Apple has released the second developer betas of macOS 26.6, iOS 26.6, iPadOS 26.6, tvOS 26.6, watchOS 26.6, and visionOS 26.6. Registered developers can download the betas via Apple’s developer portal. Or they can be downloaded over-the-air once the proper...
News
Parallels announces guidance for Parallels Desktop users on macOS Golden Gate
Parallels has announced new guidance for Parallels Desktop users following Apple’s recent Worldwide Developer Conference announcements. The guidance includes how users can safely explore macOS 27 Golden Gate through virtualization without affecting their primary Mac...
Opinion
Analyst predicts features of the iPhone 17, iPhone 18, and iPhone 19
Talk about a powerful crystal ball! In a new Medium post, analyst Ming-Chi Kuo offers his predictions for the iPhone 17, iPhone 18, and iPhone 19 that will likely arrive in 2025, 2026, and 2027. He says the high-end iPhone 17 model is expected to feature an upgraded...
Scanners
- Monday June 15
- 1 hour agoWhatsApp Web extends voice and video calls test to group chats
Users who rely on WhatsApp’s web version will soon be able to make voice and video calls in group chats. Here are the details. - 09:30 pmChase Sapphire Preferred just got even better for Apple users: Free Apple TV + 3x points on streaming and travel | Mac Daily NewsChase Sapphire Preferred just got even better for Apple users: Free Apple TV + 3x points on streaming and travel
As of today, June 15, 2026, Chase has refreshed the Chase Sapphire Preferred card with a complimentary one-year Apple TV subscription… The post appeared first on MacDailyNews. - 09:30 pmApple among companies ordered to pay nearly $60 million in Brazil over loot boxes
A Brazilian court has ordered Apple and several other companies to pay nearly $60 million over loot boxes in games accessible to minors. Here are the details. - 08:41 pmHow Apple is making even aging iPhones run faster and last longer
Apple is breathing new life into older iPhones with iOS 27. Through under-the-hood optimizations — like major tweaks to the CPU scheduler… The post appeared first on MacDailyNews. - 08:30 pmThis hidden iOS feature is my daily go-to when using AirPods Pro 3
I use AirPods Pro 3 all day, every day while I work, and there’s one hidden iOS tool that I’ve found pairs perfectly with the product: it’s a little-known feature called Background Sounds. - 08:19 pmPreview on iOS 27 inherits fun Liquid Glass easter egg from iPadOS 26
When Apple introduced the Liquid Glass redesign last year, it also added a fun interactive easter egg to the Preview app on iPadOS. Now, it is bringing the same playful element to iOS 27. - 08:04 pmApple reveals why macOS might block your Terminal prompt
In macOS 26.4, Apple introduced new popup warnings when you try to paste a command into the Terminal. Now, a new support document explains why these and other Mac Terminal popups appear. - 07:43 pmApple rolls out RC builds for upcoming macOS Sonoma and macOS Sequoia updates
In addition to releasing macOS Tahoe 26.6 developer beta 2 today, Apple also seeded Release Candidates for two older versions of macOS. Here are the details. - 07:30 pmApple TV teases ‘Widow’s Bay’ season finale, coming Tuesday night
Apple TV has dropped an intriguing teaser for the Season 1 finale of "Widow’s Bay," one of the year’s most delightful breakout hits… The post appeared first on MacDailyNews. - 07:19 pmApple explains why Siri’s major iOS 27 overhaul took so long
iOS 27’s new Siri AI is a huge upgrade from the old Siri, but it also took longer than expected to arrive. Here’s why the new Siri took so long, per Mike Rockwell. - 06:54 pmiOS 27 basically turns your iPhone and AirPods into an Apple Watch at the gym
GymKit has been one of Apple Watch’s smartest fitness features since it launched in 2017. Tap your watch to compatible gym equipment, and Apple Watch shares your heart rate while the machine sends back metrics like distance, incline, pace, and calories. With iOS 27, Apple is expanding that idea beyond Apple Watch. I tested the new GymKit on iPhone and AirPods Pro 3 ($179, reg. $249) experience with a GymKit-compatible treadmill. It basically gives you the Apple Watch GymKit workout tracking experience, just without the watch. This could be useful in a lot of scenarios. - 06:29 pmMagSafe Monday: Spigen turned a MagSafe wallet into a mini backpack
If you’re looking for a nice balance between a crossbody and a backpack when traveling or camping, you might be interesting to take a look at the Spigen Snapzip Mag Fit. I recently picked one up and am looking forward to using it while traveling. It can hold your AirPods, keys, cash, and much more. It’s like a mini backpack for your iPhone. - 06:23 pmApple releases second macOS 26.6, iOS 26.6, iPadOS 26.6, watchOS 26.6, tvOS 26.6, and visionOS 26.6 betas | Mac Daily NewsApple releases second macOS 26.6, iOS 26.6, iPadOS 26.6, watchOS 26.6, tvOS 26.6, and visionOS 26.6 betas
Apple has just seeded the second developer betas for its current-generation operating systems, focusing primarily on stability… The post appeared first on MacDailyNews. - 05:59 pmDoctor Pairs TextExpander with a Gaming Mouse for Improved Telehealth Communications
Former TidBITS managing editor Josh Centers profiles a telehealth doctor who uses a 12-button gaming mouse and TextExpander’s branching snippets to generate complete, error-free patient documentation with a single click.Read original article - 05:51 pmAt WWDC 2026, energy and optimism were high as Apple finally delivers
After spending several days at Apple's campus for WWDC, developers seem to feel energized by everything Apple has announced. Here's my early impression of what Apple has coming.Apple's WWDC 2026 status that looks like the new Siri AI windowWWDC is one of my favorite times of the year. I appreciate seeing the features coming to existing hardware and connecting with the developers building the apps.While most users and media alike had cautious expectations going in after two years of underwhelming AI advancements, I still felt excited. I knew this was going to be the year Apple was going to deliver on what it had previously previewed. Continue Reading on AppleInsider | Discuss on our Forums - 05:28 pmApple teases Widow’s Bay season finale, airing this week
Widow’s Bay season finale airs this week on Apple TV, and Apple just posted a short video teasing what’s coming. - 05:22 pmSecond developer betas for iOS 26.6, macOS 26.6 have arrived
Apple's beta testing routine for the current-gen operating systems continues, with the second developer builds of iOS 26.6, iPadOS 26.6, watchOS 26.6, tvOS 26.6, visionOS 26.6, and macOS Tahoe 26.6 out now.Apple's hardware that works with the 26-generation operating systems - Image Credit: AppleThe second developer builds arrive after the first, which landed on May 26.While usually we deal with only one set of betas, sometimes we have to manage two of them. Following the WWDC keynote, Apple has introduced developer betas of its 27-generation operating systems, including iOS 27 and macOS 27. Continue Reading on AppleInsider | Discuss on our Forums - 05:21 pmThis rugged, 10-foot Beats 240W cable is on sale for less than $17
Macworld Beats 240W USB-C cable View Deal (function () { document.querySelector("#sticky-promo-block a").addEventListener("click", function(e) { const debug = document.location.host.search(/lndo.site|go-vip.net/) !== -1; const text = this.closest("#sticky-promo-block").querySelector("p.promo-title").textContent; const data = { event: "stickyConversionUnitClick", eventCategory: "Sticky Conversion", eventAction: "Click", eventLabel: text }; if(debug)console.log("Sticky Conversion CLick - pushing to dataLayer: ", data); dataLayer.push(data); return true; }); })(); Beats’ 10-foot 240W USB-C to USB-C cable is down to $16.49 right now when you clip the coupon on the listing page. That’s good for nearly half off its $30 MSRP and the best price we’ve ever seen. The absolute most important feature of this Beats product is the 240W power rating. That’s well beyond what a phone needs, which means this cable can fast-charge a laptop at full speed, not just trickle power to a handset. Pair it with a capable USB-C wall adapter, and it’ll keep up with a MacBook or any other power-hungry laptop. And while the power is absolutely amazing, the length of this cable is the star of the show. At 10 feet (3 meters), this reaches from a couch to a far-off outlet, or from a nightstand to a wall plug that isn’t conveniently close. I have 6-foot cables and still wish I’d have had this one instead because we did not think out the placement of the couch well enough. Plus, most cables that ship with your devices are barely 3 feet, which means you’re probably only using them for desk charging. Durability is one thing you won’t have to worry about when it comes to these Beats cables. The braided design protects the wires against the usual tear that happens when you bend them over and over. The Beats 240W USB-C cable is also versatile. Beyond charging, it can help you sync information, transfer data, listen to high-quality audio, and so on. It works with all USB-C Apple and Android devices, and it’ll charge your Beats Studio Pro, Solo 4, or Pill while you keep listening. You do have to keep in mind that this cable may be able to deliver 240W charging, but you need a wall charger that can actually deliver all that power. That one’s going to cost you extra. At $16.49, this Beats 240W cable is an easy pick if you want one long, rugged cable that can fast-charge a laptop, sync data, and survive daily abuse. - 05:16 pmiOS 26.5.2 update likely coming soon for iPhone users
While much of the attention has shifted to iOS 27, that update won’t ship to customers until later this year. In the meantime, iOS 26 remains the iPhone software version in use by iPhone users everywhere. As such, Apple appears to be prepping iOS 26.5.2 as an upcoming bug fix update … - 05:08 pmmacOS 26.6 beta 2 rolling out now, plus iPadOS 26.6, watchOS 26.6, tvOS 26.6, more
After last week’s release of the first developer betas for the operating systems announced during the WWDC keynote, Apple is now releasing a new round of betas for its current software lineup. Here are the details. - 05:06 pmApple’s new AI-powered Image Playground doesn’t suck and actually works!
Apple’s Image Playground finally delivers on its promise with iOS 27, iPadOS 27, and macOS 27. The AI image generator that launched to… The post appeared first on MacDailyNews. - 05:06 pmApple releases iOS 26.6 beta 2 for iPhone, here’s what to expect
While iOS 27 is the new focus for pre-release software, Apple is still preparing iOS 26.6 as the next iPhone update. Apple has released the second iOS 26.6 developer beta. The update follows the first developer beta release and public beta release in May. - 04:32 pm20 years of Intel Macs: Why Apple switched, and why it switched again
Remembering the ups and downs of the Intel Mac era as it finally winds down. - 04:23 pmAdobe crams more AI into Lightroom, Premiere, Photoshop, After Effects
Adobe has added new features to most of its Creative Cloud software, including quite a few that are powered by artificial intelligence.Image Credit: AdobeOn Monday, Adobe announced that it had begun rolling out the next batch of updates to its popular design software. The updates, while minimal for each program, are substantial across the entire platform.As expected, many of these features are powered by AI. This strategy has put Adobe at odds with many of the creatives who use its software. Continue Reading on AppleInsider | Discuss on our Forums - 04:21 pmPath Finder 26.1.4
Removes the AirDrop view from the file browser alternative to the macOS Finder. ($29.95 anual subscription, free update, 19.3 MB, macOS 10.13+) - 04:19 pmOmniOutliner Essentials and Pro 6.2
Information organization apps add localizations and a few improvements. ($24.99/99.99 new, free update, 59.2 MB, macOS 15+) - 04:18 pmMimestream 1.10.2
Maintenance release for the Gmail-specific email app focused on bug fixes. ($49.99 annual subscription, free update, 12.8 MB, macOS 12+) - 04:11 pmFantastical 4.1.14
Brings AI-related enhancements, user interface improvements, and bug fixes to the calendar app. ($57 annual subscription, free update, 70.2 MB, macOS 12+) - 04:06 pmChase adds free Apple TV, discounted Apple One benefit to popular credit card
Chase announced new benefits for its Sapphire Preferred card today, including free Apple TV for a year or discounted Apple One. Here are the details. - 03:50 pmApple, please jump on the removable-battery bandwagon
With a bonafide trend building, we ask Apple to please use removable batteries in portable audio. It's the right thing to do. (via Cult of Mac - Your source for the latest Apple news, rumors, analysis, reviews, how-tos and deals.)
- Monday June 15
- 1 hour agoApple Card Promo Doubles Daily Cash Back on Nike Purchases
Apple is teaming up with Nike for an Apple Card promotion that gives extra Daily Cash back. For the next month, Apple Card users can get 6% Daily Cash back when making a purchase with Apple Card using Apple Pay at a Nike retail store, the Nike website or Swoosh website, or Nike's apps. The Apple Card normally offers 3% cash back on Nike purchases, so the bonus is doubled during the promotion period (June 15 to July 15). Apple Card holders can get the 6% Daily Cash back on up to $500 in purchases, for a total of $30 back. The deal is available to Apple Card owners, co-owners, and participants, so multiple family members can take advantage of the bonus offer. Most Apple Pay purchases provide 2% Daily Cash, but Apple has partnered with companies like Nike to increase that to 3%. Extra cash back is available when using Apple Pay and Apple Card for purchases at Ace Hardware, Apple retail stores, ChargePoint, Duane Reade, Hertz, Booking.com, Uber, and Walgreens. Tags: Apple Card, Apple Pay PromoThis article, "" first appeared on MacRumors.comDiscuss this article in our forums - 07:07 pmChase Sapphire Preferred Card Introduces New Perk for Apple Customers
Chase this week announced new perks for its Sapphire Preferred credit card, and one of them is a complimentary one-year Apple TV streaming subscription. To get the free year of Apple TV, which typically costs $12.99 per month in the U.S., you must activate the card by December 31, 2026. If you are already subscribed to Apple TV directly through Apple, the complimentary subscription from Chase will automatically supersede your paid subscription until it ends, at which point the paid subscription will resume at the going price. As noted by 9to5Mac, Apple One subscribers can receive a $7.50 discount per month instead. If you are subscribed to Apple One directly through Apple, and activate your complimentary Apple TV access on Chase.com or the Chase Mobile app with the same Apple Account connected to your Apple One billing, you will automatically receive a $7.50 discount on your Apple One subscription for 12 months starting on your next billing period. Chase's Sapphire Preferred card continues to have a $95 annual fee. New and existing cardholders have access to these new benefits starting today. The other new benefits include 3× points on gas, EV charging, and Airbnb and Vrbo bookings, while the card's annual hotel statement credit has been doubled to $100. There is also a new $120 Global Entry, TSA PreCheck, or NEXUS credit every four years, along with new "emergency evacuation and transportation" coverage. On the other hand, the 10% anniversary bonus benefit is being discontinued, and Ultimate Rewards points will transfer to World of Hyatt at a rate of 4:3. More details are available in Chase's press release. For a limited time, new cardholders can earn 100,000 points after spending $5,000 in the first three months. Chase's higher-end Sapphire Reserve credit card offers complimentary Apple TV and Apple Music subscriptions, but it has an annual fee of $795.Tags: Apple One, Apple TV Service, ChaseThis article, "" first appeared on MacRumors.com - 05:51 pmNo iPhone 18 This Year, Apple Supplier Comments Seemingly Confirm
Apple's standard iPhone 18 model will launch in early 2027, based on comments from a partner in the company's supply chain that appear to corroborate rumors of a delayed spring release for the base model. Apple typically works on an annual smartphone launch cycle where it releases the entirety of its latest flagship iPhone series in the fall, usually around mid-September. That appears set to change this year, however. Multiple reports claim the base iPhone 18 model will be held over until spring 2027, and only the iPhone 18 Pro models will debut this year alongside Apple's first foldable iPhone. Now, comments from a key Apple supplier appear to offer corroborating evidence that the company is preparing to break from its traditional launch schedule. Speaking at Largan Precision's annual shareholders' meeting, chairman Lin En-ping said a major U.S. customer had postponed the launch of a new model to the first quarter of 2027, shifting component procurement later into the year and boosting expected factory utilization in the fourth quarter. Lin did not identify the customer or product, but Largan is Apple's primary supplier of iPhone camera lenses, so the remarks are notable in light of reports that the standard iPhone 18 will not launch alongside Apple's higher-end models this time around. The comments are particularly noteworthy because Apple suppliers rarely offer public details about clients' future product launches, even indirectly. According to reports, Apple plans to split future iPhone launches across two release windows. Under the new strategy, premium models would continue to debut in September, while lower-cost models would follow the next spring. If accurate, the standard iPhone 18 will arrive in early 2027 alongside the iPhone 18e and iPhone Air 2, roughly six months after the iPhone 18 Pro, iPhone 18 Pro Max, and Apple's much-rumored foldable "iPhone Ultra." The staggered approach is expected to help Apple manage manufacturing resources more efficiently as its lineup grows to six devices instead of five, while helping maintain sales momentum throughout the year. If implemented, it would be the first deliberate separation of Apple's flagship iPhone releases since the company established its annual fall launch pattern with the iPhone 4S in 2011. The standard iPhone 18 models are not expected to feature design changes, with Apple using the same 6.3-inch display size for the iPhone 18 and the 6.1-inch size for the iPhone 18e. For everything we know so far, be sure to check out our dedicated roundup.Related Roundup: iPhone 18Related Forum: iPhoneThis article, "" first appeared on MacRumors.comDiscuss this article in our forums - 05:09 pmSecond macOS Tahoe 26.6 Beta Now Available for Developers
Apple today provided the second beta of an upcoming macOS Tahoe 26.6 update to developers for testing purposes, with the update coming almost three weeks after Apple seeded the first beta. Developers can download the macOS Tahoe 26.6 update by opening up the System Settings app, selecting the General category, and then choosing Software Update. Beta Updates will need to be enabled, and a free developer account is required. With macOS Golden Gate set to launch in just a few months, Apple is likely focusing most of its attention on the new software. We are not expecting any major new features in macOS Tahoe 26.6.Related Roundup: macOS TahoeRelated Forum: macOS TahoeThis article, "" first appeared on MacRumors.comDiscuss this article in our forums - 05:07 pmApple Seeds Second iOS 26.6 and iPadOS 26.6 Betas to Developers
Apple today seeded the second betas of upcoming iOS 26.6 and iPadOS 26.6 updates to developers for testing purposes, with the software coming three weeks after Apple seeded the first betas. Registered developers can download the betas from the Settings app on the iPhone or iPad by going to the General section and selecting Software Update. With iOS 27 set to launch in September, Apple is wrapping up work on iOS 26. We are not expecting any major new features in the iOS 26.6 update, and it will primarily focus on bug fixes and performance improvements. The update adds new wording around blocked contact limits, letting users know when they have exceeded the maximum number of blocked contacts. The update might also include a new anti-snatching feature that locks your iPhone if it's grabbed from your hand.Related Roundups: iOS 26, iPadOS 26Related Forum: iOS 26This article, "" first appeared on MacRumors.comDiscuss this article in our forums - 05:06 pmApple Releases Second watchOS 26.6, tvOS 26.6 and visionOS 26.6 Betas
