Skip to content
View in the app

A better way to browse. Learn more.

hosang I.T.

A full-screen app on your home screen with push notifications, badges and more.

To install this app on iOS and iPadOS
  1. Tap the Share icon in Safari
  2. Scroll the menu and tap Add to Home Screen.
  3. Tap Add in the top-right corner.
To install this app on Android
  1. Tap the 3-dot menu (⋮) in the top-right corner of the browser.
  2. Tap Add to Home screen or Install app.
  3. Confirm by tapping Install.

Tech

Tech Articles from a wide variety of topics and categories
T-Mobile's Starlink satellite connectivity is now available for T-Mobile users who are traveling in Canada and New Zealand.


T-Mobile users have previously had access to cellular connectivity through roaming agreements in Canada and New Zealand, and now T-Satellite connectivity is included. Canada satellite coverage is enabled through Rogers Satellite, and in New Zealand, satellite coverage is provided by One NZ. Both Rogers and One NZ have agreements with Starlink provider SpaceX.

T-Mobile updated its website to mention satellite roaming last week, and the company says that support for other locations will be coming in the future. T-Mobile is working with global roaming partners and SpaceX to expand T-Satellite.

T-Satellite is available to T-Mobile subscribers in the continental U.S., Puerto Rico, Hawaii, and parts of southern Alaska. It is also now available in Canada and New Zealand, with a coverage map available on the T-Mobile website.

Rogers and One NZ customers can also use T-Satellite when traveling in the United States as part of the new partnership.

T-Mobile's satellite connectivity launched in July 2025 after several months of beta testing, and it is compatible with the iPhone 13 and later. In October 2025, T-Mobile added support for using satellite data with some third-party apps, an option not available with Apple's built-in satellite feature on the iPhone 14 and later.

Like Apple's satellite option, T-Satellite kicks in when users do not have a Wi-Fi or cellular connection available. A view of open sky is required to establish connectivity, but there is no need to manually hold an iPhone to the sky to connect as there is with Apple's implementation.

T-Satellite works on Apple iPhones, and it can be used alongside the native satellite connectivity. Satellite service is included in T-Mobile's Experience Beyond plans, and is priced at $10 per line for other T-Mobile plans.

Smartphone users without T-Mobile service can sign up for T-Satellite for $10 per month.Tag: T-Mobile
This article, "T-Mobile Customers Can Now Use Satellite Connectivity in Canada and New Zealand" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Major international events attract not just global audiences but also distributed denial-of-service (DDoS) attacks. The Milano Cortina 2026 Winter Games proved no exception: DDoS attack volume against Italian infrastructure in the country surged 181 percent over 2025 levels, which were themselves elevated by sustained NoName057(16) campaigns. Attackers treated the Winter Games calendar as an operational playbook, escalating two weeks before opening ceremonies and terminating abruptly after the event’s closing.
Key Findings
Attack volumes 6–10x historical levels during the Winter Games period (February 6–23, 2026) Peak attack count reached more than 2,200 attacks on February 23 NoName057(16) dominated public DDoS hacktivist claims with 47, although ransomware groups (Qilin, LockBit 5.0) also claimed success in various attacks Tactical shift from pre-Winter Games high-bandwidth attacks (412.89Gbps peak) to Winter Games-period high-throughput attacks Geographic concentration on Milan (Winter Games cohost), Cortina infrastructure (hotels, ski sites), and symbolic targets (consulates, defense) Temporal Analysis
Attack activity in Italy can be divided into three distinct periods:
Pre-Winter Games (January 20–February 5): 4,963 attacks, averaging 300 daily. The first escalation occurred January 22, with triple the 2024 and 2025 levels for comparable dates. January 25 recorded maximum traffic intensity of 412.89Gbps, with average bandwidth per attack ranging from 0.74 to 5.45Gbps. These high-magnitude attacks suggest testing network capacity limits and defensive responses.
Winter Games period (February 6–23): 12,963 attacks, averaging 720 daily. This period accounted for 56 percent of total attack volume and 6x times higher attack activity compared with 2024 and 2025. Activity escalated from 191 attacks on February 16 to 1,890 on February 23. During the Winter Games, we can see tactical shifts in attack types to packet rate­–intensive patterns to sustain pressure via quantity over bandwidth knockouts.
Post-Winter Games (February 24–March 3): 5,315 attacks, peaking at 2,281 on February 24—a record-breaking single-day count representing the highest attack volume observed against Italy in the past three years. Activity declined 88 percent to 272 attacks by February 26.
NETSCOUT
Figure 1: Year-over-year DDoS attack comparison during Milano Cortina 2026
The temporal pattern with the Winter Games calendar shown in Figure 1 illustrates the dramatic escalation in attack frequency during 2026 compared with prior years. Notably, the five highest single-day attack counts recorded against Italy in the past three years all occurred during the February 17–25 period: February 24 (2,281 attacks), February 23 (1,890 attacks), February 21 (1,865 attacks), February 22 (1,828 attacks), and February 20 (1,684 attacks). Beyond attack volume, the intensity of individual attacks also showed significant variation throughout the observation period.
Attack Vector Analysis
Attackers combined multiple techniques simultaneously, averaging more than two vectors per attack; UDP flooding was dominant, showing up in 85 percent of attacks, while additional DDoS attack vectors showed up in 87 percent, meaning most attacks mixed direct UDP flooding with amplified traffic from devices susceptible to reflection/amplification.
NETSCOUT
Figure 2: Attack vector distribution during Milano Cortina 2026
UDP flooding led attacks at 85 percent, followed by DNS amplification (19 percent), and memcached amplification (11.8 percent). The amplification toolkit extended to NTP (7.5 percent), STUN (6.6 percent), SSDP (5.9 percent), and SNMP (5 percent).
Threat Actor Claim Analysis
Between February 4 and February 24, 2026, threat actors publicly claimed responsibility for attacks targeting Italian infrastructure via social media and Telegram channels. These claims represent self-reported attribution and have not been independently validated against observed DDoS telemetry.
NoName057(16) dominated claims activity with 47 attacks claimed against Italy during this period, representing 40 percent of all the attribution. This represents notable concentration of NoName activity: The group claimed a total of 488 attacks globally during same time frame, meaning Italy accounted for 10 percent of NoName’s global targeting. Historical analysis shows that between December 1 and February 3, NoName057(16) claimed only one attack against Italy and made no claims toward Italy after February 28, 2026, indicating the Winter Games period attracting the threat actor.
Secondary actors generated 60 percent of the remaining claims, but in substantially lower claim volumes during the Winter Games period: Server Killers (8 claims), Z-Pentest Alliance (4 claims), Dark Storm Team (3 claims). The remaining 47 attacker claims were distributed among ransomware groups, individual actors, and various entities.
DDoSia Analysis
DDoSia is a homegrown DDoS platform developed by NoName057(16) operating since early 2022. DDoSia detection events by the NETSCOUT ASERT team recorded 3,491 attacks against 74 unique Italian domains during pre-Winter Games and Winter Games periods, aimed at disrupting the Winter Games infrastructure, government operations, and critical services. The primary vectors include HTTP/HTTPS/HTTP2 floods; TCP floods on port 80, 443, 2222, 8080; and slowloris-style resource exhaustion attacks.
NETSCOUT
Table 1: DDoSia target categories and observations count during Milano Cortina Winter Games 2026

Aisuru IoT Botnet Analysis
Aisuru operates as a Mirai-derivative Internet of Things (IoT) botnet first disclosed in August 2024, comprising of more than 1 million compromised consumer routers, cameras, and IoT systems. (Note: This analysis period is prior to the recent law-enforcement takedown action impacting the Aisuru botnet.) The botnet functions as DDoS-for-hire services, with attacks of up to 31Tbps purported. After observing dominance of direct-path UDP flooding—the most common Aisuru attack type—NETSCOUT’s ASERT team tracked more than 683 Aisuru-tagged instances against Italian cities, with Milan absorbing 94 percent of activity (642 instances).
NETSCOUT
Table 2: Aisuru geographic distribution during Milano Cortina Winter Games 2026
 
Conclusion
The DDoS campaign targeting Italy during the Milano Cortina 2026 Winter Games demonstrated how major international events create predictable windows for coordinated cyberthreat activity. The attack activity observed against Italy between January and March 2026 demonstrates an elevated DDoS threat landscape as compared with global DDoS trends during the same periods in prior years. The attacks represented a 181 percent frequency increase compared with 2025, when Italy was the target of NoName057 due to global geopolitical tensions reported by the ASERT team in the “Italy in the Crosshairs” campaign. 
Global visibility via NETSCOUT ATLAS threat intelligence and adaptive DDoS protection via NETSCOUT Arbor products equip organizations with robust and proactive defense strategies, ensuring the supporting infrastructure of major international events remains undisrupted.
To learn more, visit us here.

View the full article
End-to-end encryption (E2EE) for RCS messages between iPhone and Android devices is coming in iOS 26.5, Apple confirmed today. The feature is listed in Apple's iOS 26.5 release notes.


Apple says end-to-end encrypted ‌RCS‌ messaging remains in beta even though it is being released in iOS 26.5. The feature is available with supported carriers and will roll out over time, and for conversations to be encrypted, both the receiver and the sender must use a carrier that supports the latest version of ‌RCS‌.

End-to-end encryption is on by default, and there is a toggle for it in the Messages section of the Settings app. Encrypted messages are denoted with a small lock symbol.

Testing of E2EE for ‌RCS‌ began in iOS 26.4, but Apple did not launch the feature in the iOS 26.4 update. It returned in the iOS 26.5 beta, and has been available throughout the beta testing process.

E2EE means that messages sent between devices cannot be intercepted and read by a third party. As of now, ‌RCS‌‌ messages sent between Android and iPhone users do not have E2EE, but iOS 26.5, iPadOS 26.5, macOS Tahoe 26.5, and watchOS 26.5 will put Android/iPhone conversations on par with iPhone to iPhone conversations that are encrypted through iMessage.

Apple worked with the GSM Association to implement E2EE for ‌RCS‌ messages. E2EE is part of the ‌RCS‌ Universal Profile 3.0, published with Apple's help and built on the Messaging Layer Security protocol. ‌‌RCS‌‌ Universal Profile 3.0 also includes editing and deleting messages, cross-platform Tapback support, and replying to specific messages inline during cross-platform conversations.Related Roundups: iOS 26, iPadOS 26Tags: Android, RCSRelated Forum: iOS 26
This article, "iOS 26.5 Brings End-to-End Encryption to iPhone-Android RCS Messages" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Back in April, we highlighted a new add-your-own card Wallet app option coming in iOS 27, and now Bloomberg has shared additional information. At the time, we said Apple was working on a feature that would let users generate digital passes from scans of things like movie tickets, concert passes, and gym membership cards.


The option will be called "Create a Pass," and it will bridge the gap between the Wallet app and passes that are not compatible with it. Users will be able to tap on the "+" button in the Wallet app and then scan a QR code on a pass or ticket if one is available. If there is no QR code available, there will be an option to create a custom pass.

Text in the app suggests the feature will work for tickets, memberships, gift cards, and more. There are three pass types, each with a different color. Apple is using purple for events, blue for memberships, and orange for other types of passes. Users will be able to customize images, colors and style, and text on the digital passes.

The new Wallet option is one of many features coming in ‌iOS 27‌, which will be previewed at Apple's June WWDC event. More information on what to expect from ‌iOS 27‌ can be found in our roundup.Related Roundup: iOS 27Tag: Apple Wallet
This article, "iOS 27 Will Let You Create Custom Wallet Passes" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Apple today provided the release candidate version of an upcoming macOS Tahoe 26.5 update to developers for testing purposes, with the update coming a week after Apple seeded the fourth beta.


Developers can download the ‌macOS Tahoe‌ 26.5 update by opening up the System Settings app, selecting the General category, and then choosing Software Update. Beta Updates will need to be enabled, and a free developer account is required.

No new features were found in the first four ‌macOS Tahoe‌ 26.5 betas, and it's likely the update primarily focuses on bug fixes and performance improvements.Related Roundup: macOS TahoeRelated Forum: macOS Tahoe
This article, "macOS Tahoe 26.5 Release Candidate Now Available" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Apple today seeded the release candidate versions of upcoming iOS 26.5 and iPadOS 26.5 updates to developers for testing purposes, with the software coming a week after Apple released the fourth betas.


Registered developers can download the betas from the Settings app on the iPhone or iPad by going to the General section and selecting Software Update.

iOS 26.5 and iPadOS 26.5 do not include new Siri capabilities, suggesting any ‌Siri‌ updates are being held until iOS 27. The Maps app has a Suggested Places feature for recommending locations to visit nearby based on trends and recent searches, plus Apple is laying the groundwork for ads in the Apple Maps app.

Apple is continuing to test end-to-end encryption (E2EE) for RCS messages between iPhone and Android users. Apple included the feature in the iOS 26.4 beta, but removed it before the update launched to the public.

There is a new Pride wallpaper to go along with the Pride Apple Watch band for this year.

In the European Union, Apple is testing proximity pairing, notification forwarding, and Live Activities for third-party wearables like earbuds and smartwatches. The functionality will allow third-party wearables to have many of the same features as the Apple Watch and AirPods.

More detail on what's new in iOS 26.5 can be found in our iOS 26.5 beta features guide. iOS 26.5 is likely to see a launch next week. Related Roundups: iOS 26, iPadOS 26Related Forum: iOS 26
This article, "Apple Seeds iOS 26.5 and iPadOS 26.5 Release Candidates to Developers" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Apple today provided developers with the release candidate versions of upcoming watchOS 26.5, tvOS 26.5, and visionOS 26.5 betas for testing purposes. The software comes a week after Apple released the fourth betas for each platform.


The software updates are available through the Settings app on each device, and because these are developer betas, a free developer account is required.

watchOS 26.5 adds a new Pride watch face to go along with the 2026 Pride Apple Watch band.

There's no word on what other features are in the software as of yet. watchOS, tvOS, and visionOS often get few features in each new beta, with updates primarily focusing on bug fixes and performance improvements. Nothing new was found in the betas.

watchOS 26.5, visionOS 26.5, and tvOS 26.5 are likely to see a public release next week.Related Roundups: Apple TV, Apple Vision Pro, watchOS 26Buyer's Guide: Apple TV (Don't Buy), Vision Pro (Buy Now)Related Forums: Apple TV and Home Theater, Apple Vision Pro, Apple Watch
This article, "Apple Seeds watchOS 26.5, tvOS 26.5 and visionOS 26.5 Release Candidates" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Orphaned applications are a significant driver of shadow IT and a major headache for asset and identity management. We all know the drill: an account should have been deprovisioned years ago, but somehow fell through the cracks. Now, the application is just… sitting there, still running, still exchanging data. It’s hard to even know what exists, let alone how it’s affecting network performance or expanding the attack surface.
The irony of shadow IT isn’t how an app, a browser extension, or a cloud service entered the environment. It’s whether IT still has visibility into it and any ability to control what it’s doing. 
Orphaned applications are often adopted as part of legitimate business workflows, introduced by individual teams to support revenue, respond to customer needs, or meet time-sensitive departmental goals when centralized IT processes cannot move fast enough. Over time, workforce transitions or shifting business priorities leave behind not just the applications, but the workflows built around them, along with accounts, credentials, service identities, and access permissions that remain active without clear operational intent.
Digital transformation, software-as-a-service (SaaS) growth, the rise of artificial intelligence (AI) agents, connected devices, including Internet of Things (IoT) systems, and generative AI (GenAI) have made orphaned workflows much easier to overlook. Cloud-based tools, browser plugins, and desktop software often remain connected to IT infrastructure long after the original project is forgotten. When no one knows who owns the credentials, these tools often stop being updated and operate outside normal monitoring and maintenance cycles, creating several critical issues:
Operational and financial overhead: Orphaned applications continue consuming licenses and infrastructure while cluttering configuration management databases (CMDBs). They introduce undocumented dependencies that skew asset management and complicate troubleshooting. Security exposure: Applications without active ownership are rarely reviewed. This means updates are missed, underlying components are no longer maintained, and access paths remain open far longer than intended. Hidden data movement: Applications may not stop exchanging data just because teams stop using them. Orphaned services may continue storing or transmitting sensitive data entirely outside security controls. Compliance and governance gaps: When IT loses awareness of an application, it also loses the ability to enforce retention policies, access controls, and audit requirements. This creates a significant paper trail risk during a formal audit. Observability that reveals hidden systems operating on the network
Most organizations rely on inventories, configuration records, and ownership data maintained in IT asset inventories, CMDBs, and application mapping tools to understand their environments. The problem is that these sources reflect planning decisions and historical states, not what’s actually happening right now. Orphaned applications persist because they may continue functioning without obvious signals or active users. Because they often rely on service identities or automated API keys, they may authenticate normally, respond as expected, and continue moving data in ways that don’t raise alarms. To IT teams, nothing appears broken.
Network data reflects the current state of how applications and services interact. Packet-derived insight captures real-time behavior, making it possible to see what is actually communicating rather than what inventories or records suggest should exist. Hidden systems aren’t passive; they continue polling databases and holding open connections, quietly consuming bandwidth and processing capacity needed by active, revenue-generating services. As organizations introduce more cloud services and AI-driven tools, new communication paths can appear faster than CMDB records, and ownership data can be updated, creating observability gaps that affect how systems and services perform and interact.
How blind spots lead to security exposure
Many security incidents don’t begin with sophisticated attacks. They begin with blind spots and gaps in understanding that attackers can exploit. Orphaned applications increase exposure because they lack active ownership and routine security review. For example, a forgotten project management app might still be connected to production systems, but because it’s faded from memory, it falls out of routine security checks. If IT is unaware it’s there, it cannot patch it, review permissions, or validate compliance.
As apps lose owners, related service accounts and API tokens often become orphaned as well. These credentials continue to authorize activity, creating unmonitored access paths that attackers can exploit. As a result, they become ideal entry points for credential stuffing and lateral movement, allowing attackers to pivot into the core network. Common risk patterns include:
Dormant accounts and credentials that remain valid: User accounts, service identities, and tokens tied to abandoned applications may not be reviewed or revoked, creating authorization paths that no one is actively tracking. Outdated configurations and dependencies: Orphaned applications may continue running older libraries, frameworks, or integrations that no longer meet current security or compliance standards. Extended attacker dwell time: Systems without active monitoring may not trigger alerts, allowing threat actors to maintain ongoing access without being detected. From blind spots to insight
Addressing orphaned applications starts with finding them. The Omnis AI Insights solution organizes NETSCOUT’s packet-derived Smart Data into curated and customizable datasets that integrate with platforms such as Splunk and ServiceNow to reduce shadow IT–related blind spots. This insight exposes hidden dependencies and identifies operational and security risks, while giving IT and business teams a shared view of what is active in the environment today to support better planning and more informed decisions.
Download this fact sheet to see how NETSCOUT Smart Data enriches the ServiceNow CMDB and exposes shadow IT.

View the full article
Notepad++ creator Don Ho said the macOS version of the popular Windows code editor is fake and using the Notepad++ trademark without permission.

The unofficial Notepad++ app for macOS
In a blog post, Ho said the macOS app is "not authorized, not endorsed, and not affiliated with" the official version of Notepad++ in any way, adding that it is "misleading, inappropriate, and frankly disrespectful to both the project and its users."

In coordination with Ho, the developer of the macOS port Andrey Letov said he will rebrand the Mac app and its corresponding website in the coming days:Notepad++ has been one of the most popular text and code editors on Windows for more than 20 years, and many users have long hoped for a Mac version. It appears the unofficial port will live on for now, but with a new name and branding.

Emphasis on unofficial.

"To be crystal clear: Notepad++ has never released a macOS version," said Ho.
This article, "Notepad++ Creator Calls Out 'Fake' Mac App Over Trademark Violation" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
iOS 26.5 is expected to be released this May, following more than a month of beta testing. The update is relatively minor so far, which is not too surprising given that Apple is starting to shift its focus towards iOS 27.


iOS 26.5 lays the groundwork for end-to-end encryption for RCS in the Messages app and ads in the Apple Maps app, and it will include a new Pride wallpaper and a few other changes. Below, we outline all of the notable additions in iOS 26.5.

End-to-End Encryption for RCS


End-to-end encryption for ‌RCS‌ is a security feature that ensures that messages sent between supported iOS 26.5 and Android devices are encrypted and cannot be intercepted and read by a third party while they are being delivered.

Apple already tested end-to-end encryption for RCS in the iOS 26.4 beta, but the feature did not make it into the final release of iOS 26.4 in March. The option returned in the iOS 26.5 beta, but it remains to be seen if it makes it into the final release.

Ads and "Suggested Places" in Apple Maps


In March, Apple announced that localized ads are coming to the Apple Maps app on the iPhone and iPad in the U.S. and Canada starting "this summer," and there is evidence of Apple preparing for that within iOS 26.5's code.

Apple says businesses in the U.S. and Canada will be able to place local ads in search results and at the top of a new "Suggested Places" section.

"Ads on Maps will appear when users search in Maps, and can appear at the top of a user's search results based on relevance, as well as at the top of a new Suggested Places experience in Maps, which will display recommendations based on what's trending nearby, the user's recent searches, and more," says Apple.

Similar to the ads that are already shown in App Store search results on the iPhone and iPad, ads in Apple Maps will have an "Ad" label, and Apple promises strong privacy protections. For example, Apple says a user's location and the ads they see and interact with in Apple Maps are not associated with a user's Apple Account.

New Pride Wallpaper


Alongside the new Pride Edition Sport Loop and Pride Luminance watch face for the Apple Watch, iOS 26.5 will include a matching iPhone wallpaper.

Apple said the wallpaper features a "joyful, vibrant design to celebrate LGBTQ+ communities worldwide during Pride Month and beyond."

The wallpaper has a dynamic design with customizable colors.

More

In the iOS 26.5 beta, Apple is also working to extend iPhone features like notifications, Live Activities, and AirPods-like pairing to third-party smartwatches and headphones in the EU, as required under the Digital Markets Act.

Beyond that, iOS 26.5 has only a few other minor changes.Related Roundups: iOS 26, iPadOS 26Related Forum: iOS 26
This article, "iOS 26.5 Coming Soon With These New Features" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
This week, the shadows moved faster than the patches. While most teams were still triaging last month’s alerts, attackers had already turned control panels into kill switches, kernels into open doors, and open-source pipelines into silent delivery systems. The game has shifted from breach to occupation. They’re living inside SaaS sessions, pushing code with trusted commits, and scalingView the full article
Amazon today has expanded its sale on the M4 iPad Air with new all-time low prices on a handful of models. This includes both 11-inch and 13-inch models of the brand new 2026 M4 iPad Air.

Note: MacRumors is an affiliate partner with Amazon. When you click a link and make a purchase, we may receive a small payment, which helps us keep the site running.

Specifically, the 128GB Wi-Fi 11-inch M4 iPad Air has dropped to $519.99, down from $599.00, beating the previous low price by about $40. You'll also find new low prices on the 256GB Wi-Fi 11-inch model and 256GB Wi-Fi 13-inch model, both of which we're only tracking on Amazon.

$79 OFF11-inch M4 iPad Air (128GB Wi-Fi) for $519.99
$89 OFF11-inch M4 iPad Air (256GB Wi-Fi) for $609.99
$109 OFF13-inch M4 iPad Air (256GB Wi-Fi) for $789.99

The new iPad Air features the M4 chip, C1X modem, and N1 networking chip, which brings support for Wi-Fi 7 and Bluetooth 6. In terms of design, the 2026 models are identical to the 2025 iPad Air tablets, with an edge-to-edge display, slim bezels, and aluminum chassis.

If you're on the hunt for more discounts, be sure to visit our Apple Deals roundup where we recap the best Apple-related bargains of the past week.



Deals Newsletter

Interested in hearing more about the best deals you can find in 2026? Sign up for our Deals Newsletter and we'll keep you updated so you don't miss the biggest deals of the season!




Related Roundup: Apple Deals
This article, "M4 iPad Air Hits New Low Prices on Amazon, Available From $519.99" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Apple today introduced its 2026 Pride Collection, including a new Apple Watch band, watch face, and a matching wallpaper for the iPhone and iPad.


Apple said its Pride Collection celebrates LGBTQ+ communities around the world during Pride Month in June and beyond. In addition, the company noted that it is proud to financially support organizations that serve LGBTQ+ communities.

The new Pride Edition Sport Loop is available to order now on Apple.com and in the Apple Store app in 40mm, 42mm, and 46mm sizes, and it will be available at Apple Store locations starting later this week. In the U.S., the band costs $49.

The band is woven from a rainbow of 11 colors of nylon yarns.

"The intricate weaving blends one color into the next, creating depth and movement across the band," said Apple. "The resulting design is joyful and vibrant, showcasing a full spectrum of colors that reflect the unique identities that shape LGBTQ+ communities worldwide."

There is also a new Pride Luminance watch face for the Apple Watch, and a matching Pride Luminance wallpaper for the iPhone and iPad. The watch face and wallpaper will be available on watchOS 26.5, iOS 26.5, and iPadOS 26.5, which are currently in beta and expected to be released to all users this month.


Apple said the Pride Luminance watch face is designed in two geometric patterns: radial, featuring rays of color that align with the hour marks, and vertical, reflecting the colorful linear stripes of the new Pride Edition Sport Loop.

Both the Pride Luminance watch face and wallpaper feature customizable colors.Related Roundup: Apple Watch 11Tag: PrideBuyer's Guide: Apple Watch (Neutral)
This article, "Apple Announces 2026 Pride Band, Watch Face, and iPhone Wallpaper" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
For watchOS 27, Apple is testing new Apple Watch faces, and one of them is a simpler version of an existing Apple Watch Ultra watch face that could be coming to standard Series models.


Writing in his latest Power On newsletter, Bloomberg's Mark Gurman reports that Apple is testing multiple new faces for watchOS 27, code-named "Orchid." One of them is said to be a "simplified take" on the Modular Ultra design.

From the report:Gurman believes the new face is an attempt to bring the Ultra look to the standard Series watches in a way that dials down the density while still offering more at-a-glance information.

In its current form, the Modular Ultra offers seven complications and six options for the size and layout of the time. With the training bezels providing Vitals and training load, it's arguably the most info-dense face there is.

Separately, Gurman reported last week that watchOS 26.5 will include a new Pride Luminance watch face, with the update expected to drop this month.

Related Roundups: Apple Watch 11, watchOS 26Tags: Bloomberg, Mark GurmanBuyer's Guide: Apple Watch (Neutral)Related Forum: Apple Watch
This article, "watchOS 27 to Offer New Watch Faces, Including 'Modular Ultra' Variant" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
On December 4, 2025, a 17-year-old was arrested in Osaka under Japan’s Unauthorized Access Prohibition Act. The young man had run malicious code to extract the personal data of over 7 million users of Kaikatsu Club, Japan's largest internet cafe chain. When asked, the young man shared his motivation for the hack: he wanted to buy Pokémon cards. In a sense, this is a fairly conventional story.View the full article
The China-based cybercrime group known as Silver Fox has been linked to a new campaign targeting organizations in Russia and India with a new malware called ABCDoor. The activity involved using phishing emails that mimic correspondence from the Income Tax Department of India in December 2025, followed by a similar campaign aimed at Russian entities. "Both waves followed a nearly identicalView the full article
With prompt injection and other attack pathways consistently surfacing across agentic AI deployments, security watchdogs have stepped in, collectively, to draw some hard boundaries.
A joint advisory from the US Cybersecurity and Infrastructure Security Agency (CISA) and international partners has called for tighter control over permissions, stronger monitoring, and a more deliberate rollout strategy, urging organizations to treat agentic AI with caution.
“Organizations cannot just drop agents into production and hope the guardrails hold,” said Piyush Sharma, CEO and co-founder of Tuskira, agreeing with CISA’s instructions. “They need to understand what each agent can access, how it behaves, what systems trust its outputs, and which attack paths become reachable if it is manipulated.”
The advisory outlined design and development guidelines for organizations to follow before the implementation of AI agents. A few of these included strong authentication using Secure by Design principles, system transparency to flag deceptive indicators, least privilege across workflows, secure development principles as per DevSecOps fundamentals, and regular testing of incident response plans, among a host of others.
The advisory was co-authored by the Australian Signals Directorate’s Australian Cyber Security Centre, Canadian Centre for Cyber Security, New Zealand’s National Cyber Security Centre, and the UK’s National Cyber Security Centre.
Least privilege and tight boundaries
One of the clearest through-lines in the advisory was the need to constrain what agentic AI can access.
“Privilege risks are a key concern for agentic AI, and strict adherence to the principle of least privilege is critical,” CISA said in the advisory. “Privileges assigned to agents directly determine the level of risk they can introduce. Poor management of privileges can expose organisations to privilege compromise, scope creep, identity spoofing, and agent impersonation.”
The agencies emphasized enforcing least-privilege principles, isolating agent capabilities, and rigorously defining what data, tools, and systems each agent can interact with.
This is easier said than done, especially as agents are increasingly wired into APIs, internal systems, and external services. “Every tool, data source, memory store, and permission an agent touches becomes another possible way in for attackers,” Sharma noted.
To tackle this, the advisory recommends organizations maintain a clear inventory of agent capabilities and dependencies, while also validating how agents interpret and act on inputs. This includes guarding against prompt injection and ensuring that agents don’t blindly trust external content or instructions.
Continuous monitoring with human-in-the-loop control
While the first half of the advisory focused on limiting what agents can do, the second was about watching what they actually do, reacting quickly when things go sideways.
“Operators should implement continuous monitoring and auditing to maintain awareness of AI agent operation and ensure traceability for decisions and actions,” CISA added. “Continuous auditing processes improve security measures and ensure alignment with governance standards (such as risk management, oversight, and usage restrictions).”
CISA and its international partners also recommended integrating human control and oversight into agentic AI workflows to ensure they are approved for non-sensitive, low-risk tasks. For this, the agencies suggested live monitoring during task execution, human approval for decision-making steps, and auditing upon task execution.
Experts agree that visibility is critical. “Security teams need continuous visibility into how agents behave, what systems they touch, and when their actions deviate from expected patterns,” said Nick Tausek, Lead Security Automation Architect at Swimlane. “Building human approval into high-risk workflows and automating containment is paramount for taking action when agent behavior crosses a line.”
Putting it all together, the advisory detailed core risk areas, from prompt injection and data exposure to tool misuse and privilege creep, urging organizations to lock down privileged access, validate inputs and outputs, monitor agent behavior, and tightly control how these systems interact with data, tools, and other services.
View the full article
Introduction
The transition from traditional IT spending to cloud consumption has fundamentally changed how organizations manage their finances. The Certified FinOps Architect is a senior-level credential designed for those who bridge the gap between engineering, finance, and business leadership. This guide is curated for professionals navigating the complexities of cloud-native environments where cost efficiency is as critical as system performance. By focusing on the intersection of DevOps and financial accountability, this program ensures that platform engineering remains sustainable and profitable. Choosing the right path at finopsschool allows engineers to transition from technical execution to strategic cloud value management.
What is the Certified FinOps Architect?
The Certified FinOps Architect represents the pinnacle of cloud financial management expertise, focusing on the architectural decisions that drive long-term cost efficiency. Unlike entry-level certifications that focus on terminology, this program emphasizes production-focused strategies for building and scaling cloud infrastructure. It exists to solve the “bill shock” problem by embedding financial awareness directly into the engineering workflow and architectural design. By aligning modern engineering practices like CI/CD and infrastructure-as-code with financial guardrails, it enables enterprises to maintain agility without sacrificing their margins.
Who Should Pursue Certified FinOps Architect?
This certification is specifically designed for senior engineers, cloud architects, and SREs who have a direct impact on infrastructure spend. Engineering managers and technical leaders who need to justify cloud budgets to stakeholders will find immense value in the strategic frameworks provided here. In the Indian market and global tech hubs, companies are increasingly looking for professionals who can optimize multi-cloud environments across AWS, Azure, and Google Cloud. Even data and security professionals are finding this certification relevant as they manage high-scale, resource-intensive workloads that require precise financial governance.
Why Certified FinOps Architect is Valuable in Beyond
In the current era of enterprise cloud adoption, the demand for professionals who understand the unit economics of the cloud is reaching an all-time high. This certification provides longevity because it focuses on principles and cultural shifts rather than just specific tool features that may change over time. It helps professionals stay relevant by teaching them how to communicate technical debt and architectural choices in the language of business value. The return on career investment is significant, as organizations prioritize candidates who can demonstrate a direct contribution to the company’s bottom line.
Certified FinOps Architect Certification Overview
The program is delivered via the official platform and is formally hosted on the official website. It follows a rigorous assessment approach that evaluates a candidate’s ability to apply FinOps principles to complex, real-world architectural scenarios. The ownership of the program lies with industry experts who ensure the content stays updated with the latest trends in cloud governance and automated cost optimization. Structurally, the certification moves beyond theoretical exams into practical application, ensuring that an architect can actually lead a FinOps transformation within a large enterprise.
Certified FinOps Architect Certification Tracks & Levels
The certification hierarchy begins with a foundation level that introduces core concepts and the lifecycle of Inform, Optimize, and Operate. The professional level deepens this knowledge by focusing on policy automation and advanced reporting for multi-cloud and containerized environments. Finally, the advanced architect level challenges candidates to design organizational-wide frameworks for cloud financial management. This progression ensures that a professional can grow their skills alongside their career responsibilities, moving from individual contributor roles to leadership positions.
Complete Certified FinOps Architect Certification Table
TrackLevelWho it’s forPrerequisitesSkills CoveredRecommended OrderCore FinOpsFoundationBeginners and Non-Technical StaffBasic Cloud LiteracyFinOps Principles, Lifecycle, PersonasFirstEngineeringProfessionalSREs, DevOps, Platform EngineersFoundation CertificationTagging, Automation, RightsizingSecondArchitectureAdvancedSolutions Architects, CTOs, LeadsProfessional CertificationUnit Economics, Governance, Multi-cloudThirdSpecializedExpertFinOps Practice Leads5+ Years ExperienceChange Management, Executive ReportingFinal Detailed Guide for Each Certified FinOps Architect Certification
Certified FinOps Architect – Foundation
What it is
This certification validates a candidate’s understanding of the basic terminology and the cultural shifts required to implement FinOps. It serves as the baseline for all subsequent specialized training.
Who should take it
Entry-level cloud engineers, finance professionals, and procurement teams who interact with cloud billing and resource management daily.
Skills you’ll gain
Understanding the three phases of the FinOps lifecycle. Identifying the different personas involved in cloud financial management. Learning the basic metrics for cloud cost reporting. Real-world projects you should be able to do
Create a basic cloud cost visibility dashboard. Perform a simple audit of unused cloud resources. Preparation plan
7-14 Days: Review the official glossary and attend introductory webinars. 30 Days: Complete the self-paced foundation course and practice mock exams. 60 Days: Engage in community forums to understand common implementation challenges. Common mistakes
Focusing only on cost cutting rather than value realization. Ignoring the cultural aspect of cross-departmental collaboration. Best next certification after this
Same-track option: Certified FinOps Professional Cross-track option: Cloud Practitioner (AWS/Azure/GCP) Leadership option: FinOps Certified Professional Certified FinOps Architect – Professional
What it is
This certification validates the ability to implement technical solutions for cost optimization and automated governance. It focuses on the “how” of engineering financial accountability.
Who should take it
Cloud engineers and DevOps practitioners who are responsible for infrastructure deployment and resource scaling.
Skills you’ll gain
Developing automated scripts for resource rightsizing. Implementing advanced tagging and labeling strategies. Managing costs in Kubernetes and containerized environments. Real-world projects you should be able to do
Build an automated “stop-start” schedule for non-production environments. Implement a showback/chargeback system for different engineering teams. Preparation plan
7-14 Days: Focus on technical documentation for cloud pricing APIs. 30 Days: Set up a sandbox environment to test cost-optimization scripts. 60 Days: Deep dive into case studies involving large-scale cloud migrations. Common mistakes
Over-automating without setting proper safety guardrails. Failing to account for the performance impact of rightsizing. Best next certification after this
Same-track option: Certified FinOps Architect Cross-track option: SRE Professional Leadership option: IT Financial Management Professional Certified FinOps Architect – Advanced Architect
What it is
This is the highest level of certification, focusing on the strategic design of a cloud financial management office. It validates leadership in architectural governance.
Who should take it
Principal architects, lead engineers, and technology executives who define the cloud strategy for their entire organization.
Skills you’ll gain
Designing a multi-cloud financial governance framework. Calculating unit economics for complex microservices architectures. Leading organizational change management for FinOps adoption. Real-world projects you should be able to do
Create a 3-year cloud financial roadmap for an enterprise. Design a centralized governance policy that balances speed and cost. Preparation plan
7-14 Days: Study executive-level reporting and business financial metrics. 30 Days: Review complex architectural patterns for cost-efficient cloud designs. 60 Days: Conduct a mock organizational audit and gap analysis. Common mistakes
Getting lost in technical details while ignoring business objectives. Failing to secure executive buy-in for FinOps initiatives. Best next certification after this
Same-track option: Master FinOps Practitioner Cross-track option: CTO/Engineering Leadership Certification Leadership option: MBA or Business Strategy certificates Choose Your Learning Path
DevOps Path
The DevOps path focuses on integrating financial feedback loops directly into the CI/CD pipeline. Professionals here learn to treat cost as a first-class metric alongside performance and reliability. By mastering FinOps, DevOps engineers can ensure that every code deployment is evaluated for its financial impact before it hits production. This path leads to a more mature “You Build It, You Run It, You Pay For It” culture.
DevSecOps Path
The DevSecOps path emphasizes the intersection of security, compliance, and cost management. Security tools and logging can often become significant cost drivers, and this path teaches how to optimize those resources. Professionals learn to balance the cost of data retention with regulatory requirements and security posture. It ensures that being secure does not mean being financially inefficient or over-provisioned.
SRE Path
The SRE path focuses on the relationship between reliability, error budgets, and cloud spending. Site Reliability Engineers use FinOps to determine the point of diminishing returns when investing in high availability. This path teaches how to manage the trade-offs between system uptime and the cost of redundancy. SREs gain the skills to justify infrastructure investments based on service level objectives and financial data.
AIOps Path
The AIOps path explores how machine learning can be used to predict cloud spending and automate anomalies detection. Professionals in this track learn to use AI-driven tools to identify patterns in resource usage that humans might miss. This path is essential for organizations dealing with massive scales where manual intervention is impossible. It bridges the gap between proactive maintenance and predictive financial modeling.
MLOps Path
The MLOps path specifically addresses the high costs associated with training and deploying machine learning models. Professionals learn to optimize GPU usage and manage the expensive storage requirements of large datasets. This track ensures that data science projects remain economically viable from research to production. It focuses on the specific unit economics of compute-heavy artificial intelligence workloads.
DataOps Path
The DataOps path concentrates on the financial management of data pipelines, warehouses, and analytical platforms. Data engineers learn how to optimize query performance to reduce costs in platforms like Snowflake or BigQuery. This path teaches how to manage data lifecycle policies to ensure that storage costs do not grow exponentially. It is vital for organizations that treat data as a core product and need to manage its overhead.
FinOps Path
The dedicated FinOps path is for those moving into specialized Cloud Financial Management roles. This path covers the full spectrum of the discipline, from technical implementation to procurement and executive reporting. It is ideal for individuals who want to lead a FinOps Center of Excellence. This track provides a comprehensive view of how to drive cloud value across the entire enterprise ecosystem.
Role → Recommended Certified FinOps Architect Certifications
RoleRecommended CertificationsDevOps EngineerFinOps Foundation, FinOps ProfessionalSREFinOps Professional, FinOps ArchitectPlatform EngineerFinOps Foundation, FinOps ProfessionalCloud EngineerFinOps Foundation, FinOps ProfessionalSecurity EngineerFinOps Foundation, DevSecOps SpecialistData EngineerFinOps Foundation, DataOps SpecialistFinOps PractitionerFinOps Foundation, Professional, and ArchitectEngineering ManagerFinOps Foundation, FinOps Architect Next Certifications to Take After Certified FinOps Architect
Same Track Progression
For those looking to go even deeper into the financial domain, pursuing specialized courses in cloud procurement and vendor management is the logical next step. Deep specialization allows a professional to become a subject matter expert in niche areas like Reserved Instance (RI) and Savings Plan (SP) portfolio management. This path is suitable for those who want to be the primary authority on cloud economics within their organization.
Cross-Track Expansion
Expanding into SRE or Platform Engineering certifications helps a FinOps professional understand the technical constraints that lead to certain cost profiles. By broadening your skills, you can better empathize with engineering teams and provide more practical optimization advice. This cross-pollination of skills makes you a more versatile leader who can bridge the gap between finance and engineering effectively.
Leadership & Management Track
Transitioning into leadership requires a shift from technical execution to organizational strategy and people management. Certifications in ITIL, PMP, or general engineering leadership complement the Certified FinOps Architect by providing the soft skills needed for large-scale transformation. This track is designed for those aiming for roles like Director of Infrastructure, VP of Cloud, or Chief Technology Officer.
Training & Certification Support Providers for Certified FinOps Architect
DevOpsSchool
DevOpsSchool provides a robust ecosystem for professionals looking to master the intricacies of cloud financial management through hands-on labs and instructor-led training. Their curriculum is designed to bridge the gap between theoretical knowledge and practical application, ensuring that students can handle real-world infrastructure challenges. With a focus on the latest industry trends, they offer comprehensive support for various cloud platforms and automation tools. The platform is well-regarded for its community-driven approach and its commitment to helping engineers advance their careers through continuous learning and expert mentorship.
Cotocus
Cotocus stands out as a specialized provider that focuses on high-end technical training for modern engineering roles. They offer deep dives into FinOps and SRE practices, providing participants with the tools needed to optimize complex cloud environments effectively. Their training modules are crafted by industry veterans who bring years of experience into the classroom setting. By emphasizing a results-oriented learning path, Cotocus ensures that their graduates are ready to contribute to enterprise-level projects immediately. Their focus on emerging technologies makes them a preferred choice for professionals looking to stay ahead of the curve.
Scmgalaxy
Scmgalaxy is a well-established platform that serves as a central hub for configuration management and DevOps resources. They offer a wide range of training programs that include specialized tracks for cloud financial management and governance. The platform is known for its extensive library of tutorials, webinars, and practical guides that support self-paced learning. Scmgalaxy emphasizes the importance of community interaction, allowing learners to connect with experts and peers from around the world. Their certifications are designed to validate a professional’s ability to manage software delivery pipelines with a focus on efficiency and cost-effectiveness.
BestDevOps
BestDevOps focuses on providing streamlined and efficient training paths for busy professionals who need to acquire new skills quickly. Their courses are structured to deliver maximum value in a concise format, focusing on the most critical aspects of cloud operations and FinOps. They provide a balance of video content, practical assignments, and assessment tools to ensure a well-rounded learning experience. The platform is particularly popular among those looking for certification preparation that is both rigorous and accessible. BestDevOps prides itself on its high success rate and its ability to help engineers transition into more senior roles.
devsecopsschool.com
This provider specializes in the intersection of security and operations, offering a unique perspective on how FinOps integrates with a secure development lifecycle. Their training programs emphasize the financial impact of security decisions and provide strategies for building cost-efficient, secure infrastructure. With a global reach, they cater to a diverse audience of engineers and security professionals. The curriculum is updated regularly to reflect the evolving landscape of cloud security and compliance. Students benefit from expert guidance and a wealth of practical resources that help them implement DevSecOps principles in a financially responsible manner.
sreschool.com
Sreschool.com is dedicated to the discipline of Site Reliability Engineering and its fundamental connection to cloud financial management. Their courses teach engineers how to manage reliability and cost as twin objectives, using data-driven approaches to optimize system performance. The platform offers a variety of learning formats, including interactive workshops and detailed case studies. By focusing on the practical challenges faced by SREs in large-scale environments, they prepare their students for leadership roles in platform engineering. Their commitment to excellence has made them a trusted partner for organizations looking to upskill their engineering teams.
aiopsschool.com
Aiopsschool.com provides cutting-edge training on the application of artificial intelligence to IT operations and financial management. Their programs explore how machine learning can be leveraged to automate cost optimization and detect spending anomalies in real-time. This specialized focus is ideal for professionals working in high-scale environments where traditional management methods are no longer sufficient. The curriculum covers a range of AI and ML tools, providing students with the technical skills needed to build intelligent infrastructure. Aiopsschool.com is at the forefront of the industry, helping engineers navigate the future of automated cloud governance.
dataopsschool.com
This provider focuses on the specific challenges of managing data pipelines and analytical platforms with a FinOps mindset. Their training programs are designed for data engineers and architects who need to optimize the cost and performance of their data infrastructure. The curriculum covers everything from data lifecycle management to the financial governance of cloud-native data warehouses. By providing practical tools and frameworks, they help professionals ensure that their data initiatives are both scalable and economically sustainable. Dataopsschool.com is a vital resource for any organization that relies on data-driven decision-making.
finopsschool.com
As the primary host for the Certified FinOps Architect program, finopsschool.com offers a specialized and authoritative learning environment. Their focus is entirely on the discipline of cloud financial management, providing a comprehensive range of certifications for all experience levels. The platform is backed by a network of experts who define the standards for FinOps across the industry. With a focus on real-world application and architectural governance, they provide the most direct path to becoming a certified expert in the field. Finopsschool.com is the go-to destination for anyone serious about a career in FinOps.
Frequently Asked Questions (General)
What is the typical difficulty level of the Architect certification?
The Architect certification is considered advanced and requires a deep understanding of both technical infrastructure and business finance. How long does it take to prepare for the exam?
Most professionals spend between 30 to 60 days preparing, depending on their existing experience with cloud billing and architecture. Are there any mandatory prerequisites?
While not always strictly enforced, having a Foundation or Professional level certification is highly recommended before attempting the Architect level. What is the career ROI for this certification?
Professionals often see increased salary potential and opportunities for leadership roles as organizations prioritize cloud cost efficiency. Is the exam proctored or open-book?The assessment approach typically involves a proctored environment to ensure the integrity and value of the credential. Does this certification cover multiple cloud providers?
Yes, the principles taught are cloud-agnostic and applicable to AWS, Azure, Google Cloud, and even hybrid environments. How often do I need to recertify?
Certifications generally require renewal every two to three years to ensure you are up to date with the latest industry practices. Can a non-technical manager pass this exam?
It is possible, but the Architect level requires a significant amount of technical knowledge regarding cloud infrastructure and automation. What resources are provided for exam preparation?
Candidates usually receive access to official study guides, practice exams, and community forums. Is there a focus on containerization and Kubernetes?
Yes, modern FinOps practices heavily emphasize managing costs within dynamic containerized environments. How does this differ from a standard Cloud Architect certification?
A standard architect certification focuses on performance and availability, while the FinOps Architect adds a critical layer of financial accountability. Is this certification recognized globally?
Yes, it is a standard credential recognized by major enterprises and consulting firms worldwide. FAQs on Certified FinOps Architect
What specific architectural patterns are covered?
The program focuses on patterns like multi-cloud governance, serverless cost optimization, and tiered storage strategies. Does it include hands-on lab work?
Yes, practical labs are often included to simulate real-world cost optimization scenarios in a safe environment. How does it address unit economics?
It teaches how to map cloud costs to business metrics, such as cost per transaction or cost per customer. Is there a focus on automated governance?
Yes, learning to implement policy-as-code to prevent cost overruns is a core component of the program. Does the curriculum include change management?
The Architect level places a strong emphasis on the cultural shifts needed to drive FinOps adoption across an organization. What role does tagging play in the curriculum?
Advanced tagging and resource allocation strategies are treated as the foundation for all financial reporting and accountability. How are multi-cloud environments managed?
The program provides frameworks for normalizing cost data across different providers to create a unified financial view. Are real-world case studies used in the training?
Yes, candidates analyze successful (and unsuccessful) FinOps implementations at large-scale enterprises. Final Thoughts: Is Certified FinOps Architect Worth It?
The transition to cloud-native operations is no longer just about speed; it is about sustainability. The Certified FinOps Architect is one of the few credentials that directly addresses the economic reality of modern engineering. If you are an engineer looking to move into a high-impact leadership role, or a manager trying to bring order to your cloud spend, this certification is a highly practical investment. It moves you away from “guessing” about costs toward a disciplined, data-driven approach to architectural value. In a competitive market, being the person who can balance high-performance engineering with financial health makes you indispensable. This is not about saving money; it is about making sure every dollar spent on the cloud is driving maximum business value.
View the full article
A previously unknown threat actor has been observed targeting government and military entities in Southeast Asia, alongside a smaller cluster of managed service providers (MSPs) and hosting providers in the Philippines, Laos, Canada, South Africa, and the U.S., by exploiting the recently disclosed vulnerability in cPanel. The activity, detected by Ctrl-Alt-Intel on May 2, 2026, involves theView the full article
Hiring fake IT workers has been a growing problem in recent years — but it’s often a problem very few want to admit to. From Fortune 500 companies down to smaller organizations, remote hiring practices have been exploited to grant trusted access to individuals who are not who they claim to be creating an insider threat risk.
Estimates suggest there are thousands of fake IT workers operating across the US who are in a position to steal information, IP and data, outsource work offshore, carry out sabotage, or funnel money to foreign governments.
Amazon has identified and blocked more than 1,800 attempts by North Korea to secure IT roles — and the numbers are rising, according to its chief security officer, Steve Schmidt.
In some cases, individuals impersonate US employees for personal gain; in others, state-based operatives such as those from North Korean pose as IT workers for state financial gain and other nefarious purposes.
AI is now enabling deepfakes, more convincing video interviews, and rapid identity cycling.
Adversary tactics are also shifting, from fabricating profiles to purchasing legitimate American identities, Schmidt has warned.
“This is not a ‘recruiting scam’ in the traditional sense. It’s an insider-risk problem, where the adversary’s first move is to get hired,” says Tom Hegel, distinguished threat researcher at SentinelOne.
CIOs, CISOs, and other IT leaders need to be continually on guard against fake and fraudulent IT workers, but organizations can fall victim without realizing it.
How fake hires get through
There’s no single point of failure in the recruitment process. Fake and fraudulent IT workers conceal their identity, falsify their skills and experience, and move through interview and screening processes undetected.
SentinelOne has tracked roughly 360 fake personas and more than 1,000 job applications linked to North Korean IT worker operations, including attempts to apply for roles within the company itself.
According to Hegel, adversaries are increasingly deploying social engineering tactics and identity obfuscation at scale, and the hiring process is a prime entry point.
Synthetic or stolen identities are used to create resumes and online profiles; interviews are passed with the help of scripts, stand-ins, or AI-assisted responses; and background checks confirm only what’s presented to them.
“Fake job seekers now leverage AI tools to mimic legitimate candidates, creating synthetic identities that pass initial background checks, falsifying employment histories and even responding convincingly in interviews using real-time AI assistance,” Hegel says.
Flashpoint investigations have found malware-infected hosts containing HR and job-board logins, browser histories showing Google-translated coaching notes, remote-access “laptop farms” used to control corporate devices from overseas, and shell companies to prove reference checks for fabricated resumes.
Once they’re hired, credentials are issued, equipment is shipped, and access is granted — and they become a trusted insider. “The long-term risk isn’t just hiring a fake employee — it’s unknowingly opening your systems and sensitive data to malicious access,” he says.
What to do if you suspect a fake IT worker
When a CIO suspects a fake IT worker, next steps are important as the issue shifts from recruitment to insider risk management.
During his time at MongoDB, George Gerchow, IANS faculty advisor and Bedrock Data CSO, oversaw the investigation after the company detected it had unknowingly hired a North Korean IT worker.
It was first discovered after alerts that an individual was attempting to uninstall endpoint protections, including CrowdStrike Overwatch. “Overwatch then detected the laptop communicating with a North Korean IP address,” says Gerchow.
“That combination of tool tampering plus DPRK-linked traffic immediately signaled that this was not a typical new hire,” he tells CIO.
Mongo realized the fake worker used a stolen identity, paired with AI-generated resume content and scripted interview responses, to evade background checks that verify only the information provided and do not detect fraud.

