惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Security Latest
Security Latest
U
Unit 42
D
Docker
H
Help Net Security
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
H
Hackread – Cybersecurity News, Data Breaches, AI and More
Microsoft Azure Blog
Microsoft Azure Blog
C
Cisco Blogs
阮一峰的网络日志
阮一峰的网络日志
S
Schneier on Security
Project Zero
Project Zero
F
Future of Privacy Forum
V
Vulnerabilities – Threatpost
Recent Announcements
Recent Announcements
T
Threatpost
T
True Tiger Recordings
量子位
The Hacker News
The Hacker News
Stack Overflow Blog
Stack Overflow Blog
Recorded Future
Recorded Future
T
The Blog of Author Tim Ferriss
S
SegmentFault 最新的问题
A
Arctic Wolf
Martin Fowler
Martin Fowler
I
InfoQ
Malwarebytes
Malwarebytes
T
Tor Project blog
Hugging Face - Blog
Hugging Face - Blog
M
MIT News - Artificial intelligence
S
Securelist
T
Tailwind CSS Blog
Blog — PlanetScale
Blog — PlanetScale
P
Proofpoint News Feed
W
WeLiveSecurity
The Register - Security
The Register - Security
Cisco Talos Blog
Cisco Talos Blog
H
Hacker News: Front Page
The Cloudflare Blog
O
OpenAI News
C
CERT Recently Published Vulnerability Notes
Hacker News: Ask HN
Hacker News: Ask HN
NISL@THU
NISL@THU
E
Exploit-DB.com RSS Feed
Scott Helme
Scott Helme
Jina AI
Jina AI
Spread Privacy
Spread Privacy
T
The Exploit Database - CXSecurity.com
T
Troy Hunt's Blog
N
News | PayPal Newsroom
李成银的技术随笔

