Skip to content
View in the app

A better way to browse. Learn more.

hosang I.T.

A full-screen app on your home screen with push notifications, badges and more.

To install this app on iOS and iPadOS
  1. Tap the Share icon in Safari
  2. Scroll the menu and tap Add to Home Screen.
  3. Tap Add in the top-right corner.
To install this app on Android
  1. Tap the 3-dot menu (⋮) in the top-right corner of the browser.
  2. Tap Add to Home screen or Install app.
  3. Confirm by tapping Install.

Tech

Tech Articles from a wide variety of topics and categories
A China-aligned threat actor has set its sights on European government and diplomatic organizations since mid-2025, following a two-year period of minimal targeting in the region. The campaign has been attributed to TA416, a cluster of activity that overlaps with DarkPeony, RedDelta, Red Lich, SmugX, UNC6384, and Vertigo Panda. "This TA416 activity included multipleView the full article
Google has patched another zero-day vulnerability in Chrome, its fourth this year. In patching the vulnerability, tracked as CVE-2026-5281, the company acknowledged that an exploit for it already exists in the wild.
According to the report in NIST’s National Vulnerability Database, the vulnerability in Dawn, the implementation of WebGPU used by Chrome, allowed a remote attacker who had compromised the renderer process to execute arbitrary code via a crafted HTML page. It advised users to update to Chrome 146.0.7680.178 or newer.
The three previous vulnerabilities patched in Chrome this year were in different areas of the code.
The first, tracked as CVE-2026-2441 and patched in February, was a fault in the way memory was managed in the processing of cascading style sheets (CSS).
The other two were patched in March. One was a bug in the Skia graphics library (CVE-2026-3909) that allowed write access to memory addresses outside the boundaries of a predefined buffer. The second one (CVE-2026-3910) was found in the V8 JavaScript engine, and was described by Google as an “inappropriate implementation.”
It will concern Google that, barely a quarter way through the year, it has already had to deliver fixes for four exploits in the wild. Last year, it introduced Code Mender, a security tool to help fix security vulnerabilities in open source projects, and will be looking to introduce more AI help to fix these issues.

View the full article
Researchers who identify and report bugs in open-source software will no longer be rewarded by the Internet Bug Bounty team. HackerOne, which administers the program, has said that it is “pausing submissions” while it contemplates ways in which open source security can be handled more effectively.
The Internet Bug Bounty program, funded by a number of leading software companies, has been run since 2012 and has awarded more than $1.5m to researchers who have reported bugs. Up to now, 80% of its payouts have been for discoveries of new flaws, and 20% to support remediation efforts. But as artificial intelligence makes it easier to find bugs, that balance needs to change, HackerOne said in a statement.
“AI-assisted research is expanding vulnerability discovery across the ecosystem, increasing both coverage and speed. The balance between findings and remediation capacity in open source has substantively shifted,” said HackerOne.
Among the first programs to be affected is the Node.js project, a server-side JavaScript platform for web applications known for its extensive ecosystem. While the project team will continue to accept and triage bug reports through HackerOne, without funding from the Internet Bug Bounty program it will no longer pay out rewards, according to an announcement on its website.
The Internet Bug Bounty Program is not the only bug-hunting project that has struggled with the onset of AI in vulnerability hunting. In January, the Curl program said that it was not taking any more submissions. And just last month, Google also put a halt to AI-generated submissions provided to its Open Source Software Vulnerability Reward Program.
This article first appeared on InfoWorld.
View the full article
If you often find yourself adding a track to an Apple Music playlist, going back, and then adding it to other playlists, iOS 26.4 includes an option that could save you bags of time: You can now select multiple playlists when adding a song.


Previously, tapping Add to Playlist would take you to a list of your playlists, and you could only pick one at a time. In iOS 26.4, there's a new multi-select option that lets you check off as many playlists as you like in one go. Here's how it works.

In the Music app, find the song you want to add.
Long press the song, or tap the three-dot menu (...) next to it.
Tap Add to Playlist.

In the bottom-right corner, tap the new multi-select button.
Select all the playlists you want to add the song to – each one gets a red checkmark.
Tap the checkmark button in the top-right corner to confirm.

The header at the top of the screen will update to reflect how many playlists you've selected, so you can keep track before confirming.

It might seem like a minor addition, but if you maintain several playlists organized by mood, genre, or occasion, it eliminates so much back-and-forth navigation. It's no exaggeration to say that some users will have been waiting years for this option.

In iOS 26.4, Apple has also given albums and playlists a new fullscreen design so that the album artwork colors style the entire background of the track list and other UI elements to give each album a more immersive, authentic look. To check out what's new, make sure your iPhone is up-to-date with the latest version by going to Settings ➝ General ➝ Software Update.Related Roundups: iOS 26, iPadOS 26Tag: Apple MusicRelated Forum: iOS 26
This article, "This Music Selection Tweak in iOS 26.4 Will Save You Bags of Time" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
The leak of Claude Code’s source is already having consequences for the tool’s security. Researchers have spotted a vulnerability documented in the code.
The vulnerability, revealed by AI security company Adversa, is that if Claude Code is presented with a command composed of more than 50 subcommands, then for subcommands after the 50th it will override compute-intensive security analysis that might otherwise have blocked some of them, and instead simply ask the user whether they want to go ahead. The user, assuming that the block rules are still in effect, may unthinkingly authorize the action.
Incredibly, the vulnerability is documented in the code, and Anthropic has already developed a fix for it, the tree-sitter parser, which is also in the code but not enabled in public builds that customers use, said Adversa.
Adversa outlined how attackers might exploit the vulnerability by distributing a legitimate-looking code repository containing a poisoned CLAUDE.md file. This would contain instructions for Claude Code to build the project, with a sequence of 50 or more legitimate-looking commands, followed by a command to, for example, exfiltrate the victim’s credentials. Armed with those credentials, the attackers could threaten a whole software supply chain.
This article first appeared on Infoworld.
View the full article
The European Union’s Computer Emergency Response Team, CERT-EU, has traced last week’s theft of data from the Europa.eu platform to the recent supply chain attack on Aqua Security’s Trivy open-source vulnerability scanner.
The attack on the AWS cloud infrastructure hosting the Europa.eu web hub on March 24 resulted in the theft of 350 GB of data (91.7 GB compressed), including personal names, email addresses, and messages, according to CERT-EU’s analysis.
The compromise of Trivy allowed attackers to access an AWS API key, gaining access to a range of European Commission web data, including data related to “42 internal clients of the European Commission, and at least 29 other Union entities using the service,” it said.
“The threat actor used the compromised AWS secret to create and attach a new access key to an existing user, aiming to evade detection. They then carried out reconnaissance activities,” said CERT-EU. The organization had found no evidence that the attackers had moved laterally to other AWS accounts belonging to the Commission.
Given the timing and involvement of AWS credentials, “the European Commission and CERT-EU have assessed with high confidence that the initial access vector was the Trivy supply-chain compromise, publicly attributed to TeamPCP by Aqua Security,” it said.
In the event, the stolen data became public after the group blamed for the attack, TeamPCP, leaked it to the ShinyHunters extortion group, which published it on the dark web on March 28.
Back door credentials
The Trivy compromise dates to February, when TeamPCP exploited a misconfiguration in Trivy’s GitHub Actions environment, now identified as CVE-2026-33634, to establish a foothold via a privileged access token, according to Aqua Security.
Discovering this, Aqua Security rotated credentials but, because some credentials remain valid during this process, the attackers were able to steal the newly rotated credentials.
By manipulating trusted Trivy version tags, TeamPCP forced CI/CD pipelines using the tool to automatically pull down credential-stealing malware it had implanted.
This allowed TeamPCP to target a variety of valuable information including AWS, GCP, Azure cloud credentials, Kubernetes tokens, Docker registry credentials, database passwords, TLS private keys, SSH keys, and cryptocurrency wallet files, according to security researchers at Palo Alto Networks. In effect, the attackers had turned a tool used to find cloud vulnerabilities and misconfigurations into a yawning vulnerability of its own.
CERT-EU advised organizations affected by the Trivy compromise to immediately update to a known safe version, rotate all AWS and other credentials, audit Trivy versions in CI/CD pipelines, and most importantly ensure GitHub Actions are tied to immutable SHA-1 hashes rather than mutable tags.
It also recommended looking for indicators of compromise (IoCs) such as unusual Cloudflare tunnelling activity or traffic spikes that might indicate data exfiltration.
Extortion boost
The origins and deeper motives of TeamPCP, which emerged in late 2025, remain unclear. The leaking of stolen data suggests it might be styling itself as a sort of initial access broker which sells data and network access on to the highest bidder.
However, the fact that stolen data was handed to a major ransomware group suggests that affected organizations are likely to face a wave of extortion demands in the coming weeks.
If so, this would be a huge step backwards at a time when ransomware has been under pressure as the proportion of victims willing to pay ransoms has declined.
The compromise of Trivy, estimated to have affected at least 1,000 SaaS environments, is rapidly turning into the one of the most consequential supply-chain incidents of recent times.
The number of victims is likely to grow in the coming weeks. Others caught up in the incident include Cisco, which reportedly lost source code, security testing company Checkmarx, and AI gateway company LiteLLM.

View the full article
On this week's episode of The MacRumors Show, we talk through everything the iPhone 18 Pro will feature, according to the latest rumors.

Subscribe to The MacRumors Show YouTube channel for more videos
Following last year's major redesign, the ‌iPhone 18 Pro‌ models are expected to feature a very similar design to their predecessors. There is likely to be a smaller Dynamic Island, with Face ID's flood illuminator component moved under the screen to reduce the cutout's size. It is rumored to be approximately 35% narrower than the iPhone 17 Pro's. The Pro Max will be slightly thicker than its predecessor, rising to around 8.8mm and over 240 grams to accommodate a larger battery of 5,100 to 5,200 mAh, up from the ‌iPhone 17 Pro‌ Max's 5,088 mAh.

The rear will see a slight design shift as well. Apple is reportedly dropping the two-tone look found on ‌iPhone 17 Pro‌ models in favor of a more seamless aesthetic, with improved alignment between the Ceramic Shield back glass and the aluminum frame. The devices are also expected to come in a special red color.

The camera system will undergo more substantial changes. Both Pro models' main 48-megapixel Fusion camera are rumored to feature variable aperture, which would allow users to control the lens opening to manage light intake and depth of field. The aperture would function similarly to a DSLR camera, giving photographers greater control over focus sharpness and background blur in different lighting conditions. Additionally, Samsung is developing a new three-layer sensor for the ‌iPhone 18 Pro‌, designed to reduce noise, improve dynamic range, and enhance camera responsiveness compared to Sony's current sensors.

The Camera Control button is also getting a simplification. Rather than supporting both capacitive touch gestures and pressure sensing as on the iPhone 17, the iPhone 18 will rely on pressure sensing alone, reducing manufacturing complexity and the cost of repairs, while improving ease of use.

The A20 Pro chip will mark Apple's debut of a 2-nanometer processor, with a reported 15% speed increase and about 30% better power efficiency compared to the A19 Pro. The chip will use TSMC's Wafer-Level Multi-Chip Module technology, integrating RAM directly onto the same wafer as the CPU, GPU, and Neural Engine rather than mounting it separately, which should improve performance and battery life while reducing the physical footprint of the chip.

The ‌iPhone 18 Pro‌ models will also feature Apple's C2 modem, which is expected to bring faster speeds, improved power efficiency, and support for mmWave 5G in the United States, a capability absent from the C1 and C1X modems used in earlier iPhones. Other upgrades include Apple's N2 wireless chip and 5G satellite internet.

The ‌iPhone 18 Pro‌ and ‌iPhone 18 Pro‌ Max are expected to launch in September 2026, with the standard ‌iPhone 18‌ and the lower-end iPhone 18e following in spring 2027. A foldable iPhone is also expected to debut alongside the Pro models in the fall. The MacRumors Show has its own YouTube channel, so make sure you're subscribed to keep up with new episodes and clips.

Subscribe to The MacRumors Show YouTube channel!

You can also listen to ‌The MacRumors Show‌ on Apple Podcasts, Spotify, Overcast, or other podcast apps. You can also copy our RSS feed directly into your player.



If you haven't already listened to the previous episode of The MacRumors Show, catch up to hear our discussion about Apple's announcement of its 37th annual Worldwide Developers Conference (WWDC), where the company is expected to unveil a major Siri overhaul alongside iOS 27, macOS 27, and other next-generation operating systems.

Subscribe to ‌The MacRumors Show‌ for new episodes every week, where we discuss some of the topical news breaking here on MacRumors, often joined by interesting guests such as Kayci Lacob, Kevin Nether, John Gruber, Mark Gurman, Jon Prosser, Luke Miani, Matthew Cassinelli, Brian Tong, Quinn Nelson, Jared Nelson, Eli Hodapp, Mike Bell, Sara Dietschy, iJustine, Jon Rettinger, Andru Edwards, Arnold Kim, Ben Sullins, Marcus Kane, Christopher Lawley, Frank McShan, David Lewis, Tyler Stalman, Sam Kohl, Federico Viticci, Thomas Frank, Jonathan Morrison, Ross Young, Ian Zelbo, and Rene Ritchie.

‌The MacRumors Show‌ is on X @MacRumorsShow, so be sure to give us a follow to keep up with the podcast. You can also email us at [email protected] or head over to The MacRumors Show forum thread. Remember to rate and review the podcast, and let us know what subjects and guests you would like to see in the future.Related Roundup: iPhone 18 ProTag: The MacRumors Show
This article, "The MacRumors Show: Everything We Know About iPhone 18 Pro" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Threat actors are increasingly using HTTP cookies as a control channel for PHP-based web shells on Linux servers and to achieve remote code execution, according to findings from the Microsoft Defender Security Research Team. "Instead of exposing command execution through URL parameters or request bodies, these web shells rely on threat actor-supplied cookie values to gate execution,View the full article
Earlier this week, Apple seeded the first beta of iOS 26.5 to developers. The software update is relatively minor so far, which is not too surprising given that Apple is likely shifting its focus towards iOS 27. Apple is expected to unveil iOS 27 during its WWDC 2026 keynote on June 8, and the update should be released in September.


Below, we outline what is new in iOS 26.5 so far, along with rumored iOS 27 features.

iOS 26.5

iOS 26.5 lays the groundwork for two changes, including end-to-end encryption for RCS in the Messages app and ads in the Apple Maps app.

End-to-end encryption for ‌RCS‌ is a security feature that ensures that messages sent between supported iOS 26.5 and Android devices are encrypted and cannot be intercepted and read by a third party while they are being delivered.

Apple already tested end-to-end encryption for RCS in the iOS 26.4 beta, but the feature did not make it into the final release of iOS 26.4 last week. It remains to be seen if the feature launches with iOS 26.5, or if it will be removed again before beta testing ends and return at some point during the iOS 27 software cycle.

Last month, Apple announced that ads are coming to the Apple Maps app on the iPhone and iPad in the U.S. and Canada starting "this summer," and there is evidence of Apple preparing for that within iOS 26.5's code.


Apple says businesses in the U.S. and Canada will be able to place ads in search results and at the top of a new "Suggested Places" section in the app.

The new "Suggested Places" section is visible in the iOS 26.5 beta.

"Ads on Maps will appear when users search in Maps, and can appear at the top of a user's search results based on relevance, as well as at the top of a new Suggested Places experience in Maps, which will display recommendations based on what's trending nearby, the user's recent searches, and more," says Apple.

Similar to the ads that are already shown in App Store search results on the iPhone and iPad, ads in Apple Maps will have an "Ad" label, and Apple promises strong privacy protections. For example, Apple says a user's location and the ads they see and interact with in Apple Maps are not associated with a user's Apple Account.

Read our coverage of Apple's announcement for more details about the ads.

In the iOS 26.5 beta, Apple is working to extend iPhone features like notifications, Live Activities, and AirPods-like pairing to third-party smartwatches and headphones in the EU, as required under the Digital Markets Act.

Beyond that, iOS 26.5 has only a few other minor changes.

iOS 27

Apple's long-awaited Siri revamp is finally expected to arrive with iOS 27.

The more personalized version of Siri will have understanding of a user's personal context, on-screen awareness, and deeper per-app controls. For example, during its WWDC 2024 keynote, Apple showed an iPhone user asking Siri about their mother's flight and lunch reservation plans based on info from the Mail and Messages apps.


That is not all, though, as iOS 27 will reportedly feature a dedicated Siri app with its own chatbot functionality and conversation history, or users will be able to tap into third-party chatbots such as OpenAI's ChatGPT, Google's Gemini, and Anthropic's Claude through a so-called "Extensions" feature in the app.

Earlier this year, Apple and Google announced that Gemini will help to power Apple Intelligence's underlying models and features, including the more personalized version of Siri. iOS 27 will likely expand Apple Intelligence to additional Apple apps, and it was rumored that this will include the Apple Calendar app.

iOS 27 will reportedly support 5G satellite internet connectivity, although this functionality might be limited to the upcoming iPhone 18 Pro models with Apple's next-generation C2 modem. Additional satellite features have been rumored, including Apple Maps via satellite and the ability to send and receive photos when using Messages via satellite.

iOS 27 may be similar to Mac OS X Snow Leopard, in the sense that Apple is apparently focused on improving "quality and underlying performance." Apple is expected to focus on bug fixes, improved stability, and Liquid Glass design enhancements.

Apple has reportedly tested an updated iPhone keyboard with enhanced autocorrect. The features should debut on iOS 27 if Apple moves forward with it.

Similar to Grammarly, the keyboard "expands autocorrect by offering alternative words."

iOS 27 is not expected to include any major Liquid Glass design changes, but the update may add a system-wide Liquid Glass slider for precisely adjusting the opacity of the interface. A similar slider already exists for the Lock Screen's clock.

Of course, these are only the known or rumored features so far.Related Roundups: iOS 26, iPadOS 26, iOS 27Related Forum: iOS 26
This article, "iOS 26.5 and iOS 27 Will Add These New Features to Your iPhone" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
This week was the launch of the AirPods Max 2, and Amazon has the first cash discount on these brand new headphones for launch week. Below, you'll also find great deals on the M5 MacBook Air, 2026 Studio Display, and M4 iPad Air.

Note: MacRumors is an affiliate partner with some of these vendors. When you click a link and make a purchase, we may receive a small payment, which helps us keep the site running.

AirPods Max 2


What's the deal? Take $20 off AirPods Max 2
Where can I get it? Amazon
Where can I find the original deal? Right here
$20 OFFAirPods Max 2 for $529.00

Apple's new AirPods Max 2 launched this week, and Amazon is one of the only retailers offering any sort of discount on the headphones. You can get the Midnight and Starlight color options for $529.00 on Amazon, down from $549.00.

M5 MacBook Air


What's the deal? Take up to $84 off M5 MacBook Air
Where can I get it? Amazon
Where can I find the original deal? Right here
$66 OFF13-inch M5 MacBook Air (512GB) for $1,033.00
$84 OFF13-inch M5 MacBook Air (24GB/1TB) for $1,415.50

Amazon has introduced a few new record low prices on the new M5 MacBook Air this week, with up to $84 off these notebooks. The biggest markdowns can be found on the 13-inch MacBook Air, but there are still some solid deals on 15-inch models as well.

Apple Studio Display


What's the deal? Take $100 off the new Studio Display
Where can I get it? Amazon
Where can I find the original deal? Right here
$100 OFFApple Studio Display (Standard/Tilt) for $1,499.00
$100 OFFApple Studio Display (Standard/VESA) for $1,499.00
$100 OFFApple Studio Display (Nano-Texture/VESA) for $1,799.00
$100 OFFApple Studio Display (Standard/Tilt and Height) for $1,899.00

Apple just launched the new line of Studio Displays last month, and Amazon already has a few $100 discounts on select models. You can get the Standard Glass Studio Display with Tilt-Adjustable Stand for $1,499.00, down from $1,599.00, an all-time low price.

M4 iPad Air


What's the deal? Take up to $80 off M4 iPad Air
Where can I get it? Amazon
Where can I find the original deal? Right here
$40 OFF11-inch M4 iPad Air for $559.00
$50 OFF13-inch M4 iPad Air for $749.00

Last month saw the launch of all of Apple's new products, and Amazon is already offering good discounts on many models of the M4 iPad Air. We're seeing up to $80 off both the 11-inch and 13-inch models, which is solid for a brand-new product.

If you're on the hunt for more discounts, be sure to visit our Apple Deals roundup where we recap the best Apple-related bargains of the past week.



Deals Newsletter

Interested in hearing more about the best deals you can find in 2026? Sign up for our Deals Newsletter and we'll keep you updated so you don't miss the biggest deals of the season!




Related Roundup: Apple Deals
This article, "Best Apple Deals of the Week: AirPods Max 2 Launch Deal Arrives, Plus $100 Off Apple Studio Display and More" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
An incredibly busy March in the Apple world has come to end, punctuated by the company celebrating its 50th anniversary on April 1.


That doesn't mean the news and rumors have stopped, however, as this week saw new discussion of the foldable iPhone, the iPhone 18 Pro, a potential future iMac upgrade, and much more to come throughout the remainder of the year, so read on below for all the details!

Top Stories

Apple Preparing 'Most Significant Overhaul in the iPhone's History'

Bloomberg's Mark Gurman has high expectations for Apple's first foldable iPhone. In his Power On newsletter this week, he said the foldable iPhone will be "the most significant overhaul in the iPhone's history."


"iPhone 4, iPhone 6 and iPhone X were clearly a big deal, but this is a whole new design," he said. Like Samsung's Galaxy Z Fold 7, the foldable iPhone will reportedly open up like a book, providing users with a large inner screen for watching videos, playing games, and multitasking. iOS 27 is expected to be optimized for the foldable iPhone, allowing for apps to be open side-by-side and for other iPad-like multitasking functionality.

We're expecting the foldable iPhone to be unveiled in September alongside iPhone 18 Pro and iPhone 18 Pro Max models, though it may not ship until a few months later.

Everything New in iOS 26.5 Beta 1

Following last week's public release of iOS 26.4 and related updates, this week saw the first developer betas of iOS 26.5, macOS Tahoe 26.5, and more.


While we still haven't seen the revamped Siri powered by Apple Intelligence that had previously been rumored for iOS 26.4 and is now seemingly pushed back until iOS 27, the new update does have some changes and we've recapped all of the ones we've spotted in the first beta.

Apple to Launch These 15+ New Products Later This Year

March was an incredibly busy month for Apple, with the company unveiling more than 10 new products and accessories. We said hello to the MacBook Neo at the start of the month, and we bid farewell to the Mac Pro at the end of it.


Nevertheless, there is still a lot more to come this year.

Beyond the usual annual updates to iPhones and Apple Watches, Apple's all-new smart home hub is finally expected to launch later this year, once the more personalized version of Siri arrives. We are also expecting a foldable iPhone, a MacBook Pro with an OLED display, and long-awaited updates to the Apple TV and HomePods this year.

Check out our full list of everything we're expecting to see through the rest of this year, according to rumors.

Apple Celebrates 50th Anniversary With Employee Gifts, Finale Concert With Paul McCartney at Apple Park

Apple celebrated its 50th anniversary this week, and the company's month-long celebration that saw a variety of events around the world culminated with a major party at Apple Park.


As hinted at by Bloomberg's Mark Gurman over the previous weekend, the Apple Park celebration was highlighted by a concert by Paul McCartney. Apple employees also received commemorative t-shirts, enamel pins, and limited-edition posters to mark the milestone anniversary.

iPhone 18 Pro's Smaller Dynamic Island Revealed

New images of an alleged iPhone 18 Pro prototype and screen protectors have emerged from multiple sources, adding weight to earlier reports that Apple plans to significantly shrink the Dynamic Island later this year.


An X user called @earlyappleleaks recently shared an image purportedly showing a prototype ‌iPhone 18 Pro‌ with a noticeably smaller ‌Dynamic Island‌. In the picture, the flashlight of another iPhone is held over the corner of the display, revealing a small circular punch-hole cutout under the display, which is presumably a relocated Face ID sensor.

Apple Reportedly Planning to Launch iMac With OLED Display

Apple is preparing to launch an iMac featuring an OLED panel with higher brightness, according to ZDNet Korea.


Apple has apparently requested that Samsung Display, LG Display, and other suppliers produce 24-inch OLED panel samples suitable for a future ‌iMac‌ model using their mass-production facilities. This would be the biggest ever OLED display offered on an Apple device.

Specifically, Apple asked suppliers for 24-inch OLED panels with 600 nits of brightness and around 218 pixels-per-inch (PPI). By comparison, the current ‌iMac‌ features a 24-inch LCD display with 500 nits of brightness and 218 PPI.

MacRumors Newsletter

Each week, we publish an email newsletter like this highlighting the top Apple stories, making it a great way to get a bite-sized recap of the week hitting all of the major topics we've covered and tying together related stories for a big-picture view.

So if you want to have top stories like the above recap delivered to your email inbox each week, subscribe to our newsletter!Tag: Top Stories
This article, "Top Stories: Foldable iPhone, iOS 26.5 Beta, Apple's 50th, and More" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
While the iPhone 18 Pro and iPhone 18 Pro Max are not expected to launch for more than five more months, there are already plenty of rumors about the devices.


It was initially reported that the iPhone 18 Pro models would have fully under-screen Face ID, with only a front camera visible in the top-left corner of the screen. However, the latest rumors indicate that only one Face ID component will be moved under the screen on the devices, which will result in merely a smaller Dynamic Island.

