Kategorie
ToxicPanda Android malware uses VPN permissions to block Google Play
TikTok Agrees to $400 Million Settlement in U.S. Child Privacy Lawsuit
Hackers infect Android car head units with proxy botnet malware
Named Pipes Under Attack: Securing Windows Interprocess Communication
eBPF Security Is Moving Beyond the Kernel Verifier
Kata Containers Flaw Weakens Container Security With Host-Chosen Mounts
KVM’s TDX Control-Plane Blind Spot: When “Enabled” Does Not Mean Enforced
14 Trojanized npm Packages Drop RedC2 4.0 Linux Backdoor With AI-Assisted C2
New SynkLoader malware pushed in Microsoft Teams phishing campaign
Linux ShieldZFS Adds Freshness Proofs for Confidential Computing
Hundreds of leaked AWS keys give full control over corporate accounts
Microsoft Defender's Own Driver Can Be Weaponized to Delete Security Software at Boot
Android Car Malware Spreads Through Built-In Updaters for Ad Fraud, Proxy Botnet
ChatGPT wants Full Disk Access to your Mac and Messages
<br><!--<br>/* Style Definitions */<br> p.MsoNormal, li.MsoNormal, div.MsoNormal<br> {mso-style-unhide:no;<br> mso-style-qformat:yes;<br> mso-style-parent:"";<br> margin:0cm;<br> mso-pagination:widow-orphan;<br> font-size:12.0pt;<br> font-family:"Aptos",sans-serif;<br> mso-fareast-font-family:Aptos;<br> mso-bidi-font-family:"Times New Roman";<br> mso-fareast-language:EN-US;}<br>a:link, span.MsoHyperlink<br> {mso-style-priority:99;<br> color:#467886;<br> mso-themecolor:hyperlink;<br> text-decoration:underline;<br> text-underline:single;}<br>a:visited, span.MsoHyperlinkFollowed<br> {mso-style-noshow:yes;<br> mso-style-priority:99;<br> color:#96607D;<br> mso-themecolor:followedhyperlink;<br> text-decoration:underline;<br> text-underline:single;}<br>.MsoChpDefault<br> {mso-style-type:export-only;<br> mso-default-props:yes;<br> font-size:10.0pt;<br> mso-ansi-font-size:10.0pt;<br> mso-bidi-font-size:10.0pt;<br> font-family:"Aptos",sans-serif;<br> mso-ascii-font-family:Aptos;<br> mso-fareast-font-family:Aptos;<br> mso-hansi-font-family:Aptos;<br> mso-font-kerning:0pt;<br> mso-ligatures:none;}<br>@page WordSection1<br> {size:595.3pt 841.9pt;<br> margin:72.0pt 72.0pt 72.0pt 72.0pt;<br> mso-header-margin:35.4pt;<br> mso-footer-margin:35.4pt;<br> mso-paper-source:0;}<br>div.WordSection1<br> {page:WordSection1;}<br> /* List Definitions */<br> @list l0<br> {mso-list-id:1984120649;<br> mso-list-type:hybrid;<br> mso-list-template-ids:226894856 134807553 134807555 134807557 134807553 134807555 134807557 134807553 134807555 134807557;}<br>@list l0:level1<br> {mso-level-number-format:bullet;<br> mso-level-text:;<br> mso-level-tab-stop:none;<br> mso-level-number-position:left;<br> text-indent:-18.0pt;<br> font-family:Symbol;}<br>@list l0:level2<br> {mso-level-number-format:bullet;<br> mso-level-text:o;<br> mso-level-tab-stop:none;<br> mso-level-number-position:left;<br> text-indent:-18.0pt;<br> font-family:"Courier New";}<br>@list l0:level3<br> {mso-level-number-format:bullet;<br> mso-level-text:;<br> mso-level-tab-stop:none;<br> mso-level-number-position:left;<br> text-indent:-18.0pt;<br> font-family:Wingdings;}<br>@list l0:level4<br> {mso-level-number-format:bullet;<br> mso-level-text:;<br> mso-level-tab-stop:none;<br> mso-level-number-position:left;<br> text-indent:-18.0pt;<br> font-family:Symbol;}<br>@list l0:level5<br> {mso-level-number-format:bullet;<br> mso-level-text:o;<br> mso-level-tab-stop:none;<br> mso-level-number-position:left;<br> text-indent:-18.0pt;<br> font-family:"Courier New";}<br>@list l0:level6<br> {mso-level-number-format:bullet;<br> mso-level-text:;<br> mso-level-tab-stop:none;<br> mso-level-number-position:left;<br> text-indent:-18.0pt;<br> font-family:Wingdings;}<br>@list l0:level7<br> {mso-level-number-format:bullet;<br> mso-level-text:;<br> mso-level-tab-stop:none;<br> mso-level-number-position:left;<br> text-indent:-18.0pt;<br> font-family:Symbol;}<br>@list l0:level8<br> {mso-level-number-format:bullet;<br> mso-level-text:o;<br> mso-level-tab-stop:none;<br> mso-level-number-position:left;<br> text-indent:-18.0pt;<br> font-family:"Courier New";}<br>@list l0:level9<br> {mso-level-number-format:bullet;<br> mso-level-text:;<br> mso-level-tab-stop:none;<br> mso-level-number-position:left;<br> text-indent:-18.0pt;<br> font-family:Wingdings;}<br><br>--><br>Apple