Skip to content
View in the app

A better way to browse. Learn more.

hosang I.T.

A full-screen app on your home screen with push notifications, badges and more.

To install this app on iOS and iPadOS
  1. Tap the Share icon in Safari
  2. Scroll the menu and tap Add to Home Screen.
  3. Tap Add in the top-right corner.
To install this app on Android
  1. Tap the 3-dot menu (⋮) in the top-right corner of the browser.
  2. Tap Add to Home screen or Install app.
  3. Confirm by tapping Install.

Tech

Tech Articles from a wide variety of topics and categories
Apple CEO Tim Cook met with United States Secretary of Commerce Howard Lutnick on Monday. The U.S. Department of Commerce shared details on the meeting on social media, and said that Lutnick wished Cook well, commending his "remarkable leadership and lasting contributions to American technology."


Last week, Apple announced that Cook would be stepping down from his role as CEO on September 1, 2026, with current hardware engineering chief John Ternus set to take over. Cook's visit with Lutnick was his first high-level Trump administration meeting since last week's transition news.

Cook does not plan to leave Apple, and will instead transition to executive chairman, where he will "assist with certain aspects of the company, including engaging with policymakers around the world."

In a letter to employees, Cook said that he is healthy and that he plans to be at Apple "for a long time" in his new role. "Apple will be my top priority," he said. "It's who I am at my core, and I can't imagine it any other way."

Cook told employees that he believes he can help strengthen Apple's global relationships. Cook has navigated two Trump presidencies so far, maintaining a positive relationship with the Trump administration and earning tariff exemptions for Apple.

Cook personally donated $1 million to Trump's inaugural fund in 2025, and he presented Trump with a custom gift featuring a glass plaque with a 24-karat gold base after promising Apple would invest a total of $600 billion in the U.S. over a four-year period.

Trump last week said that he has "always been a big fan" of Cook, and that the two had a "long and very nice relationship." Trump said he was pleased with Cook's outreach efforts. "I was very impressed with myself to have the head of Apple calling to 'kiss my ass,'" said Trump. According to Trump, he solved a "fairly large problem" for Cook during his first term, and he said he would help Cook where possible when Cook is not "too aggressive" in what he asks for.

Ahead of announcing his transition to a new role, Cook said in an early April interview that the Trump administration was "very accessible," and willing to "engage." Cook explained that he felt engagement and communication were important values, giving some insight into how he is approaching his new position.

With Cook taking on communication with policymakers around the world, incoming CEO John Ternus will be able to spend more time focusing on Apple's growth, and he won't be exposed to the same criticism that Cook has faced for his relationship with Trump and other world leaders.

Cook is still in Washington and he attended today's State Arrival Ceremony for King Charles III and Queen Camilla, who began their four-day state visit on Monday. Cook may also attend the State Dinner this evening.Tag: Tim Cook
This article, "Tim Cook Meets With Commerce Secretary Howard Lutnick Ahead of CEO Transition" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Apple last month announced a new MacBook Air, introducing the M5 chip, faster wireless connectivity, double the base storage, and a more capable charger, while simultaneously discontinuing the M4 model. So how does the new machine compare?


The M5 MacBook Air starts at $1,099 for the 13-inch model and $1,299 for the 15-inch, a $100 increase over the equivalent M4 models. In exchange, base storage doubles from 256GB to 512GB, and Apple says the new SSD delivers twice the read and write speeds of the previous generation. Education pricing is also available directly from Apple and typically shaves at least $100 off the price.

The main upgrade between the two models is the chip. Compared to the M4, the M5 delivers:


Up to 15% faster multithreaded CPU performance
Up to 30% faster overall graphics performance
Up to 45% faster ray tracing performance
27.5% higher unified memory bandwidth


In addition to these general performance claims, Apple published a set of specific real-world workload results showing measurable gains in AI-driven applications:


4×+ peak GPU compute performance for AI
3.6× faster time to first token (LLM)
1.8× faster Topaz Video Enhance AI processing
1.7× faster Blender ray-traced rendering
2.9× faster AI speech enhancement in Premiere Pro


Beyond raw performance, the M5 introduces several meaningful architectural changes. The GPU includes a dedicated Neural Accelerator in every core, a hardware addition absent from the M4, and Apple is exposing this via new Metal 4 developer APIs with Tensor capabilities.

The ray tracing engine advances to its third generation, and dynamic caching moves to its second generation. Memory bandwidth rises from 120 GB/s to 153 GB/s, enabled by the move from TSMC's second-generation 3nm process (N3E) to its third-generation ‌3nm‌ process (N3P).

The M5 ‌MacBook Air‌ also gains Apple's N1 wireless chip, bringing Wi-Fi 7 and Bluetooth 6 in place of the M4 model's Wi-Fi 6E and Bluetooth 5.3.



‌MacBook Air‌ (2025)
‌MacBook Air‌ (2026)


Apple M4 chip
Apple M5 chip


Based on A18 chip from 2024's iPhone 16
Based on A19 Pro chip from 2025's iPhone 17 Pro


4 performance + 6 efficiency cores
4 super cores + 6 efficiency cores


Made with TSMC's second-generation ‌3nm‌ node (N3E)
Made with TSMC's third-generation ‌3nm‌ node (N3P)


No integrated Neural Accelerators
Integrated Neural Accelerator in every GPU core


Metal 3 developer APIs
Metal 4 developer APIs with Tensor APIs to program GPU Neural Accelerators


Second-generation ray tracing engine
Third-generation ray tracing engine


First-generation dynamic caching
Second-generation dynamic caching


Shader cores
Enhanced shader cores


120 GB/s memory bandwidth
153 GB/s memory bandwidth



Apple N1 chip


Wi-Fi 6E
Wi-Fi 7


Bluetooth 5.3
Bluetooth 6 (Apple N1 chip)


Support for up to two external displays when the lid is open
Support for up to two external displays simultaneously over a single Thunderbolt port; one display up to 8K at 60Hz or 5K at 120Hz


30W USB-C Power Adapter
40W Dynamic Power Adapter with 60W Max


256GB base storage, up to 2TB
512GB base storage, up to 4TB


Introduced in March 2025
Introduced in March 2026


Started at $999 (13-inch), $1,199 (15-inch)
Starts at $1,099 (13-inch), $1,299 (15-inch)




For users whose workloads include on-device AI inference, complex 3D rendering, or other GPU-bound and memory-intensive tasks, the jump from M4 to M5 is significant. The combination of per-core Neural Accelerators, higher memory bandwidth, and the new GPU architecture produces multi-fold speed-ups in specific AI operations. In environments where time-to-result directly affects workflow such as local LLMs, diffusion models, video enhancement, or ray-traced production, the M5 represents a meaningful step-change.

For typical day-to-day usage including browsing, office work, media playback, and basic editing, the difference is highly unlikely to be perceptible in any way. The M4 was already a high-performance chip that routinely exceeded the demands of normal Mac workloads, and for the overwhelming majority of M4 ‌MacBook Air‌ owners, there is clearly no general-purpose reason to upgrade.

For new buyers choosing between the two models, the M5 is the more straightforward long-term choice. The doubled base storage alone changes the value calculus, and when you consider that Apple previously charged $200 to upgrade the M4 Air from 256GB to 512GB, the M5 effectively costs $100 less than a comparably configured M4 model would have at launch. If future-proofing is a priority and you intend to keep the machine for many years, the M5 model will be better equipped to handle increasingly prevalent on-device AI workloads as they mature. Related Roundup: MacBook AirBuyer's Guide: MacBook Air (Buy Now)Related Forum: MacBook Air
This article, "M4 vs. M5 MacBook Air Buyer's Guide" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Apple's Vision Pro has hit another medical-use milestone, with a New York ophthalmologist becoming the first surgeon to perform cataract surgery using the spatial computing headset.


Dr. Eric Rosenberg of SightMD completed the initial procedure in October 2025 and has since performed hundreds of additional cases using ScopeXR, a surgical platform he co-developed for Apple's mixed reality device.

ScopeXR streams live feeds from 3D digital surgical microscopes directly into the Vision Pro, which lets the surgeon view the operative field in stereoscopic 3D while overlaying preoperative diagnostic data. The platform also supports real-time remote collaboration, allowing surgeons to virtually join procedures and see exactly what the operating surgeon sees.
It's another example of Apple's move toward enterprise and professional use cases for Vision Pro, with widespread consumer adoption beleaguered by the headset's $3,499 starting price and bulky form factor. Apple has increasingly leaned into specialized applications in fields like medicine, aviation training, and industrial design - markets where the device's capabilities can justify its cost, in other words.

The headset was never expected to be mass-market from day one, according to Apple. Even so, enthusiasm is said to have cooled far faster than anticipated. Based on the latest reports, there are now no Apple Vision headsets in active development, with the company's focus pivoting to lightweight smart glasses, where Meta has already seen success. Last October, Apple introduced an updated Vision Pro model featuring the M5 chip, the first hardware revision of the device.Related Roundup: Apple Vision ProBuyer's Guide: Vision Pro (Buy Now)Related Forum: Apple Vision Pro
This article, "Apple Vision Pro Used in World-First Cataract Surgery" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Apple today announced that its hit comedy-drama series "Ted Lasso" is returning for a fourth season with a first episode on Wednesday, August 5. One new episode will follow every Wednesday thereafter through October 7.


"Ted Lasso" is one of the most popular shows ever released on the Apple TV streaming service. The eponymous character Ted Lasso, played by Jason Sudeikis, starts off as a small-time football coach from Kansas who is hired to coach a professional soccer team in England, despite having no experience coaching soccer.

In the fourth season, Apple says Lasso returns to England to take on his biggest challenge yet: coaching a second division women's soccer team.

"Throughout the course of the season, Ted and the team learn to leap before they look, taking chances they never thought they would," said Apple.

Apple has shared a teaser trailer for the new season.


Fan favorites such as Hannah Waddingham, Juno Temple, Brett Goldstein, Brendan Hunt, and Jeremy Swift are all set to return in the fourth season.

The third season of "Ted Lasso" was released in 2023, so there has been a long wait for a fourth season. The series has won several major awards since it debuted in 2020, with its overall positive tone making it a popular comfort show.Tags: Apple TV Service, Apple TV Shows
This article, "Apple Shares 'Ted Lasso' Season Four Streaming Date and Teaser Trailer" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Amazon today has the AirPods Pro 3 available for $199.99, down from $249.00. This is a match of the all-time low price on the AirPods Pro 3, and it's accompanied by a solid deal on the AirPods 4.

Note: MacRumors is an affiliate partner with some of these vendors. When you click a link and make a purchase, we may receive a small payment, which helps us keep the site running.

This model of the AirPods Pro launched in September 2025 and has 2x better Active Noise Cancellation than the previous generation, better audio quality, a revised fit that's meant to improve comfort and stability, Live Translation for in-person conversations, and heart rate sensing for workouts.

$49 OFFAirPods Pro 3 for $199.99

You can also get the AirPods 4 for $99.00, down from $129.00. This is a second-best price on the AirPods 4, which is the base model without Active Noise Cancellation. Amazon provides a May 4 estimated delivery date for free shipping, with faster delivery options for Prime members.

$30 OFFAirPods 4 for $99.00

Head to our full Deals Roundup to get caught up with all of the latest deals and discounts that we've been tracking over the past week.



Deals Newsletter

Interested in hearing more about the best deals you can find in 2026? Sign up for our Deals Newsletter and we'll keep you updated so you don't miss the biggest deals of the season!




Related Roundup: Apple Deals
This article, "AirPods Pro 3 Return to $199.99 Low Price on Amazon" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Security researchers have disclosed a high-severity vulnerability affecting the Cursor IDE, allowing arbitrary code execution on a developer’s machine through a seemingly routine repository interaction.
According to findings by AI pentesting platform Novee Security, once a developer cloned and interacted with a malicious repository, the IDE’s AI agent could trigger embedded Git logic, resulting in attacker-controlled code execution.
“The root cause is not a flaw in Cursor’s core product logic, but rather a consequence of a feature interaction in Git, one that becomes exploitable the moment an AI agent starts autonomously executing Git operations inside a repository it doesn’t control,” said Assaf Levkovich, a vulnerability researcher at Novee, in a blog post shared with CSO ahead of its publication on Tuesday.
The flaw could be used to enable the AI agent (through prompt injection) to write to improperly protected Git configurations, which could allow out-of-sandbox RCE on the next trigger. It is now patched by Cursor, with no indication of any in-the-wild exploitation as yet.
Using a legit Git feature for code execution
The exploit depends on standard Git features, including Git hooks and Bare repositories. Hooks are scripts that run automatically during events like pre-commits or post-checkouts, while bare repositories are repositories that contain only version control metadata and can be nested within other repositories.
According to Novee, an attacker could embed a malicious bare repository inside an otherwise legitimate project and plant a harmful pre-commit hook within it. When Cursor’s AI agent performs a routine operation, like a git checkout triggered by a high-level prompt, it could execute that hook. This would result in automatic execution of remote attacker code on the developer’s machine.
Levkovich noted that the underlying Git behavior allowing the attack path is well documented, but what’s different here is Cursor autonomously deciding to execute Git operations (running hooks) that ultimately result in code execution.
The flaw is tracked as CVE-2026-26268, with a critical severity rating of 9.9 out of 10 assigned by NVD, and affects Cursor versions prior to 2.5. “Sandbox escape via writing .git configuration was possible in versions prior to 2.5,” reads an NVD description of the flaw. “A malicious agent (i.e. prompt injection) could write to improperly protected .git settings, including git hooks, which may cause out-of-sandbox RCE next time they are triggered.”
Expanded attack surface with agentic IDEs
Novee warned that while traditional IDEs are passive, doing what developers explicitly tell them to do, Cursor’s AI agent interprets intent and autonomously decides which commands to run, which includes Git operations. And that’s where the problem lies.
“In traditional pentesting, ‘client-side’ attacks targeting developer machines have always been a known vector,” Levkovich noted. “But they relied on user error or a lapse in vigilance, typically requiring a degree of deliberate action on the part of the victim: opening a malicious file, executing a script, clicking a link.”
Security has long relied on trusted IDEs and human action as safeguards, but AI agents remove both constraints, he added.
As the attack path does not need phishing or tricking the user into running scripts beyond cloning the bare repository, and malicious code executes as part of the normal development workflow, it is quite difficult to detect.
Still, Cursor contested NVD’s critical rating of the flaw and instead issued its own high-severity CVSS score of 8.0 out of 10. The flaw is patched in Cursor version 2.5.
View the full article
Apple's 20th-anniversary iPhone will use a new type of curved screen technology that more effectively hides the display bezels from the user's line of sight for a purer viewing experience, claims a Chinese leaker.


Apple is reportedly planning a radical redesign for the 20th-anniversary iPhone that could feature a display that curves around all four edges of the device. To achieve this, Apple will reportedly use an equal-depth quad-curved panel supplied by Samsung, and it sounds like it's going to be quite different from typical curved screens.

According to leaker Ice Universe, "It is not a traditional quad curved display, nor is it anything like the curved screen solutions we have seen on Android phones over the years." This is said to be down to its extremely subtle curvature, but there are apparently other factors that could come into play.
Apple will also reportedly adopt a Samsung-made OLED technology called COE (Color Filter on Encapsulation) to make the 20th-anniversary iPhone's display brighter and thinner than previous panels. Apple may refer to it as a "Liquid Glass Display," in a nod to its latest software interface redesign, claims the leaker.


To mark the 20th-anniversary of the iPhone in 2027, Apple ideally wants an uninterrupted display with no cutouts for the most visual impact, but concealing the Face ID system and selfie camera under the panel is going to be a challenge.