Below, we have recapped 12 features rumored for the iPhone 18 Pro models, as of April 2026:Red Color: The special color for the iPhone 18 Pro models will reportedly be red.
Smaller Dynamic Island: It has been rumored that Face ID's flood illuminator will be moved under the screen on the iPhone 18 Pro models, paving the way for a smaller Dynamic Island on the devices.
6.3-inch and 6.9-inch Display Sizes: The next Pro models are expected to have the same overall design as the iPhone 17 Pro models, including 6.3-inch and 6.9-inch display sizes and a "plateau" housing three rear cameras.
LTPO+ Displays: More power-efficient displays could contribute to longer battery life.
Variable Aperture: The main 48-megapixel Fusion camera on both iPhone 18 Pro models is rumored to have a variable aperture, which would allow users to control the amount of light that passes through the camera's lens and reaches the sensor. This would provide greater control over depth of field. However, given that iPhones have smaller image sensors due to smartphone size constraints, it is unclear exactly how meaningful this improvement would be.
A20 Pro Chip: Apple's next-generation A20 Pro chip is expected to use TSMC's first-generation 2nm process, whereas the A19 Pro chip is 3nm. With a 2nm architecture and a new packaging design, the A20 Pro chip should deliver solid year-over-year performance and power efficiency gains.
C2 Modem: Apple's custom C1 cellular modem for 5G and LTE debuted in the iPhone 16e last year, and that was followed by a C1X chip in the iPhone Air. Apple says the C1X modem is up to twice as fast as the C1 modem, and the most power-efficient modem in an iPhone ever. The improvements should continue with Apple's third-generation C2 modem in the iPhone 18 Pro models.
N2 Chip: Most of the iPhone 17 models and the iPhone Air are equipped with an Apple-designed N1 chip that enables Wi-Fi 7, Bluetooth 6, and Thread. Apple says the N1 chip also improves the overall performance and reliability of features like Personal Hotspot and AirDrop. iPhone 18 Pro models are expected to have Apple's next-generation N2 chip, but it is not yet known what improvements would come with this upgrade.
A simplified Camera Control button with no swipe gestures.
Design changes to the rear Ceramic Shield for MagSafe charging, potentially including a more frosted glass appearance.
Web browsing via satellite.
The iPhone 18 Pro Max may be slightly thicker than the iPhone 17 Pro Max, perhaps to accommodate a larger battery.Apple is expected to release the iPhone 18 Pro, iPhone 18 Pro Max, and a foldable iPhone in September, followed by a standard iPhone 18 model, a lower-end iPhone 18e, and potentially a second-generation iPhone Air early next year.Related Roundup: iPhone 18 Pro
This article, "iPhone 18 Pro Launching Later This Year With These 12 New Features" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
The maintainer of the Axios npm package has confirmed that the supply chain compromise was the result of a highly-targeted social engineering campaign orchestrated by North Korean threat actors tracked as UNC1069. Maintainer Jason Saayman said the attackers tailored their social engineering efforts "specifically to me" by first approaching him under the guise of the founder of aView the full article
The next major breach hitting your clients probably won't come from inside their walls. It'll come through a vendor they trust, a SaaS tool their finance team signed up for, or a subcontractor nobody in IT knows about. That's the new attack surface, and most organizations are underprepared for it. Cynomi's new guide, Securing the Modern Perimeter: The Rise of Third-PartyView the full article
Cybersecurity researchers have discovered a new version of the SparkCat malware on the Apple App Store and Google Play Store, more than a year after the trojan was discovered targeting both the mobile operating systems. The malware has been found to conceal itself within seemingly benign apps, such as enterprise messengers and food delivery services, whileView the full article
The 2026 RSA circus is over. The tents are packed and the elephants have been loaded onto the train.
Nevertheless, it was an eventful week. There were fleets of vehicles — Escalades, Rivians, trucks but curiously, no Teslas — strewn with vendor names and tag lines, and you couldn’t walk anywhere near Howard Street in San Franciso without seeing, “AI-[insert word here like enabled, enhanced, native, powered, etc., etc., etc.]”
I spent the week speaking with CISOs, cybersecurity professionals, technology vendors, and service providers. Here are a few of my takeaways.
The CISO AI hierarchy is real
While every vendor communicated AI opportunity gaga, cybersecurity professionals’ mood was one of trepidation. In fact, I came away with a profile of three distinct CISO archetypes:
The proactive CISO (approximately 20%): These security leaders were well aware of the AI-driven business and technology changes afoot and came armed with a list of questions tailored to their specific enterprise requirements. Many of these executives brought along security engineers and architects — an action-oriented team. These CISOs had a decent understanding about their organization’s AI business initiatives, as well as their own security needs. The goal? Develop a shopping list that aligns with their organization’s strategy and supports their governance models, policy enforcement controls, and security technology stacks.
The curious and confused CISO (approximately 40%): These executives know something is happening with AI in their organization, but they aren’t sure what, where, or how much is going on. Their goal was education —  what risks they face, what risk mitigation steps they should take, and what’s available from the industry to help them stop the bleeding. CISOs in this category are somewhat desperate for help.
The blissfully ignorant CISO (approximately 40%): Okay, this one is a bit unfair to CISOs as it’s more about their organizations. There’s likely AI development and usage the CISO and probably some executives are unaware of. They approached RSA believing time was on their side, so they probably skimmed through the AI rhetoric, shmoozed with vendors, and looked for the best cocktail parties.
In my humble opinion, CISOs will cycle through this hierarchy quickly over the next year. Blissfully ignorant CISOs will get wind of AI projects at their organization and move on to curiosity and confusion. This won’t take long. Proceeding from curious and confused to proactive will be the more difficult transition. These CISOs must assess business objectives, active projects, and user activities, then work with executives to develop a governance framework, create policies, implement guardrails, monitor activities, and manage a flexible model that keeps up with current and future business and technical requirements. A common analogy heard at RSA is that companies must be able to fix the plane while it’s in flight.
Legacy security vendors have the inside track on AI — for now
As far as AI technology consumption for cybersecurity, most CISOs I spoke with were open-minded while leaning toward their existing vendors — at least in the short term. This may buy legacy security vendors a bit, but not much time.
Remember what happened in the cloud as we progressed from a lack of cloud trust, to “lift and shift,” to cloud-native? The same thing is happening with AI, only even faster than the cloud. Bolting AI to existing tools won’t work for long, a year at most.
You’ve got to get the AI foundations right
I was encouraged to hear vendors describe how they started their AI transition by building an infrastructural foundation — data foundation/context engine, intelligent control plane, execution layer, services, guardrails, etc. — and then adding functional agents on top of this foundation. Cisco/Splunk impressed me with its development approach and roadmap, while AI-based startups such as Abstract, Crogl, and Sidekick are betting the farm on this methodology.
AI code is making an impact
Vendors are also all-in on using AI-development tools and seeing strong results. I heard about project acceleration along with staff reduction. Building connectors is a good example. Axonius and Tenable, both known for broad technology integration, are using AI to offload a lot of this tedious but necessary work, freeing developers to work on functionality rather than plumbing.
AI pricing remains a mess
While AI capabilities appear to be baked into many tools, I found that no one knows how to price their AI services. Some are doing so by the token, some by the number of users, and some are charging by the agent. The market will flush this out over the rest of the year.
Application security is getting its AI makeover
We all know the impact of AI on software development. It’s clear to me after RSA that the same thing is happening to application security. Anthropic’s Claude Code Security is one example, but I also got a view of the AWS Security Agent, which provides software testing capabilities across the software development lifecycle — from design, to development, to runtime, to red teaming.
Likewise, I met with a company named XBow that focuses on autonomous offensive security based on AI agents. Based on these developments, we will see a very different application security market at RSA 2027.
Few may be prepared for what comes next from cyber-adversaries
There’s active debate in the industry about the impact of AI within the threat landscape: Are existing cybersecurity defenses adequate or will AI tilt the battlefield toward adversaries?
After RSA, I believe both premises are true. Sophisticated firms with strong governance, risk management, asset visibility, modern training, and sound hygiene and posture management should be okay. Alarmingly, this is a small percentage of organizations. Most others lack advanced security skills and adequate resources. Adversaries armed with AI tools and automated workflows will have a field day here.
Managed providers are advancing the AI SOC
Managed security service providers (MSSPs) and managed detection and response (MDR) vendors are pushing the envelope on the AI-enabled security operations center (SOC).
Arctic Wolf unveiled its Aurora Superintelligence Platform and the Aurora Agentic SOC, which includes agents for triage, alerting, investigations, and more. I also met with Ontinue, an MSSP that provides services on top of Microsoft security tools such as Defender for Endpoint, Defender for Azure, and MS Sentinel. It is using AI to establish what it calls “hyper-contextualization” to understand all it can about its customers’ business processes and technology infrastructure so it can improve decision-making.
Microsoft cements its position
Speaking of Microsoft, it’s hard to point to any other vendor that can match its cybersecurity coverage.
Unlike others, Microsoft came to RSA armed with AI metrics and proof points. For example, Microsoft provided specific metrics from several customers that turned on its Defender agents and saved hundreds of hours of work while improving accuracy and productivity. I’m sure Microsoft has many examples to share.
Beware the cyber category killers
We’ve always viewed cybersecurity through the lens of security product categories — EDR, firewalls, SIEM, CSPM, etc. But multi-agent AI products could take on many of these tasks simultaneously, breaking down traditional product buckets and acting as category killers.
CISOs must anticipate this and be open to organizational, process, and budgetary changes. Also, will multi-agent cybersecurity products mean the death of the Gartner Magic Quadrant and all other me-too vendor mapping products?
Awareness training gradually transforms
Training is in transition. I’m pleased with this development. Awareness training is being replaced by behavior monitoring and change. Human risk management (HRM) tools from Fable Security, KnowBe4, and Mimecast, among others, watch over users and provide a nudge when they go astray.
Beyond synthetic phishing, some tools even provide synthetic deepfake training. HRM sales are limited today to progressive organizations, but I believe they will become a de facto standard as regulators and cyber-insurance companies see the light and support this training renaissance.
Security claims ownership of identities
Well, partial ownership, but this is a step in the right direction. I’m seeing interesting advancements in areas such as passwordless authentication (I can’t believe it’s 2026 and we’re still using passwords), browser security, non-human identity (NHI) security, and privileged account management.
RSA also pushed discussions about AI-agent access and action control — detection, monitoring, control of shadow agents, zero-standing privilege, etc. AI will be a big player, helping to ease the painful identity modernization process.
As a cryptographer might say, with this article, I’ve tried to hash the entire RSA event into a single key. I really enjoyed RSA 2026 (my 20th) and look forward to next year. See you at the Moscone Center from April 5 through April 8, 2027.
View the full article
Solana-based decentralized exchange Drift has confirmed that attackers drained about $285 million from the platform during a security incident that took place on April 1, 2026. "Earlier today, a malicious actor gained unauthorized access to Drift Protocol through a novel attack involving durable nonces, resulting in a rapid takeover of Drift’s Security Council administrative powers," the&View the full article
ArtemisDiana | shutterstock.com
Manuelles, siloartiges Management ist in der modernen IT-Welt unangebracht. Erst recht im Bereich der IT-Sicherheit: Der Umfang von modernem Enterprise Computing und State-of-the-Art-Application-Stack-Architekturen erfordern Sicherheits-Tools, die:
Einblicke in den Sicherheitsstatus von IT-Komponenten ermöglichen,
Bedrohungen in Echtzeit erkennen, und
Aspekte der Bedrohungsabwehr automatisieren.
Diese Anforderungen haben zum Aufkommen von Extended-Detection-and-Response- (XDR) Lösungen geführt. Diese Sicherheits-Tools kombinieren die stärksten Elemente von Security Incident and Event Management (SIEM), Endpoint Detection and Response (EDR) und Security Orchestration and Response (SOAR) – und bauen darauf auf.
XDR-Tools evaluieren
Der Preis wird immer ein Schlüsselfaktor bei Enterprise-Sicherheitssystemen sein, die skalierbar sein müssen – da bilden auch XDR-Systeme keine Ausnahme. Die Lösungen im Bereich Extended Detection and Response sind fast ausschließlich abonnementbasiert, verursachen also laufende Kosten. Wie bei vielen Sicherheits-Tools stellen diese Kosten angesichts der finanziellen Risiken eines Datenverlusts oder den geschäftlichen Auswirkungen einer Kompromittierung einen guten Kompromiss dar. Gleiches gilt mit Blick auf den Personalaufwand, der nötig wäre, um mit bestehenden Systemen und manueller Korrelation von Ereignisdaten dasselbe Schutzniveau zu erreichen.
Zu den wichtigsten XDR-Funktionen zählen:
Die Möglichkeit zur Integration mit vorhandener Hardware, Software und Cloud-Investitionen. Das kann sich sowohl auf die Effektivität der gewählten Plattform sowie auf die Kosten und den Aufwand für die anfängliche Implementierung der Lösung auswirken.
Richtlinien und Regeln managen zu können, ist ebenfalls von entscheidender Bedeutung. Nur so können Sie die XDR-Funktionen auf Ihre geschäftlichen Anforderungen abstimmen und Ihre IT-Sicherheitsteams in die Lage versetzen, effektiv auf Bedrohungen zu reagieren.
Benutzerfreundlichkeit und Schulungsoptionen (entweder durch den Anbieter oder die Community) sind schließlich ebenfalls wichtig, damit sich Ihre Investition in eine XDR-Plattform langfristig bezahlt macht.
Die besten XDR-Lösungen
Nachfolgend haben wir einige der wichtigsten XDR-Tools in alphabetischer Reihenfolge für Sie zusammengestellt.
Bitdefender GravityZone Business Security Enterprise CrowdStrike Falcon Insight XDR Cybereason XDR Cynet 360 AutoXDR Elastic Security for XDR Microsoft SecOps Palo Alto Networks Cortex XDR SentinelOne Singularity XDR Trellix XDR Platform Trend Micro Vision One (fm)
View the full article
ArtemisDiana | shutterstock.com
Manuelles, siloartiges Management ist in der modernen IT-Welt unangebracht. Erst recht im Bereich der IT-Sicherheit: Der Umfang von modernem Enterprise Computing und State-of-the-Art-Application-Stack-Architekturen erfordern Sicherheits-Tools, die:
Einblicke in den Sicherheitsstatus von IT-Komponenten ermöglichen,
Bedrohungen in Echtzeit erkennen, und
Aspekte der Bedrohungsabwehr automatisieren.
Diese Anforderungen haben zum Aufkommen von Extended-Detection-and-Response- (XDR) Lösungen geführt. Diese Sicherheits-Tools kombinieren die stärksten Elemente von Security Incident and Event Management (SIEM), Endpoint Detection and Response (EDR) und Security Orchestration and Response (SOAR) – und bauen darauf auf.
XDR-Tools evaluieren
Der Preis wird immer ein Schlüsselfaktor bei Enterprise-Sicherheitssystemen sein, die skalierbar sein müssen – da bilden auch XDR-Systeme keine Ausnahme. Die Lösungen im Bereich Extended Detection and Response sind fast ausschließlich abonnementbasiert, verursachen also laufende Kosten. Wie bei vielen Sicherheits-Tools stellen diese Kosten angesichts der finanziellen Risiken eines Datenverlusts oder den geschäftlichen Auswirkungen einer Kompromittierung einen guten Kompromiss dar. Gleiches gilt mit Blick auf den Personalaufwand, der nötig wäre, um mit bestehenden Systemen und manueller Korrelation von Ereignisdaten dasselbe Schutzniveau zu erreichen.
Zu den wichtigsten XDR-Funktionen zählen:
Die Möglichkeit zur Integration mit vorhandener Hardware, Software und Cloud-Investitionen. Das kann sich sowohl auf die Effektivität der gewählten Plattform sowie auf die Kosten und den Aufwand für die anfängliche Implementierung der Lösung auswirken.
Richtlinien und Regeln managen zu können, ist ebenfalls von entscheidender Bedeutung. Nur so können Sie die XDR-Funktionen auf Ihre geschäftlichen Anforderungen abstimmen und Ihre IT-Sicherheitsteams in die Lage versetzen, effektiv auf Bedrohungen zu reagieren.
Benutzerfreundlichkeit und Schulungsoptionen (entweder durch den Anbieter oder die Community) sind schließlich ebenfalls wichtig, damit sich Ihre Investition in eine XDR-Plattform langfristig bezahlt macht.
Die besten XDR-Lösungen
Nachfolgend haben wir einige der wichtigsten XDR-Tools in alphabetischer Reihenfolge für Sie zusammengestellt.
Bitdefender GravityZone Business Security Enterprise CrowdStrike Falcon Insight XDR Cybereason XDR Cynet 360 AutoXDR Elastic Security for XDR Microsoft SecOps Palo Alto Networks Cortex XDR SentinelOne Singularity XDR Trellix XDR Platform Trend Micro Vision One (fm)
View the full article
Cloudflare on Wednesday rolled out EmDash, which it described as “the spiritual successor to WordPress.” The security vendor positioned EmDash as a far more secure site building tool that avoids the extensive cybersecurity problems with WordPress plugins. 
But the Cloudflare claims go far beyond cybersecurity issues. The vendor is arguing that the very nature of websites in 2026 is sharply different to the kind of website that WordPress was designed to handle. 
“WordPress powers over 40% of the internet. It is a massive success that has enabled anyone to be a publisher, and created a global community of WordPress developers. But the WordPress open source project will be 24 years old this year,” the Cloudflare announcement said. “Hosting a website has changed dramatically during that time. When WordPress was born, AWS EC2 didn’t exist. In the intervening years, that task has gone from renting virtual private servers, to uploading a JavaScript bundle to a globally distributed network at virtually no cost. It’s time to upgrade the most popular CMS on the internet to take advantage of this change.”
More flexible licensing
Cloudflare’s statement also suggested that it is delivering open source in a way that is potentially more open and flexible than the WordPress approach. 
“EmDash is fully open source, MIT licensed, and available on GitHub. While EmDash aims to be compatible with WordPress functionality, no WordPress code was used to create EmDash. That allows us to license the open source project under the more permissive MIT license. We hope that allows more developers to adapt, extend, and participate in EmDash’s development,” the company said. “EmDash is committed to building on what WordPress created: an open source publishing stack that anyone can install and use at little cost, while fixing the core problems that WordPress cannot solve.”
The next wave of web development
In an interview with Computerworld, Cloudflare senior product manager Matt Taylor said his team sees the project as the next wave of web development platforms.
“There is a whole new generation of developers, and WordPress is old news to them. If you are starting today, there is no way you are picking WordPress,” Taylor said, adding that AI agents are also not going to opt for WordPress platforms when creating new sites. 
Even when adding Cloudflare in front of a WordPress site to enhance security, he noted, “you have to hack the system to work with the modern internet.”
WordPress was unable to provide its feedback on the announcement by deadline.
WordPress not for new users
Melody Brue, principal analyst for Moor Insights & Strategy, said she has not seen many developers who are not already experienced with WordPress choosing it to build sites, and that she is also seeing that AI agents never opt for WordPress unless they were given explicit instructions to do so. Given how rampant autonomous AI agents are today, the ability to be more hospitable to agentic systems may prove a massive advantage.
“For somebody new, you have this opportunity to skip all of these legacy CMS assumptions and have true least privilege by design, a first class experience for agents. At least, that is what [Cloudflare] is trying to deliver,” Brue said. “They are baking in agent skills.”
Enterprise concerns
When it comes to enterprise web development strategies, however, things get a little more complex, Brue said. Given how deeply they are already invested in WordPress code and plugins and the support environment, existing WordPress enterprise users are not likely to easily move. 
But the extensive legal outbursts from last year involving Automattic CEO Matt Mullenweg, and the lawsuit with WP Engine, made some enterprise IT executives nervous, once they realized how much control one person had over WordPress platforms.
Brue said, “I can understand the concerns,” but added that the WordPress squabbles seem to have become more subdued lately: “There is now less of the tantrum throwing happening.”
Thomas Randall, a research director at Info-Tech Research Group, agreed with Brue that enterprise environments are unlikely to abandon WordPress any time soon.
“Is EmDash the spiritual successor to WordPress? Not from what Cloudflare has shown so far. The problem Cloudflare highlights, security vulnerabilities in WordPress plugins, is real. But the rest of the announcement deserves skepticism,” Randall said. “For instance, enterprise IT teams with complex WordPress environments will encounter nontrivial barriers for migration. EmDash uses Portable Text rather than WordPress’s HTML content model, which would significantly complicate automated migration. Existing PHP themes and plugins would not carry over directly and would likely require substantial redevelopment.”
But that would still open the door to newcomers who have not already invested in the WordPress environment.
Competing in a different layer
Noah Kenney, principal consultant for Digital 520, said the future is likely to look much more inviting for an EmDash-like approach than for legacy WordPress.
“Cloudflare’s EmDash is less about replacing WordPress outright and more about setting a new security baseline, which is that CMS platforms should have isolated execution environments, least-privilege access, and verifiable permission models,” Kenney said. “That has implications for both content management and how enterprises evaluate third-party extensibility risk more broadly.”
However, he noted, “viability is an ecosystem question just as much as it is a technical one. EmDash, even if superior from an architectural perspective, is effectively starting from zero. Enterprise adoption will depend heavily on migration tooling, developer adoption, and whether Cloudflare can build a credible plugin and integration ecosystem.”
Kenney added that he sees EmDash as “very likely to influence the next phase of CMS architecture, particularly in security-sensitive and enterprise environments where plugin risk is already a prevalent issue.”
Sanchit Vir Gogia, chief analyst at Greyhound Research, saw the EmDash move in a much broader context, potentially signaling the near-term future of website strategies. 
“EmDash is competing in a different layer altogether,” Gogia said. “It sits closer to composable and headless CMS platforms like Contentful and Strapi, and even closer to developer frameworks like Astro. It is collapsing what used to be separate concerns; content management, execution runtime, and security enforcement are being fused into one programmable environment.”
This, he observed, “is where the real friction emerges. Traditional CMS buyers are not necessarily developers first. They prioritize usability, ecosystem depth, and speed of execution for business teams. EmDash is clearly optimized for developers and architects. So the competition is not just product versus product. It is operating model versus operating model. And in that contest, incumbents have inertia on their side, while EmDash has architectural purity. History shows those two rarely move at the same speed.”
This article originally appeared on Computerworld.
View the full article
Cisco has released patches for a critical vulnerability in its out-of-band management solution, present in many of its servers and appliances. The flaw allows unauthenticated remote attackers to gain admin access to the Cisco Integrated Management Controller (IMC), which gives administrators remote control over servers even when the main OS is shut down.
The vulnerability, tracked as CVE-2026-20093, stems from incorrect handling of password changes and can be exploited by sending specially crafted HTTP requests. This means servers with their IMC interfaces exposed directly to the local network — or worse, to the internet — are at immediate risk.
The Cisco IMC is a baseboard management controller (BMC), a dedicated controller embedded into server motherboards with its own RAM and network interface that gives administrators monitoring and management capabilities as if they were physically connected to the server with a keyboard, monitor, and mouse (KVM). Because BMCs run their own firmware independently of the OS, they can be used to perform operations even when the OS is shut down, including reinstalling it.
The IMC provides an HTML5 web interface, an SSH-based command line interface, and an XML API. It also supports Redfish, a standardized RESTful API for BMCs and virtual KVM.
“A successful exploit could allow the attacker to bypass authentication, alter the passwords of any user on the system, including an Admin user, and gain access to the system as that user,” Cisco said in its advisory.
The IMC is present in 5000 Series Enterprise Network Compute Systems, Catalyst 8300 Series Edge uCPE, UCS C-Series M5 and M6 Rack Servers in standalone mode, UCS E-Series Servers M3, and UCS E-Series Servers M6. However, a long list of Cisco products and appliances that are based on the Cisco Unified Computing System (UCS) C-Series platform are also affected if they have their IMC interface exposed.
While Cisco is not currently aware of any malicious attacks exploiting this vulnerability, BMC flaws in servers from other manufacturers have been exploited in the past. In 2022, security researchers found a malicious implant dubbed iLOBleed that was likely developed by an APT group and was being deployed through vulnerabilities in HPE iLO (HPE’s Integrated Lights-Out) BMC. In 2018, a ransomware group called JungleSec used default credentials for IPMI interfaces to compromise Linux servers.
The risk of attacks against such management interfaces is serious enough that the US Cybersecurity and Infrastructure Security Agency (CISA) and the National Security Agency (NSA) issued guidance on hardening BMC back in 2023.
More recently researchers also warned about vulnerabilities in cheap KVM-over-IP devices that some organizations or admins use as alternatives for managing systems that don’t have dedicated BMC controllers.
View the full article
Cisco has released patches for a critical vulnerability in its out-of-band management solution, present in many of its servers and appliances. The flaw allows unauthenticated remote attackers to gain admin access to the Cisco Integrated Management Controller (IMC), which gives administrators remote control over servers even when the main OS is shut down.
The vulnerability, tracked as CVE-2026-20093, stems from incorrect handling of password changes and can be exploited by sending specially crafted HTTP requests. This means servers with their IMC interfaces exposed directly to the local network — or worse, to the internet — are at immediate risk.
[ Related: More Cisco news and insights ]
The Cisco IMC is a baseboard management controller (BMC), a dedicated controller embedded into server motherboards with its own RAM and network interface that gives administrators monitoring and management capabilities as if they were physically connected to the server with a keyboard, monitor, and mouse (KVM). Because BMCs run their own firmware independently of the OS, they can be used to perform operations even when the OS is shut down, including reinstalling it.
The IMC provides an HTML5 web interface, an SSH-based command line interface, and an XML API. It also supports Redfish, a standardized RESTful API for BMCs and virtual KVM.
“A successful exploit could allow the attacker to bypass authentication, alter the passwords of any user on the system, including an Admin user, and gain access to the system as that user,” Cisco said in its advisory.
The IMC is present in 5000 Series Enterprise Network Compute Systems, Catalyst 8300 Series Edge uCPE, UCS C-Series M5 and M6 Rack Servers in standalone mode, UCS E-Series Servers M3, and UCS E-Series Servers M6. However, a long list of Cisco products and appliances that are based on the Cisco Unified Computing System (UCS) C-Series platform are also affected if they have their IMC interface exposed.
While Cisco is not currently aware of any malicious attacks exploiting this vulnerability, BMC flaws in servers from other manufacturers have been exploited in the past. In 2022, security researchers found a malicious implant dubbed iLOBleed that was likely developed by an APT group and was being deployed through vulnerabilities in HPE iLO (HPE’s Integrated Lights-Out) BMC. In 2018, a ransomware group called JungleSec used default credentials for IPMI interfaces to compromise Linux servers.
The risk of attacks against such management interfaces is serious enough that the US Cybersecurity and Infrastructure Security Agency (CISA) and the National Security Agency (NSA) issued guidance on hardening BMC back in 2023.
More recently researchers also warned about vulnerabilities in cheap KVM-over-IP devices that some organizations or admins use as alternatives for managing systems that don’t have dedicated BMC controllers.
More Cisco news:
Chained vulnerabilities in Cisco Catalyst switches could induce denial-of-service Cisco goes all in on agentic AI security Cisco Talos 2025 year in review and lessons learned How Cisco’s platform mindset is meeting the AI era Cisco extends AgenticOps across networking, security, observability products Cisco amps up Silicon One line, delivers new systems and optics for AI networking Takeaways from Cisco’s AI Summit Cisco: Infrastructure, trust, model development are key AI challenges AI, security tailwinds signal promising 2026 for Cisco Cisco adds intelligent policy enforcement to mesh firewall family Actively exploited Cisco UC bug requires immediate, version‑specific patching Cisco’s 2026 agenda prioritizes AI-ready infrastructure, connectivity Cisco finally patches seven-week-old zero-day flaw in Secure Email Gateway products Cisco routers knocked out due to Cloudflare DNS change
View the full article
Students and developers who won the lottery to attend the WWDC 2026 Special Event at Apple Park on June 8 have started receiving their invites.


Apple is holding a WWDC keynote viewing at ‌Apple Park‌, but space is limited so invites were done on a lottery basis. Apple accepted submissions from those interested in attending until Monday night, and winners are now being notified.

Developers and students who won a spot will take part in an all-day event. The day will begin with the keynote viewing at 10:00 a.m. Pacific Time, followed by the Platforms State of the Union, ‌Apple Park‌ tours, and a dinner. Attendees will be able to connect with Apple engineers and experts.

Current Apple Developer Program members, Apple Developer Enterprise Program members, Apple Entrepreneur Camp alumni, and Swift Student Challenge winners from 2024 to 2026 were eligible to apply, with attendees chosen by random selection.

Apple does not charge a fee for the ‌Apple Park‌ special event, but the company does not cover transportation or lodging. Out-of-state attendees will need to purchase airfare, hotel accommodations, and transportation to ‌Apple Park‌.

‌WWDC 2026‌ will take place from June 8 to June 12. Developers and students not selected to attend the ‌Apple Park‌ event can follow along with WWDC through Apple's developer website and app. Apple plans to share 100+ WWDC sessions that walk through all of the new features, and developers can attend interactive group labs and get one-on-one help from Apple engineers.Related Roundup: WWDC 2026Related Forum: Apple, Inc and Tech Industry
This article, "Apple Sending WWDC 2026 Invites to Special Event Lottery Winners" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
App developer Clément Sauvage has designed a set of enamel pins for Apple fans who want to commemorate WWDC 2026 and Apple's 50th anniversary. Sauvage is offering the pins on Kickstarter, and plans to start shipments in May ahead of WWDC.


The pins feature the Apple developer logo, the Apple Intelligence icon, Apple's "spaceship" and rainbow at the Apple Park campus, the entrance to Apple's Infinite Loop campus, the Swift logo, and more. A single pin is available for 10 euros, while a full set of eight WWDC-themed pins is priced at 45 euros.


Sauvage has done enamel pin sets in 2021 and 2024, so this is his third offering. There are some add-on pins from prior years available as well.

Apple often designs its own WWDC pins that are given to developers that attend the WWDC Special Event, but the pins are not available for general purchase.Related Roundup: WWDC 2026Related Forum: Apple, Inc and Tech Industry
This article, "Apple Fan Creates Unofficial WWDC 2026 and 50th Anniversary Enamel Pins" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
The latest version of Apple's 140W USB-C Power Adapter included with 16-inch MacBook Pro models with the M5 Pro or M5 Max chip has an issue for some.


After the 16-inch MacBook Pro was updated last month, customers in some countries began to notice that Apple's 140W USB-C Power Adapter that comes with it has a subtle design change that breaks compatibility with Apple's Power Adapter Extension Cable.

Specifically, while the charger continues to have a removable plug, Apple has apparently tweaked the design of the underlying male connector with two pins. The connector now has a slimmer pill-like shape, whereas it previously had a small triangular indent in the bottom of it. Due to this change, the new charger does not work with Apple's Power Adapter Extension Cable, which still has a female connector designed to match the previous male connector.

The redesigned male connector (on the right in the photo)
Oddly, Apple's product page for the Power Adapter Extension Cable says the cable is compatible with its 140W USB-C power adapters, despite this issue.

Apple's discontinued World Travel Adapter Kit is also incompatible with the version of Apple's 140W USB-C Power Adapter with the redesigned male connector.

The new design has been spotted in Australia and China, but other customers have said their power adapters are not affected, so it is a hit-or-miss situation. We have yet to confirm exactly which countries are impacted by this issue, or if the 140W USB-C Power Adapter that Apple sells separately is affected by this change anywhere.

We have reached out to Apple for comment.Related Roundup: MacBook ProBuyer's Guide: MacBook Pro (Buy Now)Related Forum: MacBook Pro
This article, "Apple's New 16-Inch MacBook Pro Charger Has a Compatibility Issue" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Anker this week launched a useful new accessory for your desk, debuting the 10-in-1 Nano Power Strip. Priced at $70, the Nano Power Strip has a unique clamp design that puts multiple ports on your desktop while eliminating cable clutter.


I was able to test out the Nano Power Strip ahead of when it launched, and found it to be a useful alternative to standard under-desk power strips. The power strip comes in black or white and it's made of plastic, but the matte finish adds aesthetic appeal, as does a silver front plate for some of the ports.

The clamp is adjustable with an included knob and it fits desktops from 0.6 inches to 1.8 inches. Unfortunately, I have a Parsons-style desk that's too thick to use the power strip as intended, so it's worth measuring. With my thicker desk, I can still attach it to a leg or the back of the desk, but it doesn't put all of the outlets in the ideal position. There are silicone pads at both sides of the clamp to keep furniture from being scratched.


There are two outlets at the top, two outlets at the bottom, and two outlets at the sides, for a total of six outlets. There are two USB-C ports with 70W max charging (split between 45W and 25W when charging two devices), and two 12W USB-A ports. 70W isn't going to charge a MacBook Pro at its maximum speed, but it's enough for day-to-day use, and it'll fast charge most other Apple devices. I do wish there was more USB-C power and one less USB-A port, but it's easy enough to use one of the top outlets to plug in one of Anker's small multi-port power adapters.

With the power strip positioned at the edge of a desk, the two outlets on the top of the device are accessible from the desktop. The four other outlets are accessible from the bottom of the desk, so cables can be hidden away. The USB-A and USB-C ports are also meant to be used from the desktop, and the above-desk portion is slim, coming in at under an inch.

Because the Nano Power Strip attaches to a desk, it stays secure when plugging things in to the ports or the top outlets, which is convenient. I don't need to hold it down to unplug something, and it doesn't move around on a tabletop. If you've ever had a power strip with a bunch of heavy cables plugged in, you probably know what a hassle it can be trying to keep it upright.

The Nano Power Strip is a surge protector, and Anker says that it has overload, short-circuit, and temperature control.

Anker's Nano Power Strip can be purchased from the Anker website or from Amazon for $70.Tag: Anker
This article, "Anker's $70 Nano Power Strip Clamps to Your Desk for Easy Access to 10 Ports" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
A large-scale credential harvesting operation has been observed exploiting the React2Shell vulnerability as an initial infection vector to steal database credentials, SSH private keys, Amazon Web Services (AWS) secrets, shell command history, Stripe API keys, and GitHub tokens at scale. Cisco Talos has attributed the operation to a threat cluster it tracks asView the full article
The software supply chain is under sustained attack. Not from a single threat actor or a single incident, but from an ecosystem-wide campaign that has been escalating for months and shows no signs of slowing down.
This week, axios, the HTTP client library downloaded 83 million times per week and present in roughly 80% of cloud environments, was compromised via a hijacked maintainer account. Two backdoored versions deployed platform-specific RATs attributed with high confidence to North Korea’s Lazarus Group. The malicious versions were live for approximately three hours. That was enough.
This follows the TeamPCP campaign in March, which weaponized Aqua Security’s Trivy vulnerability scanner, a security tool trusted by thousands of organizations, and cascaded the compromise into Checkmarx KICS, LiteLLM, Telnyx, and 141 npm packages via a self-propagating worm. Before that, the Shai-Hulud worm tore through the npm ecosystem in late 2025, and GlassWorm infected 400+ VS Code extensions, GitHub repos, and npm packages using invisible Unicode payloads.
The pattern is consistent across all of these incidents: attackers steal developer credentials, use them to poison trusted packages, and the compromised packages steal more credentials. It is self-reinforcing, it is accelerating, and it now has ransomware monetization pipelines behind it.
The common thread is implicit trust
If you look at what actually failed in each of these compromises, the answer is the same every time: trust was assumed where it should have been verified. Organizations trusted a container tag because it had a familiar name. They trusted a GitHub Action because it had a version number. They trusted a CI/CD secret because the workflow was authored by someone on the team. In every case, the attacker exploited the gap between assumed trust and verified trust.
The organizations that came through these incidents with minimal damage had already begun replacing implicit trust with explicit verification at every layer of their stack: verified base images instead of community pulls, pinned references instead of mutable tags, scoped and short-lived credentials instead of long-lived tokens, and sandboxed execution environments instead of wide-open CI runners. None of these are new ideas, and none of them are difficult to implement. What they require is a shift in default posture, from “trust unless there’s a reason not to” to “verify before you trust, and limit the blast radius when verification fails.”
Here is what we recommend every engineering organization should do, and what we practice ourselves at Docker:
Secure your foundations
Start with trusted base images
Don’t build on artifacts you can’t verify. Docker Hardened Images (DHI) are rebuilt from source by Docker with SLSA Build Level 3 attestations, signed SBOMs, and VEX metadata, free and open source under Apache 2.0. DHI was not affected by TeamPCP because its controlled build pipeline and built-in cooldown periods mean short-lived supply chain exploits (typically 1 to 6 hours) are eradicated before they ever enter the image. There is no reason not to use these today.
Pin everything by digest or commit SHA
Mutable tags are not a security boundary. This is exactly how TeamPCP hijacked 75 of 76 trivy-action version tags. Pin GitHub Actions to full 40-character commit SHAs. Pin container images by sha256 digest. Pin package dependencies to exact versions and remove ^ and ~ ranges. If a reference can be overwritten without changing its name, it will be.  Inventory every third-party GitHub Action in use across your org and enforce an allowlist policy as you cannot pin what you haven’t cataloged. Enable two-factor authentication on every package registry account in your organization like npm, PyPI, RubyGems, Docker Hub as account takeover of a single maintainer is how most of these attacks begin. Commit your lock files and use npm ci (or the equivalent in your package manager) in all CI pipelines – this prevents builds from silently pulling new versions that aren’t in your lock file.
Use cooldown periods for dependency updates
Both npm and Renovate support minimum release age settings that delay adoption of new versions. Most supply chain attacks have a shelf life of hours, and a 3-day cooldown eliminates the vast majority of them. We maintain a collection of safe default configurations for common package managers and tooling. Use it. Contribute to it.
Generate SBOMs at build time
When an incident hits, the first question is always: “are we affected?” If you use docker buildx to build your images, you can generate and attach SBOMs and provenance attestations during the build. Sign them. Store them alongside your images. When the next axios or Trivy happens, you check the build metadata rather than having to exec into live Kubernetes pods to figure out what’s running. Docker Scout can then continuously monitor those SBOMs against known vulnerabilities and policy violations.
Secure your CI/CD
Treat every CI runner as a potential breach point
TeamPCP’s credential stealer ran inside CI/CD pipelines, dumping process memory and sweeping 50+ filesystem paths for secrets. Anything accessible to a workflow step is accessible to an attacker who compromises a dependency in that step. Avoid pull_request_targe triggers in GitHub Actions unless absolutely necessary and with explicit security checks as this is the exact mechanism TeamPCP used to execute code in the context of the base repository with access to its secrets.  Audit what secrets each workflow step can reach. If a scanning step has access to your deployment credentials, that is a blast radius problem, not a scanning problem.
Use short-lived, narrowly scoped credentials
The root cause of the Trivy breach was a single Personal Access Token with broad scope used across 33+ workflows. Use short-lived, narrowly-scoped credentials. No single token should grant cross-repository or organization-wide access. Use a secrets manager, not environment variables scattered across workflow files. This is an area where the ecosystem, including Docker Hub, needs to continue improving, and we are actively working on it.
Use an internal mirror or artifact proxy
Place Artifactory, CodeArtifact, or Nexus between your build systems and public registries. Scan and approve versions before they reach your pipelines. Docker Business customers can also use Registry Access Management and Image Access Management to restrict which registries and images developers can pull, providing a lighter-weight policy layer for teams that don’t run a full artifact proxy.
Test dependency updates where production secrets don’t exist
Evaluate updates in dev/staging environments that have no access to production credentials. If a malicious package runs in staging, it steals nothing of value.
Secure your endpoints
This is where most of these attacks actually start. TeamPCP, Shai-Hulud, and now axios all deploy infostealers that sweep developer machines for credentials stored in dotfiles, environment variables, SSH keys, browser sessions, and cloud configs. Protecting CI/CD pipelines matters, but if the developer machine that authors those pipelines is compromised, the attacker inherits whatever that developer can reach.
Deploy canary tokens
Place fake credentials across your fleet, AWS keys, API tokens, SSH keys, that serve no purpose other than to alert you when they’re exfiltrated. If an infostealer sweeps a machine, canary tokens fire before the real credentials are used. Tools like Tracebit and Canarytokens make this trivial. If you have an MDM solution (Jamf, Intune, Jumpcloud), push canaries to every managed device. We deployed this across our fleet in under a day.
Clean up credential sprawl
Audit ~/.ssh/, ~/.aws/credentials, ~/.docker/config.json, .env files, and shell histories for hardcoded secrets. Move everything to a password manager or secrets vault (1Password, HashiCorp Vault). Passphrase-protect all SSH keys. An infostealer that lands on a machine with no cleartext credentials gets nothing useful. Audit the extensions and plugins installed across your developer tools (IDE extensions, browser extensions, coding agent extensions like skills, plugins, MCP servers, etc…) as these tend to run with developer-level permissions and most marketplaces do not re-review updates after initial publication.
Deploy EDR with behavioral detection
Endpoint detection and response tools should cover developer machines and CI runners, with detections tuned for credential sweeping, persistence mechanisms, and unusual process behavior rather than just known malware signatures.
Secure your AI development
AI coding agents are compounding supply chain risk in ways the industry is only beginning to appreciate. Agents install packages, modify configs, make API calls, and spin up containers with developer-level access. A compromised dependency pulled by an agent has the same blast radius as a compromised developer machine, and the people using these agents now include non-developers who may not recognize suspicious behavior.
Run agents in sandboxed environments
Docker Sandboxes (sbx) run AI coding agents like Claude Code, Gemini CLI, Codex, and others inside isolated microVMs. Each sandbox gets its own kernel, filesystem, Docker Engine, and network, completely separated from your host. Credentials are injected into HTTP headers by the host proxy and never enter the VM directly. Network access is deny-by-default, with explicit allowlists. If a compromised dependency runs inside a sandbox, it cannot reach your host filesystem, your Docker daemon, your other containers, or any domain you haven’t explicitly approved.
Govern your MCP servers
Model Context Protocol servers are the new unvetted dependency. They run with broad permissions, connect AI agents to internal systems, and 43% of analyzed MCP servers have command injection flaws. Use signed, hardened images for MCP servers. Docker maintains 300+ verified MCP server images with the same SLSA/SBOM standards as DHI. Docker’s MCP Gateway provides centralized proxy, policy enforcement, secret blocking, and audit logging for all agent-to-tool traffic.
Standardize on fewer tools, governed centrally
It’s tempting to run every AI tool and model. Don’t. Consolidate on a trusted stack, push managed configurations via MDM, and use Docker Desktop’s administrative features (registry access management, proxy configuration, image access management) to control what agents can pull and where they can push.
Build muscle for incident response
Maintain SBOMs for everything in production
When the next compromise drops, you need to answer “are we affected?” in minutes, not days. Build-time SBOMs via docker buildx, combined with Docker Scout’s continuous monitoring, give you that capability. If you have to exec into running containers to determine exposure, you’re already behind.
Have playbooks ready
Know how to freeze your GitHub org, pause CI/CD without breaking everything, revoke credentials in bulk, and communicate to customers before you need to do it under pressure. The time to figure out your incident response workflow is not during the incident. If you haven’t already, audit your npm/PyPI/Docker, Hub accounts for unauthorized publishes, review recent CI logs for unexpected network calls or secret access, and rotate any long-lived tokens that were accessible to CI in the past 90 days.
Verify before you trust, slow down where it counts
Most supply chain attacks burn out within hours. A small delay in adopting new versions, whether via cooldown periods, manual review gates, or simply waiting 72 hours, eliminates the majority of the risk. Speed of adoption is not worth the cost of compromise.
The landscape has changed, your defaults should too
The supply chain attack wave is not a single incident to respond to. It is a permanent shift in the threat landscape. The attackers range from nation-state operators like Lazarus Group to opportunistic teenagers like TeamPCP and LAPSUS$ who are building the plane as it takes off, using AI to accelerate, and monetizing through ransomware partnerships. The ecosystem they are exploiting, npm, PyPI, GitHub Actions, container registries, has not fundamentally changed in its trust model.
What has changed is that defenders now have the tools to establish explicit trust boundaries where implicit trust used to be the only option. Hardened base images, build-time attestations, sandboxed execution, and canary-based detection did not exist at this maturity level two years ago. The gap between organizations that adopt these layers and those that don’t is going to widen fast.
Everything we’ve recommended here, we practice at Docker. We pull from public registries, we run CI/CD pipelines, we use AI agents, and we face the same threat actors you do. This is how we’re protecting ourselves.
Further reading:
Docker Hardened Images: free, signed, SLSA-compliant base images Docker Scout: SBOM generation, vulnerability detection, and policy enforcement Docker Sandboxes: isolated microVMs for AI coding agents Safe Defaults: secure configurations for package managers and tooling Building SBOMs with Docker Buildx: attach provenance and SBOMs at build time
View the full article
Apple has continued posting short videos featuring its new Little Finder Guy mascot on TikTok and YouTube Shorts, taking advantage of the popularity of the anthropomorphized Mac Finder icon.