wasn’t joking when it <a style="color: rgb(150, 96, 125);" href="https://www.apple.com/newsroom/2025/09/the-digital-markets-acts-impacts-on-eu-users/">warned</a> us that competitors want access to our most private data. Now <a style="color: rgb(150, 96, 125);" href="https://www.computerworld.com/article/4212037/apple-to-openai-go-to-your-room.html">OpenAI’s ChatGPT</a>has introduced a new plugin that can control Apple’s Messages app on Macs. This follows its introduction earlier of a new Computer History feature that <a style="color: rgb(150, 96, 125);" href="https://x.com/OpenAI/status/2087996496088297746?s=20">monitors what you do on your Mac</a>, and while I don’t think Apple will challenge the new feature – yet – on Mac, I do see trouble ahead on other platforms.So, what’s ChatGPT’s new thing? Its latest tool means you can use the Chat GPT app to read, write and send texts via Messages. The app can also search through messages and get message summaries and other information directly from the Messages app. <b>What is happening?</b>“The Apple Messages plugin is available on all plans in the ChatGPT desktop app for macOS. In Codex and ChatGPT Work, it can read and search iMessage, SMS, and RCS chats on your Mac and send messages on your behalf through the Messages app. It doesn’t let you interact with ChatGPT remotely through Messages, and it doesn’t work in regular ChatGPT chats,” <a style="color: rgb(150, 96, 125);" href="https://learn.chatgpt.com/docs/plugins?surface=app">says OpenAI</a>.What this means is that if you’ve ever wanted an AI system to go through all your messages to give you insights, you’re in luck – though you’ll probably want to check in with corporate legal before doing so. The system does require user consent before working, and OpenAI itself suggests such permission is given only on a per-use, rather than a blanket basis.<b>How might you use this tool?</b>ChatGPT’s tool is not dissimilar to the contextual personal data insights promised by Apple’s SiriAI. You might use it to search for information buried in old messages, create new messages, delete them and more. You might get ChatGPT to recommend a set of secure browser and messaging services you can use to communicate without sharing your information with an AI company and ask it to write a cheery message about dystopia for you, for example. There’s an ad featuring much more mundane examples available <a style="color: rgb(150, 96, 125);" href="https://x.com/ChatGPT/status/2090499359641329950?s=20">here</a>.The company has suggested some prompts, including:<li class="MsoNormal">Suggest follow ups from yesterday in messages.Check my calendar and reply to (contact name) with a few times I'm free for dinner next week.Find birthdays in Messages and add them to my calendar.</li><b>How does it work?</b>The way the system works isn’t quite as clear as I’d like it to be, given the personal data being parsed by the system, along <a style="color: rgb(150, 96, 125);" href="https://tech.yahoo.com/general/articles/chatgpt-macos-just-got-caught-134547811.html">with recent history</a> on how ChtGPT protects such data on Macs. OpenAI told <a style="color: rgb(150, 96, 125);" href="https://www.bloomberg.com/news/articles/2026-08-20/chatgpt-can-now-control-imessage-potentially-raising-apple-privacy-concerns">Bloomberg</a> the plug-in runs locally on the Mac, and doesn’t create an index of a user’s messages, but that may not mean too much given the system does read a user’s existing messages and presumably has some kind of record of the data analysis itself. It is also not especially reassuring that OpenAI tells people not to turn on persistent approval, saying that doing so, “removes your final chance to review a message before ChatGPT sends it as you.”Perhaps of more concern is that the plugin also demands Full Disk Access in System Settings, along with access to contact names and automation tools. The plugin also makes use of AppleScript and Accessibility settings.