Skip to main content

Share story

Security

Apple's macOS 26.4 Warns Users Before Running Terminal Commands Pasted From the Web

Apple's macOS 26.4 Warns Users Before Running Terminal Commands Pasted From the Web Image: Primary
Apple has introduced a new security feature in macOS 26.4 that warns users when they attempt to paste commands copied from Safari or other applications into Terminal, flagging potentially harmful code before it executes, 9to5Mac reports. The feature is a direct response to a social engineering attack technique that has become increasingly common: cybercriminals trick users into manually copying and pasting malicious Terminal commands by disguising them as legitimate instructions in fake app downloads or impersonated software documentation. The method is particularly dangerous because it bypasses macOS's Gatekeeper security layer, which the system treats manual user input as inherently authorized. Apple's new paste warning introduces a critical friction point that gives users a moment to reconsider before executing code they may not understand, offering protection that is especially relevant for less technically experienced users.
Sources
In this story
Published by Tech & Business, a media brand covering technology and business. This story was sourced from 9to5Mac and reviewed by the T&B editorial agent team.
Back to Newswire
Keep reading
Full wire
Infrastructure Capital
Infrastructure Capital

Nscale secures $3.36 billion in financing ahead of planned IPO

British AI data center developer Nscale said it secured $3.36 billion in convertible-note financing ahead of a planned US stock-market listing. The Third Point-led deal makes $2.36 billion available immediately, while a further $1...

Infrastructure Products
Infrastructure Products

Tower and Japan plan $4 billion optical chip expansion

Tower Semiconductor and Japan's government plan to invest a combined $4 billion in Japanese factories that make chips for optical connections, Tom's Hardware reports. Tower plans to contribute $3 billion and Japan's Ministry of Ec...

Capital AI
Capital AI

Enveda raises $311 million to advance AI-assisted drug candidates

Enveda has raised $311 million in Series E financing at a $2 billion valuation as it moves drug candidates found through its AI-assisted search of natural compounds into human testing. Catalio Capital Management led the round, wit...

Security Infrastructure
Security Infrastructure

Researchers find personal data exposed in around 16,000 Supabase databases

Security firm UpGuard found around 16,000 databases hosted by Supabase with some personal data exposed to the public web, TechCrunch reports. The accessible information included names, addresses and phone numbers; a smaller number...

Security Policy
Security Policy

CISA sets deadlines for agencies to address four exploited software flaws

CISA has added exploited vulnerabilities affecting WSO2 products, Adobe Commerce, Microsoft SharePoint and Mikrotik RouterOS to its Known Exploited Vulnerabilities catalog. Federal agencies using the affected products must apply r...

AI Products
AI Products

S&P Global Energy opens governed data queries to customer AI agents

S&P Global Energy says it has built a way for customers' AI agents to query its structured energy data in natural language. Its domain experts organize datasets into focused Databricks Genie Agents, each with business definitions ...