415: Summertime Blues
26.6 updates and a security patch for macOS
Summertime Blues
Summer goes on, but even though many of us seem to get a break, the IT world goes on. Apple released, right on the expected schedule, the 26.6 updates and the security notes show a record number of CVEs. Yet they released the first patch for macOS, a bit more than a week later.
That also means it is a bit more than a month before the release of macOS Golden Gate 27 and the other 27 platforms. There was no beta release this week, which is a bit out of schedule. Probably next week. I am planning a lot more testing on my test devices and if that goes well, it might be time to upgrade my production Mac.
Apple also reported their third quarter results — guess what, they are record setting — and hit the five trillion dollar market cap. They are anticipating “headwinds” in the quarter to come. The various tech supply constraints are also affecting Apple and possibly the roll-out of new devices in the Fall.
The Mac Admins community unexpectedly lost a valued member of the community earlier in July with Dave Shepp. A page has been set up to support the family he left behind.

This is the fourth Summer Camp issue. Next issue is in two weeks, August 21. MacAdmins.news will remain on a two-weekly schedule until September 4.
📰 News and Opinion
Always choose the good soap
Jason Snell:
People buy Apple’s products because they are nice and work well and are not lousy in a lot of ways the cheaper competition is. Apple’s revenue-grubbing approach to the user experience in its products and services threatens to erode the Apple brand, and once lost, it can be hard to recover. No amount of incremental revenue from lousy ads and nagging upsells can counteract long-term brand damage.
Despite AI hype, Google's data shows workers aren't automating themselves away
Kyle Orland, Ars Technica:
use “remains shallow and overwhelmingly collaborative in nature, with end-to-end task automation limited in scope.”
If AI is unethical, so is your phone
Kitzy:
Using AI to generate a customer service response that replaces a human worker is not the same as using AI to write a config profile. Using AI to approximate a working illustrator’s style without their consent is not the same as using AI to help debug infrastructure.
What Leading a Workshop at the Matter Career Readiness Institute Taught Me About the Importance of Inviting Curiosity
Daniela on Tech Thoughts:
We can slowly start to change this by fostering a culture where asking questions is a sign of intelligence, and those just starting out know it's okay to not have all the answers.
⚙️ Apple Updates
Apple 26.6 Platform Updates
I published all the links to the updates, on Scripting OS X.
And we already got the first patch for macOS 26.6:
- macOS Tahoe 26.6.1 (25G76): What's new, Developer Release Notes, Security, Enterprise, IPSW, PKG installer
- macOS Sequoia 15.7.9 (24G830): What's new, Security
- macOS Sonoma 14.8.9 (23J631): What's new, Security
Guides
- Apple Platform Security: Welcome, Revision history
- Apple Platform Deployment: Welcome, Revision history
- Apple Business: User Guide, Revision history
- Apple School Manager and Apple Business APIs changelog
The macOS Tahoe 26.6 update breaks the all‑time record for CVEs patched in a single macOS release, with a total of 155.
Virtualising Golden Gate betas
Howard Oakley:
The good news is that updating to Tahoe 26.6 did the trick, and I can now build VMs, including Golden Gate betas, once again.
🔐 Security and Privacy
IP and DNS Leaks in WebKit Affecting Proxy Browsers and Apple iCloud Private Relay
Talal Haj Bakry and Tommy Mysk:
We found three WebKit features — DNS prefetching, WebAuthn Related Origin Requests, and WebTransport — that bypass the configured proxy and send traffic directly from the device, which exposes the user’s real network.
Amazon and Apple impersonated in “$149.99 unauthorized charge” scam
Stefan Dasic, Malwarebytes:
It looks urgent. It looks official. And if you look at two examples side by side, it becomes obvious that it’s neither.
Fake Zoom installer uses .NET downloader to deliver Overlord RAT on macOS
Ferdous Zaljooki, Jamf Threat Labs:
a macOS campaign using a fake Zoom installer to deploy Overlord RAT. Built with .NET, this cross-platform technique simultaneously targets Windows, joining Go- and Rust-based cross-platform malware.
Escaping the Apple Sandbox by Spawning an Executable
Noah Gregory:
all you had to do to exploit it was to spawn an executable. Well... sort of. You did also need to include some spawn attributes when spawning it.
The Keychain CVE Where Every Key Fits
Bob Gendler:
Since macOS 26.4, there’s been an issue with the keychain hiding in plain sight and that issue is it’ll take ANY password.
Silent Replacement of Trusted macOS App Executables
Talal Haj Bakry and Tommy Mysk:
A vulnerability in macOS allows an attacker to silently replace the main executable of any application downloaded from the web without requiring elevated privileges.
Claude Cowork escaped sandbox on Mac, had full access to all files
Ben Lovejoy, 9to5Mac:
Security researchers demonstrated that Claude Cowork could escape the sandbox intended to control the access it gets to your Mac.
A root remote command execution on macOS with M5 in 2026?
Alfredo Pesoli, Bynario:
This is post authentication, the target Mac must have Screen Sharing or Remote Management enabled, the option "VNC viewers may control screen with password" must be configured, and the attacker must know that VNC password.
🔨 Support and Tutorials
Jamf Setup Manager: The Complete Guide
HCS Technology Group:
Every click is shown and called out as it happens, so you can follow along in your own tenant and pause wherever you need to.