<b>Something to think about</b>The degree to which OpenAI is digging into the macOS to make these features work is already driving some backlash. Some <a style="color: rgb(150, 96, 125);" href="https://x.com/markgurman/status/2090580272433832177?s=20">apologists</a> tend to dismiss concerns around privacy, while others warn that AI automation is becoming an <a style="color: rgb(150, 96, 125);" href="https://x.com/GaryMarcus/status/2090583038338236533?s=20">always-on surveillance system</a> that itself becomes a target for exploitation and attack. It’s possible both parties have a point, but what I don’t see yet is any clear transparency around how the system delivers all its promised convenience without undermining user privacy.It also seems very likely OpenAI plans to bring similar features to iPhones and iPads, which may yet open up a new front in Apple/OpenAI’s ongoing litigation around the provision of equal access to user data, particularly in Europe where <a style="color: rgb(150, 96, 125);" href="https://digital-markets-act.ec.europa.eu/developer-portal/interoperability_en">the Digital Markets Act</a> requires Apple to provide third-party AI developers with the same deep system-level APIs and device access that Apple uses for its own AI tools. It remains to be seen how Apple intends to meet that commitment, particularly as it has chosen not to offer SiriAI in Europe until it can agree some way to offer that kind of access to third parties while continuing to protect user privacy. It is also hard to ignore that ChatGPT on a Mac has now become a prime target for hackers, as if they can’t get into Messages directly, now all they need to do is hack the ChatGPT app to do it for them, perhaps using ChatGPT to <a style="color: rgb(150, 96, 125);" href="https://x.com/ControlAI/status/2090565786205118516?s=20">help them build the code with which to do it</a>. <b>What next? </b>I don’t think Apple will challenge OpenAI’s approach right now as the company doesn’t appear to have actively subverted Mac security protection, but I do predict a show down on iOS, particularly if Apple is unable to build support for the ‘<a style="color: rgb(150, 96, 125);" href="https://www.applemust.com/apples-siri-ai-stand-off-with-europe-just-escalated/">trusted intermediary’</a> approach it <a style="color: rgb(150, 96, 125);" href="https://www.applemust.com/eu-regulators-just-killed-europes-ios-developer-industry/">originally proposed</a> to the EU, if only because of the much wider extent of information collected on mobile. It also puts yet another slant on the <a style="color: rgb(150, 96, 125);" href="https://www.computerworld.com/article/4212037/apple-to-openai-go-to-your-room.html">ongoing litigation between both companies</a>.<em><span style="font-size: 13.5pt; font-family: Arial, sans-serif; color: rgb(12, 12, 12); letter-spacing: -0.15pt;">Join me on <a style="color: rgb(150, 96, 125); -webkit-font-smoothing: antialiased;" href="https://bsky.app/profile/jonnyevanssays.bsky.social"><span style="color: rgb(12, 12, 12);">BlueSky</span></a>, <a style="color: rgb(150, 96, 125); -webkit-font-smoothing: antialiased;" href="http://www.linkedin.com/in/jonnyevans"><span style="color: rgb(12, 12, 12);">LinkedIn</span></a>, <a style="color: rgb(150, 96, 125); -webkit-font-smoothing: antialiased;" href="https://social.vivaldi.net/@jonnyevans"><span style="color: rgb(12, 12, 12);">Mastodon</span></a> and <a style="color: rgb(150, 96, 125); -webkit-font-smoothing: antialiased;" href="https://thecorenews.substack.com/?r=5l3lg&utm_campaign=profile&utm_medium=profile-page"><span style="color: rgb(12, 12, 12);">subscribe to my newsletter</span></a> for news and analysis.</span></em>Apple wasn’t joking when it warned us that competitors want access to our most private data. Now, OpenAI’s ChatGPT has introduced a new plugin that can control Apple’s Messages app on Macs. This follows the earlier introduction of a new Computer History feature that monitors what you do on your Mac. And while I don’t think Apple will challenge the new feature — yet — on the Mac, I do see trouble ahead on other platforms.
So, what’s ChatGPT’s new thing? Its latest tool means you can use the tool to read, write and send texts via Messages. The app can also search through messages and get message summaries and other information directly from Messages.