It highlights a gap in many background checks. “They don’t detect fabricated work histories, synthetic identities, or recycled developer profiles, which is how this individual passed screening and interviews without raising formal flags,” he says.
The subsequent investigation found attempts to disable security tooling, establish persistence on the device, and probe for elevated access.
“Had they remained undetected, their access would have eventually expanded into our FedRAMP environment, which makes these fraud techniques especially high-risk,” Gerchow adds.
After the discovery, several yellow flags became obvious such as poor video quality and unclear visuals during interviews, a noticeably inconsistent accent between calls, and scattered interview feedback with no centralized review.


Another tell was a last-minute change to the laptop shipping address. “That’s a common shadow-worker tactic,” notes Gerchow.
With hindsight, Gerchow joined the dots and it became clear how the person had made it through to employment because any irregularities were treated in isolation.
“None of these individually would prevent a hire. However, because no one was responsible for aggregating subtle anomalies, the pattern wasn’t recognized until the endpoint alert fired,” he says.
When they were discovered, the team quickly isolated the device, revoked all credentials, conducted a full forensic investigation, and notified federal authorities. “We verified there was no data exfiltration or lateral movement,” he says.
The mitigation steps introduced included strengthening identity fraud screening in the hiring process, assigning a Yellow Flag owner to connect early signals, and enforcing zero access until trust is earned for new hires,

Gerchow also believes that behavioral telemetry post-hire is necessary, because behavior, not credentials, reveals impostors.
Mongo recommends organizations designate a reviewer in Security or HR to identify inconsistencies in the hiring process, such as poor video quality. “Also watch for AI-generated LinkedIn profiles, mismatched resumes and questionable changes in laptop shipping addresses,” he says.
“Use panel interviews and project-based evaluations to identify candidates who recycle stolen or fake developer identities, and start new hires without access to sensitive data or production environments,” he advises.
Then employ alerts if security agents (such IAM, EDR, VPN) are disabled before a new hire logs in, and test detection, escalation, and device recovery by simulating the hiring of a fake developer.
“And look for off-hours access, broad internal search activity and large-scale cloning of documents or code repositories,” he adds.
What IT leaders see on the inside
The problem of employment fraud is only expected to worsen, with Gartner predicting that one in four candidate profiles worldwide will be fake by 2028.
“The rise of fake and fraudulent job applicants has become an epidemic across organizations,” says David Weisong, CIO of Energy Solutions.
Weisong says attackers consistently target high-access technical roles such as DevOps, systems administrators, data engineers, and database administrators, where successful hires can gain deep visibility and control over core systems.
“These are the roles with the keys to the castle,” Weisong says. “If you’re trying to gain access, they’re far more valuable than a standard developer position.”
Operating in a regulated energy market, Energy Solutions is contractually required to employ a US-based workforce and keep data within US jurisdiction.
Weisong has first-hand experience with detecting fake IT workers and wants to share his advice with other IT leaders. One of the earliest warning signs was a sudden, abnormal surge in applications — hundreds arriving within hours, far out of proportion to the company’s brand profile, pointing to automated or coordinated activity.
During the interview stage, identity switching was observed. “We saw cases where one person passed the phone screen, a different person showed up on Zoom, and sometimes a third appeared later — all under the same name and resume,” Weisong says.
Part of the problem is that standard hiring practices validate information and skills in isolation. “Traditional background checks only verify the information provided and do not detect fraud,” Weisong also notes.
The uncomfortable reality for some CIOs is that the work may be completed to a high standard and detection comes from signals, not performance.
However, fake IT workers create business and compliance risk as much as security risk, exposing organizations to contractual breaches, regulatory consequences, and loss of client trust — particularly in regulated industries.
Weisong says fake IT workers create business and compliance risk as much as security risk, exposing organizations in regulated industries to contractual breaches, regulatory scrutiny, and loss of client trust.
Combating the problem of fake IT workers
Amazon is using AI-based tools with human oversight to identify unusual contact information, as well as fake academic institutions and companies in resumes, according to Schmidt. Security teams will flag LinkedIn profiles that look suspicious, require more in-person interviews and in-office attendance, monitor computer usage and quality of work, and authenticate with a physical token.
He has also said that IT and HR need to collaborate on hiring to combat the problem.
“It’s actually a lot cheaper for the HR organization if we discover the problem up front,” Amazon’s Schmidt told Fortune.
The shift required, says SentinelOne’s Hegel, is treating hiring decisions as an access control problem rather than a recruitment task. “Stop treating identity as a one-time HR checkbox and start treating remote hiring like you would grant privileged access,” he says.
In the wake of his experience, Weisong instituted a raft of changes to its applicant tracking system and across the organization’s internal systems and processes.
When advertising for positions, they make it clear that candidates applying for technical positions understand the expectations and consequences outlined in all written communication. “Additionally, removing the term ‘fully remote’ from our hiring practices has significantly reduced opportunities for fraud and for applicants applying from outside the US,” he says.
“While a ‘zero-trust’ approach would be ideal for all hiring, we cannot allow it to impede the process or discourage legitimate candidates from applying. Instead, we need sufficient countermeasures to prevent automated and fraudulent applicants from reaching the pipeline in the first place,” he adds.
To control the large volume of applications, many of which are bots, Energy Solutions job listings now have strict CAPTCHA settings, referral bonuses help draw on employee networks, and there’s a 90-day satisfactory performance review for new hires.
During the screening process, interviews are conducted via video not phone, and applicants must share their screen for live challenges. A post-video interview report allows them to verify the exact location of applicants after screening and interview meetings. If a candidate is outside the US, it’s treated as a Yellow/Red flag.
Applicants must select which office they want to work from and they must acknowledge they understand use of AI during interviews will result in disqualification.
To verify references and employment history, they require two references, with one a former supervisor or manager. Employment history is checked, including previous employers, and full home address must be provided.
To guard access, a question has been added to the job kick-off form that indicates whether a new role will have elevated access to confidential or sensitive information.
The first day on the job requires new hires to come into an office to pick up equipment and undertake training and onboarding. All roles must be onsite, with the option to go hybrid after satisfactory performance.
Combating the problem, says Weisong, requires reviewing hiring processes, partnering closely with HR, and monitoring the effectiveness of each countermeasure. For CIOs, the lesson is not that hiring is broken, but that trust must be earned progressively.
View the full article
Every CISO eventually faces the same tension: You know your security program needs to mature, but the budget and headcount to do it all aren’t there. That tension is especially sharp when it comes to data security posture management (DSPM).
Not every organization can afford, or even needs, the gold standard of DSPM deployment. Full-featured platforms can require anywhere from 1 to 3 dedicated FTEs to maintain, a cost that’s well within bounds for a large bank but potentially prohibitive for a mid-size or smaller technology firm. But the underlying principles of DSPM, such as verifying where your sensitive data lives, quantifying its value and using that information to inform decisions, should be used by every security leader, with or without a dedicated tool.
What DSPM does, and why the thinking matters more than the tool
In their simplest form, DSPM platforms scan an organization’s environment and use a series of classifiers to identify where sensitive information lives, check compliance and surface potential exposures. More advanced implementations connect with Data Leakage Prevention (DLP) tools to enforce these rules, and some can even infer new datatypes or labels, or apply them automatically.
If you are a payment processor, you’ll be well acquainted with PCI standards on the storage of credit card numbers, or similarly, PHI storage standards in the healthcare industry. DSPM tools raise exceptions to ensure you comply with these rules and allow you to document exceptions or risk acceptances within the platform. Addressing these exceptions requires a process involving both Information Security, Information Technology and data owners. 
Even if a dedicated DSPM platform isn’t in your budget, the core exercise is the same: Gain visibility into your organization’s data so you can make better business cases around security investments for the systems and environments under your remit.
Applying the principles at any maturity level
Whether you’re working with a full DSPM platform, a lightweight open-source scanner or even manual data inventories, CISOs can use this thinking to apply quantification (or at least an order of magnitude) to risk decisions. For example, you may have a written policy in place that a database can store up to “restricted” records – some of your organization’s most sensitive data. An operations team may want to attach a workflow automation tool to that database to allow them to service customer requests faster. A DSPM mindset helps you answer the questions that drive associated decisions.
DSPM can answer how many records are contained in a database, and coupled with cyber risk quantification, can help you estimate the financial exposure that would be if they were all compromised. It will tell you which data is “restricted” or “confidential,” and which records are subject to additional regulation. Finally, you can use it to understand how many users or roles can access the database, and help you apply a more limited role, add security monitoring or alerting, and add human touchpoints to autonomous workflows.
If this seems too fundamental, you may already be in a highly mature or regulated environment.  But elsewhere, and especially down market, there are lots of edge cases and grey areas that this kind of analysis helps inform. Crucially, it helps us move from binary labels and all-or-nothing decisions to quantified, accepted and mitigated risk.
Scaling the approach to bigger decisions
Let’s take this up a level, and this time, consider your entire security architecture. You have 15 “restricted” repositories. A critical remote code execution vulnerability is released, which affects eight of them, and your team moves into incident response mode. Which ones do you prioritize for patching with IT operations and forensic analysis? Pick the one with the most sensitive records (weighed against compensating controls), and thus, value at risk. You don’t need a six-figure platform to make that call, but you do need to have done the work of understanding where your most sensitive data sits. 
What if you inherit the same architecture from an M&A transaction? Let’s also assume that the new acquisition had a single IT staff member and no dedicated security staff, and you raised concerns about this during diligence. You are granted a budget for only one additional security engineer as part of the transaction. How do you prioritize their focus for security integrations such as central alert consolidation, log forwarding to your SIEM and detection engineering? Again, lean towards the systems with the most value at risk, informed by whichever data inventory or DSPM capability you have available to you.
Even without these urgent scenarios, DSPM thinking should increasingly inform your IAM posture in 2026. The lowest common denominator for compliance-driven access reviews is anchored on users (not roles, or non-human identities) and incentivizes binary decision-making. Further, there is an extreme disincentive to pick anything besides “maintain access.” I’d argue that DSPM and the associated mindset should be informing permission levels around your riskiest systems and driving decisions on how to reduce them. This can include creating newer, more limited roles or introducing time-bound access. Conducting access reviews without a source of truth or based solely on what is supposed to be happening is, at best, guesswork, and at worst, negligent.
Why this is more urgent now, and what to watch for
There is still real incentive for organizations to place their proverbial head in the sand when it comes to data security posture; an oversimplified thought process being that if they weren’t aware of it, they couldn’t be held liable. But that posture is increasingly untenable. Increasing adoption of Agentic AI means that concerns about data discovery (read-only) that were so prevalent in 2023 and 2024 are going to translate into actions (read-write) in 2026, if left unlabeled or unmitigated. The cost of not knowing is going up.
For organizations that do invest in a DSPM platform, one key risk is the level of access they require to your own data and systems. To scan and classify the data, extensive read-level access is required, and some level of access to redacted content is required to interpret and action the results. This creates two imperatives for CISOs: Evaluate and re-evaluate your DSPM vendors carefully and apply strict access control to these systems within your own organization. To that end, this is not an area to look for a bargain – select only vendors with the highest security posture and features that make your security team more effective and safer.
Finally, consider the total cost of ownership, not just the software sticker price. As alluded to earlier, these programs (with or without tools and software) can be costly to maintain, and as a CISO, your role is to balance the tradeoff of risk reduction and business enablement.
Finding your pragmatic step forward
For security leaders, the question isn’t whether you can afford a top-tier DSPM tool. It’s whether you can afford not to understand your data. Start with what you have: Manual inventories, existing DLP outputs or lightweight scanning tools. Apply the DSPM mindset of quantifying where sensitive data lives, who can access it and what it would cost you if it were compromised. Anchoring your risk decisions in these specifics, rather than fear and anxiety, will serve you and your business well.
This article is published as part of the Foundry Expert Contributor Network.
Want to join?
View the full article
A coordinated international operation involving U.S. and Chinese authorities has arrested at least 276 suspects and shut down nine scam centers used for cryptocurrency investment fraud schemes targeting Americans, resulting in millions of dollars in losses. The crackdown was led by the Dubai Police, under the United Arab Emirates (UAE) Ministry of Interior, in partnership with the U.S. FederalView the full article
Ein Botnetz besteht aus vielen “Zombie”-Rechnern und lässt sich beispielsweise einsetzen, um DDoS-Attacken zu fahren. Das sollten Sie zum Thema wissen. 
FOTOKINA | shutterstock.com
Kriminelle Hacker suchen stets nach Möglichkeiten, Malware in großem Umfang zu verbreiten oder Distributed-Denial-of-Service (DDoS)-Angriffe zu fahren. Ein Botnet eignet sich dazu besonders gut.
Botnet – Definition
Ein Botnet ist eine Sammlung von mit dem Internet verbundenen Geräten, die von einem Angreifer kompromittiert wurden, um DDoS-Angriffe und andere “Tasks” im “Schwarm” auszuführen. Die Idee dahinter: Jeder Rechner, der Teil des Botnetzes wird, wird zu einem “Zombie”-Rechner – ein hirnloser Bestandteil eines großen Netzwerks identischer Bots.
“Malware infiziert einen Computer, der dem Botnet-Betreiber zurückmeldet, dass der Rechner nun bereit ist, blindlings Befehle zu befolgen”, erklärt Nasser Fattah, North America Steering Committee Chair bei Shared Assessments. “Das geschieht ohne das Wissen des Benutzers. Das Ziel besteht darin, das Botnetz weiter auszubauen, um großangelegte Angriffe zu automatisieren und zu beschleunigen.”
Botnets – Architektur
Botnetze sind ein Beispiel für verteilte Computersysteme, die über das Internet betrieben werden. Die Personen oder Teams, die ein Botnet betreiben, sogenannte “Controller” oder “Herders”, müssen möglichst viele “Zombies” für ihre Armee rekrutieren – und dann deren Aktivitäten koordinieren, um Profit zu machen. Die Architektur, die zur Bildung und Aufrechterhaltung von Botnets beiträgt, besteht aus mehreren Komponenten:
Botnet-Malware: Cyberkriminelle übernehmen die Kontrolle über die Zielcomputer mithilfe von Malware. Es gibt eine Vielzahl von Vektoren, über die Malware auf einen Computer gelangen kann – von Phishing- und Watering-Hole-Angriffen bis hin zur Ausnutzung ungepatchter Sicherheitslücken. Der bösartige Code ermöglicht es Angreifern, kompromittierte Rechner zu Aktionen zu zwingen, ohne dass der Besitzer davon etwas bemerkt. “Die Malware selbst versucht oft nicht, etwas zu stehlen oder Schaden anzurichten”, erklärt Jim Fulton, Vice President beim Sicherheitsanbieter Forcepoint. “Stattdessen versucht sie, im Verborgenen zu bleiben, damit die Botnet-Software unbemerkt weiterarbeiten kann.”
Botnet-Drones: Sobald ein Gerät vom Angreifer übernommen wurde, wird es zur “Drone” – quasi einem “Fußsoldat” oder “Zombie” innerhalb der Botnetz-Armee -, der allerdings über ein gewisses Maß an Autonomie und in einigen Fällen auch über künstliche Intelligenz verfügt. “Eine Botnet-Drone kann andere Computer und Geräte mit einer gewissen Intelligenz rekrutieren, wodurch es schwieriger wird, sie zu finden und zu stoppen”, weiß Andy Rogers, Senior Assessor bei Schellman. “Sie findet anfällige Hosts und lädt sie ohne Wissen des Benutzers in das Botnetz ein.”
In Botnet Drones lassen sich alle Arten von Geräten verwandeln, die mit dem Internet verbunden sind, von PCs über Smartphones bis hin zu IoT-Devices. Letztere, etwa internetfähige Sicherheitskameras oder Kabelmodems, könnten für Angreifer sogar besonders interessant sein, wie Dave Marcus, Senior Director of Threat Intelligence bei LookingGlass Cyber, erklärt: “Bei solchen Devices neigen die Leute dazu, zu vergessen, dass sie da sind, weil man sie einmal einschaltet, und dann nicht mehr beachtet. Dazu kommt, dass viele Leute bei Routern und Switches keine Updates durchführen wollen, aus Angst, dabei etwas falsch zu machen. In beiden Fällen kann das dazu führen, dass die Geräte ungepatcht und damit angreifbar bleiben.”
Ganz wesentlich ist jedoch, dass es viele dieser Botnet Drones gibt und diese legitim wirken, wie Ido Safruti, Mitbegründer und CTO von PerimeterX zu bedenken gibt: “Indem legitime Geräte mit Malware infiziert werden, gewinnen Botnetz-Betreiber Ressourcen, die private IP-Adressen nutzen und wie legitime Nutzer aussehen sowie darüber hinaus auch kostenlose Rechenressourcen, um Aufgaben auszuführen.”
Botnet Command & Control: Das letzte Teil des Puzzles ist der Mechanismus, mit dem die Botnetze gesteuert werden. Frühe Botnets wurden in der Regel von einem zentralen Server aus gesteuert. Das machte es jedoch relativ leicht, das gesamte Netzwerk auszuschalten, indem dieser zentrale Knotenpunkt abgeschaltet wird. Moderne Botnetze operieren mit einem Peer-to-Peer-Modell, bei dem Befehle von Drone zu Drone weitergegeben werden, sobald diese ihre individuellen Malware-Signaturen über das Internet erkennen. Die Kommunikation der Bot-Herder und zwischen den Bots kann über verschiedene Protokolle erfolgen. Dabei kommt immer noch häufig das Oldschool-Chatprotokoll Internet-Relay-Chat (IRC) zum Einsatz, da es relativ leichtgewichtig ist und leicht auf Bots installiert werden kann, ohne viele Ressourcen zu beanspruchen. Es kommen aber auch eine Reihe anderer Protokolle zur Anwendung, darunter Telnet und normales HTTP, was die Erkennung des Datenverkehrs erschwert. Einige Botnets nutzen besonders kreative Mittel zur Koordination, und veröffentlichen Befehle auf öffentlichen Websites wie Twitter oder GitHub.
So wie die Botnetze selbst sind auch die verschiedenen Komponenten ihrer Architektur verteilt. “Kriminelle Hacker sind Spezialisten und die meisten Gruppen arbeiten in einem losen Verbund mit anderen Gruppen zusammen”, meint Garret Grajek, CEO von YouAttest. “In der Cybercrime-Welt kann es eine Gruppe geben, die eine neue, unveröffentlichte Schwachstelle ausnutzt, eine andere, die dann die Nutzlast des Botnetzes erstellt und eine weitere, die das Command & Control Center kontrolliert.”
Botnetze – Angriffsarten & Beispiele
Distributed Denial of Service (DDoS)-Angriffe sind wahrscheinlich die bekannteste und beliebteste Art von Angriffen, die über Botnetze initiiert werden. Im Rahmen dieser Angriffe versuchen Hunderte oder Tausende von kompromittierten Computern, einen Server oder eine andere Online-Ressource mit Anfragen zu überlasten und diese so außer Betrieb zu setzen. Das ist ohne Einsatz eines Botnet nicht möglich. Zudem sind DDoS-Attacken einfach zu initiieren, da fast jedes kompromittierbare Device über Internetkonnektivität und einen zumindest rudimentären Webbrowser verfügt.
Doch es gibt noch viele weitere Möglichkeiten für Angreifer, ein Botnetz zu nutzen. Die Zielsetzung der Angreifer kann dabei über die Art der Geräte bestimmen, die infiziert werden sollen, wie Marcus erklärt: “Wenn ich mein Botnet für Bitcoin-Mining nutzen möchte, habe ich es vielleicht auf IP-Adressen in einem bestimmten Teil der Welt abgesehen, weil diese Maschinen generell leistungsfähiger sind – sie haben einen Grafikprozessor und eine CPU und die Benutzer werden nicht unbedingt bemerken, dass im Hintergrund geschürft wird.”
Die Opfer der Angriffe bekommen zwar die kriminelle Energie derjenigen zu spüren, die das Botnet kontrollieren – die Besitzer der Bots selbst sollen jedoch, wenn es nach den Angreifern geht, nichts davon bemerken, was ihre Rechner anrichten. “Was passiert, hängt einfach davon ab, wie viel sich der Betreiber herauszunehmen bereit ist. Der Einsatz einer hochfunktionalen Malware, die viele verschiedene Dinge tut, erhöht die Wahrscheinlichkeit, entdeckt zu werden, weil der Besitzer Performance-Probleme seines Rechners auffallen könnten.”
Heutzutage sorgen zwar vor allem DDoS-Angriffe im Zusammenhang mit Botnetzen für Aufmerksamkeit – das allererste Botnet wurde allerdings kreiert, um Spam zu verbreiten. Khan C. Smith baute 2001 eine Bot-Armee auf, um sein Spam-Imperium auszubauen und verdiente damit Millionen von Dollar. Bis er schließlich vom Internetdienstleister EarthLink (erfolgreich) auf Schadensersatz in Höhe von 25 Millionen Dollar verklagt wurde.
Eines der wichtigsten Botnetze der letzten Jahre basierte auf der Schadsoftware Mirai und legte 2016 kurzzeitig einen großen Teil des Internets lahm. Mirai wurde von einem College-Studenten aus New Jersey geschrieben und entstand aus einer Auseinandersetzung zwischen Server-Hosts des populären Videospiels Minecraft. Das Botnet zielte speziell auf TV-Kameras mit Internetverbindung ab – ein Beleg dafür, wie bedeutend IoT-Gerätschaften in diesem Zusammenhang sind.
Es gibt jedoch noch zahlreiche andere Beispiele für Botnetze, weiß Kevin Breen, Director of Cyber Threat Research bei Immersive Labs: “Größere Botnets wie TrickBot nutzen Malware wie Emotet, die sich bei der Installation eher auf Social Engineering stützt. Diese Botnetze sind in der Regel widerstandsfähiger und werden für die Installation zusätzlicher, bösartiger Software wie Banking-Trojaner und Ransomware verwendet. In den letzten Jahren haben die Strafverfolgungsbehörden mehrfach – mit vereinzelten Erfolgen – versucht, die großen, kriminellen Botnetze zu zerstören. Diese scheinen sich im Laufe der Zeit jedoch immer wieder zu erholen.”
Botnet kaufen – so geht’s
Viele Cyberkriminelle bauen ihre Botnets nicht für den persönlichen Gebrauch auf, sondern um sie zu verkaufen. Diese Geschäfte laufen mehr oder weniger klandestin ab. Allerdings lassen sich mit einer einfachen Google-Suche schon relativ leicht Services finden, die euphemistisch als “Stresser” oder “Booter” bezeichnet werden: “Diese SaaS-Lösungen können ganz einfach – zum Beispiel über Paypal – gebucht werden – eigentlich, um die Belastbarkeit des eigenen Netzwerks zu testen. Einige dieser Serviceanbieter verkaufen ihre Dienste allerdings an jeden – ohne Auftraggeber oder Ziel zu überprüfen”, weiß Fattah.
Auch Security-Spezialist Breen ist der Meinung, dass jeder, der Botnet-Software herunterladen möchten, diese auch finden wird: “Wer nach den richtigen Begriffen sucht, landet schnell in einschlägigen Foren, wo neben entsprechenden Services oft auch Quellcode und geleakte Botnetze angeboten werden. Solche Angebote werden wird typischerweise von den berühmten ‘Skript-Kiddies’ genutzt, die damit zum Beispiel die Verbreitung von Krypto-Minern vorantreiben wollen.” Die echten Profis operieren hingegen im Darknet und können schwieriger zu finden sein: “Spezialisierte Darknet-Marktplätze werden in der Regel moderiert und sind nur auf Einladung zugänglich”, weiß Josh Smith, Analyst für Cyberbedrohungen bei Nuspire. “Hat man jedoch einmal Zugang erlangt, ist der weitere Prozess bemerkenswert kundenfreundlich ausgestaltet – inklusive Reputationssystem für Verkäufer.”
“Viele dieser Services bieten ein simples Interface, mit dem ein Botnet auf eine IP oder URL ausgerichtet und der Angriff dann mit einem Knopfdruck gestartet wird. Die Benutzer können Websites und Server direkt von Ihrem Browser aus lahmlegen und bleiben durch die Bezahlung mit Kryptowährungen weitgehend anonym“, erklärt Rogers. “Anspruchsvollere Bedrohungsakteure wie Ransomware-Banden arbeiten möglicherweise direkt mit den Betreibern großer Botnetze wie TrickBot zusammen, um großangelegte Spear-Phishing-Kampagnen anzustoßen”, meint Laurie Iacono, Associate Managing Director of Cyber Risk bei Kroll. “Sobald die Rechner infiziert sind, sammelt Malware Informationen, die Ransomware dabei hilft, das Netzwerk zu infiltrieren.”
Die Kosten für einen solchen Botnet-Service sind dabei relativ überschaubar, wie Anurag Gurtu, CPO von StrikeReady, preisgibt: “Der Zugang zu einem Botnet kann bis zu zehn Dollar pro Stunde kosten.” Dabei bekommen die Nutzer das, wofür sie bezahlen: “Wenn man einen ganz bestimmten Bot in einem spezifischen Teil der Welt haben möchte, steigen die Preise”, meint Marcus. “In bestimmten Teilen der Welt gibt es qualitativ bessere Rechner. Ein Botnetz, das auf Maschinen und IP-Adressen in den USA basiert, ist beispielsweise erheblich teurer als eines innerhalb der EU, weil die Rechner in den Staaten leistungsfähiger sind.”
Botnetz-Angriffe verhindern
Die Absicherung gegen Botnets kann zwei verschiedene Formen annehmen:
Entweder Sie verhindern, dass Ihre eigenen Geräte zu Bots werden oder
Sie wehren Angriffe ab, die über Botnetze gestartet werden.
In beiden Fällen gibt es wenige Verteidigungsmöglichkeiten, die nicht bereits Bestandteil einer ordentlichen Sicherheitsstrategie sind:
Hacker verwandeln Geräte häufig mit Malware in Zombie-Rechner, die über Phishing-E-Mails verbreitet wird. Sie tun also gut daran, Ihre Mitarbeiter in Sachen Phishing umfassend aufzuklären.
Auch unzureichend abgesicherte IoT-Geräte werden oft in Botnetze integriert. Stellen Sie also sicher, dass solche Devices nicht das herstellerseitig gesetzte Standardpasswort nutzen.
Gelingt es Cyberkriminellen, Malware auf Ihren Computern einzuschleusen, benötigen Sie eine aktuelle Antivirus-Lösung, um sie zu erkennen.
Wenn Sie Opfer eines DDoS-Angriffs werden, können Sie den bösartigen Traffic herausfiltern oder Ihre Kapazitäten mit Hilfe eines Content Delivery Network aufstocken.
Darüber hinaus gibt es auch einige Botnet-spezifische Techniken, die Sie einsetzen können, um sich zu schützen. Breen schlägt beispielsweise vor, auf verdächtigen Datenverkehr achten: “Eine Datenflussanalyse klingt kompliziert, kann aber Botnet-Command-and-Control-Traffic zu Tage fördern.”
“Wir verwenden mehrere Tools, um Botnetze zu stoppen”, erläutert Mark Dehus, Director of Threat Intelligence bei Lumen Black Lotus Labs. “Sobald ein neues Malware-Sample entdeckt wird, können wir beispielsweise die Methoden, mit denen es sich an einen Command & Control-Server meldet, mit Reverse Engineering nachvollziehen. So können wir einen Bot emulieren, der sich mit verdächtigen Servern verbinden, sie validieren und die Befehle überwachen kann, die sie an die Bots übermitteln. Der Kampf gegen Botnetze und ihre Betreiber ist langwierig, aber wir hoffen, das Blatt wenden zu können.” (fm)
View the full article
Apple's new AirPods Max 2 launched last month, and Amazon is still one of the only retailers offering a discount on the headphones. You can get the Midnight, Purple, and Starlight color options for $509.99 on Amazon, down from $549.00.

Note: MacRumors is an affiliate partner with some of these vendors. When you click a link and make a purchase, we may receive a small payment, which helps us keep the site running.

This represents a new all-time low price on the brand new AirPods Max 2 headphones. Free delivery has the AirPods Max 2 arriving around May 4-5, which is a guaranteed delivery date in time for Mother's Day if you're shopping for that holiday.

$39 OFFAirPods Max 2 for $509.99

If you're on the hunt for more discounts, be sure to visit our Apple Deals roundup where we recap the best Apple-related bargains of the past week.



Deals Newsletter

Interested in hearing more about the best deals you can find in 2026? Sign up for our Deals Newsletter and we'll keep you updated so you don't miss the biggest deals of the season!




