and ask, “How can I automate this?” Review Logs: When your pipeline fails, do not panic. Read the logs. The error messages are your best teachers. Role of DevOpsSchool in Learning CI
Learning Continuous Integration requires more than just reading documentation; it requires practical application. DevOpsSchool provides the structured environment and hands-on experience necessary to move from theory to implementation. By working on real-world projects and learning from experienced mentors, beginners can develop the engineering mindset required to handle complex CI/CD environments. The focus is on practical skills, industry-standard tools, and the logic behind automation, ensuring that students are ready for the demands of the modern job market.
Career Importance of Continuous Integration Skills
CI is no longer a “nice-to-have” skill; it is a fundamental requirement for many technical roles.
DevOps Engineer: You are responsible for designing and maintaining the CI/CD pipelines that power the entire software delivery process. Software Engineer: You are expected to write testable code and understand how your changes interact with the broader system. QA Automation Engineer: You build the automated test suites that run within the CI pipelines. SRE Engineer: You focus on the reliability of the system, using CI to ensure that deployments are safe and automated. Platform Engineer: You build the internal tools and frameworks that make CI easier for other developers. Proficiency in CI signals to employers that you understand how to deliver value safely and efficiently.
Industries Using Continuous Integration
The principles of CI are applied across almost every sector that relies on software.
SaaS Platforms: They release updates multiple times a day to stay competitive. Banking & Finance: CI ensures that every financial transaction system change is thoroughly tested for security and accuracy. Healthcare: Automated testing ensures that patient data systems remain compliant and stable. E-Commerce: Platforms use CI to manage high-traffic websites that cannot afford downtime. Telecom: Large-scale infrastructure requires constant updates and rigorous testing. Future of Continuous Integration
The landscape of CI is evolving. We are moving toward “smarter” pipelines.
AI-Assisted Testing: AI tools are beginning to automatically detect which tests need to be run, speeding up pipelines even further. Cloud-Native Pipelines: Everything is moving to the cloud, with pipelines becoming ephemeral (created and destroyed on the fly). Security Integration (DevSecOps): Security scanning is now becoming a standard step within the CI pipeline, not an afterthought. Smarter Automation: Pipelines are becoming more intelligent, self-healing, and better at managing dependencies without human input. FAQs
What is the primary goal of Continuous Integration?The goal is to detect integration errors early by merging code changes into a central repository frequently and automatically testing those changes. Does Continuous Integration require specific coding languages?No, CI is a practice, not a language. It applies to any software project, whether you are using Java, Python, JavaScript, or C++. Is CI the same as Continuous Deployment?No. CI focuses on merging and testing code. Continuous Deployment (CD) takes that tested code and automatically releases it to the production environment. Can I practice Continuous Integration on my personal projects?Yes. In fact, it is the best way to learn. Create a free repository on GitHub and enable GitHub Actions to run tests on your personal code. How often should a developer commit code in a CI environment?Developers should aim to commit and push their code at least once a day, or whenever a small, logical piece of work is complete. Do I need a dedicated server to run CI?Not necessarily. Cloud-based CI providers like GitHub Actions or CircleCI offer free tiers that run pipelines on their infrastructure. What is the most common reason for a CI build to fail?Usually, it is due to a developer pushing code that fails unit tests or fails to compile because of missing dependencies. Is it difficult for a complete beginner to set up a CI pipeline?With modern tools like GitHub Actions, it is quite accessible. Most setups involve adding a simple configuration file to your repository. Should I use Jenkins or GitHub Actions as a beginner?GitHub Actions is generally easier to start with because it is built into the repository and requires less setup. Does CI make the development process slower?Initially, it requires time to set up. However, in the long run, it makes development significantly faster by preventing “integration hell” and reducing debugging time. Can CI help with security?Yes. You can configure your CI pipeline to run security scans on your code, checking for vulnerabilities before the code is ever merged. Is CI suitable for small teams?CI is beneficial for teams of any size, even for solo developers working on their own projects. What happens if a test fails in the CI pipeline?The build is marked as “failed,” and the team is notified. The developer must then fix the code and push it again to trigger a new build. Do I need to learn Docker to use CI?While not strictly mandatory, knowing Docker is highly recommended, as most modern CI pipelines use containers to build and test code in consistent environments. How does CI relate to the overall DevOps lifecycle?CI is the foundation. It feeds into the Continuous Delivery/Deployment (CD) phase, which completes the automation of the entire software delivery lifecycle. Final Thoughts
Continuous Integration is not just a technical process; it is a change in mindset. It is about moving away from the fear of breaking things and toward a system where you are confident that your code works because it has been proven by automation. As you begin your journey in DevOps, remember that CI is your safety net. Start by learning the basics, practice consistently, and do not be discouraged by failing builds—they are simply part of the learning process. Mastering these concepts will position you well for a long and successful career in the software industry.
View the full article
Apple is set to unveil iOS 27 during its WWDC 2026 keynote today, and there are many rumored features and changes for iPhones.


The first developer beta of iOS 27 will likely be available immediately following the keynote, and a public beta typically follows in July. Following beta testing, the software update should be released to all users with a compatible iPhone in September.

Below, we outline 12 new features that are rumored to be coming with iOS 27:

Siri App: A dedicated Siri app will allow users to have back-and-forth conversations with Siri, similar to other chatbots like ChatGPT.
Search or Ask: Swiping down on the Dynamic Island area will open a new "Search or Ask" interface powered by the revamped Siri.
"Create a Pass" in Apple Wallet: iOS 27 will reportedly let users create their own digital passes for physical items like a gym membership card.
Apple Cash Bill Splitting: In the Wallet and Messages apps, a person who paid a bill in full will be able to take a photo of the receipt, assign individual items to certain people, and then generate Apple Cash payment requests for the purpose of reimbursement. Apple Cash is currently available in the U.S. only.
"Extend" and "Reframe" in Photos: Two new Apple Intelligence photo editing options.
Generated Subtitles: Apple previewed new accessibility features coming in iOS 27, including automatic captions for personal iPhone videos.
Apple Maps via Satellite: iOS 27 will reportedly include several new satellite features, including Apple Maps via satellite.
Battery Life Enhancements: iOS 27 been likened to Mac OS X Snow Leopard, in the sense that Apple is reportedly focused on bug fixes and performance improvements. Longer battery life is expected as a result.
Improved Autocorrect: Apple has reportedly tested an updated iPhone keyboard with enhanced autocorrect functionality.
Visual Intelligence Expansion: A new "Siri" mode in the Camera app will let you scan nutrition labels and contact information.
Apple Intelligence for Shortcuts: In the Shortcuts app, Apple Intelligence will be able to create shortcuts based on natural language prompts.
Custom Wallpapers: Apple Intelligence will be able to generate iPhone wallpapers.As was the case with iOS 26, it is likely that anyone with an Apple Developer account will be able to install the iOS 27 developer beta for free, with Apple Developer Program membership for $99 per year no longer required. After registering, restart your iPhone and open the Settings app. Next, tap on General → Software Update → Beta Updates and select the iOS 27 Developer Beta once it is seeded later today.

To install a public beta, first sign up at beta.apple.com. After enrolling, restart your iPhone and open the Settings app. Next, tap on General → Software Update → Beta Updates and select the iOS 27 Public Beta once it is available.

iOS beta versions can have bugs and performance issues. Backing up your iPhone before installing beta software is highly recommended.Related Roundup: iOS 27
This article, "iOS 27 Beta Available Today With These 12 New Features" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Amazon is set to host its annual Prime Day event later in June, but you can already find massive discounts across popular accessories right now. This includes year's best prices on Anker chargers, Samsung monitors, Sonos audio products, and more.

Note: MacRumors is an affiliate partner with some of these vendors. When you click a link and make a purchase, we may receive a small payment, which helps us keep the site running.

An ongoing highlight of these deals is Anker's Prime 3-in-1 Wireless Charging Station, available for $109.99 for Prime members this week, down from $149.99. This is one of Anker's newest accessories, and Amazon's sale today is a solid second-best price on the device.

$40 OFFAnker Prime 3-in-1 Wireless Charging Station for $109.99

The Prime 3-in-1 Wireless Charging Station features Qi2.2 support, which lets a compatible MagSafe ‌iPhone‌ charge at up to 25W. It's the same speed as Apple's ‌MagSafe‌ charger, and it is 10W faster than the standard Qi2 ‌MagSafe‌ chargers. You can also simultaneously charge an Apple Watch and AirPods with the device.

We're also tracking big discounts from brands like UGREEN, Sony, Samsung, Sonos, and more in the lists below. Accessories on sale include USB-C wall chargers, MagSafe-compatible wireless chargers, portable batteries, headphones, soundbars, and monitors.

Docks

iVANKY 23-in-1 Thunderbolt 5 FusionDock Max 2 - $399.99, down from $499.99

Wall Chargers

Anker Nano USB-C Wall Charger - $27.99, down from $39.99
UGREEN 100W GaN 4-Port Charger - $33.23, down from $54.99
Anker 140W 4-Port GaN USB-C Charger - $64.99, down from $99.99
Anker 3-Port Prime Charger - $115.99, down from $149.99
Wireless Chargers

Anker 3-in-1 MagSafe-Compatible UFO Charger - $67.49, down from $89.99
Anker 3-in-1 MagSafe-Compatible Foldable Charging Station - $89.99, down from $109.99
Anker 3-in-1 MagSafe-Compatible Charging Cube - $89.99, down from $129.99
Anker 3-in-1 Prime Wireless Charging Station - $109.99, down from $149.99
Anker Prime MagSafe-Compatible 3-in-1 Charging Station - $149.99, down from $229.99
Portable Chargers

Anker MagGo Power Bank With Stand - $67.99, down from $89.99
Anker MagGo Power Bank 10,000 mAh - $69.99, down from $79.99
Anker Prime Power Bank 20,100 mAh - $125.99, down from $179.99
Anker SOLIX C300 Power Station with Lantern - $169.99, down from $249.00
Anker Prime Power Bank 26,250 mAh - $199.99, down from $229.99
Anker SOLIX C1000 Gen 2 Portable Power Station - $499.99, down from $799.00
Jackery Explorer 1000 v2 Portable Power Station - $449.00, down from $799.00
Anker SOLIX C2000 Gen 2 Portable Power Station - $749.00, down from $1,499.00
Audio

Sonos Beam Gen 2 - $369.00, down from $499.00
Sony WH-1000XM6 Noise Canceling Wireless Headphones - $398.00, down from $459.00
Monitors

Samsung 27-inch Odyssey G5 Monitor - $179.99, down from $249.99
LG 27-inch UltraGear Monitor - $319.99, down from $499.99
Samsung 27-inch Odyssey OLED G5 - $399.00, down from $499.99

If you're on the hunt for more discounts, be sure to visit our Apple Deals roundup where we recap the best Apple-related bargains of the past week.



Deals Newsletter

Interested in hearing more about the best deals you can find in 2026? Sign up for our Deals Newsletter and we'll keep you updated so you don't miss the biggest deals of the season!




Related Roundup: Apple Deals
This article, "Anker 3-in-1 Wireless Charging Station Now $40 Off Ahead of Amazon Prime Day" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Sonny Dickson today shared detailed images of a foldable iPhone dummy unit with what appears to be a finalized design, providing the best look yet at the device's look, with the suggestion that the device may only be available in white.


Dummy units are non-functional units intended primarily for display purposes and accessory manufacturers, who need a high level of physical accuracy to mass produce cases and other accessories ahead of a device's announcement. Dickson first shared early-production dummy models of the foldable iPhone alongside the iPhone 18 Pro and ‌iPhone 18 Pro‌ Max in April, providing the first real visual confirmation of the foldable's passport-style form factor.

The latest foldable iPhone dummy is markedly more detailed than those that have previously circulated. Earlier this week, the leaker known as "Ice Universe" shared what appeared to be an image of a white foldable iPhone dummy, but Dickson's unit offers a substantially clearer view of the design and display.



The images align with the wider body of design rumors accumulated so far. The device is expected to feature a book-style, passport-shaped design with a 4:3 aspect ratio, wider than it is tall and unlike any foldable currently on the market, with a 5.5-inch outer display and a 7.8-inch inner OLED panel that would make it just slightly smaller than the iPad mini when open.

Rumors point to an ultra-thin 4.5mm titanium frame, with volume buttons relocated to the top edge of the device, no Action Button, Touch ID in place of Face ID, and a horizontal dual-camera array on the back in an iPhone Air-style camera plateau.

The latest dummy models reveal several new design aspects, such as the fact that the cover display will be edge-to-edge and slightly curved at the edges, the camera flash will be located below the rear microphone in the camera plateau, the rear microphone has a new design consisting of five drilled holes, and the front-facing camera on the inner display is located on the top left. This will almost certainly have implications for the Dynamic Island.

On the device's color, Dickson's observation corroborates a report from Friday, in which the Weibo leaker known as "Instant Digital" suggested that there may be no black finish, with white potentially being the only option. Bloomberg's Mark Gurman previously reported that Apple planned to avoid bold colors and stick to traditional finishes.

It is worth noting that several new high-end products such as the Apple Watch Ultra and Vision Pro only launched with one color option. The approach would be broadly consistent with how Apple has handled generationally significant launches before. The iPhone X debuted in November 2017 in just two colors, Silver and Space Gray, at a then-record starting price of $999. The iPhone XS that followed a year later added Gold to the lineup, and Apple may take the same incremental approach with the iPhone Ultra over time.

The foldable iPhone is expected to be announced in September 2026 alongside the ‌iPhone 18 Pro‌ and ‌iPhone 18 Pro‌ Max, at a starting price Gurman says will cross the $2,000 threshold.Related Roundup: iPhone FoldTags: Foldable iPhone, Sonny Dickson
This article, "Best Look at Foldable iPhone Design Revealed, May Only Come in White" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
A researcher has reverse-engineered the iOS SDK that Bright Data embeds in consumer apps and documented how it turns devices, including always-on smart TVs, into exit nodes that relay web-scraping traffic for a data business Bright Data markets heavily to the AI industry. The company, the successor to Luminati, operates what it calls the largest residential proxy network in the world,View the full article
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a high-severity security flaw impacting SolarWinds Serv-U multi-protocol file server software to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. The vulnerability, tracked as CVE-2026-28318 (CVSS score: 7.5), is a denial-of-service (DoS) bug that causes the service to crashView the full article
Two things landed within days of each other this week. A security startup reported 21 previously unknown vulnerabilities in FFmpeg, the media library inside almost everything that touches video, all of them found by an autonomous AI agent. The same week, Google shipped Chrome 149 with patches for 429 security bugs, the most ever in a single release. Only the FFmpeg bugs were found by AI.View the full article
Microsoft's GitHub repositories have become the latest to fall victim to the ongoing Miasma self-replicating supply chain attack campaign. The incident impacted 73 Microsoft repositories across four of its GitHub organizations, including Azure, Azure-Samples, Microsoft, and MicrosoftDocs, per OpenSourceMalware. The development has GitHub to disable access to those repositories. "Access to thisView the full article
Cisco has warned that a high-severity security flaw impacting Catalyst SD-WAN Manager has come under active exploitation. The vulnerability, tracked as CVE-2026-20245, carries a CVSS score of 7.8 out of a maximum of 10.0. It affects the following deployment types - On-Prem Deployment Cisco SD-WAN Cloud-Pro Cisco SD-WAN Cloud (Cisco Managed) Cisco SD-WAN for Government (FedRAMP) "AView the full article
Introduction
In 2026, no-code platforms have revolutionized the way businesses and individuals build applications. These platforms enable users with little to no coding experience to create functional, custom solutions. Whether it’s designing websites, automating processes, or building complex enterprise-level applications, no-code tools have democratized software development, making it accessible to everyone from small businesses to large enterprises.
The importance of no-code platforms in 2026 lies in their ability to reduce development costs, speed up time to market, and empower non-developers to contribute to digital transformation efforts. As the demand for digital solutions continues to grow, having the right no-code platform can be a game-changer. When choosing a no-code platform, users should consider factors like ease of use, customization options, scalability, integrations, and pricing to find the tool that best fits their needs.
Top 10 No-Code Platforms Tools in 2026
1. Bubble
Short Description:
Bubble is a powerful no-code platform that allows users to build complex web applications without writing a single line of code. It is ideal for entrepreneurs and startups looking to rapidly prototype or build fully functional apps.
Key Features:
Drag-and-drop interface for designing responsive web pages Built-in database and API integrations Custom workflows and logic for complex actions Real-time collaborative editing Hosting and scalability options Pros & Cons:
Pros:
Flexible and customizable Supports complex applications like social networks or marketplaces Strong community and extensive resources Cons:
Steep learning curve for beginners Performance may slow with high user traffic 2. Atoms
Short Description:
Atoms is a no-code AI platform that turns a plain-language idea into a working website or app. Unlike most vibe coding tools such as Lovable, Replit, and similar prompt-to-app builders that rely on one model to generate everything, Atoms runs a team of specialized AI agents, including a Product Manager, Engineer, Data Scientist, and others, to research, design, build, and help launch the product.
Built on MetaGPT, a 68K-star open-source multi-agent framework and one of the most-referenced projects in AI agent research, Atoms is designed for non-technical founders who want to go from idea to live product without hiring a full team. Since launching in early 2026, Atoms has passed 1M users and has been stress-tested across hundreds of thousands of real build sessions.
Key Features:
Multi-agent AI workflow with specialized roles such as Product Manager, Engineer, and Data Scientist Plain-language app and website generation for non-technical users Visual editor for building complete pages and user flows without code Built-in user authentication, data storage, and Stripe payments Research, design, build, launch, user acquisition, and monetization support in one platform Multi-language natural-language input, so users are not limited to English-only prompts Powered by MetaGPT, a 68K-star open-source multi-agent framework with strong credibility in AI agent research Free entry point, with paid plans for custom domains and production hosting Pros & Cons:
Pros:
Uses a team of AI agents instead of relying on a single prompt or one model Built on MetaGPT, a 68K-star open-source framework and highly referenced AI agent research project Covers the full product loop: research, design, build, launch, user acquisition, and monetization Includes authentication, data storage, and Stripe payments out of the box Suitable for non-technical founders who want to ship real websites, apps, and MVPs without a developer Supports multi-language input for users building in their own language Already passed 1M users since launching in early 2026 Stress-tested across hundreds of thousands of real build sessions One Atoms subscription can replace a designer, a developer, and separate auth, payments, and hosting tools Cons:
Custom domains and production hosting require a paid plan Newer than longer-established no-code builders, so community templates and third-party tutorials are still developing The multi-agent workflow adds a review step, which can take slightly longer than one-shot prompt-to-app tools 3. Airtable
Short Description:
Airtable combines the simplicity of a spreadsheet with the power of a database, allowing users to manage projects, workflows, and data effortlessly. It is used by a wide range of industries, including marketing, education, and logistics.
Key Features:
Customizable tables, fields, and views Advanced filtering, sorting, and search capabilities Integrates with over 1,000 apps through Zapier Automations for streamlining workflows Collaboration tools for teams Pros & Cons:
Pros:
Versatile for various use cases (project management, CRM, etc.) Intuitive and easy-to-learn interface Flexible API integrations Cons:
Limited formula capabilities for advanced users Can become expensive as team size grows 4. OutSystems
Short Description:
OutSystems is an enterprise-grade no-code platform that offers powerful tools for building scalable web and mobile apps. It is used by large companies to accelerate application development and streamline their IT infrastructure.
Key Features:
Full-stack development capabilities Built-in integrations with popular enterprise systems Automated testing and continuous deployment Real-time collaboration tools High scalability for enterprise applications Pros & Cons:
Pros:
Enterprise-level features for large businesses Robust security and compliance features Ideal for cross-platform development Cons:
Requires technical knowledge for advanced features Pricing can be prohibitive for small businesses 5. Webflow
Short Description:
Webflow is a no-code platform specifically designed for creating responsive websites. It combines web design, content management, and hosting into a single platform, making it a popular choice for designers and marketers.
Key Features:
Drag-and-drop website builder with full customization CMS for managing dynamic content SEO tools to optimize your website’s performance Integrated e-commerce for online stores Hosting and security features included Pros & Cons:
Pros:
Highly customizable and scalable Powerful CMS for dynamic content No-code approach with flexibility Cons:
Steeper learning curve compared to other platforms Some limitations for large-scale websites 6. Glide
Short Description:
Glide is a no-code platform that transforms Google Sheets into mobile apps. It is perfect for individuals and small businesses who need to quickly create apps using data they already have in spreadsheets.
Key Features:
Converts Google Sheets into mobile apps instantly Customizable layouts and components User authentication and access controls Real-time data syncing with Google Sheets In-app purchases and payments Pros & Cons:
Pros:
Quick and easy to use for Google Sheets users Ideal for creating simple mobile apps Free tier available Cons:
Limited design and customization options Less suitable for complex applications 7. Wix
Short Description:
Wix is a no-code website builder that empowers users to create stunning websites quickly. It is popular for small businesses and individuals looking to build a professional web presence without hiring developers.
Key Features:
Drag-and-drop website builder with pre-designed templates E-commerce and blogging capabilities AI-driven design suggestions Mobile optimization for responsive websites Integrates with multiple third-party apps Pros & Cons:
Pros:
Extremely easy to use with a visual editor Variety of templates and features for different industries Affordable pricing plans Cons:
Limited flexibility for complex websites May not scale well for large businesses 8. Integromat
Short Description:
Integromat is an automation tool that allows users to connect apps and automate workflows without writing any code. It is great for businesses looking to streamline processes and reduce repetitive tasks.
Key Features:
Connects over 1,000 apps for seamless integrations Visual interface for designing automation workflows Customizable triggers and actions Real-time error handling Detailed analytics and logs for tracking automations Pros & Cons:
Pros:
Powerful automation capabilities Large number of pre-built integrations Affordable and flexible pricing Cons:
Can become complex for advanced workflows Limited documentation for beginners 9. Thunkable
Short Description:
Thunkable is a no-code platform for building cross-platform mobile apps. It allows users to design, build, and deploy apps for both Android and iOS with an intuitive drag-and-drop interface.
Key Features:
Cross-platform app development for Android and iOS Real-time preview and testing on devices Customizable components and layouts API and database integration Monetization options for in-app purchases Pros & Cons:
Pros:
User-friendly interface for beginners Ideal for mobile-first applications Allows for app monetization Cons:
Limited functionality for more complex apps Some users report performance issues 10. Zapier
Short Description:
Zapier is an automation tool that connects various apps and services to automate workflows. It’s an essential tool for businesses looking to streamline processes, saving time by automating repetitive tasks.
Key Features:
Connects over 2,000 apps for seamless integrations Customizable “Zaps” for automating workflows Supports multi-step workflows and conditional logic Real-time syncing across apps Intuitive interface with easy-to-create automation Pros & Cons:
Pros:
User-friendly and requires no coding Huge number of integrations with popular apps Flexible pricing with a free tier Cons:
Limited functionality in the free version Can become costly with high usage Comparison Table
Tool NameBest ForPlatform(s) SupportedStandout FeaturePricingG2/Capterra/Trustpilot RatingBubbleStartups, EntrepreneursWebFull-stack app developmentFree / Starts at $29/month4.5/5AdaloMobile App DevelopersiOS, AndroidNative mobile appsFree / Starts at $50/month4.7/5AirtableTeams, Project ManagersWeb, iOS, AndroidCustomizable databasesFree / Starts at $10/month4.6/5OutSystemsEnterprisesWeb, iOS, AndroidEnterprise-grade appsCustom pricing4.5/5WebflowDesigners, Small BusinessesWebResponsive websitesFree / Starts at $12/month4.6/5GlideGoogle Sheets UsersiOS, AndroidGoogle Sheets integrationFree / Starts at $25/month4.8/5WixSmall BusinessesWebAI-powered designFree / Starts at $14/month4.5/5IntegromatTeams, AutomatorsWebApp integrationsFree / Starts at $9/month4.7/5ThunkableMobile App DevelopersiOS, AndroidCross-platform developmentFree / Starts at $21/month4.4/5ZapierBusiness UsersWebWorkflow automationFree / Starts at $19.99/month4.6/5 Which No-Code Platform Tool is Right for You?
Choosing the right no-code platform depends on several factors including your use case, budget, and the complexity of your project. Here’s a decision guide to help:
For mobile app development: Adalo, Thunkable For website development: Webflow, Wix For workflow automation: Zapier, Integromat For building complex web apps: Bubble, OutSystems For data management and project management: Airtable, Glide Conclusion
No-code platforms are increasingly critical in enabling digital transformation, especially in 2026 when speed and flexibility are crucial. From small startups to large enterprises, these platforms make it possible for non-developers to create robust applications without technical barriers. Choosing the right tool depends on your specific needs, whether it’s mobile app development, website creation, or workflow automation. We encourage you to explore demos or free trials to see which tool aligns best with your business goals.
FAQs
What are the best no-code platforms for building mobile apps?
Adalo and Thunkable are great for building mobile apps without code.
Are no-code platforms suitable for enterprises?
Yes, platforms like OutSystems and Bubble are built for enterprise-grade applications and scalability.
Can I automate workflows using no-code platforms?
Yes, Zapier and Integromat are excellent tools for automating workflows.
Do no-code platforms offer integrations with other apps?
Yes, most no-code platforms, such as Airtable and Zapier, offer extensive integrations with other apps.
How much do no-code platforms cost?
Pricing varies from free plans to custom pricing for enterprise solutions, with most platforms offering tiered pricing to fit different needs.
View the full article
Apple's big week for developers is just around the corner, and that means WWDC 2026 will also be giving everybody else their first peek at what Apple has in store for iOS 27, macOS 27 and more later this year.


Other notable Apple news this week included the popularity of the budget MacBook Neo, the status of new Apple TV and HomePod mini models, iOS 26.5.1 and macOS 26.5.1 bug-fix updates, and more, so read on below for all the details!

Top Stories

What to Expect From WWDC 2026: Gemini-Powered Siri, iOS 27, macOS 27 and More

Apple's annual developer conference WWDC returns for 2026 next week, so be sure to check out our comprehensive guide of everything we're expecting to see at Monday's keynote event.


Apple this week teased the event with a new "All systems glow" tagline, a play on the phrase "all systems go," and it likely hints at Siri's rumored new design on iOS 27. Both a dedicated Siri app and a new "Search or Ask" feature in the iPhone's Dynamic Island will reportedly have a dark color scheme with glowing elements, as shown in leaked images last week.

Apple has also shared new WWDC 2026-themed wallpapers, an Apple Music playlist, and a "Get Ready" video to help developers prepare to get the most out of next week's conference.

MacBook Neo is So Popular That Apple Reportedly Doubled Production

On an earnings call in late April, Apple's CEO Tim Cook said that customer response to the MacBook Neo was "off the charts," and the popularity of the laptop has reportedly led the company to significantly boost production.


Apple supply chain analyst Ming-Chi Kuo this week said he believes that MacBook Neo shipments to Apple were doubled from an initial target of 5 million units to 10 million units in 2026 at some point after the laptop launched in March.

The MacBook Neo is quickly reshaping the low-cost laptop segment, with companies like Acer, ASUS, and Dell reacting to the shift and in some cases already introducing their own competing products.

New Apple TV and HomePod Mini Are 'Nearly Ready' to Launch, New Siri Remote Also Rumored

New models of the Apple TV 4K and HomePod mini are "nearly ready to go," according to the latest word from Bloomberg's Mark Gurman.

Subscribe to the MacRumors YouTube channel for more videos.
Both devices have been ready "for months," but Apple is holding off on launching them until the more personalized version of Siri is available, he said.

"I am told the hardware for the next Apple TV set-top box and HomePod mini has been done for months and that both devices are already in active use among employees at the company's headquarters in Cupertino, California," wrote Gurman.

Apple Releases iOS 26.5.1 to Fix Charging Issue on iPhone Air and iPhone 17 Models

Apple this week released iOS 26.5.1, a bug fix update that is only available for the iPhone Air and all models in the iPhone 17 lineup. According to Apple's release notes, the update fixes a previously documented charging issue with ‌iPhone Air‌ and ‌iPhone 17‌ models.


macOS Tahoe also got a 26.5.1 release this week, and it fixes an issue that can affect certain enterprise users on Macs equipped with the latest M5 chip.

First 'Confirmed' iPhone Ultra Color Allegedly Revealed in Leaked Image

Apple is expected to launch its first foldable iPhone later this year. Rumors suggest the "iPhone Ultra" will come in two color options, and a leaker shared an image this week that allegedly shows one of them.


Posted on Weibo by the Chinese leaker known as Ice Universe, the image purportedly offers a first glimpse of Apple's foldable in white. The device is believed to have entered early mass production, but the model shown is likely a dummy. Regardless, fellow leaker Instant Digital has said white is so far the only "confirmed" finish that the device will be available in.

The iPhone Ultra will reportedly feature vapor chamber cooling and a liquid metal hinge, with production efforts said to be ramping up now following reports of some delays due to various challenges with the complicated high-end device.

iPhone 18 Pro Battery Capacities Allegedly Leaked

Battery capacities for Apple's upcoming iPhone 18 Pro have allegedly surfaced, and the numbers suggest only a modest increase over the iPhone 17 Pro.


According to prolific Weibo-based leaker Digital Chat Station, Apple is testing the iPhone 18 Pro with different battery capacities for the China and U.S. versions of the device, similar to last year's iPhone 17 Pro models. The Chinese model is said to have a roughly 4,056 mAh battery, while the U.S. model is said to have a roughly 4,288 mAh battery.

In other iPhone 18 Pro rumors, the all-new variable aperture camera will reportedly cost Apple 50% more than the corresponding unit in the current iPhone 17 Pro, while some fresh dummy units revisited the expected colors for this year's Pro models.

MacRumors Newsletter

Each week, we publish an email newsletter like this highlighting the top Apple stories, making it a great way to get a bite-sized recap of the week hitting all of the major topics we've covered and tying together related stories for a big-picture view.

So if you want to have top stories like the above recap delivered to your email inbox each week, subscribe to our newsletter!Tag: Top Stories
This article, "Top Stories: 'All Systems Glow' for WWDC, MacBook Neo Popularity, and More" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Apple's 2026 Worldwide Developers Conference is just days away, and it's going to be an interesting event because it will give us a look at Apple's AI plans. We'll see how Apple is going to compete with OpenAI, Anthropic, and Google in the months to come with an AI version of Siri and new AI features for its apps.

Subscribe to the MacRumors YouTube channel for more videos.
iOS 27 Siri Changes

Big changes are coming in iOS 27, iPadOS 27, and macOS 27, and Apple employees haven't been able to keep quiet. We've heard details on a long list of AI updates Apple has planned, with enough detail that screenshots could be recreated by Bloomberg. Much of what's rumored relates to AI features and changes.

New Siri Features

Based on Apple's promises and rumors about what's coming in the new version of iOS, ‌Siri‌ in ‌iOS 27‌ will be nothing like ‌Siri‌ in iOS 26. In 2024, Apple showed us three ways that ‌Siri‌ will improve, but two years have passed and extra work has been done, so we're expecting even more than what Apple demonstrated back then.


‌Siri‌ is going to be able to draw on user data and information from Apple devices, with access to personal data for completing tasks. The assistant is also going to be able to do more with apps, and it will be able to tell what's on the screen to answer questions.

Personal Context

‌Siri‌ will be able to access emails, messages, files, photos, and more, learning all about you to help you complete tasks and keep track of what you've been sent. Apple offered some examples of how personal context will work:

Show me the files Eric sent me last week.
Find the email where Eric mentioned ice skating.
Find the books that Eric recommended to me.
Where's the recipe that Eric sent me?
What's my passport number?


Onscreen Awareness

Onscreen awareness will let ‌Siri‌ see what's on your screen and complete actions involving whatever you're looking at. If someone texts you an address, you can tell ‌Siri‌ to add it to their contact card. Or if you're looking at a photo and want to send it to someone, you can ask ‌Siri‌ to do it for you.

App Integration

‌Siri‌ will be able to do more in and across apps, performing actions and completing tasks that are just not possible with the personal assistant right now. We don't have a full picture of what ‌Siri‌ will be capable of, but Apple gave a few examples of what to expect.

Moving files from one app to another.
Editing a photo and then sharing it with someone.
Getting directions home and sending the ETA in the Messages app.
Drafting and then sending an email.

‌Siri‌ will be able to complete tasks in Apple apps and in third-party apps, with developers able to expose app capabilities to ‌Siri‌.

Siri Chatbot

Apple needs a ‌Siri‌ app because ‌Siri‌ is becoming a chatbot. ‌Siri‌ will be like ChatGPT or Claude, able to draw on information from the web to provide answers to questions.

‌Siri‌ will be deeply integrated into iOS, iPadOS, and macOS at the system level, and can draw on device information. It will know more personal context than before, and will be able to access emails, texts, photos, calendar information, contacts, notes, and other personal data. Some of what ‌Siri‌ will be able to do:

Search the web for information
Generate images
Generate content
Summarize information
Analyze uploaded files
Use personal data to complete tasks
Ingest information from emails, messages, files and more
Write emails, notes, and texts
Analyze open windows and on-screen content to take action
Control device features and settings
Search for on-device content, replacing Spotlight

‌Siri‌ will be integrated into Apple apps like Mail, Messages, Photos, and Apple TV.

Siri Design

With ‌Siri‌'s chatbot transition, Apple will be making multiple Siri-related design changes. ‌Siri‌ will largely live in the Dynamic Island, and Bloomberg says there will be new ways to access ‌Siri‌.

Swiping down from the center of the iPhone's display from the Home Screen or any app will bring up a new "Search or Ask" feature in the ‌Dynamic Island‌. A glowing, pill-shaped animation will be displayed in the ‌Dynamic Island‌ to indicate that ‌Siri‌ is processing a request.

When ‌Siri‌ has an answer, the ‌Dynamic Island‌ will expand into a transparent card with the result, incorporating images, info from the web, notes and other information relevant to the query or request. Swiping on the results card will bring up a conversation mode that looks similar to an iMessage chat, and there will be an option to transition to the full ‌Siri‌ app.

Search or Ask replaces ‌Siri‌ Suggestions and will let users launch apps, start text messages, ask about the weather, add calendar appointments, trigger shortcuts in apps, and search the web using Apple's new AI web search feature. Search or Ask queries can also be sent to third-party chatbot services like ChatGPT instead of ‌Siri‌.

While ‌Siri‌ can be accessed through a swipe in ‌iOS 27‌, Apple is keeping the "Hey ‌Siri‌" wake word and ‌Siri‌ activation through the Side button. With the new center swipe, accessing the Notification Center will be done with a swipe down on the left side of the display. Swiping down on the right side will continue to bring up Control Center. With the change to how Notification Center is accessed, notifications will now slide in from the left side of the iPhone instead of the top of the display.

Apple will also integrate an "Ask ‌Siri‌" button into the menus of its apps, giving users a way to send content directly to ‌Siri‌ alongside a request.

The new ‌Siri‌ interface uses dark colors with no light mode available. ‌Siri‌ UI elements have a dark background with color accents that mirror the options Apple is using in WWDC imagery. Apple's WWDC website features a white Swift bird with subtle highlights in pink, dark blue, purple, and orange.


Standalone Siri App

Bloomberg recently shared a mockup of what the standalone ‌Siri‌ app will look like, and it's similar to other chatbot apps like ChatGPT, Claude, or Gemini.