Apple today provided developers with the second betas of upcoming watchOS 26.6, tvOS 26.6, and visionOS 26.6 betas for testing purposes. The software comes three weeks after Apple seeded the first betas. The software updates are available through the Settings app on each device, and because these are developer betas, a free developer account is required. There's no word on what's in the software as of yet. watchOS, tvOS, and visionOS often get few features in each new beta, with updates primarily focusing on bug fixes and performance improvements. Related Roundups: Apple TV, Apple Vision Pro, watchOS 26, watchOS 27Buyer's Guide: Apple TV (Don't Buy), Vision Pro (Neutral)Related Forums: Apple TV and Home Theater, Apple Vision Pro, Apple WatchThis article, "" first appeared on MacRumors.comDiscuss this article in our forums - 05:03 pmiOS 26.5.2 Coming Soon Alongside the iOS 26.6 and iOS 27 Betas
Apple is internally testing iOS 26.5.2, according to the MacRumors visitor logs, which have accurately confirmed many future iOS versions over the years. iOS 26.5.2 will almost certainly be a minor update that fixes software bugs and/or security vulnerabilities. We do not know exactly when the update will be released, but our best guess is that it will arrive this week or next week. iOS 26.5.1 was released earlier this month with a fix for a charging issue that impacted some iPhone 17, iPhone 17 Pro, iPhone 17 Pro Max, and iPhone Air units. That update was not released for any other iPhones, so it is reasonable that Apple is apparently planning a follow-up iOS 26.5.2 update that supports the full range of compatible models. Apple has a lot of software updates in the works, as iOS 26.5.2 will arrive alongside the iOS 26.6 beta and iOS 27 beta. The first iOS 26.6 beta did not introduce any major new features, as Apple is focused on the much bigger iOS 27 update with a more intelligent and personal version of Siri, design tweaks, and performance improvements.Related Roundups: iOS 26, iPadOS 26, iOS 27, iPadOS 27Related Forum: iOS 26This article, "" first appeared on MacRumors.comDiscuss this article in our forums - 03:38 pmPhilips Hue and WiZ Launch Sports Live Feature for the 2026 World Cup
Signify has launched Sports Live, a new feature for Philips Hue and WiZ smart lighting products that synchronizes lighting effects with live soccer match data in real time (via Hue Blog). The feature is rolling out now ahead of the 2026 FIFA World Cup. Sports Live uses live match data to trigger lighting changes at key in-game moments, including goals, yellow cards, and red cards, with the aim of making at-home viewing feel more immersive. Unlike traditional TV sync systems that rely on HDMI-based hardware to analyze on-screen content, Sports Live connects directly to live match data and responds to events as they occur, eliminating the need for additional synchronization hardware. During quieter periods, lights adapt to reflect a favorite team's colors, the leading team's colors, or a neutral white when the score is tied. Setup is handled through either the Philips Hue or WiZ mobile app. In the Hue app, the feature is found under the Sync tab, where users select a room or zone, which must include at least one color-capable light, and optionally choose favorite teams to receive match suggestions. Current games appear directly in the Sync tab, with a separate list available for upcoming fixtures. Sports Live automatically starts 15 minutes before kickoff once a match is selected, and a delay adjustment tool lets viewers sync lighting effects to their specific broadcast. After setup, users can still customize the default scene, brightness, and room. Any lights paired with Hue Sync Box take priority and will not be used for Sports Live. WiZ users can access the feature through the company's Wi-Fi platform without requiring a hub. The Philips Hue 5.69 app update that delivers Sports Live also introduces a new Bridge zone, which consolidates all devices and automations across an entire Hue Bridge into a single group on the home dashboard, with options to create scenes and hide or rearrange groups. The zone appears in the "Hidden" section by default and must be manually surfaced. Sports Live is compatible with existing Hue and WiZ entertainment features, including Hue Sync and WiZ Sync with TV, with the 2026 FIFA World Cup now underway in Mexico, Canada, and the U.S.Tag: Philips HueThis article, "" first appeared on MacRumors.comDiscuss this article in our forums - 01:52 pmApple Watch Ultra 3 Drops to $699.99 Ahead of Prime Day
Early Prime Day deals continue to trickle in as Amazon this week has brought back the best price of the year so far on the Apple Watch Ultra 3, taking $99 off the Black Titanium model with the Black Ocean Band. It's been nearly two months since we last tracked notable discounts on the Apple Watch Ultra 3, and right now only one model is on sale at $99 off. Note: MacRumors is an affiliate partner with some of these vendors. When you click a link and make a purchase, we may receive a small payment, which helps us keep the site running. There are discounts on a wide array of different Ultra 3 models, but they're only hitting around $50 off as of writing. For the Black Ocean Band model, Amazon provides an estimated delivery date before the end of the week, so it will arrive before Father's Day. $99 OFFApple Watch Ultra 3 for $699.99 You'll also find all-time low prices on the Apple Watch Series 11 on Amazon ahead of Prime Day, with $100 discounts across numerous models of the smartwatch. This sale includes a handful of GPS aluminum models on sale at record low prices. $100 OFFApple Watch Series 11 (42mm GPS) for $299.00 $100 OFFApple Watch Series 11 (46mm GPS) for $329.00 You can get the 42mm GPS Apple Watch Series 11 for $299.00, down from $399.00, and the 46mm GPS model for $329.00, down from $429.00. On Amazon, you'll find four of the 42mm GPS models and four of the 46mm GPS models on sale at these all-time low prices. If you're on the hunt for more discounts, be sure to visit our Apple Deals roundup where we recap the best Apple-related bargains of the past week. Deals Newsletter Interested in hearing more about the best deals you can find in 2026? Sign up for our Deals Newsletter and we'll keep you updated so you don't miss the biggest deals of the season! Related Roundup: Apple DealsThis article, "" first appeared on MacRumors.comDiscuss this article in our forums - 12:56 pmLeaker Warns iPhone 18 Pro New Colors May Face Same Durability Issues
A known Weibo leaker has reiterated that the iPhone 18 Pro will retain its aluminum alloy build, while issuing a specific warning that the new color options may be susceptible to paint peeling. In a new Weibo post, the leaker "Fixed Focus Digital" said the iPhone 18 Pro "will still feature an aluminum alloy build" and noted that heat dissipation is "indeed excellent." The leaker then added a pointed caveat: anyone unfamiliar with the durability problems that plagued the iPhone 17 Pro should "be careful about potential paint-peeling issues with the new color options." Fixed Focus Digital previously pointed out that surface chipping on the iPhone 17 Pro is a common complaint, and that users who seek recourse from Apple are often told they cannot claim it, with the company classifying the issue as an inherent characteristic of the aluminum alloy material and normal wear and tear. The leaker added at the time that the iPhone 18 Pro would "continue to utilize this same design approach" despite its weaknesses. The iPhone 17 Pro moved away from the titanium frames Apple used in its Pro lineup for the previous two years, adopting an anodized aluminum unibody design. Surface durability concerns surfaced almost immediately after launch. Reports suggested that Dark Blue and Cosmic Orange models appeared to scratch more easily than other finishes, with MacRumors forum users describing visible marks on in-store display units within days of availability. A scratch test by YouTuber JerryRigEverything added some nuance, finding that most of the anodized shell holds up well against everyday items like keys and coins, but pinpointing the camera plateau as a clear weak point where the raised, unchamfered edges chip and scratch easily. A separate issue emerged the following month, when a number of Cosmic Orange iPhone 17 Pro owners reported color shift, with the aluminum frame and camera plateau drifting toward a rose-gold or pink hue and in some cases prompting device replacements by Apple Support. Rumors point to four color options for the iPhone 18 Pro models: Dark Cherry, Light Blue, Dark Gray, and Silver. Dark Cherry is expected to serve as the signature new color, described as a deep, wine-like red that is considerably more muted than last year's Cosmic Orange. The iPhone 18 Pro is not expected to offer a black option for the second consecutive year, but the rumored gray option could come very close. The iPhone 18 Pro and iPhone 18 Pro Max are expected to be announced in September 2026, alongside the first foldable iPhone.Related Roundup: iPhone 18 ProTag: Fixed Focus DigitalThis article, "" first appeared on MacRumors.comDiscuss this article in our forums - 12:18 pmApple Adds Personalized Recommendations and New Marketing Tools to the App Store
Apple last week announced a series of new App Store features, including personalized app recommendations and expanded tools for developers to market their apps. The most visible change for users is Personalized Collections, a new discovery feature that surfaces app and game recommendations tailored to individual interests and behavior. Alongside each recommendation, new "App Notes" explain why a specific app is being surfaced. The collections can appear across the Apps, Games, and Search tabs, and will evolve over time as users' download and usage patterns change. Apple says the feature is now available in English in the U.S., with additional languages and regions to follow. For developers, Apple introduces Creative Assets, rich images and videos that can appear in a product page header and search results, going beyond standard screenshots and app preview clips. These assets can be used to highlight seasonal content, new features, or brand identity, and are compatible with custom product pages and Apple's existing product page optimization testing tools. A new Asset Library in App Store Connect gives developers a single place to manage all creative materials, with the ability to reuse assets across in-app events and promotions without re-uploading them. Developers can also submit assets for App Review approval independently of a full app update, which is useful for time-sensitive campaigns. Mac App Store apps and games no longer require Intel support, allowing developers to ship Apple silicon-only binaries. Apple is also allowing developers to group multiple In-App Purchases into a single App Review submission, streamlining the process. Apple also announced that the age rating questionnaire in App Store Connect will be updated in July to allow developers to indicate whether their app includes social media capabilities such as interacting with user-generated content through a social feed. This ties into new Time Allowances features coming in iOS 27, iPadOS 27, and macOS 27, which give parents more granular controls over how much time children spend in apps across categories including Entertainment, Games, and Social Media.Tag: App StoreThis article, "" first appeared on MacRumors.comDiscuss this article in our forums - 11:26 amThese Three Unannounced iOS 27 Features Are Still Coming
Apple developed more for iOS 27 than it revealed at WWDC last week, with three features already present in internal builds being deliberately withheld from the public announcement, Bloomberg's Mark Gurman reports. Writing in the latest edition of his "Power On" newsletter, Gurman says all three missing features are active in internal versions of Apple's operating systems on employee devices today, and each is expected to surface publicly at a later date. Modular Watch Face A new Modular watch face for Apple Watch was among the items Gurman had flagged as expected at WWDC but did not appear. Gurman's earlier claim that watchOS 27 would introduce new faces centered on a simplified take on the Modular Ultra design currently exclusive to the Apple Watch Ultra. Gurman now expects the new face to debut alongside new Apple Watch models this fall. Customizable Camera App A customizable Camera app for the iPhone, first reported by Gurman in May, also failed to appear at WWDC. The feature would let users rearrange camera controls as widgets along the top of the interface, choosing from options like flash, exposure, timer, depth of field, photo styles, and resolution. Gurman believes Apple is holding it back specifically for the iPhone 18 Pro, which is expected to bring the most significant camera hardware upgrade in several years. Siri Extensions The most notable omission is Extensions, a framework that would allow third-party AI chatbots beyond ChatGPT to integrate with Siri, Apple Intelligence, and features like Writing Tools and Image Playground. Gurman says underlying support for Extensions is already present and visible in the first iOS 27 developer beta, with both a dedicated settings panel and an App Store section built and waiting to be switched on. Apple has reportedly already held discussions with OpenAI, Anthropic, and Google about the framework, including details about an entitlement those companies would need to apply for. Gurman says he has "no doubt" the feature will arrive eventually. As for why the Extensions feature was kept out of the WWDC, Gurman offers four theories. Firstly, demonstrating strong AI interoperability could weaken Apple's ongoing argument against EU regulators. Secondly, announcing robust third-party chatbot support could have overshadowed Apple's own Siri overhaul. Thirdly, the threat of litigation from OpenAI may have persuaded Apple to avoid publicly stripping ChatGPT of its exclusive status at its developer conference. Finally, adding a range of external AI options would have further complicated Apple's messaging at a time when it already needed to explain its use of Google's AI models in Siri AI. Anyone running the first iOS 27 or macOS Golden Gate betas can already see a chatbot picker allowing users to switch between Siri and ChatGPT; Gurman says that list is expected to grow via the new developer framework and App Store section. The feature has reportedly been in active use inside Apple for months.Related Roundups: iOS 27, iPadOS 27Tags: Bloomberg, Mark Gurman, Siri AIThis article, "" first appeared on MacRumors.comDiscuss this article in our forums - 10:47 amApple Could Build an OpenClaw Competitor Eventually
Apple may eventually build a direct competitor to OpenClaw, an agentic AI system capable of autonomously operating software on behalf of the user, Bloomberg's Mark Gurman believes. Writing in his Power On newsletter, Gurman says he expects Apple to develop a system that could fully operate iPhone, iPad, and Mac software on the user's behalf. The prediction comes on the back of comments made by Apple's Siri engineering chief, Mike Rockwell, following last week's WWDC keynote. Rockwell appeared to leave the door open for Siri to expand beyond its current capabilities, describing the new engine underpinning the assistant as "a completely modern architecture" built with extensibility in mind: [An agent is] something that is operating on a loop of information coming in, making decisions, and then taking action. And ours is primarily request based today. But the underpinning architecture for Siri is a completely modern architecture, and so our ability to extend in the future is is very similar. Apple's SVP of Software Engineering, Craig Federighi, acknowledged the broader category but was measured in his framing of it, describing the space as experimental and saying that finding the right user experience remains the priority, while stopping short of ruling out Apple's eventual participation. Apple's upcoming Siri implementation is newly rebuilt on a large language model foundation, and remains a request-based system. Full computer-use agentic functionality of the kind offered by OpenClaw and similar tools from Google and Anthropic would represent a significant expansion beyond what Apple announced last week.Tags: Bloomberg, Mark Gurman, Siri AIThis article, "" first appeared on MacRumors.comDiscuss this article in our forums - 09:09 amUK to Ban Social Media for Under-16s Starting in 2027
The British government will introduce a ban on social media access for all users under 16 years of age, set to take effect in 2027. UK prime minister Keir Starmer announced the plans on Monday, calling the move "the right step for Britain" and the best way to keep children safe online. "This is not something I do lightly, and I will not present it as cost-free, as if social media has [brought no] benefits to young people, because clearly that is wrong," he said. "But government is always about choices, and it's clear to me that a total ban is the right choice."The plan goes further than a similar ban introduced in Australia. It will cover major platforms Snapchat, TikTok, YouTube, Instagram, Facebook, and X. An exhaustive list has not yet been released, but Starmer said the rules will apply to services "whose purpose is to enable social interaction and which allow users to post material." Messaging apps like WhatsApp and Signal are not covered by the ban, and most social media platforms already require children to be over 13 to create an account and use their services. Platforms will also be required to stop under-16s from livestreaming, including on gaming services, and to block functions that let strangers contact children. Those restrictions will be on by default for under-17s to avoid what the government called "a cliff-edge at 16." Meanwhile, "romantic companion" chatbots designed to simulate sexual relationships will have to enforce a minimum age of 18, and AI chatbots in general must restrict "intimate functionalities" for under-18s. "I am not prepared to compromise on the safety and happiness of our children, and that is why this ban must happen, and that is why this ban will happen," Starmer said. "Yes, it's hard – hard to legislate for, hard to regulate, hard to enforce. That's why we sought a wide range of views on this. That's why we listened to people, had a conversation, we looked carefully at the evidence, learned from countries like Australia that are taking similar steps."Starmer said he plans to pass legislation before Christmas, ahead of a spring 2027 rollout. The government said on Sunday that responses to its "Growing Up in the Online World" consultation showed that 90 percent of parents supported setting a minimum age of 16 for access to the apps.Tag: United KingdomThis article, "" first appeared on MacRumors.comDiscuss this article in our forums - Saturday June 13
- 10:13 pmAntonee Robinson Shows Off Unreleased Two-Tone Beats Over-Ear Headphones at the World Cup | MacRumorsAntonee Robinson Shows Off Unreleased Two-Tone Beats Over-Ear Headphones at the World Cup