Related Roundup: Apple Deals
This article, "AirPods Max 2 Drop to New Low Price of $509.99 on Amazon" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Apple is expected to unveil iOS 27 during its WWDC 2026 keynote on June 8, and there are already many rumored features and changes for iPhones.


The first developer beta of iOS 27 will likely be available immediately following the keynote, and a public beta typically follows in July. Following beta testing, the software update should be released to all users with a compatible iPhone in September.

Below, we outline some of the new features that are rumored to be coming with iOS 27, as reported by sources such as Bloomberg and The Information.

Siri App


Apple reportedly plans to debut an all-new, dedicated Siri app with a so-called "Extensions" feature across iOS 27, iPadOS 27, and macOS 27.

With the Siri app, iPhone, iPad, and Mac users will reportedly be able to interact with Apple's assistant in both text and voice modes. The app will also provide users with access to their past conversations with Siri. Overall, the Siri app would function similarly to chatbots like ChatGPT, Gemini, and Claude.

It has been rumored that iOS 27 will include a new Siri interface in the Dynamic Island. When you trigger Siri, the Dynamic Island will reportedly show a "Search or Ask" prompt, and this will apparently be accompanied by a "glowing cursor" that looks similar to how the "26" is highlighted in the WWDC 2026 graphic.

iOS 27 should also include Apple's delayed personalized Siri features from 2024. For example, Apple showed a user asking Siri about their mother's flight and lunch reservation based on info retrieved from the Mail and Messages apps.

"We look forward to bringing a more personalized Siri to users coming this year," said Apple's CEO Tim Cook, on an earnings call this week.

New Satellite Features


iOS 27 will reportedly support 5G satellite internet connectivity, although this functionality might be limited to the upcoming iPhone 18 Pro, iPhone 18 Pro Max, and iPhone Ultra models with Apple's next-generation C2 modem.

Four additional satellite features have been rumored:Apple Maps via satellite
Photos support for Messages via satellite
Third-party apps in the App Store will be able to integrate Apple's satellite features
The ability to connect an iPhone to a satellite without pointing the device toward the skyAmazon last month announced plans to acquire Globalstar, the satellite company that powers Apple's satellite features on the iPhone 14 and newer and the Apple Watch Ultra 3. In turn, Amazon announced that it has signed an agreement with Apple to provide satellite connectivity for current and future iPhone and Apple Watch features.

Apple's current satellite features:Emergency SOS via satellite
Find My via satellite
Roadside Assistance via satellite
Messages via satellite All of the features are currently free to use in supported areas without Wi-Fi or cellular connectivity. Availability varies by country.

"Mac OS X Snow Leopard" Approach to Bug Fixes

iOS 27 may be similar to Mac OS X Snow Leopard, in the sense that Apple is apparently focused on improving "quality and underlying performance." Apple is expected to focus on bug fixes, improved stability, and Liquid Glass design enhancements.

More Rumored Features

Apple has reportedly tested an updated iPhone keyboard with enhanced autocorrect. The features should debut on iOS 27 if Apple moves forward with it. Similar to Grammarly, the keyboard "expands autocorrect by offering alternative words."

iOS 27 is not expected to include any major Liquid Glass design changes, but the update may add a system-wide Liquid Glass slider for precisely adjusting the opacity of the interface. A similar slider already exists for the Lock Screen's clock.

The update may include four new Apple Intelligence features for the iPhone 15 Pro and newer, based on code on Apple's servers discovered by Nicolás Alvarez:Visual Intelligence will let you scan nutrition labels on food packaging, for tracking calories and macronutrients in the Health app.
Visual Intelligence will let you scan phone numbers and addresses printed on paper or a business card and add them to the Contacts app.
In the Wallet app, you will likely be able to scan physical event tickets, gym membership cards, and so forth and generate digital versions.
In the Safari app, you will be able to automatically name Tab Groups for users based on the contents of the tabs within the group.A subsequent report provided more details about the new Visual Intelligence features.

iOS 27 may also have three new Apple Intelligence photo editing tools in the Photos app.

Apple reportedly plans to add "Undo" and "Redo" options to the iPhone's Home Screen customization menu on iOS 27.Compatible iPhone Models


iOS 27 will be compatible with the iPhone 12 series and newer, according to Instant Digital, a known Apple leaker on the Chinese social media platform Weibo.

If this rumor is accurate, iOS 27 will drop support for the following iPhone models:iPhone 11
iPhone 11 Pro
iPhone 11 Pro Max
iPhone SE (2nd generation)However, these devices will continue to receive iOS 26 security updates for at least a few years.

iOS 27 will be compatible with the following iPhone models, according to the leaker:iPhone 17e
iPhone 17
iPhone 17 Pro
iPhone 17 Pro Max
iPhone Air
iPhone 16e
iPhone 16
iPhone 16 Plus
iPhone 16 Pro
iPhone 16 Pro Max
iPhone 15
iPhone 15 Plus
iPhone 15 Pro
iPhone 15 Pro Max
iPhone 14
iPhone 14 Plus
iPhone 14 Pro
iPhone 14 Pro Max
iPhone 13
iPhone 13 mini
iPhone 13 Pro
iPhone 13 Pro Max
iPhone 12
iPhone 12 mini
iPhone 12 Pro
iPhone 12 Pro Max
iPhone SE (3rd generation)Any new Apple Intelligence features introduced in iOS 27 will require an iPhone 15 Pro or newer.

Instant Digital has accurately leaked Apple information before, such as the yellow color for the iPhone 14 and iPhone 14 Plus, and the Apple Watch Ultra 2's Titanium Milanese Loop. However, the account does not have a perfect track record.Related Roundup: iOS 27
This article, "iOS 27 Will Add These New Features to Your iPhone" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Amazon is offering a few all-time low prices on Apple's M5 Pro/M5 Max MacBook Pro, with up to $216 off select models. These deals join Amazon's discounts on the M5 MacBook Air from last week, which are seeing $150 in savings on multiple models.

Note: MacRumors is an affiliate partner with Amazon. When you click a link and make a purchase, we may receive a small payment, which helps us keep the site running.

Starting with the 14-inch models, you can get the 24GB/1TB M5 Pro MacBook Pro for $1,983.94, down from $2,199.00. This deal, along with all of the others we're tracking in this article, represent best-ever prices on the new M5 Pro and M5 Max MacBook Pro.

$216 OFF14-inch M5 Pro MacBook Pro (24GB/1TB) for $1,983.94
$205 OFF14-inch M5 Pro MacBook Pro (24GB/2TB) for $2,394.50
$150 OFF14-inch M5 Max MacBook Pro (36GB/2TB) for $3,449.00

You can get up to $200 off the 16-inch MacBook Pro right now on Amazon, with the 24GB RAM/1TB M5 Pro model hitting a new all-time low price of $2,549.00, down from $2,699.00. Most of the MacBook Pro devices in this sale have an estimated delivery date of May 7 with free shipping.

$150 OFF16-inch M5 Pro MacBook Pro (24GB/1TB) for $2,549.00
$200 OFF16-inch M5 Pro MacBook Pro (48GB/1TB) for $2,899.00
$200 OFF16-inch M5 Max MacBook Pro (36GB/2TB) for $3,699.00

If you're on the hunt for more discounts, be sure to visit our Apple Deals roundup where we recap the best Apple-related bargains of the past week.



Deals Newsletter

Interested in hearing more about the best deals you can find in 2026? Sign up for our Deals Newsletter and we'll keep you updated so you don't miss the biggest deals of the season!




Related Roundup: Apple Deals
This article, "Apple's 2026 MacBook Pro Hits New Record Low Prices on Amazon" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
An AI agent that revealed sensitive data without being asked. An agent that overruled its own guardrails. Another that sent credentials to an attacker via Telegram, because it forgot it wasn’t supposed to do so after a reset.
It’s no secret that AI agents have huge potential, balanced by equally big risks. What’s becoming apparent, however, is how quickly agentic systems can veer wildly off course and start exposing critical information under real-world conditions.
A look at just how easily this can happen emerges from Phishing the agent: Why AI guardrails aren’t enough, a report on tests conducted by cloud identity and access management (IAM) company Okta Threat Intelligence, which uncovered all of the problems cited above, and more.
Their research focused on OpenClaw, a model-agnostic multi-channel AI assistant which has seen explosive growth inside enterprises since appearing in late 2025.
The Telegram hack
In common with the growing list of rival agents, OpenClaw is only as useful as the access it is given to files, accounts, browsers, network devices, and, most significant of all, credentials.
One test conducted by Okta assessed how easy it would be to trick OpenClaw running Claude Sonnet 4.6 into handing over an OAuth token. This shouldn’t be possible; the LLM should refuse this request. However, what might have held true when prompting Claude as a chatbot quickly fell apart when it was accessed through OpenClaw.
The test assumed that a user had given OpenClaw full access to their computer, that they regularly controlled the agent over Telegram, and that their Telegram account had been hijacked.
First, the attacker instructed the agent via Telegram to retrieve an OAuth token, but to only display it in a terminal window on the computer. Claude Sonnet’s guardrails would prevent it from copying the token, however, the testers were able to reset the agent, causing it to forget it had displayed the token in the terminal window.
At that point, Okta said in its writeup, “The agent was instructed to take a screenshot of the desktop, which included the token, and then drop the screenshot in the Telegram chat, which it did. Exfiltration accomplished.”
Agent-in-the-middle
Agentic AI is really two things: a powerful orchestration system coupled to one or more highly-capable LLMs. What an agent isn’t is a simple interface, and it must be viewed as a separate system capable of autonomous, unpredictable reasoning.  
In fact, Okta threat intelligence director Jeremy Kirk pointed out, “It opens up a new attack surface. Someone gets SIM swapped, their Telegram is hooked up to an agent that has carte blanche to run anything on their computer, and possibly their employer’s network. In an enterprise context, this is a total nightmare.”
OpenClaw is also so hard-wired to find ways around problems, it will sometimes do unexpected, improper things. Kirk said that an agent, when prompted in tests to access a website, requested the site’s login credentials in chat via a Telegram bot, an unencrypted channel which would expose them to anyone with access to that chat.
In another example, OpenClaw was asked to search X for AI stories. That shouldn’t have been possible; the machine was logged into X, but OpenClaw’s isolated Chrome profile was not. However, when prompted to grab the session cookies from the logged-in session and inject them into its own browser process, it happily attempted to do so.
This is similar in principle to adversary-in-the-middle phishing attacks, which allow attackers to bypass protections such as MFA. It should be a no-go, and yet OpenClaw thought the action was valid, underlining how an attacker could manipulate it to do the same.
“The agents are prompted to be as helpful as possible by default, a characteristic that poses particular concerns when it comes to credentials and tokens,” said Kirk.
‘Defying security gravity’
According to Kirk, many enterprises are, sometimes unwittingly, running unsanctioned or weakly managed ‘shadow’ agents inside their networks. An example of how this could go wrong was the recent Vercel compromise in which the Context.ai app opened the door to the theft of downstream OAuth session tokens.
The problem stems from agents being used experimentally by developers and employees, with little or no governance or oversight. The answer is to secure them using the same controls applied to users or service accounts, said Kirk. And as well as limiting the scope of agents, enterprises should also look to securing the credentials and tokens themselves, avoiding giving them long expiry dates.
Agents are only the latest example of a technology that is being deployed faster than it can be secured, Kirk observed. “Much of AI right now is defying security gravity,” he said. “But there are ways to use agents safely and keep credentials out of their reach, which is the only safe way to use them.”
View the full article
Apple refreshed the 14-inch and 16-inch MacBook Pro with M5 Pro and M5 Max models in March 2026, but depending on your needs and interests, you might want to skip this generation because there's something better in the works.


The M5 Pro and M5 Max ‌MacBook Pro‌ models have faster chips, but the same design that Apple has used since 2021. An updated design with new display technology and faster performance is coming in late 2026 or early 2027.

OLED Touchscreen Display

The next ‌MacBook Pro‌ that comes out will be the first with an OLED display, according to rumors. iPhones have used OLED for years, and Apple launched a larger-screened OLED device with the M4 iPad Pro in 2024.

OLED has benefits over the mini-LED display in current ‌MacBook Pro‌ models. Pixels can be lit individually for deeper blacks, brighter colors, and no bloom from surrounding pixels. There can be power savings when compared to mini-LED displays, response times are quicker, and viewing angles are better. OLED brightness can be an issue compared to LEDs, but as OLED technology has improved, so has brightness. The combination of true black and vivid color is ideal for HDR content.

Along with OLED, the next ‌MacBook Pro‌ is expected to have touchscreen capabilities.

Apple said repeatedly that the Mac wouldn't get a touchscreen, but Apple's position has shifted. Multiple rumors suggest that touch capabilities are coming, making the Mac more like an iPad. Touch-based controls will be available alongside traditional mouse and keyboard input options.

Design Update

Some rumors suggest the OLED ‌MacBook Pro‌ will be thinner, and since Apple hasn't updated the ‌MacBook Pro‌ design since 2021 and this is a major technology shift, some kind of design refresh is likely. Sizes will stay the same, and Apple isn't removing the keyboard or trackpad.

Instead of a notch, the OLED ‌MacBook Pro‌ is expected to have a Dynamic Island that takes up less screen space. The Dynamic Island will be interactive, and it will contextually expand based on the app or Mac feature in use.

2nm Chip

The OLED ‌MacBook Pro‌ models will be the first to use Apple's 2-nanometer chip technology that's supposed to be coming in the M6-series chips.

The change in node size is expected to bring faster speeds with reduced power consumption and higher transistor density. Performance per watt will improve, and the 2nm chips will use GAA nanosheet transistors instead of FinFET. TSMC says the new transistor technology will bring improved performance and lower power consumption.

Cellular Connectivity

There have been rumors that 5G could come to Macs, and if that's Apple's plan, it would make a lot of sense to offer it in the OLED ‌MacBook Pro‌.

Ultra Branding

OLED touch displays will be limited to the highest-end 14-inch and 16-inch ‌MacBook Pro‌ models because of the cost, and Apple might even use new "Ultra" branding.

It's possible the OLED M6 model will be sold alongside the existing M5, M5 Pro, and M5 Max models rather than replacing them, and if that's the case, we're likely looking at a serious price increase. Apple could also refresh the entire line with M6 chip variants, reserving the OLED display for the most expensive models.

If you don't care about OLED display technology or a touchscreen and want something lower-cost, you're probably not going to want to hold off on purchasing.

First-Generation Tech

Some of Apple's first-generation Macs can have more problems than expected, which was the case with the 2016 transition to the butterfly keyboard.

If you don't want to get AppleCare+ and are concerned about first-generation problems, the M5 Pro and M5 Max ‌MacBook Pro‌ models are a safer bet.

Launch Date

The OLED ‌MacBook Pro‌ could come as soon as late 2026, but it's looking more like Apple will hold it until early 2027. Apple is facing chip shortages that will require it to hold the ‌MacBook Pro‌ for longer to build up stock.Related Roundup: MacBook ProBuyer's Guide: MacBook Pro (Buy Now)Related Forum: MacBook Pro
This article, "Why You Might Want to Wait to Buy a MacBook Pro" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Apple is facing over 30 lawsuits from people who claim to have been stalked using Apple AirTags. The filings come after an AirTag lawsuit from 2022 (Hughes v. Apple) failed to get class certification.


In each filing, Apple is accused of releasing the ‌AirTag‌ while being aware that it could be "purchased and used by abusive, dangerous individuals, to track, coerce, control, and otherwise endanger and abuse innocent victims."

Further, the lawsuits say that Apple knew adequate safeguards were not in place when the ‌AirTag‌ launched in 2021, and Apple is aware that "AirTags remain a profound risk" to people like the plaintiffs. Apple reportedly received more than 40,000 stalking reports between April 2021 and April 2024, and Apple internal documents sourced from the original lawsuit show the company knew its safeguards would only "deter as opposed to prevent malicious use." The company also acknowledged that it "should have consulted domestic abuse organizations on the unwanted tracking policy before shipping."

Multiple news reports of AirTags being used for stalking are referenced, including cases that ended in murder. The lawsuits claim that AirTags "revolutionized the scope, breadth, and ease of location-based stalking."

While there are other tracking options on the market, the ‌AirTag‌ uses the Find My network that leverages any nearby device to relay the ‌AirTag‌'s location back to its owner.

Apple has put multiple anti-stalking measures in place, including cross-platform notifications that let potential stalking victims know that an unknown ‌AirTag‌ is following them, but the plaintiffs don't feel that Apple's protections are adequate. The lawsuit cites the 4-to-8-hour delay before a notification is received, and notes that originally, AirTags didn't send a notification to potential stalking victims until 72 hours had passed.

One of the ways an ‌AirTag‌ alerts users to its presence is by playing a sound, but the speaker can be removed. Sellers on sites like eBay even offer modified silent AirTags.

Each lawsuit includes the personal story of the plaintiff involved and all of whom claim to have been stalked using an ‌AirTag‌. Plaintiffs are seeking compensatory damages, punitive damages, attorney's fees, and an order preventing Apple from engaging in the unlawful business practices alleged in the filings.

The judge overseeing the 2022 ‌AirTag‌ lawsuit denied class certification because of the difference in state laws and the individual nature of each stalking incident. The plaintiffs were advised to file individual lawsuits within 28 days of the class certification denial.Related Roundup: AirTagTag: Apple LawsuitsBuyer's Guide: AirTag (Buy Now)
This article, "Apple Faces Dozens of Lawsuits Over AirTag Stalking After Class Action Denied" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Apple will unveil its latest software platforms during its WWDC 2026 keynote on Monday, June 8, and one of them will be macOS 27 for the Mac.


The first developer beta of macOS 27 will likely be available immediately following the keynote, and a public beta typically follows in July. Following beta testing, the software update should be released to all users in September.

macOS 26 is known as macOS Tahoe, but the name of macOS 27 has yet to leak.

Below, we recap what to expect from macOS 27.

Siri Upgrades

macOS 27 will reportedly include a dedicated Siri app with conversation history. This would make Siri more like OpenAI's ChatGPT and Google's Gemini.

macOS 27 should also include the personalized Siri features that Apple previewed all the way back at WWDC 2024. For example, Apple showed a user asking Siri about their mother's flight and lunch reservation based on info retrieved from the Mail and Messages apps. This functionality was previewed on an iPhone, but it will extend to the iPad and Mac.

"We look forward to bringing a more personalized Siri to users coming this year," said Apple's CEO Tim Cook, on an earnings call this week.

More Apple Intelligence Features

Earlier this year, Apple and Google announced that Google Gemini will help power future Apple Intelligence features, and that will extend beyond the more personalized version of Siri. However, exactly which features arrive remains to be seen.

Touch Interface


Bloomberg's Mark Gurman reported that Apple is preparing a touch-optimized version of macOS for the rumored MacBook Pro or "MacBook Ultra" with a touchscreen.

For example, if a user touches a button or control on the screen, the report said a relevant set of commands will instantly appear in a menu surrounding their finger. And if a user taps on an item in the menu bar at the top of the screen, the report said the controls will enlarge so they are easier to select with a finger.

Gurman expects a MacBook Pro or MacBook Ultra with a touchscreen to be released by early 2027, so these touch optimizations will presumably arrive in macOS 27. However, the changes might be hidden until the laptop launches.

Improved Stability

macOS 27 will reportedly be similar to 2009's Mac OS X Snow Leopard, in the sense that Apple is apparently very focused on improving "quality and underlying performance." Apple is expected to implement many bug fixes and stability improvements, and there may also be some much-needed Liquid Glass design enhancements.

No Intel Macs

Last year, Apple announced that macOS Tahoe would be the final major macOS release for Intel-based Macs, meaning that macOS 27 will be compatible with Apple silicon Macs with the M1 chip and newer only. However, Apple will likely continue to release security fixes for some Intel-based Macs for at least a few more years.

No AirPort Time Capsule Support

Starting with macOS 27, Macs will not support the AirPort Time Capsule or any other storage drives that use the Apple Filing Protocol (AFP), according to a warning shown by Apple on macOS Tahoe. Time Capsule backups will require a storage drive that supports more current file-sharing protocols like SMBv2 and SMBv3.Related Roundup: macOS 27
This article, "Apple to Unveil macOS 27 Next Month With These New Features" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Microsoft and the US Cybersecurity and Infrastructure Security Agency (CISA) have sounded the alarm about a Windows shell spoofing vulnerability that is already being exploited by attackers. It is not clear by whom as yet, but the main suspects are hackers in Russia.
CISA has mandated that all federal agencies patch this vulnerability, designated CVE-2026-32202, by May 12. According to a Microsoft advisory, exploitation of the flaw could lead to access to sensitive data, but attackers would not be able to gain control of the system.
However, one security expert has warned that the considerable gap between the time Microsoft identified the bug and the date by which the systems must be patched leads to increased risk.
The patch gap
Lionel Litty, CISO for security company Menlo, said that an incomplete patch for CVE-2026-21510 that resulted in the issue tracked as CVE-2026-32202 adds to the problem. “This has been a theme for many years. A vulnerability exists and the vendor has not been thorough enough in dealing with it, so a small variation has not been fully patched. What normally happens is that they’ve dealt with the main vulnerability, but there are still side effects.” The result of this is that there is a further delay in a complete fix while a new update is developed.
The big problem, said Litty, is the so-called patch gap. He said that initially there’s a gap between the time the vendors find a vulnerability and the time it issues a patch, and there is also a subsequent gap between the patch being issued and organizations completing the update. For example, he noted, if an update interrupts users’ work, they may be reluctant apply it. ”We can see on our platform that many users don’t update for weeks, or even months,” he said.
He pointed out that the vendors themselves are acting efficiently. But, he said, “as a CISO, I have to decide what level of pain to inflict on our users.”
A difficult balance
Erik Avakian, technical counselor at Info-Tech Research Group, noted that when it set the patching deadline, CISA had been operating within the guidelines laid down in Binding Operational Directive (BOD) 22-01, which requires US federal  agencies to patch vulnerabilities within the timelines outlined under the policy, which range from 14 to 21 days.
“In cases of high-risk exploitation, CISA can shorten the deadline to three days,” he said. “But in the case of CVE-2026-32202, the CVSS score was rated at 4.3, and even though the vulnerability has been actively exploited, the rating does not meet the policy threshold for a faster patch cycle. In this case, CISA allotted a 14-day deadline, which meets its aggressive timeline standard based on the vendor rating.”
He said that there is indeed an argument that the 14 day window to patch a vulnerability that is being actively exploited in the wild is too long. But, he said, “I’m assuming in this case, the reason why it was not elevated to an emergency directive type patch cycle (which would require as little as 48 to 72 hours to patch) is due to Microsoft’s rating, as well as several other factors”.
Avakian explained his reasoning: “First, organizations can help mitigate the risk without applying a full patch by blocking certain ports for traffic at the firewall perimeter,” he said. “This type of countermeasure helps to reduce the risk while the 14-day patch window clock is ticking. The longer window gives testers added time to test patches being applied properly in a test/staging environment before rolling to production.”
Secondly, he said, “it’s one thing [for IT] to patch systems quickly, but it’s another when they’re rushed, because that carries the potential for additional unintended risk of breaking critical systems and applications if something goes wrong, or if the patch wasn’t tested properly.”
Avakian did agree that CISOs are facing a difficult balancing act, where they have to weigh risk against the stability of systems. 
And, as Litty pointed out, the situation is constantly changing; the emergence of AI will cause more issues in the future. “We’re seeing a shrinking gap as AI becomes part of the problem,” he said, adding that AI use means people with fewer technical skills are able to exploit systems, and do so more quickly, so CISOs should not assume that sophisticated attacks are coming from nation states. There needs to be a change of mindset within organizations to deal with this.
“You can no longer spend a few weeks testing an upgrade and then implementing it: you have to do things much faster,” he said.
View the full article
Apple this week stopped offering a 256GB storage option for the Mac mini worldwide. As a result, the desktop computer now has a higher starting price.


In the U.S., for example, the Mac mini now starts at $799 with the M4 chip, 16GB of RAM, and 512GB of storage, whereas it previously started at $599 with the M4 chip, 16GB of RAM, and 256GB of storage.

Mac mini models with the M4 Pro chip already had a minimum of 512GB of storage, so there are no pricing changes for those configurations.

The base Mac mini with 256GB of storage had already been unavailable to order since last week, but it has now been removed from Apple's configurator entirely. We have reached out to Apple for comment and will update this story if we hear back.

On an earnings call this week, Apple CEO Tim Cook acknowledged that Mac mini and Mac Studio supply is constrained, and he said it may take "several months" for Apple to achieve supply-demand balance. He said both of these Macs are "amazing platforms for AI and agentic tools," resulting in higher-than-expected demand.

In March, Apple stopped offering the Mac Studio with 512GB of RAM.

These changes to Mac mini and Mac Studio configurations are occurring amid a global memory chip shortage, driven by companies building out AI server facilities. Cook said Apple is expecting "significantly higher memory costs" in the current quarter, and tight availability of RAM is likely forcing Apple to make tough business decisions.

Thanks, Spencer!Related Roundup: Mac miniBuyer's Guide: Mac Mini (Caution)Related Forum: Mac mini
This article, "Apple Stops Offering Mac Mini With 256GB of Storage, Starting Price Rises to $799" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
It was another jam-packed week of Apple news this week, with fresh rumors on the touchscreen "MacBook Ultra" and the foldable "iPhone Ultra," as well as Apple's 20th-anniversary iPhone coming next year.


This week also saw more word that Apple is shifting focus away from the Vision Pro, so read on below for all the details on these stories and more!

Top Stories

Apple to Launch 'MacBook Ultra' With These Six New Features

While the 14-inch and 16-inch MacBook Pro were just updated with M5 Pro and M5 Max chips last month, bigger changes are reportedly around the corner.


According to Bloomberg's Mark Gurman, the higher-end MacBook Pro models will be receiving a major redesign by early 2027, and he said that Apple might use "MacBook Ultra" branding for them. If so, the MacBook Ultra would likely be a higher-priced model at the top of the MacBook lineup, sitting above the MacBook Pro entirely.

Up to six new features have been rumored so far, including an OLED display, touch capabilities, a Dynamic Island, M6 Pro and M6 Max chips manufactured with TSMC's advanced 2nm process, a thinner design, and built-in cellular connectivity.

Apple Has Given Up on the Vision Pro After M5 Refresh Flop

Apple has all but given up on the Vision Pro after the M5 model failed to revitalize interest in the device, MacRumors has learned. Apple updated the Vision Pro with a faster M5 chip and a more comfortable band in October 2025, but there were no other hardware changes, and consumers still weren't interested.


Apple has apparently stopped work on the Vision Pro and the Vision Pro team has been redistributed to other teams within Apple. Some former Vision Pro team members are working on Siri, which is not a surprise as Vision Pro chief Mike Rockwell has been leading the Siri team since March 2025.

Foldable 'iPhone Ultra' Could Be Missing These 5 Key Features Despite $2,000 Price Tag

Apple's first foldable iPhone, dubbed the "iPhone Ultra," could be missing at least five key features present on the iPhone 18 Pro models despite its $2,000 price point.

Image via Vadim Yuryev
Recent images of dummy models shared by Sonny Dickson and Vadim Yuryev seem to reveal two previously undiscussed missing features of the ‌iPhone Ultra‌: MagSafe and the Action Button. That's in addition to several other features like Face ID and a Telephoto camera lens that have already been rumored for some time to be lacking on the foldable iPhone.

Apple Introduces App Store Monthly Subscriptions With 12-Month Commitment

Apple this week announced the launch of a new subscription option for App Store developers: monthly subscriptions with a 12-month commitment. The new option allows developers to offer subscribers discounted pricing typically associated with an annual subscription but paid on a monthly basis to keep payments more affordable.


This new payment option allows you to offer subscribers more affordable options. People can cancel their subscription at any time, which will prevent the subscription from renewing after they've completed their agreed-to payments to fulfill their commitment.

Notably, the new subscription type will be worldwide except for the United States and Singapore, at least for now.

20th Anniversary iPhone to Feature Custom 'Micro-Curved' OLED Panel

For its 20th-anniversary iPhone, Apple is tapping Samsung to produce a custom micro-curved OLED display that is brighter and thinner than existing panels, according to new supply chain information out of China.


Apple is reportedly considering a radical redesign for the 20th-anniversary iPhone that could feature a completely bezel-less display that curves around all four edges of the device.

To that end, Apple is said to be seeking from Samsung an equal-depth quad-curved panel design that uses "micro-curves" to keep the curve very shallow, as opposed to the aggressively curved "waterfall" edges of some existing Samsung panels.

Apple Shares 'Ted Lasso' Season Four Streaming Date and Teaser Trailer

Apple this week announced that its hit comedy-drama series "Ted Lasso" is returning for a fourth season with a first episode on Wednesday, August 5. One new episode will follow every Wednesday thereafter through October 7.


"Ted Lasso" is one of the most popular shows ever released on the Apple TV streaming service. The eponymous character Ted Lasso, played by Jason Sudeikis, starts off as a small-time football coach from Kansas who is hired to coach a professional soccer team in England, despite having no experience coaching soccer.

MacRumors Newsletter

Each week, we publish an email newsletter like this highlighting the top Apple stories, making it a great way to get a bite-sized recap of the week hitting all of the major topics we've covered and tying together related stories for a big-picture view.

So if you want to have top stories like the above recap delivered to your email inbox each week, subscribe to our newsletter!Tag: Top Stories
This article, "Top Stories: MacBook Ultra, Vision Pro, and iPhone Ultra Rumors" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
For this week's giveaway, we've teamed up with Astropad to offer MacRumors readers a chance to win a Mac mini to use with Astropad's new Workbench app. For those unfamiliar with Astropad, it is the company behind Astropad Studio and Luna Display. Astropad Studio lets you use an iPad as a drawing tablet connected to a Mac and Luna Display turns an ‌iPad‌ into a secondary display for a Mac, so Workbench is a natural evolution of Astropad's existing products.


The ‌Mac mini‌ has become the must-have platform for local agentic AI, and Astropad Workbench is the perfect companion app. Workbench is a remote desktop app for the Mac, and Astropad built it for use with AI. Workbench uses the LIQUID engine that Astropad designed for Luna Display and Astropad Studio.


Using Workbench, you can control your AI agents remotely on an iPhone, making it ideal for people who have set up a ‌Mac mini‌ as a personal server for OpenClaw and other agentic AI platforms. Workbench can be used to check logs and verify agent work, restart failed tasks, or reconnect to long-running jobs. Workbench is more full-featured than options like Remote Control for Claude Code, because Anthropic's tool only provides terminal access, while Workbench offers access to your full desktop.


Workbench lets you monitor your AI agents from anywhere with no need to be tied to a desk. Astropad has native apps for Mac, iPhone, and ‌iPad‌, so you can interface with your Mac desktop from an iPhone or ‌iPad‌ no matter where you are. There are even tools for quickly switching between multiple Macs connected to a Workbench account.


The app supports high-fidelity streaming with a unified virtual display for multiple monitors, low latency, voice dictation, and multiple control options, including gestures, keyboard input, mouse, and Apple Pencil. For large desktops, there's a mini-map that helps with navigation.


Setup is simple thanks to a global relay network across 11 regions, with no network configuration required. End-to-end encryption protects your data, and no display recordings are captured and saved.

Workbench requires macOS 15 or later, iPadOS 26 or later, and iOS 26 or later. It will work best on Apple silicon Macs, with limited support on Intel Macs.


Workbench is free to use for 20 minutes each day, with an unlimited paid plan available for $10 per month or $50 per year.

Astropad is giving away a 16GB ‌Mac mini‌ with a 512GB SSD. To enter to win, use the widget below and enter an email address. Email addresses will be used solely for contact purposes to reach the winner(s) and send the prize(s). You can earn additional entries by subscribing to our weekly newsletter, subscribing to our YouTube channel, following us on Twitter, following us on Instagram, following us on Threads, or visiting the MacRumors Facebook page.

Due to the complexities of international laws regarding giveaways, only U.S. residents who are 18 years or older, UK residents who are 18 years or older, and Canadian residents who have reached the age of majority in their province or territory are eligible to enter. All federal, state, provincial, and/or local taxes, fees, and surcharges are the sole responsibility of the prize winner. To offer feedback or get more information on the giveaway restrictions, please refer to our Site Feedback section, as that is where discussion of the rules will be redirected.


Astropad Workbench Giveaway
The contest will run from today (May 1) at 9:00 a.m. Pacific Time through 9:00 a.m. Pacific Time on May 8. The winner will be chosen randomly on or shortly after May 8 and will be contacted by email. The winner will have 48 hours to respond and provide a shipping address before a new winner is chosen.Related Roundup: Mac miniTags: Astropad, GiveawayBuyer's Guide: Mac Mini (Caution)Related Forum: Mac mini
This article, "MacRumors Giveaway: Win a Mac Mini to Run AI Agents With Astropad's 'Workbench' App" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
You'll find great deals on Apple's M5 MacBook Air, Apple Watch Series 11, and a few AirPods models this week. The highlight is the 46mm cellular Apple Watch Series 11 at the new all-time low price of $399.00, a $130 discount that can be found on Amazon.

Note: MacRumors is an affiliate partner with some of these vendors. When you click a link and make a purchase, we may receive a small payment, which helps us keep the site running.

M5 MacBook Air


What's the deal? Take $149 off M5 MacBook Air
Where can I get it? Amazon
Where can I find the original deal? Right here
$149 OFF13-inch M5 MacBook Air (512GB) for $949.99
$149 OFF15-inch M5 MacBook Air (512GB) for $1,149.99

Amazon has a few record low prices on the new M5 MacBook Air this week, with $149 off select models of the brand new notebook. You can get the 512GB 13-inch M5 MacBook Air for $949.99, down from $1,099.00, available in all colors.

Apple Watch Series 11


What's the deal? Take up to $130 off Apple Watch Series 11
Where can I get it? Amazon
Where can I find the original deal? Right here
$100 OFFApple Watch Series 11 (42mm GPS) for $299.00
$100 OFFApple Watch Series 11 (46mm GPS) for $329.00
$100 OFFApple Watch Series 11 (42mm Cell) for $399.00
$130 OFFApple Watch Series 11 (46mm Cell) for $399.00

Amazon this week has all-time low prices on the Apple Watch Series 11, with up to $130 off numerous models of the smartwatch. This sale includes nearly every aluminum model of the Series 11 on sale at a record low price, plus new steep markdowns on cellular models.

AirPods


What's the deal? Take $49 off AirPods Pro 3
Where can I get it? Amazon
Where can I find the original deal? Right here
$49 OFFAirPods Pro 3 for $199.99
$29 OFFAirPods 4 for $99.99

Amazon this week has the AirPods Pro 3 available for $199.99, down from $249.00. This is a match of the all-time low price on the AirPods Pro 3, and it's accompanied by a solid deal on the AirPods 4.

If you're on the hunt for more discounts, be sure to visit our Apple Deals roundup where we recap the best Apple-related bargains of the past week.



Deals Newsletter

Interested in hearing more about the best deals you can find in 2026? Sign up for our Deals Newsletter and we'll keep you updated so you don't miss the biggest deals of the season!




Related Roundup: Apple Deals
This article, "Best Apple Deals of the Week: Rare $130 Discounts on Apple Watch Series 11, Plus AirPods and MacBook Sales" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
On this week's episode of The MacRumors Show, we answer your listener questions about the future of Apple's product lineup, the software and services shaping the ecosystem, and our own personal histories with the company and its devices.

Subscribe to The MacRumors Show YouTube channel for more videos

Some questions center on the iPhone Air and its future direction, including whether Apple might adopt silicon-carbon battery technology for a second-generation model, or prioritize adding a second camera lens instead. There is also interest in how ‌iPhone Air‌ might evolve with features like a vibrating surface speaker.

The foldable iPhone generates a lot of discussion, with questions touching on whether listeners would choose it over an ‌iPhone Air‌, whether it could replace both an iPhone and iPad mini, and whether its arrival signals the end of the dedicated compact tablet.

Broader hardware questions include when the 11th-generation iPad will be updated, when Apple plans to complete the OLED with ProMotion rollout across its entire laptop lineup, whether the MacBook Neo risks cannibalizing ‌iPad‌ sales, and what the future holds for Apple Vision Pro given its underwhelming reception.

On the software side, questions cover what visionOS might look like several years down the line, Photomator's future and whether Apple intends to develop it into a proper Lightroom alternative, and whether Apple is falling behind competitors like Alexa on basic smart home automation, pointing out that HomePod still relies on Shortcuts for many routines that Alexa handles natively.

The general tech questions are the most varied, asking which Apple device would cause the biggest bottleneck if swapped for an entry-level version, whether we would attempt an Apple Watch-only week without an iPhone, and what device combinations we actually rely on day to day. There is also curiosity about Nothing as a brand and whether it is worth taking seriously, as well as concerns about the escalating cost of MacBook Pro models and where the ceiling might be.

A number of questions are more personal, asking about our first Apple products, what originally drew us to the ecosystem, our favorite and oldest devices, and whether family members using non-Apple products causes any friction. ‌The MacRumors Show‌ has its own YouTube channel, so make sure you're subscribed to keep up with new episodes and clips.

Subscribe to The MacRumors Show YouTube channel!

You can also listen to ‌The MacRumors Show‌ on Apple Podcasts, Spotify, Overcast, or other podcast apps. You can also copy our RSS feed directly into your player.



If you haven't already listened to the previous episode of The MacRumors Show, catch up to hear our discussion about Apple's bombshell announcement that Tim Cook will step down as CEO on September 1, 2026, with hardware engineering chief John Ternus set to succeed him.

Subscribe to ‌The MacRumors Show‌ for new episodes every week, where we discuss some of the topical news breaking here on MacRumors, often joined by interesting guests such as Kayci Lacob, Kevin Nether, John Gruber, Mark Gurman, Jon Prosser, Luke Miani, Matthew Cassinelli, Brian Tong, Quinn Nelson, Jared Nelson, Eli Hodapp, Mike Bell, Sara Dietschy, iJustine, Jon Rettinger, Andru Edwards, Arnold Kim, Ben Sullins, Marcus Kane, Christopher Lawley, Frank McShan, David Lewis, Tyler Stalman, Sam Kohl, Federico Viticci, Thomas Frank, Jonathan Morrison, Ross Young, Ian Zelbo, and Rene Ritchie.

‌The MacRumors Show‌ is on X @MacRumorsShow, so be sure to give us a follow to keep up with the podcast. You can also email us at [email protected] or head over to The MacRumors Show forum thread. Remember to rate and review the podcast, and let us know what subjects and guests you would like to see in the future.Tag: The MacRumors Show
This article, "The MacRumors Show: Your Tech Questions Answered" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Apple's most affordable MacBook ever appears to be a resounding hit with customers, based on comments shared by CEO Tim Cook this week.


On an earnings call on Thursday, Cook said that customer response to the MacBook Neo has been "off the charts" since the laptop was unveiled in March.

"We could not be happier with how things are going at the moment," he said.

Apple was very optimistic about the MacBook Neo before announcing it, but the company still "undercalled" the level of enthusiasm that the laptop would generate, according to Cook. He said that MacBook Neo demand has exceeded Apple's expectations and helped to drive a record number of first-time Mac buyers last quarter.

"We're very focused on customers new to the Mac and customers that have been holding on to their Mac a very long period of time," said Cook.

As a result of high demand, Cook added that the MacBook Neo is currently "supply constrained." For orders placed today, Apple's online store in the U.S. currently shows a 2-3 week delivery estimate for all configurations of the laptop.

Apple released the MacBook Neo on March 11, following a week of pre-orders. In the U.S., pricing starts at just $599 for the general public and an even lower $499 for college students and qualifying educational staff. Powered by a version of the iPhone 16 Pro's A18 Pro chip, the laptop is available in Citrus, Blush, Indigo, and Silver finishes.Related Roundup: MacBook NeoTag: Tim CookBuyer's Guide: MacBook Neo (Buy Now)Related Forum: MacBook Neo
This article, "Apple Was Caught Off Guard by MacBook Neo's 'Off the Charts' Demand" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
A new entry-level iPad 12 with Apple Intelligence support likely remains months away, based on a comment shared by an Apple executive this week.


On an earnings call on Thursday, Apple's CFO Kevan Parekh said that the company's iPad revenue in the March-June quarter will face a "difficult compare" due to the the launch of the entry-level iPad 11 with the A16 chip in March 2025.