‌Siri‌ will support text or voice-based conversations. The app will open with an "Ask ‌Siri‌" bar where users can type in a question. A paperclip icon will be available for attaching images, PDFs, and other documents. Apple will provide prompts with suggestions on what users can ask.

Questions will resemble iMessage chat bubbles, with Apple adopting a design that is familiar to users. Responses will include links, images, and other information.

A section of the app will be dedicated to past conversations that can be shown in a card-style interface with conversation summaries, or a list view. Users will be able to tap into a conversation to continue it.

Siri Privacy

Apple plans to lean into privacy as a central principle of its approach to AI, giving it a way to distinguish ‌Siri‌ from other chatbot options. Apple will likely aim to keep as much processing on-device as possible to limit the amount of data that leaves a user's device.

Apple said that Apple Intelligence features will continue to run on Apple devices and Private Cloud Compute.

Apple will have limits around memory, including restrictions on the information that can persist and how long it is kept. Users will be able to auto-delete ‌Siri‌ chats and requests after a set period of time, like 30 days or one year. There will also be an option to keep chats permanently, and chats will sync across Apple devices signed into the same iCloud account.

‌Siri‌ can be turned off right now, as can ‌Apple Intelligence‌, and there's no sign that's going to change in ‌iOS 27‌. Users who don't want to enable ‌Siri‌ or use the new features will not have to.

Siri Extensions

Apple is letting rival chatbots integrate with ‌Siri‌ in ‌iOS 27‌, expanding on the OpenAI partnership that currently allows ‌Siri‌ to hand off requests to ChatGPT, Bloomberg says Apple plans to allow other chatbots like Claude and Gemini to work with ‌Siri‌, so users will be able to send questions to their favorite chatbot instead of ‌Siri‌.

iPhone users will be able to select which services they want to use inside ‌Siri‌ through "Extensions" options coming to ‌iOS 27‌, iPadOS 27, and ‌macOS 27‌. The options will be available in the ‌Apple Intelligence‌ and ‌Siri‌ section of the Settings app, with Apple providing download links for chatbot apps. There will be a dedicated Extensions section in the App Store that will serve as a way to choose a third-party AI app.

‌Siri‌ will be the default for the Search or Ask interface, but rumors suggest users will be able to select other chatbots to speak with. Users will also be able to choose third-party AI services as the default for ‌Apple Intelligence‌ features like Writing Tools and Image Playground, expanding ‌Apple Intelligence‌ integration beyond ChatGPT.

Apple also plans to let users choose voices from third-party AI to use instead of ‌Siri‌, so there will be a distinct audio difference between a response from ‌Siri‌ and a response from the user's chatbot of choice. ‌Siri‌ would use one voice, while responses from third-party AI options would use another voice.

Google Gemini Backbone

To get ‌Siri‌ up and running, Apple partnered with Google to use Gemini AI models instead of using its own AI models. Apple signed a multi-year deal to use Google's Gemini models and cloud technology for its Apple Foundation Models, and it's costing Apple somewhere around $1 billion a year.


Google and Apple said that the next generation of Apple Foundation Models will be based on Google Gemini models, with Gemini used to power future ‌Apple Intelligence‌ features and the more personalized version of ‌Siri‌.

Apple said Google's AI technology offered the most capable foundation for its models.

iOS 27 Apps and Feature Updates

Camera

Apple is moving Visual Intelligence from the Camera Control button to the Camera app in ‌iOS 27‌. Bloomberg has shared images of the new interface, featuring a ‌Siri‌ mode that's available alongside the existing Photo, Video, Portrait, and Panorama modes. When in ‌Siri‌ mode, the existing Camera app shutter button will feature the ‌Apple Intelligence‌ logo, letting users know the ‌Siri‌ features are available.


‌Siri‌ mode is a renaming of ‌Visual Intelligence‌, and it will make the feature more visible. Accessing ‌Visual Intelligence‌ in ‌iOS 26‌ requires users to hold down the Camera Control button or assign the feature to the Action button, and many people may not even know it exists.

‌Visual Intelligence‌ can identify objects, plants, animals, art, books, and more, searching for whatever the user snaps on Google Image Search. In ‌iOS 27‌, ‌Siri‌ will be able to answer questions about what a user is looking at, providing information from the web.


Apple is adding new ‌Visual Intelligence‌ capabilities in ‌iOS 27‌, and they will be available through the Camera app ‌Siri‌ mode.

Nutrition - Users can scan nutrition labels on food packaging for calorie and macronutrient tracking using the Health app.
Contacts - ‌Visual Intelligence‌ will let users scan phone numbers and addresses on business cards and other print media, adding the information to the Contacts app.

Apple plans to make the Camera app more customizable in ‌iOS 27‌. iPhone users will be able to replace the top row of camera shortcuts with options of their choosing, selecting features like flash, exposure, timer, depth of field, photo styles, and resolution.

Camera controls, now labeled as widgets, can be placed at the top of the Camera interface in any order. Users can select widgets from a transparent widget tray that comes up from the bottom of the app and organizes widgets into categories like basic, manual, and settings.

The Camera app will have the same default layout that's available now with quick tap buttons for flash, Live Photos, and Night Mode, but the customizable widget interface will be added as an advanced layout that will appeal to professional users.

iPhone users can currently tap on an icon at the top right of the Camera app to access all of the Camera controls, but Apple is moving that view to the right of the shutter button in ‌iOS 27‌.

The Camera app is also going to get new grid and level options that will join the existing features.

Photos

The ‌Photos‌ app will have an Apple Intelligence Tools section when editing an image. According to Bloomberg, there will be new Extend and Reframe options.



Extend - Extend generates additional image content beyond the original frame of the photo, filling in scenery when changing the crop of an image. This tool will support expanding the edges of an image with zoom gestures.
Reframe - When used with spatial photos, Reframe will let users change the perspective of an image after it's captured.

Apple is also testing an AI photo editing feature that lets users request edits using natural language. Users would be able to tweak color, lighting, cropping, and other image parameters without having to use manual tools. The natural-language editing feature may not arrive in the first version of ‌iOS 27‌.

Shortcuts

The ‌iOS 27‌ Shortcuts app will support using natural language to create a shortcut with AI. Users will be able to tell ‌Siri‌ what they want to accomplish with a multi-step shortcut, and ‌Siri‌ will generate it.

The Shortcuts app will open with a prompt that says "What do you want your shortcut to do?" with a text field to enter a description. Shortcuts that are created using AI are then automatically installed and immediately available for use.

Wallet

The Wallet app is getting a "Create a Pass" option so users can generate digital passes from scans of physical items like movie tickets, concert passes, and gym membership cards.


Users can tap on the "+" button in the Wallet app and then scan a QR code on a pass or ticket if one is available. If there is no QR code available, there will be an option to create a custom pass.

There are three pass types in Create a Pass, each with a different color. Apple is using purple for events, blue for memberships, and orange for other types of passes. Users can customize images, colors, style, and text on the digital passes.

Apple is also adding an AI bill-splitting feature that will work with Apple Cash. iPhone users will be able to take a photo of a receipt and generate Apple Cash payment requests for different people.

Image Playground and Genmoji

Apple is updating the ‌Image Playground‌ app. The interface for generating a new image has fewer controls and a "describe a change" option for editing images that are created. Previously created images are displayed in a grid with more rounded edges, and instead of a New Image button, there's a "+" button.


Apple has also been testing new models that produce more lifelike images, so we could see new image generation capabilities in ‌iOS 27‌ with better image quality.

Genmoji is also getting an update so it will use fewer resources, causing less battery drain and fewer heat problems. ‌Genmoji‌ will be better quality with a new ‌Genmoji‌ model, and a Suggested ‌Genmoji‌ feature will bring up custom emoji ideas based on your media and text history.

Writing Tools

Apple is testing an expanded version of Writing Tools that will do more rewriting and text generation than the current version. There is a "Write with ‌Siri‌" toggle at the top of the keyboard, according to Bloomberg, along with a "Help Me Write" option that comes up when ‌Siri‌ is activated while a text field is open.

Apple is going to add a dedicated AI grammar checker that will work alongside the current spell check. When writing in Messages, Mail, and other apps there will be a translucent menu that slides up from the bottom of the iPhone's screen, and it will show suggested revisions next to the original written text.

Users can go through the suggestions and accept or reject them one by one, approve all of the changes at once, or ignore the changes.

Other Features


Wallpaper - There will be an option to generate custom wallpapers with the ‌Image Playground‌ app, with the feature built into the interface for selecting a new wallpaper.
Safari - Safari will get an updated start page with four tabs for switching between favorites, bookmarks, Reading List, and history.
Calendar - Rumors suggest the Calendar app will incorporate new AI features. ‌Siri‌ will also be able to draw on information in the app.
Health - With a new calorie scanning feature coming to the Camera app, calorie tracking will be more prominent in the Health app. Apple was also planning a Health+ subscription service, and while that's been scaled back, there could be other AI health app changes.
Weather - The Weather app will have a new Conditions panel for switching between temperature, rain, and wind from the main interface, without the need to tap into a weather module.
AirPods settings - The AirPods interface in the Settings app will be simplified, with options featuring better organization. Major features like hearing health will be easier to find.
AirPlay Alternatives - Apple is adding a feature that will let users beam content to AirPlay alternatives like Google Cast. It could be limited to iPhone users in the EU because it is being implemented as a Digital Markets Act requirement.


iOS 27 System-Wide Design Changes

There are system-wide design changes coming in ‌iOS 27‌. The separate tab bar in apps like Apple Music, Podcasts, News, and ‌Apple TV‌ will be adjusted to combine search with the other navigation options. Apple separated search in many apps when introducing Liquid Glass, but it's reverting to the original look.

When using the on-screen keyboard, there's a new animation that shows the keys sliding up from the bottom of the iPhone interface, and Apple is adding redo and undo controls for easier customization of the ‌Home Screen‌'s icon and widget layouts.



Apple doesn't plan to make major changes to the Liquid Glass aesthetic in ‌iOS 27‌, but the company is mulling a system-wide setting that would precisely adjust the look of the interface. In iOS 26.2, Apple added a slider that lets users adjust the opacity of Liquid Glass for the Lock Screen's clock, and that setting could be expanded to the entire operating system.

iOS 27 Updates for Foldable iPhone

The first foldable iPhone will be introduced in September. Rumors suggest that it will feature a 5.5-inch display when folded, and a 7.8-inch display when it's opened up like a book.



An iPhone with a larger display will require major updates to iOS, and ‌iOS 27‌ will focus on building new interfaces and experiences made for a larger smartphone display.

The iPhone Fold will operate like a cross between an iPhone and an iPad, but it will run iOS, not iPadOS, and it won't support ‌iPad‌ apps. When unfolded, the iPhone will have an iPad-like layout that supports multitasking with two apps side-by-side. Many of Apple's iPhone apps will have sidebars on the left of the display, with Apple providing developers with tools to easily adapt their apps to the new layout.

Apple is using a wider design for the ‌iPhone Fold‌ than most foldable smartphone makers have used, and it is rumored to have an iPad-like 4:3 aspect ratio. When the iPhone is closed, it will have a standard iPhone layout that looks like the version of iOS we have now.

iOS 27 Satellite Features

Apple is working on several new satellite features for the iPhone, and it's possible some features could be introduced as soon as 2027.

Apple Maps via satellite
‌Photos‌ in Messages via satellite
Satellite API framework for third-party apps
Satellite over 5G
Satellite connectivity without the need for a view of the sky


iOS 27 Accessibility Updates

Each May, Apple previews new accessibility features that are coming later in the year. This year, Apple showed off some new options that are expected in the ‌iOS 27‌ update.





Apple is adding new ‌Apple Intelligence‌ features to VoiceOver, Magnifier, Voice Control, and Accessibility Reader.



VoiceOver Image Explorer uses ‌Apple Intelligence‌ for detailed descriptions of images throughout the system, including photographs, scanned bills, and personal records. Users can press the Action button on the iPhone to ask questions about what the camera viewfinder sees, with follow-up questions supported in natural language.
Magnifier brings Apple Intelligence-powered visual descriptions to its high-contrast interface for users with low vision, with support for spoken commands like "zoom in" or "turn on flashlight."
Voice Control gains natural language input so users can describe onscreen elements conversationally, such as "tap the guide about best restaurants" or "tap the purple folder," rather than memorizing exact label names or numbers. Apple says the feature can also help when users want to access on-screen elements that don't have clear accessibility labels.
Accessibility Reader gains support for more complex document layouts including scientific articles with multiple columns, images, and tables, plus on-demand summaries and built-in translation that retains a user's custom font, color, and formatting preferences.
Generated Subtitles use on-device speech recognition to automatically transcribe spoken audio in uncaptioned video content, including clips recorded on iPhone, received from friends and family, or streamed online, across the iPhone, ‌iPad‌, Mac, ‌Apple TV‌, and Apple Vision Pro. The feature will be available in English in the U.S. and Canada at launch.


iOS 27 Performance and Stability

Bloomberg has described iOS 27 as a "Snow Leopard" update, suggesting that Apple will focus on improving underlying performance and quality.

Apple is prioritizing cleaning up the iOS code and removing anything that's outdated, which could mean upgrading apps to improve performance and rewriting some existing features to be more efficient. The code updates could provide a more responsive, faster version of iOS.

Apple is also aiming for efficiency improvements that could translate into tangible battery life gains.

iOS 27 Compatibility

‌iOS 27‌ is expected to drop support for the iPhone 11, iPhone 11 Pro, iPhone 11 Pro Max, and second-generation iPhone SE. It will be available on all other iPhones that support ‌iOS 26‌.

iPadOS 27

Many of the features that are coming in ‌iOS 27‌ will also extend to the ‌iPad‌, including all of the new ‌Siri‌ capabilities. We haven't heard rumors of iPad-specific features as of yet.

macOS 27

Like ‌iOS 27‌ and iPadOS 27, ‌macOS 27‌ will adopt the new version of ‌Siri‌ with chatbot capabilities, personal context and the ability to access data on your Mac, and improved integration in and between apps. A standalone ‌Siri‌ app for the Mac is likely.


We've heard a lot about what ‌Siri‌ will look like on the iPhone, with it set to be integrated into the ‌Dynamic Island‌, but no detail on how ‌Siri‌ will look on the Mac. The ‌Siri‌ Mac interface will be more of a surprise.

The ‌Photos‌ app feature for AI reframing and extending an image will be available, as will the text-based option to create a Shortcut with natural language commands. Grammar checking capabilities will be added to Writing Tools, and ‌Image Playground‌ and ‌Genmoji‌ will see improvements to the underlying models. Apple is experimenting with more realistic models, so ‌Image Playground‌ might be able to generate content that's not so cartoonish.

Safari is expected to have a new feature that uses AI to automatically group tabs that are similar to one another, expanding on the tab groups feature.

In ‌iOS 27‌, we're getting some minor tweaks to Liquid Glass, including tab bars that do away with the standalone search option and possibly a slider for adjusting the overall look of Liquid Glass, but we know less about what to expect for Liquid Glass on the Mac. There has been criticism of the Mac's Liquid Glass interface in particular, so Apple could have changes planned.

Bloomberg claims Apple is working on a "slight redesign" for ‌macOS 27‌, with plans to address "quirks" with shadows and transparency.

Apple is working on an OLED MacBook Pro with a touchscreen, so there could be new touch-based interface options hidden in ‌macOS 27‌. The OLED ‌MacBook Pro‌ likely isn't launching until early 2027, so it's not something we're expecting to see in the launch version of ‌macOS 27‌.

macOS Naming

We don't know what Apple is going to call ‌macOS 27‌, but it will likely continue to have a California landmark name. The filename of Apple's hashmoji for WWDC 2026 on X is "Project Big Bear," leading to speculation that Apple might go with macOS Big Bear.

The filename could be unrelated to ‌macOS 27‌, and it's possible Apple will choose something else entirely. Apple has trademarked multiple California-themed names in the past, including Diablo, Grizzly, Mammoth, Miramar, Pacific, Redtail, Redwood, Shasta, Skyline, and Tiburon.

Performance Improvements

Apple has been working on refinements to macOS that will include bug fixes, performance improvements, and tweaks to boost battery life.

No More Intel Macs

Apple is dropping support for Intel Macs with ‌macOS 27‌, so if you have an Intel Mac, it's not going to be able to run the new Mac software. macOS Tahoe is the last version of macOS that will work on Intel Macs.

Apple is also phasing out Rosetta 2 support, and ‌macOS 27‌ will be the last version of macOS that includes it. Rosetta 2 lets Apple silicon Macs run apps built for Intel Macs, so older apps that still have the outdated architecture will no longer work in macOS 28.

Current Intel Macs that run ‌macOS Tahoe‌ but won't run ‌macOS 27‌ include the 13-inch ‌MacBook Pro‌ from 2020, the 16-inch ‌MacBook Pro‌ from 2019, the 27-inch iMac from 2020, and the 2019 Mac Pro.

watchOS 27

In watchOS 27, Apple plans to introduce new watch faces, including a variant of the Modular Ultra face. The new watch face will have a large time readout with three complications, and it will be available for all Apple Watch models.


We haven't heard anything else about new watchOS 27 features, and Apple Watch software updates tend to be on the smaller side. With Apple planning to add an option for generating a wallpaper using AI on the iPhone, it's possible there could be some Apple Watch equivalent feature.

Some of the new ‌Siri‌ features could work on the watch, and some of the AI features might transition, like grammar correction when writing or dictating on the watch.

tvOS 27

We haven't heard anything about tvOS 27, and ‌Apple TV‌ updates are usually not super exciting. With the ‌Apple TV‌ expected to be refreshed with a chip that works with ‌Apple Intelligence‌ later this year, we could see Apple introduce some AI features for the ‌Apple TV‌.


Better TV and movie recommendations are a possibility, as is a more capable ‌Siri‌ that is better at handling requests. There could also be new smart home integrations that will work alongside a centralized smart home hub Apple is rumored to be launching this year. One feature we do know about is larger text, which is an Accessibility option Apple is adding.

visionOS 27

visionOS 27 will apparently be "light on new features," but it could get the same AI app updates and ‌Siri‌ changes that are coming to Apple's other platforms.

New Hardware?

There are several products that Apple is still expected to launch in 2026, but it's not looking like any of them are going to be unveiled at WWDC. With several new software updates to cover and an all-new version of ‌Siri‌, Apple may not want to take the focus away from its software announcements.

We are expecting M5 Mac Studio and Mac mini updates at some point, plus there could be a new ‌iMac‌. Unfortunately, high RAM costs and chip shortages mean delayed Mac refreshes, and new models aren't expected until later in the year.

The low-cost ‌iPad‌ still hasn't been refreshed, and updates for the HomePod mini and ‌Apple TV‌ are apparently ready to go. There's also a new smart home hub tied to the new version of ‌Siri‌, but it's not likely to come out until ‌Siri‌ sees an official launch in the fall.

How to Watch

‌WWDC 2026‌ begins at 10:00 a.m. Pacific Time on June 8. Apple plans to stream the WWDC keynote on YouTube, the ‌Apple TV‌ app everywhere it's available, and the Apple Events website.


For those who are unable to watch the livestream, we'll have live coverage at MacRumors.com and the MacRumorsLive X (Twitter) account.

Launch Timeline

Betas of ‌iOS 27‌, iPadOS 27, ‌macOS 27‌, tvOS 27, watchOS 27, and visionOS 27 will be seeded to developers after Apple's keynote event. Public betas will come out in July, and after several months of testing, the updates will launch to the public in the fall.Related Roundups: iOS 27, macOS 27, WWDC 2026Tag: SiriRelated Forum: Apple, Inc and Tech Industry
This article, "What to Expect From WWDC 2026: Gemini-Powered Siri, iOS 27, macOS 27 and More" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Apple is now selling refurbished versions of the Apple Watch Series 11, Apple Watch Ultra 3, and Apple Watch SE 3 at discounted prices.


This is the first time the Series 11, Ultra 3, and SE 3 have been available through Apple's online refurbished store since the devices launched last September.

Refurbished pricing on the 46mm GPS Apple Watch Series 11 starts at $369, down from $429, while Apple Watch Ultra 3 pricing starts at $699, down from $799. Apple Watch SE 3 40mm models start at $209, which is $40 less than the standard $249 price.

Apple has limited colors and sizes available for the Apple Watch Series 11, but refurbished stock changes regularly. If you're looking for a specific color, you can check back later to see if it's in stock. Both ‌Apple Watch Ultra 3‌ colors are available, and there are also several SE 3 options in stock.

Refurbished devices go through a rigorous cleaning and inspection process prior to sale, according to Apple. Refurbished products feature the same one-year limited warranty as newly purchased devices, and they are eligible for AppleCare+.

Apple offers around a 15 percent discount on its refurbished products, but you can get even better prices from third-party sellers. Amazon has the Apple Watch Series 11 available starting at $299 this week.Related Roundups: Apple Watch 11, Apple Watch SE 3, Apple Watch Ultra 3Buyer's Guide: Apple Watch (Caution), Apple Watch SE (Buy Now), Apple Watch Ultra (Neutral)Related Forum: Apple Watch
This article, "Apple Starts Selling Refurbished Apple Watch Series 11, Ultra 3, and SE 3" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
AI agents are moving fast. According to our State of Agentic AI report, 60% of organizations already have AI agents in production, yet 40% cite security and compliance as the number-one barrier to scaling them further. And that gap between adoption and oversight is exactly where AI governance lives.
As AI takes on higher-stakes decisions and agents begin operating with greater autonomy, the organizations that lack clear guardrails face mounting exposure to regulatory penalties, security vulnerabilities, and reputational damage. AI governance closes that gap by establishing the rules, roles, and review processes that keep AI systems aligned with business goals, legal requirements, and ethical standards. This guide covers what AI governance is, why it matters, the key principles and frameworks shaping it, and how to start building a governance practice that scales with your AI ambitions.
What is AI governance?
AI governance is the system of frameworks, policies, and controls that direct how an organization builds, deploys, and oversees artificial intelligence. It defines who is accountable for AI decisions, what standards those systems need to meet, and how performance and compliance are monitored over time.
Think of it as the operating model for responsible AI. Just as software engineering teams rely on CI/CD pipelines, code reviews, and access controls to ship reliable software, AI governance provides the equivalent structure for AI systems. It brings together technical safeguards (like model monitoring and access policies), organizational processes (like review boards and risk assessments), and regulatory alignment (like compliance with the EU AI Act or NIST AI Risk Management Framework) into a unified approach.
AI governance is not just a policy document. It’s a living practice that spans the full AI lifecycle, from data collection and model training to deployment, monitoring, and retirement. And as AI systems grow more capable, governance needs to evolve with them.
Why is AI governance important?
AI is no longer experimental. Organizations are embedding it into hiring workflows, financial modeling, customer support, infrastructure management, and software development. When AI operates at that scale, the consequences of getting it wrong are significant.
And a lot could go wrong without the right guardrails. An automated hiring tool could filter out qualified candidates based on biased training data. A model running on sensitive customer data with no access controls, could create an exposure that only surfaces during a compliance audit. These scenarios are not far-fetched. They represent the kinds of governance gaps that organizations encounter when AI adoption outpaces oversight.
AI governance matters because it helps organizations:
Reduce risk and prevent harm. AI models can reflect biases in their training data, produce unreliable outputs, or behave unpredictably in production. Governance establishes testing, monitoring, and review processes that catch these problems early. Meet regulatory and compliance requirements. Legislation like the EU AI Act, the NIST AI RMF, and ISO/IEC 42001 are creating enforceable standards for AI. Organizations operating across jurisdictions need governance to stay compliant and avoid penalties. Build trust with users and stakeholders. Transparent AI practices, from explainable models to clear data-handling policies, give customers, partners, and employees confidence that AI is being used ethically. Protect data privacy and security. AI systems often process sensitive data. Governance defines how data is collected, stored, accessed, and used, reducing the risk of breaches or misuse. Scale AI with confidence. Without governance, every new AI initiative introduces uncoordinated risk. A well-designed governance framework turns AI adoption into a repeatable, auditable process rather than a series of one-off experiments. For enterprises where senior leadership actively shapes AI governance, the payoff is measurable. Research from Deloitte’s 2026 State of AI Report found that organizations with strong senior leadership involvement in AI strategy achieve significantly greater business value from their AI investments than those that delegate governance to technical teams alone.
Key principles of AI governance
While every organization will tailor governance to its specific context, most effective programs share a core set of key principles. These principles serve as the foundation for policies, processes, and technical controls.

Principle
What it means in practice
Transparency
AI systems should be understandable. Teams need to document how models are trained, what data they use, and how they arrive at decisions. Transparency builds trust and makes it possible to audit and troubleshoot AI behavior.
Accountability
Every AI system should have a clear owner. Governance assigns responsibility for decisions at each stage of the AI lifecycle, from data selection through deployment and monitoring. When something goes wrong, there should be no ambiguity about who is responsible.
Fairness and bias control
AI models can inherit and amplify biases present in training data. Governance programs include processes for evaluating datasets, testing for disparate outcomes, and correcting bias before models reach production.
Privacy and data protection
AI governance defines rules for how personal and sensitive data is collected, stored, processed, and shared. This includes compliance with data protection regulations like the General Data Protection Regulation (GDPR) and alignment with organizational data policies.
Safety and reliability
AI systems need to perform consistently and predictably across the environments where they are deployed. Governance establishes testing standards, performance benchmarks, and fallback mechanisms to keep systems reliable.
Human oversight
For high-stakes use cases, governance frameworks define where human review is required. This includes setting thresholds for automated decisions, designing escalation paths, and ensuring humans can intervene when AI behavior deviates from expectations.
Core components of an AI governance framework
Principles are the starting point, but turning them into a working program takes concrete building blocks. An effective AI governance framework typically includes the following components:
Policy and standards. The rules that govern AI development and use: acceptable use policies, data handling standards, model documentation requirements, and approval workflows. For governance to work, these need to be embedded in the workflows teams already use, not filed away in a wiki nobody checks. Risk assessment and management. A classification system that matches oversight to impact. Not every AI application warrants the same scrutiny, and a risk-tiered approach applies proportional controls. For teams building AI agents, this extends to security and access controls like runtime isolation and scoped permissions. Monitoring and observability. AI systems behave differently over time as data distributions shift and environments evolve. Governance defines what’s monitored, what triggers alerts, and what requires human intervention. Compliance and audit. How you verify that policies are actually being followed. Every significant action in the AI lifecycle should produce a record, from training data to production behavior, so compliance becomes a byproduct of good engineering rather than a separate manual process. Lifecycle management. Models need to be retrained, updated, versioned, and eventually retired. This component defines who owns each stage, what checks apply at each transition, and when to roll back or decommission. And before any of these components can function, organizations need clear ownership, whether that’s a dedicated AI ethics board, a cross-functional governance committee, or designated AI owners within each business unit. Without that, these components exist on paper only.
The regulatory landscape for AI governance
AI regulation is evolving quickly, and organizations operating across multiple jurisdictions need to track a growing patchwork of requirements. Here are the most significant frameworks shaping AI governance today:
The EU AI Act
The European Union’s AI Act, which entered into force in 2024, is the world’s first comprehensive AI regulation. It takes a risk-based approach, classifying AI systems into four tiers: 
Unacceptable risk (such as social scoring) High-risk (applications in employment, education, and law enforcement) Limited-risk (with specific transparency obligations) Minimal-risk (with few regulatory requirements)  Organizations deploying high-risk AI systems in the EU face strict compliance obligations, including conformity assessments, transparency requirements, and human oversight mandates. Penalties for noncompliance can reach up to 7% of global annual turnover, depending on the risk tier.
The NIST AI Risk Management Framework (AI RMF)
In the United States, the National Institute of Standards and Technology (NIST) AI RMF offers a voluntary but widely adopted approach to AI risk management. It’s organized around four core functions: 
Govern: Establish organizational accountability. Map: Identify and categorize AI systems and their impacts. Measure: Assess risks using quantitative and qualitative methods. Manage: Prioritize and act on risks through continuous monitoring.  While not legally binding, the AI RMF is increasingly referenced by US federal agencies and is a practical starting point for organizations building governance programs.
ISO/IEC 42001
ISO/IEC 42001 is the first international management system standard for AI. It provides a certifiable framework for governing AI across its lifecycle, covering risk management, data quality, transparency, and continuous improvement. For organizations that already hold ISO certifications (like ISO 27001 for information security), ISO/IEC 42001 integrates naturally into existing compliance programs.
Other notable frameworks
United Kingdom: The UK favors a pro-innovation, sector-based approach. Rather than a single AI law, UK regulators issue industry-specific guidance focused on safety, transparency, and accountability. United States (state level): Federal AI legislation remains limited, but states like California, Colorado, Illinois, and Utah are advancing their own AI and automated-decision laws. OECD AI Principles: Adopted by over 40 countries, the OECD Principles on AI emphasize transparency, fairness, accountability, and human-centered design. Common AI governance challenges
Implementing AI governance is rarely straightforward. Even organizations that recognize the importance of governance face a set of recurring AI governance challenges:
Keeping pace with AI adoption. AI capabilities are advancing faster than most governance programs can adapt. New model architectures, agentic AI workflows, and third-party AI integrations can introduce risks that existing policies were not designed to address. Fragmented ownership. In many organizations, AI projects are distributed across teams with no centralized oversight. This makes it difficult to maintain consistent standards, track all active AI systems, or enforce policies uniformly. Balancing innovation with control. Overly restrictive governance can slow down development and frustrate engineering teams. The goal is to design guardrails that protect the organization without creating bottlenecks that discourage experimentation. Measuring effectiveness. Unlike security or performance, governance outcomes are harder to quantify. Organizations often struggle to define meaningful metrics that demonstrate whether their governance program is actually reducing risk. Navigating regulatory uncertainty. With regulations varying by jurisdiction and evolving rapidly, organizations face the challenge of building governance programs that are flexible enough to accommodate future requirements without constant rework. Top 6 AI governance best practices
Building an effective AI governance program takes more than writing a policy document. It requires a sustained, cross-functional effort. These AI governance best practices can help teams move from intention to implementation:
Start with a clear AI inventory. You cannot govern what you cannot see. Begin by cataloging all AI systems in use across the organization, including third-party tools and embedded AI features. Document their purpose, data sources, risk level, and current oversight status. Assign ownership early. Designate governance owners at both the organizational level (such as an AI governance lead or committee) and the project level (such as an AI owner for each deployment). Make accountability explicit. Classify by risk, then apply proportional controls. Not every AI system warrants the same level of scrutiny. Use a risk-based classification system to focus governance resources where they matter most, reserving the heaviest controls for high-risk, high-impact applications. Embed governance into development workflows. Governance should be part of the AI development lifecycle, not a checkpoint that happens after the fact. Integrate policy reviews, bias testing, and documentation requirements into your CI/CD pipelines so they run automatically alongside your existing build and test steps. AI governance tools can help automate parts of this process. Monitor continuously, not just at launch. AI systems can drift over time as data distributions change or new edge cases emerge. Implement ongoing monitoring for model performance, fairness, and compliance rather than relying solely on pre-deployment reviews. Build for adaptability. Regulatory requirements and AI capabilities will continue to evolve. Design your governance framework to be modular, so you can update policies, add new controls, and respond to emerging regulations without overhauling the entire program. What AI governance looks like for developers
Much of the conversation around AI governance focuses on policy, committees, and compliance frameworks. But for the engineers and platform teams actually building and shipping AI systems, governance shows up in much more practical ways. 
Here’s what it looks like at the development level:
Model cards and documentation as part of the PR process
Just as code changes go through review, AI model updates should include structured documentation covering training data, known limitations, performance benchmarks, and intended use cases. This makes governance a natural part of the development workflow rather than a separate bureaucratic step.
Automated bias and fairness checks as part of testing in CI/CD
Rather than relying on manual reviews before launch, teams can integrate bias detection and fairness testing directly into their continuous integration pipelines. When a model update introduces a regression in fairness metrics, the pipeline catches it before it reaches production.
Sandbox-by-default for AI agents
When developing and testing AI agents, running them inside sandboxed containers ensures they cannot access resources or perform actions beyond their intended scope. This is especially critical for agents that execute code, make API calls, or interact with live infrastructure.
AI governance and access controls
Governance at the platform layer means enforcing least-privilege access policies for AI workloads through the same container orchestration and networking tools teams already use. This includes controlling which models, APIs, tools (MCP servers) and data stores an AI system can reach at runtime.
Audit trails and observability built in
Logging every decision an AI system makes, every data source it touches, and every action it takes provides the foundation for both compliance and debugging. Treat AI observability with the same rigor you would apply to any production service.
For teams already working with containers and cloud-native development practices, many of these controls map directly onto familiar patterns. The goal is to extend your existing engineering discipline to cover AI-specific risks, not to build a parallel governance bureaucracy.
Where does your organization stand?
Not every organization is starting from scratch, and not every organization needs the same level of governance rigor on day one. A useful way to think about your current state is through a simple maturity spectrum:
Maturity stage
What it looks like
Ad hoc
No formal AI governance policies exist. Individual teams make their own decisions about AI use, with no centralized oversight, documentation, or review process. Risk management is reactive, addressed only after incidents occur.
Informal
Some governance practices are in place, but they are inconsistent across teams. There may be general guidelines or an AI ethics statement, but no structured enforcement, regular audits, or clear ownership.
Structured
The organization has defined governance policies, assigned ownership, and implemented review processes for AI systems. Risk classification is in use, and governance is integrated into at least some development workflows. Compliance with relevant regulations is actively tracked.
Integrated
Governance is embedded across the AI lifecycle, from development through deployment and monitoring. Automated controls enforce policies at the infrastructure level. Governance practices adapt as new AI capabilities, regulations, and use cases emerge. The organization treats governance as a competitive advantage, not a compliance burden.
Most organizations today fall somewhere between ad hoc and informal. If that sounds familiar, that’s completely normal and a perfectly fine place to start. The goal is not to leap to full integration overnight. It’s to identify where you are, pick the highest-impact gaps, and close them incrementally.
AI governance for AI agents
The rise of AI agents introduces a new dimension to AI governance. Unlike traditional AI models that respond to a single prompt, AI agents operate with greater autonomy. They can make decisions, call external tools, execute multi-step workflows, and interact with live systems, often with minimal human intervention.
This autonomy creates new governance requirements. Organizations need to define what actions agents are allowed to take, what data they can access, how their behavior is logged and audited, and under what conditions they should escalate to a human. Traditional governance models built around static model evaluations are not sufficient for systems that act independently in production environments.
Tackling agent governance also raises questions about runtime security. When an AI agent can execute code, make API calls, or modify infrastructure, the blast radius of a governance failure is significantly larger than a chatbot returning a biased response. Controls like sandboxing, least-privilege access, and real-time monitoring become essential.
Effective AI agent governance means defining clear boundaries for agent behavior, enforcing them at the infrastructure level, and maintaining audit trails that satisfy both internal stakeholders and external regulators. And as agentic AI becomes more widespread, organizations that build agent-specific governance practices early will be better positioned to scale AI adoption safely.
Common misconceptions about AI governance
“AI governance is just compliance.” Compliance is one component, but governance also covers ethics, risk management, operational controls, and organizational accountability. Treating governance as a checkbox exercise leaves significant gaps. “Governance slows everything down.” Well-designed governance enables speed by reducing rework, preventing costly incidents, and creating clear approval pathways. The goal is not to add friction, but to build confidence that AI systems are safe to scale. “Only regulated industries need AI governance.” Every organization using AI faces risks related to bias, security, and reliability, regardless of industry. Governance is not just about avoiding penalties. It’s about building systems that stakeholders trust. “Governance is a one-time project.” AI governance is an ongoing practice. As models evolve, regulations change, and new use cases emerge, governance frameworks need continuous refinement and adaptation. “Small teams can skip governance.” Even small-scale AI deployments benefit from basic governance practices like documentation, access controls, and monitoring. Starting small makes it easier to scale governance as AI adoption grows. Getting started with AI governance
AI governance is no longer optional for organizations that want to use AI responsibly and at scale. The gap between AI adoption and governance maturity is real, but it’s also closable. By establishing clear principles, assigning ownership, building governance principles into development workflows, and investing in the right tools and controls, teams can move from reactive risk management to proactive, scalable governance.
The organizations that get this right will not only avoid regulatory pitfalls and security incidents. They’ll build the kind of trust and operational confidence that makes it possible to innovate faster. Whether you’re governing traditional machine learning models or a fleet of autonomous AI agents, the fundamentals are the same: define the rules, enforce them consistently, and keep evolving as the technology does.
That’s where Docker AI Governance comes into play. It brings network, sandbox, and MCP tool controls into a single console — so your team can define the rules once and enforce them everywhere developers work.
Stop reacting to AI risk. Start governing it. See how Docker AI Governance works →
Frequently asked questions
What is the primary focus of AI governance?
The primary focus of AI governance is ensuring that AI systems are developed and used in ways that are safe, ethical, compliant with regulations, and aligned with an organization’s values and strategic goals. It brings together policy, process, and technology to manage AI risk across the entire lifecycle.
What’s the difference between AI governance and AI ethics?
AI ethics defines the moral principles that should guide AI development, such as fairness, transparency, and respect for privacy. AI governance is the operational framework that puts those principles into practice through policies, roles, controls, and accountability structures. Ethics informs governance. Governance enforces ethics.
Who’s responsible for AI governance in an organization?
AI governance is a shared responsibility. Senior leadership (CEO, CTO, CISO) sets the strategic direction and accountability structures. Cross-functional governance committees or AI ethics boards define policies. Individual project teams are responsible for implementing and adhering to governance standards in their day-to-day work.
How do you measure the effectiveness of AI governance?
Common metrics include the percentage of AI systems covered by governance policies, incident rates related to AI bias or failures, compliance audit results, time to resolve governance issues, and stakeholder satisfaction with AI transparency and fairness practices.
How does AI governance apply to AI agents?
AI agents operate with greater autonomy than traditional models, making governance more critical. Agent-specific governance covers what actions agents can take, what data they can access, how their behavior is logged, and when they should escalate to a human. Runtime controls like sandboxing and least-privilege access are especially important.
View the full article
Google's Chrome browser hit new records on browser benchmarking tools Speedometer 3.1 and JetStream 3, Google said today.