Several players involved in the World Cup have been spotted wearing unreleased Beats over-ear headphones over the past couple of weeks, and U.S. men's national soccer team star Antonee Robinson is the latest to be spotted with them. Robinson was captured in a photo on his Instagram account wearing a two-tone version that appears to feature a white headband and housings but with royal blue ear cups. Previous versions of the headphones seen in photos of Yamine Lamal have featured only a single color, and it's unclear which color options are going to be available to the public, whether ear cups will be swappable to customize your own set, or if Robinson's set is a custom version produced only for him or a limited number of influencers. View this post on Instagram A post shared by Antonee Robinson (@antonee_jedi) The unreleased headphones first appeared in a U.S. Federal Communications Commission database last month, and it's clear Beats is undertaking a influencer seeding campaign throughout the World Cup to generate anticipation ahead of a public release, but the timing of availability remains unknown. It's also unclear whether these will be a new version of the existing Beats Studio Pro over-ear headphones or if they will be positioned as a new product.Tag: BeatsThis article, "" first appeared on MacRumors.comDiscuss this article in our forums - 03:00 pmHave One of These 16 Apple Devices? Software Support Ends This Fall
Apple will end software support for 16 devices this fall across four product lines, with the Apple Watch seeing the most sweeping cull in the product's history. The full extent of this year's software drops became clear with the announcements of macOS 27 Golden Gate, iPadOS 27, tvOS 27, and watchOS 27 at WWDC this week. The one bright spot is that iOS 27 features identical device support to iOS 26, with no iPhone models removed from the compatibility list, and the same goes for the HomePod. The Apple Watch sees the sharpest cuts. watchOS 27 drops the Series 6, Series 7, Series 8, Apple Watch Ultra (first generation), and Apple Watch SE (second generation) in a single wave, requiring an S9 or S10 chip. watchOS 26 had supported the same lineup as watchOS 11 before it, including the Series 6 and later, the SE (2nd generation) and later, and all Apple Watch Ultra models. Wiping out three launch generations at once is the biggest loss of latest-generation support for Apple Watch to date. The iPad lineup also sees an unusually aggressive set of cuts. iPadOS 27 raises the floor to the A14 Bionic chip or the M1 chip, dropping five models that still run iPadOS 26: The iPad Air (3rd generation), the iPad Pro 12.9-inch (3rd generation), the iPad Pro 11-inch (1st generation), the iPad (8th generation), and the iPad mini (5th generation). By comparison, iPadOS 26 cut only a single device from the iPadOS 18 list (the 7th generation iPad). macOS Golden Gate brings the era of Intel Macs to a close. The four remaining Intel machines supported by macOS Tahoe don't make the cut this year: The MacBook Pro (16-inch, 2019), MacBook Pro (13-inch, 2020, Four Thunderbolt 3 ports), iMac (2020), and Mac Pro (2019). Apple said last year that macOS Tahoe would be the final release for pre-Apple silicon Macs, and macOS 27 makes that official. Apple TV sees two models dropped with tvOS 27: The Apple TV HD from 2015 and the Apple TV 4K (1st generation) from 2017. Only the 2nd and 3rd generation Apple TV 4K models will receive the update. The full list of devices losing support for the latest software this fall is as follows: watchOS 27 Apple Watch Series 6 (2020) Apple Watch Series 7 (2021) Apple Watch Series 8 (2022) Apple Watch Ultra (1st generation, 2022) Apple Watch SE (2nd generation, 2022) iPadOS 27 iPad Air (3rd generation, 2019) iPad Pro 12.9-inch (3rd generation, 2018) iPad Pro 11-inch (1st generation, 2018) iPad (8th generation, 2020) iPad mini (5th generation, 2019) macOS 27 Golden Gate MacBook Pro (16-inch, 2019) MacBook Pro (13-inch, 2020, Four Thunderbolt 3 ports) iMac (2020) Mac Pro (2019) tvOS 27 Apple TV HD (2015) Apple TV 4K (1st generation, 2017) Owners of affected devices aren't entirely without options in the near term; Apple typically continues issuing security patches for the previous OS version for at least a year after it's superseded. For the latest features, though, newer hardware is the only path forward. Apple's new operating systems are expected to be released in September following a period of beta testing.Related Roundups: iOS 26, iPadOS 26, iOS 27, iPadOS 27, macOS Tahoe, macOS Golden Gate, watchOS 26, watchOS 27Related Forums: iOS 26, macOS Tahoe, Apple WatchThis article, "" first appeared on MacRumors.comDiscuss this article in our forums - 01:33 pmRecord AirPods Price Drops and a Rare Switch 2 Sale: This Week's Top Tech Deals
Multiple AirPods models hit record low prices this week, including the AirPods Pro 3 and AirPods Max 2. We're tracking these great discounts alongside an ultra rare discount on a new Switch 2 on Woot, plus a Summer sale at Sonos. Note: MacRumors is an affiliate partner with some of these vendors. When you click a link and make a purchase, we may receive a small payment, which helps us keep the site running. Nintendo Switch 2 What's the deal? Take $15 off Switch 2 with code NEW15 Where can I get it? Woot $15 OFFNintendo Switch 2 for $434.00 Woot has a rare deal on a brand new Nintendo Switch 2 console with the code NEW15, which can be used at checkout for customers making their first purchase on Woot. With this code you can take $15 off the base Switch 2 system, which isn't a lot, but given that these systems are rarely on sale (and are about to get a $50 price increase in September), this is a fairly notable sale. AirPods Pro 3 What's the deal? Take $70 off AirPods Pro 3 Where can I get it? Amazon Where can I find the original deal? Right here $70 OFFAirPods Pro 3 for $179.00 AirPods deals were in abundance this week, with the AirPods Pro 3 on sale at a new all-time low price on Amazon. You can still get this model for $179.00, down from $249.00. AirPods Max 2 What's the deal? Take $40 off AirPods Max 2 Where can I get it? Amazon Where can I find the original deal? Right here $50 OFFAirPods Max 2 for $499.00 Amazon this week has a record low price on the AirPods Max 2, now available for $499.00, down from $549.00. This sale is available in all five colors of the headphones. Sonos What's the deal? Take up to 25% off Sonos devices Where can I get it? Sonos Where can I find the original deal? Right here UP TO 25% OFFSonos Summer Sale Sonos this week kicked off a new summer sale, with big discounts aimed at dads and anyone else shopping ahead of Father's Day. This sale includes deals on Sonos smart speakers, sound bars, subwoofers, and more. If you're on the hunt for more discounts, be sure to visit our Apple Deals roundup where we recap the best Apple-related bargains of the past week. Deals Newsletter Interested in hearing more about the best deals you can find in 2026? Sign up for our Deals Newsletter and we'll keep you updated so you don't miss the biggest deals of the season! Related Roundup: Apple DealsThis article, "" first appeared on MacRumors.comDiscuss this article in our forums - 01:00 pmTop Stories: WWDC 2026 Recap With Siri AI, iOS 27, macOS Golden Gate, and More
WWDC 2026 has come to a close, and it brought a number of announcements with the headliner being the new Siri AI functionality available both in a standalone app and integrated throughout most of Apple's next-generation operating systems. iOS 27 brings a host of other improvements with an emphasis on performance, while macOS 27, known as macOS Golden Gate, delivers some Liquid Glass design refinements and more, so read on below for all of the details! Top Stories Everything Apple Announced at WWDC 2026 in 10 Minutes Apple held its WWDC 2026 keynote on Monday, introducing iOS 27, macOS 27, iPadOS 27, watchOS 27, visionOS 27, and tvOS 27. It took Apple around an hour and 15 minutes to walk through the major new features in the updates, but we have a quicker 10-minute recap for those who want the highlights. Our recap also includes links to all of our keynote-day article coverage, so it's a great place to catch up on all of the big announcements. And if you want a full summary of the keynote as it happened but don't want to watch the video, check out our live blog transcript. Hands-On With iOS 27's Siri AI The overarching theme of the WWDC 2026 keynote was the new Siri AI, which is integrated throughout most of Apple's operating systems and comes with a dedicated app. Access to Siri AI in the developer betas involves a waitlist, so it may take a bit before you can start trying it out, but we've already gone hands on for an early overview of how it works, so be sure to check out our video. Apple Announces macOS 27 Golden Gate With New Siri and 'Tons' of Refinements Early in Monday's keynote, Apple made one of the most anticipated announcements of the event, revealing that macOS 27 is named macOS Golden Gate. Much like Mac OS X Snow Leopard in 2009, Apple said it focused on improving macOS's performance and dozens of underlying technologies this year. Apple says macOS Golden Gate offers quicker AirDrop transfers, faster network file browsing, improved syncing in the Messages app, better Spotlight search suggestions, and other changes that make your Mac feel "more responsive than ever." "With improvements at the very core of the system and enhancements to apps and experiences you rely on every day, macOS feels better than ever," said Apple. Apple Says iOS 27 Adds These 12 New Features to Your iPhone iOS 27's key new feature is a more intelligent and personal version of Siri, but the changes go well beyond that. In a press release this week, Apple outlined additional enhancements coming across Apple Maps, Find My, Apple Wallet, Apple Music, and more. In fact, one super-dense slide briefly shown during Monday's keynote listed over 250 changes across iOS 27 and Apple's other updates. iPadOS 27 Drops Support for a Wave of iPads While iOS 27 is supported on all of the same iPhone models that work with iOS 26, the iPad lineup saw a significant cut in supported models this year. Each member of the iPad family saw the oldest model currently supporting iPadOS 26 dropped for iPadOS 27, meaning your iPad will need a minimum of an A14 or M1 chip in order to upgrade. The Apple Watch lineup saw even steeper cuts to the list of supported models, with the Apple Watch Series 6, Series 7, Series 8, Ultra 1, and SE 2 all not making the cut for watchOS 27. watchOS 27 also drops the Walkie-Talkie app that has been available on Apple Watch since watchOS 5 debuted in 2018. iPhone 17's 8GB Limit Costs It These Two Siri AI Features in iOS 27 In its Siri AI announcement during WWDC 2026, Apple introduced a more powerful on-device AI model which in addition to standard Siri AI functionality also powers two exclusive features: more expressive Siri voices and a major accuracy gain for systemwide dictation. Both require 12GB of unified memory. Among current iPhone models, that limits the more powerful AI model to the iPhone Air, iPhone 17 Pro, and iPhone 17 Pro Max, alongside iPad models with the M4 chip or later, Macs with M3 or later, and Apple Vision Pro with M5. That's right, the standard iPhone 17 misses out. Having only 8GB to its name – the minimum Apple Intelligence has required since launch – the base flagship model falls short of the new threshold. MacRumors Newsletter Each week, we publish an email newsletter like this highlighting the top Apple stories, making it a great way to get a bite-sized recap of the week hitting all of the major topics we've covered and tying together related stories for a big-picture view. So if you want to have top stories like the above recap delivered to your email inbox each week, subscribe to our newsletter!Tag: Top StoriesThis article, "" first appeared on MacRumors.comDiscuss this article in our forums - Friday June 12
- 10:30 pmiOS 27: All the New Safari Features
Safari is one of the apps that Apple focused on in iOS 27, and it includes multiple new Apple Intelligence features. From automatically organizing tab groups to custom extensions, Safari is getting useful new capabilities. Automatic Tab Organization Safari uses Apple Intelligence to organize your open tabs into relevant topics, grouping like concepts together to make it easier to browse your open tabs. If you're searching for a new couch while also planning a weekend trip, websites that you open for each topic are grouped together. Automatic sorting can be enabled by tapping on the icon with three lines in the upper right of the display while in tab view and turning on the Automatically Create Topics setting. This same Safari menu also lets you see all of the groups and filter by topic so you can open just the tabs related to a specific topic while avoiding the other tabs. There is a new "Resume Browsing" section of the Start Page that lets you continue browsing topics you recently closed or topics you have open on other devices. You can also group pages you've saved to Bookmarks and Reading List by topic. Custom Extensions You can use AI to create Safari Extensions in iOS 27 with Apple's new Create an Extension option. In the Safari settings accessible from the left of the URL bar, tapping into Create an Extension brings you to an interface where you can type in whatever you want an extension to do. Apple also includes suggestions in categories that include Boost Productivity, Improve Focus, Get Creative, and Develop and Design. Some of Apple's extension suggestions: Create a citation for the current webpage and copy it to my clipboard Create a 3-minute focus timer for the page Set the minimum font size to 14pt Turn the page into pirate speak Style websites like 90s websites with bold colors and type Every time I open a new tab, draw me a different flower Highlight and show the dimensions of webpage elements when I tap on them Enter the design mode for a website so that I can edit the contents Notify Me Safari can monitor a website for changes and alert you when new information is detected. Apple says it's useful for monitoring when concert tickets go on sale or watching for a product to be restocked. To use it, navigate to a website, then tap on the settings icon to the left of the URL bar, and choose the Notify Me option. You can type in what you want Safari to watch for and set a frequency and a time. At most, Safari will check websites once per day at a set time, with weekly and monthly checks also available. Passwords The Passwords app can use Safari to automatically change flagged weak and compromised passwords, turning them into strong passwords. The feature uses Apple Intelligence to automatically navigate to eligible websites, sign in, and update your password with a tap. Ask to Browse Apple added new parental controls in iOS 27, including an "Ask to Browse" feature that requires children to get parental approval before visiting a new website. Performance Improvements Apple says Safari's power efficiency has improved, so it will drain less battery. Web apps and start page content load faster, JavaScript handling is faster, and animations and graphics are smoother. Compatibility Safari features like automatic tab grouping, custom extensions, and custom notifications require Apple Intelligence. Apple Intelligence is available on the iPhone 15 Pro and later. Availability iOS 27 is in beta, and it is set to launch in fall 2026 alongside new iPhone models.Related Roundups: iOS 27, iPadOS 27This article, "" first appeared on MacRumors.comDiscuss this article in our forums - 09:05 pmHow to See Which Mac Apps Will Stop Working After macOS Golden Gate
Apple is phasing out support for Rosetta 2, which is a feature that allows Intel-based apps to run on Apple silicon Macs. Rosetta is going to stop working for most apps in macOS 28, and when that happens, apps that use it will stop working. Apple began warning customers and companies about the upcoming sunsetting of Rosetta with macOS Tahoe, and the warnings go even further in macOS Golden Gate. If you have apps that still use Rosetta, you'll get a warning every time you restart your Mac or open an Intel app. macOS Golden Gate also adds a new list where you can check which apps are going to stop working in the future. You can get to the list by going to Settings > General > About > Intel-Based apps and clicking on the "Details" option. The interface lists all of the apps that are going to stop working, giving Mac users plenty of time to contact app developers or find alternative apps. macOS Golden Gate does not install Rosetta automatically, so if you still have these outdated Intel apps, there will be a short installation when you try to open one for the first time after upgrading to Golden Gate. Authentication plugins and other pre-login utilities that require Rosetta fail to load in macOS Golden Gate because of the limitation. Apple designed Rosetta to help users and developers transition from Intel to Apple silicon, but Apple phased out the last Intel-based Mac years ago. Apple only sells Apple silicon Macs, and it is slowly ending support for Intel-based models. macOS Tahoe was the final version of macOS available for Intel Macs, and macOS Golden Gate requires a Mac with an Apple silicon chip.Related Roundup: macOS Golden GateThis article, "" first appeared on MacRumors.comDiscuss this article in our forums - 08:30 pmApple's Limited-Edition 2026 'Close Your Rings' Watch Band Revealed
Apple's employees who participated in the company's annual Close Your Rings Challenge have begun to receive a limited-edition Apple Watch band and a special enamel pin marking the 10th anniversary of the internal challenge. This year's band is a black Sport Loop with special lugs and an end piece that are colored similarly to the Apple Watch's Move, Exercise, and Stand rings. Given that these bands are limited to Apple's employees, rather than being sold directly to customers, they are relatively rare. You can keep track of hundreds of Apple Watch bands released since 2015 through the Bandbreite app on the iPhone.Related Roundup: Apple Watch 11Tag: Apple Watch BandsBuyer's Guide: Apple Watch (Caution)This article, "" first appeared on MacRumors.comDiscuss this article in our forums - 06:26 pmLast Chance: Apple Card Sign-Up Promo Can Earn You Free AirPods Pro 3
Time is running out on the Apple Card sign-up promo that began last month. For three more days, you can effectively receive AirPods Pro 3 for free when you sign up for a new Apple Card, but there are some strings attached. If you sign up for and are approved for an Apple Card for the first time, and use it to purchase AirPods Pro 3 by June 15, you can earn up to $250 in bonus cash back over a 10-month period if you meet minimum transaction requirements. Specifically, from July 1, 2026 through April 30, 2027, you can earn a bonus $25 cash back each month when you use your new Apple Card to make a minimum of 10 purchases of any amount ($0.01 or higher) that post to your account each month. The initial purchase of the AirPods Pro 3 does not count towards this requirement. AirPods Pro 3 are regularly priced at $249 in the U.S. — but are currently on sale on Amazon for an all-time low price of $179 — so this promotion effectively allows you to earn back the cost of the wireless earbuds over 10 months. If you already have an Apple Card, you are not eligible for this promotion. Apple's website outlines full terms and conditions for this promotion, so be sure to look over the fine print at the bottom of the page. Apple's credit card launched in 2019, and it remains available in the U.S. only. The card can be managed in the Apple Wallet app on an iPhone, has no annual fee, and offers up to 3% cash back (known as Daily Cash) on purchases paid out daily. Daily Cash amounts: 1% on purchases with the physical Apple Card, 2% on purchases with the digital Apple Card via Apple Pay, and 3% on purchases from Apple itself and select partners such as Nike, Walgreens, Ace Hardware, and Uber.Related Roundup: AirPods Pro 3Tags: AirPods Pro 3, Apple CardBuyer's Guide: AirPods Pro (Neutral)Related Forum: AirPodsThis article, "" first appeared on MacRumors.comDiscuss this article in our forums - 05:39 pmmacOS 27 Golden Gate Hands-On: Every Major New Feature