The short videos promote the MacBook Neo through a series of Mac tips, all of which include Little Finder Guy in cute poses. A video about journaling features the character with a book and a pen, while another about the Passwords app has Little Finder Guy with a magnifying glass.






Apple has shared nine Little Finder Guy videos this week, and on TikTok, the thumbnails for the videos come together to make a Little Finder Guy mosaic on the Apple TikTok page.


Now that Apple has likely completed its Little Finder Guy image on TikTok, videos with the character could stop or become less frequent, but Apple might opt to keep the mascot around because of how it's caught on.


Apple introduced Little Finder Guy after launching the ‌MacBook Neo‌ in early March, and Apple users immediately liked the character. Stephen Hackett of 512 Pixels created a 3D print version, and Basic Apple Guy has a series of mockups, plus stickers for sale. PCalc's James Thomson also made a set of 5K Little Finder Guy wallpapers.Tags: Little Finder Guy, TikTok
This article, "Little Finder Guy Stars in Nine New Apple TikTok and YouTube Videos" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Docker Hub is quickly becoming the home for AI models, serving millions of developers and bringing together a curated lineup that spans lightweight edge models to high-performance LLMs, all packaged as OCI artifacts.
Today, we’re excited to welcome Gemma 4, the latest generation of lightweight, state-of-the-art open models. Built on the same technology behind Gemini, Gemma 4 introduces three architectures that scale from low-power efficiency to high-end server performance.
By packaging models as OCI artifacts, models behave just like containers. They become versioned, shareable, and instantly deployable, with no custom toolchains required. You can pull ready-to-run models from Docker Hub, push your own, integrate with any OCI registry, and plug everything directly into your existing CI/CD pipelines using familiar tooling for security, access control, and automation.
And this is just the start. Over the next few weeks, Gemma 4 support is coming to Docker Model Runner, so you will not just discover models on Hub, you will be able to run, manage, and deploy them directly from Docker Desktop with the same simplicity you expect from Docker.
Docker Hub’s growing GenAI catalog already includes popular models like IBM Granite, Llama, Mistral, Phi, and SolarLLM, alongside apps like JupyterHub and H2O.ai, plus essential tools for inference, optimization, and orchestration.
What Docker Brings to Gemma 4
Gemma 4 expands what efficient, high-performance models can do. Docker makes them simple to run, share, and scale anywhere.
Run efficiently at the edge: Smaller Gemma 4 variants are optimized for on-device performance. Docker enables consistent deployment across laptops, edge devices, and local environments. Scale performance with ease: From sparse to dense architectures, you can run any model like a container, making it easy to scale across cloud or on-prem infrastructure.  One command to get started: Gemma 4 is just one command away: docker model pull gemma4 No proprietary download tools. No custom authentication flows. Just the same pull, tag, push, and deploy workflow you already use.
By bringing Gemma 4 to Docker Hub, you get powerful models with a familiar, production-ready workflow.
What’s New in Gemma 4?
Gemma 4 redefines what “small” models can do, with architectures optimized across multiple sizes and use cases:
Small & Efficient (E2B, E4B): Built for on-device performance with high throughput and low memory use. Sparsely Activated (26B A4B): Mixture-of-Experts design delivers large-model quality with smaller-model speed. Flagship Dense (31B): High-performance model with a 256K context window for long-context reasoning. Key capabilities include multimodal support (text, image, audio), advanced reasoning with “thinking” tokens, and strong coding plus function-calling abilities.
Technical Specifications

Model Name
Type
Total Params
Input Modalities
Context Window
Gemma 4 E2B
Dense (Small)
5.1B
Text, Vision, Audio
128K
Gemma 4 E4B
Dense (Small)
8.0B
Text, Vision, Audio
128K
Gemma 4 26B A4B
MoE
26.8B (3.8B active)
Text, Vision
256K – 512K
Gemma 4 31B
Dense
31.3B
Text, Vision
256K – 512K
Build the Future of AI with Docker Hub
The arrival of Gemma 4 on Docker Hub reinforces our commitment to making Docker Hub the best place to discover, share, and run AI models. Whether you are building a voice-activated mobile assistant or a large-scale document retrieval system, Docker Hub makes it simple to find the right model, pull it instantly, and run it anywhere.
Ready? Head over to Docker Hub to pull the models

Want to join the Docker Model Runner community? Please star, fork and contribute to our GitHub repo

View the full article
As of April 1, payment processing is no longer available for purchases made across the App Store and other Apple services in Russia, according to Apple.


In a new support document, Apple said new purchases, in-app purchases, and subscription renewals are no longer available in Russia unless a user already has funds in their Apple Account balance, which can continue to be used.

This change affects the following services and items:
Apple Arcade
Apple Fitness+
Apple Music
Apple Podcasts subscriptions
Apple One
App Store purchases and subscriptions
Apple TV purchases and subscriptions
iTunes Store purchases
iCloud+
Ringtone & Tone purchasesApple said apps and content that users previously bought will remain available, and it ensured that iCloud data will remain accessible after an iCloud+ subscription ends. More details are available in Apple's support document.

Apple reportedly took this action in response to an order from the Russian government, which allegedly hopes that the lost services revenue from Russian users will pressure the company to add some popular Russian apps back to the App Store, after those apps were removed due to sanctions arising from Russia's war with Ukraine. The order would presumably end if Apple were to make those apps available again.Tags: App Store, Russia
This article, "Apple Turns Off Payments in Russia" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Cisco has released updates to address a critical security flaw in the Integrated Management Controller (IMC) that, if successfully exploited, could allow an unauthenticated, remote attacker to bypass authentication and gain access to the system with elevated privileges. The vulnerability, tracked as CVE-2026-20093, carries a CVSS score of 9.8 out of a maximum of 10.0. "ThisView the full article
When ‌macOS Tahoe‌ and iPadOS 26 launched last September, Apple quietly removed Safari's Compact tab layout – the option that merged the address bar and the tab bar into a single, space-saving row. If you were a fan of it, you will have been out of luck for months.


The good news is that Apple has brought it back. In macOS 26.4 and iPadOS 26.4, the Compact tab bar is once again available as an alternative to the default Separate layout. Here's how to enable it on both platforms.

On Mac


Open Safari.
In the menu bar, click Safari ➝ Settings....
Click the Tabs pane.
Next to "Tabs Layout," select Compact.


The address bar and tab bar will immediately merge into a single row, freeing up vertical screen space.

On iPad


Open the Settings app.
Scroll down and tap through to Apps ➝ Safari.
Under "Tabs," tap Compact Tab Bar.


That's all there is to it. If you decide you prefer the standard layout, simply retrace your steps and select Separate (on Mac) or Separate Tab Bar (on ‌iPad‌).

The Compact layout can be handy on the smaller screens of the MacBook Air or iPad mini, where every pixel of vertical space counts. It's worth trying if you've never used it, just be aware that tab titles are truncated more aggressively in this view, so when switching between many open tabs you'll have to rely more on favicons than on page names.Tag: Safari
This article, "Safari's Compact Tab Bar Is Back on Mac and iPad" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Apple today shared a trailer for Widow's Bay, a mysterious new "genre-bending" horror-comedy series set to premiere on Apple TV on Wednesday, April 29.


Widow's Bay is described as a "quaint island town 40 miles off the coast of New England," but apparently "something lurks beneath the surface."

Matthew Rhys stars as Mayor Tom Loftis, who is trying to revive the struggling community.


"There's no Wi-Fi, spotty cellular reception and he must contend with superstitious locals who believe their island is cursed," Apple explains.

"Loftis is determined to build a better future for his teenage son and turn the island into a tourist destination," adds Apple. "Miraculously, he succeeds: tourists are finally coming. Unfortunately, the locals were right. After decades of calm, the old stories that seemed too ludicrous to be true, start happening again."

Apple says Widow's Bay blends genuine horror with character-driven comedy.

The first three episodes in the 10-episode season are set to premiere on Apple TV on Wednesday, April 29, and one additional episode will come out every Wednesday through June 17, with a special two-episode release on Wednesday, May 27. The series is created and executive produced by Katie Dippold, and Hiro Murai directs five episodes this season.

In the U.S., Apple TV is priced at $12.99 per month or $129 per year, with a free one-week trial available for new subscribers. Apple TV is also included in Apple One and Peacock bundles, with all of the options outlined on Apple's website.

You can stream Apple TV in the Apple TV app, which is available on the iPhone, iPad, Mac, Apple TV 4K, Apple Vision Pro, Android, PlayStation, Xbox, Roku, Amazon Fire TV, select smart TVs, on the web at tv.apple.com, and more.Related Roundup: Apple TVTags: Apple TV Service, Apple TV ShowsBuyer's Guide: Apple TV (Don't Buy)Related Forum: Apple TV and Home Theater
This article, "Apple TV Releases Trailer for Mysterious New 'Genre-Bending' Series" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Despite releasing more than 10 new products so far this year, Apple has yet to hold a traditional event with a live-streamed video in 2026.


While anything is possible, our best guess at this point is that Apple's next event will likely be its annual developers conference WWDC in June, with standalone live-streamed Apple Events this April or May currently looking improbable.

New Products in 2026 So Far

Apple kicked off 2026 by unveiling an AirTag 2 in January, along with a Black Unity Connection Braided Solo Loop for the Apple Watch.

February went by without any new Apple products.


Apple then had a busy March, unveiling the iPhone 17e, iPad Air models with the M4 chip, MacBook Air models with the M5 chip, MacBook Pro models with M5 Pro and M5 Max chips, the all-new MacBook Neo, a new Studio Display, a higher-end Studio Display XDR, AirPods Max 2, and Nike Powerbeats Pro 2.

Apple also introduced new color options for select iPhone cases, Apple Watch bands, and the iPhone's Crossbody Strap. The new colors include the likes of Bright Guava, Vanilla, Soft Pink, Clementine, and Electric Lavender.

Announcement Dates

Here is when Apple announced each new product so far in 2026:
AirTag 2: January 26
Black Unity Connection Braided Solo Loop: January 26
iPhone 17e: March 2
New Accessory Colors: March 2
iPad Air with M4 chip: March 2
MacBook Air with M5 chip: March 3
MacBook Pro with M5 Pro and M5 Max chips: March 3
Studio Display (2026): March 3
Studio Display XDR: March 3
MacBook Neo: March 4
AirPods Max 2: March 16
Nike Powerbeats Pro 2: March 17

Rumored Products

Here is what to expect from Apple later this year, according to rumors.

Beyond the usual annual updates to iPhones and Apple Watches, Apple's all-new smart home hub is finally expected to launch later this year, once the more personalized version of Siri arrives. We are also expecting a foldable iPhone, a MacBook Pro with an OLED display, and long-awaited updates to the Apple TV and HomePods this year.

iPhones

iPhone 18 Pro: A20 Pro chip, a smaller Dynamic Island, a simplified Camera Control button, a red color option, variable aperture for at least one rear camera, web browsing via satellite, Apple-designed C2 modem for 5G, and more.
iPhone 18 Pro Max: The same features rumored for the iPhone 18 Pro, but the Pro Max model might be slightly thicker.
Foldable iPhone: 7.7-inch inner display with a reduced crease, 5.3-inch outer display, two rear cameras, one front camera, a Touch ID power button instead of Face ID, and more. iOS 27 is expected to be tailored for the foldable iPhone, allowing for side-by-side apps and other iPad-like multitasking functionality.

Apple Watches
Apple Watch Series 12: A new chip, design changes (or not), and potentially Touch ID.
Apple Watch Ultra 4: A new chip and potentially Touch ID.

iPads
iPad 12: A16 chip → A18 chip or A19 chip with Apple Intelligence support.
iPad mini: A17 Pro chip → A19 Pro or A20 Pro chip, an OLED display, a vibration-based speaker system, and a water-resistant design.
Macs

Mac Studio: M4 Max and M3 Ultra chips → M5 Max and M5 Ultra chips.
Mac mini: M4 and M4 Pro chips → M5 and M5 Pro chips.
iMac: M4 chip → M5 chip, plus new color options.
MacBook Pro with OLED display: A major redesign towards the end of 2026, with M6 Pro and M6 Max chips, an OLED display, a touch screen, a Dynamic Island, and a thinner design. On this device, which could also be named MacBook Ultra, macOS 27 is expected to offer a touch-friendly interface.

Home

Apple TV: A17 Pro chip with support for the more personalized Siri, and Apple's N1 chip with Wi-Fi 7 support. A built-in FaceTime camera has been rumored for a future Apple TV, but it is unclear if that will arrive with the next model.
HomePod mini: S9 chip or newer with support for the more personalized Siri, Apple's N1 chip with Wi-Fi 7 support, improved sound quality, a second-generation Ultra Wideband chip, and potentially new color options like red.
HomePod: A new full-sized HomePod that supports the revamped Siri.
Home Hub: An all-new smart home hub featuring the more personalized version of Siri, a 6-inch to 7-inch square display, an A18 chip for Apple Intelligence, FaceTime, and more. Place it on a table or mount it on a wall.
Security Camera/Sensor: Apple-designed, HomeKit-enabled security camera/sensor accessory to be sold alongside the new smart home hub.
Face ID Doorbell: A video doorbell with Face ID and HomeKit Secure Video, wirelessly connects to a compatible deadbolt lock.

Apple Event Timing

As we mentioned above, our best guess at this point is that Apple's next event will likely be its annual developers conference WWDC in June. The reason for this is that very few Apple products if any in the list above are rumored to be launching imminently, with all of the new smart home products and related accessories in particular reportedly held up until the more personalized version of Siri is finally ready later this year.


Siri's long-awaited revamp is expected to arrive as part of iOS 27, which should be available in beta starting in June and widely released in September.

The only product in the list above that might arrive before WWDC is an iPad 12 with Apple Intelligence support, but it would have been more fitting for Apple to announce that device alongside the new iPad Air last month, so even the entry-level iPad might not be updated again until the second half of this year.

WWDC runs from Monday, June 8 through Friday, June 12 this year. The conference primarily focuses on Apple's latest software platforms, which will include iOS 27, iPadOS 27, macOS 27, watchOS 27, tvOS 27, and visionOS 27 this year, but Apple has also announced new hardware during its WWDC keynote in some years. The last time that happened was at WWDC 2023, when Apple unveiled the Vision Pro, the first 15-inch MacBook Air, Mac Studio models with M2 Max and M2 Ultra chips, and a Mac Pro with the M2 Ultra.

If history repeats itself, the product most likely to be unveiled at WWDC 2026 could be the next Mac Studio, which would be powered by the existing M5 Max chip and an all-new M5 Ultra chip. Apple skipped an M4 Ultra chip, resulting in the current Mac Studio having a mishmash of M4 Max and M3 Ultra chips. This time around, the M5 Ultra chip would not extend to the Mac Pro, as the desktop tower has been discontinued entirely.

Of course, Apple could always surprise us, so stay tuned.Tag: Apple Event
This article, "When is the Next Apple Event?" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Amazon has introduced a few new record low prices on the new M5 MacBook Air this week, with up to $84 off these notebooks. The biggest markdowns can be found on the 13-inch MacBook Air, but there are still some solid deals on 15-inch models as well.

Note: MacRumors is an affiliate partner with Amazon. When you click a link and make a purchase, we may receive a small payment, which helps us keep the site running.

Amazon has the 512GB 13-inch M5 MacBook Air for $1,033.00, down from $1,099.00, and the 24GB/1TB model for $1,415.50, down from $1,499.00. Both of these are only available in Silver and represent new record low prices for each configuration.

$66 OFF13-inch M5 MacBook Air (512GB) for $1,033.00
$84 OFF13-inch M5 MacBook Air (24GB/1TB) for $1,415.50

In terms of the 15-inch models, you'll find $50 discounts across nearly every configuration of the M5 MacBook Air. Prices start at $1,249.00 for the 512GB model, down from $1,299.00, and also include both 1TB models on sale.

$50 OFF15-inch M5 MacBook Air (512GB) for $1,249.00
$50 OFF15-inch M5 MacBook Air (16GB/1TB) for $1,449.00

If you're on the hunt for more discounts, be sure to visit our Apple Deals roundup where we recap the best Apple-related bargains of the past week.



Deals Newsletter

Interested in hearing more about the best deals you can find in 2026? Sign up for our Deals Newsletter and we'll keep you updated so you don't miss the biggest deals of the season!




Related Roundup: Apple Deals
This article, "M5 MacBook Air Hits New Low Prices on Amazon With Up to $84 Off" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Docker Desktop is one of the most widely used developer tools in the world, yet for millions of enterprise developers, running it simply hasn’t been an option. The environments they rely on, such as virtual desktop infrastructure (VDI) platforms and managed desktops, often lack the resources or capabilities needed to run Docker Desktop.
As enterprises scaled to support remote and contractor teams, these environments became the default, effectively blocking many developers from using Docker Desktop altogether. This slowed teams down and cut developers off from faster builds, the latest Docker features, and meaningful productivity gains. As a result, teams were forced into expensive workarounds that are difficult to secure and painful to maintain. 
Today, that changes.
Docker Offload is a fully managed cloud service that moves the container engine into Docker’s secure cloud, allowing developers to run Docker from any environment without changing their existing workflows. As of today, Docker Offload is generally available.
What this means in practice is simple. Developers keep using the same terminal, the same docker run commands, and the same Docker Desktop UI they are already familiar with. The only thing that has changed is where the engine runs, and by moving it to the cloud, Docker Desktop now works in every environment that once blocked it.
How It Works
When you run Docker Offload, it automatically routes the container engine to Docker’s secure cloud. The developer opens Docker Desktop exactly as they always have. No configuration. No retraining or reconfiguring applications for new tools. Containers run in Docker’s cloud infrastructure, and everything, including bind mounts, port forwarding, and Docker Compose, works identically to local.
Every connection runs over an encrypted tunnel on SOC 2 Certified infrastructure, and session activity is logged centrally, giving security teams the audit trail they already require without any changes to existing tooling, firewall rules, or endpoint policies. Every session runs in a temporary, isolated environment without data persistence, and closes cleanly.

What Can You Do With Docker Offload?
Run full Docker in any environment
Every Docker CLI command and every Docker Desktop feature works in VDI, locked-down laptops, remote workstations, and policy-restricted networks. Developers are productive from day one, using the exact CLI commands, workflows, and muscle memory they already have.
Same Infrastructure. New Capabilities. 
Offload deploys alongside your existing VDI infrastructure without touching a single piece of it. Infrastructure and platform teams get a clean drop-in: existing network segmentation, IAM boundaries, and access control policies all stay exactly in place. Centralized admin controls, SSO, and per-user access management are built in from day one. 
Keep security non-negotiable
Dedicated cloud sessions are destroyed at every session end, data stays clean, developer devices stay completely unaffected, and your security perimeter stays intact. Offload operates within your existing security architecture, not around it. SOC 2 Certified, with deployment options that scale from multi-tenant VM-level isolation up to a dedicated single-tenant VPC with private network connectivity for regulated environments.
Unblock developers in minutes
Offload detects constrained environments automatically and activates without developer configuration. Teams go from blocked to building without tickets, setup queues, or IT escalations. When nothing changes for the developer, adoption actually happens.
Current Deployment Options
Docker Offload is currently  available in two deployment methods.
Multi-Tenant provides VM-level isolation on Docker-managed infrastructure. It’s the fastest path for most enterprise teams: no ops overhead, no infrastructure to maintain, productive from the moment it’s enabled.
Single-Tenant provides a dedicated VPC and private network access available, important for organizations in Finance, Healthcare, Government, and other regulated industries. Traffic never traverses the public internet, meeting the network isolation requirements most regulated enterprises enforce as a baseline. For security architects evaluating data residency and compliance requirements, this is the deployment model built for you.
Docker Offload is an add-on to Docker Business. Available now, through Docker’s Sales Team.
Coming Soon
Today’s launch addresses the environment problem. Developers in managed and constrained environments can finally run Docker, without workarounds and without compromise. But we’re not stopping there. Also shipping this year:
Single-Tenant Bring-Your-Own-Cloud (BYOC): Compute runs in your cloud account, your data never leaves your environment, and SOC 2 Certified security stays intact.  CI/CD Pipeline Integration:  Bring Offload to GitHub Actions, GitLab CI, and Jenkins to give every developer the same Docker experience in CI as locally, with cloud-based pipeline compute.  GPU-backed instances: Unlocking AI/ML workloads in managed environments for the first time. The Road Ahead
Development has outgrown the local machine. Docker Offload closes that gap. Infrastructure teams keep their architecture intact. Security teams get the compliance they require. Developers keep the workflows they know. The full power of Docker, for every developer, everywhere. 
This is just the beginning. Learn more about the power of Docker Offload , explore our Docker Offload Docs, and reach out to the Docker Sales Team to start your journey with Offload. 

View the full article
Apple's vice president of fitness technologies Jay Blahnik will retire this summer, bringing to an end a 13-year stint with Apple that was marred by accusations that he created a toxic work environment and sexually harassed an employee.


In an email to employees this week, Apple said Blahnik, 57, will retire in July "to spend time with his family and make an exciting move to New York City," according to The New York Times.

Blahnik joined Apple in 2013 after two decades as a consultant at Nike. He played a central role in developing the Apple Watch's iconic Activity rings (the three colored circles that users close daily by exercising, standing, and burning calories) and later oversaw Fitness+, Apple's subscription workout service featuring video classes for strength work, HIIT, cycling, meditation, yoga, and more.

His leadership of the Fitness+ team however drew serious complaints. In an August 2025 report by the Times, nine current and former employees accused Blahnik of being "verbally abusive, manipulative and inappropriate." More than 10 of the roughly 100 employees on his team had sought extended mental health or medical leaves of absence since 2022, the report said.

Apple settled one complaint alleging sexual harassment by Blahnik and is currently defending him in a separate lawsuit brought by employee Mandana Mofidi, who accused him of bullying. That case is scheduled to go to trial next year.

When employees raised concerns about Blahnik's conduct, Apple initiated an internal investigation and found no evidence of wrongdoing, so Blahnik remained in his role. At the time, Apple spokesperson Lance Lin called the NYT report full of "many inaccurate claims and mischaracterizations," but didn't specify which claims the company disputed.

It's unclear who will succeed Blahnik at Fitness+. Meanwhile, the future of Fitness+ is itself said to be "under review," according to Bloomberg, with services chief Eddy Cue apparently "considering changes" to the service.

Apple Fitness+ launched in 2020. In the U.S., the service costs $9.99 per month or $79.99 per year. Apple Fitness+ is also available as part of the Apple One Premier bundle, with U.S. pricing set at $37.95 per month.Tags: Apple Fitness Plus, New York Times
This article, "Apple VP Behind Activity Rings Retiring After Misconduct Claims" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
The latest ThreatsDay Bulletin is basically a cheat sheet for everything breaking on the internet right now. No corporate fluff or boring lectures here, just a quick and honest look at the messy reality of keeping systems safe this week. Things are moving fast. The list includes researchers chaining small bugs together to create massive backdoors, old software flawsView the full article
A new phishing-as-a-service (PhaaS) campaign is abusing Microsoft’s device code authentication flow to gain unauthorized access to user accounts.
Sekoia researchers first spotted the toolkit “EvilTokens” that lets attackers capture authentication tokens by tricking users into completing a legitimate login process in Microsoft’s own environment.
The activity, observed since at least mid-February, relies on social engineering lures that prompt victims to enter a device code on a real Microsoft login page, Sekoia researchers noted in a blog post. “To compromise Microsoft 365 accounts, EvilTokens pages rely on device code phishing, a technique that differs from the common AitM tactic of replicating Microsoft authentication pages,” the researchers said.
The PhaaS toolkit is offering a host of features to its affiliates, including modules for access weaponization, email harvesting, reconnaissance capabilities, and a built-in webmail interface, all powered through Ai automation, the researchers added.
EvilTokens was found operating through bots on Telegram, with a dedicated channel for kit upgrades. The campaign has so far mostly affected countries, including the US, Australia, Canada, France, India, Switzerland, and the UAE.
Device code authentication as an access broker
The campaign centers around the abuse of Microsoft’s device authorization grant flow, a feature designed to simplify logins for devices like smart TVs or command-line tools. EvilTokens repurposes this workflow by generating a legitimate device code and then tricking victims into entering it themselves on the official login page.

Once the victim completes authentication, the attacker receives access tokens tied to the session. These tokens can then be used to access Microsoft 365 services, including email and cloud resources, without triggering typical credential-based alerts.
Sekoia researchers noted that this technique sidesteps many conventional phishing detections. Because the authentication happens on a legitimate Microsoft domain, there is no credential interception in transit, and multi-factor authentication is completed as happens in a normal login flow.
The attack results in a form of account takeover coming from a seemingly expected user behavior.
A phishing package with post-compromise focus
Beyond the initial access vector, EvilTokens is structured as a full-service phishing platform. The kit provides affiliates with ready-to-use lures, infrastructure, and automation tools designed to carry out both the phishing phase and post-compromise activity.
The lures used in the campaign include fake SharePoint document notifications, DocuSign requests, and account alerts, all meant to urge users toward entering device codes. Once access is obtained, the platform enables inbox analysis, allowing attackers to identify high-value targets such as financial conversations or invoice threads.
“By leveraging the short-lived access token, the attacker can exfiltrate targeted user data for up to 60 minutes following the device code phishing attack,” they said. “Depending on the targeted service, the attacker can access emails via Exchange Online, documents from Microsoft SharePoint Online and OneDrive, or conversation history in Microsoft Teams.” The received tokens with 60 minutes expiry can also be redeemed for generating new access tokens, with a rolling 90-day validity, allowing attackers to maintain persistence on the compromised account.
Distributed through Telegram channels, the PhaaS service includes bot-driven workflows to manage campaigns and token collection. Researchers also observed ongoing development efforts, with indications that support for additional platforms beyond Microsoft may be introduced.
Sekoia shared a set of attack infrastructure details to support tracking. These include phishing domain and URL patterns, self-hosted affiliate domains, EvilTokens admin domains, and the YARA rule for detecting the phishing page.
View the full article
Apple's 20 percent stake in satellite partner Globalstar has become a sticking point in Amazon's reported bid to acquire the company, according to the Financial Times ($).


Amazon is in talks to buy Globalstar in a deal that would value the satellite telecommunications firm at roughly $9 billion, as part of a broader push to compete with SpaceX's Starlink. But Apple's ownership interest – acquired as part of a $1.5 billion investment in 2024 – has required separate negotiations between the two tech giants, the report says.

Under its existing agreement with Globalstar, Apple has access to 85 percent of the company's satellite network capacity for iPhone features including Emergency SOS, Messages via satellite, and Find My location updates. It's unclear how an Amazon acquisition would affect that arrangement.

Apple has not publicly commented on the talks, and no deal has been finalized. Discussions could still fall apart, according to people familiar with the matter who spoke to FT.

Amazon currently has more than 180 satellites in orbit through its own satellite internet program, known as Leo, but that figure is dwarfed by SpaceX's fleet of over 10,000 active satellites. Bloomberg reported in October that Globalstar was exploring a sale and had held early talks with SpaceX.

Apple is working on a series of new satellite connectivity features for the iPhone which will apparently require upgrades to Globalstar's infrastructure. They include Apple Maps via satellite, photos in Messages via satellite, connectivity in indoors environments, satellite over 5G, and a satellite API for third-party apps. Tags: Amazon, Financial Times
This article, "Amazon Reportedly in Talks to Buy Apple Satellite Partner Globalstar" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
A financially motivated operation codenamed REF1695 has been observed leveraging fake installers to deploy remote access trojans (RATs) and cryptocurrency miners since November 2023. "Beyond cryptomining, the threat actor monetizes infections through CPA (Cost Per Action) fraud, directing victims to content locker pages under the guise of software registration," ElasticView the full article
In December 2025, we shared the first-ever The State of Trusted Open Source report, featuring insights from our product data and customer base on open source consumption across our catalog of container image projects, versions, images, language libraries, and builds. These insights shed light on what teams pull, deploy, and maintain day to day, alongside the vulnerabilities andView the full article
Apple offers the iPhone 17 Pro and ‌iPhone 17 Pro‌ Max in just three colors – Silver, Cosmic Orange, and Deep Blue – but notably there's no black option. Last year was the first time Apple's high-end iPhones have not been available with a black or dark gray color option in any way, but those hoping for the return of black this year for the iPhone 18 Pro should look away now.