Parekh is essentially saying that Apple's year-over-year iPad revenue growth might be impacted in the current quarter, as a result of the company having no plans to update the entry-level iPad this quarter like it did in the year-ago quarter. If an iPad 12 were to be coming this quarter, this "difficult compare" remark would have been unlikely.

In short, do not expect an iPad 12 to be released during Apple's current fiscal quarter, which runs through June 27. That seemingly rules out a product announcement at the WWDC 2026 conference taking place from June 8 through June 12.

Here is Parekh's full comment:

While it appears that an iPad 12 will not be released through June, a launch later this year is still possible. In March, Bloomberg's Mark Gurman said an entry-level iPad with an A18 chip was "ready to go" and "still coming this year."

An earlier report from Macworld's Filipe Espósito claimed that the iPad 12 will actually have an A19 chip, so we will have to see which report turns out to be accurate. In any case, both the A18 and A19 chips are compatible with Apple Intelligence, which is something that the current iPad base model with an A16 chip lacks.

Apple Intelligence is already available on all other current-generation iPad models, including the iPad mini, iPad Air, and iPad Pro.

No other major changes have been rumored so far for the iPad 12, so we expect the device to have the same overall design as the current model. In the U.S., the device currently starts at $349 and is available in pink, yellow, blue, and silver.Related Roundup: iPadTag: Apple IntelligenceBuyer's Guide: iPad (Don't Buy)Related Forum: iPad
This article, "Here's When to Expect an iPad 12 With Apple Intelligence" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
A Weibo leaker today suggested that Apple's iPhone Air 2 may be the only next-generation ultra-thin flagship smartphone from a major brand, after the original model's poor sales performance appears to have led competing manufacturers to abandon plans for their own follow-up products.


The leaker known as "Digital Chat Station" today posted on Weibo, claiming that the ‌iPhone Air‌ barely surpassed 700,000 unit activations even after multiple rounds of price reductions. The post also noted that an unspecified domestic Chinese ultra-thin device managed only 50,000 activations, and that the rival's planned follow-up now looks "highly precarious" and is in all likelihood going to be scrapped. The leaker concluded that the ‌iPhone Air‌ 2 may end up as the sole ultra-thin flagship of the next generation.

The ‌iPhone Air‌ has struggled commercially since its September 2025 launch. A KeyBanc Capital Markets survey found "virtually no demand" for the device, supply chain analyst Ming-Chi Kuo reported that suppliers had been asked to cut capacity by more than 80% between launch and early 2026, and the ‌iPhone Air‌ is now widely believed to be entirely out of production.

The device's poor reception has reverberated across the industry. Xiaomi reportedly planned a "true Air model" to rival Apple's offering, while Vivo targeted thinness within its mid-range S series. Both companies are said to have halted related projects. Samsung similarly cancelled the Galaxy S26 Edge after the Galaxy S25 Edge sold poorly.

Despite all of this, a separate leaker claimed last month that Apple will push ahead with at least two generations of the device regardless of sales performance. Reports are now aligned around a spring 2027 launch, with the delay attributed both to poor sales of the original and to Apple's new split launch strategy, which moves the standard iPhone 18, iPhone 18e, and ‌iPhone Air‌ 2 to a spring window while reserving fall 2026 for the iPhone 18 Pro, ‌iPhone 18 Pro‌ Max, and foldable iPhone. Reports from Nikkei Asia, Bloomberg's Mark Gurman, and The Information all point to an early 2027 release.

Apple is said to be significantly revising the ‌iPhone Air‌ 2 to address the main criticisms of the original. The Information reported that Apple is considering adding a second rear camera, likely an Ultra Wide lens to complement the existing 48-megapixel Fusion camera, along with lower pricing. Other rumored changes include reduced weight, vapor chamber cooling, and increased battery capacity. Apple is believed to have requested an ultra-thin Face ID module from suppliers to free up internal space for the additional camera. According to The Elec, Apple also plans to bring a thinner, brighter Samsung OLED technology called CoE (Color Filter on Encapsulation) to the ‌iPhone Air‌ 2, after debuting it first on the foldable iPhone.Related Roundup: iPhone AirTag: Digital Chat StationBuyer's Guide: iPhone Air (Buy Now)
This article, "iPhone Air's Poor Sales Spook Rivals Into Ditching Ultra-Thin Phone Plans" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
MacRumors is pleased to announce our Seventeenth Annual MacRumors Blood Drive, throughout the month of May 2026. Let's save lives together by encouraging donations of blood, platelets, and plasma, and signing up as bone marrow and organ donors. While most blood drives are specific to a geographic location, our blood drive is online and worldwide. Anyone can participate.


Over the past 16 years, MacRumors Blood Drives have recorded donations of 1,795 units of blood, platelets, and plasma, cheered for donors, and celebrated new signups for the bone marrow and organ donor registries. We've heard from hundreds of forum members who donate or whose lives were saved by the donations of strangers.

This year's featured donor is user m53rd. Not only is he a blood donor, registered as an organ donor, and registered as a bone marrow donor, but he's already been an organ donor, having donated a kidney and then 60% of his liver to people in need. It's a magnificent example how a single person can save many lives.

Whether you're a regular donor or someone overcoming apprehension to donate for the very first time, we welcome and congratulate you.


How to participate in the MacRumors Blood Drive

If you are an eligible donor, schedule a blood, platelet, or plasma donation (FAQ) at any donation center near you. Post in the MacRumors 2026 Blood Drive! thread to tell us about it. Also post if you sign up for the bone marrow registry (FAQ) or register as an organ donor. We'll add all registrants to our Honor Roll.
Not everyone is eligible to donate blood, due to their health status or based on risk factors that result in deferrals (see LGBTQ+ donor information). If you aren't eligible to donate blood, please encourage a friend or relative to make a donation, and let us know. If they donate, you'll both be added to our Honor Roll.
Share our #MacRumorsBloodDrive message with friends, relatives, and followers. Help us thank the forum members who post in the MacRumors 2026 Blood Drive! thread.
After the MacRumors Blood Drive ends on May 31, continue recording your blood, platelet, and plasma donations, from June 2026 through next April 2027, on our Team MacRumors 2026-2027 page (instructions). We'll tally your donations and count them for the MacRumors 2027 Blood Drive next May.Tag: MacRumors Blood Drive
This article, "MacRumors 2026 Blood Drive" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
I work on Coding Agent Sandboxes, aka “sbx” at Docker. The project provides secure, microVM-based isolation for running AI coding agents like Claude Code, Gemini, Codex, Docker Agent and Kiro. Agents get full autonomy inside a sandbox (their own Docker daemon, network, filesystem) without touching your host system. Over the past couple of weeks, we built something on top of it: a virtual team of seven AI agent roles that test the product, triage issues, post release notes, and even fix bugs, all running autonomously in CI. We call it the Fleet.
The Fleet is built on Claude Code skills: markdown files that give an agent a persona, a set of responsibilities, and the tools it’s allowed to use. Think of a skill not as a script that says “run these steps,” but as a role description that says “you are the build engineer, here’s what you know and how you make decisions.” That distinction matters because agents need judgment, not just instructions. When a test fails unexpectedly, a script stops. A role investigates.
The same skill file, the same behavior, whether it runs on a developer’s laptop or in CI.
Local First, CI Second
Coding Agent Sandboxes is a CLI tool (sbx) that manages sandbox lifecycles: create, start, stop, remove, configure networking, mount workspaces, and more. It runs on MacOS, Linux and Windows. Every release needs testing across both platforms, across upgrade paths between versions, and under sustained load to catch resource leaks. The team also needs daily visibility into what shipped, and a way to triage the growing issue backlog without it becoming a full-time job.
We could have written traditional test scripts and reporting tools. Instead, we built agent roles that handle these tasks autonomously, both on our laptops and in CI.
The design principle behind the Fleet is simple: every skill runs on your machine first.
When we built the /cli-tester skill (the Fleet’s exploratory tester, more on that below), we didn’t start by writing a GitHub workflow. We started by invoking it locally. We watched it build the binaries, exercise the CLI commands, find issues, and report them. We tweaked the skill until it did the right thing in our terminal. Only then did we wire it into a workflow.
This matters because the alternative is painful. If you build CI-only agents, you debug them through commit-push-wait-read-logs cycles. Every iteration takes minutes. When the skill runs locally first, the iteration takes seconds. You see the agent think. You see where it gets confused. You fix the skill file, re-invoke, and try again.
CI is just another runtime for the same skill. The /cli-tester that runs nightly on MacOS, Linux and Windows runners is the exact same skill we invoke from our terminals. The workflow sets up the environment, checks out the code, and calls the skill. That’s it. No separate “CI version.” No translation layer. One skill, two runtimes.
This is what makes the Fleet practical. You’re not maintaining two systems. You’re maintaining one set of skills and a set of workflows that invoke them.
The Roster
The skills directory has 20 skills in total. Most are foundational knowledge (architecture, code style, Go conventions, security, testing patterns). Seven of them are the Fleet: the roles that run autonomously on CI. Each one is a SKILL.md file that describes a persona, not a procedure.

/build-engineer is the foundation that other skills stand on. It references topic files for building binaries, container templates, and local installs. It knows the Taskfile.yml, the docker-bake.hcl, and the platform-specific build flags. It doesn’t run on CI by itself. Other skills load it when they need to compile anything.
/project-manager is the team’s memory. It deduplicates findings against existing issues and PRs before creating new ones, manages the GitHub Projects board (setting status, priority, and labels), and handles interactive triage when running locally. On CI, it switches to fully automatic mode: no questions asked, just deduplicate and create. It uses GraphQL pagination to scan the entire project board, not just the first page. Every other skill that discovers something calls the project-manager before opening an issue.
/product-owner translates commit-speak into human language. It collects merged PRs from a date range, categorizes them (New Features, Bug Fixes, Improvements, Documentation, Maintenance), and rewrites each one in plain English. “feat(cli): add TZ env passthrough” becomes “Docker Sandboxes now automatically use your local timezone.” On CI, it outputs Slack Block Kit JSON. Locally, it renders a markdown table. It filters out noise from bots (Dependabot bumps, workflow-only changes) and skips posting when there’s nothing meaningful to report.
/cli-tester is the exploratory tester of the Fleet, and it’s the largest skill by far. Unlike traditional test scripts that assert expected output and fail on any deviation, the cli-tester investigates what it finds. When output doesn’t match expectations, it asks why before filing a bug.
It defines 52+ test scenarios organized into 14 tiers: Core Lifecycle, Agent Smoke, Workspace, Network Policy, Sandbox Features, Blueprint, CLI UX, Environment, Code Tasks, Agent Network, Reliability, Collaboration, Error Recovery, and Human-Only (skipped in CI). It builds the binaries through the build-engineer, triages findings through the project-manager, and loads product scenarios defined by the actual Product Manager on the team. It monitors disk space during testing, posts an executive summary to Slack when it finishes, and runs nightly on CI across MacOS, Linux and Windows.
It also powers a slash command on GitHub. When someone comments /cli-tester-review on a pull request, CI spins up three runners (MacOS, Linux and Windows), each loading the skill to exercise the PR’s changes on that platform. The agents explore the code, run the scenarios, and post their findings as comments directly on the pull request.
/performance-tester runs in two modes. Lifecycle Endurance repeatedly cycles create/stop/rm to detect reliability issues and resource leaks, producing xUnit JSON output. Code Exploration Benchmark clones a real Git repository and compares host-vs-sandbox I/O performance and Claude Code session behavior. Both modes measure disk usage over time and flag regressions. The goal is catching the slow degradation that no single test run would notice.
/upgrade-tester runs a four-phase test plan. Phase A creates pre-upgrade state (sandboxes, configurations). Phase B installs the new version. Phase C verifies everything still works after the upgrade. Phase D optionally downgrades and verifies again. It takes two version tags as input, builds the binaries for each, creates VMs, and produces an executive summary with pass/fail per phase. Upgrade regressions are the kind of bug that’s invisible in a single-version test suite.
/software-engineer operates in two modes. Reactive: when someone adds the agent-fix label to a GitHub issue, a MacOS runner picks it up and runs a ralph-loop to work the issue, contributing a PR with minimal, focused changes. Proactive: weekly, it runs in architect mode, scanning the codebase for quality issues, producing up to five findings, triaging them through the project-manager, then spawning three MacOS runners in parallel to fix three of them. Each runner delivers a PR targeting a specific simplification or tech-debt reduction.
Skills That Compose
Individual skills are useful. Skills that load other skills are a team.
The seven Fleet roles sit on top of thirteen foundational skills: architecture, code style, Go conventions, software design, security, testing patterns, development workflow, git worktrees, and others. The foundational skills encode project knowledge. The Fleet roles encode behavior. A Fleet role loads the foundational skills it needs, the same way a new team member reads the project’s contributing guide before writing code.
The /cli-tester doesn’t know how to build binaries. It loads the /build-engineer for that. It doesn’t know whether the bug it found is a duplicate. It loads the /project-manager to check. The tester focuses on testing. The builder focuses on building. The manager focuses on triaging. Each role stays in its lane, and the composition creates something none of them could do alone.
The /software-engineer follows the same pattern. It loads the /build-engineer so it can compile the project, and it loads coding best practices and software design conventions so its output meets the team’s standards. The skill doesn’t try to encode everything. It delegates to the foundational skills.
The /performance-tester loads the /cli-tester, extending it with duration and metrics. Instead of duplicating the testing logic, it reuses it and adds a measurement layer on top.
This is the skills-as-roles principle in practice. When you design skills as personas with clear responsibilities (instead of step-by-step commands), they compose naturally. A tester that loads a builder and a manager is doing the same thing a human tester does: asking a colleague to compile the project and checking with the PM before filing a bug. The difference is that the “asking” happens through skill composition instead of a Slack message.
The Ralph-Loop Is the Engine
The Ralph Wiggum loop is a pattern popularized by Geoffrey Huntley in 2025: a Bash loop that keeps feeding an AI coding agent the same task until the work is done. At its simplest, it’s while :; do cat PROMPT.md | claude-code ; done. Each iteration spawns a fresh agent with a clean context window. The agent reads the task, implements one piece, runs the tests, commits if they pass, and exits. The loop restarts, and the next iteration picks up where the previous one left off. Instead of hoping for first-try perfection, you design for iteration.
Our implementation of this pattern is called a Ralph-loop. The Fleet skills define what each agent role knows. The Ralph-loop defines how the iteration runs.
Our Ralph-loop is a composite GitHub Action backed by a shell script that adds a layer on top of the basic pattern: a separate worker and reviewer. It fetches the issue context, creates a working branch, and iterates: the worker implements changes and writes a summary, the reviewer evaluates the diff and decides SHIP or REVISE. If REVISE, the feedback goes back to the worker for another pass. Up to five iterations by default. If the reviewer says SHIP, the loop pushes the branch, creates a PR, and comments on the original issue.
The worker and reviewer run as separate Claude invocations with different models. The worker uses Opus for implementation. The reviewer uses Opus with 1M context to evaluate the full diff against the task requirements. Each one loads the /software-engineer skill (which in turn loads the build-engineer and coding best practices), so they share the same project knowledge but apply it from different perspectives.
Separating generation from evaluation is deliberate. The same agent that wrote the code shouldn’t evaluate whether the code is good. It’s the oldest principle in quality assurance: the person who built the thing shouldn’t be the only person who tests it. The worker’s job is to solve the problem. The reviewer’s job is to decide whether the problem is actually solved.
The Ralph-loop works locally too. The same ralph-loop.sh script that CI calls can be invoked from your terminal with --issue-number 42. Locally, it parses CLI arguments instead of reading environment variables, and outputs plain text instead of streaming JSON. Same loop, same prompts, same iteration pattern. We debugged the worker and reviewer prompts on our laptops before they ever ran in CI.
The workflows handle scheduling and triggering: nightly cron for the testers, label events for the software-engineer, weekly cron for the architect mode. The Ralph-loop handles the iteration pattern. The skills handle the domain knowledge. Three layers, each with a clear job.
This separation is what made the Fleet possible to build in a couple of weeks. We didn’t have to reinvent the automation loop for every role. The Ralph-loop already knew how to iterate. We just needed to give each role its own skill file and wire the triggers.
What the Fleet Ships
The Fleet has been running for a couple of weeks. Here’s what it delivers.
Automated issue resolution. A team member labels an issue with agent-fix. The CI grabs a MacOS runner, reads the issue, and starts working. The result is a pull request that addresses the issue. Not every PR lands without changes, but the first draft is there for review, often within the hour.
Daily release notes. The product-owner traverses the git log every day and posts a Slack summary for stakeholders. No one has to manually compile “what shipped this week.” The stakeholders see progress in real time, at the speed the team actually moves.
Nightly exploratory testing. The cli-tester runs every night on MacOS and Windows. It loads the product scenarios that the Product Manager has defined, exercises the CLI, and opens issues for anything it finds. Before opening an issue, it checks for duplicates through the project-manager. When it finishes, it posts a Slack message with the results.
Performance and upgrade testing. The performance-tester and upgrade-tester run on CI across both platforms. Disk usage regressions, behavioral differences between sandbox and non-sandbox modes, and version compatibility issues get caught before they reach a human reporter.
Weekly tech-debt reduction. Every week, the software-engineer runs in architect mode. It reviews the codebase, identifies three spots where code can be simplified or legacy patterns can be cleaned up, spawns three parallel runners, and delivers three PRs. Each one is a small, focused improvement. Over time, they compound.
What We Don’t Automate
The Fleet creates pull requests. It does not merge them.
That’s the trust boundary, and it’s deliberate. Merge decisions stay with humans. So do architectural choices, scope decisions, and prioritization. The agents do the work. The team decides what work matters and whether the output meets the bar.
The supervision model scales the same way it works on a developer’s laptop. When we run multiple agents locally in parallel worktrees, we review their output before merging. With the Fleet, the team supervises seven agent roles running on CI. The shape of the oversight is the same: review the output, approve or adjust, move on. The difference is that the agents don’t need anyone’s laptop to start working.
The Fleet is not replacing the team. It’s extending it. Seven roles that handle repetitive, well-defined work so humans can focus on work that requires judgment, context, and taste. The Fleet has many arms, but the team still steers the ship.
What We Learnt Building the Fleet
Start with the foundation, not the flashiest skill. We started with the /cli-tester because testing the CLI felt like the highest-value target. But it needed to build binaries, triage issues, and load product scenarios, all things that depended on other skills we hadn’t written yet. We should have started with the /build-engineer, the skill everything else stands on. The second skill was better because of what we learned from the first. Don’t design the full fleet upfront.
Build locally first, deploy to CI second. The commit-push-wait-read-logs cycle is where velocity goes to die. If you can’t debug a skill in your terminal, it’s not ready for a workflow. Some behaviors only surface on CI runners (different OS, permissions, network constraints), and those iterations cost hours of wall-clock time. Minimize what can only be tested in CI.
Write skills as roles, not scripts. Ask yourself: “If a new team member joined tomorrow with this exact role, what would I tell them?” What do they need to know? What tools can they use? How should they handle ambiguity? That conversation is your SKILL.md. “You are the build engineer, here’s what you know” produces better judgment than “run these five steps.” When something unexpected happens, a role investigates. A script stops.
Compose skills like you compose teams. The /cli-tester doesn’t know how to build binaries or triage bugs. It loads the /build-engineer and /project-manager for that. Each role stays in its lane. The composition creates what none of them could do alone.
Separate generation from evaluation. The agent that wrote the code shouldn’t be the only one that reviews it. Our Ralph-loop uses a worker and a reviewer for a reason: the oldest principle in quality assurance applies to agents too.
Triage matters more than detection. The /cli-tester initially filed issues for every unexpected output. Transient failures, timing-dependent behavior, environment quirks: everything became an issue. The signal-to-noise ratio got bad enough that the team started ignoring findings. Getting the triage right (deduplication, confirming before filing) took longer than building the tester itself.And one more thing. All Fleet agents, even on ephemeral CI runners, run inside Coding Agent Sandboxes. We test with what our users use.
View the full article
The following is the list of F5 Distributed Cloud Services technical knowledge updates:
IP Addresses and Domains
Updated the F5 Customer Edge IP Address and Domain Reference for Firewall or Proxy Settings guide. Added new IP address and domain to sections "Public IPv4 Addresses for Site Registration and Updates (Legacy)" and "Egress Domain Rules (Legacy)".
View the full article
Business email compromise (BEC) is still thriving even in organizations that have implemented multi-factor authentication (MFA). As security professionals, we often assume that MFA is the silver bullet for email security, but real-world incidents suggest otherwise. Attackers exploit human behaviors, process gaps and operational blind spots that MFA alone cannot address. In many modern BEC cases, no account is technically compromised at all, which places these attacks outside the protection boundary of MFA controls.
In 2019, Toyota Boshoku Corporation fell to a BEC attack with an employee transferring over $30m to scammers following a cloned email from a 3rd party company with urgency citing the need for the transaction to be completed urgently so as not to slow down Toyota’s production line. There was no indication that the Toyota employee’s email had been compromised. Take also the 2024 case of Arup where attackers impersonated a senior manager using Deepfake voices and videos and convinced a member of the finance team to make payments totaling $25m. The compromise did not rely on stolen credentials but on carefully orchestrated social engineering, timing and the finance team’s procedural shortcuts.  The technical safeguards could have been strong, but human oversight proved to be the weakest link. In both cases, the failure occurred at the decision point, not at the authentication layer, exploiting trust, timing and established, convenient, approval habits.
Where security controls end and business risk begins
From experience, this scenario is all too common. Organizations often focus on deploying security technology without addressing human workflows and culture. This often includes shiny new EDR technology which are used to check boxes for audit and compliance purposes, and which CIOs are quick to sign off on to show stakeholders they are cyber resilient. This is not a failure of EDR itself, but of how security investments are scoped. Endpoint and identity controls protect systems, but they do not govern how financial approvals, vendor changes or executive requests are validated in practice.
MFA reduces risk but cannot replace the need for process controls, verification routines and continuous awareness training especially as there are now AITM phishing kits which bypass MFA in the wild. The operational blind spots being exploited sit in business workflows where speed, trust and authority override verification, particularly in finance and procurement processes.
These blind spots exist because business processes are optimized for speed and continuity, not verification. Finance teams are trained to keep operational lines moving, and attackers who have now taken cognizance of this, use this advantage to their own advantage by introducing urgency or invoking authority. When a request appears legitimate, time-sensitive and from someone with perceived authority, employees often follow familiar patterns rather than pause to challenge intent. This is not a failure of technology, but a failure of process design.
Practical steps for IT leaders include redesigning approval workflows so that high-value transactions require multi-step verification including out-of-band call to confirm, simulating BEC scenarios in realistic exercises to identify gaps in response and decision-making, embedding security awareness into daily routines using micro-learning and real incident reviews, and empowering teams to challenge unusual requests without fear of reprisal. Instances of successful attacks can also be shared with employees who distribute invoices, financial documents or oversee making decisions regarding transfers
Designing approval workflows that thwart BEC attacks
Redesigning approval workflows means explicitly defining what constitutes a high-risk request, such as first-time payments, changes to vendor banking details, sudden payment requests from an executive or requests that bypass standard procedures. These requests should require independent verification using known contact details, not information provided in the email itself.
When reviewing and redesigning approval workflows, organizations should begin by asking salient, hard, operational questions at the decision-making point. Does this request align with how payments are normally initiated/approved? Is the requester the typical communication channel and tone? Has this vendor or account been paid before, and under similar circumstances? Does the email tally with the one on the sender’s company website without alterations? Is there a different reply-to email visible? Can a quick call to confirm be made? Teams should also ask what assumptions are being made under time pressure, whether authority is being inferred rather than verified, and who is accountable if the decision turns out to be wrong. These questions force employees to slow down, recognize deviations from normal behavior and treat unusual requests as potential security events rather than routine business tasks.
Simulating BEC transcends phishing tests and should mirror real business scenarios, including urgent executive requests or supplier payment changes, allowing organizations to observe how staff respond to pressure and ambiguity. Effective simulations introduce urgency, impersonate authority figures with typosquatted emails and exploit realistic business contexts such as end-of-quarter payments, supplier changes and times of the year when attackers like to strike such as festive periods and before holidays. Participants are observed on how they verify requests, whether they escalate concerns and how quickly they move to execution without confirmation. The outcome is not a pass or fail score but can provide insight into where processes encourage compliance over caution. These simulations allow organizations to refine approval rules, reinforce escalation paths and normalize verification as part of everyday operations.
Empowerment must be formalized through policy, making it clear that pausing or escalating a suspicious request is expected behavior, not an obstacle to productivity. Staff who report suspicious requests also should be encouraged and used as good examples in internal communications where possible.
Using friction and alerts in workflows
Insights from cross-border operations is that attackers exploit time pressure and executive assumptions often seen in CEO/CFO themed fraud. Teams often follow cues from perceived authority, scoped by attackers from email flows and urgency often attached to making large payments, tying them to critical business needs. By implementing friction in critical workflows such as mandatory pauses for large transfers or automated anomaly alerts, organizations can reduce risk without hampering productivity
Effective friction does not mean indiscriminately grinding the business or its process to a halt. Mandatory pauses for large or unusual transfers create space for verification and reduce impulsive decisions and actions. During these pauses, specific actions should occur, such as email/signature checks, verbiage, secondary approval, independent confirmation or automated checks against historical payment behavior as stated above.
Automated anomaly alerts are only useful when they focus on deviations that matter and are tied to clear response expectations. Alerts should prioritize scenarios such as out-of-hours payment requests, changes to established vendor details or transfers that fall outside normal patterns. Ownership of BEC-related alerts should sit with teams that control financial decisions, such as finance operations, fraud risk units or cross-functional payment risk groups that combine security and business authority, rather than being routed exclusively to noisy SOC queues.
To reduce false positives also, the concept of enhanced monitoring for priority accounts should also be introduced. This can be made better by routing emails containing specific payment keywords to these risk groups to evaluate before landing in the intended inboxes.
What security leaders should change now
BEC continues to succeed because human decision points are rarely treated as security-critical systems. MFA, email filtering and endpoint protections remain necessary, but they do not control how people make decisions under pressure. Until financial and executive workflows are designed with the same rigor applied to technical systems, attackers will continue to exploit the impact of human behavior on cybersecurity with social engineering and human weaknesses at the top of the pile.
Added to this, there should also be clear ownership of BEC risk at the leadership level. If no single role is accountable for payment verification failures, responsibility defaults to frontline staff under pressure who often bear the brunt of being sacked or prosecuted following successful BEC attacks. Assigning ownership to finance leadership, risk committees or cross-functional governance groups ensures that process failures are treated as systemic issues rather than individual mistakes.
Although equally important, leaders should not measure success solely by the number of blocked phishing emails, but by how often verification steps are followed, how many payment requests are challenged and how quickly suspicious transactions are paused and reviewed.
In conclusion, security leaders who reduce BEC risk align people, processes and technology so that verification becomes routine, hesitation is acceptable and authority is never assumed without confirmation. In 2026 and beyond, business workflows should continue to be treated as a core part of the security architecture and not a peripheral component.
This article is published as part of the Foundry Expert Contributor Network.
Want to join?

View the full article
Declining job satisfaction means that only one in three (34%) cybersecurity professionals plan to stay with their current employer, increasing the pressure on CISOs’ talent retention strategies.
And according to a survey of 500 cybersecurity professionals by IANS and Artico Search, while salary remains important it is not the primary driver of retention.
Flexible work models correlate strongly with satisfaction and retention, however. Hybrid work arrangements, particularly those that require only one to two days onsite per week, also tend to reduce the desire for talented cybersecurity staffers to jump ship, according to IANS’s Cybersecurity Talent Report.
The researchers found that wage growth is more important in minimizing staff turnover than the absolute value of compensation packages.
“As pressure on cyber teams skyrockets, CISOs who double down on mentorship, coaching, and career development can create a sense of purpose and progression that helps their employees avoid burnout,” says Nick Kakolowski, senior research director at IANS.
Cybersecurity staff who feel their employer views security as a priority (73%) are more likely to stay than those working for enterprises who perceive little or no organizational backing for security, where the desire to stay with their current employer drops to just 19%.
“Visibility, career growth, and support from security leadership are necessary to keep high performers,” adds Steve Martano, an IANS faculty member and partner at Artico Search.
Cybersecurity training and certification body ISC2 estimates that the global cybersecurity workforce gap peaked at 4.8 million in 2024. Although budget cuts last year have reduced the number of unfilled cybersecurity roles, the employment market remains tight and highly competitive. In CIO.com’s State of the CIO survey, cybersecurity tied AI for the hardest skill to fill despite notably higher demand for AI talent (42% to 38%).
Career progression and workplace autonomy
Along with flexibility, recruitment experts polled by CSO say that cybersecurity professionals consistently look for opportunities to develop their skills, to have agency over how they work, and to have their expertise taken seriously.
“When candidates see a defined career progression, the offer of ongoing certifications and training, direct visibility into strategy, and access to modern security stacks, that’s when your role becomes desirable,” says Archie Payne, president at recruitment agency CalTek Staffing.
Employers that fail to offer some form of remote, or at least hybrid work, will miss out on a sizable portion of the talent pool.
“We regularly see candidates decline otherwise strong offers because of rigid location requirements,” Payne says. “Again, top candidates know they are in-demand and won’t settle for a role that doesn’t support their work-life balance needs.”
Skills development
Richard Demeny, founder and CTO at Canary Wharfian, an online finance career platform, says that graduates and early professionals know they are calling the shots because even at the entry level talent is scarce.
“[New entrants] are prioritizing opportunity and learnings, as pay is pretty much standard across the board, except for maybe high-finance areas like hedge funds,” Demeny says.
“These professionals know that staying at the same employer for long will greatly limit their professional development: Often times, the best way to supercharge their knowledge, skills, and network is to simply change workplaces,” he adds, regarding rising employee turnover rates.
David Berwick, director at Adria Solutions, argues that CISOs need to be more consistent in their attempts to retain cybersecurity workers.
“Clear progression, realistic workloads, visible support from leadership, and flexibility where it makes sense,” says Berwick. “The organizations that get those fundamentals right tend to attract and retain people far more effectively than those relying on compensation alone.”
Avoiding burnout
Oliver Legg, co-founder of cybersecurity recruiter Aspiron Search, says that employee burnout is a growing problem for CISOs managing security teams.
“What we’re seeing in the market is that retention goes beyond pay and depends heavily on the environment you create, the support you show, and how you evolve alongside an increasingly complex threat landscape,” says Legg.
Security teams need to stay up to date with modern tooling to both defend against adversaries and keep teams engaged and effective.
“Cyber pros working with outdated tools or purely reactive processes are far more likely to disengage and look elsewhere,” Legg warns.
Growth and elevation
Offering cybersecurity staff learning opportunities can be a powerful driver of engagement and retention.
“Providing opportunities to attend or speak at industry conferences, along with support for new or refreshed certifications, helps teams stay motivated and continue developing,” Legg advises.
CalTek Staffing’s Payne notes that cybersecurity professionals are both “highly specialized and in high demand.” This means workers are “constantly being approached by companies eager for their talents and are well aware that their skills are in short supply,” he says.
Job candidates increasingly ask sharper questions about what their growth path would look like and whether they’ll have a voice in security strategy rather than focusing on compensation alone, according to Payne.
Earning employee engagement
Retention has become less about preventing dissatisfaction and more about continuously earning engagement.
“One of the biggest drivers of turnover we see is a disconnect between what the candidate was promised during the hiring process and what’s actually supported internally,” Payne says. “Many companies talk about security being ‘mission-critical’ but operate with chronically understaffed security teams, or don’t give the CISO budget authority.”
Payne concludes: “Strong candidates can spot this kind of problem very quickly, and they’ll leave just as fast.”
View the full article
The first time I approached an OT environment, I assumed that the strategies effective in IT cybersecurity would be equally applicable. I was wrong. The experience revealed a fundamental difference, highlighting the need for a distinct approach to OT cyber risk management.
The mistake was not technical. It was conceptual. I was treating OT as another security domain that needed stronger controls, better tooling and greater discipline. But OT lives under different conditions. Systems stay in service for years, sometimes decades. Patching is limited. Change windows are negotiated. Vendor dependencies are part of daily operations. Asset visibility is often incomplete and the highly distributed environments depend heavily on third-party access.
In summary, OT cyber risk fundamentally constitutes a challenge of leadership and governance. The primary concern at scale is not isolated technical controls at individual sites, but rather the enterprise’s ability to ensure consistent decision-making across all sites through clearly defined roles and shared accountability.
OT changes the nature of cyber risk
Boards have improved their cyber oversight of IT, but OT requires a different perspective. Here, cyber risk goes beyond data and compliance into operational processes, industrial assets and critical services.
OT architecture begins in the physical world, moves through control systems and operations networks, and increasingly connects to enterprise systems and cloud services. This creates a consequence profile distinct from IT, in which cyber risk directly affects physical operations.
OT operating constraints include long asset lifecycles, incomplete asset visibility, embedded third-party access, fragmented ownership across engineering, operations, site leadership, vendors and security. IT cyber assumptions often fail in OT because risk and responsibility structures diverge fundamentally.
The governance baseline for OT remains thin, as reflected in recent World Economic Forum research that highlights broader issues of leadership and oversight. Only 16 percent of organizations with industrial environments report OT security issues to their boards and just 20 percent maintain dedicated OT security teams. Furthermore, in only 36 percent of cases is the CISO directly responsible for OT security. These low levels of reporting and responsibility indicate not only a maturity gap in organizational processes but, more critically, a substantial accountability gap that directly reinforces the thesis: OT cyber risk management at scale is fundamentally a challenge of leadership and governance, rather than solely a technical concern.
At scale, a local weakness becomes an enterprise coordination issue. Differences in maturity, ownership, vendor dependencies and business priorities create uneven exposure. The board question is not whether OT controls exist, but whether the enterprise can make consistent, defensible decisions about OT cyber risk before and during disruption.
At scale, incident outcomes become leadership outcomes
Effective OT oversight shifts from control-by-control discussions to scenario and consequence analysis.
Common OT exposure paths include remote access abuse, shared accounts, weak segmentation, infected maintenance media, compromised workstations and poorly governed vendor connectivity. In OT, these exposures have direct operational consequences. A SCADA compromise can reduce visibility across power operations. Poor remote access governance can degrade rail operations. Infected media can trigger plant downtime. Unauthorized parameter changes can force emergency shutdowns and manual safety validation.
OT risk appetite cannot be reduced to the enterprise itself. OT impact may extend to the economy, environmental, critical services and, sometimes, human safety. As the consequences broaden, oversight standards must rise. A technical control gap is one risk. A governance structure that cannot support safe, coherent decisions under pressure is a different order of magnitude in terms of exposure.
In OT, incident outcomes are determined by leadership choices made before disruption begins.
Should the organization isolate quickly to stop propagation, or continue operating in a constrained way to protect essential output? Should authority be centralized to improve consistency, or federated to improve speed and local judgment? Should the organization restore quickly, or verify process integrity first and accept a longer recovery path? Should vendor and remote support remain broadly enabled for operational convenience, or be reduced because it has become part of the real perimeter? No single option is always correct. The key is whether leaders understand trade-offs before action is required. Executive decisions such as isolate versus operate, centralize versus federate and restore versus verify change outcomes. These are governance choices, not technical defaults.
I have seen both sides of this in practice. In one environment, centralization accelerated capability building. It improved consistency, but it also introduced the risk of slower decisions in a crisis because authority sat too far from the operational edge. In another, responsibility was distributed across business units, which improved local ownership but increased coordination risk under stress. The lesson was never ideological. It was operational. The operating model had to match the risk reality.
This is also why the strongest board-level conversations in OT are rarely about tools first. They are about decision rights, escalation logic, crisis thresholds and assurance. The NIST Cybersecurity Framework 2.0 is useful here not because it provides boards with a script, but because it explicitly frames cybersecurity as part of how organizations understand and manage cyber risk.
What boards should ask now
Boards do not need to become technical experts in OT. They do need to demand decision-grade oversight.
First, clarify the operating model. Who owns OT cyber risk across the enterprise? Where does business unit accountability sit? Which decisions are centralized and which are delegated? Who has authority in a crisis when continuity and containment are in tension? If these answers are unclear, residual risk is likely underestimated.
To help make this concrete, consider two common operating models. In a centralized model, OT cyber risk governance, tooling decisions and incident response authority reside primarily at the enterprise or group level, typically under the leadership of a central security or risk function. Local sites implement enterprise direction but have limited autonomy to define controls or crisis actions. In contrast, a federated model grants more decision rights to individual business units or operating sites. Here, local leaders often own OT cyber controls, incident triage and vendor management, while the central organization coordinates standards and provides guidance. Each model brings different trade-offs in consistency, speed and local adaptation. Directors should ask management to clarify which approach is in place today and why it fits the organization’s risk profile.
Second, identify the two or three OT cyber scenarios that would most impact continuity, key operations and external defensibility. Scenarios should be concrete enough to guide priorities, budget and crisis preparation. Generic statements about protecting critical infrastructure are not enough.
Third, require assurance. Boards should ask whether a baseline exists and whether it has been independently tested for effectiveness. Governance and assurance should sit above the technical baseline and operating model. In OT, site assessments, adversarial simulations, tabletop exercises and validation of remote access controls provide more insight than maturity scoring.
Fourth, address innovation. AI and cloud are changing operational environments, even when adoption begins at the physical layer. The leadership agenda is moving toward governance, resilience and control of increasingly complex digital dependencies. For OT, boards should treat these shifts as operating model and assurance questions, not just technology questions.
This is where the board agenda becomes practical. Directors should ask management to clarify decision rights, define the top OT cyber scenarios, establish an enterprise minimum baseline for priority environments and run independent assurance on the sites or operations that matter most. These are not technical housekeeping tasks. They are the foundations of defensible oversight.
This article builds on a recent RSAC session on managing OT risk at scale, but the lesson is broader. OT cyber risk at scale is not simply a controls problem. It is a leadership problem because real outcomes depend on governance, accountability and pre-agreed trade-offs. The organizations that navigate OT disruption better are usually not the ones with the most ambitious slide decks. They are the ones who decided in advance how they will govern, escalate, verify and recover.
That is what the shift boards should insist on. In OT, resilience is built by decisions made before the incident alarm sounds.
This article is published as part of the Foundry Expert Contributor Network.
Want to join?
View the full article
Artificial intelligence has had an immediate and profound impact on software development. Coding practices, coding tools, developer roles, and the software development process itself are all being reimagined as AI agents advance on every stage of the software development life cycle, from planning and design to testing, deployment, and maintenance.
Download the May 2026 issue of the Enterprise Spotlight from the editors of CIO, Computerworld, CSO, InfoWorld, and Network World and learn how to harness the power of AI-enabled development.
View the full article
According to IDC, agentic AI is on track to become mainstream infrastructure. The analyst firm expects 45% of organizations to have autonomous agents operating at scale across critical business functions by 2030. In enterprise SOCs, AI is already reshaping functions like alert triage, enrichment, data correlation, IOC validation and initial containment. It could soon move up the stack to take on more complex tasks like incident investigation, root cause analysis, and response.
“AI acts as a force multiplier in the SOC,” says Nicole Carignan, senior VP, security and AI strategy at Darktrace. But harnessing that promise will require organizations to invest now in reskilling analysts, redesigning processes, building new technical roles, and establishing guardrails and governance frameworks to ensure autonomous AI agents operate safely. “It’s not enough to simply deploy an AI solution. Security practitioners must understand how the underlying machine learning techniques function, what their strengths and limitations are, and how to evaluate their outputs,” Carignan says. “Without explainability and trust, AI risks are exacerbating alert fatigue rather than solving it.”
Here is what security leaders need to know — and do — to prepare their SOCs for the agentic AI era.
Reskill analysts to become AI collaborators and overseers
Increasingly, human roles in the SOC will shift from hands-on execution to supervision, governance, design, and oversight. As AI agents take on more operational tasks, analysts will need to focus on managing AI systems, interpreting outputs, and resolving the nuanced challenges machines cannot handle, says Casey Ellis, founder of Bugcrowd. “Jobs won’t disappear, they’ll adapt. The key is ensuring that SOC professionals are prepared for this shift through ongoing education, training, and tooling.”
Few expect the transition will occur organically or without friction. Many SOC leaders will need to reskill existing staff to manage AI effectively; to interrogate AI reasoning; enrich investigations with contextual insight; and apply informed human analysis to AI-driven outputs.
When acting on an AI tool’s recommendation, analysts must understand what questions the agent asked, which data sources it queried, and what evidence informed its decision, according to Dov Yoran, co-founder and CEO of Command Zero. From there, they need to be able to pivot to additional data sources, pursue new artifacts, and extend the investigative timeline as needed. “Junior analysts who might not know how to start an investigation from scratch can become effective by learning how to extend and refine what the agent produced,” Yoran says. “It’s a different skill set from traditional SOC work, and in many ways, a more accessible one.”
In the SOC of the future, analysts must also act as adversarial reviewers of AI-driven conclusions. That’s because AI systems can introduce hallucinations, training-data bias, and other vulnerabilities while also being vulnerable to adversarial manipulation. Analysts need to recognize these risks to ensure decisions remain grounded and defensible, says Ensar Seker, CISO at SOCRadar. “Analysts need to be trained less as button-pushers and more as adversarial reviewers of AI output. That means understanding how models reason, where they fail, how bias and data gaps surface, and how to interrogate confidence levels and assumptions. The goal isn’t to ‘trust AI faster,’ but to develop the instinct to ask: What would make this conclusion wrong?” Seker says.
Analysts will also play a critical role in enabling organization-specific context into AI-driven workflows. Without that context, agents risk missing threats, amplifying noise, or triggering risky actions based on incomplete information. SOC leaders need to remember that “AI agents are only as smart as the context they have access to,” Yoran says. Analysts must learn to annotate identities, maintain watch lists, document recurring false-positive patterns, and build enrichment layers that strengthen future investigations, he said, “This is knowledge work, not data work.”
Ultimately, the objective is not to outperform AI, but to do better where AI falls short. For example, “accept that autonomous alert triage will become table stakes,” Yoran says. “Your processes need to shift from ‘how do we triage every alert’ to ‘how do we handle escalations from autonomous investigations’.”
Build capabilities for AI governance, content and quality
Upskilling existing analysts alone is not enough. As AI agents begin operating across tools, making decisions and triggering actions with minimal human involvement, the demands on the SOC will extend well beyond traditional analyst capabilities, experts say.
Content engineering, for instance, is one emerging requirement. In an AI-enabled SOC, detection engineers will no longer write only static rules. They must design dynamic content such as questions, prompts and investigation templates that agents can use to reason, enrich data, correlate signals and act autonomously. These content engineers curate the structured inputs that power agents, including telemetry, threat models, and playbooks.
“This is the most underappreciated role in AI-powered security operations,” Yoran notes. “These are people who build and maintain the questions that agents can ask, the investigation plans that guide autonomous work, and the knowledge bases that provide context,”. Organizations need someone who can translate detection logic from their SIEM, import best practices from frameworks like MITRE ATT&CK, and encode institutional knowledge into the platform. “This isn’t traditional security engineering, it’s closer to knowledge management combined with threat intelligence,” he says.
Mature SOCs will also require clear ownership of AI governance and agent oversight. That includes roles that have oversight over model risk evaluation, prompt and policy management, continuous performance validation, and even red teaming the agents themselves, Seker says. “You don’t need a massive new team, but you do need clear accountability for how autonomous decisions are made, tested, and constrained.”
Another emerging need is analysts with deep fluency in data management. An AI-driven SOC will require professionals who understand how information should be classified, protected, normalized, and monitored to ensure reliable conclusions. “With 64% of organizations planning to add AI-powered solutions to their security stack in the next year, it is critical for professionals to cross-skill in AI,” Carignan says. “Cybersecurity professionals must become fluent in AI and data, developing a deeper understanding of data classification, governance, and model behavior.” Cross-skills in data science, machine learning, and cybersecurity enable analysts to critically evaluate AI outputs, tune models for security use cases, and adapt defenses as threats evolve, making them indispensable in an AI-augmented SOC.
Frank Dickson, an analyst at IDC, urged organizations to think of this capability as similar to a data architect role. “The key to getting value from AI is having data located in a place where you can get to it, having it formatted in a homogeneous way so you can do analysis on it, and then manage the data,” he says. “The success of your AI initiative is going to be tied to the effectiveness of your ability to get data. A data architect manages that.”
Dickson also emphasized the need for an “orchestration platform engineer” role responsible for ensuring effective communication and workflow integration across security tools. The SOC of the future will not hinge on a single platform but on an interconnected ecosystem of SIEM, EDR, SOAR, identity, cloud and other systems that must operate in concert to support AI-driven, agentic investigations and automation, Dickson tells. Dedicated orchestration expertise will become essential to maintain reliable data flows and automation logic in such an environment, he noted.
Redesign SOC processes and playbooks where needed
Organizations will need to review and rework SOC processes and playbooks to ensure their AI-augmented SOC is consistent, efficient and continuously learning. Yoran recommends that SOC leaders focus on codifying institutional knowledge into AI agent-accessible questions and plans. Translate playbooks into investigation plans that AI agents can follow on a repeatable basis. In situations where an agent might hit a wall, have processes in place for a smooth handoff to a human analyst and build feedback loops for continuous improvement, Yoran adds.
“Playbooks must shift from step-by-step human procedures to intent-based guardrails,” Seker points out. “Instead of telling analysts how to investigate, define what outcomes are allowed, what actions are prohibited, and when human approval is mandatory.”. The objective is not to micromanage every alert but to assume AI agents operate continuously across tools, with humans only supervising exceptions, edge cases, and strategic decisions.
SOCs also need to rethink metrics, accountability, and documentation within the SOC. Traditional performance indicators, such as ticket closure rates or mean time to resolution, may need to broaden to include model accuracy, escalation quality, and the effectiveness of automated containment actions. “The biggest mistake is optimizing for speed metrics instead of investigation quality,” Yoran says. “I see this constantly: vendors promising 90% faster time to resolution or reduce tier-one workload by 80% or close alerts in seconds instead of hours. These metrics while seductive are dangerous,” he cautions. “Making the same mistake faster benefits no one. An incomplete investigation that closes in two minutes isn’t better than a thorough investigation that takes 30 minutes.”
Auditability too becomes critical. All AI-driven decisions should be traceable, explainable, and reviewable from both an internal governance standpoint and for external compliance requirements.  “If you can’t explain why an AI took an action to an auditor, regulator, or executive, it shouldn’t be allowed to take that action. Explainability isn’t a nice-to-have; it’s a prerequisite for autonomy,” Seker says.
Implement AI guardrails and principles
Formal guardrails and operating principles are going to be critical in SOCs where AI agents influence decisions, initiate responses and help prioritize threats. That means setting defined boundaries around data access and model behavior, having processes to validate responses and making sure humans remain in the loop on all high-impact decisions.
Focus areas should include approval thresholds for autonomous actions, figuring out allowed and disallowed actions for an agent, protecting against prompt injection attacks, testing and red-teaming of agentic workflows and ensuring IR policies are updated for AI-driven actions. “Require transparent decision trails, rate limiting, least-privilege, and instant override,” Seker advises. “Hard limits on action scope, blast radius, and privilege are non-negotiable. Agents should operate under least-privilege identities, with explicit kill-switches, change-control boundaries, and environment awareness. The key is to ensure that AI is never allowed to silently escalate its own authority or modify guardrails without human approval.”
IDC analyst Dickson pointed to identity and access as two other areas to focus on by way of guardrails and policies. “In the past, when we gave humans access, we often over-provisioned by default. That approach does not work with agents. With agentic AI, permissions must start at least privilege, defined precisely from day one.”
The focus should be on ensuring no standing privileges, implementing dynamic authorization and establishing clear role definitions, Dickson says. “Agentic AI is enormously powerful. Constraining access correctly is non-negotiable.”
There’s no playbook for leading through today’s cyber risk — only experience. The CSO Cybersecurity Awards & Conference, May 11-13, brings together CISOs and senior security executives for peer‑driven insight, unfiltered conversations, and practical strategies that drive real business impact. Secure your seat before it fills up.
View the full article
Apple held its earnings call for the second fiscal quarter (first calendar quarter) of 2026 today after announcing its best March quarter ever. Apple saw revenue of $111.2 billion with double-digit growth across every geographic segment and across every product category. Apple CEO Tim Cook and Apple CFO Kevan Parekh provided insight into iPhone sales, Mac sales, RAM supply issues, and more.