Chrome earned a score of 61 on Speedometer, a five percent improvement since last year. It earned a 469 on JetStream 3, a 10 percent improvement since the beginning of 2026. Tests were done on an M5 MacBook Pro running macOS 26.0.1.

Google says it holds a dual record across all browsers, beating every other Mac browser, including Safari.

Google reworked JavaScript handling to boost its benchmarking scores, skipping unnecessary execution steps and inlining asynchronous operations. Inlining "fast paths" for common operations resulted in speed gains across multiple daily tasks.

Improvements were also implemented for WebAssembly workloads and the Blink rendering engine, with details available on Google's Chromium blog.

Google says the benchmarking wins translate into a "meaningfully faster" browsing experience for Chrome users.Related Roundup: MacBook ProTag: ChromeBuyer's Guide: MacBook Pro (Buy Now)Related Forum: MacBook Pro
This article, "Chrome Sets Browser Speed Records on M5 MacBook Pro" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Microsoft has identified seven new failure modes in agentic AI systems, in addition to those it identified last year in its first Taxonomy of Failure Modes in Agentic AI Systems.
Four things contributed to the growing list of ways agentic AI can go wrong: the speed at which the technology went mainstream, the growing maturity of the Model Context Protocol (MCP) ecosystem, the rise of computer-use agents, and finally the gathering of more empirical evidence as researchers obtained more real-life findings.
The seven new failure modes it has identified are:
Agentic Supply Chain Compromise —agent behavior can be affected by natural language rather than malicious code; Goal Hijacking — adversarial instructions appear aligned with legitimate task completion, while silently redirecting the agent’s terminal goal; Inter-Agent Trust Escalation —a compromised agent asserts false identity or inflates claimed permissions to an orchestrator; Computer Use Agent (CUA) Visual Attack — agents operating through graphical interfaces can be manipulated through content that carries adversarial instructions for the agent; Session Context Contamination —an adversary introduces data that biases the agent’s reasoning in subsequent steps, without triggering safety controls at any individual step; MCP / Plugin Abuse — an update on the original taxonomy’s coverage of function compromise around MCP and plugin protocols, specifically attack surfaces specific to those protocols; Capability / Architecture Disclosure —an agent reveals internal implementation details such as tool names and schemas, system-prompt structure, memory interfaces, or consent/human-in-the-loop trigger logic. Microsoft advises security teams using these definitions to influence their planning to inventory their your supply chain, generating a software bill of materials (SBOM) for every deployed agent, to verify agent identity cryptographically, not positionally, by issuing attestable credentials at provisioning, to add the seven new failure modes to their red-team coverage matrix, and to audit the human-in-the-loop user experience as a security control.
This article first appeared on InfoWorld.

View the full article
The team behind RubyGems, a package hosting site for Ruby developers, has added a new feature to bundler, a tool for managing Ruby packages (or ‘gems’) to protect developers against the recent wave of software supply chain attacks: A cooling-off period before recently updated packages are installed on their systems.
Recent attacks on software repositories have focused on stealing developer credentials in order to introduce malicious code into the packages they create, which then steals more developers’ credentials when they install the malicious updates, and so on. Users of the repositories are vulnerable if they download an affected package during the short interval between it being interfered with and the malicious additions being discovered and removed.
To counteract this, RubyGems team has added a new cooldown argument to Bundler that takes ignores gems until they have been published for a specified number of days. This provides an additional layer of defense against malicious package releases as it gives others an opportunity to identify any malicious code they contain before installation.
The cooldown system works by checking the timestamp of any new versions of gems. Any new additions to the source will have to come from older versions, any new additions will be delayed until they are validated.
In situations where waiting is unhelpful — for instance when a known-good package is released to patch a dangerous security flaw — the delay can be overridden.
This article first appeared on InfoWorld.
View the full article
On this week's episode of The MacRumors Show, we talk through all of the major rumors surrounding Apple's announcements at WWDC 2026.

Subscribe to The MacRumors Show YouTube channel for more videos
The event's tagline, "All Systems Glow," is widely seen as a hint at Siri's new design. Bloomberg's Mark Gurman has reported that Apple is rebuilding ‌Siri‌ as a full chatbot to compete with ChatGPT, Claude, and Gemini, complete with a dedicated app, Dynamic Island integration, and a new system-wide search interface wrapped in a dark, glowing aesthetic that matches the WWDC branding. The dedicated Siri app for back-and-forth conversations is said to be modeled on iMessage, with voice input and the ability to attach images and documents. Users will reportedly be able to set conversation history to auto-delete after 30 days, one year, or never.
 
A new system-wide interface called "Search or Ask" purportedly replaces ‌Siri‌ Suggestions entirely, triggered by swiping down from the top center of the screen. From there, users can launch apps, start texts, set reminders, trigger Shortcuts, or query Apple's new AI web search, which Gurman says Apple is positioning as a Perplexity competitor. Results apparently appear as a translucent card in the ‌Dynamic Island‌, and swiping further opens the full ‌Siri‌ app. Notification Center moves to a top-left swipe, while Control Center stays top-right.
 
The new Siri will reportedly be able to answer multi-part questions, maintain conversational context, summarize uploaded documents, generate images, and draw on personal data across first-party apps like Mail, Messages, Photos, Notes, Contacts, Calendar, and Reminders. Apple is powering its new AI features with a custom model based on Google's Gemini, after its own models reportedly fell short. Gurman says the personalized ‌Siri‌ still carries a "beta" label in internal builds, and there is a "strong chance" it ships that way.
 
iOS 27 will also purportedly introduce an "Extensions" feature letting users choose which AI service powers ‌Siri‌, with a dedicated App Store section for third-party integrations. Users will reportedly be able to set ChatGPT, Gemini, Claude, and others as the default for Writing Tools, Image Playground, and more, with third-party responses using a distinct voice so users can tell which is speaking. Apple has also reportedly held talks with developers about deeper agentic integrations, and is said to be replacing Core ML with a new Core AI framework.
 
Apple is reportedly giving the Camera app a major overhaul, moving Visual Intelligence from the Camera Control button into a dedicated Siri mode inside the app. Apple is also purportedly making the interface fully customizable via a widget tray, letting users arrange controls like flash, exposure, timer, and depth of field. ‌Visual Intelligence‌ will allegedly also gain the ability to scan nutrition labels for Health app tracking and read contact details from business cards.
 
‌Photos‌ is said to be getting three new AI editing tools alongside the existing Clean Up feature. "Extend" generates content beyond the original frame, "Reframe" changes the perspective of spatial photos, and "Enhance" applies automatic color and lighting adjustments. Writing Tools are reportedly getting a grammar checker with per-suggestion accept and reject controls, and keyboard autocorrect is said to be gaining Grammarly-style alternative word suggestions.
 
Apple is reportedly redesigning Image Playground with a simpler interface and new models producing more lifelike images. Genmoji is allegedly getting a new model that improves quality and reduces battery drain, with a Suggested ‌Genmoji‌ feature drawing on the user's media and messages. AI-generated wallpapers are also reportedly coming, with ‌Image Playground‌ built into the wallpaper picker.
 
The Wallet app is purportedly gaining a "Create a Pass" feature for digitizing physical tickets and membership cards, and Apple Cash is reportedly getting a bill-splitting feature that lets users photograph a receipt, assign items to individuals, and send payment requests via Wallet or Messages. Shortcuts is said to be getting a natural language interface for building automations by description.

Other notable changes include a system-wide Liquid Glass opacity slider that Apple apparently couldn't get working in iOS 26, the option to beam content to AirPlay alternatives like Google Cast (reportedly EU-only as a DMA requirement), and expanded satellite features including Apple Maps and photo sharing over satellite.
 
Apple also previewed a wide range of accessibility improvements ahead of WWDC, including AI-powered descriptions in VoiceOver and Magnifier, an upgraded Accessibility Reader for complex document layouts, automatic video captions generated on-device, and a new FaceTime API for live sign language interpretation. For visionOS, Apple is adding Power Wheelchair Control using Vision Pro's eye-tracking, Vehicle Motion Cues for users in moving vehicles, and face gesture support for system actions.
 
Leaker "Instant Digital" claims ‌iOS 27‌ will drop support for the iPhone 11 lineup and second-generation iPhone SE, requiring at least an iPhone 12, with Apple Intelligence continuing to require an iPhone 15 Pro or newer. macOS 27 is said to share the same ‌Siri‌ and ‌Apple Intelligence‌ upgrades, with refinements to Liquid Glass and the same performance focus. It will reportedly be Apple silicon only, dropping all remaining Intel Macs, and is said to be the last release to include full Rosetta support.
 
Gurman described ‌iOS 27‌ overall as a "Snow Leopard" update, with Apple prioritizing stability, code cleanup, and battery life gains alongside the new features. The keynote begins June 8 at 10 a.m. Pacific Time, with developer betas expected the same day and a public release in September. The MacRumors Show has its own YouTube channel, so make sure you're subscribed to keep up with new episodes and clips.

Subscribe to The MacRumors Show YouTube channel!

You can also listen to ‌The MacRumors Show‌ on Apple Podcasts, Spotify, Overcast, or other podcast apps. You can also copy our RSS feed directly into your player.



If you haven't already listened to the previous episode of The MacRumors Show, catch up to hear our discussion Apple's ‌WWDC 2026‌ keynote date, the sweeping ‌Siri‌ redesign coming in ‌iOS 27‌, Apple's latest accessibility feature previews, and the hinge troubles reportedly plaguing the foldable iPhone ahead of its expected launch in the fall.

Subscribe to ‌The MacRumors Show‌ for new episodes every week, where we discuss some of the topical news breaking here on MacRumors, often joined by interesting guests such as Kayci Lacob, Kevin Nether, John Gruber, Mark Gurman, Jon Prosser, Luke Miani, Matthew Cassinelli, Brian Tong, Quinn Nelson, Jared Nelson, Eli Hodapp, Mike Bell, Sara Dietschy, iJustine, Jon Rettinger, Andru Edwards, Arnold Kim, Ben Sullins, Marcus Kane, Christopher Lawley, Frank McShan, David Lewis, Tyler Stalman, Sam Kohl, Federico Viticci, Thomas Frank, Jonathan Morrison, Ross Young, Ian Zelbo, and Rene Ritchie.

‌The MacRumors Show‌ is on X @MacRumorsShow, so be sure to give us a follow to keep up with the podcast. You can also email us at [email protected] or head over to The MacRumors Show forum thread. Remember to rate and review the podcast, and let us know what subjects and guests you would like to see in the future.Related Roundup: WWDC 2026Tags: The MacRumors Show, WWDC 2026Related Forum: Apple, Inc and Tech Industry
This article, "The MacRumors Show: What to Expect at WWDC 2026" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
CalDigit is best known for its docks and hubs, and it has two options designed for Apple's latest Macs. I reviewed the larger $500 20-port TS5 Plus last summer, and for the last couple of weeks, I've been testing the $400 15-port TS5 that launched a bit later than the premium model, and the smaller $250 Element 5 Hub.


TS5

The TS5 is probably the Thunderbolt 5 dock that I would recommend if someone on the street came up to me and asked which Thunderbolt 5 dock to buy. It's smaller and takes up less space on a desk than the TS5 Plus, it has no fans like some competing docks, and it has a useful port selection. With some exceptions, it'll meet the needs of most people.


Thunderbolt 5 docks are ideal for Apple's Thunderbolt 5 Macs (the M4 Pro, M4 Max, M5 Pro, and M5 Max), but they're also backwards compatible with Thunderbolt 3 and Thunderbolt 4 Macs, so you can use the TS5 with almost any Mac to add ports for displays and accessories.

Ports on the front:

Audio jack
USB-C with 10Gb/s speeds and 7.5W
USB-C with 10Gb/s speeds and 20W
MicroSD card slot (UHS-II)
SD card slot (UHS-II)

Ports on the back:

Audio in/out
USB-C port with 10Gb/s speeds and 7.5W
USB-A port with 10Gb/s speeds and 7.5W
USB-A port with 480Mb/s speeds and 7.5W
2.5 GbE
Three downstream Thunderbolt 5 ports with 15W charging
One upstream Thunderbolt 5 port with 140W charging

The TS5 does not have dual USB controllers like the TS5 Plus, it has 2.5 Gigabit Ethernet instead of 10GbE, it doesn't have DisplayPort, and it has three fewer USB-A ports and two fewer USB-C ports than the TS5 Plus. The TS5 has three downstream Thunderbolt 5 ports instead of two, so it beats the TS5 Plus (which only has two), but the higher-end TS5 Plus has more charging power. The front USB-C port on the TS5 Plus is 36W, as are the two downstream Thunderbolt 5 ports at the back.


The TS5 has the same general design that CalDigit has used for its last several docks. It's made from a space gray aluminum material with ribbing on the top and sides for dissipating heat. Though it has no fan, it never got beyond lukewarm in my testing, and I was surprised at how cool it stayed. The TS5 Plus ran much warmer when I tested it, but the smaller TS5 wouldn't keep me cozy on a freezing night.

The dock's design blends in well with a desk setup, but like most Thunderbolt 5 docks, it's not going to turn any heads. I don't have space gray equipment so the color doesn't match my MacBook or my Studio Display, but it doesn't look too out of place. I wish accessory makers would adopt bolder, brighter colors, but I'm guessing gray and black are what sell.

CalDigit's TS5 dock is about 5.5 inches tall, 4.5 inches wide, and a little under two inches thick. It fits well under a display, and it can be positioned either upright or on its side. There is a separate 240W power brick, and that's typical for most Thunderbolt 5 docks. Along with the power supply, CalDigit includes a braided 1-meter Thunderbolt 5 cable, and I appreciate the cable upgrade because not all docks come with nice cables.

One thing I appreciate about CalDigit over some other dock makers is the info the website provides. I think the average person probably finds hubs and docks somewhat confusing, especially when it comes to determining which displays and how many external displays a dock supports with a given Mac. CalDigit has an extensive chart with all Apple silicon Macs listed, so it's fairly easy to see what your Mac will support. Thunderbolt 5 supports up to 80Gb/s speeds with bandwidth boost up to 120Gb/s for displays, twice that of Thunderbolt 4.


The TS5 supports up to four 6K 60Hz displays, but only if you're using a Mac with an M5 Max chip. It'll also run dual 8K 60Hz displays, dual 4K 240Hz displays, or four 4K displays with up to a 144Hz refresh rate. When used with an M5 Pro Mac, the dock supports up to three 6K 60Hz displays, and for Macs with earlier Pro/Max chips, the dock is limited to dual displays. You can power dual 8K 60Hz displays using the TS5 with an M4 Max or M5 Max Mac, while other machines cap out with two 6K 60Hz displays. The base M-series chips have different support depending on generation too. The M4 and M5 chips can support two external displays up to 6K at 60Hz with the TS5, but M1 and M2 chips only support one. The M3 is a special exception because it supports two displays when the Mac is in clamshell mode, or one with the display open.

I tested with a ‌Studio Display‌ and a ‌Studio Display‌ XDR, both of which are 5K displays. I also tested with a ‌Studio Display‌ and a 32-inch 120Hz OLED display, and I didn't run into any issues with either setup.


There is one 5K display limitation that potential buyers should be aware of, and that's support for the LG UltraFine 5K monitors. The dock does not support dual LG UltraFine 5K displays unless used with an M5 Max MacBook Pro.

I used every port at once and performance was as expected, but I did run into an issue with the TS5 not recognizing SSDs. SSDs that I plugged into the two USB-C ports weren't popping up, but a Thunderbolt 5 SSD was fine. Unplugging the dock and plugging it in again didn't work, but restarting my Mac did. I've had the same problem intermittently, but after the first time, unplugging the dock and then plugging it back in seemed to work. It doesn't happen every time, but losing SSD connectivity through the USB-C ports is a hassle.


The TS5 has 140W host charging, which is more than enough for all of Apple's notebooks. The Thunderbolt 5 ports and the 10Gb/s USB-C and USB-A ports have offline charging so you can charge accessories with the dock when your Mac isn't connected.

Element 5 Hub

I also spent a short amount of time with CalDigit's $250 Element 5 Hub, which is an impressive little device. It's as small as the 180W power brick it comes with, and it's the Thunderbolt 5 option to get if you need minimal ports.


The Element 5 Hub has four Thunderbolt 5 ports (one upstream, three downstream), two USB-C ports, and three USB-A ports. 90W host charging is available for a connected Mac, which is enough to keep my 16-inch ‌MacBook Pro‌ charged. The downstream Thunderbolt 5 ports have 15W for accessories, and the USB-C ports offer 7.5W. Like the TS5, the ports work even when the hub isn't connected to a host computer.

Since there are three Thunderbolt 5 ports, the Element 5 Hub can drive the same number of displays as the TS5. It doesn't have as many USB-C ports, no SD card slots, and no audio jack, but if all you need is Thunderbolt and a couple of USB-C/USB-A ports, this is the way to go.


I love how little space the Element 5 takes up on my desk, so much so that I may adopt one for long-term use. I do use SD card slots, but the smaller size may be worth the sacrifice. The Element 5 is 2.75 inches wide, 4.5 inches long, and an inch thick. It's about the same size as my Thunderbolt 5 SSD, and smaller than an iPhone. If you want compact, get this dock.

Bottom Line

I prefer the TS5 over the TS5 Plus because of the extra Thunderbolt 5 port on the TS5. I can connect two displays and still have a port for a Thunderbolt 5 SSD, which isn't the case with the TS5 Plus. Unfortunately, I'm continually running into problem where SSDs connected to the USB-C ports on the dock don't work, and that makes it hard to recommend to someone who needs to use it for storage purposes. I can just restart the dock, but I shouldn't have to. TB5 SSDs are fine, so are USB-C SSDs connected through a Thunderbolt port.

CalDigit's more expensive TS5 Plus is a better option than the TS5 if you need DisplayPort 2.1, 10GbE, or an absurd number of USB-A ports (five for the TS5 Plus vs two for the TS5). The TS5 Plus also has dual 10Gb/s USB controllers, which is useful if you want to run multiple high-speed SSDs or drives at the same time.

If you only need a limited number of ports, I'd definitely recommend checking out the Element 5 Hub. It's compact, but still includes four Thunderbolt 5 ports, three USB-A ports, and two USB-C ports. I didn't seem to have the same SSD problem with the TS5 Plus or the Element 5.

I like CalDigit's Thunderbolt 5 docks over competing docks from Anker and Satechi, mainly because CalDigit doesn't include fans and its docks operate silently. The SSD problem might be my particular dock or my ‌MacBook Pro‌, but if you pick up a TS5, get it from a place with a return policy just in case.

I like all of the docks I've tried so far, though, and they've all been good options with no major problems. I'd pick Anker's Prime Thunderbolt 5 dock if I wanted a dock with no external power supply, or Satechi's CubeDock if I wanted a built-in SSD or had a Mac mini and wanted to match it.

Thunderbolt 4 docks are cheaper than Thunderbolt 5 options, but if you have a Thunderbolt 5 Mac or are planning to get one in the next year or two, it's worth going for Thunderbolt 5 for the upgraded bandwidth.

How to Buy

The CalDigit TS5 can be purchased from the CalDigit website or from Amazon for $400.

The Element 5 Hub is available from the CalDigit website or from Amazon for $250.

Note: CalDigit provided MacRumors with a TS5 and Element 5 Hub for the purpose of this review. No other compensation was received.Tag: CalDigit
This article, "CalDigit TS5 and Element 5 Hub Review: Two Thunderbolt 5 Docks for Apple's Latest Macs" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Apple has yet to finalize whether its upcoming foldable iPhone will be available in black, according to a questionable new rumor.


The Weibo leaker known as "Instant Digital" commented today that Apple "hasn't even decided yet whether the foldable screen will come in black," adding pointedly: "Do they have a vendetta against the color black?" The remark suggests black is at least under consideration, but has not been confirmed as part of the lineup, a notably open question for a device that is expected to enter mass production imminently and launch as soon as September.

In February, the leaker described the device as coming in just two color options, with white as the only confirmed shade and the second unspecified. Instant Digital revisited that report in May without walking back any color details, keeping the two-option account intact. Today's comment does not necessarily contradict that, but introduces new uncertainty about what the second option actually is.

Separately, Macworld cited a supply chain source claiming the second finish will be an indigo option similar to the iPhone 17 Pro's Deep Blue, alongside a classic silver and white model. That source also said the device will offer fewer choices than the iPhone 18 Pro models, with no bold or vibrant colors. Bloomberg's Mark Gurman similarly reported that Apple plans to "stay away from fun colors" and stick to more traditional silver/white and space gray/black finishes.

Samsung Display's OLED panels for the device are already entering mass production, and ramp-up is underway. Color decisions typically feed directly into manufacturing and component procurement, all of which needs to be locked well in advance of launch. For a device as complex and supply-constrained as the foldable iPhone is expected to be, any severe late-stage indecision seems unlikely, so the rumor may simply indicate some opaqueness in the supply chain about the second color.

That being said, dummy models that have surfaced so far have only been seen in white. It is also worth noting that new high-end products such as the Apple Watch Ultra and Vision Pro only launched with one color option.

A limited color offering may partly reflect the practical realities of manufacturing the device at all. Supply chain analyst Ming-Chi Kuo has warned that early-stage yield and ramp-up challenges could constrain supply through at least the end of 2026, and that the frequently cited figure of 15 to 20 million units likely reflects cumulative demand across the product's full two to three year lifecycle, not 2026 alone. Adding color variants increases the number of SKUs to produce, stock, and allocate, which is a complication Apple has little commercial incentive to absorb when launch supply is expected to be tight regardless.

The approach would be broadly consistent with how Apple has handled generationally significant launches before. The iPhone X debuted in November 2017 in just two colors, Silver and Space Gray, at a then-record starting price of $999. The iPhone XS that followed a year later added Gold to the lineup, and Apple may take the same incremental approach with the iPhone Ultra over time.

At a starting price that Gurman says will "cross the $2,000 threshold", the foldable iPhone is unlikely to attract buyers whose purchasing decision is heavily determined by color options. That gives Apple room to keep the initial palette narrow.

The first foldable iPhone is expected to be announced in September 2026 alongside the ‌iPhone 18 Pro‌ and ‌iPhone 18 Pro‌ Max.Related Roundup: iPhone FoldTags: Foldable iPhone, Instant Digital
This article, "Foldable iPhone May Not Come in Black, Leaker Suggests" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Apple has several hardware releases in the pipeline, but will we see any of them unveiled at this year's Worldwide Developers Conference?


WWDC is primarily a software event where new versions of iOS, iPadOS, macOS, watchOS, tvOS, and visionOS take center stage, but it's not unusual for Apple to introduce new hardware during the developer conference. Take WWDC 2017, for example, where Apple first unveiled the original HomePod over six months ahead of its launch.

Apple has chosen to show off other major products at the annual event, like the redesigned Mac Pro and Pro Display XDR announced in June 2019. More recently, Apple unveiled the first 15-inch MacBook Air in 2023, along with the M2 Ultra chip in the Mac Studio, and the first Mac Pro powered by Apple silicon.

So What Can We Expect at WWDC 2026?

Probably not much. Apple has actually released a lot of updates already in 2026. We've seen the AirTag 2, the iPhone 17e, and a new iPad Air with M4 chip, along with refreshed M5 MacBook Air and M5 Pro/Max MacBook Pro models.

Indeed, March was a big month for Apple. The Studio Display XDR arrived with mini-LED backplane technology and a 120Hz refresh rate, the regular Studio Display received a Thunderbolt 5 upgrade, and the company also debuted its industry-disrupting $599 MacBook Neo. It even quietly updated the AirPods Max with an H2 chip.

But despite the flurry of spring announcements, Apple reportedly has more products waiting in the wings. According to Bloomberg's Mark Gurman, new models of the Apple TV 4K and HomePod mini are "ready to go" and have been "for months." So why has Apple yet to launch the new devices, and should we expect to see them at WWDC?


Unfortunately, it's unlikely that we will see either of these products announced during the conference. The main reason is that Apple is holding them back until the more personalized version of Siri and other Apple Intelligence upgrades are released later this year. We'll undoubtedly see these software features previewed at WWDC, but they won't be released to the public until mid-September, so it's not reasonable to expect that the new Apple TV and HomePod mini will launch before then.

The same goes for other rumored products like smart glasses, AirPods with cameras, and the smart home hub or so-called "HomePad." All of these devices will rely on an enhanced Siri and a version of Apple Intelligence that finally lives up to its promises, but we won't see these improvements go public until the fall.

Mac Updates? Unlikely

It's not looking good for Mac mini or Mac Studio updates arriving anytime soon, either.

Apple is battling a global memory chip shortage, driven by hyperscalar companies building out AI server facilities. The squeeze has already seen Apple remove desktop Macs from its online store – Mac mini models with 32GB and 64GB of RAM are no longer available for purchase, nor is the M3 Ultra Mac Studio with 256GB RAM. Apple even went so far as to remove the ‌Mac mini‌ with 256GB of SSD storage, leaving the 512GB model as the minimum option. Apple CEO Tim Cook himself has said that the Mac mini and Mac Studio could be hard to get for months to come.

Perhaps the best we can hope for is a hardware preview of Apple's smart home accessories. Other than that, the safest overriding assumption is not to expect hardware-based product launches at all until Apple's new software updates mature to a point where its AI-based features no longer carry the "beta" badge caveat, and there's no sign that's about to happen anytime soon.

WWDC 2026 kicks off with Apple's keynote on Monday, June 8 at 10 a.m. Pacific Time. Be sure to stay tuned here at MacRumors for comprehensive coverage of all the announcements.Related Roundup: WWDC 2026Related Forum: Apple, Inc and Tech Industry
This article, "Will Apple Launch New Hardware at WWDC Next Week?" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
This week's best Apple deals included a new all-time low price on the AirPods Max 2, which have now hit $499.00 thanks to a $50 discount at Amazon and Best Buy. You'll also find great deals on AirPods Pro 3, Apple Watch Series 11, and LG accessories below.

Note: MacRumors is an affiliate partner with some of these vendors. When you click a link and make a purchase, we may receive a small payment, which helps us keep the site running.

AirPods Max 2


What's the deal? Take $50 off AirPods Max 2
Where can I get it? Amazon
Where can I find the original deal? Right here
$50 OFFAirPods Max 2 for $499.00

Apple's AirPods Max 2 hit a new record low price of $499.00 this week on Amazon and Best Buy, down from $549.00. On Amazon, you'll find four colors of the headphones on sale at this price.

AirPods Pro 3


What's the deal? Take $50 off AirPods Pro 3
Where can I get it? Amazon
Where can I find the original deal? Right here
$50 OFFAirPods Pro 3 for $199.00

AirPods deals were in abundance this week, with the AirPods Pro 3 also on sale at an all-time low price on Amazon. You can still get this model for $199.00, down from $249.00.

AirTag


What's the deal? Take $40 off first gen AirTag 4-Pack
Where can I get it? Woot
$40 OFFAirTag 4-Pack for $59.99

Woot has Apple's first generation AirTag 4-Pack for $59.99 this week, down from $99.99. The AirTag 4-Pack is in new condition and comes with a 90-day Woot limited warranty.

Apple Watch Series 11


What's the deal? Take $100 off Apple Watch Series 11
Where can I get it? Amazon
Where can I find the original deal? Right here
$100 OFFApple Watch Series 11 (42mm GPS) for $299.00
$100 OFFApple Watch Series 11 (46mm GPS) for $329.00

Amazon this week has all-time low prices on the Apple Watch Series 11, with $100 discounts across numerous models of the smartwatch. This sale includes a handful of GPS aluminum models on sale at record low prices.

LG


What's the deal? Save sitewide at LG
Where can I get it? LG
Where can I find the original deal? Right here
SITEWIDE SALELG Summer Sale

LG is hosting a big savings event on its website this week, with deals on monitors, TVs, home appliances, and more. Highlights of the event include up to $500 off select LG monitors and up to $1,500 off LG's best TV sets.

If you're on the hunt for more discounts, be sure to visit our Apple Deals roundup where we recap the best Apple-related bargains of the past week.



Deals Newsletter

Interested in hearing more about the best deals you can find in 2026? Sign up for our Deals Newsletter and we'll keep you updated so you don't miss the biggest deals of the season!




Related Roundup: Apple Deals
This article, "$499 AirPods Max 2? The Best Apple Deals of the Week Are Here" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
This week's best Apple deals included a new all-time low price on the AirPods Max 2, which have now hit $499.00 thanks to a $50 discount at Amazon and Best Buy. You'll also find great deals on AirPods Pro 3, Apple Watch Series 11, and LG accessories below.

Note: MacRumors is an affiliate partner with some of these vendors. When you click a link and make a purchase, we may receive a small payment, which helps us keep the site running.

AirPods Max 2


What's the deal? Take $50 off AirPods Max 2
Where can I get it? Amazon
Where can I find the original deal? Right here
$50 OFFAirPods Max 2 for $499.00

Apple's AirPods Max 2 hit a new record low price of $499.00 this week on Amazon and Best Buy, down from $549.00. On Amazon, you'll find four colors of the headphones on sale at this price.

AirPods Pro 3


What's the deal? Take $50 off AirPods Pro 3
Where can I get it? Amazon
Where can I find the original deal? Right here
$50 OFFAirPods Pro 3 for $199.00

AirPods deals were in abundance this week, with the AirPods Pro 3 also on sale at an all-time low price on Amazon. You can still get this model for $199.00, down from $249.00.

AirTag


What's the deal? Take $40 off first gen AirTag 4-Pack
Where can I get it? Woot
$40 OFFAirTag 4-Pack for $59.99

Woot has Apple's first generation AirTag 4-Pack for $59.99 this week, down from $99.99. The AirTag 4-Pack is in new condition and comes with a 90-day Woot limited warranty.

Apple Watch Series 11


What's the deal? Take $100 off Apple Watch Series 11
Where can I get it? Amazon
Where can I find the original deal? Right here
$100 OFFApple Watch Series 11 (42mm GPS) for $299.00
$100 OFFApple Watch Series 11 (46mm GPS) for $329.00

Amazon this week has all-time low prices on the Apple Watch Series 11, with $100 discounts across numerous models of the smartwatch. This sale includes a handful of GPS aluminum models on sale at record low prices.

LG


What's the deal? Save sitewide at LG
Where can I get it? LG
Where can I find the original deal? Right here
SITEWIDE SALELG Summer Sale

LG is hosting a big savings event on its website this week, with deals on monitors, TVs, home appliances, and more. Highlights of the event include up to $500 off select LG monitors and up to $1,500 off LG's best TV sets.

If you're on the hunt for more discounts, be sure to visit our Apple Deals roundup where we recap the best Apple-related bargains of the past week.



Deals Newsletter

Interested in hearing more about the best deals you can find in 2026? Sign up for our Deals Newsletter and we'll keep you updated so you don't miss the biggest deals of the season!




Related Roundup: Apple Deals
This article, "$499 AirPods Max 2? The Best Apple Deals of the Week Are Here" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
iOS 27 is rumored to be focused on bug fixes and performance improvements, and this should result in "longer battery life," according to Bloomberg's Mark Gurman.

In line with his previous reporting, Gurman today said Apple is "making performance improvements aimed at extending the battery life of the iPhone," but he said it is "unclear if Apple will quantify how much longer devices will last." In other words, it remains to be seen if Apple highlights the battery life improvements during its WWDC 2026 keynote this Monday.Related Roundup: iOS 27
This article, "iOS 27 Will Reportedly Give Your iPhone 'Longer Battery Life'" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Bloomberg's Mark Gurman today revealed another iOS 27 change: notifications will slide in from the left side of the screen instead of from the top.


In addition, accessing Notification Center on iOS 27 will require swiping down on the top-left corner of the screen. If you swipe down on the Dynamic Island area, a new "Search or Ask" interface tied to the revamped Siri will appear, instead of Notification Center. This change may be limited to the iPhone 15 Pro and newer if the "Search or Ask" interface ends up requiring an iPhone model with Apple Intelligence.