Image credit: Instant Digital
According to Weibo-based leaker Instant Digital, Apple won't be offering its next-generation premium models in a black color option. Bloomberg's Mark Gurman has suggested that Apple is testing a deep red finish for the iPhone 18 Pro models, alongside a couple of more traditional color options. But black doesn't appear to be one of them.

It was previously rumored that Apple was also considering purple and brown finishes for the iPhone 18 Pro models, but Gurman has said he believes those color options are "just variants of the same red idea."

There's better news for anyone planning to buy Apple's rumored foldable iPhone in a more traditional finish. Gurman said Apple plans to "stay away from fun colors" and stick to more conservative space gray/black and silver/white colors.

Instant Digital has a good track record for Apple rumors and has provided some strikingly accurate information ahead of time, such as the imminent launch of 2023's Yellow iPhone 14, as well as the frosted back glass of the iPhone 15 and iPhone 15 Plus.

The iPhone 18 Pro models are expected to launch in September, with the foldable iPhone potentially arriving later in the year.Related Roundup: iPhone 18 ProTag: Instant Digital
This article, "iPhone 18 Pro Reportedly Won't Come in Black" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Meta-owned messaging platform WhatsApp said it alerted about 200 users who were tricked into installing a bogus version of its iOS app that was infected with spyware. According to reports from Italian newspaper La Repubblica and news agency ANSA, the vast majority of the targets are located in Italy. It's assessed that the threat actors behind the activity used social engineeringView the full article
AI is rapidly changing how software is written, deployed, and used. Trends point to a future where AIs can write custom software quickly and easily: “instant software.” Taken to an extreme, it might become easier for a user to have an AI write an application on demand — a spreadsheet, for example — and delete it when you’re done using it than to buy one commercially. Future systems could include a mix: both traditional long-term software and ephemeral instant software that is constantly being written, deployed, modified, and deleted.
AI is changing cybersecurity as well. In particular, AI systems are getting better at finding and patching vulnerabilities in code. This has implications for both attackers and defenders, depending on the ways this and related technologies improve.
In this essay, I want to take an optimistic view of AI’s progress, and to speculate what AI-dominated cybersecurity in an age of instant software might look like. There are a number of unknowns that will factor into how the arms race between attacker and defender might play out.
How flaw discovery might work
On the attacker side, the ability of AIs to automatically find and exploit vulnerabilities has increased dramatically over the past few months. We are already seeing both government and criminal hackers using AI to attack systems. The exploitation part is critical here, because it gives an unsophisticated attacker capabilities far beyond their understanding. As AIs get better, expect more attackers to automate their attacks using AI. And as individuals and organizations can increasingly run powerful AI models locally, AI companies monitoring and disrupting malicious AI use will become increasingly irrelevant.
Expect open-source software, including open-source libraries incorporated in proprietary software, to be the most targeted, because vulnerabilities are easier to find in source code. Unknown No. 1 is how well AI vulnerability discovery tools will work against closed-source commercial software packages. I believe they will soon be good enough to find vulnerabilities just by analyzing a copy of a shipped product, without access to the source code. If that’s true, commercial software will be vulnerable as well.
Particularly vulnerable will be software in IoT devices: things like internet-connected cars, refrigerators, and security cameras. Also industrial IoT software in our internet-connected power grid, oil refineries and pipelines, chemical plants, and so on. IoT software tends to be of much lower quality, and industrial IoT software tends to be legacy.
Instant software is differently vulnerable. It’s not mass market. It’s created for a particular person, organization, or network. The attacker generally won’t have access to any code to analyze, which makes it less likely to be exploited by external attackers. If it’s ephemeral, any vulnerabilities will have a short lifetime. But lots of instant software will live on networks for a long time. And if it gets uploaded to shared tool libraries, attackers will be able to download and analyze that code.
All of this points to a future where AIs will become powerful tools of cyberattack, able to automatically find and exploit vulnerabilities in systems worldwide.
Automating patch creation
But that’s just half of the arms race. Defenders get to use AI, too. These same AI vulnerability-finding technologies are even more valuable for defense. When the defensive side finds an exploitable vulnerability, it can patch the code and deny it to attackers forever.
How this works in practice depends on another related capability: the ability of AIs to patch vulnerable software, which is closely related to their ability to write secure code in the first place.
AIs are not very good at this today; the instant software that AIs create is generally filled with vulnerabilities, both because AIs write insecure code and because the people vibe coding don’t understand security. OpenClaw is a good example of this.
Unknown No. 2 is how much better AIs will get at writing secure code. The fact that they’re trained on massive corpuses of poorly written and insecure code is a handicap, but they are getting better. If they can reliably write vulnerability-free code, it would be an enormous advantage for the defender. And AI-based vulnerability-finding makes it easier for an AI to train on writing secure code.
We can envision a future where AI tools that find and patch vulnerabilities are part of the typical software development process. We can’t say that the code would be vulnerability-free — that’s an impossible goal — but it could be without any easily findable vulnerabilities. If the technology got really good, the code could become essentially vulnerability-free.
Patching lags and legacy software
For new software — both commercial and instant — this future favors the defender. For commercial and conventional open-source software, it’s not that simple. Right now, the world is filled with legacy software. Much of it — like IoT device software — has no dedicated security team to update it. Sometimes it is incapable of being patched. Just as it’s harder for AIs to find vulnerabilities when they don’t have access to the source code, it’s harder for AIs to patch software when they are not embedded in the development process.
I’m not as confident that AI systems will be able to patch vulnerabilities as easily as they can find them, because patching often requires more holistic testing and understanding. That’s Unknown No. 3: how quickly AIs will be able to create reliable software updates for the vulnerabilities they find, and how quickly customers can update their systems.
Today, there is a time lag between when a vendor issues a patch and customers install that update. That time lag is even longer for large organizational software; the risk of an update breaking the underlying software system is just too great for organizations to roll out updates without testing them first. But if AI can help speed up that process, by writing patches faster and more reliably, and by testing them in some AI-generated twin environment, the advantage goes to the defender. If not, the attacker will still have a window to attack systems until a vulnerability is patched.
Toward self-healing
In a truly optimistic future, we can imagine a self-healing network. AI agents continuously scan the ever-evolving corpus of commercial and custom AI-generated software for vulnerabilities, and automatically patch them on discovery.
For that to work, software license agreements will need to change. Right now, software vendors control the cadence of security patches. Giving software purchasers this ability has implications about compatibility, the right to repair, and liability. Any solutions here are the realm of policy, not tech.
If the defense can find, but can’t reliably patch, flaws in legacy software, that’s where attackers will focus their efforts. If that’s the case, we can imagine a continuously evolving AI-powered intrusion detection, continuously scanning inputs and blocking malicious attacks before they get to vulnerable software. Not as transformative as automatically patching vulnerabilities in running code, but nevertheless valuable.
The power of these defensive AI systems increases if they are able to coordinate with each other, and share vulnerabilities and updates. A discovery by one AI can quickly spread to everyone using the affected software. Again: Advantage defender.
There are other variables to consider. The relative success of attackers and defenders also depends on how plentiful vulnerabilities are, how easy they are to find, whether AIs will be able to find the more subtle and obscure vulnerabilities, and how much coordination there is among different attackers. All this comprises Unknown No. 4.
Vulnerability economics
Presumably, AIs will clean up the obvious stuff first, which means that any remaining vulnerabilities will be subtle. Finding them will take AI computing resources. In the optimistic scenario, defenders pool resources through information sharing, effectively amortizing the cost of defense. If information sharing doesn’t work for some reason, defense becomes much more expensive, as individual defenders will need to do their own research. But instant software means much more diversity in code: an advantage to the defender.
This needs to be balanced with the relative cost of attackers finding vulnerabilities. Attackers already have an inherent way to amortize the costs of finding a new vulnerability and create a new exploit. They can vulnerability hunt cross-platform, cross-vendor, and cross-system, and can use what they find to attack multiple targets simultaneously. Fixing a common vulnerability often requires cooperation among all the relevant platforms, vendors, and systems. Again, instant software is an advantage to the defender.
But those hard-to-find vulnerabilities become more valuable. Attackers will attempt to do what the major intelligence agencies do today: find “nobody but us” zero-day exploits. They will either use them slowly and sparingly to minimize detection or quickly and broadly to maximize profit before they’re patched. Meanwhile, defenders will be both vulnerability hunting and intrusion detecting, with the goal of patching vulnerabilities before the attackers find them.
We can even imagine a market for vulnerability sharing, where the defender who finds a vulnerability and creates a patch is compensated by everyone else in the information-sharing/repair network. This might be a stretch, but maybe.
Up the stack
Even in the most optimistic future, attackers aren’t going to just give up. They will attack the non-software parts of the system, such as the users. Or they’re going to look for loopholes in the system: things that the system technically allows but were unintended and unanticipated by the designers — whether human or AI — and can be used by attackers to their advantage.
What’s left in this world are attacks that don’t depend on finding and exploiting software vulnerabilities, like social engineering and credential stealing attacks. And we have already seen how AI-generated deepfakes make social engineering easier. But here, too, we can imagine defensive AI agents that monitor users’ behaviors, watching for signs of attack. This is another AI use case, and one that I’m not even sure how to think about in terms of the attacker/defender arms race. But at least we’re pushing attacks up the stack.
Also, attackers will attempt to infiltrate and influence defensive AIs and the networks they use to communicate, poisoning their output and degrading their capabilities. AI systems are vulnerable to all sorts of manipulations, such as prompt injection, and it’s unclear whether we will ever be able to solve that. This is Unknown No. 5, and it’s a biggie. There might always be a “trusting trust problem.”
No future is guaranteed. We truly don’t know whether these technologies will continue to improve and when they will plateau. But given the pace at which AI software development has improved in just the past few months, we need to start thinking about how cybersecurity works in this instant software world.
View the full article
Introduction
Cloud testing tools have become an essential part of the software development lifecycle, allowing teams to test their applications and services in cloud environments. These tools help organizations ensure that their applications are performing as expected, scalable, and ready to handle the complexities of modern cloud infrastructures. In 2026, as cloud adoption continues to rise and businesses rely on complex cloud-based environments, the need for efficient cloud testing tools has never been more important.
Choosing the right cloud testing tool involves evaluating several factors such as ease of use, integration capabilities, pricing, and the types of testing supported (e.g., performance, security, scalability, and compatibility). With many options available, it is crucial for decision-makers to select the tool that best fits their specific requirements.
In this blog post, we’ll highlight the top 10 cloud testing tools in 2026, discussing their key features, pros and cons, and providing a detailed comparison to help you make the right decision for your organization.
Top 10 Cloud Testing Tools for 2026
1. LambdaTest
Short Description: LambdaTest is a cloud-based cross-browser testing tool that allows you to run automated Selenium scripts across different browsers and operating systems on real cloud grids.
Key Features:
Cross-browser testing on over 3000 browsers and OS combinations. Real-time browser testing and automated Selenium grid. Visual regression testing capabilities. Integrates with CI/CD pipelines. Supports mobile web testing and screenshot testing. Pros:
Extensive browser and OS coverage. Easy to integrate with other DevOps tools. Cloud grid provides high scalability. Cons:
Pricing can be steep for smaller teams. Learning curve for beginners. 2. Sauce Labs
Short Description: Sauce Labs provides a cloud-based platform for automated testing across desktop and mobile devices, including support for Selenium, Appium, and other frameworks.
Key Features:
Automated cross-browser testing. Real mobile device testing. Continuous testing with integrations into CI/CD workflows. Detailed analytics and video playback of tests. Scalability for parallel test execution. Pros:
Wide browser and mobile device support. Powerful integrations with DevOps tools. Extensive test analytics. Cons:
Higher costs for extensive usage. Sometimes slower response times with large test suites. 3. BrowserStack
Short Description: BrowserStack is a cloud testing platform that enables real-time browser testing, mobile testing, and automated Selenium testing, offering a robust set of tools for developers.
Key Features:
Real mobile device testing. Automated Selenium testing on a cloud grid. Cross-browser testing across 2000+ real devices. Integrates with CI/CD pipelines. Live and visual testing options. Pros:
User-friendly interface. Comprehensive testing capabilities across devices and browsers. Great customer support. Cons:
Expensive for small businesses. Limited integrations with some niche tools. 4. TestComplete
Short Description: TestComplete is an automated UI testing tool that offers cloud-based and desktop testing capabilities, providing detailed test analytics and reporting for cross-platform testing.
Key Features:
Automated UI testing across web and mobile applications. Integrates with popular DevOps tools. Supports a wide range of scripting languages. Cloud-based execution on remote machines. Detailed reporting and error detection. Pros:
High level of customization for automation. Broad language support (JavaScript, Python, etc.). Detailed insights into test failures. Cons:
Somewhat complex setup process. Can be resource-heavy for long test suites. 5. Applitools
Short Description: Applitools offers AI-powered visual testing and monitoring tools that integrate with your cloud-based DevOps tools to provide automated visual validation across browsers and devices.
Key Features:
AI-driven visual validation. Automated functional testing with visual comparisons. Cross-browser and cross-device support. Integrates with CI/CD tools. Cloud-based test execution. Pros:
Excellent for visual testing and UI validation. Strong integrations with DevOps tools. Scalable for enterprise-level applications. Cons:
Limited to visual and functional testing; not a full-featured testing suite. Can be pricey for smaller teams. 6. Rainforest QA
Short Description: Rainforest QA offers a unique cloud-based testing solution that utilizes human testers to execute automated tests across web and mobile platforms.
Key Features:
Manual and automated test execution with real human testers. Integrates with existing DevOps tools. Scalable testing solution for enterprises. Visual reporting and detailed test metrics. Test management capabilities for teams. Pros:
Combines human intelligence with automation. Scalable and quick to implement. Supports both manual and automated testing. Cons:
Test turnaround time can be slower with human testing. Requires ongoing human involvement, which can be costly. 7. Testlio
Short Description: Testlio offers an on-demand testing platform where you can access a team of experienced testers to perform cloud-based testing across your applications.
Key Features:
Managed testing with professional QA testers. Support for web, mobile, and API testing. Cloud-based, scalable test execution. Robust reporting and issue tracking. Integrates with CI/CD pipelines. Pros:
On-demand access to a network of expert testers. Ideal for teams needing fast and reliable testing. Comprehensive test management capabilities. Cons:
Costs may be prohibitive for smaller businesses. Less control over specific testing environments. 8. Katalon Studio
Short Description: Katalon Studio is a comprehensive testing platform that provides cloud testing and automation capabilities for both web and mobile applications with minimal coding required.
Key Features:
Supports automated testing for web, mobile, and APIs. Built-in integrations for CI/CD tools. Keyword-driven testing interface for easier automation. Cloud-based execution with remote test environments. Real-time reporting and dashboards. Pros:
Free tier available for smaller teams. Easy to use for teams with limited programming experience. Offers a cloud-based solution for scalability. Cons:
Limited advanced features in the free version. Less flexibility for complex test scenarios. 9. TestCraft
Short Description: TestCraft is a no-code cloud testing platform designed for automated testing of web applications. It provides AI-driven test creation and execution.
Key Features:
AI-powered test creation without code. Cloud-based execution on various browsers and devices. Continuous testing and monitoring capabilities. Seamless integration with CI/CD pipelines. Detailed reporting and issue tracking. Pros:
Easy to use for non-technical testers. AI-driven test creation saves time and resources. Quick setup and execution. Cons:
Limited to web application testing. Not as feature-rich for complex test scenarios. 10. Xray for Jira
Short Description: Xray for Jira integrates directly with the Jira ecosystem to provide a comprehensive cloud testing solution for agile teams, offering test management and execution within Jira projects.
Key Features:
Test management integration with Jira. Automated and manual test execution. Supports web, mobile, and API testing. Real-time dashboards and reporting. Scalable for large projects. Pros:
Seamlessly integrates with Jira for easy tracking. Ideal for teams already using Jira for project management. Provides a wide range of test execution and management features. Cons:
Limited functionality outside the Jira ecosystem. Learning curve for non-Jira users. 11. Functionize
Short Description: Functionize is an enterprise-grade AI-powered cloud testing platform that enables codeless automated testing across web, mobile (Android and iOS), and API environments using natural language processing and machine learning.
Key Features:
AI-powered test creation using plain English — no scripting or coding required Cloud-based Android and iOS device emulation via Google Nested Virtualization Self-healing tests that automatically adapt to UI and layout changes ML-driven visual analysis with before, during, and after screenshots for every test step Unified platform for web, mobile, and API testing Seamless integration with CI/CD pipelines for continuous testing Pros:
Codeless approach makes it accessible to non-technical testers Self-healing AI dramatically reduces test maintenance overhead Eliminates the need for physical device labs for mobile testing Cons:
Custom pricing may be a barrier for smaller teams Primarily suited for enterprise-level organizations Comparison Table
Tool NameBest ForPlatforms SupportedStandout FeaturePricingRating (G2/Capterra)LambdaTestCross-browser testingWebReal-time browser testingStarts at $15/month4.5/5Sauce LabsCross-device testingWeb & MobileMobile device testingStarts at $19/month4.7/5BrowserStackReal-time testingWeb & MobileReal devices for testingStarts at $29/month4.6/5TestCompleteUI & functional testingWeb & DesktopAutomated UI testingStarts at $899/year4.3/5ApplitoolsVisual testingWeb & MobileAI-driven visual testingStarts at $99/month4.7/5Rainforest QAOn-demand testingWeb & MobileHuman testersCustom4.4/5TestlioManaged testingWeb & MobileExpert testers on demandCustom4.6/5Katalon StudioAutomated testingWeb & MobileNo-code automationFree, Starts at $750/year4.2/5TestCraftNo-code testingWebAI-powered test creationCustom4.1/5Xray for JiraJira usersWeb & MobileJira integrationStarts at $10/month4.5/5 Which Cloud Testing Tool is Right for You?
Choosing the right cloud testing tool depends on your specific needs, team size, and the complexity of your testing environment. Here’s a quick decision-making guide:
For teams focusing on cross-browser or cross-device testing, LambdaTest or BrowserStack will be ideal, as both platforms offer extensive coverage across multiple browsers and devices. For AI-powered visual testing, Applitools is a strong contender with its powerful visual validation capabilities. For teams looking for a no-code solution, TestCraft and Katalon Studio provide easy-to-use interfaces that don’t require deep technical knowledge. For enterprise-level teams requiring on-demand testers, Rainforest QA and Testlio offer flexible, scalable solutions with expert testers. Conclusion
In 2026, the cloud testing tools landscape is evolving rapidly to meet the increasing demands of modern software development. As cloud environments become more complex and integrated into businesses’ daily operations, testing tools that offer automation, scalability, and real-time collaboration will be essential.
These top 10 cloud testing tools offer a wide range of features, from cross-browser testing to AI-driven visual validation, to suit various business needs. Each tool has its strengths and weaknesses, so evaluating them based on your team’s requirements is crucial for selecting the right solution.
We encourage you to explore demos or free trials of these tools to see which one fits your testing needs best.
FAQs
Q1: What are cloud testing tools?
Cloud testing tools help organizations test their software applications in cloud environments, ensuring scalability, performance, and compatibility with cloud-based infrastructures.
Q2: Why is cloud testing important in 2026?
As cloud computing continues to dominate, businesses must ensure their applications work seamlessly across different cloud platforms, devices, and browsers. Cloud testing tools help achieve this.
Q3: How do I choose the best cloud testing tool for my business?
Consider factors like the types of testing supported, ease of integration with existing tools, pricing, and scalability. Evaluate your team’s specific needs before choosing a tool.
Q4: Are there free cloud testing tools available?
Yes, many cloud testing tools, like Katalon Studio, offer free versions with limited features, making them a good option for small teams or individual users.
Q5: Can these tools integrate with my existing CI/CD pipelines?
Most cloud testing tools, including LambdaTest, Sauce Labs, and BrowserStack, offer seamless integrations with CI/CD tools like Jenkins, CircleCI, and GitHub Actions.
View the full article
Apple on Wednesday expanded the availability of iOS 18.7.7 and iPadOS 18.7.7 to a broader range of devices to protect users from the risk posed by a recently disclosed exploit kit known as DarkSword. "We enabled the availability of iOS 18.7.7 for more devices on April 1, 2026, so users with Automatic Updates turned on can automatically receive important securityView the full article
Gorodenkoff | shutterstock.com
Model Context Protocol (MCP) verbindet KI-Agenten mit Datenquellen und erfreut sich im Unternehmensumfeld wachsender Beliebtheit. Allerdings ist auch MCP nicht frei von Sicherheitslücken, wie entsprechende Entdeckungen, etwa beim SaaS-Anbieter Asana oder dem IT-Riesen Atlassian gezeigt haben. Inzwischen hat sich jedoch einiges in Sachen MCP-Sicherheit getan. Einerseits wurden mit Blick auf das Kernprotokoll etliche Fortschritte erzielt. Beispielsweise in Form von Support für OAuth sowie für Authentifizierungs-Server von Drittanbietern und Identity-Management-Systeme. Darüber hinaus wurde inzwischen auch eine offizielle MCP Registry geschaffen, die einen Überblick über sichere, öffentlich verfügbare MCP-Server bietet.
Dennoch bestehen weiterhin Sicherheitslücken, die sich für diverse Cyberschandtaten ausnutzen lassen – Prompt Injection, Tool Poisoning, Token-Diebstahl, Server-übergreifende Attacken oder manipulierte Messages sind nur einige von vielen Beispielen. Mit anderen Worten: Unternehmen, die sich beim Aufbau von Agentic-AI-Systemen einen Wettbewerbsvorteil verschaffen wollen, müssen erhebliche Anstrengungen unternehmen, um zu gewährleisten, dass sensible Daten nicht nach außen dringen. Glücklicherweise gibt es diverse Tools, die dabei Unterstützung versprechen.
In diesem Artikel lesen Sie:
was Security-Tools für MCP leisten sollten, und welche Angebote in diesem Bereich interessant sind. Das sollten MCP-Sicherheitslösungen können
Die Gefahr von Datenlecks, Prompt Injections und weiteren Sicherheitsbedrohungen besteht unabhängig davon, ob Unternehmen:
ihre eigenen KI-Agenten mit MCP-Servern von Drittanbietern, ihre eigenen MCP-Server mit Drittanbieter-Agenten, oder ihre eigenen Server mit den eigenen Agenten verbinden. Soll heißen: Unternehmen müssen in jedem Fall Autorisierungen und Berechtigungen überprüfen, detaillierte Zugriffskontrollen implementieren und alles protokollieren. Daraus ergeben sich auch die Anforderungen für MCP-Sicherheitslösungen. Diese sollten bieten:
MCP-Servererkennung. Für Mitarbeiter eines Unternehmens ist es einfach, MCP-Server herunterzuladen und zu nutzen. Mit Scan-Services für MCP-Server können Unternehmen sämtliche Instanzen von Schatten-MCP-Servern in ihrer Umgebung finden. Laufzeitschutz. KI-Agenten kommunizieren mit MCP-Servern in natürlicher Sprache. MCP-Sicherheits-Tools sollten deshalb in der Lage sein, diese Kommunikation auf Sicherheitsprobleme wie Prompt Injections hin zu überwachen. Authentifizierungs- und Zugriffskontrollen. Das MCP-Protokoll unterstützt inzwischen OAuth, aber das ist nur ein erster Schritt. Für zusätzliche Sicherheit empfehlen sich Tools mit integrierten Kontroll-Frameworks für Zero Trust und Least Privilege. Logging und Observability. Tools und Plattformen sollten zudem die Möglichkeit bieten, MCP-Protokolle zu sammeln, Sicherheitsteams über Richtlinienverstöße zu informieren, Compliance-Daten zu erfassen oder Protokolle in die bestehende Sicherheitsinfrastruktur einzuspeisen. MCP-Security-Angebote
Im Folgenden haben wir die Anbieter von MCP-Security-Tools in drei Kategorien aufgeteilt. Diese Aufstellung erhebt keinen Anspruch auf Vollständigkeit.
Hyperscaler
Für Unternehmen, die sich vollständig auf eine bestimmte Cloud-Plattform verlassen, bieten die MCP-Tools des jeweiligen Hyperscalers einen einfachen Einstieg.
Amazon Web Services (AWS) hat Mitte 2025 seine eigene agentenbasierte KI-Plattform eingeführt. Amazon Bedrock AgentCore umfasst ein Gateway, das mehrere Protokolle unterstützt (darunter auch MCP), ein Identity-Management-System sowie Observability. Microsoft bietet einen grundlegenden Azure-MCP-Server an, inklusive Support für Azure Key Vault. Darüber hinaus unterstützen auch Azure AI Foundry Agent Service und Azure API Management das Model Context Protocol. Zudem bietet Microsoft mit dem Agent Framework auch ein Open-Source-Entwicklungskit, das sowohl MCP als auch Agent2Agent unterstützt und beispielsweise Schutz vor Prompt Injections verspricht. Google Cloud kündigte Anfang 2025 seine MCP Toolbox für Datenbanken an – inklusive integrierter Authentifizierung und Observability. Außerdem hat der Hyperscaler auch eine Referenzarchitektur veröffentlicht, um MCP-Server auf seiner Cloud-Plattform abzusichern. Große Plattformanbieter
Der IT-Dienstleister Cloudflare hat mit MCP Server Portals ein Tool veröffentlicht, mit dem Unternehmen MCP-Verbindungen zentralisiert absichern und überwachen können. Die Funktion ist Bestandteil der Cloudflare-One-Plattform. Palo Alto Networks hat mit Blick auf MCP-Sicherheit mehrere Eisen im Feuer. Mit Prisma AIRS hat das Unternehmen einen eigenen, intermediären MCP-Server veröffentlicht. Dieser sitzt zwischen den KI-Agenten und dem eigentlichen MCP-Server und erkennt schadhafte Inhalte und Daten. Das Tool MCP Security ist hingegen Bestandteil von Cortex Cloud WAAS und überprüft die MCP-Kommunikation an der Netzwerkgrenze auf bösartige Aktivitäten. SentinelOne gewährt mit seiner Singularity Platform ebenfalls Einblick in die MCP-Interaktionskette und bietet zum Beispiel Warnmeldungen und automatisierte Incident Response für MCP-Server auf lokaler oder Remote-Ebene. Daneben hat auch Broadcom MCP-Sicherheitsfunktionen für VMware Cloud Foundation angekündigt, die künftig mehr Sicherheit für agentenbasierte Workflows gewährleisten sollen. Startups
Die Plattform von Acuvity (seit Februar 2026 Teil von Proofpoint) verspricht, MCP-Server umfassend abzusichern. Dafür sorgt laut dem Anbieter eine Kombination aus Least-Privilege-Execution, unveränderlichen Laufzeiten, kontinuierlichen Schwachstellenscans, Authentifizierung und Bedrohungserkennung. Das API-Security-Startup Akto hat eine MCP-Security-Plattform im Angebot. Sie umfasst ein Discovery Tool, um MCP-Server in Unternehmensumgebungen zu identifizieren, Security-Testing-Werkzeuge sowie Monitoring- und Threat-Detection-Funktionen. Invariant Labs bietet mit MCP-Scan ein quelloffenes Tool, das die statische Analyse und Echtzeitüberwachung von MCP-Servern ermöglicht. Mit Guardrails hat das Startup auch ein kommerzielles Produkt im Angebot. Dabei handelt es sich um einen Proxy. Der zwischen KI-Agenten und MCP-Servern sitzt und vor Security-Risiken schützen soll. Das Tool befähigt Anwender außerdem dazu, Richtlinien aufzusetzen. Highflame (vormals Javelin) addressiert ebenfalls das Thema MCP-Sicherheit. Etwa mit Funktionen wie MCP-Server auf Risiken zu scannen oder Datenanfragen zu überprüfen.   Lasso Security stellt ein Open-Source-MCP-Gateway zur Verfügung, das die Konfiguration und das Lebenszyklusmanagement von MCP-Servern ermöglicht und Messages um sensible Informationen bereinigt. (fm)
View the full article
Gorodenkoff | shutterstock.com
Model Context Protocol (MCP) verbindet KI-Agenten mit Datenquellen und erfreut sich im Unternehmensumfeld wachsender Beliebtheit. Allerdings ist auch MCP nicht frei von Sicherheitslücken, wie entsprechende Entdeckungen, etwa beim SaaS-Anbieter Asana oder dem IT-Riesen Atlassian gezeigt haben. Inzwischen hat sich jedoch einiges in Sachen MCP-Sicherheit getan. Einerseits wurden mit Blick auf das Kernprotokoll etliche Fortschritte erzielt. Beispielsweise in Form von Support für OAuth sowie für Authentifizierungs-Server von Drittanbietern und Identity-Management-Systeme. Darüber hinaus wurde inzwischen auch eine offizielle MCP Registry geschaffen, die einen Überblick über sichere, öffentlich verfügbare MCP-Server bietet.
Dennoch bestehen weiterhin Sicherheitslücken, die sich für diverse Cyberschandtaten ausnutzen lassen – Prompt Injection, Tool Poisoning, Token-Diebstahl, Server-übergreifende Attacken oder manipulierte Messages sind nur einige von vielen Beispielen. Mit anderen Worten: Unternehmen, die sich beim Aufbau von Agentic-AI-Systemen einen Wettbewerbsvorteil verschaffen wollen, müssen erhebliche Anstrengungen unternehmen, um zu gewährleisten, dass sensible Daten nicht nach außen dringen. Glücklicherweise gibt es diverse Tools, die dabei Unterstützung versprechen.
In diesem Artikel lesen Sie:
was Security-Tools für MCP leisten sollten, und welche Angebote in diesem Bereich interessant sind. Das sollten MCP-Sicherheitslösungen können
Die Gefahr von Datenlecks, Prompt Injections und weiteren Sicherheitsbedrohungen besteht unabhängig davon, ob Unternehmen:
ihre eigenen KI-Agenten mit MCP-Servern von Drittanbietern, ihre eigenen MCP-Server mit Drittanbieter-Agenten, oder ihre eigenen Server mit den eigenen Agenten verbinden. Soll heißen: Unternehmen müssen in jedem Fall Autorisierungen und Berechtigungen überprüfen, detaillierte Zugriffskontrollen implementieren und alles protokollieren. Daraus ergeben sich auch die Anforderungen für MCP-Sicherheitslösungen. Diese sollten bieten:
MCP-Servererkennung. Für Mitarbeiter eines Unternehmens ist es einfach, MCP-Server herunterzuladen und zu nutzen. Mit Scan-Services für MCP-Server können Unternehmen sämtliche Instanzen von Schatten-MCP-Servern in ihrer Umgebung finden. Laufzeitschutz. KI-Agenten kommunizieren mit MCP-Servern in natürlicher Sprache. MCP-Sicherheits-Tools sollten deshalb in der Lage sein, diese Kommunikation auf Sicherheitsprobleme wie Prompt Injections hin zu überwachen. Authentifizierungs- und Zugriffskontrollen. Das MCP-Protokoll unterstützt inzwischen OAuth, aber das ist nur ein erster Schritt. Für zusätzliche Sicherheit empfehlen sich Tools mit integrierten Kontroll-Frameworks für Zero Trust und Least Privilege. Logging und Observability. Tools und Plattformen sollten zudem die Möglichkeit bieten, MCP-Protokolle zu sammeln, Sicherheitsteams über Richtlinienverstöße zu informieren, Compliance-Daten zu erfassen oder Protokolle in die bestehende Sicherheitsinfrastruktur einzuspeisen. MCP-Security-Angebote
Im Folgenden haben wir die Anbieter von MCP-Security-Tools in drei Kategorien aufgeteilt. Diese Aufstellung erhebt keinen Anspruch auf Vollständigkeit.
Hyperscaler
Für Unternehmen, die sich vollständig auf eine bestimmte Cloud-Plattform verlassen, bieten die MCP-Tools des jeweiligen Hyperscalers einen einfachen Einstieg.
Amazon Web Services (AWS) hat Mitte 2025 seine eigene agentenbasierte KI-Plattform eingeführt. Amazon Bedrock AgentCore umfasst ein Gateway, das mehrere Protokolle unterstützt (darunter auch MCP), ein Identity-Management-System sowie Observability. Microsoft bietet einen grundlegenden Azure-MCP-Server an, inklusive Support für Azure Key Vault. Darüber hinaus unterstützen auch Azure AI Foundry Agent Service und Azure API Management das Model Context Protocol. Zudem bietet Microsoft mit dem Agent Framework auch ein Open-Source-Entwicklungskit, das sowohl MCP als auch Agent2Agent unterstützt und beispielsweise Schutz vor Prompt Injections verspricht. Google Cloud kündigte Anfang 2025 seine MCP Toolbox für Datenbanken an – inklusive integrierter Authentifizierung und Observability. Außerdem hat der Hyperscaler auch eine Referenzarchitektur veröffentlicht, um MCP-Server auf seiner Cloud-Plattform abzusichern. Große Plattformanbieter
Der IT-Dienstleister Cloudflare hat mit MCP Server Portals ein Tool veröffentlicht, mit dem Unternehmen MCP-Verbindungen zentralisiert absichern und überwachen können. Die Funktion ist Bestandteil der Cloudflare-One-Plattform. Palo Alto Networks hat mit Blick auf MCP-Sicherheit mehrere Eisen im Feuer. Mit Prisma AIRS hat das Unternehmen einen eigenen, intermediären MCP-Server veröffentlicht. Dieser sitzt zwischen den KI-Agenten und dem eigentlichen MCP-Server und erkennt schadhafte Inhalte und Daten. Das Tool MCP Security ist hingegen Bestandteil von Cortex Cloud WAAS und überprüft die MCP-Kommunikation an der Netzwerkgrenze auf bösartige Aktivitäten. SentinelOne gewährt mit seiner Singularity Platform ebenfalls Einblick in die MCP-Interaktionskette und bietet zum Beispiel Warnmeldungen und automatisierte Incident Response für MCP-Server auf lokaler oder Remote-Ebene. Daneben hat auch Broadcom MCP-Sicherheitsfunktionen für VMware Cloud Foundation angekündigt, die künftig mehr Sicherheit für agentenbasierte Workflows gewährleisten sollen. Startups
Die Plattform von Acuvity (seit Februar 2026 Teil von Proofpoint) verspricht, MCP-Server umfassend abzusichern. Dafür sorgt laut dem Anbieter eine Kombination aus Least-Privilege-Execution, unveränderlichen Laufzeiten, kontinuierlichen Schwachstellenscans, Authentifizierung und Bedrohungserkennung. Das API-Security-Startup Akto hat eine MCP-Security-Plattform im Angebot. Sie umfasst ein Discovery Tool, um MCP-Server in Unternehmensumgebungen zu identifizieren, Security-Testing-Werkzeuge sowie Monitoring- und Threat-Detection-Funktionen. Invariant Labs bietet mit MCP-Scan ein quelloffenes Tool, das die statische Analyse und Echtzeitüberwachung von MCP-Servern ermöglicht. Mit Guardrails hat das Startup auch ein kommerzielles Produkt im Angebot. Dabei handelt es sich um einen Proxy. Der zwischen KI-Agenten und MCP-Servern sitzt und vor Security-Risiken schützen soll. Das Tool befähigt Anwender außerdem dazu, Richtlinien aufzusetzen. Highflame (vormals Javelin) addressiert ebenfalls das Thema MCP-Sicherheit. Etwa mit Funktionen wie MCP-Server auf Risiken zu scannen oder Datenanfragen zu überprüfen.   Lasso Security stellt ein Open-Source-MCP-Gateway zur Verfügung, das die Konfiguration und das Lebenszyklusmanagement von MCP-Servern ermöglicht und Messages um sensible Informationen bereinigt. (fm)
View the full article
For its 50th anniversary celebration, Apple invited The Wall Street Journal's Ben Cohen to Apple Park to meet up with Apple CEO Tim Cook.


