Agregátor RSS

Apple locks down Full Disk Access, and AI agents are the reason

Computerworld.com [Hacking News] - 5 Říjen, 2026 - 12:13

Apple has been forced to make macOS even more locked down, to the dismay of some developers. It has announced plans to introduce more user-facing control over the process of giving apps Full Disk Access.

Some developers are upset, believing this will put more barriers in place to those creating apps outside the App Store. Endpoint security vendors voiced some concern but understand the cause: “poorly written/insecure/greedy AI agents/assistants insisting on Full Disk Access, and then once granted/obtained, abusing that, to access ,” as Objective-See co-founder Patrick Wardle wrote on X.

Explaining its plans, Apple says it will still make it possible for customers to choose to enable Full Disk Access; it’s just going to make the decision much more intentional, with additional steps to ensure that users know what they are signing up for.

Why is Apple doing this?

It may or may not be in reaction to Meta’s Muse AI agent, which was accused of reading a journalist’s private messages without permission — a claim Meta denies. 

But even if it is not a reaction to that, the move attempts to put additional obstacles in place to prevent users from casually giving AI agents the power to ransack their private data when they give them Full Disk Access without fully understanding the consequences of doing so.

What Apple said

Here’s what Apple said in a note on its developer website:

“We give developers powerful APIs to build incredible capabilities into their apps for Apple products, backed by a set of controls designed to protect users’ private data. Full Disk Access largely sidesteps these controls in order to allow backup apps to function properly on the Mac. Some developers are using Full Disk Access in ways that could put users at risk, exposing everything on their systems—including files, mail, messages, and even browsing history—without users’ full knowledge and understanding. For communication apps, this can also compromise the privacy of the people users are communicating with.

“Going forward, we will introduce additional controls to ensure that users who genuinely wish to grant an app this extraordinary level of access can only do so with very explicit user action. Addressing this is critical. As AI agents become increasingly capable and autonomous, the risks associated with this level of access will grow substantially. We are committed to ensuring users clearly understand these risks before granting such access, so they can make informed decisions about their own data and privacy.”

The note makes it quite clear that Apple is doing this in reaction to the real and present danger that unconstrained AI places on security systems everywhere. 

Accident, or design?

After all, for every denied instance in which Meta’s Muse may, or may not, have surveyed private messages, there are now many incidents in which some “rogue” AI has “escaped” to do some kind of harm.

Except it’s quite easy to think these incidents are not really escapes, isn’t it? 

If you do, then this is AI doing precisely what it’s designed to do. 

Rather than railing at Apple, developers and critics should focus on why this change has been put in place. It should be recognized as another of the huge “benefits” most humans are already experiencing at this stage of AI disruption.

It’s a benefit to accompany hyper-inflated memory prices on consumer electronics costs. It’s a benefit that flows with the energy and water price increases we are seeing as AI data centers consume more of both, even as inventors of this tech warn that what they have invested hundreds of billions of dollars in poses an “existential threat” to humanity.

Sure, AI can and does release positive consequences, and I celebrate that, but that doesn’t give it a pass on its damage and risk, particularly existential risk.

Obsolete software

“Redefining” that risk is perhaps why Anthropic co-founder Christopher Olah visited Pope Leo XIV to convince people around the head of the Catholic church that AI can be considered conscious. 

One way to see that argument is that AI is not really an existential threat to humanity if you redefine it as some kind of evolution toward a new super race. It becomes a painful but necessary step toward the next phase of humanity, even if that does sound rather messianic (some say fascistic, as Gil Duran explains).

Thankfully, the Pope didn’t buy it. “Algorithms lack the spark of humanity. For this reason, the Church wishes to renew an alliance with artists and cultural institutions to safeguard our humanity,” he wrote in a recent declaration concerning the impact of AI on creative arts.

If I’m honest, and I do try to be, developers and critics attacking Apple for its decision to lock down this aspect of the Mac experience are focused on the wrong target. You need to reconsider who to blame.

For the many

It’s time, urgently time, for people in tech to get back on the road to what makes it great, which is now and always has been what results from the marriage of technology and liberal arts. AI is not conscious. AI has no moral soul. 

With that in mind, it’s appropriate to ensure that humans have informed agency before they provide AI with access to their data. Religions claim that divinity gave us free will. Do you think AI and the billionaires who own it want us to keep that gift? 