Apple is set to unveil iOS 27 during its WWDC 2026 keynote on Monday, and the first developer beta should be available on the same day. A public beta typically follows in July, and the update should be widely released in September.Related Roundup: iOS 27Tags: Bloomberg, Mark Gurman
This article, "iOS 27 Notifications Will Slide in From Left Side of Your iPhone's Screen" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Ongoing cyber-attacks on automated tank gauges (ATGs) could result in fuel tanks being drained without businesses noticing, the US Cybersecurity & Infrastructure Security Agency has warned. Connected ATGs are widely deployed in gas stations, as well as on military bases, in hospitals, and in manufacturing plants. And it’s not just fuel stores at risk: ATGs are also used in the chemical, food, and agriculture industries.
CISA and other agencies warned that such attacks could lead to the gauges being dangerously compromised, leaving tank owners unaware of leaks or theft of their contents.
The attacks take three forms: authentication bypass and hardcoded credentials, which allow attackers to gain access to device management; OS command execution and SQL injection to manipulate underlying databases; and privilege escalation, in which attackers obtain full administrator access.
System administrators working for organizations using ATGs are advised to protect their systems by removing connections to serial ports to eliminate public internet exposure by, changing default passwords immediately, applying the latest patches, reporting any suspicious activity to the CISA, and urging companies in their supply chain to also adopt best practises against such attacks.
CISOs in these companies should already be doing this as they can’t say that they were unaware of the risks: Last year, a Canadian fuel company was attacked and its systems compromised and in 2024, security company BitSight warned that ATGs were a sitting target for cyber criminals.

View the full article
Bloomberg's Mark Gurman has published his WWDC preview ahead of Monday's keynote, and while almost all of the iOS 27 features he covers have already made the rounds, there are a couple of details worth highlighting.


As we've covered previously, Apple is turning Siri into a full chatbot that users can interact with, similar to Claude or ChatGPT. The Siri chatbot will be integrated into Apple's operating systems at the system level, and there will also be a Siri app for back-and-forth conversations.

Perhaps unsurprisingly, Gurman says that Siri chats will sync across devices via iCloud, making Apple's assistant similar to rivals like ChatGPT that retain history across sessions. Users' chats with Siri will also be able to auto-delete on a schedule, 30 days, a year, or never. The options will be controlled in Settings, much like Messages.

Notably, Gurman says that Apple is still internally labeling the long-delayed revamped Siri as a "beta" and "preview," suggesting it won't be marketed as finished software when it arrives later this year. That may frustrate some users, given that Apple Intelligence features that were first teased in 2024 have been repeatedly delayed, but it's worth noting that the original Siri also held the same "beta" caveat for two years after its 2011 debut.

As a result of the abiding "beta" moniker, Gurman says it's possible that Apple will initially introduce a waitlist for the new Siri that could gate access to certain features when iOS 27 arrives in September, similar to the initial launch of the Apple Intelligence platform two years ago. It's not clear which features they might be, though.
Siri in iOS 27: Every New Feature and Change to Expect
WWDC 2026 kicks off with Apple's keynote on Monday, June 8 at 10 a.m. Pacific Time.Related Roundup: iOS 27Tags: Mark Gurman, Siri
This article, "iOS 27: New 'Beta' Siri Features Could Be Gated Behind a Waitlist" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Planning a trip often feels like balancing a complex puzzle. Between hunting for reliable accommodation, decoding confusing transportation schedules, and trying to find authentic local experiences, the excitement of travel can quickly be overshadowed by the stress of logistics. While search engines provide a flood of generic information, they often lack the personal touch and real-world nuance required to make a trip truly memorable. This is where community-driven knowledge transforms the planning process from a chore into an adventure.
The HolidayLandmark Forum serves as a vital bridge between uncertainty and informed decision-making. By connecting travelers with a global network of explorers, local experts, and seasoned wanderers, the platform changes how we approach our vacations. Whether you are navigating your first international flight or planning a complex multi-city itinerary, finding the right support system is the key to unlocking a seamless and enjoyable journey.
Engaging with a community allows you to move past polished marketing brochures and into the realm of honest, actionable insights. By participating in a global travel discussion community, you gain access to lessons learned by others, preventing common mistakes and helping you uncover hidden gems that rarely appear on top-ten lists. With a collaborative spirit, travel planning becomes more efficient, confident, and inherently more rewarding.
What Is HolidayLandmark Forum?
The HolidayLandmark Forum is a dedicated travel discussion community designed to facilitate the exchange of knowledge among travelers worldwide. Unlike static websites, this is a dynamic, interactive space where users can post inquiries, share their own travel experiences, and receive feedback from a diverse group of contributors.
The platform operates on the concept of community-driven travel knowledge. By providing a structured question and answer functionality, it allows users to receive timely, relevant advice for their specific needs. From destination insights to logistical tips, the forum fosters an environment where the collective wisdom of thousands of travelers is available at your fingertips.
Why Travel Forums Still Matter
In an era of AI-generated content and sponsored articles, the human element in travel advice has never been more valuable. HolidayLandmark Forum stands out because it offers:
Real Traveler Experiences: Access authentic stories and tips from people who have actually walked the streets you plan to visit. Unbiased Travel Insights: Receive recommendations free from paid promotions, focusing solely on what genuinely makes a destination worth visiting. Practical Destination Knowledge: Get the “how-to” details—like where to find the best street food or how to navigate local public transport—that guidebooks often omit. Travel Planning Support: Turn vague ideas into concrete plans with the help of community moderators and contributors. Community Recommendations: Discover unique local favorites that you wouldn’t find on standard travel aggregator sites. Who Should Use HolidayLandmark Forum
This platform is a versatile resource catering to a wide spectrum of explorers, including:
First-time travelers looking for confidence and preparation tips. Solo travelers seeking safety advice and social opportunities. Family travelers needing kid-friendly destination planning. International tourists navigating visa and cultural nuances. Backpackers looking for budget-friendly routes and hostels. Adventure travelers scouting trails and unique activities. Business travelers in need of efficient, comfortable transitions. Travel enthusiasts who enjoy sharing their own global expertise. Key Features of HolidayLandmark Forum
The forum is structured to address the various stages of travel planning through specialized sections:
Travel Questions and Answers
The core of the platform is the best travel forum to ask questions. Post your query, and within a short time, you receive responses from people with direct experience in your destination.
Destination Discussions
Dive deep into specific locations. Whether you are curious about the best time to visit or the current weather conditions, these threads provide targeted info.
Trip Planning Support
Get help from the community to organize your thoughts and logistical requirements. It is a highly effective way to brainstorm and refine your goals.
Travel Itinerary Discussions
Use the platform as a travel itinerary discussion forum. Share your drafted schedule, and experienced travelers will provide feedback on whether your timeline is realistic or if you are missing key stops.
Local Travel Advice
Receive guidance on local etiquette, language tips, and hidden dangers, ensuring you remain respectful and safe throughout your trip.
Community Recommendations
From hotel choices to restaurant reviews, get suggestions backed by the reputation of the community.
Travel Experience Sharing
Read detailed reports from other travelers to inspire your future destinations.
Tourist Guide Discussions
Connect with others to discuss professional guides, walking tours, or self-guided options in various cities.
Benefits of Asking Travel Questions Online
Choosing to ask travel questions online via the HolidayLandmark Forum provides several strategic advantages:
Faster Problem-Solving: Get answers to specific roadblocks in hours rather than spending days researching. Better Trip Planning: Utilize collective brainstorming to optimize your route. Access to Experienced Travelers: Connect with veterans who have visited dozens of countries. Real-World Recommendations: Avoid “tourist traps” by listening to those who have navigated them. Reduced Travel Uncertainty: Enter your destination with knowledge, leading to a more relaxed and confident experience. Best Travel Forum for Trip Planning
As the best travel forum for trip planning, the platform excels at helping users construct a cohesive strategy. When you approach your planning through the forum, you can effectively manage:
Itineraries: Building a logical flow for your stops. Destinations: Researching where to spend your limited time. Culture: Understanding local norms to ensure a smooth interaction. Transportation: Figuring out the best ways to get from point A to point B. Accommodation: Choosing the right neighborhood and lodging type for your budget. Activities: Prioritizing experiences that match your personal interests. Travel Questions Travelers Commonly Ask
Travel CategoryCommon QuestionsBenefits of Community AnswersTraveler TypeLogistics“What is the best way to get from X to Y?”Avoids expensive tourist transport.First-time travelersBudget“How much daily budget for a week in X?”Helps in realistic financial planning.BackpackersItinerary“Is this 3-day plan too rushed?”Optimizes time and energy.Adventure travelersCulture“What should I wear in [religious site]?”Ensures respect and comfort.International touristsSafety“Is this area safe to walk at night?”Provides real-time safety context.Solo travelers Destination Travel Questions and Answers
Destination-specific questions are the lifeblood of the community. Instead of reading generalized advice, you can ask about:
Seasonal information: Is it worth visiting in the off-season? Attractions: Are there any local festivals happening during my stay? Safety: What specific precautions should I take in this city? Transportation: Should I use ride-shares or the local metro? Travel Advice for First-Time Travelers
If you are new to the world of travel, the HolidayLandmark Forum is an essential travel advice forum for first-time travelers. The community provides guidance on:
Preparation: Checklists for documents and health requirements. Budgeting: Tips on how to stretch your currency. Packing: Advice on what is essential vs. unnecessary weight. Safety: Guidelines on how to keep your documents and belongings secure. Common Mistakes: Learning from the mishaps of others to ensure your trip stays stress-free. Travel Itinerary Discussion Forum Benefits
Creating an itinerary is where many travelers struggle. Using the travel itinerary discussion forum allows you to:
Receive constructive feedback on your schedule. Find hidden attractions near your planned routes. Optimize your travel path to minimize time in transit. Receive local recommendations that add authenticity to your schedule. Why Travelers Prefer Community-Based Advice
Travelers favor the HolidayLandmark Forum because it offers:
Authentic Experiences: Perspectives that haven’t been sanitized by marketing teams. Real Reviews: Honest opinions on services and locations. Up-to-date Information: News about changes in local laws, transit, or venues. Diverse Perspectives: Advice from various cultures and backgrounds, providing a well-rounded view. Global Travel Discussion Community
Participating in a global travel discussion community opens doors to networking opportunities. You aren’t just getting info; you are learning about the world through the eyes of people living in or visiting those countries. It promotes cross-cultural understanding and creates a unique environment of shared learning.
Real-World Travel Scenarios
Scenario A: A solo backpacker wants to explore Southeast Asia but is worried about budget. They post on the forum and get advice on the cheapest, safest hostels and local bus routes. Scenario B: A family is planning their first trip to Europe and isn’t sure which cities are kid-friendly. The community suggests areas with parks and museums that keep children engaged. Scenario C: An adventure traveler is prepping for a trekking trip and needs to know about specific gear requirements for high-altitude weather. They get tips from climbers who have recently conquered that specific trail. How HolidayLandmark Forum Improves Travel Planning
By leveraging the forum, you transition from “guessing” to “knowing.” This results in:
Better Decision-Making: Choosing destinations and activities based on proven facts. Travel Confidence: Knowing you have a support system if things go wrong. Reduced Mistakes: Avoiding common pitfalls others have already fallen into. Improved Experiences: Maximizing your time and budget for higher-quality memories. Common Travel Planning Mistakes
Ignoring Local Advice: Relying solely on big-name travel blogs. Over-planning: Creating a schedule that is impossible to follow. Not Asking Questions: Forgetting that community knowledge is a resource. Outdated Data: Using old guidebooks instead of checking live forum discussions. Missing Hidden Gems: Sticking to the main tourist paths. Tips for Getting Better Answers in Travel Forums
To get the most out of your post:
Be Specific: Instead of “Tell me about Japan,” ask “What are the best 3-day itineraries for Kyoto for a family with a toddler?” Provide Context: Mention your travel dates, budget range, and primary interests. Engage: Thank those who answer and ask follow-up questions. Use Destination Tags: Ensure your post is in the right category. Travel Forum Features Comparison Table
FeaturePurposeBenefit to TravelersBest Use CaseQ&A SectionRapid info gatheringSolves specific doubtsUrgent/quick questionsItinerary SharingPeer reviewRefines schedulingPre-trip planningLocal ThreadsCultural contextDeeper understandingCultural preparationGeneral DiscussionNetworkingBroad inspirationEarly brainstorming Frequently Asked Questions (FAQs)
How do I get started with the HolidayLandmark Forum?Simply navigate to the forum, create an account, and browse the categories that interest you to start participating in discussions. Is it free to use the HolidayLandmark Forum?Yes, the forum is open for all travelers to ask questions and share their knowledge without any cost. Can I ask about hidden gems in popular cities?Absolutely. Many community members love sharing “off the beaten path” recommendations that tourists often miss. Is this platform suitable for solo travelers?It is perfect for solo travelers to gather safety tips and meet others for travel advice. How quickly can I expect answers to my questions?Because the community is global, you often receive responses within hours from people in different time zones. Can I post my full travel itinerary for feedback?Yes, sharing your itinerary in the dedicated section is one of the best ways to get expert refinement advice. Are there local experts available to answer questions?Many members are locals or long-term expats who provide highly accurate, on-the-ground information. Does the forum help with visa requirements?Members can share their recent personal experiences with visa processes, though official government sites should always be your final authority. Is the advice on the forum unbiased?Yes, the community prides itself on honest, personal experiences rather than commercial marketing content. How can I find destination-specific discussions easily?Use the search functionality on the forum homepage to filter discussions by country or city. Final Recommendation
Travel planning is an art, but it shouldn’t be a struggle. By utilizing the HolidayLandmark Forum, you gain access to a powerful, global knowledge base that empowers you to plan smarter and travel deeper. Whether you need a quick answer about transportation or a comprehensive review of your itinerary, there is a community of travelers ready to help. Start your journey by engaging with the forum today, and transform the way you explore the world.
View the full article
Claude Code is Anthropic’s AI coding assistant — a command-line tool that developers are adopting fast. It connects to external services through Model Context Protocol, the standard that lets AI tools interact with Jira, Confluence, GitHub, databases and internal APIs. When a developer connects one of those services, Claude Code runs an OAuth flow, the user approves the scopes and the tool receives a bearer token it uses for every subsequent request.
That token is stored in plaintext in a configuration file on the developer’s machine. And researchers have now shown exactly how attackers are getting to it.
What researchers found
Last week, researchers atMitiga Labs published an attack chain that should concern every security team whose developers use Claude Code. The attack starts with a malicious npm package — something that looks like a legitimate utility or wrapper. Hidden inside is a post-install hook that runs silently during installation. That hook rewrites a single file: ~/.claude.json.
That file is the control point for how Claude Code routes MCP traffic. Change it, and you can point Claude Code’s authenticated requests to attacker-controlled infrastructure instead of the legitimate service. The OAuth tokens stored in that same file get intercepted in transit. The attacker now holds valid, long-lived bearer tokens for every SaaS platform the developer had connected — Jira, Confluence, GitHub, whatever was integrated.
What makes this particularly difficult to detect is what the audit logs look like on the other end. The IP address in the provider’s logs resolves to Anthropic’s egress range. The user is real. The session is valid.As Mitiga put it, nothing in that log row is wrong — but nothing in it is right either. The user did not run the query. An attacker did, using a token that was silently redirected before it ever reached its intended destination.
Mitiga reported this to Anthropic on April 10.Anthropic responded on April 12 that the issue was out of scope, reasoning that the attack requires prior code execution through a package installation that the user consented to. As of this writing, no patch exists. The attack chain is live.
This is not the first time
The Mitiga disclosure is the most recent, but it is not the first time Claude Code’s configuration model has created a security problem.
In February 2026,Check Point Research published findings on two separate vulnerabilities. The first, CVE-2025-59536, allowed remote code execution through malicious hooks planted in a repository’s settings file — code that ran before the user could even read the trust dialog. The second, CVE-2026-21852, allowed API key exfiltration by overriding a single environment variable, redirecting authenticated traffic to attacker-controlled infrastructure before any consent prompt appeared.Simply cloning and opening an untrusted repository was enough to trigger both.
Anthropic patched those vulnerabilities after Check Point’s disclosure. But the pattern they reveal — configuration files that security teams treat as passive metadata actually functioning as active execution paths — is the same pattern the Mitiga attack exploits. The mechanism keeps working because the underlying architecture creates it.
Why security teams need to pay attention
If you have read about adversary-in-the-middle phishing, this should feel familiar. AiTM attacks do not steal credentials directly — they sit between the user and the legitimate service, wait for authentication to succeed and walk away with the session token that proves it happened. The Mitiga attack on Claude Code works the same way. The OAuth flow completes legitimately. The user approved the scopes. The token is valid. The attacker just inserted themselves into the routing layer before the token reached its intended destination.
The difference is that AiTM attacks target browser sessions. This targets developer tooling — and developer tooling sits closer to your source code, your internal APIs, your cloud infrastructure and your production systems than most browser sessions ever do.
Claude Code adoption is accelerating. Developers install it because it genuinely improves their workflow. They connect it to the tools they use every day. Most of them are not thinking about what the post-install scripts in their npm dependencies are doing to their local configuration files. That is not a failure of awareness — it is an unreasonable expectation. The security team needs to be thinking about it instead.
Three controls that help right now
Monitor ~/.claude.json for unexpected changes. This file is the pivot point in the Mitiga attack. Changes to MCP server endpoints in that file — particularly additions of new localhost proxy addresses or unfamiliar external endpoints — should trigger an alert. Most organizations have no monitoring on user-level configuration files in developer environments. That needs to change.Mitiga specifically recommends tracking changes to Claude Code configuration, MCP server URLs and OAuth refresh behavior as the primary detection layer. Treat npm post-install hooks as a first-class security concern. The Mitiga attack begins with a malicious npm package. Post-install hooks that execute arbitrary code at install time are a known supply chain risk class — but enforcement in developer environments is inconsistent. Audit what runs during package installation in your development pipelines. Consider requiring review of packages that include post-install scripts before they reach developer machines. This is not a Claude Code-specific recommendation; it applies to every tool in your development stack. Claude Code just made the consequences of getting it wrong much more tangible. Audit OAuth tokens connected to Claude Code integrations and rotate them. Developers who connect Claude Code to Jira, Confluence, GitHub or any other SaaS platform create OAuth tokens that persist across sessions. If those tokens were active during a period when a malicious package was installed, they should be treated as potentially compromised. Rotate them. Review the audit logs on the provider side for the activity patterns Mitiga describes — valid-looking requests from Anthropic’s egress IPs that the developer did not initiate. Note thattoken rotation alone does not break the chain if the malicious hook is still present — the hook will reseed the configuration and capture new tokens on the next refresh. Remediation requires removing the hook and cleaning the configuration first. An honest assessment
Anthropic’s response to the Mitiga disclosure — that the attack is out of scope because the user consented to installing the package — follows a logic that security practitioners will recognize and most will reject. Consent to install a package is not consent to have that package rewrite your AI tool’s routing configuration and intercept your SaaS credentials. The two things are not the same and treating them as equivalent places the entire burden of supply chain security on the developer, making a split-second judgment about a dependency name.
That is not a reasonable security model.
The patched Check Point vulnerabilities show that Anthropic is responsive when the issue is framed correctly. The Mitiga research is a week old. Whether a patch follows is an open question, but the attack chain works today regardless of how that question resolves.
Your developers are using Claude Code. The question for security teams is not whether to engage with this risk but how quickly you can implement detection and response that accounts for it. The configuration file is small, the monitoring requirement is specific, and the attack chain is documented. Starting there is better than waiting for a vendor patch that may not come.
This article is published as part of the Foundry Expert Contributor Network.
Want to join?
View the full article
The 2026 Worldwide Developers Conference will take place this week from June 8 through June 12, and like the last six years, it will be an online event, although select developers and students will be invited to Apple Park. To kick things off, Apple holds a keynote event on the Monday to announce new software, which is what makes it of interest to the general public.


During the keynote event on Monday, June 8, Apple is expected to unveil iOS 27, iPadOS 27, macOS 27, tvOS 27, watchOS 27, and visionOS 27. (The "27" represents the September 2026 to September 2027 release season.)

You can watch the WWDC 2026 keynote event using one of the methods outlined below. The live stream is set to start at 10:00 a.m. Pacific Time from ‌Apple Park‌ in Cupertino, California. We have a full list of when the event will begin in other time zones in the United States and around the world.

Honolulu, Hawaii -- 7:00 a.m. HAST
Anchorage, Alaska -- 9:00 a.m. AKDT
Cupertino, California -- 10:00 a.m. PDT
Phoenix, Arizona -- 10:00 a.m. MST
Vancouver, Canada -- 10:00 a.m. PDT
Denver, Colorado -- 11:00 a.m. MDT
Dallas, Texas -- 12:00 noon CDT
New York, New York -- 1:00 p.m. EDT
Toronto, Canada -- 1:00 p.m. EDT
Halifax, Canada -- 2:00 p.m. ADT
Rio de Janeiro, Brazil -- 2:00 p.m. BRT (no DST)
London, United Kingdom -- 6:00 p.m. BST
Berlin, Germany -- 7:00 p.m. CEST
Paris, France -- 7:00 p.m. CEST
Cape Town, South Africa -- 7:00 p.m. SAST
Helsinki, Finland -- 8:00 p.m. EEST
Istanbul, Turkey -- 8:00 p.m. TRT
Dubai, United Arab Emirates -- 9:00 p.m. GST
Delhi, India -- 10:30 p.m. IST
Jakarta, Indonesia -- 12:00 a.m. WIB next day
Shanghai, China -- 1:00 a.m. CST next day
Singapore -- 1:00 a.m. SGT next day
Perth, Australia -- 1:00 a.m. AWST next day
Hong Kong -- 1:00 a.m. HKT next day
Seoul, South Korea -- 2:00 a.m. KST next day
Tokyo, Japan -- 2:00 a.m. JST next day
Adelaide, Australia -- 2:30 a.m. ACST next day
Sydney, Australia -- 3:00 a.m. AEST next day
Auckland, New Zealand -- 5:00 a.m. NZST next day
Watch the Keynote on YouTube

Watching the WWDC keynote on YouTube may be one of the quickest and easiest ways to catch the event because YouTube is generally available on most devices, including TV sets and consoles.


The YouTube live stream above will be accessible on June 8 when the event kicks off.

Watch the Keynote on Mac, iPhone, iPad, or Vision Pro

You can watch the WWDC keynote on any Mac, iPhone, iPad, or Vision Pro using Apple's native Safari browser or another browser. iOS devices must be running iOS 10 or later, and Macs need to be running macOS Sierra 10.12 or later to access the stream.

Launch Safari from your chosen device and follow this link to the WWDC 2026 Keynote.

Watch the Keynote Using the Apple TV App

You can watch the WWDC keynote via Apple's TV app on Mac, iPhone, iPad, Vision Pro, and Apple TV, with the link in the TV app becoming available on the day of the event or just before.

Open the TV app on your chosen device.
Scroll down the Watch Now category and select WWDC 2026. Alternatively, type "WWDC" into the Search field and select WWDC 2026 from the results.
Click Play.

The app may tell you to tune in at your local time to watch the event live prior to when the WWDC keynote begins.

Watch the Keynote on a Windows PC

If you don't have an Apple device handy, you can still watch the WWDC 2026 keynote on a PC running Windows 10 or later. Open Microsoft Edge browser and follow this link to the WWDC 2026 Livestream.

While Apple offers no guarantees, other platforms may also be able to access the WWDC 2026 keynote using recent versions of Chrome or Firefox (MSE, H.264, and AAC codecs/extensions must be installed).

Watch in the Apple Developer App or Developer Website

Apple also plans to stream the keynote in the Apple Developer app, and on the Apple Developer website, making it easier than ever for Apple fans and developers to catch the event.

MacRumors Coverage

For those unable to watch the live stream, or who prefer to read a text version of the announcements, we'll have live coverage both here on MacRumors.com and through our MacRumorsLive X (Twitter) account, so make sure to follow.Related Roundup: WWDC 2026Related Forum: Apple, Inc and Tech Industry
This article, "How to Watch Apple's WWDC 2026 Keynote on June 8" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Threat actors are actively exploiting a critical security flaw in Everest Forms Pro, a WordPress plugin with about 4,000 active installations, to execute arbitrary code, leading to a complete site compromise. The vulnerability in question is CVE-2026-3300 (CVSS score: 9.8), a remote code execution bug impacting all versions of the plugin up to, and including, 1.9.12. A patch for the flaw wasView the full article
Modern travel is undergoing a significant transformation. Today, discerning travelers are moving beyond conventional tourist traps and pre-packaged corporate itineraries. There is a growing demand for authentic travel experiences that offer genuine cultural immersion, personal connection, and a deeper understanding of a destination. This shift represents a move toward community-driven tourism, where the focus is not just on the place, but on the people who call it home.
Finding these authentic connections can be a challenge in a digital landscape crowded with mass-market platforms. This is where HolidayLandmark changes the game. As a worldwide local tourism marketplace, it bridges the gap between curious travelers and the local organizers who make a destination truly come alive. By prioritizing direct communication and verified connections, this platform ensures that your travel planning is not just logistical, but foundational to a meaningful journey.
Whether you are looking to navigate the bustling markets of a heritage city with an expert guide, stay in a quiet village homestay, or participate in unique food experiences, connecting with local organizers creates a travel narrative that is uniquely yours. It is time to step away from the standardized tourist brochure and embrace a way of traveling that is as rewarding as the destination itself.
What Is HolidayLandmark?
HolidayLandmark is a worldwide local tourism marketplace designed to streamline the way travelers find and connect with local organizers. Unlike traditional travel sites that limit their scope to hotel bookings and flight aggregation, this platform brings together the individuals who actually run a destination: local guides, homestay hosts, food experts, transport providers, and independent travel organizers.
The platform functions as a direct connection hub. When you discover an experience that resonates with your interests, you send a booking request. Once the local organizer accepts, you coordinate the details and payments directly with them. This removes the middleman, allowing for a flexible, transparent, and personalized travel planning experience. From the largest metropolitan hubs to the smallest, most remote villages, you can access a wide array of services that are verified, honest, and community-focused.
Why Local Tourism Is Growing Worldwide
The global travel community is increasingly prioritizing “slow travel” and sustainable practices. Local tourism is at the heart of this movement for several key reasons:
Authentic Cultural Experiences: Travelers want to see a destination through the eyes of someone who lives there, not just through a tour operator’s script. Community-Driven Tourism: By booking directly with locals, travelers contribute directly to the local economy, helping small businesses and families thrive. Sustainable Travel Benefits: Local organizers are often the best stewards of their environment and culture, promoting responsible and respectful tourism practices. Personalized Travel Experiences: Local organizers can tailor itineraries to your specific pace and interests, which is rarely possible with standardized commercial tours. Key Features of HolidayLandmark
To help you navigate your next trip, the platform categorizes offerings to make discovery intuitive and reliable.
Local Travel Experiences
From heritage walks in ancient cities to off-the-beaten-path expeditions, you can discover trips, local guides, homestays, food, transport and authentic experiences that fit your specific travel style.
Local Guides
Find local guides and travel experiences that go beyond the guidebook. These experts provide historical context, stories, and the kind of insider knowledge that turns a simple walk into a memorable journey.
Homestays
Discover homestays and village tourism opportunities that allow you to live like a local. Staying with a host family provides a window into daily life, traditions, and local customs that you simply cannot get from a hotel room.
Food Experiences
Go beyond the restaurant menus. Connect with hosts for cooking classes, home-cooked traditional meals, and guided food walks that showcase the authentic flavors of the region.
Transportation Services
Book local guides, food experiences and transport seamlessly. Having a trusted local driver or transport organizer not only makes navigation easier but also safer, providing you with a reliable partner on the ground.
Local Events and Activities
Whether it is a regional festival, a traditional craft workshop, or a music performance, you can discover trips directly from local organizers that give you access to events that aren’t marketed to the general tourist crowd.
Verified Travel Organizers
Trust is paramount. The platform emphasizes transparency by vetting organizers. You can see profile reviews and verified badges before you commit, making this the best platform for local travel experiences.
HolidayLandmark Services at a Glance
Service CategoryPurposeBest ForKey BenefitsLocal GuidesProvide historical and cultural contextHistory buffs, curious explorersInsider knowledge, unique storiesHomestaysOffer immersive living arrangementsCultural seekers, familiesDeep local integration, authentic lifestyleFood ExperiencesShare traditional cuisine and skillsFoodies, home-cooking fansHands-on experience, local flavorsTransportProvide reliable local mobilityIndependent travelers, remote travelSafe, convenient, efficient navigationVillage TourismShowcase rural, offbeat lifeNature lovers, sustainable travelersCommunity support, quiet escapes Why Travelers Prefer Local Experiences
Travelers are increasingly seeking deeper connections rather than just ticking off sightseeing checklists. Cultural immersion is the primary driver—people want to understand the why and how behind the customs they encounter. Personalized itineraries ensure that you spend your time on what you value most. Furthermore, tapping into local knowledge provides access to “hidden” destinations that do not appear in mainstream advertisements, leading to more authentic food experiences and meaningful travel memories that last a lifetime.
How to Find Local Guides and Travel Experiences
Using HolidayLandmark to plan your journey is straightforward:
Searching Experiences: Use the discovery tools to filter by destination, experience type, and specific interests. Reviewing Options: Look through the profiles of potential hosts. Check their verified badges, language capabilities, and reviews from previous travelers who have completed bookings. Connecting with Organizers: Once you find the right fit, send a booking request with your specific dates and requirements. Coordinating Directly: After the organizer accepts your request, you gain direct access to them. Use this time to finalize the itinerary, discuss logistics, and agree on payment details. Booking Experiences: Secure the arrangement by confirming the plan and keeping communication open with your host as you travel. Homestays and Village Tourism Experiences
Engaging in village tourism or staying in a homestay changes the entire dynamic of a vacation. Instead of observing a destination from the outside, you become a participant. You get to witness the morning rituals of a community, understand how local agriculture works, and participate in festivals that have been celebrated for generations. This form of travel creates a cultural exchange where both the traveler and the host learn from one another, fostering global understanding and respect.
Food, Transport, and Local Activities
Practical travel logistics are often the biggest hurdle in foreign lands. By using this travel marketplace for local guides and hosts, you can secure transport services that are reliable and fairly priced. Beyond logistics, having a local organizer to guide you to the best street food or introduce you to local artisans adds a layer of depth to your trip. Whether it is a jeep ride through remote mountains or a guided market tour, these activities turn a simple trip into a comprehensive adventure.
Why Verified Local Travel Organizers Matter
Safety and reliability are the foundations of good travel. Verified organizers are essential because they provide a layer of trust. When you know an organizer has been vetted by the platform, you can travel with confidence. Improved communication is another advantage; because you coordinate directly, you can ask questions, clarify requirements, and set expectations before you even pack your bags. Reliable support on the ground ensures that if plans change or local conditions shift, you have an ally to help navigate the situation.
Real-World Travel Scenarios
The Solo Traveler: A solo traveler arriving in a new city uses the platform to book a local guide for the first two days. This allows them to get oriented, learn the transport system, and find safe, local-approved eateries. The Family Vacation: A family looking for a cultural getaway books a rural homestay. The host arranges a cooking class and a guided walk, providing a safe, educational, and engaging environment for both adults and children. The Adventure Traveler: An adventure seeker connects with a verified local trekking organizer to explore hidden mountain trails, ensuring they have an experienced guide who knows the terrain and safety protocols. The Cultural Enthusiast: A traveler interested in local heritage finds a host who specializes in traditional music and festivals, gaining access to events that are not open to the general public. How HolidayLandmark Supports Sustainable Tourism
This platform acts as a catalyst for economic growth in local communities. When you book directly with a local guide or host, the majority of the revenue remains within that community, supporting families and preserving local traditions. Responsible tourism is encouraged by fostering direct relationships, which naturally leads to more respectful interactions. By promoting village tourism and hidden destinations, the platform also helps distribute tourism traffic more evenly, preventing the overcrowding of major tourist hubs.
Common Mistakes Travelers Should Avoid
Many travelers inadvertently limit their experience by relying solely on mainstream commercial attractions.
Ignoring Local Wisdom: Failing to leverage the knowledge of local guides means missing out on the best hidden spots and cultural nuances. Overlooking Smaller Hosts: Assuming that only large organizations can provide quality services is a mistake; local organizers often offer far more personalized and passionate service. Not Researching: Always take the time to read reviews and verify organizer profiles before booking. Missing Opportunities: Being too focused on rigid itineraries means you might miss spontaneous cultural events or local invitations. Tips for Getting the Best Travel Experience
Plan Ahead: While spontaneity is fun, connecting with local organizers early ensures availability and allows for better itinerary customization. Be Clear: When sending a request, be specific about your needs—dietary restrictions, activity levels, and what you hope to gain from the experience. Stay Curious: Ask your local host questions. They are your best resource for understanding the culture, customs, and history of the place. Prioritize Quality: Look for organizers with clear, verified profiles rather than just the lowest price. A great local connection is worth the investment. Frequently Asked Questions (FAQs)
1. Is it safe to book through this local tourism marketplace?
Yes. The platform reviews organizer profiles before they go live and uses a verification system for IDs and business credentials. Reviews are only left by travelers who have completed a booking, ensuring authenticity.
2. How does the booking process work?
You search for an experience, send a request to the organizer with your details, and they accept. Once accepted, you communicate directly with the organizer to finalize all arrangements.
3. Do I pay the platform or the organizer directly?
Payment is arranged directly between you and your local organizer. This ensures transparency and allows you to confirm all details before money changes hands.
4. What types of experiences can I book?
You can book a wide variety of services, including local guides, homestays, village stays, food experiences, transportation, adventure trips, and cultural activities.
5. How do I know if an organizer is reliable?
Check the profile for verified badges (ID, business, etc.) and read the reviews from previous travelers. The platform ensures reviews come from actual completed trips.
6. Can I coordinate with multiple organizers for one trip?
Absolutely. Many travelers mix and match, booking a guide in one city, a homestay in a village, and transport services as needed.
7. Are there options for remote or offbeat destinations?
Yes, the platform focuses on connecting travelers with organizers in all types of locations, from major cities to the smallest, most remote villages.
8. What should I do if I have specific dietary or activity requirements?
Because you coordinate directly with your organizer, you can communicate these specific needs clearly before you arrive to ensure your host is prepared.
9. How does this help the local economy?
By removing the middleman, your payment goes directly to the people providing the service, which supports local families and small businesses directly.
10. Is the forum useful for planning?
Yes, the community forum is an excellent place to ask questions, read travel stories, and get honest advice from locals and fellow travelers.
Final Recommendation
Travel is more than just moving from one location to another; it is about the stories you collect and the people you meet. By choosing to travel through a local tourism marketplace, you move from being a spectator to a participant. HolidayLandmark provides the necessary tools to make this transition possible. By connecting directly with verified local organizers, you ensure that your travel experiences are authentic, culturally rich, and economically sustainable. Whether you are seeking the hustle of a historic market or the quiet of a village homestay, start your journey by connecting with the people who make the world a home. Explore local, travel better, and turn your next vacation into a truly meaningful adventure.
View the full article
Sales of AI-based tools is accelerating within underground ransomware marketplaces, lowering the barrier to entry for new actors in the process.
An analysis of Telegram channels, 20 dark web forums, and five underground markets by anti-ransomware platform vendor Halcyon found that AI utility posts grew to 1,486 in February 2026, up from just 38 in December 2025.
The AI tools for sale divided into four categories:
Weaponized LLMs: Sometimes called dark LLMs, these tools omit the safety guardrails and rules present in legitimate large language models (LLMs). “WormGPT” is the market leader in this category of cybercrime-focused AI tooling but only as a brand used by multiple operators, some of which are straightforward scams that collect payments without offering any service. AI-enabled identity fraud: Tools in this category include voice and video-enabled deepfakes, created using AI, that are used to fool selfie-based recognition systems and other know your customer (KYC) security controls, among other fraudulent applications. The same tools can also be used as part of business email compromise scams. AI-augmented malware and attack infrastructure: AI-driven infrastructure is being used to aggregate, process, and exfiltrate stolen data more efficiently. Jailbroken and stolen AI services: Hacked AI accounts are the largest category of services offered and the cheapest. Halcyon estimates that ransomware attacks have grown in volume by 20% since 2023 with an increased focus on targeting smaller enterprises, which now comprise 80% of attacks.
During a keynote presentation at Infosecurity Europe, Cynthia Kaiser, SVP of Halcyon’s Ransomware Research Center, told delegates that the largest ransomware operators — such as Akira — are increasingly operating the same business models as legitimate vendors by selling services and infrastructure to their clients and affiliates. The main difference is that the goods on offer are exploits and stolen credentials rather than the legitimate goods sold through legitimate marketplaces.
Ransomware groups sell routinely through multiple channels, thereby creating redundancy in the event that any channel is taken down. Their services are often offered with tiered pricing, and are commonly available with a freemium model popularised by legitimate web services. Telegram bot-driven channels are automating the process of sales and marketing, while AI-based utilities are being applied by cybercriminals to offer customer service.
“Modern ransomware operators don’t need to build their operations from scratch,” said Kaiser, the former deputy assistant director of the FBI’s Cyber Division, who added that the skill level required from would-be cybercriminals has dropped.
Dishonour among thieves
All this may seem impressive, but Kaiser noted that criminal operational security (OpSec) is weaker than it looks.
“Criminal AI markets have a theft problem [because] black hats are attacking each other,” Kaiser said.
For example, credentials from one WormGPT instance were stolen by rival cybercriminals and dumped back onto the same forum that originally sold access to the malign AI-based utility.
Such disruption aside, the greater use of AI tooling is part of a sign that the underground ransomware scene has professionalised not least by making it easier in run multiple attacks at scale.
Raking it in
According to separate research from Rapid7, ransomware is becoming more profitable, up 39% between Q1 2025 and Q1 2026.
The Qilin ransomware group made an estimated $193 million between July 2025 and March 2026. And The Gentleman, which is just behind Qilin as the biggest ransomware group, made an estimated $52 million between July 2025 and March 2026, according to Rapid7.
Rapid7’s analysis is based on average ransom payments and payment rates from CoveWare, a ransomware and cyber extortion incident response firm.
Thom Langford, CTO EMEA at Rapid7, said that the ransomware ecosystem has evolved into a mature underground marketplace where access, tooling, and full attack services are now commercially available to almost anyone.
Langford added that AI-based social engineering, primarily to craft more convincing phishing lures, is widely used.
Marketplaces offer an a la carte menu where cybercriminals can contract services for initial access, exfiltration, or negotiation with victims, according to Langford, who added that many if not all of the principal players in the ransomware scene “speak Russian.”
Countermeasures
Law enforcement takedowns are curtailing the growth of ransomware operations, but businesses also need to play their part in defence, Halcyon advises.
Enterprises should concentrate on measures such as stopping initial access, detecting lateral movement, and disrupting exfiltration and encryption. Companies can also build resilience through tabletop exercises, Kaiser concluded.
View the full article
The threat actor known as PCPJack has hijacked cloud servers associated with Amazon Web Services (AWS), Google Cloud, and Microsoft Azure to create a covert SMTP email relay network. "Compromised business servers across the U.S., Europe, and Asia were quietly converted into SMTP proxies, verified for mail relay capability, and synced to a downstream consumer every five minutes," Hunt.io said inView the full article
A report from the US Commerce department’s inspector general blames the National Institute of Standards and Technology (NIST) for the ever-growing backlog of vulnerabilities for inclusion in the National Vulnerability Database (NVD). But cybersecurity practitioners say that the backlog, although very real, has been building for years, and that the government is doing little to help.
NIST defenders point to budget cuts that have made its mission far more difficult. And a potentially bigger issue is that the nature of vulnerability identification and patching has changed sharply over the last two years, via genAI developments that have dramatically increased the number of vulnerabilities discovered and accelerated of those discoveries. That raises questions about whether NVD processes need to be completely re-envisioned. 
Inter-agency squabbles
The Inspector General’s report blamed NIST for a variety of management and strategy shortcomings. 
“NIST’s lack of strategic planning and decisive action have allowed the backlog of unprocessed vulnerabilities to continue growing,” the report said, pointing out that NIST and the Cybersecurity and Infrastructure Security Agency (CISA) are operating two vulnerability enrichment programs with significant overlap, leading to duplicated efforts and waste of approximately $200,000 since May 2024. Additionally, it said, NIST’s insufficient communication has frustrated stakeholders and decreased confidence in the NVD.
The report also said, “NIST must improve the efficiency of enrichment processes to ensure sustainability. We estimate that NIST could put approximately $800,000 to better use over the next two years.”
It also attributed some of the issues with the vulnerability identification programs to bureaucratic infighting over the years, pointing out that for two years, CISA has been independently providing nearly all of the same enrichment data as NIST.
“Therefore,” it said, “an opportunity existed for NIST to leverage CISA’s data to expedite backlog reduction. However, NIST officials stated that the NVD system required technical updates to incorporate CISA’s enrichment data because the system lacked the capability to attribute data to specific sources.”
Because of this, before system updates and subsequent process changes were completed in March 2025, NIST refused to use CISA’s data because it would have appeared that an NVD analyst had performed the enrichment.
“While it is understandable that NIST wanted to be clear about the source of data in the NVD,” the report said, “it ultimately delayed vulnerability processing to distinguish whether enrichment was completed by NIST or CISA, both federal agencies with access to the same public information.”
Another example of inefficiency also involved enrichment: “In May 2024 … CISA launched its own vulnerability enrichment program, called Vulnrichment. At the time, CISA invited NIST to collaborate and issue a joint statement about the new program. However, NIST did not take part in a joint statement or issue any announcement about CISA’s program. Ultimately, the two programs have operated without coordination and have duplicated enrichment activities.”
NIST severity score calculations ‘may no longer be necessary’
Another concern cited was the reliability of NIST’s calculation of severity scores.
“To generate a severity score for vulnerabilities, NIST uses the industry standard Common Vulnerability Scoring System (CVSS). … Our review found that implementation is highly dependent on available information and professional judgment,” the report said, noting that in internal testing, severity scores among independent OIG evaluators matched just 12% of the time. “We concluded that severity scores vary depending on who performs the work and the information available to them.”
It added: “Traditionally, NIST calculated its own independent severity score for each vulnerability. NIST stated that it did so as part of its mandate to determine the nature and extent of information security vulnerabilities and independently assign severity metrics to identified vulnerabilities. However, NIST is not required to calculate a severity score for every vulnerability. Today, this approach may no longer be necessary and, considering the increasing volume of vulnerability submissions, is no longer sustainable.”
The IG report also included an official NIST response; CSO Online asked NIST for clarifications, but it did not respond before publication. 
In that response, NIST said that it agreed with all of the report’s technical recommendations, mostly involving creating a better strategic plan for the NVD and a better backlog management plan, but that it disagreed with the tone and phrasing used.
“Rather than assess the impact of NIST’s actions in a fair, factual, and objective manner, this statement unnecessarily casts doubt on NIST’s intentions and priorities,” the NIST response, attributed to Acting Director Craig Burkhardt, said. “The Draft Report is replete with language that goes beyond objective, factual evaluation.”
Industry response
However, said some observers, while the AG report was accurate, it missed the bigger picture.
“The backlog is getting all the attention, but underneath it, this is a money story. CISA was covering close to half the NVD’s funding and then walked away from it, and NIST’s lab budget got cut on top of that. You can’t pull that kind of money out of something this important and then act surprised when it breaks,” said Jeff Williams, CTO at Contrast Security.
He noted the revelation that OIG analysts’ vulnerability severity calculations only matched NIST’s 12% of the time, suggests that the measure, used by IT to prioritizes fixes, “is barely better than guessing.” That should worry people more than the backlog does, he said.
Williams also argued that the manual parts of threat analysis no longer make much sense, pointing out that the “easy parts” of security such as scanning and ticketing are already automated.
“We got very good at producing findings and never got good at dealing with them. The real prevention work — threat modeling and looking hard at architecture — is still done by hand by a small number of senior people,” he pointed out. “We automated the wrong half. Where AI can be truly groundbreaking is helping with the expert work we could never hire enough people for, to prevent vulnerabilities in the first place.”
Braden Perry, a litigation, regulatory, and government investigations attorney at Kennyhertz Perry, also took issue with NIST’s defense that legal obligations forced it to make some of those decisions. 
“It’s a lawyer’s argument and a partial one,” he said. “The law sets the mission. It doesn’t dictate the choices that created the backlog. Here’s the distinction: NIST cites [a federal rule] which directs the agency to assign severity metrics to open source software vulnerabilities. That’s a mandate. But it only covers open source software, not all vulnerabilities. It says ‘severity metrics,’ not CVSS.”
And, he said, the rule doesn’t tell NIST to recalculate a score that a vendor or CISA already produced; that was NIST’s decision. “So the mandate is narrow and the practice is broad,” he said, pointing out that the inspector general’s report made that clear.
“The statutes NIST cites don’t say how to run the database or what to produce,” he noted. “They leave the operational calls to NIST. On the central question, whether NIST was legally compelled into this backlog, the answer is no. The duty to keep the database running is real. The mess was a choice.”
NIST’s complaints, he said, “are management failures, not statutory commands. [NIST] spends most of its energy arguing that the report was unfair and lacked context. That is a process complaint. It is not a defense of the record.”
Erik Avakian, technical counselor at Info-Tech Research Group, said the NVD issues identified in the report are less of a concern than the fact that too many enterprises have grown addicted to NVD as their sole source of vulnerability truth.
“I would ask the question: why are we waiting for NIST to tell us something that’s important?” Avakian said. “Organizations that are relying so much on the NVD have deeper maturity problems because NVD should be treated as a support function to a vulnerability management program, not the entirety of it.”
Ishraq Khan, CEO of coding productivity tool vendor Kodezi, added that the changing scale of vulnerability discovery is the bigger issue. 
“Cybersecurity infrastructure must scale at the same pace as vulnerability discovery. If discovery becomes exponentially faster through automation and AI, while enrichment and analysis remain heavily manual, the gap will continue widening,” Khan said.
“I suspect many CISOs will read this report less as an audit finding and more as a warning sign. The question is no longer whether vulnerabilities can be found. The question is whether the institutions responsible for organizing and prioritizing them can keep pace.”
View the full article
iOS 27 has been the star of the rumors we've been hearing ahead of Apple's WWDC 2026 event, but there have also been a few tidbits about the next version of macOS, macOS 27. We don't know as much about ‌macOS 27‌ as we do about ‌iOS 27‌, so there will be some surprises in store.