Cohen and Cook took a look at rare archival materials from the early days of Apple, some of which Cook wasn't even familiar with. Cook said that he had seen a lot of the devices for the first time while preparing for Apple's 50th anniversary.

Items on display included the first patent Apple filed, which was for the Apple II, the original 2001 iPod, early iPhone components and prototypes, the Apple Watch Cook wore on stage when announcing the device, and more.

According to Cook, the launch of the iPhone was his favorite moment at Apple. When asked why, he said it was because a phone was something everyone at Apple was using every day.
Cook declined to speak on future products, but he suggested Apple's next hit would be something that "finds the intersection of hardware, software, and services." Cook also declined to comment on talk about him retiring. "My answer to that is when the day comes, I'll know it," he said.

Apple celebrated its 50th anniversary with a Paul McCartney concert for employees last night, and today, in addition to speaking with the ‌Wall Street Journal‌, Cook sent out a heartfelt letter to employees.

Prior to today, Apple also celebrated its 50th anniversary with a series of concerts and events around the world.Tags: Apple 50th Anniversary, Tim Cook
This article, "Tim Cook Says iPhone Launch Was His Favorite Apple Moment in 50th Anniversary Interview" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Apple today updated the Sports app for iPhone to add more 2026 FIFA World Cup content. Soccer fans are now able to view complete tournament groupings and follow their favorite national teams in the app. This is the first 48-team World Cup and a departure from the traditional 32-team format.


Following teams allows Apple Sports users to get real-time score updates and stats, plus there is support for Live Activities for tracking games. Apple says that it's easier than ever for fans to stay up to date on the tournament action when it begins on June 11.

The Apple Sports app lets users follow their favorite teams, tournaments, and leagues, with tools for navigating between scores and upcoming games, viewing play-by-play and lineup details, and tapping into the Apple TV app to watch live events.

Apple Sports includes support for more than 30 of the top soccer leagues and tournaments across North America, Latin America, and Europe.

The Apple Sports app is free to download from the App Store.Tag: Apple Sports
This article, "Apple Sports Now Lets You Follow Your Favorite 2026 FIFA World Cup Teams" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Apple's final product in (PRODUCT)RED is no longer available, as the iPhone 14 Silicone Case in that color was marked as sold out on its online store last month.


Since 2006, Apple has partnered with the (RED) brand to raise money for The Global Fund, an organization that aims to combat diseases such as HIV/AIDS, tuberculosis, and malaria in Africa. Through this partnership, Apple had long offered a (PRODUCT)RED option for some products, but the color is no longer available at all.

While the (PRODUCT)RED era is over for now, the color could always make a return one day. The upcoming iPhone 18 Pro and iPhone 18 Pro Max will reportedly be available in a "deep red" finish, but this might look more like burgundy than bright red, so it remains to be seen if Apple revives the (PRODUCT)RED brand for that.


(RED) was co-founded by U2 singer Bono, and Apple's partnership with the brand goes back to the Steve Jobs days. Apple continues to support The Global Fund through its annual Apple Pay donation program, which raised $3 million last year. So, PRODUCT(RED) is over for now, but Apple's partnership with (RED) remains alive.

Apple offered a variety of iPod, iPhone, and Apple Watch models in (PRODUCT)RED over the years, with some of the most recent products available in the color being the iPhone SE 3, iPhone 14, iPhone 14 Plus, and Apple Watch Series 9. A variety of iPhone cases, Apple Watch bands, and other accessories also came in the color.Related Roundup: iPhone 18 ProTag: (PRODUCT)RED
This article, "Apple's (PRODUCT)RED Era is Over, But What About the iPhone 18 Pro?" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Apple today updated its vintage and obsolete product page to add the Wi-Fi version of the third-generation iPad Air. Cellular ‌iPad Air‌ 3 models were already on the list, but the Wi-Fi models were sold for a longer period of time, and are now just appearing.


The ‌iPad Air‌ 3 was released in March 2019, five years after the prior-generation ‌iPad Air‌ 2. It was a new iPad in Apple's tablet lineup, featuring the same design as the 2017 iPad Pro with 10.5-inch display, A12 Bionic chip, and support for the first-generation Apple Pencil.

It was one of the last iPads to feature a Lightning port and Home button before Apple transitioned to USB-C, an all-display design, and a Touch ID power button. It's also the last version of the ‌iPad Air‌ that featured white bezels around the display.

Apple discontinued the ‌iPad Air‌ 3 in September 2020 with the launch of the ‌iPad Air‌ 4. Some devices had an issue with screen flickering flashing, or dying, leading to a recall program where Apple replaced affected models for up to two years from the purchase date.

Apple adds a product to its "vintage" list when it has been five years since it was last distributed for sale, and then it becomes "obsolete" at the seven-year mark. With vintage products, Apple retail locations and Apple Authorized Service Providers can do repairs if the required parts are available.

Devices that are obsolete are generally not eligible for repair and Apple stops providing repair components.

Earlier this week, Apple added the 13-inch 2017 MacBook Air to its vintage list, and moved the iPad mini 4 and the 32GB Apple TV HD to its obsolete product list.Tag: Vintage and Obsolete Apple Products
This article, "Apple Adds Another iPad to Vintage Products List" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
When your network goes down, your business stops. That’s a stark truth we see confirmed daily in incident response—and N-able’s 2026 State of the SOC Report only underscores it. Backup isn’t just an IT routine anymore; it’s the backbone of your business resilience strategy. Yet, too many teams leave gaps that threat actors are ready to exploit. 
Let’s get proactive. Here are seven common backup priorities and what we recommend to ensure your organization can recover from anything the modern threat landscape throws at you. 
1. Prioritize your most critical data 
You can’t protect everything at the same level, and you shouldn’t try. Businesses focusing on mission-critical systems for backup and rapid recovery have significantly shorter downtime post-incident. 
The Fix: Identify revenue-driving applications, regulated data, and anything core to daily operations—then align backup policies with these priorities. If you treat your archive data with the same urgency as your production data, you’re wasting resources that could save your business during a crisis. 
2. Ensure off-site backup copies 
Local backups are fast, but they are also vulnerable to the same physical disasters and ransomware attacks that hit your primary servers. If your production environment and your backups are on the same network segment without air-gapping, a single compromise becomes a total extinction event. 
The Fix: Adopt a 3-2-1 strategy (3 total copies of data, 2 different media types, 1 offsite copy) but modernize it. Ensure at least one copy is off-site and immutable. Our cloud-first backup solution shows how reducing the attack surface mitigates risk. 
3. Implement backup immutability 
Ransomware attacks increasingly target repositories to force payment. If an attacker can delete your backups, you have no leverage. 
The Fix: Immutable backups—backups that can’t be changed or deleted, even by admins—are non-negotiable. In N-able’s cloud, automated immutable storage and air-gapped backups consistently prevented data loss, even when primary systems were compromised. 
N-able’s Cove Data Protection is ransomware ready with cyber-resilient architecture, immutable copies, and ransomware recovery to keep you in control and able to restore data successfully. 
4. Automating RPO and RTO 
Recovery Point Objective (RPO) and Recovery Time Objective (RTO) are your real commitments to stakeholders. Not enforcing or automating RPO and RTO means an organization lacks defined, measurable targets for data loss and downtime, leading to high-risk, manual, and often chaotic recovery processes. Without automation, organizations rely on manual, human-driven procedures, which increase the likelihood of data loss, extended outages, and failure to meet compliance requirements (e.g., HIPAA, PCI DSS) 
The Fix: Establish RTO and RPO for each application based on criticality. Implement automation and regularly test recovery processes to ensure they meet targets. Don’t rely on manual checks; let the system tell you if you are drifting from your resilience goals. 
Why RPO and RTO metrics matter for cyber resilience and how they are different. 
5. Real-world backup testing 
The worst time to test a backup is when you’re restoring it under pressure. In our experience, corrupted backups surface as a leading cause of failed recoveries. A screenshot of a “success” message isn’t enough proof that a server will boot. 
The Fix: Make automated recovery testing a daily habit and not a quarterly dread. We advocate solutions that boot VMs from backups, run service checks, and supply verifiable evidence after every run. 
6. Integrate backup with security ops 
Too often, backup and security exist in silos. The most resilient organizations are integrating backup failures directly into their SOC dashboards. 
The Fix: Treat backup failures as security incidents. Any surprise failure or agent tampering gets immediate incident review and threat hunting. Bonus: Scan backup images for malware before restoring to avoid reintroducing threats during your most vulnerable moment. 
7. Implement scalable recovery playbooks 
Recovering one file is easy; recovering your business under attack is chaos without a plan. This was painfully clear in cases where teams restored non-essential servers, leaving core business processes offline. 
The Fix: Build recovery runbooks. Know what to bring back first (typically identity, DNS, DB servers), document dependencies, and rehearse recovery from “zero” infrastructure. 
Proving resilience, not just activity 
Executives and clients want to know: “Are we protected if disaster strikes?” Reporting on backup success means showing more than last night’s log. Demonstrate that your tests meet RPO/RTO, that DR rehearsals succeed, and that automated processes kick in as designed. 
We recognize backup is about more than files—it’s about business continuity and trust. With the number of alerts every minute hitting SOCs today, automated orchestration helps you respond to the velocity of modern attacks so you can recover fast and stay compliant, operational, and secure. 
Data threats are evolving, and your backup needs to evolve with them. See how N-able’s Cove Data Protection beats legacy backups.  
View the full article
How many times has your SOC hit crisis mode at 2:00 AM, with the dashboard blaring red and analysts scrambling to separate real threats from useless noise? We’ve all been there, and if you’re still measuring success by the number of alerts closed, chances are you’re feeling the strain. The truth is, responding to everything is neither sustainable nor effective—and it puts resilience at risk. 
In this article, we’ll show you the five most important steps you can take to move from alert fatigue to business resilience, supported by hard data from the 2026 N-able State of the SOC Report. These are the practical habits security-driven IT leaders are adopting to future-proof their operations and protect what matters most. 
1. Recognize the cost of noise: When “more alerts” means more risk 
Many SOCs still believe that more data equals better protection. But our 2026 State of the SOC report found that traditional alert volumes have hit a breaking point— our SOC team had to process an average of 2 alerts per minute last year. When everything is urgent, nothing is. Analysts get burned out, and critical threats can slip by undetected, leading to increased dwell times and real business impact. 
Key N-able SOC stat: 18% of threats in 2025 were only caught by network and perimeter layers—outside endpoint visibility. 
It’s clear: If you’re over-relying on endpoint or cloud signals, you’re missing threats and putting uptime and client trust at risk. 
2. Prioritize outcomes over ticket volume 
Stop focusing on how many alerts are cleared. This may be a metric for a better understanding of where automation or headcount are necessary but prioritize outcomes. Instead, the right questions are: How quickly did you contain a threat? Did we disrupt business operations or keep recovery swift and effective? 
A practical, outcome-driven SOC measures: 
Dwell time: How long before a threat was neutralized?  Mean Time to Contain: How quickly were you able to halt an attack?  Business downtime avoided: How resilient were you when tested?  Tie these metrics back to resilience. When you can tell the CEO or client you prevented X hours of downtime or stopped ransomware in minutes, you position yourself as more than a cost center—you’re a driver of business continuity. 
Hear how customers use N-able to boost efficiency, gain peace of mind, and ensure business resiliency.  
3. Put AI and automation to work—or get left behind 
According to our SOC report, 90% of all investigations in 2026 could be automated by AI. In fact, only organizations that shifted to AI-centric security models kept up with the onslaught. Those stuck with purely manual playbooks fell behind. 
Here’s what works: 
AI-driven correlation to unify context across endpoints, networks, identities, and more.  Automation to handle tasks like remediation, account disables, password resets, and notifications—repetitive work that machines do faster and with less error.  Last year, our SOAR actions surged 500%, making up almost a quarter of all responses. That’s what resilience in the face of “volume crisis” looks like. 
Explore the benefits of integrating AI into your strategy and how it impacts your security team across crucial threat and detection stages.  
4. Build defense-in-depth (and don’t rely on magic bullets) 
The “magic bullet” mindset, where a single security layer or tool is supposed to protect everything, doesn’t cut it. The 2026 N-able State of the SOC report underscores that business resilience depends on a defense-in-depth strategy: 
In 2025, half of all attacks bypassed endpoint controls entirely.  137,187 network and perimeter threats were invisible to endpoint-only deployments.  The lesson: Layered security isn’t just “nice to have”—it’s the difference between stopping attacks and suffering a breach. Even with the right foundational layers in place, the real power only emerges when they operate as a unified system. Multi-layer correlation connects the signals coming from identity, endpoint, cloud, network, and perimeter controls, transforming isolated alerts into a clear, actionable picture of an unfolding attack. 
5. Design playbooks that focus on business resilience 
Your playbooks shouldn’t just stop at technical containment—think bigger. The best teams design for resilience, from automated isolation and communication to verified recovery. 
For ransomware: 
Confirm the scope rapidly (AI correlates affected assets).  Automate isolation of the subnet or systems involved.  Communicate with stakeholders per your IR plan.  Initiate backup restoration, leveraging recent, immutable recovery points.  In our 2026 SOC report, organizations with unified, automated playbooks contained perimeter-initiated attacks in under 10 minutes—even during off-hours. That’s the bar you need to hit. 
The bottom line 
Volume and complexity aren’t going away, but SOC fatigue doesn’t have to be your story. By shifting to outcome-driven defense, embracing automation, layering controls, and focusing on measurable resilience, you move from reactive to proactive—protecting your clients, your brand, and your peace of mind. 
Are you ready to take the next step? Take a tour of Adlumin’s AI-powered XDR platform and expert-led MDR service. 
View the full article
Business resilience starts at the endpoint. Between March and December 2025, the N-able SOC processed over 900,000 alerts—and a staggering 18% originated from network and perimeter exploits that most endpoint-only security never saw. Attackers are constantly shifting tactics, and endpoints remain an exposed attack surface. The good news: the right proactive strategies put you in control, stopping threats before they ripple across your business. 
Here’s our concise, field-tested playbook to operationalize resilient endpoint security and avoid the single-layer fallacy that leaves half your risks unseen. 
1. Start with full endpoint visibility—No blind spots allowed 
You can’t protect what you don’t know about. As mentioned in our State of the SOC report, network and perimeter threats flew under the radar for organizations lacking unified visibility. These weren’t minor threats — many were initial stages of attacks that would have become full breaches without multi-layer visibility. 
Inventory all devices continuously. Go beyond manual tracking. Automated discovery tools can identify each device, from remote laptops to IoT assets, as soon as they join your network.  Mitigate shadow IT risk. Unmanaged devices are a favorite entry point for attackers. Every asset must be accounted for and brought under management. No exceptions.  Learn more about automating discovery and reducing blind spots in your endpoint management strategy with N-able. 
2. Standardize secure configurations (…don’t fall for the “good enough” trap) 
Uniform security policies are your first solid defense. The data is clear: attackers exploit inconsistencies, and endpoints with misconfigurations are easy targets. 
Enforce least privilege. Remove local admin rights unless absolutely necessary—stopping malware before it can spread.  Apply strict allow-listing. Application control blocks unauthorized installations, cutting off common threat vectors.  Leverage policy automation. Templates make it easy to deploy secure configurations at scale across Windows, macOS, and Linux environments.  Failing to standardize? You’re inadvertently creating opportunities for lateral movement and targeted exploits. 
3. Automate patching and remediation—manual processes are a liability 
Waiting on manual patch cycles? That’s a recipe for disaster. Automation is now essential for effective vulnerability management because attackers are moving faster than ever. AI lets threat actors scan for weaknesses, generate new exploits, and launch broad attacks at a pace manual processes cannot match. When vulnerabilities emerge, the gap between disclosure and exploitation is shrinking, which leaves organizations that rely on human-driven workflows exposed. 
Manual patching and tracking introduce delays and inconsistencies that create easy openings for attackers. Automated discovery, prioritization, and patch deployment help close these gaps by removing human bottlenecks and ensuring critical fixes are applied quickly and consistently. In a world where AI accelerates both the volume and speed of attacks, automation is the only sustainable way to reduce risk and maintain a strong security posture. 
Prioritize based on real risk. Focus on vulnerabilities under active attack or critical to business continuity.  Automate across OS and third-party software. Don’t let browsers or document tools become overlooked gateways.  Measure what matters. Track metrics like “percentage of devices patched” and “average remediation time” for continuous improvement.  Explore N-able’s automated patch management for fast, scalable response. 
4. Add EDR to detect what endpoint antivirus misses 
Prevention is never 100%. Our 2026 SOC report shows that 50% of attacks bypassed endpoint controls entirely, often moving laterally or exploiting identity layers. To achieve true resilience, include Endpoint Detection and Response (EDR) in your security stack. 
Behavioral threat detection: AI-driven EDR stops zero-day and fileless attacks that signature-based tools miss.  Automated response: Compromised endpoints are isolated automatically, containing threats before they spread.  Forensic insight: EDR gives you visibility into attack paths, enabling rapid remediation and long-term learning.  Leverage N-able EDR to transform your endpoint monitoring and response. 
5. Connect endpoints to backup and recovery—plan for when (…not if) something gets through 
Even with layers of defense, you can’t eliminate risk. How fast you bounce back determines your business resilience. In environments with integrated endpoint and backup management, the N-able SOC observed faster incident recovery and reduced downtime. 
Ensure every critical device is covered. Regular checks ensure backup policies include your entire asset inventory.  Prioritize rapid recovery. Restore the systems that matter most first to maintain operational uptime.  Unify workflows. Centralized platforms streamline both the detection and restoration process, cutting downtime.  Lessons from the front lines 
Don’t rely on “magic bullet” solutions—The SOC’s 2026 alert data proves: defense-in-depth is essential. Relying on endpoint protection alone means missing critical network and perimeter threats.  Automate and correlate across layers. Human-driven response can’t keep up. In 2026, 90% of investigation steps could be automated, and multi-layer correlation stopped ransomware in under 10 minutes during real-world attacks.  Measure and report. Regular status updates on patch levels, detection rates, and recovery speed keep your team—and your leadership—aligned and ready.  Embedding resilience: Why N-able customers succeed 
We recognize the weight IT security teams carry. Managing inventory, patching, EDR, and backup across hybrid workforces isn’t just complex—it’s mission critical. N-able brings unified monitoring, orchestration, and rapid response under one platform, helping internal IT teams and MSPs operationalize resilience, reduce downtime, and drive business continuity. 
See how N-able is delivering business resilience in 2026. 
View the full article
Silos are the enemy of business resilience. As IT leaders, we’ve all felt the pain: the backup administrator, SOC analyst, and endpoint engineer operating in separate worlds—often meeting for the first time in the chaos of a live cyberattack. The result? Delayed responses, missed signals, and greater impact on the business.
The N-able 2026 State of the SOC Report leaves no doubt. In just one year, 18% of all security alerts came from network and perimeter exploits—risks many endpoint-only teams never saw coming. Even scarier? 50% of attacks completely bypass endpoint controls. You can’t afford to be siloed. Here’s where most organizations go wrong—and the six crucial steps you need to take to align our teams, tools, and processes for true business resilience.
Mistake 1: Unclear roles and responsibilities
Confusion creates costly delay. During an incident, who owns quarantine actions on high-value endpoints? Who can take critical apps offline? Without a detailed, cross-team RACI matrix (Responsible, Accountable, Consulted, Informed), response efforts stall and attackers gain precious minutes.
Fix: Build a unified RACI for incident response and disaster recovery. Everyone from endpoint to SOC to backup should know their duties in a crisis. Learn how different personalities affect cyber crisis response in this Guide to Managing Strong Personalities During a Cybercrisis.
Mistake 2: Fragmented asset and risk views
Fragmented asset and risk views make it difficult for teams to understand what is actually in their environment and where the most pressing exposures reside. When devices, configurations, and identity data live in separate tools or are maintained inconsistently, gaps appear that attackers can exploit. This lack of a unified perspective slows decision making, complicates prioritization, and obscures the relationships that matter most during an investigation or response.
Fix: Create a single, reliable view of assets and risks across the entire environment. Consolidating inventories, vulnerability data, and identity insights helps teams quickly see what they have, how it is behaving, and where risk is concentrated. With a unified source of truth, organizations can prioritize more effectively, enforce policies consistently, and respond with greater confidence.
Mistake 3: Policies and playbooks that don’t talk to each other
Our State of the SOC report found that 18% of alerts now originate from the network edge, which is a significant shift from previous years. If the SOC keeps logs for 90 days, but IT rotates them every 30, the evidence of those attacks may be lost forever. Gaps like this lead to missed detection and slow recovery.
Fix: Align policies, retention schedules, and playbooks across security and IT. Aligning evidence ensures alerts can be fully investigated. Establishing unified standards for log retention, data sources, and workflow handoffs ensures that every team is operating from the same information and timeframes. When policies are coordinated and playbooks are connected, organizations can detect edge‑based attacks more reliably and accelerate recovery with complete, consistent evidence.
Mistake 4: Disconnected tools prevent timely action
The best-intentioned teams are blocked when they operate in silos. Our research shows a 5x year-over-year jump in automated response actions (SOAR), but unless EDR, backup, and SOC tools integrate, you can’t leverage this automation at scale.
Fix: Invest in integrating toolsets and automating workflows. For example:
EDR detects ransomware and triggers automated isolation. Backup systems auto-scan restore points for malware before allowing recovery. Failed backup alerts create tickets in both security and endpoint queues. By breaking down the data silos, you move from reaction to prevention. Looking for ways to automate at scale? This Playbook for Smarter Automation offers practical steps and scripts to take your IT security team to the next level.
Mistake 5: No cross-team drills or incident simulations
A playbook only works if everyone’s practiced. Too often, organizations run isolated tests—file restores here, pen tests there—but rarely do we rehearse the full detection-through-recovery scenario.
Fix: Schedule regular tabletop exercises involving endpoint, SOC, and backup teams. Scenarios pulled from the State of the SOC Report, like holiday weekend ransomware, are essential for exposing process gaps before real attackers do. Planning and preparing are key. Here are some best practices when it comes to planning a tabletop exercise.
Mistake 6: Measuring success in silos
If the backup team meets its targets, but recovery takes three days because detection lagged, the business still suffers. The SOC’s speed means little if the restored data is compromised.
Fix: Track success with unified, resilience-focused KPIs. For example:
Mean Time to Recover (MTTR): How quickly can we restore critical systems after an attack? Patching SLA compliance: Not just an IT metric, but key to threat prevention. Successful recovery testing: Are we validating backups or just assuming they work? N-able: Your partner in business resilience
We’ve learned—sometimes the hard way—that business resilience depends on breaking down silos. That’s why N-able unifies endpoint management, security operations, and data protection into a single, powerful view. With automation, integration, and real-time intelligence, we empower you to see threats earlier, recover faster, and keep your teams focused on what matters most: uptime, compliance, and customer trust.
Ready to build your resilience strategy? Check out N-able’s unified end-to-end cybersecurity and IT solutions.  
View the full article
If you’re in IT, you know: what we don’t measure puts business resilience at risk. In the face of rising threat volumes, scaling complexity, and board-level scrutiny, tracking the right operational metrics isn’t just about visibility—it’s the foundation for proactive risk management and business continuity. Compliance and insurance demands are also driving the scrutiny around measuring cybersecurity programs.  
Recent findings from the 2026 N-able State of the SOC Report are clear: the threat landscape keeps shifting, automation and integration are now must-haves, and organizations delivering true resilience measure what matters most. 
Below are the six metrics that we use to move the needle from firefighting to futureproofing. 
1. Mean time to detect (MTTD): The speed of awareness 
Attackers are faster and stealthier than ever. In 2025 alone, N-able’s SOC processed more than 900,000 alerts, with attackers exploiting both endpoints and newly reemerging network perimeters. Our own data shows that rapid detection is non-negotiable: every extra minute a threat goes unseen increases the likelihood of a business-impacting event. 
If your MTTD is measured in hours, not minutes, you’re exposing your organization to avoidable risks. Automated threat detection, AI-driven analytics, and streamlined alert management significantly reduce dwell time. 
Key stat: The N-able SOC now averages 2 alerts per minute, an alert velocity that demands automated detection—not just human monitoring. 
2. Mean time to respond (MTTR): From triage to containment 
It’s not enough to spot threats—you have to contain them fast. MTTR tracks how quickly your team can isolate and neutralize incidents. Integrated SOAR (Security Orchestration, Automation, and Response) workflows now drive a 500% year-over-year increase in orchestrated alert response actions, according to our latest SOC report.  
The difference? Teams leveraging automation have moved from after-the-fact remediation to business-saving containment in minutes rather than hours. 
3. Time to recover: The business resilience reality check 
A single outage can mean hours or days of operational downtime. That’s why recovery time is a core resilience metric. It’s not just about restoring data; it’s about rebuilding trust and revenue streams. 
In 2025, we saw the top-performing organizations combine automated backup and disaster recovery solutions, rapid failover, and regular recovery testing to drive down time-to-recover. Cloud-native backups with built-in recovery processes are now the difference between near-instant resumption and prolonged business impact. 
Access the Cybersecurity Incident Response Plan template to help your team build a structured, comprehensive, and actionable approach to identifying, managing, and mitigating cyber incidents. 
4. Endpoint patch compliance: Closing the doors 
Vulnerability exploits remain a constant threat, and unpatched endpoints often provide the easiest entry points. Maintaining a high percentage of fully patched endpoints helps reduce these paths of attack and strengthens your overall security posture. 
With centralized patch management, resilient teams can automate updates, track compliance, and remove the guesswork from keeping environments secure. This reduces risk surface area even as your operations grow. 
5. Asset and identity coverage: Eliminate blind spots 
You can’t protect what you don’t see. With over 432,000 endpoint-layer detections and 14,000 identity threats recorded by the N-able SOC team between March and December 2025, the risk of shadow IT or credential theft from memory is real.  
Eliminating blind spots starts with full visibility across every asset in the environment. As devices, cloud workloads, and remote access points continue to expand, unmanaged or misconfigured assets can create opportunities for attackers to establish a foothold. Continuous discovery and consistent monitoring help ensure nothing operates outside the security team’s line of sight. 
Identity visibility is equally essential. With credential abuse now a leading attack vector, organizations need awareness of how accounts authenticate, when privileges change, and where anomalies appear across systems. Bringing asset and identity coverage together helps close the gaps attackers look for and strengthens an organization’s overall security posture. 
Your asset and identity coverage percentage tells you whether you’re operating with full visibility or exposing the business to unseen gaps. 
Resilient organizations unify asset discovery, endpoint management, and identity monitoring on a single pane of glass—empowering teams to stay ahead even as environments sprawl. 
Take a tour of N-central and see how we unify IT Ops and SecOps for stronger resilience.  
6. Downtime avoided: Quantifying security’s business value 
Translating technical wins into business outcomes is how IT earns board trust. By correlating incident response and recovery metrics with downtime costs, you deliver a dollar-value impact: tangible proof that your efforts directly protect revenue. 
Integrated platforms, real-time dashboards, and automatic reporting transform security from a cost center into a business safeguard. 
Make metrics your roadmap 
The real message from the latest N-able SOC data? Single-layer approaches and isolated tools are dead ends. According to our recent State of the SOC report, 137,000+ network and perimeter threats bypassed endpoints, and nearly half of all alerts never touched a traditional endpoint. 
Business resilience is now about defense-in-depth, layered visibility, and automation. If you’re relying on what worked last year, you’re behind. We encourage you to start with these six metrics, identify your gaps, and leverage unified security solutions that support operational clarity and proactive resilience. 
Ready to up your security game? Learn more about N-able’s unified end-to-end cybersecurity and IT solutions. 
View the full article
What does it really take to keep your organization running when attackers strike? The answer is business resilience—being able to detect, contain, and recover fast enough that disruptions are minimized, customers stay confident, and operations keep moving.  
From the latest 2026 State of the SOC Report, which is based on more than 900,000 alerts observed between March and December 2025 from the Adlumin Managed Detection and Response (MDR) provided by the N-able SOC, we’ve seen firsthand where security strategies succeed—and where they fall short. 
Below, we break down five actionable ways to build true resilience for your IT environment, using real-world data, strategic guidance, and frameworks that leading IT teams put into practice today.
1. Stop trusting single-layer security 
If you’re depending on just endpoint or cloud controls, you’re missing nearly half the risk surface—and the numbers prove it. In 2025, 18% of all alerts at the N-able SOC came from network and perimeter (Unified Threat Management) exploits that bypassed endpoint visibility. Over 137,000 threats were detected where endpoint-only controls would have been blind. 
What we recommend: 
Embrace layered, defense-in-depth designs. That means combining identity, endpoint, network, cloud, and perimeter visibility—not just bolting on tools. Relying on a “magic bullet” solution leaves dangerous gaps. 
Looking for end-to-end coverage of your environment? Check out N-able Unified Security Solutions. 
2. Transition from manual to automated response 
SOC teams can’t keep up with the flood of alerts—N-able handled 2 alerts per minute on average in 2025. That’s why automation and Security Orchestration, Automation and Response (SOAR) saw a 500% YoY surge—almost one in four responses are now orchestrated automatically. 
Pro tip for IT leaders: 
Streamline workflows, so triage and containment happen at machine speed, not human speed. Automate password resets, containment, and endpoint remediation, then focus your analysts on proactive threat hunting. 
3. Modernize endpoint and identity management 
Attack patterns are shifting. Out of 909,155 total alerts identified in N-able’s 2026 SOC report, only about half touched the endpoint layer. Identity has become one of the fastest‑growing attack surfaces, and organizations need visibility into suspicious sign‑ins, privilege misuse, and anomalous authentication behavior before a breach unfolds. 
A flexible, unified endpoint management solution that helps you manage, control, and secure endpoints is table stakes in your tech stack. To address identity attacks, an Identity Threat Detection and Response (ITDR) solution helps close this gap by correlating identity events, detecting credential abuse, and stopping identity‑based attacks in progress. ITDR gives security teams a clearer picture of how users, systems, and privileges are being accessed so they can contain threats early, before lateral movement or escalation occurs. 
Actionable step: 
Integrate advanced multi-factor authentication, real-time patch management, and privileged access controls as foundational layers. Add continuous identity monitoring to detect unusual authentication patterns and catch malicious activity that endpoint‑only tools cannot see.  
Transform your endpoint management – Explore how N-able’s N-central delivers simpler, smarter IT and security management. 
4. Build recovery readiness into your plan 
Resilience isn’t just stopping an attack—it’s restoring operations quickly and minimizing downstream damage. In an N-able case study, an MSP’s customer suffered a 1.5 terabyte ransomware attack on a Friday. Thanks to Cove’s reliable backups (validated via recovery testing), the entire environment was fully restored by Monday, getting the business back online in under 3 days. This rapid recovery dramatically limited downtime and business disruption. 
Our advice: 
Test backups regularly, ensure they’re immutable, and tie recovery procedures directly into your SOC playbooks. Business continuity hinges on the speed and certainty of your recovery. 
See how Cove Data Protection delivers data resiliency by recovering quickly and reliably after every disaster.   
5. Prepare for the next attack surface: AI 
AI is transforming both defense and risk. By 2026, up to 90% of investigations could be automated by AI. But adversaries aren’t far behind—compromised AI orchestration or poisoning can create new attack vectors that bypass traditional controls. 
What you need to do now: 
Audit where AI and automation touch your environment and monitor their actions with the same rigor as human activity. Prepare to secure agent-to-agent communications and maintain oversight as AI-driven processes mature. 
Explore how N-able leverages AI to protect customer environments around the clock. 
Strengthen your business with resilience-first security 
Resilience isn’t a buzzword—it’s the only practical answer for IT leaders dealing with today’s complex, fast-moving threat landscape. By focusing on layered defense, automation, unified recovery, and AI-integrated controls, you position your organization for uptime and continued success.  Ready to level up your approach? Get started with our Cyber Resilience Primer: What You Need to Know in 2026.  