Display analyst Ross Young has said that Apple won't have under-display ‌Face ID‌ ready to go for a 2027 iPhone, but other leakers think it's possible. If Apple can't get everything under the display, we may see under-display ‌Face ID‌ and then a small hole-punch cutout on the front for the front-facing camera.Tags: 20th-Anniversary iPhone, Ice Universe
This article, "20th Anniversary iPhone's 'Liquid Glass' Display to Make Bezels Vanish" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
In the enterprise SaaS space, AI agents are becoming an integral part of the SaaS product. To make these intelligent agents truly useful, they need contextual, customer-specific knowledge, something standard Large Language Models (LLMs), open source or otherwise, inherently lack since they are not trained on customer proprietary data.
Retrieval-Augmented Generation (RAG) is the bridge that grants AI agents real-time access to a company’s most sensitive data: Internal wikis, CRM records, code repositories, task tracking system and intellectual property. However, this bridge introduces significant security liabilities. The cost of getting RAG security wrong in a SaaS environment is catastrophic, ranging from cross-tenant data leaks and unauthorized PII exposure to malicious prompt injections.
Recent RAG-related security failures
Over the past year, several high-profile incidents have underscored the vulnerabilities of enterprise AI integrations:
Zero-Click data exfiltration (Late 2025): The “EchoLeak” vulnerability demonstrated how attackers could use a specially crafted, unclicked email to manipulate Microsoft 365 Copilot’s massive enterprise RAG pipeline. The AI was tricked into retrieving and exfiltrating sensitive corporate data without any employee interaction. Vector database exposures (2024 – 2025): Several incidents involved exposed API keys for vector databases. In one notable fintech breach, attackers used “reconstruction attacks” to reverse-engineer embeddings back into millions of original client investment portfolios. A similar access-control bypass in Pinecone exposed over 200,000 healthcare records. Indirect prompt injection in development environments (August 2025): Attackers implanted hidden, malicious text inside public GitHub README files. When developers used the Cursor IDE’s AI assistant to summarize these repositories, the AI unwittingly executed the hidden commands, granting attackers unauthorized access to developer machines. Knowledge base poisoning (March 2026): A massive operation flooded external knowledge bases with manipulated data. Because AI answering systems rely on RAG for up-to-date functionality, this “data irrigation” successfully poisoned the retrieval pipelines, forcing AIs to push false information and disguised ads to millions of users. To secure RAG pipelines effectively against these evolving threats, organizations must thoroughly understand their architecture, map the threat models and implement defense-in-depth strategies.
Deconstructing the enterprise RAG architecture
To secure a RAG system, you must first understand how data flows through it. A typical enterprise RAG pipeline operates in three distinct phases:
Ingestion & embedding (data layer): Raw enterprise data is pulled from sources like ERPs, CRMs and document repositories. This data is cleaned, chunked into smaller segments and passed through an embedding model that converts the text into high-dimensional numerical vectors. Storage & retrieval (vector layer): These vectors, along with metadata (e.g., source tags, access permissions), are stored in a specialized Vector Database (like Pinecone, Milvus or ElasticSearch). When a user asks a question, the system runs a similarity search to retrieve the most semantically relevant document chunks. Generation & orchestration (LLM layer): The retrieved enterprise data is combined with the user’s original query to create an augmented prompt. The LLM then uses this context to generate a highly accurate, grounded response. Here is a visual representation of the RAG architecture, overlaid with the primary threat vectors targeting each phase:
IMAGE GOES HERE
The threat model: How RAG pipelines are attacked
The integration of dynamic data retrieval fundamentally shifts the AI threat landscape. Frameworks like the OWASP Top 10 for LLM Applications highlight several critical vulnerabilities specific to RAG:
Prompt injection (Direct and indirect)
Prompt injection remains the most critical vulnerability in AI systems. While direct injection involves a user trying to jailbreak the chatbot, RAG introduces indirect prompt injection. Here, an attacker hides malicious instructions within an external document (e.g., a customer support ticket or an uploaded PDF). When the RAG system retrieves this poisoned document as context, the LLM unwittingly executes the hidden commands. This can lead to data exfiltration or the hijacking of the AI agent’s actions.
Knowledge base poisoning
Unlike prompt injection, which targets execution logic, data poisoning targets the integrity of the knowledge base. Attackers inject manipulated, biased or false information into the data sources feeding the ingestion pipeline. Because the LLM inherently trusts the retrieved context, it will confidently generate harmful or factually incorrect responses, destroying trust in the SaaS application.
Sensitive information disclosure and vector weaknesses
RAG pipelines frequently process Personally Identifiable Information (PII) and confidential business logic. If the pipeline lacks robust filtering, sensitive documents are vectorized without proper access boundaries. Furthermore, vectors are not inherently secure; sophisticated “embedding inversion” attacks can reverse-engineer vectors to reconstruct the original sensitive text.
Cross-tenant contamination
In multi-tenant SaaS environments, poor isolation can lead to cross-tenant contamination. A poorly architected retrieval system might inadvertently allow one customer to retrieve another customer’s proprietary data via a perfectly normal semantic search.
Prevention and detection
Securing a RAG pipeline requires a zero-trust posture across the entire data lifecycle. You cannot rely solely on the LLM to behave safely; security must be layered across ingestion, retrieval and generation.
Prevention strategies
Sanitize the ingestion pipeline (DLP): Prevention begins before data reaches the vector database. Implement Data Loss Prevention (DLP) controls to scan documents before they are chunked and embedded. Anonymize, redact or pseudonymize sensitive fields (like SSNs or API keys) so that a leak, if it occurs, yields useless data. Compliance & data privacy (The right to be forgotten): Enterprise SaaS is heavily bound by regulations like GDPR, CCPA and HIPAA. A massive, often-overlooked challenge in RAG pipelines is data deletion. In a traditional database, deleting a user record is a simple SQL query. In a Vector Database, if a user requests their data be deleted, you must ensure every fragmented, embedded vector chunk related to that user is also destroyed. Implement rigorous metadata tagging during ingestion so that specific customer data can be easily located and purged from the vector database to maintain full compliance. Vector database encryption: Treat your vector database as a highly sensitive asset. Ensure data is encrypted at rest and in transit. Retrieval-time access control (RBAC & ABAC): The most effective defense against data leakage is enforcing document-level permissions during the retrieval phase. When a similarity search is executed, the vector database must strictly honor the querying user’s access rights. If a user doesn’t have permission to view a document in the underlying CRM, the RAG system should not be able to retrieve it for them. Prompt isolation and input guardrails: Implement architectural guardrails that separate the system prompt from the retrieved context and the user input. Pre-process incoming queries to detect jailbreak attempts or known injection signatures before passing them to the LLM. Detection strategies
Output filtering: Do not implicitly trust the LLM’s output. Deploy output filters to evaluate the generated response for regurgitated PII, toxic content or anomalous behavior before delivering it to the user. Telemetry and semantic monitoring: Standard logging isn’t enough. Monitor for token usage spikes (which can indicate Denial of Wallet attacks) and track the hit/miss ratio of the retrieval component. Look for semantic anomalies, such as an AI agent consistently pulling documents that seem unrelated to the user’s role. Evaluate against data drift: Continuously evaluate the pipeline using frameworks like RAGAS to detect if the knowledge base has been poisoned or if the model’s accuracy is decaying over time. Operationalizing security with Google cloud tools
Implementing these defense-in-depth strategies requires robust tooling. For organizations building on Google Cloud, several native enterprise-grade services map directly to the RAG security lifecycle:
Data ingestion & sanitization: Google cloud sensitive data protection (formerly Cloud DLP) inspects, classifies and redacts sensitive PII and financial data from raw documents before they are ever chunked and sent to the embedding model. Vector storage & access control: Vertex AI vector search integrates directly with Google Cloud IAM, allowing developers to enforce strict, retrieval-time access controls and ensure strong tenant isolation within multi-tenant SaaS environments. Input/output guardrails: Vertex AI model armor serves as a dedicated security layer between the user and the LLM. It evaluates incoming prompts to block jailbreaks and indirect prompt injections and it filters outgoing responses to prevent sensitive data leaks and toxic content. Pipeline evaluation: Vertex AI evaluation continuously assesses the quality and safety of your RAG pipeline, tracking critical metrics like “groundedness” to ensure the AI’s responses are strictly based on the retrieved context and not hallucinated or poisoned data. Overall AI security posture: Security command center (SCC) enterprise integrates AI security posture management (AI-SPM) to automatically discover AI workloads across your environment, identify misconfigurations (such as exposed vector databases), and detect potential data exfiltration paths. Conclusion
As AI agents take on increasingly autonomous roles within Enterprise SaaS platforms, RAG pipelines serve as their vital connection to reality. However, the operational benefits of augmented intelligence come with profound security risks. Securing these pipelines demands a departure from legacy application security models.
By enforcing strict access controls at the point of retrieval, aggressively sanitizing inputs and outputs and maintaining continuous observability over AI operations, enterprise SaaS providers can confidently harness the power of AI while safeguarding their customers’ most valuable assets.
This article is published as part of the Foundry Expert Contributor Network.
Want to join?
View the full article
In the enterprise SaaS space, AI agents are becoming an integral part of the SaaS product. To make these intelligent agents truly useful, they need contextual, customer-specific knowledge, something standard Large Language Models (LLMs), open source or otherwise, inherently lack since they are not trained on customer proprietary data.
Retrieval-Augmented Generation (RAG) is the bridge that grants AI agents real-time access to a company’s most sensitive data: Internal wikis, CRM records, code repositories, task tracking system and intellectual property. However, this bridge introduces significant security liabilities. The cost of getting RAG security wrong in a SaaS environment is catastrophic, ranging from cross-tenant data leaks and unauthorized PII exposure to malicious prompt injections.
Recent RAG-related security failures
Over the past year, several high-profile incidents have underscored the vulnerabilities of enterprise AI integrations:
Zero-Click data exfiltration (Late 2025): The “EchoLeak” vulnerability demonstrated how attackers could use a specially crafted, unclicked email to manipulate Microsoft 365 Copilot’s massive enterprise RAG pipeline. The AI was tricked into retrieving and exfiltrating sensitive corporate data without any employee interaction. Vector database exposures (2024 – 2025): Several incidents involved exposed API keys for vector databases. In one notable fintech breach, attackers used “reconstruction attacks” to reverse-engineer embeddings back into millions of original client investment portfolios. A similar access-control bypass in Pinecone exposed over 200,000 healthcare records. Indirect prompt injection in development environments (August 2025): Attackers implanted hidden, malicious text inside public GitHub README files. When developers used the Cursor IDE’s AI assistant to summarize these repositories, the AI unwittingly executed the hidden commands, granting attackers unauthorized access to developer machines. Knowledge base poisoning (March 2026): A massive operation flooded external knowledge bases with manipulated data. Because AI answering systems rely on RAG for up-to-date functionality, this “data irrigation” successfully poisoned the retrieval pipelines, forcing AIs to push false information and disguised ads to millions of users. To secure RAG pipelines effectively against these evolving threats, organizations must thoroughly understand their architecture, map the threat models and implement defense-in-depth strategies.
Deconstructing the enterprise RAG architecture
To secure a RAG system, you must first understand how data flows through it. A typical enterprise RAG pipeline operates in three distinct phases:
Ingestion & embedding (data layer): Raw enterprise data is pulled from sources like ERPs, CRMs and document repositories. This data is cleaned, chunked into smaller segments and passed through an embedding model that converts the text into high-dimensional numerical vectors. Storage & retrieval (vector layer): These vectors, along with metadata (e.g., source tags, access permissions), are stored in a specialized Vector Database (like Pinecone, Milvus or ElasticSearch). When a user asks a question, the system runs a similarity search to retrieve the most semantically relevant document chunks. Generation & orchestration (LLM layer): The retrieved enterprise data is combined with the user’s original query to create an augmented prompt. The LLM then uses this context to generate a highly accurate, grounded response. Here is a visual representation of the RAG architecture, overlaid with the primary threat vectors targeting each phase:
Mayank Singhi
The threat model: How RAG pipelines are attacked
The integration of dynamic data retrieval fundamentally shifts the AI threat landscape. Frameworks like the OWASP Top 10 for LLM Applications highlight several critical vulnerabilities specific to RAG:
Prompt injection (Direct and indirect)
Prompt injection remains the most critical vulnerability in AI systems. While direct injection involves a user trying to jailbreak the chatbot, RAG introduces indirect prompt injection. Here, an attacker hides malicious instructions within an external document (e.g., a customer support ticket or an uploaded PDF). When the RAG system retrieves this poisoned document as context, the LLM unwittingly executes the hidden commands. This can lead to data exfiltration or the hijacking of the AI agent’s actions.
Knowledge base poisoning
Unlike prompt injection, which targets execution logic, data poisoning targets the integrity of the knowledge base. Attackers inject manipulated, biased or false information into the data sources feeding the ingestion pipeline. Because the LLM inherently trusts the retrieved context, it will confidently generate harmful or factually incorrect responses, destroying trust in the SaaS application.
Sensitive information disclosure and vector weaknesses
RAG pipelines frequently process Personally Identifiable Information (PII) and confidential business logic. If the pipeline lacks robust filtering, sensitive documents are vectorized without proper access boundaries. Furthermore, vectors are not inherently secure; sophisticated “embedding inversion” attacks can reverse-engineer vectors to reconstruct the original sensitive text.
Cross-tenant contamination
In multi-tenant SaaS environments, poor isolation can lead to cross-tenant contamination. A poorly architected retrieval system might inadvertently allow one customer to retrieve another customer’s proprietary data via a perfectly normal semantic search.
Prevention and detection
Securing a RAG pipeline requires a zero-trust posture across the entire data lifecycle. You cannot rely solely on the LLM to behave safely; security must be layered across ingestion, retrieval and generation.
Prevention strategies
Sanitize the ingestion pipeline (DLP): Prevention begins before data reaches the vector database. Implement Data Loss Prevention (DLP) controls to scan documents before they are chunked and embedded. Anonymize, redact or pseudonymize sensitive fields (like SSNs or API keys) so that a leak, if it occurs, yields useless data. Compliance & data privacy (The right to be forgotten): Enterprise SaaS is heavily bound by regulations like GDPR, CCPA and HIPAA. A massive, often-overlooked challenge in RAG pipelines is data deletion. In a traditional database, deleting a user record is a simple SQL query. In a Vector Database, if a user requests their data be deleted, you must ensure every fragmented, embedded vector chunk related to that user is also destroyed. Implement rigorous metadata tagging during ingestion so that specific customer data can be easily located and purged from the vector database to maintain full compliance. Vector database encryption: Treat your vector database as a highly sensitive asset. Ensure data is encrypted at rest and in transit. Retrieval-time access control (RBAC & ABAC): The most effective defense against data leakage is enforcing document-level permissions during the retrieval phase. When a similarity search is executed, the vector database must strictly honor the querying user’s access rights. If a user doesn’t have permission to view a document in the underlying CRM, the RAG system should not be able to retrieve it for them. Prompt isolation and input guardrails: Implement architectural guardrails that separate the system prompt from the retrieved context and the user input. Pre-process incoming queries to detect jailbreak attempts or known injection signatures before passing them to the LLM. Detection strategies
Output filtering: Do not implicitly trust the LLM’s output. Deploy output filters to evaluate the generated response for regurgitated PII, toxic content or anomalous behavior before delivering it to the user. Telemetry and semantic monitoring: Standard logging isn’t enough. Monitor for token usage spikes (which can indicate Denial of Wallet attacks) and track the hit/miss ratio of the retrieval component. Look for semantic anomalies, such as an AI agent consistently pulling documents that seem unrelated to the user’s role. Evaluate against data drift: Continuously evaluate the pipeline using frameworks like RAGAS to detect if the knowledge base has been poisoned or if the model’s accuracy is decaying over time. Operationalizing security with Google cloud tools
Implementing these defense-in-depth strategies requires robust tooling. For organizations building on Google Cloud, several native enterprise-grade services map directly to the RAG security lifecycle:
Data ingestion & sanitization: Google cloud sensitive data protection (formerly Cloud DLP) inspects, classifies and redacts sensitive PII and financial data from raw documents before they are ever chunked and sent to the embedding model. Vector storage & access control: Vertex AI vector search integrates directly with Google Cloud IAM, allowing developers to enforce strict, retrieval-time access controls and ensure strong tenant isolation within multi-tenant SaaS environments. Input/output guardrails: Vertex AI model armor serves as a dedicated security layer between the user and the LLM. It evaluates incoming prompts to block jailbreaks and indirect prompt injections and it filters outgoing responses to prevent sensitive data leaks and toxic content. Pipeline evaluation: Vertex AI evaluation continuously assesses the quality and safety of your RAG pipeline, tracking critical metrics like “groundedness” to ensure the AI’s responses are strictly based on the retrieved context and not hallucinated or poisoned data. Overall AI security posture: Security command center (SCC) enterprise integrates AI security posture management (AI-SPM) to automatically discover AI workloads across your environment, identify misconfigurations (such as exposed vector databases), and detect potential data exfiltration paths. Conclusion
As AI agents take on increasingly autonomous roles within Enterprise SaaS platforms, RAG pipelines serve as their vital connection to reality. However, the operational benefits of augmented intelligence come with profound security risks. Securing these pipelines demands a departure from legacy application security models.
By enforcing strict access controls at the point of retrieval, aggressively sanitizing inputs and outputs and maintaining continuous observability over AI operations, enterprise SaaS providers can confidently harness the power of AI while safeguarding their customers’ most valuable assets.
This article is published as part of the Foundry Expert Contributor Network.
Want to join?
View the full article
Identity has always been central to security, but the proliferation of AI agents is rapidly changing the challenge of managing and securing identity, spurring CISOs to rethink their identity strategies — even how it is defined.
“Identity is now both a control surface and an attack surface. We’ve had non-human identities as API keys, tokens, service accounts, but now we have agents, and that’s a new class,” says Dustin Wilcox, senior VP and CISO at S&P Global.
The challenge is attributing actions to non-human identities because the typical signals don’t apply. “The techniques to identify a person, like the telemetry of how they use the keyboard, we won’t be able to do that when it’s an agent that’s working entirely digitally,” Wilcox tells CSO.
And as agents proliferate, it becomes difficult for CISOs to maintain a complete picture of how many exist, what they’re used for, and what they’re authorized to do.
“With a human identity, you can validate access needs directly. With service accounts, and now with agents, that clarity is harder to achieve,” says Docusign CISO Michael Adams.
“Treating them as if they fit existing models can create gaps in visibility and control. At the same time, AI systems are contributing to rapid growth in non-human identities, including the creation of new credentials and tokens, which many inventory processes weren’t designed to track,” he adds.
“And on the human side, generative AI is making social engineering more convincing, eroding some of the behavioral signals defenders have historically relied on. The result is an expanding attack surface at the same moment traditional indicators are becoming less reliable,” Adams tells CSO.
The advice for CISOs is to adopt an identity-first security model that treats identity as the foundational layer of the security architecture.
“Every access decision flows through identity and is continuously verified, not just checked at the door,” says Adams.
Identity becomes the primary control plane
CISOs are now managing a new class of identities that includes copilots, autonomous agents, and AI-powered workflows that don’t fit neatly into existing frameworks. And they can access systems, take actions, and make decisions at machine speed.
Wilcox and Adams are speaking at the CSO Cybersecurity Awards & Conference, May 11–13. Reserve your place.
As a result, Adams says CISOs will increasingly need to adopt an identity-centric security architecture and there are several key tenets to consider.
Build a strong foundation before layering on complexity. The instinct when modernizing an identity program, says Adams, is to reach for sophisticated tooling. Instead, his advice is to get the fundamentals in place — clean directories, enforced least privilege, and reliable offboarding processes.
“Organizations that jump to continuous verification without establishing basic identity hygiene may find themselves building on an unstable foundation,” he says.
Design for the new class of identities. When designing role models and access policies, the temptation is to mirror existing structures.
“That often carries years of permission creep into a new architecture. Starting from least privilege rather than from legacy helps ensure users receive only the access required for their job functions,” he says. “It’s important to challenge ‘it’s always been done this way’ where appropriate.”
Get your non-human identity inventory in order. Build a full inventory of non-human identities and include who is responsible for each identity, and what each one is authorized to do. Do this before any more agents are operating.
“This is as much a governance challenge as a technology one,” he notes.
Treat MFA as a starting point, not a destination. The identity roadmap needs to include phishing-resistant alternatives to SMS or push-based MFA. Least privilege, micro-segmentation, and continuous monitoring are part of the playbook.
“Assume credentials may be compromised and architect accordingly,” Adams advises.
AI and the shifting security balance
Identity systems have long been targets for attack. But as identity becomes the primary control plane, the risk becomes more concentrated and requires a different approach.
“I’d encourage every CISO to think deeply about the intersection of identity and AI,” says Adams, adding that systems need to be redesigned around the principle of intent instead of actual behavior to ensure agents operate within appropriate boundaries.
“That requires behavioral monitoring and real-time access evaluation — capabilities many organizations are still building toward,” he notes. “That’s the work ahead.”
Wilcox is ultimately optimistic that AI offers security practitioners more tools to combat malicious actors. If CISOs can get this right, it’s a way to level the playing field with the attackers in a way not previously available.
“We’ve had this asymmetric playing field where they’ve had the advantage for as long as I can remember. Now we can use AI both strategically and tactically to improve our defenses,” he says.
Agentic AI is rewriting the identity security playbook in real-time, and your peers are already adapting. Hear Dustin Wilcox, Michael Adams, Renee Guttmann, and other leading CISOs share what’s actually working at the CSO Cybersecurity Awards & Conference, May 11–13. Secure your seat before it fills up.
View the full article
The security industry has spent years building better authentication. Longer passwords, second factors, hardware tokens. And attackers responded by moving past authentication entirely.
Adversary-in-the-middle (AiTM) phishing does not steal credentials and replay them. It sits between the user and the legitimate service, watches a real authentication succeed in real time, and walks away with the session token that proves it happened. The login was genuine. The MFA prompt was real. The attacker just observed — and copied the result.
If you have read the analysis of how these attacks work, you understand the mechanism. This piece is about what comes after that understanding. Specifically: What controls reduce risk when the attack does not touch credentials at all?
Why most current defenses miss the point
The instinct after learning about AiTM phishing is to strengthen authentication. Buy hardware keys. Deploy passkeys. Force phishing-resistant MFA for privileged accounts.
That instinct is correct but incomplete.
Phishing-resistant authentication stops the credential theft phase. FIDO2 and passkeys bind the authentication challenge cryptographically to the legitimate domain, so a proxy domain cannot complete the handshake. This works. Organizations that have deployed passkeys broadly have significantly reduced their AiTM exposure at the authentication layer.
But authentication is not the only layer that matters. Session tokens issued after successful authentication are the real target, and most organizations treat them as inherently trustworthy once issued. They are not.
A session cookie is a bearer token. Whoever holds it is authenticated. There is no cryptographic binding between the token and the device that generated it, no ongoing proof that the holder is who they claim to be, and no automatic expiry triggered by location change or device mismatch. An attacker who steals a session token in one country can replay it from another, and the identity provider will accept it as legitimate.
This is where most defenses currently have a gap.
The 3 controls that close the gap
Control #1: Bind sessions to managed devices
The most impactful single control for session security is requiring managed, compliant devices as a condition of accessing sensitive resources. When access policies —such as Microsoft Entra Conditional Access — require that the device presenting a session token is enrolled, managed and meets compliance requirements, stolen tokens become significantly harder to replay.
An attacker who intercepts a session token cannot easily replay it from an unmanaged machine if the policy requires device compliance. The session gets terminated. The attacker needs not just the token but also a compliant device — a much higher bar.
This control is not foolproof. Sophisticated attackers can attempt to compromise managed devices directly. But it eliminates the easiest replay vector: Taking a stolen token and opening it in a browser on a completely different machine.
The practical challenge is rollout. Requiring managed devices for all users immediately creates friction for contractors, part-time workers and anyone using personal devices for work. The pragmatic approach is to start with the highest-risk access: Administrative roles, finance systems and any application handling sensitive data. Expand from there as device management coverage improves.
Control #2: Monitor for post-authentication anomalies
AiTM attacks do not generate failed login attempts. They generate successful ones. Traditional monitoring focused on authentication failures will miss these attacks entirely.
The signals that matter are in what happens after authentication succeeds. Specifically:
Impossible travel. If a session authenticates from one location and then accesses resources from a geographically distant location minutes later, that warrants investigation. The time between events matters — a session that authenticates in New York and then accesses resources from a different continent thirty minutes later is not a normal user scenario. New device registration. Attackers who gain session access often immediately register a new MFA device or add a new authentication method to ensure persistent access. A new device registration occurring within minutes of a successful login is a high-fidelity signal worth alerting on. Inbox rule creation. A consistent post-compromise behavior across many attack campaigns is the creation of email forwarding rules or inbox filters designed to hide security alerts and forward communications to attacker-controlled addresses.Microsoft’s own incident response teams have documented this pattern repeatedly. Monitoring for inbox rule creation, particularly rules that forward externally or hide emails containing specific keywords, catches this behavior reliably. Privilege escalation attempts. Attackers who gain access to a standard user account typically attempt to escalate to higher-privilege roles or access administrative interfaces. Anomalous access attempts against admin portals or privilege management systems shortly after a new session authentication are worth flagging. None of these signals is conclusive on its own. But building detection rules around the combination — successful authentication followed by impossible travel followed by new device registration, for example — creates a detection capability that catches AiTM post-compromise activity that authentication monitoring misses entirely.
Control #3: Shorten session lifetimes for high-value access
Long-lived session tokens give attackers more time to operate after a successful interception. A token that remains valid for seven days provides a much larger window than one that expires after an hour and requires reauthentication.
The friction of more frequent reauthentication is real. Users notice. For productivity applications used continuously throughout the day, aggressive session timeouts create a poor experience.
The answer is risk-based session management rather than uniform policies. Sessions accessing low-sensitivity productivity tools can have longer lifetimes. Sessions accessing financial systems, administrative interfaces, HR data or anything handling regulated information should have short lifetimes and require reauthentication before performing sensitive operations.NIST’s Digital Identity Guidelines provide a useful framework for thinking about session timeout thresholds by assurance level.
This approach concentrates the friction where the risk is highest, which makes it more defensible to users and leadership alike.
The training problem has not gone away
Technical controls reduce risk. They do not eliminate it. Users remain part of the attack surface, and the awareness training most organizations provide does not prepare them for what AiTM phishing looks like.
Traditional phishing training teaches people to look for indicators of fake pages: Misspellings, suspicious URLs, unusual sender addresses. AiTM phishing pages show none of these indicators because they are not fake. They proxy the real service in real time. The URL may be suspicious, but users who click links in emails rarely check URLs carefully, even after training.
The one behavioral change that reduces AiTM exposure is simple and teachable: Do not start authentication flows from links in emails. Navigate directly to the service. Bookmark login pages. If you receive an email telling you to log in somewhere, open a browser tab and type the address yourself rather than clicking through.
This sounds obvious. It is not instinctive. Most users have spent years clicking login links in emails because it is faster and those links usually are legitimate. Changing that behavior requires explicit, repeated training that explains why the old approach is no longer safe — not just instruction to be more suspicious of phishing generally.
Pair this with a low-friction reporting mechanism. Users who notice something feels wrong should be able to flag it in seconds. The value of early reporting in limiting the damage from a successful session compromise is significant, and that value disappears if reporting requires effort or feels like it will generate blame rather than action.
The honest assessment
AiTM phishing is a real and growing threat.Phishing-as-a-Service platforms like Tycoon 2FA and FlowerStorm have lowered the barrier to entry to the point where this is no longer an advanced technique requiring sophisticated threat actors. It is a commodity attack available to anyone willing to pay a subscription.
The organizations that reduce their exposure are those that treat session security as seriously as credential security, build detection capability around post-authentication behavior rather than just failed logins, and give users a realistic model of how modern phishing works.
Phishing-resistant authentication is the right long-term direction. Getting there takes time, budget and change management. In the meantime, the controls above provide meaningful risk reduction without waiting for full passkey deployment.
The goal is not to make AiTM attacks impossible. It is to make them expensive enough that attackers move on to easier targets.
This article is published as part of the Foundry Expert Contributor Network.
Want to join?
View the full article
An administrative role meant for artificial intelligence (AI) agents within Microsoft Entra ID could enable privilege escalation and identity takeover attacks, according to new findings from Silverfort. Agent ID Administrator is a privileged built-in role introduced by Microsoft as part of its agent identity platform to handle all aspects of an AI agent's identity lifecycle operations in aView the full article
Microsoft on Monday revised its advisory for a now-patched, high-severity security flaw impacting Windows Shell to acknowledge that it has been actively exploited in the wild. The vulnerability in question is CVE-2026-32202 (CVSS score: 4.3), a spoofing vulnerability that could allow an attacker to access sensitive information. It was addressed as part of its Patch Tuesday update for thisView the full article
SvetaZi | shutterstock.com
Software im Bereich Endpoint Detection and Response (EDR) erfreut sich weiterhin steigender Beliebtheit – und wird mit zunehmender Reife immer effektiver. EDR-Lösungen bieten Realtime-Einblicke in die Endpunkt-Aktivitäten und ermöglichen es, Mobiltelefone, Workstations, Laptops, Server und andere Devices vor Cyberangriffen zu schützen.
In diesem Kaufratgeber erfahren Sie:
wie sich Endpoint Detection and Response definiert, welche Fähigkeiten EDR-Tools an Bord haben sollten, welche Anbieter und Lösung in Sachen Endpunkt-Sicherheit tonangebend sind, und welche konkreten Fragen vor einer Investition relevant sind. Endpoint Detection and Response erklärt
EDR-Tools erfassen Verhaltensdaten aus diversen Endpunkt-Quellen. Dazu gehören herkömmliche Computing Devices wie Windows- oder Mac-Rechner genauso wie Peripherie- und IoT-Geräte, beispielsweise Drucker oder Controller. Um IT-Profis auf verdächtige Aktivitäten oder laufende Cyberangriffe aufmerksam zu machen, analysieren Endpoint-Security-Lösungen zudem auch Signale aus:
Netzwerk-Traffic-Mustern, Cloud-Computing-Anwendungen und Systemprotokollen. Das deckt die “Detection-Seite” ab. Mit Blick auf die “Response-Seite” sind EDR-Lösungen auch in der Lage, Schaden zu begrenzen und zu beheben. Zum Beispiel, indem sie auffällige Devices isolieren oder problematische Netzwerksegmente mit einer Firewall absichern. Je nachdem, wie das jeweilige Tool funktioniert, können diese Prozesse mehr oder weniger manuellen Aufwand erfordern.  
Schwierig ist hingegen mittlerweile, EDR von anderen Detection-Produktkategorien zu unterscheiden. Das beste Beispiel ist Extended Detection and Response (XDR): Inzwischen haben viele EDR-Lösungen deutlich an Umfang und Funktionen zugelegt, was dazu geführt hat, dass sie teilweise zu XDR “umetikettiert” wurden. Das lässt die Grenzen zwischen den Kategorien immer weiter verschwimmen.  
Die zunehmende Verschmelzung von EDR und XDR ist mit Blick auf den Detection-Gesamtmarkt jedoch nur ein Aspekt. Die Produkte in diesem Bereich laufen unter anderem auch unter folgenden Bezeichnungen:
Network Detection and Response (NDR), Managed Detection and Response (MDR), oder Application Detection and Response (ADR). Was EDR-Tools leisten sollten
Folgende Funktionen sollte eine hochwertige Endpoint-Security-Lösung mitbringen:
Fortschrittliche Threat-Detection-Funktionen: Effektive Endpoint-Detection-and-Response-Lösungen sind in der Lage, Events zu beobachten und in Echtzeit darauf zu reagieren. Sie sollten außerdem automatisch mit einer wachsenden Zahl von Netzwerken und Anwendungen skalieren können. Support für tiefgehende Untersuchungen: So können Security-Teams potenzielle Bedrohungen verstehen und möglichst zeitnah entsprechende Gegenmaßnahmen einleiten.  Integrationsfähigkeit: EDR-Tools sollten sich mit diversen anderen Sicherheitslösungen integrieren lassen – etwa Firewalls, SIEM, SOAR und Incident-Response-Tools. Das ermöglicht Anwenderunternehmen, Bedrohungsinformationen über APIs und Konnektoren systemübergreifend zu teilen. Zentralisierte Management-Funktionen und Analytics-Dashboards: Um ausufernde Schulungen zu vermeiden und jederzeit den Überblick über den aktuellen Status aller Endpunkte im Unternehmen zu wahren, sollte EDR-Software eine zentrale Konsole und Datenanalysen bereitstellen.    Lückenloser Support für die fünf wesentlichen Endpoint-Betriebssysteme: Windows-, macOS-, Android-, iOS- und Linux-Devices sollten im Idealfall abgedeckt sein. Die 6 wichtigsten Endpoint-Security-Lösungen
Der Endpoint-Detection-and-Response-Markt hält unzählige Lösungen diverser Anbieter bereit. Um Sie nicht zu erschlagen, stellen wir Ihnen an dieser Stelle sechs bewährte und empfehlenswerte Lösungen namhafter Anbieter vor.
CrowdStrike Falcon Insight EDR
Die Crowdstrike-Lösung kombiniert XDR- und EDR-Funktionen und soll (Advanced) Threats auf Android-, Chrome-OS-, iOS-, Linux-, macOS- und Windows-Geräten automatisch identifizieren und priorisieren. Zudem stellt Falcon Insight EDR Echtzeit-Response-Funktionalitäten zur Verfügung, um auf Endpunkte zuzugreifen, während sie untersucht werden.
Um schadhafte Aktivitäten automatisch zu identifizieren und zu klassifizieren, nutzt die Crowdstrike-Software KI-gestützte Angriffsindikatoren. Die automatisierte Alert-Priorisierung verspricht, manuelle Suchen und zeitaufwändige Recherche-Arbeiten überflüssig zu machen. Dank der integrierten Threat-Intelligence-Funktion kommt auch der übergeordnete Kontext von Cyberangriffen nicht zu kurz – inklusive Attribution.
Microsoft Defender for Endpoint
Ransomware, Fileless Malware und weitere raffinierte Angriffsmethoden verspricht Microsoft mit Defender for Endpoint den Wind aus den Segeln zu nehmen. Das Tool funktioniert auf Android, iOS, Linux, macOS und Windows. Die integrierten Threat-Analytics-Reportings sollen Unternehmen in die Lage versetzen:
sich schnell einen Überblick über neu aufkommende Bedrohungen verschaffen zu können; ihre Gefährdungslage evaluieren zu können; sowie geeignete Gegenmaßnahmen zu definieren. Darüber hinaus überwacht Defender for Endpoint die Sicherheitskonfigurationen von Microsoft- und Drittanbieter-Produkten. Sollte die Software fündig werden, ergreift sie automatisiert Maßnahmen, um Risiken zu minimieren.
Palo Alto Networks Cortex XDR
Cortex wurde von Palo Alto ursprünglich als EDR-Tool vermarktet. Inzwischen wurde die Lösung allerdings zu einem XDR-Produkt erweitert. Die Palo-Alto-Endpunktlösung deckt alle relevanten Betriebssysteme ab und integriert mit zahlreichen anderen Palo-Alto-Tools – etwa XSOAR.  
Auch diese Endpoint-Detection-and-Response-Lösung deckt automatisch Angriffsursachen und -sequenzen auf. Sie verspricht Anwendern außerdem, Fehlalarme zu reduzieren und damit der gefürchteten „Alert Fatigue“ ein Schnippchen zu schlagen.
SentinelOne Singularity
Diese cloudbasierte Plattform von SentinelOne kombiniert EDR-Funktionen mit Workload Protection und Identity Threat Detection. Sie funktioniert mit Android-, iOS-, Linux-, macOS- und Windows-Geräten, sowie Kubernetes-Instanzen.
Die Singularity-Plattform verspricht darüber hinaus:
optimierte Bedrohungserkennung, verkürzte Reaktionszeit bei Cybervorfällen sowie eine effektive Risikominimierung. Darauf zahlen unter anderem auch die transparente Ausgestaltung der Plattform, ihre performanten Analytics-Funktionen sowie automatisierte Reaktionsfähigkeiten ein. Zu guter Letzt ist die Endpoint-Lösung von SentinelOne auch noch einfach zu implementieren, skalierbar und mit einem benutzerfreundlichen Interface ausgestattet.
Sophos XDR
Diese Endpoint-Security-Lösung nutzt Telemetriedaten verschiedener Sophos- und Secureworks-Produkte und kombiniert diese mit weiteren Daten anderer, externer Tools. Im Ergebnis steht eine Software, die EDR- und XDR-Funktionalitäten zusammenbringt. Auch mit Blick auf die Integrationsfähigkeit überzeugt Sophos XDR. Das Tool integriert mit:    
Firewall-Produkten, Identity-Lösungen, Netzwerksicherheits-Tools, Productivity-Apps, E-Mail-Security-Lösungen, Backup- und Recovery-Software sowie Cloud-Instanzen. Mit seinen Generative-AI-Funktionen will Sophos XDR Security-Profis ermöglichen, Angreifer schneller zu neutralisieren. In Kombination mit dem Echtzeit-Schutz, der laufende Angriffe erkennt und automatisiert Abwehrmaßnahmen ergreift, steigt die Wahrscheinlichkeit, Cyberattacken abwehren zu können.  
Trend Micro Apex One
Die Trend-Micro-Lösung Apex One ist in die Vision-One-Plattform des Sicherheitsanbieters integriert. Auch dieses Produkt bietet sowohl EDR- als auch XDR-Features und unterstützt Android, iOS, macOS und Windows. Linux-Systeme bleiben leider außen vor.
Apex One verspricht, vor Zero-Day-Bedrohungen schützen zu können – und zwar mit Hilfe einer Kombination aus Antimalware-Techniken und virtuellem Patching. Ransomware, Malware und bösartige Skripte sollen so keine Chance mehr haben, Endpunkte heimzusuchen. Um Security-Tools von Drittanbietern zu integrieren, bietet die Trend-Micro-Lösung eine Vielzahl von APIs.
4 Fragen vor dem EDR-Investment
Bevor Sie eine Kaufentscheidung in Sachen EDR treffen, sollten Sie sich, beziehungsweise dem Anbieter Ihrer Wahl einige Fragen stellen:
Mit welchen anderen Sicherheits-Tools ist die Lösung integriert und wie wird das erreicht? Wie unterscheidet die betreffende Lösung zwischen verdächtigen und böswilligen Verhaltensmustern? Deckt die Software sämtliche relevanten Endpunkte ab und lässt sie sich auch auf größere Netzwerke skalieren? Wie gut identifiziert das Tool Fehlalarme? (fm)
View the full article
SvetaZi | shutterstock.com
Software im Bereich Endpoint Detection and Response (EDR) erfreut sich weiterhin steigender Beliebtheit – und wird mit zunehmender Reife immer effektiver. EDR-Lösungen bieten Realtime-Einblicke in die Endpunkt-Aktivitäten und ermöglichen es, Mobiltelefone, Workstations, Laptops, Server und andere Devices vor Cyberangriffen zu schützen.
In diesem Kaufratgeber erfahren Sie:
wie sich Endpoint Detection and Response definiert, welche Fähigkeiten EDR-Tools an Bord haben sollten, welche Anbieter und Lösung in Sachen Endpunkt-Sicherheit tonangebend sind, und welche konkreten Fragen vor einer Investition relevant sind. Endpoint Detection and Response erklärt
EDR-Tools erfassen Verhaltensdaten aus diversen Endpunkt-Quellen. Dazu gehören herkömmliche Computing Devices wie Windows- oder Mac-Rechner genauso wie Peripherie- und IoT-Geräte, beispielsweise Drucker oder Controller. Um IT-Profis auf verdächtige Aktivitäten oder laufende Cyberangriffe aufmerksam zu machen, analysieren Endpoint-Security-Lösungen zudem auch Signale aus:
Netzwerk-Traffic-Mustern, Cloud-Computing-Anwendungen und Systemprotokollen. Das deckt die “Detection-Seite” ab. Mit Blick auf die “Response-Seite” sind EDR-Lösungen auch in der Lage, Schaden zu begrenzen und zu beheben. Zum Beispiel, indem sie auffällige Devices isolieren oder problematische Netzwerksegmente mit einer Firewall absichern. Je nachdem, wie das jeweilige Tool funktioniert, können diese Prozesse mehr oder weniger manuellen Aufwand erfordern.  
Schwierig ist hingegen mittlerweile, EDR von anderen Detection-Produktkategorien zu unterscheiden. Das beste Beispiel ist Extended Detection and Response (XDR): Inzwischen haben viele EDR-Lösungen deutlich an Umfang und Funktionen zugelegt, was dazu geführt hat, dass sie teilweise zu XDR “umetikettiert” wurden. Das lässt die Grenzen zwischen den Kategorien immer weiter verschwimmen.  
Die zunehmende Verschmelzung von EDR und XDR ist mit Blick auf den Detection-Gesamtmarkt jedoch nur ein Aspekt. Die Produkte in diesem Bereich laufen unter anderem auch unter folgenden Bezeichnungen:
Network Detection and Response (NDR), Managed Detection and Response (MDR), oder Application Detection and Response (ADR). Was EDR-Tools leisten sollten
Folgende Funktionen sollte eine hochwertige Endpoint-Security-Lösung mitbringen:
Fortschrittliche Threat-Detection-Funktionen: Effektive Endpoint-Detection-and-Response-Lösungen sind in der Lage, Events zu beobachten und in Echtzeit darauf zu reagieren. Sie sollten außerdem automatisch mit einer wachsenden Zahl von Netzwerken und Anwendungen skalieren können. Support für tiefgehende Untersuchungen: So können Security-Teams potenzielle Bedrohungen verstehen und möglichst zeitnah entsprechende Gegenmaßnahmen einleiten.  Integrationsfähigkeit: EDR-Tools sollten sich mit diversen anderen Sicherheitslösungen integrieren lassen – etwa Firewalls, SIEM, SOAR und Incident-Response-Tools. Das ermöglicht Anwenderunternehmen, Bedrohungsinformationen über APIs und Konnektoren systemübergreifend zu teilen. Zentralisierte Management-Funktionen und Analytics-Dashboards: Um ausufernde Schulungen zu vermeiden und jederzeit den Überblick über den aktuellen Status aller Endpunkte im Unternehmen zu wahren, sollte EDR-Software eine zentrale Konsole und Datenanalysen bereitstellen.    Lückenloser Support für die fünf wesentlichen Endpoint-Betriebssysteme: Windows-, macOS-, Android-, iOS- und Linux-Devices sollten im Idealfall abgedeckt sein. Die 6 wichtigsten Endpoint-Security-Lösungen
Der Endpoint-Detection-and-Response-Markt hält unzählige Lösungen diverser Anbieter bereit. Um Sie nicht zu erschlagen, stellen wir Ihnen an dieser Stelle sechs bewährte und empfehlenswerte Lösungen namhafter Anbieter vor.
CrowdStrike Falcon Insight EDR
Die Crowdstrike-Lösung kombiniert XDR- und EDR-Funktionen und soll (Advanced) Threats auf Android-, Chrome-OS-, iOS-, Linux-, macOS- und Windows-Geräten automatisch identifizieren und priorisieren. Zudem stellt Falcon Insight EDR Echtzeit-Response-Funktionalitäten zur Verfügung, um auf Endpunkte zuzugreifen, während sie untersucht werden.
Um schadhafte Aktivitäten automatisch zu identifizieren und zu klassifizieren, nutzt die Crowdstrike-Software KI-gestützte Angriffsindikatoren. Die automatisierte Alert-Priorisierung verspricht, manuelle Suchen und zeitaufwändige Recherche-Arbeiten überflüssig zu machen. Dank der integrierten Threat-Intelligence-Funktion kommt auch der übergeordnete Kontext von Cyberangriffen nicht zu kurz – inklusive Attribution.
Microsoft Defender for Endpoint
Ransomware, Fileless Malware und weitere raffinierte Angriffsmethoden verspricht Microsoft mit Defender for Endpoint den Wind aus den Segeln zu nehmen. Das Tool funktioniert auf Android, iOS, Linux, macOS und Windows. Die integrierten Threat-Analytics-Reportings sollen Unternehmen in die Lage versetzen:
sich schnell einen Überblick über neu aufkommende Bedrohungen verschaffen zu können; ihre Gefährdungslage evaluieren zu können; sowie geeignete Gegenmaßnahmen zu definieren. Darüber hinaus überwacht Defender for Endpoint die Sicherheitskonfigurationen von Microsoft- und Drittanbieter-Produkten. Sollte die Software fündig werden, ergreift sie automatisiert Maßnahmen, um Risiken zu minimieren.
Palo Alto Networks Cortex XDR
Cortex wurde von Palo Alto ursprünglich als EDR-Tool vermarktet. Inzwischen wurde die Lösung allerdings zu einem XDR-Produkt erweitert. Die Palo-Alto-Endpunktlösung deckt alle relevanten Betriebssysteme ab und integriert mit zahlreichen anderen Palo-Alto-Tools – etwa XSOAR.  
Auch diese Endpoint-Detection-and-Response-Lösung deckt automatisch Angriffsursachen und -sequenzen auf. Sie verspricht Anwendern außerdem, Fehlalarme zu reduzieren und damit der gefürchteten „Alert Fatigue“ ein Schnippchen zu schlagen.
SentinelOne Singularity
Diese cloudbasierte Plattform von SentinelOne kombiniert EDR-Funktionen mit Workload Protection und Identity Threat Detection. Sie funktioniert mit Android-, iOS-, Linux-, macOS- und Windows-Geräten, sowie Kubernetes-Instanzen.
Die Singularity-Plattform verspricht darüber hinaus:
optimierte Bedrohungserkennung, verkürzte Reaktionszeit bei Cybervorfällen sowie eine effektive Risikominimierung. Darauf zahlen unter anderem auch die transparente Ausgestaltung der Plattform, ihre performanten Analytics-Funktionen sowie automatisierte Reaktionsfähigkeiten ein. Zu guter Letzt ist die Endpoint-Lösung von SentinelOne auch noch einfach zu implementieren, skalierbar und mit einem benutzerfreundlichen Interface ausgestattet.
Sophos XDR
Diese Endpoint-Security-Lösung nutzt Telemetriedaten verschiedener Sophos- und Secureworks-Produkte und kombiniert diese mit weiteren Daten anderer, externer Tools. Im Ergebnis steht eine Software, die EDR- und XDR-Funktionalitäten zusammenbringt. Auch mit Blick auf die Integrationsfähigkeit überzeugt Sophos XDR. Das Tool integriert mit:    
Firewall-Produkten, Identity-Lösungen, Netzwerksicherheits-Tools, Productivity-Apps, E-Mail-Security-Lösungen, Backup- und Recovery-Software sowie Cloud-Instanzen. Mit seinen Generative-AI-Funktionen will Sophos XDR Security-Profis ermöglichen, Angreifer schneller zu neutralisieren. In Kombination mit dem Echtzeit-Schutz, der laufende Angriffe erkennt und automatisiert Abwehrmaßnahmen ergreift, steigt die Wahrscheinlichkeit, Cyberattacken abwehren zu können.  
Trend Micro Apex One
Die Trend-Micro-Lösung Apex One ist in die Vision-One-Plattform des Sicherheitsanbieters integriert. Auch dieses Produkt bietet sowohl EDR- als auch XDR-Features und unterstützt Android, iOS, macOS und Windows. Linux-Systeme bleiben leider außen vor.
Apex One verspricht, vor Zero-Day-Bedrohungen schützen zu können – und zwar mit Hilfe einer Kombination aus Antimalware-Techniken und virtuellem Patching. Ransomware, Malware und bösartige Skripte sollen so keine Chance mehr haben, Endpunkte heimzusuchen. Um Security-Tools von Drittanbietern zu integrieren, bietet die Trend-Micro-Lösung eine Vielzahl von APIs.
4 Fragen vor dem EDR-Investment
Bevor Sie eine Kaufentscheidung in Sachen EDR treffen, sollten Sie sich, beziehungsweise dem Anbieter Ihrer Wahl einige Fragen stellen:
Mit welchen anderen Sicherheits-Tools ist die Lösung integriert und wie wird das erreicht? Wie unterscheidet die betreffende Lösung zwischen verdächtigen und böswilligen Verhaltensmustern? Deckt die Software sämtliche relevanten Endpunkte ab und lässt sie sich auch auf größere Netzwerke skalieren? Wie gut identifiziert das Tool Fehlalarme? (fm)
View the full article
Apple today announced the launch of a new subscription option for App Store developers: monthly subscriptions with a 12-month commitment. The new option allows developers to offer subscribers discounted pricing typically associated with an annual subscription but paid on a monthly basis to keep payments more affordable.

Apple says that the new feature provides transparency to users by allowing them to easily view the number of completed and remaining payments they've made toward their annual commitment. Apple will also send email and optional push notifications ahead of renewals.

Developers can begin creating these new subscription types in ‌App Store‌ Connect and testing them in Xcode starting today, and they will go live to users on iOS 26.4 and equivalent versions for other platforms next month alongside the launch of iOS 26.5 and related updates.

Notably, it appears the United States and Singapore will be excluded from these subscriptions for the time being, and there's no word on when they might roll out in these markets.Tag: App Store
This article, "Apple Introduces App Store Monthly Subscriptions With 12-Month Commitment" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Spotify today launched a new Fitness hub, bringing over 1,400 on-demand Peloton workout classes to Premium subscribers alongside a range of free content from independent wellness creators.


The Peloton classes span strength, cardio, yoga, pilates, barre, meditation, stretching, and outdoor run and walk, and require no specialist equipment. Peloton's bike workouts are not included. The catalog is available in the U.S., UK, Australia, Germany, Austria, Canada, Mexico, Sweden, and Spain, with Spotify saying it will expand to more countries over time.

Both free and Premium subscribers can access curated playlists and content from a range of established wellness creators, including Yoga With Kassandra, Caitlin K'eli Yoga, Sweaty Studio, Chloe Ting, Pilates Body by Raven, Abi Mills Wellness, and Sophiereidfit. The Peloton partnership content, featuring instructors such as Rebecca Kennedy, Ally Love, and Rad Lopez, is available to Premium subscribers only, ad-free.

The Fitness hub includes an onboarding questionnaire that asks users what type of movement they want, how hard they want to push, and their experience level, then generates a personalized starter pack. Classes are primarily in English, with select options in Spanish and German. Offline downloads are supported, and users can switch between watching a class on TV and listening on a phone or smart speaker in audio-only mode.

Nearly 70% of Premium subscribers apparently work out monthly, and there are more than 150 million fitness playlists active on the platform. Fitness and workout content also ranks among the top use cases for the company's recently launched AI-powered Prompted Playlist feature.

The Fitness hub is accessible by searching "fitness" in the Spotify app's Search tab, or via the "Browse all" menu.Tags: Peloton, Spotify
This article, "Spotify Launches Fitness Hub With 1,400+ Peloton Workouts" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Apple today provided the fourth beta of an upcoming macOS Tahoe 26.5 update to developers for testing purposes, with the update coming a week after the third beta.


Developers can download the ‌macOS Tahoe‌ 26.5 update by opening up the System Settings app, selecting the General category, and then choosing Software Update. Beta Updates will need to be enabled, and a free developer account is required.

No new features were found in the first three ‌macOS Tahoe‌ 26.5 betas, and it's likely the update primarily focuses on bug fixes and performance improvements.Related Roundup: macOS TahoeRelated Forum: macOS Tahoe
This article, "Fourth macOS Tahoe 26.5 Beta Now Available for Developers" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Apple today seeded the fourth betas of upcoming iOS 26.5 and iPadOS 26.5 updates to developers for testing purposes, with the software coming a week after Apple released the third betas.


Registered developers can download the betas from the Settings app on the iPhone or iPad by going to the General section and selecting Software Update.

iOS 26.5 and iPadOS 26.5 do not include new Siri capabilities, suggesting any ‌Siri‌ updates are being held until iOS 27. The Maps app has a Suggested Places feature for recommending locations to visit nearby based on trends and recent searches, plus Apple is laying the groundwork for ads in the Apple Maps app.

Apple is continuing to test end-to-end encryption (E2EE) for RCS messages between iPhone and Android users. Apple included the feature in the iOS 26.4 beta, but removed it before the update launched to the public.

In the European Union, Apple is testing proximity pairing, notification forwarding, and Live Activities for third-party wearables like earbuds and smartwatches. The functionality will allow third-party wearables to have many of the same features as the Apple Watch and AirPods.

More detail on what's new in iOS 26.5 can be found in our iOS 26.5 beta features guide.Related Roundups: iOS 26, iPadOS 26Related Forum: iOS 26
This article, "Apple Seeds Fourth iOS 26.5 and iPadOS 26.5 Betas to Developers" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Apple today provided developers with the fourth betas of upcoming watchOS 26.5, tvOS 26.5, and visionOS 26.5 betas for testing purposes. The software comes a week after Apple released the third betas for each platform.


The software updates are available through the Settings app on each device, and because these are developer betas, a free developer account is required.

There's no word on what's in the software as of yet. watchOS, tvOS, and visionOS often get few features in each new beta, with updates primarily focusing on bug fixes and performance improvements. Nothing new was found in the first three betas. Related Roundups: Apple TV, Apple Vision Pro, watchOS 26Buyer's Guide: Apple TV (Don't Buy), Vision Pro (Buy Now)Related Forums: Apple TV and Home Theater, Apple Vision Pro, Apple Watch
This article, "Apple Releases Fourth watchOS 26.5, tvOS 26.5 and visionOS 26.5 Betas" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
The IAM Union representing Apple employees in Towson, Maryland today said that it is filing an Unfair Labor Practice charge [PDF] against Apple with the National Labor Relations Board. The union is accusing Apple of unlawful discrimination against unionized workers.


Earlier this month, Apple announced plans to close the Towson Apple Store alongside two other Apple locations in Connecticut and California. The Towson store was the first Apple retail location to unionize in the U.S. back in 2022.

With most store closures, employees are relocated automatically to nearby stores, but Apple said the union rules at the Towson location prevented it from moving the workers to other stores. Apple instead said that Towson employees are "eligible to apply for open roles at Apple in accordance with the collective bargaining agreement."

The IAM Union said at the time that it was "outraged" by Apple's decision, and that there was nothing in the agreement that prevented employees from being relocated. IAM said Apple's claim was false, and that it raised "serious concerns" that the closure was a "cynical attempt to bust the union."

In today's filing, the IAM Union complained that Apple allowed employees at two non-union stores to transfer to other locations, but forced Towson employees to reapply for positions through the same process as external candidates.

The union has asked Apple to reverse its decision and give Towson workers the same opportunity to transfer to other retail locations.

The three stores that Apple is closing are located in struggling shopping malls that are slowly shutting down and losing foot traffic.Tag: Apple Store
This article, "Apple Hit With Unfair Labor Practice Charge for Refusing to Transfer Unionized Towson Workers" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Apple's MacBook Neo has recently been struck by delayed delivery estimates on Apple.com, due to the notebook's booming popularity. However, both Walmart and Amazon offer deliveries as soon as tomorrow, and even feature small discounts on the Neo.



Following its launch in March, the ‌MacBook Neo‌ has become a big hit for Apple, with the company struggling to keep the computer in stock online and in Apple stores. As of writing, Apple.com quotes a 2-3 week delivery estimate on every model of the Neo in the U.S. and many other countries.

If you want to prioritize saving a bit of money, Amazon has every model of the MacBook Neo for $9 off this week. Free delivery options place the Neo arriving as soon as May 2, while Prime members can get same-day shipping on the 256GB models in many locations.

Over at Walmart, you won't find any discounts, but you will find similarly quick delivery estimates. Select locations should see delivery estimates as soon as April 28 through April 29 on every model of the ‌MacBook Neo‌. If you have Walmart+ instead of Amazon Prime, this could be a better option despite the lack of a straight cash discount.

The ‌MacBook Neo‌ is Apple's low-cost Mac, priced at $599 for the 256GB model and $699 for the 512GB model with Touch ID. Students can get the computer for even cheaper at $499 through Apple's education store on its website.

If you're shopping for the new M5 MacBook Air, Amazon is currently hosting big $150 discounts on nearly every model. Prices now start at $949.99 for the 512GB 13-inch model.

