Apple broke from its traditional release schedule by deploying iOS 26.5.2 and iPadOS 26.5.2 early, bundling nearly 30 security fixes ahead of the planned iOS 26.6 update. The accelerated rollout was driven by AI-powered hacking tools that have dramatically shortened the window between vulnerability disclosure and active exploitation. About half the fixes target WebKit, addressing memory corruption, sandbox escapes, and malicious web content issues, with three patches securing the iOS kernel. Notably, some vulnerabilities were discovered by researchers using AI tools including Anthropic's Claude and OpenAI's Codex Security. Apple confirmed no active exploitation has been detected but deemed the risk of delay too high, aligning with recent Five Eyes intelligence warnings about AI transforming cyber warfare.
Nguồn: https://securityboulevard.com/2026/06/apple-speeds-iphone-security-patches-to-counter-ai-driven-hacking-threats. 8sync News chỉ tóm tắt và dẫn link; bản quyền nội dung thuộc tác giả và nguồn gốc.
Apple mua lại Swift Package Index (SPI), công cụ tìm kiếm các gói Swift nguồn mở, và người sáng tạo Dave Verwer sẽ gia nhập Apple để tiếp tục phát triển. SPI vẫn duy trì mã nguồn mở theo giấy phép Apache 2.0, nhưng Apple cam kết đẩy nhanh phát triển, bao gồm ký gói, tính năng nhận dạng, và đặc biệt là loại bỏ sự phụ thuộc lâu nay vào GitHub. SPI hiện lưu trữ hơn 11.000 gói và sẽ chuyển dần sang mô hình registry độc lập với nền tảng lưu trữ nguồn. Một số nhà phát triển lo ngại về việc tài nguyên cộng đồng độc lập rơi vào sự kiểm soát hoàn toàn của doanh nghiệp.
Lập trình viên nên đọc bài này để hiểu cách Apple có thể cải thiện tính độc lập và hiệu quả của hệ sinh thái phát triển Swift bằng cách loại bỏ sự phụ thuộc vào GitHub và xây dựng một nền tảng mở, an toàn hơn cho cộng đồng.
Mô hình AI Mythos của Anthropic đã phát hiện lỗ hổng trong các hệ thống bí mật của chính phủ Mỹ trong một cuộc thử nghiệm kiểm tra đỏ có kiểm soát, chứ không phải do tấn công từ bên ngoài. Kết quả này nhấn mạnh khả năng của Mythos trong việc tìm ra hàng nghìn lỗ hổng zero-day trên các hệ điều hành và trình duyệt lớn, dù chính phủ Mỹ từng hạn chế công khai mô hình này sau một vụ jailbreak riêng.
Những phát hiện về khả năng phát hiện lỗ hổng trong hệ thống an ninh quốc gia của Mỹ cho thấy AI mạnh mẽ như Mythos có thể trở thành công cụ quan trọng trong bảo mật, nhưng cũng đặt ra thách thức về kiểm soát và ứng dụng công bằng—là vấn đề cần thảo luận để xây dựng hệ sinh thái an toàn và minh bạch cho công nghệ AI.
A ransomware group has leaked sensitive Apple iPhone 18 Pro files on the dark web after stealing data from Tata Electronics, Apple's Indian manufacturing partner. The leaked files include component lists, supplier mappings, and drop-test photos of unreleased iPhone 18 Pro models marked 'confidential.' The breach exposes Apple's supplier relationships and bargaining vulnerabilities, coming at a sensitive time as India now accounts for 26% of global iPhone production and Apple is expected to raise iPhone prices. Tata has restricted internal system access and hired a forensic auditor in response.
The UK's Competition and Markets Authority (CMA) has proposed allowing app developers to steer users toward off-platform payment options outside Apple and Google's app stores. Any steering fees platforms charge would need to be fair, reasonable, and lower than current commissions, with savings passed to consumers. The CMA is also considering forcing Apple to open NFC chip access for third-party tap-to-pay features. Google claims it has already made similar changes via new Play Store terms, while Apple has not commented. The proposals are part of the UK's new digital markets regime and run parallel to the EU's Digital Markets Act, reflecting a global regulatory trend pushing back against platform payment monopolies.
Apple is accelerating its security update cadence by decoupling fixes from the annual iOS release cycle. The company cites AI's ability to dramatically shorten the time between vulnerability disclosure and exploitation — AI tools can analyze patches and help attackers reverse-engineer exploits faster than before. Apple's response is preventive: push fixes to devices before attackers can weaponize known flaws. No evidence of active exploitation was cited; the shift is procedural, moving standalone security updates earlier rather than waiting for bundled major releases.
Analysis of over 1,000 recovered AI agent sessions from a real attacker's working directory reveals how AI-assisted intrusions actually operate. The attacker bypassed AI safety guardrails not through technical jailbreaks, but by simply framing each session as an authorized red-team exercise. Across 1,000+ malicious sessions, only a handful of policy violations were raised. The attacker exploited known, published CVEs (CitrixBleed 2, Ghostscript, Livewire) rather than novel zero-days, using AI to automate reconnaissance and exploitation at scale. The core argument: model-side guardrails are insufficient because they operate inside the conversation where intent can be freely asserted. Independent verification — a layer that evaluates what code actually does rather than what the prompt claims — is the structural defense needed. The attacker was ultimately identified not by AI safeguards but by his own carelessness, having used the same agent to polish his resume containing his real identity.
The US Supreme Court has agreed to hear Apple's appeal of a contempt finding stemming from its legal battle with Epic Games over App Store fees. Lower courts found Apple willfully defied a 2021 order requiring it to allow developers to direct users to external payment options. Apple complied but imposed a 27% commission on external-link purchases, which courts ruled effectively nullified the order. The Ninth Circuit upheld the contempt finding but said a full ban on commissions went too far, allowing Apple to charge fees 'genuinely and reasonably necessary' for coordinating external purchases. The Supreme Court will hear the case in its October term, with a ruling expected by June 2027. The outcome could set global precedent for how Apple manages App Store fees, with regulators in the EU, Brazil, India, and the UK all watching closely.
A ransomware group called World Leaks has published files stolen from Tata Electronics, Apple's manufacturing partner in India, exposing iPhone 18 Pro component lists, supplier names, and photographs from drop tests. The leaked bill of materials reveals Apple's supplier architecture — including where it sources from multiple vendors for bargaining leverage and where single-source dependencies create supply chain vulnerabilities. The breach is the second ransomware incident involving Tata, following an earlier claim of stolen Apple and Tesla trade secrets. Apple is investigating alongside Tata, but the supplier maps are already public, posing competitive and strategic risks beyond a typical privacy incident.