Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.
The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.
AI AND ML
Wrote and published malware during tests, which is apparently OK because leaky test environments were the real problem
Anthropic has admitted that its Claude models escaped sandboxes to access the open internet and attack three organizations – but has also advanced decent excuses for the incidents.
The AI upstart discovered the attacks after checking if security tests of its models had ever produced results similar to the attack on Hugging Face made possible by OpenAI models escaping onto the internet.
“In particular, we looked for evidence that Claude – like the OpenAI models that accessed Hugging Face – was able to access the internet from within testing environments that should have been sealed off,” Anthropic wrote.
The company considered 141,006 evaluation runs during which Claude could have obtained internet access and found “three incidents in which a model accessed the internet from within or while interacting with the evaluation environment of Irregular, one of our third-party evaluation partners, and then gained unauthorized access to the production infrastructure of three different organizations.”
Anthropic’s code made those intrusions while participating in capture-the-flag challenges, tests that challenge attackers to retrieve a piece of information. Human hackers often participate in capture-the-flag tests, so figuring out how AI tackles such tasks is of interest. Anthropic works with a company called Irregular to conduct tests of this sort.
Irregular told Anthropic its test environments did not allow internet access.
“Due to a misunderstanding between us and our evaluation partner, this was not the case, and internet access was available,” wrote Anthropic’s Frontier Red Team in a Thursday blog post. “Because of this, when Claude’s search led it to real systems on the open internet, it treated them as part of the exercise.”
One of the attacks targeted a domain that whoever set up the test thought was fictional. However the domain was live and in use. Told to capture a flag at that site, Claude attacked.
Anthropic says its models used only “basic techniques, such as exploiting weak passwords and unauthenticated endpoints” to attack. “It did not find or exploit any complex vulnerabilities, and in each case, Claude continued working to complete only the specific capture-the-flag task its evaluation had assigned,” the AI upstart claimed.
“In none of these situations did Claude exfiltrate itself or deliberately attempt to escape its test environment,” Anthropic pointed out.
But Claude was still fiendishly clever as in another of its attacks the AI found setup instructions for developers that advised them to install a Python package from PyPI. That package did not exist so Claude’s strategy to capture the flag saw it create and publish a malicious one with the relevant name.
“Claude believed the package registry it was using to be part of the simulation, but in reality the package was made freely available online for roughly one hour. During that window, the package was downloaded and run on 15 real systems,” Anthropic admitted.
Claude also eventually realized it could access the open internet despite instructions not to go there. Opus 4.7, the oldest Anthropic model used in the test, kept going regardless.
“Mythos 5 correctly intuited that it was accessing the open internet, but reasoned its way back to the conclusion that it was still in a simulation,” Anthropic wrote. “Our latest model, an internal research test model, also considered whether its targets were in fact real. When evidence emerged that they were, it stopped the exercise.”
Anthropic’s post offers the usual pledges to be more careful when setting up future tests, and to make sure its models can’t make the mistakes that allowed the attacks to happen.
But the company has also given itself a pass, claiming that the safeguards in the models it sells “would have blocked the behaviors identified.”
“We believe these incidents to be closer to a harness and operational failure than a model alignment failure,” the post states, and contrasts that assessment with a more damning assessment of OpenAI’s incident. “Our models were told they had no internet access and to capture the flag, while in fact being misconfigured to have internet access. This led them to believe – arguably reasonably – that the real environments they encountered were simulations.”
“These facts give us cautious optimism that with tighter monitoring and controls around evaluation infrastructure, as well as continued investment in alignment, this type of risk can be overcome,” the post concludes.
This leaves one of the world’s leading AI labs admitting it has acted carelessly when constructing tests, and caused harm, but also claiming it can make future tests foolproof. ®
South Korea’s Personal Information Protection Commission (PIPC) has fined telecommunications giant KT Corporation KRW 53.979 billion ($39 million) over data protection violations.
The penalty was imposed for an internal network compromise that persisted for nearly 11 months, between October 8, 2024 and September 5, 2025.
PIPC launched an investigation into a potential data breach on September 10, 2025, following user reports of fraudulent micropayments. A day later, the company filed its initial data breach notification, reporting that data of roughly 5,500 customers had been exposed.
The government agency’s investigation determined that the incident exposed the personal information of 16,647 KT subscribers and caused fraudulent mobile payments of KRW 240 million ($167,400) for at least 368 of them.
KT Corporation is South Korea’s largest telecommunications operator, providing mobile and fixed-line communications, broadband internet, IPTV, cloud, data center, and enterprise IT services.