Note: MacRumors is an affiliate partner with some of these vendors. When you click a link and make a purchase, we may receive a small payment, which helps us keep the site running.Related Roundup: MacBook NeoBuyer's Guide: MacBook Neo (Buy Now)Related Forum: MacBook Neo
This article, "MacBook Neo Still Seeing Extended Delivery Estimates at Apple, But Amazon and Walmart Have Stock" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Apple has decided to market two of its new products over the next year as "Ultra" devices, Macworld reports.


Citing sources familiar with the matter, the report claims that Apple's first foldable iPhone will be called the "iPhone Ultra." The device will become the highest end option in the lineup.

The ‌iPhone Ultra‌ will not be considered part of the iPhone 18 iPhone lineup, despite arriving alongside the iPhone 18 Pro and ‌iPhone 18 Pro‌ Max. This would be just like how the iPhone Air is not considered to be part of the iPhone 17 series. Although Apple is hoping to ship the ‌iPhone Ultra‌ alongside the ‌iPhone 18 Pro‌, it may launch a few weeks later and with scarcer availability.

Moreover, Apple is apparently planning to release a "MacBook Ultra" later this year or in early 2027. It will feature an OLED panel and a touchscreen, sitting above the MacBook Pro in the lineup at a "significantly" higher price point. While the device was originally intended to launch later this year, it is now likely pushed back by several months due to memory supply chain shortages.

Apple already offers M-series Ultra chips, the Apple Watch Ultra, and CarPlay Ultra. "Ultra" branding for the foldable iPhone and OLED MacBook was previously rumored by Bloomberg, which added that "AirPods Ultra" could also be on the way.Related Roundups: iPhone Fold, MacBook ProTags: iPhone Ultra, MacBook Ultra, MacworldBuyer's Guide: MacBook Pro (Buy Now)Related Forum: MacBook Pro
This article, "Apple Planning to Launch Two New 'Ultra' Products in the Next Year" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Checkmarx has disclosed that its ongoing investigation tied to the supply chain security incident has revealed that a cybercriminal group published data related to the company on the dark web. "Based on current evidence, we believe this data originated from Checkmarx's GitHub repository, and that access to that repository was facilitated through the initial supply chain attack of March 23, 2026,View the full article
OpenAI is working on a smartphone in what appears to be a significant reversal from previous reports that the company had no plans to enter the phone market, according to supply chain analyst Ming-Chi Kuo.


Kuo shared the findings from his latest supply chain checks in a post on X, saying MediaTek and Qualcomm are the chosen chip partners and Luxshare Precision Industry is the exclusive manufacturing partner, with mass production scheduled for 2028. Exact chip specifications and additional suppliers are expected to be finalized by late 2026 or the first quarter of 2027.

Kuo argues that the smartphone remains uniquely positioned for AI agent use because it is the only device that captures a user's full real-time state, including location, activity, communication, and context, which he describes as the most important input for real-time AI agent inference. He claims that AI agents will fundamentally change how people interact with a phone, shifting the focus from launching individual apps to completing tasks through a more continuous, context-aware interface.

He argues that fully controlling both the operating system and the hardware is the only way for the company to deliver a comprehensive AI agent service, and that a subscription-bundled business model could enable OpenAI to build a developer ecosystem around those agents.

Kuo suggests that Luxshare, which has long sought to reduce its dependence on Apple supply chain work, could benefit substantially from an early position in what he frames as the next generation of smartphone hardware.

The development represents a notable reversal in OpenAI's publicly stated hardware strategy. Previous reports have consistently described the company's hardware ambitions as centered on non-phone form factors developed in collaboration with Jony Ive, the former Apple design chief whose startup io Products was acquired by OpenAI for $6.5 billion. Those plans include a smart speaker, which is likely the first product to launch, along with smart glasses, a smart lamp, and potentially earbuds. OpenAI Chief Global Affairs Officer Chris Lehane has said the first hardware announcement is expected in the second half of 2026, with launch around early 2027.

OpenAI CEO Sam Altman posted on X the same day Kuo published his analysis, writing that it "feels like a good time to seriously rethink how operating systems and user interfaces are designed." Such a device would obviously put OpenAI in direct competition with Apple's iPhone.Tags: Ming-Chi Kuo, OpenAI
This article, "OpenAI Reportedly Working on an AI Smartphone to Rival iPhone" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Earlier this month, Amazon introduced a few new record low prices on the M5 MacBook Air and the best deal is back today. You can get the 512GB 13-inch M5 MacBook Air for $949.99, down from $1,099.00, available in all colors.

Note: MacRumors is an affiliate partner with Amazon. When you click a link and make a purchase, we may receive a small payment, which helps us keep the site running.

You'll find up to $150 off every model of the M5 MacBook Air on Amazon, with free delivery around May 2 for most models. In terms of other 13-inch models, Amazon also has the 24GB/1TB model for $1,349.00, down from $1,499.00. Both of these represent a match for the record low prices for each configuration.

$149 OFF13-inch M5 MacBook Air (512GB) for $949.99
$150 OFF13-inch M5 MacBook Air (16GB/1TB) for $1,149.00
$150 OFF13-inch M5 MacBook Air (24GB/1TB) for $1,349.00

In terms of the 15-inch models, you'll find up to $150 off the M5 MacBook Air, with multiple color options on sale for each configuration. Prices start at $1,149.99 for the 512GB model, down from $1,299.00, and also include both 1TB models on sale.

$149 OFF15-inch M5 MacBook Air (512GB) for $1,149.99
$150 OFF15-inch M5 MacBook Air (16GB/1TB) for $1,349.00
$150 OFF15-inch M5 MacBook Air (24GB/1TB) for $1,549.00

If you're on the hunt for more discounts, be sure to visit our Apple Deals roundup where we recap the best Apple-related bargains of the past week.



Deals Newsletter

Interested in hearing more about the best deals you can find in 2026? Sign up for our Deals Newsletter and we'll keep you updated so you don't miss the biggest deals of the season!




Related Roundup: Apple Deals
This article, "Apple's M5 MacBook Air Returns to $949.99 Low Price on Amazon" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Everything is dumb again. This week feels broken in a very familiar way. Old tricks are back. New tools are doing shady crap. Supply chains got hit. Fake help desks worked. Weird research showed how easy some attacks still are. Most of it feels like stuff we should have fixed years ago. Bad extensions. Stolen creds. Remote tools are getting abused. Malware hides in places people trust. SameView the full article
An administrative role meant for AI agents within Microsoft’s Entra ID ecosystem could allow privilege escalation and tenant takeover attacks, as it had privileges over more than agent-related objects.
Researchers at Silverfort found that users assigned to Microsoft’s “Agent ID Administrator” role, scoped to agent-related objects like blueprints and agent identities, could take ownership of unrelated service principals across the tenant. These users could then attach credentials and authenticate as those applications (unrelated services) to potentially manipulate app-to-app communication inside enterprise environments.
“Prior to the fix, the Agent ID Administrator role allowed assigning ownership over service principals beyond agent-related identities, effectively enabling similar capabilities to roles such as Application Administrator, but without being scoped specifically to agent use cases,” Silverfort researchers said in a blog post.
Microsoft has reportedly patched the issue across all cloud environments, blocking the role from modifying non-agent service principals. The cloud giant did not immediately respond to CSO’s request for comments.
Agent-only briefly meant everything
The problem was a failure in scope enforcement within a new agent identity security offering.
Introduced as part of Microsoft’s push to operationalize AI agents through its Agent Identity Platform, the Agent ID Administrator role is an effort to give autonomous agents their own governed identities inside Entra ID.
The role was designed to operate within a newly introduced set of objects tied to AI agents. However, because agent identities are ultimately built on the same primitives as applications, namely service principals, the boundary between “agent” and “non-agent” objects was not properly defined.
This architectural confusion could allow role holders to add themselves as owners of a wide range of service principals across the tenant. But the same action was blocked for application objects, suggesting the flaw was specific to the service principal layer rather than the broader identity model.
Application object and service principal are two related objects created every time an application is registered in Microsoft Entra ID.
“The application object serves as the global definition of the app and describes its configuration,” the researchers explained. “The service principal represents the app as an identity within a tenant and is the object that authenticates, is assigned roles and permissions, and accesses resources.”
The lack of definition allowed privilege expansion, allowing the role to mimic capabilities of a higher-privileged role like an Application Administrator. This was happening by default and did not trigger any alarm, the researchers noted.
From principal ownership to full takeover
Once ownership of a service principal was obtained, the attacker could generate new credentials like client secrets or certificates, and use them to authenticate as the compromised application. If the application held elevated directory roles or sensitive API permissions, the attackers could inherit those privileges.
“The impact depends on the privileges assigned to the targeted service principal,” the researchers said. “In environments where service principals are widely used or hold elevated permissions, this can lead to significant escalation. Tenant posture can further influence the impact, for example in cases of broadly consented applications or permissive configurations.”
The researchers noted that Agent ID Administrator is fairly new and isn’t in wide use yet, but the service principal-based escalation path is. “About 99% of tenants have at least one privileged service principal (not necessarily agent-related),” they said. Of them, more than half use agent identities averaging around 100 per tenant, creating a “real risk.”
Microsoft Security Response Center (MSRC) told Silverfort that an internal fix was fully rolled out by April 9, 2026, requiring no further user action. Researchers still published a few recommendations along with detection steps to help users identify and respond to similar patterns.

View the full article
Anthropic’s Claude Mythos Preview has dominated security discussions since its April 7 announcement. Early reporting describes a powerful cybersecurity-focused AI system capable of identifying vulnerabilities at scale and raising serious questions about how quickly organizations can validate, prioritize, and remediate what it finds. The debate that followed has mostly focused on the rightView the full article
A pro-Ukrainian hacktivist group called PhantomCore has been attributed to attacks actively targeting servers running TrueConf video conferencing software in Russia since September 2025. That's according to a report published by Positive Technologies, which found the threat actors to be leveraging an exploit chain comprising three vulnerabilities to execute commands remotely on susceptibleView the full article
Cybersecurity researchers have flagged dozens of Microsoft Visual Studio Code (VS Code) extensions on the Open VSX repository that are linked to a persistent information-stealing campaign dubbed GlassWorm. The cluster of 73 extensions has been identified as cloned versions of their legitimate counterparts. Of these, six have been confirmed to be malicious, with the remaining acting as seeminglyView the full article
Introduction
The transition from experimental machine learning to production-grade AI systems has created a significant gap in technical leadership. The Certified MLOps Manager designation is designed to bridge this gap by combining the principles of DevOps with the unique challenges of machine learning lifecycles. This guide is crafted for professionals who want to move beyond building models and start managing the infrastructure, pipelines, and teams that keep those models running at scale.
In the modern enterprise, high-performing software delivery is no longer just about code; it is about data and model integrity. As organizations look to scale their AI initiatives, the need for structured governance and operational excellence has become paramount. By following this guide, you will understand how this certification positions you within the broader ecosystem of AIOps School, cloud-native engineering, and platform management. Our goal is to provide a clear roadmap for engineers and managers to make informed decisions about their technical career trajectory.
What is the Certified MLOps Manager?
The Certified MLOps Manager is a professional credential that signifies a deep understanding of the intersection between data science and operational engineering. Unlike theoretical data science courses, this program focuses heavily on the “Ops” side of the equation. It addresses how to automate the deployment, monitoring, and management of machine learning models in a reliable and repeatable manner within a production environment.
It represents a shift from manual, artisanal model deployment to automated, enterprise-grade pipelines. The certification exists because the industry has realized that a model is a liability until it is successfully deployed and monitored. It aligns with modern engineering workflows by emphasizing Version Control for Data (DVC), Continuous Integration/Continuous Deployment (CI/CD) for ML, and the rigorous monitoring of data drift and model performance.
Who Should Pursue Certified MLOps Manager?
This certification is ideal for senior software engineers, SREs, and cloud architects who are increasingly tasked with supporting data science teams. If you are responsible for the reliability of applications that leverage AI, this credential provides the necessary framework to manage those specialized workloads. It helps traditional DevOps professionals pivot into the high-growth area of machine learning operations.
For engineering managers and technical leaders, the Certified MLOps Manager provides the vocabulary and strategic oversight needed to build and lead multidisciplinary teams. In the Indian market, where many global enterprises are establishing their AI centers of excellence, this certification serves as a powerful differentiator. It is equally relevant for data engineers who want to expand their influence into the deployment and governance phases of the lifecycle.
Why Certified MLOps Manager is Valuable in 2026 and Beyond
As AI moves from a “nice-to-have” feature to a core component of enterprise software, the demand for professionals who can manage these systems is skyrocketing. Traditional software deployment is relatively predictable, but ML models are non-deterministic and require a different set of management skills. This certification ensures that you remain relevant by mastering the tools and philosophies that handle this complexity.
The longevity of this career path is rooted in its focus on principles rather than just specific tools. While tools change, the need for data lineage, model reproducibility, and automated testing remains constant. Investing time in this certification provides a high return on investment because it places you at the center of the most significant architectural shift in the industry—the move toward intelligent, automated systems.
Certified MLOps Manager Certification Overview
The program is delivered through a structured learning path that emphasizes hands-on mastery over passive consumption. It is hosted on the primary educational platform for operational excellence, offering a curriculum that has been vetted by industry veterans. The assessment approach is designed to test your ability to solve real-world problems rather than just memorizing definitions or syntax.
The certification is structured into logical tiers that allow professionals to enter at a level that matches their current experience. Ownership of the certification resides with a body dedicated to advancing the standards of AIOps and MLOps globally. By completing this program, you demonstrate a commitment to the highest standards of production engineering in the context of machine learning.
Certified MLOps Manager Certification Tracks & Levels
The certification is divided into three distinct levels: Foundation, Professional, and Advanced. The Foundation level focuses on the core concepts of the ML lifecycle and basic pipeline automation. It is designed for those new to the intersection of ML and Ops who need a solid ground in the terminology and basic tooling.
The Professional level moves into complex orchestration, monitoring, and security. Here, the focus shifts to specialized tracks such as MLOps for SREs or MLOps for Data Engineers. Finally, the Advanced level is geared toward leadership and architecture, focusing on organizational strategy, cost management (FinOps for ML), and long-term governance. These levels align directly with career progression from individual contributor to principal engineer or manager.
Complete Certified MLOps Manager Certification Table
TrackLevelWho it’s forPrerequisitesSkills CoveredRecommended OrderCore MLOpsFoundationBeginners, Junior DevsBasic Python, LinuxML Lifecycle, Git, Docker1EngineeringProfessionalSREs, DevOps EngineersFoundation LevelCI/CD for ML, Kubernetes2ManagementProfessionalTeam Leads, PMsBasic ML knowledgeProject Lifecycle, Budgeting3ArchitectureAdvancedPrincipal EngineersProfessional LevelScaling ML, Infrastructure as Code4StrategyAdvancedEngineering ManagersManagement LevelGovernance, Compliance, ROI5 Detailed Guide for Each Certified MLOps Manager Certification
Certified MLOps Manager – Foundation Level
What it is
This certification validates a candidate’s grasp of the fundamental machine learning operations lifecycle. It confirms that the professional understands how data, code, and models interact in a development environment.
Who should take it
It is suitable for software engineers or data scientists who are new to operationalizing models and want to understand the basic requirements for building a reproducible ML pipeline.
Skills you’ll gain
understanding the core components of an MLOps pipeline. Versioning data and models alongside code. Basic containerization of machine learning environments. Knowledge of model training vs. inference environments. Real-world projects you should be able to do
Create a versioned data repository using DVC. Containerize a simple Scikit-learn model using Docker. Set up a basic GitHub Actions workflow for model testing. Preparation plan
7-14 Days: Focus on the MLOps manifesto and basic terminology. 30 Days: Practice with Git and Docker specifically for ML workloads. 60 Days: Build and document a complete end-to-end toy pipeline. Common mistakes
Focusing too much on model accuracy rather than deployment stability. Ignoring data versioning in favor of just code versioning. Best next certification after this
Same-track: Professional Engineering Track. Cross-track: DataOps Foundation. Leadership: MLOps Management Track. Certified MLOps Manager – Professional Level
What it is
This certification validates the ability to build and maintain production-grade ML infrastructure. It focuses on the automation of the entire lifecycle, from data ingestion to continuous monitoring in the cloud.
Who should take it
This is for experienced DevOps or Data Engineers who are responsible for the uptime and scalability of machine learning models in a business-critical environment.
Skills you’ll gain
Advanced orchestration using tools like Kubeflow or MLflow. Implementing automated testing for model drift and data quality. Managing GPU and TPU resources in cloud-native environments. Scaling inference services using Kubernetes. Real-world projects you should be able to do
Deploy a multi-node Kubeflow cluster on a major cloud provider. Implement a monitoring dashboard that alerts on feature drift. Build a rolling deployment strategy for an ML model with A/B testing. Preparation plan
7-14 Days: Review Kubernetes and advanced container orchestration. 30 Days: Deep dive into MLflow for experiment tracking and registry. 60 Days: Build a full CI/CD pipeline that includes automated model validation. Common mistakes
Over-engineering the infrastructure for simple models. Failing to implement proper logging and observability from day one. Best next certification after this
Same-track: Advanced Architecture Track. Cross-track: DevSecOps for ML. Leadership: Technical Program Management. Choose Your Learning Path
DevOps Path
The DevOps path focuses on applying traditional CI/CD principles to the world of machine learning. You will learn how to treat models as software artifacts that need to be tested, packaged, and deployed. This path emphasizes automation, infrastructure as code, and the seamless integration of ML pipelines into existing corporate software delivery systems. It is perfect for those who want to ensure that AI does not become a siloed department.
DevSecOps Path
The DevSecOps path is critical for organizations dealing with sensitive data and regulated industries. This path teaches you how to secure the ML supply chain, including data privacy, model poisoning prevention, and vulnerability scanning for ML libraries. You will focus on building security into every stage of the pipeline, ensuring that the speed of AI development does not compromise the security posture of the organization.
SRE Path
The SRE path for MLOps focuses on the reliability and performance of ML systems in production. You will learn about Service Level Objectives (SLOs) specifically for models, handling “black swan” events in data, and managing the latency of high-scale inference services. This path is ideal for engineers who care about uptime, error budgets, and the long-term sustainability of complex, non-deterministic systems.
AIOps Path
The AIOps path focuses on using artificial intelligence and machine learning to improve IT operations. You will learn how to deploy models that predict outages, automate root cause analysis, and manage huge volumes of telemetry data. This path is distinct because the “customer” of your models is usually the internal IT or platform team, aiming for a self-healing infrastructure.
MLOps Path
The MLOps path is the core journey of operationalizing data science. It covers the entire lifecycle from data preparation and model training to deployment and monitoring. You will learn the nuances of managing the “three-way” versioning of code, data, and models. This path is the most comprehensive for those who want to be the bridge between data scientists and the production environment.
DataOps Path
The DataOps path focuses on the “upstream” part of the machine learning lifecycle. It emphasizes data quality, data lineage, and the automated delivery of clean data to ML pipelines. You will learn how to treat data as a product, ensuring that the inputs to your models are reliable, consistent, and compliant with data governance standards.
FinOps Path
The FinOps path for MLOps is becoming essential as cloud costs for AI training and inference spiral out of control. This path teaches you how to monitor, manage, and optimize the costs of GPU instances, cloud storage, and data transfer. You will learn how to balance model performance with financial accountability, ensuring that AI initiatives remain profitable for the business.
Role → Recommended Certified MLOps Manager Certifications
RoleRecommended CertificationsDevOps EngineerMLOps Foundation, Professional EngineeringSREMLOps Professional, SRE Specialized TrackPlatform EngineerAdvanced Architecture, MLOps FoundationCloud EngineerProfessional Engineering, FinOps TrackSecurity EngineerDevSecOps for ML TrackData EngineerDataOps Track, MLOps FoundationFinOps PractitionerFinOps for ML TrackEngineering ManagerMLOps Management, Strategy Track Next Certifications to Take After Certified MLOps Manager
Same Track Progression
Once you have mastered the management aspects of MLOps, the natural progression is to move toward Advanced Architecture or AI Strategy. This involves moving from managing a single team or pipeline to overseeing an entire organization’s machine learning infrastructure. You will focus on multi-cloud strategies, enterprise-wide governance, and the integration of diverse AI technologies into a unified platform.
Cross-Track Expansion
If you have completed the MLOps track, expanding into DevSecOps or DataOps is highly recommended. Understanding the security implications of your models or the data engineering challenges that precede model training makes you a much more versatile professional. This “T-shaped” skill set allows you to collaborate more effectively across the entire engineering organization.
Leadership & Management Track
For those looking to move away from day-to-day technical implementation, a transition into technical leadership or product management for AI is a viable path. This focuses on the ROI of ML projects, team building, and aligning technical capabilities with business objectives. It prepares you for roles like VP of Engineering or Chief Data Officer.
Training & Certification Support Providers for Certified MLOps Manager
DevOpsSchool
DevOpsSchool provides an extensive array of resources for those pursuing MLOps credentials. They offer live instructor-led training and a vast library of recorded sessions that cover the technical nuances of pipeline automation. Their focus is on practical, hands-on labs that simulate real-world production environments. They are known for their community support and mentor-driven approach to learning.
Cotocus
Cotocus specializes in high-end technical training for modern engineering roles. Their approach to MLOps is deeply rooted in cloud-native technologies and Kubernetes. They provide specialized consulting and training services that help professionals understand the complexities of scaling machine learning. Their curriculum is updated frequently to reflect the latest shifts in the industry and tooling.
Scmgalaxy
Scmgalaxy is a premier destination for configuration management and DevOps resources. They offer a wealth of blog posts, tutorials, and certification guides that assist candidates in navigating the MLOps landscape. Their content is designed to be accessible to working professionals who need to upskill quickly. They provide a strong bridge between traditional software management and modern AI operations.
BestDevOps
BestDevOps focuses on curating the most effective learning paths for engineers. Their coverage of MLOps is concise and results-oriented, designed to help students pass their certifications while gaining actual job skills. They emphasize the “best practices” of the industry, helping candidates avoid common pitfalls and architectural mistakes during their training journey.
devsecopsschool.com
DevSecOpsSchool is the leading provider for security-focused engineering training. Their MLOps modules integrate security at every level, from data encryption to model integrity checks. This is the place for professionals who want to ensure their AI systems are not just fast and accurate, but also safe and compliant with global security standards.
sreschool.com
SRESchool focuses on the reliability and observability aspects of MLOps. Their training emphasizes monitoring, alerting, and incident management for machine learning models. If your goal is to manage models that never sleep and perform consistently under high load, their curriculum provides the necessary engineering rigor and mathematical grounding to succeed.
aiopsschool.com
AIOpsSchool is the primary host and developer of the MLOps Manager certification. They offer the most direct and comprehensive training for this specific credential. Their programs are designed by practitioners who have built and managed ML systems at scale. By training here, you are getting information directly from the source of the certification standards.
dataopsschool.com
DataOpsSchool provides the essential foundation for any MLOps professional by focusing on the data layer. Their training covers data pipelines, quality control, and the automation of data delivery. Understanding these concepts is vital for any MLOps manager, as the quality of the model is always limited by the quality of the data it consumes.
finopsschool.com
FinOpsSchool addresses the critical issue of cloud spending in AI and machine learning. Their training helps managers and engineers understand how to track and optimize the costs associated with massive model training jobs and inference clusters. As businesses demand more transparency in AI spending, the skills learned here become increasingly valuable for career growth.
Frequently Asked Questions (General)
How long does it take to get certified?
Most professionals complete the foundation level in 4-6 weeks, while advanced levels can take 3-6 months. Is there a prerequisite for the management track?
While not mandatory, having a basic understanding of the software development lifecycle and Python is highly recommended. What is the pass mark for the exams?
Typically, you need a score of 70% or higher to pass the assessment and receive your certification. Can I skip the foundation level?
If you have significant documented experience in MLOps, some tracks allow you to challenge the professional level directly. Are the exams lab-based or multiple choice?
The certification uses a mix of multiple-choice questions for theory and performance-based labs for practical skills. How long is the certification valid?
The certification is valid for two years, after which you must recertify to stay updated with current technologies. Is this certification recognized globally?
Yes, it is designed to meet international standards for production engineering and is recognized by major tech hubs. Do I need to be a data scientist to take this?
No, this is an operations and management certification; it does not require you to write complex ML algorithms. Does the program cover specific cloud providers like AWS or Azure?
The principles are cloud-agnostic, but labs often use major cloud providers to demonstrate real-world implementation. What kind of job support is provided?
Most providers offer resume reviews, interview coaching, and access to an exclusive community of MLOps professionals. Is the training available in different time zones?
Yes, training providers usually offer both live sessions in various time zones and self-paced recorded options. Can my company pay for this certification?
Yes, most organizations have a professional development budget that covers these types of industry-recognized credentials. FAQs on Certified MLOps Manager
What makes this different from a standard DevOps certification?
It specifically addresses the challenges of data drift, model retraining, and non-deterministic software behavior that standard DevOps does not cover. Will I learn how to use Kubeflow?
Yes, Kubeflow is a core component of the professional and engineering tracks within the certification curriculum. How does this certification help an Engineering Manager?
It provides the framework to evaluate team performance, manage technical debt in ML systems, and communicate effectively with data scientists. Is Python the only language used in the labs?
While Python is the primary language, the focus is on the operational tools like Docker, Kubernetes, and Jenkins. Does the certification cover LLMOps for Large Language Models?
The advanced tracks include modules on managing LLMs, including fine-tuning pipelines and vector database operations. How much math is involved in the exam?
The math is limited to understanding performance metrics like precision, recall, and monitoring statistics; you won’t be doing calculus. Can I use this certification to pivot from SRE to MLOps?
Absolutely, this is one of the most common and successful career pivots facilitated by this specific certification path. Are there any group discounts for enterprise teams?
Yes, most training providers offer corporate packages for teams of five or more engineers looking to standardize their MLOps practices. Final Thoughts: Is Certified MLOps Manager Worth It?
The decision to pursue a certification should always be based on the practical value it adds to your daily work and your long-term career goals. In the case of the Certified MLOps Manager, the value is clear: it provides a structured, standardized way to handle the most complex part of modern software—AI in production. As companies move past the “hype” phase of AI and into the “execution” phase, the people who can manage these systems will be the most sought-after talent in the market.
This certification is not a magic bullet, but it is a powerful tool in your professional arsenal. It demonstrates to employers that you have the discipline, the knowledge, and the practical skills to manage the risks and complexities of machine learning at scale. If you are looking to lead the next wave of technical innovation within your organization, this path is an excellent investment in your future. Focus on the learning, build the projects, and the career growth will naturally follow.
View the full article
Artificial intelligence tools are revamping DevSecOps processes, enabling security and development teams to more effectively build safeguards into software products from the get-go.
But AI’s impact on DevSecOps goes well beyond tooling and processes, altering the scope, skills, and strategies foundational to the discipline as well.
“AI is fundamentally shifting DevSecOps from reactive validation to continuous, intelligent enforcement,” says Siddardha Vangala, senior AI engineer and AI systems architect at engineering and construction company MasTec. “In enterprise environments, the biggest gains are coming from automation that operates alongside development workflows rather than after deployment.”
Revamping DevSecOps processes
AI is reshaping DevSecOps first and foremost by embedding security earlier in development and improving how issues are detected and remediated, says Katie Norton, a research manager for IDC’s DevSecOps and software supply chain security research practice.
Its impact on DevSecOps processes breaks down into three main areas, Norton says. The first is AI-assisted secure coding. “One of the clearest changes is the integration of third-party security tooling into coding assistants and agents,” she says. “Rather than assuming AI-generated code is secure by default, organizations are increasingly embedding security controls into the generation workflow itself.”
These controls provide policy guidance, secure coding patterns, validation checks, secrets detection, and approved dependency or configuration recommendations while code is produced, Norton says. As a result, security’s position within the development lifecycle is changing.
“Security is no longer interacting only with the developer after or alongside code creation,” Norton says. “It is increasingly interacting with the agent that is generating the code. That changes DevSecOps in a practical way. Security controls are moving closer to the point of generation, and [application security] teams are beginning to govern the behavior of AI systems, not just the behavior of human developers.”
The second area is large language model (LLM) vulnerability scanning. “LLMs are increasingly used to analyze code, configurations, and APIs for vulnerabilities, using contextual reasoning rather than fixed rules,” Norton says. “This allows them to identify logic flaws and insecure usage patterns that traditional scanners often miss. This expands detection coverage, particularly in complex or modern application architectures.”
At the same time, scanning itself is evolving, Norton says, becoming more autonomous and in some cases capable of initiating analysis, confirming findings, and integrating more directly into development workflows without requiring explicit human activities.
A third area is automated remediation suggestions and execution. “AI is increasingly used to generate fixes for vulnerabilities, including code changes, dependency updates, and configuration adjustments,” Norton notes. “These suggestions are often integrated directly into developer workflows, such as pull requests or IDEs [integrated development environments]. This reduces mean time to remediation and lowers the expertise required to resolve issues.”
The overall impact of AI on DevSecOps processes is that it’s collapsing the distance between writing code, finding vulnerabilities, and fixing them. “That makes DevSecOps more continuous, but also more machine-mediated,” Norton says. “The key challenge now becomes validating machine-generated code, machine-identified findings, and machine-suggested remediation across a development lifecycle.”
Explicit security requirements elevate AI benefits
While deploying AI with DevSecOps is helping to shift the emphasis on security to earlier in the development lifecycle, this requires “explicit instruction to do it right,” says Noe Ramos, vice president of AI operations at business software provider Agiloft.
“AI coding assistants accelerate development meaningfully, but they optimize for functional code by default, not secure enterprise code,” Ramos says. “Those aren’t the same target. We’ve had to build explicit security requirements into our AI coding prompts and project-level instructions — input validation, secrets management, least privilege, vulnerability patterns — because if you don’t specify it, it won’t reliably appear.”
Once that instruction layer is in place, “it applies consistently at scale in a way human developers working under deadline pressure don’t,” Ramos says.
AI tools are increasingly useful for flagging dependency vulnerabilities, identifying common vulnerability patterns, and suggesting remediation, tasks that previously required dedicated security review cycles, Ramos says. “This is compressing the feedback loop between writing code and catching security issues,” she says.
AI has improved the ability of teams to prioritize vulnerabilities. “Too much noise has been a long-standing problem in the DevSecOps space,” says Monika Malik, lead data/AI software engineer at communications provider AT&T. “Too many findings are generated with little context provided to make informed decisions.”
AI tools provide value by correlating multiple types of findings across code, dependencies, configurations, and runtime behaviors, Malik says. “This allows teams to then focus on those items that represent actual exploits or operationally impactful issues,” she says. “Teams are no longer treating all scanner results as equal.”
For example, AI-assisted analysis identifies actual exposures related to public-facing services, privileged workloads, or sensitive data, Malik says. “This enables teams focused on security engineering [to] spend time addressing relevant issues,” she says.
Transforming DevSecOps as a discipline
Given the impact AI is having in transforming DevSecOps on a larger scale, IT, security, and development leaders need to be on top of what changes when AI is introduced into development strategies.
“Historically, DevSecOps has been centered on application code security, infrastructure security, and software supply chain security,” Malik says. “With the introduction of AI, the scope of concern has expanded significantly. DevSecOps can no longer simply address source code security, container security, pipeline security, and cloud infrastructure security.”
Additional concerns now include model access exposure, prompt abuse/injection risks, sensitive data leakage, data lineage, third-party models and API dependencies, deployment of AI-generated code, and others, Malik says.
Strategic impact and challenges
“From a strategic standpoint, AI is leading DevSecOps towards a more risk-based operating model,” Malik says. “The mature strategy will be to apply different levels of scrutiny to different use cases. Teams will increasingly separate low-risk internal productivity use cases from high-risk use cases based upon customer-facing decisions, regulated data usage, authentication flows, privileged operations, etc.”
Agiloft is treating AI coding governance not as a DevSecOps-specific problem, “but as an enterprise governance problem with a DevSecOps component,” Agiloft’s Ramos says. That means cross-functional alignment among security, IT, AI operations, engineering, legal, and others, rather than expecting DevSecOps to absorb the entire new surface area alone, she says.
“The organizations that will get this right are the ones building governance infrastructure now, before the incidents force it,” Ramos says.
Traditional DevSecOps processes assumed human authorship of code, Ramos says. “AI authorship creates new questions: Who is accountable for AI-generated code that passes review and later causes a breach?” she says. “How do you track provenance? How do you handle the reality that developers are copy-pasting AI-generated code from consumer tools into enterprise codebases, potentially carrying licensing, security, or compliance baggage with it?”
New threat vectors arise
New threats are emerging, many of which stem from the growing use of AI.
“DevSecOps now has to cover a new attack surface it didn’t exist to address,” Ramos says. “AI models themselves, the prompts sent to them, the data used to fine-tune them, the outputs fed into production systems, are all threat vectors. That’s a material scope expansion on top of an already stretched discipline.”
DevSecOps is expanding beyond application and cloud security to include AI systems as “first-class” assets, IDC’s Norton says. “This includes securing models, training data, prompts, and inference pipelines, as well as addressing new attack vectors such as prompt injection, data leakage, and model manipulation,” she adds.
At a strategic level, “organizations are shifting from controlling developer behavior alone to governing AI-assisted development as a system,” Norton says. “This includes standardizing approved tools, defining usage policies, and embedding security controls into developer environments and AI systems.”
Application security teams are increasingly responsible for shaping how code is generated, by influencing the behavior of AI systems rather than relying solely on downstream detection and remediation, Norton says.
Skill sets evolve
AI’s infusion into DevSecOps will have a big impact on skills. “Security and engineering teams need a broader skill set that includes understanding how AI systems behave, how data flows through them, and where they introduce risk,” Norton says.
There is a shift away from developers needing to be deeply knowledgeable about how to write secure code themselves, as more of that responsibility is mediated through AI systems and embedded controls, Norton says.
“Developers need to understand how to use AI coding tools responsibly, while [application security] teams need to define and implement guardrails that shape what AI systems produce,” she says.
The DevSecOps practitioner “now needs enough AI literacy to evaluate risk in AI-assisted code, not just, ‘Does this code have a SQL injection risk?’ But, ‘Did an AI generate this in a way that introduced subtle logic errors or trained-in vulnerabilities?’” Ramos says. “That’s a different kind of code review skill, and most teams haven’t fully developed it yet.”
Among the necessary skill sets for DevSecOps teams, Malik says, are AI threat modeling; the ability to investigate model and prompt abuse scenarios and ensure secure use of coding copilots; data governance and provenance; and knowing how to evaluate supply chain AI models and services.
There is growing demand for engineers who understand both traditional security practices and AI-specific risks such as prompt injection, data leakage, and model misuse, Vangala says. “Teams increasingly need hybrid skills combining DevOps, application security, and AI system architecture,” he says.
Automation in overdrive
One of the biggest impacts of AI in any area is the rise in automation, and applying AI to DevSecOps will make automation increasingly common in the coming months.
DevSecOps practices are becoming more machine-to-machine and more tightly looped, while also reinforcing separation of concerns, IDC’s Norton says. “Security teams are shaping how AI systems generate code through embedded guardrails, while independently scaling detection and remediation through automated workflows,” she says.
The result is less reliance on manual, developer-mediated handoffs and more reliance on coordinated systems where code generation, analysis, and remediation occur through automated interactions, with humans focused on validation and oversight.
“When developers generate code using AI assistants, automated validation checks flag insecure patterns such as unsafe API calls, improper authentication logic, or exposed secrets,” Vangala says. “This reduces the number of security issues reaching downstream testing environments.”
Security logs are increasingly analyzed using AI models to identify anomalies and prioritize alerts, Vangala says. “Instead of manually reviewing large volumes of telemetry, automated systems highlight suspicious activity patterns and reduce alert fatigue by grouping related signals into actionable insights,” he says.
View the full article
Every SOC analyst has heard it by now: “AI is coming for your job”.
I hear it in conversations with SOC teams. I see it in the hesitation during evaluations. And increasingly, I feel it as a source of resistance — especially from the very people AI is supposed to help.
But the reality is the opposite.
Instead of eliminating the Tier 1 analyst role, AI is elevating it — from a job defined by repetitive tasks to one defined by judgment, oversight and decision-making. In short, it makes them more powerful as SOC commanders.
The work was never the point
To understand what’s changing, we need to be honest about the historical role of Tier 1 analysts.
In a typical SOC, a Tier 1 analyst might spend 20–30 minutes investigating a single phishing alert — pivoting across email logs, endpoint data and threat intelligence tools, validating signals and documenting findings. It’s necessary work, but it’s also highly repetitive and time-consuming.
Modern security operations generate more data than humans can reasonably process. Investigating a single alert often requires pivoting across identity systems, endpoint telemetry, cloud logs and threat intelligence sources. Multiply that by hundreds or thousands of alerts per day, and you have a workload that is fundamentally misaligned with human capacity.
More importantly, SOC analysts are too talented for this kind of non-human work. For years, we’ve accepted this as the cost of doing business. AI changes that equation.
From doing the work to directing it
What agentic AI introduces into the SOC is the ability to delegate.
Instead of analysts manually gathering evidence and stitching together context, AI agents can now autonomously execute investigative steps: Querying systems, correlating signals and building evidence chains in real time. It doesn’t remove the human from the process. It elevates them within it.
The emerging model is one where analysts manage a system of agents — each responsible for a piece of the investigation — rather than performing each step themselves. The human role shifts from operator to orchestrator.
What I consistently hear from security leaders isn’t, “I need my analysts to move faster.” It’s, “I need my analysts to stop collecting data and start making decisions based on it.” Those are fundamentally different problems. And the gap between them is where AI creates the most value.
The rise of the ‘manager of agents’
This is where the Tier 1 role evolves — not disappears.
In this new model, entry-level analysts are effectively managing a swarm of AI agents. They are responsible for reviewing investigations, validating conclusions and ensuring actions align with business context and risk tolerance.
They are not “in the loop” for every step. They are “on the loop” — overseeing outcomes rather than executing tasks.
When analysts are forced to stay in the loop — checking every enrichment, every query, every intermediate step — they become a bottleneck. When they move on the loop, they can operate at scale, reviewing dozens or hundreds of investigations with the right level of oversight.
This is how trust in AI is built: Not by asking humans to verify everything, but by giving them the visibility to verify anything.
Transparency becomes the control plane. Analysts can see exactly what the AI did, how it reached a conclusion and where uncertainty exists. Over time, as accuracy proves out, they naturally increase their level of trust — just as they would with a new colleague joining the team.
Why cybersecurity is different
The fear of job displacement is understandable. In many industries, AI is reducing the need for entry-level roles. Cybersecurity is one of the few domains where AI won’t reduce work. It will expose how much work we’ve been unable to do.
The volume and complexity of threats are increasing faster than teams can scale. Attackers are already using AI to automate reconnaissance, generate code and accelerate exploitation. Defenders don’t have the option to sit this out.
Threat hunting, detection engineering and control optimization have historically been under-resourced because teams were consumed by alert triage. When AI removes that burden, it creates much-needed capacity for analysts to do what they were trained to do. The work doesn’t shrink. The right work finally gets done.
A new baseline for entry-level talent
This shift also changes what we expect from entry-level analysts.
Historically, Tier 1 roles were designed as places where analysts learned by doing repetitive tasks. That model no longer makes sense when those tasks can be automated.
The baseline is moving toward understanding how AI systems operate: Interpreting their outputs, questioning their reasoning and guiding their behavior. Human-centric skills become more important, not less. Curiosity, critical thinking and the ability to connect disparate signals into a coherent narrative — these are the differentiators in an AI-driven SOC.
We’re already seeing organizations rethink how they hire for these roles. There is less emphasis on credentials and more on how someone thinks and solves problems. When AI handles the mechanics, judgment is the job.
Building trust that holds
If the future is so clear, why is there resistance? In most cases, it comes down to trust — and trust must be earned, not assumed.
The deployments I’ve seen fail share a common pattern: Organizations treat AI as a binary shift from no automation to full autonomy. That’s not how security teams work, and it’s not how they should be asked to work.
What works is a progression. Start with limited, high-confidence use cases. Provide full transparency into how the system reaches its conclusions. Let analysts validate outcomes before expanding the scope. And critically, put practitioners in the room. Not implementation consultants or project managers, but people who have run SOC shifts, triaged thousands of alerts and earned credibility the hard way.
This is why, when we deploy, we bring former SOC leads, threat hunters and detection engineers to work directly alongside analyst teams. They’re not there to configure software. They’re there to build trust in the system — because they’ve already earned trust from the people using it. When analysts see that the people helping them deploy this technology have lived the same grind, the conversation changes. It stops being “will this replace me” and starts being “how do I use this well.”
That shift in orientation — from threat to tool — is what separates a successful deployment from one that stalls.
The trust gap isn’t a technology problem. It’s a human one. And it closes the same way trust always closes: Through demonstrated competence, shared context and time.
The future SOC is human-led
The end state here is not an autonomous SOC with no humans involved. It’s a human-led SOC, powered by AI.
AI agents handle the labor-intensive, evidence-gathering aspects of security operations. Humans provide direction, oversight and accountability. Together, they operate at a speed and scale neither could achieve alone. That’s not a theory — it’s what’s happening in production environments today.
Elevation, not elimination
The narrative that AI will eliminate Tier 1 analysts misses the point. The role isn’t going away. It’s being redefined.
The analysts who succeed in this new environment will be those who can manage intelligence systems, interpret complex outputs and make high-quality decisions under uncertainty.
They won’t be replaced. They’ll be promoted.
This article is published as part of the Foundry Expert Contributor Network.
Want to join?
View the full article
Cybersecurity researchers have disclosed details of a telecommunications fraud campaign that uses fake CAPTCHA verification tricks to dupe unsuspecting users into sending international text messages that incur charges on their mobile bills, generating illicit revenue for the threat actors who lease the phone numbers. According to a new report published by Infoblox, the operation is believed toView the full article
mikeledray | shutterstock.com
Vor seinen MAGA- und DOGE-Eskapaden wurde Elon Musk in erster Linie als visionärer Entrepreneur wahrgenommen. Damals, im Jahr 2010, ließ er den Mitarbeitern seines Raumfahrtunternehmens SpaceX ein Memo zukommen. Darin kritisierte er den übermäßigen, internen Gebrauch von Abkürzungen in gewohnt ausdrucksstarkem Stil: “Bei SpaceX gibt es eine schleichende Tendenz, erfundene Akronyme zu nutzen. Geschieht das exzessiv, wird die Kommunikation erheblich beeinträchtigt […] Niemand kann sich diese Abkürzungen merken und manche Leute wollen in Meetings nicht dumm erscheinen und nehmen es einfach hin […] Das muss sofort aufhören, sonst werde ich drastische Maßnahmen ergreifen”, drohte Trumps ehemaliger Sidekick damals.
Tatsächlich lässt sich nicht leugnen, dass der übermäßige Gebrauch von Akronymen ein erhebliches Hindernis für präzise Kommunikation darstellen kann – insbesondere in der Cybersicherheitsbranche, denn hier steht besonders viel auf dem Spiel. Wie Akronym-überladen die Security ist, veranschaulicht diese kuratierte Liste aller derzeit in Gebrauch befindlichen Security-Abkürzungen. Ein (kleiner) Auszug:
BAS, CTI, DDoS, DLP, EDR, IAM, MDR, MSSP, SASE, SIEM, SOC, DevSecOps, SAST/DAST, MFA. Mag sein, dass Cybersicherheitsprofis und -entscheider mit jedem dieser Akronyme direkt etwas anfangen können. In vielen anderen Teilen der Belegschaft werden sie vermutlich vor allem für fragende Blicke sorgen – insbesondere bei den Menschen, die gerade neu ins Unternehmen kommen.
In diesem Artikel werfen wir einen Blick darauf, wie Organisationen internen Buchstabenschlachten ein Ende bereiten können.
Abkürzungsschäden
Ian P. McCarthy, Professor für Innovations- und Betriebsmanagement an der kanadischen Simon Fraser University, erklärt, was es mit der Tendenz auf sich hat, komplexe Begrifflichkeiten zu kryptischen Kurzformen zu transformieren: “Einerseits werden Akronyme verwendet, um die Kommunikation kurz, standardisiert und effizient zu gestalten. Andererseits trägt Kommunikation auch dazu bei, die Identität und Exklusivität eines Berufs zu definieren.”
Insofern sei es auch eine Form von Elitismus, Akronyme zu nutzen, so der Akademiker: “Das schränkt ein, wer zu dieser Berufsgemeinschaft zählen kann.”  
Tatsächlich erweckt es den Anschein, als ob die Tech-Branche Akronyme zur ultimativen Geheimwaffe erklärt hat. Die kommt aber nicht nur zum Einsatz, um Zeit zu sparen, sondern auch um einen exklusiven “Club” zu etablieren. Das ist für die “Nicht-Mitglieder” nicht nur frustrierend, sondern kann auch Einarbeitungszeiten verlängern und potenzielle, neue Mitarbeiter abschrecken. Stichwort: Diversity.
Die Nachteile exzessiver Akronym-Angewohnheiten im Überblick:
Zugangsbarrieren: Stellen Sie sich einen neuen Mitarbeiter vor, der versucht, Cybersecurity-Protokolle zu verstehen, dabei aber von Tausenden unbekannter Abkürzungen erschlagen wird. Was ursprünglich dazu gedacht war, Brancheninsidern eine schnelle Kommunikation zu ermöglichen, wird so schnell zum Abschreckungs- und Erlahmungsfaktor. Doppel- und Mehrdeutigkeiten: Je nach Kontext können Abkürzungen manchmal mehrere Bedeutungen haben – wie im Fall von APT (Advanced Persistent Threat vs. Advanced Packaging Tool). Das kann unter Umständen zu Missverständnissen in wichtigen Mitteilungen führen und begünstigt damit potenziell Sicherheitslücken. Akronym-Müdigkeit: Nicht nur neue Mitarbeiter können von übermäßig verwendeten Abkürzungen überfordert werden. Auch versierte Cybersicherheitsexperten können einer „Acronym Fatigue“ erliegen – einfach, weil es viel zu viele Abkürzungen gibt und es unmöglich ist, auch noch mit allen neuen Entwicklungen Schritt zu halten. Die sind aber besonders im Bereich IT-Sicherheit wichtig. Transparenzverlust: Da Cybersecurity eine immer wichtigere Rolle im täglichen Leben einnimmt, ist es essenziell, grundlegende Sicherheitskonzepte allgemeinverständlich zu kommunizieren. Dabei können Akronyme unkundige Benutzer oft mehr verwirren, als für Klarheit zu sorgen. Akronymabhilfe
Natürlich gibt es je nach Organisation Unterschiede mit Blick darauf, wie mit Akronymen umgegangen wird. Eine allgemeine Faustregel könnte beispielsweise darstellen, ausschließlich diejenigen zu verwenden, die innerhalb der Organisation bekannt sind. Abkürzungen, die nicht in einem Gespräch verwendet werden, sollten bei schriftlicher Kommunikation auf jeden Fall vermieden, beziehungsweise ausgeschrieben werden – zumindest bei der ersten Erwähnung.  
Keine Lösung ist es hingegen, auf Abkürzungen ganz generell zu verzichten. Stattdessen empfiehlt es sich, sie maßvoll einzusetzen und mit dem zugehörigen Kontext auszustatten. Die folgenden vier Ansätze können Unternehmen und Organisationen dabei unterstützen, das umzusetzen.
Glossare: Standardisierte Glossare mit häufig verwendeten Akronymen erleichtern nicht nur Neueinsteigern, sich mit den wichtigsten, relevanten Begrifflichkeiten vertraut zu machen. Einfache Erklärungen: Kurze Erklärungen oder Definitionen, die bei weniger gebräuchlichen Akronymen eingeblendet werden, sind in Dokumentationen und journalistischen Fachartikeln bereits üblich. Dieser Ansatz ließe sich auch auf Präsentationen, Meetings und E-Mails ausweiten. Unnötiges vermeiden: Nicht jeder Begriff braucht ein Akronym, In manchen Fällen kann einfache Sprache, die kryptische Begriffe umschreibt, die bessere Wahl sein. Schulungen: Regelmäßige Trainingseinheiten zu neuen und bestehenden Terminologien können dazu beitragen, die gesamte Belegschaft einer Organisation auf dem aktuellen Stand zu halten, ohne dabei Einzelne zu überfordern. Laut dem Dramatiker George Bernard Shaw ist das größte Hindernis der Kommunikation die Illusion, dass sie stattgefunden hat. Exzessiv mit Akronymen um sich zu werfen, trägt dazu bei, dieses Trugbild zu erzeugen. 
Sie wollen weitere interessante Beiträge rund um das Thema IT-Sicherheit lesen? Unser kostenloser Newsletter liefert Ihnen alles, was Sicherheitsentscheider und -experten wissen sollten, direkt in Ihre Inbox.
View the full article
mikeledray | shutterstock.com
Vor seinen MAGA- und DOGE-Eskapaden wurde Elon Musk in erster Linie als visionärer Entrepreneur wahrgenommen. Damals, im Jahr 2010, ließ er den Mitarbeitern seines Raumfahrtunternehmens SpaceX ein Memo zukommen. Darin kritisierte er den übermäßigen, internen Gebrauch von Abkürzungen in gewohnt ausdrucksstarkem Stil: “Bei SpaceX gibt es eine schleichende Tendenz, erfundene Akronyme zu nutzen. Geschieht das exzessiv, wird die Kommunikation erheblich beeinträchtigt […] Niemand kann sich diese Abkürzungen merken und manche Leute wollen in Meetings nicht dumm erscheinen und nehmen es einfach hin […] Das muss sofort aufhören, sonst werde ich drastische Maßnahmen ergreifen”, drohte Trumps ehemaliger Sidekick damals.
Tatsächlich lässt sich nicht leugnen, dass der übermäßige Gebrauch von Akronymen ein erhebliches Hindernis für präzise Kommunikation darstellen kann – insbesondere in der Cybersicherheitsbranche, denn hier steht besonders viel auf dem Spiel. Wie Akronym-überladen die Security ist, veranschaulicht diese kuratierte Liste aller derzeit in Gebrauch befindlichen Security-Abkürzungen. Ein (kleiner) Auszug:
BAS, CTI, DDoS, DLP, EDR, IAM, MDR, MSSP, SASE, SIEM, SOC, DevSecOps, SAST/DAST, MFA. Mag sein, dass Cybersicherheitsprofis und -entscheider mit jedem dieser Akronyme direkt etwas anfangen können. In vielen anderen Teilen der Belegschaft werden sie vermutlich vor allem für fragende Blicke sorgen – insbesondere bei den Menschen, die gerade neu ins Unternehmen kommen.
In diesem Artikel werfen wir einen Blick darauf, wie Organisationen internen Buchstabenschlachten ein Ende bereiten können.
Abkürzungsschäden
Ian P. McCarthy, Professor für Innovations- und Betriebsmanagement an der kanadischen Simon Fraser University, erklärt, was es mit der Tendenz auf sich hat, komplexe Begrifflichkeiten zu kryptischen Kurzformen zu transformieren: “Einerseits werden Akronyme verwendet, um die Kommunikation kurz, standardisiert und effizient zu gestalten. Andererseits trägt Kommunikation auch dazu bei, die Identität und Exklusivität eines Berufs zu definieren.”
Insofern sei es auch eine Form von Elitismus, Akronyme zu nutzen, so der Akademiker: “Das schränkt ein, wer zu dieser Berufsgemeinschaft zählen kann.”  
Tatsächlich erweckt es den Anschein, als ob die Tech-Branche Akronyme zur ultimativen Geheimwaffe erklärt hat. Die kommt aber nicht nur zum Einsatz, um Zeit zu sparen, sondern auch um einen exklusiven “Club” zu etablieren. Das ist für die “Nicht-Mitglieder” nicht nur frustrierend, sondern kann auch Einarbeitungszeiten verlängern und potenzielle, neue Mitarbeiter abschrecken. Stichwort: Diversity.
Die Nachteile exzessiver Akronym-Angewohnheiten im Überblick:
Zugangsbarrieren: Stellen Sie sich einen neuen Mitarbeiter vor, der versucht, Cybersecurity-Protokolle zu verstehen, dabei aber von Tausenden unbekannter Abkürzungen erschlagen wird. Was ursprünglich dazu gedacht war, Brancheninsidern eine schnelle Kommunikation zu ermöglichen, wird so schnell zum Abschreckungs- und Erlahmungsfaktor. Doppel- und Mehrdeutigkeiten: Je nach Kontext können Abkürzungen manchmal mehrere Bedeutungen haben – wie im Fall von APT (Advanced Persistent Threat vs. Advanced Packaging Tool). Das kann unter Umständen zu Missverständnissen in wichtigen Mitteilungen führen und begünstigt damit potenziell Sicherheitslücken. Akronym-Müdigkeit: Nicht nur neue Mitarbeiter können von übermäßig verwendeten Abkürzungen überfordert werden. Auch versierte Cybersicherheitsexperten können einer „Acronym Fatigue“ erliegen – einfach, weil es viel zu viele Abkürzungen gibt und es unmöglich ist, auch noch mit allen neuen Entwicklungen Schritt zu halten. Die sind aber besonders im Bereich IT-Sicherheit wichtig. Transparenzverlust: Da Cybersecurity eine immer wichtigere Rolle im täglichen Leben einnimmt, ist es essenziell, grundlegende Sicherheitskonzepte allgemeinverständlich zu kommunizieren. Dabei können Akronyme unkundige Benutzer oft mehr verwirren, als für Klarheit zu sorgen. Akronymabhilfe
Natürlich gibt es je nach Organisation Unterschiede mit Blick darauf, wie mit Akronymen umgegangen wird. Eine allgemeine Faustregel könnte beispielsweise darstellen, ausschließlich diejenigen zu verwenden, die innerhalb der Organisation bekannt sind. Abkürzungen, die nicht in einem Gespräch verwendet werden, sollten bei schriftlicher Kommunikation auf jeden Fall vermieden, beziehungsweise ausgeschrieben werden – zumindest bei der ersten Erwähnung.  
Keine Lösung ist es hingegen, auf Abkürzungen ganz generell zu verzichten. Stattdessen empfiehlt es sich, sie maßvoll einzusetzen und mit dem zugehörigen Kontext auszustatten. Die folgenden vier Ansätze können Unternehmen und Organisationen dabei unterstützen, das umzusetzen.
Glossare: Standardisierte Glossare mit häufig verwendeten Akronymen erleichtern nicht nur Neueinsteigern, sich mit den wichtigsten, relevanten Begrifflichkeiten vertraut zu machen. Einfache Erklärungen: Kurze Erklärungen oder Definitionen, die bei weniger gebräuchlichen Akronymen eingeblendet werden, sind in Dokumentationen und journalistischen Fachartikeln bereits üblich. Dieser Ansatz ließe sich auch auf Präsentationen, Meetings und E-Mails ausweiten. Unnötiges vermeiden: Nicht jeder Begriff braucht ein Akronym, In manchen Fällen kann einfache Sprache, die kryptische Begriffe umschreibt, die bessere Wahl sein. Schulungen: Regelmäßige Trainingseinheiten zu neuen und bestehenden Terminologien können dazu beitragen, die gesamte Belegschaft einer Organisation auf dem aktuellen Stand zu halten, ohne dabei Einzelne zu überfordern. Laut dem Dramatiker George Bernard Shaw ist das größte Hindernis der Kommunikation die Illusion, dass sie stattgefunden hat. Exzessiv mit Akronymen um sich zu werfen, trägt dazu bei, dieses Trugbild zu erzeugen. 
Sie wollen weitere interessante Beiträge rund um das Thema IT-Sicherheit lesen? Unser kostenloser Newsletter liefert Ihnen alles, was Sicherheitsentscheider und -experten wissen sollten, direkt in Ihre Inbox.
View the full article
Amazon today has the AirPods 4 available for $99.00, down from $129.00. This remains one of the best deals on the AirPods 4 so far in 2026, and it's accompanied by a solid deal on the AirPods Max 2.