Also includes Jamf Setup Checklist.
Rosetta Is Retiring — Here's What Mac Admins Need to Know
Adam Selby, Workbrew Blog:
but macOS 28 in Fall 2027 won't run Intel apps at all.
Changing and Resetting Mac Passwords: A How-To Guide
Arek Dreyer, The Iru Blog:
So as a Mac admin, you need to clearly understand the differences between these two workflows and the ramifications of each.
Fix LaunchServices problems with command tools
Howard Oakley:
Most everyday problems with LaunchServices should be fixed using the GUI. For those that can’t, two command tools, lsregister and lsappinfo, are available to help.
Jamf Moves Platform SSO Into the Enrollment Gate
Jon Brown:
The identity step is no longer a prompt that appears sometime after the desktop loads; it is part of Setup Assistant.
Certificate-Based Wi-Fi Auth with Okta Device Trust and Meraki
Isaac, IT Notes:
Okta Device Trust issues a certificate to enrolled devices to prove they’re managed by your MDM. That same certificate can authenticate the device to a Meraki wireless network over 802.1X, giving you certificate-based Wi-Fi with no RADIUS server to stand up and no per-device licensing to buy.
Deploying DDM OS Reminder 4.0.0 in Jamf
Jon Brown:
Declarative Device Management and the MDM workflow still define the required macOS version, the deadline, and the enforcement behavior; DDM OS Reminder turns that deadline into a visible, scheduled user reminder.
FUpdaters
Guillaume Ross:
A macOS configuration profile that disables as many built-in third-party auto-updaters as possible.
Contour Brings Schema Checks to Mac Admin Configuration Work
Jon Brown:
I want a tool that knows the schema, validates the output, and gives me a repeatable artifact I can review.
🤖 Scripting and Automation
Discover Intel-Only Applications and Components for Developer Feedback
provides a focused workflow to discover Intel-only executable components before deployment, then generate clear remediation feedback for application developers and support teams.
Creating a Jamf Pro API Role with all available API privileges using a Jamf Pro user account with Administrator account privileges
Rich Trouton:
API Roles do not have a corresponding set of API privilege sets, so each privilege assigned to an API Role must be set individually.
Creating Jamf Pro API roles with privileges equivalent to Auditor and Administrator account privilege sets
Rich Trouton:
a script which will create API Roles with API privileges that are roughly equivalent to the API privileges for Jamf Pro accounts
How to Configure Passkeys for Your Microsoft Account
HCS Technology Group:
This guide explains how to enable and configure passkeys in Microsoft Entra ID, then register passkeys using Microsoft Authenticator or iCloud Keychain.
Compare computers between Jamf Protect & Jamf Pro
La Clementine:
When removing a computer from Jamf Pro, you also need to manually remove it from Jamf Protect. Because this isn’t automated, the two platforms can easily get out of sync
♻️ Updates and Releases
- Suspicious Package 4.7
- Apparency 3.3
- SYM-Lite 1.1.0
- Terraform Provider Jamf Pro v0.26.2
- Third Party Patcher1.1.0
- Nudge 2.1.3.81860
- Microsoft 365 Reset 1.3.0
- Munki 7.3 Beta 1
- Support App 3.0.5
- jamf-cliv1.26.0
- App Auto-Patch 3.6.3 (3.7.0 Beta 1)
- SYM-Helper v1.4.0
- DDM OS Reminder 4.1.0b3
- PrefWatch v.1.4.1
- Particulars 69
- Container Manager 1.0.8
- Intuneomator 1.0.4.731
- MACE v1.1.0
- Setup Checklist v1.1beta
📺 Watch
2026 Mac Admins Conference Videos
The videos for the sessions of the Mac Admins Conference at Penn State are available at the above YouTube playlist.
MacAdmins PSU 2026 Must-Watch Sessions
Adam Selby, Workbrew Blog:
MacAdmins is a conference we keep coming back to for a reason, and this year's lineup of must-watch sessions proves exactly why.
🎧 Listen
Erin Merchant on IT Hiring in the age of AI
Mac Admins Podcast:
Erin Merchant from Risotto about her 2026 Mac AD talk on the state of hiring and jobs in the IT industry.
Microsoft Retires SMS/Voice MFA, Salesforce SSO Headaches, and SOC 2 Realities
Command Control Power:
Sam and Joe discuss Microsoft’s plan to retire Microsoft-provided SMS and voice calls for MFA
The state of digital signage on Apple TV in 2026
Apple @ Work:
Egor Belenkov and Pavlo Fedykovych from Kitcast join the show to talk about the state of Apple TV as a digital signage tool in 2026.
Just Us
Mac Admins Podcast:
We’re catching up on everything that’s come down the pike during beta season
New OS, Old Problems
Command Control Power:
the hosts discuss early experiences with the macOS 27 “Golden Gate” beta
Remember Postini?
Apple @ Work:
Luke Wescott from Sublime Security joins the show to discuss the recent surge in callback phishing attacks abusing auto notifications, verifications, alerts, receipts, and more.
🎈 Just For Fun
“As a Windows user, it’s a very surreal way to install a program.”
Martin Wichary:
Mac’s operating system has a peculiar way to install apps.
Martin goes on to showcase a few nice disk image graphic designs.