#MacOS,
I wish Apple would stop making macOS look and feel like iOS.

There's a reason they had different design philosophies...it's almost like one is a computer and one is a fucking PHONE.
September 29, 2026 at 2:49 PM
One of the things I love about Shottr is built in OCR/Text recognition.

Posting an image with lots of text? Shottr makes it easy to grab the text from the image to put into Alt Text.

Need to translate text in an image> Copy it with Shottr, paste into Apple Notes, and use the built-in translator.
Shottr – screenshot app for pixel professionals
Shottr is a free macOS screenshot app with scrolling screenshots, OCR, annotation and measurement instruments.
shottr.cc
September 29, 2026 at 2:47 PM
Hackers Turned Ethereum Into a Secret Messaging System for Malware
Hackers Turned Ethereum Into a Secret Messaging System for Malware
A North Korea-linked malware campaign has found a way to keep infected computers connected to its operators. Instead of storing malware on Ethereum, the attackers hide the location of a control server inside cryptocurrency transfers. The campaign reaches developers through fake job offers, tainted code repositories and malicious software packages. Running the code can install a remote access tool and a credential stealer across Windows, macOS and Linux. Researchers from Ransom-ISAC identified the new Ethereum component in September 2026 samples of XCTDH. Ransom-ISAC said in a report shared with Cyber Security News (CSN) that the technique gives the malware another way to find its operator if other routes are disrupted. The operation was first documented in October 2025, but the researchers found its Ethereum signals began in June 2026. They counted 2,655 transactions over 90 days. The report does not establish how many computers were infected or how much data was stolen. Hackers Turned Ethereum Into a Secret Messaging System The method, called HashHiding by Ransom-ISAC, turns the recipient address of an Ethereum transfer into a tiny message. Its first four bytes represent the server’s internet address, and the next two represent its port. The remaining bytes contain a second endpoint and padding. That is different from placing full malware payloads in blockchain transaction data. These transfers carry no smart contract call or hidden script. Most move no cryptocurrency, while a few transfer a tiny amount to an address whose private key nobody is expected to control. The malware watches transactions sent from the operator’s signaling wallet. It scans recent Ethereum blocks through public access points, finds a matching transfer, decodes its recipient address and contacts the server it reveals. The server then supplies code that can rebuild the infection. Earlier reporting on malware servers hidden inside Ethereum transfers described a related method called NullReceiver. Kill Chain (Source – Ransom-ISAC) Ransom-ISAC credits that earlier public description, while tracing this separate campaign through its own on-chain collection. The distinction matters because a blockchain address here acts as a signpost, not a storage site for malware. The operator changed the encoded destination four separate times during the observed period. The first two signals pointed to the same internet address on different ports; later signals moved to another address range. One subsequent change altered only the final number of the server address, a shift that could escape blocklists. Multiple Paths Keep Malware Connected Ethereum is only one part of this operation. The initial loader checks transactions on TRON, with Aptos as a backup, to locate encrypted JavaScript stored in BNB Smart Chain transactions. That older route delivers code, while the Ethereum route supplies a fresh server location. The attack begins when a developer follows a fake recruitment prompt and runs a poisoned project or package. As JavaScript loaders hidden in repositories have shown, a project can carry code that contacts blockchain services after execution. Here, the hidden loader brings in later stages without an obvious malicious download link. The updated remote access tool can run commands, record keystrokes and watch the clipboard. A separate one-time stealer seeks browser information, password manager data, cloud storage credentials and cryptocurrency wallet material. Researchers counted 153 wallet targets and said stolen data leaves through a messaging bot interface. The Ethereum scanner starts alongside the remote access tool, not only after a connection fails. A hardcoded server location and the older cross-chain