The Latest

We may earn a commission from links on this page.

From its debut in 2009 to its series finale in 2020, Modern Family delivered something remarkable: A consistently funny comedy with a subtle-but-deep emotional core. Its “mockumentary” structure was the perfect choice, because it allowed us to watch the extended Pritchett Family as both a fly on the wall and via direct interviews—and as any fan of The Office knows, that structure allows for some very specific joke-telling you can’t manage in a more traditional format. If you’ve watched all 11 seasons (and checked out all the similar series out there), then it’s time to branch out to movies with the same comedic sensibility. That movie definitely should be Real Life, which was co-written and directed by Albert Brooks.

Real Life (1979)

Real Life, released in 1979, isn’t as well-known as it should be. The film basically invented the mockumentary—we probably wouldn’t have The Office or Modern Family without it. At the time, it was satirizing a television series called An American Family that aired on PBS (itself regarded as the first example of what would come to be known as reality TV). An American Family followed the lives of a real family in California, and was a cultural sensation in the early 1970s. Albert Brooks saw an opportunity to have some fun with the concept—but Real Life is a lot more than just a satire of a TV show.

Brooks plays a version of himself in Real Life: a young comedian who aspires to make documentary films (and who could have been a “scientist or a doctor of some kind” if he’d been “graded more fairly” in school). He presents the project as a chance to not only document and observe a real American family, but also the filmmakers and crew.

What follows is a hilarious send-up of everyone involved. The family being documented begins to crumble under the pressure almost immediately, quickly descending into chaos and nervous breakdowns. The production team begins to fracture as Brooks engages in a series of ethically murky moves to try to goose up drama and keep the family involved despite their spiraling psyches. And Brooks repeatedly reveals himself to be an insincere and slimly talented man with an ego the size of a planet. At one point he shows up dressed as a clown to try to cheer up the kids, not realizing they’re not home, and winds up forced to have a deeply serious interview with the parents ... while dressed as a clown.

Real Life is certainly less sweet than Modern Family, but it basically invented the genre, and is deeply, deeply funny. Rent Real Life on Prime Video.

More movies to watch if you love Modern Family

Need more funny family films? No problem—here are a few more hilarious family-focused comedies that fans of Modern Family will love.

Parenthood (1989)

Parenthood is funny because, like Modern Family, it’s grounded in reality. Director Ron Howard, producer Brian Grazer, and screenwriters Lowell Ganz and Babaloo Mandel all had kids at various stages of life, and they based much of the film on their own experiences raising families in the modern era, translating it into a story about the sprawling, chaotic Buckman family. It follows a huge number of storylines as it gives each family member some attention, with Steve Martin on hand to provide plenty of belly laughs along the way. Stream Parenthood on Netflix or rent it on Prime Video.

Little Miss Sunshine (2006)

Every comedy lives and dies by its characters—you have to care about them in order to laugh at (or with) them. Little Miss Sunshine offers up the Hoovers, a perfectly imperfect family. When the youngest daughter, Olive (Abigail Breslin), qualifies for a beauty pageant located nearly 1,000 miles away, the Hoovers pile into their van. Crammed in together, the family's dysfunction, insecurity, rage, and love come pouring out, usually in pretty funny ways. It all leads to one of the most heartwarming (and famous) climaxes in modern cinema, capping off a film that will delight anyone looking for the sort of warm comedy Modern Family specializes in. Rent Little Miss Sunshine on Prime Video.

The Family Stone (2005)

The engine that drives family comedies is the tension everyone feels with their relatives. We love and hate them in equal measure, sometimes, and quirks that might seem delightful to others become excruciating to us. That’s where The Family Stone lives, telling the story of high-strung, nervous Meredith (Sarah Jessica Parker) meeting her boyfriend’s super-cool, tight-knit family for the first time—and on Christmas, no less. Awkward hilarity ensues as Meredith’s increasingly sweaty efforts to win over the family just make things worse, pushing everyone to a series of emotional revelations and confessions. Rent The Family Stone on Prime Video.

