Apple says it is adding controls around Full Disk Access on macOS, the setting that lets an app read files, mail, messages and browsing history. In a developer blog post, Apple said some developers use the permission in ways that could put users at risk. Apple says the new controls will let users grant that level of access only with very explicit user action. The move comes after two reports. Inc. columnist Jason Aten said Meta's Muse knew the content of his private messages, though he says he never gave it permission. Meta disputes this. Wired reported a flaw in ChatGPT's Mac app that could have let hackers reach sensitive data.
Why it matters for builders
If your Mac agent or desktop app asks for Full Disk Access, expect a harder consent step and fewer users who get through it. Apple hasn't said when the controls arrive, which macOS version gets them, or what developers have to change. Build agent features that still work with narrower permissions, and watch Apple's developer blog for the details.
The DGX Spark 64GB starts at $4,999 and arrives October 23. Acer, ASUS, Dell, Gigabyte, HP and MSI will sell it. It has 64GB of unified LPDDR5X memory, half the capacity of the original machine. ThePCEnthusiast says it can run models of up to 100 billion parameters locally, while the 128GB model goes up to 200 billion. The article is unclear on the bigger model's price. One passage puts the 128GB model at $6,950, which makes the gap only $1,951. Another calls $4,699 Nvidia's official price for the 128GB Founders Edition, which would be less than the 64GB box costs.
Why it matters for builders
The smaller box only makes sense if the 128GB model really costs $6,950. If you can still get a Founders Edition at Nvidia's listed price, you pay less and can run models twice as large. Before October 23, check what the 128GB model actually costs today. Also make sure the models you plan to run fit under the 100 billion parameter limit.
Microsoft's 2026 Digital Defense Report covers July 2025 to June 2026. It puts the median time from finding a vulnerability in the wild to weaponizing it at well below 24 hours. CVEs tracked for 2026 are on track for a record of about 72,000. That is a projection for the full year, not a final count. Phishing was the way in for 23% of the intrusions Microsoft's incident responders investigated, up from 7% a year earlier. The report names Anthropic's Mythos and OpenAI's GPT-5.5 as the first models to show the potential to run complex attacks on their own. These figures come via Help Net Security's coverage and were not checked against the report itself.
Why it matters for builders
Microsoft expects known, unpatched vulnerabilities to pile up for several years because fixes ship more slowly than new bugs are found. If exploits show up within hours, a weekly patch cycle leaves you exposed for days. Turn on automated dependency updates for anything public-facing, and make sure you can ship a security fix the same day it lands.