Now please subscribe to my daily, human-curated Apple-related news headline feed at The Core, or follow me on BlueSky, LinkedIn, or Mastodon.

Kategorie: Hacking & Security

The Catch 2026

AbcLinuxu [zprávičky] - 5 Říjen, 2026 - 11:58
Dnes startuje desátý ročník oblíbené kyberbezpečnostní soutěže The Catch organizované Forenzní laboratoří CESNETu. Letos zavede soutěžící do světa národních výzkumných a vzdělávacích sítí (NREN). Čekají na vás tematické úlohy založené na principu Capture the Flag (CTF), hledání ukrytých flagů i zajímavé ceny. Otestujte své schopnosti a vyrazte na lov flagů.
Kategorie: GNU/Linux & BSD

Americká armáda hledá obrněné humanoidy pro nebezpečné mise. Jedním z nich by mohl být Alex

Živě.cz - 5 Říjen, 2026 - 11:55
Americká armáda nedávno uspořádala další ročník soutěže xTechHumanoid, která se už podle svého názvu zaměřuje na využití humanoidních robotů ve vojenském prostředí. Klání se uskutečnilo na základně americké námořní pěchoty Quantico ve Virginii. Letos dorazilo 103 návrhů ve formě odborných ...
Kategorie: IT News

Microsoft: Windows KB5124010 update crashes some games and apps

Bleeping Computer - 5 Říjen, 2026 - 11:37
Microsoft confirmed over the weekend that some games and applications using AC-3 (Dolby Digital) audio decoding will crash after installing the September 2026 KB5124010 Windows 11 preview update. [...]
Kategorie: Hacking & Security

Neničte si páteř koukáním do notebooku. Do kanceláře se bude hodit tento stojan za 499 Kč

Živě.cz - 5 Říjen, 2026 - 10:45
Otočný stojan na notebook Tigo Office ProView zlevnil o 40 % na 499 Kč. • Je skládací, umožňuje nastavit výšku i úhel. • Pomáhá s chlazením, ale hlavně zvedne displej do úrovně očí.
Kategorie: IT News

Google halts open-source bug bounty program amid AI spam surge

Bleeping Computer - 5 Říjen, 2026 - 10:27
Google has now suspended submissions to its Open Source Software Vulnerability Rewards Program (OSS VRP) after being flooded by AI-generated reports. [...]
Kategorie: Hacking & Security

Attackers Target Rejetto HFS Flaw That Enables Admin Session Forgery and RCE

The Hacker News - 5 Říjen, 2026 - 10:09
A critical security flaw impacting Rejetto HTTP File Server (HFS) is witnessing active exploitation attempts, according to VulnCheck. The vulnerability in question is CVE-2026-61500 (CVSS score: 9.3), a case of session forgery stemming from the use of a weak pseudo-random number generator (PRNG) that can lead to a predictable key, which an attacker can then use to gain unauthorized access and Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Ryzen Z3 pro konzole je semi-custom: 4× Zen 6(c), 2× Zen-LP a 768 SP RDNA 4M

CD-R server - 5 Říjen, 2026 - 10:00
APU příští generace pro handheld herní konzole tentokrát nebude vycházet ze standardní řady produktů, ale půjde o semi-custom návrh na míru tomuto segmentu. Chystá se Ryzen Z3 a Ryzen Z3 Extreme…
Kategorie: IT News

Ani třídenní pojistka neudělá z iPhonu nedobytný trezor. Vyšetřovatelé z něj dostanou i smazaná data

Živě.cz - 5 Říjen, 2026 - 09:45
Každý iPhone se po 72 hodinách bez použití tajně restartuje • To proto, aby uložená data zůstala v bezpečí • Ukázalo se však, že forenzní software může automatický restart zablokovat
Kategorie: IT News

Ani třídenní pojistka neudělá z iPhonu nedobytný trezor. Vyšetřovatelé z něj dostanou i smazaná data

Zive.cz - bezpečnost - 5 Říjen, 2026 - 09:45
** Každý iPhone se po 72 hodinách bez použití tajně restartuje ** To proto, aby uložená data zůstala v bezpečí ** Ukázalo se však, že forenzní software může automatický restart zablokovat
Kategorie: Hacking & Security

15 let od smrti Steva Jobse. Vizionář bez kompromisů byl vyhozen z vlastní firmy, aby ji později dovedl na vrchol