Note: MacRumors is an affiliate partner with some of these vendors. When you click a link and make a purchase, we may receive a small payment, which helps us keep the site running.

Apple's new AirPods Max 2 launched earlier this month, and Amazon is still one of the only retailers offering a discount on the headphones. You can get the Midnight and Starlight color options for $529.99 on Amazon, down from $549.00.

$30 OFFAirPods 4 for $99.00
$19 OFFAirPods Max 2 for $529.99

Although this is only a $19 discount on the AirPods Max 2, it's the best markdown you'll find online if you're looking to order the new headphones. Free delivery has the AirPods Max 2 arriving around April 30, but they can be delivered as soon as tomorrow with Prime shipping.

If you're on the hunt for more discounts, be sure to visit our Apple Deals roundup where we recap the best Apple-related bargains of the past week.



Deals Newsletter

Interested in hearing more about the best deals you can find in 2026? Sign up for our Deals Newsletter and we'll keep you updated so you don't miss the biggest deals of the season!




Related Roundup: Apple Deals
This article, "Get AirPods 4 for $99 and AirPods Max 2 for $529.99 on Amazon" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Cybersecurity researchers have discovered a new Lua-based malware created years before the notorious Stuxnet worm that aimed to sabotage Iran's nuclear program by destroying uranium enrichment centrifuges. According to a new report published by SentinelOne, the previously undocumented cyber sabotage framework dates back to 2005, primarily targeting high-precision calculation software to tamperView the full article
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added four vulnerabilities impacting SimpleHelp, Samsung MagicINFO 9 Server, and D-Link DIR-823X series routers to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. The list of vulnerabilities is below - CVE-2024-57726 (CVSS score: 9.9) - A missing authorization vulnerability inView the full article
Apple is planning to start showing ads in the Apple Maps app this summer, and signs of ads have already shown up in the iOS 26.5 beta as Apple prepares to roll them out.



Where Ads Show Up

Ads will be displayed in the ‌Apple Maps‌ search interface. Depending on the search, relevant ads will be shown first in search results.

Apple is also implementing a new Suggested Places feature in Maps that will show recommendations based on what's trending nearby and the user's recent searches.

Suggested Places

The Maps app is getting a Suggested Places feature that recommends locations to visit based on trending places that are around you and your recent Maps searches. Ads will be shown in Suggested Places.



No Opt-Out

Similar to ads in the App Store, there will be no option to turn off ads in ‌Apple Maps‌. Ads will be displayed for all users in the U.S. and Canada.

Countries

Ads will be shown in ‌Apple Maps‌ in the United States and Canada first, and could expand to other countries in the future.

Platforms

Ads will be displayed in the Maps app on iPhone and iPad.

What Ads Look Like

Apple says that ads in Maps will be clearly marked as ads with an "Ad" label, similar to how ads show up in the ‌App Store‌ search results.

Businesses will be able to bid for ad placement, which is how ads in the ‌App Store‌ work. The highest bidder for a given term will have their ad shown in the app.

Privacy

Your location and ads that you see and interact with in the Maps app are not associated with your Apple Account, and the data is not shared with third parties.

Beta Testing

Apple is laying the groundwork for Maps ads in the iOS 26.5 and iPadOS 26.5 betas. There's an ads splash screen in the Maps app along with underlying ad code, but ads are not yet live.

Launch Date

Apple only said "summer" for the ads launch. "Summer" in the Northern Hemisphere starts on June 21 and ends on September 22. iOS 26.5 is likely to launch in late May or early June, and it's possible ads will be tied to the update.Tag: Apple Maps
This article, "Ads Are Coming to Apple Maps This Summer: Here's What to Expect" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
X today launched XChat, a standalone messaging app for the iPhone and iPad, available now on the App Store.


XChat allows users to chat with anyone on X in a private, focused space separate from the main X app. At launch, the app supports direct messaging and group chats, audio and video calls, and file sharing. X claims all messages are end-to-end encrypted and PIN protected, with no ads or tracking.

Other features include disappearing messages, the ability to edit and delete messages for everyone in a chat, and a mechanism to block or alert users when a screenshot is attempted. The app is free to download and requires iOS 26.0 or later.



The app has been in testing with a small group of beta users since last year. X says more updates are still planned, with X lead designer Benji Taylor teasing that XChat is "just the beginning of what we're building for messaging."

Unlike the main X app, XChat adopts iOS 26 design conventions, including the ‌iOS 26‌ keyboard. The app offers several customization options, including light and dark modes, message permissions, left-swipe interaction settings, and a selection of app icon options. There is also a prominent button within XChat for jumping back to the main X app.

XChat can now be downloaded from the App Store in the United States. A release date for an Android version of the app has not yet been announced.Tag: Twitter
This article, "XChat App Now Available" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Apple's standard iPhone 18 could feature 12GB of memory for the first time, according to analyst Dan Nystedt.


In a new post on X, Nystedt said that the standard ‌iPhone 18‌ will match the 12GB of RAM Apple gave the iPhone 17 Pro and ‌iPhone 17 Pro‌ Max last September. It would mark the first time the entry-level iPhone model has shipped with that much memory.



Nystedt also flagged an earlier rumor claiming that Apple has secured TSMC's first 2nm chip production run for the A20 chip set to power the ‌iPhone 18‌ lineup. According to that report, TSMC's 2nm process delivers 15% better computing performance than 3nm, with no loss in power efficiency. The iPhone 17 series uses TSMC's N3P ‌3nm‌ node.

The jump to 12GB of RAM on the base model is likely tied to Apple Intelligence. Apple is expected to introduce expanded AI features with iOS 27, which the company is set to announce at WWDC on June 8. On-device AI workloads are memory-intensive, and keeping the entry-level iPhone capable of running ‌Apple Intelligence‌ in full would give Apple reason to push the standard model's memory up to par with last year's Pro tier.

The ‌iPhone 18‌ is not expected to launch alongside the iPhone 18 Pro this fall. Apple is reportedly planning to delay the standard model until early 2027, alongside the iPhone 18e and a second-generation iPhone Air, while the Pro models and the long-anticipated foldable iPhone will ship in the usual fall time frame.Related Roundup: iPhone 18Related Forum: iPhone
This article, "iPhone 18 Could Come With 12GB of RAM" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
US House Republicans have introduced two major privacy proposals that would reshape how US companies collect, process, and retain consumer data: the SECURE Data Act for general consumer privacy and the GUARD Financial Data Act for financial institutions.
The bills would create national standards for privacy and security practices while broadly preempting many state privacy laws, including the stronger protections already in place in states like California and Maryland. They also would eliminate the possibility of private lawsuits under the federal framework, leaving enforcement primarily to the Federal Trade Commission and state attorneys general.
That combination of federal preemption, weaker enforcement, and broad compliance changes has made the bills politically toxic for Democrats and privacy advocates alike. The Electronic Privacy Information Center (EPIC) called the SECURE Data Act “a huge gift to Big Tech” and warned that “a weak federal standard is worse than no standard at all.”
Congress has spent more than a decade failing to produce a comprehensive federal privacy law, often under less polarized conditions than today. “Support from one party in a single house of Congress is not going to do it,” said Alan Butler, executive director and president of EPIC. “It takes a bipartisan process, actually, to pass substantive legislation like this.”
The bills matter because they expose the privacy issues enterprises are already being forced to confront under existing state laws and federal guidance, including data minimization, automated profiling, data broker accountability, and increasingly complex rules around sensitive data.
Why data minimization is becoming a business issue
The SECURE Data Act includes familiar privacy rights: access, correction, deletion, portability, opt-outs for targeted advertising and data sales, and restrictions on certain forms of automated profiling. It also creates a federal data broker registry and formal controller-processor obligations for companies and vendors.
The most consequential operational issue for enterprises, however, is data minimization, the increasingly accepted principle that companies should collect only what they need, retain it only as long as necessary, and be able to justify both decisions.
The National Institute of Standards and Technology (NIST) already treats minimization as a core privacy and security principle. In its “Collection and Data Minimization” guidance, the agency says organizations should collect only the personal information necessary for a stated purpose, because excess retention creates avoidable privacy and security risks
That principle is increasingly central to state privacy laws as well. California and Maryland both impose stronger restrictions on unnecessary collection and retention than many earlier state frameworks.
For CIOs, CISOs, and CFOs, this is not simply a privacy-notice issue. Dormant customer records, excessive telemetry, forgotten SaaS archives, oversized AI training datasets, and legacy marketing databases all increase breach exposure. The more unnecessary data a company stores, the larger its attack surface becomes.
Butler argues the SECURE bill’s own minimization language is weaker than what leading states already require.
“The answer is that the law doesn’t really do anything,” he said, because the provision largely ties collection limits to what companies disclose in their privacy policy rather than imposing a stronger necessity standard.
That creates an unusual enterprise dynamic: the bill could weaken privacy protections overall while still reinforcing the long-term expectation that companies must be able to justify why they keep the data they have.
Where privacy law overlaps with AI governance
The SECURE Data Act does not contain broad, standalone AI governance rules, but it still touches AI in meaningful ways.
The bill includes opt-outs for fully automated profiling used for decisions with legal or similarly significant effects. That language can clearly implicate some uses of AI, particularly in hiring, lending, insurance, and other high-impact decisions.
Butler said that the profiling provision is worth watching, because several state laws already include similar requirements, and the concept is expanding.  That means privacy law may become the first practical form of AI regulation for many enterprises.
Training datasets, customer prompts, telemetry collection, and retention periods all become harder to defend when regulators ask whether the data is truly necessary. Legal teams, privacy officers, and CISOs may find themselves shaping AI strategy well before Congress passes a standalone AI law.
The teen-data provision that could break everything
One of the least-discussed but most disruptive provisions in the SECURE Data Act involves teens.
It states that a controller, namely any entity that is processing personal data, may not process the sensitive data of a teen without obtaining verifiable parental consent. The problem is that the bill defines sensitive data to include personal data collected from a teen, meaning almost any interaction involving a known user between 13 and 15 years old could trigger the requirement.
“If you operate a website, an app, a service, and there are users you know who are between 13 and 15, it’s going to break everything,” Butler said. “You’re going to have to get verifiable parental consent every time you touch the data—collect it, transfer it, store it, process it, anything.”
To comply, companies would need not only age awareness, which many already have through account creation or app stores, but also a system for verifying parent-child relationships. That would likely require collecting additional sensitive identity documents and personal records, the exact kind of information most organizations should try to avoid storing.
“It doesn’t work. It doesn’t make sense,” Butler said. “If I were a CIO or CISO, I would be very concerned, because it is completely unworkable.”
Why vendors and data brokers matter more
The SECURE bill requires formal controller-processor contracts covering confidentiality, deletion, retention limits, subcontractor obligations, and other safeguards. That pushes privacy compliance directly into procurement and third-party risk management.
For companies with inherited vendors from acquisitions and unclear data ownership, privacy compliance becomes an exercise in figuring out who has what data, where it sits, and whether anyone can actually force its deletion.
Butler points to the federal data broker registry as one of the few provisions in the bill that clearly reflects where privacy law is already moving. More states are adopting registry requirements, and businesses increasingly have to evaluate what data they buy, where it came from, and whether they qualify as brokers themselves.
Why financial firms should watch GUARD more closely
While the SECURE Data Act affects far more enterprises, the companion GUARD Financial Data Act may matter more for banks, insurers, and fintechs.
Rather than creating an entirely new framework, GUARD would significantly modernize Title V of the Gramm-Leach-Bliley Act (GLBA). It would preserve consumer opt-out rights while expanding access rights, adding former-customer deletion rights, requiring affirmative opt-in consent before disclosure of sensitive personal information, and imposing stronger obligations around financial data aggregators and access credentials.
It also includes provisions around data processing involving “covered nations,” tying financial privacy more directly to national security and supply chain concerns.
For institutions that still treat GLBA privacy notices as an annual compliance exercise, GUARD would turn privacy into a daily operational issue, touching open banking, credential handling, vendor relationships, and retention practices for former customers.
A federal law may not be the best for business
Business groups have long wanted a single national standard to replace the state-by-state patchwork of privacy laws. One federal framework is easier to govern than 20 competing ones, and many companies would welcome the predictability.
Brendan Thomas, executive director of the Internet for Growth coalition, praises the SECURE Data Act for providing a federal framework against the patchwork of state laws, which the coalition says is driving up prices for small businesses. “The introduction of the SECURE Data Act (H.R. 8413) in the House is an important step in the ongoing effort to establish a national privacy framework,” Thomas said in a statement.
But EPIC’s Butler argues that wiping away stronger state laws may not actually be good for business.
He says that companies have already invested heavily in compliance programs around those frameworks, and replacing them with weaker, vaguer federal rules could create new uncertainty rather than less.
“It breeds distrust among your customers,” Butler said. “It’s not good for business for people to mistrust what’s happening with these apps. All of a sudden, [consumers] don’t feel like their privacy is protected anymore.”
View the full article
Apple today released a YouTube Short revealing a rare behind-the-scenes look at the making of its playful MacBook Neo introduction video.


The short clip gives what Apple describes as "a peek at some handmade magic," revealing the physical models and camera techniques used during production. Apple shows how real-world props were combined with visual effects to produce the final sequences. Apple does not usually share production insights for a major product launch videos.

See the original "Hello, MacBook Neo" video below:



The MacBook Neo launched in March at $599, and its introductory video was widely noted for its whimsey and charm. The ‌MacBook Neo‌ itself has proven to be very strong seller since its launch; Apple reportedly broke a Mac launch week record in the weeks following its debut, and the device has since sold out of inventory until the middle of next month.Related Roundup: MacBook NeoBuyer's Guide: MacBook Neo (Buy Now)Related Forum: MacBook Neo
This article, "Apple Shares Behind-the-Scenes Look at MacBook Neo Intro Video" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Another member of the notorious Scattered Spider gang of cyber criminals has pleaded guilty in a US court, and will be sentenced later this year.
Tyler Buchanan pleaded guilty in a Florida court to conspiring with others to hack into companies’ computer systems with the intent of stealing at least $8 million in virtual currency. He faces up to
Other members of the gang have already been arrested: In 2024, a British national was picked up in Spain while, in the same year, another was charged in Florida.
However, there are members of the Scattered Spider group still active: last year it branched out and attacked a number of other businesses, including Marks and Spencer, Co-op and Harrods – although there were other arrests following these attacks.
The group works by sending SMS phishing attacks to the mobile phones of employees of its targets. The messages purport to come from suppliers to those companies but contain links to websites set up by group members, allowing them to steal information from the employees.
However, last year the cyber criminals revealed a new line of attack — pretending to be fellow employees of the victims, tricking help desks to reveal more personal information.
Despite the arrests, CISOs are being advised to be on alert against such attacks and take appropriate measures to guard against them.
View the full article
The US Cybersecurity and Infrastructure Security Agency (CISA) does not yet have access to Anthropic’s bug-hunting AI model, Claude Mythos, even though other government agencies do, Axios reported earlier this week.
As if that weren’t a big enough slap in the face for the national cyber-defense agency, the list of those who do have access to Mythos includes several unauthorized users, according to Bloomberg News. Members of a private Discord channel specializing in seeking information about unreleased AI models, have gained access to Mythos, according to one unnamed member of the group, Bloomberg reported. “The group has been using Mythos regularly since then, though not for cybersecurity purposes,” the person told Bloomberg, supplying screenshots to back up their claim.
As a result of its fear that the powerful model could be used to identify and exploit flaws in software and online services, Anthropic has limited access to a preview of Mythos to an exclusive group of government agencies, industry groups, and software providers through an initiative it calls Project Glasswing.
Even if CISA is shut out, some government agencies do have access to Mythos, including the US Department of Commerce’s Center for AI Standards and Innovation and the US National Security Agency, which Axios said are already assessing Mythos.
This article first appeared on Computerworld.
View the full article
Apple's first foldable iPhone, dubbed the "iPhone Ultra," could be missing at least five key features present on the iPhone 18 Pro models despite its $2,000 price point.