macOS 27 Golden Gate is in beta ahead of a fall release, and we thought we'd go over what's new for those who don't want to risk beta software on their Mac. macOS Golden Gate adds Siri AI, Liquid Glass updates, and multiple new Apple Intelligence features. Subscribe to the MacRumors YouTube channel for more videos. Siri on the Mac lives in Spotlight. Command + Space brings up a new Search or Ask interface for searching for files on the Mac or asking Siri a question. Siri is able to access data on the Mac, and it can answer the same general questions any chatbot can answer. The combination of personal context and world knowledge lets Siri do some things that are unavailable to other AI services like ChatGPT or Claude. Siri answers appear in Spotlight with an option to ask follow-up questions, but there's also a standalone Siri app where you can find all of your past Siri interactions. Siri is also integrated into the system for features like Write with Siri. Siri can compose emails and messages for you in your own writing style, check your grammar, or just give you general feedback on what you've written. Apple brought Visual Intelligence to the Mac, and it's available through the screenshot interface. When activated, you can select an area of your display that has something you want to know more about, and Siri can answer questions you have. In apps like Safari, you can select text or images, then ask Siri about your selection. Many of the same Visual Intelligence features that are on iPhone have carried over to the Mac, so Siri can identify plants and animals or even tell you the nutritional value of food in an image, which is a new feature this year. Apple Intelligence makes many of the built-in Mac apps better. Safari can group similar tabs together by subject, Passwords can automatically change weak passwords for you, Photos has new AI editing tools for changing framing and perspective, and Image Playground can generate photorealistic images. Shortcuts uses AI to build shortcuts for you based on natural language requests, Calendar supports natural language event input, Mail search is better than before with quick action suggestions, and the Messages app also supports AI suggestions for actions you might want to take, like inserting a photo to send to a friend. Apple updated Liquid Glass in macOS Golden Gate. There's a slider for adjusting overall system opacity, refraction and contrast have been improved, sidebars are unified with less wasted space, and Apple has removed many of the unnecessary icons from menu bars. If you have a Mac that can run Golden Gate, you're going to get Siri AI and the Apple Intelligence features. Apple Intelligence works on all Apple silicon Macs, and Golden Gate doesn't run on devices with an Intel chip. EU users can't use Siri AI on the iPhone and the iPad because Apple isn't making it available yet, but Siri AI is available on macOS in the European Union.Related Roundup: macOS Golden GateThis article, "" first appeared on MacRumors.comDiscuss this article in our forums - 04:41 pmiOS 27 and macOS 27 Golden Gate Expand Drawing Tools to Three Apps
The upcoming iOS 27 and macOS 27 Golden Gate updates expand drawing tools to more of Apple's built-in apps across the iPhone and Mac. In the Messages app on iOS 27, there is a new "Drawing" option in the app drawer, which can be opened by tapping the plus sign in the bottom-left corner. On older iOS versions, the Messages app once had a very basic drawing tool that was accessible by tapping a button on the keyboard in landscape orientation, but now Apple's complete set of Markup tools are available in the app. On the Mac, macOS 27 adds the Markup tools to the Notes and Freeform apps. iOS 27 and macOS 27 are currently available in developer beta. The updates are expected to be released to the general public in September.Related Roundups: iOS 27, iPadOS 27, macOS Golden GateThis article, "" first appeared on MacRumors.comDiscuss this article in our forums - 03:10 pmNotion Is Migrating to SwiftUI, Apple Confirms at WWDC
Apple this week confirmed that Notion is migrating its user interface to SwiftUI, citing the app's desire for greater performance and UI consistency than its existing web-based stack can deliver. Notion is a productivity app that combines notes, documents, databases, and project management tools in one place. Users can create pages containing text, tables, kanban boards, calendars, and more, and organize them in a flexible hierarchy. The announcement was made during Apple's SwiftUI segment during its Platforms State of the Union, where Notion was used as a flagship example of an app moving away from cross-platform and web technologies to native Apple frameworks. The callout was clearly deliberate; Notion is one of the most widely used productivity apps on the Mac, and has long been criticized for the sluggishness that comes with its Electron-based architecture. This is not Notion's first step toward native. Notion had already been gradually moving its iOS and Android apps away from web-based rendering in 2025, with most of the mobile experience now running natively except for the editor. The WWDC mention suggests that effort is now extending more substantially, with SwiftUI as the target framework. Apple also noted that agentic coding tools are making migrations like this more practical, saying "porting code to Swift has never been easier," pointing to AI-assisted development workflows lowering the barrier for teams considering a move away from cross-platform stacks. The SwiftUI session also covered a broad set of framework improvements. Apple is unifying SwiftUI, AppKit, and UIKit around a common foundation, so improvements made for Apple's own apps automatically benefit third-party developers. Nested stack layouts now resize up to twice as fast, state objects initialize lazily, and AsyncImage gains automatic HTTP caching. SwiftUI also gains reorderable containers for drag-to-reorder in any container type, swipe actions inside any container, and full-fidelity text selection on iOS. On macOS, Text now supports custom renderers, text vibrancy, and vertical text. Toolbar control is more granular, with a new visibilityPriority modifier, an overflow menu for deprioritized actions, and a topBarPinnedTrailing placement to anchor items to the trailing edge. A new document infrastructure adds first-class URL access for reading and writing to disk, and the ability to write only changed file portions on save.Related Roundup: WWDC 2026Tags: SwiftUI, WWDC 2026Related Forum: Apple, Inc and Tech IndustryThis article, "" first appeared on MacRumors.comDiscuss this article in our forums
- Tuesday June 02
- 06:00 pmIntroducing Microsoft Scout: Your always-on personal agent
Microsoft Scout is integrated across the Microsoft 365 apps you use every day, keeping it grounded in your flow of work. The post appeared first on Microsoft 365 Blog. - 05:00 pmAnnouncing the new Work IQ APIs
Work IQ is a new intelligence layer for Microsoft 365, designed to understand how work gets done across your organizations. The post appeared first on Microsoft 365 Blog. - 03:50 pmIntroducing the 2026 Apple Design Award winners
Join us in celebrating these extraordinary apps and games.Meet the 2026 Apple Design Award winners - Thursday May 28
- 07:00 pmIntroducing Microsoft 365 Business with Copilot: The new standard for small business | Office for MacIntroducing Microsoft 365 Business with Copilot: The new standard for small business
On July 1, we're introducing new Microsoft 365 SKUs with Copilot built-in, designed to fit into the way small businesses already work. The post appeared first on Microsoft 365 Blog. - 03:00 pmIntroducing a new design for Microsoft 365 Copilot
We’ve redesigned the Copilot app and how Copilot shows up across Microsoft 365 apps to better move with it: cleaner, faster, and in the flow of your work. The post appeared first on Microsoft 365 Blog. - Tuesday May 26
- 04:00 pmNew and improved: Computer-using agents, a new workflows experience, and real-time voice experiences | Office for MacNew and improved: Computer-using agents, a new workflows experience, and real-time voice experiences
Learn what’s new in Copilot Studio, May 2026: computer-using agents are now generally available, plus redesigned workflows and Work IQ extensibility. The post appeared first on Microsoft 365 Blog. - Monday May 11
- 05:25 pmNew and improved: Agent governance, intelligent workflows, and connected app experiences | Office for MacNew and improved: Agent governance, intelligent workflows, and connected app experiences
See what's new in Copilot Studio, April 2026: updates to workflows, increased control over agent operations, and an expanded agent usage estimator. The post appeared first on Microsoft 365 Blog. - Tuesday May 05
- 10:00 amMicrosoft 365 Copilot, human agency, and the opportunity for every organization
As AI and agents take on more of the execution, people have more agency than ever to unlock their ambition, direct what gets done, and own the outcomes. The post appeared first on Microsoft 365 Blog. - 10:00 amCopilot Cowork: From conversation to action across skills, integrations, and devices | Office for MacCopilot Cowork: From conversation to action across skills, integrations, and devices
Today, we’re announcing additional capabilities in Cowork to expand on what it can make possible for you. The post appeared first on Microsoft 365 Blog. - Friday May 01
- 03:00 pmMicrosoft Agent 365, now generally available, expands capabilities and integrations | Office for MacMicrosoft Agent 365, now generally available, expands capabilities and integrations
Microsoft Agent 365 helps you take control of agent sprawl as your control plane to observe, govern, and secure agents and their interactions. The post appeared first on Microsoft 365 Blog. - Thursday April 23
- 12:00 amCopilot’s agentic capabilities in Word, Excel, and PowerPoint are generally available | Office for MacCopilot’s agentic capabilities in Word, Excel, and PowerPoint are generally available
From first draft to final polish, Copilot acts as a true collaborator, taking action while you stay in control. The post appeared first on Microsoft 365 Blog.
Reviews & KoolTools
Unbreakable Style: The Best Hardshell Phone Cases on the Market
Are you looking for the ultimate protection for your smartphone? Hardshell phone cases are the answer. These cases are designed to withstand impact. They keep your phone safe from drops and scratches. In a world full of choices, how do you find the best? We have...
Plugable’s 5-in-1 USB Hub expands your MacBook Pro or MacBook Air’s connection options
The new 5-in-1 USB-C hub from Plugable turns two Mac laptop ports into (as the name implies) five, including Ethernet and more. Designed specifically for MacBook Pro and MacBook Air models, the hub (with the moniker AMS-5IN1E) fits flush against the host Mac and adds...
Community and More
MacTech Events and COVID
Due to the pandemic, the regional MacTech Pro events were pushed into 2021 — as early as reasonably possible. This means at best, early in the third quarter of the year. But depending on guidance and public health, it could be later than that. Once there are details,...
Software & Services Scanners
- Wednesday June 10
- 02:03 pmWho Runs the Ransomware Group ‘The Gentlemen?’
A cybercrime group known as The Gentlemen has emerged as the second most active ransomware gang by victim count, rapidly attracting a talented pool of hackers through an aggressive recruitment strategy that promises affiliates 90 percent of any ransom paid by victims. This post examines clues pointing to a real life identity for the administrator of The Gentlemen ransomware group. - Tuesday June 09
- 10:07 pmA Record-Breaking Patch Tuesday for June 2026
Microsoft today released software updates to plug nearly 200 security holes across its Windows operating systems and supported software, a record number of fixes for the company's monthly Patch Tuesday cycle. Nearly three dozen of those bugs earned Microsoft's most dire "critical" rating, and exploit code for at least three of the weaknesses is now publicly available. - Monday June 01
- 05:32 pmHackers Used Meta’s AI Support Bot to Seize Instagram Accounts
The Instagram accounts for the Obama White House and the Chief Master Sergeant of the U.S. Space Force were briefly defaced with pro-Iranian images and messages over the weekend, after instructions began circulating on Telegram showing how to trick Meta's "AI support assistant" bot into resetting account passwords. - Monday May 25
- 01:21 pmNetherlands Seizes 800 Servers, Arrests 2 for Aiding Cyberattacks
Authorities in the Netherlands have arrested the co-owners of two related Internet hosting companies for operating IT infrastructure used by Russia to carry out cyberattacks, influence operations and disinformation campaigns inside the European Union. The two men were the focus of a 2025 KrebsOnSecurity story about how their hosting companies had assumed control over the technical infrastructure of Stark Industries Solutions, an Internet service provider sanctioned last year by the EU as a frequent staging ground for cyber mischief from Russia's intelligence agencies. - Friday May 22
- 04:34 pmLawmakers Demand Answers as CISA Tries to Contain Data Leak
Lawmakers in both houses of Congress are demanding answers from the U.S. Cybersecurity & Infrastructure Security Agency (CISA) after KrebsOnSecurity reported this week that a CISA contractor intentionally published AWS GovCloud keys and a vast trove of other agency secrets on a public GitHub account. The inquiry comes as CISA is still struggling to contain the breach and invalidate the leaked credentials. - Thursday May 21
- 09:50 pmAlleged Kimwolf Botmaster ‘Dort’ Arrested, Charged in U.S. and Canada
Canadian authorities on Wednesday arrested a 23-year-old Ottawa man on suspicion of building and operating Kimwolf, a fast spreading Internet-of-Things botnet that enslaved millions of devices for use in a series of massive distributed denial-of-service (DDoS) attacks over the past six months. KrebsOnSecurity publicly named the suspect in February 2026 after the accused launched a volley of DDoS, doxing and swatting campaigns against this author and a security researcher. He now faces criminal hacking charges in both Canada and the United States. - Monday May 18
- 08:48 pmCISA Admin Leaked AWS GovCloud Keys on Github
Until this past weekend, a contractor for the Cybersecurity & Infrastructure Security Agency (CISA) maintained a public GitHub repository that exposed credentials to several highly privileged AWS GovCloud accounts and a large number of internal CISA systems. Security experts said the public archive included files detailing how CISA builds, tests and deploys software internally, and that it represents one of the most egregious government data leaks in recent history. - Tuesday May 12
- 09:46 pmPatch Tuesday, May 2026 Edition
Artificial intelligence platforms may be just as susceptible to social engineering as human beings, but they are proving remarkably good at finding security vulnerabilities in human-made computer code. That reality is on full display this month with some of the more widely-used software makers -- including Apple, Google, Microsoft, Mozilla and Oracle -- fixing near record volumes of security bugs, and/or quickening the tempo of their patch releases. - Friday May 08
- 02:58 amCanvas Breach Disrupts Schools & Colleges Nationwide
An ongoing data extortion attack targeting the widely-used education technology platform Canvas disrupted classes and coursework at school districts and universities across the United States today, after a cybercrime group defaced the service's login page with a ransom demand that threatened to leak data from 275 million students and faculty across nearly 9,000 educational institutions. - Tuesday May 05
- 04:16 pmVulnerability Summary for the Week of April 27, 2026
High Vulnerabilities PrimaryVendor -- Product Description Published CVSS Score Source Info Patch Info n/a-- OVMS3 3.3.005 Buffer overflow vulnerability in Open Vehicle Monitoring System 3 (OVMS3) 3.3.005. In canformat_gvret.cpp, the length field in GVRET binary data is not properly validated, allowing remote attackers to cause a denial of service or possibly execute arbitrary code via crafted GVRET frames. 2026-05-01 10 CVE-2026-37541 https://github.com/openvehicles/Open-Vehicle-Monitoring-System-3https://gist.github.com/sgInnora/f4ac66faeefe07a653ceeb3f58cdc381 tendacn[.]com-- W308R Tenda W308R v2 V5.07.48 contains a cookie session weakness vulnerability that allows unauthenticated attackers to modify DNS settings by exploiting insufficient session validation. Attackers can send GET requests to the goform/AdvSetDns endpoint with a crafted admin language cookie to change DNS servers and redirect user traffic to malicious sites. 2026-04-29 9.8 CVE-2018-25316 ExploitDB-44373VulnCheck Advisory: Tenda W308R v2 V5.07.48 Cookie Session Weakness DNS Change tendacn[.]com--W3002R Tenda W3002R/A302/W309R wireless routers version V5.07.64_en contain a cookie session weakness vulnerability that allows unauthenticated attackers to modify DNS settings by exploiting insufficient session validation. Attackers can send GET requests to the /goform/AdvSetDns endpoint with a crafted admin language cookie to change primary and secondary DNS servers, redirecting user traffic to malicious DNS servers. 2026-04-29 9.8 CVE-2018-25317 ExploitDB-44380VulnCheck Advisory: Tenda W3002R/A302/W309R V5.07.64_en Cookie Session Weakness DNS Change tendacn[.]com--FH303/A300 Tenda FH303/A300 firmware V5.07.68_EN contains a session weakness vulnerability that allows unauthenticated attackers to modify DNS settings by exploiting insufficient cookie validation. Attackers can send GET requests to the /goform/AdvSetDns endpoint with a crafted admin cookie to change DNS servers and redirect user traffic to malicious sites. 2026-04-29 9.8 CVE-2018-25318 ExploitDB-44381VulnCheck Advisory: Tenda FH303/A300 V5.07.68_EN Cookie Session Weakness DNS Change Weaver Network Co., Ltd.--E-office Weaver (Fanwei) E-office versions prior to 10.0_20221201 contain an unauthenticated arbitrary file upload vulnerability in the OfficeServer.php endpoint that allows remote attackers to upload malicious files by sending multipart POST requests with arbitrary filenames and disguised content types. Attackers can upload PHP webshells to the Document directory and execute them via HTTP GET requests to achieve remote code execution as the web server user. Exploitation evidence was first observed by the Shadowserver Foundation on 2022-10-10 (UTC). 2026-04-30 9.8 CVE-2022-50993 https://service.e-office.cn/knowledge/detail/5https://cn-sec.com/archives/1453025.htmlhttps://bbs.chaitin.cn/topic/37https://www.vulncheck.com/advisories/weaver-e-office-10-0-20221201-unauthenticated-arbitrary-file-read-via-xmlrpcservlet synway[.]net-- SMG Gateway Management Synway SMG Gateway Management Software contains an OS command injection vulnerability in the RADIUS configuration endpoint at /en/9-2radius.php where the radius_address POST parameter is split and interpolated directly into a sed command without sanitization. An unauthenticated remote attacker can inject arbitrary shell commands by submitting a POST request with crafted radius_address, radius_address2, shared_secret2, source_ip, timeout, or retry parameters along with save=1 and enable_radius=1 to achieve remote code execution. Exploitation evidence was first observed by the Shadowserver Foundation on 2025-07-11 (UTC). 2026-04-30 9.8 CVE-2025-71284 https://github.com/projectdiscovery/nuclei-templates/blob/main/http/vulnerabilities/synway/synwaysmg-radius-rce.yamlhttps://mrxn.net/jswz/synway-9-2radius-rce.htmlhttps://mp.weixin.qq.com/s/PyepoFSuQ63E3RnpQa9nsAhttps://www.synway.net/https://www.vulncheck.com/advisories/synway-smg-gateway-management-software-os-command-injection-via-radius-address Directorist Booking--Directorist Booking Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Directorist Booking allows SQL Injection.This issue affects Directorist Booking: from n/a before 3.0.2. 2026-04-27 9.3 CVE-2026-22336 https://patchstack.com/database/wordpress/plugin/directorist-booking/vulnerability/wordpress-directorist-booking-plugin-2-4-1-sql-injection-vulnerability?_s_id=cve Directorist--Directorist Social Login Incorrect Privilege Assignment vulnerability in Directorist Directorist Social Login allows Privilege Escalation.This issue affects Directorist Social Login: from n/a before 2.1.4. 2026-04-27 9.8 CVE-2026-22337 https://patchstack.com/database/wordpress/plugin/directorist-social-login/vulnerability/wordpress-directorist-social-login-plugin-2-1-1-privilege-escalation-vulnerability?