Cheaper by the Dozen (2003)

Based on the semi-autobiographical novel by Frank B. Gilbreth Jr. and Ernestine Gilbreth Carey (who grew up with 10 siblings), Cheaper by the Dozen is gently hilarious. When his wife embarks on a book tour, Tom Baker (Steve Martin) insists he can handle a household filled with raucous, chaotic children—but, of course, he’s hilariously outmatched. Like Modern Family, Cheaper by the Dozen finds plenty of real emotion as it ruminates on the bonds formed between siblings and parents, and how we all come to miss the chaos when we leave our families behind. Stream Cheaper by the Dozen on Hulu or rent it on Prime Video.

Home for the Holidays (1995)

What Modern Family understands is that family is complicated. Our families can be funny, loving, exasperating, and sustaining all at once. Home for the Holidays, directed by Jodie Foster and starring Holly Hunter at the peak of her powers, knows this perfectly well. When Claudia (Hunter) returns home for Thanksgiving, she’s at her lowest point in life. At first, the squabbling chaos and ominous signs of incipient tragedy are alarming and triggering—but, ultimately, she finds that there’s no place else she’d rather be. Stream Home for the Holidays on Kanopy, YouTube, or Hoopla, or rent it on Prime Video.


from Lifehacker https://ift.tt/tOuyAWk

The threat actor targeting internet-facing PaperCut Application Servers is covertly installing legitimate remote access software on them, PaperCut Software shared in the most recent update on the ongoing attack campaign.

OPIS

PaperCut zero-days exploited to deploy remote access tools

The vendor first warned of in-the-wild compromises on August 27, 2026, when it urged customers using the PaperCut NG and MF print management solutions to “immediately restrict web access to trusted IP addresses only.”

At the time, PaperCut believed the threat actor exploited a previously unknown vulnerability to gain access and control over the solutions’ Application Server, but their investigation later revealed they leveraged two zero-day vulnerabilities:

  • CVE-2026-81578, an improper access control vulnerability in the web management interface of PaperCut MF and PaperCut NG
  • CVE-2026-82078, an unsafe dynamic class loading vulnerability in the database connection utilities of the two solutions

Chained together, the two flaws allowed the unauthenticated threat actor to bypass authentication, modify certain system configurations, and execute arbitrary Java bytecode under the security context of the PaperCut server process.

With the help of a university customer’s security and digital forensics and incident response teams, PaperCut Software reproduced the vulnerabilities, and pushed out emergency patches on August 28.

Later that same day, the vendor published a second round of emergency patches (with “additional hardening developed with internal security and external researchers”) and urged customers to apply them even if they had already applied the initial ones.

On August 30, they followed up by extending the initial list of provided indicators of compromise and shared a command sequence that shows what the attackers are doing after gaining access to the Application Servers:

  • They list users and their privileges and running processes
  • Enumerate domain controllers in the domain
  • List logged-on user sessions
  • Download a malicious payload from a file-sharing host (sendit.sh) into C:\ProgramData
  • Silently install and run the payload, which installs SimpleHelp remote access software and sets it up to auto-start, and checks that it’s running
  • Download AnyDesk to establish a second, redundant remote access channel

“As every customer environment is unique, it is difficult to identify a single consistent pattern of post-compromise activity, but observed behaviour includes the pc-app.exe (or pc-app) process launching child shell processes (cmd.exe) and running whoami & ver, with endpoint protection in some cases preventing further execution and isolating the machine,” PaperCut noted.

In cases where execution was not prevented, the attackers performed the above listed actions that ended with AnyDesk being installed.

Since PaperCut’s initial disclosure, Rapid7 published a technical overview of the vulnerabilities, watchTowr researchers discovered multiple patch bypasses and identified an additional authentication bypass vulnerability, which they reported to PaperCut.

Huntress analysts found evidence of exploitation in two customer environments, but the exploitation activity was limited. In one of the cases, the exploited instance was running PaperCut MF version 24.1.5.71847.

