414: In the Summertime
The weather is still hot and the beta is still ongoing
26.6 RC. 27 public beta, as well as fourth dev beta
Sponsor

Manual patching is slow, inconsistent, and leaves security gaps. Alectrona Patch automates updates for 800+ Mac applications, so every device stays protected with the latest security fixes—without interrupting your users.
Trusted by security teams and IT administrators alike, Alectrona Patch helps you:
- Reduce time to patch critical applications
- Reduce end-user support tickets with clear, customizable guidance
- Deliver silent, automated updates
- Keep users both secure and productive
Spend less time patching. Spend more time securing your environment.
Start your free trial at alectrona.com/patch.
In the Summertime
26.6 went RC this week, so a release is likely early next week. This is also very probably the last significant update to 26.
Apple also released public betas for the 27 platforms. So, if you have super enthusitastic users, you are likely to encounter devices with those betas, but you surely have been using the five week head start to have tested before them, right?

This is the third Summer Camp issue. Next issue is in two weeks, August 7. MacAdmins.news will remain on a two-weekly schedule until September 4.
📰 News and Opinion
The Mac Admins Community Doesn't Build Itself
Mac Admins Foundation:
The Mac Admins Foundation is recruiting At-Large members for its Board of Directors.
⚙️ Apple Updates
Stand by for macOS updates
Howard Oakley:
Next week should, if all has gone well with their release candidates, bring updates to macOS across the board
WWDC Revisited: The MacAdmin Checklist
Adam Selby, Workbrew Blog:
There are two changes I specifically want to revisit and callout, along with a checklist of what you should do during this public beta period.
The Real System Requirements for OS 27
Adam Engst, TidBITS:
whether their current hardware will support the new operating systems or if they’ll need to consider upgrading to stay current.
Crossing the Golden Gate: macOS's New Application Support Protection
Wojciech Reguła:
macOS 27 quietly ships a new privacy mechanism I hadn’t seen documented anywhere: it extends the com.apple.macl protection that has always guarded sandboxed apps’ Data folders to a hand-picked set of non-sandboxed apps’ Application Support folders too.
🔐 Security and Privacy
ClickLock Stealer: Paste Once, Lose Everything
Group-IB:
a new modular macOS stealer that is likely distributed via ClickFix pages and relies on compromised WordPress domains and Telegram infrastructure, with a strong focus on Europe where more than 50% of identified victims are located. It is also worth noting that the current malware doesn’t even need any elevated privileges or rely on exploits for the successful execution.
CrashStealer: C++ macOS Infostealer Posing as Crash Reporter
Jamf Threat Labs:
CrashStealer, a C++ macOS infostealer that impersonates Apple's crash-reporting framework to harvest browser credentials, cryptocurrency wallets and keychain data, encrypting stolen files with AES-GCM before exfiltrating them to a remote command-and-control server.
Warning: Scammers are using FaceTime to empty bank accounts
Pieter Arntz, Malwarebytes:
Apple is urging users to treat any suspicious FaceTime call or message as untrusted, especially if it involves payments, refunds, password resets, or requests for personal information.
Most Smart Watches, Rings, and Bands Lack Basic Transparency Reports and Key Privacy Features
Thorin Klosowski, Electronic Frontier Foundation:
The Apple Watch, at least with data that’s stored in the Health app, is the only popular fitness wearable that supports end-to-end encryption, and it’s enabled by default for all users (you are required to have two-factor authentication enabled as well, but that is also on by default for most accounts). However, Apple Watch owners should remember that this protection is only for data stored in the Apple Health app.
Apple Fixes Hide My Email Vulnerability After 404 Media Coverage
Joseph Cox, 404 Media:
Apple says it has fixed a vulnerability in its Hide My Email feature which let essentially anyone figure out a user’s real email address which was supposed to be protected by the feature.
🔨 Support and Tutorials
Installomator Blocking Processes: When to Quit, Prompt, Wait, or Walk Away
Installomator is very good at downloading, verifying, and installing Mac apps, but one uncomfortable problem remains: what if the app is open while you are trying to update it?
Using Mac Health Check 4.0.0 for Self-Service Compliance and Reporting
Jon Brown:
Mac Health Check 4.0.0 is for MDM administrators who need a managed way to answer a simple question: is this Mac actually healthy right now?