9to5Mac

May 22, 2026 – Apple Music AI, hardware changes Unannounced Apple headphones revealed in FCC documents Google defends its Safari deal with Apple in antitrust ruling appeal Gemini app for Mac adding ‘Spark’ agent and voice control this summer WhatsApp is working on a centralized interface showing which contacts are online HomeKit Weekly: Why the Aqara G5 Pro remains one of the best outdoor HomeKit cameras Apple shares iPhone and Mac post-quantum cryptography code on GitHub Apple TV’s hit comedy lineup keeps growing, with big new series coming AirPods with cameras suddenly make a lot more sense after this new reveal iOS 26.5.1 could launch soon as next iPhone update iPhone 18 Pro leak reveals brand new colors that could be coming watchOS 27’s rumored new Apple Watch face has me very intrigued How to stop menu bar items being hidden behind the MacBook Pro notch How to watch the F1 Canadian Grand Prix Deals: AirPods Pro 3 Memorial Day deal back at $199, M5 MacBook Air Amazon low $199 off, iPad Air $400 off, Series 11, more Apple TV’s new Matthew McConaughey comedy series coming this fall WWDC invites, iOS 27 accessibility features, new Siri will be a ‘beta’ - 9to5Mac iOS 26.5 added new features to three popular iPhone apps Apple Intelligence 2.0 promises many new features I’m very excited for Meta has released two new apps for iPhone this month 9to5Mac Overtime 068: You were right to push back on that - 9to5Mac iOS 26 tweaks iPhone Always On Display in a way you might not like May 21, 2026 – iPhone Ultra leaks, more Apple to update App Store age ratings in Australia and Vietnam next month Review: SwitchBot Wallet Finder is an incredibly useful accessory to track your wallet with iPhone Find My Apple seeks Supreme Court review of contempt finding and injunction scope in Epic Games case Report: Apple sees Latin America iPhone shipments surge 31%, led by Mexico iOS 27 could drop support for four iPhone models Codex for Mac updated with new Appshots feature that instantly gives chat context Silo season 3’s significant character change revealed in new teaser ‘Shortcuts Playground’ lets you create shortcuts using natural langauge iPhone 18 Pro could make life-saving niche feature into everyday asset BBEdit 16 out now with in-image text search, deeper Shortcuts integration, notebook filtering, more Spotify to offer AI tool that will let subscribers remix songs and cover music Deals: M5 MacBook Air $199 off Amazon low, M3 iPad Air $400 off, iPhone 17 Pro Max, accessories, more Perplexity’s Comet AI browser for iOS upgraded with 8 major improvements OpenAI improves Codex iOS experience with turn completion alerts, new commands, more Apple Watch and AirPods health features get major new global expansions Apple TV to air first major live sporting event shot entirely on iPhone 17 Pro Security Bite: Tired of app tracking pop-ups? Here’s how to auto-deny them Next year’s iPhone Pro models to get radical new design, per leaker If your Oura smart ring detects sleep apnea, it can refer you to doctors Strava adds dedicated strength training support for sets, reps, weight, and muscle groups Brye song that hit 100M streams was produced in GarageBand on school iPad OLED MacBook Pro screens on-track amid talk of delayed launch AT&T announces new $15/month ‘Build-a-Plan’ wireless plan ACSI: Samsung edges out Apple in cell phone satisfaction, while Apple Watch ties at the top Adobe Photoshop update brings on-device AI processing, but there is a catch Eddy Cue named 2026 Cannes Lions Entertainment Person of the Year The Outsiders celebrates Apple Design Awards 2026 nomination with biggest update yet Apple TV renews ‘Knife Edge: Chasing Michelin Stars’ for a second season tvOS 27 will give Apple TV 4K a useful new display setting Kansas City Public Schools to replace 30,000 Windows PCs and Chromebooks with Apple devices Hovercraft is a new Mac app that makes video call presentations feel more personal Apple Music shares what it is doing to ‘keep music fair’ in an AI world iOS 26.5 won’t let users downgrade to prior update any longer MacBook Ultra could be very good news for MacBook Pro users Airbnb upgrades iOS and Android app with three key enhancements for your next trip Deals: M3 iPad Air $400 off, 1TB M5 iPad Pro all-time low, 24GB M5 MacBook Pro $1,499, Apple Watch Ultra 3, more Apple’s three goals for iOS 27 sound like a big win for users Apple gives update on the App Store and its key protections New ‘Steve Jobs in Exile’ book reads like a lost season of your favorite series AI companies and data brokers even resort to fake forms to keep selling our data Apple Immersive video on Real Madrid coming this week to Vision Pro Jamf names former CTO Beth Tschida as CEO to lead its new AI push Android cloning Apple’s Handoff feature is cheeky but a good thing Discord now uses end-to-end encryption for all voice and video calls by default May 20, 2026 – New Apple accessibility features, Apple Watch rumors ‘Maximum Pleasure Guaranteed’ premieres on Apple TV WhatsApp working on messages that disappear once you’ve read them Apple’s global F1 ambitions hit roadblock as Sky extends U.K. and Italy rights ‘Pluribus’ lead Rhea Seehorn joins upcoming Apple Original Film ‘Running’ Apple strikes talent and IP deal with virtual avatar startup Animato iOS 26’s Wallet app has long-awaited order tracking fix, here’s how to use it Disney announces three new Disney+ and Hulu app features May 19, 2026 – WWDC invites, iOS 27 expectations Spotify confirms CarPlay bug causing wrong song info to appear Everything Google announced at I/O 2026: Gemini, Search, Android XR, & more Apple TV announces four new Peanuts premieres coming this summer Here’s how Johny Srouji plans to speed up Apple’s product development: report Apple Sports app launches World Cup support, expands availability worldwide iOS 27’s new video feature could prove one of Apple’s best additions Deals: AirPods Pro 3 Memorial Day deal, 24GB M5 MacBook Pro $320 off, MacBook Neo, Apple Watch Ultra, more Apple Watch has a useful hidden feature for tracking a great healthy habit Anthropic enhances Claude Managed Agents with two new privacy and security features macOS 27: Five new Mac features being announced next month Plex increasing Lifetime Plex Pass cost to whopping $750 Apple just revealed an iOS 27 feature that hints at Siri’s new powers Fortnite is back on the App Store worldwide, says Epic Games Apple announces return of popular MagSafe iPhone stand and grip Apple announces AI-powered accessibility features and eye-controlled wheelchair functionality PSA: Watch out for this potential gotcha on the Apple Card free AirPods deal iPhone Ultra will take us closer to the long-rumored iPad Fold, suggests leaker Apple @ Work Podcast: How NeXT built the foundation for Apple in the enterprise - 9to5Mac Apple ordered to cooperate with India antitrust probe as court declines to pause case MagSafe Monday: The UGREEN Nexode Power Bank might be the ultimate 3-in-1 MagSafe charger With iOS 27, Shortcuts is about to become what it was always meant to be iPhone 18 Pro release date: Here’s when Apple’s new model is coming iOS 26.5 adds new setting for alternative app marketplaces in Brazil macOS 27 will drop support for these four Mac models
Apple @ Work: Why the ClickFix campaign means it is time to kill the 90 day update deferral
Bradley C · 2026-05-23 · via 9to5Mac