_s_id=cve Milesight--MS-Cxx63-PD Specific firmware versions of Milesight AIOT cameras use SSL certificates with default private keys. 2026-04-27 9.8 CVE-2026-32644 https://www.cisa.gov/news-events/ics-advisories/icsa-26-113-03https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-113-03.jsonhttps://www.milesight.com/support/download/firmware n/a--Automotive Grade Linux (AGL) AGL app-framework-main thru 17.1.12 contains a Zip Slip path traversal vulnerability (CWE-22) combined with a TOCTOU race condition (CWE-367) in the widget installation flow. The is_valid_filename function in wgtpkg-zip.c validates ZIP entry names but does not check for dot notation directory traversal sequences it only blocks absolute paths. The zread extraction function uses openat(workdirfd, filename, O_CREAT) which resolves dot notation values relative to the work directory, allowing files to be written anywhere on the filesystem. Critically, in function install_widget in file wgtpkg-install.c, extraction via zread occurs BEFORE signature verification via check_all_signatures. Even if signature verification fails, the error cleanup (remove_workdir) only deletes the temporary work directory files written outside via path traversal persist permanently. 2026-05-01 9.8 CVE-2026-37531 https://gerrit.automotivelinux.org/gerrit/src/app-framework-mainhttps://gist.github.com/sgInnora/8526eedcfd826d05ef1fc45d8f405643 n/a-- cannelloni v2.0.0 Buffer overflow vulnerability in cannelloni v2.0.0 in CAN frame parsing in parser.cpp in function parseCANFrame, and decoder.cpp in function decodeFrame allowing remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via crafted CAN FD frames. 2026-05-01 9.8 CVE-2026-37539 https://github.com/mguentner/cannellonihttps://gist.github.com/sgInnora/f4ac66faeefe07a653ceeb3f58cdc381 Carlson Software--VASCO-B GNSS Receiver The Carlson VASCO-B GNSS Receiver lacks an authentication mechanism, allowing an attacker with network access to directly access and modify its configuration and operational functions without needing credentials. 2026-04-28 9.4 CVE-2026-3893 https://www.carlsonsw.com/support-and-training/https://www.cve.org/CVERecord?id=CVE-2026-3893https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-113-02.json Mersenne--Prime95 Prime95 29.4b8 contains a local buffer overflow vulnerability that allows attackers to execute arbitrary code by exploiting structured exception handling (SEH) mechanisms. Attackers can inject malicious payload through the optional proxy hostname field in the PrimeNet connection settings to trigger the overflow and execute system commands. 2026-04-29 8.4 CVE-2018-25299 ExploitDB-44649Official Product HomepageProduct ReferenceVulnCheck Advisory: Prime95 29.4b8 Local Buffer Overflow via SEH xataboost--XATABoost CMS XATABoost CMS 1.0.0 contains a union-based SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the id parameter. Attackers can send GET requests to news.php with malicious id values to extract sensitive database information. 2026-04-29 8.2 CVE-2018-25300 ExploitDB-44622Official Product HomepageVulnCheck Advisory: XATABoost CMS 1.0.0 SQL Injection via news.php Easy MPEG--Easy MPEG to DVD Burner Easy MPEG to DVD Burner 1.7.11 contains a structured exception handling (SEH) local buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying a malicious username string. Attackers can craft a payload containing junk data, SEH chain pointers, and shellcode that overwrites the SEH handler to redirect execution and run arbitrary commands like opening calc.exe. 2026-04-29 8.4 CVE-2018-25301 ExploitDB-44565Product ReferenceVulnCheck Advisory: Easy MPEG to DVD Burner 1.7.11 SEH Local Buffer Overflow Alloksoft--Allok Video to DVD Burner Allok Video to DVD Burner 2.6.1217 contains a stack-based buffer overflow vulnerability in the License Name field that allows local attackers to execute arbitrary code by triggering a structured exception handler (SEH) overwrite. Attackers can craft a malicious input string with 780 bytes of junk data followed by SEH chain pointers and shellcode, then paste it into the License Name field during registration to achieve code execution. 2026-04-29 8.4 CVE-2018-25303 ExploitDB-44518Official Product HomepageVulnCheck Advisory: Allok Video to DVD Burner 2.6.1217 Buffer Overflow SEH Filehippo--Free Download Manager Free Download Manager 2.0 Built 417 contains a local buffer overflow vulnerability in the URL import functionality that allows attackers to trigger a structured exception handler (SEH) chain exploitation. Attackers can craft a malicious URL file that, when imported through the File > Import > Import lists of downloads menu, causes a buffer overflow in the Location header response that overwrites the SEH chain and executes arbitrary code. 2026-04-29 8.4 CVE-2018-25304 ExploitDB-44499Product ReferenceVulnCheck Advisory: Free Download Manager 2.0 Built 417 Local Buffer Overflow SEH Sysgauge--SysGauge Pro SysGauge Pro 4.6.12 contains a local buffer overflow vulnerability in the Register function that allows local attackers to overwrite the structured exception handler by supplying a crafted unlock key. Attackers can inject shellcode through the Unlock Key field during registration to execute arbitrary code with application privileges. 2026-04-29 8.4 CVE-2018-25307 ExploitDB-44455VulnCheck Advisory: SysGauge Pro 4.6.12 Local Buffer Overflow SEH donmik--Buddypress Xprofile Custom Fields Type BuddyPress Xprofile Custom Fields Type 2.6.3 contains a remote code execution vulnerability that allows authenticated users to delete arbitrary files by manipulating unescaped POST parameters. Attackers can modify the field_hiddenfile and field_deleteimg parameters during profile editing to unlink files from the server. 2026-04-29 8.8 CVE-2018-25308 ExploitDB-44432Official Product HomepageVulnCheck Advisory: BuddyPress Xprofile Custom Fields Type 2.6.3 Remote Code Execution Alloksoft--WMV to AVI MPEG DVD WMV Converter Allok soft WMV to AVI MPEG DVD WMV Converter 4.6.1217 contains a buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying an oversized string in the License Name field. Attackers can craft a malicious input containing shellcode with structured exception handler (SEH) overwrite to bypass protections and execute code with application privileges. 2026-04-29 8.4 CVE-2018-25314 ExploitDB-44365Official Product HomepageProduct ReferenceVulnCheck Advisory: Allok soft WMV to AVI MPEG DVD WMV Converter 4.6.1217 Buffer Overflow Alloksoft--Video Joiner Alloksoft Video joiner 4.6.1217 contains a buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying a malicious string in the License Name field. Attackers can craft a payload with structured exception handler (SEH) overwrite and shellcode to achieve code execution when the application processes the license registration input. 2026-04-29 8.4 CVE-2018-25315 ExploitDB-44364Official Product HomepageProduct ReferenceVulnCheck Advisory: Alloksoft Video joiner 4.6.1217 Buffer Overflow via License Name marketingfire--Widget Options Advanced Conditional Visibility for Gutenberg Blocks & Classic Widgets The Widget Options - Advanced Conditional Visibility for Gutenberg Blocks & Classic Widgets plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 4.2.2 via the Display Logic feature. This is due to the plugin using eval() on user-supplied Display Logic expressions with an insufficient blocklist/allowlist that can be bypassed using array_map with string concatenation, combined with a lack of authorization enforcement on the extended_widget_opts_block attribute. This makes it possible for authenticated attackers, with Contributor-level access and above, to execute code on the server. The vulnerability was partially patched in version 4.2.0. 2026-05-02 8.8 CVE-2026-2052 https://www.wordfence.com/threat-intel/vulnerabilities/id/68023557-fc92-4cf6-96b4-405ff5a5fd5a?source=cvehttps://plugins.trac.wordpress.org/browser/widget-options/trunk/includes/widgets/gutenberg/gutenberg-toolbar.php#L843https://plugins.trac.wordpress.org/browser/widget-options/trunk/includes/extras.php#L495https://plugins.trac.wordpress.org/browser/widget-options/trunk/includes/extras.php#L534https://plugins.trac.wordpress.org/changeset/3481338/https://plugins.trac.wordpress.org/changeset/3514411/ Milesight--MS-Cxx63-PD An out-of-bounds memory access vulnerability exists in specific firmware versions of Milesight AIOT cameras. 2026-04-27 8.8 CVE-2026-20766 https://www.cisa.gov/news-events/ics-advisories/icsa-26-113-03https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-113-03.jsonhttps://www.milesight.com/support/download/firmware wclovers--WCFM Frontend Manager for WooCommerce The WCFM - Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 6.7.25 via the 'wcfm_delete_wcfm_customer' due to missing validation on the 'customerid' user controlled key. This makes it possible for authenticated attackers, with Vendor-level access and above, to delete arbitrary users, including Administrators. 2026-05-02 8.1 CVE-2026-2554 https://www.wordfence.com/threat-intel/vulnerabilities/id/21e397a4-0b32-4b13-a46b-c465acea0796?source=cvehttps://plugins.trac.wordpress.org/browser/wc-frontend-manager/tags/6.7.24/core/class-wcfm-customer.php#L386https://plugins.trac.wordpress.org/changeset/3483695/ opencats--OpenCATS OpenCATS prior to commit 3002a29 contains a PHP code injection vulnerability in the installer AJAX endpoint that allows unauthenticated attackers to execute arbitrary code by injecting PHP statements into the databaseConnectivity action parameter. Attackers can break out of the define() string context in config.php using a single quote and statement separator to inject malicious PHP code that persists and executes on every subsequent page load when the installation wizard remains incomplete. 2026-04-28 8.1 CVE-2026-27760 https://chocapikk.com/posts/2026/opencats-installer-rce/https://github.com/opencats/OpenCATS/pull/706https://github.com/opencats/OpenCATS/commit/3002a29f4c3cada1aa2c4f3d4ae4e189906606b6https://github.com/opencats/OpenCATS/blob/46e4727/lib/CATSUtility.php#L142-L172https://github.com/opencats/OpenCATS/blob/46e4727/modules/install/ajax/ui.php#L130https://www.vulncheck.com/advisories/opencats-php-code-injection-via-installer-ajax-endpoint Milesight--MS-Cxx63-PD Specific firmware versions of Milesight AIOT camera firmware contain hard-coded credentials. 2026-04-27 8.8 CVE-2026-27785 https://www.cisa.gov/news-events/ics-advisories/icsa-26-113-03https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-113-03.jsonhttps://www.milesight.com/support/download/firmware Cockpit--Cockpit CMS Cockpit CMS contains an authenticated remote code execution vulnerability in the /cockpit/collections/save_collection endpoint that allows authenticated attackers with collection management privileges to inject arbitrary PHP code into collection rules parameters. Attackers can inject malicious PHP code through rule parameters which is written directly to server-side PHP files and executed via include() to achieve arbitrary command execution on the underlying server. 2026-04-29 8.8 CVE-2026-34965 https://github.com/agentejo/cockpithttps://gist.github.com/thepiyushkumarshukla/64d2318518b17f529bc3ccb11fd5be90https://github.com/agentejo/cockpit/commits/494765e4f0fb9484f320aee0c6ee889b6fa789b9https://www.vulncheck.com/advisories/cockpit-cms-authenticated-remote-code-execution-via-collections n/a--(UDS) & OBD-II (On Board Diagnostics for Vehicles) miaofng/uds-c commit e506334e270d77b20c0bc259ac6c7d8c9b702b7a (2016-10-05) contains a stack buffer overflow in send_diagnostic_request. A 6-byte stack buffer (MAX_DIAGNOSTIC_PAYLOAD_SIZE=6) receives memcpy at offset 1+pid_length with payload_length bytes. MAX_UDS_REQUEST_PAYLOAD_LENGTH=7, so 1+2+7=10 exceeds buffer by 4 bytes. No bounds check on payload_length before memcpy. 2026-05-01 8.8 CVE-2026-37536 https://github.com/miaofng/uds-chttps://github.com/openxc/uds-chttps://gist.github.com/sgInnora/f4ac66faeefe07a653ceeb3f58cdc381 n/a--Open-SAE-J1939 (Daniel Martensson) collin80/Open-SAE-J1939 thru commit 744024d4306bc387857dfce439558336806acb06 (2023-03-08) contains an integer underflow leading to out-of-bounds write in Transport Protocol Data Transfer handling. At line 23: uint8_t index = data[0] - 1. When data[0] (sequence number from CAN frame) is 0, index underflows to 255. Subsequent write at tp_dt- >data[255*7 + i-1] reaches offset 1791, exceeding the MAX_TP_DT buffer (1785 bytes) by 6 bytes. 2026-05-01 8.1 CVE-2026-37537 https://github.com/DanielMartensson/Open-SAE-J1939https://github.com/collin80/Open-SAE-J1939https://gist.github.com/sgInnora/f4ac66faeefe07a653ceeb3f58cdc381 openampproject[.]org--OpenAMP v2025.10.0 OpenAMP v2025.10.0 ELF loader contains an integer overflow vulnerability in firmware image parsing. In elf_loader.c, it performs multiplication of two attacker-controlled 16-bit values from the ELF header without overflow checking. On 32-bit embedded systems (STM32MP1, Zynq, i.MX), large values can cause the product to wrap around to a small value. 2026-05-01 8.4 CVE-2026-37540 https://github.com/OpenAMP/open-amphttps://github.com/OpenAMP/open-amp/blob/main/lib/remoteproc/elf_loader.chttps://gist.github.com/sgInnora/f4ac66faeefe07a653ceeb3f58cdc381 n/a--MixPHP Framework 2.x Unsafe deserialization vulnerability in MixPHP Framework 2.x thru 2.2.17. The sync-invoke TCP server (Server.php:87) receives data from a TCP socket, passes it directly to OpisClosureunserialize(), then executes the result via call_user_func(). No authentication or signature verification exists on the TCP connection. An attacker with access to the localhost TCP port (server binds 127.0.0.1) can send a crafted serialized PHP closure to achieve arbitrary code execution. 2026-05-01 8.4 CVE-2026-37552 https://github.com/mix-php/mixhttps://github.com/mix-php/mix/blob/v2.2.17/src/sync-invoke/src/Server.phphttps://gist.github.com/sgInnora/fa46386840fe978a30d7e53c458f2975 benjaminprojas--WP Editor The WP Editor plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2.9.2. This is due to missing nonce verification in the 'add_plugins_page' and 'add_themes_page' functions. This makes it possible for unauthenticated attackers to overwrite arbitrary plugin and theme PHP files with attacker-controlled code via a forged request, granted they can trick a site administrator into performing an action such as clicking a link. 2026-05-01 8.8 CVE-2026-3772 https://www.wordfence.com/threat-intel/vulnerabilities/id/b1bc4a87-d5de-4d66-9cc5-802ef11f886c?source=cvehttps://plugins.trac.wordpress.org/browser/wp-editor/trunk/classes/WPEditorPlugins.php#L60https://plugins.trac.wordpress.org/browser/wp-editor/trunk/classes/WPEditorThemes.php#L103https://plugins.trac.wordpress.org/changeset/3480577/ chartbrew--chartbrew Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create charts. In version 4.9.0, Chartbrew allows authenticated users with access to one project to update or delete a SharePolicy record that belongs to a different project. The affected routes authorize the caller against the project in the URL path, but they never verify that policy_id belongs to that project. This permits cross-project modification of dashboard sharing rules, including visibility, password requirements, allowed parameters, and expiration settings. This issue has been patched in version 5.0.0. 2026-04-30 8.1 CVE-2026-40600 https://github.com/chartbrew/chartbrew/security/advisories/GHSA-pq8h-2h99-39xmhttps://github.com/chartbrew/chartbrew/releases/tag/v5.0.0 TRENDnet--TEW-821DAP A security vulnerability has been detected in TRENDnet TEW-821DAP 1.12B01. Impacted is the function auto_update_firmware of the component Firmware Udpate. The manipulation of the argument str leads to buffer overflow. The attack may be initiated remotely. The vendor explains: "That firmware version will only work on our hardware version v1.xR. We have already EOL that product 8 years ago and are no longer selling". This vulnerability only affects products that are no longer supported by the maintainer. 2026-05-02 8.8 CVE-2026-7607 VDB-360564 | TRENDnet TEW-821DAP Firmware Udpate auto_update_firmware buffer overflowVDB-360564 | CTI Indicators (IOB, IOC, IOA)Submit #806214 | Trendnet TEW-821DAP v1.12B01 CWE-120 Buffer Copy without Checking Size of Inputhttps://github.com/IOTRes/IOT_Firmware_Update/blob/main/Trendnet/TEW-821DAP_BO.md carazo--Import and export users and customers The Import and export users and customers plugin for WordPress is vulnerable to Privilege Escalation in all versions up to and including 2.0.8 via the `save_extra_user_profile_fields()` function. This is due to an incomplete blocklist that correctly restricts capability meta keys for the primary site (e.g., `wp_capabilities`, `wp_user_level`) but fails to block the equivalent meta keys for any other subsite in a WordPress Multisite network (e.g., `wp_2_capabilities`, `wp_2_user_level`), allowing these keys to pass the `in_array()` check and be written directly to user meta via `update_user_meta()`. This makes it possible for authenticated attackers, with Subscriber-level access and above, to escalate their privileges to Administrator on any subsite within the Multisite network by submitting a crafted profile update to `/wp-admin/profile.php`. Exploitation requires that an administrator has previously imported a CSV file containing multisite-prefixed capability column headers and has enabled the 'Show fields in profile?' option, which causes those keys to be stored in the `acui_columns` option and exposed as editable fields on the user profile page. 2026-05-02 8.8 CVE-2026-7641 https://www.wordfence.com/threat-intel/vulnerabilities/id/368cff00-6a86-443e-aec4-4115a229a3c1?source=cvehttps://plugins.trac.wordpress.org/browser/import-users-from-csv-with-meta/trunk/classes/columns.php#L221https://plugins.trac.wordpress.org/browser/import-users-from-csv-with-meta/tags/2.0.8/classes/columns.php#L221https://plugins.trac.wordpress.org/browser/import-users-from-csv-with-meta/trunk/classes/columns.php#L198https://plugins.trac.wordpress.org/browser/import-users-from-csv-with-meta/tags/2.0.8/classes/columns.php#L198https://plugins.trac.wordpress.org/browser/import-users-from-csv-with-meta/trunk/classes/helper.php#L150https://plugins.trac.wordpress.org/browser/import-users-from-csv-with-meta/tags/2.0.8/classes/helper.php#L150https://plugins.trac.wordpress.org/browser/import-users-from-csv-with-meta/trunk/classes/multisite.php#L21https://plugins.trac.wordpress.org/browser/import-users-from-csv-with-meta/tags/2.0.8/classes/multisite.php#L21https://plugins.trac.wordpress.org/browser/import-users-from-csv-with-meta/tags/2.0.6/classes/columns.php#L221https://plugins.trac.wordpress.org/browser/import-users-from-csv-with-meta/tags/2.0.6/classes/columns.php#L198https://plugins.trac.wordpress.org/browser/import-users-from-csv-with-meta/tags/2.0.6/classes/helper.php#L150https://plugins.trac.wordpress.org/browser/import-users-from-csv-with-meta/tags/2.0.6/classes/multisite.php#L21https://plugins.trac.wordpress.org/changeset/3515646 Cozmoslabs--Profile Builder Pro The Profile Builder Pro plugin for WordPress is vulnerable to PHP Object Injection in all versions up to and including 3.14.5. This is due to the use of PHP's maybe_unserialize() function on the attacker-controlled 'args' POST parameter within the wppb_request_users_pins_action_callback() AJAX handler, which lacked any nonce verification, type checking, or input validation before deserialization. Because the handler was registered with both wp_ajax_ and wp_ajax_nopriv_ hooks, it was reachable by completely unauthenticated users. This makes it possible for unauthenticated attackers to inject arbitrary PHP objects into application memory. 