What should customers do?

The initial round of emergency patches for PaperCut NG and MF were made available only for the v25 and v26 branches, but the second one includes patches for the v24 branch.

Huntress researchers noted that “47% of the approximately 2,500 PaperCut installations Huntress tracks are running v23 or older, for which no patch is currently available.”

PaperCut advises customers running PaperCut NG/MF versions older than v24 to upgrade to the latest version.

“Site Servers and secondary/print servers should be updated to a patched version, not just the primary Application Server. Other components such as Print Deploy and Mobility Print are not affected and do not need to be updated,” the vendor added.

Huntress advises users to:

  • Preserve forensic evidence before updating
  • Implement the provided emergency updates and restrict web access to PaperCut Application Server to trusted IP addresses
  • Review the preserved logs for known indicators of compromise

“We recommend checking for the presence of a Windows service named ‘Remote Access Service’ running SimpleService.exe from the [C:\ProgramData\JWrapper-Remote Access\JWAppsSharedConfig\restricted\ path], and for unexpected AnyDesk installations, as potential indicators of post-compromise remote access tooling,” PaperCut advised.

But, they also pointed out that the absence of already shared indicators of compromise doesn’t mean a system has not been affected. “PaperCut will publish validated, specific indicators and further guidance here as soon as they are available,” they added.

“If you suspect your server has been compromised, we recommend securing current server backups, completely wiping and rebuilding the Application Server, and restoring a clean backup taken before any suspicious behavior was detected. Additionally, you should activate your organization’s security response procedures and follow standard incident protocols.”

The attackers’ ultimate goal remains unknown.

Three years ago, Clop and LockBit affiliates exploited two known PaperCut vulnerabilities to compromise servers and deploy ransomware. This time the flaws were zero-days rather than known bugs, but today’s attackers have an additional edge: AI tools that can help them analyze target software, surface previously unknown vulnerabilities, and write working exploits.

Subscribe to our breaking news e-mail alert to never miss out on the latest breaches, vulnerabilities and cybersecurity threats. Subscribe here!


from Help Net Security https://ift.tt/bDfYeTW

Brian Kuan wrote halo-record, a small Python package that sits inside an AI agent and writes down the moves it makes: tool calls, model calls, data access, approvals. Each action becomes one line in a file that only ever gets appended to, and every line carries a hash of the line before it, a hash being a short fingerprint computed from content. Edit a record later and every fingerprint after it stops matching. The code is open source, and anyone can run that check with no key, no account and no permission from the vendor whose agent produced the log.

AI agent audit trail

A customer’s security team asks what your agent did with their data, and the answer they get is a paragraph you wrote about yourself. A hash-chained log replaces the paragraph with a file the customer can test. Wrapping an agent takes one line of Python, and adapters pull records in from OpenTelemetry spans, LangChain, MCP servers and gateway logs, so the evidence can come from tooling you already run.

Raw arguments never enter a record. Values get hashed and kept as a redacted summary, and the redaction is pattern matching against common secret and personal-data formats. The package has no runtime dependencies and runs about 5,300 lines of Python, which matters when the recorder goes inside your own product.

Nothing was edited is not the same as nothing is missing

A chain you hold yourself proves one thing: no record was altered or reordered after it was written. It cannot prove that every record was written. Delete the embarrassing Tuesday, re-seal the chain, and the file stays internally consistent.

Closing that hole takes a witness, some party outside the operator’s control that periodically stores two numbers: how many records exist and the hash at the head of the chain. A witness you run yourself proves integrity to you and nothing to your customer. A hosted witness service is also how Kuan intends to fund the work.

Why a vendor would sign up for a log it cannot edit

“Vendors volunteer because it closes deals,” Kuan told Help Net Security. An agent vendor walks into a security review today carrying a certification built for deterministic software, an expensive new audit standard, or its own logs. On the last of those, he said: “handing a prospect your own logs and asking them to trust you breaks the oldest rule in assurance. It’s why SOC 2 requires an independent AICPA-accredited auditor in the first place.”