View the full article
Apple added the 14-inch MacBook Pro with M5 chip and the iPad 11 to its online store for refurbished products today, allowing customers to purchase like-new models at a discount. The refurbished devices are available in the U.S., Canada, UK, and many other European countries.


Pricing on the 14-inch ‌MacBook Pro‌ with M5 chip starts at $1,359 in the U.S. for the model with a 10-core CPU, 10-core GPU, 16GB unified memory, and 512GB SSD.

Apple has several configurations available at different price points, including a high-end model with 32GB RAM and a 4TB SSD for $2,759. Discounts are right around 15 percent, which is common for refurbished Macs.

As for the ‌iPad‌ 11, refurbished pricing starts at $299 for the base model, which is a $50 discount off of the regular $349 price. Apple has higher tier models with more storage, along with Wi-Fi + Cellular models.

The 14-inch M5 ‌MacBook Pro‌ models came out in October 2025, while the ‌iPad‌ 11 with A16 chip debuted in March 2025.

Refurbished products are sold with the same one-year warranty offered with a new Apple device, plus they come with all manuals and accessories. Apple employs a testing, repair, repackaging, and cleaning process to ensure that refurbished devices are identical to new devices. All refurbished products are eligible for AppleCare+.Related Roundups: iPad, MacBook ProTag: Apple Refurbished ProductsBuyer's Guide: iPad (Don't Buy), MacBook Pro (Buy Now)Related Forums: iPad, MacBook Pro
This article, "Apple Now Selling Refurbished M5 MacBook Pro and iPad 11 at Reduced Prices" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Apple has tested an updated iPhone keyboard with autocorrect enhancements, according to a report this week from Bloomberg's Mark Gurman.


The report said the keyboard "expands autocorrect by offering alternative words," similar to tools like Grammarly. "It suggests alternative words in addition to word fixes like today's autocorrect," said Gurman, in a follow-up social media post.

Grammarly evolved to use AI in recent years, so perhaps the iPhone keyboard's expanded autocorrect system would be powered by Apple Intelligence. The report did not provide any further details, so we will have to wait and see.

Gurman briefly touched on the keyboard plans in a report focused on how Siri may be able to handle multiple requests in a single query on iOS 27.

Apple has not made a final decision on whether to release the updated keyboard, according to Gurman, but it would presumably debut as part of iOS 27 as well if it does materialize. The first developer beta of iOS 27 is expected to be released in June, and the software update should be widely released in September.

iOS 26.4 already "improved keyboard accuracy when typing quickly," according to Apple's release notes for that update, released last week.Related Roundup: iOS 27Tags: Bloomberg, Mark Gurman
This article, "iOS 27 Rumored to Feature Keyboard Upgrade" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
We're only months away from our first look at Apple's smarter, redesigned version of Siri. iOS 27, iPadOS 27, and macOS 27 will focus on an entirely revamped version of ‌Siri‌, and rumors about what we can expect are picking up.

Subscribe to the MacRumors YouTube channel for more videos.
There's a chatbot version of ‌Siri‌ in the works that will change the way that we use Apple's personal assistant. ‌Siri‌ will be more like Claude or ChatGPT, marking a major improvement in how ‌Siri‌ works and what it can do.

SiriBot

With ‌iOS 27‌, Apple is turning ‌Siri‌ into a chatbot. Right now, ‌Siri‌ can answer common questions and complete simple tasks, but you can't engage it in a back and forth conversation, get help with multi-step tasks, or ask complicated questions with multiple steps in one query.

Based on the ‌Siri‌ chatbot rumors, ‌Siri‌ will be able to do all of that and more with the upcoming upgrade, and it will work like competing chatbots.

Apple wasn't initially planning to introduce a full chatbot like ChatGPT, but chatbots have become too popular for Apple to ignore. Simply adding AI capabilities to apps and features isn't enough for Apple to stay competitive with the way people have embraced chatbots for everything from web searches to coding help.

Google has already integrated Gemini into its Android device lineup, and chatbots like ChatGPT and Claude have hundreds of millions of weekly active users. Apple can't afford not to compete.

Standalone Siri App

When ‌Siri‌ evolves into a Apple-designed chatbot, it will launch alongside a standalone ‌Siri‌ app. The ‌Siri‌ app will look similar to apps from other companies like OpenAI, displaying a grid or list of past ‌Siri‌ conversations.

‌Siri‌ will support text and voice-based conversations, and there will be options to favorite chats, search for content within chats, initiate new chats, and save chats. Conversations with ‌Siri‌ will apparently resemble iMessage conversations, with Apple adopting chat bubbles.

New conversations will start with suggested prompts on what users can ask ‌Siri‌.

Deep Integration

While there will be a standalone ‌Siri‌ app for back-and-forth conversations, ‌Siri‌ will be deeply integrated into Apple devices at the system level. ‌Siri‌ will be activated the same way as today, by speaking the ‌Siri‌ wake word or pressing on the side button of a Siri-enabled device. ‌Siri‌ will be able to respond to both voice and text-based requests.

Siri Capabilities

‌Siri‌ will be able to do what current chatbots can do, such as searching the web with visually rich results, providing summaries, and evaluating uploaded documents. The personal assistant will still be integrated into Apple devices. ‌Siri‌ integration will replace the current Spotlight search functionality, but Apple plans to keep and expand on ‌Siri‌ Suggestions. ‌Siri‌ Suggestions will have more access to user data to provide more relevant prompts.

Search the web for information
Generate images
Generate content
Summarize information
Analyze uploaded files
Use personal data to complete tasks
Ingest information from emails, messages, files and more
Analyze open windows and on-screen content to take action
Control device features and settings
Search for on-device content, replacing Spotlight

‌Siri‌ will also be integrated into Apple's core apps, including Mail, Messages, Apple TV, Xcode, and Photos. ‌Siri‌ will be able to search for specific images, edit photos, help with coding, make suggestions for TV shows and movies, and send emails.

New Look

Chatbot ‌Siri‌ will have an updated look to go along with the dedicated app. Activating ‌Siri‌ will have a new animation that prompts the user to search or ask a question, and Bloomberg says Apple is testing a version of ‌Siri‌ integrated into the Dynamic Island. Apple's test interface includes a glowing ‌Siri‌ icon and a "searching" label in the ‌Dynamic Island‌ while ‌Siri‌ is processing a request, and once done, ‌Siri‌ expands into a larger translucent panel with the results. Pulling down on the menu initiates an interface for a conversation.

Apple may also integrate an "Ask ‌Siri‌" button into the menus of other apps, giving users a way to send content directly to ‌Siri‌ alongside a request. The iOS keyboard could get a Write with ‌Siri‌ option that surfaces Writing Tools.

Memory

Claude, ChatGPT, and Gemini can remember past conversations and interactions, retaining a memory of the user. Apple is said to be discussing how much the ‌Siri‌ chatbot will be able to remember.

Apple may limit conversational memory to protect user privacy.

Third-Party Chatbot Integrations

Apple will allow third-party AI chatbots to integrate with Siri in ‌iOS 27‌. Apple already has a partnership with OpenAI that lets ‌Siri‌ hand questions off to ChatGPT, but that integration will expand to chatbots from other companies like Google and Anthropic.

An iPhone user with the Claude or Gemini app installed will be able to send questions from ‌Siri‌ to those chatbots, similar to how the OpenAI integration works today.

iPhone users will be able to choose which services they want to use inside ‌Siri‌ through a new "Extensions" option coming to the ‌Siri‌ and Apple Intelligence section in the Settings app.

Promised iOS 18 Features

‌Apple Intelligence‌ ‌Siri‌ features that were originally planned for iOS 18 will finally be introduced in ‌iOS 27‌, with ‌Siri‌ able to use personal data and context to answer queries. ‌Siri‌ will also be able to do more in and between apps, and will be able to see what's on the user's screen. Apple promised that those features would appear before the end of 2026.

Underlying Architecture and Servers

Apple has inked a deal with Google that will see Gemini powering upcoming versions of ‌Siri‌. Apple plans to use Gemini for the ‌Siri‌ chatbot and the other ‌Siri‌ features coming in ‌iOS 27‌.

"Apple and Google have entered into a multi-year collaboration under which the next generation of Apple Foundation Models will be based on Google's Gemini models and cloud technology," the two companies said in a statement in January.

The ‌Siri‌ chatbot will rely on a custom AI model developed by the Google Gemini team. Gurman claims that the custom model is comparable to Gemini 3, and that it is more powerful than models Apple has developed in-house.

Apple and Google are also discussing running the ‌Siri‌ chatbot on Google's servers powered by Tensor Processing Units, probably because Apple doesn't yet have the infrastructure to handle chatbot queries from billions of active devices per day.

Launch Date

Apple is planning to introduce ‌Siri‌'s chatbot capabilities when it announces ‌iOS 27‌, iPadOS 27, and ‌macOS 27‌ at the June Worldwide Developers Conference, which starts on Monday, June 8. It is still unclear which ‌Siri‌ features Apple will be ready to unveil, and some could be held for future updates.

Read More

We have a dedicated iOS 27 roundup that goes into more detail on all of the features that we might see in the ‌iOS 27‌ update.Related Roundup: iOS 27Tag: Siri
This article, "Siri in iOS 27: Everything We Know" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Developers can spend days using fuzzing tools to find security weaknesses in code. Alternatively, they can simply ask an LLM to do the job for them in seconds.
The catch: LLMs are evolving so rapidly that this convenience might come with hidden dangers.
The latest example is from researcher Hung Nguyen from AI red teaming company Calif, who, with simple prompts to Anthropic’s Claude Code, was able to uncover zero-day remote code exploits (RCEs) in the source code of two of the most popular developer text editors, Vim and GNU Emacs.
Nguyen started with Vim. “Somebody told me there is an RCE 0-day when you open a file. Find it,” he instructed Claude Code. 
Within two minutes, Claude Code had discovered the flaw: missing critical security checks (P_MLE and P_SECURE) in the tabpanel sidebar introduced in 2025, and a missing security check in the autocmd_add() function.
Claude Code then helpfully tried to find ways to exploit the vulnerability, eventually suggesting a tactic that bypassed the Vim sandbox by persuading a target to open a malicious file. It had gone from prompt to proof-of-concept (PoC) exploit in minutes.
“An attacker who can deliver a crafted file to a victim achieves arbitrary command execution with the privileges of the user running Vim,” Vim maintainers noted in their security advisory. “The attack requires only that the victim opens the file; no further interaction is needed.”
GNU Emacs ‘forever-day’
Surprised, Nguyen then jokingly suggested Claude Code find the same type of flaw in a second text editor, GNU Emacs.
Claude Code obliged, finding a zero-day vulnerability, dating back to 2018, in the way the program interacts with the Git version control system that would make it possible to execute malicious code simply by opening a file.
“Opening a file in GNU Emacs can trigger arbitrary code execution through version control (git), most requiring zero user interaction beyond the file open itself. The most severe finding requires no file-local variables at all — simply opening any file inside a directory containing a crafted .git/ folder executes attacker-controlled commands,” he wrote.
One fixed, one not
When notified, Vim’s maintainers quickly fixed their issue, identified as CVE-2026-34714 with a CVSS score of 9.2, in version 9.2.0272.
Unfortunately, addressing the GNU Emacs vulnerability, which is currently without a CVE identifier, isn’t as straightforward. Its maintainers believe it to be a problem with Git, and declined to address the issue; in his post, Nguyen suggests manual mitigations. The vulnerable versions are 30.2 (stable release) and 31.0.50 (development).
Vulnerable code
What does the discovery of these flaws tell us? Clearly, that large numbers of old codebases are potentially vulnerable to the power of AI tools such as Claude Code. Just because a weakness hasn’t been noticed for years doesn’t mean it will hide for long in the AI era.
That is, potentially, a big change, although hardly one that hasn’t already been flagged by Anthropic itself. In February, the company revealed that its Opus 4.6 model had been used to identify 500 high-severity security vulnerabilities.
“AI language models are already capable of identifying novel vulnerabilities, and may soon exceed the speed and scale of even expert human researchers,” it said at the time.
The platform is powerful enough that an enterprise version with the same capabilities, Claude Code Security, even negatively affected stock market sentiment towards several traditional cybersecurity companies when it was launched.
A second issue is that LLMs are now capable of spotting, iterating, and creating PoCs for vulnerabilities in ways developers still need to come to terms with. Meanwhile, the potential for malicious use is hard to ignore.
“How do we professional bug hunters make sense of this?” Nguyen asked. “This feels like the early 2000s. Back then a kid could hack anything, with SQL Injection. Now [they can] with Claude.”
View the full article
Apple today released a new build of iOS 18.7.7 and iPadOS 18.7.7, presumably with a fix for the DarkSword exploit. Apple told Wired that it would release an iOS 18 update for more devices, allowing users with auto-update turned on to receive the security update. iOS 18.7.7 was initially limited to the iPhone XS and XR models, but it is now available for other iPhones.


Apple is pushing the iOS 18 fix to customers who have decided not to upgrade to iOS 26, but the company encourages users with supported devices to update to ‌iOS 26‌ to get better protection.

Devices running ‌iOS 26‌ are already protected against DarkSword, which is a vulnerability that allows a malicious entity to take over an iPhone if the iPhone user visits a website with infected code.

It is highly unusual for Apple to provide a security update to iOS 18 users who simply don't want to upgrade to ‌iOS 26‌, as Apple uses security fixes as a way to push people to the latest version of iOS or iPadOS that their device supports.

DarkSword has received quite a bit of attention, and it has been used by hacker groups to break into the iPhones of people in Malaysia, Saudi Arabia, Turkey, and Ukraine. The exploit kit has also been posted to open source code repository GitHub, which makes it more widely available to bad actors.Related Forums: iOS 18, iPadOS 18
This article, "Apple Issues Rare iOS 18 Security Update to Protect Against DarkSword Exploit" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Apple's CEO Tim Cook has maintained a working relationship with U.S. President Donald Trump, and he touched on that in a recent interview.


Cook sat down with Esquire's Ryan D'Agostino to discuss Apple's 50th anniversary, but he was also asked about how he navigates the Trump administration.

Cook responded by saying that "the Trump administration is very accessible."

"So you can talk with them about your point of view on things," said Cook. "They may not agree, but you can engage. You can be heard. You may not, in the end, be able to convince. But engagement for me, not just in the U.S. but around the world, is so important because it is very complex, working through local laws, local customs, local culture, local regulations. Every country is its own story. Everybody's looks at things differently."

"The only way you get a feel for that is to sit before someone and communicate and engage," he added. "If you went in my conference room, you would see the Teddy Roosevelt quote 'It is not the critic who counts.' I've never believed that just yelling from the sideline about plus or minus was a good strategy. Your voice just goes into the wind."

Cook went on to say that it is important to have "values that are consistent," and he assured that Apple's values and his own have not changed.

He emphasized Apple's focus on user privacy, the environment, accessibility, and education.

"So you'll see me everywhere, and you'll wonder 'oh, he's meeting with somebody that has a different view than him,'" Cook concluded. "I think that's good. I think it's good. I think a problem in the world right now is that it's so polarized and different views aren't shared or discussed. They just become hardened. And I don't think that's good."

In an interview last month, Cook said he is "not a political person."

"I interact on policy, not politics," he said.Tags: Donald Trump, Tim Cook
This article, "Apple CEO Tim Cook Explains His Relationship With Trump" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
The Computer Emergency Response Team of Ukraine (CERT-UA) has disclosed details of a new phishing campaign in which the cybersecurity agency itself was impersonated to distribute a remote administration tool known as AGEWHEEZE. As part of the attacks, the threat actors, tracked as UAC-0255, sent emails on March 26 and 27, 2026, posing as CERT-UA to distribute a password-protected ZIP archiveView the full article
TechRadar's Jacob Krol recently sat down with Apple's VP of Platform Architecture Tim Millet and Director of Audio Product Marketing Eric Treski to discuss the AirPods Max 2, including the H2 chip and increased active noise cancellation.


AirPods Max 2 have the same overall design as the previous generation, with most of the improvements coming from the upgrade to the H2 chip, including up to 1.5× more active noise cancellation, enhanced sound quality, and features such as Adaptive Audio, Conversation Awareness, Voice Isolation, and Live Translation.

Even still, Apple suggested that the H2 chip has more to offer, with future AirPods Max 2 firmware updates likely to unlock additional features.

"H2 is this platform that continues to demonstrate that it has continued headroom," said Millet.

Regarding the up to 1.5× more active noise cancellation, Apple said it is not a cherry-picked stat.

"We take that average at 1.5 times across an average of all frequencies," said Treski. "We're not cherry-picking individual frequencies or a certain range."

TechRadar's interview contains more comments from Millet and Treski, so be sure to check it out if you are interested in learning more.

AirPods Max 2 are available at Apple Stores and began arriving to customers starting today.Related Roundup: AirPods Max 2Tag: H2 ChipBuyer's Guide: AirPods Max (Buy Now)Related Forum: AirPods
This article, "Apple Discusses AirPods Max 2, Says H2 Chip Has More to Offer in Future" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Starting today, the AirPods Max 2 are available for purchase at many Apple Store locations around the world, and deliveries to customers have also begun.


Apple's website shows same-day pickup availability at many Apple Stores in the U.S. and abroad.

AirPods Max 2 are equipped with the H2 chip that debuted in the AirPods Pro 2. Compared to the previous generation, the new AirPods Max feature up to 1.5× more active noise cancellation, enhanced sound quality, and features such as Adaptive Audio, Conversation Awareness, Voice Isolation, and Live Translation.

AirPods Max 2 feature a new high dynamic range amplifier for "even cleaner audio," and Apple says Spatial Audio content "sounds better than ever." The headphones also have reduced wireless audio latency compared to the previous generation.

A new Camera Remote feature allows users to press the Digital Crown on the AirPods Max 2 to take a photo and start or stop video recording while using Apple's Camera app or compatible third-party camera apps on an iPhone or iPad.

The headphones still have a USB-C port and up to 20 hours of battery life on a single charge with active noise cancellation enabled.

Color options remain Midnight, Starlight, Orange, Purple, and Blue, and pricing remains set at $549 in the U.S., although there is already an Amazon sale.Related Roundup: AirPods Max 2Tag: Apple StoreBuyer's Guide: AirPods Max (Buy Now)Related Forum: AirPods
This article, "AirPods Max 2 Now Available at Apple Stores" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
The iPhone 17e and iPhone 17 are among the most affordable iPhones in Apple's current lineup, separated by just $200, but the gap between them is more significant than the price difference alone suggests.


The $599 ‌iPhone 17e‌ is Apple's budget-first option, built around the efficient C1X modem and a single-camera system. The $799 ‌iPhone 17‌, meanwhile, represents a substantial update over the iPhone 16, featuring a larger display with ProMotion, a much-improved Ultra Wide camera, a brighter panel, and significantly longer battery life. Understanding where the 17e makes compromises is key to making the right choice. Our guide helps to answer the question of how to decide which of these two iPhones is best for you.

The two devices share the same A19 chip and main rear camera system. Both support Face ID, MagSafe charging, USB-C, and Apple Intelligence. Here is everything that differs between them:



‌iPhone 17e‌ (2026)
‌iPhone 17‌ (2025)


6.1-inch display
6.3-inch display


"Notch"
Dynamic Island


60Hz display
ProMotion for refresh rates up to 120Hz



Always-On display


800 nits max brightness (typical)
1,000 nits max brightness (typical)


1,200 nits peak brightness (HDR)
1,600 nits peak brightness (HDR)



3,000 nits peak brightness (outdoor)


Available in White, Black, and Soft Pink
Available in Lavender, Sage, Mist Blue, White, and Black


12-megapixel front-facing camera
18-megapixel front-facing camera



Tap to zoom and rotate on front-facing camera



Center Stage front-facing camera



Ultra-stabilized video on front-facing camera



48-megapixel Ultra Wide camera


1x or 2x optical zoom options
0.5x, 1x, or 2x optical zoom options


Optical image stabilization
Sensor-shift optical image stabilization


Photographic Styles
Latest-generation Photographic Styles



Macro photography



Spatial photos and videos



Cinematic mode (up to 4K Dolby Vision at 30 fps)



Action mode



Dual Capture (up to 4K Dolby Vision at 30 fps)



Camera Control


4-core GPU with Neural Accelerators
5-core GPU with Neural Accelerators


Apple C1X modem
Qualcomm Snapdragon X80 modem



mmWave 5G connectivity


Wi-Fi 6 connectivity
Wi-Fi 7 connectivity


Bluetooth 5.3 connectivity
Bluetooth 6 connectivity



Apple N1 chip for Bluetooth and Wi-Fi



Thread connectivity



Ultra Wideband chip for Precision Finding


GPS
Precision dual-frequency GPS


26-hour battery life
30-hour battery life


Up to 50% charge in 30 minutes with 20W adapter or higher
Up to 50% charge in 20 minutes with 40W adapter or higher


256GB or 512GB storage
256GB or 512GB storage


Starts at $599
Starts at $799


Released March 2026
Released September 2025




For most buyers choosing between these two devices, the ‌iPhone 17e‌ is the default choice. At $200 less, it delivers the same A19 chip and main rear camera as the ‌iPhone 17‌, with an excellent 26-hour battery life and ‌Apple Intelligence‌ support. The ‌iPhone 17e‌ is an outstanding device for price-conscious customers.

That said, the ‌iPhone 17‌ is a substantially more capable device across several areas that will matter to many buyers. The jump to a 6.3-inch ProMotion display with Always-On is one of the most significant display upgrades ever to come to a non-Pro iPhone. The ‌iPhone 17‌ also brings a peak outdoor brightness of 3,000 nits versus the 17e's 800 nits, which makes a dramatic difference in direct sunlight.

The camera gap is also wide. The ‌iPhone 17‌'s 48-megapixel Ultra Wide represents a major increase in utility over the 17e, which has no Ultra Wide camera at all. The 17 also gains Camera Control, macro photography, Spatial photo and video capture, Cinematic mode, Action mode, and a significantly upgraded 18-megapixel front-facing camera with Center Stage and Dual Capture. If you shoot video regularly, take a lot of selfies, or use your camera as a creative tool, the ‌iPhone 17‌ is the meaningfully better device.

The two devices also differ significantly in design. The ‌iPhone 17e‌ carries forward a form factor based on the iPhone 13, with flatter edges and a traditional notch, while the ‌iPhone 17‌ features a more modern design with softer, more rounded edges and the ‌Dynamic Island‌ in place of a notch. The ‌iPhone 17‌ also offers a wider selection of colors, with five options compared to the 17e's three.

For buyers upgrading from an iPhone 13 or older, either model will feel like a dramatic improvement, but the ‌iPhone 17‌ is the better long-term investment given the display and camera advantages. The ‌iPhone 17e‌ is an excellent value at $599 and it makes very few compromises on the fundamentals, but the ‌iPhone 17‌ offers so much more for $200 extra that it is hard to argue against if your budget allows. A larger display with ProMotion and the ‌Dynamic Island‌, a vastly more capable camera system, and four additional hours of battery life represent a meaningful quality-of-life upgrade. New buyers who want the most complete iPhone experience at the lower end of the lineup should strongly consider spending the extra $200 for the ‌iPhone 17‌.Related Roundups: iPhone 17, iPhone 17eBuyer's Guide: iPhone 17 (Neutral), iPhone 17e (Buy Now)Related Forum: iPhone
This article, "iPhone 17e vs. iPhone 17 Buyer's Guide: 35+ Differences Compared" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
In iOS, Apple's Audio Zoom feature automatically focuses your iPhone's microphones on whatever you've zoomed in on while recording video. It's great for isolating a subject in a noisy environment, but it can also strip away the ambient sound that can give your footage a broader context. Fortunately, iOS 26.4 adds a dedicated toggle for Audio Zoom so you can decide for yourself when it's truly required.


What Is Audio Zoom?

Audio Zoom is likely to be most useful if you're recording at a concert, sporting event, or any scenario where you want to isolate a specific sound source from a noisy environment. But what if you want to capture the full acoustic experience rather than just the subject you've zoomed in on? In those situations, the audio narrowing effect could risk making your video sound flat and unnatural.

In iOS 26.4, Audio Zoom is on by default, but now you can also turn it off. If you haven't updated yet, head to Settings ➝ General ➝ Software Update on your iPhone to download the latest version. Once you're up and running, here's how to find the setting:

Open Settings on your iPhone.
Scroll down and tap Camera.
Tap Record Sound.
Toggle Audio Zoom on or off.


Note that Audio Zoom only works when Spatial Audio or Stereo is selected as your recording format. If you've switched to Mono, the option will be grayed out.

If you shoot a lot of zoomed-in video and want the clearest possible audio of your subject, it's best to leave Audio Zoom enabled. But if you prefer capturing the full ambient soundscape of a scene regardless of zoom level, be sure to switch it off.
This article, "Stop Your iPhone Suppressing Background Audio in Videos" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Accessory company Alogic has been releasing an increasing number of displays, and the latest model arrives as a 40-inch 5K2K ultrawide model that joins existing 34-inch and 40-inch 4K models in the Edge family. I've been testing out the new 40-inch 5K2K model for the past few months, and I've found it to be a solid display offering major screen real estate for productivity users.


As a 40-inch ultrawide display, the Edge 5K is big, and it arrives in a fairly large box, although it is packaged efficiently with styrofoam padding, stand parts, and other accessories nestled around the massive display. The Edge 5K is available in either silver or space gray, and setup is simple, with a large metal foot that's attractively thin paired with a solid arm that features a cable passthrough for organization. The two stand pieces attach easily to each other with a single screw that can be tightened by hand or with a screwdriver, and the whole stand snaps easily into the back of the display.

Alternatively, you can use any sturdy 100×100mm VESA mount if you prefer a different method of supporting the display. A separate 180-watt power brick powers the display and attached accessories, and it can push up to 90 watts upstream to a connected computer.

I will say that there is a bit of wobble in the display, due partly to the sheer size of the display panel and also the range of adjustments supported by the stand, which includes height, tilt, swivel, and rotation. It remains stable enough on my desk amid vibrations from typing and other movement, but it can definitely wobble if you bump it or have it on surface that is anything less than rock solid. Alogic tells me the bit of wobble is a tradeoff it elected to make in order to maximize adjustability. It's certainly not a deal-breaker for me, but something to be aware of.


This display looks sleek, with thin black bezels around the top and sides and then a thicker silver aluminum chin with some subtle Alogic branding and a power status light (that does unfortunately pulse rather brightly while the display is sleeping, so be aware if you're using it in a bedroom). The panel housing itself has a very thin profile on the upper two-thirds, and then a thicker portion bulging out of the back on the lower third where the stand attachment, ports, and electronics are housed.

The upper two thirds is actually glass on the rear, which brings a bit of class if you position your display such that the rear of it is visible. The design also takes advantage of the display backlight to provide a lighted Alogic logo on the rear of the display, which could be a positive or a negative depending on your preference. Alogic tells me it put extra focus on the design of the display's backside, based on feedback from users who like to use these monitors in offices where the rear is frequently visible to others sitting across a desk, for example.


I was impressed with the display quality out of the box. I really didn't need to make any adjustments in either macOS or the through on-screen menus of the display, though I did ultimately play around with them to understand the range of adjustments that are available. As a 40-inch 5K2K display, it measures in at 5,120 by 2,160 pixels at 138 pixels per inch. That doesn't match true Retina pixel density of an iMac or a smaller 4K or 5K display, but I was pleasantly surprised at how sharp everything looked, even coming from my usual setup of as pair of high-density LG UltraFine 5K displays.

The Edge 5K offers 100% coverage of the sRGB spectrum, 99% of DCI-P3, and 94% of Adobe RGB. It also supports refresh rates up to 100Hz, and while that's not as high as some gaming-specific displays on the market, the bandwidth demands of the display's high resolution limits the ability to push a super-high refresh rate. Still, 100Hz is great for a productivity-focused setup and will even work fine for many games.

This is a matte display, so definitely be aware of that if it's a concern for you. I'm doing productivity work near a window and can get a bit of glare at certain times of day, so I prefer matte displays and this one looks great to my eye. It's an IPS panel with up to 400 nits of typical brightness, which is fine for my workspace although there are brighter displays on the market.

While you can certainly run the display at full 5,120 × 2,160 resolution, I found that it made on-screen content too small given the viewing distance I am typically at. On the other end, running at 2,560 × 1,080 as a true Retina display made content too large, so I found the 3,840 × 1,620 scaled option to be the perfect resolution for this display in my setup. It provides a large canvas for putting multiple apps and windows side-by-side, with everything appearing at a legible size, and macOS handles scaled resolutions quite well so I had no issues with display quality.

Coming from a pair of 27-inch 5K displays, I did have to figure out a new layout for my desktop with the slightly smaller amount of screen real estate, but having it all on one display made it easier to adjust my window sizes and tile them on my desktop.


The Edge 5K features a number of handy connectivity options on the rear, with display connectivity options of USB-C (supports both data and power delivery), DisplayPort 1.4, and HDMI 2.0 (refresh rate limited to 30Hz at 5K resolution). When connected over USB-C, the display also acts as a hub with two additional downstream USB-C ports running at USB 2.0 speeds, a Gigabit Ethernet port, and a 3.5mm audio jack for connecting headphones or externally-powered speakers (does not support microphone input).

Two 3-watt speakers are built into the display, but as is typical in most displays, they don't sound great. The speakers also don't integrate with Mac keyboard shortcut keys for volume (the same is true for display brightness), but Alogic tells me it's planning a firmware update for around the middle of the year to add this functionality.


The rear of the Edge 5K features a joystick button to access and navigate through the on-screen menus. It provides quick access to volume, brightness, display presets, and cycling through connected video sources, and then you can dive deeper into an array of adjustments for the backlight, contrast, blue light shift, Adaptive Sync, sharpness, Picture by Picture and Picture in Picture mode settings, color temperature, HDR, and more.