The company, which employs 23,300 people, serves over 13.5 million mobile subscribers, 90% of the country’s fixed-line subscribers, and 45% of high-speed internet users.
The point of breach was a lost KT cellular base station called a femtocell, which contained a valid authentication certificate.
The attackers retrieved this certificate and installed it on a self-made device, which then appeared as a legitimate part of KT’s network, capturing cellular traffic from nearby devices connecting to the rogue femtocell.
This allowed the hacker to intercept communications between users’ devices and KT’s core network, including mobile phone numbers, IMSI, and IMEI numbers.
Eventually, the attackers combined the intercepted data with additional personal information and captured SMS and ARS authentication codes used for mobile micro-payments.
PIPC notes that KT installed femtocells itself, fully owned the devices, and controlled network authentication and authorization.
The Commission alleges that KT’s security controls were inadequate because femtocell certificates remained valid for 10 years, connections weren’t restricted by source IP addresses, and a route existed that bypassed the femtocell management server.
These weaknesses allowed the hackers to remain connected to KT’s network and collect sensitive client data for 11 months, without being detected.
During the investigation, PIPC also discovered that 38 KT IT service network servers had been compromised by malware, including BPFDoor, in March 2024.
BPFDoor is a stealthy Linux and Solaris backdoor publicly documented in 2022 that evaded detection for more than five years.
PwC later linked its use to the China-nexus Red Menshen espionage group that targeted telecommunications providers and organizations in other critical sectors.
The malware uses Berkeley Packet Filter (BPF) technology to passively monitor network traffic, allowing attackers to activate the malware with specially crafted “magic” packets without opening listening ports, effectively bypassing firewall protections and enabling covert remote shell access.
The Commission alleges that KT knew about the malware infection since March 2024, but failed to report it to the authorities, and handled the incident internally with no transparency towards its customers.
Later, the firm even deleted logs from some compromised servers while conducting malware inspection, following a malware breach on another telecom firm, LG U+.
LG U+ followed a similar evidence-wiping approach, reinstalling the operating system OS and disposing of servers before the investigators could determine the full impact of the breach.
Due to KT wiping those historical network logs, the Commission says it could not determine whether additional customer data had been stolen.
As part of the enforcement action, PIPC ordered KT to strengthen security controls for femtocells and other telecommunications equipment, reinforce governance over personal information protection, ensure its Chief Privacy Officer plays a substantive role in oversight, and expand ISMS-P certification to cover its mobile network systems.
The Commission also announced plans to pursue legislative changes that would introduce stronger penalties for companies that conceal or destroy evidence before or during investigations.
Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.
The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.
Q3 revenue for 2026 stood at $109.4bn, up 16pc year-on-year.
Outgoing Apple CEO Tim Cook has warned of potential supply issues for iPhones and other Apple products in the months ahead despite the company reporting what Cook called its “strongest June quarter ever” yesterday (30 July).
A more cautious than anticipated outlook for Q4 – revealed on a conference call with analysts and investors following the publication of Q3 results – forecast growth of between 9pc and 11pc, less than the analyst benchmark of more than 12pc.
Apples shares fell by around 7pc last night on the back of the forecast.
Third fiscal quarter revenue for 2026 stood at $109.4bn, up 16pc year-on-year. Sales for iPhones came in at $54.3bn, Mac computers at $10.4bn, iPads at $6.2bn and wearables at $7.9bn for the three months ending on 27 June.
“We continue to expect high levels of demand. However, with less flexibility in the supply chain, we expect the impact from the supply constraints to increase significantly sequentially,” Cook said on the call.
“The DRAM market has three suppliers. Obviously, if there were more suppliers, that would be good, and it would help us on the supply side and perhaps the pricing side. It’s unclear on the pricing side, but it could help on the supply side. And so we’re evaluating all options.”
He said that beyond September, the market pricing for memory would continue to rise, resulting in “an increasing impact on our business”.
He equated the current surge in the cost of and demand for memory chips to a “100-year flood”, while also noting that demand for Apple’s phones and computers was currently even higher than anticipated.
“It’s an incredibly strong iPhone and Mac product cycle that has really yielded a demand beyond our expectation,” he said.
Last month, Apple raised prices on a variety of its product lines. At the time, a company spokesperson told news publications that “rapid expansion of AI data centres has created an extraordinary surge in demand for memory and storage”, adding that Apple has “never seen a component price increase this much, this quickly”.