Živě.cz - 5 Říjen, 2026 - 08:45
Před patnácti lety zemřel Steve Jobs, jedna z nejvýraznějších osobností počítačového průmyslu. Za svůj život stihl založit Apple, být z něj vyhozen, vybudovat Pixar, vrátit se zpět a pomoci vytvořit počítače, telefony i přehrávače, které změnily celé obory.
Kategorie: IT News

New NetScaler Zero-Day Exploited in Targeted Attacks Can Knock SAML Deployments Offline

The Hacker News - 5 Říjen, 2026 - 08:40
Citrix has released security updates for a high-severity security flaw in NetScaler ADC and NetScaler Gateway that has been exploited as part of targeted zero-day attacks. The vulnerability, tracked as CVE-2026-88779, carries a CVSS score of 8.7 out of 10.0. "CVE-2026-88779 is a memory overflow vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway that can lead to Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Evropa roky zavírala uhelné elektrárny. Kvůli Hormuzu by jich teď potřebovala víc, než jí zbylo

Živě.cz - 5 Říjen, 2026 - 07:45
Kvůli konfliktu mezi Íránem a USA zdražil plyn a Evropa se vrací k uhlí • Výroba elektřiny z uhelných bloků vzroste během půl roku zhruba o 25 % • Obnovitelným zdrojům chybí stabilita a staré elektrárny už víc nezvládnou
Kategorie: IT News

Chystá se 7 modelů Nova Lake, velkou cache poznáte podle „BFC“

CD-R server - 5 Říjen, 2026 - 07:40
Na vydání první vlny produktů postavených na architektuře Nova Lake se chystá 7 modelů s 18-28 jádry. Je možné, že tato nabídka zahrne i jeden 65W produkt…
Kategorie: IT News

Falešný šéf vás požádá o platbu. Firmy tak přicházejí i o desítky milionů

Lupa.cz - články - 5 Říjen, 2026 - 00:00
Stačí e-mail od ředitele, naléhavý požadavek a účet, na který je potřeba rychle poslat peníze. Podvodník přitom nemusí znát heslo k firemnímu bankovnictví. Stačí jen přesvědčit správného zaměstnance, aby platbu provedl sám.
Kategorie: IT News

Život bez banky se prodraží. Za obyčejné platby můžete dát tisíce korun ročně

Lupa.cz - články - 5 Říjen, 2026 - 00:00
Nemít bankovní účet a fungovat jen s hotovostí je pro někoho projev svobody, pro člověka v exekuci zase jediný způsob, jak zaplatit složenky. Klasické pokladny z poboček bank mizí, a tam, kde zůstaly, zaplatíte za vklad třetí osobou i více než stokorunu.
Kategorie: IT News

Postřehy z bezpečnosti: forenzní software české policie má skryté ruské vazby

ROOT.cz - 5 Říjen, 2026 - 00:00
Podíváme se na forenzní software české policie se skrytými ruskými vazbami, kritickou chybu ve FortiMailu, AI agenty útočící na vládní weby USA a Kanady, rozbití gangu KillSec a únik dat tří milionů lidí z Pentagonu.
Kategorie: GNU/Linux & BSD

postmarketOS se nově jmenuje Nura, GhostBSD připravuje nové prostředí

ROOT.cz - 5 Říjen, 2026 - 00:00
Projekt postmarketOS dostal nové jméno Nura. GhostBSD připravuje nové desktopové prostředí Mocka, které má v budoucnu postupně nahradit MATE. OpenMandriva vydala nový snapshot své rolling-release distribuce ROME s označením 26.09.
Kategorie: GNU/Linux & BSD

Mini Commander 2.0 přichází s podporou UTF-8

ROOT.cz - 5 Říjen, 2026 - 00:00
Vydávám Mini Commander verze 2.0, novou verzi malého dvoupanelového správce souborů pro Linux. Je napsaný v C, používá ncurses a obsahuje vlastní prohlížeč i editor souborů.
Kategorie: GNU/Linux & BSD

Německo staví nejvyšší větrnou turbínu na světě

OSEL.cz - 5 Říjen, 2026 - 00:00
V Německu vyrostla větrná turbína, která i s rotorem měří 365 metrů. Kromě rekordu samotného by po uvedení do provozu měla poskytnout data, z nichž vyplyne, jestli velká výška skutečně přináší očekávaný nárůst výroby větrné energie. Pokud jde o větrné turbíny, platí, že vyšší je lepší?
Kategorie: Věda a technika
Syndikovat obsah