Recent images of dummy models shared by Sonny Dickson and Vadim Yuryev seem to reveal two previously undiscussed missing features of the ‌iPhone Ultra‌: MagSafe and the Action Button.

iPhone dummy units are intended to take the place of real devices for testing purposes, particularly for accessory manufacturers, who seek to mass produce items such as cases prior to the announcement of new devices, which necessitates a high level of accuracy and manufacturing precision.

Both sets of dummy models show that the volume buttons will be located on the top edge of the device, aligned to the right, similar to the iPad mini. This aspect was first rumored by Weibo leaker "Instant Digital," who said that the motherboard is apparently located on the right side of the device. As to not run cables across the screen to the left side for the volume buttons (where they are located on all other iPhone models), Apple is said to have decided to run them directly upwards, which maximizes internal space.

Image via Vadim Yuryev.

While a power button and volume buttons in their new location are clearly visible on the dummy models, the Action button is curiously missing. This suggests that the ‌iPhone Ultra‌ will be the first iPhone model with no Action button or silent switch. Apple introduced the Action button on the iPhone 15 Pro as a replacement for the silent switch, and it has since come to every available iPhone model.

The images of the foldable iPhone dummy models shared so far have been shown alongside mock ‌iPhone 18 Pro‌ and ‌iPhone 18 Pro‌ Max units. These dupes for the high-end models, like most dummies, clearly show precise indentations for the internal array of ‌MagSafe‌ magnets to help manufacturers obtain correct alignment with their accessories.

Image via Vadim Yuryev.

Crucially, these indentations are absent on the foldable iPhone dummies, suggesting that the device may not have ‌MagSafe‌. This aspect remains speculative, but at 4.5mm, the ‌iPhone Ultra‌ is expected to be Apple's thinnest iPhone to date by a considerable margin, so it is not implausible that it could be too thin for ‌MagSafe‌.

The ‌iPhone Ultra‌ is believed to be too thin to accommodate Apple's TrueDepth camera array, which is required for Face ID authentication and now located in the Dynamic Island. As a result, Apple is expected to revert to Touch ID on the device. The last iPhone to feature ‌Touch ID‌ was 2022's iPhone SE 3, where it was part of the device's budget offering. The last flagship iPhone with ‌Touch ID‌ was 2016's iPhone 7, so the return of ‌Touch ID‌ as the sole method of authentication on what will be the highest-end iPhone will be unprecedented.

Image via Sonny Dickson.

As visible on the dummy models, which corroborate a multitude rumors, the ‌iPhone Ultra‌ is expected to sport only two rear cameras. These are expected to be wide and ultra wide cameras, just like the iPhone 17. Unlike the Pro iPhones, there will be no third camera with telephoto capabilities.

Previous rumors indicate that the ‌iPhone Ultra‌ will also not have a SIM card slot, again just like the iPhone Air, being compatible with eSIM only. As a result, the ‌iPhone Ultra‌ could be missing the following features:


‌Face ID‌/TrueDepth camera array
Telephoto camera/third rear camera
‌MagSafe‌
Action Button
Physical SIM card slot

The ‌iPhone Air‌ lacks Ultra Wide and Telephoto rear cameras, a SIM card slot, and stereo speakers. With a super-thin design, a titanium frame, and a glass back, the ‌iPhone Ultra‌ is expected to be very similar to the ‌iPhone Air‌ in terms of design, and it is possible that similar feature concessions will be present on the device when it launches later this year. There are no indications that the ‌iPhone Ultra‌ will be missing stereo speakers, but it is not out of the question given the other design compromises Apple has chosen to make with the device.

The rumored starting price for the ‌iPhone Ultra‌ varies somewhat, but reports agree that it will not be below $1,999. The iPhone 17 Pro starts at $1,099 and has all of the above missing features, so the ‌iPhone Ultra‌'s compromises could be controversial given its markedly higher price point. The device is expected to launch alongside the ‌iPhone 18 Pro‌ and ‌iPhone 18 Pro‌ Max in the fall.Related Roundup: iPhone FoldTags: Face ID, Foldable iPhone, iPhone Ultra, MagSafe
This article, "Foldable 'iPhone Ultra' Could Be Missing These 5 Key Features Despite $2,000 Price Tag" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
While the 14-inch and 16-inch MacBook Pro were just updated with M5 Pro and M5 Max chips last month, bigger changes are reportedly around the corner.


According to Bloomberg's Mark Gurman, the higher-end MacBook Pro models will be receiving a major redesign by early 2027, and he said that Apple might use "MacBook Ultra" branding for them. If so, the MacBook Ultra would likely be a higher-priced model at the top of the MacBook lineup, sitting above the MacBook Pro entirely.

Up to six new features have been rumored so far, including an OLED display, touch capabilities, a Dynamic Island, M6 Pro and M6 Max chips manufactured with TSMC's advanced 2nm process, a thinner design, and built-in cellular connectivity.

The exact launch timing remains to be seen, but Gurman recently said that early 2027 is now looking more likely than late 2026 due to the global memory chip shortage. Apple's supply of RAM is constrained, which might push back the launch.

Keep in mind that the entry-level 14-inch MacBook Pro with the M6 chip is not expected to receive many of the changes listed below.

Apple last redesigned the MacBook Pro in 2021, when the M1 Pro and M1 Max models launched, so the MacBook Ultra would represent the first major redesign in at least five years and is a model that many customers are holding out for.

Below, we recap rumored MacBook Ultra features.

OLED Display

Regardless of whether Apple uses MacBook Pro or MacBook Ultra branding, it is widely expected that these will be the first MacBooks with OLED displays.

The current MacBook Pro models are equipped with LCD displays with mini-LED backlighting. The move to OLED technology would result in improved image quality, thanks to richer colors and higher contrast ratio with true blacks.

All of the iPhone, Apple Watch, and iPad Pro models that Apple sells today are already equipped with OLED displays, excluding refurbished models.

Touch Screen

Not only will the MacBook Ultra be moving to OLED, but the display will apparently have touch-screen capabilities too. This functionality would allow Mac users to use both their fingers and a keyboard and mouse/trackpad for input.

Steve Jobs said that a touch-screen Mac would cause arm fatigue, but he made that comment a long time ago, and Apple does reverse course from time to time.

Dynamic Island

Yet another display-related change rumored for the MacBook Ultra is a hole-punch camera, and this will pave the way for a Dynamic Island instead of a notch.

With a Dynamic Island, the MacBook Ultra would be another step towards a truly edge-to-edge display with thin bezels. Like on the iPhone, the Dynamic Island would display things such as low battery life alerts and AirPods connection indicators in the area surrounding the camera at the top-center part of the screen.

M6 Pro and M6 Max Chips

This one is obvious, but the MacBook Ultra is expected to be powered by Apple's next-generation M6 Pro and M6 Max chips. Notably, these chips are expected to be manufactured with TSMC's advanced 2nm process, which should result in greater year-over-year performance and efficiency gains than usual.

The current M5 Pro and M5 Max chips are built with TSMC's third-generation 3nm process.

Thinner Design

MacBook Ultra is expected to have a thinner design compared to the MacBook Pro.

The move from LCD with mini-LED backlighting to OLED would contribute to the thinner design, and there could be other changes that help to slim things down.

As of now, there has been no indication that Apple plans to once again remove ports like HDMI, MagSafe, or the SD card slot in order to achieve this thinner design, but we shall see. That was a very unpopular decision the last time it happened.

Cellular

Macs can already connect to a cellular network via the Personal Hotspot feature on a nearby iPhone or iPad, but Apple has reportedly at least considered built-in cellular connectivity for future Macs. If these plans moved forward, the MacBook Ultra would likely be equipped with Apple's C1X or future C2 modem for 5G and LTE.Related Roundup: MacBook ProTag: MacBook UltraBuyer's Guide: MacBook Pro (Buy Now)Related Forum: MacBook Pro
This article, "Apple to Launch 'MacBook Ultra' With These Six New Features" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
On this week's special episode of The MacRumors Show, we discuss Apple's bombshell announcement that Tim Cook will step down as CEO on September 1, 2026, with hardware engineering chief John Ternus set to succeed him.

Subscribe to The MacRumors Show YouTube channel for more videos
Cook will transition to executive chairman, where he will "assist with certain aspects of the company, including engaging with policymakers around the world." The transition was approved by the board and is the result of a "thoughtful, long-term succession planning process." Current board chair Arthur Levinson will become the lead independent director. Cook has served as Apple's CEO since 2011.

Ternus, who has spent nearly his entire career at Apple, will join the board ahead of assuming the CEO role. He is a product person in the mold of Steve Jobs rather than a supply chain operator like Cook, and according to Bloomberg's Mark Gurman, he is expected to take a more centralized approach to decision-making. "If you go to Tim with 'A' or 'B,' he won't pick," one person who has worked closely with both executives told Gurman. "Ternus will make decisions." Ternus will take over in time to oversee the launch of the iPhone 18 Pro models and Apple's first foldable iPhone, both expected in September.

Alongside the leadership transition, Apple said that Johny Srouji, currently SVP of Hardware Technologies, will take on an expanded role as Chief Hardware Officer, leading Hardware Engineering and reporting to Ternus. Srouji's remit will cover everything from product design to system engineering to reliability and durability testing. Cook described Srouji as having "played a singular role in driving Apple's silicon strategy" and said his influence has been felt "not just inside the company, but across the industry."

In a statement, Cook said leading Apple has been the "greatest privilege" of his life and described Ternus as "a visionary whose contributions to Apple over 25 years are already too numerous to count." Ternus said he is "filled with optimism" about what Apple can achieve in the years to come, adding that he promises to "lead with the values and vision that have come to define this special place for half a century."

The MacRumors Show has its own YouTube channel, so make sure you're subscribed to keep up with new episodes and clips.

Subscribe to The MacRumors Show YouTube channel!

You can also listen to ‌The MacRumors Show‌ on Apple Podcasts, Spotify, Overcast, or other podcast apps. You can also copy our RSS feed directly into your player.



If you haven't already listened to the previous episode of The MacRumors Show, catch up to hear our discussion about Apple's upcoming overhaul of the iPad mini and iPad Air, looking at the future of the product lineup as a whole.

Subscribe to ‌The MacRumors Show‌ for new episodes every week, where we discuss some of the topical news breaking here on MacRumors, often joined by interesting guests such as Kayci Lacob, Kevin Nether, John Gruber, Mark Gurman, Jon Prosser, Luke Miani, Matthew Cassinelli, Brian Tong, Quinn Nelson, Jared Nelson, Eli Hodapp, Mike Bell, Sara Dietschy, iJustine, Jon Rettinger, Andru Edwards, Arnold Kim, Ben Sullins, Marcus Kane, Christopher Lawley, Frank McShan, David Lewis, Tyler Stalman, Sam Kohl, Federico Viticci, Thomas Frank, Jonathan Morrison, Ross Young, Ian Zelbo, and Rene Ritchie.

‌The MacRumors Show‌ is on X @MacRumorsShow, so be sure to give us a follow to keep up with the podcast. You can also email us at [email protected] or head over to The MacRumors Show forum thread. Remember to rate and review the podcast, and let us know what subjects and guests you would like to see in the future.Tags: The MacRumors Show, Tim Cook
This article, "The MacRumors Show: Tim Cook to Step Down as Apple CEO" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
AI agents are becoming a serious topic in security operations because teams need more than static automation to keep pace with modern threats. In this blog, we explain what AI agents actually do inside the SOC, how they support autonomous SOC and agentic SOC models, and what security teams should understand before they adopt them. The goal is not to separate hype from reality with broad claims, but to show where AI agents can create operational value and where human oversight still matters most.
View the full article
It wasn't necessarily a surprise given circulating rumors, but the biggest news in the Apple world this week was the announcement that Tim Cook will be stepping down as CEO, with John Ternus taking over the reins as of September 1.


Other recent news included updated details on color options for the iPhone 18 Pro, as well as fresh rumors about the standard iPhone 18 and timing for the launch of the highly anticipated touch screen-equipped MacBook Pro and updated Mac Studio, so read on below for all the details on these stories and more!

Top Stories

Apple CEO Tim Cook Stepping Down, John Ternus Taking Over

Apple CEO Tim Cook is stepping down as chief executive officer, and hardware engineering chief John Ternus is set to take over, Apple announced this week.


Cook will continue on as Apple CEO through the summer, with Ternus set to join Apple's Board of Directors and take over as CEO on September 1, 2026. Cook is going to transition to executive chairman, and he will "assist with certain aspects of the company, including engaging with policymakers around the world."

In an all-hands meeting for Apple employees following the announcement, Cook said that he remains healthy and that he plans to stay in the executive chairman role "for a long time."

Apple's current chip chief Johny Srouji will also be taking on an expanded role as Chief Hardware Officer, adding oversight of the Hardware Engineering group that had reported to John Ternus to his existing responsibilities with Apple's Hardware Technologies group.

iPhone 18 Pro's Four Rumored Colors Revealed, Including 'Dark Cherry'

A source said to be familiar with Apple's supply chain recently revealed the color options Apple is planning for the iPhone 18 Pro and ‌iPhone 18 Pro‌ Max.


The information comes from Macworld, which says the signature new color for this year's Pro models will be Dark Cherry, a deep wine-like red. While other sources had previously reported on a "Dark Red" option, the hue is said to be considerably closer to wine than a brighter red.

According to Macworld's source, Apple has been working on four color options for the ‌iPhone 18 Pro‌ and Pro Max, with the following Pantone codes said to be in use internally:
Light Blue (Pantone 2121), resembling the current iPhone 17's Mist Blue
Dark Cherry (Pantone 6076), the headline new color
Dark Gray (Pantone 426C)
Silver (Pantone 427C), similar to the current generation

MacBook Pro With Touch Screen and New Mac Studio Likely 'Postponed'

The global memory chip shortage may result in the next MacBook Pro and Mac Studio models launching later than expected, according to the latest rumor.


Bloomberg's Mark Gurman has repeatedly stated that 14-inch and 16-inch MacBook Pro models with a touch screen are slated to launch in late 2026 to early 2027. In his Power On newsletter this week, though, he said to be prepared for the laptops to potentially arrive towards the end of that timeframe due to the chip shortage.

In other words, early 2027 is now more likely than late 2026.

Gurman previously expected a new Mac Studio to launch around the middle of 2026, which pointed towards an announcement around WWDC 2026 in June. However, in his newsletter, he wrote that sources within Apple believe that the next Mac Studio models will not ship until around October this year as a result of the shortage.

Leaker: Apple Downgrading iPhone 18 to Cut Costs

Apple is downgrading the planned specifications of the standard iPhone 18 to cut costs, a leaker claims.


In a new post on Weibo, the user known as "Fixed Focus Digital" said that the ‌iPhone 18‌ features "certain manufacturing downgrades" that bring it more into line with the low-cost iPhone 18e model. The decision is said to be "a cost-cutting measure" that will "effectively bring it in line with the '18e' model."

In follow-up posts, the leaker provided further detail indicating the iPhone 18 is likely to see downgrades to the display and main chip compared to Apple's original plans.

iOS 27 Rumored to Drop Support for These iPhone Models

iOS 27 will be compatible with the iPhone 12 series and newer, according to Instant Digital, a known Apple leaker on the Chinese social media platform Weibo.


If this rumor is accurate, iOS 27 will drop support for the following iPhone models, although they will continue to receive iOS 26 security updates for at least a few years:
iPhone 11
iPhone 11 Pro
iPhone 11 Pro Max
iPhone SE (2nd generation)

macOS 27 Will Mark the End of an Era

During its Platforms State of the Union segment at WWDC 2025, Apple revealed that macOS 26 Tahoe is the final major macOS version for Intel-based Macs.


The upcoming macOS 27 release will be compatible with Apple silicon Macs only, meaning that you will need a Mac with an M-series chip or a MacBook Neo with an A18 Pro chip in order to install the software update. macOS 27 should be available in beta starting in June, and the update will likely be widely released in September.

MacRumors Newsletter

Each week, we publish an email newsletter like this highlighting the top Apple stories, making it a great way to get a bite-sized recap of the week hitting all of the major topics we've covered and tying together related stories for a big-picture view.

So if you want to have top stories like the above recap delivered to your email inbox each week, subscribe to our newsletter!Tag: Top Stories
This article, "Top Stories: Tim Cook Stepping Down, iPhone 18 Pro Colors, and More" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
This week's best deals include lowest-ever prices on Apple Watch Series 11, M5 MacBook Air, and AirTag 1. We're also tracking some last-minute Earth Day deals on Anker accessories below.

Note: MacRumors is an affiliate partner with some of these vendors. When you click a link and make a purchase, we may receive a small payment, which helps us keep the site running.

M5 MacBook Air


What's the deal? Take $150 off M5 MacBook Air
Where can I get it? Amazon
Where can I find the original deal? Right here
$150 OFF13-inch M5 MacBook Air (16GB/1TB) for $1,149.00
$150 OFF15-inch M5 MacBook Air (512GB) for $1,149.00

Amazon has a few record low prices on the new M5 MacBook Air this week, with $150 off select models of the brand new notebook. Stock has begun dwindling on these notebooks and we're no longer tracking an all-time low price on the 512GB 13-inch M5 MacBook Air, but most other configurations have availability.

Apple Watch Series 11


What's the deal? Take $100 off Apple Watch Series 11
Where can I get it? Amazon
Where can I find the original deal? Right here
$100 OFFApple Watch Series 11 (42mm GPS) for $299.00
$100 OFFApple Watch Series 11 (46mm GPS) for $329.00

Amazon this week has all-time low prices on the Apple Watch Series 11, with $100 discounts across numerous models of the smartwatch. This sale includes many aluminum models of the Series 11 on sale at record low prices.

AirTag 1


What's the deal? Take $42 off first gen AirTag
Where can I get it? Woot
Where can I find the original deal? Right here
$42 OFFAirTag 4-Pack (1st Gen) for $56.99

Woot this week introduced a great deal on Apple's first generation AirTag 4-Pack, and it's set to last only for a few more hours. You can get this accessory for $56.99, down from $99.00, which is a match of the all-time low price on this model. The AirTag 4-Pack is in new condition and comes with a 90-day Woot limited warranty.

Anker


What's the deal? Take $42 off first gen AirTag
Where can I get it? Amazon and Anker
Where can I find the original deal? Right here
$29 OFFAnker Prime 3-in-1 Wireless Charging Station for $119.99

We began tracking a few different Earth Day-related sales from Anker this week, including events on Amazon and Anker.com. This includes a wide array of charging accessories like the new Prime 3-in-1 Wireless Charging Station for $119.99, down from $149.99.

If you're on the hunt for more discounts, be sure to visit our Apple Deals roundup where we recap the best Apple-related bargains of the past week.



Deals Newsletter

Interested in hearing more about the best deals you can find in 2026? Sign up for our Deals Newsletter and we'll keep you updated so you don't miss the biggest deals of the season!




Related Roundup: Apple Deals
This article, "Best Apple Deals of the Week: Low Prices on Apple Watch, MacBook Air, AirTag 1, and More" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Apple's new 14-inch M5 Pro MacBook Pro with 24GB RAM and 1TB SSD has hit a new all-time low price today. It's available for $1,999.00 on Amazon, down from $2,199.00.

Note: MacRumors is an affiliate partner with Amazon. When you click a link and make a purchase, we may receive a small payment, which helps us keep the site running.

This beats the previous deal we tracked on this model by about $50, and as of writing it's only available in Space Black. Amazon provides a free delivery estimate by around April 29, with earlier delivery for Prime members.

$200 OFF14-inch M5 Pro MacBook Pro (24GB/1TB) for $1,999.00

You can also get $200 off every 16-inch MacBook Pro model right now on Amazon, with the 24GB RAM/1TB M5 Pro model hitting a new all-time low price of $2,499.00, down from $2,699.00.

If you're on the hunt for more discounts, be sure to visit our Apple Deals roundup where we recap the best Apple-related bargains of the past week.



Deals Newsletter

Interested in hearing more about the best deals you can find in 2026? Sign up for our Deals Newsletter and we'll keep you updated so you don't miss the biggest deals of the season!




Related Roundup: Apple Deals
This article, "Get the 2026 MacBook Pro for New Record Low $1,999 Price" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
OpenAI has announced the release of GPT-5.5, the latest upgrade to the company's family of models powering its ChatGPT and Codex apps.


OpenAI describes GPT-5.5 as better at multi-step work, claiming it can plan, use tools, and verify its own output with less hand-holding. The model is said to offer gains in agentic coding, computer use, and early-stage scientific research.

GPT-5.5 Thinking offers "faster help for harder problems," according to OpenAI, while GPT-5.5 Pro is being pitched as a research partner for tougher questions where accuracy matters more than speed.

OpenAI argues that its latest model is more token-efficient, so Codex tasks should – in theory – finish with less overhead despite the bump.

ChatGPT Plus, Pro, Business, and Enterprise subscribers get GPT-5.5 Thinking, while the more powerful GPT-5.5 Pro model is limited to ChatGPT Pro, Business, and Enterprise. In Codex, GPT-5.5 spans Plus, Pro, Business, Enterprise, Edu, and Go plans. API access is said to be coming "very soon."Tags: ChatGPT, OpenAI
This article, "OpenAI Debuts GPT-5.5 Claiming Agentic Coding and Research Gains" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
For its 20th-anniversary iPhone, Apple is tapping Samsung to produce a custom micro-curved OLED display that is brighter and thinner than existing panels, according to new supply chain information out of China.


Apple is reportedly considering a radical redesign for the 20th-anniversary iPhone that could feature a completely bezel-less display that curves around all four edges of the device.

To that end, Apple is said to be seeking from Samsung an equal-depth quad-curved panel design that uses "micro-curves" to keep the curve very shallow, as opposed to the aggressively curved "waterfall" edges of some existing Samsung panels.

Apple's preference for slightly rounded edges may ensure that the device feels softer in the hand and that swipes from the edge of the display feel more natural. It could also prevent distortion of on-screen content around the edges.

The latest supply chain information comes from Weibo-based leaker Digital Chat Station, who also says that Apple wants a "pol-less" display from Samsung – in other words, a panel design that removes the polarizer layer that sits on top of most current OLED screens.

That claim lines up with a September 2025 report out of Korea that said Apple will adopt a Samsung-made OLED technology called COE (Color Filter on Encapsulation) to make the 20th-anniversary iPhone's display brighter and thinner than previous panels.

COE displays remove the polarizing film from an OLED panel, applying the color filter directly onto the encapsulation layer of the display.

The technique reduces the thickness of the overall display stack, and it lets more light through to improve brightness while reducing power draw. Reflections are harder to deal with when there's no polarizing film, but in its latest iPhones, Apple added a new anti-reflective coating that is expected to be improved for future versions of the iPhone.

Apple is also said to be employing a crater-shaped light diffusion layer in the display to even out the brightness so that the screen looks uniformly lit across all areas.

2027 will mark the 20th-anniversary of the iPhone, and Apple reportedly wants to create a high-end all-glass model that doesn't have cutouts in the display.

Display analyst Ross Young said that Apple won't have under-display ‌Face ID‌ ready to go for a 2027 iPhone, but other leakers think it's possible. If Apple can't get everything under the display, we may see under-display ‌Face ID‌ and then a small hole-punch cutout on the front for the front-facing camera.

The latest rumors suggest that Apple is still testing an under-display iPhone camera for 2027, so it remains a possibility.Tags: 20th-Anniversary iPhone, Digital Chat Station, OLED
This article, "20th Anniversary iPhone to Feature Custom 'Micro-Curved' OLED Panel" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Following the latest update of Apple's Invites app, hosts can now manually edit the guest list to update guest responses and adjust the number of additional guests.


This v1.8.0 update appears to have focused on delivering a more streamlined experience for managing and sharing events. Within Messages, a new Invites iMessage app allows users to quickly share an existing invite without needing to leave the conversation.

Elsewhere, the dashboard has been expanded with an All Events view, bringing both upcoming and past events into a single, unified interface. Sharing options have also been improved for hosts, who can now generate and download an image of their invite card.

Additionally, music integration has been enhanced through the Apple Music Shared Playlist feature, which now provides personalised playlist suggestions based on listening habits.

Finally, hosts can now specify a time zone for their event, and the update also contains bug fixes and performance improvements.

Apple Invites is available on the iPhone, and on the web at iCloud.com/invites. Guests can RSVP in the iPhone app, or on the web from any device.Tag: Apple Invites
This article, "Apple Invites App for iPhone Updated – Here's What's New" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
A high-severity security flaw in LMDeploy, an open-source toolkit for compressing, deploying, and serving LLMs, has come under active exploitation in the wild less than 13 hours after its public disclosure. The vulnerability, tracked as CVE-2026-33626 (CVSS score: 7.5), relates to a Server-Side Request Forgery (SSRF) vulnerability that could be exploited to access sensitive data. "A server-sideView the full article
Cybersicherheit zu messen, ist kein Kinderspiel.
Foto: Ultraskrip – shutterstock.com
Eine wichtige Säule jedes ausgereiften Cyberrisk-Programms ist die Fähigkeit, die Performance der IT-Security und registrierte Bedrohungen zu messen, zu analysieren und zu melden. Die Cybersecurity zu messen, ist allerdings kein leichtes Unterfangen: Einerseits, weil sich viele Führungskräfte ohne entsprechenden Background schwer tun, IT-Risiken zu verstehen. Andererseits verstricken sich Sicherheitsprofis auch zu oft in technische Details, die die Stakeholder verwirren und auf den falschen Weg führen.
Das ideale Szenario: Security-Experten messen und reporten die Cybersicherheit auf eine Art und Weise, die für Führungskräfte leicht verständlich und nützlich ist – was zu umsetzbaren Ergebnissen führt. Klingt gut? Dieser Artikel vermittelt Ihnen, wie Sie das anstellen.
Messkategorien der IT-Sicherheit
Die meisten Stakeholder beschäftigen Fragen zu Risiken, Compliance oder Sicherheit. Diese lassen sich jedoch in der Regel nicht mit einem einzigen Datenpunkt beantworten. Doch es gibt eine Reihe von Dingen, die Security-Profis messen können, um auf die Fragen und Bedenken der Stakeholder einzugehen. Diese lassen sich (grob) in folgende Kategorien einordnen:
Kontrollen: Maßnahmen, die ergriffen werden, um Bedrohungen abzuwehren und Risiken zu reduzieren.
Assets: Jeder Gegenstand, der für die Organisation einen Wert besitzt, beziehungsweise sich in ihrem Besitz befindet.
Vulnerabilities: Schwachstellen in einem System, die ausgenutzt werden können.
Threat Events: Von einer Bedrohung ausgelöste Ereignisse, die Assets potenziell Schaden zufügen können.
Sicherheitsvorfälle: Ereignisse, die “erfolgreich” Wirkung auf das Unternehmen entfaltet haben, etwa in Form von (System-)Ausfällen, Datenschutzverletzungen oder Cyberangriffen.
Diese Kategorien lassen sich weiter nach verschiedenen Faktoren aufschlüsseln: Zahlen, Zeit oder Kosten.
Zahlen könnten beispielsweise in Form des Prozentsatzes der ungepatchten Server gemessen werden. Eine weitere Möglichkeit: Sie messen die Zeit, die benötigt wurde, um einen Sicherheitsvorfall zu identifizieren. Schließlich könnten Kosten – zum Beispiel in Form von Wiederherstellungs- oder Ausfallkosten – Aufschluss über die finanziellen Auswirkungen von Security-Ereignissen geben.
Cybersicherheits-Metriken, -KPIs und -KRIs
Wenn Security-Profis oder -Entscheider an Business Teams berichten, sollten sie dazu möglichst relevante Messerwerte wählen. Dabei konzentrieren sich die meisten Sicherheitsteams auf Metriken, die Low-Level-Messungen bezüglich Assets, Schwachstellen und Threat Events abbilden. Auf Führungs- und Vorstandsebene sind hingegen vor allem KPIs (Key Performance Indicators) und KRIs (Key Risk Indicators) entscheidend, weil diese dazu beitragen können, spezifische Fragen in Bezug auf IT-Risiko, -Status und -Vorbereitung zu beantworten. Beispielsweise:
Sind wir sicher?
Liefern die Sicherheitsinvestitionen dem Unternehmen Mehrwert?
Erfüllen wir aus Sicherheitsperspektive alle regulatorischen Anforderungen?
Wie gut sind wir auf Ransomware- oder Supply-Chain-Angriffe vorbereitet?
Deshalb sollten sich Security-Praktiker auch auf KPIs und KRIs konzentrieren.


Sie wollen weitere interessante Beiträge rund um das Thema IT-Sicherheit lesen? Unser kostenloser Newsletter liefert Ihnen alles, was Sicherheitsentscheider und -experten wissen sollten, direkt in Ihre Inbox.
Jetzt CSO-Newsletter sichern
Cybersecurity messen in 5 Schritten
Der Aufbau des richtigen Messrahmens ist ein schrittweiser, iterativer Prozess. Im Folgenden die fünf wichtigsten Schritte, um einen Security Measurement Cycle aufzubauen.
1. Anforderungen definieren
Sprechen Sie mit relevanten Stakeholdern, um deren Bedürfnisse zu definieren und zu verstehen. Diese haben zu diesem Zeitpunkt möglicherweise noch kein umfassendes Verständnis über IT-Risiken – oder ihre eigenen Anforderungen. Deshalb ist für Security-Praktiker ein Bottom-Up-Ansatz empfehlenswert, bei dem sie selbst die Initiative ergreifen und Fragen zu stellen, um die Anforderungen definieren zu können.
2. Key Indicators auswählen
Sobald die Anforderungen der Stakeholder definiert sind, sollten Sicherheitsexperten diejenigen Key Indicators auswählen, die auf diese einzahlen. Dabei sollten die Stakeholder konsultiert und über die beabsichtigten, späteren Messungen informiert werden.
Wenn die Stakeholder die Key Indicators kennen, können sie Maßnahmen ergreifen oder Entscheidungen treffen. Die Schlüsselindikatoren sollten auf hoher Ebene angesiedelt sein – und ihre Anzahl überschaubar bleiben. Das Ziel besteht schließlich darin, die Entscheidungsfindung zu erleichtern.
3. Metriken identifizieren
Nachdem Ziele und Key Indicators festgelegt sind, gilt es für die Sicherheitsteams, die Low-Level-Messgrößen zu fokussieren, die dabei unterstützen, die Indikatoren zu reporten. Das kann – je nach Art des Indikators – bedeuten, dass Dutzende von Metriken aus den verschiedenen oben beschriebenen Messkategorien erforderlich sind.
4. Metriken sammeln und analysieren
Da die Anforderungen nun feststehen, die Schlüsselindikatoren ausgewählt und die Messgrößen festgelegt sind, können die Praktiker nun damit beginnen, Daten auf dieser Grundlage zu sammeln und zu analysieren. Metriken dürfen dabei nur aus Daten abgeleitet werden, die akkurat, aktuell, relevant und vertrauenswürdig sind. Anderenfalls kann es zu Entscheidungen kommen, die schwerwiegende Folgen für die Sicherheitslage des Unternehmens nach sich ziehen.
Es ist die Aufgabe der Security-Teams, Wege zu finden, Daten kontinuierlich zu sammeln (die meisten Messungen erfordern einen Überblick über Trends im Zeitverlauf) und den Prozess vorzugsweise so weit wie möglich zu automatisieren (ein manueller Prozess kann ermüdend und zeitaufwändig sein).
5. Key Indicators reporten
Key Indicators müssen zeitnah an die Entscheidungsträger reported werden. Dabei sollten sich Security-Profis und Stakeholder auf einen zeitlichen Rhythmus einigen – ebenso wie über die Art der Berichterstattung: Sind Dashboards erforderlich oder reichen Powerpoint-Präsentationen aus? Die Schlüsselindikatoren sollten deutlich sichtbar und leicht verständlich sein, um zu Entscheidungen oder Maßnahmen zu führen.
Darüber hinaus ist es wichtig, nach jedem Berichtszyklus die Key Indicators zu überprüfen und sie (unter Einbeziehung der Stakeholder) neu zu bewerten. Haben sich die geschäftlichen Anforderungen tatsächlich geändert, müssen die Anforderungen erneut definiert und ein anderer Satz von Indikatoren und Messgrößen erarbeitet werden.
Unternehmen, Stakeholder und Sicherheitsexperten sollten keine Angst vor Rückwärts- oder Vorwärtsschritten haben: Die Fähigkeit, nach einem schnellen Fail direkt weiterzumachen, zu improvisieren oder sich neu auszurichten sind entscheidende Fähigkeiten, wenn es darum geht, Cybersicherheit erfolgreich zu messen. (fm)