We've rounded up the most interesting takeaways from the call.

iPhone 17 Sales

Apple attributed its success to the new iPhone models. Cook said "demand was off the charts," but Apple was facing supply constraints that impacted revenue. Had there not been supply issues, Apple would have seen higher revenue.

The A19 and A19 Pro chips from TSMC proved to be a bottleneck because TSMC uses the same 3nm process for AI chips that are in high demand. Cook said iPhone constraints were "primarily driven" by the availability of the advanced nodes Apple's SoCs are produced on.

According to Parekh, the iPhone 17 family is Apple's best-selling iPhone lineup to date. "The ‌iPhone 17‌ family is now the most popular lineup in our history... we believe we gained market share during the quarter," he said.

iPhone revenue was $57 billion, up 22 percent year-over-year, which is a new March quarter record. Apple saw strong demand from upgraders and customers choosing an iPhone for the first time. Cook said Apple is "enormously pleased" with how the ‌iPhone 17‌ lineup has been received.
Memory Costs

Apple had higher memory costs during the March quarter, and the impact is expected to get worse as the year goes on. Apple CEO ‌Tim Cook‌ said that Apple is expecting "significantly higher memory costs" in the June quarter, and beyond June, memory costs will "drive an increasing impact" on Apple's business.
Mac Sales

Mac revenue was $8.4 billion, up six percent year-over-year. Cook said sales were impacted by supply constraints "driven by higher than expected levels of demand."

The MacBook Neo that was introduced during the quarter was a hit, and Apple sold out. Shipping times for new machines reached several weeks. Apple also saw high demand for the Mac mini and the Mac Studio from people buying the machines for use with AI.

Apple set March quarter records for upgraders and customers new to the Mac, leading to a new all-time record for the overall Mac install base. Apple is focused on customers new to the Mac and customers who have been holding onto their Mac for a long period of time, and the Neo is selling well to those customers.

Apple expects Macs to face supply constraints in the June quarter due to continued high demand and "less flexibility in the supply chain."
Mac Studio and Mac mini Supplies

Apple expects it to take months to reach supply/demand balance on the ‌Mac Studio‌ and ‌Mac mini‌, suggesting they are going to be hard to get for months to come.

Apple underestimated demand for the ‌Mac mini‌ and the ‌Mac Studio‌. "Both of these are amazing platforms for AI and agentic tools and the customer recognition of that is happening faster than what we had predicted, and so we saw higher than expected demand," Cook said.
John Ternus

Cook addressed John Ternus, who will take over as Apple's CEO on September 1, 2026.

Ternus also spoke on the call, where he teased Apple's upcoming product lineup.

Wearables

Wearables revenue was $7.9 billion, an increase of five percent year-over-year. Apple's wearables install base hit a new all-time high, and more than half of customers who purchased an Apple Watch during the quarter were new to the product.
Services

Apple's services revenue reached $31 billion, a new all-time revenue record.

Apple has an install base of over 2.5 billion active devices, a new all-time high across all major product categories. Both transacting and paid accounts hit new all-time highs in the quarter.
Retail

Apple had a March quarter revenue record for retail, with "very high levels of store traffic throughout the quarter."
AI

Parekh said that AI is a "really important investment area" for Apple, and the company plans to continue to invest in AI "incrementally on top of" what it normally invests in its product roadmap.

Apple's R&D spending accelerated during the quarter, and Cook said that Apple is investing in products and services. "We see opportunities in both of those," he said. "We could not be more excited about how the future is playing out."

On the collaboration with Google, Cook said things are going well. "We're happy with where things are, and we're happy with the work that we're doing independently as well," he said.
Tariffs

From Q1 to Q2, Apple saw less impact from tariffs due to the reduction in IEEPA tariff rates, and the reduced global tariff rate under Section 122. Cook said Apple is following the established processes of applying for a refund of tariffs paid, and any amount received will be invested back into U.S. innovation and advanced manufacturing. Any investment of refunded tariff fees will be in addition to Apple's prior commitments in the U.S.
Next Quarter

Parekh said June quarter total revenue is expected to grow 14 to 17 percent year-over-year. Services revenue is expected to grow at a similar rate to what was reported in the March quarter.

Parekh warned investors about iPad revenue because last year, Apple released the A16 ‌iPad‌. "Keep in mind, we face a difficult compare driven by the launch of the A16-powered ‌iPad‌ in the prior year," Parekh said.

Apple's guidance for the June quarter relies on global tariff rates and policies remaining as they are today.
This article, "Apple's Q2 2026 Earnings Call: 11 Key Takeaways" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
During today's earnings call for the second fiscal quarter of 2026, Apple CEO Tim Cook said that the Mac mini and Mac Studio could be hard to get for months to come.


"We think, looking forward, that the ‌Mac mini‌ and ‌Mac Studio‌ may take several months to reach supply demand balance," Cook said.

Apple underestimated demand for the ‌Mac mini‌ and the ‌Mac Studio‌. "Both of these are amazing platforms for AI and agentic tools and the customer recognition of that is happening faster than what we had predicted, and so we saw higher than expected demand," Cook said.

Shipping delays for the ‌Mac mini‌ and the ‌Mac Studio‌ have been increasing over the last few months, and the waits for some models stretch into months. Apple stopped selling the ‌Mac Studio‌ with 512GB RAM entirely, and it stopped accepting orders for some models with higher amounts of RAM. As of last week, the base ‌Mac mini‌ was listed as "Currently Unavailable" from Apple's online store because it is out of stock.Related Roundups: Mac Studio, Mac miniBuyer's Guide: Mac Studio (Caution), Mac Mini (Caution)Related Forums: Mac Studio, Mac mini
This article, "Apple Says Mac Studio and Mac Mini Will Be in Short Supply for Months" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Apple had higher memory costs during the March quarter, and the impact is expected to get worse as the year goes on. Apple CEO Tim Cook said that Apple is expecting "significantly higher memory costs" in the June quarter, and beyond June, memory costs will "drive an increasing impact" on Apple's business.


Cook said the higher memory costs have been partially offset because the company is selling existing inventory that it has stockpiled. As those supplies dwindle, Apple's costs will go up.

According to Cook, Apple is going to look at a "range of options" and the company is "continuing to evaluate" the situation. Cook declined to provide more insight into how Apple plans to deal with the problem.

Memory costs have been soaring due to global supply constraints caused by AI server demand. Chip makers are prioritizing memory for AI servers rather than consumer devices, causing prices to go up.
This article, "Apple Expects 'Significantly Higher Memory Costs' in June Quarter and Beyond" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Apple's iPhone 17 models are its most popular iPhones to date, Apple CFO Kevan Parekh told the Financial Times. Both Parekh and Apple CEO Tim Cook attributed Apple's stellar Q2 2026 performance to iPhone sales.


"The ‌iPhone 17‌ family is now the most popular line-up in our history... we believe we gained market share during the quarter," said Parekh. Cook told Reuters that iPhone demand was "off the charts," and that supply was constrained despite the impressive sales.

"And there's just a little less flexibility in the supply chain at the moment for getting more parts," Cook said. Apple's iPhone sales were held back by the A19 and A19 Pro chips that it gets from TSMC, as TSMC also manufactures AI chips.

Parekh said that memory had an "increasing impact" between the first and second quarters of 2026.

Issues with chip supply and increasing problems acquiring RAM could potentially have an impact on the iPhone 18 lineup that Apple is expected to introduce this September. The lineup will include Apple's first foldable iPhone.

The current ‌iPhone 17‌ family includes the ‌iPhone 17‌, iPhone 17 Pro, ‌iPhone 17 Pro‌ Max, iPhone 17e, and iPhone Air.Related Roundups: iPhone 17, iPhone 17 ProTag: EarningsBuyer's Guide: iPhone 17 (Neutral), iPhone 17 Pro (Neutral)Related Forum: iPhone
This article, "iPhone 17 Is Apple's Most Popular Lineup Ever" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Apple today announced financial results for the second fiscal quarter of 2026, which corresponds to the first calendar quarter of the year.


For the quarter, Apple posted revenue of $111.2 billion and net quarterly profit of $29.6 billion, or $2.01 per diluted share, compared to revenue of $95.4 billion and net quarterly profit of $24.8 billion, or $1.65 per diluted share, in the year-ago quarter. Services revenue again reached an all-time high during the quarter, while company revenue, earnings per share, and iPhone revenue all set March quarter records.

Gross margin for the quarter was 49.3 percent, compared to 47.1 percent in the year-ago quarter. Apple's board of directors also authorized an additional $100 billion for share repurchases and declared an increased dividend payment of $0.27 per share, up from $0.26 per share. The dividend is payable May 14 to shareholders of record as of May 11.

Apple will provide live streaming of its fiscal Q2 2026 financial results conference call at 2:00 pm Pacific, and MacRumors will update this story with coverage of the conference call highlights.

Conference call starts at 2:00 p.m. Pacific - No need to refresh

Loading live updates...

Tag: Earnings
This article, "Apple Reports Record-Breaking 2Q 2026 Results: $29.6B Profit on $111.2B Revenue" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Discover is planning to eliminate some of the Apple Wallet integrations that it introduced in 2023, according to letters that cardholders are receiving. As of June 4, 2026, Discover users will no longer be able to see their total card balance and transaction history in the iPhone's Wallet app, or use the Pay with Rewards feature in Apple Pay.


Apple has a Connected Cards feature that allows credit cards from participating companies to display balances and recent transactions when they're added to the Wallet app. Discover has supported the feature for nearly three years, as have many UK banks, but other credit card companies in the U.S. did not add support.

Pay with Rewards, which is also being eliminated, allows Discover cardholders use their cashback bonuses toward ‌Apple Pay‌ purchases.

Discover says that while several ‌Apple Pay‌ features are being eliminated, Discover users will still be able to use the Discover card to make ‌Apple Pay‌ purchases in retail locations and online. Here's a full list of the changes Discover is making:

Enrollment Cancellation - If applicable, your enrollment in Connected Account and Pay with Rewards with ‌Apple Pay‌ from Discover will be canceled on June 4, 2026.
Access to Information - You will continue to have full access to your account, rewards, balances, transactions and payments on Discover.com, the Discover mobile app, and on your monthly statements. Starting June 4, 2026, you will no longer have access to such details within your Apple Wallet. You will continue to see your ‌Apple Pay‌ transactions in your wallet.
Pay with Rewards - Starting June 4, 2026, you will no longer be able to use rewards to cover an ‌Apple Pay‌ purchase directly at digital checkout. Your options for redeeming your Discover rewards otherwise remain the same.
Terms - Connected Accounts and Pay with Rewards with ‌Apple Pay‌ cancellation does not affect any other terms of your Discover accounts and agreements. Eligibility, service, and cancellation are subject to the ‌Apple Pay‌ terms.

It is not clear if these features are being eliminated because Apple is ending the integrations, or because Discover is opting out. The changes will go into effect on June 4, 2026.Tags: Apple Wallet, Discover
This article, "Discover Dropping Two Apple Wallet Features" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Apple today released new firmware for the AirPods Pro 3. The firmware has a version number of 8B40, up from 8B39.



There is no word on what's included in the new firmware, but Apple has a support document with limited notes. Most updates are limited to bug fixes and performance improvements.

To get the updated firmware, make sure your AirPods Pro are in range of your iPhone, iPad, or Mac and are connected via Bluetooth.

From there, connect your Apple device to Wi-Fi, put your AirPods in the Charging Case, and connect the Charging Case to power. Keep the case closed and wait at least 30 minutes for the firmware update to install. After that, check the version number and repeat the process if the update hasn't been installed.Related Roundup: AirPods Pro 3Tag: AirPods Pro 3Buyer's Guide: AirPods Pro (Buy Now)Related Forum: AirPods
This article, "Apple Releases New Firmware for AirPods Pro 3" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Porsche today announced a new collaboration with Apple that will see two Porsche 963 vehicles outfitted with an Apple Computer-inspired wrap in round four of the IMSA WeatherTech SportsCar Championship at Laguna Seca. The event is set to take place on Sunday, May 3.


Porsche says that the one-time design is meant to celebrate the 75th anniversary of Porsche Motorsport and the 50th anniversary of Apple's founding. The wrap pays homage to the Porsche 935 K3, which competed in the 1980 season and raced at Le Mans.


In a statement, Apple Music, Sports, and Beats Vice President Oliver Schusser said that Apple is proud to once again partner with Porsche.

Porsche Motorsport Vice President Thomas Laudenbach said Porsche and Apple are both "icons that stand for innovation and continuous development by experts in Zuffenhausen, Weissach and Cupertino."


The Laguna Seca Raceway is located 80 miles south of the Apple Park campus, and the fourth round is set to last for two hours and 40 minutes. The No. 6 Porsche 963 will be shared by France's Kévin Estre and Belgium's Laurens Vanthoor, while the No. 7 car will be shared by France's Julien Andlauer and Brazil's Felipe Nasr. The No. 7 vehicle currently leads the IMSA championship standings after winning the opening two rounds at Daytona and Sebring.

Earlier this year, Porsche featured an Apple Music-themed livery for the third round of the IMSA Championship at Long Beach.

(Thanks, Greg!)Tag: Porsche
This article, "Porsche Celebrates Apple's 50th Anniversary With Throwback Race Car Livery" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Mother's Day is coming up on Sunday, May 10, and for those who want to order flowers, Apple has a $20 discount available.


Apple Pay users in the U.S. can get $20 off a purchase from 1-800-Flowers when spending $49.99 or more on a Mother's Day flower bouquet and other select merchandise. The discount is available through May 9 with the promo code APPLEPAY.

To get the deal, iPhone users will need to make a purchase on the 1-800-Flowers website and pay with ‌Apple Pay‌.

Apple also has a Mother's Day gift guide on its website with suggestions for those who want to get their mom a Mac, iPhone, iPad, or AirPods.Related Roundup: Apple PayTag: Apple Pay PromoRelated Forum: Apple Music, Apple Pay/Card, iCloud, Fitness+
This article, "Apple Pay Users Can Get $20 Off Flowers for Mother's Day" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Earlier this week, 9to5Mac's Benjamin Mayo reported on an apparent charging issue affecting at least some of Apple's latest iPhone models.


In short, Mayo said that when he attempted to charge his iPhone Air with a USB-C cable just seconds after the device ran out of battery, it failed to turn on and did not display the usual red battery icon that indicates charging is occurring.

Mayo subsequently realized that several users have posted about this issue across websites such as Reddit and iFixit Answers, but it is unclear what the root cause is or how widespread it is. Apple has yet to publicly comment on the matter, and the issue does not appear to be fixed in the latest iOS 26.4.1 and iOS 26.4.2 software releases.

As far as I can tell, I also experienced this issue with my iPhone 17 Pro Max earlier this month. While staying at a hotel, I accidentally forgot to charge the device one night, leading it to shut off on me when I woke up the next morning. Naturally, I plugged in a USB-C cable, but the screen remained black with no battery icon for many minutes. At the time, I thought that maybe the hotel's outlets were not working correctly, but I knew something was up after I tried a variety of different outlets and chargers without success.

Just like Mayo, I was eventually able to get my iPhone to turn on by placing it on a MagSafe charger and waiting about 10 to 15 minutes. In my case, it was a MagSafe battery pack from Anker that I carry with me while traveling.

A few Reddit users said the standard iPhone 17 model is also impacted.

All in all, it would appear that the new iPhones have a hit-or-miss charging problem when they fully run out of battery, but there is no guarantee that everyone will experience it. With the issue now receiving attention on 9to5Mac and MacRumors, hopefully Apple is made aware and provides a fix in an upcoming iOS version.Related Roundups: iPhone 17 Pro, iPhone AirBuyer's Guide: iPhone 17 Pro (Neutral), iPhone Air (Buy Now)Related Forum: iPhone
This article, "Some iPhone 17 Pro and iPhone Air Users Experiencing a Charging Issue" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
In November 2025, a team self-hosting Langfuse, an open-source LLM observability platform, on Kubernetes uploaded their ClickHouse image to AWS ECR as part of their production preparation. They found that the pipeline scanner had returned three critical vulnerabilities – not in ClickHouse, but in the base image. Their security team saw the findings and blocked the deployment before it ever reached production.
“Our security team is not allowing us to take it to production. Please suggest alternatives.“
vinaygoel586
GitHub Issue #286, November 28, 2025
If you’ve shipped containers into an enterprise environment recently, this situation will sound familiar. A perfectly functional deployment gets blocked not because something is broken, but because a scanner found CVEs in packages the application never even touches. A day goes into investigating the findings, a risk exception gets written up, and the security team rejects it anyway, because the vulnerabilities are technically real even if they’re practically irrelevant to your workload.
This post is about how Docker Hardened Images (DHI) gets you unstuck, when a security team blocks the deployment of a container that has CVEs. In this case we will specifically look at the image for ClickHouse, one of the most widely pulled database images on Docker Hub.
A Quick Word on ClickHouse
ClickHouse is an open-source columnar database built for analytical workloads at scale. It is capable of querying billions of rows and returning results in milliseconds in a way that traditional row-oriented databases simply can’t match. Companies such as Cloudflare, Uber, and Spotify all run it in production. With over 100 million pulls from Docker Hub, it has become the default infrastructure choice for teams that need serious analytics throughput. The image’s default security posture, though, was designed with developer ease-of-use in mind rather than the hardening that enterprise production environments demand and that gap is where the trouble starts.
Figure: The layered architecture of ClickHouse
How ClickHouse is Structured
ClickHouse follows a layered architecture. It is designed for analytical speed at scale. SQL queries arrive over HTTP (port 8123) or TCP (port 9000), then pass through the optimizer which parses into an abstract syntax tree and prunes it before the pipeline executor picks it up and hands the work off to parallel threads. Beneath the query layer sits the MergeTree storage engine, the heart of ClickHouse which stores data in columnar .bin files. It uses a sparse primary index to skip irrelevant granules without reading entire columns, and runs background merge processes to compact parts and maintain query performance over time. 
At the bottom, storage is pluggable: local disk, S3, HDFS, or Azure Blob, with tiered hot/warm/cold policies to balance cost and latency. In distributed deployments, ClickHouse Keeper (or ZooKeeper) coordinates replication across replicas, while sharding splits data horizontally across nodes allowing the cluster to scale reads and writes independently. The result is a database that processes hundreds of millions of rows per second per server, making it the default choice for teams running serious analytics workloads.
The Real Problem: It’s Not ClickHouse, It’s the Packaging
The standard clickhouse/clickhouse-server image is built on a full Ubuntu 22.04 base. The base ships with a lot of things ClickHouse doesn’t need such as Perl, system utilities, apt itself, and dozens of transitive dependencies that exist in the image simply because Ubuntu brought outdated package along and in many cases, Ubuntu maintainers decide to not backport fixes from upstream.
ClickHouse doesn’t use most of those system utilities. But the CVEs in those packages are real. They show up in Trivy, Grype, and AWS ECR has no way to distinguish a vulnerable library that’s never loaded from one that’s actively running in production. Your security team sees critical findings and blocks the deployment, which is the correct thing for them to do given what the scanner is telling them.
The instinct at this point is to argue the case, documenting why each CVE doesn’t apply to your workload, writing risk exceptions and escalating, but that’s a slow process. The only real fix is to remove those unnecessary packages entirely. That’s what Docker Hardened Images do.
What DHI Actually Changes
Docker Hardened Images for ClickHouse are built around a straightforward question: what does the database actually need to run? Rather than starting from a full Ubuntu base and hoping the CVE count stays manageable, DHI ships only what ClickHouse requires and leaves everything else out.
The most immediate consequence of that is the absence of apt at runtime. Without a package manager, an attacker who gains a foothold in the container has no obvious path to installing tools or establishing persistence. Network utilities like curl and wget are gone for the same reason, the standard clickhouse/clickhouse-server image has been carrying wget with CVE-2021-31879 unpatched since 2021 because there is no upstream fix as noted by the Ubuntu maintainer, a vulnerability in a tool ClickHouse never needed in the first place. DHI doesn’t patch it; it simply doesn’t include wget at all. A shell is still available for operational work, but without the package manager and network tools, there’s very little an attacker can actually do with it.
To make this practical across different stages of a pipeline, DHI ships two variants. The development image (dev) includes additional tooling that makes local testing and debugging more comfortable. The production image (runtime) strips that back to the absolute minimum, giving you the smallest possible attack surface for the workload that actually faces the world. The intent is that teams adopt the dev variant early in the pipeline and promote the hardened production image through to deployment, rather than discovering the differences at the point where it matters most.
The image also runs as a non-root user uid=65532 out of the box, with no additional Dockerfile configuration required. On the provenance side, every DHI image ships with SLSA Level 3 attestation, which provides cryptographic proof of exactly what went into the build and how it was produced. Docker’s security team actively tracks and patches CVEs, and the presence of 2026 CVE IDs in DHI’s findings is evidence of that remediation happening ahead of public disclosure feeds rather than in response to them.
Getting Started
Before you can pull a DHI image, you need to mirror it to your organization’s namespace on Docker Hub. This is a one-time setup per image not per tag and it means all future updates flow to your namespace automatically.
Log in to Docker Hub and open the DHI catalog Find clickhouse-server and select Mirror to repository Follow the on-screen instructions Authenticate locally: docker login dhi.io Once that’s done, you’re pulling from your own namespace with the same image, same tags, same ClickHouse – just hardened.
Your first DHI ClickHouse container
docker run --name my-clickhouse-server -d \ --ulimit nofile=262144:262144 \ dhi.io/clickhouse-server:26.2-debian13 The --ulimit nofile=262144:262144 flag is a ClickHouse requirement, not a DHI one – ClickHouse needs high file descriptor limits to operate correctly. Keep it in all your run commands.
Verify it started:
docker exec my-clickhouse-server clickhouse-client \ --query "SELECT 'Hello from DHI ClickHouse!'" Production setup with persistent storage
For anything beyond local testing, you want volumes and a password:
docker run -d \ --name my-clickhouse-server \ --ulimit nofile=262144:262144 \ -e CLICKHOUSE_PASSWORD=mysecretpassword \ -v clickhouse-data:/var/lib/clickhouse \ -v clickhouse-logs:/var/log/clickhouse-server \ -p 8123:8123 -p 9000:9000 \ dhi.io/clickhouse-server:26.2-debian13 Note that CLICKHOUSE_PASSWORD is required if you want to access ClickHouse over the network. DHI disables unauthenticated network access by default which is the right call for any production deployment.
Test it over HTTP:
curl "http://localhost:8123/?query=SELECT%20version()&user=default&password=mysecretpassword" Custom configuration
If you’re already running ClickHouse with custom XML config, nothing changes. Same format, same mount path:
cat > custom-config.xml << EOF <clickhouse> <logger> <level>information</level> <console>true</console> </logger> <listen_host>0.0.0.0</listen_host> </clickhouse> EOF docker run -d \ --name my-clickhouse-server \ --ulimit nofile=262144:262144 \ -v $(pwd)/custom-config.xml:/etc/clickhouse-server/config.d/custom.xml:ro \ -p 8123:8123 -p 9000:9000 \ dhi.io/clickhouse-server:26.2-debian13 Running DHI ClickHouse on Kubernetes
For Kubernetes, there’s one important addition to your pod spec. Since DHI runs as a non-root user, you need to set fsGroup to ensure your persistent volume data is accessible:
spec: template: spec: securityContext: runAsNonRoot: true runAsUser: 65532 # DHI nonroot user fsGroup: 65532 # makes mounted volumes accessible to the nonroot user containers: - name: clickhouse-server image: dhi.io/clickhouse-server:26.2-debian13 ports: - containerPort: 8123 - containerPort: 9000 volumeMounts: - name: clickhouse-data mountPath: /var/lib/clickhouse - name: clickhouse-logs mountPath: /var/log/clickhouse-server resources: limits: cpu: "2" memory: "4Gi" One thing worth mentioning: ClickHouse’s default ports 8123 and 9000 are above the 1024 privileged port boundary, so running as nonroot doesn’t cause any port binding issues.
The metrics exporter
If you’re running ClickHouse on Kubernetes and need Prometheus metrics, Docker also ships clickhouse-metrics-exporter – a hardened image that works with the ClickHouse Operator to expose a /metrics endpoint. It’s 65% smaller than the standard exporter (10.3 MB vs 29.4 MB) and has 75% fewer layers (5 vs 20). Same data, dramatically smaller surface.
containers: - name: metrics-exporter image: dhi.io/clickhouse-metrics-exporter:0-debian13 ports: - name: metrics containerPort: 8888 resources: limits: cpu: 100m memory: 128Mi requests: cpu: 50m memory: 64Mi Debugging without the usual tools
The debugging story is simpler than it might seem. docker debug attaches an ephemeral layer to the running container that includes bash, curl, strace, vim, and anything else you need without modifying the production image itself. When you exit, the layer disappears and the container is exactly as it was. It’s a cleaner approach than shelling directly into a production container, and in practice it’s a single command:
docker debug my-clickhouse-server Or if you prefer, you can mount a debug image alongside the container:
docker run --rm -it --pid container:my-clickhouse-server \ --mount=type=image,source=<your-namespace>/dhi-busybox,destination=/dbg,ro \ dhi.io/clickhouse-server:26.2-debian13 /dbg/bin/sh There’s also a broader security benefit that goes beyond CVE counts. If something does go wrong in production, an attacker who gets into the container finds no package manager to install tools with, no curl or wget to exfiltrate data through, and no obvious path to reach out to the network which significantly limits what a compromise can actually turn into.
ClickHouse: Non-hardened Image vs. Hardened Image Compared
A Docker Scout scan of both images puts the difference in plain numbers. Using ubuntu:22.04 as its base, the standard image carries 8 medium and 11 low severity vulnerabilities across 111 packages, including the wget and tar findings that are most likely to trigger a security block in an enterprise pipeline. The DHI image eliminates all medium severity findings entirely and comes in at 14 low severity items but these are in core system libraries like glibc and openssl where no fix exists on any distribution, not in unnecessary utilities that had no business being in the image. The 3 unconfirmed findings that Scout surfaces have already been assessed and suppressed via VEX attestation, which ships with the image as part of its SLSA Level 3 provenance
To view the difference between versions for any other image, you can run your own scan with Docker Scout for a quick comparison using this command:
docker scout quickview clickhouse/clickhouse-server:latest docker pull dhi.io/clickhouse-server:26.2-debian13 docker tag dhi.io/clickhouse-server:26.2-debian13 clickhouse-dhi:latest docker scout quickview clickhouse-dhi:latest



Non-Hardened  ClickHouse Image
Docker Hardened Image
Default user
root (steps down to clickhouse user at runtime via entrypoint, but Dockerfile has no USER directive overridable with CLICKHOUSE_RUN_AS_ROOT=1)
nonroot (enforced at image level via USER directive cannot be overridden at runtime)
Shell access
Full shell (bash/sh) available
bash present, no network tools or package manager
Package manager
apt available
No package manager
CVE exposure
Ships wget (CVE-2021-31879, unpatched since 2021), tar (CVE-2025-45582)
No wget, no tar – unnecessary packages removed entirely
CVE patching
Unpatched findings from 2021–2025 due to the lack of upstream fixes from Ubuntu base image.
Actively tracked, 2026 CVE IDs show proactive remediation
Provenance
Standard
SLSA Level 3 attestation
Compliance
Manual hardening required
CIS, NIST, FedRAMP-aligned
Debugging
Traditional shell debugging
Use docker debug or Image Mount for troubleshooting

The Security Team Conversation
The team that got blocked at AWS ECR in November 2025 didn’t have a ClickHouse problem, they had a base image problem. Their database was fine; what the scanner was finding were CVEs in Perl, system utilities, and other packages that had come along in the Debian base and never used by the application. Nothing in the scanner output made that distinction, so the security team did exactly what they were supposed to do and blocked the deployment.
With DHI, that conversation with your security team becomes considerably more straightforward. Rather than building a case for why specific CVEs don’t apply to your workload, you can point to an image built by Docker’s security team from the minimum required components, with SLSA Level 3 provenance and independent validation by SRLabs. The ClickHouse runtime itself is unchanged ~ queries, ports, configuration files, and performance all carry over so the only thing you’re actually changing is the answer you can give when someone asks whether this image can go to production.For teams that need stronger guarantees, DHI Enterprise adds SLA-backed CVE remediation within seven days, FIPS and STIG variants, and extended lifecycle support. For most teams, the free Enterprise trial is the right starting point. It answers the question that actually matters before you commit to anything. Interested to learn further? Start with this blog that walks through the trial and sets you up for success.
Migration Checklist
☐ Mirror clickhouse-server DHI image to your Docker Hub namespace (one-time setup) ☐ Update your image reference to dhi.io/clickhouse-server:26.2-debian13 ☐ Set CLICKHOUSE_PASSWORD (required for network access in DHI) ☐ Keep --ulimit nofile=262144:262144 on all run commands ☐ In Kubernetes: add fsGroup: 65532 to your pod securityContext ☐ Switch from kubectl exec to kubectl debug for troubleshooting ☐ Run trivy against both images to see the difference yourself: trivy image clickhouse/clickhouse-server:latest trivy image dhi.io/clickhouse-server:26.2-debian13 The migration is narrower in scope than it might appear – your volume mounts, port mappings, and existing XML configuration files all carry over without modifications, and on Kubernetes the only structure addition is the fsGroup security context. Everything else is an image reference change.
Resources
Docker Hardened Images Documentation DHI ClickHouse Server Guide DHI ClickHouse Metrics Exporter Guide Docker Debug Documentation Free DHI Catalog DHI Community Announcement Docker Scout Documentation View the full article
In a social media post this week, Bloomberg's Mark Gurman reiterated that Apple is planning to release new AirPods with cameras "for Siri."


Last month, Gurman said these AirPods will likely be priced above the current AirPods Pro 3, which Apple sells for $249. As a result, he said Apple is likely considering using "AirPods Ultra" branding for the camera-equipped AirPods.

"AirPods Ultra" would not have typical cameras for capturing photos and videos. Instead, Gurman previously reported that the earbuds will be equipped with infrared cameras that use computer vision to feed data about a user's surroundings to Siri. The cameras should help to enhance the Visual Intelligence feature on the iPhone 15 Pro and newer.

This would be similar to the infrared camera built into the Face ID system on iPhones.

In June 2024, Apple supply chain analyst Ming-Chi Kuo said AirPods with cameras would potentially enable "in-air gesture control." In his post this week, however, Gurman said he does not expect the AirPods to support hand gestures.

It was initially rumored that the camera-equipped AirPods would be a higher-end AirPods Pro 3 configuration, much like the AirPods 4 are available in variants with or without active noise cancellation. However, it is increasingly sounding like the earbuds will instead be "AirPods Ultra" positioned above the AirPods Pro entirely.

Macworld's Filipe Espósito recently reported that Apple plans to release an "iPhone Ultra" and a "MacBook Ultra" within the next year, so "AirPods Ultra" would be part of a trio of new "Ultra" devices. Apple already uses "Ultra" branding for the Apple Watch Ultra, CarPlay Ultra, and the M1 Ultra to M3 Ultra series of chips.

It is not entirely clear when the "AirPods Ultra" will arrive, but September of this year is a possibility if Apple plans to announce them alongside the "iPhone Ultra," its long-rumored foldable iPhone. A redesigned "MacBook Ultra" with an OLED display and touch-screen capabilities is expected to follow by early 2027.Related Roundup: AirPods Pro 3Tags: AirPods Ultra, Mark GurmanBuyer's Guide: AirPods Pro (Buy Now)Related Forum: AirPods
This article, "'AirPods Ultra' Rumored to Feature a Major Upgrade Over AirPods Pro" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Apple remains the top manufacturer of satellite-capable smartphones globally, with such devices projected to reach 46% of all smartphone shipments by 2030, according to a new report from Counterpoint Research.


The firm's Smartphone Satellite Connection Report finds that Apple kickstarted the satellite phone trend when it partnered with Globalstar to bring Emergency SOS via satellite to the iPhone 14 in 2022 and has maintained a clear lead since. Samsung leads the Android ecosystem, while Huawei and Google also follow a proprietary approach. Other Android players, including Xiaomi, OPPO, HONOR, and vivo, have aligned with the 3GPP non-terrestrial network (NTN) standard to enable broader scalability and interoperability.