The Alogic Edge 5K is normally priced at $1,699.99, but Alogic is currently offering a 10% discount that brings it down to $1,529.99. Silver and Space Gray color options are available, and it comes with a solid two-year warranty.

Comparison to Apple's Studio Display

At this price point, it is natural to compare the Edge 5K to Apple's just-upgraded Studio Display, but these displays serve very different purposes. The ‌Studio Display‌ measures just 27 inches with a 16:9 aspect ratio, and for most users it will run best in true Retina mode, yielding a desktop size of 2,560 × 1,440 from the display's 5,120 × 2,880 pixels.

While the Edge 5K also offers 5,120 pixels in the horizontal dimension, the 21:9 ultrawide aspect ratio means it offers fewer pixels in the vertical dimension than the ‌Studio Display‌. But the much larger 40-inch size means you can effectively have more screen real estate than on the ‌Studio Display‌ if you run it a scaled resolution in between full and Retina sizes.

The ‌Studio Display‌ does of course also offer a true Apple design aesthetic and build quality, and offers tight integration with macOS that the Edge 5K can't currently match. The Edge 5K also lacks a built-in webcam and microphone, and downstream USB-C connectivity options are more limited at just USB 2.0 speeds.

On the positive side, the Edge 5K offers more connectivity options, so if you have a PC or other video source, you can use HDMI or DisplayPort to connect it directly to the Edge 5K without the need for adapters, and you can easily switch between inputs or even take advantage of dual sources simultaneously with Picture in Picture or Picture by Picture.

Both of these displays are toward the pricier end of things among more mainstream displays, but they're different enough that you should be able weigh your needs (physical display size, connectivity, etc.) to figure out what's most important to you and which display will meet those needs the best.

Note: Alogic provided MacRumors with the Edge 5K display for the purposes of this review. No other compensation was received. MacRumors is an affiliate partner with Alogic. When you click a link and make a purchase, we may receive a small payment, which helps us keep the site running.Tag: Alogic
This article, "Review: Alogic's Edge 5K Display Offers an Ultrawide Big-Screen Experience" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Apple was founded 50 years ago today, and the company has celebrated the milestone in a variety of ways over the past few weeks, as outlined below.


Apple's CEO Tim Cook kicked things off by sharing a letter titled "50 Years of Thinking Different" on Apple's website. The letter touches on the 50th anniversary and says that "the world is moved forward by people who think different."

"Think Different" was a famous slogan used by Apple in the late 1990s to early 2000s.

"At Apple, we're more focused on building tomorrow than remembering yesterday," a part of Cook's letter reads. "But we couldn't let this milestone pass without thanking the millions of people who make Apple what it is today."


Second, Apple celebrated the anniversary by hosting surprise concerts and events around the world in the second half of March. Alicia Keys performed at Apple's store inside New York's Grand Central Terminal, Mumford & Sons took the stage outside of Apple's UK headquarters at the former Battersea Power Station in London, models walked around a catwalk set up in front of Apple's Jing'an store as part of Shanghai Fashion Week, Apple illuminated iPad artwork on the Sydney Opera House's sails, and much more.

Third, much of Apple's senior leadership gathered at Apple Park to ring the Nasdaq stock market index's opening bell on Tuesday morning. Apple executives in attendance included Cook, operations chief Sabih Khan, services chief Eddy Cue, retail chief Deirdre O'Brien, marketing chief Greg Joswiak, financial chief Kevan Parekh, hardware engineering chief John Ternus, hardware design chief Molly Anderson, and others.


Fourth, Apple set up various installations inside Apple Park, including a showcase of various iMac designs released between 1998 and 2021.


Fifth, Apple's employees received 50th-anniversary merchandise, including a commemorative t-shirt, a limited-edition poster, and a "50" pin.

Sixth, Apple's employees were invited to watch legendary musician Paul McCartney perform under the rainbow arches at Apple Park on Tuesday evening.

And finally, Apple marked its 50th anniversary today by updating the homepage of its website with an animation and sharing a rewind video.


Apple may have a few other things in store for us, but with it now being April 1, the anniversary celebrations are likely wrapping up. So far, the company has not publicly released any special products or merchandise to mark the occasion.

Related Reading: Apple Turns 50 Today: Reflecting on Each Decade's Biggest MomentsTag: Apple 50th Anniversary
This article, "Apple Celebrates 50th Anniversary in Seven Ways" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Apple's new AirPods Max 2 launch today, and Amazon is one of the only retailers offering any sort of discount on the headphones. You can get the Midnight color option for $529.00 on Amazon, down from $549.00.

Note: MacRumors is an affiliate partner with some of these vendors. When you click a link and make a purchase, we may receive a small payment, which helps us keep the site running.

Although this is only a $20 discount on the AirPods Max 2, it's the best markdown you'll find online if you're looking to order the new headphones. Free delivery has the AirPods Max 2 arriving around April 6, but they can be delivered as soon as tomorrow with Prime shipping.

$20 OFFAirPods Max 2 for $529.00

In other AirPods discounts on Amazon, you can get the AirPods Pro 3 for the all-time low price of $199.00 right now, down from $249.00. If you're on the hunt for more discounts, be sure to visit our Apple Deals roundup where we recap the best Apple-related bargains of the past week.



Deals Newsletter

Interested in hearing more about the best deals you can find in 2026? Sign up for our Deals Newsletter and we'll keep you updated so you don't miss the biggest deals of the season!




Related Roundup: Apple Deals
This article, "Get AirPods Max 2 on Sale for Launch Day" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
There is a character that keeps appearing in enterprise security departments, and most CISOs know exactly who that is. It doesn’t build. It doesn’t enable. Its entire function is to say "No." No to ChatGPT. No to DeepSeek. No to the file-sharing tool the product team swears by. For years, this looked like security. But in 2026, "Doctor No" is no longer just a management headache &View the full article
A multi-pronged phishing campaign is targeting Spanish-speaking users in organizations across Latin America and Europe to deliver Windows banking trojans like Casbaneiro (aka Metamorfo) via another malware called Horabot. The activity has been attributed to a Brazilian cybercrime threat actor tracked as Augmented Marauder and Water Saci. The e-crime group was first documented by Trend Micro inView the full article
Apple's website homepage is doing its part for the company's 50th anniversary celebrations today, showcasing a special animated video that references some of Apple's most memorable products.


The sketch-style animation outlines the original Mac, iMac, iPod, MacBook, AirPods, iPhone 17 Pro, and Vision Pro, as well as the Finder icon, App Store, Apple Music, and more. Beneath the video, the webpage reads:
Separately, Apple CEO Tim Cook has shared on X (Twitter) a video celebrating 50 years of innovation at Apple, featuring many of the same products alluded to in the homepage animation.


Apple was founded on April 1, 1976, by Steve Jobs and Steve Wozniak, making the company officially 50 years old today. An Apple Park show headlined by Paul McCartney last night capped weeks of anniversary events that also included performances by Alicia Keys at Apple Grand Central in New York City and Mumford & Sons at Apple Battersea in London.Tag: Apple 50th Anniversary
This article, "Apple Marks 50th Anniversary With Animated Homepage Tribute" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Microsoft is calling attention to a new campaign that has leveraged WhatsApp messages to distribute malicious Visual Basic Script (VBS) files. The activity, beginning in late February 2026, leverages these scripts to initiate a multi-stage infection chain for establishing persistence and enabling remote access. It's currently not known what lures the threat actors use to trick users intoView the full article
Google on Thursday released security updates for its Chrome web browser to address 21 vulnerabilities, including a zero-day flaw that it said has been exploited in the wild. The high-severity vulnerability, CVE-2026-5281 (CVSS score: N/A), concerns a use-after-free bug in Dawn, an open-source and cross-platform implementation of the WebGPU standard. "Use-after-free in Dawn in Google Chrome priorView the full article
Paul McCartney performed a concert for Apple employees at Apple Park in Cupertino last night, capping the company's 50th anniversary celebrations with a career-spanning set that included songs from The Beatles, Wings, and his solo career.


Apple CEO Tim Cook introduced McCartney to the crowd, calling him "a songwriter, a pioneer and one of the most influential artists of all time" and adding that he has "been a lifelong fan of his music and so have billions of people all over the planet." The show took place under ‌Apple Park‌'s rainbow arches, which had been transformed into a full concert stage with lighting rigs and large screens on either side.

McCartney's setlist spanned his entire career. Beatles classics including "Help," "Got To Get You Into My Life," "Blackbird," "Lady Madonna," "Something," "Ob-La-Di, Ob-La-Da," "From Me To You," "Let It Be," and "Hey Jude" featured alongside Wings cuts "Coming Up," "Let Me Roll It," "Getting Better," "Let 'Em In," "Band On The Run," and solo favorites "Maybe I'm Amazed" and "Every Night." The show closed with "Golden Slumbers." McCartney also staged his famous "Live and Let Die" pyrotechnics segment.



Bloomberg's Mark Gurman had hinted at McCartney as the headliner days before the show, saying "he's still going strong, was part of the British Invasion and Jobs would've been ecstatic." McCartney's ‌Apple Park‌ appearance was confirmed when images of his soundcheck circulated on social media, showing the 83-year-old artist and his band on the illuminated rainbow stage inside the ring.

The concert came just days after McCartney played two intimate, phone-free shows at the Fonda Theatre in Los Angeles, where the 1,200-seat venue attracted a remarkable cross-section of Hollywood: Attendees included Ringo Starr, Stevie Nicks, Margot Robbie, Billie Eilish, Taylor Swift, Elton John, Jon Hamm, Harrison Ford, Reese Witherspoon, Anthony Kiedis, Olivia Rodrigo, Sabrina Carpenter, Tate McCrae, Laura Dern, Emma Watson, Steve Carell, Dakota Johnson, and more. McCartney's 19th studio album, "The Boys of Dungeon Lane," is set to be released next month.



The choice of McCartney carries particular historical resonance. The Beatles founded Apple Corps, their own record label and holding company, in 1968, eight years before Steve Jobs started Apple Computer. Jobs was a lifelong Beatles fan who once said "my model for business is The Beatles," describing them as four people who balanced each other and produced something greater than the sum of their parts.

The shared name was a source of costly legal friction between the two companies for nearly three decades, resolved only in 2007 when Apple Inc. purchased all trademarks related to "Apple" and licensed some of them back to Apple Corps. The Beatles' catalogue didn't arrive on iTunes until 2010, and has been on Apple Music ever since, making McCartney's appearance at ‌Apple Park‌ something of a full-circle moment.

The ‌Apple Park‌ show brings to a close weeks of anniversary events that also included performances by Alicia Keys at Apple Grand Central in New York City and Mumford & Sons at Apple Battersea in London, along with special anniversary gift bags for employees including a commemorative t-shirt, enamel pin, and limited-edition poster.Tags: Apple 50th Anniversary, The Beatles
This article, "Paul McCartney Blazes Through Career-Spanning Set at Apple Park for 50th Anniversary Celebrations" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Microsoft is warning WhatsApp users of a new malware campaign that tricks them into executing malicious Visual Basic Script (VBS) files, ultimately enabling persistence and remote access.
In a March 31 report, Microsoft Defender Experts said attackers have been distributing malicious Visual Basic Script (VBS) files through WhatsApp since at least late February, relying on social engineering to get them executed.
Once launched, the scripts run a delayed malware execution, first initiating a multi-stage infection flow designed to blend into normal system activity while working in the background to pull additional payloads for remote control. “The campaign relies on a combination of social engineering and living-off-the-land (LOTL) techniques,” Microsoft researchers wrote in the report. “By combining trusted platforms with legitimate tools, the threat actor reduces visibility and increases the likelihood of successful execution.”
The campaign ultimately installs malicious Microsoft Installer (MSI) packages to maintain control of the infected devices.
Campaign deploys a LOTL infection chain
The attack begins with a WhatsApp message carrying a VBS file. Once executed, the script creates hidden directories on the system and begins staging the next steps of the compromise.
However, rather than dropping the custom malware immediately, the campaign moves to living-off-the-land techniques. The VBS payload deploys renamed versions of legitimate Windows utilities, such as curl.exe and bitsadmin.exe, disguised under misleading filenames to evade casual inspection.
These binaries retain their original metadata, but their altered names allow them to blend into the environment while performing malicious tasks like downloading additional payloads. “Microsoft Defender and other security solutions can leverage this metadata discrepancy as a detection signal, flagging instances where a file’s name does not match its embedded OriginalFileName,” the report added.
The researchers noted that even payload retrieval happens from legitimate hosting sources. Attackers host components on well-known cloud platforms, including AWS, Tencent Cloud, and Blackblaze B2. Use of these trusted tools, trusted infrastructure, and staged execution was flagged as a reason for this being a low-noise, reliable attack path.
MSI as the backdoor vehicle for persistence
The final stages of the campaign lead to persistence, using Microsoft Installer (MSI) packages as the delivery mechanism for backdoors.
MSI files are an effective choice as they are not usually treated as inherently suspicious and can execute custom actions during installation. In this campaign, they are used to deploy malware that maintains access, escalates privileges, and enables remote control of infected systems.
By the time the MSI component is installed, the attackers have already established a foothold using scripts and system tools, making the backdoor just one layer in a broader persistence strategy found by Microsoft. The earlier stages ensure the environment is prepared, while the installer formalizes long-term access.
Microsoft also noted that the campaign incorporates privilege escalation to strengthen persistence, enabling malware to run with elevated privileges and maintain access beyond the initial user-level compromise. Recommendations included monitoring scripts and installer execution, watching for misuse of legitimate tools, and tracking suspicious activity tied to files delivered through platforms like WhatsApp.
View the full article
For years, cybersecurity has followed a familiar model: block malware, stop the attack. Now, attackers are moving on to what’s next. Threat actors now use malware less frequently in favor of what’s already inside your environment, including abusing trusted tools, native binaries, and legitimate admin utilities to move laterally, escalate privileges, and persist without raising alarms. MostView the full article
PX Media – shutterstock.com
Hacker haben nach Angaben der iranischen Justiz mutmaßlich Zugriff auf Daten eines bekannten Exilportals erlangt. Dabei seien große Menge an Daten erbeutet worden, darunter Schriftwechsel, Listen von Angestellten, Informanten sowie streng vertrauliche Daten, berichtete das Sprachrohr der iranischen Justiz, die Nachrichtenagentur Misan. 
Bei dem Portal handelte es sich um die gut informierte Website Iranwire. Sie war am Dienstag zunächst nicht wie gewöhnlich erreichbar. “Derzeit führen wir planmäßige Wartungsarbeiten durch. Wir sind so bald wie möglich wieder online”, hieß es dort. In den sozialen Medien war das Medium jedoch weiter aktiv. Auf der Plattform X berichtete Iranwire am Dienstag weiter, ohne einen Hacker-Angriff zu melden.
In ihrem Bericht schrieb Misan, die Hackergruppe “Handala” sei für den mutmaßlichen Angriff verantwortlich. Dieselbe Gruppe soll hinter einem Cyberangriff auf den Direktor der US-Bundespolizeibehörde FBI, Kash Patel, vor wenigen Tagen stecken. (dpa)
View the full article
Apple has quietly reduced the price of the Studio Display XDR when configured with the VESA mount adapter, dropping it from $3,299 to $2,899 – a $400 cut. The nano-texture VESA version has also dropped from $3,599 to $3,199.


Apple has also reworked the purchasing pattern on its website, making the stand choice the first step in the configuration process instead of the glass selection.

When the Studio Display XDR launched last month, both stand options cost the same $3,299. That felt unfair to a lot of people, since the VESA mount adapter is just a flat metal plate that lets you attach the display to a monitor arm or wall mount, whereas the alternative stand is both height- and tilt-adjustable.

VESA mount options are normally priced lower than the fancier stand versions on most displays (including Apple's own Pro Display XDR, for which the VESA option was always cheaper). The price change for the Studio Display XDR is therefore more in line with how these things are typically priced.


The standard Studio Display has not received a similar adjustment – both the stand and VESA mount configurations of the non-XDR model remain priced at $1,499 – but the cheaper tilt-adjustable stand is usually considered price-equivalent to the VESA mount.
This article, "Apple Adjusts Studio Display XDR Pricing Weeks After Launch" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Apple on Wednesday will issue software updates to devices still running iOS 18 to protect them from an exploit called DarkSword, which can silently take over an iPhone if it visits a website infected with the malicious code.


Devices on iOS 26 are already protected against DarkSword, but in a surprising move for Apple, its latest critical update is designed to specifically protect vulnerable iOS 18 users who have consciously decided not to update to iOS 26, even though their iPhone model supports it. Some users may be hesitant to upgrade to ‌iOS 26‌ because of the Liquid Glass design overhaul that makes major changes to the iPhone interface.
iPhone users can install the updates by opening up the Settings app, going to General, and selecting the Software Update option. Those with automatic updates turned on will see the new software installed automatically.

It's the second time in the last few weeks that Apple has pushed a critical update to iPhones running out-of-date software. On March 11, Apple issued a patch to protect users from a different iOS hacking toolkit known as Coruna. The patch was for older devices that can't run iOS 26. Apple recommended that everyone else update to the latest OS version that their device supports.

The practice of protecting an older operating system version is known in the cybersecurity industry as "backporting," but it's not something that Apple typically does if a newer, compatible version of iOS has the same protections already baked in.

According to Google, DarkSword has been used by various hacker groups to break into the iPhones of users in Malaysia, Saudi Arabia, Turkey, and Ukraine. Last week, the exploit kit was posted to open source code repository GitHub, making it even more likely to be used by bad actors.
This article, "Apple to Issue Rare iOS 18 Software Update for DarkSword Exploit" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
AI hallucinations are a well-known problem and, when it comes to compliance assessments, these convincing but inaccurate assessments can cause real damage with poor risk assessments, incorrect policy guidance, or even inaccurate incident reports.
Cybersecurity leaders say the real trouble starts when AI moves past writing summaries and begins making judgment calls. That’s when it’s asked to decide things such as whether security controls are doing their job, if a company is meeting compliance standards, or if an incident was handled the right way.
Here are nine ways CISOs can tackle the problem of AI hallucinations.
Keep humans in the loop for high-stakes decisions
Fred Kwong, vice president and CISO at DeVry University, says his team is carefully testing AI in governance, risk, and compliance work, especially in third-party risk assessments. He notes that while AI helps review vendor questionnaires and supporting evidence that assess the security posture of those vendors, it doesn’t replace people.
“What we’re seeing is the interpretation is not as good as I would want it to be, or it’s different than how we’re interpreting it as humans,” Kwong says.
He explains that AI often reads control requirements differently than experienced security professionals do. Because of that, his team still reviews the results manually. For now, AI is not saving much time because the trust in the technology just is not there yet, he says.
Mignona Coté, senior vice president and CISO at Infor, agrees that human oversight is critical, especially in risk scoring, control assessments, and incident triage. “Keep the human in the loop, full stop,” says Coté, who sees AI as a productivity tool, not something that should make final decisions on its own.
Treat AI outputs as drafts, not finished products
One of the biggest risks is over-trusting AI, according to security experts. Coté says her organization changed its policy so AI-generated content cannot go straight into compliance documentation without a human review.
“The moment your team starts treating an AI-generated answer as a finished work product, you have a problem,” she says. “Treat every output as a first draft as opposed to a final one. There will come a point where repetitive questions will have repetitive answers. By labeling those answers and time stamping them at origination time, they can be addressed at scale.”
Srikumar Ramanathan, chief solutions officer at Mphasis, says this over-trust often comes from what he calls “automation bias.” People naturally assume that something written clearly and confidently must be correct.
To counter that, he says companies need to build an “active skepticism” culture. “[That means] looking upon AI outputs as unverified drafts that require a signature of human accountability before they are actionable,” he explains.
Demand proof, not polished prose, from vendors
When vendors say their AI can “assess compliance” or “validate controls,” security leaders say buyers need to ask the tough questions.
Kwong says he pushes vendors to provide traceability of the answers that the AI gives so his team can see how the AI reached its conclusions. “Without that traceability, it makes it even that much harder for us to identify,” he says.
Ramanathan says buyers should ask whether the system can point to the exact evidence behind its answer, such as a time-stamped log entry or a specific configuration file. If it can’t, the tool may just be generating text that sounds right.
Puneet Bhatnagar, a cybersecurity and identity leader, says the key question is whether the AI is actually analyzing live operational data or just summarizing documents. “If a vendor cannot show a deterministic evidence path behind its conclusion, it’s likely generating narrative – not performing an assessment,” says Bhatnagar who most recently served as SVP and head of identity management at Blackstone. “Compliance isn’t about language. It’s about proof.”
Stress-test models before extending trust
Kwong recommends testing AI tools to see how consistent they are. For example, send the same data through twice and compare the results.
“If you send the same data again, is it spitting back the same result?” he asks.
If answers change significantly, that’s a red flag. He also suggests removing important evidence to see how the model reacts. If it confidently gives an answer anyway, that could signal a hallucination.
Coté says her team checks AI outputs against other tools, including scanning systems and external penetration testing results. “And we don’t extend trust to any AI tool until it has proven itself against known outcomes repeatedly,” she says.
Measure hallucination rates and monitor drift
Security leaders say organizations need to track how accurate AI is over time. Kwong says teams should regularly compare AI-generated assessments with human reviews and study the differences. That process should happen at least quarterly.
Ramanathan suggests tracking metrics such as “drift rate,” which measures how often AI conclusions differ from human reviews. “A model that was 92% accurate six months ago and is 85% accurate today is more dangerous than one that’s been consistently at 80% because your team’s trust was calibrated to the higher number,” he notes.
He also recommends measuring how often cited evidence truly supports the AI’s claims. If hallucination rates climb too high, organizations should reduce how much authority the AI has, for example, downgrading it to a less autonomous role in their governance models.
Watch for contextual blind spots in compliance mapping
Bhatnagar says the most dangerous hallucinations happen when AI is asked to make judgment calls about control effectiveness, regulatory gaps, or incident impact.
AI can produce what he calls “plausible compliance”, or answers that sound convincing but are wrong because they lack real-world context. Compliance often depends on technical details, compensating controls, and operational realities that documentation alone doesn’t show.
Ramanathan adds that AI often struggles with the nuance of permissive language, (“may,” “can”) versus restrictive language (“must,” “is required to”).
“For example, AI often misinterprets permissive language like ’employees may access the system after completing training’ as a strict, enforceable rule, treating optional permissions as mandatory controls,” Ramanathan explains. “This causes AI to overestimate the authority of permissive or vague language, resulting in incorrect assumptions about whether policies are properly enforced or security measures are effective.”
Push back on generic or identical assessments
Some vendors overstate what their AI tools actually do. Bhatnagar says many tools summarize documents or generate gap reports but vendors market those features as if they’re doing full, automated compliance checks.
The risk increases when multiple customers receive nearly identical assessments. Organizations may believe their controls were thoroughly evaluated when the AI only performed a surface-level document review.
Ramanathan says this creates false confidence and broader industry risk. If one popular model has a flaw, that blind spot can spread widely.
Bhatnagar adds that he has seen vendors market AI tools as assessing whether organizations are compliant, even when multiple customers receive structurally similar or nearly identical assessments.
In those situations, the tool may not actually be analyzing company-specific policies or evidence but instead generating text that appears customized without being grounded in reality, he says. “We are still in the early stages of separating AI narrative generation from AI-based verification,” he says. “That distinction will define the next phase of governance tooling.”
Reinforce accountability in audits and legal reviews
From a regulatory standpoint, AI does not remove responsibility, according to experts. Ramanathan says regulators are clear that duty of care stays with corporate officers.
“If an AI-generated assessment misses a material weakness, the organization is liable for ‘failure to supervise,'” he says. “We are already in an era wherein relying on unverified AI outputs could be seen as gross negligence. If your audit findings are wrong because of an AI error, you haven’t just failed an audit, you are held responsible for filing a misleading regulatory statement. ‘AI told me so’ is not a defense.”
Coté says being able to show that a human reviewed and approved each consequential decision is critical during audits. “The key is proving a human was at every consequential decision point, with a timestamp and an audit trail to back it up,” she notes.
Be cautious with automated regulatory mapping
Ramanathan says that one of the biggest compliance risks appears when companies rely on AI to automatically map internal controls to regulatory frameworks, such as GDPR or SOC 2.
“The greatest compliance risk by far is in automated regulatory mapping,” he notes. “The AI might confidently claim a control exists or satisfies a requirement based on a linguistic pattern rather than a functional or operational reality.”
For example, an AI tool might see an encryption setting listed in a database configuration and assume encryption is active, even if that feature is turned off in the system.
Ramanathan says this can create “a massive security gap where a company believes they are audit-ready, only to discover during a breach that their AI-verified defenses were nonexistent or misconfigured.”
To reduce that risk, he says organizations need to structure their policies and regulations more clearly and connect them to enforceable technical rules rather than relying only on AI to interpret documents.
View the full article
Organizations have been responding to phishing, business email compromise, and credential theft in essentially the same manner for over ten years. They essentially follow a playbook that involves investing in awareness training, running phishing simulations, and requiring employees to complete annual security modules. The reason behind this is simple and the reasoning behind these efforts is straightforward: if people can better spot malicious emails and recognize malicious activity, incidents will decrease.
Yet, the amount of money lost because of business email compromise keeps rising. Credential harvesting is still successful. Conventional multi-factor authentication is frequently circumvented by adversary-in-the-middle phishing kits. Under duress, senior executives, including seasoned finance leaders, continue to approve fraudulent payments.
A deeper misclassification in enterprise security strategy is shown in this persistence. Although awareness is an educational measure that promotes culture rather than imposes results, it has been viewed as a control. This distinction has important ramifications for how businesses evaluate and control risk.
The core misunderstanding
A true security control prevents, detects, or limits an outcome regardless of what an individual does, knows or does not know. Conditional access rules, for instance, do not depend on an employee having a good day, and network segmentation does not depend on an employee remembering a policy. Likewise, Segregation of duties in finance exists precisely to ensure that no single individual can independently authorize high-risk transactions. These mechanisms are engineered to constrain risk structurally rather than depend on behavioral perfection.
Security awareness has its own purpose to influence behavior through the improvement of human judgment in situations that deal with time pressure and often incomplete information. Although these initiatives can lessen the possibility of poor decisions, they are unable to ensure consistent results for a varied workforce with individual differences working in a variety of environments. Human performance is inherently variable, especially when exposed to different conditions, and training does not eliminate that variability.
When organizations term security awareness as a “layer of defense,” they implicitly place it alongside technical and procedural safeguards, which can distort how risk is understood and assigned. Responsibility for incidents thus shifts subtly toward individuals, especially when an employee clicks a malicious link or authorizes a fraudulent request. The resulting narrative often emphasizes human error rather than examining whether the surrounding system allowed a single, foreseeable mistake to create material impact.
Examining whether the organization’s controls were made to foresee anticipated human mistakes and limit their effects before they cause enterprise-level harm is a more constructive line of inquiry. 
The predictability of human error
Human error is sometimes viewed as an exception in security incident conversations, as if a breach happened because someone made a mistake that should have been prevented. Human error is a constant in complex systems, especially in huge organizations where everyday operations are shaped by scale, pace, and conflicting agendas. The pertinent question is whether the surrounding environment has been constructed with the inevitable occurrence of mistakes in mind, rather than whether mistakes will occur at all.
Modern social engineering campaigns reflect a sophisticated understanding of how organizations function. Attackers study and understand reporting lines, financial processes, vendor relationships, and executive communication styles, sometimes gleaned from previously compromised accounts in similar industries. They time their messages to coincide with legitimate business activity and plan these messages to align with travel schedules, invoice payments and quarter-end reporting pressure. In many business email compromise cases, there is no malware involved and no technical exploit in the traditional sense of it and attacks are successful because it takes advantage of the trust that is ingrained in regular operations blended in seamlessly with established routines.
Under such conditions, expecting flawless human performance is unrealistic. Employees manage high volumes of communication while also combating deadlines and performance expectations. Senior leaders frequently make decisions with incomplete information, balancing urgency against risk to keep the business running. When a request appears in line with organizational standards and past experience, even highly skilled individuals may misunderstand it. These mistakes are a natural result of cognitive load, environmental clues, and institutional dynamics, not necessarily proof of carelessness.
This reality is acknowledged by high-risk industries like aviation and healthcare, which create multi-layered protections to stop a single error from turning into a disaster. Checklists, redundancy, and cross-verification processes are embedded as part of organizational pipelines to ensure that systems remain safe even when individuals are imperfect. On the other hand, the same discipline has not always been used in enterprise cybersecurity. A single compromised credential or a single configuration error, exemplified in the CrowdStrike outrage,  can still result in serious operational or financial harm in many settings. When that degree of fragility is present, the system’s authority distribution and error-absorbing capabilities become more pertinent than individual behavior.
Awareness cannot function as a primary safeguard
There are structural limitations that prevent awareness from serving as a dependable control. First, cognitive load and decision fatigue are unavoidable in complex organizations. Even experienced professionals make mistakes due to reduced scrutiny when under pressure and awareness training does not eliminate this human reality. Awareness training may increase general suspicion, but it cannot eliminate the reality that individuals must constantly triage information under time pressure and occasional lapses in judgment are statistically inevitable as a result.
Secondly, organizational dynamics further complicate the picture, especially in traditional societies where this is strongly upheld. Hierarchy and perceived authority are exploited in many successful business email compromise incidents as a result. Requests that seem to come from senior executives are implicitly urgent and significant for the organization. Employees are frequently trained to support executive instructions rather than impede them, particularly when it comes to urgent financial concerns, which could slow down business processes.
Lastly, the widespread adoption of multi-factor authentication has also contributed to an inflated sense of security. While MFA greatly improves security over password-only settings, not all implementations are impervious to modern attack methods. Push fatigue attacks take advantage of routine approval patterns, adversary-in-the-middle frameworks can steal and replay session tokens, and device code / OAuth consent phishing can provide continuous access without the need for conventional credential theft. In these cases, there is a likelihood employees comply with established security procedures and still be compromised because the architectural design allows it.
When combined, these reasons show why awareness is not a reliable main protection. It can strengthen best practices and lower risk at the edges, but it cannot make up for shoddy identity architecture, brittle finance procedures, or inadequate monitoring.
Treating human risk as a design constraint
A more pruned approach reframes human risk as an engineering consideration as opposed to a behavioral flaw. Security leaders should assess which decisions entail a disproportionate amount of risk when carried out in isolation, rather than asking how to train staff to recognize every potential phishing variant.
Salient questions in this regard include:
Should a single email request ever be sufficient to initiate a high-value transfer? Are payment instruction changes subject to enforced out-of-band verification? Does identity infrastructure continuously validate session integrity? Are anomalous financial behaviors detected in real time? This shift moves the focus from persuading individuals to behave perfectly toward building systems that remain resilient when they do not.
What structural controls should look like
An enterprise strategy that effectively tackles human-centric threats includes defenses that function without constant monitoring. Device-bound passkeys and hardware-backed credentials are examples of phishing-resistant authentication techniques that lessen vulnerability to push-based manipulation and token interception. Compared to static MFA prompts alone, conditional access policies that also assess device health and onboarding status, geolocation anomalies, and behavioral risk signals offer greater assurance.
In the same vein, financial workflows should embed separation of duties and enforced verification. Secondary validation should be required through separate channels for high-value transactions, vendor banking changes, and urgent payment requests. Systems for tracking transactions should also be able to spot anomalous payment amounts or departures from historical trends.
Particular consideration should also be given to identity telemetry. Persistence tactics frequently employed in business email compromise campaigns can be found by keeping an eye on mailbox rules, atypical travel, OAuth grants, privileged role assignments, and session oddities. Using Privileged Identity Management solutions, privileged access should be time-bound and approval-based to reduce the blast radius of credential misuse. Although human error cannot be eliminated, these precautions greatly lessen the chance that a single error will result in severe material loss.
From blame game to architecture
It makes sense that organizations would choose to gravitate towards awareness-raising campaigns. They are visible, often reasonably priced when bundled as part of existing security tooling and quantifiable. On the other hand, more funding and cross-functional cooperation are needed for architectural redesign, identity modernization, and workflow reorganization.
Threat actors, however, are becoming more adept at taking advantage of human behavior patterns that are predictable in current corporate procedures. They only require people to be human because they comprehend the urgency, trust, and operational complexity that frequently accompany working in time-sensitive professions, high-pressure conditions, and the ensuing complacency.
The rational response is to assume imperfection and build accordingly.
A more honest assessment of systemic risk
Security awareness remains an important component of organizational culture. Employees should understand common attack patterns and feel empowered to report suspicious activity. However, awareness should be viewed as a supporting measure rather than a primary safeguard.
When a single decision can still trigger substantial financial or operational damage, the organization’s exposure is rooted in design. Resilient enterprises acknowledge that human error is inevitable and ensure that their identity architecture, financial controls, and monitoring capabilities are robust enough to absorb it.
Reframing awareness in this way does not diminish its value. It places it in the correct category and forces a more honest assessment of systemic risk. Until that shift occurs, many organizations will continue to invest heavily in training while leaving structural weaknesses intact, and attackers will continue to exploit the gap between education and engineering.
This article is published as part of the Foundry Expert Contributor Network.
Want to join?
View the full article
The Swiss robotics engineer behind a commercial case that adds USB-C to Lightning iPhones has now built a reverse version: A case that adds a fully functional Lightning port to the iPhone 17 Pro.