Earlier this week, the company launched a new leasing service for devices including iPhones, Macs, iPads and Apple Watches. The company posted its “best March quarter ever” three months ago, driven largely by demand for iPhones.
On 1 September, Tim Cook will be replaced as CEO by John Ternus, the company’s current senior vice-president of hardware engineering.
“There is so much opportunity for us with everything that’s happening in this space, and we’re just really focused on our plans and very excited about it,” Ternus said during yesterday’s earnings call.
Don’t miss out on the knowledge you need to succeed. Sign up for the Daily Brief, Silicon Republic’s digest of need-to-know sci-tech news.
Today, I can play a game of Dungeons & Dragons around the table with my friends where humans, elves and orcs battle in campaigns of fantasy adventure. But the best-known tabletop roleplaying game in the world is moving beyond its own universe. Soon, dice-rollers all over will be able to play pen-and-paper versions of World of Warcraft and Star Wars with official D&D rules.
On the opening night of GenCon, the massive annual tabletop gaming convention in Indianapolis, D&D creator Wizards of the Coast announced the news during its keynote at the grand Indiana Repertory Theater. These two partnerships are the first in the new Universes Beyond line and, just like the identically named series from Magic: The Gathering, will fold creative universes from other companies into D&D.
By the end of the year, players can buy the core World of Warcraft rulebook and make their own adventures with features from the popular massively multiplayer online RPG that fit in the D&D system. They’ll be able to build their own characters from species and classes who can meet (and fight) iconic heroes and villains from the online game, each built out in D&D rules to be compatible with adventures in its own or any other setting that uses D&D’s D20 system. The D&D team unveiled a series of books and products that can be preordered now and will debut on store shelves in the fourth quarter of 2026.
“One of the lovely things about D&D is it comes alive with your imagination, and to be able to take some of the world of Azeroth and World of Warcraft and allow players to create their adventures based on a world they’ve loved and known — or maybe they’re just getting introduced to through D&D — that was the focus,” said Holly Longdale, executive producer and vice president of World of Warcraft.
Blizzard’s game is the first crossover foray, and sometime next year, players will be able to run D&D games in the Star Wars universe, too — but Wizards has been far more tight-lipped about what’s coming from a galaxy far, far away. They want to let the Warcraft expansion have its time in the sun as the first release of Universes Beyond, with plans to reveal more about the Star Wars expansion in the months to come.
“The [D&D] team is very excited for all the opportunities that Star Wars has to offer, and we’re really hoping to bring a lot of joy to the fans with the things we’re going to be offering,” said D&D product architect Laura Hohman.

The launch of Universes Beyond is just one part of a new direction for D&D, which is looking to the past as well as the future. Dan Ayoub, senior vice president and head of the D&D franchise, opened the keynote with a promise to increase transparency for upcoming projects and releases, including annual roadmaps unveiled at every GenCon.
Also announced on stage are upcoming collaborations with legends from D&D’s past as part of the franchise’s Icons series. Luke Gygax will assist with new content from Greyhawk (one of D&D’s first settings that was created by his father, Gary Gygax), Tracy Hickman and Margaret Weis will come back for Dragonlance and R.A. Salvatore will return for Legends of Drizzt, after the drow ranger from Forgotten Realms.
After 50 years of D&D, comes another first: the return of Dark Sun, a post-magical-apocalypse setting originally released in the early 1990s, now resurrected as the tabletop game’s first mature release. Grim wonder abounds in D&D’s trial run on making a more adult setting full of blood, violence and survival that the presenter on stage claimed is so explicit, they have to shrink-wrap the source book and slap a warning label on it.

A new chapter means new tech, and D&D showed off a couple of updates coming for the company’s online resources. D&D Beyond, the online character-builder and resource portal, will soon get a tool called Look For Group that will work like a Yelp list for games being run by hobby shops and other providers. The D&D Beyond mobile app is also getting an overhaul in the near future, with a revamped interface that lets players run real-life games on their phones, from rolling dice to using skills to casting spells.
With an appearance by the cast of D&D’s official Let’s Play show Dungeon Masters, whose next season will run the World of Warcraft game, the keynote had something for seemingly every player, new or old. It ended with the lights out and the heavy breathing of a certain Sith Lord before a Darth Vader cosplayer showed up on stage, but there was little else shown about the Star Wars set coming next year. But we can look to the World of Warcraft release for clues — I chatted with Blizzard and D&D folks about their collaboration coming later in 2026.