Dieser Beitrag basiert auf einem Artikel unserer US-Schwesterpublikation CSO Online.
View the full article
Researchers warn of a new software supply chain attack that resulted in a malicious version of Bitwarden CLI, the terminal version of the extremely popular open-source password manager. The attack is believed to be related to the string of recent supply chain compromises attributed to a group called TeamPCP.
“The attack appears to have leveraged a compromised GitHub Action in Bitwarden’s CI/CD pipeline, consistent with the pattern seen across other affected repositories in this campaign,” researchers from security firm Socket.dev said in a report.
The attackers managed to publish a malicious Bitwarden CLI version 2026.4.0 on the npm registry. The version did not have a corresponding official release on the project’s GitHub repository and was detected and deleted in around 1.5 hours, between 5:57 PM and 7:30 PM ET on April 22.
“The investigation found no evidence that end user vault data was accessed or at risk, or that production data or production systems were compromised,” Bitwarden said in a statement on its community forums. “Once the issue was detected, compromised access was revoked, the malicious npm release was deprecated, and remediation steps were initiated immediately.”
The attack appears to be related to the recent supply chain compromise that impacted the Docker images and VS Code extensions of the KICS infrastructure-as-code vulnerability scanner from security firm Checkmarx. The group alleged to be involved, TeamPCP, has been responsible for a wave of supply chain attacks that have impacted open-source projects in recent months, including the Trivy security scanner.
Luckily the new attack only impacted the CLI version of Bitwarden and not the much more widely used web browser extension and other client applications. Bitwarden is estimated to have over 10 million users, including 50,000 business customers.
Attackers target cloud and development credentials
The trojanized Bitwarden CLI version 2026.4.0 contained a custom loader called bw_setup.js that checks if the bun package manager is installed and then uses it to execute bw1.js. If bun doesn’t exist, it is downloaded and installed from GitHub.
According to an analysis by security firm JFrog, the malicious payload is designed to detect and collect a board range of credentials and access tokens from the filesystem, shell environment variables, and GitHub actions configurations. Targeted credentials include GitHub and npm tokens, AWS and GCP credentials, API keys from MCP and AI agent configurations, Git credentials, SSH keys, and more.
If GitHub tokens are found, the malicious code automatically weaponizes them by contacting https://api.github.com/user and trying several escalation paths, including executing GitHub Actions and listing secrets from their workflows.
“This is not passive credential theft,” the JFrog researchers said. “It is a secondary access mechanism built to extract more secret material from GitHub-hosted automation environments.”
Remediation
Users who determined that their Bitwarden CLI installation was updated to the malicious 2026.4.0 version should assume developer and cloud credentials present on their machine have been compromised and should be rotated immediately. The goal of this attacker group is to gather credentials that would enable additional software supply chain attacks.
After uninstalling the malicious version, clearing the npm cache, deleting bw1.js and bw_setup.js from the system, the JFrog researchers recommend:
Revoking all GitHub PATs present on affected systems Rotating npm tokens and invalidating CI publishing tokens Rotating AWS access keys and reviewing access to SSM and Secrets Manager Reviewing Azure Key Vault audit logs and rotating affected secrets Reviewing GCP Secret Manager access logs and rotating affected secrets Inspecting GitHub Actions workflows and repository artifacts for unauthorized runs or branches Reviewing shell history and AI tooling configuration files for sensitive data leakage Blocking audit[.]checkmarx[.]cx and 94[.]154[.]172[.]43 at network egress points Enforcing npm script controls where possible, including ignore-scripts for untrusted installs View the full article
Why “more alerts” isn’t the same as better security
If you run security in an enterprise environment, you already know the problem. Generic detection tools generate thousands of alerts, most of them low value. Analysts spend hours chasing noise while attackers quietly move laterally using valid credentials and trusted tools.
AI‑driven threat detection promises to fix this, but not every “AI‑powered” platform actually delivers at enterprise scale. Real cyber resilience depends on something much simpler and harder to get right: detecting threats faster, containing them sooner, and reducing the operational impact when something slips through.
Here are three practical ways AI threat detection helps make that happen.
1. AI detection reduces noise so teams can focus on real threats
Traditional, rule‑based detection only catches what it already knows. That works for known malware and predictable attacks, but it breaks down when attackers use stolen credentials, PowerShell, or built‑in admin tools. Nothing looks obviously malicious, so alerts either never fire or fire constantly without context.
AI‑driven detection flips the model. Instead of matching signatures, it builds behavioral baselines for users, endpoints, identities, and cloud workloads, then flags deviations that don’t fit normal patterns.
At enterprise scale, this matters because:
Legitimate admin activity and malicious behavior often look similar without context Hybrid environments generate fragmented telemetry that rule sets can’t correlate Lean teams don’t have time to manually connect the dots across systems Platforms like Adlumin MDR™ apply behavioral models and automated triage to suppress low‑value alerts and elevate incidents that actually matter. Fewer alerts, better context, and clearer prioritization reduce analyst fatigue and improve detection speed.
From a resilience standpoint, this is the first win: faster detection means attackers have less time to move, escalate privileges, or reach critical systems.
2. Correlation and automated triage limit blast radius during an attack
Most serious incidents aren’t a single event. They’re a chain of small actions that only look dangerous when viewed together.
A failed login by itself is noise. Pair that login with unusual file access, an unexpected VPN session, and a new process on a server, and suddenly you have an incident worth acting on.
AI‑driven detection at enterprise scale depends on cross‑telemetry correlation, pulling signals together from endpoints, identity providers, networks, and cloud services before analysts ever see an alert. This turns weak signals into actionable incidents.
Automated triage takes it a step further by:
Enriching alerts with investigative context Suppressing routine activity automatically Triggering response playbooks when risk crosses a defined threshold That automation is critical when attacks start moving quickly. Containing threats early reduces lateral movement and keeps incidents from turning into business‑level disruptions.
This is where MDR really enables cyber resilience. It is not just about detection. It is about shrinking the window between intrusion and containment.
3. AI detection works best as part of a before‑during‑after resilience model
Detection alone does not equal resilience. Enterprise environments need coverage before, during, and after an attack.
A practical framework looks like this:
Before an attack: Reduce exposure with patching, vulnerability management, endpoint hardening, and DNS filtering. Tools like N-central UEM™ help close common entry points before attackers exploit them. During an attack: Detect and contain threats with AI‑driven MDR. Behavioral detection, correlation, and automated response limit blast radius when prevention fails. After an attack: Recover quickly and confidently. Cove Data Protection™ supports resilience with isolated cloud backups, flexible recovery options, and ransomware rollback when downtime matters most. AI threat detection sits squarely in the “during” phase, but its real value shows up when it is integrated with prevention and recovery. That handoff is where point solutions usually fail and where platform approaches hold up under pressure.
AI detection has to fit the enterprise you actually run
AI threat detection fails when it is bolted onto architectures designed for simpler environments. It works when behavioral detection, correlation, automation, and human expertise operate together as a system built for scale, segmentation, and lean teams.
For IT security leaders, the takeaway is practical: cyber resilience improves when detection reduces noise, response happens faster, and recovery is ready when needed. MDR enables that by changing how quickly teams can see and stop what matters.
Discover what 500+ midmarket leaders are experiencing as AI reshapes the threat landscape in the Futurum research report: Cybersecurity in the Age of AI: Moving from Fragile to Resilient.
View the full article
Donald Trump’s nominee to lead the Cybersecurity and Infrastructure Security Agency (CISA), Sean Plankey, informed Homeland Security Secretary Markwayne Mullin and the White House that he is withdrawing his nomination after a 13-month stall, during which the well-regarded cybersecurity veteran faced mounting resistance.
“After thirteen months since my initial nomination, it has become clear the Senate will not confirm me,” he wrote in a letter sent to the White House, according to Politico.
Plankey was nominated by Trump last March but failed to be confirmed by the end of 2025. He was renominated in January, only to face resistance to his confirmation. While he waited for his CISA confirmation, he worked for then-DHS Secretary Kristi Noem on Coast Guard issues, retiring from the Coast Guard last month.
The administration’s failure to confirm Plankey comes amid great turmoil at the nation’s cybersecurity agency, which has suffered severe staff reductions and budget cuts since the start of Trump’s current administration, capped by the sudden departure of CISA’s acting director, Madhu Gottumukkala, in February, who was moved into a position at DHS following revelations of embarrassing security missteps he made during his short tenure.
Policy experts say this turmoil is not simply bureaucratic drift — it weakens US cybersecurity at a dangerous moment, inviting foreign adversaries to exploit the aimlessness of an agency that is crucial to national security. “It’s hard for an agency to go this long without confirmed leadership,” Michael Daniel, president and CEO of the Cyber Threat Alliance (CTA), told CSO. “That’s not a good place for the country to be.”
Problems on the Senate side
Although neither Plankey nor the White House has clearly stated why his nomination stalled, a series of poorly sourced allegations and reported behind-the-scenes maneuvering over the past few months indicate that adversaries to Plankey’s confirmation were working to derail his leadership of the agency.
On the surface, two Senators vowed to stop Plankey’s CISA confirmation. Sen. Rick Scott (R-FL) blocked Plankey’s nomination due to a Coast Guard issue. At the same time, Sen. Ron Wyden (D-OR) held up Plankey’s nomination to force CISA to release an unclassified report on telephone network security.
A knowledgeable source told CSO they heard on the “backchannel” that someone on the Senate side called on US Representative Hillary Scholten (D-MI) to send a March 24 letter to DHS Inspector General Joseph Cuffari to investigate Plankey’s connection to a government contracting firm, alleging that he failed to cut his financial ties with the firm before his CISA nomination.
However, the CEO of that firm told CSO he was blindsided by Scholten’s letter and that Plankey had forfeited all financial interest in the company prior to the announcement of his CISA nomination. The CEO told CSO he sent a letter to the Coast Guard detailing the facts after Scholten — who he said never contacted his company — sent her letter to DHS.
CSO contacted Scholten’s office multiple times seeking comment, but received no response. CSO also received no response to the questions surrounding this letter from either DHS or CISA. CSO made efforts to reach Plankey for comment, but yielded no response.
Questions over who wanted Plankey blocked
On March 3, Ana Visneski, a former head of global disaster response at Amazon Web Services and former chief of digital media for the US Coast Guard, posted on Bluesky that she was “hearing from multiple sources” that Plankey “has been fired and escorted out of Coast Guard HQ by security,” a post that was picked up by at least one influential military analyst. Visneski did not respond to CSO’s request for comment.
Following Visneski’s social media post, CBS News published a report repeating the allegation, saying that Plankey was abruptly escorted out of the US Coast Guard headquarters and had his access badge removed. CBS News also reported that sources said Plankey’s renomination was made in error, which the White House denied.
The CBS report also highlights longstanding tensions between Plankey and Madhu Gottumukkala over cybersecurity contracts. Gottumukkala had been former DHS Secretary Kristi Noem’s CIO in North Dakota, and Plankey, by all accounts, had an excellent relationship with Noem while at DHS.
Two sources told CSO that it was highly unlikely that Plankey was fired because he received a Coast Guard award days after he was supposedly escorted out of the building, and, moreover, he was still the CISA nominee at that point, an unlikely status if he had indeed been fired.
A weak agency in the middle of a hot war
Whatever harm may have been done to Plankey, it is certain that the lack of leadership at CISA risks damage to the nation’s security, particularly in the middle of the Iran war.
“Cybersecurity is not just a law enforcement or an economic issue,” CTA’s Daniel said. “It’s both of those things, but it is also a national security issue. And we are in a position now where we have started a hot war, a kinetic war.”
He added, “One of the tools that Iran has at its disposal is its cyber capabilities, and it would be foolish of anyone to think that Iran would not at least consider targeting US critical infrastructure because of that ongoing conflict. You have left your nation’s cyber defense agency, which is responsible for working with critical infrastructure across the whole country, leaderless when you’re in an active hot conflict. So that seems like a problem to me.”
Just how long CISA will be leaderless is unclear. One thing that is clear is that Plankey will support whoever does become the next CISA leader.
“While I humbly request the removal of my nomination, I wholeheartedly support President Trump’s upcoming nomination for CISA and look forward to the continued success of the United States of America,” Plankey told the White House.
In the end, the story may be less about Sean Plankey than about what happens when Washington treats cybersecurity leadership as expendable. Leaving the nation’s primary cyber defense agency weakened, underfunded, and without confirmed leadership is not simply a personnel problem — it is a national security risk.
View the full article
Donald Trump’s nominee to lead the Cybersecurity and Infrastructure Security Agency (CISA), Sean Plankey, informed Homeland Security Secretary Markwayne Mullin and the White House that he is withdrawing his nomination after a 13-month stall, during which the well-regarded cybersecurity veteran faced mounting resistance.
“After thirteen months since my initial nomination, it has become clear the Senate will not confirm me,” he wrote in a letter sent to the White House, according to Politico.
Plankey was nominated by Trump last March but failed to be confirmed by the end of 2025. He was renominated in January, only to face resistance to his confirmation. While he waited for his CISA confirmation, he worked for then-DHS Secretary Kristi Noem on Coast Guard issues, retiring from the Coast Guard last month.
The administration’s failure to confirm Plankey comes amid great turmoil at the nation’s cybersecurity agency, which has suffered severe staff reductions and budget cuts since the start of Trump’s current administration, capped by the sudden departure of CISA’s acting director, Madhu Gottumukkala, in February, who was moved into a position at DHS following revelations of embarrassing security missteps he made during his short tenure.
Policy experts say this turmoil is not simply bureaucratic drift — it weakens US cybersecurity at a dangerous moment, inviting foreign adversaries to exploit the aimlessness of an agency that is crucial to national security. “It’s hard for an agency to go this long without confirmed leadership,” Michael Daniel, president and CEO of the Cyber Threat Alliance (CTA), told CSO. “That’s not a good place for the country to be.”
Problems on the Senate side
Although neither Plankey nor the White House has clearly stated why his nomination stalled, a series of poorly sourced allegations and reported behind-the-scenes maneuvering over the past few months indicate that adversaries to Plankey’s confirmation were working to derail his leadership of the agency.
On the surface, two Senators vowed to stop Plankey’s CISA confirmation. Sen. Rick Scott (R-FL) blocked Plankey’s nomination due to a Coast Guard issue. At the same time, Sen. Ron Wyden (D-OR) held up Plankey’s nomination to force CISA to release an unclassified report on telephone network security.
A knowledgeable source told CSO they heard on the “backchannel” that someone on the Senate side called on US Representative Hillary Scholten (D-MI) to send a March 24 letter to DHS Inspector General Joseph Cuffari to investigate Plankey’s connection to a government contracting firm, alleging that he failed to cut his financial ties with the firm before his CISA nomination.
However, the CEO of that firm told CSO he was blindsided by Scholten’s letter and that Plankey had forfeited all financial interest in the company prior to the announcement of his CISA nomination. The CEO told CSO he sent a letter to the Coast Guard detailing the facts after Scholten — who he said never contacted his company — sent her letter to DHS.
CSO contacted Scholten’s office multiple times seeking comment, but received no response. CSO also received no response to the questions surrounding this letter from either DHS or CISA. CSO made efforts to reach Plankey for comment, but yielded no response.
Questions over who wanted Plankey blocked
On March 3, Ana Visneski, a former head of global disaster response at Amazon Web Services and former chief of digital media for the US Coast Guard, posted on Bluesky that she was “hearing from multiple sources” that Plankey “has been fired and escorted out of Coast Guard HQ by security,” a post that was picked up by at least one influential military analyst. Visneski did not respond to CSO’s request for comment.
Following Visneski’s social media post, CBS News published a report repeating the allegation, saying that Plankey was abruptly escorted out of the US Coast Guard headquarters and had his access badge removed. CBS News also reported that sources said Plankey’s renomination was made in error, which the White House denied.
The CBS report also highlights longstanding tensions between Plankey and Madhu Gottumukkala over cybersecurity contracts. Gottumukkala had been former DHS Secretary Kristi Noem’s CIO in South Dakota, and Plankey, by all accounts, had an excellent relationship with Noem while at DHS.
Two sources told CSO that it was highly unlikely that Plankey was fired because he received a Coast Guard award days after he was supposedly escorted out of the building, and, moreover, he was still the CISA nominee at that point, an unlikely status if he had indeed been fired.
A weak agency in the middle of a hot war
Whatever harm may have been done to Plankey, it is certain that the lack of leadership at CISA risks damage to the nation’s security, particularly in the middle of the Iran war.
“Cybersecurity is not just a law enforcement or an economic issue,” CTA’s Daniel said. “It’s both of those things, but it is also a national security issue. And we are in a position now where we have started a hot war, a kinetic war.”
He added, “One of the tools that Iran has at its disposal is its cyber capabilities, and it would be foolish of anyone to think that Iran would not at least consider targeting US critical infrastructure because of that ongoing conflict. You have left your nation’s cyber defense agency, which is responsible for working with critical infrastructure across the whole country, leaderless when you’re in an active hot conflict. So that seems like a problem to me.”
Just how long CISA will be leaderless is unclear. One thing that is clear is that Plankey will support whoever does become the next CISA leader.
“While I humbly request the removal of my nomination, I wholeheartedly support President Trump’s upcoming nomination for CISA and look forward to the continued success of the United States of America,” Plankey told the White House.
In the end, the story may be less about Sean Plankey than about what happens when Washington treats cybersecurity leadership as expendable. Leaving the nation’s primary cyber defense agency weakened, underfunded, and without confirmed leadership is not simply a personnel problem — it is a national security risk.
View the full article
There are a lot of folks waiting for a new version of the Apple TV because the set-top box hasn't been updated since 2022. There is an update coming this year, but people will need to wait a bit longer because Apple is holding the next ‌Apple TV‌ until the new version of Siri comes out this fall.


Design

‌Apple TV‌ design updates don't happen often, and that's not changing in 2026. The next ‌Apple TV‌ is going to have the same squircle shape as the current model, and it'll continue to be made from a black plastic material.

We're expecting the 2026 ‌Apple TV‌ to be indistinguishable from the existing ‌Apple TV‌ on the exterior, with no changes to size or design.

New Chip

The ‌Apple TV‌ 4K is going to get a new A-series chip, and that'll be the biggest upgrade. Rumors suggest Apple is planning to use the A17 Pro that was first introduced in the iPhone 15 Pro models.

Compared to the A15 Bionic in the current ‌Apple TV‌, the A17 Pro is a solid update, and it's a good reason to hold off on buying the current model. The A17 Pro is built on a 3-nanometer process for faster speeds and better efficiency, and it has hardware-accelerated ray tracing for higher-quality graphics in games.

The A17 Pro is the oldest chip Apple makes that supports Apple Intelligence, and it's also used in the iPad mini 7.

Given that Apple has held the ‌Apple TV‌ update for so long, it's possible it'll get an even newer chip like the A18 or A19. A RAM update is possible too, especially if the ‌Apple TV‌ has any kind of ‌Apple Intelligence‌ support.

Apple Intelligence and Siri

The next ‌Apple TV‌ is ready to launch, but new ‌Siri‌ features are the holdup. Apple wants to release the ‌Apple TV‌ with the smarter version of ‌Siri‌ that's in the works, and it's not ready to go.

Bloomberg's Mark Gurman says the Apple TV is linked to "new artificial intelligence features" that Apple has postponed until iOS 27, which is coming in September 2026. Apple intended to launch the ‌Apple Intelligence‌ ‌Siri‌ features in spring 2026, but the company was still experiencing issues with ‌Siri‌. At this point, we're not going to see new ‌Siri‌ capabilities until iOS 27, which also means a delay for all the devices that Apple is holding.

Along with the ‌Apple TV‌, the rumored home hub and a new version of the HomePod are waiting on ‌Siri‌.

Updated ‌Siri‌ features may require more RAM and a faster chip, so if you want the smarter ‌Siri‌ on the ‌Apple TV‌, that's another reason to wait before making a purchase.

Wi-Fi

The ‌Apple TV‌ could get Apple's N1 networking chip with Wi-Fi 7 support. Wi-Fi 7 works with the 6GHz band offered by newer routers.

6GHz connectivity is faster and less congested, which you want for a device designed for streaming content.
Bluetooth and Thread

The ‌Apple TV‌ 4K could get Bluetooth 6 for connecting devices like controllers and earbuds.

Apple's N1 chip also supports Thread, so the ‌Apple TV‌ will be able to continue to serve as a Thread border router and a Matter hub for smart home devices.

Pricing

There have been rumors of a price drop, so it's possible Apple has plans for a cheaper ‌Apple TV‌.

Apple could release two models, one that's higher-end and one that has lower specs and a lower price tag, or it could keep the existing ‌Apple TV‌ around as a low-cost option.

Launch Date

Since the new version of ‌Siri‌ has been pushed to ‌iOS 27‌ and the ‌Apple TV‌ is tied to that update, we're likely not going to see the ‌Apple TV‌ refreshed until September 2026 at the earliest.Related Roundup: Apple TVBuyer's Guide: Apple TV (Don't Buy)Related Forum: Apple TV and Home Theater
This article, "Here's What's Coming in the 2026 Apple TV" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Apple has published a new ad to appeal to customers in the market for an iPhone and Apple Watch pairing, highlighting the insights it can offer for your health.


Titled simply "Health with iPhone + Apple Watch," the half-minute ad focuses on a woman waiting in line at a cafe who begins receiving unsolicited health and fitness advice from other people in the queue, as well as local residents, drivers, and passersby – and even accompanying pets.

An Apple Watch notification about her new cardio fitness trend cuts through the cacophony, and she subsequently looks into the Health app on iPhone to learn that her cardio fitness is above average. "Listen to your body. Not everybody," says the onscreen slogan, as she grabs her coffee and goes about her day. The YouTube blurb reads:Apple Watch Cardio Fitness determines cardiorespiratory fitness as measured by VO2 max. VO2 max is the maximum amount of oxygen that the body is able to use during exercise, and it can be improved through physical activity. Apple introduced the feature in 2020.

Cardio Fitness is a category in the Health app on iPhone, and fitness level is classified as high, above average, below average, or low relative to people in your same age group and of the same sex. Users can also track how their cardio fitness levels have changed over the past week, month, six months, or year, and if fitness levels fall into the low range, they can get a notification on Apple Watch that includes guidance on improving it.Related Roundup: Apple Watch 11Tag: Apple AdsBuyer's Guide: Apple Watch (Neutral)
This article, "New Apple Ad Sells the iPhone and Apple Watch Health Pairing" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Apple's entire entry-level product lineup now costs less than a single 16-inch MacBook Pro with the M5 Pro chip.


The ten products that now define Apple's lowest-cost tier are as follows:


iPhone 17e: $599
MacBook Neo: $599
iPad (11th generation): $349
Magic Keyboard Folio: $249
Apple Pencil (USB-C): $79
Apple Watch SE 3: $249
AirPods 4: $129
Apple TV 4K: $129
HomePod mini: $99
AirTag: $29


The total comes to $2,510, which is $189 less than the $2,699 starting price of the 16-inch ‌MacBook Pro‌ with the M5 Pro chip. AppleCare One, which can cover any three Apple devices of the buyer's choosing, costs an additional $19.99 per month.

The MacBook Neo, announced on March 4, is the linchpin of the shift. At $599, it is Apple's most affordable laptop ever and the first Mac to contain an A-series chip, using the A18 Pro that debuted in the iPhone 16 Pro. After its March 11 launch, Apple CEO Tim Cook said Apple saw its "best launch week ever for first-time Mac customers."

The iPhone 17e and MacBook Neo, both at $599, anchor the lineup at an identical price point that would have seemed implausible just two years ago, when the cheapest Mac laptop cost $999.

What is striking about today's lineup is how capable most of Apple's entry-level products have become relative to their more expensive siblings. The iPhone 17e uses the same A19 chip and 48-megapixel main camera as the $799 iPhone 17, differing meaningfully only in its slightly smaller 60Hz display, single rear camera, and notch design. The ‌MacBook Neo‌'s A18 Pro chip posts a single-core score of 3,461, within 6% of the M5 MacBook Air, and is highly capable for everyday tasks. The Apple Watch SE 3 shares the same S10 chip as the $399 Series 11 and, with its last refresh, gained an always-on display, sleep apnea detection, body temperature sensing, and fast charging. The notable exception in the lineup is the entry-level iPad, which is the only current Apple device that does not support Apple Intelligence.

It is also notable that three of the eleven products on the list are also due for imminent replacements. The 12th generation ‌iPad‌ with an A18 chip and Apple Intelligence support is said to be "ready to go" and "still coming this year." The next Apple TV and HomePod mini are expected to gain faster chips, along with Apple's N1 chip for Wi-Fi 7 and Thread support. All three devices have reportedly been ready for release since last year, primarily held up by the delayed arrival of a more capable version of Siri.

Overall, Apple's entry-level lineup arguably never seems to have been stronger or more affordable.Related Roundup: MacBook ProBuyer's Guide: MacBook Pro (Buy Now)Related Forum: MacBook Pro
This article, "A Full Apple Ecosystem Now Costs Less Than a MacBook Pro" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Catching the KICS push: what happened, and the case for open, fast collaboration
In the past few weeks we’ve worked through two supply chain compromises on Docker Hub with a similar shape: first Trivy, now Checkmarx KICS. In both cases, stolen publisher credentials were used to push malicious images through legitimate publishing flows. In both cases, Docker’s infrastructure was not breached. And in both cases, the software supply chain of everyone who pulled the compromised tags was briefly exposed.
This is our account of what happened with KICS, what affected users should do, and what the pattern says about where defenders need to invest.
What happened
On April 22, 2026 at approximately 12:35 UTC, a threat actor authenticated to Docker Hub using valid Checkmarx publisher credentials and pushed malicious images to the checkmarx/kics repository. Five existing tags were overwritten to malicious digests (latest, v2.1.20, v2.1.20-debian, alpine, debian) and two new tags (v2.1.21, v2.1.21-debian) were created. The images were built from an attacker-controlled source repository, not from Checkmarx’s.
The poisoned binary kept the legitimate scanning surface intact and added a quiet exfiltration path. Scan output was collected, encrypted, and sent to attacker-controlled infrastructure at audit.checkmarx[.]cx, with the User-Agent KICS-Telemetry/2.0. Because KICS scans Terraform, CloudFormation, Kubernetes and similar configuration files, its output routinely contains secrets, credentials, cloud resource names, and internal topology. 
Affected malicious digests (any one of these in your pull history should be treated as malicious):
For alpine, v2.1.20, v2.1.21 -> Index manifest digest: sha256:2588a44890263a8185bd5d9fadb6bc9220b60245dbcbc4da35e1b62a6f8c230d Image digest (amd64): sha256:d186161ae8e33cd7702dd2a6c0337deb14e2b178542d232129c0da64b1af06e4 Image digest (arm64): sha256:415610a42c5b51347709e315f5efb6fffa588b6ebc1b95b24abf28088347791b For debian, v2.1.20-debian, v2.1.21-debian -> Index manifest digest: sha256:222e6bfed0f3bb1937bf5e719a2342871ccd683ff1c0cb967c8e31ea58beaf7b Image digest (amd64): sha256:a6871deb0480e1205c1daff10cedf4e60ad951605fd1a4efaca0a9c54d56d1cb Image digest (arm64): sha256:ff7b0f114f87c67402dfc2459bb3d8954dd88e537b0e459482c04cffa26c1f07 For latest -> Index manifest digest: sha256:a0d9366f6f0166dcbf92fcdc98e1a03d2e6210e8d7e8573f74d50849130651a0 Image digest (amd64): sha256:26e8e9c5e53c972997a278ca6e12708b8788b70575ca013fd30bfda34ab5f48f Image digest (arm64): sha256:7391b531a07fccbbeaf59a488e1376cfe5b27aef757430a36d6d3a087c610322 If your CI ran kics against any repository with credentials in scope during the exposure window, rotate those credentials now. Re-pull checkmarx/kics by digest, not tag, and pin your CI to the digest so a future overwrite cannot silently affect you again. Purge the malicious digests from local caches, CI runners, pull-through registries, and mirrors: a clean pull won’t remove what’s already been cached. Check egress logs for connections to audit.checkmarx[.]cx, or outbound traffic with the KICS-Telemetry/2.0 User-Agent, which are strong indicators that exfiltration occurred on your infrastructure.
The affected digests are disabled, the repository has been restored to its last known-good state, and pulls of checkmarx/kics today return the legitimate March 3, 2026 image. The publisher account used to push the malicious images has been suspended, and we’ve notified the small number of users our telemetry shows pulled the compromised digests.
Socket’s technical analysis of the issue is here. Their post also covers what appears to be a broader Checkmarx compromise, including recent VS Code extension releases, which is worth reading if your developers use those extensions.
How we caught this breach
Within about half an hour of the push, a new image on a repository we monitor triggered a review. A check against the upstream source found no matching release, and the provenance showed the image had been built from a different source repository created one day before the push. That was enough to quarantine the repository and start forensics with Socket and Checkmarx.
The defense is in correlation, not any single signal. In this episode, we found a new tag without an upstream release, provenance from an unfamiliar source, and a timing pattern that did not appear to match normal publishing behavior. Since we happened to see these signals together, they bought us a narrow window in which to act. It has to be noted that layered defense shortens the window between push and takedown, it does not prevent the push.
The bar for this kind of attack has collapsed
The uncomfortable thing about this incident, and Trivy before it, is how little sophistication incidents such as these require these days. A stolen credential from an IDE extension compromise, a target chosen from a public profile, a push through the normal publishing flow, and the attacker is inside the software supply chain of every organization that pulls that tag. Our assumption is this attack did not require any zero-days, novel tradecraft, or nation-state level budgets. The ingredients are stolen credentials and time, and both are abundant right now.
Every registry, every package manager, and every publisher of any consequence is in the firing line, including Docker. This isn’t a Checkmarx problem or a Hub problem or an npm problem. It’s the new baseline, and defenders who aren’t planning for it as the default case are already behind.
There are two implications for our ecosystem.
Credential hygiene at the publishing boundary matters more than it used to: fine-grained tokens scoped to a single registry, shorter credential lifetimes, clean separation between personal and publisher identities.
And that no single layer will catch all of this. Publishing-time verification, provenance, signatures, registry-side monitoring, deep package inspection (the kind Socket does to catch malicious behavior in dependencies), runtime egress controls, and cross-registry signal correlation each have to do some of the work, because any of them alone will miss cases the others catch.
A note on where this is structurally harder
In the Docker Hardened Images catalog, images are built by Docker from source, with verified provenance and signed releases produced through a hardened build pipeline. The class of attack described above, where a valid publisher credential pushes a tag that diverges from its upstream source, is structurally much harder to execute against an image built this way. There is no external credential that can substitute its way in; the provenance and the signatures have to match, or the image doesn’t ship. The DHI catalog is expanding, and we’re investing in this layer precisely because of the scenario and reasons explored in this blog. 
No one catches this alone
The reason this incident got caught quickly, the reason Socket was able to produce a technical analysis within hours, and the reason Checkmarx’s response could move in parallel with ours, is that all three teams shared signals and samples in real time. The Trivy response looked the same, as did the rapid notification to GitHub about the attacker-controlled source repository.
This is the posture the ecosystem needs more of, not less. Supply chain attackers are routing  across registries, IDE marketplaces, source hosts, and CI systems in hours. Defenders who don’t share signals across those same boundaries are operating from a point of disadvantage.  Formal standards for cross-registry coordination are still emerging, and they will matter eventually. What’s kept the windows short so far has been teams working with a spirit of openness, willingly sharing what they’re discovering, in real time.
Docker will keep investing in layered defenses on Hub, keep extending publishing-time verification to more of the catalog, and keep showing up to share signals, whether this is across a partner’s incident channel, a peer registry’s investigation, or the rooms where a more durable framework for coordination eventually takes shape.
We want to thank the Socket research team for fast, independent analysis, and to Checkmarx for moving alongside us on a tight timeline for this one.
Further reading
Socket blog: https://socket.dev/blog/checkmarx-supply-chain-compromise
Docker Hardened Images on Docker Hub: https://hub.docker.com/hardened-images/catalog

View the full article
The interest rate on Apple Card's savings account was today lowered from 3.65% to 3.50%.


Push notifications regarding the cut were sent to ‌Apple Card‌ users on Thursday. Savings account interest rates often fluctuate with changes made by the Federal Reserve, and when rates are lowered, banks cut their annual percentage yield (APY). That said, today's cut doesn't appear tied to a specific Federal Reserve move.

Apple introduced its savings account in April 2023, partnering with Goldman Sachs. Designed for ‌Apple Card‌ holders, the account is exclusively available to U.S. residents aged 18 and above. It can be managed through the iPhone's Wallet app, offering a user-friendly experience with no fees, minimum deposits, or balance requirements.

The account allows users to earn interest on their Daily Cash cashback balance, as well as on funds transferred from linked bank accounts or Apple Cash balances. Initially capped at $250,000, the maximum balance has since been increased to $1,000,000.

In January 2026, JPMorgan Chase reached a deal to take over operation of the Apple Card, with the transition expected to take approximately two years.

Alongside its new Apple Card partnership, JPMorgan Chase will reportedly launch a new Apple savings account, but existing users with Apple savings accounts at Goldman Sachs will not be automatically transitioned and will need to decide whether they want to stay at Goldman Sachs or open new accounts with Chase. Apple has a FAQ about the transition. Tag: Apple Card
This article, "Apple Lowers Savings Account Rate for Apple Card Users" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
The UK’s National Cyber Security Centre (NCSC) is recommending passkeys as the default authentication method for businesses to offer consumers, citing industry progress that now makes them a more secure and user-friendly alternative to passwords.
In a blog post published this week, the agency said passkeys can now be recommended to both the public and businesses as a primary authentication method.
“Passkeys should now be consumers’ first choice of login,” the UK cybersecurity authority said in a blog post, adding that passwords are “no longer resilient enough for the contemporary world.”
“Passkeys are a newer method for logging into online accounts which do much of the heavy lifting for users, only requiring user approval rather than needing to input a password. This makes passkeys quicker and easier to use and harder for cyber attackers to compromise,” the NCSC added in the blog.
The agency said passkeys should be used wherever supported, describing them as resistant to phishing and eliminating risks associated with password reuse.
Focus on phishing-resistant authentication
The guidance is based on the agency’s assessment of how authentication methods perform against real-world attacks.
The NCSC said its analysis examines common techniques, including phishing, credential reuse, and session hijacking, and evaluates how credentials are exposed across their lifecycle, from creation and storage to use.
“Passkeys are resistant to phishing attacks and remove the risks associated with password reuse,” the agency said.
In its accompanying technical paper, the NCSC said traditional authentication methods, including passwords combined with one-time codes, remain “inherently phishable.”
By contrast, FIDO2-based credentials such as passkeys are “as secure or more secure than traditional MFA against all common credential attacks observed in the wild,” the agency said.
However, NCSC cautioned in the technical paper that “while much of the analysis in this paper also applies to enterprise authentication scenarios (for example staff authenticating to a Single Sign On), the different threat model and usage scenarios mean this paper is not intended for enterprise risk assessment.”
How passkeys change the attack model
The NCSC added that passkeys reduce risk by removing reliance on shared secrets and binding authentication to the legitimate service.
According to the agency, this prevents credential reuse and relay attacks, as authentication cannot be intercepted and reused by an attacker.
Passkeys use cryptographic key pairs stored on a user’s device, with authentication tied to device-based verification such as biometrics or PINs, the agency said.
Shift in user-level authentication
For organizations that provide online services to customers, the guidance signals a shift in how authentication is implemented at the user interface level.
“This is a fundamental architectural change, not an incremental authentication upgrade,” said Madelein van der Hout, senior analyst at Forrester. “It moves organizations beyond the passwords-plus-MFA paradigm toward a phishing-resistant foundation.”
Van der Hout said passkeys eliminate risks associated with credential theft by using device-bound cryptographic authentication rather than shared secrets.
“Organizations that treat this as a credential swap will underinvest,” she said. “Those who treat it as a broader identity modernization opportunity will get ahead.”
The NCSC said organizations should also consider how authentication is implemented across the full user journey, including account recovery and fallback mechanisms.
While passkeys reduce reliance on passwords, the agency noted that weaker processes, such as password resets or account recovery flows, can still introduce risk if not properly secured.
Adoption challenges remain
The NCSC said passkeys are not yet universally supported and recommended password managers and multi-factor authentication where passkeys cannot be used.
“Where a particular service does not support passkeys, the NCSC’s advice to consumers is to use a password manager to create stronger passwords and keep using two-step verification,” NCSC noted in the blog post.
Van der Hout said implementation challenges are likely, particularly for organizations operating across multiple platforms and user environments.
“Legacy systems and fragmented identity environments present significant obstacles,” she said.
She added that organizations must also consider non-human identities. “Any passkey strategy that ignores the machine identity layer will create new security gaps,” she said.
Device requirements and account recovery processes may also affect how passkeys are deployed, she said.
Hybrid model is expected during the transition
A full transition away from passwords is unlikely in the near term, analysts believe.
“Expect a hybrid model lasting several years,” van der Hout said, as organizations continue to support both passkeys and traditional authentication methods.
During this period, organizations will need to manage authentication across multiple login options while ensuring that fallback methods do not weaken overall security, she added
The NCSC similarly advised maintaining strong authentication practices where passkeys are not yet available.
Policy signal strengthens shift toward passwordless login
The guidance adds to broader efforts to move away from passwords in consumer authentication.
“The guidance matters because it gives security leaders leverage,” van der Hout said, including in discussions with vendors and internal stakeholders.
The NCSC said that moving toward phishing-resistant authentication could reduce a major cause of cyber compromise, particularly in services that rely on user login credentials.
View the full article
Outgoing Apple CEO Tim Cook has named the botched 2012 launch of Apple Maps as his "first really big mistake" in the role, according to a Bloomberg report covering the town hall meeting that was held Tuesday with his recently announced successor, John Ternus.


The Maps app launched with mislabeled landmarks, faulty directions, and a user experience that fell well short of Google Maps at the time. "The product wasn't ready, and we thought it was because we were testing more of local kind of stuff," Cook told staff.

Reflecting on the debacle, Cook said it was "valuable," noting that he expressed regret to users at the time and suggested they use competing navigation apps instead.

From the report:
The fallout led to the first major management shake-up of Cook's tenure, with software chief Scott Forstall – a close Steve Jobs collaborator – pushed out in the aftermath. (Fun fact: Forstall was recently invited back to Apple Park to celebrate the company's 50th anniversary.)

On the bright side, Cook singled out the Apple Watch and its expanding health features as the work he's most proud of. He recalled receiving his first note from a user whose life had been saved by the device. "It caused me to just stop in my steps," he said.

Cook conceded that his list of mistakes would be "extraordinary in length" (the never-released AirPower charging mat and Apple's abandoned car project would surely be high up there) but the CEO has successfully avoided the kind of product recalls and cancellations that have plagued other consumer device companies over the last 15 years.