2026-05-02 8.1 CVE-2026-7647 https://www.wordfence.com/threat-intel/vulnerabilities/id/c7b897f5-f988-4515-83bc-456f041d7e2e?source=cvehttps://plugins.trac.wordpress.org/browser/profile-builder-pro/trunk/add-ons/user-listing/one-map-listing.php#L271https://plugins.trac.wordpress.org/browser/profile-builder-pro/tags/3.14.5/add-ons/user-listing/one-map-listing.php#L271https://plugins.trac.wordpress.org/browser/profile-builder-pro/trunk/add-ons/user-listing/one-map-listing.php#L13https://plugins.trac.wordpress.org/browser/profile-builder-pro/tags/3.14.5/add-ons/user-listing/one-map-listing.php#L13 Shenzhen Libituo Technology--LBT-T300-HW1 A flaw has been found in Shenzhen Libituo Technology LBT-T300-HW1 up to 1.2.8. This issue affects the function start_single_service of the component Web Management Interface. Executing a manipulation of the argument vpn_pptp_server/vpn_l2tp_server can lead to buffer overflow. The attack can be executed remotely. The vendor was contacted early about this disclosure but did not respond in any way. 2026-05-03 8.8 CVE-2026-7674 VDB-360827 | Shenzhen Libituo Technology LBT-T300-HW1 Web Management start_single_service buffer overflowVDB-360827 | CTI Indicators (IOB, IOC, IOA)Submit #800705 | Libtor Technology lbt-t300-hw1 closure, xreq). The NULL propagation chain through afb-context.c:110 (context- >credentials = afb_cred_addref(NULL)) and afb-cred.c:163 (returns NULL when cred is NULL) confirms that credentials are zeroed before the target API executes. The attacker controls both api and verb parameters via JSON input, allowing execution of any registered API with a NULL credential context. APIs that rely on context- >credentials for authorization decisions may fail open when receiving NULL credentials, enabling privilege escalation. This vulnerability was introduced in commit abbb4599f0b921c6f434b6bd02bcfb277eecf745 on 2018-02-14. 2026-05-01 7.8 CVE-2026-37525 https://gerrit.automotivelinux.org/gerrit/src/app-framework-binderhttps://gist.github.com/sgInnora/8526eedcfd826d05ef1fc45d8f405643 n/a--Automotive Grade Linux (AGL) afb-daemon v19.90.0 AGL app-framework-binder (afb-daemon) through v19.90.0 allows any local process to execute privileged supervision commands (Exit, Do, Sclose, Config, Trace, Debug, Token, slist) without authentication via the abstract Unix socket @urn:AGL:afs:supervision:socket. The on_supervision_call function in src/afb-supervision.c dispatches all 8 commands without any credential verification. The abstract socket has no DAC protection, as acknowledged in the official CAUTION comment in src/afs-supervision.h. This allows a low-privileged local process to kill the daemon (DoS via Exit command), execute arbitrary API calls (via Do command), close arbitrary user sessions (via Sclose command), or leak the entire global configuration (via Config command). The vulnerability was introduced in commit b8c9d5de384efcfa53ebdb3f0053d7b3723777e1 on 2017-06-29. 2026-05-01 7.8 CVE-2026-37526 https://gerrit.automotivelinux.org/gerrit/src/app-framework-binderhttps://gist.github.com/sgInnora/8526eedcfd826d05ef1fc45d8f405643 n/a--Automotive Grade Linux (AGL) aglservice v17.1.12 AGL agl-service-can-low-level thru 17.1.12 contains a heap buffer over-read in the isotp-c library. In isotp_continue_receive (receive.c:87-89), the payload_length for a Single Frame is extracted from a 4-bit nibble in the CAN frame data, yielding values 0-15. However, a standard CAN frame is only 8 bytes, with payload starting at data[1] (7 bytes available). When payload_length exceeds the available data (e.g., nibble=15 but only 7 payload bytes exist), memcpy(message.payload, &data[1], payload_length) reads up to 8 bytes past the end of the data buffer. 2026-05-01 7.1 CVE-2026-37532 https://gerrit.automotivelinux.org/gerrit/apps/agl-service-can-low-levelhttps://gist.github.com/sgInnora/8526eedcfd826d05ef1fc45d8f405643 n/a--Automotive Grade Linux (AGL) isotp-c openxc/isotp-c thru commit 5a5d19245f65189202719321facd49ce6f5d46ac (2021-08-09) contains an out-of-bounds read in the ISO-TP Single Frame receive handler, where the 4-bit payload length nibble is used directly as the memcpy size without validating it against the actual CAN data length. A malicious CAN frame with an oversized length nibble can cause memory reads beyond the buffer, allowing attackers to cause a denial of service, or gain sensitive information. 2026-05-01 7.1 CVE-2026-37535 https://github.com/openxc/isotp-chttps://github.com/openxc/isotp-c/blob/master/src/isotp/receive.chttps://gist.github.com/sgInnora/f4ac66faeefe07a653ceeb3f58cdc381 n/a-- Vanetza V2X v26.02 An issue was discovered in Vanetza V2X v26.02 allowing remote unauthorized attackers to cause a denial of service. The vulnerability exists in the GeoNetworking packet processing pipeline where OpenSSL exceptions from ECC point validation (invalid compressed point, point not on curve) are not properly caught by the Router::indicate() call chain. The openssl_wrapper.cpp check() function (line 19) throws openssl::Exception when OpenSSL operations fail. The parser's catch block in parse_secured() should catch these, but the exception escapes through subsequent processing stages (indicate_common, indicate_extended). This causes std::terminate, crashing the V2X receiver. 2026-05-01 7.5 CVE-2026-37554 https://github.com/riebl/vanetzahttps://github.com/riebl/vanetza/blob/master/vanetza/security/openssl_wrapper.cpphttps://github.com/riebl/vanetza/blob/master/vanetza/geonet/router.cpphttps://gist.github.com/sgInnora/45128ae15d52df7238680a8f2da8359f chartbrew--chartbrew Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create charts. In version 4.9.0, Chartbrew exposes public chart retrieval and export routes that only verify project-level public access and, for exports, a team-level export toggle. The routes do not verify whether the target chart is actually allowed on the public report or whether the governing SharePolicy permits public access. An unauthenticated attacker who knows a chart identifier in a public project can read or export chart data for charts that were intentionally hidden from the report. This issue has been patched in version 5.0.0. 2026-04-30 7.5 CVE-2026-40595 https://github.com/chartbrew/chartbrew/security/advisories/GHSA-mq7q-6xh6-5649https://github.com/chartbrew/chartbrew/releases/tag/v5.0.0 cyberhobo--Geo Mashup The Geo Mashup plugin for WordPress is vulnerable to Time-Based SQL Injection via the 'sort' parameter in all versions up to, and including, 1.13.18. This is due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. The `esc_sql()` function is applied but is ineffective in the `ORDER BY` context because the value is not enclosed in quotes. Additionally, while a `sanitize_sort_arg()` allowlist-based sanitizer was added in version 1.13.18, it is only applied in the AJAX code path (`sanitize_query_args()`) and not in the `render-map.php` or template tag code paths. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database via a time-based blind approach. 2026-05-02 7.5 CVE-2026-4060 https://www.wordfence.com/threat-intel/vulnerabilities/id/2fa5ae9a-532c-40f9-b70a-217f0f9cd473?source=cvehttps://plugins.trac.wordpress.org/browser/geo-mashup/trunk/geo-mashup-db.php#L1767https://plugins.trac.wordpress.org/browser/geo-mashup/trunk/geo-mashup-db.php#L1785https://plugins.trac.wordpress.org/browser/geo-mashup/trunk/render-map.php#L166https://plugins.trac.wordpress.org/changeset/3503627/ chartbrew--chartbrew Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create charts. In version 4.9.0, Chartbrew exposes POST /api/chart/:chart_id/query without authentication. The endpoint only checks team.allowReportRefresh and does not verify that the target chart belongs to a public report, that the project is public, or that sharing policy allows the operation. An unauthenticated attacker who knows a chart identifier can trigger a data refresh and retrieve the current data of private charts. This issue has been patched in version 5.0.0. 2026-04-30 7.5 CVE-2026-40601 https://github.com/chartbrew/chartbrew/security/advisories/GHSA-cpr6-mhgm-893whttps://github.com/chartbrew/chartbrew/releases/tag/v5.0.0 cyberhobo--Geo Mashup The Geo Mashup plugin for WordPress is vulnerable to Time-Based SQL Injection via the 'map_post_type' parameter in all versions up to, and including, 1.13.18. This is due to the `SearchResults` hook explicitly calling `stripslashes_deep($_POST)` which removes WordPress magic quotes protection, followed by the unsanitized `map_post_type` value being concatenated into an `IN(...)` clause without `esc_sql()` or `$wpdb- >prepare()`. The 'any' branch of the same code correctly applies `array_map('esc_sql', ...)`, but the else branch does not. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database via a time-based blind approach. Exploitation requires the Geo Search feature to be enabled in plugin settings. 2026-05-02 7.5 CVE-2026-4061 https://www.wordfence.com/threat-intel/vulnerabilities/id/cc3cf6c5-643e-49ca-b09c-bd7cfec328ee?source=cvehttps://plugins.trac.wordpress.org/browser/geo-mashup/trunk/geo-mashup-db.php#L1748https://plugins.trac.wordpress.org/browser/geo-mashup/trunk/php/Hooks/SearchResults.php#L39https://plugins.trac.wordpress.org/browser/geo-mashup/trunk/php/Search.php#L152https://plugins.trac.wordpress.org/changeset/3503627/ cyberhobo--Geo Mashup The Geo Mashup plugin for WordPress is vulnerable to Time-Based SQL Injection via the 'object_ids' and 'exclude_object_ids' parameters in all versions up to, and including, 1.13.18. This is due to insufficient escaping on the user supplied parameters and lack of sufficient preparation on the existing SQL query. The `esc_sql()` function is applied but is ineffective because the values are placed in an unquoted `IN(...)` / `NOT IN(...)` SQL context - `esc_sql()` only escapes quote characters and provides no protection against parenthesis or SQL keyword injection. Additionally, while a numeric-only sanitizer exists in `sanitize_query_args()`, it is only applied in the AJAX code path and not in the `render-map.php` or template tag code paths. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database via a time-based blind approach. 2026-05-02 7.5 CVE-2026-4062 https://www.wordfence.com/threat-intel/vulnerabilities/id/abc5ed0a-504f-4d8c-9662-a4c9f7c7acb8?source=cvehttps://plugins.trac.wordpress.org/browser/geo-mashup/trunk/geo-mashup-db.php#L1755https://plugins.trac.wordpress.org/browser/geo-mashup/trunk/geo-mashup-db.php#L1759https://plugins.trac.wordpress.org/browser/geo-mashup/trunk/render-map.php#L166https://plugins.trac.wordpress.org/changeset/3503627/ n/a--libssh2 A security vulnerability has been detected in libssh2 up to 1.11.1. The impacted element is the function userauth_password of the file src/userauth.c. Such manipulation of the argument username_len/password_len leads to integer overflow. The attack may be launched remotely. The name of the patch is 256d04b60d80bf1190e96b0ad1e91b2174d744b1. A patch should be applied to remediate this issue. 2026-05-01 7.3 CVE-2026-7598 VDB-360555 | libssh2 userauth.c userauth_password integer overflowVDB-360555 | CTI Indicators (IOB, IOC, IOA)Submit #805564 | libssh2 Shell interface, gaining root-level access to the device. 2026-04-29 4.3 CVE-2018-25310 ExploitDB-44387Vulnerability AdvisoryVulnCheck Advisory: VideoFlow Digital Video Protection DVP 10 Authenticated Remote Code Execution gnu--wget2 wget2 accepts a server certificate with incorrect Key Usage (KU) or Extended Key Usage (EKU). If the attackers compromise a certificate (with the associated private key) issued for a different purpose, they may be able to reuse it for TLS server authentication. 2026-04-29 4.8 CVE-2026-1858 https://www.tenable.com/security/research/tra-2026-37 wazuh--wazuh Wazuh is a free and open source platform used for threat prevention, detection, and response. From version 1.0.0 to before version 4.14.4, a heap-based out-of-bounds WRITE occurs in GetAlertData, resulting in writing a NULL byte exactly 1 byte before the start of the buffer allocated by strdup. Due to unsigned integer underflow and pointer arithmetic wrapping, the write lands at offset -1 from the buffer, corrupting heap metadata. A malicious actor can potentially leverage this issue through a compromised agent to cause denial of service or heap corruption by injecting a specially crafted alert into the alerts log file monitored by wazuh-logcollector. This issue has been patched in version 4.14.4. 2026-04-29 4.4 CVE-2026-26204 https://github.com/wazuh/wazuh/security/advisories/GHSA-j4c7-hwjw-8857https://github.com/wazuh/wazuh/releases/tag/v4.14.4 Oracle Corporation--Oracle Linux An unprivileged attacker can craft a user-space process with a malicious ELF binary containing an out-of-range sh_link field. When root-level dtrace attaches to -- or instruments -- that process (via dtrace -p , pid probes, or USDT), the ELF parser reads heap memory beyond the allocated section cache array without any bounds check. This results in an uninitialized/out-of-bounds heap read that can cause a NULL pointer dereference crash of the dtrace process (DoS), or -- depending on heap layout -- a read-then-use of a garbage pointer controlled by adjacent allocations, providing a foothold toward further exploitation in a privileged context. 2026-05-01 4.4 CVE-2026-35233 Oracle Advisory n/a-- V2Board v1.7.4 SQL Injection via ORDER BY clause in V2Board thru 1.7.4. In app/Http/Controllers/Admin/UserController.php, the sort parameter from user input is passed directly to User::orderBy($sort, $sortType) without validation. An authenticated admin can sort users by any database column including password, remember_token, and other sensitive fields, enabling information disclosure through ordering analysis. 2026-05-01 4.9 CVE-2026-37505 https://github.com/v2board/v2boardhttps://gist.github.com/sgInnora/1330e1a82caa79906eec55eeff2c99b9 nextlevelbuilder--ui-ux-pro-max-skill A vulnerability has been found in nextlevelbuilder ui-ux-pro-max-skill up to 2.5.0. Affected by this issue is the function data.get of the file .claude/skills/design-system/scripts/generate-slide.py of the component Slide Generator. Such manipulation leads to cross site scripting. The attack may be performed from remote. The exploit has been disclosed to the public and may be used. The project was informed of the problem early through a pull request but has not reacted yet. 2026-05-01 4.3 CVE-2026-7596 VDB-360549 | nextlevelbuilder ui-ux-pro-max-skill Slide Generator generate-slide.py data.get cross site scriptingVDB-360549 | CTI Indicators (IOB, IOC, TTP, IOA)Submit #805510 | nextlevelbuilder ui-ux-pro-max-skill 2.5.0 Slide Generator Multiple Stored XSShttps://github.com/nextlevelbuilder/ui-ux-pro-max-skill/issues/247https://github.com/nextlevelbuilder/ui-ux-pro-max-skill/pull/274https://github.com/nextlevelbuilder/ui-ux-pro-max-skill/ n/a--Open5GS A vulnerability has been found in Open5GS up to 2.7.6. Affected is an unknown function of the file src/amf/gmm-handler.c of the component AMF. The manipulation of the argument reg_type leads to denial of service. The attack is possible to be carried out remotely. Upgrading to version 2.7.7 is able to address this issue. The identifier of the patch is ebc66942b6f8f1fab2d640e71cf4e9f1a423b426. It is advisable to upgrade the affected component. 2026-05-02 4.3 CVE-2026-7601 VDB-360558 | Open5GS AMF gmm-handler.c denial of serviceVDB-360558 | CTI Indicators (IOB, IOC, TTP, IOA)Submit #805675 | Open5GS v.2.7.6 Denial of Servicehttps://github.com/open5gs/open5gs/issues/4321https://github.com/open5gs/open5gs/commit/ebc66942b6f8f1fab2d640e71cf4e9f1a423b426https://github.com/open5gs/open5gs/releases/tag/v2.7.7https://github.com/open5gs/open5gs/ itsourcecode--Courier Management System A vulnerability was determined in itsourcecode Courier Management System 1.0. Affected is an unknown function of the file /edit_user.php. Executing a manipulation of the argument ID can lead to sql injection. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized. 2026-05-02 4.7 CVE-2026-7612 VDB-360569 | itsourcecode Courier Management System edit_user.php sql injectionVDB-360569 | CTI Indicators (IOB, IOC, TTP, IOA)Submit #806275 | itsourcecode Courier Management System V1.0 SQL Injectionhttps://github.com/ltranquility/submit/issues/12https://itsourcecode.com/ ChatGPTNextWeb--NextChat A flaw has been found in ChatGPTNextWeb NextChat up to 2.16.1. This impacts an unknown function of the file Next.js of the component API Endpoint. Executing a manipulation can lead to permissive cross-domain policy with untrusted domains. The attack may be launched remotely. The exploit has been published and may be used. The project was informed of the problem early through an issue report but has not responded yet. 2026-05-02 4.3 CVE-2026-7643 VDB-360755 | ChatGPTNextWeb NextChat API Endpoint Next.js cross-domain policyVDB-360755 | CTI Indicators (IOB, IOC, IOA)Submit #806833 | ChatGPTNextWeb NextChat 2.16.1 Permissive CORS Wildcard Policyhttps://github.com/ChatGPTNextWeb/NextChat/issues/6756https://github.com/ChatGPTNextWeb/NextChat/ n/a--crmeb_java A vulnerability was detected in crmeb_java up to 1.3.4. This vulnerability affects unknown code of the file crmeb/crmeb-service/src/main/java/com/zbkj/service/service/impl/UploadServiceImpl.java of the component Admin Upload. Performing a manipulation of the argument model results in unrestricted upload. Remote exploitation of the attack is possible. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. 2026-05-03 4.7 CVE-2026-7673 VDB-360826 | crmeb_java Admin Upload UploadServiceImpl.java unrestricted uploadVDB-360826 | CTI Indicators (IOB, IOC, TTP, IOA)Submit #800684 | crmeb crmeb_java 1.3.4 Unrestricted Uploadhttps://fx4tqqfvdw4.feishu.cn/docx/EgMOdHyq6oyxhux5vpJcr5cgnAf?from=from_copylink kerwincui--FastBee A vulnerability was found in kerwincui FastBee up to 1.2.1. The affected element is the function ToolController.download of the file springboot/fastbee-open-api/src/main/java/com/fastbee/data/controller/ToolController.java of the component Tool Download Endpoint. The manipulation of the argument fileName results in path traversal. The attack may be performed from remote. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way. 2026-05-03 4.3 CVE-2026-7676 VDB-360829 | kerwincui FastBee Tool Download Endpoint ToolController.java ToolController.download path traversalVDB-360829 | CTI Indicators (IOB, IOC, TTP, IOA)Submit #800723 | kerwincui FastBee ≤ 1.2.1 Path Traversalhttps://fx4tqqfvdw4.feishu.cn/docx/Yv1gdAzFpoHCUUxDdKSculR4nKf?from=from_copylink jsbroks--COCO Annotator A weakness has been identified in jsbroks COCO Annotator up to 0.11.1. Affected is an unknown function of the file backend/webserver/api/datasets.py of the component Data Endpoint. Executing a manipulation of the argument folder can lead to path traversal. The attack can be launched remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way. 2026-05-03 4.3 CVE-2026-7680 VDB-360833 | jsbroks COCO Annotator Data Endpoint datasets.py path traversalVDB-360833 | CTI Indicators (IOB, IOC, TTP, IOA)Submit #801150 | jsbroks COCO Annotator 0.11.1 Absolute Path Traversalhttps://github.com/natanmorette-thoropass/thoropass-vuln-research-program/tree/main/2026/Path%20Traversal%20via%20Dataset%20Folder%20Parameter AMTT--Hotel Broadband Operation System A vulnerability was determined in AMTT Hotel Broadband Operation System 1.0. Affected is an unknown function of the file /manager/card/cardhand_submit.php. This manipulation of the argument ID causes sql injection. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way. 2026-05-03 4.7 CVE-2026-7697 VDB-360866 | AMTT Hotel Broadband Operation System cardhand_submit.php sql injectionVDB-360866 | CTI Indicators (IOB, IOC, TTP, IOA)Submit #803272 | Anmei Century (Beijing) Technology Co., Ltd. Hotel Broadband Operation System v1.0 SQL Injectionhttps://github.com/testnet0/testnet/issues/74 Telegram--Desktop A security vulnerability has been detected in Telegram Desktop up to 6.7.5. This vulnerability affects the function RequestButton of the file Telegram/SourceFiles/boxes/url_auth_box.cpp of the component Bot API. The manipulation of the argument login_url leads to null pointer dereference. It is possible to initiate the attack remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way. 2026-05-03 4.3 CVE-2026-7701 VDB-360870 | Telegram Desktop Bot API url_auth_box.cpp RequestButton null pointer dereferenceVDB-360870 | CTI Indicators (IOB, IOC, IOA)Submit #804341 | Telegram Telegram Desktop - Thursday April 30
- 02:04 pmAnti-DDoS Firm Heaped Attacks on Brazilian ISPs
A Brazilian tech firm that specializes in protecting networks from distributed denial-of-service (DDoS) attacks has been enabling a botnet responsible for an extended campaign of massive DDoS attacks against other network operators in Brazil, KrebsOnSecurity has learned. The firm's chief executive says the malicious activity resulted from a security breach and was likely the work of a competitor trying to tarnish his company's public image.