The market is currently dominated by the premium segment, with the lack of compelling everyday use cases limiting broader adoption. 3GPP Release 17 supports only SOS messaging and basic location sharing. Release 18 is expected to expand adoption further across premium brands, but mass-market penetration in the mid-price segment is not anticipated until Release 19.

Qualcomm leads among Android vendors with its Snapdragon X80 and X85 modems, with MediaTek, Samsung, Google, and Huawei all increasing competition. North America is the leading region for adoption, driven by carrier partnerships including T-Mobile with SpaceX, AT&T with AST Mobile, and Rogers with SpaceX, alongside Apple's Globalstar arrangement. Amazon's acquisition of Globalstar is seen as a notable development, potentially opening new connectivity-as-a-service revenue streams.

Counterpoint expects Apple, Google, and Samsung to lead in overall market penetration toward 2030, with Android brands targeting entry-level and mid-range price points seeing slower uptake. Apple recently agreed a new satellite deal with Amazon following its acquisition of Globalstar, and has several new satellite features in development, including Maps via satellite, photos in Messages via satellite, and a satellite API for third-party apps.Tags: Counterpoint, Emergency SOS via Satellite, iPhone Satellite Features
This article, "Apple Leads Global Market for Satellite-Connected Smartphones" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Amazon this week has all-time low prices on the Apple Watch Series 11, with up to $130 off numerous models of the smartwatch. This sale includes nearly every aluminum model of the Series 11 on sale at a record low price, plus new steep markdowns on cellular models.

Note: MacRumors is an affiliate partner with Amazon. When you click a link and make a purchase, we may receive a small payment, which helps us keep the site running.

You can get the 42mm GPS Apple Watch Series 11 for $299.00, down from $399.00, and the 46mm GPS model for $329.00, down from $429.00. On Amazon, you'll find four of both the 42mm and 46mm GPS models on sale at these all-time low prices.

$100 OFFApple Watch Series 11 (42mm GPS) for $299.00
$100 OFFApple Watch Series 11 (46mm GPS) for $329.00

A new highlight of Series 11 deals is on the 46mm cellular model, which has hit $399.00, down from $529.00. This is a big $130 discount on the cellular Apple Watch, and it's available in three colors. You'll also find $100 off the 42mm cellular model right now.

$100 OFFApple Watch Series 11 (42mm Cell) for $399.00
$130 OFFApple Watch Series 11 (46mm Cell) for $399.00

Head to our full Deals Roundup to get caught up with all of the latest deals and discounts that we've been tracking over the past week.



Deals Newsletter

Interested in hearing more about the best deals you can find in 2026? Sign up for our Deals Newsletter and we'll keep you updated so you don't miss the biggest deals of the season!




Related Roundup: Apple Deals
This article, "Apple Watch Series 11 Hits $100 Off Nearly Every GPS Aluminum Model, Plus $130 Off Cellular" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
A Brazilian tech firm that specializes in protecting networks from distributed denial-of-service (DDoS) attacks has been enabling a botnet responsible for an extended campaign of massive DDoS attacks against other network operators in Brazil, KrebsOnSecurity has learned. The firm’s chief executive says the malicious activity resulted from a security breach and was likely the work of a competitor trying to tarnish his company’s public image.
An Archer AX21 router from TP-Link. Image: tp-link.com.
For the past several years, security experts have tracked a series of massive DDoS attacks originating from Brazil and solely targeting Brazilian ISPs. Until recently, it was less than clear who or what was behind these digital sieges. That changed earlier this month when a trusted source who asked to remain anonymous shared a curious file archive that was exposed in an open directory online.
The exposed archive contained several Portuguese-language malicious programs written in Python. It also included the private SSH authentication keys belonging to the CEO of Huge Networks, a Brazilian ISP that primarily offers DDoS protection to other Brazilian network operators.
Founded in Miami, Fla. in 2014, Huge Networks’s operations are centered in Brazil. The company originated from protecting game servers against DDoS attacks and evolved into an ISP-focused DDoS mitigation provider. It does not appear in any public abuse complaints and is not associated with any known DDoS-for-hire services.
Nevertheless, the exposed archive shows that a Brazil-based threat actor maintained root access to Huge Networks infrastructure and built a powerful DDoS botnet by routinely mass-scanning the Internet for insecure Internet routers and unmanaged domain name system (DNS) servers on the Web that could be enlisted in attacks.
DNS is what allows Internet users to reach websites by typing familiar domain names instead of the associated IP addresses. Ideally, DNS servers only provide answers to machines within a trusted domain. But so-called “DNS reflection” attacks rely on DNS servers that are (mis)configured to accept queries from anywhere on the Web. Attackers can send spoofed DNS queries to these servers so that the request appears to come from the target’s network. That way, when the DNS servers respond, they reply to the spoofed (targeted) address.
By taking advantage of an extension to the DNS protocol that enables large DNS messages, botmasters can dramatically boost the size and impact of a reflection attack — crafting DNS queries so that the responses are much bigger than the requests. For example, an attacker could compose a DNS request of less than 100 bytes, prompting a response that is 60-70 times as large. This amplification effect is especially pronounced when the perpetrators can query many DNS servers with these spoofed requests from tens of thousands of compromised devices simultaneously.
A DNS amplification and reflection attack, illustrated. Image: veracara.digicert.com.
The exposed file archive includes a command-line history showing exactly how this attacker built and maintained a powerful botnet by scouring the Internet for TP-Link Archer AX21 routers. Specifically, the botnet seeks out TP-Link devices that remain vulnerable to CVE-2023-1389, an unauthenticated command injection vulnerability that was patched back in April 2023.
Malicious domains in the exposed Python attack scripts included DNS lookups for hikylover[.]st, and c.loyaltyservices[.]lol, both domains that have been flagged in the past year as control servers for an Internet of Things (IoT) botnet powered by a Mirai malware variant.
The leaked archive shows the botmaster coordinated their scanning from a Digital Ocean server that has been flagged for abusive activity hundreds of times in the past year. The Python scripts invoke multiple Internet addresses assigned to Huge Networks that were used to identify targets and execute DDoS campaigns. The attacks were strictly limited to Brazilian IP address ranges, and the scripts show that each selected IP address prefix was attacked for 10-60 seconds with four parallel processes per host before the botnet moved on to the next target.
The archive also shows these malicious Python scripts relied on private SSH keys belonging to Huge Networks’s CEO, Erick Nascimento. Reached for comment about the files, Mr. Nascimento said he did not write the attack programs and that he didn’t realize the extent of the DDoS campaigns until contacted by KrebsOnSecurity.
“We received and notified many Tier 1 upstreams regarding very very large DDoS attacks against small ISPs,” Nascimento said. “We didn’t dig deep enough at the time, and what you sent makes that clear.”
Nascimento said the unauthorized activity is likely related to a digital intrusion first detected in January 2026 that compromised two of the company’s development servers, as well as his personal SSH keys. But he said there’s no evidence those keys were used after January.
“We notified the team in writing the same day, wiped the boxes, and rotated keys,” Nascimento said, sharing a screenshot of a January 11 notification from Digital Ocean. “All documented internally.”
Mr. Nascimento said Huge Networks has since engaged a third-party network forensics firm to investigate further.
“Our working assessment so far is that this all started with a single internal compromise — one pivot point that gave the attacker downstream access to some resources, including a legacy personal droplet of mine,” he wrote.
“The compromise happened through a bastion/jump server that several people had access to,” Nascimento continued. “Digital Ocean flagged the droplet on January 11 — compromised due to a leaked SSH key, in their wording — I was traveling at the time and addressed it on return. That droplet was deprecated and destroyed, and it was never part of Huge Networks infrastructure.”
The malicious software that powers the botnet of TP-Link devices used in the DDoS attacks on Brazilian ISPs is based on Mirai, a malware strain that made its public debut in September 2016 by launching a then record-smashing DDoS attack that kept this website offline for four days. In January 2017, KrebsOnSecurity identified the Mirai authors as the co-owners of a DDoS mitigation firm that was using the botnet to attack gaming servers and scare up new clients.
In May 2025, KrebsOnSecurity was hit by another Mirai-based DDoS that Google called the largest attack it had ever mitigated. That report implicated a 20-something Brazilian man who was running a DDoS mitigation company as well as several DDoS-for-hire services that have since been seized by the FBI.
Nascimento flatly denied being involved in DDoS attacks against Brazilian operators to generate business for his company’s services.
“We don’t run DDoS attacks against Brazilian operators to sell protection,” Nascimento wrote in response to questions. “Our sales model is mostly inbound and through channel integrator, distributors, partners — not active prospecting based on market incidents. The targets in the scripts you received are small regional providers, the vast majority of which are neither in our customer base nor in our commercial pipeline — a fact verifiable through public sources like QRator.”
Nascimento maintains he has “strong evidence stored on the blockchain” that this was all done by a competitor. As for who that competitor might be, the CEO wouldn’t say.
“I would love to share this with you, but it could not be published as it would lose the surprise factor against my dishonest competitor,” he explained. “Coincidentally or not, your contact happened a week before an important event – ​​one that this competitor has NEVER participated in (and it’s a traditional event in the sector). And this year, they will be participating. Strange, isn’t it?”
Strange indeed.
View the full article
Apple's AirTag item tracker turns five years old today, with the $29 accessory having spent half a decade as the best-selling item tracker in the world.



The ‌AirTag‌ launched on April 30, 2021, alongside the M1 iMac, a new iPad Pro, and a new Apple TV 4K. The coin-shaped accessory has a polished stainless steel back, IP67 water resistance, and a U1 Ultra Wideband chip that powers Precision Finding, a feature that combines haptic, visual, and audio feedback to guide users to a lost item's precise location with the iPhone 11 and later.

Setup works by bringing the tag close to an iPhone, with each ‌AirTag‌ appearing in the Items tab of the Find My app. The ‌Find My‌ network, which relies on Bluetooth signals from nearby Apple devices to relay location data, allows a lost item to be tracked even when out of direct range. The ‌AirTag‌ is priced at $29 for a single tag or $99 for a four-pack, with free engraving available.

Reports of the AirTag being misused for stalking and vehicle theft surfaced within months of launch, with its small size, low price, and the breadth of the ‌Find My‌ network making it an attractive tool for bad actors. Apple released a statement in February 2022 saying incidents of misuse were "rare; however, each instance is one too many," and introduced setup warnings making clear that using an ‌AirTag‌ to track people without consent is a crime in many regions.

A class-action lawsuit filed in California in December 2022, later expanded to include more than three dozen plaintiffs, alleged that the product's accuracy and affordability made it well-suited for misuse, and a federal judge allowed certain claims to move forward in March 2024. Apple and Google later aligned on cross-platform specifications so that Android users receive automatic unwanted tracking alerts alongside iPhone users.

Despite the controversy, Apple says the ‌AirTag‌ became its best-selling item tracking accessory, citing user stories of recovering lost luggage, bicycles, and bags in the years since launch.

Apple released the second-generation AirTag in January 2026. The updated model features a second-generation Ultra Wideband chip with Precision Finding working from up to 50% farther away, an upgraded Bluetooth chip, and a speaker 50% louder than the original. For the first time, Precision Finding also works with Apple Watch Series 9 models and later. A teardown revealed that the speaker magnet is more firmly secured in the second-generation model, making it harder to remove, a modification that had previously been used to silence unwanted tracking alerts. Pricing remains $29 for a single tag and $99 for a four-pack.Related Roundup: AirTagBuyer's Guide: AirTag (Buy Now)
This article, "Apple Launched AirTag 5 Years Ago Today" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
The US Cybersecurity and Infrastructure Security Agency (CISA) has asked owners and operators of operational technology to stop assuming their networks are safe, and has released joint guidance to adapt zero trust principles for industrial systems that support US power, water, transportation, building automation, and weapons-support infrastructure.
OT owners should design controls on the assumption that adversaries are already inside the network, and validate every access request based on identity, context, and risk rather than network location, CISA and four partner agencies wrote in a 28-page document titled Adapting Zero Trust Principles to Operational Technology.
The guide was developed with the Department of War, the Department of Energy, the FBI, and the Department of State, with technical contributions from the National Institute of Standards and Technology.
The agencies were direct about the threat driving the publication.
“CISA has observed threat actors like Volt Typhoon targeting OT systems to compromise, escalate, and maintain access within operational environments,” CISA Acting Executive Assistant Director for Cybersecurity Chris Butera said in a statement accompanying the release. “Zero Trust architecture is critical to preventing cyber incidents that could cause operators to lose visibility or control of essential systems.”
CISA, the FBI, and the National Security Agency first warned in February 2024 that the Chinese state-sponsored group was prepositioning on US IT networks to enable lateral movement to OT assets in the event of geopolitical conflict. The group has since resurfaced with renewed botnet activity exploiting end-of-life routers and exploited a Versa Director zero-day to harvest credentials from US ISPs.
Pete Luban, field CISO at cybersecurity firm AttackIQ, said the convergence of IT and OT was the structural reason the guidance was needed. “Systems that were once isolated are now increasingly connected to enterprise networks and third-party services, and attackers are taking full advantage,” Luban said. “Adversaries aren’t just looking for data to steal, but for the weak seams between business and operational systems that can be used to move laterally across networks.” In OT, a successful intrusion can escalate quickly from a cybersecurity issue to an operational, safety, and public trust issue, he added.
A reference architecture built for the plant floor
It is precisely those weak seams that the new guide tries to close. The document is structured around the six functions of NIST Cybersecurity Framework 2.0 — Govern, Identify, Protect, Detect, Respond, and Recover — and aligns with CISA’s Cross-Sector Cybersecurity Performance Goals 2.0, the DoD Zero Trust Reference Architecture v2.0, NIST SP 800-82r3, and the international ISA/IEC 62443 series.
But the agencies wrote that none of those frameworks could be applied to OT unmodified.
“The blanket application of traditional information technology (IT)-focused ZT capabilities to OT is neither reasonable nor feasible,” the document stated, calling instead for continuous collaboration between OT engineers, IT architects, and cybersecurity professionals.
The guidance directs operators to segment Active Directory used in OT into a “separate forest or domain, avoid direct trust relationships between IT and OT identity systems, and enforce multi-factor authentication at the jump host level” where the underlying device cannot support it. Privileged sessions should be vaulted, recorded, and time-bound, with just-in-time access used to restrict remote vendor connections to narrowly defined maintenance windows, the document advised.
On encryption, the document distinguished confidentiality and integrity. Integrity and authentication through digital signing are typically more critical than confidentiality in OT, the agencies wrote, because expired certificates will not halt operations if communications remain in the clear. At the same time, encryption can introduce latency that disrupts safety-critical systems.
That kind of nuance is precisely why the model cannot be transplanted wholesale, said Nick Tausek, lead security automation architect at Swimlane. “OT teams cannot simply lift and shift an IT security model into environments where downtime, latency, and safety risks carry real-world consequences,” Tausek said. “Zero trust has to be implemented with precision, operational awareness, and automation that can enforce policy without creating more friction for the people keeping critical systems running.”
What it means for security teams
The publication closes a gap that CISA’s Zero Trust Maturity Model 2.0 acknowledged, having stated it did not address challenges specific to operational technology. It follows February’s Barriers to Secure OT Communications and earlier CISA warnings that exposed VPNs, firewalls, and legacy edge devices remain the dominant entry points for critical infrastructure attacks.
The document told buyers that strategic procurement is how operators escape the legacy trap, and pointed them to the Secure by Demand guide for contracting criteria and to its open-source SIEM tool, Malcolm, for OT protocol parsing.
Luban said the harder problem is verifying that any of these controls hold. Organizations need to test boundaries against real-world adversary tactics, he said, to identify “where trust is being assumed, where access is too broad, and where attackers may still be able to cross from enterprise environments into operational systems before those gaps are exposed in a real incident.” The tooling adopted to run those tests carries its own risk. Tausek said AI-driven security agents now sitting alongside OT environments have become high-value targets in their own right. “If an attacker can tamper with an agent, disable it, or use it as a trusted pathway, the tool meant to improve detection can become part of the problem,” he said.
View the full article
Security researchers are warning about a max severity vulnerability in Google Gemini CLI that could allow remote code execution (RCE) in environments where the tool processes untrusted inputs.
The issue was disclosed by Novee Security researchers and affects the @google/gemini-cli package and its associated GitHub Action, widely used in CI/CD workflows.
“Gemini CLI (@google/gemini-cli) and the run-gemini-cli GitHub Action are being updated to harden workspace trust and tool allowlisting, in particular when used in untrusted environments like GitHub Actions,” reads a GitHub advisory issued on the flaw.
Google acknowledged the flaw and thanked security researchers Elad Meged from Novee Security and Dan Lisichkin from Pillar Security for reporting the issue through its Vulnerability Rewards Program.

The issue was fixed in @google/gemini-cli versions 0.39.1 and 0.40.0-preview.3. A run-gemini-cli fix was also released in version 0.1.22.
Overtrusting workspace configurations
The problem lay in how the CLI handled workspace trust and command execution in automated, non-interactive environments.“In affected versions, Gemini CLI running in CI environments automatically trusted workspace folders for the purpose of loading configurations and environment variables,” the advisory said.
This could have been easily exploited by attackers by injecting their own malicious configurations into the trusted workspace.
“The vulnerability allowed an unprivileged external attacker to force their own malicious content to load as Gemini configuration,” Novee researcher, Elad Meged, said in a blog post. “This triggered command execution directly on the host system, bypassing security before the agent’s sandbox even initialized.”
The impact of the flaw was limited to workflows using Gemini CLI in headless mode, without an interactive interface.
While a CVE ID has not been assigned to the flaw yet, Meged said Google assessed a severity rating of 10.0, the maximum on the CVSS scale. The maximum severity rating likely comes from the exploit requiring low complexity, minimal privileges, and little to no user interaction.
Google did not immediately respond to CSO’s request for comments.
The flaw was, however, categorized under CWE-20, CWE-77, CWE-78, and CWE-200, which roughly refer to improper input validation, command injection, and information disclosure weaknesses.
The behavior is now fixed
Google has addressed the issue by removing implicit workspace trust in headless environments and enforcing stricter tool controls, effectively changing how Gemini CLI behaves in CI/CD pipelines.
The patched versions (0.39.1 and 0.40.0-preview.3) now require explicit trust decisions before loading workspace configurations, aligning non-interactive execution with the same safeguards expected in interactive use.
Additionally, the fix closed a critical gap in “–yolo” mode by ensuring that tool allowlisting is actually enforced, preventing loosely scoped permissions from turning into unrestricted command execution.
Previously, allowlisting could be bypassed, letting CLI run commands outside the intended restrictions.
Google has also brought in a broader ecosystem change. The run-gemini-cli GitHub Action (patched in v0.1.22) now automatically pulls and executes the latest version of the CLI. Workflows that pin a specific gemni-cli-version are advised to upgrade to a patched release and review their existing Gemini CLI configurations to ensure they don’t rely on unsafe defaults.


View the full article
A supply chain attack on SAP-related npm packages has put fresh scrutiny on the developer tools and build workflows that enterprises rely on to produce software.
The campaign, referred to as “mini Shai-Hulud,” affected packages used in SAP’s JavaScript and cloud application development ecosystem.
The malicious versions added installation-time code that could steal developer credentials, GitHub and npm tokens, GitHub Actions secrets, and cloud credentials from AWS, Azure, GCP, and Kubernetes environments.
Researchers at SafeDep, Aikido Security, Wiz, and several other security firms said the affected packages included [email protected], @cap-js/[email protected], @cap-js/[email protected], and @cap-js/[email protected].
The suspicious versions were published on April 29 and were later replaced by safe releases.
The malware encrypted stolen data and sent it to public GitHub repositories created from victims’ own accounts, according to the researchers. It also used stolen GitHub and npm tokens to add malicious GitHub Actions workflows to accessible repositories and publish poisoned package versions.
SafeDep said the attackers abused a configuration gap in npm’s OIDC trusted publishing setup for the affected @cap-js packages. The compromise of mbt, meanwhile, is suspected to involve a static npm token.
The attackers also attempted to persist through Visual Studio Code and Claude Code configuration files. The technique puts developer workstations and AI-assisted coding tools closer to the center of supply chain security concerns.
Implications for CISOs
For CISOs, the case shows how quickly a tainted dependency can move beyond the build process. It also adds to concerns that developer environments, though central to enterprise software delivery, are still not governed with the same rigor as production systems.
“The fact that the malware was designed to harvest GitHub and npm tokens, GitHub Actions secrets, and cloud credentials from AWS, Azure, GCP, and Kubernetes in a single pass tells you that attackers now treat the developer workstation as a master key,” said Sakshi Grover, senior research manager for IDC Asia Pacific Cybersecurity Services.
A single compromised developer identity in a CI/CD pipeline can give attackers a route into the wider software supply chain, allowing them to push malicious code into packages that downstream developers may install with little visibility into tampering.
That lack of visibility remains a concern, Grover said, citing IDC’s Asia Pacific Security Survey 2025, which found that 46% of enterprises plan to deploy AI for third-party and supply chain risk analysis over the next 12 to 24 months. For now, she said, many organizations are still in the planning stage and have yet to operationalize AI-driven defenses against attacks such as the mini Shai-Hulud campaign.
Sunil Varkey, a cybersecurity analyst, described the campaign as a case of “living off the developer,” where attackers target developers, their tools, and automation rather than only the software package itself.
Varkey said the attackers went beyond poisoning npm packages by compromising maintainer GitHub accounts, abusing loosely configured npm OIDC Trusted Publishing, and using preinstall hooks to publish credential-stealing malware.
The more troubling element, he said, was the use of Visual Studio Code and Claude Code configuration files, specifically .vscode/tasks.json and .claude/settings.json, for persistence and propagation. That allowed the malware to execute when an infected repository was opened in Visual Studio Code, or when a Claude Code session started, he said.
“The attacker is turning the modern developer experience itself into an attack vector,” Varkey said.
View the full article
In their infancy, LLM models were not difficult to contain. You gave a prompt; they responded, and if something was wrong it was usually “just text.” This could take the form of a summary that missed the best bits, a tone-deaf line or a wordy sentence.
But then, agents were co-opted as the core reasoning layer inside AI agents, and the game changed overnight. Agents connect databases and business applications, interact with external systems and execute multi-step tasks.
So, the question isn’t only, “How capable is the model?” The more important question I believe is, “How are AI agents being treated and permissioned inside your environment?”
The failures that sting aren’t limited to moments when an agent spouts inaccuracies or conjures hallucinations; they also occur when the agent takes actions it shouldn’t, simply because it has the capability, the permissions and the autonomy to do so.
The shift from answering to execution
I’m seeing interoperability accelerate agent adoption. Standards like the Model Context Protocol (MCP) are making it easier for models to connect with tools and data sources, while agent-to-agent approaches allow agents to exchange context, goals and actions across workflows.
More connections mean more reach, and more reach means more room for things to go wrong.
With AI spending forecasted to hit$2.5 trillion in 2026, and with40% of enterprise apps expected to embed task-specific AI agents by the end of 2026, the real question is no longer about adoption, it’s about visibility and control. With numbers like these, it is clear that AI integration is scaling quickly, but there is a security gap.
While AI security checks are catching up quickly, rising from 37% in 2025 to64% in 2026, that still leaves over a third without a formal assessment. This is why the right permissioning often lags behind.
As I have observed, when agents operate across multiple tools and systems, organizations are no longer managing just “AI output quality.” They’re managing action pathways, often in environments where it’s difficult to pinpoint where a request went wrong, where an input was manipulated, or which step triggered the final action. Permissioning, in this context, becomes the difference between useful automation and unauthorized behavior at scale.
Excessive agency directly proportional to over-permissioning
Organizations are worried about the level of autonomy AI introduces into their operational framework. Nearly three-quarters of organizations say agents often receive more access than necessary. It’s this excessive agency that needs to be reined in.
In practice, unchecked autonomy within a particular workflow means the agent can access systems it doesn’t need, execute actions outside its predetermined role and interact with external systems beyond predefined parameters. This means organizations are not just looking at a ‘wrong answer’ as the biggest risk, but ‘unauthorized action.’ This action may involve unintended data exposure, unauthorized commands or integrity-impacting changes that are difficult to unwind.
Over-permissioning is a sneaky beast. I’ve seen it slowly creep into agentic AI workflows, usually driven by three common factors:
The people in charge, in their ‘wisdom,’ enable a broad range of tools/APIs to make the agent even more useful. There might be some integration problems, and elevated access is given to make integration work smoothly, which means extra permissions that exceed the safe-use threshold. Agents can decide with fewer human checkpoints, especially for actions that have a tangible impact. This can stem from a blind trust in AI and a focus on being an execution-first business. 3 systemic risks in agentic AI workflows
Less than half of businesses have adopted formal risk management frameworks for AI, and I believe that’s where the real challenge with agentic AI begins. It’s not about what it can do, but that its actions become harder to observe and govern once it operates across connected systems.
First, many models are effectively black boxes. Opaque internal workings make it harder to verify outputs, explain decisions or confidently audit what happened after the fact.
Second, capability invites overreliance. In conversations I’ve had with CISOs, a consistent theme emerges. As agents appear to “handle it,” humans step back and critical reviews thin out. The result is mistakes and biases persisting longer because fewer people are watching closely, especially dangerous in high-stakes environments.
Thirdly, attackers don’t need to compromise the model itself if they can compromise what the agent reads or the services feeding it. Connected workflows create supply-chain-style attack modes, where upstream manipulation becomes the lever.
The road toward re-permissioning: Controlling agency
Re-permissioning is not about limiting the autonomy of AI agents, but more about controlling them appropriately. AI agents execute, and we need them to execute well, but we must implement a continuous permission audit to identify agents slowly climbing the ‘agency’ ladder.
Organizations must have complete visibility so they can evaluate agentic AI interactions, flag irregular behaviors, verify if permissions conform to policy and use tabletop real-world exercises like prompt-injection tests to guard against vulnerabilities. Also, subscribe to a human-in-the-loop workflow in which human oversight is mandatory when sensitive data, financial decisions, access changes or major operational updates are involved.
It’s also necessary to avoid giving agents tools ‘just in case they need them.’ Instead, implement least-privilege context sharing, limiting the agent’s view and tool access to only what the task truly requires.
Finally, let me emphasize that you shouldn’t forget the agent AI supply chain that includes integration, libraries, APIs and third parties. These need to be vetted, patched and secured with tight network controls to build a trusted ecosystem and reduce the risk of upstream manipulation.
If AI agents are treated like harmless helpers, they’ll be permissioned like harmless helpers, and excessive agency becomes normalized.
We must pump the brakes on the inevitability of unchecked autonomy. Take control of broader functionality and permissions; focus on instilling oversight where it matters. Agents can enhance operations, but only if they’re governed as actors within guardrails and not trusted by default.
This article is published as part of the Foundry Expert Contributor Network.
Want to join?
View the full article
Every year, CISOs, CSOs, and chief risk officers pore over the Office of the Director of National Intelligence (ODNI)’s Annual Threat Assessment (ATA) for insights on emerging threats they may soon face. This year, however, structural changes to the report itself underscore a foundational shift that CISOs, CSOs, and CROs must pay attention to.
In March, ODNI issued its 2026 ATA, describing threats to the United States as assessed by the Intelligence Community (IC) writ large. The 2026 ATA has seen a notable bifurcation. While still of use for the CISO/CSO/CRO, it has moved from a global, future-leaning assessment to a report of decidedly active operational reporting. Secondly, it has shifted its focus toward the “Homeland” at the expense of foreign adversary projection, most notably the absence of standalone sections on China, Russia, Iran, and the Democratic People’s Republic of Korea (DPRK).
This structural shift is a signal of intelligence contraction. Based on this ATA, the IC has moved from forecasting long-term adversary intent to reporting on immediate domestic stability. The implicit message to the private sector is clear: You are largely on your own.
The infrastructure blind spot: Omitted successes
Analytically, the most obvious shift in the ATA from the CISO perspective is the omission of the systemic infrastructure vetting that defined the 2025 ATA.
The IC appears to assume the story of infrastructure infiltration has been “told.” While the 2025 report provided robust tracking of named campaigns such as Volt Typhoon and Salt Typhoon, which detailed the pre-positioning of access in US water and power, that level of granular visibility is now missing.
This is a dangerous assumption because “pre-positioning” does not expire. By pivoting away from these long-term “hidden wars,” the 2026 report tethers cyber analysis almost exclusively to active kinetic conflict. We are now being briefed on reactive events, such as retaliatory strikes against medical technology firms, rather than the persistent, systemic infiltration of the infrastructure, supply chains, and company grids.
The bifurcated framework: Operational reporting vs. homeland focus
The report now operates on two distinct tracks that risk narrowing the threat horizon for CROs. In a departure from traditional probabilistic forecasting, the IC has transitioned toward active operational reporting. This shift prioritizes immediate success metrics, such as a significant drop in border encounters and fentanyl seizures, framing these as clear operational wins.
For the enterprise, this signals a significant contraction of the “early warning” function. Rather than receiving a strategic roadmap regarding the evolution of adversary strategy, security leaders are being briefed on the tactical aftermath of US policy.
Parallel to this operational pivot is a decisive movement toward a homeland-centric defensive posture. This pivot has effectively eclipsed foreign adversary projection as the lead intelligence priority. The IC has elevated domestic ideological infiltration to a primary concern, identifying specific ideological movements as fundamental threats to Western principles and foundational security.
This internal focus is paired with a massive reinvestment in domestic kinetic defense, exemplified by the Golden Dome for America. With the global missile threat projected to reach 16,000 by 2035, the intelligence focus has turned inward to defend the US interior, leaving the private sector to bridge the gap in understanding how foreign adversaries are adapting in the shadows.
Adversary status: The regional dissipation
The structural shift in the 2026 assessment is more than a change in document formatting; it is a signal of intelligence contraction.
By prioritizing immediate domestic metrics and homeland defense, the ODNI’s ATA has effectively dispersed the threats, essentially outsourcing the strategic heavy lifting to the private sector. The implicit message is clear: The government is now tracking the aftermath of its policies, but the burden of forecasting adversary adaptation and long-term intent now rests entirely on your shoulders.
From this jaded eye, the following are the most glaring omissions:
China: The illusion of economic pragmatism
The 2026 report has effectively archived the systemic threat posed by the People’s Republic of China, omitting the robust tracking of named infrastructure campaigns like Volt Typhoon and Salt Typhoon that defined the 2025 brief.
By folding China into a broader Asia regional challenge, the IC has swapped strategic warning for a narrative of economic pragmatism. The report prioritizes the Busan Agreement and the lack of a fixed 2027 invasion timeline for Taiwan as signs of a stable relationship.
For the C-suite, this is a dangerous dilution. China has had and continues to have an all-of-government and nation approach to adversarial relationships, to include preparing the technological environments for future conflict. The absence of reporting on pre-positioned cyber access does not mean that access has been removed; it simply means the ODNI chose not to share information about it.
Russia: The neighborhood challenger
Russia has been downgraded from a global spoiler to a neighborhood challenger focused on the Arctic and its immediate near abroad.
The 2026 assessment omits the detailed analysis of Russian hybrid warfare and de-dollarization strategies that were hallmarks of prior years. In addition, the Russian misinformation and disinformation capabilities targeting the United States and other nations is largely omitted.
Instead, it signals a desire for a geostrategic thaw contingent on a settlement in Ukraine. This regional focus masks Moscow’s continued development of asymmetric capabilities, such as satellite-based nuclear weapons and gray zone tools, which remain persistent threats to global enterprise operations regardless of a localized ceasefire.
The Democratic People’s Republic of Korea: The invisible proxy
The DPRK has nearly vanished as a standalone strategic priority. The 2026 report omits the deep-dive analysis into Pyongyang’s nuclear brinkmanship, viewing the regime instead through the lens of its tactical partnership with Russia.
While the report briefly mentions the $1 billion dollars annually netted through cybercrime, it fails to project how the regime’s new combat experience in Europe will refine its special operations or its human insider infiltration tactics. By treating the nation as a secondary proxy, the ODNI ignores its agile evolution into an independent, global cyber-mercenary force.
Iran: The fragmented adversary
The most significant omission regarding Iran is the lack of a projected roadmap for its asymmetric recovery.
The 2026 assessment characterizes the regime as severely degraded and facing its most fragile internal state since the 1980s. Given the assessment that was issued two weeks into Operation Epic Fury, it fails to address how Tehran will adapt its “Axis of Resistance” into a more decentralized, cyber-centric threat.
For the enterprise, the report’s focus on internal survival obscures a capacity for opportunistic, retaliatory strikes against Western commercial interests, a vector that often intensifies when a regime feels its conventional power is slipping. Now, 60-plus days into Operation Epic Fury, Iran’s capabilities remain, albeit in a degraded capacity.
Actionable close: The resilience premium framework
The 2026 ATA marks a departure from systemic state-actor tracking, signaling that the burden of discovery and long-term strategic defense has shifted to the private sector.
CISOs and CROs must fund a “resilience premium” (cybersecurity spend) to address these emerging operational specifics. This investment represents a fundamental analytic pivot, namely prioritizing resilience over pure efficiency to ensure task-critical assets remain functional during systemic shocks.
Here are four domains where CISOs and CROs should take action to ensure resilience:
1. Identity and insider integrity (the human vector):
Action: Overhaul identity proofing for remote hires to counter the DPRK’s agile use of IT workers with falsified credentials to gain “human insider access.” Action: Expand insider threat programs beyond data theft to include utilization of enterprise resources by those sympathetic to an “ideological” segment. The ATA would have one create an “ideological radicalization” detection capability, when the reality is a robust insider program focused on coherence, behavior, and intent will serve one well. 2. Infrastructure continuity (the “Typhoon” legacy):
Action: Conduct a “dormant access audit” of all industrial control systems (ICS). Since the IC has ceased public tracking of specific pre-positioning campaigns, the burden of identifying these “held in reserve” disruptive options now rests entirely on you. Action: Execute a C-suite tabletop focused on a “regional escalation” scenario where pre-positioned access is triggered during geopolitical tension. Include the loss of infrastructure due to kinetic events as witnessed when the UAE sustained damage to key buildings, some of which hosted the regional support for Amazon Web Services (AWS). Algorithmic defense (AI and quantum):
Action: Re-baseline quantum migration roadmaps with an 18-to-24-month hard deadline for crown-jewel systems. The IC assesses the threat of a cryptographically relevant quantum computer (CRQC) as an extraordinary technological advantage that will break current encryption protecting finance and healthcare data. Action: Force-multiply the defensive stack with AI-driven anomaly detection to counter the adversary’s use of AI as a defining technology to accelerate the speed and scale of cyber operations. Intelligence integration:
Action: Deepen public-private intelligence flows via Information Sharing and Analysis Centers (ISACs) and direct agency relationships. Use the 2026 ATA’s shift to “active operational reporting” as the catalyst for establishing more robust, independent bilateral sharing agreements. In closing, the 2026 ATA told us what has already happened. The enterprise’s job now is to figure out what happens next. You have the remit and the tools, formulate the plan and act.
View the full article
Google has addressed a maximum severity security flaw in Gemini CLI -- the "@google/gemini-cli" npm package and the "google-github-actions/run-gemini-cli" GitHub Actions workflow -- that could have allowed attackers to execute arbitrary commands on host systems. "The vulnerability allowed an unprivileged external attacker to force their own malicious content to load as Gemini configuration,"View the full article
Lesen Sie, worauf es bei der Zusammenarbeit zwischen Ihrem IT-Security- und Engineering-Team ankommt.
Foto: Lipik Stock Media – shutterstock.com
Security-Teams bestehen in erster Linie aus Mitarbeitern, die für den Betrieb und die Einhaltung von Vorschriften und Richtlinien zuständig sind. IT-Sicherheitstechnik-Teams, neudeutsch Security-Engineering-Teams, hingegen sind Konstrukteure. Sie entwickeln Dienste, automatisieren Prozesse und optimieren Bereitstellungen, um das zentrale IT-Sicherheitsteam und seine Stakeholder zu unterstützen. Das Security-Engineering-Team bestehen in der Regel aus Software- und Infrastrukturingenieuren, Architekten und Produktmanagern.
Technische Fähigkeiten im Bereich IT-Sicherheitstechnik
Security Engineering ist im Wesentlichen eine technische Disziplin, so dass eines der grundlegenden Elemente dieser Rolle natürlich in der Technologie verwurzelt ist. Dies sind die wesentlichen Fähigkeiten, die CISOs in ihren Security-Engineering-Teams vermitteln und entwickeln sollten:
Verstehen des technischen Umfelds
Dass es von entscheidender Bedeutung ist, die technische Umgebung zu verstehen und in ihr zu arbeiten, scheint eine Selbstverständlichkeit zu sein. Doch wenn ein Unternehmen beispielsweise Dienste in Kubernetes bereitstellt und das Technikteam noch nie mit Containern gearbeitet hat, ist das ein Problem. Ein hohes Maß an technischem Verständnis der gesamten IT-Umgebung wirkt sich positiv auf das Security-Team aus.
Ein Kontrapunkt dazu ist die Förderung eines vielfältigen Teams in Bezug auf die Fähigkeiten, Problemlösungsperspektiven und Erfahrungsstufen in den verschiedenen Bereichen eines Unternehmens. Es gibt natürlich viele Möglichkeiten, diese Vielfalt in einem Team anzustreben und zu fördern, vom Geschlecht und der ethnischen Zugehörigkeit über den Bildungshintergrund bis hin zu früheren Berufserfahrungen und dem Alter. Diversität kann die kreative Energie eines Teams stark erhöhen, wenn Ideen in Frage gestellt, debattiert und wiederholt werden.
Allerdings sollten Führungskräfte mit der Vielfalt an Perspektiven und Erfahrungen sorgfältig umgehen. Ein übermäßiges Maß an Variation und Reibung im Denk- und Kooperationsprozess kann zum Gegenteil der gewünschten Wirkung führen. Häufig kommt es zu einer Analyse-Paralyse, bei der die Teams in einem Zustand des Nachdenkens über das Tun statt des Tuns stecken bleiben. Ein ähnlicher Zustand, der sich aus übermäßig unterschiedlichen Teams ergeben kann, ist eine komplexe Reihe von voneinander abhängigen Ergebnissen, die miteinander verbundene Fehlerbedingungen aufweisen.
Den gesamten Stack beherrschen
IT-Sicherheitstechnikteams sollten in der Lage sein, die von ihnen entwickelten Dienste zu erstellen und zu betreiben. Dieses Maß an Eigenverantwortung innerhalb einer Gruppe ist aus Sicht der technischen Kompetenz und aus kultureller Sicht von entscheidender Bedeutung, da es den Ton in Bezug auf die Verantwortlichkeit angibt. Technisch gesehen wird ein Team, das in der Lage ist, seine Dienste selbst zu verwalten, die Infrastruktur, die CI/CD-Tools, die Security-Tools, den Anwendungscode, die Deployments und die von einem Dienst ausgehenden operativen Telemetriedaten kompetent verwalten. Darüber hinaus sind die Fähigkeiten, die hinter der Unterstützung durch ein Team stehen, in hohem Maße übertragbar, um andere Gruppen im Unternehmen zu unterstützen.
Das Entwicklererlebnis miteinbeziehen (DevX)
Security-Teams, die das Entwickler-Tool DevX verstehen, annehmen und optimieren, werden wahrscheinlich besser zusammenarbeiten. Darüber hinaus wird ein besonderer Schwerpunkt auf der Beseitigung von Reibungsverlusten liegen. Reibung führt dazu, dass Dinge länger dauern und mehr kosten, dass sich Lernzyklen verlängern und dass Frustration auftritt. Weniger Reibung wird dazu führen, dass die Dinge im Allgemeinen viel besser ablaufen.
Manchmal sind Reibungen aber auch notwendig und sollten gewollt sein. Ein Beispiel ist eine erzwungene Codeüberprüfung von kritischem Code, bevor er zusammengeführt wird. Wenn diese Unterbrechung, Überprüfung und Zusammenführung auf einer bewussten Entscheidung beruht, ist das eine gerechtfertigte, bewusste Reibung. Wenn das IT-Sicherheitsteam Reibungsverluste im Freigabeprozess von Entwicklern anstrebt, sollten diese auf spezifischen Anforderungen beruhen, zum Beispiel auf einer Compliance-Kontrolle, die eine manuelle Überprüfung als Teil des Change Managements vorschreibt. Diese Kontrollen sollten nicht unüberlegt eingesetzt werden. Die Reibungsverluste, die den Entwicklern entstehen, stellen Nachteile dar, die jedes vom IT-Sicherheitsteam in Betracht gezogene, nicht definierte Risiko aufwiegen könnten.
IT-Sicherheitsteams, die die Erfahrung der Entwickler als oberste Priorität betrachten, müssen die Werkzeuge und Abläufe verstehen, die für das Schreiben von Qualitätssoftware auf verschiedenen Ebenen des Stacks erforderlich sind. Die Übernahme dieser Denkweise, bei der der Entwickler im Vordergrund steht, erfordert möglicherweise Kenntnisse im Bereich Infrastruktur oder Plattform-Engineering. Andererseits kann sich der Output eines IT-Sicherheitstechnik-Teams auf andere auswirken, die ebenfalls mit der Automatisierung von Arbeitsabläufen, der Verbindung von Diensten untereinander und im Wesentlichen mit der gemeinsamen Instrumentierung einer immer größer werdenden Umgebung beschäftigt sind. All diese Arbeiten helfen den Entwicklern, schneller und mit weniger Reibungsverlusten zu arbeiten. Resultat sind mehr Flexibilität und ein schnelleres Deployment. Unabhängig davon ist dies eine Eigenschaft und ein Leitfaden, von dem ein Security-Engineering-Tem in seiner Produktivität profitiert und das Einfühlungsvermögen derer, denen es dient, fördert und kultiviert.
Fähigkeiten zur Führung und Zusammenarbeit in der Sicherheitstechnik
Security-Entwickler-Teams arbeiten nicht im luftleeren Raum, unabhängig von ihrem Umfang und ihrer Projektauslastung. Die Arbeit an der Seite und im Dienste anderer ist ein wesentlicher Bestandteil des Auftrags. Sie ist ein notwendiger Teil des Ganzen und hilft anderen, erfolgreiche Ergebnisse zu erzielen.
Kommunizieren und zusammenarbeiten
Die Mitglieder des Security-Engineering-Teams sollten in der Lage sein, miteinander und mit den Beteiligten außerhalb der Gruppe zu kommunizieren. Darüber hinaus sollten sie die Fähigkeit besitzen, gut zusammenzuarbeiten, um die gemeinsamen Ziele zu erreichen. Verstehen der Probleme, der Reibungspunkte, der Beschränkungen und der Möglichkeiten der IT-sicherheitsorientierten Entwicklung. Letztendlich ist es wichtiger, die richtigen Dinge zu tun, als einfach nur effizient zu arbeiten.
All diese Fragen müssen durch gezielte Kommunikation und Zusammenarbeit erforscht werden. Dies kann sich in menschenzentrierten Gestaltungsprinzipien, matrixbasierten Ressourcen oder einer auf Teamtopologien basierenden Ausrichtung manifestieren. Natürlich gibt es kein Patentrezept für die Kommunikation und Zusammenarbeit in und zwischen Teams. Unabhängig von der Herangehensweise sind Vertrauensbildung, Einfühlungsvermögen, Interesse an gemeinsamen Zielen und die Bereitschaft, den eigenen Stolz zugunsten der Mission zurückzustellen, die Grundlage.
Führen und andere beeinflussen
Seth Godin, Bestsellerautor und Marketingexperte, vertritt die Ansicht, dass jeder eine Führungspersönlichkeit sein kann – es ist eine Entscheidung, kein Titel. Es geht um das Zusammentreffen von Ideen, eine Lücke in der Richtung und jemanden, der motiviert genug ist, sich zu engagieren.
Der Erfolg von Security-Engineering-Teams ist, wie bei anderen Cybersecurity-Bereichen auch, von anderen abhängig. Er ist jedoch unabhängig von der Leistung des Teams, so optimal diese auch sein mag. Anders ausgedrückt: Man kann nicht einfach etwas bauen und dann gehen. Sie müssen anderen zuhören, sie einbeziehen, sie zur Übernahme bewegen und vieles mehr.
All das erfordert Führung. Genauer gesagt, Führung ohne Autorität. Die Mitglieder eines leistungsstarken Teams sollten in der Lage sein, das IT-Sicherheitstechnikteam selbst zu leiten und außerhalb der Gruppe Einfluss aufzubauen und zu nutzen. Das kann mit anderen Beteiligten oder mit internen Kunden eines Dienstes geschehen. Führen ohne Autorität bringt das Team dem Erfolg näher. Starke Beziehungen, organisatorisches Wissen und Kontext sowie technisches Fachwissen sollte zusammengebracht werden, um andere zu beeinflussen.
Soft Skills für Sicherheitsingenieure
Die Fähigkeiten eines Security Engineers und des gesamten Teams sollten über Kommunikation und Zusammenarbeit hinausgehen. In diesem Zusammenhang bezieht sich der Begriff “Soft Skills” auf die zahlreichen nichttechnischen Fähigkeiten, die eher nach innen gerichtet sind und die technischen Fähigkeiten ergänzen.
Zeit- und Prioritätenmanagement
Security-Entwickler werden immer viel zu tun haben. Die technischen Fähigkeiten führen dazu, dass häufig Anfragen zum Erstellen, Härten, Patchen oder allgemein zum Einmischen in die Software einer Umgebung eingehen werden. Zeit ist eine universelle Einschränkung für alle Teams. Aus diesem Grund müssen sowohl Einzelpersonen als auch Teams effektiver darin werden, Prioritäten zu setzen. Effizient zu sein, aber die falschen Dinge zu tun, bringt keinen Fortschritt. Es gibt viele Techniken, um Arbeit zu priorisieren, Wert gegen Komplexität abzuwägen und sich auf die Kundenzufriedenheit zu konzentrieren oder verschiedene Faktoren zu gewichten. Kunden- und Compliance-Anforderungen sind oft die treibende Kraft hinter den Prioritäten des Teams. Die Art der Prioritätensetzung ist weniger wichtig als die rücksichtslose Einhaltung der Prioritäten und der Schutz vor dem endlosen Ansturm von Anfragen, die mehr wertvolle Zeit in Anspruch nehmen.
Anpassungsfähigkeit
Security-Engineering-Teams sollten in der Lage sein, sich an veränderte Anforderungen, Technologien und Umstände anzupassen. Anpassungsfähigkeit bedeutet mehr als die Priorisierung einer Aufgabe gegenüber einer anderen: Entscheiden ist die Anpassung der Herangehensweise an ein Problem auf der Grundlage der Bedürfnisse der Beteiligten. IT-Sicherheitstechnikteams müssen sich an die Eigenverantwortung auf der Grundlage des Teamwachstums und der sich ändernden Bedürfnisse der Interessengruppen sowie an die bewusste Einbeziehung einer vielfältigen Gruppe von Stimmen in den Problemlösungsprozess anpassen. Der Nutzen für die Beteiligten und die gesamte IT-Sicherheitsorganisation liegt dabei in der Agilität und Flexibilität. Ein agiles Team ist ein widerstandsfähigeres Team.
Kontinuierliches Lernen
Ein Team, das in der Lage ist, ständig neue Fähigkeiten, organisatorische Zusammenhänge, Richtlinien und Arbeitsweisen zu erlernen, ist in der heutigen schnelllebigen Welt unbedingt notwendig. So sollten sich Mitglieder des Security Engineering-Teams ständig weiterentwickeln, sich selbst erneuern und auf bestehenden mentalen Modellen und Erfahrungen aufbauen. Dieses Konstrukt mentaler Modelle ermöglicht es Menschen, in Situationen einzutreten, die ähnliche Eigenschaften aufweisen wie etwas, an dem sie zuvor gearbeitet haben, und damit zu beginnen, etwas beizutragen, zu erforschen und zu tun.
Kontinuierliches Lernen kann sich auch auf die Kultur in einer Organisation auswirken. Wissen führt zum Austausch, Austausch führt zu Diskussionen und die Diskussion über neue Dinge weckt Interesse und Gespräche. Diese kollektive Entwicklung der mentalen Modelle, die das Unternehmen durchdringen, und der Art und Weise, wie Teams mit IT-Sicherheit umgehen und sich darauf beziehen, bringt die Kultur der Zusammenarbeit voran.
Die Arbeit in diesem hoch spezialisierten Bereich bedeutet nicht, dass sich ein leistungsstarkes Team nur auf die Technologie konzentrieren kann. Menschen, die Erforschung von Problemen, der Aufbau von Beziehungen und die Festlegung von Prioritäten sind allesamt wesentliche Bestandteile eines leistungsstarken Sicherheitstechnikteams. Achten Sie beim Aufbau Ihres Teams darauf, diese Elemente zu investieren und zu pflegen. (jm)
Dieser Beitrag basiert auf einem Artikel unserer US-Schwesterpublikation CSO Online.
View the full article
Designed to cripple Iran’s nuclear enrichment program, the 2010 Stuxnet worm set a cybersecurity precedent as the first time a nation escalated its activities from strategic espionage to sabotage in cyberspace. Now, a new discovery suggests such operations were in full swing years before Stuxnet came to light.
Researchers from SentinelOne have tracked down samples of a malware framework that was active in 2005 and targeted engineering modeling software by corrupting high-precision floating-point arithmetic operations.
One component of the framework, a kernel driver called fast16.sys, is briefly mentioned in the 2017 Shadow Brokers leak of documents covering exploits and tools used by US National Security Agency cyber teams.
“This 2005 attack is a harbinger for sabotage operations targeting ultra expensive high-precision computing workloads of national importance like advanced physics, cryptographic, and nuclear research workloads,” the SentinelOne researchers said in their report.
The malware framework uses a variety of techniques that are considered very advanced for malware from that era. A copy was uploaded to the VirusTotal online scanning engine almost a decade ago but remained undetected until researchers went on a hunt for pieces of malware that embed a Lua virtual machine.
The malware uses more than 100 rules to identify the exact workloads it should sabotage. While the researchers don’t know exactly what those workloads were, based on those rules they’ve narrowed down the list of targeted applications to three engineering programs, one of which appears in reports about Iran’s nuclear program and another being widely used in China for construction and structural design.
Chasing Lua-enabled malware
Lua is a programming language that originated in the early 1990s and is very popular in game and embedded systems development. Its primary attraction is that it can be embedded into existing C and C++ applications as a scripting engine.
Lua is used in modern malware to provide a way to obfuscate and deliver payloads in the form of scripts that get loaded and executed by the embedded Lua VM inside the main loader. One of the first threat actors to employ this technique is the Equation Group, an APT group that’s widely associated with the NSA’s Tailored Access Operations (TAO) team.
“We wanted to determine whether that development style arose from a shared source, so we set out to trace the earliest sophisticated use of an embedded Lua engine in Windows malware,” the researchers said.
This led to the discovery of a file called svcmgmt.exe, a malicious executable from the Windows 2000/XP era, originally created in 2005. The file is a modular service binary that uses encrypted Lua bytecode for most of its logic and includes two payloads: a file called ConnotifyDLL and one called fast16.sys.
In addition, svcmgmt.exe can execute additional Lua payloads dubbed wormlets that are used for propagation to other systems. For example, one of the identified wormlets, called SCM, attempts to copy the malware to network shares and then execute it as a remote service. This makes svcmgmt.exe the earliest documented Lua worm.
An unusual rootkit that corrupts floating point calculations
The fast16.sys payload is even more interesting as it is loaded as a kernel filesystem driver that can intercept and modify executable code when it’s read from disk. Malware components that install themselves as kernel drivers are called rootkits because they provide the highest possible privileges on the system.
In the Windows XP era, when system drivers didn’t require trusted digital signatures to be installed, rootkits were common and were used to hide the malware program’s components and activity. However, fast16.sys has a very specific purpose.
The driver monitors for the execution of .exe files compiled with the Intel C/C++ compiler, injects additional sections in their headers, and then applies a complex set of 101 bytecode pattern matching and replacement rules.
While some of the logic targets typical x86 instructions with the goal of hijacking execution flow, one injected block stands out as highly unusual for malware operations: a complex sequence of Floating Point Unit (FPU) instructions dedicated to precision arithmetic and scaling values in internal arrays.
When the researchers took those pattern matching rules and ran them against a large corpus of legitimate software from that era, only 10 files matched. All were calculation tools used in domains such as civil engineering, physics, and physical process simulation.
“The FPU patch in fast16.sys was written to corrupt these routines in a controlled way, producing alternative outputs,” the researchers said. “This moves fast16 out of the realm of generic espionage tooling and into the category of strategic sabotage. By introducing small but systematic errors into physical‑world calculations, the framework could undermine or slow scientific research programs, degrade engineered systems over time or even contribute to catastrophic damage.”
Furthermore, due to its ability to infect other systems over the network, it’s likely that more engineering workstations and servers in an environment would have been compromised, so attempts to verify the calculation by running the same simulation on multiple systems could have returned the same bogus results.
Engineering simulation targeted
SentinelOne identified three software programs that contain code matching the patching engine. One, LS-DYNA version 970, is an engineering simulation software suite that uses high-precision calculations to determine how materials behave under extreme conditions, such as high-speed impacts, crashes, explosions, metal forming, and so on.
The software was used in many industries, including automotive, aerospace, defense and manufacturing, but is also mentioned in public reporting related to Iran performing tests on warheads in connection to its AMAD program for developing nuclear weapons.
Another likely identified target, known as Practical Structural Design and Construction Software (PKPM), is a CAD suite widely used in civil engineering and building design in China. The software can simulate concrete shear design for beams and columns, providing seismic, wind, and load analysis for high-rise buildings.
The third potential target that matched the rules, Modelo Hidrodinâmico (MOHID), is an open-source water modeling system developed at the Instituto Superior Técnico in Lisbon, Portugal. The software covers hydrodynamics, water quality simulation, sediment transport, oil spill modeling, and Lagrangian particle tracking.
Implications
The SentinelOne researchers could not definitely say which workflows from these three possible programs were specifically targeted by the malware, but the implication is clear: Strategic industrial sabotage using malware was being performed by nation-state actors as far back as 20 years ago, before Stuxnet was used to damage uranium enrichment centrifuges at Iran’s nuclear plant in Natanz by injecting malicious code into programmable logic controllers.
“If I had to guess, I think the target was the simulation of specific material physics, and the implant was intended to mess with their characteristic curves (e.g. stress-strain),” independent researcher Ruben Santamarta, who also analyzed the fast16 FPU patching code, posted on LinkedIn. “For example, this would make engineers think something is more resistant than expected, when in reality, it would fail earlier than expected … as in Stuxnet.”
Santamarta, who has been researching proof-of-concept attacks against nuclear-related devices and software, said that finding something in the wild that’s potentially capable of causing physical failures by sabotaging the design phase represents a paradigm shift.
“The thing is, it happened 20 years ago, so it would be interesting to revisit some of the failures in certain countries over the years, stare at the monitor for a while, and just ponder the possibilities,” he posted.
View the full article
YouTube's picture-in-picture mode on the iPhone and iPad is expanding to more users worldwide, YouTube said today. Picture-in-picture (PiP) will be rolling out globally, so it will no longer be limited to those in the U.S. and Premium subscribers.