“It’s early. Adopters are mostly engineers and security researchers kicking the tires, but the mandate pressure is just starting to form, from standards like AIUC-1 that now require tamper-evident runtime logging, and from insurers starting to ask the same questions,” Kuan said.

Pressure of a less voluntary kind is arriving too. “July’s Hugging Face intrusion was run by an autonomous agent – roughly 17,600 actions over five days – and their own write-up says reconstructing what it did by hand was impractical, and that only some of the agent’s logs could be retrieved,” Kuan said. Take the arithmetic from that number: a responder reading one action per minute needs twelve straight days to get through the week.

The format is open, and that is on purpose

Kuan controls the record format today, and it is versioned, public and small enough that anyone can implement it without asking. “If a big platform ships its own incompatible version, that mostly proves the point – the market agrees the evidence matters,” he said. “And honestly, the more the format gets copied, the better – the format was never the moat. Any variant still faces the same question: can anyone besides the vendor verify it?”

Nobody gets certified by any of this. A report gives an assessor something checkable next to record-keeping language in the EU AI Act and the action receipts in the Cloud Security Alliance’s AARM model.

Halo-record is available for free on GitHub.

Must read:

Subscribe to the Help Net Security ad-free monthly newsletter to stay informed on the essential open-source cybersecurity tools. Subscribe here!


from Help Net Security https://ift.tt/Ya7Mj9J

Say you’re on the free plan and you ask ChatGPT to help you pick a mattress. An ad may turn up next to the answer, and it got there because of what you just asked about, plus your rough location and whatever device you’re on. What ChatGPT remembers about you from earlier chats doesn’t come into it, at least not yet.

ChatGPT ads

Which plans get ads

Ads may show up for people on the Free and Go plans. Plus, Pro, Enterprise, Business and Education subscribers do not get them, and ad-free options remain available. If you are on a free account and would rather not have advertising in the product at all, the plan you are on is the thing to check.

You get asked before the ads get personal

OpenAI will put a choice in front of you before personalized ads begin: opt in, or don’t. Take the offer and the ads start drawing on your activity inside the product, including ads you have interacted with and context from your conversations, with a setting to manage the choice afterward. Decline, and selection stays on the current topic plus that same slim set of signals. The contextual information is described as limited, and the two things named are general location and device type.

Whether you look at an ad or tap it gets counted, and the count feeds back into judging how well the advertising works. “Advertisers only receive overall information about how their ads perform, such as total views or clicks.”

What OpenAI says stays the same

Ads carry labels and sit visually apart from the model’s replies. On the question a lot of people will ask first, OpenAI says: “Ads do not influence the answers ChatGPT gives you.” Your conversations and personal details are not handed to advertisers, who get no access to chats, chat history, memories, or personal details.

The privacy policy is being updated to spell out how the ads work and what controls you have over them. Until the personalization prompt shows up in your account, the topic on your screen is what picks the ad.


from Help Net Security https://ift.tt/FXb3pi2

Here’s an overview of some of last week’s most interesting news, articles, interviews and videos:

Week in review

Unpatched Zimbra servers are falling to CVE-2026-73570 attacks
At least 274 internet-facing Zimbra instances have been compromised by unknown attackers via CVE-2026-73570, the Shadowserver Foundation shared on Monday.

AI supply chain risk is showing up in developer workflows first
In this Help Net Security interview, Dr. Jaushin Lee, CEO of Zentera Systems, discusses where AI supply chain risk shows up. He says most incidents still hit developer workflows and open-source package repositories, while poisoned model weights and compromised MCP servers stay mostly in research demos.

Suspected Iran-linked attack knocked UK power plant offline for days
News that suspected Iranian hackers caused the shutdown of a British power plant broke over the weekend, raising the question of whether UK’s power grid and, indeed, the country’s critical infrastructure can fend off destructive cyber attacks.