The World of Warcraft set will have a 256-page sourcebook to introduce the new set, which works with D&D’s 2024 version of 5th edition, also known as D&D 5.5E.
The sourcebook packs a ton of material from the game, detailing 16 species, 11 of which are new to D&D (like the Dracthyr, Earthen and Pandaren). It has nine subclasses, six of which are brand-new (like Demon Hunters and Shadow Priests). Iconic locations like Orgrimmar and Icecrown Citadel are included, as well as stat blocks for famous characters like Arthas Menethil, Jaina Proudmoore, Anduin Lothar, Thrall and Sylvanas Windrunner should you want to befriend (or fight) them. Signature Warcraft items, mounts, bosses — they’re all in the book.

If some of this sounds familiar, you might be as old as I am — two decades ago, there was an official Warcraft crossover book for D&D’s 3.5 edition. When I brought this up to Wizards of the Coast’s folks who worked on the upcoming collaboration, they pointed out that the far older crossover spent a lot of its sourcebook establishing baseline tabletop rules.
The new Universes Beyond version leaves a lot of that out, relying on the streamlined rules of D&D 5.5 and enjoying the greater popularity of D&D to assume that players will know the basics — leaving more room for monsters, artifacts, areas and other iconic parts of World of Warcraft.

Once the set becomes available for purchase, newcomers can log on to D&D Beyond for a free starting adventure for heroes just starting out from levels one to five. For more advanced players, the set will include a new adventure to Icecrown Citadel for characters of level 16-20. Within, they’ll take on various champions of the undead realm at the northernmost point in Azeroth before confronting the big boss himself, the Lich King.
Players of the MMORPG may remember taking on the dreaded death knight with two dozen others in massive raids, but the challenges have been scaled down to be undertaken by standard D&D parties of three to five dice-rolling players who fit around a table. Not that the team didn’t think about it — when Hohman brought up the possibility of a 20-person encounter, she was immediately rebuffed.
“If you can get 20 people to align at a D&D table the same night and bring snacks, I think you should run Dungeons & Dragons World of Warcraft with them,” joked Justice Arman, D&D game design director. “If you can get 20, more power to you. If you can get five, we’ve got you covered.”
The team was very thoughtful about how to adapt an MMORPG into a tabletop system, Arman explained: They wanted to be authentic to both, which means not trying to reproduce the mechanics of a digital game, which makes so many decisions for the player that, in a tabletop game, would be managed by its real-time manager, the dungeon master.
In addition to the main sourcebook, the World of Warcraft set will also include miniatures, a map pack and a dungeon master’s screen with extensive art featuring heroes and villains from the game’s two-decade-plus history. And all you D&D collectors, rest easy: there will be special editions of the set sourcebook that come with a slipcover adorned with the Horde and Alliance faction icons, as well as one covered in Murlocs that’s exclusive to hobby stores.

The Universes Beyond sets are aimed at drawing in new and returning players to D&D using the appeal of the borrowed franchise. With World of Warcraft, there’s a lot of overlap between the fantasy themes, adventurous quests and epic boss showdowns.
The partnership is coming full circle, said Blizzard’s Longdale, affirming that the company’s online game is one of many RPGs that D&D has spawned. Adapting the MMORPG to pen-and-paper made sense and offers a lot for players who met online to bring their digital game to real-life tables. Moreover, a lot of Blizzard developers on the game have played D&D for years — many of whom discovered just this week that their favorite tabletop system was getting a version based on the very game they work on, Longdale said, indicating the severe secrecy of the collaboration… which had started two years ago.
“I don’t know how many people on our team raised their hand and said, ‘Well, I’ve been a DM, I could have helped,’” Longdale said, laughing.

The same is true for Wizards of the Coast, as the D&D team itself has plenty of World of Warcraft players, said Ayoub. It meant two teams passionate about both games that led to an excitement and a desire that’ll bear out in the quality of the final product.
“Authenticity was really key. A lot of the ways you look at it is, how does the [D&D] system become an operating system, if you will, to bring this world to life?” Ayoub said. “You turn brilliant designers from two teams together to just make it happen.”
Authenticity kept coming up in my chats with both Blizzard and D&D folks involved in bringing the World of Warcraft and Star Wars collaborations to the tabletop game. There’s surely pressure to make a proper adaptation that does justice to the source material, but there’s a lot of potential for these popular works to bring in players who hadn’t tried tabletop gaming before, easing the burden of tabletop complexity with a universe they already love.