Ken Pillonel describes the project as a tongue-in-cheek response to reader requests, and says he has no plans to sell it. "It's part hack, part mod, and one of the most cursed things I've ever built," he wrote in the video description, "Be careful what you wish for."

The build involved designing custom PCBs for precise connector placement, 3D printing a flexible TPU case on a Formlabs SLS printer, and fabricating a magnet installation jig on a Prusa printer. The finished case is slim and flexible, with MagSafe alignment and a snap-fit assembly.

Pillonel set himself a deadline of April Fools' Day to complete the prototype. The project builds on his long history of connector-swapping work, which includes adding USB-C to an iPhone X in 2021 and a USB-C conversion kit for AirPods Max in 2024.Related Roundup: iPhone 17 ProTags: Ken Pillonel, LightningBuyer's Guide: iPhone 17 Pro (Neutral)Related Forum: iPhone
This article, "Engineer Brings Lightning Port to iPhone 17 Pro" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Google has formally attributed the supply chain compromise of the popular Axios npm package to a financially motivated North Korean threat activity cluster tracked as UNC1069. "We have attributed the attack to a suspected North Korean threat actor we track as UNC1069," John Hultquist, chief analyst at Google Threat Intelligence Group (GTIG), told The Hacker News in a statement. "North KoreanView the full article
Anthropic on Tuesday confirmed that internal code for its popular artificial intelligence (AI) coding assistant, Claude Code, had been inadvertently released due to a human error. "No sensitive customer data or credentials were involved or exposed," an Anthropic spokesperson said in a statement shared with CNBC News. "This was a release packaging issue caused by human error, not a securityView the full article
IT leaders are setting their operations strategies for 2026 with an eye toward agility, flexibility, and tangible business results. 
Download the January 2026 issue of the Enterprise Spotlight from the editors of CIO, Computerworld, CSO, InfoWorld, and Network World and learn about the trends and technologies that will drive the IT agenda in the year ahead.

View the full article
Sergey Zaykov | shutterstock.com
Regelmäßige Netzwerk-Scans reichen für eine gehärtete Angriffsfläche nicht mehr aus. Um die Sicherheit von Unternehmensressourcen und Kundendaten zu gewährleisten, ist eine kontinuierliche Überwachung auf neue Ressourcen und Konfigurationsabweichungen erforderlich. Werkzeuge im Bereich Cyber Asset Attack Surface Management (CAASM) und External Attack Surface Management (EASM) sind darauf ausgelegt, die Angriffsfläche von Unternehmen:
zu quantifizieren,
zu minimieren, und
zu härten.
Das Ziel besteht dabei darin, den Angreifern möglichst wenig Informationen über das Security-Niveau des Unternehmens zu geben und gleichzeitig kritische Business Services aufrechtzuerhalten. Dabei spielt inzwischen auch Agentic AI eine immer größere Rolle.
12 Attack-Surface-Management-Tools
Die folgenden zwölf Lösungen unterstützen Sie dabei, Risiken zu identifizieren und zu managen.
Axonius Cyber Asset Attack Surface Management
Diese CAASM-Suite von Axonius deckt alle wichtigen Aspekte ab, wenn es um Attack Surface Monitoring geht. Das Tool erstellt zunächst ein Asset-Inventar, das automatisch aktualisiert und mit Kontext aus internen Datenquellen und Ressourcen angereichert wird.
Dabei ist es auch möglich, Monitoring-Prozesse aufzusetzen, die auf Grundlage von Richtlinien wie PCI oder HIPAA ablaufen. So lassen sich Konfigurationen oder Schwachstellen identifizieren, die diesen zuwiderlaufen und entsprechende Maßnahmen ergreifen.
Bugcrowd EASM
Bugcrowd hat im Mai 2024 Informer.io übernommen und dessen EASM-Angebot in seine Security-Plattform integriert. Diese automatisiert die Asset Discovery über Webapplikationen, APIs und andere “public facing”-Komponenten des IT-Stacks hinweg.
Assets überwacht die Lösung kontinuierlich, wobei identifizierte Risiken in Echtzeit priorisiert werden. Darüber hinaus stehen auch Zusatz-Services wie manuelle Risikoprüfungen oder Penetrationstests zur Verfügung. Das Workflow-basierte Response-System der Lösung verspricht eine einfachere Einbindung mehrerer Teams, indem existierende Ticketing- und Kommunikations-Tools integriert werden. Praktisch ist auch die Möglichkeit, Konfigurationsänderungen oder System Updates zu validieren, um sicherzustellen, dass identifizierte Bedrohungen tatsächlich bereinigt wurden.  
CrowdStrike Falcon Exposure Management
Crowdstrike hat sein Falcon-Surface-Angebot von einem Standalone EASM-Tool zu einem Kernbestandteil von Falcon Exposure Management ausgebaut. Die Lösung wird nun auch durch KI-nativen Code dabei unterstützt, Risiken zu identifizieren und auszuschalten. Darüber hinaus kommt die Technologie auch für Adversarial-AI-Szenarien zum Einsatz.
Die Crowdstrike-Lösung kann außerdem:
Risiken mit dem Business-Kontext korrelieren, die Ausnutzbarkeit validieren und direkte Abhilfemaßnahmen über die Falcon-Plattform einleiten. Unternehmen sollen sich mit dem Tool einen nachhaltigen Überblick über ihre Angriffsfläche verschaffen und Risiken oder Bedrohungen mit einer Vielzahl von Techniken aufspüren können. Dazu gehören etwa aktive, passive und API-basierte Scans, um mit dem Internet verbundene Ressourcen zu identifizieren.
Falcon Exposure Management ist nicht Teil des Enterprise-Softwarepakets von Crowdstrike. Es kann als Abonnementlizenz auf Basis der gemanagten Endpunkte erworben werden.
CyCognito Attack Surface Management
Das CAASM-Produkt von CyCognito bietet eine kontinuierliche Überwachung und Inventarisierung von Assets. Dabei spielt es keine Rolle, ob diese On-Premises, in der Cloud, bei einem Drittanbieter oder einer Tochtergesellschaft vorliegen.
Um den Triage-Prozess und die Risiko-Priorisierung zu erleichtern, kann auch Business-Kontext hinzugefügt werden (beispielsweise Beziehungen zwischen einzelnen Assets). Das hilft dabei, sich auf die wichtigsten Netzwerkrisiken zu konzentrieren. CyCognitos Tool verfolgt darüber hinaus auch Konfigurationsänderungen und ermöglicht so, neue Risiken für die Unternehmensinfrastruktur schnell zu identifizieren.
JupiterOne Cyber Asset Attack Surface Management
JupiterOne preist seine CAASM-Lösung als eine Möglichkeit an, “Cyber-Asset-Daten nahtlos in einer einheitlichen Ansicht zu aggregieren”. Der Kontext wird bei Bedarf automatisch hinzugefügt, und die Beziehungen zwischen den Assets können definiert und optimiert werden, um Schwachstellenanalyse und Incident-Response-Fähigkeiten zu verbessern.
Benutzerdefinierte Abfragen ermöglichen es Cybersecurity-Teams, komplexe Fragen zu beantworten, während der Asset-Bestand über eine interaktive Map durchsucht werden kann. Die Security-Tools, in die Sie bereits investiert haben, können Sie integrieren – was eine ganzheitliche, zentralisierte Perspektive auf das Security-Niveau zulässt.
Microsoft Defender External Attack Surface Management
Microsoft Defender EASM erkennt nicht verwaltete Assets und Ressourcen, die per Schatten-IT bereitgestellt werden oder sich auf anderen Cloud-Plattformen befinden. Sobald die Assets und Ressourcen identifiziert sind, sucht das Tool nach Schwachstellen auf jeder Ebene des Technologie-Stacks, einschließlich der zugrunde liegenden Plattform, App-Frameworks, Webanwendungen, Komponenten und des Kerncodes.
Defender EASM ermöglicht es IT-Profis, Schwachstellen in neu entdeckten Ressourcen schnell zu beheben, indem diese nach Entdeckung in Echtzeit kategorisiert und priorisiert werden. Naturgemäß lässt sich Defender EASM eng mit anderen Microsoft-Lösungen wie Security Copilot integrieren.
Outpost24 EASM
Der schwedische Anbieter Outpost24 hat 2023 den belgischen EASM-Anbieter Sweepatic übernommen und dessen Tool in seine Modul-Kollektion für Threat Intelligence, Data Leakage und Pentesting integriert. Diese EASM-Lösung ist sowohl Standalone, als auch als Managed Service erhältlich und kann Daten entweder passiv über DNS und andere TCP/IP-Details oder über direkte Verbindungen zu Cloud-Anbietern wie AWS und Azure sowie den Lösungen großer Softwareanbieter (etwa ServiceNow, Slack oder Atlassian) erfassen.
Palo Alto Networks Cortex Xpanse
Xpanse ist Teil der XSIAM-Produktsuite von Palo Alto, kann jedoch auch separat erworben werden. Das Standalone-Produkt hat allerdings einen etwas geringeren Funktionsumfang.
Das Palo-Alto-Tool unterstützt auch die Integration mit Tools von Drittanbietern wie Qualys, Jira und ServiceNow. Zudem verfügt das Produkt über eine beeindruckende Auswahl an vorgefertigten Detection-Regeln, Widgets, um Queries und Discovery-Routinen zu erstellen und anpassbare Daten-Dashboards aufzusetzen.
Rapid7 Surface Command
Surface Command ist nur eines von zahlreichen Modulen, das Rapid7 im Angebot hat (unter anderem Vulnerability und Incident Management sowie Cloud-Native Security). Das Tool bringt Threat Exposure, Detection und Response unter einen Nenner und verspricht eine kontinuierliche „Vogelperspektive“ über sämtliche Schwachstellen – vom Endpunkt bis hin zur Cloud.
Das Rapid-7-Tool ist darauf konzipiert, blinde Flecken in der Security aufzuspüren sowie Reaktion und Behebung zu beschleunigen. Für letzteres sind zudem auch agentenbasierte KI-Funktionen enthalten.
RiskProfiler EASM
Über die RiskProfiler-Plattform lassen sich sämtliche externen Bedrohungen managen. Das Tool ermöglicht beispielsweise Dark-Web_monitoring, digitales Monitoring sowie Hacking-Kampagnen, Schwachstellen und Supply-Chain-Angriffe zu tracken. Die hieraus gewonnenen Bedrohungsinformationen werden von KI-Agenten zu einem einheitlichen Korpus verdichtet.
Bestandteil des Tools sind zudem mehr als 13.000 vorinstallierte Regeln, die sowohl Open-Source- als auch eigene proprietäre Algorithmen miteinander verbinden. Auch die Risikobewertungen von Drittanbietern werden analysiert. Ein anpassbares Management-Dashboard visualisiert die Daten in diversen Ansichten. 
SOCRadar AttackMapper
Mit AttackMapper (ein Teil der Tool-Suite für SOC-Teams), will SOCRadar, den Anwendern die Sicht der Angreifer auf die Assets ermöglichen. Das Tool überwacht Assets mithilfe von Agentic AI dynamisch in Echtzeit, identifiziert neue oder veränderte und analysiert sie auf potenzielle Schwachstellen.
Die Ergebnisse werden mit bekannten Angriffsmethoden korreliert, um den Entscheidungsfindungs- und Triageprozess zu unterstützen. Dabei überwacht AttackMapper nicht nur Endpunkte und Software Vulnerabilities, sondern auch SSL-Schwachstellen, abgelaufene Zertifikate, DNS-Einträge und Konfigurationen. Das Tool erkennt selbst Website-Defacement-Angriffe, was entscheidend sein kann, um die Markenreputation zu schützen.
Tenable Attack Surface Management
Tenable hat schon seit einigen Jahren Tools im Angebot, um Schwachstellen aufzuspüren – und auch die aktuelle Tool-Suite wird modernen IT-Sicherheitsanforderungen gerecht. Bei Tenable Attack Surface Management handelt es sich um das EASM-Modul des Unternehmens, das in dessen Exposure-Management-Plattform „One“ integriert ist.
Tenable Attack Surface Management liefert Kontext und Details zu Assets und Schwachstellen, allerdings nicht nur aus technischer Sicht, sondern auch auf Business-Ebene, was für eine umfassende Priorisierung der Maßnahmen erforderlich ist.
7 Fragen vor dem ASM-Invest
Die folgenden Fragen sollten Sie sich und potenziellen Anbietern von Attack-Surface-Management-Lösungen stellen, bevor Sie einen Vertrag unterzeichnen.
Benötigt unser Unternehmen eine EASM- oder eine CAASM-Lösung? Die Antwort darauf hängt davon ab, ob Sie nach internen oder externen Angreifern suchen – und wie groß der Anteil Ihrer lokalen Infrastruktur ist. Wie umfangreich – und effektiv – ist das Tool automatisiert? Erkennt es zuverlässig alle anfälligen Ressoucren, einschließlich digitaler Zertifikate, offengelegter Anmeldedaten und mit dem Netz verbundene Server und Services? Welche Metadaten und weiteren Details liefert die Lösung?   Wie behebt die Lösung Schwachstellen, wenn sie welche findet? Läuft das automatisiert ab oder sind manuelle Eingriffe erforderlich? Unterstützt das Tool Continuous Monitoring? Und falls ja: Wie werden Veränderungen nachgehalten? Welche Schwachstellen werden wie mit anderen SOC-Tools geteilt oder integriert? Gibt es unterschiedliche Dashboards für Management- und andere Zwecke? Beziehungsweise: Wie lässt sich das Tool auf unterschiedliche Benutzergruppen anpassen? Wie sieht ihre Preisgestaltung im Detail aus? Stellen Sie sicher, dass Sie das Preisgefüge des Anbieters Ihrer Wahl wirklich verstehen. In den meisten Fällen sind Sie dabei mit komplexen, nutzungsabhängigen Abrechnungsmodellen konfrontiert. (fm)
View the full article
An Anthropic employee accidentally exposed the entire proprietary source code for its AI programming tool, Claude Code, by including a source map file in a version of the tool posted on Anthropic’s open npm registry account, a risky mistake, says an AI expert.
“A compromised source map is a security risk,” said US-based cybersecurity and AI expert Joseph Steinberg. “A hacker can use a source map to reconstruct the original source code and [see] how it works. Any secrets within that code – if someone coded in an API key, for example – is at risk, as is all of the logic. And any vulnerabilities found in the logic could become clear to the hacker who can then exploit the vulnerabilities.”
However, Anthropic spokesperson told CSO, “no sensitive customer data or credentials were involved or exposed. This was a release packaging issue caused by human error, not a security breach. We’re rolling out measures to prevent this from happening again.”
But it wasn’t the first time this had happened; according to Fortune and other news sources, the same thing happened last month.
Don’t expose .map files
Map files shouldn’t be left in the final version of code published on open source registries, where anyone can download a package; they can be sources of useful information for hackers.
According to developer Kuber Mehta, who published a blog on the latest incident, when someone publishes a JavaScript/TypeScript package to npm, the build toolchain often generates source map files (.map files). These files are a bridge between the minified/bundled production code and the original source; they exist so that when something crashes in production, the stack trace can point to the actual line of code in the original file, not to some unintelligible reference.
What’s available in these files? “Every file. Every comment. Every internal constant. Every system prompt. All of it, sitting right there in a JSON file that npm happily serves to anyone who runs npm pack or even just browses the package contents,” said Mehta.
“The mistake is almost always the same: someone forgets to add *.map to their .npmignore or doesn’t configure their bundler to skip source map generation for production builds,” Mehta said. “With Bun’s bundler (which Claude Code uses), source maps are generated by default unless you explicitly turn them off.”
Think of a source map as a file that shows what parts of minified computer code, which is not easily understandable to humans, are doing, shown in the human-readable source code, said Steinberg. For example, he said, it may indicate that the code in a specific portion of the executable code is performing the instructions that appear in some specific snippet of source code.
A source map can help with debugging, he added. Without it, he said, many errors would be identified as coming from a larger portion of code, rather than showing exactly where the errors occur.
The world learned of this incident when security researcher Chaofan Shou posted this message early Tuesday on X: “Claude code source code has been leaked via a map file in their npm registry!”, along with a link to the file.
A common error
Leaving source map files in a package “is an incredibly common mistake developers make quite often,” said secure coding trainer Tanya Janca. “In this specific situation, it is more serious than it would be somewhere else, mostly because of the incredibly high value of the intellectual property involved, and because now malicious actors can analyze the source code directly for vulnerabilities instead of having to reverse engineer it, which adds time, cost, and complexity.”
Ideally, Janca said, developers should harden their build environment, so they don’t ship debug information/features with production. She offered these tips to developers:
disable source maps in the build/bundler tool; add the .maps file to the .npmignore / package.json files field to explicitly exclude it, even if it was generated during the build by accident; exclude the .maps files from the list of published artifacts in the continuous integration/continuous deployment environment; carefully separate debug builds from production builds if there are differences; even the comments could be incredibly sensitive. A critical layer
Any exposure of source code or system-level logic is significant, because it shows how controls are implemented, commented Dan Schiappa, president of technology and services at Arctic Wolf. With this information exposed, the number of people who now understand how the model enforces behavior, manages access, and handles edge cases increases, he said.
“In AI systems, that layer is especially critical,” he added. “The orchestration, prompts, and workflows effectively define how the system operates. If those are exposed, it can make it easier to identify weaknesses or manipulate outcomes. Knowing that attackers are still discovering the most optimal ways to leverage AI means that in any instance where a tool could be compromised, there are likely cybercriminals waiting in the wings.”
This article originally appeared on InfoWorld.
View the full article
Apple today released new firmware for its second-generation AirTag item trackers. The firmware has a 3.0.45 version number, up from 3.0.41, and it is the first firmware update that Apple has provided for the ‌AirTag‌ 2 that launched in January 2026.


‌AirTag‌ updates are infrequent, and there is no word yet on what's included in the new firmware. Apple has shared release notes in the past, and software updates are usually bug fixes and improvements.

In the past, new ‌AirTag‌ firmware was distributed on a rolling basis over two weeks, but it appears the latest firmware is available for all ‌AirTag‌ 2 users immediately.

You can check your ‌AirTag‌ firmware by opening up the Find My app, going to the Items tab, tapping on an ‌AirTag‌ in the list, and tapping on the ‌AirTag‌'s name to see its firmware version.

There is no way to force an ‌AirTag‌ update, and with firmware distributed over the air with an iPhone, iPad, or Mac. Make sure your ‌AirTag‌ is in range of an Apple device, and then wait for the firmware to roll out.Related Roundup: AirTagBuyer's Guide: AirTag (Buy Now)
This article, "Apple Releases First Firmware Update for AirTag 2" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Attackers compromised the npm account of the lead maintainer of Axios, a widely used JavaScript HTTP client library, and used it to publish malicious versions of the package that deployed a cross-platform remote access trojan on developer machines. The incident represents the highest-impact npm supply chain attack on record given Axios’ approximately 100 million weekly downloads and its presence in frontend frameworks, backend services, and countless enterprise applications.
Luckily the trojanized versions, [email protected] and [email protected], were detected by multiple security companies monitoring the npm registry within minutes of publication, triggering a rapid response that saw the malicious packages removed by the npm team between two to three hours later. That said, given the high download activity this project sees, the short time window was enough to impact a significant number of developer environments.
According to cloud security firm Wiz, Axios is used in 80% of cloud and code environments; the company observed execution of the malware in roughly 3% of impacted environments. Researchers with security firm Snyk noted that “even a two-hour malicious window represents an enormous potential blast radius” given the library’s popularity. Almost 175,000 other projects on npm list Axios as a dependency, meaning this had a huge cascade effect through the ecosystem.
The attack follows a series of supply chain attacks that impacted multiple open-source projects across different package repositories over the past several weeks, most of them attributed to a group known as TeamPCP. However, the Google Threat Intelligence Group (GTIG) has attributed the Axios attack to a North Korean threat actor it tracks as UNC1069.

“North Korean hackers have deep experience with supply chain attacks, which they’ve historically used to steal cryptocurrency,” said John Hultquist, chief analyst with GTIG. “The full breadth of this incident is still unclear, but given the popularity of the compromised package, we expect it will have far reaching impacts.”
In their analysis, Snyk researchers also noted the sophistication of techniques involved in the attack.
“The attacker also showed meaningful operational sophistication, pre-staging the malicious dependency, using a ‘clean’ version history, double-obfuscating the dropper, building platform-specific RATs, and implementing anti-forensic self-deletion,” the Snyk researchers said in their report. “This was not opportunistic.”
How the attack unfolded
Attackers began preparing the Axios attack roughly 18 hours before when an account named nrwise published a package called [email protected]. This was a clean decoy designed to establish registry history and legitimacy. The malicious payload arrived later the same day in [email protected], which contained a postinstall hook that would execute a dropper script when it was pulled in by a different package as a dependency.
Shortly after midnight UTC on March 31 a new version of the Axios package, [email protected], was published on npm followed by [email protected] 39 minutes later. Both listed [email protected] as a dependency in their package.json files, but the rest of the components remained unchanged.
A package that appears in the manifest but has zero usage or imports in the codebase is called a phantom dependency and is a high-confidence indicator of compromise, according to researchers at StepSecurity. Another indicator was that these versions appeared only on npm and not in the project’s GitHub repo as tagged releases.
Axios’ legitimate 1.x releases were configured to use npm’s OIDC Trusted Publisher mechanism bound to GitHub Actions, but the 1.14.1 release was published manually via a stolen token with no corresponding commit or tag in the repository.
In comments on GitHub, the project’s principal maintainer Jason Saayman acknowledged that while v1.x had trusted publishing configured, the v0.x branch still relied on a legacy long-lived token. A community member further pointed out that the v1.x publish workflow still passed NODE_AUTH_TOKEN to npm, which takes precedence over OIDC when both are present, meaning the long-lived token was also being used for v1.x rather than the intended trusted publishing mechanism.
Cross-platform malware
The obfuscated and encrypted postinstall script contacted a command-and-control (C2) server on a domain registered the day before by the attackers and downloaded platform-specific second-stage RAT payloads.
On macOS, the binary is written to /Library/Caches/com.apple.act.mond and can self-sign injected payloads via codesign —force —deep —sign, bypassing macOS Gatekeeper protections. The malware fingerprints the system, collects hostname, username, macOS version, boot and install times, CPU architecture, and running processes, and then reaches out to the C2 server every 60 seconds.
On Windows machines the payload is a PowerShell script copied to %PROGRAMDATA%\wt.exe, masquerading as Windows Terminal. The malware establishes persistence through a registry Run key named “MicrosoftUpdate” and a re-download batch file. Meanwhile Linux systems receive a Python script stored as /tmp/ld.py that gets executed via nohup python3.
The RAT supports four commands: peinject for deploying additional binaries, runscript for executing shell or AppleScript code, rundir for directory enumeration, and kill for self-termination.
According to researchers from security firm Socket, after execution the malware attempts to erase its tracks by deleting setup.js, removing the malicious package.json that contained the postinstall hook and replacing it with a clean copy that reports version 4.2.0 instead of 4.2.1. This means users running npm list in an affected project directory will see [email protected], potentially misleading them into believing the installed version predates the attack.
Detection and maintainer response
Security firms monitoring npm flagged [email protected] within minutes after it was published, triggering a series of responses, including by the npm registry team that removed the packages. However, the Axios project itself had difficulty containing the issue because the incident happened during the lead maintainer’s nighttime.
A core collaborator of the project responded to the community-reported issue on GitHub also within minutes, but his permissions were lower than those of the maintainer whose token was compromised.
This underscores a potential incident response gap open-source projects might face, because even if project contributors notice a breach immediately, the attacker could have higher privileges than them through a stolen token and could slow down attempts at damage control.
In the recent Trivy compromise, attackers flooded the GitHub issue with spam comments from bots to make it harder for maintainers to respond and communicate with the community.
Prepare for more compromises
The cascade effect of the Axios incident became visible as dependency scanning tools flagged hundreds of downstream projects that had pulled the malicious versions. One user posted warnings to more than 50 repositories after detecting plain-crypto-js in their lockfiles, while another identified dozens more, from personal blogs to enterprise apps.
This demonstrates how quickly the compromise of a popular npm package propagates through the ecosystem, even if the breach is detected within a few hours.
Organizations should audit lockfiles and installed dependencies for the malicious versions immediately. If the malicious versions were installed, assume the development environments are fully compromised. Security teams should isolate affected systems, rotate all credentials present on them such as npm tokens, cloud provider keys, SSH private keys, CI/CD secrets, etc.
“Do not rotate in place; revoke and reissue,” the Snyk researchers advised. “Do not attempt to clean compromised systems. Rebuild from a known-clean snapshot.”
In the long term, organizations should enforce npm ci —ignore-scripts in CI/CD pipelines to prevent postinstall hooks from executing during automated builds and consider package age policies such as npm’s minimumReleaseAge setting. This gives development teams the ability to block the installation of packages that don’t have a minimum age, which would have blocked this attack since “plain-crypto-js” existed for less than 24 hours before being pulled into Axios’ dependency tree.
The use of AI tools like Claude Code or OpenAI Codex in enterprise environments via their respective desktop apps extend the impact past developer environments. These tools are increasingly being used by non-developers in their work workflows, and LLMs tend to rely heavily on the npm and PyPI ecosystems for CLI tools.
View the full article
Apple was founded on April 1, 1976, meaning the company is officially 50 years old as of today. To honor the occasion, we have reflected on some of Apple's biggest moments of each decade, from the 1970s through to the 2020s.


Apple has an extensive history, so this list is far from comprehensive, but it captures some of the pivotal events over the company's first 50 years.

1970s

While the Apple-1 was released in 1976, it was the Apple II in 1977 that became the company's first successful, mass-market computer.


Unlike the Apple-1, the Apple II came fully assembled in a plastic case with a keyboard, and Apple sold millions of units of the computer over the years. This product gave Apple sustained cash flow, allowing it to become a major company.

1980s

In 1984, Steve Jobs introduced the Macintosh, the world's first successful mass-marketed computer with a graphical user interface (GUI).

The original Macintosh popularized the computer mouse, allowing users to control an on-screen pointer. This point-and-click method of computer navigation was still a novel concept to most people at the time, as personal computers in this era typically had text-based command-line interfaces controlled with a keyboard.


Apple said the Macintosh typically took "only a few hours to learn," and it touted what are now basic computer features, such as a desktop with icons, the ability to use multiple programs in windows, drop-down menus, and copy and paste.

Pricing for the original Macintosh started at $2,495, equivalent to nearly $8,000 today. Key specs and features included an 8 MHz processor, 128 KB of RAM, a 400 KB floppy disk drive for storage, and serial ports for connecting a printer and other accessories.

1990s

By the 1990s, Apple had largely lost its way. That changed when Jobs returned to the company in 1997, as part of Apple's acquisition of NeXT, another computer company founded by Jobs after he was ousted from Apple in the mid-1980s.


Apple did release some unique products in the 1990s, ranging from the Newton personal assistant to the Pippin video game console to the QuickTake digital camera, but Jobs' return was easily the company's pinnacle moment of the decade. Jobs quickly simplified and improved Apple's product lineup, starting with the colorful iMac in 1998.

2000s

Apple's renaissance continued into the 2000s with the launch of the iPod in 2001. The portable music player was extremely popular and helped turn Apple into a consumer electronics company rather than merely a computer company.


Six years later, Apple combined an iPod with a mobile phone. Enter the iPhone.

Jobs famously introduced the original iPhone as if it were three separate products: a widescreen iPod with touch controls, a revolutionary mobile phone, and a breakthrough internet communications device. The crowd at Macworld San Francisco erupted with cheerful applause upon realizing that Jobs was referring to a single device.


While the iPod was hugely successful, the iPhone is absolutely massive, and it is now one of the most successful products of any kind ever released. Last year, Apple announced that it had shipped its three billionth iPhone. That is 3,000,000,000.

2010s

Three major Apple products launched throughout the 2010s, including the iPad in 2010, the Apple Watch in 2015, and the AirPods in 2016.


While the iPad was essentially just a large-screened iPhone when it first launched, the device has received significant advancements like trackpad support over the years, and it has since redefined what a personal computer is.

Millions of people wear an Apple Watch, and it has become one of the world's most popular fitness devices. With health and safety features like the ECG app, Crash Detection, Fall Detection, Emergency SOS, and more, the Apple Watch has even saved lives, which is a remarkable feat and something that Apple's CEO Tim Cook is very proud of.


As for AirPods, Apple says they are the world's most popular wireless headphones. Enough said.

2020s

In 2020, the Mac's transition from Intel processors to Apple silicon began, resulting in industry-leading performance-per-watt to this day.


After years of rumors, Apple unveiled its plan to transition the entire Mac lineup from Intel processors to its own custom-designed chips at WWDC in June 2020. Later that year saw the release of the first three Mac models powered by Apple silicon, including a 13-inch MacBook Pro, MacBook Air, and Mac mini. The transition was completed in 2023 when the Mac Pro—which was recently discontinued—received the M2 Ultra chip.

Apple said macOS Tahoe is the final macOS release that will support Intel-based Macs.Tag: Apple 50th Anniversary
This article, "Apple Turns 50 Today: Reflecting on Each Decade's Biggest Moments" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
OpenAI has updated ChatGPT with support for CarPlay, which means ‌CarPlay‌ users can now ask ChatGPT questions and make requests directly from their vehicle dashboard.


Apple began allowing third-party voice-based conversational apps to interface with ‌CarPlay‌ in iOS 26.4, but apps need to implement the feature and get a special entitlement from Apple.


For the ChatGPT app and other apps that implement ‌CarPlay‌ support, voice has to be the primary method of interaction. Apple says that chatbot apps should not show text or imagery in response to queries.


Apple has a voice control template that apps are required to use. Apps have to display the voice control screen while voice-based services are active, and apps are able to have up to four action buttons. To use ChatGPT with ‌CarPlay‌, an iPhone running iOS 26.4 or later is required.

‌CarPlay‌ has supported third-party apps for years, but Apple limits the types of apps that are available to cut down on driver distractions. Apple has a list of allowed app categories, which includes audio apps, communication apps, EV charging apps, and navigation apps.

ChatGPT integration will let users ask questions hands-free, but the chatbot is not able to control vehicle or iPhone functions. There is no wake word, so users will need to open the ChatGPT app to use it.Related Roundup: CarPlayTags: ChatGPT, OpenAIRelated Forum: HomePod, HomeKit, CarPlay, Home & Auto Technology
This article, "OpenAI Brings ChatGPT to CarPlay for Hands-Free Voice Conversations" first appeared on MacRumors.com

Discuss this article in our forums

View the full article
Apple is providing employees with a special gift in honor of its 50th anniversary, which takes place on Wednesday, April 1. Employees will receive a commemorative t-shirt, enamel pin, and limited-edition poster, all of which have the scribble-style rainbow Apple logo that Apple has been using for its 50th anniversary artwork.


An Apple Park sign says that products are "crafted by hand" and are available for employees to pick up until April 30.





Apple kicked off its 50th anniversary celebrations in March, and has been hosting concerts and Today at Apple events around the world. There was an Alicia Keys concert in New York, a Li Yuchun performance in Chengdu, a Mumford & Sons concert in London, a meetup with professional figure skater Elladj Baldé in Vancouver, a light show with music composed by Bailey Pickles in Sydney, and more.

Apple plans to wrap up its 50th anniversary party with a special finale performance at its ‌Apple Park‌ campus for employees. The musical guest hasn't yet been announced, but rumors suggest that it will be Paul McCartney.Tag: Apple 50th Anniversary
This article, "Apple Celebrates 50th Anniversary With Employee Gifts, Plans Finale Concert at Apple Park" first appeared on MacRumors.com

Discuss this article in our forums

View the full article

Account

Navigation

Search

Search

Configure browser push notifications

Chrome (Android)
  1. Tap the lock icon next to the address bar.
  2. Tap Permissions → Notifications.
  3. Adjust your preference.
Chrome (Desktop)
  1. Click the padlock icon in the address bar.
  2. Select Site settings.
  3. Find Notifications and adjust your preference.