What is happening?“The Apple Messages plugin is available on all plans in the ChatGPT desktop app for macOS,” says OpenAI. “In Codex and ChatGPT Work, it can read and search iMessage, SMS, and RCS chats on your Mac and send messages on your behalf through the Messages app. It doesn’t let you interact with ChatGPT remotely through Messages, and it doesn’t work in regular ChatGPT chats.”
So, if you’ve ever wanted an AI system to go through all your messages to pluck out insights, you’re in luck (though you’ll probably want to check in with corporate legal before doing so). The system does require user consent before working, and OpenAI itself suggests such permission is given only on a per-use, rather than a blanket basis.
How might you use this tool?ChatGPT’s tool is not dissimilar to the contextual personal data insights promised by Apple’s SiriAI. You might use it to search for information buried in old messages, create new messages, delete them, and more. You might get ChatGPT to recommend a set of secure browser and messaging services you could use without sharing your information with an AI company and ask it to write a cheery message about dystopia for you, for example. There’s an ad featuring much more mundane examples here.
The company has suggested some prompts, including:
- Suggest follow ups from yesterday in messages.
- Check my calendar and reply to (contact name) with a few times I’m free for dinner next week.
- Find birthdays in Messages and add them to my calendar.
The way the system works isn’t quite as clear as I’d like it to be, given the personal data being parsed, along with recent history on how ChatGPT protects such data on Macs.
OpenAI told Bloomberg the plug-in runs locally on the Mac, and doesn’t create an index of a user’s messages. But that may not mean much, given the system does read a user’s existing messages and presumably has some kind of record of the data analysis itself. It is also not especially reassuring that OpenAI tells people not to turn on persistent approval, saying that doing so, “removes your final chance to review a message before ChatGPT sends it as you.”
Perhaps of more concern is that the plugin also demands Full Disk Access in System Settings, along with access to contact names and automation tools.
Something to think aboutThe degree to which OpenAI is digging into the macOS to make these features work is already driving some backlash. Some apologists tend to dismiss concerns around privacy, while others warn that AI automation is becoming an always-on surveillance system that itself becomes a target for exploitation and attack. Both sides may have a point. But what I don’t see yet is any clear transparency around how the system delivers all its promised convenience without undermining user privacy. It’s all well and good to require consent to make the AI magic happen, but it would be far better, and more legitimate, for such consent to be informed.
It also seems very likely OpenAI plans to bring similar features to iPhones and iPads, which might yet open up a new front in Apple/OpenAI’s ongoing litigation around the provision of equal access to user data. That’s particularly true in Europe, where the Digital Markets Act requires Apple to provide third-party AI developers with the same deep system-level APIs and device access that Apple uses for its own AI tools.
It remains to be seen how Apple intends to meet that commitment, particularly as it has chosen not to offer SiriAI in Europe until it can agree on some way to offer that kind of access to third parties while continuing to protect user privacy. It is also hard to ignore that ChatGPT on a Mac has now become a prime target for hackers; if they can’t get into Messages directly, now all they need to do is hack the ChatGPT app to do it for them — perhaps using ChatGPT to help them build the code with which to do it.
What’s next?I don’t think Apple will challenge OpenAI’s approach for now, as the company doesn’t appear to have actively subverted Mac security protection. But I do predict a showdown on iOS, particularly if Apple is unable to build support for the “trusted intermediary” approach it originally proposed to the EU, if only because of the wider extent of information collected on mobile. It also puts yet another slant on the ongoing litigation between both companies.
Join me on BlueSky, LinkedIn, Mastodon and subscribe to my newsletter for news and analysis.
Microsoft blames Windows gaming issues on RGB lighting devices
Is Online Privacy Possible? How Digital Identities Can Help
Microsoft rolls out Classic Outlook theme for New Outlook users
Waymo doubles spending on lobbying in robotaxi battle with Uber
Waymo has sharply increased its lobbying spending as it seeks to persuade US regulators to clear a path for fully autonomous taxi services, intensifying its battle with rival Uber over the future of robotaxis.
The Alphabet-owned company spent more than $1 million between April and June on lobbying the federal government, more than double its outlay a year earlier, according to filings. That put Waymo’s spending close to Uber’s and well ahead of rivals including Amazon’s Zoox and Tesla.