Liquid Glass Revision

Hate Liquid Glass on the Mac? It's not going anywhere, but Apple is planning a "slight redesign."

Liquid Glass transparency and shadows don't work as well on the Mac as they do on the iPhone, and Apple has some revisions in mind. Don't expect Apple to revert to the pre-Tahoe design, but minor improvements are likely.

Siri

Most people probably never use Siri on the Mac, but that could change with ‌macOS 27‌. The smarter, more capable version of ‌Siri‌ that we've been hearing about endlessly isn't just for iOS. ‌Siri‌ is also coming to macOS, with a new ‌Siri‌ interface planned and, presumably, a standalone ‌Siri‌ app for the Mac.

We don't know as much about the ‌macOS 27‌ ‌Siri‌ interface as we do about the ‌iOS 27‌ interface, but it'll probably parallel what's coming in iOS. On the iPhone, ‌Siri‌ will be integrated in the Dynamic Island. Will Apple somehow carry that over to the Mac's notch? Who knows, but it's possible. ‌Siri‌ on iOS has a dark interface that's hinted at in WWDC graphics, and we could get that same style in ‌macOS 27‌.

If you want to read more about the changes coming to ‌Siri‌, check out our iOS 27 roundup.

AI App and Feature Updates

Most of these rumors are for ‌iOS 27‌, but a lot of what's available on iOS is also available on macOS.

Photos - The Photos app will include new Extend and Reframe options. Extend generates image content beyond the original frame of the photo, and Reframe lets users change the perspective of an image after it's captured. There's also a tool for natural language photo edits, but it might not be ready to go when ‌macOS 27‌ launches.
Image Playground - Apple is testing new models that produce more lifelike images, plus there could be some updates to the app interface.
Wallpaper - ‌iOS 27‌ is getting a wallpaper-generating feature that uses Image Playground, so it makes sense for it to be available in ‌macOS 27‌ too.
Shortcuts - The Shortcuts app will let users ask ‌Siri‌ to generate a shortcut using natural language. With a short statement on what a shortcut should do, AI will whip it up and add it to the app. It'll make shortcuts much easier for the average person to use.
Writing Tools - In addition to spell check, there will be a grammar check feature. Writing Tools will also support expanded rewriting and text generation capabilities.
Safari - Safari is getting a feature for automatically organizing browser tabs into groups, which will be useful for tab addicts who like to see just how many tabs their Mac can handle before it starts to feel sluggish.


Bug Fixes and Performance Improvements

Bug fixes and performance improvements will be a focus in both ‌iOS 27‌ and ‌macOS 27‌. In fact, Bloomberg's Mark Gurman said Apple is working on a "Snow Leopard-style update" for ‌iOS 27‌ and ‌macOS 27‌.

Apple wants to improve the underlying quality and performance of macOS.

Touchscreen Support

There is a MacBook Pro with a touchscreen OLED display that's going to come at some point during the ‌macOS 27‌ release cycle, so there could be hidden touch-based tweaks. This isn't a device that we're expecting until late 2026 at the earliest (and 2027 is more likely), but researchers who like to dig into macOS code might find some hints of touchscreen support.

No More Intel Macs

It's the end of the road for Intel Macs. If you're still using a Mac with an Intel chip, you won't be able to upgrade to ‌macOS 27‌. macOS Tahoe is the last version of macOS that runs on Intel Macs, and ‌macOS 27‌ will require an M1 Apple silicon chip or later.

Apple has phased out all Intel Macs, and it stopped selling the last Mac with an Intel chip in 2023.

Speaking of phasing things out, Apple is ending support for Rosetta 2 after ‌macOS 27‌. Rosetta will still be available in ‌macOS 27‌, but not macOS 28. If you're still using an app that relies on Rosetta, it will need an Apple silicon update by fall 2027 or it's not going to work anymore.

macOS Name

One detail that rarely leaks ahead of WWDC is Apple's name for the next version of macOS. Apple uses California landmarks for its Mac software, and there are still plenty to choose from. "Project Big Bear" is the name of the hashmoji file that Apple shared on X, so macOS Big Bear is a possibility. If ‌macOS 27‌ focuses on bugs and is a "Snow Leopard" update, Apple could pick macOS Emerald after Emerald Bay.

Emerald Bay is a small bay off of Lake Tahoe, and it would be a fitting choice. "Snow Leopard" followed "Leopard," and using the same kind of linked name would be a strong signal of Apple's commitment to performance improvements in the ‌macOS 27‌ update.

Launch Date

‌macOS 27‌ will be available for developers after the June 8 WWDC keynote event. A public beta will follow in July, and the software will see a public launch in the fall.Related Roundup: macOS 27
This article, "5+ New Features Coming in macOS 27" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
We have four days to go until Apple's WWDC keynote event begins on Monday, June 8. iOS 27 has been the focus of most of the rumors, but we're also going to get a new version of macOS, macOS 27.


Some of the same features that are coming in ‌iOS 27‌ will come to ‌macOS 27‌, like the new version of Siri and the dedicated ‌Siri‌ app, but we want to hear from MacRumors readers. What are you hoping to see in ‌macOS 27‌?

Do you want updates to Liquid Glass? Changes to multitasking? Bug fixes? Better external display support? Improved memory management since no one can afford RAM anymore?

Guessing the name Apple will choose for the next version of macOS is always fun. There are still plenty of California landmarks for Apple to choose from, and the filename of Apple's hashmoji for the event on X hints that macOS Big Bear is a possibility.

Let us know what name you think Apple will pick, and tell us your most wanted features in the comments below.Related Roundups: macOS 27, WWDC 2026Related Forum: Apple, Inc and Tech Industry
This article, "macOS 27 Wishlist: What Do You Want From Apple at WWDC 2026?" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
A few days after teasing upcoming Beats over-ear headphones in pink, football superstar Lamine Yamal today shared a Story on his Instagram account revealing a second color for the unreleased headphones: an ivory or stone color.


The Instagram Story is a still photo showing Yamal greeting a fan, and he is carrying a bag with both the pink and ivory color versions of the headphones hanging around the bag's strap, but we don't have any other views of the product.

It's still unclear exactly what features these upcoming headphones are going to offer, and whether they will be considered a successor to the current Beats Studio Pro over-ear model or if they will be a separate product. The headphones first appeared a couple of weeks ago in a U.S. Federal Communications Commission database, but we don't yet know when they will see a public release.
Tag: Beats
This article, "Upcoming Beats Headphones Teased in a Second Color by Lamine Yamal" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
iPhone accessory maker Ugreen recently came out with a new Nexode Air charger and MagFlow Air power bank, two products that are designed for Apple users.


MagFlow Air

The $60 MagFlow Air is a 10,000mAh Qi2 power bank that also has a built-in USB-C cable. The power bank is 4.4 inches long, 2.75 inches wide, and 0.55 inches thick. It has some weight to it, and feels like a good quality device. It's about the same weight as the iPhone 17 Pro Max. It's close in size and design to Anker's MagGo, which is $20 more expensive at $80.


The MagFlow Air has a clever design. It's a Qi2 charger so you can charge your iPhone wirelessly, but there's also a pull-out braided USB-C cable that unclips from the bottom corner. When it's clipped in, it serves as a lanyard. There's another USB-C port at the bottom for charging the power bank or charging a third device (though you can also charge it with the built-in cable). It does support passthrough charging, so you can connect it to a power adapter and then plug in an iPhone. With this setup, the iPhone charges first and then the power bank charges.

I would not choose Qi charging over USB-C charging when there's a choice, but it's useful to have both in case you need to charge two devices at one time. I am a fan of built-in cables, and this one seems well-attached. It takes some force to pull the cable out, so it stays in place when it's used as a carrying strap. The cable is not removable, and it is not replaceable. Ugreen says it has been bent over 10,000 times in testing with no issue.

Qi2 charges a compatible iPhone at up to 15W, and it's not the fastest wireless charging available. You can get up to 25W with one of Apple's MagSafe chargers or a Qi2.2 charger. The magnets in the MagFlow Air are strong, making for a secure connection to an iPhone. It stayed in place when pulling my iPhone out of a pocket.


USB-C charging is faster at 30W, and if you use the USB-C cable instead of the Qi2 charger, you can fast charge your iPhone. You can attach the charger via ‌MagSafe‌ and plug it in, which is useful because it combines USB-C charging speeds with the convenience of a magnetic attachment. An iPhone plugged in via the USB-C cable won't charge wirelessly, but the connection remains available.

I have an ‌iPhone 17 Pro‌ Max, so 10,000mAh isn't quite enough for two full charges, but it is sufficient for a full charge and then some. The MagFlow Air gets warm when charging an iPhone wirelessly, which is not unusual for a Qi charger.

I tested the space gray aluminum color, but the power bank also comes in blue and white. The back has a soft touch material that won't scratch an iPhone, and that provides grip. A button on the side lights up four LEDs to let you know the charge level. It takes about two hours to charge the MagFlow Air from empty to full over USB-C.

Ugreen says the power bank has "Dymondcell ATL cells with 13-layer protection," "intelligent safety protection," and "Thermal Guard temperature control," which will hopefully keep it from exploding on an airplane (it is under the airline limit of 100Wh). The 13-layer protection is supposed to prevent "overheating, overcurrent, and short circuits" for safer charging.

Ugreen doesn't explain what Dymondcell is, but it has partnered with battery maker Amperex Technology Limited (ATL) and is using ATL lithium-ion batteries. Ugreen's UK site has a little more information, but it doesn't detail what the 13 layers are. The battery cells can apparently withstand a 4mm tungsten steel nail penetration test and survive a 1.43-ton crush resistance test. I can't test those claims, but it sounds impressive.

Nexode Air

Priced at $25, the USB-C Nexode Air is the slimmest 65W charger I've seen to date. It uses GaN, and it's not too far off from the size of the tiny power bricks that Apple used to provide with the iPhone.


The Nexode Air is just over 1.6 inches long, 1.2 inches wide, and 1.3 inches deep. The prongs fold in when it's not in use, making it more compact for travel. I tend to prefer multi-port chargers so I can charge more than one device at a time, but if you need a single charger for a Mac or another device, it's a good option.

Ugreen's 65W Nexode Air next to 30W Apple USB-C charger
I tested a space gray version that charges at 65W, but it also comes in 45W and in orange, white, and blue to match Apple's ‌iPhone 17 Pro‌ models. 65W is enough to fast charge a MacBook Air, and it also works for iPhones and iPads. It fit well in a plug, left plenty of space to plug in something else, and it charged as expected.

Ugreen includes a color-matched braided USB-C to USB-C cable that feels like it's made well. The cable is 3.3 feet, which is a standard size that usually comes with accessories.

Bottom Line

There are a ton of power banks out there, so the MagFlow Air has a lot of competition. This little Anker Nano is my favorite 10K option, but the MagFlow Air is growing on me. I like the magnetic connection with the option to charge over USB-C because it's a combo that most power banks don't offer.

$60 is on the high side for a 10K power bank, but with the built-in cable and the Qi2 magnetic charging, it's priced competitively with other trusted brands.

As for the Nexode Air, it's a good little USB-C power adapter if you need a pocketable single-device charging option.

How to Buy

The 65W Nexode Air is available from Amazon for $25. The MagFlow Air is available from Amazon for $60.

Note: Ugreen provided MacRumors with an MA320UG for the purpose of this review. No other compensation was received.
This article, "Ugreen MagFlow Air and Nexode Air Review: A Power Bank and Charger Built for iPhone" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
With developers and members of the media soon to arrive at the Apple Park campus for WWDC 2026, Apple has added new merchandise to the store at the ‌Apple Park‌ Visitor Center.


Mr. Macintosh shared images of the new items, including crewneck sweatshirts with the classic Apple Garamond text featuring rainbow lettering, hats with a rainbow Apple logo, and water bottles in gray and white.


He also said Apple is using new merchandise drawers at the ‌Apple Park‌ Visitor Center to hold the ‌WWDC 2026‌ gear.

The ‌Apple Park‌ Visitor Center sells Apple-branded gear unavailable at other Apple retail stores. Apple regularly introduces new T-shirt and sweatshirt designs, and it sells water bottles, notebooks, pens, and other small items.

‌Apple Park‌ is also a full Apple Store with the option to purchase standard Apple products like iPhones, iPads, Macs, and accessories.

Apple invited members of the media and select developers to an in-person ‌WWDC 2026‌ keynote viewing event. WWDC is set to begin on Monday, June 8, which means attendees will be heading to ‌Apple Park‌ in the coming days.Related Roundup: WWDC 2026Tag: Apple ParkRelated Forum: Apple, Inc and Tech Industry
This article, "Apple Park Visitor Center Gets New Merch Ahead of WWDC 2026" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Accessory maker Satechi released its first Thunderbolt 5 dock earlier this year, debuting the $400 Thunderbolt 5 CubeDock. Satechi's dock combines Thunderbolt 5 connectivity with the traditional ports you expect from a dock, plus extra SSD storage thanks to an added SSD enclosure.


Satechi likes to make things shaped like the Mac mini, and the CubeDock gives ‌Mac mini‌ vibes. It's five inches by five inches, and two inches thick, identical to the ‌Mac mini‌. It's silver, so it matches Apple hardware that comes in that shade, and it would pair well with a ‌Mac mini‌.

The front of the dock has a 30W/10Gbps USB-C port, a 7.5W/10Gbps USB-A port, a 3.5mm audio jack, and SD and microSD card slots. I like the positioning of the card readers because they're easy to get to. I don't use wired headphones, but if I did, I'd also appreciate having that front audio jack. 30W charging for the front USB-C port is useful too, because 30W is enough to fast charge an iPhone and charge an iPad or MacBook Air.


The back has a 2.5Gb Ethernet port, an 80/120Gbps Thunderbolt 5 host port to connect to a Mac, three additional 80Gbps Thunderbolt 5 ports (with 15W each for accessories), a 10Gbps 4.5W USB-A port, a 10Gbps 7.5W USB-C port, and a DC port for connecting the power supply. The CubeDock provides 140W for a MacBook,can charge the 16-inch MacBook Pro at the fastest speed.


At the bottom of the CubeDock, there's a panel that can be popped out to add in up to an 8TB NVMe SSD. It supports 2230, 2242, 2260, and 2280 sizes with transfer speeds of up to 6000MB/s, depending on the SSD used. The CubeDock has an SSD enclosure, but it does not come with SSD storage. You need to buy an internal SSD separately if you want to use the enclosure, and SSDs aren't cheap right now.


I installed a 2TB SSD in the slot at the bottom of the CubeDock. There's a plastic cover that comes off, and the SSD plugs in underneath. It's held in place with a screw, but the installation process was a little annoying because the screw needs to be positioned before the SSD is inserted. Satechi includes a thermal pad, which I added before closing it back up. My Mac recognized the SSD in the enclosure just as it would any other SSD I plugged in.


There is a fan in the CubeDock that circulates air, along with vent holes at the sides. It has an LED power button on the front, and it charges with an included 180W power supply. The power supply is not built into the dock and is instead an external brick. Satechi also includes a Thunderbolt 5 cable to connect the dock to a Mac.

I don't generally mind the sound of fans, but the CubeDock's fans have a subtle electronic whine that bothers me. I know some people can't hear that high-pitched electronic noise, but I can, and in a quiet room, it's the audio equivalent of having a pebble stuck in my shoe. I can't hear the sound when the TV is on, when music is playing, or when my AC is running. Anker's Thunderbolt 5 Dock has fans and had a similar noise, but fanless models like the CalDigit TS5 Plus are silent.

With the fans, the CubeDock doesn't get blazingly hot, but it is warm to the touch. The temperature is closer to a hand warmer on a cold day than scorching coffee. I didn't notice a temperature difference testing with the SSD installed and without it.


The CubeDock supports up to three 8K displays at 60Hz, but Satechi says 8K is limited to Windows machines. The M5 Pro and M5 Max chips do support 8K displays, but I don't have one to test with.

What I do have on hand is a 5K Studio Display and a 32-inch 4K 120Hz OLED display, both of which the CubeDock can handle with no problem. I plugged in two iPhones to charge, put in an SD card, and connected two SSDs, and transferred large files. I had no issues with the CubeDock under this stress test, and everything also worked during day-to-day testing.

The benefit of a dock like the CubeDock is being able to plug in multiple displays, peripherals, and accessories while only having one cable connected to a Mac. I can tuck the CubeDock under a display, route the cables out the back, and keep my desk neater with less cable clutter. I felt like the CubeDock had a good number of ports for everyday use, and I wasn't missing anything. It has fewer USB-C and USB-A ports than some other docks that it competes with, but I have few enough USB-A devices that even two USB-A ports felt like one too many.

The Apple silicon chip you have determines the number of displays that the CubeDock can drive over a single Thunderbolt port. M5 Pro and M5 Max Macs can drive three displays at 6K/60Hz with Satechi's dock. M4 Max, M4 Pro and earlier Pro/Max chips support up to two external displays with the CubeDock (up to 6K/60Hz).


Pro/Max Macs can generally support more than two external displays, but you need to use more than one Thunderbolt port. I have two displays connected to an M1 Max with the CubeDock, and a third display plugged into a different Thunderbolt port.

Base M1 and M2 Macs support a single external display over Thunderbolt, but base M4 and M5 Macs can drive two. The M3 is complicated because an M3 ‌MacBook Air‌ can support two displays, but only in clamshell mode. It's best to check Satechi's website for compatibility info to make sure you can connect what you want to connect.

Bottom Line

Satechi's dock lets you connect multiple displays, peripherals, and accessories to your Mac with one cable, offering easy plug-and-play functionality. The addition of an SSD enclosure helps differentiate the CubeDock from competing products. It puts the ports most people need right up front, and hides the rest away for desk organization.

The CubeDock is one of the better looking options on the market because of how well it matches Apple's aesthetic, and it doesn't run as hot as docks without a fan included. Unfortunately, the fan noise can be distracting for people who are sensitive to certain sounds.

With two generations of Thunderbolt 5 Macs now available, there's more reason to choose a Thunderbolt 5 over a Thunderbolt 4 dock. Compared to Thunderbolt 4, Thunderbolt 5 offers double the bandwidth (80Gbps instead of 40Gbps) and up to 120Gbps for display-heavy setups.

If you have a newer Mac that supports Thunderbolt 5 and need extra ports, a Thunderbolt 5 dock makes the most sense. If you have an older Mac and are trying to decide between Thunderbolt 4 and Thunderbolt 5, Thunderbolt 5 is the better choice if you're going to upgrade anytime in the next couple of years.

How to Buy

The Satechi Thunderbolt 5 CubeDock with SSD Enclosure can be purchased from the Satechi website or from Amazon.com for $399.99.

Note: Satechi provided MacRumors with a CubeDock for the purpose of this review. No other compensation was received. MacRumors is an affiliate partner with Satechi and may earn commissions on purchases made through links in this article.Tag: Satechi
This article, "Satechi CubeDock Review: A Thunderbolt 5 Dock That Doubles as an SSD Enclosure" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
When security teams scan their container environments for the first time, they often discover hundreds of known vulnerabilities, and almost none of them trace back to application code.
The overwhelming majority come from packages that shipped with the base image: shells, compilers, debug utilities, and libraries the application never calls. In a software supply chain built on containers, the base image is the foundation. If that foundation ships with unnecessary components, every workload built on top of it inherits the risk.
Hardened images address this problem at the source. They are purpose-built base images stripped down to only the runtime components an application needs, continuously patched, and shipped with verifiable metadata that lets security teams confirm exactly what is inside and how it was built.
Why standard container images carry hidden risk
A general-purpose base image like a standard Linux distribution might ship with 400 or more installed packages. A typical containerized application uses 20 to 30 of them. The rest are inherited baggage: package managers, text editors, network diagnostic tools, documentation files, and libraries for use cases the container was never intended to serve.
Each of those unused packages is a potential attack surface. Vulnerability scanners flag them because they are genuinely present in the image, even if the application never imports or executes them. The result is a signal-to-noise problem that burns through security team capacity. When a team faces 200 findings and 80% of them exist in packages no running workload touches, the real vulnerabilities that need immediate attention get buried in triage.
The packages themselves are the other half of the problem. A shell in a production container gives an attacker an interactive environment to work from if they achieve initial access. A package manager lets them install additional tooling. Debug utilities help them map the network and identify lateral movement targets. None of these belong in a production container, but they ship by default in most general-purpose base images, quietly expanding the blast radius of any breach.
What makes a container image “hardened”
So what are hardened images in practice? Minimization gets the most attention, but it’s only one of three requirements. A genuinely hardened image is also continuously maintained and independently verifiable.
Quick definition: Hardened images are minimal, continuously patched base images that ship only the runtime components an application needs, paired with verifiable supply chain metadata like SBOMs, build provenance, and cryptographic signatures.
Minimized attack surface
The most visible characteristic of a hardened image is minimization. Shells, package managers, and debug tools are removed. Only the runtime components the application needs to function are included. This is more aggressive than simply choosing a slim base image variant. Hardened images are often rebuilt from the package level up, selecting each component deliberately rather than subtracting from a general-purpose distribution.
The result is a dramatically smaller CVE surface. Where a general-purpose image might carry hundreds of known vulnerabilities, a hardened equivalent for the same runtime typically carries single digits or none.
Continuous patching and rebuilds
A hardened image that’s never updated becomes a snapshot of the day it was built. An image hardened on Tuesday can start drifting by Friday: three upstream CVEs published, two library patches released, and the image is already accumulating the kind of exposure it was designed to prevent.
Security requires ongoing maintenance: monitoring upstream projects for fixes, rebuilding images to incorporate patches, and doing this on a defined cadence with clear SLAs. The best hardened images are rebuilt continuously, not on a quarterly or release-driven schedule. That’s what separates production-grade hardened images from one-time efforts to slim down a Dockerfile.
Verifiable supply chain metadata
This is where hardened images connect to the broader supply chain security best practices that organizations are adopting. A truly hardened image ships with:
Software Bills of Materials (SBOMs) that list every package, version, and dependency in the image Build provenance attestations aligned to frameworks like SLSA, providing cryptographic proof of how and where the image was built Vulnerability Exploitability eXchange (VEX) data that identifies which CVEs present in the image are not exploitable given how the software is actually configured Cryptographic signatures that verify the image has not been tampered with between build and deployment This metadata is what makes automated policy enforcement possible in CI/CD pipelines. A CI gate that blocks deployments unless the base image has a signed SBOM and valid provenance attestation is only feasible when the image provider builds that metadata into the supply chain from the start. For organizations operating in regulated environments, it’s also what allows security and compliance teams to verify an image without reverse-engineering its contents.
Container hardening vs. VM hardening
The term “hardened image” appears in both container and virtual machine contexts, but the two practices address different layers of the stack.
VM hardening focuses on OS configuration: disabling unnecessary services, tightening firewall rules, restricting user permissions, and tuning kernel parameters. Defined by frameworks like CIS Linux Benchmarks. Takes a full operating system and locks it down. Container hardening operates at the image layer: what is packaged (minimization), how the image was assembled (provenance), and whether the contents are transparent (SBOMs and vulnerability data). Starts from a minimal foundation and builds up only what the application requires. Both practices are valid and often coexist. Many organizations apply VM hardening to their container host nodes and container hardening to the images running on those nodes. They complement each other, but the techniques, tooling, and evaluation criteria are different. A CIS-hardened AMI and a hardened container base image solve distinct problems at distinct layers.
How to evaluate hardened images
Not all images marketed as hardened meet the same standards. When evaluating options, look for these characteristics:
Transparency: Can you see every package in the image? Is there a complete, machine-readable SBOM? Provenance: Can you independently verify how and where the image was built? Are attestations signed and aligned to a recognized framework? Patch cadence: How quickly are upstream security fixes incorporated? Is there a defined SLA, or is patching best-effort? Compatibility: Do the images work as drop-in replacements in existing Dockerfiles and CI/CD pipelines, or do they require workflow changes? Vulnerability data integrity: Does the provider suppress or filter CVE data to make the image look cleaner, or do they publish full vulnerability transparency with exploitability context? The answers to these questions separate genuinely hardened images from images that are simply minimal. Minimization is necessary but not sufficient. Without provenance, patching discipline, and transparency, a small image is just a smaller attack surface with less visibility.
What hardened images are not
The term “hardened” is sometimes applied loosely. Because of this, it’s worth clarifying what does not qualify, because each of these approaches solves part of the problem while leaving the rest exposed.
Choosing a slim or Alpine variant reduces image size, but it does not address provenance, patching cadence, or supply chain metadata. The image is smaller, not hardened. Running a scanner and manually removing flagged packages produces a point-in-time fix, not a continuously maintained hardened image. The next upstream CVE puts you back where you started. Building a distroless image from scratch achieves minimization but requires significant ongoing effort to maintain patch currency across every image in a portfolio. Without a defined rebuild cadence and verifiable metadata, the maintenance burden scales with the number of images. Hardening, in the supply chain security sense, means all of these concerns are addressed systematically: the image is minimal, maintained, and verifiable.
Getting started with hardened images
Hardened container images are becoming the standard foundation for secure container deployments. They address the root cause of most container vulnerability findings: unnecessary packages inherited from general-purpose base images. And with verifiable supply chain metadata, they give security teams the transparency and audit trail that modern compliance requirements demand.
Docker Hardened Images provide this foundation across several thousand images spanning runtimes, frameworks, databases, and infrastructure components. Every image ships with SBOMs, SLSA Build Level 3 provenance, VEX data, and cryptographic signatures. The Community tier is free and open under Apache 2.0 with no restrictions on use or redistribution.
Explore our full catalog of hardened images and start replacing your base images today.
Frequently asked questions
What is the difference between a hardened image and a minimal image?
A minimal image has fewer packages, but that’s only one dimension of hardening. A hardened image also includes continuous patching with defined SLAs, verifiable build provenance, complete SBOMs, and vulnerability exploitability data. Minimization reduces the attack surface; hardening ensures the remaining surface is maintained, transparent, and verifiable.
Do hardened images work with existing CI/CD pipelines?
Well-designed hardened images are built to serve as drop-in replacements for standard base images. If your Dockerfile starts with a general-purpose runtime image, you can typically swap in a hardened equivalent without changing your build process. The key consideration is shell access: some hardened images remove shells entirely, which means build steps that rely on shell commands may need adjustment for multi-stage builds.
How do hardened images reduce CVE counts?
Every package in a container image is a potential source of CVEs. By removing packages the application does not need, hardened images eliminate the vulnerabilities those packages carry. A general-purpose base image with 400 packages might have 200 known CVEs. A hardened equivalent with 30 packages might have fewer than 5, because the vast majority of vulnerable components were never included. This significantly shrinks the surface an attacker can target and reduces the triage burden on security teams.
View the full article
Security researchers are warning of an issue with the default HTTP/2 configuration used by major web servers which reportedly survived more than a decade of human review before showing up in Codex-assisted analysis.
A flaw in the handling of the HTTP/2 protocol made a denial-of-service (DoS) attack possible on web servers including nginx, Apache HTTP server, Microsoft IIS, Envoy, and Cloudflare’s Pingora, according to security consultancy Calif.
HTTP/2 was introduced in 2015 to increase the speed of HTTP by allowing multiple simultaneous connections, and is gradually being superceded by HTTP/3, which is built on the new QUIC encrypted transport protocol. The problem uncovered by Calif lies in how affected servers handle HTTP/2 header compression and request processing, allowing an attacker to trigger disproportionate memory consumption.
“The attack chained two techniques known to humans for a decade: a compression bomb and a Slowloris-style hold,” Calif CEO Thai Duong said in a blog post, calling the technique HTTP/2 Bomb. A search of Shodan revealed 880,000+ websites supporting HTTP/2 and running one of these servers, although many of these websites use a Content Delivery Network (CDN), which may add some complexity to the attack, he said.
Weaponizing a compression feature for DoS
The issue, tracked as CVE-2026-49975, involves HPACK, the header compression mechanism built into HTTP/2. Calif found that attackers can abuse the protocol’s dynamic header table in a way that forces servers to repeatedly allocate memory far beyond what would normally be expected from the size of incoming requests.
A relatively small amount of attacker-controlled traffic can trigger excessive memory allocations on the target server, Duong said.
“The bomb targets HPACK, HTTP/2’s header compression scheme: One byte on the wire becomes one full header allocation on the server, repeated thousands of times per request,” he said. “The hold is a zero-byte flow-control window that keeps the server from ever freeing any of it.”
This isn’t the first time HTTP/2 was flagged for allowing DoS attacks. In 2019, multiple HTTP/2 denial-of-service vulnerabilities disclosed by Netflix affected numerous server implementations and prompted emergency patches across the ecosystem.
In October 2023, the protocol was disclosed to be prone to massive DDoS attacks owing to its stream multiplexing capability.
Duong recalled in the post how in 2012 he contributed to the discovery and patching of a flaw in HPACK, that back then was exploited by a different attack, CRIME. “I was too fixated on fighting CRIME and missed the Bomb,” he reflected.
Calif reported the flaw to all affected projects. nginx and Apache HTTP Server moved quickly to block the attack path, while Envoy patched on June 3. Microsoft IIS and Cloudflare’s Pingora had yet to release patches at the time of publication.
Admins will need to obtain the fixed versions of nginx (v1.29.8+) or Apache (mod_http2 v2.0.41), through the normal update channels used for these products. Envoy issued patches for versions 1.35.11, 1.36.7, 1.37.3, and 1.38.1.
For organizations without a patch available to them, Calif recommended disabling HTTP/2 if possible, or “front the server with something that enforces a hard cap on header count per request.”