Cook became CEO in August 2011 and hands over the reins to Ternus, currently chief of hardware engineering, on September 1, 2026.Tags: Apple Maps, Tim Cook
This article, "Tim Cook Calls Apple Maps Launch His 'First Really Big Mistake' as CEO" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
In response to Anthropic Mythos, instead of launching another LLM, Google unveiled a broad push toward agentic, AI-driven defense at Google Cloud Next ‘26 to help SOC analysts as they scramble to keep up with the influx of CVEs Mythos threatens.
As Mythos promises more vulnerabilities, and reports of unauthorized access despite its limited preview emerge, Google is betting that only agents, not analysts, can keep pace with what is coming.
Google unveiled new capabilities focused on automating detection, accelerating response, and securing the increasingly messy intersection of AI, cloud, and third-party ecosystems.
Under this, the search giant announced three new agents in Google Security Operations, expanded security across clouds and AI studios with expanded Wiz integration, and the Gemini Enterprise Agent Platform that promises a defense layer against shadow AI.
Additionally, Google said it is working on simplifying permissions with modern IAM, along with a handful of improvements in Google Cloud Security.
New emphasis on agentic defense
Google’s most direct help to SOC teams comes in the form of three new AI agents embedded in Google Security Operations. These include a threat hunting agent, a detection engineering agent, and a third-party context agent.
While the threat hunting and detection engineering agents, both now in preview, aim to identify novel attack patterns and close detection gaps, respectively, the third-party context agent, set to enter preview, is designed to enrich investigations with external intelligence.
Google claimed its existing triage and investigation agent has already processed over five million alerts, shrinking analysis time from 30 minutes to roughly a minute using Gemini.
There’s also a push toward what Google calls “agentic automation,” where response actions can be triggered automatically, paired with new dark web intelligence (infused into Google Threat Intelligence) capabilities to prioritize real threats with high accuracy.
Wiz, AI-BOMs, and securing the AI development sprawl
Google has expanded its Wiz portfolio to tackle the chaos of AI development and multi-cloud risk.
Wiz is being positioned as the connective tissue across environments, supporting everything from AWS and Azure to SaaS platforms and AI agent studios.“Wiz now supports Databricks as well as new agent studios like AWS Agentcore, Gemini Enterprise Agent Platform, Microsoft Azure Copilot Studio, and Salesforce Agentforce, so customers gain visibility however their teams choose to build,” said Francis deSouza, COO, Google Cloud and President, Security Products.
Other new capabilities from the integration come in the form of inline scanning of AI-generated code, integrations directly into developer workflows, and an AI-bill of materials (AI-BOM) that inventories all AI components, including models, frameworks, and IDE plugins across an organization.
AI-BOM is targeted as a practical response to shadow AI, offering visibility into tools developers use versus what’s approved.
Securing the agentic web
Google is also aiming to have visibility into the plane where AI agents interact autonomously across systems, something it calls the “agentic web.”
To address that, it introduced Agent Identity and Agent Gateway for governance and policy enforcement, alongside deeper integrations for Model Armor to mitigate risks like prompt injection and data leakage. There’s also a reworked approach to bot and fraud detection through Google Cloud Fraud Defense, which aims to distinguish between humans, bots, and AI agents across the workflows.
View the full article
In response to Anthropic Mythos, instead of launching another LLM, Google unveiled a broad push toward agentic, AI-driven defense at Google Cloud Next ‘26 to help SOC analysts as they scramble to keep up with the influx of CVEs Mythos threatens.
As Mythos promises more vulnerabilities, and reports of unauthorized access despite its limited preview emerge, Google is betting that only agents, not analysts, can keep pace with what is coming.
Google unveiled new capabilities focused on automating detection, accelerating response, and securing the increasingly messy intersection of AI, cloud, and third-party ecosystems.
Under this, the search giant announced three new agents in Google Security Operations, expanded security across clouds and AI studios with expanded Wiz integration, and the Gemini Enterprise Agent Platform that promises a defense layer against shadow AI.
Additionally, Google said it is working on simplifying permissions with modern IAM, along with a handful of improvements in Google Cloud Security.
New emphasis on agentic defense
Google’s most direct help to SOC teams comes in the form of three new AI agents embedded in Google Security Operations. These include a threat hunting agent, a detection engineering agent, and a third-party context agent.
While the threat hunting and detection engineering agents, both now in preview, aim to identify novel attack patterns and close detection gaps, respectively, the third-party context agent, set to enter preview, is designed to enrich investigations with external intelligence.
Google claimed its existing triage and investigation agent has already processed over five million alerts, shrinking analysis time from 30 minutes to roughly a minute using Gemini.
There’s also a push toward what Google calls “agentic automation,” where response actions can be triggered automatically, paired with new dark web intelligence (infused into Google Threat Intelligence) capabilities to prioritize real threats with high accuracy.
Wiz, AI-BOMs, and securing the AI development sprawl
Google has expanded its Wiz portfolio to tackle the chaos of AI development and multi-cloud risk.
Wiz is being positioned as the connective tissue across environments, supporting everything from AWS and Azure to SaaS platforms and AI agent studios.“Wiz now supports Databricks as well as new agent studios like AWS Agentcore, Gemini Enterprise Agent Platform, Microsoft Azure Copilot Studio, and Salesforce Agentforce, so customers gain visibility however their teams choose to build,” said Francis deSouza, COO, Google Cloud and President, Security Products.
Other new capabilities from the integration come in the form of inline scanning of AI-generated code, integrations directly into developer workflows, and an AI-bill of materials (AI-BOM) that inventories all AI components, including models, frameworks, and IDE plugins across an organization.
AI-BOM is targeted as a practical response to shadow AI, offering visibility into tools developers use versus what’s approved.
Securing the agentic web
Google is also aiming to have visibility into the plane where AI agents interact autonomously across systems, something it calls the “agentic web.”
To address that, it introduced Agent Identity and Agent Gateway for governance and policy enforcement, alongside deeper integrations for Model Armor to mitigate risks like prompt injection and data leakage. There’s also a reworked approach to bot and fraud detection through Google Cloud Fraud Defense, which aims to distinguish between humans, bots, and AI agents across the workflows.
View the full article
Google unveiled a broad push toward agentic, AI-driven defense at Google Cloud Next ‘26 to help SOC analysts as they scramble to keep up with the influx of CVEs Mythos threatens.
As Mythos promises to uncover more software vulnerabilities, Google is betting that only agents, not analysts, can keep pace with what is coming.
Google unveiled new capabilities focused on automating detection, accelerating response, and securing the increasingly messy intersection of AI, cloud, and third-party ecosystems.
Under this, the search giant announced three new agents in Google Security Operations, expanded security across clouds and AI studios with expanded Wiz integration, and the Gemini Enterprise Agent Platform that promises a defense layer against shadow AI.
Additionally, Google said it is working on simplifying permissions with modern IAM, along with a handful of improvements in Google Cloud Security.
New emphasis on agentic defense
Google’s most direct help to SOC teams comes in the form of three new AI agents embedded in Google Security Operations. These include a threat hunting agent, a detection engineering agent, and a third-party context agent.
While the threat hunting and detection engineering agents, both now in preview, aim to identify novel attack patterns and close detection gaps, respectively, the third-party context agent, set to enter preview, is designed to enrich investigations with external intelligence.
Google claimed its existing triage and investigation agent has already processed over five million alerts, shrinking analysis time from 30 minutes to roughly a minute using Gemini.
There’s also a push toward what Google calls “agentic automation,” where response actions can be triggered automatically, paired with new dark web intelligence (infused into Google Threat Intelligence) capabilities to prioritize real threats with high accuracy.
Wiz, AI-BOMs, and securing the AI development sprawl
Google has expanded its Wiz portfolio to tackle the chaos of AI development and multi-cloud risk.
Wiz is being positioned as the connective tissue across environments, supporting everything from AWS and Azure to SaaS platforms and AI agent studios.“Wiz now supports Databricks as well as new agent studios like AWS Agentcore, Gemini Enterprise Agent Platform, Microsoft Azure Copilot Studio, and Salesforce Agentforce, so customers gain visibility however their teams choose to build,” said Francis deSouza, COO, Google Cloud and President, Security Products.
Other new capabilities from the integration come in the form of inline scanning of AI-generated code, integrations directly into developer workflows, and an AI-bill of materials (AI-BOM) that inventories all AI components, including models, frameworks, and IDE plugins across an organization.
AI-BOM is targeted as a practical response to shadow AI, offering visibility into tools developers use versus what’s approved.
Securing the agentic web
Google is also aiming to have visibility into the plane where AI agents interact autonomously across systems, something it calls the “agentic web.”
To address that, it introduced Agent Identity and Agent Gateway for governance and policy enforcement, alongside deeper integrations for Model Armor to mitigate risks like prompt injection and data leakage. There’s also a reworked approach to bot and fraud detection through Google Cloud Fraud Defense, which aims to distinguish between humans, bots, and AI agents across the workflows.
View the full article
Apple is expected to bring several camera enhancements to the iPhone 18 Pro models this year, but there have been no fixed rumors suggesting these upgrades will require measurable, visible changes to the device's rear camera plateau. And yet a new series of dummies suggests exactly that.

iPhone 17 Pro dummy (left) vs. iPhone 18 Pro (image: Vadim Yuryev)
YouTube channel Max Tech's Vadim Yuryev recently shared images of dummy units for the iPhone 18 Pro and iPhone 18 Pro Max – as well as Apple's upcoming foldable iPhone. Dummy units are typically created by third-party case makers based on information that leaks out of Apple's partner factories.

Yuryev says the dummy units have "much thicker cameras... The black glass on the cameras protrudes a bit more too." He also says the camera plateau itself is "a bit thicker" than on the iPhone 17 Pro Max, and he provided the above image for comparison. The silver unit is the iPhone 18 Pro Max dummy, while the blue is an iPhone 17 Pro Max dummy. Other than the rear triple lens camera system, the two device's dimensions are said to be extremely similar – same thickness, but a slight height (.36mm) and width (.39mm) increase on the 18 Pro Max unit.

Yuryev says he stands by the accuracy of the iPhone 18 Pro dummies, claiming they should be "spot on" like the iPhone 17 Pro dummy units he received last year, presumably from the same source.

The Main camera in the iPhone 18 Pro could have a variable aperture, which would provide users with more control over how their photos look. iPhone users would be able to manually adjust how much light gets to the sensor, cutting down on overexposure and providing new customization options for lighting and depth of field.

The Telephoto lens in the iPhone 18 Pro models could also feature a larger aperture, allowing for more light in poor lighting conditions.

At least one of the iPhone 18 Pro models could also feature a new three-layer stacked image sensor developed by Samsung. The advanced image sensor would make the camera more responsive, plus it could cut down on noise, increase dynamic range, and more.

Will any of these upgrades necessitate a larger camera module? Theoretically, but no leak has explicitly said the lenses on either 18 Pro model will stick out more or that the camera plateau will get thicker. It's especially surprising given that the industry is actively targeting flat or near-flush camera systems in future devices, but Apple could well be taking a different tack.

We'll know for sure when the devices arrive around mid-September alongside the company's first foldable iPhone.Related Roundup: iPhone 18 Pro
This article, "Latest iPhone 18 Pro Max Dummies Suggest Thicker Camera Plateau, More Protruding Lenses" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Apple Maps has updated its "2026 Formula 1 Tracks Around the World" guide with a dedicated experience for the Miami F1 Gran Prix, which takes place on May 3 and will be streamed exclusively on Apple TV in the United States.


The guide offers an immersive way to explore F1 circuits. It began with Albert Park in Australia, with more 3D circuit experiences to be added as the season progresses.

The Miami experience adds detailed features at key locations in Miami International Autodrome circuit. As spotted by 9to5Mac, there are 3D landmarks for things like grandstands, The Marina, the Pit Building, the Finish Line, and more. The area also includes technical information about the circuit, along with local gates, race entrances, bridges, restrooms, and water stations.

There are also some guides for fans attending the race, such as "A Local's Guide to Miami F1 Race Week" for dining and shopping recommendations, and "Hyperlocal F1 Miami Race Week Spots," for identifying prime viewing locations close to the track.

The 2026 F1 season kicked off in Australia on March 8. Last October, Apple and Formula 1 announced a five-year partnership including exclusive streaming rights in the U.S. The partnership allows ‌Apple TV‌ to provide comprehensive coverage of Formula 1, including all practice, qualifying, Sprint sessions, and Grands Prix.Tag: Apple Maps
This article, "Apple Maps Gains Immersive 3D Experience of Miami F1 Grand Prix" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
With dummy models of Apple's rumored foldable iPhone now circulating, YouTube channel Max Tech's Vadim Yuryev has shared images and video of the book-style form factor compared to existing Apple devices, giving us a better idea of what to expect when it launches later this year.


The foldable iPhone's inner display is said to have a 4:3 aspect ratio like an iPad, and it will have an iPad mini-sized OLED display when it's opened up. Most rumors say it will be 5.5 inches when closed, and 7.8 inches when open, making it a bit smaller than the 8.3-inch iPad mini (shown behind the dummy in the image above).


Compared to an iPhone 17 Pro Max in landscape orientation, Yurydev says the width of the foldable is basically the same, but it has a 56.9 percent taller display (71 mm vs. 111.5 mm). Yurydev suggests this will provide a more immersive video experience at 16:9 and will be "awesome" for gaming using onscreen controls.


Yurydev also shared a video showing what it might be like to interact with the outer display, which is probably smaller than many people will be expecting. According to The Information, it will measure just 5.3 inches – smaller than the 5.4-inch screen on the iPhone 13 mini – but that claim is an outlier, whereas most rumors put it at 5.5 inches. Either way, bigger hands may find it takes some getting used to.


Further images give us an idea of the side of the device when folded. A Touch ID-integrated power button and a Camera Control button can be seen set apart on the right side, with volume buttons along the top like the iPad mini. Face ID is not expected to feature because of space constraints, while Apple apparently sees Camera Control as a key feature for the device, enabling users to maintain a steady grip while making any required adjustments, or do so one-handed if they wish.

Note the raised camera bump or "plateau" that does not span across the entire back of the device. It houses a two-lens camera system, rather than three, which is expected.


Yurydev says his dummy unit is exactly 11mm thick when it's closed. That contrasts with rumors suggesting the foldable could be around 9mm to 9.5mm when closed. Yurydev stands by the accuracy of his dummy, saying it should be "spot on" like last year's iPhone 17 Pro units. Yurydev did not disclose the thickness of the unit when open, but if it is 4.5mm as some rumors claim, the foldable iPhone will be Apple's thinnest device by far.


iPhone Ultra: Launch, Pricing, and What to Expect From Apple's Foldable
Apple is expected to unveil the foldable iPhone in September alongside the iPhone 18 Pro and iPhone 18 Pro Max models (shown above), whose dimensions are expected to remain identical to the iPhone 17 Pro series, albeit with a smaller Dynamic Island. Apple may call its first foldable "iPhone Ultra," according to an oft-reliable Chinese leaker.Tag: iPhone Ultra
This article, "Here's How the iPhone Ultra Compares to Other Apple Devices" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Microsoft plans to integrate Anthropic’s Mythos AI model into its Security Development Lifecycle, a move that suggests advanced generative AI is beginning to play a direct role in how major software vendors identify vulnerabilities and harden code against attack.
The company said it will use Mythos Preview, along with other advanced models, as part of a broader push to strengthen secure coding and vulnerability detection earlier in the software development process.
The announcement comes as Anthropic’s Mythos heightens concerns that advanced AI models could dramatically shrink the time between finding a software flaw and exploiting it. Analysts say Mythos marks a notable leap in AI-driven vulnerability research, with the ability to uncover thousands of serious flaws across major operating systems and browsers.
OpenAI has also entered the space with GPT-5.4-Cyber, a version of its flagship model tailored for defensive cybersecurity work. Keith Prabhu, founder and CEO of Confidis, said a future OpenAI model, which he referred to as “Spud,” could emerge as an even stronger rival.
The move matters beyond Microsoft’s own engineering organization. For enterprise security leaders, it offers a clear sign that frontier AI models are starting to move from experimental use into core cybersecurity workflows.
That could change how software vendors build products and how defenders view the risks and benefits of using the same AI tools attackers may also exploit.
“This marks a seminal turning point in the secure software development lifecycle process,” Prabhu said. “While earlier tools were only capable of static code scanning for vulnerabilities, with AI, there is a possibility of a dynamically learning model which can also perform dynamic vulnerability and even penetration testing in real time.”
Over time, Prabhu said, the pressure to adopt AI-assisted security tools is likely to spread beyond the largest software vendors.
Why Microsoft’s move matters
Neil Shah, vice president for research at Counterpoint Research, said more than 95% of Fortune 500 companies use Microsoft Azure in some capacity, while Azure AI and the Copilot suite are entrenched across about 65% of those companies. Millions of businesses also rely on multiple Microsoft products and cloud services.
“Using Mythos in Microsoft’s Security Development Lifecycle could help strengthen and harden products like Windows, Azure, Microsoft 365, and developer tools,” Shah said. “Every enterprise running those products could benefit from the security improvement without needing direct Mythos access themselves.”
Prabhu noted that Microsoft said it had evaluated Mythos using its open-source benchmark for real-world detection engineering tasks, with results showing substantial improvements over prior models.
“Such a claim coming from Microsoft does suggest that these new AI models are becoming materially better at identifying exploitable flaws than earlier generations,” Prabhu added. “However, as with any AI tool, the strength of the tool lies in its ability to analyze code quickly based on past learning. There is a possibility that it could miss new types of vulnerabilities that only a ‘human-in-the-loop’ could identify.”
View the full article
Mongolian governmental institutions have emerged as the target of a previously undocumented China-aligned advanced persistent threat (APT) group tracked as GopherWhisper. "The group wields a wide array of tools mostly written in Go, using injectors and loaders to deploy and execute various backdoors in its arsenal," Slovakian cybersecurity company ESET said in a report shared with The HackerView the full article
Vercel on Wednesday revealed that it has identified an additional set of customer accounts that were compromised as part of a security incident that enabled unauthorized access to its internal systems. The company said it made the discovery after expanding its investigation to include an extra set of compromise indicators, alongside a review of requests to the Vercel network and environmentView the full article
Apple has rolled out a software fix for iOS and iPadOS to address a Notification Services flaw that stored notifications marked for deletion on the device. The vulnerability, tracked as CVE-2026-28950 (CVSS score: N/A), has been described as a logging issue that has been addressed with improved data redaction. "Notifications marked for deletion could be unexpectedly retained on the device,"View the full article
Gorodenkoff | shutterstock.com
Cloud Security bleibt ein diffiziles Thema und die Tools, mit denen sie sich gewährleisten lässt, werden zunehmend komplexer und schwieriger zu durchschauen – auch dank der ungebrochenen Liebe der Branche zu Akronymen. Mit CNAPP kommt nun ein weiteres hinzu.
CNAPP – Definition
Die Abkürzung steht für Cloud-Native Application Protection Platform – und kombiniert die Funktionen von vier separaten Cloud-Security-Werkzeugen:   
Cloud Infrastructure Entitlement Management (CIEM), um sämtliche Zugriffskontrollmaßnahmen und Risikomanagement-Tasks zu managen. Cloud Workload Protection Platform (CWPP), um Code in allen cloudbasierten Repositories abzusichern sowie Laufzeitschutz für die gesamte Entwicklungsumgebung und alle Code-Pipelines zu gewährleisten. Cloud Access Security Broker (CASB) für Authentifizierungs- und Encryption-Aufgaben. Cloud Security Posture Management (CSPM), das Threat Intelligence und Abhilfemaßnahmen kombiniert. Über diese vier „klassischen“ Elemente hat sich CNAPP inzwischen auch auf andere Bereiche ausgeweitet. Zum Beispiel:
API-, Skript-, Supply-Chain– sowie Infrastructure-as-Code (IaC)-Sicherheit, Container– und Serverless-Security, sowie weitere Posture-Management-Tools, einschließlich Daten- und SaaS-Applikationen. Aus Anwendersicht ist CNAPP damit sowohl schwer zu verstehen als auch diffizil zu evaluieren – und entsprechend schwer einzukaufen, wie Forrester-Chefanalyst Andras Cser in einem Blogbeitrag zum Thema nahelegt. Weil teilweise auch Security-Optionen außerhalb der Cloud abgedeckt würden, sei jede CNAPP-Kaufentscheidung und -Implementierung auch eine Team- oder abteilungsübergreifende Aufgabe, so der Analyst.
Anders ausgedrückt: Geht‘s um CNAPP, muss eine ganze Menge Software abgestimmt, gemanagt, integriert und verstanden werden. Um Ihnen den Überblick zu erleichtern, haben wir die Details zu den wichtigsten Anbietern und Angeboten in diesem Kaufratgeber zusammengetragen.
Der CNAPP-Markt
Geprägt hat die Produktkategorie – beziehungsweise das Akronym – einmal mehr Gartner. Das Analystenhaus verwendete den Begriff CNAPP erstmals in seinem „Innovation Insight“-Report aus dem August 2021. Der Schlüssel zum Verständnis dieser Produktkategorie liegt in den Integrationsherausforderungen für Unternehmensanwender: Im „State of Observability Report“ von VMware geben 57 Prozent der Befragten an, dass innerhalb einer typischen Cloud-Anwendung bis zu 50 verschiedene Technologien zum Einsatz kommen – die im Schnitt mit zehn Monitoring-Tools gemanagt werden.
Und laut dem „Observability Report 2024“ (Download gegen Daten) von Dynatrace besteht eine typische Enterprise-Umgebung im Schnitt aus einem Dutzend unterschiedlichen Cloud-Plattformen, wobei regelmäßig ein Mix aus Private-, Public- und Hybrid-Cloud-Strategien zur Anwendung kommt. Hinzu kommen dann noch verschiedene Instanzen virtueller Maschinen, Kubernetes-Container sowie Serverless- und Microservices-Tools. Diese erhebliche Integrationsbelastung könnte auch ein Grund dafür sein, dass der CNAPP-Markt im zweiten Quartal 2024 ein Gesamtvolumen von 700 Millionen Dollar erreicht hat und damit im Jahresvergleich um 42 Prozent gewachsen ist – wie die Analysten der Dell’Oro Group berichten.
CNAPP-Anbieter und ihre Angebote
Im Idealfall sollte eine CNAPP-Lösung:
Fehlkonfigurationen reduzieren, das Security-Niveau der Entwicklungspipeline optimieren, sowie effektiv automatisieren. Die Anbieter verfolgen mit Blick auf CNAPP zwei unterschiedliche Ansätze: Entweder sie fokussieren die DevSecOps– oder die traditionelle IT-Security-Perspektive. Ersteres hat einen stärkeren Fokus auf den Schutz der Applikationen selbst zur Folge (CIEM/CWPP), letzteres eine Ausweitung traditioneller Schutzmaßnahmen auf Netzwerkebene (CASB/CSPM). Bislang deckt kein CNAPP-Offering wirklich konsequent alle vier Bereiche ab.
Natürlich spielt künstliche Intelligenz (KI) auch in diesem Bereich zunehmend eine Rolle: Diverse CNAPP-Anbieter integrieren, beziehungsweise kombinieren KI-Agenten und agentenlose Lösungen in ihren Produkten, um ein umfassenderes Monitoring und eine möglichst breite Abdeckung und Scalability zu bieten. 
Aqua Security Platform
Fokus: DevSecOps
Form: Einheitliche Plattform mit verschiedenen Produkten;
Besondere Features/Integrationen: „(No-)Breach-Garantie“ bis zu einer Million Dollar;
Preisgefüge: kostenlose Trial-Version; ab 850 Dollar pro Monat;

CrowdStrike Falcon Cloud Security
Fokus: DevSecOps / IT-Security
Form: Einheitliche Plattform mit verschiedenen Produkten;
Besondere Features/Integrationen: Cloud Detection and Response (CDR), AppSec, Schwachstellenanalyse für Container-Images;
Preisgefüge: Abonnement-Preis richtet sich nach den gewählten Produkten;

Data Theorem
Fokus: DevSecOps
Form: Separate Produkte für Cloud, Web und Supply Chain;
Besondere Features/Integrationen: Headliner Attack Policies, Artifact Scanning, zentrale Analyse-Engine, Kubernetes-Support;
Preisgefüge: komplex und teuer; unterschiedliche Tarife für jedes Produkt;

Lacework FortiCNAPP
Fokus: IT-Security
Form: Einheitliche Plattform mit verschiedenen Produkten;
Besondere Features/Integrationen: Verhaltensbasierte Schutzregeln, SOAR, AppSec, Scans für Build- und Deployment-Pipelines;
Preisgefüge: kostenlose Probeversion; richtet sich nach der Nutzungsdauer sowie den in Anspruch genommenen vCPUs;

Orca CNAPP
Fokus: IT-Security
Form: Einheitliche Plattform mit verschiedenen Produkten;
Besondere Features/Integrationen: Side Scanning, Risikopriorisierung, AppSec-Pipelines, KI-Features;
Preisgefüge: orientiert sich an Workloads, Storage Buckets und Datenbank-Scans sowie den eingesetzten Sensoren;

Palo Alto Networks Cortex Cloud
Fokus: IT-Security
Form: Einheitliche Plattform mit verschiedenen Produkten;
Besondere Features/Integrationen: CDR, AppSec-Integration, Laufzeitschutz und DSPM, Support für IBM und Akamai Clouds geplant;
Preisgefüge: komplex und teuer; richtet sich nach den gewählten Modulen und abgesicherten Workloads;

Qualys Total Cloud CNAPP
Fokus: IT-Security
Form: Einheitliche Plattform;
Besondere Features/Integrationen: CDR, Container und IaC-Security, SaaS Posture Management, KI-Funktionen;
Preisgefüge: kostenlose Probeversion; Abo-Modell auf Workload-Basis;

Sysdig Secure
Fokus: DevSecOps
Form: Einzelprodukt;
Besondere Features/Integrationen: „Next Generation“ CDR, Risikopriorisierung, KI-Funktionen und-Analysen;
Preisgefüge: Festpreis pro Host Model; ab circa 500 Dollar pro Monat;

Tenable Cloud Security
Fokus: IT-Security
Form: Standalone-Lösung oder als Bestandteil der Exposure-Management-Plattform Tenable One;
Besondere Features/Integrationen: Exposure Management, DSPM, KI Security, Kubernetes- und IaC-Support;
Preisgefüge: kostenlose Probeversion; komplexes Preismodell, das sich an Nodes oder Workloads ausrichten lässt; 

Tigera Calico Cloud
Fokus: DevSecOps
Form: Einzelprodukt;
Besondere Features/Integrationen: fokussiert in erster Linie auf Container- und Kubernetes-Security;
Preisgefüge: kostenlose Open-Source-Version; kommerzielle Optionen mit Abo-Abrechnungsmodell oder pro Node-Stunde;

Uptycs
Fokus: IT-Security
Form: Einheitliche Plattform;
Besondere Features/Integrationen: XDR, AppSec, DSPM, KI- und ML-Funktionen;
Preisgefüge: diverse Optionen; ab circa 5.000 Dollar pro Jahr (200 Cloud Assets);

Wiz
Fokus: IT-Security
Form: Einheitliche Plattform mit verschiedenen Produkten;
Besondere Features/Integrationen: Risikopriorisierung mit Graph-basierten Visualisierungen und Analysen von Code zu Cloud zu Runtime, KI-Funktionen, Container- und Kubernetes-Support;
Preisgefüge: verschiedene Preispläne, die sich nach den Workloads richten;
5 Fragen vor dem CNAPP-Investment
Bevor Sie sich für einen dieser CNAPP-Anbieter entscheiden, sollten Sie sich folgende Fragen stellen:
Welche Cloud-Artefakte lassen sich mit der gewählten Lösung scannen? Einige Produkte (Lacework) fokussieren auf die drei großen IaaS-Anbieter, andere (Tigera) unterstützen nur die Kubernetes-Dienste der Hyperscaler. Wieder andere (Sysdig) nehmen vor allem Container und die verschiedenen Linux-Server, auf denen diese laufen, in den Fokus. Vor allem kommt es jedoch darauf an, die Artefakte kontinuierlich und (nahezu) in Echtzeit überwachen zu können. Wie werden Sicherheitsvorfälle gemeldet? Gibt es separate Zugriffsregeln, damit sich verschiedene Mitarbeiter auf bestimmte Bereiche konzentrieren können? Gibt es separate oder kombinierte, vordefinierte Sicherheitsrichtlinien, um Daten mit und ohne Agenten zu erfassen? Wie aussagekräftig sind die Dashboards und die Visualisierungen, die diese liefern? Inwieweit werden die vier Management-Tool-Bereiche abgedeckt? Einige Angebote bieten CWPP- und CSPM-Elemente, müssen aber, etwa für Kubernetes-Support, erweitert werden. Welche DevOps-Frameworks werden unterstützt? Wie sieht es mit Blick auf Open-Source-Repositories aus? Wie viel kostet die Lösung konkret? Nur wenige CNAPP-Anbieter bieten eine wirklich transparente Preisgestaltung. Insbesondere bei komplexen Preismodellen (Data Theorem, Qualys, Orca) besteht deshalb Klärungsbedarf. (fm)
View the full article
Serial-to-Ethernet adapters used in industrial, retail, and healthcare environments to link serial devices to TCP/IP networks are riddled with vulnerabilities and outdated open-source components, researchers warn. The flaws enable various attacks scenarios, including taking full control of mission-critical equipment such as remote terminal units, programmable logic controllers, point-of-sale systems, and bedside patient monitors.
In a new study dubbed BRIDGE:BREAK, researchers from cybersecurity firm Forescout analyzed the firmware from five major vendors of serial-to-IP converters and found that each firmware image contained on average 80 open-source software components with almost 2,500 known vulnerabilities in them and 89 publicly available exploits.
In addition, the researchers identified 22 new vulnerabilities in three devices from Lantronix and Silex Technology America with impact ranging from remote code execution to authentication bypass, information disclosure, and denial-of-service.
Search engines such as Shodan show close to 20,000 internet-exposed serial-to-Ethernet converters, though the number of such devices deployed within networks is likely in the millions, as they are used across many industries. But even when they are not directly connected to the internet, attackers can still reach such devices after breaking into internal networks through a variety of other initial access vectors.
Because serial protocols often lack authentication or encryption “attackers may alter serial data received from a sensor as it moves into the IP network,” the researchers said. “For example, changing temperature, pressure, humidity, flow, patient heart rate readings to arbitrary values. Conversely, attackers may modify commands traveling from the IP network to the serial side before they reach an actuator. For example, changing the speed or direction of a servo motor.”
Serial-to-IP converters have been targeted in real-world attacks against critical infrastructure in the past. For example, in a 2015 cyberattack that disrupted power distribution at several power substations in Ukraine, attackers loaded corrupted firmware onto Moxa serial-to-IP converters via the firmware update function.
Then just a few months ago in December, wind and solar farms in Poland were targeted by Russian hackers in a cyberattack that involved resetting the configurations on Moxa NPort serial device servers. The devices were not directly exposed to the internet, but attackers gained access to them after compromising VPN concentrators.
Vulnerable components and lack of firmware hardening
Firmware in devices analyzed by Forescout was running old versions of the Linux kernel as well as other outdated libraries and userspace binaries. In addition, half of the Linux kernel branches observed reached end of life, complicating future updates.
As a result, analyzed firmware images had more than 2,000 known vulnerabilities on average, most located in the Linux kernel itself. The firmware image with the lowest number of flaws still had 210 vulnerabilities. Of course, not all flaws are equal, but on average 68% were low or medium severity, 29% were high severity, and 3% were critical severity.
Because of the old kernel versions used, the anti-exploit mitigations applied at the OS level for binaries were also highly inconsistent. Only 23% of firmware images used stack canaries, a feature that prevents stack smashing exploits; 44% used RELRO (Relocation Read-Only), which prevents attackers from redirecting execution by overriding the Global Offset Table; 67% used PIE (Position Independent Executable), a mechanism that makes Return Oriented Programming (ROP) attacks much harder; and 84% used NX (No-eXecute bit), a feature that marks certain memory stack and heap areas as non-executable to prevent straightforward buffer overflow exploits.
New RCE and other vulnerabilities
Aside from all the known vulnerabilities from open-source components, the Forescout researchers also performed manual security analysis and identified previously unknown flaws in the firmware of three specific devices from two vendors: Lantronix EDS3000PS Series, Lantronix EDS5000 Series, and Silex SD330-AC.
The web-based management interface of the Lantronix EDS5000 had five flaws in multiple pages and fields caused by missing input sanitization that could lead to remote code execution as root. The Lantronix EDS3000PS had one RCE, an authentication bypass issue and a device takeover flaw where the password change feature did not ask for the old password, potentially allowing attackers to change the password for the administrator account.
While the Lantronix flaws were all in the web interface, some of the 12 vulnerabilities found in the Silex SD-330AC were in various network services, exploitable via UDP packets. In total the researchers found three new RCE flaws, an authentication bypass, an arbitrary file upload issue that could allow unauthenticated attackers to upload firmware binaries, two device takeover and privilege escalation bugs, two configuration tampering flaws, and other issues that could lead to information disclosure and denial-of-service.
In addition, the researchers found that the firmware signing key may be obtainable by attackers, which could give them the ability to create malicious firmware images. Silex is in the process of remediating this issue.
Mitigation
“As these devices are increasingly deployed to connect legacy serial equipment to IP networks, vendors and end-users should treat their security implications as a core operational requirement,” the Forescout researchers said.
Both Lantronix and Silex already released firmware updates to address the reported flaws: SD-330AC Firmware version 1.50, EDS5000 series version 2.2.0.0R1, and EDS3000 series version 3.2.0.0R2.
In addition to patching, Forescout recommends:
Replacing default credentials and prohibiting weak passwords to reduce the risk of exploiting authenticated vulnerabilities Segmenting networks to prevent threat actors from reaching vulnerable serial-to-IP converters or using those devices to compromise other critical assets Ensuring they are not exposed to the internet Implementing strict access controls for management interfaces (such as the Web UI) so only preapproved management workstations can access them Using dedicated subnetworks or VLANs where they are only allowed to communicate with the serial devices they manage and the IP-side devices that should have access to that serial data Monitoring for exploitation attempts on serial-to-IP converters and for unusual communication patterns that suggest an attacker is targeting data read from, or sent to, the serial link View the full article
The Claude Mythos Preview appears to be living up to the hype, at least from a cybersecurity standpoint. The model, which Anthropic rolled out to a small group of users, including Firefox developer Mozilla, earlier this month, has discovered 271 vulnerabilities in version 148 of the browser. All have been fixed in this week’s release of Firefox 150, Mozilla emphasized.
These findings set a new precedent in AI’s ability to unearth bugs, and could turbocharge cybersecurity efforts.
“Nothing Mythos found couldn’t have been found by a skilled human,” said David Shipley of Beauceron Security. “The AI is not finding a new class of AI-exclusive super bugs. It’s just finding a lot of stuff that was missed.”
However, the news comes as Anthropic is reportedly investigating unauthorized use of Mythos by a small group who reportedly gained access via a third party vendor environment, revealing the double-edged nature of AI.
Closing the fuzzing gap
Firefox has previously pointed AI tools, notably Anthropic’s Claude Opus 4.6, at its browser in a quest for vulnerabilities, but Opus discovered just 22 security-sensitive bugs in Firefox 148, while Mythos uncovered more than ten times that many.
Firefox CTO Bobby Holley described the sense of “vertigo” his team felt when they saw that number. “For a hardened target, just one such bug would have been red-alert in 2025,” he wrote in a blog post, “and so many at once makes you stop to wonder whether it’s even possible to keep up.”
Firefox uses a defense-in-depth strategy, with internal red teams applying multiple layers of “overlapping defenses” and automated analysis techniques, he explained. Teams run each website in a separate process sandbox.
However, no layer is impenetrable, Holley noted, and attackers combine bugs in the rendering code with bugs in the sandboxes in an attempt to gain privileged access. While his team has now adopted a more secure programming language, Rust, the developers can’t afford to stop and rewrite the decades’ worth of existing C++ code, “especially since Rust only mitigates certain, (very common) classes of vulnerabilities.”
While automated analysis techniques like fuzzing, which uncovers vulnerabilities or bugs in source code, are useful, some bits of code are more difficult to fuzz than others, “leading to uneven coverage,” Holley pointed out. Human teams can find bugs that AI can’t by reasoning through source code, but this is time-consuming, and is bottlenecked due to limited human resources.
Now, Claude Mythos Preview is closing this gap, detecting bugs that fuzzing doesn’t surface.
“Computers were completely incapable of doing this a few months ago, and now they excel at it,” Holley noted. Mythos Preview is “every bit as capable” as human researchers, he asserted, and there is no “category or complexity” of vulnerability that humans can find that Mythos can’t.
Defenders now able to win ‘decisively’?
Gaps between human-discoverable and AI-discoverable bugs favor attackers, who can afford to concentrate months of human effort to find just one bug they can exploit, Holley noted. Closing this gap with AI can help defenders erode that long-term advantage.
The industry has largely been fighting security “to a draw,” he acknowledged, and security has been “offensively-dominant” due to the size of the attack surface, giving adversaries an “asymmetric advantage.” In the face of this, both Mozilla and security vendors have “long quietly acknowledged” that bringing exploits to zero was “unrealistic.”
But now with Mythos (and likely subsequent models), defenders have a chance to win, “decisively,” Holley asserted. “The defects are finite, and we are entering a world where we can finally find them all.”
What security teams should do now
Finding 271 flaws in a mature codebase like Firefox illustrates the fact that AI-driven vulnerability discovery is now operating at a scale and depth that can outpace traditional human-led review, noted Ensar Seker, CISO at cyber threat intelligence company SOCRadar.
Holley’s “vertigo,” he said, was because defenders are realizing the attack surface is larger, and “more rapidly discoverable than previously assumed.”
Security teams must respond by shifting from periodic testing to continuous validation, Seker advised. That means integrating AI-assisted code analysis into continuous integration/continuous delivery (CI/CD) pipelines, prioritizing “patch velocity over perfection,” and assuming that any externally reachable code path will eventually be discovered and weaponized.
“The goal is no longer just finding vulnerabilities first, but reducing the window between discovery and remediation,” he said.
Shipley agreed that any company building software must evaluate resourcing so it can quickly and proactively find and fix vulnerabilities. “But stuff will happen,” he acknowledged. So, in addition to doing proactive work, enterprises must regularly exercise their incident response playbooks.
“The next few years are going to be a marathon, not a sprint,” said Shipley.
Dual-use nature of AI is a challenge
However, the dual-use nature of these systems present a big challenge. The same capability that helps defenders identify hundreds of flaws can be turned against them if the model or its outputs are exposed, Seker pointed out.
The reported unauthorized access to Mythos “reinforces that AI systems themselves are now high-value targets, effectively becoming part of the attack surface,” he said.
It’s not at all surprising that people found a way to access Mythos, Shipley agreed; it was inevitable. “Nor does Anthropic have some unique, insurmountable or exclusive AI capability for hacking,” he said, pointing out that OpenAI is already catching up in that regard, and others will “catch and surpass” Mythos.
Striking a balance requires treating AI models like privileged infrastructure, Seker noted. Enterprises need strict access controls, output monitoring, and isolation of sensitive workflows. Developers, meanwhile, must adapt by writing code that is resilient to automated scrutiny; this requires stronger input validation, safer defaults, and “fewer assumptions about obscurity.”
“In this paradigm, security isn’t just about defending systems; it’s about defending the tools that are now capable of breaking them at scale,” Seker emphasized.
View the full article
Application developers are being warned that malicious versions of pgserve, an embedded PostgreSQL server for application development, and automagik, an AI coding tool, have been dropped into the npm JavaScript registry, where they could poison developers’ computers.
Downloading and using these versions will lead to the theft of data, tokens, SSH keys, credentials, including those for Amazon Web Services (AWS), Microsoft Azure, and Google Cloud Platform (GCP), crypto coins from browser wallets, and browser passwords. The malware also spreads to other connected PCs.
The warnings came this week from researchers at two security firms.
Researchers at Socket found fake packages aimed at app developers looking for pgserve, an embedded PostgreSQL server for application development and testing, and automagik, an AI coding and agent-orchestration CLI from Namastex.ai. The researchers said the attack contains similarities to a recent campaign dubbed CanisterWorm, a worm-enabled supply chain attack that replaced the contents of legitimate packages with malware on npm.
At the time of Socket’s review, the fake automagik/genie package showed 6,744 weekly downloads, and the fake pgserve package showed about 1,300 weekly downloads.
The phony versions of automagik were versions 4.260421.33 through 4.260421.39 when Socket posted its advisory, and additional malicious versions are still being published and identified. The full scope of affected releases, maintainers, or release-path compromise is still under investigation, the researchers said.
Separately, researchers at StepSecurity also found malicious versions of pgserve on npm, noting that the compromised versions (1.1.11, 1.1.12 and 1.1.13) inject a 1,143-line credential-harvesting script that runs via postinstall every time it is installed.
The last legitimate release of pgserve is v1.1.10, according to StepSecurity.
StepSecurity said that, unlike simple infostealers, this malware is a supply-chain worm: If it finds an npm publish token on the victim machine, it re-injects itself into every package that token can publish, further propagating the compromise. Stolen data is encrypted and exfiltrated to a decentralized Internet Computer Protocol (ICP) canister, a blockchain-hosted compute endpoint chosen specifically because it cannot be taken down by law enforcement or domain seizure.
Yet another supply chain attack
This is just the latest example of a software supply chain attack, in which threat actors hope that developers will download infected utilities and tools from an open source registry and use them in packages that will spread the malware widely.
In one of the most recent examples, hackers last month compromised the npm account of the lead maintainer of the Axios HTTP client library. And last summer, attackers compromised several JavaScript testing utilities on npm.
Advice to victimized developers
Developers who have downloaded the malicious versions of pgserver and automagik need to act fast, says Tanya Janca, head of Canadian secure coding consultancy SheHacksPurple.
“Rotate every credential you can think of, right now, before you do anything else,” she said. “Then harden your CI/CD network egress controls so your build runners can only reach the domains they explicitly need. Make sure your build runners and deployment runners use separate service accounts with separate permissions. The goal is to make sure that even if a malicious package runs in your build environment, it cannot reach an attacker’s infrastructure (for data and secret exfiltration) and also block it from pivoting into your deployment pipeline.”
To prevent being compromised by any malicious npm package, Janca said IT leaders should disable automatic postinstall script execution by default.
Developers should also run this command immediately: npm config set ignore-scripts true. Some legitimate packages will occasionally break as a result of this, she admitted. But the goal is to create an intentional point of friction to force developers to consciously decide a script is or is not allowed to run on their machines.
In addition, she said, developers need tooling that checks whether what is published to npm actually matches what is in the source repository. “Not all software composition analysis tools do this,” Janca said, “so ask your vendor specifically whether the tool catches registry-to-repo mismatches.”
Finally, she advised, apply the principle of least privilege access to publishing tokens; scope them tightly, give them only the permissions they need for one specific package, and rotate them regularly — automatically, not manually.
More than just credential theft
“People tend to think of this as a credential theft incident,” Janca said. “It is actually a potential complete organizational takeover, and it can unfold in stages. First, the attacker gets your secrets on install: AWS keys, GitHub tokens, SSH keys, database passwords, everything sitting in your environment or home directory. Second, if you have an npm publish token, the worm immediately uses it to inject itself into every package you can publish, which means your downstream users are now also victims. Third, those stolen cloud credentials get used to pivot into your infrastructure: spinning up resources, exfiltrating data, moving laterally across accounts. Fourth, your CI/CD pipelines, which trust your runners and service accounts implicitly, welcomes the attackers malicious code into production.”
She pointed out that it often takes a long time for developers to notice attacks like this, “and by that time, the attacker has potentially had access to source code, production systems, customer data, and the software your users count on.”
Shift in tactics
Janet Worthington, a senior security and risk analyst at Forrester Research, said that recent attacks such as the CanisterSprawl campaign and the compromise of the Namastex.ai npm packages show a shift from threat actors toward self-propagating malware that steals credentials and uses them to automatically infect other packages.
“This behavior echoes earlier outbreaks like the Shai-Hulud worm, which spread across hundreds of packages by harvesting npm tokens and republishing trojanized versions belonging to the compromised maintainer,” she said in an email.
While open registry platforms like npm are introducing stronger protections around publisher accounts and tokens, these incidents highlight the fact that compromises are no longer isolated to a single malicious package, she said. Instead, they cascade quickly through a registry ecosystem and even jump to other ecosystems. “Enterprises should ensure that only vetted open source and third party components are utilized by maintaining curated registries, automating SCA [software composition analysis] in pipelines and utilizing dependency firewalls to limit exposure and blast radius,” said Worthington.
Developers sit at the intersection of source code, cloud infrastructure, CI/CD pipelines, and publishing credentials, Janca pointed out, so compromising one developer can mean compromising every user of every package they maintain, or even an entire organization. This attack, and several others in recent months, are also going after personal crypto wallets alongside corporate credentials. “That tells us,” she said, “that attackers understand exactly the type of person they are hitting and they are optimizing for maximum yield from a single attack.”
This article originally appeared on InfoWorld.
View the full article
Apple appears to be sold out of the base Mac mini, and the machine is listed as “Currently Unavailable” from the Apple Online Store.