Production data in testing is still common, and Tricentis’ CISO wants it gone
In this Help Net Security interview, Erika Dean, CISO at Tricentis, talks about keeping production data out of test environments and why she thinks the alternatives are good enough now. She explains how her team caught a prompt injection gap in red-teaming and held a release for a week until it was fixed.

CISA’s logging guidance works beyond government
The US Cybersecurity and Infrastructure Security Agency (CISA) wants federal agencies to (re)shape their logging strategy around one question: when an attack hits, can you actually use the logs you’ve collected to catch it and reconstruct what happened afterward?

AI will not fix a governance problem in your camera estate
Camera systems often outlive the companies that install them. In this Help Net Security interview, Rob Janssens, EMEA Cyber Security Director at Hikvision Europe, discusses what happens when the integrator is gone, the documentation is lost, and nobody holds the admin credentials.

Critical Gitea vulnerability now exploited in the wild (CVE-2026-60004)
Attackers have begun exploiting CVE-2026-60004, a critical code injection vulnerability in the Gitea Git platform, CISA confirmed on Tuesday by adding the vulnerability to its Known Exploited Vulnerabilities (KEV) catalog.

What 90 days and a small budget can buy in AI agent security
In this interview with Help Net Security, Prasad Tharippala, Field CISO at Versa, explains what organizations miss when they run open-weight models in house. He covers the hidden costs of GPU infrastructure, licensing review and staffing, and why hardening and incident response become the buyer’s job.

Fake bank websites play dead to evade security scanners
A phishing method, named Chameleon SEO Poisoning, that uses manipulated search results and cloaked fake banking websites to steal credentials while evading security scanners has been discovered by Fortra.

Android car head units infected with proxy botnet malware through built-in software updaters
A newly discovered Android malware, distributed through the built-in updaters in affected Android-based car head units, turns infected devices into ad-fraud tools and nodes in a proxy botnet, Kaspersky has found.

PaperCut NG/MF vulnerabilities exploited in zero-day attacks
PaperCut Software has identified the two vulnerabilities chained in these attacks and urged users to install a second patch.

Cybersecurity job ads demanding AI skills double in a year
Job postings asking for AI skills in cybersecurity have doubled in a single year in G7 countries according to new research from the Cisco-founded AI Workforce Consortium.

ShinyHunters taunts ReliaQuest after its own employee falls for social engineering attack
Cybersecurity company ReliaQuest has confirmed that one of its own employees fell for a social engineering attack, handing attackers a password and a brief window into the company’s identity system.

Fake OpenAI Codex download tricks macOS users into installing malware
A malware campaign using a sponsored search ad and a fake OpenAI Codex download page to trick macOS users into pasting a malicious command into Terminal has been uncovered by Cato Networks.

Bogus recruiters go after high-value corporate credentials on mobile
Scammers posing as HR staff at well-known companies are running interview scheduling scams that end with a stolen corporate password, according to Zimperium.

AnonyMousKIT phishing-as-a-service uses AI voice calls to steal iPhone passcodes
A phishing-as-a-service (PhaaS) platform called AnonyMousKIT is automating the theft of Apple ID credentials needed to remove Activation Lock from stolen iPhones, SOCRadar found.

FBI takes down China-linked hacking network behind attacks on NASA, DOJ and U.S. Senate
The Justice Department and FBI have seized domains tied to two hacking tools built and run by a Chinese state-sponsored group, cutting off access to malware that had been used against U.S. government agencies for years.

Previously patched Citrix NetScaler flaw exploited in the wild (CVE-2026-8452)
CISA added six new vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, including a previously patched Citrix NetScaler ADC and Gateway flaw, tracked as CVE-2026-8452, that is being exploited in the wild.

Cyberattack causes network outage at Boston Scientific, disrupts global operations
Medical technology company Boston Scientific suffered a cyberattack that disrupted its IT systems and caused a network outage, affecting global operations.