View the full article
OpenAI has proposed mandatory federal evaluations of the most capable AI models before public release while arguing that regulators should stop short of deciding whether those systems can be deployed, staking out a middle ground in the debate over how frontier AI should be governed.
The company’s proposal came a day after the White House issued an executive order on advanced AI innovation and security, amid ongoing discussions in Washington of whether oversight of frontier AI systems should rely on voluntary commitments, mandatory evaluations, licensing requirements, or some combination of the three.
At the center of OpenAI’s proposal is a distinction between government evaluation and government approval. The company proposed that the most capable AI models undergo pre-release assessments by the Center for AI Standards and Innovation (CAISI), the federal government’s AI evaluation and standards body, while stopping short of giving regulators authority to approve or block deployments.
“Policymakers should require the most capable frontier models to undergo a CAISI evaluation before public release,” OpenAI wrote in its proposal, “Democratic Governance of Frontier AI: A blueprint for a federal framework.” But it added that “CAISI’s role should be to conduct evaluations and recommend mitigations—not to approve or block deployments.”
It also proposed a broader federal framework that would require evaluations, audits, transparency reports, incident reporting, whistleblower protections, and stronger security controls around frontier AI systems.
Shaping the governance debate
Sanchit Vir Gogia, chief analyst at Greyhound Research, said OpenAI’s proposal appears designed to influence the direction of an emerging federal governance framework rather than respond to one that is already settled.
“The contest is no longer whether frontier AI is governed, but who governs it, on whose terms, and where final authority rests,” he said.
OpenAI argued governments need greater visibility into frontier AI development and that voluntary commitments alone will not be sufficient as AI systems become more capable.
“Democratic governments — not private companies acting alone — must ultimately determine the rules, safeguards, and accountability mechanisms,” it wrote. “Decisions about the pace of AI innovation should not be left to any one lab, company, or special interest group.”
The company also said, “If artificial general intelligence is going to benefit all of humanity, the world needs more than voluntary commitments, individual company policies, and isolated regulatory interventions.” Instead, it argued, “It needs harmonized legal frameworks and durable institutions capable of adapting as technology advances.”
A procurement gate for enterprise AI
The proposal also addresses government buyers. OpenAI said federal agencies should not run frontier AI systems that have not passed a recognized evaluation and should “prohibit procurement of products and services that rely on unevaluated frontier models” in sensitive settings.
It would also sort the federal market into evaluated and unevaluated models: Any vendor building on a frontier model would have to show the system had cleared evaluation to keep selling to government.
Gogia said compliance-heavy rules favor the largest developers, who help define the thresholds and audit templates that others inherit. “Governance of this shape can become a moat dressed as maturity,” he said.
Beyond voluntary commitments
OpenAI’s proposal goes beyond model evaluations, suggesting a broader governance framework for frontier AI developers.
Among the measures it recommends are annual third-party audits, public transparency reports, critical safety incident reporting requirements, cybersecurity protections for unreleased model weights, and whistleblower safeguards.
“Large frontier developers should annually retain an independent third party to audit compliance with frontier safety requirements,” OpenAI said in the document.
The company is also calling for mandatory reporting of critical incidents involving deployed models, including dangerous model behavior and unauthorized access to sensitive model weights.
Shreeya Deshpande, senior analyst at Everest Group, said the proposal attempts to balance stronger oversight with continued innovation.
“This creates a credible middle path between voluntary commitments and licensing, while preserving developer control,” she said. “The model’s effectiveness will depend on CAISI’s technical capacity, independent assessment quality, and the strength of enforcement mechanisms.”
Building institutions, not gatekeepers
A central element of OpenAI’s proposal is to expand CAISI into what it describes as the federal government’s primary institution for frontier AI evaluation, standards development, independent assessment certification, and coordination with national security agencies and international partners.
OpenAI argues policymakers need a permanent institution capable of monitoring frontier capabilities and evaluating emerging risks as AI systems evolve.
At the same time, the company repeatedly cautions against turning CAISI into a deployment gatekeeper. Developers, it argues, should remain responsible for release decisions, and model deployment should not be delayed because of government capacity constraints or administrative bottlenecks.
Gogia said the framework should be understood primarily as a mechanism for generating evidence about frontier AI systems rather than directly determining whether they can be deployed.
“It is best understood as an evidence-producing regime rather than an accountability-producing one,” he said. “It will make developers more legible. Whether it makes them more answerable is a separate question.”
View the full article
Apple and MLB today released the July schedule for Apple TV's weekly Friday Night Baseball doubleheader.

Friday Night Baseball games are included with an Apple TV streaming subscription at no additional cost.

Now through July 5, new and qualified returning subscribers in the U.S. and Canada can receive a one-month free trial of Apple TV. Tags: Apple TV Service, MLB
This article, "Apple TV and MLB Release July Schedule for 'Friday Night Baseball'" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
A security researcher found a flaw in Anthropic's Claude Code GitHub Action that let an attacker take over vulnerable public repositories running it, with nothing more than a single opened GitHub issue. Because Anthropic's own action repo used the same workflow, a working attack could have pushed malicious code into the action itself and onto the projects downstream that pull it. RyotaK of GMOView the full article
Apple today highlighted a new study by economists at Analysis Group that outlines four key App Store stats for 2025.

Ahead of WWDC 2026 next week, Apple's core message with this press release is that the App Store is reaching new heights and that "developers continue to thrive globally."

App Store ecosystem facilitated a record $1.4 trillion in total billings and sales
Apple received no commission on more than 90% of transactions
Apps featuring consumer-facing AI saw 4× more growth in billings
App Store ecosystem has nearly tripled in size since 2019Tag: App Store
This article, "Apple Highlights App Store Study: $1.4 Trillion in Sales Last Year, More Than 90% Commission-Free" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Apple today announced that nine new games are coming to Apple Arcade, including a mobile version of the popular game show Family Feud.


The following four games were added to Apple Arcade today:Mini Football Legends
My Talking Tom 2+
Coffee Inc 2+
FreeCell Solitaire: Card Game+Family Feud Pocket is launching on Apple Arcade on Tuesday, June 30. Apple says the game will provide an "authentic, true-to-show trivia experience."

"Hosted by the iconic Steve Harvey, the game features the classic mechanics fans know and love, along with daily challenges and exclusive questions," says Apple. "Players can guess the answer and outsmart the competition solo or with loved ones — at home or on the go — through local and online multiplayer."

Four popular App Store games will be receiving Apple Arcade editions on Thursday, July 2:
Dungeon Clawler+
Creatures of the Deep+
Pocket City 2+
Draw It+
App Store links for the above games are not functional yet. More details about all nine games are outlined in Apple's press release.

Apple Arcade is a subscription service that provides access to hundreds of games across the iPhone, iPad, Mac, Apple TV, and Apple Vision Pro. All of the games are free of ads and in-app purchases. In the U.S., Apple Arcade costs $6.99 per month, and it is also bundled with other Apple services in all Apple One plans.

Apple Arcade can be accessed through the App Store and the Apple Games app.Tag: Apple Arcade
This article, "Apple Arcade Adding Nine New Games, Including 'Family Feud Pocket'" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Amazon this week has all-time low prices on the Apple Watch Series 11, with $100 discounts across numerous models of the smartwatch. This sale includes a handful of GPS aluminum models on sale at record low prices.

Note: MacRumors is an affiliate partner with Amazon. When you click a link and make a purchase, we may receive a small payment, which helps us keep the site running.

You can get the 42mm GPS Apple Watch Series 11 for $299.00, down from $399.00, and the 46mm GPS model for $329.00, down from $429.00. On Amazon, you'll find four of the 42mm GPS models and three of the 46mm GPS models on sale at these all-time low prices.

$100 OFFApple Watch Series 11 (42mm GPS) for $299.00
$100 OFFApple Watch Series 11 (46mm GPS) for $329.00

Best Buy is matching these deals during its Apple Shopping Event, which is set to last through this Sunday. Head to our full Deals Roundup to get caught up with all of the latest deals and discounts that we've been tracking over the past week.



Deals Newsletter

Interested in hearing more about the best deals you can find in 2026? Sign up for our Deals Newsletter and we'll keep you updated so you don't miss the biggest deals of the season!




Related Roundup: Apple Deals
This article, "Apple Watch Series 11 Drops to $299 at Amazon, $100 Off Select Models" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
The annual percentage yield (APY) for the Apple Card's savings account was lowered from 3.5% to 3.4% this week.

If you deposited $1,000 and maintained that balance for one year, you would earn $34 in interest at the current APY.

Tag: Apple Card
This article, "Apple Card Savings Account's Interest Rate Lowered" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Best Buy has a new sale going on today with multiple Apple devices hitting record lows, and that includes the AirPods Max 2. You can get the brand new over-ear headphones for $499.00 in all five colors, down from $549.00.

Note: MacRumors is an affiliate partner with Best Buy. When you click a link and make a purchase, we may receive a small payment, which helps us keep the site running.

This beats Amazon's current low price by $10 and is a new record low price on the headphones. Best Buy offers both in-store pick-up and delivery options for the AirPods Max 2, so you should be able to get them before the end of the week in many locations.

$50 OFFAirPods Max 2 for $499.00

You'll also find solid deals on Beats products, Apple Watch SE 3, Apple Watch Series 11, iPad Air, iPad, AirPods Pro 3, and more during this event. We've collected some of the best deals in the list below, but be sure to browse the full sale on Best Buy's website before it ends on Sunday.

Beats Pill - $99.99 ($50 off)
Beats Solo 4 - $149.99 ($50 off)
Beats Studio Pro - $249.99 ($100 off)
AirPods Pro 3 - $199.99 ($50 off)
Apple Watch SE 3 (40mm GPS) - $219.00 ($30 off)
Apple Watch Series 11 (42mm GPS) - $299.00 ($100 off)
iPad (128GB Wi-Fi) - $299.00 ($50 off)

If you're on the hunt for more discounts, be sure to visit our Apple Deals roundup where we recap the best Apple-related bargains of the past week.



Deals Newsletter

Interested in hearing more about the best deals you can find in 2026? Sign up for our Deals Newsletter and we'll keep you updated so you don't miss the biggest deals of the season!




Related Roundup: Apple Deals
This article, "AirPods Max 2 Hit New Low Price of $499" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Apple's upcoming OLED MacBook Pro – aka "MacBook Ultra" – is expected to be the primary driver of a hybrid OLED laptop display market worth $4 billion this year, according to a new Omdia research report ($).


The report corroborates rumors that Apple's first OLED MacBook will use a hybrid OLED architecture combining oxide TFT (thin-film transistor) and tandem OLED layers. The combination is already used in Apple's iPad Pro models, and offers higher brightness, improved power efficiency, and longer lifespan compared with conventional single-stack OLED panels.

Samsung Display is said to be making the panels, and the supplier has invested heavily in an 8.6-generation OLED production line in South Korea. The line recently reached a key milestone for mass production.

It will be the first time the combination has been used for a laptop in the 14-inch and 16-inch range, and Apple's adoption is expected to pull the rest of the OLED laptop industry in the same direction. Omdia estimates that hybrid OLED panels will account for 12.6% of all OLED laptop shipments in 2026, rising dramatically to 89.5% by 2033.

Omdia says manufacturers are already exploring new patterning methods for large OLED panels. In addition to the established Fine Metal Mask (FMM) process, it says technologies such as inkjet printing (IJP) and fine photolithography mask (FPM) are being developed to improve production efficiency for larger screens.


Apple's first OLED MacBook Pro will also feature a touchscreen display, according to analyst Ming-Chi Kuo. The claim has been corroborated by Bloomberg reporter Mark Gurman, who also says the laptops will have "thinner and lighter frames." Apple is apparently focusing on delivering the thinnest possible device without compromising on battery life or major new features. That might also mean a higher price point and a new "Ultra" tier for the laptop.
MacBook Ultra: 5 Features That Could Justify the Name
The redesigned 14-inch and 16-inch MacBook Pro models are also expected to have a hole-punch camera at the top of the display, and it could potentially be housed in a pill-shaped cutout similar to the iPhone's Dynamic Island, rather than the notch MacBook Pro owners are accustomed to. Gurman says the machines will be powered by M6 chips and are being readied for a late 2026 or early 2027 launch. As things stand, the latter time frame is now looking more likely, owing to the global memory chip shortage.Related Roundup: MacBook ProTags: OLED, OmdiaBuyer's Guide: MacBook Pro (Buy Now)Related Forum: MacBook Pro
This article, "'MacBook Ultra' May Drive Industry Shift to Hybrid OLED Laptop Displays" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
The color options Apple is reportedly planning for the upcoming iPhone 18 Pro and ‌iPhone 18 Pro‌ Max have appeared online today in the form of images of chassis parts of unknown origin.


Shared by the account name "yeux1122" on the Korean-langauge Naver blog, the images show what appear to be production-ready frames for three of the four colors Apple is rumored to be planning.

Multiple rumors have suggested Apple is testing a deep red finish for the iPhone 18 Pro models, and the color is expected to be the special color that Apple chooses in 2026, similar to Cosmic Orange for iPhone 17 Pro.


Two other colors Apple is said to be planning are Light Blue and Dark Gray. Apple may also offer the iPhone 18 Pro and iPhone 18 Pro Max in Silver, though that color isn't shown in these pictures. Macworld previously shared what it said were Pantone codes for the four colors Apple is testing.

The four colors have also been spotted in the first iPhone 18 Pro dummy models to leak, providing another look at the shades Apple is likely to use.


The iPhone 18 Pro models are expected to be unveiled this September alongside Apple's first foldable iPhone, which will have its own set of color finishes that are likely to be more muted, with silver, white, and indigo rumored so far.Related Roundup: iPhone 18 ProTag: Naver
This article, "iPhone 18 Pro: Dark Cherry, Light Blue, and Dark Gray Chassis Leaked" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
A high severity vulnerability in Hugging Face Transformers enables attackers to compromise systems that use the popular Python library to test and run AI models. The flaw impacts library versions that continue to be actively downloaded and comes at a time when attackers are increasingly targeting the AI supply chain, including through malicious models hosted on the Hugging Face platform.
The exploit for this vulnerability involves adding an innocuous-looking parameter called _attn_implementation_internal to remote model configuration files on Hugging Face and bypasses the trust_remote_code=false flag that normally prevents the execution of remote code accompanying models.
“The malicious field uses an underscore-prefixed name that looks like an internal implementation detail — the kind of field that config files are full of,” researchers from Pluto Security who found the vulnerability said in their report. “There are no runtime warnings, no consent prompts, no unusual log entries.”
The Hugging Face Transformers library allows Python developers to deploy over 1 million machine learning model variants hosted on Hugging Face on their local hardware or cloud instances. It is used in many enterprise environments and CI/CD pipelines to test models pre-trained for various tasks and to fine-tune them with proprietary data.
The Hugging Face Transformers PyPI package is downloaded over 146 million times per month and has a total of 2.2 billion installs to date. The project is also one of the highest-rated repositories on GitHub with 161K+ stars, so the blast radius of a remote code execution (RCE) vulnerability is huge.
This previously undisclosed flaw, now tracked as CVE-2026-4372, was silently patched in Transformers 5.3.0, which was released on March 3, but it impacts all versions released since August starting with 4.56.0. Vulnerable versions continue to be downloaded 7 to 8 million times per week and account for around a fourth of weekly installations.
Custom ‘attention’ kernels bypass RCE defenses
AI models hosted on Hugging Face can contain custom Python code, which can present a serious security risk if downloaded and executed alongside the model automatically. In the past this capability has been abused by attackers, which is why a parameter called trust_remote_code: was added to configurations. When set to false, it is meant to give developers an assurance that additional code will not be automatically executed.
However, in March last year, Hugging Face added a feature called Hub Kernels that allows users to host custom compiled attention kernels. These kernels improve the performance of models when loaded on GPUs and require an additional package called kernels.
The presence of this package on the machine is required to exploit this vulnerability, which is a limiting factor at first glance. However, even though it’s an optional dependency, having the kernels package installed is not uncommon, especially because most users who run local AI models want to benefit from GPU acceleration and will install Transformers with all “extras” packages.
“Users who work with GPU-accelerated inference — arguably the most valuable targets — are the most likely to have it installed,” the researchers said. “Enterprise ML platforms and GPU clusters commonly install all optional dependencies to maximize hardware utilization.”
The vulnerability is the result of three separate design decisions made in the code that combine to introduce the silent RCE risk. First, when the model loading is invoked with AutoModelForCausalLM.from_pretrained(“model-name”) the library proceeds to download the model’s configuration, weights, and tokenizer from the Hub, assemble the correct architecture, and return a ready-to-use model to the application.
The code that parses the model’s config.json file uses a function called setattr that parses every key-value pair in the file and loads it into the config object, but does not differentiate between user-configurable parameters and internal parameters that start with the _ character. Such internal parameters should never be present in a user-supplied config because they are not meant to be touched by developers.
One of those internal parameters is _attn_implementation_internal, which is used to control which attention mechanism implementation the model uses: Flash Attention, SDPA, or the default eager implementation.
Furthermore, the hub_kernels.py component checks for the value of this parameter and if it’s set to a pattern that matches two strings separated by / it assumes this is an owner/repository definition from the Kernels Hub. The code then proceeds to download the kernel from the defined repository and execute it.
“No sandboxing. No code signing. No integrity verification. No user prompt,” the researchers said. “Just a raw import of whatever Python code lives in the attacker’s repository — including anything in __init__.py, which executes automatically on import.”
As a result of these three independent issues — the unfiltered setattr, the unprotected internal attribute, and the unsandboxed kernel loader — exploitation becomes trivial: Publish an attractive model with a configuration that includes _attn_implementation_internal set to attacker-repo/malicious-kernel.
Supply chain attacks via malicious AI models are increasing
This is not an unusual attack. Malicious models get uploaded to Hugging Face all the time and they can be quite successful in tricking users. Last month, a malicious Hugging Face repo posing as a new release of OpenAI’s Privacy Filter model reached the No. 1 trending spot on the platform within 18 hours and was downloaded 244,000 times. The model code contained infostealer malware for Windows.
Last year, researchers showed how attackers can hide malicious code inside Python Pickle files, a format that is commonly used to distribute AI models.
This Transformers vulnerability is not the first that enables remote code execution through maliciously crafted AI models. Last month researchers from security firm HiddenLayer disclosed a RCE vulnerability in ChromaDB that allowed unauthenticated remote attackers to trick Chroma servers into executing malicious code from model configurations hosted on Hugging Face.
Earlier that same month, the same researchers showed how remote code execution can be achieved by making minor changes to a model’s tokenizer.json file, which is used to map token IDs to words and characters creating an alphabet the model uses to generate its outputs.
Mitigation
With the number of such supply chain attacks increasing, having checks in place for model provenance becomes very important for organizations experimenting with AI and machine learning.
Cisco’s AI research team has recently released an open source-tool called the Model Provenance Kit that uses fingerprints from model weights, tokenizers, and architecture metadata to determine whether a machine learning model derives from one of the 45-plus known base model families from more than 20 trusted publishers, including the leading AI labs.
That said, the Pluto Security researchers advise organizations to treat AI model loading and config deserialization APIs in ML frameworks and libraries as code execution surfaces, regardless of the safe flags they provide.
This means model loading should be sandboxed and isolated inside monitored containers that don’t have access to host credentials, outbound network access, and extensive filesystem permissions. Configuration files should also be scanned before loading and checked for unexpected fields, including those prefixed with underscore.
Transformers users should upgrade to version 5.3.0 immediately and should search for _attn_implementation_internal in any cached or downloaded config.json files to determine whether they’ve been targeted.
View the full article
A high severity vulnerability in Hugging Face Transformers enables attackers to compromise systems that use the popular Python library to test and run AI models. The flaw impacts library versions that continue to be actively downloaded and comes at a time when attackers are increasingly targeting the AI supply chain, including through malicious models hosted on the Hugging Face platform.
The exploit for this vulnerability involves adding an innocuous-looking parameter called _attn_implementation_internal to remote model configuration files on Hugging Face and bypasses the trust_remote_code=false flag that normally prevents the execution of remote code accompanying models.
“The malicious field uses an underscore-prefixed name that looks like an internal implementation detail — the kind of field that config files are full of,” researchers from Pluto Security who found the vulnerability said in their report. “There are no runtime warnings, no consent prompts, no unusual log entries.”
The Hugging Face Transformers library allows Python developers to deploy over 1 million machine learning model variants hosted on Hugging Face on their local hardware or cloud instances. It is used in many enterprise environments and CI/CD pipelines to test models pre-trained for various tasks and to fine-tune them with proprietary data.
The Hugging Face Transformers PyPI package is downloaded over 146 million times per month and has a total of 2.2 billion installs to date. The project is also one of the highest-rated repositories on GitHub with 161K+ stars, so the blast radius of a remote code execution (RCE) vulnerability is huge.
This previously undisclosed flaw, now tracked as CVE-2026-4372, was silently patched in Transformers 5.3.0, which was released on March 3, but it impacts all versions released since August starting with 4.56.0. Vulnerable versions continue to be downloaded 7 to 8 million times per week and account for around a fourth of weekly installations.
Custom ‘attention’ kernels bypass RCE defenses
AI models hosted on Hugging Face can contain custom Python code, which can present a serious security risk if downloaded and executed alongside the model automatically. In the past this capability has been abused by attackers, which is why a parameter called trust_remote_code: was added to configurations. When set to false, it is meant to give developers an assurance that additional code will not be automatically executed.
However, in March last year, Hugging Face added a feature called Hub Kernels that allows users to host custom compiled attention kernels. These kernels improve the performance of models when loaded on GPUs and require an additional package called kernels.
The presence of this package on the machine is required to exploit this vulnerability, which is a limiting factor at first glance. However, even though it’s an optional dependency, having the kernels package installed is not uncommon, especially because most users who run local AI models want to benefit from GPU acceleration and will install Transformers with all “extras” packages.
“Users who work with GPU-accelerated inference — arguably the most valuable targets — are the most likely to have it installed,” the researchers said. “Enterprise ML platforms and GPU clusters commonly install all optional dependencies to maximize hardware utilization.”
The vulnerability is the result of three separate design decisions made in the code that combine to introduce the silent RCE risk. First, when the model loading is invoked with AutoModelForCausalLM.from_pretrained(“model-name”) the library proceeds to download the model’s configuration, weights, and tokenizer from the Hub, assemble the correct architecture, and return a ready-to-use model to the application.
The code that parses the model’s config.json file uses a function called setattr that parses every key-value pair in the file and loads it into the config object, but does not differentiate between user-configurable parameters and internal parameters that start with the _ character. Such internal parameters should never be present in a user-supplied config because they are not meant to be touched by developers.
One of those internal parameters is _attn_implementation_internal, which is used to control which attention mechanism implementation the model uses: Flash Attention, SDPA, or the default eager implementation.
Furthermore, the hub_kernels.py component checks for the value of this parameter and if it’s set to a pattern that matches two strings separated by / it assumes this is an owner/repository definition from the Kernels Hub. The code then proceeds to download the kernel from the defined repository and execute it.
“No sandboxing. No code signing. No integrity verification. No user prompt,” the researchers said. “Just a raw import of whatever Python code lives in the attacker’s repository — including anything in __init__.py, which executes automatically on import.”
As a result of these three independent issues — the unfiltered setattr, the unprotected internal attribute, and the unsandboxed kernel loader — exploitation becomes trivial: Publish an attractive model with a configuration that includes _attn_implementation_internal set to attacker-repo/malicious-kernel.
Supply chain attacks via malicious AI models are increasing
This is not an unusual attack. Malicious models get uploaded to Hugging Face all the time and they can be quite successful in tricking users. Last month, a malicious Hugging Face repo posing as a new release of OpenAI’s Privacy Filter model reached the No. 1 trending spot on the platform within 18 hours and was downloaded 244,000 times. The model code contained infostealer malware for Windows.
Last year, researchers showed how attackers can hide malicious code inside Python Pickle files, a format that is commonly used to distribute AI models.
This Transformers vulnerability is not the first that enables remote code execution through maliciously crafted AI models. Last month researchers from security firm HiddenLayer disclosed a RCE vulnerability in ChromaDB that allowed unauthenticated remote attackers to trick Chroma servers into executing malicious code from model configurations hosted on Hugging Face.
Earlier that same month, the same researchers showed how remote code execution can be achieved by making minor changes to a model’s tokenizer.json file, which is used to map token IDs to words and characters creating an alphabet the model uses to generate its outputs.
Mitigation
With the number of such supply chain attacks increasing, having checks in place for model provenance becomes very important for organizations experimenting with AI and machine learning.
Cisco’s AI research team has recently released an open source-tool called the Model Provenance Kit that uses fingerprints from model weights, tokenizers, and architecture metadata to determine whether a machine learning model derives from one of the 45-plus known base model families from more than 20 trusted publishers, including the leading AI labs.
That said, the Pluto Security researchers advise organizations to treat AI model loading and config deserialization APIs in ML frameworks and libraries as code execution surfaces, regardless of the safe flags they provide.
This means model loading should be sandboxed and isolated inside monitored containers that don’t have access to host credentials, outbound network access, and extensive filesystem permissions. Configuration files should also be scanned before loading and checked for unexpected fields, including those prefixed with underscore.
Transformers users should upgrade to version 5.3.0 immediately and should search for _attn_implementation_internal in any cached or downloaded config.json files to determine whether they’ve been targeted.
View the full article
Apple has published a new ad to appeal to customers who prioritize privacy when browsing, suggesting that Safari is the one you should use if you want to "Keep data trackers off your back."


In a new Privacy on iPhone segment titled "Safari helps block data trackers," the ad shows users of rival phones in everyday situations having to live with data trackers as they browse. The trackers are depicted as people in chrome-colored suits (get it?) who generally follow them around wherever they go to look at their screen – and in some cases literally sit on their shoulders to get a better view.

Apple on its website calls privacy a "fundamental human right," and highlights several features that Chrome doesn't come with out of the box. Safari blocks third-party cookies by default, uses machine learning to combat tracking, removes tracking parameters from URLs in Private Browsing, hides your IP address from known trackers, prevents web extensions from accessing your browsing activity by default, and blocks known trackers in Private Browsing.Tags: Apple Ads, Apple Privacy
This article, "Apple's New Ad Pitches Safari as a More Private Alternative to Chrome" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Apple's upcoming iPhone 18 Pro Max will be the same thickness as its predecessor, measuring in at 8.75mm. The latest information comes from Weibo-based leaker Ice Universe.


The leaker suggested that the lack of evolution in Apple's Pro lineup this year is because most of the company's development focus has been on the "iPhone Ultra," its rumored foldable model.

The latest claim comes as somewhat of a surprise, given that the same leaker in March said the device would be slightly thicker than the iPhone 17 Pro Max. That chimed with a report last year alleging hardware changes in the iPhone 18 Pro Max will make it the heaviest iPhone yet.

Last November, fellow Weibo-based leaker Instant Digital said the iPhone 18 Pro Max will be slightly heavier than its predecessor, tipping its weight over 240 grams and making it the heaviest iPhone since the iPhone 14 Pro Max.

Of course, if the new model does turn out to have the same thickness, this doesn't necessarily mean its weight won't change either. The device's heaviness could still be impacted by internal hardware changes.

Digital Chat Station – another Weibo-based leaker – has claimed the iPhone 18 Pro Max will feature a bigger battery, with a capacity in the range of 5,100 to 5,200 mAh (up from 5,088 mAh in the eSim version of the iPhone 17 Pro Max).

If so, Apple may have reconfigured the internal design or miniaturized aspects of it in order to accommodate the larger battery without altering the device's thickness. Apple isn't expected to change the screen size of the iPhone 18 Pro Max, and it will feature the same 6.9-inch display as the current model.

The ‌‌iPhone 18‌‌ Pro and iPhone 18‌‌ Pro Max may feature a possibly smaller Dynamic Island, along with a next-generation C2 modem, a simplified Camera Control, and an upgraded main camera with a variable aperture. The devices are expected to be unveiled around mid-September alongside the foldable iPhone.Related Roundup: iPhone 18 ProTag: Ice Universe
This article, "iPhone 18 Pro Max Device Thickness Allegedly Revealed" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Cybersecurity researchers have flagged a large-scale operation that impersonates open-source and freeware projects to funnel unsuspecting users through a Traffic Distribution System (TDS) and deliver malware families like Remus Stealer, AnimateClipper, and the SessionGate framework. "The sites are well-designed and often look like legitimate project portals at a glance, sometimes referencingView the full article
Unknown attackers spent at least five months inside the Outlook mailbox of a senior executive at a major global stock exchange, copying the inbox out in small, repeated batches and routing it through Dropbox and OneDrive so the traffic blended into normal cloud activity. Symantec and Carbon Black's Threat Hunter Team reported the campaign this week. This points to espionage, not a money grab:View the full article
Apple will rely on Google's fleet of Nvidia chips to power its overhauled version of Siri when it launches in September, according to a new report from The Information.


Last week, the outlet reported that Apple plans to highlight the on-device AI capabilities of its devices at WWDC next week, but queries that require cloud-based processing will still fall back on one of Google's large Gemini models, as per an agreement between the two companies.

Today's report adds some specificity to the planned cloud setup by revealing that Apple will tap into Google's fleet of Nvidia Blackwell B200 data center chips, where user data will be encrypted using Nvidia's hardware-based confidential compute feature. Introduced in 2024 as the successor to Hopper, Blackwell chips are designed primarily for large language models, and can dramatically speed up AI training and inference compared to the previous generation.

The report notes that the arrangement diverges from Apple's usual strategy of "attempting to control all the critical ingredients to its products." It also adds that it's unclear how Apple's previously launched server system, called Private Cloud Compute, will fit into the upcoming Siri launch.