path also remain active. This parallel design means blocking one server or one blockchain access point may leave another route open. The broader risk resembles developer attacks using blockchain payloads , where a trusted-looking development task becomes the first step of compromise. Ransom-ISAC recommends watching for unexpected Ethereum block queries followed by unusual server connections and monitoring the signaling wallet for new destination changes. Teams investigating a suspected infection should also examine Node.js processes running evaluated code and review developer environments. Removing a known server alone is not enough if the malware can read a newer server address from public blockchain records and start the chain again. Indicators of compromise (IoCs):- Type Indicator Description C2 address 23[.]27[.]20[.]143:27017 Server and port listed for the October 2025 campaign. C2 endpoint 23[.]27[.]20[.]187:80 First observed Ethereum-encoded destination. C2 endpoint 23[.]27[.]20[.]187:443 Second observed Ethereum-encoded destination. C2 endpoint 181[.]214[.]149[.]147:443 Third observed Ethereum-encoded destination. C2 endpoint 181[.]214[.]149[.]148:443 Fourth observed Ethereum-encoded destination; the report also describes a port 80 dropper path on this IP. Encoded Ethereum recipient 0x171B14bB0050171b14Bb01BB398EAAB6441Fbd47 First observed destination, encoding the port 80 C2 endpoint. Encoded Ethereum recipient 0x171B14bb01bB171B14BB0050EB7f39C35C47E682 Second observed destination, encoding the port 443 C2 endpoint. Encoded Ethereum recipient 0xB5D6959301bbB5D69593005000FfABa8a5A2ADA2 Third observed destination. Encoded Ethereum recipient 0xB5D6959401bbb5D69594005000ff8C84e0b715b1 Fourth observed destination. Ethereum signaling wallet 0x33ff3edaf55a8e03dcbc7cb40d498a49cd499891 Sender of the observed beacon transactions. Wallet match pattern 33ff3edaf55a8e03dcbc7cb40d498a49 Partial sender address used by the scanner and detection rule. BSC sender 0x9bc1355344b54dedf3e44296916ed15653844509 Address reported as shared with the October 2025 campaign. BSC transaction hash 0x84e8cecd5b077eef530e7d69d546e2555199cb61759d1224d31cb31750788f62 Chain 1 payload leading to the RAT and Ethereum scanner. BSC transaction hash 0x610c9ec972545b8df6e3aaecc7a8ab5f2f2445cf0bfbd6ee026e618d07b29e22 Chain 2 payload leading to the dropper. TRON wallet TCqf6ZkaQD84vYsC2cuu1jRwB6JveTaRrF Chain 1 transaction pointer. TRON wallet TFMryB9m6d4kBMRjEVyFRbqKSV1cV2NcpH Chain 2 transaction pointer. TRON wallet TMfKQEd7TJJa5xNZJZ2Lep838vrzrs7mAP Example wallet cited for the earlier XCTDH flow. Aptos fallback 0x9d202c824402ca89e9aaccd2390b6f8b332ae743caa1469c695feb2781d56519 Chain 1 fallback identifier. Aptos fallback 0x3d2075f97b7b1e3234bd653779d21c605d7d8c6ec9c98d983880be5c7f4f9471 Chain 2 fallback identifier. XOR key 2\[gWfGj;<:-93Z^C Chain 1 BSC payload decryption key, shown exactly as extracted from the report. XOR key m6:tTh^D)cBz?NM] Chain 2 BSC payload decryption key. XOR key ThZG+0jfXE6VAGOJ Dropper-response decryption key. C2 path /init Port 443 endpoint returning the RAT and scanner. C2 path /$/boot Port 80 endpoint returning the encrypted dropper. C2 path /$/1 Port 80 endpoint returning OmniStealer. C2 path /boot Port 443 Ethereum recovery endpoint. Campaign marker global.i = '5-3-132' Marker in the initial code. Version marker /*RS260605*/ Ethereum scanner marker. Build marker B9=260924 OmniStealer build marker. User-Agent Python-urllib/3.13 User-Agent spoofed by the Node.js loader. HTTP header Sec-V Custom header on the dropper request. File name config.js Example poisoned repository file in the September chain. File name tailwind.config.js Example weaponized file in the earlier chain. File name boot.js Script returned during Ethereum-based recovery. RPC domain ethereum-rpc.publicnode.com Legitimate public Ethereum service named in the detection rule. RPC domain eth.drpc.org Legitimate public Ethereum service named in the detection rule. RPC domain blastapi.io Legitimate public Ethereum service named in the detection rule. RPC domain bsc-dataseed.binance.org Legitimate BSC service queried by the loader. Note:   IP addresses and domains are intentionally defanged (e.g.,  [.] ) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM . Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC The post Hackers Turned Ethereum Into a Secret Messaging System for Malware appeared first on Cyber Security News .
cybersecuritynews.com
September 29, 2026 at 2:46 PM
No cloud lock-in. No code uploaded to remote servers. No per-seat subscription.