- Monday June 08
- 06:18 pmApple unveils next generation of Apple Intelligence, Siri AI, and more
Today, Apple previewed its upcoming software releases that will deliver the next generation of Apple Intelligence and introduce Siri AI. - 06:17 pmApple Intelligence brings powerful AI capabilities into everyday experiences
Apple unveils the next generation of Apple Intelligence, integrating powerful AI capabilities into iPhone, iPad, and Mac for more personal and helpful everyday experiences. - 06:17 pmApple Intelligence brings powerful AI capabilities into everyday experiences
Apple unveils the next generation of Apple Intelligence, integrating powerful AI capabilities into iPhone, iPad, and Mac for more personal and helpful everyday experiences. - 06:15 pmApple introduces Siri AI, a profoundly more capable and personal assistant
powered by Apple Intelligence, with personal context, world knowledge, and onscreen awareness. - 06:15 pmApple introduces Siri AI, a profoundly more capable and personal assistant
powered by Apple Intelligence, with personal context, world knowledge, and onscreen awareness. - 06:14 pmApple previews new child safety features
that give parents greater control over their kids’ content, communication, and device access time. - 06:14 pmApple previews new child safety features
that give parents greater control over their kids’ content, communication, and device access time. - 06:13 pmApple expands App Store capabilities to help developers grow and reach new users
New App Store capabilities will give developers more flexibility to market their apps, acquire users, and manage subscriptions. - 06:13 pmApple expands App Store capabilities to help developers grow and reach new users
New App Store capabilities will give developers more flexibility to market their apps, acquire users, and manage subscriptions. - Thursday June 04
- 03:59 pmApple and Major League Baseball announce July “Friday Night Baseball” schedule
Apple and Major League Baseball have announced the July schedule for “Friday Night Baseball” on Apple TV, featuring several marquee matchups. - Tuesday June 02
- 05:00 pmApple reveals winners of the 2026 Apple Design Awards
Apple announces the winners of the 2026 Apple Design Awards, recognizing outstanding app and game design across six categories. - Thursday May 28
- 12:59 pmCherokee language learners bridge generations with iPad and Mac
Through its Community Education Initiative, Apple has been working with OCU and Cherokee Nation to equip young learners with iPad and Mac. - Thursday May 21
- 01:59 pmApple TV to air first major live pro sports event shot on iPhone 17 Pro
On May 23, Apple TV presents a special MLS match captured on iPhone 17 Pro — a first for a major professional live sports event. - Tuesday May 19
- 03:59 pmApple Sports expands to more than 90 new countries and regions
Apple Sports is now available in more than 170 countries and regions, including more than 90 new markets. - 03:59 pmApple Sports expands to more than 90 new countries and regions
Apple Sports is now available in more than 170 countries and regions, including more than 90 new markets.
- Monday June 15
- 1 hour agoError connecting to Facebook Apps
Status: InvestigatingWe are receiving customer reports that Zap workflows using Facebook Lead Ads or Facebook Pages are returning the following error when Zap runs occur. "An unknown error occurred." Users are also unable to connect to existing or create new app connections, with those connections instantly expiring. We're looking into the issue to identify its root cause. - Sunday June 14
- 11:49 pmLHR (London) on 2026-06-15
THIS IS A SCHEDULED EVENT Jun 15, 01:00 - 07:30 UTC Jun 14, 23:28 UTC Scheduled - We will be performing scheduled maintenance in LHR (London) datacenter on 2026-06-15 between 01:00 and 07:30 UTC.Traffic might be re-routed from this location, hence there is a possibility of a slight increase in latency during this maintenance window for end-users in the affected region. For PNI / CNI customers connecting with us in this location, please make sure you are expecting this traffic to fail over elsewhere during this maintenance window as network interfaces in this datacentre may become temporarily unavailable.You can now subscribe to these notifications via Cloudflare dashboard and receive these updates directly via email, PagerDuty and webhooks (based on your plan): https://developers.cloudflare.com/notifications/notification-available/#cloudflare-status. - 06:06 amIntermittent errors loading Zapier Templates pages
Status: InvestigatingWe’re investigating an issue causing intermittent errors when loading Zapier Templates pages "Zapier Templates pages": https://zapier.com/templates, including some template detail/category pages (for example, Lead Management). You may see pages fail to load or display server errors intermittently. Our team is actively working to identify and resolve the root cause. We will provide updates as soon as we have more information. If you require any assistance, please contact our Support Team: https://zapier.com/app/get-helpAffected components Website (Degraded performance) - Saturday June 13
- 11:43 pmIntermittent Slow Cache Responses
Jun 13, 23:43 UTC Identified - The cause of this issue has been identified and a fix is being implemented. Jun 13, 23:22 UTC Investigating - We are currently investigating an issue where a small number of requests are experiencing higher than expected latency on cache HITs. - Friday June 12
- 03:03 pmCloudflare Dashboard and Cloudflare API service issues
Jun 12, 15:03 UTC Monitoring - A fix has been implemented and we are monitoring the results. Jun 12, 14:56 UTC Identified - The issue has been identified and a fix is being implemented. Jun 12, 14:27 UTC Investigating - Cloudflare is investigating issues with Cloudflare Dashboard and related APIs. These issues do not affect the serving of cached files via the Cloudflare CDN or other security features at the Cloudflare Edge. Customers using the Dashboard / Cloudflare APIs are impacted as requests might fail and/or errors may be displayed. - 11:14 amWaiting Room analytics showing a drop in number of active users
Jun 12, 11:14 UTC Update - The issue has been identified, and a fix is being implemented. Jun 12, 10:55 UTC Identified - We are currently investigating an issue where Waiting Room analytics are showing a drop in the number of active users. - 09:30 amTurnstile loading issues
Jun 12, 09:30 UTC Resolved - During the timeframe between 09:46 to 16:27UTC today on June 12th users may have observed Turnstile not loading or solving the challenges. This is now resolved. - 03:03 amTemplates not loading
Status: InvestigatingWe are currently investigating an issue affecting the Templates feature on our platform. Users may experience errors when attempting to load or select templates. Our team is actively working to identify and resolve the root cause. We will provide updates as soon as we have more information. If you require any assistance, please contact our Support Team: https://zapier.com/app/get-help Thank you for your patience.Affected components Website (Degraded performance) - 02:33 amDelayed webhook Zap runs
Status: ResolvedBetween June 9 and June 11, some webhook-triggered Zap runs experienced processing delays of up to 48 hours. All delayed events have since been processed successfully, and no data was lost during this delay. We are implementing additional safeguards to prevent recurrence. If you experience any ongoing issues, contact Support: https://zapier.com/app/get-help Thank you for your patience.Affected components Instant Triggers (Operational) - 01:17 amNetwork Performance Issues in Brisbane, QLD, Australia – (BNE)
Jun 12, 01:17 UTC Identified - Cloudflare is investigating issues with network performance in Brisbane, QLD, Australia - (BNE). We are working to analyze and mitigate this problem. More updates to follow shortly. - 12:45 amElevated number of TTFB in PHL
Jun 12, 00:45 UTC Resolved - Between 00:45 - 00:55 UTC customers reaching Philadelphia, PA may have experienced an elevated number of Time To First Byte. - 12:19 amMIA (Miami) on 2026-06-12
THIS IS A SCHEDULED EVENT Jun 12, 06:00 - 11:30 UTC Jun 11, 23:50 UTC Scheduled - We will be performing scheduled maintenance in MIA (Miami) datacenter on 2026-06-12 between 06:00 and 11:30 UTC.Traffic might be re-routed from this location, hence there is a possibility of a slight increase in latency during this maintenance window for end-users in the affected region. For PNI / CNI customers connecting with us in this location, please make sure you are expecting this traffic to fail over elsewhere during this maintenance window as network interfaces in this datacentre may become temporarily unavailable.You can now subscribe to these notifications via Cloudflare dashboard and receive these updates directly via email, PagerDuty and webhooks (based on your plan): https://developers.cloudflare.com/notifications/notification-available/#cloudflare-status. - Thursday June 11
- 06:12 pmBilling Invoice UI issue
Jun 11, 18:12 UTC Investigating - Cloudflare is investigating a Billing Dashboard UI issue. Some customers are not able to see their invoices for the last 3 months. The invoices exist in our system and automatic billing is not impacted. - 04:26 pmKUL (Kuala Lumpur) on 2026-06-11
THIS IS A SCHEDULED EVENT Jun 11, 17:00 - 18:00 UTC Jun 11, 16:14 UTC Scheduled - We will be performing scheduled maintenance in KUL (Kuala Lumpur) datacenter on 2026-06-11 between 17:00 and 18:00 UTC.Traffic might be re-routed from this location, hence there is a possibility of a slight increase in latency during this maintenance window for end-users in the affected region. For PNI / CNI customers connecting with us in this location, please make sure you are expecting this traffic to fail over elsewhere during this maintenance window as network interfaces in this datacentre may become temporarily unavailable.You can now subscribe to these notifications via Cloudflare dashboard and receive these updates directly via email, PagerDuty and webhooks (based on your plan): https://developers.cloudflare.com/notifications/notification-available/#cloudflare-status. - 03:39 pmWorkers Observability query failures
Jun 11, 15:39 UTC Identified - Cloudflare has identified an issue impacting some customers where Workers Observability queries may be returning errors. We are working to mitigate the impact. - 02:20 pmAUS (Austin) on 2026-06-12
THIS IS A SCHEDULED EVENT Jun 12, 09:00 - 11:00 UTC Jun 11, 14:15 UTC Scheduled - We will be performing scheduled maintenance in AUS (Austin) datacenter on 2026-06-12 between 09:00 and 11:00 UTC.Traffic might be re-routed from this location, hence there is a possibility of a slight increase in latency during this maintenance window for end-users in the affected region. For PNI / CNI customers connecting with us in this location, please make sure you are expecting this traffic to fail over elsewhere during this maintenance window as network interfaces in this datacentre may become temporarily unavailable.You can now subscribe to these notifications via Cloudflare dashboard and receive these updates directly via email, PagerDuty and webhooks (based on your plan): https://developers.cloudflare.com/notifications/notification-available/#cloudflare-status. - 04:30 amTitle: Network issues in Saskatoon and Calgary
Jun 11, 04:30 UTC Resolved - Cloudflare is investigating issues with network performance in Saskatoon and Calgary between 04:20 - 04:45 UTC. The incident is now resolved - 03:15 amTXL (Berlin) on 2026-06-11
Jun 11, 03:15 UTC In progress - Scheduled maintenance is currently in progress. We will provide updates as necessary. Jun 11, 03:06 UTC Scheduled - We will be performing scheduled maintenance in TXL (Berlin) datacenter on 2026-06-11 between 03:15 and 06:00 UTC.Traffic might be re-routed from this location, hence there is a possibility of a slight increase in latency during this maintenance window for end-users in the affected region. For PNI / CNI customers connecting with us in this location, please make sure you are expecting this traffic to fail over elsewhere during this maintenance window as network interfaces in this datacentre may become temporarily unavailable.You can now subscribe to these notifications via Cloudflare dashboard and receive these updates directly via email, PagerDuty and webhooks (based on your plan): https://developers.cloudflare.com/notifications/notification-available/#cloudflare-status. - 12:23 amNRT (Tokyo) on 2026-06-11
THIS IS A SCHEDULED EVENT Jun 11, 15:00 - 23:00 UTC Jun 11, 00:18 UTC Scheduled - We will be performing scheduled maintenance in NRT (Tokyo) datacenter on 2026-06-11 between 15:00 and 23:00 UTC.Traffic might be re-routed from this location, hence there is a possibility of a slight increase in latency during this maintenance window for end-users in the affected region. For PNI / CNI customers connecting with us in this location, please make sure you are expecting this traffic to fail over elsewhere during this maintenance window as network interfaces in this datacentre may become temporarily unavailable.You can now subscribe to these notifications via Cloudflare dashboard and receive these updates directly via email, PagerDuty and webhooks (based on your plan): https://developers.cloudflare.com/notifications/notification-available/#cloudflare-status. - Wednesday June 10
- 11:46 pmImage Resizing on R2 issues
Jun 10, 23:46 UTC Identified - The issue has been identified and a fix is being implemented. Jun 10, 23:44 UTC Investigating - Cloudflare has identified an issue where some customers may experience failures using Image Resizing with R2. We are working to analyze and mitigate this problem. More updates to follow shortly.
Showcase
Kool Tools: Pegasus3 Symply Edition
Promise Technology and Symply have launched the Pegasus3 Symply Edition, the next generation of the Pegasus desktop RAID storage system. The new system combines 40 Gb/s Thunderbolt 3 performance with Symply's storage management suite. The Pegasus3 Symply Edition is a...
Kool Tools: TimeCache
The Rolling Stones told us that time was on our side (or at least Mick Jagger's side). That's not always true, but with TimeCache (http://www.pandaware.com/timecache/index.html) for Mac OS X from PandaWare we can at least keep track of it. With TimeCache -- now...
Kool Tools: PDF Editor for Mac
Editing PDF files on Mac OS X can be tough, but a product from AnyBizSoft, a Wondershare company focused on PDF solutions, simplifies the process. PDF Editor for Mac, integrates AnyBizSoft's existing PDF to Word conversion technology. It not only enables users to edit...
Kool Tools: Aunsoft’s Video Converter for the Mac
Aunsoft Video Converter for Mac (http://www.aunsoft.com/video-converter-mac/) is a US$35 Mac video converting tool you can use to convert just about any type of video for use on a variety of Apple devices. What's more, it also boasts a several editing features. This...
Scanners “By The Numbers”
- Monday June 15
- 02:32 pmApple Watch Ultra 3 Drops to $699 at Amazon — Early Prime Day Deal
Amazon is now offering the Apple Watch Ultra 3 for $699, a $100 discount from Apple’s $799 MSRP and the lowest price currently available among major Apple retailers. This marks one of the first Prime Day deals on the Ultra 3 model and a solid opportunity for buyers who were waiting for a price drop. The Ultra line is designed for durability, long battery life, and advanced fitness and outdoor features, making it a strong option for more active users. View the deal here at Amazon, and compare all Apple Watch prices on our Apple Watch Price Tracker, updated daily. - 02:22 pmDeal Alert! AirPods Pro 3 now only $169 at Walmart, $80 off MSRP!