Non-Premium users worldwide will be able to use PiP for longform, non-music content on iOS and Android. This has already been available in the U.S. and to Premium subscribers globally, so there will be no change for those users.

Premium Lite members can still use PiP for longform, non-music content, and Premium members can use PiP for music and non-music content.

Picture-in-picture shrinks a video into a small player that can be used alongside other apps. To use PiP, swipe up to exit the YouTube app, and the video will continue to play in a small window that can be moved anywhere on the display.

The PiP changes are rolling out "in the coming months," according to YouTube.Tag: YouTube
This article, "YouTube Bringing Free Picture-in-Picture to iPhone Users Outside the U.S." first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Google Photos is getting a new wardrobe planning feature that will help you decide what to wear. AI will pull in images of clothing from the Google ‌Photos‌ library, organizing clothing items into a digital closet. You will be able to put items together to create outfits, and even virtually try them with a digital avatar on to see how they'll look.


The Google ‌Photos‌ app will show all items of clothing in a new Wardrobe section in the Collections tab. Clothing can also be viewed in specific categories like tops or bottoms. Items of clothing can be mixed and matched to create outfits, and the results can be shared with friends or saved to a digital moodboard.


In the popular 1995 comedy Clueless, main character Cher Horowitz has an iconic digital wardrobe that Google seems to be making a reality with Google ‌Photos‌. Cher uses a touchscreen computer to swipe through the clothes in her wardrobe, pairing different tops and bottoms to create an outfit. A built-in "Dress Me" button tells her if two items go together, and if they do, she can preview the clothes on a digital version of herself.

Google's version of the Clueless virtual wardrobe will be coming to Google ‌Photos‌ this summer. Google says it will be available to Android users first, and then iOS users.Tags: Google, Google Photos, Photos
This article, "Google Photos to Get AI 'Wardrobe' Feature" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Apple is developing a set of AI smart glasses to rival products like the Meta Ray-Bans, and MacRumors has learned a few more details about Apple's work on the device from an inside source.


The AI glasses will include two cameras. A high-resolution camera will be included for capturing photos and videos that can be shared on social media and used like iPhone photos. A second lower-resolution wide-angle lens will read hand gestures and provide visual input for Siri.

Apple uses hand gesture-based input for the Vision Pro, and rumors suggest the AirPods Pro will be updated with low-resolution cameras and support for gestures as well. Apple appears to be leaning into gesture support, and it's an ideal input method when no screen is available to interact with.

While future versions of the smart glasses could include an integrated display for augmented reality features, the first version will have no display at all. Apple will not include a screen, LiDAR, 3D cameras, or other similar technology because such features are too energy-intensive.

Battery life is a major constraint because Apple needs to keep the glasses slim and lightweight. Battery size is the bottleneck behind the hardware decisions that Apple is making, and it's why Apple is opting for a stripped-down feature set.

According to recent rumors, Apple is testing multiple styles for the smart glasses, with plans to use acetate. Acetate is a lightweight plant-based material that's more flexible than plastic.

Apple's smart glasses will incorporate the smarter version of ‌Siri‌ that Apple plans to introduce in iOS 27. The device will be able to take photos, record video, and make phone calls, plus users will be able to interact with ‌Siri‌ to ask questions about what's around them. The feature set will be similar to the features available in the Meta Ray-Bans that Apple is aiming to compete with.

Rumors suggest Apple could preview the glasses later this year, with a launch to follow in 2027, though it's also possible we won't see them announced until 2027.Tag: Apple Smart Glasses
This article, "Apple's AI Smart Glasses Likely to Support Hand Gesture Controls" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Apple has all but given up on the Vision Pro after the M5 model failed to revitalize interest in the device, MacRumors has learned. Apple updated the Vision Pro with a faster M5 chip and a more comfortable band in October 2025, but there were no other hardware changes, and consumers still weren't interested.


The Vision Pro has been criticized for its high price tag and its uncomfortable weight. The device is over 1.3 pounds, and even with the more comfortable Dual Knit Band that Apple added to redistribute weight, it continues to be hard to wear for long periods of time. The M5 chip added a 120Hz refresh rate, 10 percent more rendered pixels, and around 30 additional minutes of battery life, but the price tag stayed at $3,499, and it ended up not selling well.

The Vision Pro has been unpopular since it first launched, and Apple only sold around 600,000 units in total. Insider sources told MacRumors that Apple has received an unusually high percentage of returns, far exceeding any other modern Apple product.

Apple has apparently stopped work on the Vision Pro and the Vision Pro team has been redistributed to other teams within Apple. Some former Vision Pro team members are working on Siri, which is not a surprise as Vision Pro chief Mike Rockwell has been leading the Siri team since March 2025.

There have been mixed rumors about a new Vision Pro over the last couple of years, with Apple rumored to be working on a lighter-weight Vision Air that's much cheaper, but the project was tabled last year. If Apple finds a way to create a much cheaper, more comfortable VR headset in the future, the Vision Pro line could be revived, but right now, the company has no plans to launch a new model. Apple has not discontinued the Vision Pro and is continuing to sell the M5 model.

Instead of continuing to experiment with virtual reality, Apple is working on smart glasses that will eventually incorporate augmented reality capabilities, but the first version will be similar to the Ray-Ban Meta smart glasses with AI and no integrated display.

Apple has not been able to use the technology developed for the Vision Pro in its smart glasses because that tech draws too much power for a smaller, lighter device.Related Roundup: Apple Vision ProBuyer's Guide: Vision Pro (Buy Now)Related Forum: Apple Vision Pro
This article, "Apple Has Given Up on the Vision Pro After M5 Refresh Flop" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Apple has reportedly abandoned plans for a foldable "iPad Ultra" following years of disappointing sales performance for the iPad Pro.


The claim predominantly comes from the Weibo leaker known as "Instant Digital," who posted the remark in response to a question about whether the ‌iPad‌ would join a rumored "Ultra" series of Apple devices. Instant Digital listed the Apple Watch Ultra, M-series Ultra chips, "iPhone Ultra," and "MacBook Ultra" with an OLED display as products in the pipeline, but explicitly excluded the ‌iPad‌ from that group, citing weak market performance for the ‌iPad Pro‌. They added that Apple now has "no plans" to release an ‌iPad‌ Ultra.

The ‌iPad Pro‌'s sales struggles are well documented. In October 2024, it was reported that shipment projections for the M4 ‌iPad Pro‌ had been significantly cut after weaker-than-expected demand following its launch earlier that year. DSCC analyst Ross Young lowered his full-year 2024 forecast from up to 10 million units to just 6.7 million, with shipments of the 13-inch model projected to fall by more than 50% and 90% in the third and fourth quarters respectively.

Young attributed the sluggish reception in part to the high price point, with the 11-inch model starting at $999 and the 13-inch at $1,299, levels that deter buyers who view tablets as secondary devices alongside a smartphone or laptop. ‌iPad‌ revenue has declined for three consecutive years, and the category accounted for just 6.73% of Apple's total revenue in 2025.

In his latest "Power On" newsletter, Bloomberg's Mark Gurman said that Apple has been developing a 20-inch foldable ‌iPad‌, describing the project as a priority for Senior Vice President of Hardware Engineering and future Apple CEO John Ternus. Gurman noted, however, that the device "may end up being a wacky experiment that doesn't see the light of day, according to several people who have worked on it."

The rumored foldable ‌iPad‌ has a long and troubled development history. Last October, it emerged that engineering challenges tied to weight, features, and display technology had pushed Apple's target launch from 2028 to 2029 or later. The device was reportedly being developed with a large Samsung OLED display, with Apple focused on minimizing the visible crease, just like the upcoming foldable iPhone.

Prototype units reportedly weighed around 3.5 pounds, making them heavier than a 14-inch MacBook Pro and nearly three times the weight of a 13-inch ‌iPad Pro‌. The device could have been priced as high as $3,900, roughly triple the $1,299 starting price of the 13-inch ‌iPad Pro‌.

There has also been uncertainty about how the product would be categorized. In March, Gurman noted that a "gigantic" foldable ‌iPad‌ would challenge Apple's tradition of keeping the Mac and ‌iPad‌ as separate product lines, with some internally describing it as a foldable ‌iPad‌ and others as an all-display MacBook. When closed, the device reportedly resembles a Mac, with an aluminum shell and no exterior display. The design is said to be similar to Huawei's MateBook Fold, an 18-inch foldable tablet currently priced at $3,400.

The reports come against a backdrop of Apple's rumored plans to expand its "Ultra" branding across multiple product lines. At least three Ultra devices are believed to be in the pipeline for this year alone: a foldable ‌iPhone Ultra‌ priced at around $2,000, AirPods Ultra with cameras for Visual Intelligence, and a MacBook Ultra featuring a touch-enabled OLED display priced up to 20% above the current ‌MacBook Pro‌ lineup. A source speaking to Macworld subsequently corroborated the ‌iPhone Ultra‌ and MacBook Ultra names.

Apple already applies the "Ultra" moniker to Apple Watch Ultra, M-series Ultra chips, and CarPlay Ultra. An ‌iPad‌ Ultra might seem like a natural fit for a family of higher-end, more experimental hardware at the top of each lineup, but with the ‌iPad Pro‌ already struggling to find buyers at its current price point, the question of whether sufficient demand exists for an even more expensive ‌iPad‌ may be answering itself.Related Roundup: iPad ProTags: Bloomberg, Foldable iPad, Instant Digital, John Ternus, Mark GurmanBuyer's Guide: iPad Pro (Neutral)
This article, "Apple Has Likely Abandoned 'iPad Ultra' Plans" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Apple is planning to integrate Apple Intelligence and Siri into more of its apps in iOS 27, including the Camera app, reports Bloomberg. The ‌iOS 27‌ Camera app will have a dedicated ‌Siri‌ mode that will be available alongside the existing Photo, Video, Portrait, and Panorama modes. When in ‌Siri‌ mode, the existing Camera app shutter button will feature the ‌Apple Intelligence‌ logo, letting users know the ‌Siri‌ features are available.


‌Siri‌ mode will incorporate Visual Intelligence, making the feature more accessible. Right now, ‌Visual Intelligence‌ is activated by long pressing the Camera Control button, and it is a gesture that many people may not even be aware of.

In addition to being relocated to the Camera app with ‌Siri‌ branding, ‌Visual Intelligence‌ is also being updated with new features. It will be able to scan a nutrition label on food items to log the dietary information, plus users will be able to use it to add contact details for someone directly to the Contacts app.

MacRumors first discovered signs of the ‌Visual Intelligence‌ features in Apple code in mid-April. Here's a bit more on what we found:

Nutrition - Users will be able to scan nutrition labels on food packaging for calorie and macronutrient tracking using the Health app.
Contacts - ‌Visual Intelligence‌ will let users scan phone numbers and addresses on business cards and other print media, adding the information to the Contacts app.
Wallet - In the Wallet app, ‌Visual Intelligence‌ will capture information from physical event tickets and membership cards, generating digital versions.

Existing ‌Visual Intelligence‌ features will continue to be available, and it will be able to identify objects like plants and animals, add events to the Calendar app, and send visual information to ChatGPT and Google image search. Users will also be able to access the revamped ‌Visual Intelligence‌ through the Camera Control button, but it will open up to the ‌Siri‌ interface in the Camera app instead of the standalone ‌Visual Intelligence‌ experience that we have now.

Apple will introduce ‌iOS 27‌ at the Worldwide Developers Conference that's set to begin on June 8, 2026.Related Roundup: iOS 27Tag: Siri
This article, "iOS 27 Camera App to Get 'Siri' Mode With Nutrition Label Scanning" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
A leaker claims Apple is currently embroiled in an internal debate over whether MagSafe should remain a standard iPhone feature.


The Weibo leaker known as "Instant Digital" says that when ‌MagSafe‌ was first introduced, the mood inside Apple was reportedly aggressive about its expansion. ‌MagSafe‌ for the iPhone was introduced with the iPhone 12 lineup in 2020, bringing a ring of magnets to the back of the device for snap-on charging and accessory attachment. The ecosystem has since expanded significantly, with dozens of third-party wallets, cases, stands, and chargers built around the standard.

There were purportedly even plans to bring built-in ‌MagSafe‌ magnets to the iPad lineup, something the leaker previously hinted at, though those plans never materialized. Bloomberg's Mark Gurman first reported in 2021 that Apple was testing a glass-backed iPad Pro that would support wireless charging, specifically noting that MagSalfe was under consideration. A follow-up report in early 2022 suggested Apple had prototyped an iPad Pro with a large glass Apple logo that would serve as the wireless charging area, an approach aimed at avoiding the fragility of an all-glass back. Neither design made it to a shipping product. The rumors resurfaced in late 2023, with reports suggesting that the then-upcoming iPad Pro could include MagSafe support, based on information from sources familiar with Apple's magnet suppliers. The redesigned M4 ‌iPad Pro‌ that launched in 2024 still shipped without the feature.

Now, Instant Digital claims that confidence around ‌MagSafe‌ has given way to uncertainty. The leaker says Apple is weighing the costs of including ‌MagSafe‌ magnets in the iPhone against the strength of the accessory ecosystem that has grown up around the feature, though the nature of the debate and what any change might look like remains unclear.

The iPhone 16e launched without ‌MagSafe‌, making it the first new iPhone in years to omit it. Many iPhone 16e owners, as well as users of older iPhones without built-in magnets, turned to third-party cases with embedded magnet rings as a workaround, though the experience is generally considered to be inferior to native ‌MagSafe‌ support. The decision nonetheless drew criticism, and Apple reversed course with the iPhone 17e, restoring ‌MagSafe‌ support when the device launched earlier this year.

There is no indication that ‌MagSafe‌ is at imminent risk of disappearing from the iPhone lineup. However, the upcoming foldable "iPhone Ultra" may be a different story. Dummy models of the device show no visible indentations for the internal magnet array that ‌MagSafe‌ requires, suggesting the feature could be absent at launch. The iPhone Ultra is rumored to be just 4.5mm thin when unfolded, and it is thought that the device may simply be too slim to accommodate the magnets. If that proves accurate, the ‌iPhone Ultra‌ would be both the most expensive iPhone ever, with a starting price rumored at around $2,000, and the first new high-end model to ship without ‌MagSafe‌ since the iPhone 11 Pro.

While the wording of Instant Digital's post is somewhat ambiguous, it raises the possibility that Apple could be at least considering pulling ‌MagSafe‌ from its standard iPhone models, potentially making it exclusive to higher-end devices. Recent reports suggest that the standard iPhone 18 is being downgraded to cut costs.

An alternative scenario could see Apple scale back its in-device ‌MagSafe‌ implementation, relying more heavily on cases with embedded magnets to provide compatibility, as many iPhone 16e users already do. Given that Qi2, the open wireless charging standard now widely adopted across the industry, is built directly on ‌MagSafe‌'s magnet ring specification, a full removal of the feature from the entire iPhone lineup seems unlikely.Tags: Instant Digital, MagSafe
This article, "Apple Reportedly Questioning Whether iPhone Should Drop MagSafe" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Amazon this week has multiple discounts on the M4 iPad Air, providing up to $100 off these brand new models.

Note: MacRumors is an affiliate partner with Amazon. When you click a link and make a purchase, we may receive a small payment, which helps us keep the site running.

Specifically, Amazon has up to $90 off the 11-inch M4 iPad Air and up to $100 off the 13-inch M4 iPad Air. All of these discounts have been automatically applied and do not require a coupon code or a Prime membership.

$43 OFF11-inch M4 iPad Air for $556.50
$58 OFF13-inch M4 iPad Air for $741.50

The new iPad Air features the M4 chip, C1X modem, and N1 networking chip, which brings support for Wi-Fi 7 and Bluetooth 6. In terms of design, the 2026 models are identical to the 2025 iPad Air tablets, with an edge-to-edge display, slim bezels, and aluminum chassis.

11-inch M4 iPad Air

128GB Wi-Fi - $556.50 ($43 off)
256GB Wi-Fi - $644.99 ($55 off)
512GB Wi-Fi - $834.00 ($65 off)
1TB Wi-Fi - $1,009.00 ($90 off)

13-inch M4 iPad Air

128GB Wi-Fi - $741.50 ($58 off)
256GB Wi-Fi - $821.66 ($78 off)
512GB Wi-Fi - $1,001.72 ($98 off)
1TB Wi-Fi - $1,199.00 ($100 off)

If you're on the hunt for more discounts, be sure to visit our Apple Deals roundup where we recap the best Apple-related bargains of the past week.



Deals Newsletter

Interested in hearing more about the best deals you can find in 2026? Sign up for our Deals Newsletter and we'll keep you updated so you don't miss the biggest deals of the season!




Related Roundup: Apple Deals
This article, "Get Up to $100 Off the M4 iPad Air on Amazon" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Share tips for growing an Instagram following organically.


Explain the importance of backlinks in SEO and how they impact search engine rankings.


Provide tips for writing compelling subject lines that increase email open rates.


Share techniques for repurposing content across different platforms to maximize reach and engagement.


Explain the difference between search ads and display ads and when to use each for optimal results.


Describe how to measure and track conversion rates on a website using Google Analytics.


Generate ideas for a blog post titled '5 Innovative Social Media Marketing Strategies for 2023


Draft a script for a 30-second video ad promoting our eco-friendly skincare line


Discuss the benefits and drawbacks of running Facebook ads for small businesses.


Explain how to identify and collaborate with influencers for brand partnerships.
What's a professional way to start an email to a potential business partner?
Write an opening line for an email asking for a meeting to discuss a collaboration opportunity.
Help me explain the benefits of a collaborative project in an email to my team.
Compose a closing sentence for an email that encourages a response regarding a job application.
Suggest a formal sign-off for an email to a new client.
How can I personalize an email for a marketing campaign targeting young professionals?
My Name: Mario Boss's name: John Write an email to my boss saying that I will be out of office today since I am sick.
Write a cold outreach email to this founder, named Pranav, pitching him our product, which is a neo-CRM. Make the email formal, yet approachable.
Compose a professional introduction email to a potential client highlighting our services.
Draft an email requesting a meeting with a colleague to discuss project collaboration opportunities.
Suggest some unique blog topics about sustainable living in urban areas.
Generate 5 catchy titles for a blog post about easy home workouts.
Create an outline for a blog post about the top 10 travel destinations for 202
Write an engaging introduction for a blog post about the benefits of meditation.
List some SEO keywords for a blog post about vegan baking recipes.
What are some key points to include in a blog about starting a small business?
Compose a strong conclusion for a blog post about advances in renewable energy.
Outline a blog post on '10 Easy and Healthy Recipes for Busy Weeknights'. Include sections on preparation time, nutritional value, and beginner-friendly cooking tips.
Write an engaging introduction for a blog post titled 'Exploring the Hidden Gems of Bali: A Traveler's Diary'. Focus on vivid descriptions of landscapes and cultural experiences.
Create a comprehensive outline for a blog post reviewing the latest smartphone model. Include sections on design, performance, camera quality, battery life, and price comparison.
Apple has lost a court battle to delay App Store changes while it asks the U.S. Supreme Court to weigh in on its long-running dispute with Epic Games surrounding developer fees.


On Tuesday, the Ninth Circuit Court of Appeals reversed an earlier decision that had let Apple keep its current App Store commission structure in place while it appeals to the Supreme Court. The reversal means Apple now has to return to a lower court to work out what fees it can charge developers who steer customers to outside payment options.

Apple won the pause earlier this month by arguing that it shouldn't have to overhaul its fee structure twice if the Supreme Court ultimately ruled in its favor. In response, Epic Games immediately filed two motions: one said it hadn't been given time enough to prepare a response to Apple's stay request, and another asking the court to reject the original request.

The three-judge panel granted Epic's motion for reconsideration. The judges said Apple hadn't shown that the Supreme Court was likely to take the case, and pointed out that the high court already chose not to hear Apple's challenges once back in 2024. They also rejected Apple's claim that being forced into lower-court hearings would cause real harm.

Epic Games CEO Tim Sweeney shared the news in a post on X, adding that "Apple's delaying tactics have come to an end!"


The case now heads back to Judge Yvonne Gonzalez Rogers in California, who will determine what commission Apple can collect on purchases made through external links, if any. Apple can still petition the Supreme Court while those proceedings move ahead.

The dispute traces all the way back to the original Epic Games trial, which Apple largely won. However, one exception was a 2021 ruling from Judge Gonzalez Rogers ordering Apple to relax its "anti-steering" rules and let developers point users to outside payment options.

Apple complied with the ruling, but only slightly lowered its fees, which led few developers to even bother adding links. Epic subsequently returned to court, and the judge found Apple in willful violation of the original injunction. Consequently, it barred Apple from collecting any commission on external links.

Apple appealed and dropped the link fees while the case moved forward, but the company argued that the ruling was unconstitutional and that it should receive compensation for its technology. Then in December 2025, the appeals court delivered a split decision: Apple had violated the injunction, but the company should still be able to charge something reasonable. That sent the question of what that fee should look like back to the district court.

Apple is now hoping the Supreme Court will go further and throw out the district court's ruling altogether.Tags: App Store, Epic Games, Epic Games vs. Apple, Apple Lawsuits
This article, "Epic Games Wins Reversal of Stay in App Store Fee Legal Battle" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
A critical remote code execution (RCE) vulnerability in GitHub could potentially allow attackers to execute arbitrary code on GitHub.com and GitHub Enterprise Server.
Uncovered by Wiz researchers, the now-patched bug exploited how GitHub handles server-side “git push” operations. By crafting malicious input within a standard Git push, an authenticated user could execute arbitrary commands via GitHub’s backend Git processing pipeline.
GitHub acknowledged the severity of the finding, with CISO Alexis Wales noting, “A finding of this caliber and severity is rare, earning one of the highest rewards available in our Bug Bounty program.”
GitHub fixed the issue on GitHub.com and released patches for all supported versions of GitHub Enterprise Server within hours of the report. However, Wiz said that 88% of Enterprise Server instances remained vulnerable on the internet at the time of public disclosure.
GitHub’s faulty processing of git push
The flaw, tracked as CVE-2026-3854, stemmed from how GitHub processes git push requests within its backend Git infrastructure. According to Wiz, the issue involves an internal component referred to as X-STAT, which sits in the path of GitHub’s server-side handling of Git operations.
Wiz researchers found that a specially crafted git push could pass maliciously structured input into X-STAT, where it was not safely handled before being incorporated into backend command execution. Because this processing happens server-side as part of GitHub’s normal handling of repository events, the input could influence how commands were constructed or executed within that pipeline.
The flaw received a near-critical CVSS rating of 8.8 out of 10, and was fixed in GitHub Enterprise Server versions 3.14.25 through 3.20.0. The flaw was categorized by GitHub as a “command injection” issue, resulting from “improper neutralization of special elements used in a command.”
AI was reportedly used in finding this flaw, using the IDA MCP (AI-augmented) reverse engineering tooling. “This is one of the first critical vulnerabilities discovered in closed-source binaries using AI, highlighting a shift in how these flaws are identified,” Wiz researcher Sagi Tzadik said in a blog post. “Despite the complexity of the underlying system, the vulnerability is remarkably easy to exploit.”
Full compromise across tenants
In its analysis, Wiz detailed how the issue could be escalated from initial command execution to full remote code execution on affected systems.
“On GitHub.com, this vulnerability allowed remote code execution on shared storage nodes. We confirmed that millions of public and private repositories belonging to other users and organizations were accessible on the affected nodes,” Tzadik said, adding that the impact was even more severe for self-hosted environments. On GitHub Enterprise Server, the vulnerability granted full server compromise, including access to all hosted repositories and internal secrets.
Wiz confirmed that it did not access the contents of other tenants’ repositories while testing the exploit. “ We validated the cross-tenant exposure using only our own test accounts, confirming that the git user’s filesystem permissions would allow reading any repository on the node,” Tzadik added.
GitHub shared remediation steps and full technical details in a security blog post, adding that “GitHub Enterprise Cloud, GitHub Enterprise Cloud with Enterprise Managed Users, GitHub Enterprise Cloud with Data Residency, and github.com were patched on March 4, 2026. No action is required from users of any of these.”
GitHub Enterprise Server users were urged to patch immediately with fixes available for all supported versions.
View the full article
Alert fatigue remains one of the clearest symptoms of a SOC operating model under strain. In this blog, we look at whether an autonomous SOC can actually reduce alert fatigue, where agentic SOC workflows help most, and why human oversight still needs to remain part of the model. The goal is not full hands-off security, but a better balance between machine-speed execution and accountable decision making.
View the full article
Memory could account for as much as 45 percent of an iPhone's component costs by 2027, up from around 10 percent today, according to a JPMorgan analysis cited by the Financial Times ($).


Apple buys memory for roughly 250 million iPhones a year and has historically been one of the largest customers in the category. But Apple has reportedly now gone from a position where it could set terms to one where it now has to compete with rivals for supply.

The principal reason is the heavily subsidized AI build-out that's underway.

In a race to make data centers that can handle more compute for frontier AI models, AI infrastructure buyers like Nvidia are now reportedly outbidding consumer electronics makers for limited supply from the likes of Samsung, SK Hynix, and Micron. Meanwhile, cloud companies are reportedly making upfront payments worth billions of dollars to secure capacity.

It's a marked break from the industry norm of committing to volumes with suppliers first and negotiating prices later.

The pressure is already reshaping Apple's product plans, and the split-launch cycle for the iPhone 18 series is said to be part of that new reality. Apple is expected to stagger the iPhone 18 launch, holding the lower-priced model until spring 2027 rather than shipping the full lineup in the usual fall window. Instead, only the iPhone 18 Pro models will be launched in September, with a foldable iPhone expected to be unveiled around the same time.