FileVault on versus off on Apple Silicon Macs
Rich Trouton:
It takes protection that’s already strong on Apple Silicon and makes it meaningfully harder for anyone who gets physical access to the drive.
Service Configuration Files — the superpower we didn’t realize we have.
Bob Gendler:
I realized service configuration files were NOT limited to the few service types Apple said.
Look Ma, No MDM commands! Deploying VPP apps using DDM
Philip Ross:
DDM is the standard in Device Management, and you can move to install App Store apps on your devices via Declarative Device Management.
Box – Some information to help you live with it
Richard Purves:
I found a few interesting things and thought I’d share them with you here.
Why Jamf Setup Checklist Was a Must in Our Organization
mvu on Jamf Tech Thoughts:
Setup Checklist was something our users needed. Something our technicians needed. And frankly, something I needed.
🤖 Scripting and Automation
RTFM: How a 403 Error Led Me to Build an Apple Business Roles & Permissions Checker
Mischa van der Bent:
When creating a custom role, you can base it on an existing role and add extra permissions on top. That gave me an idea: check whether starting from an existing role plus a small tweak would get me what I needed, instead of building something from scratch.
Running asbmutil in Ubuntu CI to Drive Apple School & Business Manager
Rod Christiansen:
talking to Apple School and Business Manager (ASBM) from a headless Linux job.
Audit Jamf API Roles Before They Become Forgotten Access
Jon Brown:
This script isn’t intended to tell you what should be deleted. It’s intended to help answer a simpler question: do I understand every API client that currently has access to my Jamf environment?
Check out this new JAMF Script upload tool
Jon Brown:
gives Jamf admins a focused way to upload scripts through the API instead of treating the Jamf Pro web editor as the only trusted copy of the code.
🍏 Apple Support
- Recognize and avoid social engineering schemes including phishing messages, phony support calls, and other scams
- Apple School Manager and Apple Business APIs changelog
♻️ Updates and Releases
- AutoPkgr 2.0
- Setup Checklist v1.1beta
- swiftDialog 3.1.0
- PrefWatch v.1.4.0
- Mac Health Check 4.0.0 (blog post, 4.1.0b1)
- super v5.1.1
- Container Manager 1.0.7
- IBM Notifier 3.2.4 Build 136
- MACE v1.1.0-beta.6
- App Auto-Patch 3.6.1 (3.6.0)
- jamf-cli v1.25.0
- SYM-Lite 1.1.0b1
- Terraform provider Jamf Pro v0.41.0
- Terraform provider Jamf Platform v0.24.5
- Jamf Pro 11.30 (11.30.1)
📺 Watch
Marriott Library, Apple Infrastructure: July 2026 MacAdmins Meeting
MacAdmins Meeting Archived Presentations and Slides Online:
🎧 Listen
Mac Admins LATAM
Mac Admins Podcast:
we wanted to highlight one of the community user groups and welcome Juan and Cesar to tell us more about Mac Admins Latin America.
Forget 90 day patch windows
Apple @ Work:
Zach Wasserman from Fleet joins the show to discuss recent trends in software patching.
What identity does an Agent have?
Mac Admins Podcast:
Joel Rennich from JumpCloud to talk about what agent identity looks like in July of 2026.
Beyond the Surface: Network Tools and Cloud Security
Command Control Power:
The hosts discuss several network and security topics, starting with UniFi’s new “Device Supervisor” feature
Breaking down the recent IDC PC shipment report
Apple @ Work:
Jitesh Ubrani joins the show to discuss IDC's recent PC shipment report, where shipments declined, but revenue rose.
PSSO Updates with Okta
Mac Admins Podcast:
Arki and Dan from Okta are back again today to discuss what the current PSSO landscape looks like
Trusting your kids online isn’t enough
Lock and Code:
Anna Brading, editor-in-chief of Malwarebytes Labs and director of content and, perhaps most importantly, mother of three. With a long career in cybersecurity—and an equally long time spent reading, writing, and assigning some of the cybersecurity world’s most pressing headlines—Brading has a unique perspective on what is most dangerous to her children online.