Download: fermata.run
Homebrew: brew install --cask fermata
Docs: docs.fermata.run
Demo: youtu.be/LtajsTBzB1M

#AI #indiedev #developer
Fermata: AI coding agents on your Mac, spec to pull request
Fermata is a native macOS software factory: AI coding agents plan, build, review, and open the pull request on your Mac. You supervise; it never merges.
fermata.run
September 29, 2026 at 2:40 PM
Fermata (𝄐) is a native macOS software factory for Claude Code.

You describe a feature; it plans, builds, reviews, and opens the PR on your Mac.

100% SwiftUI. Isolated git worktrees. Free (runs on your own Claude CLI).

fermata.run

#ClaudeCode #SwiftUI #macOS #buildinpublic
September 29, 2026 at 2:40 PM
⌨️ Raccourci IntelliJ du jour

✨ Fermer onglet

🪟 Windows/Linux: Ctrl + F4
🍎 macOS: Cmd + W

💡 Ferme l'onglet de fichier actuel

#Navigation #IntelliJ #IDE #Productivity
September 29, 2026 at 2:34 PM
you can really see the October 2019 PC/April 2020 MacOS releases of Disco Elysium in the data in that first chart, like i knew it happened but it’s still wild to see it quantified
September 29, 2026 at 2:33 PM
Star Wars: X-Wing flies again on modern PCs with OpenXW. The open-source project brings the 1993 LucasArts space combat classic to Windows, macOS and Linux with modern controls, sharper visuals and the original missions. #StarWars #RetroGaming
OpenXW gives LucasArts’ Star Wars: X-Wing new life on PC
Star Wars: X-Wing is flying again through OpenXW, an open-source project built around running LucasArts' classic space combat game on current PCs. I
www.generationamiga.com
September 29, 2026 at 2:31 PM
Apple patched a CoreGraphics zero-day vulnerability exploited in sophisticated targeted attacks on iOS, iPadOS, and macOS devices to prevent arbitrary code execution.

CVE-2026-86950 #infosec

Full synthesis & sources: yasna.io
Apple Patches CoreGraphics Flaw Possibly Exploited in Targeted Attacks
Apple patched a CoreGraphics zero-day vulnerability exploited in sophisticated targeted attacks on iOS, iPadOS, and macOS devices to prevent arbitrary code execution.
yasna.io
September 29, 2026 at 2:30 PM
September 29, 2026 at 2:26 PM
Tech rant: #MacOS 27 installed and localhost webserver stopped working. Tech support guy had no clue so bumped me up to more knowledgeable person who had NO IDEA that MacOS even had a built-in web server. Totally at a loss. Cmon #Apple....
September 29, 2026 at 2:25 PM
I think I'll be able to get @cozysters.com on phones, but it's going to take a bit of work to get it optimized properly style-wise. The park itself renders great, but a lot of these menus and such don't work on a screen that small.

But v1 is building great for macOS, Windows, and iPadOS!
September 29, 2026 at 2:08 PM
ブログ書きました。M1 Mac MiniをmacOS Tahoe 26.7.1【主にセキュリティ問題を修正】にアップデート - YUU MEDIA TOWN@blog
www.yuumediatown.com/diary/blog01...
M1 Mac MiniをmacOS Tahoe 26.7.1【主にセキュリティ問題を修正】にアップデート
わが家のM1 Mac miniを主にセキュリティの問題を改善したmacOS Ta...
www.yuumediatown.com
September 29, 2026 at 2:07 PM
If you're still running iOS, iPadOS, or macOS 26 (which is still the majority of Apple users!) then update today: Apple says hackers may be abusing a bug to target some users' devices.

Bypass for ad-block users: web.archive.org/web/20260929...
Still running iOS 26? Update your iPhones, iPads and Macs for this urgent security fix | TechCrunch
Apple says the bug was used to attack "specific targeted individuals" running iOS 26, which the majority of Apple customers are still using.
techcrunch.com
September 29, 2026 at 2:04 PM
working on a macOS design app for vector artwork. This is the the logomark

#logo #design #icon #vectorartwork #vectorillustration #pathtool
September 29, 2026 at 1:58 PM
Is Omarchy by DHH the distro for macOS peasants? Would you, a macOS Gigalord, switch to it?
https://youtu.be/6SJnmIboEXU
September 29, 2026 at 1:57 PM
I don't use that PC much anymore. pretty sure I was switched back to MacOS before Win 11 released.
September 29, 2026 at 1:56 PM
Thought the MacOS 27 update killed my Macbook air for a minute.

