Skip to content
CrashOne - A Starbucks Story - CVE-2025-24277
Csaba Fitzl & Gergely Kalman

22 min read

CrashOne - A Starbucks Story - CVE-2025-24277

On a cold autumn day in Budapest in 2024, I met independent security researcher Gergely Kalman at a local Starbucks to swap ideas, dead ends, and updates on our research. Over coffee, we started talking about crash logs, and that’s when we stumbled onto something big.

Threat Intelligence
The Top Cyber Threats Facing SMBs in 2025
Calvin So

3 min read

The Top Cyber Threats Facing SMBs in 2025

Small and midsize businesses (SMBs) are under siege. Attackers know these organizations often run lean IT teams with limited budgets, making them prime “path of least resistance” targets.

Threat Intelligence
Building a Smarter OS Update Strategy with Declarative Device Management
Weldon Dodd

5 min read

Building a Smarter OS Update Strategy with Declarative Device Management

Managing operating system updates across an Apple device fleet has always been a balancing act. Push updates too aggressively, and you risk disrupting critical workflows. Move too cautiously, and you expose your organization to security vulnerabilities. The solution? A well-designed N-1 OS update strategy powered by declarative device management (DDM).

Thought Leadership
The New Face of IT: More Ops, Less Headcount
Weldon Dodd

6 min read

The New Face of IT: More Ops, Less Headcount

The IT department of 2025 looks nothing like the help desk of 2015.

Thought Leadership
Unlocking Apple’s New Device Management API
Arek Dreyer

4 min read

Unlocking Apple’s New Device Management API

Apple Business Manager (ABM) and Apple School Manager (ASM) have evolved significantly in recent years, but one critical piece has been missing: programmatic access. That changed with the introduction of the ABM/ASM API, opening new possibilities for automation, integration, and workflow enhancement.

Thought Leadership
Brewing Trouble: Homebrew Spoofed Sites on the Rise
Adam Kohler & Christopher Lopez

5 min read

Brewing Trouble: Homebrew Spoofed Sites on the Rise

In September 2025, Iru's security researchers identified multiple spoofed Homebrew installer sites designed to mimic the official brew.sh page. These replicas injected malicious payloads under the guise of a standard install. In this post, we examine the tactics, infrastructure, and impact of the campaign.

Threat Intelligence
Ransomware Readiness: Tips from Beyond the Playbook
Arek Dreyer

4 min read

Ransomware Readiness: Tips from Beyond the Playbook

The call came at 2 AM. A major U.S. telecom provider, critical infrastructure supporting millions of cell phone users, was under active ransomware attack. Systems were encrypting rapidly across their network. Within hours, the FBI was coordinating response efforts, executives were in crisis mode, and a specialized team was rebuilding Active Directory from scratch while the clock ticked. For Eric Pittman, VP of Cybersecurity at Teradata, this wasn't a tabletop exercise or theoretical scenario. It was a real-world crisis that revealed critical gaps in how organizations prepare for and respond to ransomware attacks.

Thought Leadership
Apple’s Recent Updates to Platform SSO: What Problems Will It Solve?
Arek Dreyer

6 min read

Apple’s Recent Updates to Platform SSO: What Problems Will It Solve?

A frank look at where Platform SSO stands today, what's coming with macOS Tahoe 26, and the hard choices Mac administrators need to make

Thought Leadership
5 Lessons from One Company’s ISO 42001 Certification Journey
Satyam Patel

4 min read

5 Lessons from One Company’s ISO 42001 Certification Journey

The rapid development and adoption of AI is creating new opportunities for businesses across industries. From predictive analytics and natural language processing to automated decision-making, AI is transforming business operations and the customer experience. However, with this vast potential comes significant risk – especially for compliance leaders who must navigate an everchanging and complex landscape of emerging regulations, ethical considerations, and governance challenges.

Thought Leadership
The Vulnerability Data Crisis: Why You Can't Trust Your Security Tools
Shwena Kak

5 min read

The Vulnerability Data Crisis: Why You Can't Trust Your Security Tools

How data processing delays, inaccuracies, and systemic challenges in the National Vulnerability Database are impacting security teams and what you can do about it.

Threat Intelligence
Survey of 1,000+ IT & Security Teams Shows More Tools = More Burnout & Higher Risk
Weldon Dodd

9 min read

Survey of 1,000+ IT & Security Teams Shows More Tools = More Burnout & Higher Risk

Analysis of 1,011 IT and security professionals reveals the true price of fragmented tech stacks

Reports
The Apple OS 26 Era Begins. Iru Has You Covered.
Iru Team

4 min read

The Apple OS 26 Era Begins. Iru Has You Covered.

Deploy, manage, and secure Apple’s latest operating systems as soon as they’re released Apple has officially released its latest operating systems iOS 26, iPadOS 26, macOS 26, tvOS 26, watchOS 26, and visionOS 26. For the first time, Apple has standardized version numbers across every OS, creating a unified baseline for developers, IT teams, and end users alike. This alignment not only simplifies communication and compatibility but also underscores Apple’s commitment to delivering a consistent experience across the entire ecosystem.

Product News
Arek Dreyer

7 min read

"Keep Learning, Keep Leading": Advice for Apple Admins

Your iPhone has more computing power than entire university systems had 50 years ago. In another 50 years, the information processing capabilities available to us will be exponentially greater still. Yet our brains remain fundamentally unchanged, evolved to track seasonal patterns and remember a few dozen faces, not to process the constant stream of security bulletins, product announcements, API changes, and community discussions that define modern Apple administration.

Thought Leadership
Finding Vulnerabilities in Apple Packages at Scale
Csaba Fitzl

15 min read

Finding Vulnerabilities in Apple Packages at Scale

This article summarizes work we performed in 2024, which we shared in our “Finding Vulnerabilities in Apple Packages at Scale” talk at MacDevOpsYVR and SecurityFest conferences earlier this year. You can watch the full presentation below:

Threat Intelligence
How to Fix The Patching Problem Every IT Team Knows Too Well
Weldon Dodd

7 min read

How to Fix The Patching Problem Every IT Team Knows Too Well

Let's be honest: patch management in 2025 feels like trying to drink from a fire hose while juggling flaming torches. You're managing thousands of devices, dealing with constant vulnerability announcements, and somehow expected to keep everything secure without driving your users (or yourself) completely insane.

Thought Leadership

Stay up to date

Iru's bi-weekly collection of articles, videos, and research to keep IT & Security teams ahead of the curve.