Private Cloud Compute runs on Apple's Mac-series chips and was announced two years ago as a way to offer cloud-based computing in a more private and secure fashion. Apple reportedly tried to get a modified version of Gemini working on its in-house server system, but found that it ran too slowly. The publication's previous report said Apple will likely retain the Private Cloud Compute branding despite the change.
Siri in iOS 27: Every New Feature and Change to Expect
Apple Intelligence was unveiled at WWDC 2024, but its rollout has been overshadowed by a lukewarm reception to its initial features and ongoing delays to the more personalized version of Siri. WWDC 2026 begins on June 8, when Apple is expected to reset the narrative by revisiting those delayed features and introducing new AI capabilities.Tags: Apple Intelligence, Google, Nvidia, Siri, The Information
This article, "Apple's Overhauled Siri Will Reportedly Run on Nvidia's Blackwell Chips" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added a critical flaw impacting Mirasvit Cache Warmer, a popular Magento full-page cache extension, to its Known Exploited Vulnerabilities (KEV) catalog, following reports of active exploitation in the wild. The vulnerability, tracked as CVE-2026-45247 (CVSS score: 9.8), is a case of deserialization of untrustedView the full article
LONDON — Enterprise security teams were urged by security experts at Infosecurity Europe to brace for impact as both Anthrophic and OpenAI expand access to their frontier AI models for vulnerability discovery.
Anthropic, in particular, is significantly expanding Project Glasswing, its scheme to provide select organizations with access to Claude Mythos, an AI-powered vulnerability discovery tool that many industry observers and practitioners believe signals a structural shift for cybersecurity.
After initially granting access to around 50 organizations in April, Anthropic is now adding roughly 150 more vetted partners to its program.
In a parallel development, OpenAI reportedly has offered nine major UK banks access to its cybersecurity AI tool, GPT-5.5 Cyber.
Prepare for the son of Mythos
Speaking at Infosecurity Europe, Gunter Ollmann, CTO at penetration testing and security services firm Cobalt, said frontier AI models from Google and two from China are not far behind in their capabilities.
“Security teams should prepare for the son of Mythos,” said Ollmann. “These frontier AI tools are still restricted in their access, but they are only going to get cheaper as we go along.”
Paul Chichester, director of operations at the UK’s National Cyber Security Centre (NCSC), backed up this assessment by citing estimates that China was eight months behind. Misuse of frontier AI models represents a threat while also offering defenders the opportunity to push additional costs onto adversaries, Chichester told Infosec Europe delegates.
“Organisations can use AI to write better code and look for vulnerabilities,” said Chichester, who added that frontier AI tools have the potential to democratise security assessments and penetration testing.
Organisations should improve cybersecurity by hardening access controls and running incident response exercises, Chichester advised.
Daniel Wilcock, threat intelligence analyst at managed security services firm Talion, warned that organisations that fail to explore advanced AI risk falling behind those that are using the technology to accelerate vulnerability discovery and security operations.
“Advanced AI platforms are already being used by malicious threat actors, and all organisations must be prepared for this,” Wilcock warned.
Exploit chains
Ollmann told CSO that AI is far from replacing security experts such as penetration testers.
“The combination of AI-driven analysis and human expertise is proving far more effective than either operating alone,” Ollmann said. “The organizations that benefit most from these advances will be the ones that can rapidly validate, prioritize, and remediate the issues being discovered before attackers find them first.”
Ollmann added: “Mythos appears to be operating with a level of software access and analysis flexibility that most commercial security researchers and testing platforms don’t typically have, including the ability to examine code and behaviours that may otherwise be restricted by licensing or terms of service. That creates a unique opportunity to identify classes of vulnerabilities that conventional testing approaches often miss.”
For example, Mythos makes it easier to chain together several medium severity vulnerabilities to create a high impact risk.
The topic of AI flaw-chaining was also central to a panel on Mythos at the recent CSO Cybersecurity Awards and Conference in the US.
“When we’re doing threat modeling, we have some sense that these are the known vulnerabilities that we are modeling against and here’s where we think we are weak, and that kind of goes away with chaining multiple vulnerabilities,” Jim Reavis, CEO and co-founder of Cloud Security Alliance (CSA) told attendees. “CVSS scoring, it seems like that’s not super relevant anymore.”
Jon Yeoh, chief scientific officer at CSA, agreed, touching on the “son of Mythos” threat as well.
“It’s not just about Anthropic. It’s about what these next-generation AI will be doing,” he said. “This is a major step change in what AI can do.”
View the full article
Enterprise security teams were urged by security experts at Infosecurity Europe to brace for impact as both Anthrophic and OpenAI expand access to their frontier AI models for vulnerability discovery.
Anthropic, in particular, is significantly expanding Project Glasswing, its scheme to provide select organizations with access to Claude Mythos, an AI-powered vulnerability discovery tool that many industry observers and practitioners believe signals a structural shift for cybersecurity.
After initially granting access to around 50 organizations in April, Anthropic is now adding roughly 150 more vetted partners to its program.
In a parallel development, OpenAI reportedly has offered nine major UK banks access to its cybersecurity AI tool, GPT-5.5 Cyber.
Prepare for the son of Mythos
Speaking at Infosecurity Europe, Gunter Ollmann, CTO at penetration testing and security services firm Cobalt, said frontier AI models from Google and two from China are not far behind in their capabilities.
“Security teams should prepare for the son of Mythos,” said Ollmann. “These frontier AI tools are still restricted in their access, but they are only going to get cheaper as we go along.”
Paul Chichester, director of operations at the UK’s National Cyber Security Centre (NCSC), backed up this assessment by citing estimates that China was eight months behind. Misuse of frontier AI models represents a threat while also offering defenders the opportunity to push additional costs onto adversaries, Chichester told Infosec Europe delegates.
“Organisations can use AI to write better code and look for vulnerabilities,” said Chichester, who added that frontier AI tools have the potential to democratise security assessments and penetration testing.
Organisations should improve cybersecurity by hardening access controls and running incident response exercises, Chichester advised.
Daniel Wilcock, threat intelligence analyst at managed security services firm Talion, warned that organisations that fail to explore advanced AI risk falling behind those that are using the technology to accelerate vulnerability discovery and security operations.
“Advanced AI platforms are already being used by malicious threat actors, and all organisations must be prepared for this,” Wilcock warned.
Exploit chains
Ollmann told CSO that AI is far from replacing security experts such as penetration testers.
“The combination of AI-driven analysis and human expertise is proving far more effective than either operating alone,” Ollmann said. “The organizations that benefit most from these advances will be the ones that can rapidly validate, prioritize, and remediate the issues being discovered before attackers find them first.”
Ollmann added: “Mythos appears to be operating with a level of software access and analysis flexibility that most commercial security researchers and testing platforms don’t typically have, including the ability to examine code and behaviours that may otherwise be restricted by licensing or terms of service. That creates a unique opportunity to identify classes of vulnerabilities that conventional testing approaches often miss.”
For example, Mythos makes it easier to chain together several medium severity vulnerabilities to create a high impact risk.
The topic of AI flaw-chaining was also central to a panel on Mythos at the recent CSO Cybersecurity Awards and Conference in the US.
“When we’re doing threat modeling, we have some sense that these are the known vulnerabilities that we are modeling against and here’s where we think we are weak, and that kind of goes away with chaining multiple vulnerabilities,” Jim Reavis, CEO and co-founder of Cloud Security Alliance (CSA) told attendees. “CVSS scoring, it seems like that’s not super relevant anymore.”
Jon Yeoh, chief scientific officer at CSA, agreed, touching on the “son of Mythos” threat as well.
“It’s not just about Anthropic. It’s about what these next-generation AI will be doing,” he said. “This is a major step change in what AI can do.”
View the full article
The U.S. Department of Justice (DoJ) on Wednesday announced the results of a sweeping action undertaken by government authorities and private sector companies to combat cyber-enabled and cryptocurrency fraud targeting Americans. The "Disruption Week" operation began May 18, 2026, leading to the takedown of millions of social media, email, and internet access accounts used by transnationalView the full article
Introduction
DevOps is no longer just a trend or a buzzword; it is the backbone of modern software delivery. Whether you are a developer looking to bridge the gap between code and operations, or a system administrator wanting to modernize your skillset, the demand for competent DevOps engineers remains at an all-time high. Yet, the path to becoming one is often obscured by an overwhelming array of tools, cloud platforms, and methodologies.
If you have tried searching for a learning path, you have likely encountered a wall of information that makes you question where to start. Is it Docker? Is it AWS? Is it coding? This confusion is common because the ecosystem moves fast. The secret to success is not to learn every tool, but to learn the foundational principles that allow you to adapt to any tool.
To navigate this successfully, you need a structured path that respects your time and builds your confidence. Platforms like DevOpsSchool provide the hands-on exposure and clear guidance required to navigate these complexities. This roadmap is designed to strip away the noise and focus on what truly matters for your career growth.
Why DevOps Learning Feels Confusing
The primary reason learners feel overwhelmed is the sheer volume of technologies marketed as “essential.” a beginner might see a job description asking for Kubernetes, Terraform, AWS, Azure, Python, Go, Ansible, and Jenkins all at once.
This is a classic trap. You see an advanced job description and assume you must learn it all to get started. The reality is that organizations use a subset of these tools. The confusion stems from:
Tool Fatigue: You see a new tool released every week and feel pressure to learn it. The “Jack-of-all-Trades” Myth: The misconception that a DevOps engineer is a master of networking, coding, security, and cloud architecture on day one. Cloud Complexity: The shift toward multi-cloud and serverless architectures has made the learning curve steeper than it was a few years ago. You do not need to master the entire ecosystem. You need to master the concepts of automation, version control, and infrastructure. Tools change; principles do not.
What Skills Matter Most in DevOps
To thrive, you must focus on core competencies. While specific tools change, the categories remain consistent.
Skill CategoryWhy It MattersLinuxNearly all servers and container runtimes operate on Linux. It is the foundation.NetworkingUnderstanding IP, DNS, and HTTP is critical for troubleshooting application connectivity.GitIt is the universal language of collaboration and code versioning.CI/CDThis represents the core “DevOps” philosophy of continuous integration and deployment.ContainersDocker and containerization are the standard for packaging applications.CloudAWS, Azure, or GCP are the environments where software lives.MonitoringYou cannot fix what you cannot measure; observability is vital.SecuritySecurity is no longer an afterthought; it is integrated into the pipeline (DevSecOps).AutomationIf you do it twice, automate it. This is the heart of the role. Overview Table: DevOps Learning Roadmap
Follow this sequence to ensure you are building a house on a strong foundation, not on shifting sand.
StageLearning GoalStage 1Master Linux FundamentalsStage 2Understand Networking BasicsStage 3Learn Git and Version ControlStage 4Learn Scripting (Bash or Python)Stage 5Understand CI/CD FundamentalsStage 6Learn Docker ContainersStage 7Master Cloud Platform Basics (AWS/Azure/GCP)Stage 8Learn Kubernetes OrchestrationStage 9Learn Monitoring and ObservabilityStage 10Build Real-World Projects Stage #1: Learn Linux Fundamentals
If you skip Linux, you are building a house without a foundation. You do not need to be a kernel developer, but you must be comfortable in the terminal.
What to focus on:
File system hierarchy and permissions. Basic command-line utilities (ls, grep, cat, chmod, chown). Process management (ps, top, kill). Package management (apt, yum/dnf). User and group management. Beginner Scenario: Do not just read. Install a Linux distribution on your laptop or a virtual machine and force yourself to perform tasks—like managing users or installing a web server—entirely through the command line.
Stage #2: Learn Networking Basics
Most DevOps issues are actually networking issues in disguise. If your application cannot talk to the database, you need to understand why.
What to focus on:
IP Addresses and Subnets: How devices communicate. DNS: How domain names map to IP addresses. Ports and Protocols: Understanding TCP/UDP, and common ports (80, 443, 22). HTTP/HTTPS: How web traffic works. Analogy: Think of an IP address as a house address and a Port as the specific room in that house. If you send a package (data) to the right house but the wrong room, it will never be delivered.
Stage #3: Learn Git and Version Control
DevOps is about collaboration. Git is how teams manage changes to infrastructure and application code.
What to focus on:
Basic commands: init, clone, add, commit, push, pull. Branching strategies: Understanding how to create and merge branches. Handling conflicts: Learning how to resolve code disagreements. Advice: Stop using email to share code. Create a profile on a platform like GitHub or GitLab and start pushing your configuration files there.
Stage #4: Learn Scripting Basics
Automation is the defining characteristic of DevOps. You cannot automate without scripting.
What to focus on:
Bash Scripting: Essential for automating Linux tasks. Python: The industry standard for automation, tooling, and cloud interaction. Advice: Start small. Write a script to back up a folder or clean up old log files. Do not try to write massive applications. Start with simple tasks that solve your own problems.
Stage #5: Learn CI/CD Fundamentals
Continuous Integration and Continuous Deployment (CI/CD) is the “conveyor belt” of software. It takes code from a developer’s laptop to a production server automatically.
What to focus on:
The concept of a pipeline: Code -> Build -> Test -> Deploy. Basic tools: Jenkins, GitHub Actions, or GitLab CI. Real-world example: Manually copying files to a server via FTP is risky. A CI/CD pipeline ensures that every time you save your code, it is tested and deployed consistently, reducing human error.
Stage #6: Learn Docker
Containers solved the “it works on my machine” problem. They allow you to package an application with all its dependencies.
What to focus on:
Dockerfiles: How to build images. Docker Compose: How to run multi-container applications (like a web server and a database). Container lifecycle: Running, stopping, and inspecting containers. Practical tip: Dockerize a simple static website or a Python application. Understand how the container isolates the environment from the host system.
Stage #7: Learn Cloud Basics
The cloud is the playground for DevOps. Pick one provider—AWS, Azure, or GCP—and learn the fundamentals.
What to focus on:
Compute (EC2/Virtual Machines). Storage (S3/Blob Storage). Networking (VPC, Security Groups). Identity and Access Management (IAM). Advice: Do not try to learn all three cloud providers at once. Pick one. The concepts are transferable. If you learn AWS, picking up Azure later is much easier.
Stage #8: Learn Kubernetes Basics
Once you have many containers, you need a manager. That is Kubernetes (K8s).
What to focus on:
Nodes and Pods. Deployments and Services. Basic kubectl commands. The concept of scaling applications. Warning: Do not start here. If you jump into Kubernetes before understanding containers and networking, you will feel lost. Kubernetes is complex; respect the learning curve.
Stage #9: Learn Monitoring & Reliability
You must know if your system is healthy. This is the domain of Site Reliability Engineering (SRE).
What to focus on:
Logging: Collecting logs to understand what happened. Metrics: Tracking CPU, memory, and latency. Alerting: Notifying the team when something breaks. Tools: Prometheus and Grafana are excellent starting points.
Stage #10: Build Real Projects
You cannot learn DevOps just by watching videos. You must build.
Project Ideas:
The CI/CD Pipeline: Build a pipeline that automatically deploys a simple website to a cloud server whenever you push to GitHub. Docker Deployment: Containerize an existing application and run it locally. Monitoring Dashboard: Set up a dashboard that monitors the health of your Docker containers. Real-World Example: Beginner Learning Randomly
Consider “Alex.” Alex starts by trying to learn Kubernetes on day one because they heard it pays well. They spend weeks struggling with installation errors, networking concepts they do not understand, and complex configurations. They burn out, feel discouraged, and quit because they tried to build the roof before laying the foundation.
Real-World Example: Structured DevOps Learner
Consider “Sam.” Sam follows a roadmap. They spend two weeks mastering Linux, two weeks on networking, and then move to Git. By the time Sam reaches Kubernetes, they understand what a process is, how ports work, and how code moves. When they encounter an error in Kubernetes, they have the troubleshooting skills to solve it. Sam gets hired because they can explain why something works, not just how to run a command.
Common Mistakes Beginners Make
Skipping Linux: It remains the most critical skill. Tool Obsession: Focusing on memorizing tool commands rather than understanding the underlying architecture. Lack of Hands-on Practice: Watching tutorials without doing the labs. Learning Kubernetes Too Early: Jumping into orchestration before understanding containers. Ignoring the “Ops” side: Focusing too much on the Dev side and neglecting system administration basics. Best Practices for Learning DevOps
Consistency over Intensity: 30 minutes every day is better than a 10-hour binge once a week. Focus on Fundamentals: Protocols, operating systems, and networking concepts stay relevant forever; specific tool versions change annually. Document Your Journey: Write down what you learn. It helps retention and helps you during interviews. Practice Daily: Set up a local lab environment. Use Structured Resources: Find a path, such as the one offered by DevOpsSchool, to keep you on track. Role of DevOpsSchool in Structured Learning
The journey to becoming a DevOps engineer is long, and having a guide is beneficial. DevOpsSchool provides resources that bridge the gap between theoretical knowledge and practical execution. By focusing on hands-on labs and real-world scenarios, they help learners avoid the pitfalls of “tutorial hell.” Whether you need to master CI/CD pipelines or get comfortable with cloud architecture, structured mentorship ensures you are not just learning tools, but learning how to think like a DevOps engineer.
Career Opportunities After Learning DevOps
Once you have mastered the roadmap, the career opportunities are diverse:
Junior DevOps Engineer: Focusing on pipeline maintenance and cloud infrastructure. Cloud Engineer: Specializing in cloud architecture and resource optimization. SRE (Site Reliability Engineer): Focusing on uptime, performance, and automation. Platform Engineer: Building internal tools and platforms for developers. DevSecOps Engineer: Specializing in security within the DevOps lifecycle. The market values professionals who can solve problems, not just those who can type commands.
Industries Hiring DevOps Talent
SaaS Platforms: Companies building software require constant deployment cycles. Banking & Finance: High demand for secure, automated, and reliable infrastructure. Healthcare: Systems must be compliant, secure, and always available. E-Commerce: Scalability is essential for handling traffic spikes. Telecom: Managing massive, distributed networks requires deep automation skills. Future of DevOps Learning
we are seeing the rise of AI-assisted operations. You will use AI to help write scripts or debug logs, but the human understanding of why the system is failing will be more important than ever. Platform Engineering is also becoming central, where DevOps engineers build platforms that abstract away complexity for developers. Staying relevant means keeping an open mind to these shifts while keeping your core skills sharp.
FAQs (15 Questions)
How do I start learning DevOps ? Start with Linux and networking. Do not rush. What should I learn first? Linux is the absolute baseline. Is Linux mandatory? Yes, it is the environment where 90% of DevOps work happens. Do I need coding? You need scripting (Bash/Python). You do not need to be a software developer. Is Kubernetes required? Eventually, yes. But learn containers (Docker) first. How long does DevOps take to learn? It varies, but expect 6–12 months of consistent study to become job-ready. Can freshers learn DevOps? Yes, but focus on fundamentals rather than advanced tools. Should I learn cloud first? Learn the basics of Linux and networking before diving into cloud-specific services. Which cloud provider is best? AWS is the most popular, but Azure and GCP are excellent. Pick one. Do I need to know networking? Absolutely. Networking is the language of cloud infrastructure. How do I practice without a budget? Use free tiers on cloud providers or run virtual machines locally. Is DevOps dying? No, it is evolving into SRE and Platform Engineering. Do I need a degree? Not strictly, but strong technical fundamentals are non-negotiable. How do I keep up with changes? Read technical blogs and practice new tools in small, isolated labs. Is it better to learn one tool or many? Learn one tool well (e.g., Jenkins) to understand the concept, then transfer that knowledge to others. Final Thoughts
DevOps is a journey, not a race. There is no shortcut to experience. Focus on understanding the “why” behind every command you type. The most successful engineers are not the ones who know every tool, but the ones who can look at a broken system, identify the bottleneck, and automate a solution. Build your foundation, practice daily, and stay curious. Consistency is your greatest asset.
View the full article
A vulnerability in GitHub’s browser-based VSCode editor could lead to the theft of a developer’s token under certain circumstances, says a researcher.
The issue, revealed this week in a blog by Ammar Askar, has apparently been already addressed by GitHub owner Microsoft. But it raises a questions about both DevOps security, and about the researcher’s allegation that, because Microsoft doesn’t treat bug discoveries seriously, he can justify giving it short notice before openly publishing vulnerabilities he finds.
First, the bug: Users of github.com may not realize it, but when they are on any repository, they can shift to github.dev and its browser-based version of VSCode just by changing the URL.
Why do this? Because the browser instance of VSCode is pretty powerful, Askar says in his blog. “You can view all the files in the repo (even if it’s a private one), you can send out pull requests, and even make commits.”
Rob Enderle, a IT consultant who heads the Enderle Group, agrees that jumping into VSCode this way is “an incredibly useful tactical tool for quick tasks. By just hitting the ‘.’ key in any GitHub repo, you instantly get a browser-based VS Code interface without having to clone gigabytes of data locally. It’s perfect for rapid PR reviews, quick documentation edits, or navigating code on the fly without breaking your workflow. Just keep in mind that it runs entirely in the browser sandbox; there’s no compute backend, no terminal, and no code execution.”
For any heavy lifting or actual compiling, he added, the developer will still need the raw compute of a local workstation, or a full cloud environment like Codespaces.
The problem, Askar says, is that this functionality is achieved by github.com POSTing over an OAuth token to github.dev that allows it to interact with GitHub on your behalf. “The token is not scoped to the particular repo you interacted with, meaning it has full access to every other repo that you have access to,” he wrote in the blog.
“The presence of this token, and the fact that this web app is running almost the entire brunt of VSCode’s million line Typescript codebase, makes it a great target for anyone looking into VSCode bugs,” he wrote.
The exploit
Askar said that a threat actor could install an extension in a repository using a Jupyter notebook, a web application for creating and sharing computational documents that has the ability to install a malicious local workspace extension while skipping the publisher trust check. In his proof of concept, Askar said that once his payload runs, the newly installed extension will grab the GitHub API token, run a query to get the private repos the developer has access to, and then print out the replies and the token.
This vulnerability also exists in the desktop version of VSCode, Askar said, though it’s harder to exploit, since a threat actor would need to convince the victim to clone their repo and open the notebook containing the webview script payload. “Of course,” he added, “if you [the hacker] had some other XSS [cross-site scripting attack] in a webview that you can get a victim to open, you get effectively full RCE [remote code execution] on their computer.”
In an email, he said this vulnerability was “about as serious as it gets. Any website on the internet could have redirected you to a github.dev link that could have provided an attacker a token to read and modify your code repos. If one could convince the maintainer of a popular software project to click a link, they could have made whatever modifications they wanted to their project.”
This means, said Enderle, “we have to start treating developer endpoints with strict, isolated, zero-trust parameters, because we clearly cannot rely on vendor complacency to protect us.”
This issue reinforces the point that you should never follow any links unless you know exactly where they will take you, added Dwayne McDaniel, principal developer advocate at GitGuardian.
Short notice
Here’s where things get complicated. Because of an unhappy experience when disclosing a previous VSCode vulnerability to Microsoft — the bug was fixed, but Askar wasn’t given credit — this time he only gave GitHub one hour notice that this new discovery was going to be published. Microsoft applied what Askar calls a “stopgap” fix by adding a confirmation when a developer opens notebooks in web VSCode, and by not allowing the trusted publisher requirement to be skipped by commands.
[Related content: When responsible disclosure becomes unpaid labor]
An ethical question
Askar’s short notice raises an ethical question: How far in advance should a responsible researcher give notice to a vendor about a vulnerability before publicly revealing it?
These days, most infosec pros agree that notice must be given, or else a threat actor can quickly exploit a hole. Not only that, but the researcher risks damage to their reputation if reasonable notice isn’t given. Experienced researchers often give vendors at least 30 days to create and distribute a patch.
For their part, vendors often create bug bounty programs, or partner with bug bounty programs, to reward researchers for their work. Unfortunately, some vendors don’t always credit researchers, or downplay the damage a vulnerability can cause. In fact, last month Microsoft and a prominent cybersecurity researcher got into a public spat about one such alleged incident.
An imbalance of power
Asked for comment about Askar’s most recent discovery, a Microsoft spokesperson said, “we value the critical role that the security research community plays in strengthening the security of our products, services, and the broader technology ecosystem. While independent researchers determine when and how to publish their findings, we remain committed to rapidly assessing reported issues, mobilizing the appropriate engineering and security response resources, and delivering mitigations, guidance, and protections as quickly as possible to help safeguard our customers.”
[Related content: Is the vulnerability disclosure process glitched?]
There is a balance between coordinating disclosure with a software vendor (CVD) and full disclosure, Askar told us. But, he added, there’s an imbalance of power. “A security researcher can pour countless hours into an issue, ensuring they develop a good proof of concept and provide all the steps to recreate the issue. With this, they hope to at least get an acknowledgement for their efforts, which they can use to further their security track record or, in the best case, a monetary bounty reward.”
However, he added, “If security vendors don’t adhere to their side of the bargain, public disclosure is one of the few options security researchers have (if they don’t want to sit on their vulnerabilities or sell them on the black market). It forces the vendor to acknowledge the security issue publicly and usually leads to a much faster resolution than any private communication would.”
This, said Enderle, creates problems for enterprises: “When vendor bureaucracy penalizes responsible disclosure, it alienates the security community and forces public zero-day drops, ultimately leaving enterprise customers holding the bag.”
This article originally appeared on InfoWorld.
View the full article
A vulnerability in GitHub’s browser-based VSCode editor could lead to the theft of a developer’s token under certain circumstances, says a researcher.
The issue, revealed this week in a blog by Ammar Askar, has apparently been already addressed by GitHub owner Microsoft. But it raises a questions about both DevOps security, and about the researcher’s allegation that, because Microsoft doesn’t treat bug discoveries seriously, he can justify giving it short notice before openly publishing vulnerabilities he finds.
First, the bug: Users of github.com may not realize it, but when they are on any repository, they can shift to github.dev and its browser-based version of VSCode just by changing the URL.
Why do this? Because the browser instance of VSCode is pretty powerful, Askar says in his blog. “You can view all the files in the repo (even if it’s a private one), you can send out pull requests, and even make commits.”
Rob Enderle, a IT consultant who heads the Enderle Group, agrees that jumping into VSCode this way is “an incredibly useful tactical tool for quick tasks. By just hitting the ‘.’ key in any GitHub repo, you instantly get a browser-based VS Code interface without having to clone gigabytes of data locally. It’s perfect for rapid PR reviews, quick documentation edits, or navigating code on the fly without breaking your workflow. Just keep in mind that it runs entirely in the browser sandbox; there’s no compute backend, no terminal, and no code execution.”
For any heavy lifting or actual compiling, he added, the developer will still need the raw compute of a local workstation, or a full cloud environment like Codespaces.
The problem, Askar says, is that this functionality is achieved by github.com POSTing over an OAuth token to github.dev that allows it to interact with GitHub on your behalf. “The token is not scoped to the particular repo you interacted with, meaning it has full access to every other repo that you have access to,” he wrote in the blog.
“The presence of this token, and the fact that this web app is running almost the entire brunt of VSCode’s million line Typescript codebase, makes it a great target for anyone looking into VSCode bugs,” he wrote.
The exploit
Askar said that a threat actor could install an extension in a repository using a Jupyter notebook, a web application for creating and sharing computational documents that has the ability to install a malicious local workspace extension while skipping the publisher trust check. In his proof of concept, Askar said that once his payload runs, the newly installed extension will grab the GitHub API token, run a query to get the private repos the developer has access to, and then print out the replies and the token.
This vulnerability also exists in the desktop version of VSCode, Askar said, though it’s harder to exploit, since a threat actor would need to convince the victim to clone their repo and open the notebook containing the webview script payload. “Of course,” he added, “if you [the hacker] had some other XSS [cross-site scripting attack] in a webview that you can get a victim to open, you get effectively full RCE [remote code execution] on their computer.”
In an email, he said this vulnerability was “about as serious as it gets. Any website on the internet could have redirected you to a github.dev link that could have provided an attacker a token to read and modify your code repos. If one could convince the maintainer of a popular software project to click a link, they could have made whatever modifications they wanted to their project.”
This means, said Enderle, “we have to start treating developer endpoints with strict, isolated, zero-trust parameters, because we clearly cannot rely on vendor complacency to protect us.”
This issue reinforces the point that you should never follow any links unless you know exactly where they will take you, added Dwayne McDaniel, principal developer advocate at GitGuardian.
Short notice
Here’s where things get complicated. Because of an unhappy experience when disclosing a previous VSCode vulnerability to Microsoft — the bug was fixed, but Askar wasn’t given credit — this time he only gave GitHub one hour notice that this new discovery was going to be published. Microsoft applied what Askar calls a “stopgap” fix by adding a confirmation when a developer opens notebooks in web VSCode, and by not allowing the trusted publisher requirement to be skipped by commands.
[Related content: When responsible disclosure becomes unpaid labor]
An ethical question
Askar’s short notice raises an ethical question: How far in advance should a responsible researcher give notice to a vendor about a vulnerability before publicly revealing it?
These days, most infosec pros agree that notice must be given, or else a threat actor can quickly exploit a hole. Not only that, but the researcher risks damage to their reputation if reasonable notice isn’t given. Experienced researchers often give vendors at least 30 days to create and distribute a patch.
For their part, vendors often create bug bounty programs, or partner with bug bounty programs, to reward researchers for their work. Unfortunately, some vendors don’t always credit researchers, or downplay the damage a vulnerability can cause. In fact, last month Microsoft and a prominent cybersecurity researcher got into a public spat about one such alleged incident.
An imbalance of power
Asked for comment about Askar’s most recent discovery, a Microsoft spokesperson said, “we value the critical role that the security research community plays in strengthening the security of our products, services, and the broader technology ecosystem. While independent researchers determine when and how to publish their findings, we remain committed to rapidly assessing reported issues, mobilizing the appropriate engineering and security response resources, and delivering mitigations, guidance, and protections as quickly as possible to help safeguard our customers.”
The spokesperson added that the issue Askar reported “has been mitigated for our services and no customer action is required.”
[Related content: Is the vulnerability disclosure process glitched?]
There is a balance between coordinating disclosure with a software vendor (CVD) and full disclosure, Askar told us. But, he added, there’s an imbalance of power. “A security researcher can pour countless hours into an issue, ensuring they develop a good proof of concept and provide all the steps to recreate the issue. With this, they hope to at least get an acknowledgement for their efforts, which they can use to further their security track record or, in the best case, a monetary bounty reward.”
However, he added, “If security vendors don’t adhere to their side of the bargain, public disclosure is one of the few options security researchers have (if they don’t want to sit on their vulnerabilities or sell them on the black market). It forces the vendor to acknowledge the security issue publicly and usually leads to a much faster resolution than any private communication would.”
This, said Enderle, creates problems for enterprises: “When vendor bureaucracy penalizes responsible disclosure, it alienates the security community and forces public zero-day drops, ultimately leaving enterprise customers holding the bag.”
This article originally appeared on InfoWorld.
View the full article
Cloud computing has reached a crossroads. The high cost and data sensitivity of AI workloads are raising the appeal of private clouds, even as neoclouds and sovereign clouds shake up the cloud provider landscape. New cyberthreats, shifting compute requirements, and management complexity are adding to cloud complications.
Download the June 2026 issue of the Enterprise Spotlight from the editors of CIO, Computerworld, CSO, InfoWorld, and Network World, and learn how to navigate the latest cloud strategy developments.
View the full article
Siri is getting a major overhaul in iOS 27, but Apple also has some big updates planned for apps like Camera, Photos, and Wallet. There are multiple new AI features in the works, plus some non-AI upgrades.


Camera

Apple is moving Visual Intelligence from the Camera Control button to the Camera app in ‌iOS 27‌. There will be a Siri mode that will be available alongside the existing Photo, Video, Portrait, and Panorama modes. When in ‌Siri‌ mode, the existing Camera app shutter button will feature the Apple Intelligence logo, letting users know the ‌Siri‌ features are available.

Image via Bloomberg
‌Siri‌ mode is a renaming of ‌Visual Intelligence‌, and it will make the feature more visible. Accessing ‌Visual Intelligence‌ in iOS 26 requires users to hold down the Camera Control button or assign the feature to the Action button, and many people may not even know it exists.

‌Visual Intelligence‌ can identify objects, plants, animals, art, books, and more, searching for whatever the user snaps on Google Image Search. In ‌iOS 27‌, ‌Siri‌ will be able to answer questions about what a user is looking at, providing information from the web.

Apple is adding new ‌Visual Intelligence‌ capabilities in ‌iOS 27‌, and they will be available through the Camera app ‌Siri‌ mode.

Nutrition - Users can scan nutrition labels on food packaging for calorie and macronutrient tracking using the Health app.
Contacts - ‌Visual Intelligence‌ will let users scan phone numbers and addresses on business cards and other print media, adding the information to the Contacts app.

Apple plans to make the Camera app more customizable in ‌iOS 27‌. iPhone users will be able to replace the top row of camera shortcuts with options of their choosing, selecting features like flash, exposure, timer, depth of field, photo styles, and resolution.

Camera controls, now labeled as widgets, can be placed at the top of the Camera interface in any order. Users can select widgets from a transparent widget tray that comes up from the bottom of the app and organizes widgets into categories like basic, manual, and settings.

The Camera app will have the same default layout that's available now with quick tap buttons for flash, Live Photos, and Night Mode, but the customizable widget interface will be added as an advanced layout that will appeal to professional users.

Image via Bloomberg
iPhone users can currently tap on an icon at the top right of the Camera app to access all of the Camera controls, but Apple is moving that view to the right of the shutter button in ‌iOS 27‌.

The Camera app is also going to get new grid and level options that will join the existing features.

Photos

The ‌Photos‌ app will have an Apple Intelligence Tools section when editing an image with new Extend and Reframe options.

Extend - Extend generates additional image content beyond the original frame of the photo, filling in scenery when changing the crop of an image. This tool will support expanding the edges of an image with zoom gestures.
Reframe - When used with spatial photos, Reframe will let users change the perspective of an image after it's captured.

Apple is also testing an AI photo editing feature that lets users request edits using natural language. Users would be able to tweak color, lighting, cropping, and other image parameters without having to use manual tools. The voice-based photo editing feature may not arrive in the first version of ‌iOS 27‌.
Shortcuts

The ‌iOS 27‌ Shortcuts app will support using natural language to create a shortcut with AI. Users will be able to tell ‌Siri‌ what they want to accomplish with a multi-step shortcut, and ‌Siri‌ will generate it.

The Shortcuts app will open with a prompt that says "What do you want your shortcut to do?" with a text field to enter a description. Shortcuts that are created using AI are then automatically installed and immediately available for use.

Wallet

The Wallet app is getting a "Create a Pass" option so users can generate digital passes from scans of physical items like movie tickets, concert passes, and gym membership cards.

Users can tap on the "+" button in the Wallet app and then scan a QR code on a pass or ticket if one is available. If there is no QR code available, there will be an option to create a custom pass.

There are three pass types in Create a Pass, each with a different color. Apple is using purple for events, blue for memberships, and orange for other types of passes. Users can customize images, colors, style, and text on the digital passes.

Apple is also adding an AI bill-splitting feature that will work with Apple Cash. iPhone users will be able to take a photo of a receipt and generate Apple Cash payment requests for different people.

Image Playground and Genmoji

Apple is updating the Image Playground app. The interface for generating a new image has fewer controls and a "describe a change" option for editing images that are created. Previously created images are displayed in a grid with more rounded edges, and instead of a New Image button, there's a "+" button.

Apple has also been testing new models that produce more lifelike images, so we could see new image generation capabilities in ‌iOS 27‌ with better image quality.