The base ‌Mac mini‌ is the model with an M4 chip, 256GB of storage, and 16GB RAM. M4 Mac mini models with upgraded storage are still in stock, as are ‌Mac mini‌ models that are equipped with the M4 Pro chip. Configurations with 24GB RAM are also still available, but some models that use 32GB RAM or higher are out of stock.

When an Apple device goes out of stock, it can be an indication of an imminent refresh, but it’s not clear if that’s the case with the ‌Mac mini‌. The ‌Mac mini‌ has been in high demand because people are purchasing it to use as a machine to run AI models locally, so it’s possible the shortage is related to demand rather than a sign that an update is coming soon.

Apple is also dealing with RAM shortages caused by a surge in global memory demand that has led to increased RAM pricing. The memory shortages previously caused some higher tier ‌Mac mini‌ and Mac Studio models to go out of stock. Apple removed the 512GB ‌Mac Studio‌ from its online store entirely earlier this year.

Apple is working on M5 and M5 Pro versions of the ‌Mac mini‌ for 2026, but the update may not come until later in the year due to the RAM supply issues.
Related Roundup: Mac miniBuyer's Guide: Mac Mini (Caution)Related Forum: Mac mini
This article, "Base Mac Mini Sold Out From Apple Online Store" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Apple is working on a new version of the AirPods Pro, which could come as soon as this year. The AirPods are expected to be a variant of the current AirPods Pro, which suggests they won't be called the AirPods Pro 4.


Cameras

Multiple sources have said Apple is developing AirPods Pro that have tiny infrared cameras. The cameras won't be used to take photos or videos like an iPhone camera, but will instead provide the AirPods with information about what's around the wearer.

Cameras could potentially provide data to a connected iPhone, improving Visual Intelligence and Siri features that are set to come out in iOS 27.
Gestures

The infrared cameras could recognize hand gestures, allowing music and other features to be controlled with hand movements.

The AirPods Pro already support head gestures for doing things like declining or accepting phone calls, and the addition of hand gestures could expand this functionality.

Apple could even remove pressure sensitivity from the stem of the AirPods Pro, making gestures the main control method.
Vision Pro Integration

Apple analyst Ming-Chi Kuo believes the cameras integrated into the AirPods Pro will upgrade the spatial audio experience when used with the Apple Vision Pro headset.
Naming

There is some disagreement about where the AirPods Pro with cameras will fit in the AirPods lineup, and what they will be called.

The AirPods Pro 3 came out in September 2025, and the new model with cameras isn't expected to be labeled AirPods Pro 4. Apple could just upgrade the ‌AirPods Pro 3‌ with cameras and keep the name, or call them something like ‌AirPods Pro 3‌ with Cameras.

Apple released two versions of the AirPods 4, one that has ANC and one that doesn't. The ANC model is named ‌AirPods 4‌ with Active Noise Cancellation, so there is precedent for a straightforward AirPods Pro name.

Apple could also call the AirPods Pro with cameras the "AirPods Ultra," and that's what some rumors suggest will happen.
H3 Chip

It's possible that Apple will include a new H3 chip with camera-equipped AirPods Pro. Apple is working on a new chip, but the current ‌AirPods Pro 3‌ launched with the same H2 chip that was in the AirPods Pro 2.

The H3 chip is expected to bring lower latency and improved audio quality.
Pricing

Some rumors suggest the AirPods Pro with cameras will be more expensive than the existing model, while others say they will be the same price. If Apple is planning to sell them for $249, the AirPods Pro with cameras would replace the current model. If they're more expensive at ~$299, they could be sold alongside the ‌AirPods Pro 3‌.
Launch Date

A new version of the AirPods Pro with cameras could come out as soon as 2026, and if that launch timing is accurate, we'll likely see them introduced alongside new iPhone models in September.Related Roundup: AirPods Pro 3Buyer's Guide: AirPods Pro (Buy Now)Related Forum: AirPods
This article, "What to Expect From the Next AirPods Pro, Launching as Soon as This Year" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
The iOS 26.4.2, iPadOS 26.4.2, iOS 18.7.8, and iPadOS 18.7.8 updates that Apple released today address a security vulnerability that the FBI recently used to extract Signal message previews from an iPhone even after the app was deleted.


A flaw with notification services allowed notifications that were supposed to be deleted to be retained on an iPhone or iPad. Apple says it fixed the logging issue with improved data redaction.

Apple became aware of the vulnerability after recent court testimony revealed that the FBI was able to access the internal notification database on an iPhone involved in a case, providing law enforcement with access to message previews. The iPhone in question was set to display the content of Signal messages on the Lock Screen, and with that feature enabled, the iPhone stores message content.

The defendant in the case had deleted the Signal app and had Signal messages set to disappear, but the iPhone kept the messages in its database long enough for the FBI to access them.

Apple users running iOS 26, iPadOS 26, iOS 18, or iPadOS 18 should update to the latest versions to avoid being impacted by the security flaw.Related Roundups: iOS 26, iPadOS 26Tags: FBI, SignalRelated Forum: iOS 26
This article, "iOS 26.4.2 Patches Flaw That Let FBI Extract Deleted Signal Messages" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Developers are advised to check their applications after Microsoft revealed that last week’s ASP.NET Core update inadvertently introduced a serious security flaw into the web framework’s Data Protection Library.
Microsoft describes the issue as a “regression,” coding jargon for an update that breaks something that was previously working correctly.
In this case, what was introduced was a CVSS 9.1-rated critical vulnerability, identified as CVE-2026-40372, that affects ASP.NET’s Core Data Protection application library distributed via the NuGet package manager. It impacts Linux, macOS and other non-Windows OSes, as well as Windows systems where the developer explicitly opted into managed algorithms via the UseCustomCryptographicAlgorithms API.
A bug in the .NET 10.0.6 package, released as part of the Patch Tuesday updates on April 14, causes the ManagedAuthenticatedEncryptor library to compute the validation tag for the Hash-based Message Authentication Code (HMAC) using an incorrect offset.
Incorrect calculation of security hashes results in the .AspNetCore application cookies and tokens being validated and trusted when they shouldn’t be.
“In these cases, the broken validation could allow an attacker to forge payloads that pass DataProtection’s authenticity checks, and to decrypt previously-protected payloads in auth cookies, anti-forgery tokens, TempData, OIDC state, etc,” said Microsoft’s GitHub advisory.
When embedded in applications, these long-lived tokens confer the sort of power attackers quickly jump on. “If an attacker used forged payloads to authenticate as a privileged user during the vulnerable window, they may have induced the application to issue legitimately-signed tokens (session refresh, API key, password reset link, etc.) to themselves,” the advisory noted.
This vulnerability arrives only six months after ASP.NET suffered one of its worst ever flaws, October’s CVSS 9.9-rated CVE-2025-55315 in the Kestrel web server component. But somewhat alarmingly, the current advisory goes on to compare the issue to MS10-070, an emergency patch for CVE-2010-3332, an infamous zero-day vulnerability in the way Windows ASP.NET handled cryptographic errors that caused a degree of panic in 2010.
Not a simple update
Normally, when flaws are uncovered, the drill involves merely applying an update, workaround, or mitigation. In this case, the update itself should have already happened automatically for server builds, taking runtimes to the patched version 10.0.7.
However, for developers using the popular Docker container platform, things are more complicated. For those projects, the Data Protection Library is also embedded in built applications. Addressing this requires updating and rebuilding any ASP.NET Core applications created after the April 14 update.
In addition, those using 10.0.x on the netstandard2.0 or net462 target framework asset from the flawed NuGet package, for compatibility with older operating systems including Windows, are also affected.
Detecting affected binaries
How will developers know if a vulnerable binary has been loaded? Microsoft’s security advisory offers the following advice:
“Check application logs. The clearest symptom is users being logged out and repeated The payload was invalid errors in your logs after upgrading to 10.0.6. Check your project file. Look for a PackageReference to Microsoft.AspNetCore.DataProtection version 10.0.6 in your .csproj file (or in a package that depends on it). You can also run dotnet list package to see resolved package versions.”
In summary, developers should rebuild affected applications to apply the fixed version, expire all affected authentication cookies and tokens to remove forgeries, and rotate to apply new ASP.NET Core Data Protection tokens.
While there is no evidence that the issue has been exploited by attackers, good security hygiene mandates also checking for unexpected or unusual logins failures, errors, or authentication failures, Microsoft advised.
View the full article
Google today commented on its partnership with Apple, confirming that Gemini will power a new, more personalized version of Siri that's set to be released later in 2026.


Google Cloud chief Thomas Kurian mentioned the Apple partnership during Google Cloud Next 2026, a conference that's taking place in Las Vegas, Nevada today.

Kurian's comment doesn't provide us with any new information because Apple has already committed to a 2026 launch for the new ‌Siri‌ features. When Apple first delayed the smarter ‌Siri‌ in March 2025, the company said it would launch "in the coming year."

Later in 2025, Apple said that ‌Siri‌ would get an update at some point in 2026, though it did not provide a specific launch timeline. In February 2026, Apple confirmed to CNBC that the new version of ‌Siri‌ is still set to come out this year.

According to rumors, Apple was planning to release the Apple Intelligence version of ‌Siri‌ in spring 2026, but ran into issues with accuracy. Since Apple never gave a launch date beyond 2026, the ‌Siri‌ update isn't exactly delayed, but Apple has needed to adjust its internal schedule. Apple has until December 31, 2026 to update ‌Siri‌, but we could get a first look at the new personal assistant in iOS 27.

Kurian did say that Google Cloud is Apple's "preferred cloud provider," which is the same language that Google used earlier this year. It continues to be unclear if the new ‌Siri‌ and Gemini-powered ‌Apple Intelligence‌ features will use Private Cloud Compute or will run on Google's servers.

Apple has asked Google to investigate setting up servers in Google data centers to run ‌Siri‌ because Apple is anticipating much more cloud usage when the smarter ‌Siri‌ launches.

Apple plans to introduce ‌iOS 27‌ at the Worldwide Developers Conference, which is set to begin on June 8, 2026. We'll hear more about ‌Siri‌ at WWDC.Tags: Gemini, Google, Siri, Siri Chatbot
This article, "Google Confirms Gemini-Powered Siri Coming Later This Year" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Cybersecurity researchers have warned of malicious images pushed to the official "checkmarx/kics" Docker Hub repository. In an alert published today, software supply chain security company Socket revealed that unknown threat actors managed to have overwritten existing tags, including v2.1.20 and alpine, while also introducing a new v2.1.21 tag that does not correspond to an official release. TheView the full article
Apple today released minor iOS 26.4.2 and iPadOS 26.4.2 software updates for the iPhone and iPad, respectively. The updates are available two weeks after Apple released iOS 26.4.1 and iPadOS 26.4.1.


The new software can be downloaded on eligible iPhones and iPads over-the-air by going to Settings → General → Software Update.

According to Apple's release notes, the software updates contain unspecified bug fixes and security updates.

Apple also released iOS 18.7.8 for older iPhones that are not updated to iOS 26.

Apple is already beta testing iOS 26.5 and iPadOS 26.5, the next versions of ‌iOS 26‌ that will likely launch later in May.Related Roundups: iOS 26, iPadOS 26Related Forum: iOS 26
This article, "Apple Releases iOS 26.4.2 and iPadOS 26.4.2 With Bug Fixes" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
OpenAI this week introduced ChatGPT Images 2.0, which the company says brings a new era of image generation. Images 2.0 is an updated model that can better handle complex visual tasks.


It is able to follow detailed instructions, placing and relating objects accurately, preserving fine detail, and rendering dense layouts. Images 2.0 is OpenAI’s first image model with thinking capabilities, and it has an improved sense of composition and visual taste, which OpenAI says will result in images that feel less AI-generated.

Images 2.0 is able to search the web to get real-time information, create up to eight images from a single prompt, and double-check its output. Graphics can be created across several aspect ratios and at up to 2K resolution. The new model also has improved multilingual understanding and can better render non-Latin text like Japanese, Korean, Chinese, Hindi, and Bengali.

Images 2.0 is available now for all ChatGPT, Codex, and API users.Tags: ChatGPT, OpenAI
This article, "OpenAI Launches ChatGPT Images 2.0 With Thinking Capabilities and Better Text Rendering" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Following the emergence of a rumor that Apple is planning to downgrade the iPhone 18 to cut costs, further detail has emerged suggesting that display and chip specifications will see downgrades.


Earlier this week, the leaker known as "Fixed Focus Digital" said that the ‌iPhone 18‌ features "certain manufacturing downgrades" that bring it more into line with the low-cost iPhone 18e model. The decision is said to be "a cost-cutting measure."

Now, the leaker has provided further detail. For example, the ‌iPhone 18‌'s display specifications will be downgraded, resulting in inferior screen quality. The manufacturing process itself is said to be "taking a step backward."

The iPhone 17 features a 6.3-inch display with ProMotion and up to 3,000 nits of peak outdoor brightness. Since ProMotion was among the biggest upgrades for the device last year, it seems likely that brightness could be among the display specifications to be reduced.

In a follow-up post, the leaker provided some insight into Apple's decision. Rather than increase the price of the ‌iPhone 18‌, the company plans to downgrade certain components, including the chip, to maintain the same price point.

Although both the ‌iPhone 17‌ and iPhone 17e feature the A19 chip, the ‌iPhone 17‌'s variant has a five-core GPU, instead of the ‌iPhone 17e‌'s four-core version. The iPhone 17 Pro's A19 Pro chip is essentially the same but has a six-core GPU.

As a result, a reduction from five to four GPU cores in the ‌iPhone 18‌ could be among the planned downgrades. Fixed Focus Digital added that it is "highly probable" that Apple will tweak the name of the device's A-series chip in an effort to disguise the extent of downgrade.

The Weibo leaker ultimately doubled-down on the move, saying that "the downgrade in the standard ‌iPhone 18‌ model's specifications has now been confirmed." Engineering Validation Testing (EVT) of the ‌iPhone 18‌ and iPhone 18e are apparently set to take place simultaneously in June.

The leaker's previous report outlined Apple's decision to implement new cost-control strategies for the device, including specific downgrades to manufacturing processes, chips, memory, and more. The move will "effectively bring it in line with the '18e' model."

With the ‌iPhone 17e‌ and ‌iPhone 17‌, the biggest differences are the Dynamic Island, display size, ProMotion, brightness, the front facing camera, the Ultra Wide camera, and battery life. It is not clear which key differentiators will remain between the two devices in their next iterations.

iPhone 17e vs. iPhone 17 Buyer's Guide: 35+ Differences Compared

The leaker apparently verified the information using multiple sources. They noted that the information originates from the same source who correctly confirmed that the ‌iPhone 17e‌ would continue to feature a "notch," contrary to false reports that the device would have a ‌Dynamic Island‌.

The standard ‌iPhone 18‌ is expected to launch months after the iPhone 18 Pro models as part of an all-new split launch strategy. Apple's usual fall iPhone announcement is expected to include the ‌iPhone 18 Pro‌, ‌iPhone 18 Pro‌ Max, and the so-called foldable "iPhone Ultra." The iPhone 18e, ‌iPhone 18‌, and iPhone Air 2 will likely follow in the spring of 2027. Related Roundup: iPhone 18Tag: Fixed Focus DigitalRelated Forum: iPhone
This article, "Leaker: Apple to Downgrade iPhone 18 in Two Ways" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Opera has pushed another update for its flagship browser, with new changes aimed at making video streaming and conferencing better. Here are the details.


Opera users now get direct access to YouTube and Twitch from the browser sidebar, allowing them to pin the panel for side-by-side viewing or snap the video out with the Video Popout feature, which creates a floating overlay that they can move while navigating the web.

Meanwhile, in what the company is describing as a first for any browser, Opera now has an integrated Volume Booster that lets users increase a tab's volume by up to 500 percent. The feature includes per-tab control, so users can, for example, keep background music at a quiet 5%, while simultaneously boosting a quiet video in another tab to 500%.

The company says this native feature means users no longer need to rely on third-party volume extensions that can cause full-screen glitches and security warnings.

Opera is also touting major quality-of-life upgrades to remote working in the latest update. The app now fully supports any video conferencing website that supports PiP, which includes full compatibility with Zoom. Users also get per-site control over Auto-PiP permissions for every individual conferencing website. And in an aesthetic change for consistency, the Video Popout window matches the chosen Opera One theme for the first time.


Opera browser is available now as a free update and can be downloaded from the company's website.Tag: Opera Browser
This article, "Opera Browser Gains Per-Tab Volume Booster, Video Popout" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Last week, Macworld's Filipe Espósito reported that Apple is testing four color options for the iPhone 18 Pro and iPhone 18 Pro Max, and one of those colors has since been corroborated by a known leaker on the Chinese social media platform Weibo.


The four alleged color options include Light Blue, Dark Cherry, Dark Gray, and Silver.

Dark Cherry would be the signature new color option for the iPhone 18 Pro models this year, following Cosmic Orange for the iPhone 17 Pro models. This might end up being the "deep red" that was previously rumored for the devices.

Weibo leaker "Instant Digital" today corroborated the Dark Cherry color option, describing it as a mix of burgundy, coffee, and deep purple. Those were all previously-rumored iPhone 18 Pro color options, but it appears that they are actually one in the same.

"Instant Digital" has accurately leaked Apple information before, such as the yellow color for the iPhone 14 and iPhone 14 Plus.

Light Blue looks similar to the iPhone 13 Pro's Sierra Blue color option.

Depending on the shade, Dark Gray could be similar to either the iPhone 13 Pro's Graphite color option or the iPhone 14 Pro's Space Black finish.

Silver would remain an option too — it is Apple's classic color.

iPhone 17 Pro models are available in Cosmic Orange, Deep Blue, and Silver. Macworld said Cosmic Orange and Deep Blue will likely be discontinued, so do not expect either of those color options to remain available for the iPhone 18 Pro models.

Last year, Macworld accurately leaked the iPhone 17 Pro's Cosmic Orange and Deep Blue colors, but the report also mentioned black, white, and gray color options that did not materialize. So, at least some of the rumored iPhone 18 Pro colors will likely prove to be true, but it remains to be seen if Apple moves forward with all four.

Apple is expected to unveil the iPhone 18 Pro models in September.Related Roundup: iPhone 18 ProTag: Instant Digital
This article, "iPhone 18 Pro's Special Color Rumored Yet Again" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Amazon this week has all-time low prices on the Apple Watch Series 11, with $100 discounts across numerous models of the smartwatch. This sale includes a handful of aluminum models of the Series 11 on sale at record low prices.

Note: MacRumors is an affiliate partner with Amazon. When you click a link and make a purchase, we may receive a small payment, which helps us keep the site running.

You can get the 42mm GPS Apple Watch Series 11 for $299.00, down from $399.00, and the 46mm GPS model for $329.00, down from $429.00. On Amazon, you'll find two of both the 42mm and 46mm GPS models on sale at these all-time low prices.

$100 OFFApple Watch Series 11 (42mm GPS) for $299.00
$100 OFFApple Watch Series 11 (46mm GPS) for $329.00

In terms of cellular models, Amazon doesn't have any all-time low prices as of writing, but you can shop a few solid second-best deals this week. The 42mm cellular Apple Watch Series 11 has hit $429.00, down from $499.00, and the 46mm cellular model has hit $459.00, down from $529.00.

Head to our full Deals Roundup to get caught up with all of the latest deals and discounts that we've been tracking over the past week.



Deals Newsletter

Interested in hearing more about the best deals you can find in 2026? Sign up for our Deals Newsletter and we'll keep you updated so you don't miss the biggest deals of the season!




Related Roundup: Apple Deals
This article, "Apple Watch Series 11 Hits $100 Off on Amazon, Starting at $299" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Mike Rockwell, the Apple executive who led development of the Vision Pro and is now in charge of rebuilding Siri, has considered leaving the company or moving into an advisory role as soon as next year, according to a new Bloomberg report by Mark Gurman.


Rockwell is said to have reservations about reporting to his new boss, software chief Craig Federighi, and wants a bigger remit than the one he currently has, according to people with knowledge of the matter who spoke to Gurman. Rockwell was apparently once lined up for a role defining Apple's product and AI roadmap – something close to a chief technology officer position – on the assumption that head-worn wearables would form the foundation of Apple's post-iPhone era.

However, that trajectory has gone south because the Vision Pro has struggled to find a mainstream audience, with many put off by its $3,499 price tag and physical heft. Apple is still developing smart glasses and other wearables, but the picture for Rockwell is decidedly murkier than it once was.

Rockwell took on the Siri project in March 2025 as part of a wider reshuffle, after Tim Cook lost confidence in the AI work being done under former AI chief John Giannandrea and reassigned the voice assistant away from his team.

Gurman reports that Rockwell is unlikely to walk away before finishing the Siri overhaul, which is now expected to arrive as part of iOS 27. He is one of several senior Apple figures who are said to be weighing their next move as John Ternus prepares to take over from CEO Tim Cook in September.

Among them is retail and HR chief Deirdre O'Brien, who has told colleagues she is considering retirement, while government affairs head Kate Adams is set to retire later this year. Marketing boss Greg Joswiak, App Store head Phil Schiller, and services chief Eddy Cue are all approaching four decades at the company, raising the prospect of further departures during Ternus's watch. Related Roundup: Apple Vision ProTag: BloombergBuyer's Guide: Vision Pro (Buy Now)Related Forum: Apple Vision Pro
This article, "Vision Pro Creator Mike Rockwell Has Considered Leaving Apple" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Apple is evaluating four camera upgrades for future iPhone models, with the first new feature scheduled for this year's iPhone 18 Pro models, according to a reputable Chinese leaker.


The Weibo-based account Digital Chat Station claims that Apple has implementation plans for the following upgrades:

Variable aperture
1/1.12-inch "ultra-large" main camera sensor
Enhanced optical image stabilization for ultra-wide lens
200-megapixel periscope telephoto lens
The variable aperture is widely rumored to be introduced with the iPhone 18 Pro and iPhone 18 Pro Max, expected to launch this September. Apple supply chain analyst Ming-Chi Kuo reported in December 2024 that the main rear camera on both ‌iPhone 18 Pro‌ models will offer variable aperture. More recently in October, a report claimed that Apple is moving ahead with those plans and was discussing components with suppliers.

Apple has never implemented a variable aperture on an iPhone. From the iPhone 14 Pro through the iPhone 17 Pro, the main camera uses a fixed ƒ/1.78 aperture, meaning the lens remains fully open at all times when capturing images. In contrast, a variable aperture lets the camera control how much light reaches the sensor. In low-light conditions, it opens to admit more light, while in bright scenes, it closes to avoid overexposure. This should also give users more control over depth of field.

The other camera upgrades the leaker mentioned appear to be ones that Apple is testing for future models beyond the iPhone 18 Pro, with an unclear timeline for implementation.

Regarding the "ultra-large" main sensor, the 1/1.12-inch label is based on a legacy optical format, not a literal measurement. It dates back to video camera tubes, so the number doesn't correspond directly to the sensor's physical width. In practice, a 1/1.12-inch sensor has a diagonal of around 14.5mm – far smaller than the label might suggest, but very large by smartphone standards. It's the same size as Sony's LYTIA LYT-901, which is shipping in the Vivo X300 Ultra. It's significantly larger than the 1/1.28-inch main sensor the iPhone 17 Pro models use, and would offer improved low-light performance, dynamic range, and signal-to-noise ratio.

As for the 200-megapixel periscope telephoto lens, Digital Chat Station has mentioned multiple times that Apple is studying the technology, but they recently said it is unlikely to feature in an iPhone before 2028.

Digital Chat Station has more than three million followers on Weibo, and has a track record of accurately leaking Apple-related information. For example, they accurately revealed the overall design of the iPhone Air and iPhone 17 Pro, as well as the triple 48-megapixel rear camera system of the ‌iPhone 17 Pro.‌ Recently, the leaker claimed Apple's first foldable, expected to arrive alongside the iPhone 18 Pro models, will be called "iPhone Ultra."Related Roundup: iPhone 18 ProTag: Digital Chat Station
This article, "iPhone 18 Pro to Kick Off Apple's Four-Part Camera Upgrade Plan" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Cyber crooks are abusing a trojanized Android payment application to steal near field communication (NFC) data and PINs, enabling cloning of payment cards and draining victim accounts.
According to ESET researchers, a new variant of the NGate malware has been infused into the HandyPay NFC-relay application to transfer NFC data to the attacker’s device and use it for contactless ATM cash-outs.
Use of AI is suspected in the campaign. “To trojanize HandyPay, threat actors most probably used GenAI, indicated by emoji left in the logs that are typical of AI-generated text,“ the researchers said in a blog post.
The campaign has been distributing two malware samples, through a fake lottery website and a fake Google Play website, in attacks targeting Android users in Brazil since November 2025.
Legit app doing the dirty work
ESET researchers pointed out that the campaign marks NGate operators shifting from custom tooling to a trojanized legitimate application. HandyPay, originally designed to relay NFC data between devices, is being used to require minimal permissions and blend into expected payment workflows.
This approach avoids building custom tooling from scratch, previously seen with the NFCGate abuse, and instead adds malicious code into an existing NFC-capable app. By repurposing an NFC relay app, the attackers inherit functionality that already handles the core data exchange, the researchers noted.

An NFC-relay app is a tool that captures contactless communication from a card or device and forwards it in real time to another device, extending the short-range Near Field Communication signal over a network for remote use.
Because the app operates within expected NFC workflows, it is easier for attackers to mask the attack.
The distribution channels include a fake lottery site impersonating Brazil’s “Rio de Premios,” and a spoofed Google Play page advertising a “card protection” tool.
AI was likely used
ESET researchers also spotted something unusual in the malware’s internals. Some traces suggested generative AI may have played a role in its development.
Specifically, the injected malicious code contains emoji markers in debug logs, something more commonly associated with AI-generated output than human-written malware. The researchers noted that this isn’t definitive proof but aligns with a broader trend of attackers using large language models to accelerate malware creation.
Android presently has some protection against this attack vector in the form of security alerts. “The victim needs to manually install a trojanized version of HandyPay, since the app is only available outside Google Play,” the researchers said. “When a user taps the download app button in their browser, Android automatically blocks the install and shows a prompt asking them to allow installation from this source.”
For the attack to be successful, the user then needs to tap Settings in the prompt, enable “Allow from this source,” and return to installing the app, a process quite common with third-party app installation these days. Nothing particularly suspicious stands out in the “allow download” workflow to protect against this threat.
ESET shared a list of indicators in a dedicated GitHub repository, which included files, hashes, network indicators, and MITRE ATT&CK maps to support detection efforts.
View the full article

Account

Navigation

Search

Search

Configure browser push notifications

Chrome (Android)
  1. Tap the lock icon next to the address bar.
  2. Tap Permissions → Notifications.
  3. Adjust your preference.
Chrome (Desktop)
  1. Click the padlock icon in the address bar.
  2. Select Site settings.
  3. Find Notifications and adjust your preference.