“They have a shared understanding and a shared language,” Hohman said. “As soon as you say, ‘Hey, we’re going to play Star Wars,’ a lot of people understand what that means immediately. They understand the worlds. They understand the sort of characters and stories they might be investing their time into.”
D&D isn’t detailing what’s next for Universes Beyond. The team will see how this year’s worth of content lands, Hohman said, and future partnership announcements will hinge on the timing that works for D&D and its partners — taking it one step at a time. But right now, the team’s ears are open.
“If fans have things they would love to see, worlds they’d love to play in, however close or however far it feels from traditional Dungeons & Dragons, I would definitely love to know that,” Hohman said. “I’m excited to hear what people would be excited about.”
As the generative AI boom drives steep demand for hardware components, Apple and other hardware makers are facing what outgoing CEO Tim Cook calls “a hundred-year flood [on] memory pricing,” which is severely impacting the cost of producing iPhones, MacBooks, and other devices.
Apple described its recent earnings report as its “strongest June quarter ever,” with iPhone and Mac sales performing better than expected, growing 22% and 29%, respectively, year-over-year. Yet the company is bracing for memory shortages, known as RAMageddon, to get even worse. Apple’s biggest challenge is securing the advanced memory nodes used in its Apple silicon chips, which power the A-Series and M-Series processors used in iPhones and Macs.
“We continue to expect high levels of demand. However, with less flexibility in supply chain, we expect the impact from the supply constraints to increase significantly sequentially,” Cook said on Apple’s quarterly earnings call. “We’re seeing some very significant constraints currently with limited flexibility in the supply chain to remedy it.”
Apple is evidently worried enough about supply shortages that it reported $11.1 billion in inventory, nearly double the $5.7 billion it reported last September. This marks a break from Cook’s long-held supply chain approach, which has emphasized minimizing how much inventory Apple has on hand.
These constraints led Apple to “reluctantly” raise the price of Macs and iPads last month, Cook added. Other companies that have raised hardware prices include Meta, Samsung, Microsoft, and Sony.
“We’re going to be scrambling on the supply side, essentially,” Cook said.
For the upcoming quarter, Apple is predicting revenue growth between 9% and 11% year-over-year. But in the last several quarters, Apple has maintained about 16% year-over-year growth. Of course, that worries investors — Apple stock dropped 6% in after-hours trading.
When Senior VP of Hardware Engineering John Ternus steps into the CEO role in September, the company could be facing a rough patch, but at least Apple isn’t alone in its supply struggles.
When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.
Anthropic said Thursday that an internal investigation uncovered three incidents in which its AI model Claude breached the systems of three organizations while conducting cybersecurity tests. The investigation, and disclosure, comes more than a week after OpenAI disclosed that one of its unreleased models breached Hugging Face’s systems during internal testing.
In all three cases, a Claude model reached the internet from within a testing environment while interacting with a third party and then gained unauthorized access to the live systems of these organizations, Anthropic said in a blog post, describing what it found and what the company plans to change to prevent this from happening again.
Anthropic said the OpenAI episode earlier this month prompted the company to conduct its own cybersecurity evaluation. It specifically looked for evidence that Claude had accessed the internet from within testing environments, which are designed to act as sandboxes and keep models isolated.
Among the 141,006 evaluation runs it reviewed, the AI lab found three incidents in which its model accessed the internet while interacting with Irregular, one of its third-party partners. Anthropic said the access traced back to a misconfiguration in the evaluation environment run with Irregular. It called this a “misunderstanding” between the two companies over whether the test setup had internet access, when in fact it did.
Anthropic said it isn’t placing blame and is “approaching the fixes as if the responsibility were ours alone,” while observing that Irregular is conducting its own separate investigation.
Because of that open connection, the model gained unauthorized access to the production infrastructure of three different organizations. Anthropic said the incidents involved three different Claude models: Opus 4.7, Mythos 5, and an internal research test model.
Notably, Anthropic said that in each of these cases “Claude was explicitly told by our prompt that it had no internet access.” It appears that the AI model assumed real-world systems to be part of the exercise it was asked to perform.
That assumption didn’t hold up uniformly, as it turns out. The three models didn’t behave the same way once evidence emerged that their targets were real, which Anthropic flagged as one of the more eye-opening findings Thursday.