Genmoji is also getting an update so it will use fewer resources, causing less battery drain and fewer heat problems. ‌Genmoji‌ will be better quality with a new ‌Genmoji‌ model, and a Suggested ‌Genmoji‌ feature will bring up custom emoji ideas based on your media and text history.

Writing Tools

Apple is testing an expanded version of Writing Tools that will do more rewriting and text generation than the current version. There is a "Write with ‌Siri‌" toggle at the top of the keyboard, along with a "Help Me Write" option that comes up when ‌Siri‌ is activated while a text field is open.

Apple is going to add a dedicated AI grammar checker that will work alongside the current spell check. When writing in Messages, Mail, and other apps there will be a translucent menu that slides up from the bottom of the iPhone's screen, and it will show suggested revisions next to the original written text.

Users can go through the suggestions and accept or reject them one by one, approve all of the changes at once, or ignore the changes.

Other Features


Wallpaper - There will be an option to generate custom wallpapers with the ‌Image Playground‌ app, with the feature built into the interface for selecting a new wallpaper.
Safari - Safari will get an updated start page with four tabs for switching between favorites, bookmarks, Reading List, and history.
Calendar - Rumors suggest the Calendar app will incorporate new AI features. ‌Siri‌ will also be able to draw on information in the app.
Health - With a new calorie scanning feature coming to the Camera app, calorie tracking will be more prominent in the Health app. Apple was also planning a Health+ subscription service, and while that's been scaled back, there could be other AI health app changes.
Weather - The Weather app will have a new Conditions panel for switching between temperature, rain, and wind from the main interface, without the need to tap into a weather module.
AirPods settings - The AirPods interface in the Settings app will be simplified, with options featuring better organization. Major features like hearing health will be easier to find.
AirPlay Alternatives - Apple is adding a feature that will let users beam content to AirPlay alternatives like Google Cast. It could be limited to iPhone users in the EU because it is being implemented as a Digital Markets Act requirement.

System-Wide Design Changes

There are system-wide design changes coming in ‌iOS 27‌. The separate tab bar in apps like Apple Music, Podcasts, News, and Apple TV will be adjusted to combine search with the other navigation options. Apple separated search in many apps when introducing Liquid Glass, but it's reverting to the original look.

When using the on-screen keyboard, there's a new animation that shows the keys sliding up from the bottom of the iPhone interface, and Apple is adding redo and undo controls for easier customization of the Home Screen's icon and widget layouts.



Apple doesn't plan to make major changes to the Liquid Glass aesthetic in ‌iOS 27‌, but the company is mulling a system-wide setting that would precisely adjust the look of the interface. In iOS 26.2, Apple added a slider that lets users adjust the opacity of Liquid Glass for the Lock Screen's clock, and that setting could be expanded to the entire operating system.

Foldable iPhone Interface

The first foldable iPhone will be introduced in September. Rumors suggest that it will feature a 5.5-inch display when folded, and a 7.8-inch display when it's opened up like a book.



An iPhone with a larger display will require major updates to iOS, and ‌iOS 27‌ will focus on building new interfaces and experiences made for a larger smartphone display.

The iPhone Fold will operate like a cross between an iPhone and an iPad, but it will run iOS, not iPadOS, and it won't support ‌iPad‌ apps. When unfolded, the iPhone will have an iPad-like layout that supports multitasking with two apps side-by-side. Many of Apple's iPhone apps will have sidebars on the left of the display, with Apple providing developers with tools to easily adapt their apps to the new layout.

Apple is using a wider design for the ‌iPhone Fold‌ than most foldable smartphone makers have used, and it is rumored to have an iPad-like 4:3 aspect ratio. When the iPhone is closed, it will have a standard iPhone layout that looks like the version of iOS we have now.

Satellite Features

Apple is working on several new satellite features for the iPhone, and it's possible some features could be introduced as soon as 2027.

Apple Maps via satellite
‌Photos‌ in Messages via satellite
Satellite API framework for third-party apps
Satellite over 5G
Satellite connectivity without the need for a view of the sky

Performance and Stability

Bloomberg's Mark Gurman has described iOS 27 as a "Snow Leopard" update, suggesting that Apple will focus on improving underlying performance and quality.

Apple is prioritizing cleaning up the iOS code and removing anything that's outdated, which could mean upgrading apps to improve performance and rewriting some existing features to be more efficient. The code updates could provide a more responsive, faster version of iOS.

Apple is also aiming for efficiency improvements that could translate into tangible battery life gains.

Launch Date

Apple will preview the new iOS features at its WWDC 2026 keynote event on June 8. Developers will get access the same day, and a public beta will likely be available in July. ‌iOS 27‌ will launch in September alongside new iPhones.Related Roundup: iOS 27
This article, "iOS 27: All the Rumored App Features" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
We're just a handful of days away from Apple's 2026 Worldwide Developers Conference, which will see the introduction of iOS 27, iPadOS 27, macOS 27, and more.


We've heard plenty of rumors about ‌iOS 27‌ and it sounds like most of the new features will focus on Siri and AI, but we want to hear from readers. Are you looking forward to any of the new capabilities? Read our iOS 27 roundup to see what's in store.

What's at the top of your wishlist? Do you want updates to the Liquid Glass design? Multitasking options? More emoji?

MacRumors readers have been discussing some of their ‌iOS 27‌ wants in a dedicated iOS 27 wishlist forum thread that's worth checking out. Some top picks:

Support for using any third-party AI assistant (which is rumored)
A dock with more than four icons
An option for using two apps at once
Dynamic wallpapers
Imports from the Files app to the Music and TV apps
Themes from prior versions of iOS
Multiple user accounts and/or guest mode (for iPadOS 27)
Clipboard history
An RSS app
A tool for PC file transfers

Let us know what you're hoping to see from Apple.

The WWDC 2026 keynote event will take place on Monday, June 8 at 10:00 a.m. Pacific Time or 1:00 p.m. Eastern Time.Related Roundups: iOS 27, WWDC 2026Related Forum: Apple, Inc and Tech Industry
This article, "What's on Your iOS 27 Wishlist Ahead of WWDC 2026?" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Bluetti's Elite 10 Mini Power Station is larger than your average iPhone or iPad power bank, but it's still small enough to be portable. It's ideal for camping, day trips, barbecues, or to have on hand in case of a power outage. It's also a design that works well on a desktop thanks to the included ports.


The Elite 10 has a 128Wh capacity, which is enough to charge a MacBook Neo almost three times, a MacBook Pro 1.5 times, or a MacBook Air twice. It can charge an iPhone or an ‌iPad‌ multiple times, and it supports charging multiple devices at one time too. It can power devices that draw as much as 200W and it has 300W surge capacity with 400W lifting power, so it's more than adequate for Apple products. You can plug in anything that is under 200W, so it's not going to work for things like blow dryers or heaters, but it can power all kinds of small electronics.

There's a single AC outlet on the right side of the charger, plus two USB-A ports, two USB-C ports, and a 12V DC port at the front. One of the USB-C ports offers up to 100W charging, so you can charge a Mac, ‌iPad‌, or iPhone directly with that port without the need for a power adapter. The other USB-C port is 15W, as are the two USB-A ports. As with other Bluetti chargers, you need to press the AC or DC buttons to turn on power to the ports, a feature that prevents unnecessary power draw in standby mode.


Bluetti sells the Elite 10 in a standard gray shade or a light green that's a fun match with the bright colors of the ‌MacBook Neo‌. It's made from plastic, but it's weighty and feels durable. The Elite 10 is 7.9 inches long, 5.8 inches wide, and 4.3 inches tall, so it's not something you're going to want to carry around in a backpack as a daily charger, but it is small enough to keep in the car for emergencies, and at four pounds, it's not too heavy to bring on a trip to the park or the beach.

There's a carrying handle at the top of the Elite 10, and it has built-in fans to keep it cool. The fans are barely noticeable unless you're drawing power at full capacity, and even then, they're quiet. An LED display lets you know the Elite 10's capacity, how much power is being sent to a device, and how much longer the battery will last. Alternatively, you can use the Bluetti app to see that information.


There is a built-in LED light strip at the back that offers cold light, warm light, and a flashing emergency light that can stay on for up to 50 hours. The light is bright enough to light up a tent or a small space. I'm a fan of the LED strip in the Elite 10 because it's a feature that not too many power stations offer.

I've been testing the Elite 10 since December 2025, and I have no complaints. It's worked as intended, and it's a charger that I like to keep on my desktop. I've also brought it outside to charge up smart bird feeders, and it's come on day trips. I did most of my testing of the Elite 10 back in December, but I wanted to see how it would work as a power station that's just tucked away until it's needed in an emergency.


I charged it to full in January, made sure it was off, then stuck it in my closet and left it alone. I was curious about whether it could hold a charge across multiple months, and it does. When I pulled it out of the closet on May 15, it was still at 100 percent charge. It's not ideal to leave a battery at a 100 percent charge for long periods, but if you charge it up and forget about it until a power outage, it's still good to go. Draining it to about 90 percent and then checking in on it every six months or so should be enough if you just want an in-case-of-emergency device that you don't have to think about often. Bluetti says that the LiFePO4 battery inside will last for over 3,000 cycles while remaining above 80 percent total capacity.

UPS mode is supported for uninterrupted power during an outage. You can plug the Elite 10 into a power source and then plug in a computer or router. If the power goes out, it takes 10ms for the Elite 10 to provide power to your computer or router, so your device won't shut off. When you're using it for that purpose, it supports 350W max bypass charging, so it will work for some PC setups. I tested with my router and with a light, and it did swap over as quickly as advertised.

The Elite 10 can be charged with a standard outlet (and a charging cable is included), a car (adapter sold separately), or up to a 100W solar panel. It supports simultaneous AC + solar charging too at up to 150W. With AC power, it can charge at 150W, reaching 100 percent in just over an hour.


Bluetti says that the Elite 10 is in the airline-approved range for carry-on batteries, but I'm not sure I'd try to bring it on a plane. The last few times I've flown in the U.S., flight attendants have been wary of portable batteries and there's now a rule that they must be visible and in reach at all times.

Bottom Line

If you're looking for a portable charger that's still big enough to power multiple iPhones, a couple of iPads, or a MacBook and an iPhone, the Elite 10 is a good option. It's light enough and small enough to bring on short trips, and it's also ideal for keeping in the car or on hand for power outages.

How to Buy

Bluetti's Elite 10 Mini Power Station can be purchased from the Bluetti website or from Amazon for $120.

Note: Bluetti provided MacRumors with an Elite 10 Mini Power Station for the purpose of this review. No other compensation was received. MacRumors is an affiliate partner with Bluetti and may earn commissions on purchases made through links in this article.
This article, "Bluetti Elite 10 Mini Power Station Review: Small, Capable, and Apple-Friendly" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Apple today said App Store rules in Texas are changing due to the enforcement of SB 2420, a law that adds age assurance requirements for app marketplaces and developers.


Apple users located in Texas will soon be required to confirm whether they are 18 years or older when creating an Apple Account. Apple Accounts for users under 18 must be part of a Family Sharing group, and parents need to provide consent for all App Store downloads, app purchases, and in-app transactions.

Developers need to adopt the Declared Age Range API to provide the required age categories for new account users in Texas, and they are responsible for implementing the correct age restrictions. Developers must get parental consent for a minor to download an app, and are required to re-obtain consent if there is a "significant change" to an app. It is up to developers to determine when a significant change has been made to an app.

Parents in Texas are able to revoke consent for any app they previously approved for their child, a system that developers also need to support. Apple has several APIs for developers who need to implement these features, including the Declared Age Range API and the Significant Change API. Developers could face civil penalties of up to $10,000 per violation.

Apple first outlined the changes it was making to support SB 2420 in October 2025, because it was supposed to go into effect on January 1, 2026. In December, a Texas federal judge blocked the age verification law and said it was "more likely than not unconstitutional" and a violation of the First Amendment due to the burden of age verification.

The U.S. Court of Appeals for the Fifth Circuit temporarily stayed the injunction that was blocking the law from being enforced, so SB 2420 will go into effect on June 4, 2026. Legal proceedings are still ongoing, and the Fifth Circuit has not decided on whether it will issue a permanent stay of the injunction during the appeals process. The courts still need to determine the constitutionality of SB 2420 and whether the state has the authority to impose age verification requirements on app marketplaces.

When SB 2420 is live, Apple will need to confirm user age when a person creates an Apple Account, an action that the company has not wanted to take. Apple is required to use "commercially reasonable methods to identify an individual's age" during account creation. Existing accounts are not affected. Google's Play Store is also subject to the law.

Apple fought against age assurance requirements in Texas and other states because of the data collection required to determine user age. Apple says SB 2420 forces users to share personally identifiable data to download any apps, even a simple app for checking weather or sports scores. Apple introduced the Declared Age Range API to minimize data collection where possible.

Apple CEO Tim Cook attempted to persuade Texas Governor Greg Abbott to veto the legislation, but Abbott went ahead and signed it into law.

More information on Apple's age assurance frameworks can be found on its Developer website.Tags: App Store, Texas
This article, "Apple Bringing App Store Age Verification to Texas as SB 2420 Takes Effect June 4" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Apple will be permanently closing three of its retail stores in the U.S. on the evening of Saturday, June 20, according to its website.

Apple Towson Town Center
The locations that are closing:
Apple Trumbull in Trumbull, Connecticut
Apple North County in Escondido, California
Apple Towson Town Center in Towson, Maryland
In April, Apple said it made the "difficult decision" to close the stores due to "declining conditions" at the shopping malls in which they are located.

Notably, the staff at the Towson Town Center location became Apple's first retail employees in the U.S. to unionize in 2022. They belong to the International Association of Machinists and Aerospace Workers' Coalition of Organized Retail Employees (IAM CORE), and they signed a collective bargaining agreement with Apple in 2024.

The union and the store's employees have been protesting the planned closure, and some lawmakers in Maryland have voiced their support.


The union is upset that Apple is allowing non-unionized employees at the Trumbull and North County stores to transfer to nearby locations, but not extending this offer to unionized employees at the Towson location. For its part, Apple said it is simply honoring the terms of the collective bargaining agreement that the employees agreed to.

According to Apple, the contract states that in the event of a store closure, Apple would transfer or rehire employees if the company opened a new store within 50 miles of the current location at Towson Town Center. In any other circumstance, the union negotiated for employees to receive severance, which is being provided.

Apple said it has no current plans to open a new store in the area, but if it were to do so within 18 months after the collective bargaining agreement was ratified, the affected employees would have the right of first refusal.

Nevertheless, IAM has accused Apple of potential union busting and said that the agreement "requires equal treatment."

"Apple workers in Towson voted to join the IAM, fought for and won a contract, and are now being punished for it," said IAM President Brian Bryant. "Apple signed a collective bargaining agreement that requires equal treatment. It is time for Apple to honor that agreement and do right by these workers before June 20."

Towson Town Center is genuinely in a state of decline and has lost many other major retailers in recent years, so it is very likely that Apple is exiting the shopping mall at least partly due to the worsening conditions. Nevertheless, the situation could benefit Apple by warning employees at other stores that joining a union does not always work out. However, we may never know Apple's true and full intentions behind its decision.Tag: Apple Store
This article, "Apple is Permanently Closing Three U.S. Stores This Month" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Software supply chain attacks have accelerated faster than most security teams anticipated. Sonatype’s 2026 State of the Software Supply Chain report identified more than 454,000 new malicious packages published to open source repositories in 2025, bringing the cumulative total to over 1.2 million since 2019. The blast radius keeps expanding as organizations consume more open source software, ship more container-based workloads, and distribute software through increasingly complex pipelines.
Software supply chain security is the discipline of protecting every component, process, and system involved in building and delivering software, from the source code developers write to the dependencies they pull in, the build systems that compile and package their code, the registries that store their artifacts, and the infrastructure that runs those artifacts in production. It’s a lifecycle concern, not just a deployment-time check.
What makes this discipline distinct from traditional application security is the scope. Application security focuses on the code your team writes. Supply chain security focuses on everything your code depends on, and everything that touches your code on its way to production. For container-based delivery pipelines, that means every base image, every package, every build tool, and every registry interaction is part of the attack surface.
Why software supply chain security matters now
The urgency behind software supply chain security is driven by a structural shift in how software is built. Modern applications are overwhelmingly assembled from existing components rather than written from scratch. A typical container image contains hundreds of packages, each with its own dependency tree, maintainers, and update cadence. Every one of those components is a trust decision, and most organizations are making those trust decisions implicitly rather than deliberately.
The dependency problem is a trust problem
When a developer adds a package to a project, they’re trusting that the package does what it claims, that the maintainers are who they say they are, the package registry has not been compromised, and the package will continue to receive security updates. Multiply that trust decision across every dependency in every container image across an organization, and the scale of implicit trust becomes clear.
Attackers have recognized that compromising a single widely used package can give them access to thousands of downstream organizations. Techniques like dependency confusion, typosquatting, and maintainer account takeovers have become standard tools in the attacker playbook. The impact of software supply chain attacks extends well beyond the initial compromise, propagating downstream through every organization that consumes the affected component. The software supply chain has become the preferred vector precisely because the trust relationships are implicit and the verification infrastructure is often absent.
Containers changed the attack surface
Container security has always been a multi-layered concern, but containerization accelerated the supply chain security challenge in ways that are still catching up with many organizations. A container image is a complete, immutable software artifact that bundles application code with its operating system dependencies, runtime, and configuration. That immutability is a security advantage because what you test is exactly what you deploy. But it also means every vulnerability in every layer of that image ships to production unless you’re actively scanning, verifying, and updating.
The container registry has become one of the most critical points in the supply chain. It’s where images are stored, distributed, and pulled for deployment. If an attacker can push a tampered image to a registry, or trick a deployment pipeline into pulling an unverified image, the compromise reaches production without triggering any code-level security controls. Registry security, image signing, and pull policies are supply chain security concerns that did not exist before containerized delivery became the default.
Regulatory pressure is accelerating
Government and industry mandates are making supply chain security a compliance requirement, not just a best practice. Executive Order 14028 on Improving the Nation’s Cybersecurity requires US federal software suppliers to meet specific supply chain security standards, including SBOM generation and secure development practices. The NIST Secure Software Development Framework (SSDF) provides the reference architecture. And SLSA (Supply-chain Levels for Software Artifacts) offers a graduated framework for verifying that artifacts were built securely.
These frameworks are not just government requirements. They’re shaping procurement standards across industries. Modern software is overwhelmingly assembled from open source components, and those components frequently carry known vulnerabilities. Organizations that cannot demonstrate supply chain integrity through provenance attestations, SBOMs, and verifiable build processes are increasingly locked out of enterprise and public-sector contracts.
How software supply chain security works
Supply chain security is not a single tool or practice. It’s a set of controls applied at every stage of the software delivery pipeline. Each stage has distinct attack surfaces and requires specific protections.
Securing source code and dependencies
The supply chain starts where the code starts. Source code repositories need access controls, commit signing, and branch protection rules that ensure only authorized changes make it into the codebase. But the bigger risk is usually in dependencies, not the first-party code itself.
Dependency management for supply chain security goes beyond keeping packages updated. It includes verifying that packages come from trusted sources, that they have not been tampered with since publication, and that their transitive dependencies (the packages your packages depend on) are also trustworthy. Lockfiles, hash verification, and dependency pinning are baseline controls. Private registries and curated package feeds add a layer of organizational control over what enters the dependency tree.
Securing the build process
The build system is where source code and dependencies are transformed into deployable artifacts. A compromised build environment can inject malicious code into every artifact it produces, regardless of how clean the source code is. Build integrity means running builds in isolated, ephemeral environments that start clean every time, producing provenance attestations that record exactly what was built, with what tools, from what source, and generating SBOMs that provide a complete inventory of every component in the final artifact. It’s one of the hardest stages to secure because the compromise is invisible at the source code level.
SLSA framework levels provide a useful maturity model here. At SLSA Build Level 3, the build process runs on a hardened build platform, the provenance is non-falsifiable, and the build platform isolates each build to prevent tampering between runs. This is where hardened, provenance-verified images become essential, providing cryptographic proof of how each image was produced.
Securing container images and registries
Container images are the primary delivery artifact in modern supply chains, which makes image security a central supply chain concern. Securing images starts with the base image. If the foundation is unverified, outdated, or bloated with unnecessary packages, every image built on top of it inherits those risks.
Trusted base images are minimal, regularly rebuilt against upstream security fixes, and distributed with verifiable provenance. They come with SBOMs that document every package included, vulnerability scan results that are transparent rather than suppressed, and cryptographic signatures that let consumers verify the image has not been tampered with since it was built. 
That transparency distinction matters: some image providers suppress or downplay vulnerability data to make their scan results look cleaner. A genuinely trusted image shows you everything, including what has not been patched yet, so your team can make informed decisions rather than operating on incomplete information.
Registry security involves controlling who can push and pull images, enforcing image signing policies, scanning images for vulnerabilities before they are deployed, and maintaining audit trails of every registry interaction. Organizations that treat their container registry as a trusted source of truth rather than a dumping ground for artifacts are materially better positioned to prevent supply chain compromises.
Securing deployment and runtime
The final stages of the supply chain are deployment and runtime. Deployment controls ensure that only verified, signed images from trusted registries are pulled into production environments. Admission controllers, image verification policies, and deploy-time SBOM checks create enforcement points that prevent unverified artifacts from reaching production.
Runtime security adds the last layer of defense. Even with a fully secured build and deployment pipeline, runtime monitoring detects anomalous behavior that might indicate a compromised component: unexpected network connections, unusual file system access, or processes that should not be running. Sandboxed execution environments provide isolation that limits the blast radius if a compromised component makes it past earlier controls.
The role of SBOMs in supply chain security
A Software Bill of Materials (SBOM) is a machine-readable inventory of every component in a software artifact: packages, libraries, versions, licenses, and their relationships. In the context of supply chain security, SBOMs serve as the transparency layer that makes everything else possible. You cannot verify what you cannot see, and SBOMs make the contents of software artifacts visible.
What distinguishes SBOMs as a supply chain security tool from SBOMs as a compliance artifact is how they’re generated and used. A compliance-oriented SBOM is generated once, filed away, and referenced during audits. A security-oriented SBOM is generated automatically with every build, attached to the artifact it describes, and consumed by automated tools that check for known vulnerabilities, license conflicts, and policy violations before the artifact reaches production. As GitHub’s analysis of vulnerability trends shows, the volume of published CVEs continues to grow each year, making automated SBOM-driven scanning essential rather than optional.
The most effective supply chain security programs treat SBOMs as living artifacts that travel with the software they describe. When a new vulnerability is disclosed, the SBOM lets you answer immediately: are we affected, where, and in which deployed artifacts? That response time is the difference between a controlled remediation and a scramble. For a deeper look at implementation, see our guide on software supply chain security best practices.
4 Common software supply chain attack vectors
Understanding how supply chains are attacked is essential to understanding how to defend them. Attack vectors target different stages of the pipeline, and each requires specific controls.
1. Dependency-based attacks
These target the packages and libraries your software depends on. Dependency confusion exploits the way package managers resolve names, tricking build systems into pulling a malicious public package instead of a legitimate private one. Typosquatting registers packages with names similar to popular libraries, banking on developer typos. Maintainer account takeovers compromise the credentials of a trusted package maintainer and push malicious updates through the legitimate distribution channel.
2. Build system compromises
Attackers who compromise a build system can inject code into every artifact it produces. This is particularly dangerous because the source code remains clean, and code review will not catch the compromise.
3. Image and registry attacks
Container-specific attack vectors include pushing tampered images to public registries, creating malicious images with names that mimic popular official images, and exploiting misconfigured registry access controls to replace legitimate images with compromised ones. Organizations without image signing verification and registry access management policies are particularly vulnerable to these vectors.
4. CI/CD pipeline exploitation
CI/CD pipelines often have elevated privileges (access to secrets, deployment credentials, production environments) that make them high-value targets. Attackers exploit pipeline configurations to exfiltrate secrets, modify build outputs, or inject steps that execute during otherwise legitimate workflows.
The rise of AI coding agents adds a new dimension to this threat: agents that generate code or modify dependencies can introduce supply chain risks at machine speed if they are not operating within secure, isolated environments. Poisoned pipelines are especially dangerous because they can produce artifacts that pass all automated security checks while carrying malicious payloads.
Core principles of software supply chain security
Effective supply chain security programs share a set of principles that guide both technical implementation and organizational culture.
Principle
What this means in practice
Verify, don’t assume 
Every component, dependency, and artifact should be cryptographically verified before it’s consumed. Build verification into the pipeline rather than relying on assumptions about source integrity, maintainer identity, or registry trustworthiness. 
Start with trusted content
The base images and packages at the foundation of your supply chain determine the security posture of everything built on top of them. Hardened, minimal, provenance-verified base images reduce the attack surface at the root.
Verify at every transition
Each time an artifact moves from one stage to another (source to build, build to registry, registry to deploy), verify its integrity. Signing, attestation, and hash verification at transition points prevent tampered artifacts from propagating.
Generate transparency artifacts automatically
SBOMs, provenance attestations, and vulnerability scan results should be generated automatically as part of the build process, not manually or after the fact.
Enforce policy at the infrastructure level
Supply chain security policies (which registries are allowed, which images can be deployed, what vulnerability thresholds are acceptable) should be enforced by infrastructure, not by process documentation.
Minimize the blast radius
Assume that some component will eventually be compromised and design your pipeline to limit the damage. Least-privilege access, isolated build environments, and runtime sandboxing reduce the impact of any single compromise.
Building a software supply chain security program
Moving from ad hoc security practices to a structured supply chain security program involves layering controls at each stage of the pipeline. The goal is not to implement everything at once but to establish a foundation and build on it as the organization matures.
1. Establish a trusted image foundation
The single highest-leverage action most organizations can take is to control what goes into their base images. If developers are pulling arbitrary images from public registries without verification, every other supply chain security investment is built on an unstable foundation.
A trusted image foundation means maintaining a curated set of approved base images that are minimal (reducing attack surface), regularly rebuilt (incorporating upstream fixes), and distributed with provenance attestations and SBOMs. 
The good news is that you do not have to build this from scratch. Hardened, continuously rebuilt base images with SLSA Build Level 3 provenance and full vulnerability transparency can be used as drop-in replacements for standard images, so teams can adopt them without reworking existing CI/CD pipelines.
2. Implement SBOM generation and consumption
SBOMs should be generated automatically as part of every build pipeline, attached to the artifacts they describe, and consumed by automated tools that check for vulnerabilities and policy violations. The two standard SBOM formats, SPDX and CycloneDX, are both widely supported by scanning and policy tools. Choose one and standardize across the organization.
3. Deploy image signing and verification
Image signing creates a cryptographic chain of trust between the entity that built an image and the environment that deploys it. Signing keys should be managed centrally, signing should happen automatically as part of the build pipeline, and verification should be enforced at deployment time through admission controllers or registry policies. If an image is not signed by a trusted key, it should not reach production.
4. Enforce registry and image access policies
Control which registries developers and deployment pipelines can pull from. Block access to unapproved public registries and enforce policies that require images to come from verified sources. For Docker Desktop, Registry Access Management provides these controls, ensuring policies are enforced consistently across developer workstations, not just in CI/CD.
5. Integrate vulnerability scanning into the pipeline
Scanning should happen at multiple points: 
When dependencies are added When images are built When images are pushed to registries On a continuous basis for deployed artifacts The goal is to catch vulnerabilities as early as possible in the pipeline, when remediation is cheapest and least disruptive. You’ll want continuous vulnerability analysis integrated directly into the developer workflow so issues are surfaced where engineers can act on them, rather than buried in a security dashboard that rarely gets checked.
6. Establish incident response for supply chain compromises
Supply chain incidents are different from typical security incidents because the compromise often originates outside the organization. Your incident response plan should account for scenarios where a trusted dependency is compromised, where a base image contains a newly disclosed vulnerability, or where a build system produces artifacts that cannot be verified. 
The faster you can identify which deployed artifacts are affected (this is where SBOMs pay for themselves), the faster you can respond.
Where does your supply chain security stand?
Supply chain security maturity varies widely across organizations. Use this self-assessment to identify where your organization falls and what to prioritize next.
Frameworks and standards
Several frameworks provide structured approaches to supply chain security. They’re complementary rather than competing, and mature organizations typically align with multiple frameworks.
SLSA (Supply-chain Levels for Software Artifacts)
SLSA provides a graduated framework for verifying the integrity of software artifacts. Its build levels establish increasingly rigorous requirements for how artifacts are produced, from basic build provenance at Level 1 to hardened build platforms with non-falsifiable provenance at Level 3. SLSA is particularly valuable because it translates abstract supply chain security goals into concrete, verifiable technical requirements.
NIST SSDF (Secure Software Development Framework)
The NIST SSDF (SP 800-218) provides a comprehensive set of secure development practices organized around four practice groups: Prepare the Organization, Protect the Software, Produce Well-Secured Software, and Respond to Vulnerabilities. It’s the primary reference framework for federal software supply chain requirements under Executive Order 14028.
OpenSSF Scorecard and GUAC
The Open Source Security Foundation provides tools for evaluating the security posture of open source projects (Scorecard) and for aggregating and querying supply chain metadata (GUAC, Graph for Understanding Artifact Composition). These tools help organizations make informed decisions about which open source components to trust.
Getting started
Supply chain security is an infrastructure discipline. The organizations that approach it as a set of pipeline controls rather than a compliance checklist are the ones building the most resilient software delivery systems. The practices in this guide are designed to be layered incrementally. If your organization is starting from scratch, begin with the highest-leverage action: establish a trusted image foundation. Control what goes into your base images, generate SBOMs automatically, and enforce verification at every pipeline stage from there.
Docker Hardened Images provide a production-ready foundation with SLSA Build Level 3 provenance, continuous vulnerability monitoring, and cryptographic signatures that verify integrity from build to deployment. Combined with Docker Scout for continuous vulnerability analysis and Registry Access Management for policy enforcement, teams can create an infrastructure layer for supply chain security across their full delivery pipeline.
Explore our full catalog of hardened images and start replacing your base images today.
Frequently asked questions
What is software supply chain security?
Software supply chain security is the practice of protecting every component and process involved in building and delivering software. This includes the source code, open source dependencies, build systems, container images, registries, and deployment pipelines. The goal is to ensure that every artifact deployed in production is exactly what it claims to be, has not been tampered with, and is free of known vulnerabilities. It’s a lifecycle discipline, not a single tool or checkpoint.
Why is software supply chain security important?
Modern software is assembled from hundreds or thousands of open source components, each with its own maintainers, vulnerabilities, and update cadences. A single compromised component can propagate through the entire delivery pipeline and into production. Supply chain attacks have increased significantly because they allow attackers to reach many downstream organizations by compromising a single upstream dependency or build system.
What is the difference between software supply chain security and application security?
Application security focuses on vulnerabilities in the code your team writes: injection flaws, authentication bugs, authorization issues. Supply chain security focuses on everything your code depends on and everything that touches it on the way to production. The distinction matters because most code in a modern application is not written by the team deploying it. It’s pulled in from open source libraries, base images, and system packages.
What is an SBOM and why does it matter for supply chain security?
An SBOM (Software Bill of Materials) is a machine-readable inventory of every component in a software artifact. It matters because you cannot secure what you cannot see. SBOMs enable automated vulnerability scanning, license compliance checking, and rapid incident response when a new vulnerability is disclosed. When generated automatically with every build and attached to the artifact, they provide a continuous transparency layer across the entire supply chain.
How do container images relate to supply chain security?
Container images are the primary delivery artifact in containerized supply chains. They bundle application code with all of its dependencies, making them a complete representation of everything that will run in production. This makes image security a central supply chain concern: the base image you start from, the packages you add, and how the image is signed, stored, and verified all directly impact supply chain integrity.
What frameworks should I follow for software supply chain security?
The most widely adopted frameworks are SLSA (Supply-chain Levels for Software Artifacts) for build integrity, NIST SSDF (SP 800-218) for secure development practices, and the OpenSSF Scorecard for evaluating open source dependencies. Executive Order 14028 mandates NIST SSDF alignment for federal software suppliers, and its requirements are increasingly adopted as industry standards.
View the full article
Incoming Apple CEO John Ternus signed off on a major revision of Apple's Vision Pro and smart glasses plans, consolidating Apple's work in the category.


According to Apple analyst Ming-Chi Kuo, Ternus nixed plans for a second Vision Pro and a lighter Vision Air. Kuo says there are only two smart glasses products in development, including the AI smart glasses that Apple is creating to rival the Meta Ray-Bans and a display-equipped set of AR smart glasses.

"I think removing the Vision Pro line was the right call, as Apple shifts resources toward smart glasses with greater mass-market potential," writes Kuo. Kuo says that the Vision products roadmap that he shared in June 2025 is no longer a useful reference because of the major changes that Apple has made to its plans over the last year. Kuo's product timeline originally featured seven products, but now it features just two that are still relevant.

Kuo believes the AI smart glasses will ship in 2027, while the display-equipped augmented reality glasses with "optical waveguides" won't come out until 2029 at the earliest. Optical waveguides pair a micro-display with waveguides that guide the image to the user's eyes. Lenses remain transparent, so the virtual content looks like it's overlaid on the real world view.

Bloomberg's Mark Gurman weighed in on Kuo's report and said the Vision Air was discontinued in October 2025, the display glasses meant to pair with a Mac were sunset in January 2025, and AI smart glasses will launch at the end of 2027.

While Kuo does not believe Apple is working on any version of a Vision Pro, Gurman claims Apple has a Vision Pro 2 "in testing" but the category is "on ice." Earlier this week, Gurman also said Apple is working on a cheaper, lighter Vision Pro, but the device is unlikely to launch before late 2028 or 2029.

John Ternus is set to take over as Apple's CEO on September 1, 2026. Current Apple CEO Tim Cook will remain on as Executive Chairman.Related Roundup: Apple Vision ProTags: Apple Glasses, John Ternus, Ming-Chi KuoBuyer's Guide: Vision Pro (Neutral)Related Forum: Apple Vision Pro
This article, "Kuo: Apple's Vision Pro Successors Off the Table as Focus Shifts to Smart Glasses" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Apple today shared a new Beats Pill ad that pays tribute to the reality TV show Love Island USA, which returned for an eighth season this week.


The ad does not mention Love Island USA, but the "Pill People" are said to have "entered the villa," which is a clear reference to the show.

"If you're binging a full summer of island drama, you'll need battery life that can keep up," says Apple. "Good thing the Beats Pill gets up to 24 hours of listening time, more than enough for every recoupling, challenge, and twist the summer has to offer."

Apple released the current Beats Pill in 2024. Priced at $149.99 in the U.S, the speaker comes in Matte Black, Statement Red, and Champagne Gold.Tags: Apple Ads, Beats
This article, "Apple's New Beats Pill Ad Leans Into Reality TV Show 'Love Island USA'" first appeared on MacRumors.com

Discuss this article in our forums

View the full article

Account

Navigation

Search

Search

Configure browser push notifications

Chrome (Android)
  1. Tap the lock icon next to the address bar.
  2. Tap Permissions → Notifications.
  3. Adjust your preference.
Chrome (Desktop)
  1. Click the padlock icon in the address bar.
  2. Select Site settings.
  3. Find Notifications and adjust your preference.