407: Post Conference videos, PSSO, and Papercuts
Entering the lull before WWDC.
It may be summer, but the living ain't easy…
Sponsor

Do you know where Homebrew is running across your fleet right now?
Most teams don’t. brew is already installed on developer Macs. The challenge is visibility: what packages are installed, which versions are running, and where vulnerabilities exist.
Workbrew Free gives you a complete real-time inventory of Homebrew across your fleet. Deploy through any MDM and within minutes you can see every package, dependency, and CVE with zero disruption to developers or existing workflows.
No credit card. No device limits. No expiration.
Post Conference videos, PSSO, and Papercuts
We are entering the lull before WWDC.
To pass the time, session videos are now available for Mac Admins Europe and MacAD.UK. After WWDC, we have MDOYUL, and MacAdmins Conference at Penn State coming up. Jamf Nation Live London and Berlin are also in June. Mac Admins Connect India and X World will take place in August.
Looking forward to a busy and great summer for Mac Admins!
📰 News and Opinion
Apple Papercuts
Rui Carmo, Tao of Mac:
Every one of these is fixable. Most have been fixable for years. The pattern isn’t technical inability–it’s neglect.
AI Slop is Killing Online Communities
Robin Moffat:
Like a young child coming home from kindergarten with their latest crayon scrawls, the internet is currently awash with people sharing their AI-generated work. And just like the young child’s drawings, much of that work should be proudly put up on the walls within the artist’s house—and no further.
Vibe-coded Mac apps are arriving fast — here is what gets lost in the process
Roman Kaplun, MacPaw, at Hackernoon:
What is worth examining is what happens when this wave reaches software operating at a deeper level of a user's system. Free, open-source Mac utilities are appearing on GitHub many positioning themselves as a CleanMyMac alternative or as replacements for other established Mac tools.
A Lot of Firsts at MacAD.UK
Mirko Steinbrecher on Jamf Community:
MacAD.UK gave me a lot of firsts: my first visit to Brighton, my first professional conference talk, my first experience working so closely with a mentor on a presentation, and a reminder of how open and supportive the Mac Admins community can be. I met wonderful people, had great conversations, and left with the strong feeling that I would love to come back.
⚙️ Apple Updates
Apple unveils new accessibility features, and updates with Apple Intelligence
Apple Newsroom
Apple today previewed a suite of accessibility updates that use Apple Intelligence to bring new capabilities to features users rely on every day, including VoiceOver, Magnifier, Voice Control, and Accessibility Reader.
🔐 Security and Privacy
SHub Reaper: macOS Stealer Spoofs Apple, Google, and Microsoft in a Single Attack Chain
Phil Stokes, SentinelOne:
Reaper uses fake WeChat and Miro installers as lures, but what stands out is the way the infection chain shifts its disguise at each stage.
Breaking macOS App Sandbox Data Containers, TCC, and Hijacking Apps Using Archive Utility
Talal Haj Bakry and Tommy Mysk:
Until macOS 26.4, Archive Utility had nearly unrestricted filesystem access. Combined with a drag-and-drop sandbox quirk, this let an attacker bypass App Sandbox data containers, Transparency, Consent, and Control (TCC) protections, and hijack third-party apps
🔨 Support and Tutorials
Managed Migration Assistant
Adam Selby:
Offering a supported managed migration may help ease some friction with users who have still not moved from Intel-based Macs to Macs with Apple silicon.
Apple Cache Service: a primer and why you may want to deploy it in your organization.
Adam Tomczynski: (posting on LinkedIn)
if your network is equipped with Mac(s) running the Apple Content Caching Service, this same content is downloaded one time from the Internet, and then shared from the local network storage.
"They're taking my brew away": A practical guide to managing Homebrew
Kitty Shephard, Workbrew:
This is a practical guide for the IT admin who has to do something about it without breaking everything in the process.
How to actually use AI to manage your fleet
Kitzy:
If you point an AI coding agent at a vanilla MDM repo and prompt it to add a profile, you’ll get something back. It might even apply cleanly. It also might quietly overwrite an existing profile because it reused the identifier from the file it copied.
🤖 Scripting and Automation
Backup the Backups
Mat X:
And Archiware have been great to entertain my feature requests and ideas for making P5 do what I wanted. Mostly extending the cli (and API) to help monitor the system with MunkiReport and a variety of shell scripts.
♻️ Updates and Releases
- iMazing 3.5.3
- iMazing Profile Editor 2.2.1
- BBEdit 16
- Workbrew 1.9
- Contour v0.3.0-beta.3
- JamfDash - 0.4
- super v5.1.0-rc5
- API Utility v0.9.0
- Microsoft 365 Reset 1.2.0, blog post
- DDM OS Reminder 3.3.0, blog post
- MunkiReport 5.8.1
- Python 3.14.5.80757
- MACE v0.1.8-beta
- MunkiReport 5.8.1
Xpsso
Tim Perfitt, Twocanoes:
XCreds includes Xpsso, an innovative micro-service to enable Apple’s built-in Platform Single Sign-On (PSSO) to work with Identity Providers (IdP) that have not been extended to support cloud binding of Mac systems.
Platform SSO during automated device enrollment is now generally available for macOS
Microsoft Blog:
we’re excited to announce that Platform SSO (PSSO) during Automated Device Enrollment (ADE) on macOS is now generally available.
📺 Watch
MacAD.UK 2026 (YouTube)
🎧 Listen
Live at Mac Admins Europe 2026
Mac Admins Podcast:
This episode is not that – it has many guests- who will introduce themselves, a hazy plotline, and was recorded with a stolen microphone, unofficially, guerilla style at the first ever MacAdmins Europe conference. Follow me throughout the day as I [Selina] accost victims- I mean guests- on the spot and ask questions about the conference, their perspectives, and what they’ve enjoyed most.
Adam Engst (TidBITS) Apple at 50 — The Anniversary Nobody's Talking About: Community, HyperCard, and What We Lost
Command Control Power:
Adam Angst of TidBITS reflects on Apple’s 50 years through the lens of early tech idealism, arguing that what mattered most wasn’t Apple itself but the community around it, which was weakened by shifts like the end of Macworld keynotes, Apple’s vertical integration, and the decline of user groups and independent resellers.
How NeXT built the foundation for Apple in the enterprise
Apple @ Work:
Geoffrey Cain, author of Steve Jobs in Exile: The Untold Story of NeXT and the Remaking of an American Visionary. We talk about the book, how Steve became a leader at NeXT, and how the foundation that was built during this period led to Apple's enterprise success in 2026.
Why More Security Tools = Less Security with Jonathan Poon, Zoom
Patch Me If You Can:
Zoom's Head of Threat & Vulnerability Management on why more security tools often means more problems, and how to fix it.
AI is distorting the Holocaust
Lock and Code:
Clara Mansfeld, a historian working on digital communications at one of the institutions signed onto the open letter—the Foundation of Hamburg Memorials and Learning Centers Commemorating the Victims of Nazi Crimes.