Manchester Airports Group breached, millions of customers’ data stolen
Someone broke into the systems of Manchester Airports Group (MAG) and walked away with a “quantity” of customer data from three UK airports, the company has confirmed.

North Korean remote workers are broadening their job hunt beyond IT
North Korean (DPRK) remote workers are expanding their job searches beyond IT, according to Huntress. Recent investigations have identified suspected DPRK workers employed in sales and marketing and the medical profession.

Two alleged TeamPCP hackers arrested over global supply chain attacks
Two men from Western Australia have been charged after police allege they were part of TeamPCP, a cybercrime group that planted malicious code in open-source software, then used it to break into organizations around the world.

Android 17 adds new protections against sneaky Wi-Fi tracking and web snooping
Google introduced a batch of network security changes coming in Android 17, aimed at making it harder for network operators, snoops, and scammers to track what you do on your phone.

The cybercrime supply chain has five stages, each with a price
In this Help Net Security video, Chris Nyhuis, CEO at Vigilant, explains why the picture of a lone ransomware attacker is about 15 years out of date.

Ransomware attackers are zeroing in on mid-market companies
Mid-sized companies accounted for 73% of publicly disclosed ransomware and data-extortion incidents with known revenue in North America and Europe between January 2023 and June 2026, according to Black Kite.

HOL Guard: Open-source antivirus for AI agents
HOL Guard is a free, open-source tool that sits between an AI assistant and the computer it runs on. When the assistant tries something risky, the tool pauses it and asks you first. It installs in about a minute, runs on your own machine, and a typical check takes under 50 milliseconds.

Hottest cybersecurity open-source tools of the month: August 2026
Presented here is a curated selection of noteworthy open-source cybersecurity solutions that have drawn recognition for their ability to enhance security postures across diverse settings.

Product showcase: AI Paper Trail shows the privacy cost of talking to AI
Proton’s AI Paper Trail is a free tool designed to make the information accumulated across AI conversations easier to see.

Cybersecurity jobs available right now: August 25, 2026
We’ve scoured the market to bring you a selection of roles that span various skill levels within the cybersecurity field. Check out this weekly selection of cybersecurity jobs available right now.

New infosec products of the month: August 2026
Here’s a look at the most interesting products from the past week, featuring releases from A10 Networks, Abnormal AI, F5 Networks, Intezer, Netscout, ScienceLogic, Searchlight Cyber, SelectHub, ServiceNow, Snyk, Tanium, and Tufin.


from Help Net Security https://ift.tt/MxEtYcZ

We may earn a commission from links on this page.

Spotlight search is one of the most useful features in macOS. You can access it by pressing Command-Space, and it allows you to find anything on your Mac. And there's so much more Spotlight search can do than you might realize. From performing currency conversions to running complex automation routines, here are 10 Spotlight search hacks that you'll find useful.

Enable clipboard history to keep track of everything you copy

Since the release of macOS 26 Tahoe, Spotlight search has been able to store your clipboard history. This means that Spotlight keeps a record of every item you copy on your Mac. This feature is disabled by default. You can enable it by clicking the Apple logo in the top-left corner of your Mac's screen, and going to System Settings > Spotlight. Scroll down, and enable Results from Clipboard. You can use the drop-down menu below this option to set an auto-delete timer for clipboard history, and your choices are 30 minutes, 8 hours, or 7 days.

To access clipboard history, press Command-Space to open Spotlight search, and then, press Command-4.

Use the built-in converter for instant currency and unit conversions

Currency conversion in Spotlight.
Credit: Pranay Parab

I stopped using online searches for currency and unit conversions ever since I discovered this Spotlight feature. To convert currency in Spotlight search, you can type "USD 100 to INR." The result appears in Spotlight, which is a lot faster than opening a browser and performing a web search. Feel free to replace the currency abbreviations with the ones you need, as Spotlight search supports almost all countries' currencies (but not cryptocurrencies). You can use similar syntax to convert units. For example, try something like: "100lbs to kg," or "3L to oz."