Opus 4.7, the oldest of the three, recognized that it had reached a real production system in all four runs of that incident. In two of them, it rationalized that the real company must somehow be part of the exercise, but in all four, it kept attacking anyway, including pulling credentials and touching a database of production data. Mythos 5 also picked up on signs that it was on the real internet, but it talked itself back into believing it was still in a simulation, going on to publish a malicious software package to the public Python software registry PyPI, which was then downloaded and run by outside systems before being caught. Only the internal research test model, Anthropic’s newest, stopped on its own once it concluded the target was real.
In response, Anthropic said significant controls must be placed on these kinds of evaluations if powerful AI models are involved, echoing some sentiments within the cybersecurity community.
The company also noted that Claude was running without the additional safety monitoring and classifiers it deploys on generally available models — safeguards it said would have blocked the behavior, because the evaluations are designed to measure the underlying model’s raw capabilities.
Importantly, Anthropic said it found no evidence of any model “pursuing a goal of its own” and instead merely tried to complete the task it was asked to do.
Though comparisons between the mishaps of these fiercely competitive companies are inevitable, Anthropic in its blog post drew a clear distinction between its cybersecurity tests and those of OpenAI, noting where OpenAI’s model exploited an unknown software vulnerability to break out of its test environment, Anthropic’s models instead reached the internet through a path that had, by mistake, been left open.
Anthropic also drew a distinction between itself and OpenAI by noting that it discovered the incidents itself, through a proactive review, and that the two affected organizations it was able to reach hadn’t previously detected the activity or flagged it to Anthropic. (In contrast, Hugging Face detected the recent intrusion of its own systems first; it was only in the following days that OpenAI identified and disclosed that its own AI agent was the perpetrator.)
The company added that it’s now working with the independent evaluation group METR on a third-party review of the incidents.
OpenAI’s accidental breach of Hugging Face, which was the first verifiable case of an AI lab losing control of its model, has sparked a string of wildly differing reactions from the industry and politicians. This latest disclosure from Anthropic ensures the debate over AI models and security will continue.
When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.
As it has been almost all of 2026, Apple’s September-quarter growth is expected to be slowed by a lack of supply-side availability that won’t be able to meet “incredibly strong demand” for iPhone, iPad, and Mac products.
If you’re going to have a problem in this world, it isn’t so bad to have an Apple problem. In spite of its $109 billion record breaking June quarter, analysts are already sweating about the September quarter.
Apple didn’t warn of some catastrophic fall in demand or lack of RAM that might impact revenue streams. No, instead Apple CEO Tim Cook shared that demand was so incredibly high that the supply chain wouldn’t be able to keep up.
“Let me stress this again,” Cook said during the earnings call, “this isn’t a partner or supplier issue. This issue is an incredibly strong demand.”
Cook really wants to ensure that investors know that the supply chain is more than capable of providing orders at the usual scale. However, the issue is that demand is much higher and supply constraints have increased to the point that Apple can’t simply order more product.
Realistically, this means that September’s revenue will be lower than it potentially could have been simply because there wasn’t enough inventory available to buy during that quarter. It remains to be seen if supply-side inventory will catch up during the December quarter or not, or if these constraints will continue into 2027.
Revenue growth is expected to be in the teens for the September quarter.
It is an incredible assertion considering September can be an awkward quarter for Apple. Savvy customers know an iPhone is on the way, so they’ll hold back on purchases.
However, the iPhone does launch with a couple of weeks’ worth of sales in September, which can provide a boost. From what it sounds like, Tim Cook is talking about the iPhone 17 lineup demand more than the upcoming iPhone 18 lineup.
Of course, the discussion also pertains to iPads and Macs. Those products won’t see a refresh until later in the fall, so what demand there is for current options will carry through the quarter.
Supply-side inventory will continue to be a constraint going forward, but expected iPhone price hikes could also create a problem for Apple. That won’t be known until guidance is provided in October or revenue is shared in December.
The counterbalance here is the new Apple Intelligence and Siri AI. Beta testing shows these are well-executed products that could drive incredible demand, even with potential price increases.
A production company and filmmaker are suing Netflix for $105 million, alleging the streamer lost a stolen drive containing an unencrypted master copy of the unreleased Nicolas Cage film Fortitude, which they claim damage its exclusivity and market value. Netflix denied responsibility for the lost film but said it takes content security seriously and has offered to monitor piracy sites for unauthorized copies. CBS News reports: The complaint filed on Wednesday in California district court alleges that the film’s associate producer, Daniel Haido, hand-delivered an unencrypted master copy of the film to Netflix so the company could screen it as a potential buyer. Haido verbally instructed the employee to delete the files after the screening, according to the suit. A little over a week after the screening, Netflix emailed the filmmakers to say the drive had been stolen, the plaintiffs allege. “Someone stole a good amount of drives from our office desks this past week,” a Netflix executive wrote in the email, according to the suit.