Macbook was on the black Apple/progress bar screen and stuck around 80% through the night while updating. Powercycled it this morning and it came up fine on 27.

whew.
September 29, 2026 at 1:48 PM
My 5 favorite Linux distros for AI – and why

Jack Wallen/ZDNET ZDNET's key takeaways If you need AI, try one of these Linux distros. Some systems include AI out of the box. Others require a bit of configuration. No matter how hard you try, it's getting harder and harder to escape the train of AI.…
My 5 favorite Linux distros for AI – and why
Jack Wallen/ZDNET ZDNET's key takeaways If you need AI, try one of these Linux distros. Some systems include AI out of the box. Others require a bit of configuration. No matter how hard you try, it's getting harder and harder to escape the train of AI. It's built into most apps, services and operating systems we use. AI is in Windows as Copilot, in MacOS as Apple Intelligence, and AI is also starting to make its way into Linux.
nanobyte.site
September 29, 2026 at 1:43 PM
My 5 favorite Linux distros for AI – and why

Jack Wallen/ZDNET ZDNET's key takeaways If you need AI, try one of these Linux distros. Some systems include AI out of the box. Others require a bit of configuration. No matter how hard you try, it's getting harder and harder to escape the train of AI.…
My 5 favorite Linux distros for AI – and why
Jack Wallen/ZDNET ZDNET's key takeaways If you need AI, try one of these Linux distros. Some systems include AI out of the box. Others require a bit of configuration. No matter how hard you try, it's getting harder and harder to escape the train of AI. It's built into most apps, services and operating systems we use. AI is in Windows as Copilot, in MacOS as Apple Intelligence, and AI is also starting to make its way into Linux.
nanobyte.site
September 29, 2026 at 1:43 PM
Skal si at Apple kundesupport er dedikert med å hjelpe meg med en livstid lisens på Photomator som brått sluttet å fungere på macOS. Mens det fungerer fortsatt på iPad og iPhone. Forskjellen er de som fungerer er en versjon bak gjeldende versjon.
September 29, 2026 at 1:42 PM
🏆 Yesterday's winner: Apple's macOS 27 wallpaper contains a building that cannot physically exist

https://itshouldwork.org/archive.html
September 29, 2026 at 1:38 PM
Optimizing Search and Siri Is Going To Become Old Really Quick

Sign of the Apple Intelligence times?
#apple #appleintelligence #siriai

https://warnercrocker.com/2026/09/28/optimizing-search-and-siri-is-going-to-become-old-really-quick/
## Optimizing Search and Siri Is Going To Become Old Really Quick I guess we all knew this was coming. Apple released operating system updates ending in 27.0.1 (as well as for OS 26 and macOS 15) today for iPhones, iPads, and Macs, bringing something it looks like most will have to get used to, spending more time while devices reindex Siri AI. There’s no telling if this will happen every time there’s an OS update, but Apple last year said that it will be speeding up the pace of security updates going forward in response to the risks now visited upon us from AI-powered hacking. Certainly the pace of AI development continues to rapidly increase, which can only mean the same for AI hacking. Defending against hacks, fixing bugs, and updating operating systems are facts of life these days. Always have been. Even so, when something new, or a needed bug fix is eagerly anticipated it’s largely viewed as an inconvenient chore by most. Adding time to the process for reindexing the info on a device certainly makes it more of a chore. There’s already a sour taste in many users’ mouths about AI in general. If this is an ongoing and every OS update type of thing, I’m betting this might just increase the pucker over time as the price users pay for using Apple’s on device brand of AI. For what it’s worth, and for what it means, I’m seeing the Optimizing for Search and Siri notification on an iPhone and iPad, but not on a Mac after updating. It will be interesting to see how long the process takes after the updates compared to the initial process when the OS’s 27 were first released. _Thanks for reading. You can subscribe to this blog if you care to._ _You can also find more of my writings on a variety of topics on Medium at_ _this link_ _, including in the publications_ _Ellemeno_ _and_ _Rome._ _I can also be found on social media under my name as above. This site does not use affilate links._ #ai #Apple #ArtificialIntelligence #iOS27 #iOS2701 #iPhone #Mac #Siri #SiriAI #Tech #technology
warnercrocker.com
September 29, 2026 at 1:37 PM