The rise in lobbying comes as Waymo and Uber push competing visions for the future of ride-hailing. Waymo wants a faster route to fully driverless commercial services, while Uber is advocating a staggered rollout in which robotaxis operate alongside human drivers.
CISA orders feds to patch actively exploited TrueConf Server flaws
New ‘Slack Code’ turns AI coding into a team activity
With the launch of “Slack Code” channels, Slack this week introduced a new way for developers and non-tech staff to work collaboratively with coding agents.
While Slack already integrates with several coding agents, developers have to interact with them independently to get work done. The aim of Slack Code is to make agents available to multiple coworkers in shared, project-based “code channels.”
“We built code channels to be this multi-player AI experience and bring more development into Slack,” said Sateja Parulekar, vice president of product marketing at Slack. “It’s not just engineers and product managers who are working with the coding agents; it’s the marketers, the product designers who are now able to interact with a coding agent in a safe, governed environment.”
Slack code channels are intended for one-off coding sessions and projects — building a new application feature, updating a web page, or fixing a bug, for example.
When the coding agent is tagged in a Slack channel or DM with a request, it automatically creates a new code channel, adds links to required documents, and invites relevant participants.
The code channel functions just like a normal Slack channel, with participants able to send messages and files as usual, while also letting them interact with a coding agent and track outputs via the channel’s “session artifacts.” These artifacts include “code diffs” that highlight changes to code made by the agent, as well as Slack “canvas” documents and live HTML that displays prototypes and previews created by the agent.
All participants can use natural language to direct the agent, making suggestions and signing-off on outputs, for instance. Any updates are then highlighted in the original Slack channel. And when a task or project is complete, the code channel is automatically archived.
Slack Code channels can also be customized — Slack admins can create guardrails to prevent non-technical workers from shipping code without engineering review, for example.
Code channels adhere to Slack’s existing security and permissions model, the company said, with agents able to access conversations and data based on controls set for a Slack workspace.
At launch, four agents integrate with Slack Code — Claude Code, Devin, GitHub Copilot, and Vercel — though Slack intends to expand the list of options over time. Slack Code is available at no extra cost on all Slack subscriptions.
“Slack Code closes the gap between where work gets done and where code gets written with dedicated spaces built for output along project-based channels right in Slack,” said Wayne Kurtzman, research vice president at IDC. “This furthers the Salesforce goal of making work more seamless and multi-player within the Slack environment, regardless of the other applications the business is using.
“While Slack Code may seem early to market for some companies, others are leveraging the first-mover advantage.”
While software development and coordination work “has happened in Slack forever,” according to Will McKeon-White, senior analyst at Forrester, the new features make it “easier to just stay in Slack only and [open] up who is involved with the actual code creation.”
For IT staffers who enable Slack Code, the immediate consideration involves permissions, he said — “a persistent challenge for anything multiplayer.” McKeon-White cites various approaches: “…Some inherit user permissions based on task, some have persistent permissions with different ‘invoking’ permissions for users, some inherit the permissions of the room. Each has flaws.”
The longer-term challenge, he said, is around multi-agent collaboration.
“Multi-agent collab today in successful environments isn’t very dynamic,” said McKeon-White. “Having true dynamic agents cooperating can create extremely interesting emergent behavior,” he said, pointing to recent Anthropic research on the topic.
While Slack Code is aimed at software development-related tasks, Slack also envisages a similar cross-functional, collaborative approach to AI agent interactions applied to a wider variety of purposes: marketing campaigns, for instance, or legal document reviews.
“That might not involve code per se, but it does involve a very detailed review of a document and tracking changes and a preview of what’s going to be sent out to the customer,” said Parulekar. “In the future, we see this extending to a lot of different teams and use cases for technical and non-technical users.”
Other features announced Thursday include “agent DMs” that allow for individual interactions with an agent and a new “agents tab” where users can view existing agent conversations.
Parulekar said Slack Code feeds into a wider Slack strategy centered on a “multi-player experience” for human workers and AI agents. This includes the recent announcement of Claude Tag, which makes Anthropic’s agent available to teams.
“Whether it’s the user experience that we’re evolving — like the agent tab, or coding channels where you can plan, code, test, and ship inside of Slack — it’s all part of that bigger vision of making Slack a great home for agents and furthering that vision of multiplayer AI,” she said.
- 1
- 2
- 3
- 4
- 5
- 6
- 7
- 8
- 9
- …
- následující ›
- poslední »