You should also try Spotlight's built-in calculator, which can handle arithmetic quite well. Ask it to add, subtract, divide, or multiply numbers, and Spotlight will show you the results instantly.

Try Spotlight search filters to find any file on your Mac

Once you have the search bar open, you can type any file name or app name, and Spotlight will search your Mac to locate it—that part is pretty clear. The fun begins when you start using search filters for advanced queries. You can ask Spotlight to restrict search results to PDF files by typing "/pdf" ahead of your query. This works for other file types such as jpeg, png, and tiff. To use it correctly, you'll have to select the filter from the search results. When you type "/pdf," the first search result will be "PDF" with the word Kind written under it. Select this, and type your query to restrict queries to that file type.

You can also use this format to search specific folders, such as "/downloads" to look for files in the Downloads folder in your Mac.

Send messages to any contact directly from Spotlight

Sending messages via Spotlight for Mac.
Credit: Pranay Parab

Whenever I open any chat app with the intention of messaging someone, I get distracted by other unread messages. To avoid this on my Mac, I've started messaging people directly from Spotlight, which lets me avoid looking at unrelated messages. To use this feature, open Spotlight, and type "Send Message." You can select the Send Message action from the results to start composing the text. You can then pick a recipient and hit the Return key to send the message.

Use Spotlight's built-in timer to bypass the Clock app

Your Mac's built-in Clock app lets you set alarms, timers, or use a stopwatch. This works fine, but when I'm setting timers, I usually want to do it fast. That's where Spotlight comes in. Type "Start Timer" and select the action in Spotlight. You can then add a duration for the timer, and it'll alert you when time's up.

Use this Spotlight shortcut to open files in Finder

When I see search results in Spotlight, sometimes I want to open the file or app, but more often than not, I want to open the folder that contains those results. I recently discovered a keyboard shortcut that opens the folder containing any search result directly from Spotlight. To use it, look for something in Spotlight search, and use the arrow keys to reach the correct result. Then press Command-Enter to open the file or app in Finder.

Translate languages directly from Spotlight

Translations in Spotlight for Mac.
Credit: Pranay Parab

I had no idea that Spotlight could also be your personal translator, until Lifehacker's Senior Technology Editor Jake Peterson told me about it. Now that I've used the feature, I don't think I'll be opening Google Translate by default when I need translations. To set up this feature on your Mac, go to System Settings > Language & Region, and select Translation Languages. Download the languages you need to translate, and enable On-Device Mode on the same page if you want offline translations. Click Done when all downloads are complete.

Once this is done, type "Translate" in Spotlight, and select the Translate Text action from the results. Type or paste some text into the "Text" field, and Spotlight will show you the translation shortly.

Use Spotlight to locate and open hidden system settings

Ever since macOS switched away from the old System Preferences menu, I've had trouble locating many settings on my MacBook. The new System Settings menu is less confusing for iOS users, but that doesn't help those of us who were used to the old layout. To get around this, I've started using Spotlight search to find system settings. You can type the name of the settings page, or even specific features such as Reduce Motion. Spotlight's results will show you two types of results: One where you can open the System Settings app, and the other where you can toggle the preference directly from search results. The latter is especially handy for features you want to toggle more than once, such as Bluetooth.

Assign dedicated keyboard shortcuts to your favorite actions

Now that Spotlight search lets you run actions such as creating notes, calendar events, and sending messages, it's worth considering ways to speed up this process. Typing the full name of each action isn't a good solution for actions you use frequently, which is why it's a good idea to assign keyboard shortcuts to your favorite actions. Instead of typing "Send Message" each time, you could trigger the action by typing "sm." To set this up, open Spotlight and press Command-3. This will load the list of actions supported by all installed apps on your Mac, and you can click the "Add quick keys" button next to any action to assign a keyboard shortcut.