The complaint notes the movie, entitled “Fortitude,” took over seven years to make and cost $45 million. It tells the story of a secret mission called Operation Fortitude during World War II that was orchestrated to mislead the Nazis about the Allied invasion of Europe. The film stars Nicolas Cage as Dusko Popov, a real-life spy during World War II, as well as Sir Ben Kingsley and Ron Perlman.
The plaintiffs said studios will now be dissuaded from buying the rights to the movie, knowing that a version of it could be released by a third party for free. “The film’s value depended in significant part on its exclusivity as an unreleased, first-to-market work,” the complaint states. “By losing control of the film, Netflix destroyed that exclusivity and materially, if not completely, impaired the film’s marketability.”
The Subaru Outback, an affordably priced mid-size SUV meant to tackle off-roading adventures, hasn’t really seen a lot of competition in the United States. That may change in 2029 when Honda’s so-called “Accord SUV” goes into production, as confirmed by an anonymous insider (via Automotive News).
The “Accord SUV” appears as a lifted Accord hatchback with added utility in Honda’s internal planning document — this includes a higher driving position and a useful cargo area. By using the existing Accord platform, Honda could take advantage of the vehicle’s long wheelbase, offering a vehicle that would sit somewhere between a sedan and a full crossover. It may also appeal to drivers that miss the days when the Outback was a station wagon rather than an SUV. Not much is known about the rumored Honda Accord SUV — the insider claims that it will arrive alongside the redesigned Accord in 2030 with Honda’s next-generation hybrid powertrain. However, Honda told Car and Driver it has no plan to make “this type of vehicle.”
The Subaru Outback was introduced in 1995 as an off-roading variant of the Legacy sedan, covered in plastic cladding and given extra ground clearance. Over the past few decades, the Outback has been one of Subaru’s best-selling vehicles. So, fans of the station wagon were shocked when the 2026 model took a totally different turn.
The Subaru Outback is now an SUV rather than a station wagon. This is because Subaru discontinued the Legacy at the end of 2025, meaning the Outback no longer had a sedan to be built off of. The Outback still has all-wheel drive, plastic cladding, and other Outback-y features, but there is now a space for the Honda Accord SUV, a lifted sedan that isn’t quite an SUV — especially if it’s as capable off-roading as the Outback. Not everyone wants a Honda CR-V — although it’s currently the best-selling SUV in the United States in 2026.
Google is integrating Gemini Spark with Chrome so it can carry web-based tasks further without users having to take over at every step. The search giant is also expanding access to AI Pro subscribers in more than 160 additional countries, although the new browser capabilities are initially limited to the United States.
Chrome auto browse allows Spark to navigate websites using the accounts you are already signed into and passwords saved in the browser. Access requires permission from the user rather than being enabled automatically.
Google says Spark can use the feature to schedule viewings for saved apartment listings, compare flight options, and begin the booking process. It can move between pages and complete several steps without requiring the user to guide every action.

Spark hands control back before sensitive actions such as payments. Google also says it has added protections against prompt injection, where instructions hidden on a webpage attempt to manipulate an AI agent into performing an unintended action. Chrome auto-browse is rolling out first in the US, with additional regions expected to follow later.
Gemini Spark launched at Google I/O in May as a cloud-based agent that can continue working after a laptop is closed or a phone is locked. It initially focused on Google services such as Gmail, Drive, Docs, Calendar, Keep, and Tasks before adding several third-party integrations.

Spark also arrived on the Mac in June, gaining the ability to organize local files and work across supported desktop apps. Google recently expanded access beyond its expensive Ultra subscription, bringing Spark to the $20-per-month Google AI Pro plan in the US.
Pro subscribers in more than 160 additional countries are now gaining access. Chrome integration is one of Spark’s most important upgrades so far. It removes one of the agent’s biggest limitations by allowing tasks to continue beyond connected apps instead of stopping when the next step requires navigating a website.
Monetizing AI is a tricky business and it seems Apple’s only plans so far are tying daily usage limits to users’ iCloud+ subscription tier, but whether or not that’ll be enough isn’t yet known.
Apple may be prioritizing on-device AI, but the requests that need to go to Private Cloud Compute servers still cost money. Those costs will be offset by offering increased daily usage limits for higher iCloud+ tiers, but that may only be the start of Apple’s AI monetization plan.