Walmart has dropped Apple's AirPods Pro 3 to just $169, down from Apple's standard $249 MSRP. That's a substantial $80 discount and the lowest price we've seen on Apple's flagship wireless earbuds. Check Walmart's current pricing here. Walmart also makes the deal easy to take advantage of, offering online ordering with free shipping or free local store pickup where available.For the latest sales and deals, see our AirPods Price Tracker, updated daily. - Friday June 12
- 12:22 pmAmazon & B&H cut prices on all 16″ M5 Pro and M5 Max MacBook Pro models, take up to $250 off MSRP | MacPrices.netAmazon & B&H cut prices on all 16″ M5 Pro and M5 Max MacBook Pro models, take up to $250 off MSRP
Amazon and B&H are currently offering discounts across Apple's entire standard 16-inch M5 Pro and M5 Max MacBook Pro lineup. Sale prices start at $2529 for the 24GB/1TB M5 Pro model and reach as much as $250 off Apple's MSRP on several configurations. Shop Amazon's 16-inch MacBook Pro deals here. While Amazon offers fast shipping and broad inventory availability, B&H remains competitive on pricing and includes free 1–2 day shipping to most U.S. addresses. Browse B&H's current deals here. For the latest sales and deals, see our 16" MacBook Pro Price Tracker, updated daily. - 12:00 pmApple Watch SE 3 models back on sale for $30 off MSRP, prices start at $219
Amazon has Apple Watch SE 3 models back on sale for $30 off MSRP, shipping included: - 40mm Apple Watch SE GPS: $219, $30 off MSRP - 44mm Apple Watch SE GPS: $249, $30 off MSRP - 40mm Apple Watch SE GPS + 5G: $249, $30 off MSRP - 44mm Apple Watch SE GPS + 5G: $299, $30 off MSRP These are the lowest sale prices currently available for Apple Watch SE 3 models. For the latest prices & deals, keep an eye on our Apple Watch Price Tracker, updated daily. - Wednesday June 10
- 11:37 amDeal Alert! AirPods Pro 3 Drop to Just $179 at Walmart
Walmart has dropped Apple's AirPods Pro 3 to just $179, down from Apple's standard $249 MSRP. That's a substantial $70 discount and one of the lowest prices we've seen on Apple's flagship wireless earbuds. Check Walmart's current pricing here. Walmart also makes the deal easy to take advantage of, offering online ordering with free shipping or free local store pickup where available.For the latest sales and deals, see our AirPods Price Tracker, updated daily. - Monday June 08
- 12:24 pmAirPods Deals Compared: Amazon vs Walmart vs Apple Pricing Right Now, Take $50 off MSRP! | MacPrices.netAirPods Deals Compared: Amazon vs Walmart vs Apple Pricing Right Now, Take $50 off MSRP!
Amazon and Walmart are currently offering discounts across Apple's AirPods lineup, with deals available on AirPods 4, AirPods 4 with ANC, AirPods Pro 3, and AirPods Max 2. Depending on the model, savings range from about $30 to $50 below Apple's standard MSRP. Shop AirPods deals at Amazon. Walmart is matching many of the same prices while also offering online ordering with free shipping or free local store pickup (where available). Browse Walmart's AirPods deals here. For the latest sales and deals, see our AirPods Price Tracker, updated daily. - Sunday June 07
- 12:54 pmSunday Sale: Amazon has Apple Watch Series 11 models on sale for $100 off MSRP
Amazon is offering a $100 discount on most Apple Watch Series 11 models right now. Shipping is free: - 42mm Apple Watch Series 11 GPS: $299, save $100 - 46mm Apple Watch Series 11 GPS: $329, save $100 - 42mm Apple Watch Series 11 GPS + 5G: $399, save $100 - 46mm Apple Watch Series 11 GPS + 5G: $429, save $100 These are the lowest prices available for Apple Watch Series 11 models. For the latest prices & sales, keep an eye on our Apple Watch Price Tracker, updated daily. - Thursday June 04
- 12:26 pmApple’s 11″ A16 iPad Still $50 Off at Amazon & Walmart
Amazon and Walmart are both offering Apple’s 11-inch A16 iPad for $299, down from Apple’s standard $349 MSRP. That’s a straightforward $50 discount on Apple’s newest entry-level iPad, and still one of the easiest Apple deals to recommend right now. Check Amazon’s pricing here. Walmart is matching the same $299 price and also gives buyers the option to order online for free shipping or free local store pickup where available. Browse Walmart’s current pricing here.For the latest sales and deals, see our iPad Price Tracker, updated daily. - Wednesday June 03
- 01:56 pmAmazon Cuts Prices on Standard 16″ M5 Max MacBook Pros by $250
Amazon is now offering $250 discounts on Apple's two standard 16-inch M5 Max MacBook Pro Space Black configurations, bringing both models well below Apple's MSRP. The 36GB RAM/2TB SSD model has dropped to $3649, while the 48GB RAM/2TB SSD version is now available for $4149. Check current Amazon pricing here. Both configurations are seeing the same discounts, making this one of the simplest MacBook Pro sales we've seen recently. For the latest sales and deals, see our 16" MacBook Pro Price Tracker, updated daily. - Monday June 01
- 01:58 pmMidnight 15″ M5 MacBook Air Drops to $1099 at Amazon & B&H
Amazon and B&H are both offering the Midnight 15-inch M5 MacBook Air with 16GB RAM and a 512GB SSD for just $1099, down from Apple’s standard $1299 MSRP. That works out to a clean $200 discount, making this one of the best prices currently available on Apple’s larger MacBook Air. Check Amazon's pricing here. B&H is matching the same $1099 sale price while also offering free 1–2 day shipping to most U.S. addresses. Browse current B&H pricing here. For the latest sales and deals, see our 15" MacBook Air Price Tracker, updated daily. - 01:43 pmMacBook Neo Remains Fully In Stock at Walmart — Free Shipping & Pickup Available
The MacBook Neo continues to remain fully in stock across Walmart’s online store, making it one of the easiest places right now to buy Apple’s newest budget-friendly MacBook without waiting through extended delivery windows. Check current MacBook Neo availability at Walmart. Walmart is currently offering fast free shipping on MacBook Neo orders, along with free local store pickup (where available). While stock levels continue to fluctuate at other Apple retailers, Walmart remains one of the few places where the full Neo lineup appears broadly available.For the latest sales and deals, see our MacBook Neo Price Tracker, updated daily. - 01:39 pmSpace Black 14″ M5 MacBook Pro Drops to $1499 at Amazon
Amazon is now offering Apple's Space Black 14-inch M5 MacBook Pro (16GB RAM/1TB SSD) for just $1499, down from Apple's standard $1699 MSRP. That works out to a clean $200 discount, making it one of the best prices currently available on Apple's newest 14-inch MacBook Pro. Check current Amazon pricing here. What's especially notable is that this discount applies to the upgraded 1TB configuration rather than a lower-storage model. Combined with Amazon's fast shipping, it's one of the stronger MacBook Pro deals available right now.For the latest sales and deals, see our 14" MacBook Pro Price Tracker, updated daily.
- Monday June 15
- 11:53 amRefurb Apple iPad 10.9″ 64GB WiFi Tablet (2022) for $223 + free shipping
At eBay, get the refurb Apple iPad 10.9″ 64GB WiFi Tablet (2022) for $223. It’s the best deal we’ve seen for this model in any condition. Shipping is free. A 1-year Allstate warranty is included. Buy Now at eBay Features 10.9″ IPS LED display, 2360×1640 resolution 64GB storage, 4GB RAM Wi-Fi connectivity, Bluetooth iOS operating […] - Saturday June 13
- 05:31 amRefurbished 24-inch iMac Apple M4 Chip with 10-Core CPU and 10-Core GPU, Gigabit Ethernet- Yellow – G1EL0LL/A – $1,609.00 | Refurb TrackerRefurbished 24-inch iMac Apple M4 Chip with 10-Core CPU and 10-Core GPU, Gigabit Ethernet- Yellow – G1EL0LL/A – $1,609.00
Refurbished 24-inch iMac Apple M4 Chip with 10-Core CPU and 10-Core GPU, Gigabit Ethernet- Yellow – G1EL0LL/A $1,609.00 Originally released October 2024 24-inch 4.5K Retina display 16GB unified memory 1TB SSD 12MP Center Stage camera with support for Desk View Four Thunderbolt 4 ports Gigabit Ethernet Product page on the Apple Store… - 05:31 amRefurbished 24-inch iMac Apple M4 Chip with 10-Core CPU and 10-Core GPU, Gigabit Ethernet- Purple – G1K76LL/A – $2,289.00 | Refurb TrackerRefurbished 24-inch iMac Apple M4 Chip with 10-Core CPU and 10-Core GPU, Gigabit Ethernet- Purple – G1K76LL/A – $2,289.00
Refurbished 24-inch iMac Apple M4 Chip with 10-Core CPU and 10-Core GPU, Gigabit Ethernet- Purple – G1K76LL/A $2,289.00 Originally released October 2024 24-inch 4.5K Retina display 32GB unified memory 2TB SSD 12MP Center Stage camera with support for Desk View Four Thunderbolt 4 ports Gigabit Ethernet Product page on the Apple Store… - 02:28 amRefurbished 24-inch iMac Apple M4 Chip with 10-Core CPU and 10-Core GPU, Gigabit Ethernet- Pink – FWV53LL/A – $1,439.00 | Refurb TrackerRefurbished 24-inch iMac Apple M4 Chip with 10-Core CPU and 10-Core GPU, Gigabit Ethernet- Pink – FWV53LL/A – $1,439.00
Refurbished 24-inch iMac Apple M4 Chip with 10-Core CPU and 10-Core GPU, Gigabit Ethernet- Pink – FWV53LL/A $1,439.00 $1,699.00 −15% Originally released October 2024 24-inch 4.5K Retina display 16GB unified memory 512GB SSD 12MP Center Stage camera with support for Desk View Four Thunderbolt 4 ports Gigabit Ethernet Product page on the Apple Store… - 01:32 amRefurbished 24-inch iMac Apple M4 Chip with 10-Core CPU and 10-Core GPU, Gigabit Ethernet- Pink – G1K65LL/A – $1,949.00 | Refurb TrackerRefurbished 24-inch iMac Apple M4 Chip with 10-Core CPU and 10-Core GPU, Gigabit Ethernet- Pink – G1K65LL/A – $1,949.00
Refurbished 24-inch iMac Apple M4 Chip with 10-Core CPU and 10-Core GPU, Gigabit Ethernet- Pink – G1K65LL/A $1,949.00 Originally released October 2024 24-inch 4.5K Retina display 32GB unified memory 1TB SSD 12MP Center Stage camera with support for Desk View Four Thunderbolt 4 ports Gigabit Ethernet Product page on the Apple Store… - 01:02 amRefurbished 24-inch iMac Apple M4 Chip with 10-Core CPU and 10-Core GPU, Gigabit Ethernet- Orange – G1K80LL/A – $1,779.00 | Refurb TrackerRefurbished 24-inch iMac Apple M4 Chip with 10-Core CPU and 10-Core GPU, Gigabit Ethernet- Orange – G1K80LL/A – $1,779.00
Refurbished 24-inch iMac Apple M4 Chip with 10-Core CPU and 10-Core GPU, Gigabit Ethernet- Orange – G1K80LL/A $1,779.00 Originally released October 2024 24-inch 4.5K Retina display 24GB unified memory 1TB SSD 12MP Center Stage camera with support for Desk View Four Thunderbolt 4 ports Gigabit Ethernet Product page on the Apple Store… - 12:01 amRefurbished 24-inch iMac Apple M4 Chip with 10-Core CPU and 10-Core GPU, Gigabit Ethernet- Orange – G1EW0LL/A – $1,609.00 | Refurb TrackerRefurbished 24-inch iMac Apple M4 Chip with 10-Core CPU and 10-Core GPU, Gigabit Ethernet- Orange – G1EW0LL/A – $1,609.00
Refurbished 24-inch iMac Apple M4 Chip with 10-Core CPU and 10-Core GPU, Gigabit Ethernet- Orange – G1EW0LL/A $1,609.00 Originally released October 2024 24-inch 4.5K Retina display 16GB unified memory 1TB SSD 12MP Center Stage camera with support for Desk View Four Thunderbolt 4 ports Gigabit Ethernet Product page on the Apple Store… - Friday June 12
- 11:00 pmRefurbished 24-inch iMac Apple M4 Chip with 10-Core CPU and 10-Core GPU, Gigabit Ethernet, Nano-texture glass – Orange – G1K81LL/A – $2,119.00 | Refurb TrackerRefurbished 24-inch iMac Apple M4 Chip with 10-Core CPU and 10-Core GPU, Gigabit Ethernet, Nano-texture glass – Orange – G1K81LL/A – $2,119.00
Refurbished 24-inch iMac Apple M4 Chip with 10-Core CPU and 10-Core GPU, Gigabit Ethernet, Nano-texture glass - Orange – G1K81LL/A $2,119.00 Originally released October 2024 24-inch 4.5K Retina display 32GB unified memory 1TB SSD 12MP Center Stage camera with support for Desk View Four Thunderbolt 4 ports Gigabit Ethernet Product page on the Apple Store… - 10:30 pmRefurbished 24-inch iMac Apple M4 Chip with 10-Core CPU and 10-Core GPU, Gigabit Ethernet- Yellow – G1K20LL/A – $1,779.00 | Refurb TrackerRefurbished 24-inch iMac Apple M4 Chip with 10-Core CPU and 10-Core GPU, Gigabit Ethernet- Yellow – G1K20LL/A – $1,779.00
Refurbished 24-inch iMac Apple M4 Chip with 10-Core CPU and 10-Core GPU, Gigabit Ethernet- Yellow – G1K20LL/A $1,779.00 Originally released October 2024 24-inch 4.5K Retina display 24GB unified memory 1TB SSD 12MP Center Stage camera with support for Desk View Four Thunderbolt 4 ports Gigabit Ethernet Product page on the Apple Store… - 10:09 pmRefurbished 24-inch iMac Apple M4 Chip with 10-Core CPU and 10-Core GPU, Gigabit Ethernet, Nano-texture glass – Blue – G1K59LL/A – $2,289.00 | Refurb TrackerRefurbished 24-inch iMac Apple M4 Chip with 10-Core CPU and 10-Core GPU, Gigabit Ethernet, Nano-texture glass – Blue – G1K59LL/A – $2,289.00
Refurbished 24-inch iMac Apple M4 Chip with 10-Core CPU and 10-Core GPU, Gigabit Ethernet, Nano-texture glass - Blue – G1K59LL/A $2,289.00 Originally released October 2024 24-inch 4.5K Retina display 24GB unified memory 2TB SSD 12MP Center Stage camera with support for Desk View Four Thunderbolt 4 ports Gigabit Ethernet Product page on the Apple Store… - 09:39 pmRefurbished 24-inch iMac Apple M4 Chip with 10-Core CPU and 10-Core GPU, Gigabit Ethernet- Pink – G1ES0LL/A – $1,609.00 | Refurb TrackerRefurbished 24-inch iMac Apple M4 Chip with 10-Core CPU and 10-Core GPU, Gigabit Ethernet- Pink – G1ES0LL/A – $1,609.00
Refurbished 24-inch iMac Apple M4 Chip with 10-Core CPU and 10-Core GPU, Gigabit Ethernet- Pink – G1ES0LL/A $1,609.00 Originally released October 2024 24-inch 4.5K Retina display 16GB unified memory 1TB SSD 12MP Center Stage camera with support for Desk View Four Thunderbolt 4 ports Gigabit Ethernet Product page on the Apple Store… - 09:39 pmRefurbished 24-inch iMac Apple M4 Chip with 10-Core CPU and 10-Core GPU, Gigabit Ethernet- Blue – FWV33LL/A – $1,439.00 | Refurb TrackerRefurbished 24-inch iMac Apple M4 Chip with 10-Core CPU and 10-Core GPU, Gigabit Ethernet- Blue – FWV33LL/A – $1,439.00
Refurbished 24-inch iMac Apple M4 Chip with 10-Core CPU and 10-Core GPU, Gigabit Ethernet- Blue – FWV33LL/A $1,439.00 $1,699.00 −15% Originally released October 2024 24-inch 4.5K Retina display 16GB unified memory 512GB SSD 12MP Center Stage camera with support for Desk View Four Thunderbolt 4 ports Gigabit Ethernet Product page on the Apple Store… - 09:39 pmRefurbished 24-inch iMac Apple M4 Chip with 10-Core CPU and 10-Core GPU, Gigabit Ethernet- Yellow – FWUX3LL/A – $1,439.00 | Refurb TrackerRefurbished 24-inch iMac Apple M4 Chip with 10-Core CPU and 10-Core GPU, Gigabit Ethernet- Yellow – FWUX3LL/A – $1,439.00
Refurbished 24-inch iMac Apple M4 Chip with 10-Core CPU and 10-Core GPU, Gigabit Ethernet- Yellow – FWUX3LL/A $1,439.00 $1,699.00 −15% Originally released October 2024 24-inch 4.5K Retina display 16GB unified memory 512GB SSD 12MP Center Stage camera with support for Desk View Four Thunderbolt 4 ports Gigabit Ethernet Product page on the Apple Store… - 04:15 pmRefurbished 24-inch iMac Apple M4 Chip with 10-Core CPU and 10-Core GPU, Gigabit Ethernet- Orange – FD2W4LL/A – $1,609.00 | Refurb TrackerRefurbished 24-inch iMac Apple M4 Chip with 10-Core CPU and 10-Core GPU, Gigabit Ethernet- Orange – FD2W4LL/A – $1,609.00
Refurbished 24-inch iMac Apple M4 Chip with 10-Core CPU and 10-Core GPU, Gigabit Ethernet- Orange – FD2W4LL/A $1,609.00 $1,899.00 −15% Originally released October 2024 24-inch 4.5K Retina display 24GB unified memory 512GB SSD 12MP Center Stage camera with support for Desk View Four Thunderbolt 4 ports Gigabit Ethernet Product page on the Apple Store… - 03:14 pmRefurbished 24-inch iMac Apple M4 Chip with 10-Core CPU and 10-Core GPU, Gigabit Ethernet- Blue – FD2T4LL/A – $1,609.00 | Refurb TrackerRefurbished 24-inch iMac Apple M4 Chip with 10-Core CPU and 10-Core GPU, Gigabit Ethernet- Blue – FD2T4LL/A – $1,609.00
Refurbished 24-inch iMac Apple M4 Chip with 10-Core CPU and 10-Core GPU, Gigabit Ethernet- Blue – FD2T4LL/A $1,609.00 $1,899.00 −15% Originally released October 2024 24-inch 4.5K Retina display 24GB unified memory 512GB SSD 12MP Center Stage camera with support for Desk View Four Thunderbolt 4 ports Gigabit Ethernet Product page on the Apple Store…