Change Spotlight settings to exclude certain apps from search results

If you don't want to see results from certain apps in Spotlight search, you can exclude those apps easily. On your Mac, go to System Settings > Spotlight, and scroll down to the "Results from Apps" section. You can click the button next to any app to remove it from Spotlight results. Scroll down further till you reach the "Results from System" section. Here, you can click the i button next to "Files" and exclude certain folders from Spotlight search results.


from Lifehacker https://ift.tt/lwreLY1

We may earn a commission from links on this page.

You can’t turn off Strava’s AI summaries anymore. Sometime in July or August, the feature, called “Athlete Intelligence,” became a built-in part of premium subscriptions. If you have a free account, you still won’t see it, but if you subscribe to Strava Premium, you’ll now have the summaries stuck onto all of your workouts. 

What is Strava's "Athlete Intelligence"?

Athlete Intelligence, conveniently abbreviated AI, is a Strava feature that gives text responses to your workouts. It’s only available for premium subscribers. Strava refers to “insights” in these responses, but as far as I can tell, they just seem to regurgitate the information from the workout description, sometimes with added errors. 

I used the feature briefly, around the time it launched (I was a premium subscriber then), but quickly turned it off when I realized it wasn’t telling me anything interesting. I asked my colleague Meredith Dietz, who has a premium subscription, whether she had seen anything useful in her Athlete Intelligence. She said, “They’re usually positive, so that’s nice. But ultimately: useless.” 

Meredith has written more about why AI fitness summaries are mostly useless, and Strava’s AI checks every box: it doesn’t use enough context to understand what’s going on, it presents generic advice as if it were personal, and it’s overconfident in its incomplete data. She showed me a recent Athlete Intelligence summary that said a run was both a “recovery run” and included her “fastest pace in two weeks.” Those are simply not compatible statements. Another message complimented her “solid half-marathon effort” on a run that Meredith says was “not even close to a half-marathon effort.” 

What happened behind the scenes? 

You used to be able to turn off the AI. When Strava launched Athlete Intelligence in October 2024, it was a “beta” feature available to premium users only. Since then—as far as I can remember—Strava’s support page had instructions for opting out of Athlete Intelligence. 

But that changed recently. The last Wayback Machine snapshot that included those instructions is from June 30, 2026. A snapshot from Aug. 4 removed both the question and answer about opting out. On Aug. 26, I noticed a Reddit thread where users were wondering where the opt-out feature went. The support page currently says, “There isn’t an option to opt out of Athlete Intelligence.” 

I asked what happened, and received an answer from a Strava spokesperson: “As was standard practice for experimental features, Athlete Intelligence launched with a "turn off" mechanism scoped to its initial beta period. Given the feature’s formal exit from beta, that mechanism is no longer available. We invite all subscribers to tap Give Feedback to help us improve the insights they see.”

Athlete Intelligence officially left beta in February of last year. If the support page was kept up to date over the subsequent year and a half, then it seems the opt-out was removed much later. (The instructions used to say to click “leave beta” and then changed to “leave Athlete Intelligence” sometime before June 21 this year.) I asked Strava for clarification on the timeline, and got the answer: “Thanks for the follow up, we're not able to provide additional information.”

Why “Athlete Intelligence” has been such a disappointment

Strava claimed in its February 2025 announcement that over 80% of users found Athlete Intelligence useful. That seems hard to believe, given the weaknesses that both Meredith and I noticed in our own AI summaries. For all my browsing of Strava user forums, I’ve often seen people complaining about the AI’s tone or pointing out its mistakes; I’m really not seeing anyone praising it for being insightful or for helping to analyze or plan training. 

Meredith finds the summaries easy to ignore. I found they annoyed me, so I hid them while it was still possible to do so. So far I’m not seeing anybody who opted out complaining that the summaries are back; it’s possible they will remain hidden. But the option to turn them off is no longer available. You can still “leave feedback” on a given response, but there used to be an option to leave Athlete Intelligence altogether. That option is no longer there, and given Strava’s statement, it doesn’t seem likely it will come back.


from Lifehacker https://ift.tt/1vWxiDV