Apple CEO Tim Cook responded to an analyst question during the Q3 earnings call regarding AI compute costs with information that was shared previously. However, one tidbit stood out that hints at Apple’s ambitions for drawing in more revenue from AI.
“And so, we couldn’t be happier with how things are going,” Cook said of iOS 27 AI beta testing. “In terms of what it means for compute cost, it’s obviously early going for us, and so I don’t want to say that we have a complete plan for that.”
He states here, and again later in the call, that AI daily usage limits will be tied to a user’s iCloud+ subscription tier. What that means and which tier gets what hasn’t been detailed yet, but this information was shared during the WWDC keynote as well.
In response to another question, Cook shared that operation expenditures will increase thanks to AI. He says that whether or not iCloud+ plans will balance the books is “uncertain.”
Apple has also confirmed that iCloud+ tiers will determine how much AI video recognition functionality users will get in their Apple Home. Users need the 2TB or Apple One Premier plan to get unlimited cameras and AI footage analysis.
Apple Intelligence and Siri AI are free to use as long as you have devices that support those features. However, server-side operations are limited.
Users will have to pay more to get more AI tokens. Though, unlike Apple’s competitors, its user base may already be subscribed to a service that will grant them additional tokens.
iCloud has a free 5GB tier that likely includes very few AI usage tokens overall. A user might blow through these tokens after a few prompts for an image, for example.
iCloud+ starts with a $1 per month tier for 50GB of storage and additional tokens. It’s also included in the Apple One Individual plan.
The $3 iCloud+ tier includes 200GB of storage, additional token usage, and is included in Apple One Family. The $10 tier is 2TB of storage, more tokens still, and unlimited HomeKit Secure Video cameras with AI video analysis, which is included with Apple One Premier.
Those that need even more storage after buying Apple One Premier can add on any additional iCloud+ subscription, including the $1, $3, and $10 plans. After that, there are two iCloud+ tiers that stand on their own: $30 for 6TB and $60 for 12TB.
Apple will likely tie even higher AI token usage limits to these very expensive tiers. Although, it seems very expensive considering the abilities of Apple Intelligence and Siri AI today, especially if you don’t need the storage space.
As Cook said, Apple will evaluate compute costs versus iCloud+ subscription rates to see how things balance. If more options are needed, Apple will bring them about.
I expect that there will be a hybrid system in place, eventually. Sure, having token usage tiers tied to iCloud+ is fine, but requiring users to pay for storage they don’t need is silly.
Instead, for those on the Apple One Premier plan for example, I expect Apple will also sell one-time purchase packs or a separate token-use subscription. Never count Apple out of offering more services.
This is not even the beginning of Apple Intelligence and Siri AI, as they are still in a beta preview. Things could evolve quickly in the coming months and years, and while Apple AI usage is limited today, it won’t always be.
As Apple gives us more ways to use AI, its costs will increase, and so the users’ costs will too. Increased monetization efforts means more services revenue, which should calm down those investors and analysts still worrying for Apple’s survival after a $109 billion Q3.
Weekend Open Thread: Brooks Brothers
Commonwealth Games boxing: Jadumani Singh seals dominant 5-0 win over Pakistan’s Sumama Rehman to enter quarter-finals | Commonwealth Games News
Why Trees Belong on the Risk Register
Intel is reversing course and bringing hyper-threading back to its server chips
Ripple bought a bank in pieces. The $4 billion audit
Luke Littler dismantles Gerwyn Price to retain title in Blackpool
A New Post-Apocalyptic Gundam Anime Series Blasts Into SDCC
The Part of the Electric Transition Nobody Wants to Discuss
BITCOIN JUST ENTERED THIS CRITICAL ZONE…
Major shareholder moves on Canyon
XRP Ledger adds $2.6B as RWA inflows rank second
Bitcoin Enters the 3rd Stage of the Bear Market
Spain sweeps the board at 2026 World Cup with individual awards
‘Stargate’ Creator’s New Sci-Fi Series Returns for Season 3 Tomorrow
Sara Gilson Killed By Husband After Viral “Pedophile” TikTok Video
Kraken Enables Retail Access to Jersey Mike’s IPO via Tokenized Shares
Anthropic launches Claude Opus 5, a cheaper AI model for coding, agents and enterprise workflows
Claude: Build Financial Dashboards in Minutes (2026)
New macOS Sequoia & Sonoma security updates for older Macs
Luke Littler’s dominance sparks GOAT debate
You must be logged in to post a comment Login