Apple hardware engineering chief John Ternus takes over from Tim Cook as CEO on September 1, and Cook will transition to his new role as Apple's first executive chair, where he is expected to take a direct role in day-to-day operations. Meanwhile, Ternus's first big decision will be whether Apple absorbs the increasing cost of memory or passes it onto consumers.

Bank of America analyst Wamsi Mohan reckons the decision could come down to whether Apple holds prices to please consumers or accepts a margin hit, especially in markets like India and China where it competes with local smartphone makers. "By the time September rolls around, Apple has two choices: one, they reprice [products] higher, or two, they say 'let's go ahead and gun for market share,'" Mohan told the FT. He thinks there is a decent chance that Apple will opt for market share.Tag: Financial Times
This article, "Report: iPhone Memory Costs Set to Quadruple by 2027" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
As Amazon celebrates the 20th anniversary of its AWS cloud this year, the world’s biggest cloud computing provider now faces two giant cybersecurity threats — AI and quantum.
How the company will navigate these emerging issues to ensure the security and resilience of systems used by its millions of corporate customers remains an evolving question. But senior executives at AWS believe key decisions and innovations the company has made throughout its 20-year run position it to handle these threats.
Here is a look at three key AWS advances and how they factor into what the company and its customers are dealing with as emerging threats now and in the years ahead.
Nitro and ‘zero humans’ infrastructure
When Amazon released Virtual Private Cloud, its networking layer for AWS, in 2009, it was all software.
“Now VPC is implemented in hardware,” says Eric Brandwine, who first came to AWS more than 18 years ago to work on that project and is now a VP and distinguished engineer for Amazon security.
What changed was 2017’s introduction of Nitro, a hardware foundation for networking, security, and the hypervisor that enforces strong isolation between customer instances. Amazon paid more than $350 million for a fabless semiconductor company in 2015 to make the technology shift possible.
“Commercial hypervisors are a mature and appropriate technology but not designed for cloud scale for the kind of multi-tenancy we have,” Brandwine tells CSO.
Nitro also enables Amazon to operate AWS without employees ever touching customer infrastructure. “With Nitro, there’s no human access to it,” he says. “This is one of the reasons why we’re able to offer bare-metal instances.”
If maintenance is required, all customer content is removed from the machine before employees can get into it.
“And we’ve had third parties take a look at this process,” he adds, including NCC Group, which conducted an architecture review of Amazon’s security claims in 2023.
Today, Nitro provides the trust foundation for protecting the company’s quantum-safe encryption keys, for securing the identities of AI agents, for protecting AWS infrastructure against rogue agents, and for providing the confidential compute foundation for AI workloads themselves.
Symmetric cryptography and the quantum threat
Back in the early 2010s, most hardware security modules used asymmetric cryptography to protect security keys. Asymmetric cryptography, the kind used to secure online communications, involves pairs of keys — one to lock, another to unlock. It’s a very useful and convenient approach when dealing with multiple parties.
Amazon chose to use symmetric encryption instead, where the same key is used to both lock and unlock the data, because it’s faster and more efficient.
“One of the things we did 15 years ago is that to authenticate customers who talk to us, we rely on symmetric cryptography,” says Ken Beer, director of AWS cryptography. “And the Key Management Service that I helped launch back in 2013, we also said we would rely on symmetric cryptography to protect all the keys.”
Today, over 99.9% of all the encryption of data at rest involves no asymmetric cryptography anywhere in the chain of keys that secure it, he says.
That turned out to be an extremely fortuitous decision.
The reason? Quantum computers are expected to be able to break today’s asymmetric encryption standards — but symmetric encryption is safe. And quantum computing progress has been moving so quickly of late that both Google and Cloudflare have moved up their timelines.
Companies of all sizes are now up against the clock to update their cryptography to quantum-safe algorithms — unless those algorithms are symmetric.
“We don’t have to change it, and we’re glad we don’t have to change it,” Beer says. As for all the data stored on Amazon’s servers, the company doesn’t have to decrypt and re-encrypt it with quantum-safe methods. It’s already quantum-safe.
That’s not to say that Amazon doesn’t have any asymmetric encryption anywhere. Communications with untrusted counterparties, or over the public Internet, require it.
AWS is targeting 2028 and 2029 to complete its public-certificate post-quantum authentication — there’s a delay there because the world still needs to agree on a common set of standards.
“It’s going to require cooperation between five or ten big vendors,” says Beer. “Once we agree on the method of validating digital signatures, then all the vendors that own different parts of the technology stack will go and implement it.”
Amazon has been a member of the CA/Browser Forum for over a decade, he says, referring to the industry body that sets the rules for how public key infrastructure works on the Internet. “We have confidence that we’ll move the industry by 2029.”
AWS customers who use AWS for their cryptographic heavy lifting get post-quantum protection for free without additional effort. Those who have their own asymmetric cryptography, however, will have to do some serious work.
“There’s potentially a lot of crypto embedded in people’s applications,” Beer says. “Can I find it? Can I change it? Do I have to go talk to some vendor I haven’t talked to in ten years — or that doesn’t exist anymore?” Those are the kinds of questions enterprise customers should be asking.
S3 security controls and the shared responsibility model
There have been no public instances of AWS Nitro or encryption infrastructure being compromised. The NCC report, as well as other analyst research, shows that it’s working.
But Amazon data breaches are constantly in the news. The reason? AWS customers are failing to secure their S3 buckets, leaking credentials, hard-coding keys, and making many other mistakes when managing their environments.
According to cybersecurity firm UpGuard, AWS S3 security is “flawed by design,” with thousands of breaches over the past few years detected by the firm.
“From the day that S3 launched, buckets have been secure by default,” counters Brandwine.
That is accurate, UpGuard says — but AWS makes it too easy to accidentally misconfigure buckets, it concludes.
Brandwine admits there’s an issue here. “If a customer has a bad day in the cloud, it’s something that they did,” he says. “But if a bunch of customers have a bad day in the cloud, we need to take a look.”
Say, for example, a company uses an S3 bucket to hold some content and then takes down the bucket — but there are still web pages, or services, or tools that link to it. Attackers can hijack these abandoned buckets and use them for malicious purposes.
This is user error — customers who take down buckets should also take down the links pointing to them. But it happens. And happens frequently.
“So we built a thing called active defense,” says Brandwine.
When Amazon detects someone trying to use a dictionary attack to guess bucket names, “we lie to them and say, ‘Bucket not found,’“ he says. “It makes scanning ineffective and has effectively ended dictionary attacks against S3.”
But the AWS infrastructure is complex, and there are many instances in which enterprise customers can easily set up policies incorrectly. And it’s not just customers.
Amazon employees also make mistakes. In CodeBreach, AWS engineers misconfigured AWS’s own systems, according to Wiz researchers.
Attackers have always looked for opportunities to exploit misconfigurations, weak credentials, and similar customer-side problems. Now, with AI, the risks are greater than ever.
“AI isn’t changing what threat actors do,” says Gee Rittenhouse, VP of security services at Amazon. “It changes the speed and scale at which they operate. We still see the primary threat vectors, such as phishing and credential compromise, but the exploits are much faster.”
Amazon is also leveraging this technology, he says.
At the end of March, AWS launched its AWS Security Agent for on-demand penetration testing and AWS DevOps agent, which autonomously resolves incidents.
“We have attacker agents pitted against defender agents and what used to take a few weeks we’re now able to do in a few hours,” he says.
But there’s another way in which AI is a big emerging threat for Amazon. The AI agents that enterprises are building and deploying on AWS could be the next big breach vector, the new equivalent of unsecured S3 buckets.
Can Amazon take its successes at securing its infrastructure and combine it with the lessons learned from years of S3 bucket breaches to build a security foundation for AI agents?
Rittenhouse says yes. And a lot of it comes down to the agent authentication layer and access privileges.
“We just released a new authentication, the OAuth 2 token exchange,” he says. It’s part of Amazon Bedrock AgentCore Identity, and it involves keeping track of which user the AI agent is acting on behalf of, and what resources it’s trying to access.
“It evaluates whether the agent can do this before it does it, at the infrastructure layer,” says Rittenhouse. “And if it’s no, it’s not allowed to do it then, regardless of the command, or whether it’s hallucinating, or whether it’s been taken over, our infrastructure does not allow that.”
“That’s the advantage we have,” he adds. “We go all the way from the infrastructure layer.”
View the full article
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added two security flaws impacting ConnectWise ScreenConnect and Microsoft Windows to its Known Exploited Vulnerabilities (KEV) catalog, based on evidence of active exploitation. The vulnerabilities are listed below - CVE-2024-1708 (CVSS score: 8.4) - A path traversal vulnerability in  ConnectWise ScreenConnectView the full article
CSO and CISO roles are among the hardest to fill in IT. Which should be good news for cybersecurity professionals that aspire to leadership positions as the organization’s top security exec.
For those that do, the authority, clout, pay, and benefits are increasing significantly. But so too are the responsibility and accountability placed on cybersecurity leaders today. Now typically part of the C-suite, many CSOs and CISOs report directly to the CEO, and all are expected to be a driving force for organizational security, compliance, and, in many cases, overall business success. So while either title may be very personally rewarding, the role is definitely not for the faint of heart.
With that in mind, we asked current and recently elevated CSOs, as well as executive recruiters, about what it takes to land a top security executive appointment or promotion, and how those interested in earning the CSO or CISO role should go about getting it.
Evolving responsibilities and expectations for CSOs
One person who has seen the CSO role significantly evolve is Kanani Breckenridge, CEO and headhuntress at San Diego-based Kismet Search.
“I’ve been recruiting for the CSO and CISO functions for over 25 years,” Breckenridge explains. “I started in 1999 during the dot-com bubble, when security was largely perimeter defense and antivirus software. Since then, I’ve watched the role evolve from technical gatekeeper to enterprise risk executive. Today’s CSO sits at the intersection of technology, regulatory exposure, revenue continuity, and brand trust. It is no longer a back-office function. It is a board-level accountability role.”
With this new responsibility, Breckenridge says CSO candidates today are typically expected to:
Govern the explosion of shadow AI and establish guardrails for generative AI before it creates material data leakage. Move beyond prevention and operate as a business enabler, proving the organization can maintain a minimum viable business during a sustained outage. Address compliance burdens, such as SEC disclosure rules or the EU AI Act, not as a checklist, but as a strategic shield that protects enterprise value. “Resilience, transparency, and measurable assurance are now baseline expectations,” Breckenridge explains.
Find out what it takes to be an award-winning CISO at the CSO Cybersecurity Awards & Conference, May 11-13, 2026, in Nashville. href="https://event.foundryco.com/cso-conference-awards/?utm_medium=editorial&utm_source=cso2026_foundry_pre-event_editorial&utm_campaign=cso_2026_pre_event_articles&utm_term=4/25/2026-5/16//2026&utm_content=editorial">Register to attend
Living the evolution of cybersecurity leadership
One cybersecurity professional that has lived that transformation is Dale Hoak, who in July 2025 was promoted to the role of CISO at RegScale, a leading provider of continuous controls monitoring (CCM). Hoak originally joined RegScale as its first security hire and one of its first employees. Since then, he has helped the company build its security foundation.
In announcing Hoak’s promotion at the time, RegScale CEO Travis Howerton noted, “The CISO role is often seen as a lifetime achievement award in this field, and Dale has earned it. With decades of experience in the Department of Defense and private sector, he has brought deep expertise, a relentless drive, and a clear vision to our security program.”
In his years leading up to RegScale, Hoak “built security programs from scratch, fixed ones that were broken, operated in environments where downtime and data loss or failure had real consequences,” he says. “That experience gave me what I believe to be a strong operational background and mindset and healthy respect for practicality over theory. It’s how you do it, not how you think about it.”
RegScale agreed when it offered Hoak its first cybersecurity role. For Hoak, the mission was clear: “Build trust and scale without slowing the business down,” he says. “RegScale lives in some of the most highly regulated environments out there. Security has to be an enabler; it can’t be a blocker. The CISO’s role in every company is to help the organizations get to ‘yes,’ because organizations often can’t get out of their own way.”
As a CISO, you must understand how to make a positive impact on the business, he adds. You’re not just security. Part of your job in the C-suite is to help the organization make money, Hoak advises.
The journey through the ranks to CSO
Another cybersecurity professional who worked his way up the ranks, though through a multi-employer path, is Russ Kirby, now CISO at Ping Identity.
“I’ve previously worked across technical, compliance, and business-facing roles, so I bring variety and breadth of experience,” Kirby explains. “The size and scale of those roles and companies has also been dramatically different — from startups to Fortune 50s. I can talk in context of the ‘now,’ but also look to the future and see where the company wants to go.”
That experience led Kirby to the role of CISO at ForgeRock in 2019. When ForgeRock was acquired by Ping Identity and the companies officially merged in August 2023, he took over the role of global CISO at Ping Identity.
“I view the CISO position as a business leadership role rather than just a technical one, focusing on people and strategy,” Kirby explains. “The ability to communicate and translate for a broad spectrum of audiences — technical, non-technical, business, non-business — is critical. As a CISO, you need to be able to help people understand the ‘why’ of what we do.”
Once viewed primarily as a senior technologist focused on systems and controls, today’s CISO now sits at the heart of business strategy, Kirby says. The modern CISO is also, by necessity, a futurist: forecasting not just threats, but how digital trust, identity, and security will determine which businesses succeed and which fail.
Minimal business and technology skills for CSO candidates
The gold standard CSO candidate today has a T-shaped background: deep expertise in one or two domains with broad fluency across the rest of the security ecosystem, Breckenridge explains. Here, three areas stand out:
Deep experience in identity and access management is often more valuable today than traditional network security. Leaders who have lived through large-scale hybrid or multicloud migrations across AWS, Azure, or Google Cloud Platform understand the modern attack surface in a way legacy operators often do not. You do not need to be a data scientist, but you must understand model risk, data poisoning, automated agents, and how AI reshapes both offensive and defensive security dynamics within your environment. “On the technology side, proficiency in security automation and continuous control monitoring is increasingly critical,” Breckenridge explains. “In 2026, if you cannot automate compliance and evidence collection, you cannot scale. Manual security programs do not survive growth.”
On the business side, financial acumen is non-negotiable, Breckenridge says. You must be able to explain a $5 million security investment in terms of revenue protection, contractual leverage, or reduced insurance premiums.
“Boards think in terms of exposure, enterprise value, and downside risk. If you cannot translate your strategy into that framework, you will struggle to gain sustained support,” Breckenridge says.
Challenges and surprises that often await a new CSO
Once appointed or promoted to a CSO role, certain challenges and surprises may come up that new appointees will have to navigate.
“One I learned early on, and I wasn’t ready for this, is that everything is a negotiation,” RegScale’s Hoak explains. “Whether you’re dealing with vendors or your own teams, you have to identify problems, and then negotiate with other folks to get them to understand it or to do what they need to do.”
“I’m used to the old days, where you tell somebody to do it, and they do it,” Hoak says. “Now, most everything is a negotiation, regardless of whether you’re going up or down, whether you’re talking to a superior or subordinate. The other thing is that rarely are the hardest problems technical in nature. Most of the time you’re dealing with either poor planning or poor communication. I find that I spend far more time doing research and root cause analysis now than actually fixing issues.”
Ping Identity’s Kirby agrees, noting that most CSO burnout is caused by issues related to hero culture, micromanagement, and failure to delegate.
“This is not a mental health crisis caused by hackers; it is a leadership design flaw,” Kirby explains. “The most important point is that it’s entirely fixable through modern delegation models, autonomous team structures, and trust-based leadership.”
Steps to take toward landing a CSO role
What are best steps a CSO candidate or aspirant can take to land a coveted role?
It starts with transitioning your mindset from being the “No” person to being the “How” person, Breckenridge explains. The modern CSO must evolve from cost center to trust center as the role has shifted to being a more integrated part of the overall business and associated with revenue. Security should be a reason a customer feels confident signing a contract, not the reason a product launch is delayed.
“Focus on continuous assurance,” Breckenridge says. “At any given moment, you should be able to demonstrate that your controls are functioning as intended. That level of transparency transforms board conversations from reactive to strategic.”
From a recruiting perspective, Breckenridge advises candidates not to pursue the title without the competence and real operating depth to back it up. Technology is evolving quickly, the regulatory environment is tightening, and this role carries genuine personal exposure.
When candidates move between companies, they are evaluated on measurable scope, authority, and outcomes, Breckenridge adds. Boards and hiring committees look closely at what happened under your watch. If there were material incidents, weak controls, or inflated scope relative to your actual mandate, that becomes visible very quickly. Title inflation does not hold up under due diligence.
“The successful leaders who build durable careers in this role align accountability with authority, speak fluently in both risk and revenue, and position security as an embedded strategic function of the business,” Breckenridge says. “When you do that well, you are not simply protecting the company. You are strengthening its resilience and long-term enterprise value.”
There’s no playbook for leading through today’s cyber risk—only experience. The CSO Cybersecurity Awards & Conference brings together CISOs and senior security executives for peer‑driven insight, unfiltered conversations, and practical strategies that drive real business impact. Register here
View the full article
The popular Notepad++ coding editor is now available as a native macOS app, following a successful open-source community port of the original Windows codebase. The Notepad replacement runs as a universal binary, so it works on both Apple silicon and Intel Macs.


Notepad++ has been one of the most popular text editors on Windows for more than 20 years. Until now, Mac users who switched from Windows, or who worked across both platforms, had to choose between giving up the editor and running it through a Wine or CrossOver compatibility layer. Now those users have no such dilemma.

The editing experience is identical to the Windows version, right down to the Scintilla engine, tabbed editing, syntax highlighting for 80+ languages, search and replace, macro recording, and plugin support. The only difference is that the menus, dialogs, file pickers, keyboard shortcuts, and windowing all use native macOS Cocoa APIs.

Notepad++ for macOS is maintained by Andrey Letov, who wrote the Objective-C++ Cocoa UI that replaces Notepad++'s Win32 front-end. The app is available to download from the Notepad++ website. It's completely free and released under the GNU General Public License, so there are no ads, subs, or hidden costs.

(Thanks, Mike!)
This article, "Notepad++ Code Editor Comes to Mac After 20-Year Wait" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
In yet another instance of threat actors quickly jumping on the exploitation bandwagon, a newly disclosed critical security flaw in BerriAI's LiteLLM Python package has come under active exploitation in the wild within 36 hours of the bug becoming public knowledge. The vulnerability, tracked as CVE-2026-42208 (CVSS score: 9.3), is an SQL injection that could be exploited to modify the underlyingView the full article
Introduction
In the fast-paced and ever-evolving construction industry, the need for efficient project management tools is more pressing than ever. Construction management software tools have become essential for overseeing the various aspects of construction projects, from scheduling and budgeting to resource allocation and risk management. As the industry faces rising demand for quicker project timelines and higher accountability, these software tools offer much-needed solutions for managing workflows, collaborating with stakeholders, and maintaining a clear overview of project progress.
In 2026, construction management software tools are designed to enhance productivity, reduce costs, and improve communication among teams and clients. With the advent of cutting-edge technologies such as artificial intelligence (AI), cloud computing, and mobile integration, these platforms are constantly evolving to meet the diverse needs of construction professionals. Whether you’re a small contractor or managing a large-scale construction firm, choosing the right software can significantly impact the efficiency of your operations.
This blog post will explore the top 10 construction management software tools of 2026, providing a comprehensive analysis of their features, pros, cons, and comparison to help you choose the best fit for your business.
Top 10 Construction Management Software Tools in 2026
1. Procore
Short Description: Procore is an industry-leading construction management platform that integrates project management, construction financials, and quality & safety measures. It’s designed for construction professionals to manage all project phases.
Key Features:
Comprehensive project management capabilities. Real-time collaboration with teams. Automated task management and reporting. Mobile app for on-site management. Integration with other construction tools like BIM and accounting software. Pros:
Extensive integrations with other software. Excellent customer support and training resources. Ideal for both large and small construction firms. Cons:
Pricey for small-scale contractors. Steep learning curve for new users. 2. Buildertrend
Short Description: Buildertrend is a user-friendly construction management software designed for homebuilders, remodelers, and general contractors. It focuses on simplifying project scheduling, budgeting, and customer communication.
Key Features:
Cloud-based software accessible from any device. Powerful budgeting and financial tracking tools. Customizable scheduling options. Real-time client communication via the app. Document and photo management. Pros:
Simple and intuitive interface. Excellent customer support. Good for residential and small commercial projects. Cons:
Limited functionality for large-scale commercial projects. Expensive for small contractors. 3. CoConstruct
Short Description: CoConstruct offers a comprehensive project management solution focused on custom home builders and remodelers. It simplifies project planning, client management, and team collaboration.
Key Features:
Budget management and cost tracking. Real-time collaboration with team members and clients. Customizable client-facing portals. Mobile-friendly interface. Scheduling and task management. Pros:
Great for custom home builders and remodelers. Strong focus on client management and communication. Excellent mobile app for on-the-go access. Cons:
Not as feature-rich for larger construction firms. Limited integrations with third-party tools. 4. PlanGrid (by Autodesk)
Short Description: PlanGrid is a mobile construction management software that helps teams collaborate in real time. With its ability to handle construction drawings, plans, and specs, it’s a go-to tool for field workers.
Key Features:
Easy document sharing and version control. Field management features (punch lists, change orders). Real-time collaboration and updates. Cloud storage for drawings and blueprints. Supports both desktop and mobile devices. Pros:
Excellent for field teams to manage blueprints. Seamless integration with Autodesk products. High-quality mobile app with offline capabilities. Cons:
Primarily geared toward field teams; lacks advanced project management tools. Limited financial and resource management features. 5. Smartsheet
Short Description: Smartsheet provides a flexible work management platform that offers powerful features for construction teams. It focuses on managing project schedules, resources, and budgets with real-time collaboration.
Key Features:
Spreadsheet-based interface for project management. Advanced reporting and automation. Resource allocation and tracking. Gantt charts for visual timeline management. Real-time collaboration for teams. Pros:
Highly customizable for various workflows. Excellent for managing schedules and resources. Suitable for construction teams of any size. Cons:
Some features can be complex to set up. Doesn’t specialize in construction-specific needs like blueprints. 6. e-Builder
Short Description: e-Builder is a cloud-based construction management software that helps teams streamline project workflows, budget management, and reporting. It’s designed for large construction enterprises with a focus on improving project outcomes.
Key Features:
Budget and cost management tools. Real-time data and analytics for decision-making. Document and change order management. Integration with project scheduling tools. Supports team collaboration through a centralized platform. Pros:
Advanced analytics and reporting. Great for large enterprises and complex projects. Strong document management capabilities. Cons:
Higher cost compared to some other tools. Limited mobile app functionality. 7. Jobsite Unite
Short Description: Jobsite Unite focuses on team communication and collaboration, offering simple project management tools to keep projects on track. It is great for contractors looking for a straightforward, easy-to-use platform.
Key Features:
Task management and scheduling tools. Real-time communication with teams and clients. Document storage and sharing. Photo and video management. Mobile-friendly for on-site use. Pros:
Simple and easy-to-use interface. Great for small and medium-sized contractors. Affordable for most businesses. Cons:
Lacks some advanced project management features. Limited integrations with other software. 8. Fieldwire
Short Description: Fieldwire is a jobsite-focused construction management platform that helps teams coordinate tasks, track progress, and communicate in real time. It’s especially popular among field teams for its simplicity and strong mobile experience.
Key Features:
Task management with real-time updates and notifications. Plan viewing and markup tools for easy collaboration. Offline mode for jobsite access without internet. Progress tracking with photos and reports. Seamless coordination between field and office teams. Pros:
Very user-friendly, especially for on-site crews. Strong mobile app performance (even offline). Improves communication between field workers and managers. Cons:
Limited advanced financial/project accounting features. May require integration with other tools for full project management. 9. Buildertrend Construction Management Software
Short Description: Buildertrend is a highly-rated construction management platform that excels at handling communication between contractors, project managers, and clients.
Key Features:
Budget and project management. Time tracking and reporting. Easy-to-use mobile interface. Client communication tools. Document and file storage. Pros:
Great for both contractors and clients. Mobile-friendly for ease of use on-site. Strong reporting and tracking tools. Cons:
Some features are complex for beginners. Price may be prohibitive for small-scale contractors. 10. Procore Construction Management
Short Description: Procore offers an all-in-one construction project management solution, streamlining communication, documentation, and workflows across all project stakeholders. It’s ideal for large construction firms and multi-phase projects.
Key Features:
Seamless project management capabilities. Real-time collaboration between project stakeholders. Task tracking, budgeting, and reporting. Integration with various tools like Microsoft Project. Cloud-based platform with mobile app access. Pros:
Comprehensive and robust software. Great for large construction projects and companies. Customizable to suit different project needs. Cons:
High cost for smaller contractors. Can be overwhelming for new users. Comparison Table
Tool NameBest ForPlatform(s) SupportedStandout FeaturePricingG2 RatingTrustpilot RatingProcoreLarge construction firmsWeb, iOS, AndroidComprehensive project managementCustom Pricing4.5/54.6/5BuildertrendHomebuilders, RemodelersWeb, iOS, AndroidClient communication toolsStarts at $99/mo4.4/54.3/5CoConstructCustom homebuilders, RemodelersWeb, iOS, AndroidBudgeting and cost trackingStarts at $99/mo4.5/54.4/5PlanGridField teamsWeb, iOS, AndroidReal-time blueprint sharingCustom Pricing4.6/54.7/5SmartsheetAll sizes of construction firmsWeb, iOS, AndroidGantt chart schedulingStarts at $7/mo4.3/54.2/5e-BuilderLarge enterprisesWeb, iOS, AndroidAdvanced analyticsCustom Pricing4.4/54.3/5Jobsite UniteSmall contractorsWeb, iOS, AndroidTask and scheduling toolsStarts at $49/mo4.2/54.1/5FieldwireField teams, subcontractorsWeb, iOS, AndroidPlan markup & task tracking
starts at ~$39/user/month4.6/54.6/5BuildertrendContractors & ClientsWeb, iOS, AndroidTime tracking & reportingStarts at $99/mo4.4/54.5/5ProcoreLarge-scale construction firmsWeb, iOS, AndroidAll-in-one project managementCustom Pricing4.6/54.7/5 Which Construction Management Software Tool is Right for You?
For Large Construction Firms: Procore, e-Builder, and Aconex are ideal due to their comprehensive features and scalability. For Small to Medium Contractors: Buildertrend and CoConstruct are perfect for their ease of use and excellent client communication tools. For Field Workers: PlanGrid offers robust mobile tools for real-time collaboration and blueprint sharing. For Budget and Cost Management: CoConstruct and Buildertrend provide powerful budgeting and financial tracking capabilities. Conclusion
As the construction industry grows and becomes more technology-driven, choosing the right construction management software tool is crucial for streamlining operations, improving collaboration, and ensuring timely project completion. In 2026, these top 10 software tools offer a variety of features tailored to the specific needs of contractors, builders, and project managers. Whether you’re working on a large-scale infrastructure project or a small residential build, the right tool can enhance your workflow and save you time and money.
We encourage you to explore demos or free trials of these tools to find the best fit for your business.
FAQs
Q1: What is construction management software?
A1: Construction management software helps manage and streamline construction projects by overseeing budgets, scheduling, document management, and team communication.
Q2: Which construction management software is best for small contractors?
A2: Buildertrend and Jobsite Unite are excellent options for small contractors due to their affordability and user-friendly features.
Q3: Is Procore suitable for small businesses?
A3: Procore is better suited for large businesses due to its robust features and pricing. Small businesses may find it expensive.
Q4: Can construction management software be used on mobile?
A4: Yes, most modern construction management software tools offer mobile apps for real-time updates, task management, and communication.
Q5: How much does construction management software cost?
A5: Pricing varies depending on the tool, with some offering subscription-based pricing starting at $49 per month, while others have custom pricing for larger enterprises.
View the full article
The threat actor seeding the Open VSX code marketplace with fraudulent extensions that download the GlassWorm malware has uploaded 73 more impersonated links, as its attempt to infect software supply chains continues.
Philipp Burckhardt, head of threat intelligence at Socket, which revealed the latest activity, called it a “significant escalation” in the gang’s activity, after it added 72 malicious extensions last month.
The extensions impersonate trusted developer tools. More recently, the listed extensions contain benign code so they will evade malware scanners. Later, after connecting automatically to newly-created GitHub or other public accounts, they download GlassWorm to developers’ computers as an update. This latest wave includes some extensions that rely on bundled native binaries.
“The extension itself acts as a thin loader,” Socket explained in its report. “By shifting critical logic outside of what tools typically scan, and spreading it across multiple delivery mechanisms, the threat actor increases the likelihood of evading detection.”
Of the 73 new extensions seen by Socket, last week, six were activated to connect to sources of malware. This week, eight more were activated, Burckhardt said in an interview.
Socket has notified the Eclipse Foundation, which oversees the Open VSX marketplace, of the latest fraudulent additions, and Burckhardt expects that by now all 73 have been deleted.
But the continuing attacks are another example of how threat actors are trying to use open code marketplaces used by developers, such as Open VSX and npm, to compromise applications as they are being created, to enable the later distribution of data stealing malware.
[Related content: GlassWorm malware spreads via dependency abuse]
Extensions are add-on modules that help developers speed application creation. Since Microsoft’s Visual Studio Code is one of the most common code editors around the world, VS Code extensions are a tempting target for threat actors. Popular extensions include utilities that do everything from analyzing JavaScript, TypeScript, and other supported languages for potential errors, to AI tools that suggest code completions. The Eclipse Foundation says the Open VSX registry hosts over 12,000 extensions from more than 8,000 publishers.
A systemic gap in dev environment security
GlassWorm, despite its name, isn’t a worm, but a loader. According to StepSecurity, GlassWorm’s stage 3 payload includes a dedicated credential theft module that harvests GitHub and npm tokens from multiple sources. The attacker then uses these credentials to force-push malware into all of the victim’s repositories.
The loader includes host gating that detects and negates the dropping of malware on Russian language computers, leaving Burckhardt to suspect that the threat actors behind this campaign are Russian.
Tanya Janca, who teaches secure coding through her firm, SheHacksPurple, observed, “what makes the GlassWorm campaign particularly dangerous and interesting is that it exposes a systemic gap in how we secure developer environments.”
“With software packages, we have lockfiles, pinned hashes, and reproducible builds. With IDE [integrated development environment] extensions, we have almost nothing. There is no integrity verification, no equivalent of package-lock.json, and most organizations have no policy whatsoever governing what developers are allowed to install into their IDEs.”
 Malicious actors have noticed the gap. For them, targeting VS Code extensions is a lower-friction attack surface than targeting packages, she said, specifically because the controls that organizations have spent years building around their dependency pipelines simply do not exist for extensions.
The reason only some of the 73 extensions had been activated before the warning spread is certainly deliberate, Janca added. “This looks like an intentionally staged deployment: publish them all broadly to establish credibility and accumulate downloads, then activate harmful subsets over time to avoid triggering mass detection and to preserve a reserve of ready assets if some are removed or noticed.
Advice for developers
Janca said developers who want to reduce their exposure to the GlassWorm campaign should start with the basics: install fewer extensions and treat each one as a dependency with real risk attached. Disable auto-update so you control when updates are applied, and carefully evaluate each one. Use a next-generation SCA tool that covers IDE extensions and other areas of the supply chain, not just third party packages and components.
“One thing most people overlook,” she added: “Audit what you already have installed. Extensions accumulate over the years and the developer who built that extension in 2022 may not be the same person maintaining it today.”
Teams that want stronger guarantees should use a behavioral monitoring tool that watches runtime activity, Janca said, not just install-time content. Establish a formal approval process for new extensions, with security sign-off. Maintain an allowlist of approved extensions, and do not install from alternative marketplaces like Open VSX without treating it as a higher-risk source.
“The same discipline we apply to open source packages needs to be applied to the tools living inside our IDEs and the rest of our software supply chain,” she said.
Train developers to recognize signs
Burckhardt said CSOs need to ensure developers are trained to recognize phony extensions, carefully examining the names of files they are looking for to avoid being fooled by typosquatting, and verifying a publisher is legitimate. Some GlassWorm-related extensions have more downloads than a legitimate extension, he noted, a suspicious sign.
Developers should also be restricted in what they can download, he added, particularly extensions newly added to a repository. It may also be necessary to disable the ability to automatically download extension updates, he said, and developers should be warned to only download extensions they need, not ones to experiment with.
CSOs should also look for security tools that give visibility into what developers download, Burckhardt added.
And to help detect Open VSX issues, earlier this month the Eclipse Foundation announced the Open VSX Security Researcher Recognition Program to encourage responsible vulnerability disclosure.

View the full article
Several major U.S. cities support the Apple Pay for transit feature that Apple has rolled out, providing a simple way for those who use public transportation to pay for rides.


‌Apple Pay‌ for transit works in Atlanta, the Bay Area, Boston, Chicago, Los Angeles, New York, Orange County, Philadelphia, Portland, San Diego, Seattle, and Washington, DC.

Some of these cities have supported ‌Apple Pay‌ for transit purposes for several years, and in others like Atlanta, support is new as of 2026. Atlanta launched its tap-to-pay MARTA contactless system in March 2026, allowing iPhone and Apple Watch users to tap to pay their fares at rail station fare gates using the Apple Wallet app.

Cities that support ‌Apple Pay‌ for transit allow iPhone owners to turn on Express Mode to pay for transit fares without needing to unlock their device and authenticate with Face ID or Touch ID. A card for Express Transit can be selected by opening up the Wallet and ‌Apple Pay‌ section of the Settings app and tapping on the Express Transit Card option to make a selection.

When a credit or debit card is associated with Express Mode, it can be used to pay for transit automatically with no authentication. On iPhone models that support power reserve, transit payments can also be made when the iPhone is out of battery. Power reserve works for up to five hours after an iPhone dies, and it is available on the iPhone XS and later.

Some cities support adding a credit or debit card to the Wallet app for transit, while others require a specific transit card to be added to the Wallet app. The Bay Area works with the Clipper app or a credit card. Chicago's system only works with the Ventra card, LA's transit works with the TAP card, and Portland's transit system works with the Hop card.

In some locations, there's also support for fare capping. With New York's OMNY system, for example, subway and local bus fares are capped at $35 per week. As long as you use the same device each time you tap pay for a ride, rides after the $35 cap will be free for the rest of the seven-day period. LA's TAP system and OC's Wave system also support fare capping for ‌Apple Pay‌.

The iPhone 6s and 2016 iPhone SE and later all support Express Mode with ‌Apple Pay‌ for transit purposes. Express Mode also works on the Apple Watch Series 1 or later as long as watchOS 5.2.1 or later is installed.

‌Apple Pay‌ for transit also works in several cities around the world, including London, Paris, Hong Kong, Tokyo, Toronto, Beijing, and Shanghai.

When traveling, you will need to look into how transit works in the city you're in, but it is a simple way to use public transportation because there's no need to pre-purchase travel tickets at a kiosk. Apple has a website where the different transit systems are explained.Related Roundup: Apple PayTags: Apple Wallet, Express TransitRelated Forum: Apple Music, Apple Pay/Card, iCloud, Fitness+
This article, "Apple Pay for Transit Now Works in These 12 U.S. Cities" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Anthropic today updated Claude with new connectors aimed at creative professionals, adding integrations for Ableton, Adobe, Affinity, Autodesk Fusion, Blender, Resolume Arena and Wire, SketchUp, and Splice.


Connectors are tools that Claude can use to access other platforms and help with completing tasks. Anthropic says that Claude can open up new ways for creatives to work and take on larger-scale projects.

Ableton - Allows users to ask questions about the official product documentation for Live and Push.
Adobe - More than 50 tools across Creative Cloud apps like Photoshop, Premiere, and Express are available.
Affinity - The Affinity connector lets users automate repetitive production tasks and generate custom features.
Autodesk Fusion - Fusion subscribers can create and modify 3D models through conversations with Claude.
Blender - The Blender connector adds a natural-language interface for the Python API. Users can analyze and debug Blender scenes, build custom scripts to batch-apply changes to objects, and add new tools to the Blender interface. Blender's documentation is also available.
Resolume Arena and Wire - Visual artists can control Arena, Avenue, and Wire in real time with natural language.
SketchUp - Users can describe an idea to Claude as a starting point for a 3D model and then open it in SketchUp for further revision.
Splice - Music producers can search Splice's catalog of royalty-free samples.

Anthropic suggests that Claude can be helpful for multiple creative tasks, offering tutoring for complex tools, writing scripts and plugins for software, translating formats and restructuring data, and completing repetitive production work.Tag: Anthropic
This article, "Claude Gains Integrations With Adobe, Blender, SketchUp and Other Creative Apps" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
YouTube is testing a new search feature that it says is meant to feel more like a conversation than a search interface. Users are able to ask complex questions in natural language, receive results that include video and text, and then ask follow-up questions.


The new search option is part of YouTube Labs, an opt-in program that lets YouTube Premium subscribers gain early access to experimental features and prototypes. YouTube Labs is available to U.S. users, and subscribers sign up on the YouTube Labs website.


According to YouTube, subscribers who opt in to try the new search can enter a prompt in the search bar, like "plan a 3-day road trip between San Francisco and Santa Barbara," and then select the Ask YouTube option to get the results. Search results include AI summary text, short videos, and long videos, with relevant segments in videos highlighted.

The Ask YouTube search interface suggests some search prompts, such as "unique ideas for a backyard water feature," "plan a living room redesign using thrifted items," and "how to make a traditional French omelet."


Other YouTube Labs features in testing right now include Beyond the Beat AI details when listening to radio and mixes in the YouTube Music app, and VibeCheck, an AI coaching feature that provides tips on Shorts videos before they're published.

The updated search feature will be in testing until June 8.
This article, "YouTube Tests AI-Powered 'Ask YouTube' Conversational Search Feature" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Apple will add new Apple Intelligence photo editing tools to the Photos app in iOS 27, iPadOS 27, and macOS 27, reports Bloomberg.


On-device ‌Apple Intelligence‌ will be able to make subtle changes to image quality, positioning, and focus, with the new capabilities joining Clean Up, the sole AI editing feature that Apple has released to date.

The ‌Photos‌ app in ‌iOS 27‌, iPadOS 27, and ‌macOS 27‌ will have an ‌Apple Intelligence‌ Tools section when editing an image. Options will include Extend, Enhance, and Reframe.

Extend - Extend generates additional image content beyond the original frame of the photo, filling in scenery when changing the crop of an image. This tool will support expanding the edges of an image with zoom gestures.
Enhance - Uses AI to automatically tweak color, lighting, and other image parameters, similar to how the auto editing feature works now.
Reframe - When used with spatial photos, Reframe will let users change the perspective of an image after it's captured.

Apple apparently hasn't gotten the tools working perfectly, so Extend and Reframe could be delayed or scaled back. Clean Up, Apple's existing AI tool, still has issues even a year and a half after launching. It is able to remove unwanted objects from an image, but it is not as good at filling in missing information as other AI tools from smartphone makers like Samsung and Google.

More on the features coming in ‌iOS 27‌, including Siri updates, can be found in our iOS 27 roundup. ‌iOS 27‌ will be previewed at the WWDC 2026 keynote that's set to take place on June 8, 2026.Related Roundup: iOS 27Tag: Apple Intelligence
This article, "iOS 27 to Add New Apple Intelligence Photo Editing Tools" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
If you've noticed the Apple Weather app isn't loading weather data right now, you're not alone. The app appears to be experiencing an outage.


According to Apple's System Status page, the Weather app may be slow or unavailable for some users. The problem started at 11:36 a.m. Eastern Time and is ongoing.

Reports on social media suggest that the Weather app is slow to load for some, and is not loading data for others. We'll update this article when the issue has been resolved.
This article, "Apple Weather App Experiencing Outage" first appeared on MacRumors.com

Discuss this article in our forums

View the full article

Account

Navigation

Search

Search

Configure browser push notifications

Chrome (Android)
  1. Tap the lock icon next to the address bar.
  2. Tap Permissions → Notifications.
  3. Adjust your preference.
Chrome (Desktop)
  1. Click the padlock icon in the address bar.
  2. Select Site settings.
  3. Find Notifications and adjust your preference.