Apple @ Work is exclusively brought to you by Mosyle, the only Apple Unified Platform. Mosyle is the only solution that integrates in a single professional grade platform all the solutions necessary to seamlessly and automatically deploy, manage, and protect Apple devices at work. Over 45,000 organizations trust Mosyle to make millions of Apple devices work ready with no effort and at an affordable cost. Request your EXTENDED TRIAL today and understand why Mosyle is everything you need to work with Apple.

Over the past few weeks, the Mac admins I talk with have been talking about a report from Netskope Threat Labs regarding a new macOS ClickFix campaign. The campaign is a brilliant (and scary) piece of social engineering, and it highlights exactly why the traditional 90-day software update deferral window needs to be retired, either by Apple or by IT.

About Apple @ Work: Bradley Chambers managed an enterprise IT network from 2009 to 2021. Through his experience deploying and managing firewalls, switches, a mobile device management system, enterprise-grade Wi-Fi, 1000s of Macs, and 1000s of iPads, Bradley will highlight ways in which Apple IT managers deploy Apple devices, build networks to support them, train users, stories from the trenches of IT management, and ways Apple could improve its products for IT departments.

The ClickFix threat

ClickFix is a tactic where attackers trick users into copying and pasting a malicious script directly into their Terminal app. They achieve this using fake CAPTCHA screens or fake browser update alerts. Once the user pastes and runs the script, it deploys an AppleScript dialog box that looks exactly like a native macOS system prompt.

The prompt asks for the user’s password and loops infinitely until the user provides it. There is no close button. Once the password is captured, the malware steals the entire macOS Keychain database, along with live session cookies from browsers such as Safari and Chrome. Stealing live session cookies is the ultimate prize because it allows attackers to bypass multi-factor authentication completely.

Why deferring updates is a liability

Apple is already fighting back against this specific attack type. In macOS Sequoia and macOS Tahoe 26.4, Apple introduced a native Terminal security warning. This feature specifically disrupts ClickFix attacks by alerting users when they attempt to paste harmful commands from an untrusted source into Terminal.

This brings me to my main point. Historically, Apple has allowed IT administrators to defer macOS updates for up to 90 days using their device management platform. For years, this was considered an IT best practice. It gave teams time to test internal apps, verify compatibility, and ensure a smooth rollout across the fleet.

However, the threat landscape in the age of AI is moving too fast for a three-month delay. If your organization is deferring updates for a maximum of 90 days, your users are missing out on critical OS level mitigations like the new Terminal paste warning. For three entire months, your employees are vulnerable to social engineering attacks that the operating system could easily block if it were simply up to date.

9to5Mac’s take

It might be time for Apple to rethink the management framework and formally reduce the maximum software update deferral window from 90 days to 45-30 days. The reality is that if a software vendor has not updated their enterprise app to support a new version of macOS within 30 days of release, you have a vendor problem, not an Apple problem.

Even if Apple keeps the 90-day option available indefinitely, IT teams need to manually tighten their internal policies. Enforcing a 30-day maximum deferral window strikes the perfect balance between testing application compatibility and protecting corporate data from emerging threats. You simply cannot afford to leave your fleet exposed for a quarter of the year.

Apple @ Work is exclusively brought to you by Mosyle, the only Apple Unified Platform. Mosyle is the only solution that integrates in a single professional grade platform all the solutions necessary to seamlessly and automatically deploy, manage, and protect Apple devices at work. Over 45,000 organizations trust Mosyle to make millions of Apple devices work ready with no effort and at an affordable cost. Request your EXTENDED TRIAL today and understand why Mosyle is everything you need to work with Apple.

Add 9to5Mac as a preferred source on Google Add 9to5Mac as a preferred source on Google

FTC: We use income earning auto affiliate links. More.